Cross-domain system reliability modeling and evaluation method based on OODA ring theory
By constructing an information domain-physical domain collaborative network model and a dynamic reconfiguration mechanism, the shortcomings of cross-domain system reliability assessment in existing technologies are addressed, enabling accurate assessment and capability recovery in complex environments, and improving the reliability assessment and design capabilities of cross-domain equipment systems.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- BEIHANG UNIV
- Filing Date
- 2026-02-04
- Publication Date
- 2026-05-01
AI Technical Summary
Existing technologies are unable to fully and accurately reflect the operational rules of cyber-physical cross-domain systems in complex cross-domain environments, especially the impact of communication links on the OODA loop closure. Furthermore, they lack systematic node failure and random attack recovery and reconstruction mechanisms, which affects the accuracy of system reliability assessment.
Based on the OODA loop theory, an information domain-physical domain collaborative network model is constructed, a mapping relationship model is established, and node failures and random attacks are simulated using the Monte Carlo simulation method. Combined with the dynamic reconstruction mechanism of the information domain and the physical domain, the reliability of the cross-domain system is evaluated.
It enables reliability assessment of cross-domain systems in multiple scenarios, improves the adaptability and accuracy of assessment results, reflects the system's ability to withstand failure conditions and its recovery process, and provides quantitative basis for the design and operation and maintenance of cross-domain equipment systems.
Smart Images

Figure CN121967244A_ABST
Abstract
Description
A Reliability Modeling and Evaluation Method for Cross-Domain Systems Based on OODA Loop Theory Technical Field
[0001] This invention relates to the field of complex system modeling and reliability assessment technology, and more specifically, to a cross-domain system reliability modeling and assessment method based on OODA loop theory. Background Technology
[0002] With the continuous improvement of informatization and intelligentization, cyber-physical cross-domain systems are widely used in the military field. Such systems are typically composed of physical domain elements such as detection, decision-making, and strike, and information domain elements such as gateways, routers, and terminals. Their operation relies on close collaboration between multiple layers and multiple nodes.
[0003] However, in actual operation, the system inevitably faces internal and external disturbances such as node failures and random attacks. These factors can lead to task chain interruptions, thereby affecting the overall reliability of the system. Existing research mostly focuses on reliability modeling and evaluation in the physical domain, often using only the connectivity of physical links as the criterion for whether the system forms a loop, failing to fully consider the role of the information domain in system operation, especially the impact of communication links on OODA loop closure. This approach is difficult to comprehensively and accurately reflect the actual operating rules of the system in complex cross-domain environments. At the same time, there is a lack of systematic modeling and evaluation methods for recovery and reconstruction mechanisms for node failures and random attacks, making it difficult to provide effective support for improving the reliability of the system in dynamic environments.
[0004] Therefore, there is an urgent need for a cross-domain system reliability modeling and evaluation method based on OODA loop theory to solve the above problems. Summary of the Invention
[0005] The purpose of this invention is to solve the technical problems mentioned in the background section and provide a method for cross-domain system reliability modeling and evaluation based on OODA loop theory, comprising the following steps: S1: Constructing an information domain-physical domain collaborative network model for a cross-domain equipment system; S2: Based on the information domain-physical domain collaborative network model, establishing a mapping relationship model to characterize the interaction relationships between nodes in different domains; S3: Without considering node failure, calculating the number of OODA loops that the system can form based on the mapping relationship model; S4: Considering only node failures, updating the mapping relationship model and calculating the number of OODA loops that the system can form under node failure conditions; S5: Considering only the effect of random attacks... S6: Under the combined effect of node failure and random attack, update the mapping relationship model, calculate the number of OODA rings that the system can form under joint failure conditions, and evaluate the reliability of the cross-domain system under node failure conditions accordingly. S7: Under node failure conditions, introduce a dynamic reconstruction mechanism of the information domain and physical domain to reconstruct and update the information domain-physical domain cooperative network model and mapping relationship model. S8: Based on the reconstructed information domain-physical domain cooperative network model and mapping relationship model, recalculate the number of OODA rings that the system can form, and evaluate the reliability of the cross-domain system under the reconstruction mechanism accordingly.
