Code verification method, device and equipment of train operation control system, medium and product

By employing a large language model-driven approach to perform semantic analysis and assertion specification insertion on the network communication code of the train operation control system, the problem of lacking code-level verification in existing technologies is solved, thereby improving network security and verification efficiency.

CN122027282APending Publication Date: 2026-05-12CRSC RESEARCH & DESIGN INSTITUTE GROUP CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
CRSC RESEARCH & DESIGN INSTITUTE GROUP CO LTD
Filing Date
2026-02-11
Publication Date
2026-05-12

AI Technical Summary

Technical Problem

The lack of code-level verification of network communication code in the development and verification process of existing train operation control systems leads to network security risks, and traditional methods are difficult to meet the requirements of complexity and real-time operation.

Method used

By obtaining the original network communication code and network security requirements specification document of the train operation control system, semantic analysis is performed using a large language model to extract structured information, determine the insertion position of assertion specifications and insert them into the code, and then verification is performed using target code verification tools.

Benefits of technology

This technology enables code-level verification of the network communication codes of the train operation control system, thereby improving network security, reducing network security risks, and enhancing the automation and accuracy of verification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122027282A_ABST
    Figure CN122027282A_ABST
Patent Text Reader

Abstract

The invention discloses a code verification method and device of a train operation control system, equipment, a medium and a product, and relates to the technical field of network security, and the method comprises the steps: carrying out the semantic analysis of a network security demand specification document, extracting the network security demand structured information, and determining a target code verification strategy according to the network security demand structured information; determining an assertion specification and a code insertion position of the assertion specification according to the target code verification strategy and the network security demand structured information, and inserting the assertion specification into the original network communication code according to the code insertion position to obtain a to-be-verified network communication code; and verifying the to-be-verified network communication code by using the target code verification tool according to the assertion specification to obtain a code verification result. According to the invention, the code level verification effect on the network communication code of the train operation control system is realized, the network security of the train operation control system is improved, and the possibility of occurrence of network potential safety hazards is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security technology, and in particular to a code verification method, apparatus, equipment, medium, and product for a train operation control system. Background Technology

[0002] With the continuous advancement of rail transit construction, the train operation control system, as the core system ensuring the safe and efficient operation of trains, undertakes important tasks such as train operation status perception, signal transmission, and dispatch control. The train operation control system is characterized by strong real-time performance, complex structure, and precise control. Its safety and reliability throughout the entire process of design, development, testing, and operation and maintenance are not only related to the safety of passengers' lives and property but also directly affect the stable operation of the transportation system.

[0003] However, due to the complexity and real-time nature of train operation control systems, they still face numerous safety hazards in practical applications. For example, during the development and verification of train operation control systems, manufacturers typically focus on functional safety verification while neglecting code-level verification of the network communication code. This results in the inability to guarantee the network security of the train operation control system, creating cybersecurity vulnerabilities. Summary of the Invention

[0004] This invention provides a code verification method, apparatus, equipment, medium, and product for train operation control systems, in order to solve the problem that the lack of code-level verification of network communication codes in existing train operation control systems leads to network security vulnerabilities in train operation control systems.

[0005] According to one aspect of the present invention, a code verification method for a train operation control system is provided, the method comprising: Obtain the original network communication code corresponding to the target train operation control system, and obtain the network security requirements specification document associated with the target train operation control system; Semantic analysis is performed on the network security requirements specification document to extract structured information of network security requirements, and target code verification strategies for verifying the original network communication code are determined based on the structured information of network security requirements. Based on the target code verification strategy and the network security requirement structured information, the assertion specification and the code insertion position of the assertion specification in the original network communication code are determined, and the assertion specification is inserted into the original network communication code according to the code insertion position to obtain the network communication code to be verified. The target code verification tool is used to verify the network communication code to be verified according to the assertion specification, and the code verification result is obtained.

[0006] According to another aspect of the present invention, a code verification device for a train operation control system is provided, the device comprising: The information acquisition module is used to acquire the original network communication code corresponding to the target train operation control system, and to acquire the network security requirement specification document associated with the target train operation control system. The code verification strategy determination module is used to perform semantic analysis on the network security requirements specification document, extract structured information of network security requirements, and determine the target code verification strategy for verifying the original network communication code based on the structured information of network security requirements. The network communication code acquisition module is used to determine the assertion specification and the code insertion position of the assertion specification in the original network communication code according to the target code verification strategy and the network security requirement structured information, and to insert the assertion specification into the original network communication code according to the code insertion position to obtain the network communication code to be verified. The code verification module is used to verify the network communication code to be verified using a target code verification tool according to the assertion specification, and obtain the code verification result.

[0007] According to another aspect of the present invention, an electronic device is provided, the electronic device comprising: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor to enable the at least one processor to perform the method described in any one of the present invention.

[0008] According to another aspect of the present invention, a computer-readable storage medium is provided, the computer-readable storage medium storing computer instructions for causing a processor to execute and implement the method described in any one of the present invention.

[0009] According to another aspect of the present invention, a computer program product is provided, comprising a computer program that, when executed by a processor, implements the method described in any one of the present invention.

[0010] This invention obtains the original network communication code corresponding to the target train operation control system and the associated network security requirement specification document. It performs semantic analysis on the network security requirement specification document to extract structured information about network security requirements, and determines a target code verification strategy for verifying the original network communication code based on this structured information. Based on the target code verification strategy and the structured information about network security requirements, it determines the assertion specification and its insertion position within the original network communication code, inserts the assertion specification into the original network communication code according to the insertion position, and obtains the network communication code to be verified. Finally, it uses a target code verification tool to verify the network communication code according to the assertion specification, obtaining the code verification result. The beneficial effects are: This technology enables code-level verification of the network communication code corresponding to the train operation control system, explores the network security attributes of the train operation control system from the root, fills a technological gap, improves the network security of the train operation control system, and reduces the possibility of network security risks.

[0011] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description

[0012] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0013] Figure 1 A flowchart of a code verification method for a train operation control system provided in Embodiment 1 of the present invention; Figure 2 This is a flowchart of a code verification method for a train operation control system provided in Embodiment 2 of the present invention; Figure 3 This is a schematic diagram of the structure of a code verification device for a train operation control system provided in Embodiment 3 of the present invention; Figure 4 This is a schematic diagram of the structure of an electronic device that implements the code verification method of the train operation control system according to an embodiment of the present invention. Detailed Implementation

[0014] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0015] It should be noted that the terms "candidate," "initial," "target," etc., used in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0016] Currently, some subsystems of train operation control systems suffer from inadequate cybersecurity design, insufficient verification of cybersecurity attributes, and low verification coverage. If subjected to a powerful malicious attack, these subsystems could easily expose software vulnerabilities or design flaws, leading to systemic risks. At present, the development and verification of train operation control systems commonly employ methods based on static rules and human experience for safety assessments, with a greater emphasis on functional safety assessments and a lack of effective cybersecurity assessments and verifications of the code.

