Intelligent test and verification method for aerospace complex electronic system
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-07
- Publication Date
- 2026-08-11
AI Technical Summary
[0005]本发明的目的在于提供一种面向航空航天复杂电子系统的智能测试验证方法,以解决现有常规验证体系难以在微观时域维度主动诱发网络排队抖动与硬件突发隔离相交叠的并发异常,进而无法有效排查系统底层链路连带静默丢包风险的技术问题
[0050] The testing and verification method provided by this invention analyzes the micro-time slot topology and continuously quantifies the micro-jitter of packets. When the jitter exceeds the limit, it actively adjusts the transmission phase of affected packets, compressing idle gaps within a full-load communication cycle to reconstruct a time-sensitive boundary. Based on this boundary, the method uses constructed shadow fault frames for interleaving injection, inducing underlying network nodes to execute hardware-level electrical isolation mechanisms, objectively recreating the complex waveform overlap environment when the physical medium is experiencing latency accumulation and sudden link disconnection. This dual-linkage logic of time compression and fault interleaving initiated by the test end overcomes the limitation of steady-state troubleshooting methods in easily inducing concurrent anomalies, and can accurately monitor and reproduce the hidden, silent packet loss phenomenon of the system. The method performs scatter mapping on the acquired multi-dimensional test indicators, presenting the underlying coupling relationship between the deterministic deterioration trend of the network and hardware protection actions, providing quantitative data support for subsequent optimization of network medium buffer design and system fault tolerance baseline.
Smart Images

Figure CN122554352A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of aerospace electronic communication testing and verification technology, and in particular to intelligent testing and verification methods for complex aerospace electronic systems. Background Technology
[0002] Aerospace electronic systems involve intensive concurrent multi-node communication and data exchange during their operational cycles. Conventional testing and verification methods for bus networks primarily rely on pre-defined sequences for message distribution and status feedback data comparison. Given the widely distributed and tightly timed underlying networks, basic testing procedures typically focus on verifying the connectivity of protocol links and the operation of macroscopic data cycles, meeting the standard engineering requirements for basic communication function verification under stable network load conditions.
[0003] As the frequency of communication between terminal nodes continues to increase, the media access control and queuing buffering mechanisms within the network can cause micro-delay fluctuations in data packet transmission during multi-task concurrent processing. In real physical operating environments, this data stream phase drift and abnormal electrical state changes often occur intertwined. When individual nodes in the network fail, triggering the bus protection mechanism to generate hardware-level isolation, rate-constrained packets at the edge of the communication timing are easily affected by the physical impact of local link disconnection, resulting in a low-level silent packet loss phenomenon that is difficult for the system's higher-level self-checking mechanisms to detect.
[0004] Existing conventional verification systems struggle to construct sufficient physical reproduction conditions to actively induce and monitor the aforementioned cross-anomalies. Conventional testing methods typically assess network steady-state load capacity and single hardware fault isolation functions independently, and joint troubleshooting methods at the physical level for network queuing jitter combined with random fault isolation critical states require further development. This testing status quo objectively limits the quantitative evaluation of the robustness of electronic system network communication boundaries. Engineering practice necessitates the introduction of testing mechanisms capable of applying specific timing stimuli and inducing fault boundary conditions at the micro-time slot level. Summary of the Invention
[0005] The purpose of this invention is to provide an intelligent testing and verification method for complex electronic systems in aerospace, in order to solve the technical problem that existing conventional verification systems are unable to actively induce concurrent anomalies that overlap between network queuing jitter and hardware burst isolation in the micro-time domain dimension, and thus cannot effectively investigate the risk of silent packet loss in the underlying links of the system.
[0006] To achieve the above objectives, the present invention provides the following technical solution:
[0007] A smart test and verification method for complex electronic systems in aerospace includes:
[0008] The interface control document of the electronic system under test is parsed, the micro-time slot topology defined by the underlying communication protocol is extracted, an initial scheduling sequence is generated, and various test messages are sent out. The test messages include rate constraint messages, and the absolute timestamps fed back by the physical layer are captured synchronously.
[0009] Extract the micro jitter when adjacent test messages arrive. If the micro jitter exceeds the anti-collision preset threshold, shift the transmission phase of the affected rate-constrained message to a discrete idle interval to compress the idle communication gap, thereby constructing a reconstructed time-sensitive boundary and generating a corresponding transmission phase shift record.
[0010] Extract the preset high-security-level node identifier recorded in the interface control document to construct a shadow fault frame. Fit the shadow fault frame into the tail critical protection margin of the reconstruction timing vulnerability boundary and perform interleaving injection to induce the bus protection mechanism to trigger hardware-level electrical isolation.
[0011] Monitor whether the rate-constrained packets located inside the reconfiguration timing vulnerability boundary experience cascading silent packet loss during the hardware-level electrical isolation period;
[0012] By integrating the micro-jitter amount, the transmitted phase shift record, and the associated silent packet loss phenomenon, the verification and evaluation results for the overall communication architecture are quantitatively output.