[0006] As a preferred technical solution of the present invention, step S1 includes: S1.1: Constructing a network model from two dimensions, the information layer and the physical layer, for cross-domain equipment systems. The physical layer includes three types of nodes: detection nodes, decision nodes, and strike nodes. The information layer includes four types of nodes: detection node gateways, decision node gateways, routing nodes, and strike node terminals; S1.2: Constructing network edges to describe the deployment relationship between detection nodes and detection node gateways, the information transmission relationship between detection node gateways and routing nodes, the information transmission relationship between routing nodes and decision node gateways, the deployment relationship between decision nodes and decision node gateways, and the information transmission relationship between routing nodes and strike nodes. The information transmission relationship between node terminals and the deployment relationship between strike nodes and strike node terminals; Step S2 includes: S2.1: Based on the interaction relationship between different types of nodes, a 0-1 matrix is used to represent the mapping relationship between nodes; S2.2: Construct a mapping relationship matrix including probe node-probe node gateway, probe node gateway-routing node, routing node-decision node gateway, decision node-decision node gateway, routing node-strike node terminal, and strike node-strike node terminal, where a matrix element value of 1 indicates that there is an interaction relationship between the corresponding nodes, and a value of 0 indicates that there is no interaction relationship between the corresponding nodes.
[0007] As a preferred technical solution of the present invention, steps S3 to S6 include: S3.1: Based on the constructed information domain-physical domain collaborative network model and mapping relationship matrix, the number of OODA loops that the system can form is calculated by calculating the complete path formed by "detection node – detection node gateway – routing node – decision node gateway – decision node – decision node gateway – routing node – strike node terminal – strike node", where each complete path corresponds to the completion of one OODA behavior of reconnaissance, judgment, decision and strike; S4.1: Construct a node failure model according to the failure rate of various nodes in the physical domain and information domain, and use the Monte Carlo simulation method to simulate the failure behavior of nodes under the set simulation time and step size conditions; S4.2: Update the mapping relationship matrix according to the node failure state, and count the number of OODA loops that the system can form under node failure conditions by matrix multiplication; S5.1: According to the probability of random strike occurrence and the probability of strike success, use the Monte Carlo simulation method to simulate the failure behavior of nodes under random strike, and count the number of OODA loops that the system can form under random strike conditions; S6.1: In the node itself Under the combined effects of faults and random attacks, a Monte Carlo simulation method is used to jointly update the node states and mapping relationship matrix, and the number of OODA loops that the system can form under joint failure conditions is counted. S7.1: The reliability of the cross-domain system is evaluated by calculating the ratio of the number of OODA loops that the system can form under node failure conditions to the number of OODA loops that the system can form without considering node failure. This is a preferred technical solution of the present invention. Steps S7 and S8 include: S7.1: For physical domain nodes, when a node fails, a similar resource replacement strategy or a physical node corrective maintenance strategy is used for reconstruction. S7.2: For information domain nodes, when a node fails, a resource backup strategy or an information node corrective maintenance strategy is used for reconstruction. S8.1: Under the action of the information domain and physical domain reconstruction strategies, the number of OODA loops that the system can form is recalculated. S8.2: The reliability of the cross-domain system under the reconstruction mechanism is evaluated by calculating the ratio of the number of OODA loops that the system can form under node failure and dynamic reconstruction conditions to the number of OODA loops that the system can form without considering node failure.
[0008] This invention provides a cross-domain system reliability modeling and evaluation system based on OODA loop theory, comprising: a cross-domain network modeling module for constructing an information domain-physical domain collaborative network model and generating a mapping matrix; a system reliability evaluation module for counting the number of OODA loops and evaluating system reliability based on node failure and random impact simulation processes under a given network model; and a system reliability evaluation module under a reconfiguration mechanism for introducing information domain and physical domain reconfiguration strategies under node failure conditions and evaluating the system reliability under the reconfiguration mechanism.
[0009] As a preferred technical solution of the present invention, the cross-domain network modeling module includes: a physical node and information node module, used to collect and input the type, quantity, failure rate and correspondence between nodes in the physical domain and information domain; and a mapping relationship matrix generation module, used to construct a mapping relationship matrix reflecting the interaction relationships of various nodes based on the node information.
[0010] As a preferred technical solution of the present invention, the system reliability assessment module includes: an OODA closed-loop path statistics module, used to calculate the number of OODA loop closures without considering node failures based on a mapping relationship matrix; a system reliability assessment module under node failure conditions, used to obtain the number of OODA loop closures considering node failures through simulation calculations based on a mapping relationship matrix, considering the failure rates of various nodes in the physical and information domains, and on this basis, calculate the system reliability considering node failures; a system reliability assessment module under random attack conditions, used to obtain the number of OODA loop closures under random attack conditions through simulation calculations based on a mapping relationship matrix, according to the input probability of random attack occurrence and the probability of attack success, and on this basis, calculate the system reliability under random attack; and a system reliability assessment module under the combined effect of node failures and random attacks, used to obtain the number of OODA loop closures considering node failures through simulation calculations based on a mapping relationship matrix, and on this basis, calculate the system reliability under the combined effect of node failures and random attacks.