[0017] Code verification, as a key means to ensure the security and correctness of highly reliable systems, has been widely used in aerospace, nuclear energy control, and autonomous driving. It uses mathematical logic to rigorously reason through system code or design models, effectively verifying whether they meet predetermined safety attributes and functional constraints. However, for train operation control systems with multi-language crossover, high-concurrency components, and distributed architectures, traditional code verification methods are difficult to meet the large-scale, dynamic verification needs of engineering practice due to their high usage threshold, complex modeling, and poor adaptability.

[0018] In recent years, large language models have made groundbreaking progress in natural language processing, automatic code generation, and contextual understanding, providing a new path for intelligent safety verification of train operation control systems. Large language models possess excellent semantic understanding and logical modeling capabilities, efficiently mapping natural language requirements to code verification targets. They also have the ability to automatically select verification tools, generate verification parameters, analyze verification results, and output interpretable reports, significantly improving the automation level and accuracy of the verification process. With the development of intelligent technologies, automated safety verification methods for train operation control systems driven by large language models are expected to break through the bottlenecks of traditional verification paradigms and become a core supporting technology in the development of next-generation key rail transit systems.

[0019] Example 1 Figure 1 This is a flowchart of a code verification method for a train operation control system provided in Embodiment 1 of the present invention. This embodiment is applicable to situations where automatic code verification of original network communication code is performed based on network security requirements specifications. This method can be executed by a code verification device for the train operation control system, which can be implemented in hardware and / or software. Figure 1 As shown, the method includes: S101. Obtain the original network communication code corresponding to the target train operation control system, and obtain the network security requirements specification document associated with the target train operation control system.

[0020] The target train control system refers to the train control system selected as the analysis object during the code verification process. Train control systems are typically used in railways or rail transit to monitor, control, and optimize train operation to ensure safety, punctuality, and efficiency.

[0021] Raw network communication code refers to the unmodified or unprocessed source code of network communication functions related to the train operation control system. It implements data transmission, protocol processing, and message exchange between internal system components or between the system and external devices. This type of code is typically written in a programming language and involves parts such as network sockets, packet encoding / decoding, error handling, and security mechanisms. During code verification, it forms the basis for analysis and modification to ensure compliance with network security requirements.

[0022] The Cybersecurity Requirements Specification document is a formal document that details the requirements, standards, and specifications that a train operation control system must meet in terms of cybersecurity. Based on industry standards or specific regulations, it may cover areas such as access control, data integrity, availability, vulnerability management, attack protection, and incident response. The Cybersecurity Requirements Specification document provides guidance for the design, development, and verification of the train operation control system, ensuring the system can withstand cyber threats and serving as the basis for extracting structured requirements and analyzing semantics during code verification.

[0023] In one implementation, the user uploads a cybersecurity requirements specification document associated with the target train operation control system to the security verification system through the web interface or standardized application programming interface corresponding to the security verification system. The document format of the cybersecurity requirements specification document includes, but is not limited to, “.docx”, “.pdf”, “.txt”, etc.

[0024] After receiving the network security requirements specification document uploaded by the user, the security verification system performs at least one of the following document verification operations: 1. Document type compliance verification; 2. Document size verification; 3. Document security verification.

[0025] If the cybersecurity requirements specification document passes document verification, the security verification system calls the corresponding parsing engine to parse the document content, obtaining text data and automatically generating a globally unique document ID. The document ID and the parsed text data are then persistently stored on a highly available distributed file server and metadata database to ensure content traceability and low latency for subsequent calls.

[0026] If the cybersecurity requirements specification document fails document verification, such as due to unsupported document type, excessive document size, or insecurity, or if problems occur during document content parsing and / or document storage, the security verification system will interrupt the process, record detailed error logs (such as user, time, and error type), and immediately return clear prompts to the user, guiding them to readjust and re-upload the cybersecurity requirements specification document. This ensures the robustness of the upload portal and a smooth user experience.

[0027] In another implementation, when uploading the network security requirements specification document to the security verification system, the user synchronously or asynchronously uploads the original network communication code corresponding to the target train operation control system to the security verification system, including but not limited to the original network communication code in C language format.

[0028] After receiving the raw network communication code uploaded by the user, the security verification system verifies the user's identity and permissions. If the verification passes, the system performs integrity and basic security checks on the raw network communication code. If the verification passes, the system calls the integrated compiler front-end tool to perform fine-grained syntax and static syntax tree analysis on the raw network communication code to check for syntax errors. If the verification passes, the system integrates the raw network communication code into a code package and assigns it a globally unique package ID. The package ID is then associated with the package and stored in a version-managed code repository to ensure the integrity and traceability of the code.

[0029] If an error occurs at any stage (such as identity and permission mismatch, file corruption, syntax analysis failure, storage anomaly, etc.), the security verification system will immediately terminate the process, record a structured error log containing the complete context, and return clear and actionable prompts to the user to guide them in making corrections and re-uploading, thereby ensuring the input quality and stability of the entire code verification pipeline.

[0030] S102. Perform semantic analysis on the network security requirements specification document, extract structured information of network security requirements, and determine the target code verification strategy for verifying the original network communication code based on the structured information of network security requirements.

[0031] Semantic analysis specifically refers to the process of deep understanding and information extraction from unstructured cybersecurity requirements specification documents. It aims to understand the security intent, constraints, behavioral logic, and entity relationships contained within these documents through technologies such as natural language processing, domain ontology libraries, or rule engines.

[0032] Structured information for cybersecurity requirements refers to a machine-readable representation of requirements extracted from cybersecurity requirements specification documents through semantic analysis. It transforms potentially ambiguous or redundant cybersecurity requirements specifications, described in natural language, into data structures with clearly defined attributes, classifications, and logical relationships.

[0033] Verifying raw network communication code refers to a formalized verification process whose goal is to prove whether the code's behavior conforms to the specifications defined by structured information about network security requirements. It involves checking at the code level whether specific security attributes are met.

[0034] Target code verification strategy is a combination of specific verification methods, technical approaches, and toolchains selected and configured based on the type and characteristics of the extracted structured information about cybersecurity requirements. It is a result of decision mapping, aiming to match appropriate verification methods to security requirements. Target code verification strategies include, but are not limited to, model checking, abstraction interpretation, and symbolic execution.

[0035] In one implementation, the security verification system uses a rule engine or traditional information extraction methods to perform semantic analysis on the cybersecurity requirements specification document and extract structured information about cybersecurity requirements.

[0036] In another implementation, the security verification system preprocesses the network security requirements specification document, including but not limited to text cleaning, format standardization, and logical paragraph segmentation. Further, the security verification system invokes a target large language model and, through a designed domain-adaptive prompt word project, guides the target large language model to perform semantic analysis on the network security requirements specification document. Its tasks include, but are not limited to, extracting task keywords, interface descriptions, and typical application scenarios from the document, but also identifying implicit security constraints and functional boundaries. Based on this, the target large language model automatically generates a structured requirement data output, which the security verification system uses as structured network security requirements information.

[0037] Furthermore, if timeouts, incomplete content, logical contradictions, or low confidence occur during the analysis of the target large language model, the security verification system will notify the user to supplement the network security requirements specification document. At the same time, the security verification system can automatically switch to a backup parsing engine based on predefined rules and templates for semantic analysis to ensure process continuity.