[0013] Optionally, the step of parsing the interface control document of the electronic system under test, extracting the micro-time slot topology defined by the underlying communication protocol, generating an initial scheduling sequence, and sending out various test messages includes:
[0014] The distributed simulation middleware is invoked to read the physical node matrix and bandwidth allocation ratio recorded in the interface control document;
[0015] Based on the physical node matrix and the bandwidth allocation ratio, the triggering order of various service data packets is arranged to establish the initial scheduling sequence;
[0016] Each service data packet in the initial scheduling sequence is encapsulated into a network protocol data unit and injected into the electronic system under test as a test message.
[0017] Optionally, the absolute timestamp of the synchronously captured physical layer feedback includes:
[0018] Using a high-frequency crystal clock deployed at the pins inside the electronic system under test, the network response flag is captured at the moment when the underlying level state flips.
[0019] The local inherent transmission delay consumed by the interrupt triggered by the test hardware is deducted from the time count value when the network response flag is captured;
[0020] The valid network response flag, after deducting the local inherent transmission delay, is bound to a value with global absolute time base significance and stored in the cache queue as the absolute timestamp.
[0021] Optionally, the extraction of the micro jitter amount when adjacent test messages arrive includes:
[0022] Extract the absolute timestamps corresponding to the consecutively arriving pre-test messages and post-test messages from the cache queue;
[0023] Subtract the absolute timestamp of the preceding test message from the absolute timestamp of the subsequent test message to obtain the actual flow interval.
[0024] Calculate the absolute value of the difference between the actual flow interval and the theoretical transmission interval, and define the absolute value of the difference as the micro jitter amount.
[0025] Optionally, determining that the micro-jitter amount crosses an anti-collision preset threshold includes:
[0026] The micro-jitter values obtained in multiple rounds are statistically analyzed, and a transient anti-collision jitter envelope is plotted using a curve fitting algorithm.
[0027] An alarm baseline value representing the limit of network deterministic degradation is set as the anti-collision preset threshold.
[0028] When the peak of the transient anti-collision jitter envelope exceeds the alarm reference value, it is determined that the micro jitter amount exceeds the anti-collision preset threshold.
[0029] Optionally, shifting the transmission phase of the affected rate-constrained messages to a discrete idle interval to compress idle communication gaps, thereby constructing a reconstructed temporally vulnerable boundary, includes:
[0030] Traverse the micro-time slot topology and find the continuous blank communication segments that have not been occupied by high-priority tasks in the current macro-period polling process as the discrete free intervals.
[0031] The delay offset value of the affected rate constraint message within the underlying drive queue is dynamically adjusted so that the level transmission start point of the affected rate constraint message is aligned with the starting edge of the discrete idle interval.
[0032] The start and end edges of the discrete free intervals are extracted and solidified as the reconstructed temporal fragile boundaries.
[0033] Optionally, dynamically adjusting the delay offset value of the affected rate-constrained message within the underlying driver queue includes:
[0034] The estimated transmission time of the affected rate constraint message in the physical cable medium is determined.
[0035] If the transmission duration exceeds the total time span of the discrete free interval, the affected rate-constrained message will be truncated and fragmented at the application layer to generate multiple independent sub-messages.
[0036] The multiple independent sub-messages are shifted to multiple adjacent blank communication segments for decentralized transmission.
[0037] Optionally, the step of extracting the preset high-security-level node identifiers recorded in the interface control document to construct a shadow fault frame includes:
[0038] Extract the original media access control address and sequence number increment rule of the communication node with a preset high security level defined in the interface control document;
[0039] Generate an identity tag that is of the same origin as the original media access control address, and construct a distorted sequence number whose jump range exceeds the sequence number increment rule;
[0040] The identity tag is concatenated with the distorted sequence number, and a frame check sequence polarity reversal error is introduced, which is then encapsulated to form the shadow fault frame.
[0041] Optionally, the step of inserting the shadow fault frame into the tail critical protection margin of the reconstruction timing vulnerability boundary to induce the bus guardian mechanism to trigger hardware-level electrical isolation includes:
[0042] Listen to the reference synchronization waveform on the backbone network inside the electronic system under test, and lock the absolute position of the reconstructed timing vulnerability boundary on the global time axis;
[0043] During the nanosecond-level silent protection period immediately outside the reconstructed timing vulnerable boundary, the carrier sense backoff constraint is skipped, and the shadow fault frame is injected into the bus as the interleaved injection.
[0044] The monitoring network switching node in the electronic system under test performs a physical disconnection action when it detects a polarity reversal error between the distorted sequence number carried by the shadow fault frame and the frame check sequence, as a hardware-level electrical isolation.