[0011] As a preferred technical solution of the present invention, the system reliability assessment module under the reconstruction mechanism includes: a system reliability assessment module under the physical domain reconstruction strategy, used to calculate the number of OODA loop closures under the reconstruction strategy based on the mapping relationship matrix, under the influence of node failure and random attacks, combined with the same resource replacement strategy and corrective maintenance strategy of physical domain nodes, and on this basis, assess the system reliability under the physical domain reconstruction strategy; a system reliability assessment module under the information domain reconstruction strategy, used to calculate the number of OODA loop closures under the reconstruction strategy based on the mapping relationship matrix, under the influence of node failure and random attacks, combined with the resource backup strategy and corrective maintenance strategy of information domain nodes, and on this basis, assess the system reliability under the information domain reconstruction strategy; and a system reliability assessment module under the information-physical domain reconstruction strategy, used to calculate the number of OODA loop closures under the reconstruction strategy based on the mapping relationship matrix, under the influence of node failure and random attacks, by comprehensively applying the reconstruction strategies of the physical domain and information domain, and on this basis, assess the system reliability under the information-physical domain reconstruction strategy.
[0012] Compared with the prior art, the present invention has the following beneficial effects: Based on the OODA loop theory, the present invention constructs a cross-domain system modeling and evaluation framework that coordinates the information domain and the physical domain, and extends the traditional reliability analysis method that takes a single domain or single-layer network as the object to a unified modeling and evaluation method for cross-domain equipment systems.
[0013] By introducing a mapping relationship model between the information domain and the physical domain, physical functional nodes such as detection, decision-making, and strike are structurally associated with information nodes such as information transmission, routing, and terminals. This allows the formation conditions of the OODA loop in the system to be explicitly characterized, thereby avoiding the problems of difficulty in quantifying cross-domain collaborative capabilities and difficulty in characterizing the coupling relationship between information links and physical links in existing methods. This improves the completeness and interpretability of system-level reliability assessment.
[0014] This invention uses the "number of OODA rings that can be formed" as the core quantitative indicator of the reliability of cross-domain systems. Based on this, it systematically considers various failure scenarios such as node failure, random attacks, and the combined effect of the two, and realizes multi-scenario evaluation of the operational capability of cross-domain systems.
[0015] By introducing node failure models and random hit models, and combining simulation methods to dynamically update the mapping relationship model, the OODA loop evolution process of the system under different failure conditions can be quantitatively analyzed. This overcomes the problem that traditional reliability assessment methods only focus on a single failure mode and are difficult to reflect the degradation law of system capability under complex adversarial environments, thus improving the adaptability of the assessment results to actual application scenarios.
[0016] This invention further introduces a dynamic reconstruction mechanism between the information domain and the physical domain during the reliability assessment process. Through strategies such as substitution of similar resources, resource backup, and corrective maintenance, the cross-domain architecture is adaptively adjusted, and the system reliability is evaluated based on the change in the number of OODA loops before and after reconstruction.
[0017] This method can not only reflect the passive withstand capability of the system under failure conditions, but also characterize the process of the system achieving capability recovery through structural reconstruction. It provides a quantitative basis for the reliability design, operation and maintenance support and resource allocation optimization of cross-domain equipment systems, and has strong engineering practical value and promotion significance. Attached Figure Description
[0018] Figure 1 is a mapping diagram of the nodes in Figure 1 of the present invention; Figure 2 is a schematic diagram of the physical domain reconstruction strategy of the present invention; Figure 3 is a schematic diagram of the information domain reconstruction strategy of the present invention; Figure 4 is a general technical roadmap; Figure 5 is a trend diagram of the number of OODA rings considering node failure; Figure 6 is a trend diagram of the system reliability considering node failure; Figure 7 is a trend diagram of the number of OODA rings considering and not considering the reconstruction strategy; Figure 8 is a trend diagram of the system reliability considering and not considering the reconstruction strategy; Figure 9 is a trend diagram of the number of OODA rings; Figure 10 is a trend diagram of the system reliability. Detailed Implementation
[0019] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the embodiments and Figures 1-10. It should be understood that the specific embodiments described herein are merely illustrative of the invention and are not intended to limit the invention.