[0038] After extracting structured information about network security requirements, in one implementation, the security verification system incorporates an extensible code verification strategy knowledge base. This knowledge base predefines the mapping relationships between different categories of network security requirements and code verification strategies. Once the security verification system determines the structured information about network security requirements, it first automatically classifies and labels the information based on its included fields. Then, it invokes a rule engine to match one or more candidate code verification strategies from the knowledge base based on these classifications and features, combined with preset priority rules and project configurations. Finally, the security verification system comprehensively evaluates each candidate code verification strategy and automatically selects the optimal, executable candidate code verification strategy as the target code verification strategy.

[0039] Optionally, the structured information for network security requirements includes at least one of the following: task objectives, task keywords, interface descriptions, input constraints, output constraints, and functional boundaries.

[0040] The task objective refers to the core security purpose that the network security requirements specification document aims to achieve. It describes the security intent behind the requirements, rather than the specific implementation steps. Task keywords are key terms or phrases extracted from the network security requirements specification document that represent the core security concepts and technical fields of the requirements. Interface specifications refer to the interaction points and specifications of the software modules, functions, APIs, or network services to which the network security requirements specification document applies, specifically including function signatures, message types, protocol names, port numbers, and packet formats. Input constraints refer to the security preconditions and legality rules that must be met when receiving external or upstream data. This includes not only routine checks such as data type and range, but also focuses on security-related constraints. Output constraints refer to the security postconditions and guarantees that must be ensured when generating data or actions. They ensure that the output does not leak sensitive information or violate security policies. Functional boundaries clearly define the operational scope, permission limits, and prohibited behaviors of the system functions or components associated with the network security requirements specification document.

[0041] S103. Based on the target code verification strategy and structured information on network security requirements, determine the assertion specification and the code insertion position of the assertion specification in the original network communication code, and insert the assertion specification into the original network communication code according to the code insertion position to obtain the network communication code to be verified.

[0042] Assertion specifications, based on structured information about cybersecurity requirements, are logical expressions or check statements precisely defined using formal methods. They transform a security requirement from natural language into a set of machine-checkable conditions that code verification tools can directly understand and execute. The core function of assertion specifications is to explicitly indicate in the code "what security conditions must be met under what conditions." These can take the form of preconditions, postconditions, loop invariants, or data invariants, serving as a bridge between cybersecurity requirements and code verification tools.

[0043] The code insertion point refers to the precise logical point in the original network communication code that is most suitable for embedding the assertion specification, determined through static code analysis based on the target code verification strategy and structured information on network security requirements. This location is not random, but rather designed to ensure that the assertion specification can be effectively evaluated in the correct execution context. For example, for a requirement that "the decryption key must be verified before use," the code insertion point for the assertion specification might be determined as "the instruction immediately preceding the call to the decryption function."

[0044] The network communication code to be verified refers to the source code version that has already had assertion specifications inserted. It is input code formed by embedding assertion specifications at predetermined insertion points within the skeleton of the original network communication code, and can be directly submitted to the target code verification tool for processing. This code carries the functional logic of the original network communication code and the newly added security attribute checking logic, and is the direct object of the verification process. The verification result will reflect whether this code version satisfies all the security conditions defined by the embedded assertion specifications on all possible execution paths.

[0045] In one implementation, the security verification system invokes a target large language model and uses the target large language model to determine the assertion specification and the code insertion position of the assertion specification in the original network communication code based on the target code verification strategy and network security requirements structured information.

[0046] In another implementation, the security verification system first collaboratively parses the input structured information of network security requirements and the target code verification strategy. Based on the core verification method specified by the target code verification strategy, it calls the corresponding assertion template library and rule engine. For each piece of structured information of network security requirements, the system matches and infers its key attributes with the context information extracted from the static analysis of the original network communication code. During this process, the security verification system automatically optimizes the specific logical form of the generated assertion specifications and the accuracy of their insertion positions according to the guidance of the target code verification strategy. Finally, it outputs a complete, machine-executable mapping list, which clarifies the logical content of each assertion specification and the code insertion position of the assertion specification in the original network communication code.

[0047] After determining the assertion specification and the code insertion location, the security verification system inserts the assertion specification into the original network communication code according to the code insertion location, thus obtaining the network communication code to be verified.

[0048] S104. Use the target code verification tool to verify the network communication code to be verified according to the assertion specification, and obtain the code verification results.

[0049] In this context, a target code verification tool refers to a specialized software tool selected and invoked by a security verification system to perform formal verification based on a predetermined target code verification strategy. It is a professional tool specifically designed to check whether code meets assertion specifications using logical or mathematical methods. The specific type of target code verification tool is determined by the target code verification strategy.

[0050] Code verification results are the conclusions output by the target code verification tool after analyzing the network communication code to be verified. They systematically reflect the compliance of the network communication code with the inserted assertion specifications. Code verification results include both normal and abnormal code cases.

[0051] In one implementation, the security verification system automatically schedules and executes the network communication code to be verified and its embedded assertion specifications as input tasks according to the interface specifications of a pre-configured target code verification tool. During the verification process, the tool analyzes all relevant execution paths of the code based on its built-in algorithm, checking whether the security conditions defined by the assertion specifications are always mathematically or logically true. For each verified assertion specification, the tool generates a clear judgment state and automatically generates a reproducible counterexample code execution path when a violation is found. The security verification system continuously monitors the execution status of the verification task and collects the raw result data output by the tool. If it is determined that the security conditions defined by the assertion specifications on all code execution paths are mathematically or logically true, the code verification result is determined to be normal. If it is determined that the security conditions defined by the assertion specifications on at least one code execution path are mathematically or logically false, the code verification result is determined to be abnormal.

[0052] This invention, through obtaining the original network communication code corresponding to the target train operation control system and the associated network security requirement specification document, performs semantic analysis on the network security requirement specification document to extract structured information of network security requirements. Based on this structured information, it determines a target code verification strategy for verifying the original network communication code. According to the target code verification strategy and the structured information of network security requirements, it determines the assertion specification and its insertion position in the original network communication code, inserts the assertion specification into the original network communication code according to the insertion position, and obtains the network communication code to be verified. Finally, it uses a target code verification tool to verify the network communication code to be verified based on the assertion specification, obtaining the code verification result. The beneficial effects are: This technology enables code-level verification of the network communication code corresponding to the train operation control system, explores the network security attributes of the train operation control system from the root, fills a technological gap, improves the network security of the train operation control system, and reduces the possibility of network security risks.

[0053] Example 2 Figure 2 This is a flowchart of a code verification method for a train operation control system provided in Embodiment 2 of the present invention. This embodiment further optimizes and expands the above embodiments and can be combined with the various optional implementation methods described above. Figure 2As shown, the method includes: S201. Obtain the original network communication code corresponding to the target train operation control system, and obtain the network security requirements specification document associated with the target train operation control system.

[0054] S202. Input the network security requirements specification document into the target large language model, and perform semantic analysis on the network security requirements specification document through the target large language model to determine the structured information of network security requirements contained in the network security requirements specification document; obtain the structured information of network security requirements output by the target large language model.