[0045] Optionally, the fusion of the micro-jitter amount, the transmitted phase shift record, and the associated silent packet loss phenomenon, and the quantitative output of the verification and evaluation results for the overall communication architecture, including:
[0046] Multiple sets of test data accumulated from multiple loop tests are retrieved. Each set of test data includes the micro jitter amount when the phase shift recording is triggered, as well as the associated silent packet loss phenomenon induced when the phase shift recording is transmitted.
[0047] By using a multi-dimensional coordinate system to perform scatter projection on the test data of each group, a performance bottleneck map reflecting the coupling relationship between the network deterministic deterioration trend and the hardware error isolation boundary is drawn;
[0048] The performance bottleneck map is compared with the longest fault tolerance recovery threshold defined in the system safety design baseline, and the verification and evaluation results are summarized and output.
[0049] The present invention has achieved the following beneficial effects:
[0050] The testing and verification method provided by this invention analyzes the micro-time slot topology and continuously quantifies the micro-jitter of packets. When the jitter exceeds the limit, it actively adjusts the transmission phase of affected packets, compressing idle gaps within a full-load communication cycle to reconstruct a time-sensitive boundary. Based on this boundary, the method uses constructed shadow fault frames for interleaving injection, inducing underlying network nodes to execute hardware-level electrical isolation mechanisms, objectively recreating the complex waveform overlap environment when the physical medium is experiencing latency accumulation and sudden link disconnection. This dual-linkage logic of time compression and fault interleaving initiated by the test end overcomes the limitation of steady-state troubleshooting methods in easily inducing concurrent anomalies, and can accurately monitor and reproduce the hidden, silent packet loss phenomenon of the system. The method performs scatter mapping on the acquired multi-dimensional test indicators, presenting the underlying coupling relationship between the deterministic deterioration trend of the network and hardware protection actions, providing quantitative data support for subsequent optimization of network medium buffer design and system fault tolerance baseline.
[0051] Other features and advantages of the invention will be set forth in the following description, and will be apparent in part from the description, or may be learned by practicing the invention. The objects and other advantages of the invention may be realized and obtained by means of the structures particularly pointed out in the written description and the accompanying drawings.
[0052] The technical solution of the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. Attached Figure Description
[0053] The accompanying drawings are provided to further illustrate the invention and form part of the specification. They are used in conjunction with embodiments of the invention to explain the invention and do not constitute a limitation thereof. In the drawings:
[0054] Figure 1 This is a flowchart illustrating the intelligent testing and verification method for complex electronic systems in aerospace according to an embodiment of the present invention.
[0055] Figure 2 This is a schematic diagram illustrating the process of generating the initial scheduling sequence and issuing various test messages in an embodiment of the present invention;
[0056] Figure 3 This is a schematic diagram of the process for synchronously capturing the absolute timestamp of the physical layer feedback in an embodiment of the present invention;
[0057] Figure 4 This is a schematic diagram of the process for extracting the micro-jitter amount when adjacent test messages arrive, as shown in this embodiment of the invention.
[0058] Figure 5 This is a schematic diagram of the process for constructing a shadow fault frame in an embodiment of the present invention;
[0059] Figure 6 This is a schematic diagram of the composition structure of the intelligent testing and verification system in an embodiment of the present invention. Detailed Implementation
[0060] The preferred embodiments of the present invention will be described below with reference to the accompanying drawings. It should be understood that the preferred embodiments described herein are for illustration and explanation only and are not intended to limit the present invention.
[0061] Aerospace electronic systems involve concurrent multi-node communication and data interaction during their operational cycles. Conventional testing and verification methods for bus networks primarily rely on pre-set sequences for message distribution and status feedback data comparison. However, given the large number of nodes and the tightly scheduled timing of the underlying physical network, basic testing mechanisms struggle to capture the dynamic fluctuations and communication conflict risks within the underlying micro-time domain in a timely manner. Therefore, this application provides an intelligent testing and verification method for complex aerospace electronic systems, capable of scheduling based on micro-time slot topology and implementing timing compression within specific physical time windows.
[0062] This application discloses an intelligent testing and verification method for complex electronic systems in aerospace applications, such as... Figure 1 As shown, the method includes the following steps:
[0063] Step S10: Parse the interface control document of the electronic system under test, extract the micro-time slot topology defined by the underlying communication protocol, generate the initial scheduling sequence and send out various test messages, and synchronously capture the absolute timestamps fed back by the physical layer. The test messages include rate constraint messages.