[0020] This invention proposes a cross-domain system reliability modeling and evaluation method based on OODA ring theory. The specific steps are as follows: Step 1: Based on the composition structure of the cross-domain equipment system, construct a cyber-physical multilayer network model. The network model includes seven types of nodes and six types of edges. The seven types of nodes are the detection nodes of the physical domain. Decision nodes and strike nodes and information domain detection node gateway ,routing Decision node gateway and strike node terminals The seven types of edges represent the deployment relationships between probe nodes and their gateways. Detecting the information transmission relationship between the node gateway and the router Information transmission relationship between routing and decision-making node gateway Deployment relationship between decision nodes and decision node gateways The information transmission relationship between routing and attack node terminals And the deployment relationship between strike nodes and strike node terminals. .
[0021] In addition, detection nodes Corresponding to the Observe activity in the OODA loop, it is used to acquire external information; decision nodes Corresponding to the Orient and Decide activities in the OODA loop, these activities analyze the acquired external information and form decisions; [the text abruptly shifts to a seemingly unrelated topic:] Strike node Corresponding to the Action (Act) activity in the OODA loop, it is used to execute decisions and implement actual actions.
[0022] In the information domain, gateways and routers are responsible for the information transmission function between nodes in the physical domain. They are used to transmit and forward information between different nodes, thereby ensuring the closure of the OODA loop. The schematic diagram of the model is shown in Figure 1.
[0023] Step 2: Based on the information-physical multilayer network model ,in, , Construct a mapping matrix of detection node-detection node gateway, detection node gateway-router, route-route, route-decision node gateway, decision node-decision node gateway, route-strike node terminal, and strike node-strike node terminal. .
[0024] Mapping matrix of probe nodes to probe node gateways It can be represented as: (1) Among them, Indicates the gateway of the probe node Deployed on probe nodes superior, Indicates the gateway of the probe node Not deployed on the probe node Above. Furthermore, since a gateway can only be deployed on one probe node, therefore... .
[0025] Detection node gateway-router mapping matrix It can be represented as: (2) Among them, , indicating the probe node gateway It can transmit probe information to the router. , Indicates the gateway of the probe node Probe information cannot be transmitted to the router. .
[0026] Mapping matrix of routing nodes and gateways It can be represented as: (3) Among them, Indicates routing It can transmit detection information to the decision node gateway. , Indicates routing Probe information cannot be transmitted to the decision node gateway. Meanwhile, the mapping matrix between decision node gateways and routes can be represented as follows: .
[0027] Mapping matrix of decision node - decision node gateway It can be represented as: (4) Among them, Indicates the decision node gateway Deployed at decision nodes superior, Indicates the decision node gateway Not deployed at decision nodes Above. Furthermore, since a gateway can only be deployed on one probe node, therefore... The mapping matrix between decision node gateways and decision nodes can be represented as follows: .
[0028] Mapping matrix of routing and attack node terminals It can be represented as: (5) Among them, Indicates routing Decision information can be transmitted to the strike node terminal. , This indicates that the router is unable to transmit decision information to the attack node terminal. Strike node-strike node terminal mapping matrix It can be represented as: (6) Among them, Indicates attacking node terminals Deployed at strike nodes superior, Indicates attacking node terminals Not deployed at the strike node superior.
[0029] Furthermore, since a terminal can only be deployed on one strike node, therefore The mapping matrix between strike node terminals and strike nodes can be represented as follows: .
[0030] Step 3: Based on the constructed mapping matrix, calculate the number of OODA loops that can be formed by the system without considering node failures using the following formula: (7) Step 4: Based on the constructed mapping matrix and the calculated OODA ring number, the system reliability is evaluated considering node failures.
[0031] The specific steps are as follows: 1. Set the simulation start time. Simulation end time and simulation step size 2. Based on the node failure rate, the following calculations are performed. The first type node Failure function of each node and reliability function ,in 3. Define the state matrix for each type of node. The value is 1 when the node is in normal working condition and 0 when the node is in a faulty state. Taking a probe node as an example, its state matrix... It can be represented as: (8) Among them, when Indicates the detection node In normal working condition Indicates the detection node 4. Based on the reliability function of each node in the system, Monte Carlo simulation is used to analyze the fault state. 5. The state of each node is determined at any given time, and the states of various types of nodes are updated accordingly. Based on the mapping matrix between nodes and the state matrices of various types of nodes, the mapping matrix between nodes is updated. Taking the probe node-probe node gateway mapping matrix as an example, the updated mapping matrix... It can be represented as: (9) Among them, and This is the probe node and probe node gateway state matrix obtained after the previous update. 6. Based on the updated mapping matrix, using formula (7), calculate the number of OODA rings that can be formed considering node failures: (10) Among them, For the first The results obtained from the simulation calculation The number of rings in OODA at the current time. 7. Calculate the system reliability considering node failures using formula (11): (The number of simulations is given.) (11).