[0055] The target large language model specifically refers to a specialized large language model selected, customized, or fine-tuned to complete a specific domain decision-making task. It differs from general dialogue models; its core capability lies in deeply understanding the domain language of cybersecurity requirements and software code, and performing reasoning and decision-making based on the logical connection between the two. In this embodiment, for key and typical security verification scenarios of train operation control systems, a professional knowledge base including assertion syntax, formal assertion specifications, and security policy templates was constructed. Through context injection, few-shot learning, and thought chain reasoning techniques, the target large language model acquires professional capabilities for cybersecurity verification of train operation control systems.

[0056] In one implementation, the security verification system inputs a network security requirements specification document and predefined parsing instructions (i.e., specific prompts) into a target large language model. The parsing instructions explicitly require the target large language model to identify and extract elements based on domain knowledge. After performing semantic understanding internally, the target large language model strictly follows a preset structured output template to classify and fill in the identified elements and generate corresponding structured information. The security verification system evaluates the logical completeness and confidence of the model output and finally obtains the structured information as the network security requirements structured information.

[0057] By inputting the cybersecurity requirements specification document into a target large language model and performing semantic analysis on the document using the target large language model, the structured information of cybersecurity requirements contained in the document can be determined. The beneficial effects of obtaining the structured information of cybersecurity requirements output by the target large language model are as follows: By leveraging the deep semantic understanding and reasoning capabilities of the target large language model, we can automatically capture, finely decompose, and formally model complex cybersecurity requirements in train operation control system scenarios. This ensures that every security specification and business requirement can be accurately and executablely represented, thereby improving the accuracy of semantic analysis.

[0058] S203. Input the structured information of network security requirements and the original network communication code into the target large language model, and determine the target code verification strategy identifier from the candidate code verification strategy identifiers based on the structured information of network security requirements and the original network communication code through the target large language model.

[0059] S204. Obtain the target code verification strategy identifier output by the target large language model, and determine the target code verification strategy based on the target code verification strategy identifier.

[0060] Among them, the candidate code verification strategy identifier is a predefined, finite set of identifiers, where each identifier uniquely corresponds to an available, pre-configured code verification strategy, which is the direct range of options for selection and recommendation by the target large language model.

[0061] The target code verification strategy identifier is a specific identifier ultimately selected by the target large language model from candidate code verification strategy identifiers after analysis and reasoning. It is the output of the model's decision, representing the code name of the most suitable, effective, or feasible code verification strategy for the current specific combination of "raw network communication code" and "structured information on network security requirements." Based on this identifier, the security verification system will index and load the corresponding, complete target code verification strategy from the code verification strategy library.

[0062] In one implementation, the security verification system inputs structured information on network security requirements, the original network communication code, and prompts containing decision logic into a target large language model. The prompts guide the target large language model to comprehensively analyze the key features of the input structured information on network security requirements and the original network communication code, evaluate the applicability of each candidate code verification strategy identifier, and output the most matching target code verification strategy identifier. The security verification system then uses a pre-set "identifier-policy mapping table" to parse the acquired target code verification strategy identifier into a corresponding complete target code verification strategy.

[0063] By inputting structured information on network security requirements and the original network communication code into a target large language model, and then using the target large language model to determine the target code verification strategy identifier from candidate code verification strategy identifiers based on the structured information on network security requirements and the original network communication code, the beneficial effects of obtaining the target code verification strategy identifier output by the target large language model and determining the target code verification strategy based on the target code verification strategy identifier are as follows: Firstly, it replaces the traditional model that relies entirely on security experts to manually analyze requirements and code to select code verification strategies. By using the reasoning capabilities of the target large language model, it automatically completes strategy matching, significantly shortening the decision-making cycle and reducing labor costs and subjective bias.

[0064] Secondly, the target large language model can comprehensively understand nonlinear security constraints and complex code contexts, and perform multi-dimensional evaluations. This allows it to recommend the optimal code verification strategy for a specific combination of "structured information on network security requirements - original network communication code", thereby improving the relevance and effectiveness of code verification.

[0065] S205. Input the target code verification strategy and network security requirement structured information into the target large language model, and determine the assertion specification and code insertion position based on the target code verification strategy and network security requirement structured information through the target large language model; obtain the assertion specification and code insertion position output by the target large language model.

[0066] S206. Insert the assertion specification into the original network communication code according to the code insertion position to obtain the network communication code to be verified.

[0067] In one implementation, the security verification system inputs the target code verification strategy, structured information on network security requirements, and prompts into the target large language model. The prompts guide the target large language model to act as both an "assertion generator" and a "code analyzer." The target large language model transforms the structured information on network security requirements into logically rigorous formal assertion specifications and, based on its understanding of the code structure, infers the code insertion position for each assertion specification. The security verification system obtains the well-formatted assertion specifications and their corresponding code insertion positions output by the target large language model and drives an automated code instrumentation tool to embed the assertion specifications into the original network communication code strictly according to the specified code insertion positions, thereby generating network communication code to be verified that can be directly used for code verification.

[0068] By inputting the target code verification strategy and structured information on network security requirements into the target large language model, and using the target large language model to determine the assertion specification and code insertion position based on the target code verification strategy and structured information on network security requirements; obtaining the assertion specification and code insertion position output by the target large language model; and inserting the assertion specification into the original network communication code according to the code insertion position to obtain the network communication code to be verified, the beneficial effects are: Firstly, the target large language model can deeply integrate the guiding logic of the target code verification strategy with the specific constraints of the structured information of network security requirements, and generate formal assertion specifications that strictly match the code context in terms of syntax and semantics. This avoids logical deviations or ambiguities that may be introduced by manual writing, and ensures that the verification target accurately reflects the original security requirements.

[0069] Secondly, by understanding the code structure, the target large language model can automatically reason and determine the optimal code insertion position for assertion specifications to take effect, ensuring that security conditions are verified in the correct execution context, which significantly improves the coverage and effectiveness of verification.

[0070] Thirdly, the process is fully automated, replacing the traditional high-cost model that requires security experts and developers to communicate repeatedly, manually analyze code, and insert assertion specifications. This shortens the verification preparation cycle and enables non-expert users to generate professional-grade verification code.

[0071] S207. Use the target code verification tool to parse the assertion specification and generate a verification task description that is compatible with the target code verification tool; based on the verification task description, perform corresponding verification on the network communication code to be verified and obtain the verification status data corresponding to each code execution path.

[0072] The verification task description refers to the specific instructions or configuration files that the target code verification tool can directly understand and execute. It is an intermediate representation generated by the target code verification tool after parsing and transforming the input "assertion specification," and is fully adapted to the tool's internal logic and syntax.

[0073] Performing corresponding verification on the network communication code to be verified refers to the specific operation process by which the target code verification tool systematically analyzes or simulates the input network communication code to be verified according to the verification task description. The core objective is to proactively discover whether there are any violations of the security attributes defined in the "verification task description" in the network communication code to be verified.

[0074] A code execution path refers to a series of consecutive statements or state transitions experienced by a program from its entry point to its exit point during execution. Target code verification tools systematically explore all possible logical branches, loop iterations, and concurrent interactions in the network communication code to be verified, thereby enumerating a large number of theoretically possible code execution paths. Each path represents a specific program behavior scenario, and security properties must be valid across all possible code execution paths.