[0064] Specifically, such as Figure 2As shown, the process of parsing the interface control document of the electronic system under test, extracting the micro-time slot topology defined by the underlying communication protocol, generating an initial scheduling sequence, and issuing various test messages includes: calling the distributed simulation middleware to read the physical node matrix and bandwidth allocation ratio recorded in the interface control document; arranging the triggering order of various service data packets according to the physical node matrix and the bandwidth allocation ratio to establish the initial scheduling sequence; and encapsulating the various service data packets in the initial scheduling sequence into network protocol data units, which are then injected into the electronic system under test as various test messages. Specifically, the physical node matrix is stored in the software layer using a two-dimensional structure array Node_Matrix[M]. The dynamically allocated row index M corresponds to the unique hardware identifier of the physical node, and its internal structure members sequentially store the media access control (MAC) address and communication port number of the node. The bandwidth allocation ratio is stored using a one-dimensional floating-point array Bandwidth_Array[M], whose array index is consistent with the row index M of the two-dimensional structure array, establishing a one-to-one linear mapping relationship through the hardware identifier. The interface control document is compiled in Extensible Markup Language (XML) format. The distributed simulation middleware utilizes a built-in Document Object Model (DOM) parser to locate and extract corresponding parameter values using preset XPath path matching rules (e.g., setting the retrieval path for the physical node matrix to " / ICD / Network / Nodes" and the retrieval path for the bandwidth allocation ratio to " / ICD / Network / Bandwidth").
[0065] The triggering order of the various service data packets is specifically arranged using the rate monotonic scheduling algorithm (RM algorithm), which assigns static priorities according to the length of the transmission period defined in the interface control document for each service data packet. The shorter the period, the higher the priority of the service data packet. The physical time slots are seamlessly filled in order of static priority from high to low to establish the initial scheduling sequence.
[0066] Furthermore, the interface control document is converted into a time-domain layout mapping table recognizable by the underlying hardware of the test fixture. Essentially, this constructs a static time-slot polling grid for the underlying media access controller. After the test system's main control board parses the physical node matrix and bandwidth allocation parameters, it opens a dual-port block random access memory within the field-programmable gate array (FPGA) as a hardware time wheel for the global macro-cycle. This time wheel divides continuous physical memory slots according to the microsecond-level resolution of the underlying crystal oscillator. The direct memory access start cursor for each service data packet is directly burned into the physical address of the corresponding time slot. The physical address of the corresponding time slot... The mapping relationship follows the formula: ,in This is the global base address allocated to the time wheel in the dual-port block random access memory. This is the absolute trigger time for scheduling the service data packets. This refers to the microsecond-level resolution step size of the underlying crystal oscillator. This refers to the fixed storage bit width occupied by a single physical memory slot. In specific hardware addressing implementations, the... The value is equivalent to the constant value after converting the fixed storage bit width into the base address step unit (such as a byte or word). When the read cursor of the hardware main crystal oscillator drives the time wheel to auto-increment and touches a non-empty address slot, it directly triggers the underlying direct memory access controller, pushing the pre-encapsulated test message into the physical layer transmission queue. For missing nodes that are not assembled in the test field, the test fixture does not use the pure software simulation task scheduling of the traditional operating system, but directly starts the virtual endpoint hard mapping mechanism inside the logic gate array. By using an independent hardware timer to bind the trigger parameters in the dual-port memory, it automatically generates a simulated response data stream according to a fixed physical clock, eliminating the time drift caused by software task preemption and ensuring that the message transmission sequence conforms to the underlying physical constraints.
[0067] Specifically, such as Figure 3 As shown, the method of synchronously capturing the absolute timestamp of the physical layer feedback includes: using a high-frequency crystal oscillator clock deployed at the pin of the electronic system under test to capture the network response flag at the moment when the underlying level state flips; deducting the local inherent transmission delay consumed by the interrupt triggered by the test hardware from the time count value when capturing the network response flag; binding a value with global absolute time base significance to the valid network response flag after deducting the local inherent transmission delay, and storing it in the cache queue as the absolute timestamp.
[0068] The absolute timestamps of physical layer feedback are captured synchronously to quantify and analyze the real-time transmission performance of the electronic system under test (ESD). A high-frequency crystal oscillator clock deployed at the pins inside the ESD is used to capture network response flags at the moments when the underlying level states transition. The high-frequency crystal oscillator clock is connected to the underlying hardware pins to provide measurement resolution.
[0069] Specifically, the operating frequency of the high-frequency crystal oscillator clock is configured to be no less than 1 GHz. When the communication interface output level of the electronic system under test transitions from low to high or falls back to low, the edge detection circuit of the high-frequency crystal oscillator clock triggers a hardware interrupt, latches the current clock counter's count value, and forms a network response flag. The inherent local transmission delay consumed by the interrupt triggered by the test hardware is deducted from the time count value when the network response flag is captured. The inherent local transmission delay includes the signal propagation time of the copper traces and the conversion time within the transceiver chip. The value of the inherent local transmission delay is calibrated through a short-circuit loopback test and subtracted from the count value.