[0032] Step 5: Using a method similar to Step 4, first set the probability of random attack, the probability of successful attack, and the number of nodes involved in each attack. Then, use Monte Carlo simulation to update the state matrix of various nodes at different times.
[0033] Subsequently, based on the updated state matrix, the relationship mapping matrix between nodes is updated, and the number of OODA loops that can be formed considering random disturbances is calculated, thereby assessing the reliability under random disturbances. An assessment will be conducted.
[0034] Step 6: Using a method similar to Steps 4 and 5, and considering both node failures and random disturbances, update the state matrices of various nodes at different times using Monte Carlo simulation. Then, based on the updated state matrices, update the relationship mapping matrix between nodes and calculate the number of OODA loops that can be formed considering node failures and random disturbances. This allows for an assessment of the reliability considering node failures and random disturbances. An assessment will be conducted.
[0035] Step 7: Under the combined effects of node failures and random interference, a reconstruction strategy for the physical and information domains is introduced. The reconstructed network topology and mapping matrix are updated, and the number of possible OODA rings is calculated to evaluate the system reliability under the reconstruction mechanism. The specific steps are as follows: 1. For various types of nodes in the physical domain, when a node fails due to a fault or random attack, a node of the same type connected to the same route can temporarily replace its function, thereby maintaining the normal operation of the system. At the same time, corrective maintenance is performed on the failed node. The schematic diagram of the physical domain reconstruction strategy is shown in Figure 2.
[0036] The calculation process is as follows: 1) Based on the failure rate and maintenance rate of the nodes, the state of the nodes is calculated using the Monte Carlo simulation method, and the state matrix of various types of nodes in the physical domain is updated. On this basis, the corresponding mapping relationship matrix is updated; 2) Based on the connection relationship between the node gateway / terminal and the route, the route sharing judgment matrix between nodes of the same type is constructed through formula (12) to identify which nodes of the same type are connected to the same route. The following is an explanation using probe nodes, probe node gateways and routes as examples: (12) Among them, This is a binarization operator; it is set to 1 when the matrix element value is greater than 0, and 0 otherwise. , They are identity matrices of the same dimension.
[0037] 3) Based on the mapping matrix between nodes and the state matrix of nodes, determine whether there are any other nodes of the same type connected to the same route that are functioning normally. This will be illustrated using a node detection example: (13) When the value of a matrix element is equal to 1, it means that there are nodes of the same type connected to the same route and can work normally; when the value of a matrix element is equal to 0, there are no such nodes.
[0038] 4) When a node of the same type with the necessary replacement conditions exists, it is used to replace the failed node, and the mapping matrix of the corresponding node is updated. This is illustrated using a probe node as an example: (14) (15) 2. For various nodes in the information domain, when a node fails due to a fault or random attack, other information nodes on the same physical node can temporarily replace its function, thereby maintaining the continued operation of the system. At the same time, corrective maintenance is carried out on the failed node. The schematic diagram of the information domain reconstruction strategy is shown in Figure 3.
[0039] The calculation process is as follows: 1) Based on the failure rate and maintenance rate of the nodes, the state of the nodes is calculated using the Monte Carlo simulation method, and the state matrix of various types of nodes in the information domain is updated. On this basis, the corresponding mapping relationship matrix is updated; 2) Based on the mapping relationship between physical nodes and information nodes, the information node shared judgment matrix is constructed using formula (16) to determine which information nodes belong to the same physical node. The following is an explanation using a probe node and a probe node gateway as an example: (16) Among them, This is a binarization operator; it is set to 1 when the matrix element value is greater than 0, and 0 otherwise. , They are identity matrices of the same dimension.
[0040] 3) Based on the mapping matrix between nodes and the state matrix of nodes, determine whether there are other normally functioning information nodes on the physical node where the failed information node is located to replace its function. This will be illustrated using a probe node and probe node gateway as an example: (17) Among them, This is the state matrix for the probe node gateway. When a matrix element is equal to 1, it indicates that there are other probe node gateways on this probe node; when a matrix element is equal to 0, there are no other probe node gateways.
[0041] 4) When a node of the same type with the necessary replacement conditions exists, it is used to replace the failed node, and the mapping matrix of the corresponding node is updated. This is illustrated using a probe node and its gateway as an example: (18) (19) 3. Based on the updated mapping matrix, use formulas (7) and (10) to calculate the number of OODA rings that can be formed under the reconstruction mechanism. And use formula (11) to calculate the system reliability under the reconstruction mechanism.