[0075] Verification status data refers to the actual runtime state information of the program captured by target code verification tools at key points along a specific "code execution path." This data consists of specific values ​​derived by the tool through simulated execution or analysis, such as the current values ​​of variables, memory status, and the results of conditional judgments. It reflects the actual behavior of the code under a specific path.

[0076] In one implementation, the target code verification tool automatically converts the input assertion specification into an executable verification task description within the tool using its pre-built assertion syntax parser. Subsequently, the target code verification tool loads this verification task description and the network communication code to be verified, starts its core verification engine, systematically traverses all execution paths of the code, records specific information about the program state at key points of each code execution path, and finally outputs structured verification status data corresponding to each code execution path.

[0077] S208. Compare each verification status data with the expected status data defined in the assertion specification, and determine the code verification result based on the comparison result.

[0078] Expected state data refers to the conditions or value ranges that the program state must meet at the corresponding code insertion point, as explicitly defined in the "assertion specification." It originates directly from structured information on network security requirements and is a formal expression of security attributes at specific code points.

[0079] In one implementation, the result analyzer within the target code verification tool automatically extracts the verification status data corresponding to the key points in each code execution path, compares it logically and numerically with the expected status data defined for that point in the assertion specification, and determines the code verification result based on the comparison result.

[0080] By using a target code verification tool to parse the assertion specification, a verification task description adapted to the target code verification tool is generated. Based on the verification task description, corresponding verifications are performed on the network communication code to be verified, obtaining verification status data corresponding to each code execution path. Each verification status data is compared with the expected status data defined in the assertion specification, and the code verification result is determined based on the comparison results. The beneficial effects are: Firstly, the target code verification tool automatically completes the entire process from assertion specification parsing to state comparison, eliminating the need for manual line-by-line code checking and improving the efficiency of code verification.

[0081] Secondly, by converting assertion specifications into native verification task descriptions for target code verification tools and performing formal state data collection and comparison on all possible code execution paths, the subjectivity and oversight of manual verification are eliminated, ensuring the accuracy and repeatability of the conclusions.

[0082] Optionally, the code verification result is determined based on the comparison results, including: If all verification status data match the expected status data, the code verification result is determined to be normal; if at least one verification status data does not match the expected status data, the code verification result is determined to be abnormal.

[0083] In one implementation, according to a preset judgment rule, if the verification status data on a certain code execution path meets the expected status data, the code execution path is marked as "safe"; otherwise, the path is marked as "illegal". Finally, the security verification system integrates the marking results of all code execution paths: if all paths are "safe", a code verification result of "normal code" is generated; if there is at least one "illegal" code execution path, a result of "abnormal code" is generated.

[0084] If all verification status data matches the expected status data, the code verification result is determined to be normal; if at least one verification status data does not match the expected status data, the code verification result is determined to be abnormal. The beneficial effects are: Firstly, the judgment process is fully automated, eliminating the need for experts to manually review each comparison point. The system can output conclusions instantly, significantly improving response speed and decision-making efficiency.

[0085] Secondly, by using the binary judgment logic of "full match means normal, one abnormality means overall abnormality", the ambiguity of the verification results is completely eliminated, providing unambiguous conclusions for the network security assessment of the train operation control system.

[0086] Optionally, before obtaining the code verification results, the following steps are also included: Utilizing target code verification tools to verify the network communication code to be verified according to the assertion specification. A1. Input the structured information of network security requirements and the original network communication code into the target large language model, and determine the initial code verification tool identifier from the candidate code verification tool identifiers based on the structured information of network security requirements and the original network communication code through the target large language model, and generate the running configuration parameters associated with the initial code verification tool identifier.

[0087] B1. Obtain the initial code verification tool identifier and runtime configuration parameters output by the target large language model, determine the initial code verification tool from the candidate code verification tools based on the initial code verification tool identifier, and configure the initial code verification tool according to the runtime configuration parameters to obtain the target code verification tool.

[0088] Here, the candidate code verification tool identifier refers to a predefined set of unique identifiers containing all available code verification tools. Each candidate code verification tool identifier corresponds to a specific code verification tool that is already integrated into the security verification system.

[0089] The initial code verification tool identifier refers to the specific verification tool identifier selected and recommended by the "target large language model" from the set of "candidate code verification tool identifiers" after analysis and reasoning based on the structured information of the input network security requirements and the characteristics of the original network communication code.

[0090] The initial code verification tool refers to the unconfigured code verification tool that is actually loaded and instantiated from the integrated tool library according to the "Initial Code Verification Tool Identifier". The initial code verification tool is a "default state" tool, and its behavior is determined by its own default parameters and has not yet been optimized for the current task.

[0091] The runtime configuration parameters refer to a set of adjustable runtime settings options generated by the "Target Large Language Model" along with the recommended verification tool identifier, in order to further optimize the verification effect of the initial code verification tool on structured information and raw network communication code for current network security requirements. These parameters are used to finely control the behavior of the initial code verification tool, aiming to adapt the initial code verification tool to specific verification scenarios.

[0092] In one implementation, structured information on network security requirements and the original network communication code are input into a target large language model. Preset decision prompts guide the target large language model to analyze task characteristics, thereby selecting the most suitable initial code verification tool identifier from predefined candidate code verification tool identifiers and simultaneously generating the corresponding runtime configuration parameters. After receiving the output, the security verification system locates and instantiates the corresponding initial code verification tool from the integrated tool library based on the initial code verification tool identifier. Finally, the runtime configuration parameters generated by the model are automatically applied to the initial code verification tool to complete the customization and initialization of the tool's behavior, forming a target code verification tool that can directly execute verification tasks.

[0093] By inputting structured information on network security requirements and the original network communication code into a target large language model, and using the target large language model to determine the initial code verification tool identifier from candidate code verification tool identifiers based on the structured information on network security requirements and the original network communication code, and generating the runtime configuration parameters associated with the initial code verification tool identifier; obtaining the initial code verification tool identifier and runtime configuration parameters output by the target large language model, determining the initial code verification tool from candidate code verification tools based on the initial code verification tool identifier, and configuring the initial code verification tool according to the runtime configuration parameters, the target code verification tool is obtained. The beneficial effects are: Firstly, the target large language model, through comprehensive analysis of structured information on network security requirements and original network communication code, can go beyond simple rules and intelligently recommend the most suitable initial code verification tool identifier from the tool library, generating runtime configuration parameters. This means that code verification tools no longer use default runtime configuration parameters in a "one-size-fits-all" manner, but are dynamically optimized to the optimal form for the current task, thereby directly improving the accuracy and success rate of code verification.

[0094] Secondly, traditionally, the selection and parameter tuning of code verification tools heavily rely on the in-depth knowledge of experts and repeated trial and error. This solution automates this decision-making process, enabling non-expert users to obtain code verification tool configuration results that are close to those of experts, greatly reducing the professional threshold and labor costs, and avoiding subjective configuration bias.

[0095] Optionally, after determining that the code verification result is a code exception, the following steps are also included: A2. Identify at least one verification state data that does not match the expected state data as abnormal verification state data, and determine the code execution path corresponding to the abnormal verification state data as the counterexample code execution path.