[0070] Specifically, local inherent transmission latency The calibration calculation formula is as follows ,in The absolute timestamp when the master control terminal sends the test pulse. This is the absolute timestamp of the self-transmitted pulse received at the same physical port after a short-circuit loopback. A value with global absolute time base significance is assigned to the valid network acknowledgment flag (after deducting local inherent transmission delay), and stored as an absolute timestamp in the cache queue. This assignment process aligns the local hardware counter value with the network-wide synchronization clock of the electronic system under test.
[0071] Step S20: Extract the micro jitter amount when adjacent test messages arrive. If the micro jitter amount exceeds the anti-collision preset threshold, shift the transmission phase of the affected rate constraint message to the discrete idle interval to compress the idle communication gap, thereby forming a reconstructed time-sensitive fragile boundary and generating a corresponding transmission phase shift record.
[0072] Specifically, such as Figure 4 As shown, the extraction of the micro jitter amount when adjacent test packets arrive includes: extracting the absolute timestamps corresponding to the preceding and following test packets that arrive consecutively from the cache queue; subtracting the absolute timestamp corresponding to the preceding test packet from the absolute timestamp corresponding to the following test packet to obtain the actual flow interval; calculating the absolute value of the difference between the actual flow interval and the theoretical sending interval, and defining the absolute value of the difference as the micro jitter amount.
[0073] In time-triggered networks, consecutive packets belonging to the same virtual link group arrive at the receiver at fixed time intervals. The queuing and buffering mechanisms of intermediate switching nodes cause a time skew in the transmission of data packets on the physical link. The absolute timestamps corresponding to the preceding and following test packets are extracted from the cache queue. In the data processing unit of the test equipment, the absolute timestamp corresponding to the following test packet is subtracted from the absolute timestamp corresponding to the preceding test packet to calculate the actual flow interval. The actual flow interval represents the physical time difference between the arrival of two consecutive data packets at the receiver. The absolute value of the difference between the actual flow interval and the theoretical transmission interval is calculated and defined as the micro-jitter. The theoretical transmission interval is a time span parameter pre-set by the interface control document and the initial scheduling sequence. The value of the micro-jitter reflects the degree of queuing backlog within the network link.
[0074] Further, determining that the micro-jitter amount crosses the anti-collision preset threshold includes: statistically analyzing the micro-jitter amount obtained in multiple rounds, and plotting the transient anti-collision jitter envelope using a curve fitting algorithm; setting an alarm benchmark value characterizing the limit of network deterministic degradation as the anti-collision preset threshold; and determining that the micro-jitter amount crosses the anti-collision preset threshold when the peak of the transient anti-collision jitter envelope exceeds the alarm benchmark value.
[0075] In this embodiment, the curve fitting algorithm adopts a third-order polynomial fitting algorithm, with the absolute time axis of the test execution as the independent variable (and the range of the independent variable is strictly limited to a sliding time window of fixed width N tracing back from the current moment. In this embodiment, N is fixed to 100 macro cycles), and the micro jitter amount at the corresponding moment as the dependent variable. The polynomial coefficients are solved by the least squares method to smooth the noise, and the resulting fitting curve is the transient anti-collision jitter envelope.
[0076] To address the micro-jitter acquired in multiple rounds, the main control chip of the test equipment uses an internal hardware timer to accumulate the relative clock ticks of consecutively arriving packets, stores them in a fixed-length circular buffer queue, and performs sliding window averaging calculations to filter out occasional clock glitches in the physical link. The anti-collision preset threshold setting directly anchors to the upper limit of the queue depth of the receiving first-in-first-out queue within the media access control layer of the target switching node. The test program reads the device's network interface card (NIC) datasheet to obtain the full-capacity byte capacity of the receive queue. Specifically, the reading action is automatically completed by the test program parsing the chip configuration trie tree (Trie Tree) preset in the system initialization configuration file. The system initialization configuration file is in JSON format. During the initialization phase, the test program sequentially reads the chip model string in the JSON file and dynamically generates nodes according to the hierarchical order of the character ASCII codes to construct the chip configuration trie tree. Each leaf node has a memory pointer attached to a structure containing the full-capacity byte capacity of the receive queue. The key of the trie tree is the physical media control chip model, and the value is a structure table containing parameters such as the full-capacity byte capacity of the corresponding chip's receive queue. After deducting the basic queuing margin when the network stack performs direct memory access, the remaining number of safe available bytes is divided by the physical transmission baud rate negotiated by the current link to calculate the limit queuing time tolerance, which is used as the preset anti-collision threshold.
[0077] The basic queuing margin is set to a fixed value during system initialization. Its specific value is equal to the maximum burst size supported by the underlying direct memory access controller of the network card under test, plus the maximum jitter overhead bytes for context switching in the operating system. In this embodiment, a value of 1518 bytes is preferred. Once the average jitter output by the sliding window approaches this time tolerance, it means that the receiver's hardware buffer is about to overflow, and the underlying communication timing has entered a vulnerable area prone to silent packet loss. Based on this, it is determined that the micro-jitter amount has exceeded the anti-collision preset threshold.