[0042] This invention uses an unmanned cross-domain equipment system as a simulation object to verify the feasibility of the proposed modeling and evaluation algorithm. The system consists of 100 multi-functional unmanned equipment nodes, possessing core functions such as detection, information discrimination, decision-making, and strike capabilities. Each node undertakes a corresponding task according to its functional division. To achieve these functions, various physical nodes interact with information nodes deployed on them. Specifically, detection-type unmanned equipment is responsible for detecting the external environment and transmitting the detection information to a router through its onboard gateway. The router then forwards this information to the gateway of the decision-making equipment, enabling the decision-making unmanned equipment to receive and make judgments and decisions based on the external information. Subsequently, the decision-making unmanned equipment transmits the decision results to the router through the gateway, and the router then transmits the decision information to the terminal of the strike-type unmanned equipment, which then executes the corresponding action tasks.
[0043] In terms of system architecture, detection, decision-making, and strike unmanned equipment can be considered as physical domain nodes, responsible for the actual execution of tasks; while gateways, terminals, and routers deployed on various types of equipment can be considered as information domain nodes, responsible for information transmission between nodes. Only through the coordinated action of the physical and information domains can a complete OODA loop be formed and the system's functions realized. Therefore, this invention divides the cross-domain equipment system into physical and information domains for joint modeling, thereby more accurately reflecting the system's operating mechanism and reliability characteristics in complex environments.
[0044] The unmanned cross-domain equipment system consists of 40 detection-type unmanned equipment, 20 decision-making-type unmanned equipment, and 40 strike-type unmanned equipment. The equipment parameters are shown in Table 1. Simultaneously, 8 detection-type equipment, 4 decision-making-type unmanned equipment, and 8 strike-type equipment are connected to the same route. The parameters of the gateway, terminal, and route are shown in Table 2.
[0045] Table 1 Parameters of various unmanned equipment Table 2 Parameters of Various Information Nodes Furthermore, during the simulation process, the number of Monte Carlo simulations, simulation duration, and simulation step size set by this invention are shown in Table 3.
[0046] Table 3 Simulation parameter settings 1. Information Domain-Physical Domain Network Modeling Method: Compared with existing research that only constructs OODA ring models from the perspective of the physical layer, this invention proposes an information domain-physical domain network modeling method. By constructing a mapping relationship matrix between various nodes, it can simultaneously describe the synergistic effect of the information layer and the physical layer, solving the problem that traditional methods fail to reflect the influence of information transmission nodes on the formation of OODA rings, thus more realistically reflecting the operating mechanism of cross-domain systems.
[0047] 2. A Reliability Assessment Method for Cross-Domain Systems Based on OODA Rings: This invention proposes a reliability assessment method for cross-domain systems based on OODA rings. It incorporates the closure conditions of both information and physical links into the OODA ring modeling framework, thereby revealing a more comprehensive mechanism for the formation of OODA rings. Unlike traditional studies that only consider physical link closure, this method introduces the role of communication nodes in the assessment process, addressing the shortcomings of existing models that ignore the impact of information transmission within physical nodes on ring formation. Simultaneously, a node failure model and a random attack model are established. Monte Carlo simulations are used to obtain the state changes of nodes during system operation, and the reliability of the system is evaluated based on the change in the number of OODA rings before and after node failure. The method proposed in this invention can more accurately reflect the operational patterns of cross-domain systems in complex environments, providing a more accurate assessment of system reliability and offering a reference for the design of cross-domain equipment systems.
[0048] During the operation of the unmanned equipment system, the system will be subject to random attacks. The probability of random attacks, the number of affected nodes, and the probability of nodes failing due to attacks are shown in the figure.
[0049] Table 4 Random Strike Parameters Figures 5 and 6 show the trends in the number of OODA loops formed by the system and the system reliability, considering both node failures and random attacks. As can be seen from Figures 5 and 6, the number of OODA loops formed by the system gradually decreases with increasing simulation time. The combined effects of node failures and random attacks have the greatest impact on the number of OODA loops formed by the cross-domain equipment system and its overall reliability.
[0050] 3. Physical Domain and Information Domain Reconstruction Strategies: To improve the reliability of cross-domain equipment systems under node failures and random attacks, this invention proposes reconstruction strategies applicable to both the physical and information domains. For the physical domain, this invention proposes a similar resource substitution strategy and a physical node correction and maintenance strategy: the similar resource substitution strategy means that when a node fails due to a fault or random attack, a node of the same type connected to the same route can temporarily replace its function, thereby maintaining the continuous operation of the system.
[0051] The physical node corrective maintenance strategy involves performing corrective maintenance on failed nodes to restore their performance. For the information domain, this invention proposes a resource backup strategy and an information node corrective maintenance strategy. The resource backup strategy means that when a node fails due to a fault or random attack, other information nodes located on the same physical node can temporarily replace its function to ensure the normal operation of the system. The information node corrective maintenance strategy involves performing corrective maintenance on failed information nodes to restore functionality. The maintenance rates of physical nodes and information nodes are shown in Table 5.