[0096] B2. Generate risk description information and code repair suggestions corresponding to the original network communication code based on the execution path of the counterexample code, and generate a code verification report based on the location of the abnormal code, the code verification results, the risk description information and the code repair suggestions.

[0097] Among them, abnormal verification status data refers to program status information that is actually collected at a certain code insertion point during the code verification process and does not meet the expected status data defined by the assertion specification.

[0098] The execution path of a counterexample code refers to the complete and specific code execution path that leads to the appearance of the exception verification status data. Starting from the program entry point, the execution path of a counterexample code follows specific branches and loops, ultimately reaching the violation point, providing a complete code context trajectory.

[0099] Risk description information refers to potential security hazards described in natural language or standardized terms, based on anomaly verification state data and counterexample code execution paths, combined with structured information about the network security requirements they violate. It aims to map technical state violations to business or system-level risks.

[0100] Code repair suggestions provide specific and actionable source code modification solutions targeting the execution path and location of the problematic code. The aim is to eliminate the root cause of the violation and ensure the code meets assertion specifications.

[0101] The location of the exception code is the code location associated with the execution path of the counterexample code in the network communication code to be verified. In other words, it refers to the precise source code location of the code insertion position corresponding to the exception verification status data in the original network communication code within the execution path of the counterexample code.

[0102] A code verification report is a structured and readable summary document that integrates code verification results, abnormal code locations, risk descriptions, and code remediation recommendations. It is a formal record of the code verification task's outcomes, aiming to clearly demonstrate the problem's location, cause, and solution, and is a core deliverable guiding subsequent code remediation and security improvements.

[0103] In one implementation, firstly, all verification state data that do not match the expected state data are automatically filtered from the verification results and marked as abnormal verification state data. The complete code execution sequence that caused each abnormal verification state data is extracted as a negative example code execution path. Subsequently, the code context and the violated assertion specifications of the negative example code execution path are analyzed by a finely tuned large language model or rule inference engine to automatically generate risk description information and specific code repair suggestions. At the same time, the corresponding abnormal code position in the original network communication code is accurately located from the negative example code execution path. Finally, these elements are automatically integrated and formatted according to a preset template to generate a complete and readable code verification report.

[0104] By identifying at least one verification state data that does not match the expected state data as abnormal verification state data, and determining the corresponding code execution path as a negative example code execution path; generating risk description information and code remediation suggestions for the original network communication code based on the negative example code execution path; and generating a code verification report based on the abnormal code location, code verification results, risk description information, and code remediation suggestions, the beneficial effects are: Firstly, by automatically generating risk description information and code repair suggestions, the output of formal verification is directly translated into remediation instructions that developers can understand and execute, which significantly reduces the threshold for repair and shortens the repair cycle.

[0105] Secondly, the code verification report integrates complete evidence, from the location of the abnormal code to risk description information and code remediation suggestions, forming a standardized deliverable. This facilitates division of labor and collaboration within the team and provides detailed and reliable documentation for security audits, compliance certifications, and process traceability.

[0106] Optionally, the method also includes: Based on the original network communication code, network security requirements specification document, network security requirements structured information, network communication code to be verified, and code verification report, generate information to be archived; obtain the task identification information corresponding to this code verification, and associate and store the task identification information and the information to be archived.

[0107] The information to be archived refers to the collection of core data and documents generated throughout the entire lifecycle of this code verification task, which have long-term retention value and are used for traceability, auditing, and analysis. It includes not only the process inputs (original network communication code, network security requirements specification documents) and outputs (code verification report), but also key intermediate products (structured network security requirements information) and the final verification object (network communication code to be verified).

[0108] The task identifier is a globally unique identifier automatically generated for this code verification task. It is used to uniquely identify and retrieve archived information related to this task within the storage system.

[0109] Association-based storage refers to the operation of logically associating and physically persisting all data contained in the information to be archived, using task identification information as an index. This storage method ensures the integrity, consistency, and efficient traceability of verification history.

[0110] In one implementation, a globally unique task identifier is generated when the verification task is started. Upon completion of the task, all core inputs, intermediate products, and result files involved in the verification process, including the original network communication code, network security requirements specification documents, network security requirements structured information, network communication code to be verified, and code verification reports, are automatically packaged into a complete archived information. Subsequently, the archived information is persistently stored in a database or file storage system using the task identifier as an index, ensuring that all content can be completely and efficiently retrieved and traced through the task identifier, thereby achieving associated archiving throughout the entire verification lifecycle.

[0111] By generating archived information based on the original network communication code, network security requirements specification document, structured network security requirements information, network communication code to be verified, and code verification report; obtaining the task identifier information corresponding to this code verification; and associating and storing the task identifier information and archived information, the beneficial effects are: Firstly, by systematically archiving the original network communication code, network security requirements specification documents, structured network security requirements information, network communication code to be verified, and code verification reports, a complete closed-loop evidence from security requirements to verification conclusions is formed. This provides an indispensable auditable track for the safety standard certification of train operation control systems.

[0112] Secondly, the association and storage based on unique task identifiers allows for the rapid and accurate retrieval and restoration of all contextual information for any verification task. This not only greatly facilitates problem backtracking, responsibility identification, and process review, but also ensures that the verification scenario and results can be fully reproduced when needed, guaranteeing the seriousness and scientific rigor of the verification work.

[0113] Optionally, the security verification system adopts a bottom-up, layered, decoupled modular design. The overall architecture is divided into a foundation layer, data layer, optimization layer, service layer, interaction layer, and I / O module. Each layer works together through microservices and event queues, possessing engineering characteristics such as reconfigurability, easy scalability, and high availability. The components are described below: 1. Foundation Layer: This layer provides the underlying intelligent support for semantic understanding and logical reasoning of the system. It adopts a hybrid large-model architecture, supporting flexible access and dynamic switching of general-purpose large models. The core innovation lies in establishing an intelligent prompt word engineering system for cybersecurity verification of train operation control systems: For key and typical security verification scenarios in train operation control systems, a professional knowledge base has been constructed, including assertion syntax, formal assertion specifications, and security policy templates. Through context injection, few-shot learning, and thought chain reasoning techniques, the general-purpose large model possesses professional capabilities for cybersecurity verification of train operation control systems.

[0114] 2. Data Layer: This layer is primarily responsible for the unified management of structured and unstructured data, including persistent storage of task data, management of historical records, and rapid retrieval. This layer consists of the following two key components: a. Record Storage: A unified storage management mechanism supporting multi-format documents has been established, enabling real-time recording and archiving of input documents, large language model parsing results, execution logs, and report outputs for each verification task. A unique parsing failure retry mechanism has been implemented: when document parsing fails, the system automatically saves error information and failure status, allowing users to reselect the model for parsing. It also innovatively supports persistent storage of error information and overwriting updates of parsing results. Furthermore, a complete file version management mechanism has been established, supporting full auditing and result reproduction of verification tasks, and innovatively achieving end-to-end data tracking from uploading, parsing, verification to report generation.