[0078] It is understood that shifting the transmission phase of the affected rate constraint message to a discrete idle interval to compress idle communication gaps and thus construct a reconstructed time-fragile boundary includes: traversing the micro-slot topology to find continuous blank communication segments that have not yet been occupied by high-priority tasks during the current macro-period polling process as the discrete idle interval; dynamically adjusting the delay offset value of the affected rate constraint message within the underlying drive queue so that the transmission start point of the affected rate constraint message is aligned with the start edge of the discrete idle interval; and extracting the start and end edges of the discrete idle interval and solidifying them as the reconstructed time-fragile boundary.
[0079] After determining that the micro-jitter exceeds the anti-collision preset threshold, the micro-time slot topology is traversed to find continuous blank communication segments not occupied by high-priority tasks during the current macro-cycle polling process as discrete free intervals. The scheduling module of the test equipment scans the static time slot allocation map of the macro-cycle to find communication time slots not occupied by time-triggered tasks. Through scanning, continuous blank communication segments with usable width are identified as discrete free intervals. The delay offset value of the affected rate constraint messages within the underlying drive queue is dynamically adjusted so that the transmission start point of the affected rate constraint messages is aligned with the starting edge of the discrete free interval.
[0080] The test equipment rewrites the timing values within the network card's underlying driver control to apply a delay offset value to rate-constrained packets. The delay offset value... The calculation formula is: ,in The absolute timestamp of the starting edge of the confirmed discrete free interval is used for searching. This is the theoretical timestamp of the affected rate constraint message originally scheduled for transmission in the initial scheduling sequence. The delay offset value postpones the upcoming transmission of the rate constraint message, aligning the physical level transmission action to the start edge of the discrete idle interval. The start and end edges of the discrete idle interval are extracted and solidified as the reconstructed timing fragile boundaries. The affected rate constraint messages are centrally shifted into the discrete idle interval, occupying the corresponding buffer time span.
[0081] Specifically, dynamically adjusting the delay offset value of the affected rate constraint message within the underlying drive queue includes: estimating the transmission duration of the affected rate constraint message in the physical cable medium; if the transmission duration exceeds the total time span of the discrete idle interval, then performing truncation and fragmentation processing on the affected rate constraint message at the application layer to generate multiple independent sub-messages; and shifting the multiple independent sub-messages to subsequent adjacent blank communication segments for distributed transmission.
[0082] When the estimated transmission duration exceeds the total time span of the discrete idle interval, the underlying test program proportionally converts the microsecond span of the discrete idle interval into the maximum transmittable bytes that the current time slot can accommodate, based on the current physical cable's communication baud rate. The specific logic for this proportional conversion follows the calculation formula: .in, To calculate the maximum number of bytes that can be sent, a round-down operation is performed here to absolutely ensure that the physical truncation boundary does not overflow the current empty time slot; This refers to the actual microsecond span of the discrete free interval; This is the bit-per-second transmission baud rate negotiated and determined at the underlying layer of the current physical cable medium. When the underlying logic of the test program executes this calculation, it will pre-multiply the actual microsecond span by... The conversion factors are standardized to the second level. After deducting the preamble and tail checksum bytes occupied by the underlying protocol, the safe truncation boundary of the payload is obtained. The underlying network card driver rewrites the transmit descriptor and direct memory access cursor in the memory stack, and performs hardware-level memory slicing on the original packet according to this truncation boundary. To ensure that the segmented sub-packets are filled with subsequent blank communication segments, the test master control unit bypasses the software queuing mechanism of the operating system network stack and directly writes the converted nanosecond-level offset count value into the clock comparison register of the underlying network controller. When the hardware crystal oscillator tick decreases to zero and triggers the highest-level interrupt, the transmit enable pin of the direct-drive physical transceiver controls the first level transition edge of the sub-packet to align with the physical start edge of the blank time slot.
[0083] Step S30: Extract the preset high-security-level node identifier recorded in the interface control document to construct a shadow fault frame, and insert the shadow fault frame into the tail critical protection margin of the reconstruction timing vulnerability boundary to induce the bus protection mechanism to trigger hardware-level electrical isolation.
[0084] Specifically, such as Figure 5As shown, the step of extracting the preset high-security-level node identifier recorded in the interface control document to construct a shadow fault frame includes: extracting the original media access control address and sequence number increment rule of the communication node with the preset high security level defined in the interface control document; generating an identity tag of the same origin as the original media access control address, and constructing a distorted sequence number with a jump amplitude exceeding the sequence number increment rule; concatenating the identity tag with the distorted sequence number, and introducing a frame check sequence polarity reversal error, and finally encapsulating it to form the shadow fault frame. The jump amplitude is defined as an integer that is fixedly greater than the length of the MAC layer receive buffer window of the tested node. For example, if the underlying protocol specifies that the sequence number increment step is 1 and the length of the target node's receive buffer window is 64 frames, then the distorted sequence number is fixedly increased by 65 based on the legal sequence number of the previous frame to ensure that it exceeds the normal out-of-order buffer reassembly range.