[0052] Figures 7 and 8 show the trends in the number of OODA loops and system reliability under node failure conditions, with and without a reconfiguration mechanism. As the figures show, the number of OODA loops and system reliability decrease over simulation time. Without a reconfiguration mechanism, the number of OODA loops decreases rapidly over time, indicating that node failures accumulate and cannot be recovered, leading to a rapid decline in system reliability. In contrast, with the reconfiguration mechanism, the number of OODA loops decreases, but the rate of decrease slows significantly and even shows a rebound in some stages. This is because when a node fails, the system employs reconfiguration strategies in both the physical and information domains, thus mitigating the impact of node failure to some extent. These results demonstrate that the reconfiguration mechanism can effectively alleviate the impact of node failures on the system and enhance system reliability, enabling it to continue operating under node failure conditions.
[0053] Under the combined effects of random disturbances and node failures, the trends of the number of OODA loops and system reliability are shown in the figure, considering both reconfiguration and non-reconfiguration mechanisms. As can be seen from the figure, the number of OODA loops and the system reliability decrease over time. Furthermore, compared to the case without reconfiguration, reconfiguration can slow down the decrease in the number of OODA loops and the rate of decline in system reliability.
[0054] The present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments, but the present invention is not limited to these embodiments. Equivalent modifications made by those skilled in the art without departing from the principles of the present invention should fall within the protection scope of the present invention.
[0055] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. A method for cross-domain system reliability modeling and evaluation based on OODA loop theory, characterized in that, The process includes the following steps: S1: Constructing an information domain-physical domain collaborative network model for a cross-domain equipment system; S2: Based on the information domain-physical domain collaborative network model, establishing a mapping relationship model to characterize the interaction relationships between nodes in different domains; S3: Without considering node failure, calculating the number of OODA loops that the system can form based on the mapping relationship model; S4: Considering only node failures, updating the mapping relationship model and calculating the number of OODA loops that the system can form under node failure conditions; S5: Considering only the effect of random attacks, updating the mapping relationship model and calculating the number of OODA loops that the system can form under random attack conditions. S6: Considering both node failures and random impacts, update the mapping model and calculate the number of OODA loops that the system can form under the combined failure condition. S7: Under node failure conditions, a dynamic reconstruction mechanism for the information domain and physical domain is introduced to reconstruct and update the information domain-physical domain collaborative network model and mapping relationship model. S8: Based on the reconstructed information domain-physical domain collaborative network model and mapping relationship model, recalculate the number of OODA rings that the system can form, and evaluate the reliability of the cross-domain system under the reconstruction mechanism accordingly.
2. The method for cross-domain system reliability modeling and evaluation based on OODA loop theory according to claim 1, characterized in that, Step S1 includes: S1.1: Constructing a network model from two dimensions, the information layer and the physical layer, for cross-domain equipment systems. The physical layer includes three types of nodes: detection nodes, decision nodes, and strike nodes. The information layer includes four types of nodes: detection node gateways, decision node gateways, routing nodes, and strike node terminals. S1.2: Constructing network edges to describe the deployment relationship between detection nodes and detection node gateways, the information transmission relationship between detection node gateways and routing nodes, the information transmission relationship between routing nodes and decision node gateways, the deployment relationship between decision nodes and decision node gateways, the information transmission relationship between routing nodes and strike node terminals, and the deployment relationship between strike nodes and strike node terminals. Step S2 includes: S2.1: Using a 0-1 matrix to represent the mapping relationship between nodes according to the interaction relationship between different types of nodes. S2.2: Constructing a mapping relationship matrix including detection node-detection node gateway, detection node gateway-routing node, routing node-decision node gateway, decision node-decision node gateway, routing node-strike node terminal, and strike node-strike node terminal. A matrix element value of 1 indicates that there is an interaction relationship between the corresponding nodes, and a value of 0 indicates that there is no interaction relationship between the corresponding nodes.