[0115] b. Database: An innovative five-table data model was designed for the formal verification scenario of train operation control system network security, establishing a complete data architecture including a requirements document table, code file table, ACSL code table, execution record table, and large language model table. Structured data is indexed and stored, uniquely supporting verification state machine management and dynamic configuration management of multiple language model providers. It also innovatively implements automatic database initialization, real-time updates of statistical information, and a resource management mechanism based on unique IDs, improving the traceability and maintainability of system data.

[0116] 3. Optimization Layer: This layer embeds a prompt word optimizer. This module can automatically adjust the prompts for the large model based on the verification task type, target language style, interface semantics, and contextual background, generating more targeted input content for the cybersecurity verification of the train operation control system, improving the task adaptability and response consistency of the large language model. This module improves the accuracy and stability of model invocation, avoiding problems such as prompt redundancy, ambiguity, or generation bias, and providing high-quality intelligent input for subsequent service layer modules. This environment innovatively proposes intelligent prompt word optimization technology for formal verification of train operation control systems. This layer embeds a prompt word optimizer, innovatively combining the language features of train operation control system security verification and ACSL assertion syntax specifications, and can automatically optimize the model input prompts based on the language style of the verification target, contextual interface semantics, and task type. Unique technical innovations include: adaptive prompt word generation based on the output format of the verification toolchain, semantic enhancement oriented towards C language security programming specifications, and a multi-turn dialogue context preservation mechanism, thereby enhancing the model's response stability and generation accuracy for specific tasks and avoiding the risk of misjudgment due to prompt redundancy, ambiguity, or language bias.

[0117] 4. Service Layer: This layer serves as the logical hub of the system, aggregating and carrying all core business functions from task parsing to result output. It includes the following five modules: document parsing module; verification strategy module; intelligent verification module; formal verification module; and report generation module.

[0118] 5. I / O Module: This module serves as the core intermediary for data exchange and task scheduling, implementing functions such as uploading, reading, transmitting, and task status maintenance. It ensures efficient, secure, and orderly data flow between different modules. All uploaded documents, code, logs, and reports are centrally scheduled and managed by this module.

[0119] 6. Interaction Layer: This layer is the interface between the system and the user, providing two entry points: a GUI graphical interface and a command-line interactive interface. It supports developers to upload tasks, configure verification targets, and view reports through graphical operations, and can also be quickly integrated into pipelines or automated testing platforms through the command line to achieve convenient invocation and scripted deployment, meeting the diverse needs of different types of users.

[0120] Example 3 Figure 3 This is a schematic diagram of a code verification device for a train operation control system provided in Embodiment 3 of the present invention. It is applicable to situations where automatic code verification of original network communication code is performed based on network security requirements specifications. Figure 3 As shown, the device includes: The information acquisition module 31 is used to acquire the original network communication code corresponding to the target train operation control system, and to acquire the network security requirement specification document associated with the target train operation control system. The code verification strategy determination module 32 is used to perform semantic analysis on the network security requirements specification document, extract network security requirements structured information, and determine the target code verification strategy for verifying the original network communication code based on the network security requirements structured information. The network communication code acquisition module 33 is used to determine the assertion specification and the code insertion position of the assertion specification in the original network communication code according to the target code verification strategy and the network security requirement structured information, and to insert the assertion specification into the original network communication code according to the code insertion position to obtain the network communication code to be verified. The code verification module 34 is used to verify the network communication code to be verified using a target code verification tool according to the assertion specification, and obtain the code verification result.

[0121] Optionally, the code verification strategy determination module 32 is specifically used for: The network security requirement structured information and the original network communication code are input into the target large language model, and the target code verification strategy identifier is determined from the candidate code verification strategy identifiers based on the network security requirement structured information and the original network communication code. Obtain the target code verification strategy identifier output by the target large language model, and determine the target code verification strategy based on the target code verification strategy identifier.

[0122] Optionally, the network communication code acquisition module 33 to be verified is specifically used for: The target code verification strategy and the network security requirement structured information are input into the target large language model, and the assertion specification and the code insertion position are determined by the target large language model based on the target code verification strategy and the network security requirement structured information. Obtain the assertion specification and the code insertion position output by the target large language model.

[0123] Optionally, the code verification module 34 is specifically used for: The assertion specification is parsed using the target code verification tool to generate a verification task description that is compatible with the target code verification tool; Based on the verification task description, the corresponding verification is performed on the network communication code to be verified to obtain the verification status data corresponding to each code execution path. The verification status data is compared with the expected status data defined in the assertion specification, and the code verification result is determined based on the comparison result.

[0124] Optionally, the code verification module 34 is further used for: If all the verification status data match the expected status data, then the code verification result is determined to be normal. If at least one of the verification status data does not match the expected status data, then the code verification result is determined to be a code anomaly.

[0125] Optionally, the device further includes a code verification tool parameter configuration module, specifically used for: The network security requirement structured information and the original network communication code are input into the target large language model. Based on the network security requirement structured information and the original network communication code, the target large language model determines the initial code verification tool identifier from the candidate code verification tool identifiers and generates the runtime configuration parameters associated with the initial code verification tool identifier. Obtain the initial code verification tool identifier and the running configuration parameters output by the target large language model, determine the initial code verification tool from the candidate code verification tools according to the initial code verification tool identifier, and configure the initial code verification tool according to the running configuration parameters to obtain the target code verification tool.

[0126] Optionally, the device further includes a code verification report generation module, specifically used for: The at least one verification state data that does not match the expected state data is identified as abnormal verification state data, and the code execution path corresponding to the abnormal verification state data is identified as a counterexample code execution path. Based on the execution path of the counterexample code, risk description information and code repair suggestions are generated for the original network communication code. A code verification report is generated based on the location of the abnormal code, the code verification result, the risk description information, and the code repair suggestions. The location of the abnormal code is the code location in the network communication code to be verified associated with the execution path of the counterexample code.

[0127] Optionally, the device further includes a data storage module, specifically used for: Based on the original network communication code, the network security requirements specification document, the network security requirements structured information, the network communication code to be verified, and the code verification report, information to be archived is generated; Obtain the task identifier information corresponding to this code verification, and associate and store the task identifier information and the information to be archived.

[0128] Optionally, the code verification strategy determination module 32 is further used for: The network security requirements specification document is input into the target large language model, and the target large language model is used to perform semantic analysis on the network security requirements specification document to determine the structured information of the network security requirements contained in the network security requirements specification document; Obtain the structured information of the network security requirements output by the target large language model.

[0129] Optionally, the structured information of network security requirements includes at least one of the following: task objectives, task keywords, interface descriptions, input constraints, output constraints, and functional boundaries.

[0130] The code verification device for the train operation control system provided in this embodiment of the invention can execute the code verification method for the train operation control system provided in any embodiment of the invention, and has the corresponding functional modules and beneficial effects of the execution method.

[0131] According to embodiments of this disclosure, this disclosure also provides an electronic device, a readable storage medium, and a computer program product.

[0132] Example 4 Figure 4 A schematic diagram of an electronic device 40 that can be used to implement embodiments of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (e.g., helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.