[0085] The original media access control address and sequence number incrementing rules defined in the interface control document with preset high-security nodes are extracted. The underlying logic is tested to directly concatenate the generated identity tag and out-of-bounds distorted sequence number in memory. During the frame verification sequence stage of encapsulating shadow fault frames, conventional commercial network interface cards (NICs) perform hardware-level correctness verification and self-appending actions during transmission. To overcome this physical interception, the test controller rewrites the NIC chip's transmit configuration register via the underlying microcontroller bus, overwriting the automatic frame verification sequence append enable bit to zero. After the underlying hardware intercepts the standard 32-bit checksum calculated based on the payload, it controls the hardware XOR gate circuit to inject an all-polarity flip level into the checksum. The frame tail data carrying physical-level error characteristics is then sent to the physical layer transceiver's transmission pin using the original data pass-through mode, bypassing all upper-layer protocol stack checks. This pin-level operation implements the fault waveform distortion construction at the real bus level, ensuring that faulty frames can intrude into the physical cable medium.
[0086] Furthermore, the step of inserting the shadow fault frame into the tail critical protection margin of the reconstructed timing vulnerable boundary to induce the bus guardian mechanism to trigger hardware-level electrical isolation includes: listening to the reference synchronization waveform on the backbone network inside the electronic system under test to lock the absolute position of the reconstructed timing vulnerable boundary on the global time axis; during the nanosecond-level silent protection period immediately outside the reconstructed timing vulnerable boundary, skipping the carrier sense backoff restriction and injecting the shadow fault frame into the bus as the insert injection; monitoring the physical connection disconnection action performed by the network switching node in the electronic system under test due to the detection of the polarity reversal error between the distorted sequence number carried by the shadow fault frame and the frame check sequence carried by the shadow fault frame, as the hardware-level electrical isolation.
[0087] The nanosecond-level silent protection period corresponds to the minimum physical time of the frame gap reserved in the underlying network communication standard. The test hardware's field-programmable gate array (FPGA) initiates a high-speed phase-locked loop (PLL) to track the network reference synchronization pulse, and uses a local counter to deduce and reconstruct the nanosecond-level end edge of the timing-fragile boundary. The specific time point of the deduced and reconstructed nanosecond-level end edge of the timing-fragile boundary is... The calculation formula is: ,in This is the absolute timestamp of the arrival of the reference synchronization pulse captured by the phase-locked loop. This is the total number of clock ticks accumulated by the local counter for the current discrete idle interval time span. This is the current stable real-time operating frequency locked by the high-speed phase-locked loop. As the timeline approaches the center of this frame gap, the underlying test engine, through the management data input / output bus interface, writes the highest-priority mask to the specific carrier sense (CRS) control register address mapped inside the physical layer transceiver. This mask is specifically configured as a 16-bit all-1 hexadecimal value (0xFFFF). This pin-level overwrite operation lowers the carrier sense logic flag, cutting off the conventional carrier sense backoff waiting mechanism from the underlying hardware. The test engine then raises the transmit enable signal, inputting the polarity-flipped level corresponding to the shadow fault frame into the physical cable without backoff. When the switching node encounters this non-standard waveform impact before the isolation recovery period ends, the hardware arbitration logic detects the sudden change in the physical layer error state and triggers the port circuit breaker protection mechanism to implement hardware-level electrical isolation.
[0088] Step S40: Monitor whether the rate constraint message located inside the reconstructed timing vulnerable boundary experiences cascading silent packet loss during the hardware-level electrical isolation.
[0089] Specifically, monitoring whether rate-constrained messages within the vulnerable reconfiguration timing boundary experience silent packet loss during hardware-level electrical isolation involves traffic capture using bypass monitoring modules deployed at the switching node end. The bypass monitoring module connects to the physical transmission cables of the electronic system under test via probe lines. It acquires bus level waveforms, shaping the fluctuating analog signals into digital square wave streams. These digital square wave streams are fed into a serial-to-parallel conversion shift register, where they are decoded into service data frames for the Media Access Control (MAC) layer according to the communication protocol. The payload data and cyclic redundancy checksum of the service data frames are stored in a buffer sequence. The test host periodically retrieves captured valid frame data records from the bypass monitoring modules at each node via an out-of-band management network. This out-of-band management network is physically independent of the backbone network under test.