3. The method for cross-domain system reliability modeling and evaluation based on OODA loop theory according to claim 1, characterized in that, Steps S3 to S6 include: S3.1: Based on the constructed information domain-physical domain collaborative network model and mapping relationship matrix, calculate the number of OODA loops that the system can form by calculating the complete path formed by "detector node – detector node gateway – routing node – decision node gateway – decision node – decision node gateway – routing node – strike node terminal – strike node", where each complete path corresponds to the completion of one OODA action of reconnaissance, judgment, decision and strike; S4.1: Construct a node failure model according to the failure rate of various nodes in the physical domain and information domain, and use the Monte Carlo simulation method to simulate the failure within the set simulation time and step size. S4.2: Simulate the failure behavior of nodes under random impact conditions; S5.1: Update the mapping matrix according to the node failure state, and count the number of OODA loops that the system can form under node failure conditions by matrix multiplication; S6.1: Simulate the failure behavior of nodes under random impact conditions using Monte Carlo simulation method based on the probability of random impact and the probability of successful impact, and count the number of OODA loops that the system can form under random impact conditions; S7.1: Calculate the ratio of the number of OODA loops that the system can form under node failure conditions to the number that the system can form without considering node failure conditions, and evaluate the reliability of the cross-domain system.
4. The method for cross-domain system reliability modeling and evaluation based on OODA loop theory according to claim 1, characterized in that, Steps S7 and S8 include: S7.1: For physical domain nodes, when a node fails, a similar resource replacement strategy or a physical node corrective maintenance strategy is used for reconstruction; S7.2: For information domain nodes, when a node fails, a resource backup strategy or an information node corrective maintenance strategy is used for reconstruction; S8.1: Under the action of the information domain and physical domain reconstruction strategies, the number of OODA rings that the system can form is recalculated; S8.2: The reliability of the cross-domain system under the reconstruction mechanism is evaluated by calculating the ratio of the number of OODA rings that the system can form under the condition of considering node failure and dynamic reconstruction mechanism to the number of OODA rings that the system can form without considering node failure.
5. A cross-domain system reliability modeling and evaluation system based on OODA loop theory, characterized in that, include: The cross-domain network modeling module is used to construct information domain-physical domain collaborative network models and generate mapping relationship matrices; The system reliability assessment module is used to count the number of OODA loops and evaluate the system reliability based on the simulation process of node failure and random impact under a given network model. The system reliability assessment module under the reconfiguration mechanism is used to introduce information domain and physical domain reconfiguration strategies under node failure conditions and evaluate the system reliability under the reconfiguration mechanism.
6. The cross-domain system reliability modeling and evaluation system based on OODA loop theory according to claim 5, characterized in that, The cross-domain network modeling module includes: a physical node and information node module, used to collect and input the type, quantity, failure rate, and correspondence between nodes in the physical domain and information domain; and a mapping relationship matrix generation module, used to construct a mapping relationship matrix reflecting the interaction relationships of various nodes based on the node information.
7. The cross-domain system reliability modeling and evaluation system based on OODA loop theory according to claim 5, characterized in that, The system reliability assessment module includes: an OODA closed-loop path statistics module, used to calculate the number of OODA loop closures without considering node failures based on the mapping relationship matrix; a system reliability assessment module under node failure conditions, used to calculate the number of OODA loop closures considering node failures by simulation calculations based on the mapping relationship matrix, considering the failure rates of various nodes in the physical and information domains, and then calculate the system reliability considering node failures; a system reliability assessment module under random attack conditions, used to calculate the number of OODA loop closures under random attack conditions by simulation calculations based on the mapping relationship matrix, according to the input probability of random attack occurrence and probability of attack success, and then calculate the system reliability under random attack conditions; and a system reliability assessment module under the combined effects of node failures and random attacks, used to calculate the number of OODA loop closures considering node failures by simulation calculations based on the mapping relationship matrix, and then calculate the system reliability under the combined effects of node failures and random attacks.
8. The cross-domain system reliability modeling and evaluation system based on OODA loop theory according to claim 5, characterized in that, The system reliability assessment module under the reconfiguration mechanism includes: a system reliability assessment module under the physical domain reconfiguration strategy, used to calculate the number of closed OODA loops under the reconfiguration strategy based on the mapping relationship matrix, under the influence of node failures and random attacks, combined with the resource replacement strategy and corrective maintenance strategy of physical domain nodes, and on this basis, assess the system reliability under the physical domain reconfiguration strategy; a system reliability assessment module under the information domain reconfiguration strategy, used to calculate the number of closed OODA loops under the reconfiguration strategy based on the mapping relationship matrix, under the influence of node failures and random attacks, combined with the resource backup strategy and corrective maintenance strategy of information domain nodes, and on this basis, assess the system reliability under the information domain reconfiguration strategy; and a system reliability assessment module under the information-physical domain reconfiguration strategy, used to calculate the number of closed OODA loops under the reconfiguration strategy based on the mapping relationship matrix, under the influence of node failures and random attacks, by comprehensively applying the reconfiguration strategies of the physical domain and information domain, and on this basis, assess the system reliability under the information-physical domain reconfiguration strategy.