[0133] like Figure 4As shown, the electronic device 40 includes at least one processor 41 and a memory, such as a read-only memory (ROM) 42 or a random access memory (RAM) 43, communicatively connected to the at least one processor 41. The memory stores computer programs executable by the at least one processor. The processor 41 can perform various appropriate actions and processes based on the computer program stored in the ROM 42 or loaded from storage unit 48 into the RAM 43. The RAM 43 may also store various programs and data required for the operation of the electronic device 40. The processor 41, ROM 42, and RAM 43 are interconnected via a bus 44. An input / output (I / O) interface 45 is also connected to the bus 44.

[0134] Multiple components in electronic device 40 are connected to I / O interface 45, including: input unit 46, such as keyboard, mouse, etc.; output unit 47, such as various types of monitors, speakers, etc.; storage unit 48, such as disk, optical disk, etc.; and communication unit 49, such as network card, modem, wireless transceiver, etc. Communication unit 49 allows electronic device 40 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.

[0135] Processor 41 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 41 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Processor 41 performs the various methods and processes described above, such as code verification methods for train operation control systems.

[0136] In some embodiments, the code verification method for the train operation control system may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 48. In some embodiments, part or all of the computer program may be loaded and / or installed on electronic device 40 via ROM 42 and / or communication unit 49. When the computer program is loaded into RAM 43 and executed by processor 41, one or more steps of the code verification method for the train operation control system described above may be performed. Alternatively, in other embodiments, processor 41 may be configured to perform the code verification method for the train operation control system by any other suitable means (e.g., by means of firmware).

[0137] Various implementations of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various implementations may include: implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.

[0138] Computer programs used to implement the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be performed. The computer programs may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0139] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0140] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).

[0141] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or computing systems that include middleware components (e.g., application servers), or computing systems that include frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.

[0142] A computing system can include clients and servers. Clients and servers are generally geographically separated and typically interact via communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a host product within the cloud computing service system to address the shortcomings of traditional physical hosts and virtual private servers, such as high management difficulty and weak business scalability.

[0143] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.

[0144] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.

Claims

1. A code verification method for a train operation control system, characterized in that, The method includes: Obtain the original network communication code corresponding to the target train operation control system, and obtain the network security requirements specification document associated with the target train operation control system; Semantic analysis is performed on the network security requirements specification document to extract structured information of network security requirements, and target code verification strategies for verifying the original network communication code are determined based on the structured information of network security requirements. Based on the target code verification strategy and the network security requirement structured information, the assertion specification and the code insertion position of the assertion specification in the original network communication code are determined, and the assertion specification is inserted into the original network communication code according to the code insertion position to obtain the network communication code to be verified. The target code verification tool is used to verify the network communication code to be verified according to the assertion specification, and the code verification result is obtained.

2. The method according to claim 1, characterized in that, The step of determining the target code verification strategy for verifying the original network communication code based on the structured information of network security requirements includes: The network security requirement structured information and the original network communication code are input into the target large language model, and the target code verification strategy identifier is determined from the candidate code verification strategy identifiers based on the network security requirement structured information and the original network communication code. Obtain the target code verification strategy identifier output by the target large language model, and determine the target code verification strategy based on the target code verification strategy identifier.

3. The method according to claim 1, characterized in that, The step of determining the assertion specification and the code insertion position of the assertion specification in the original network communication code based on the target code verification strategy and the network security requirement structured information includes: The target code verification strategy and the network security requirement structured information are input into the target large language model, and the assertion specification and the code insertion position are determined by the target large language model based on the target code verification strategy and the network security requirement structured information. Obtain the assertion specification and the code insertion position output by the target large language model.

4. The method according to claim 1, characterized in that, The step of using a target code verification tool to verify the network communication code to be verified according to the assertion specification, and obtaining the code verification result, includes: The assertion specification is parsed using the target code verification tool to generate a verification task description that is compatible with the target code verification tool; Based on the verification task description, the corresponding verification is performed on the network communication code to be verified to obtain the verification status data corresponding to each code execution path. The verification status data is compared with the expected status data defined in the assertion specification, and the code verification result is determined based on the comparison result.

5. The method according to claim 4, characterized in that, Determining the code verification result based on the comparison result includes: If all the verification status data match the expected status data, then the code verification result is determined to be normal. If at least one of the verification status data does not match the expected status data, then the code verification result is determined to be a code anomaly.

6. The method according to claim 1, before verifying the network communication code to be verified using the target code verification tool according to the assertion specification and obtaining the code verification result, further comprising: The network security requirement structured information and the original network communication code are input into the target large language model. Based on the network security requirement structured information and the original network communication code, the target large language model determines the initial code verification tool identifier from the candidate code verification tool identifiers and generates the runtime configuration parameters associated with the initial code verification tool identifier. Obtain the initial code verification tool identifier and the running configuration parameters output by the target large language model, determine the initial code verification tool from the candidate code verification tools according to the initial code verification tool identifier, and configure the initial code verification tool according to the running configuration parameters to obtain the target code verification tool.

7. The method according to claim 5, further comprising, after determining that the code verification result is a code exception: The at least one verification state data that does not match the expected state data is identified as abnormal verification state data, and the code execution path corresponding to the abnormal verification state data is identified as a counterexample code execution path. Based on the execution path of the counterexample code, risk description information and code repair suggestions are generated for the original network communication code. A code verification report is generated based on the location of the abnormal code, the code verification result, the risk description information, and the code repair suggestions. The location of the abnormal code is the code location in the network communication code to be verified associated with the execution path of the counterexample code.

8. The method according to claim 7, further comprising: Based on the original network communication code, the network security requirements specification document, the network security requirements structured information, the network communication code to be verified, and the code verification report, information to be archived is generated; Obtain the task identifier information corresponding to this code verification, and associate and store the task identifier information and the information to be archived.

9. The method according to claim 1, characterized in that, The semantic analysis of the network security requirements specification document to extract structured information about network security requirements includes: The network security requirements specification document is input into the target large language model, and the target large language model is used to perform semantic analysis on the network security requirements specification document to determine the structured information of the network security requirements contained in the network security requirements specification document; Obtain the structured information of the network security requirements output by the target large language model.

10. The method according to any one of claims 1-9, characterized in that, The structured information of network security requirements includes at least one of the following: task objectives, task keywords, interface descriptions, input constraints, output constraints, and functional boundaries.

11. A code verification device for a train operation control system, characterized in that, The device includes: The information acquisition module is used to acquire the original network communication code corresponding to the target train operation control system, and to acquire the network security requirement specification document associated with the target train operation control system. The code verification strategy determination module is used to perform semantic analysis on the network security requirements specification document, extract structured information of network security requirements, and determine the target code verification strategy for verifying the original network communication code based on the structured information of network security requirements. The network communication code acquisition module is used to determine the assertion specification and the code insertion position of the assertion specification in the original network communication code according to the target code verification strategy and the network security requirement structured information, and to insert the assertion specification into the original network communication code according to the code insertion position to obtain the network communication code to be verified. The code verification module is used to verify the network communication code to be verified using a target code verification tool according to the assertion specification, and obtain the code verification result.

12. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor to enable the at least one processor to perform the method according to any one of claims 1-10.

13. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions for causing a processor to perform the method of any one of claims 1-10.

14. A computer program product comprising a computer program that, when executed by a processor, implements the method according to any one of claims 1-10.