[0090] Understandably, when a network switching node triggers hardware-level electrical isolation due to receiving a shadow fault frame, the connection at the corresponding physical port is broken, causing a change in the transceiver's internal bias voltage, which propagates along the physical cable. Rate-constrained packets located inside the vulnerable boundary of the reconstruction timing are immediately adjacent to this hardware isolation action on the timeline. If the bitstream of the rate-constrained packet overlaps with the voltage fluctuation waveform, the signal-to-noise ratio (SNR) on the cable drops below the decoding threshold standard. In this embodiment, for the physical layer of the basic Ethernet protocol, the decoding threshold standard specifically refers to an SNR below 10dB, or a differential receive peak-to-peak voltage suddenly dropping below 500mV. The switching node's media access control layer generates an error result during cyclic redundancy check and discards the affected data frames according to the control logic. Because the corresponding physical port is in the disconnection and reset process, the switching node's media access control module cannot return an error code to the upper-layer software, resulting in a cascading silent packet loss phenomenon.
[0091] Unlike conventional software comparison and retrieval, the test system directly relies on the underlying dual-end high-speed memory bitmap hash matching and zeroing mechanism to verify the original total number of transmissions against the total number of payload arrivals. The test host allocates a bitmap mapping area in its internal static random access memory based on message serial number addressing. For each physical frame rate constraint message physically output by the source-end transmission engine, the underlying bus interface controller extracts the serial number from the message header as an offset address index and sets the register status word of the corresponding physical address in the bitmap mapping area to a logic true level. After the bypass listening probe captures and decodes a valid frame on the target side, it returns an arrival pulse to the test host via a physically independent out-of-band interrupt pin, directly driving the address decoding logic to reset and clear the corresponding register status word. The overflow timing value of the nanosecond-level observation timer is statically set to the sum of the maximum hardware isolation recovery time of the physical port defined in the system interface control document and the maximum bidirectional propagation delay of the physical cable. After the set nanosecond-level observation timer overflows, the test host performs a burst scan of the bitmap mapping area. If the residual state bit within the reconstructed timing vulnerability boundary is found to be logically true, and the hardware status register of the tested electronic system is found not to have triggered a link-level retransmission request level, then a silent packet loss event that is difficult for the application layer system code to perceive has been confirmed from the lowest-level physical state causal chain. The reconstructed timing vulnerability boundary causes the waveform and normal load to severely overlap on the parasitic capacitance discharge slope of the physical cable, blocking the receiver's ability to send abnormal interrupts to the upper layer at the physical electrical level.
[0092] Step S50: Integrate the micro jitter, the transmission phase shift record, and the associated silent packet loss phenomenon to quantify and output the verification and evaluation results for the overall communication architecture.
[0093] Specifically, the system integrates the micro-jitter, the transmitted phase shift record, and the associated silent packet loss phenomenon to quantify and output the verification and evaluation results for the overall communication architecture. To present the response characteristics of the underlying hardware, the system directly allocates a two-dimensional grid mapping matrix in the device memory. The total width of the discrete free interval is set as the horizontal axis addressing index, and the micro-jitter is set as the vertical axis addressing index. During the cyclic test process, whenever the bypass monitoring module reports the associated silent packet loss phenomenon, the state register bit in the matrix grid corresponding to the current operating condition coordinate is overwritten from logical false to logical true. After the full range parameter traversal is completed, the test analysis module starts the matrix boundary addressing scan: reading column by column along the horizontal axis in microsecond steps, and extracting the absolute coordinates of the critical grid where the first state changes from false to true in the vertical column. The extracted series of critical transition points are connected in the engineering interface to draw a performance bottleneck map with a stepped lower envelope shape. Based on intuitive hardware memory state boundaries, this graph quantifies the physical baseline for triggering hardware isolation protection within the target switching node. After comparing it with the longest fault tolerance recovery threshold defined in the system security design baseline, the verification and evaluation results are summarized and output.
[0094] Multiple sets of test data accumulated from repeated cyclic tests are retrieved. The test fixture undergoes cyclic testing under set ambient temperature and flow load conditions. The test analysis module establishes a structured evaluation record file, with fields including temperature value, main frequency value, background flow load rate, total width of discrete idle interval, delay offset value, load length, micro jitter, isolation recovery time value, and status code indicating whether packet loss occurred. The accompanying silent packet loss phenomenon induced by the phase shift recording is quantified using Boolean values; packet loss is recorded as a logical true value, and no packet loss is recorded as a logical false value.
[0095] Furthermore, a multi-dimensional coordinate system is used to perform scatter projection on each set of test data. Within the multi-dimensional coordinate system, the micro-jitter is set as the first coordinate variable, the hardware-level electrical isolation recovery time is set as the second coordinate variable, and the packet loss Boolean status code is mapped to the data attribute of the scatter coordinates. A density-based spatial clustering algorithm is used to perform unsupervised classification of the discrete test data points. The Euclidean distance between each data point in the coordinate system is calculated, and data points with an Euclidean distance less than a given neighborhood radius are grouped into the same cluster. In this embodiment, the density-based spatial clustering algorithm uses the DBSCAN algorithm, where the neighborhood radius is set to a constant, equal to the maximum nanosecond-level clock drift tolerance allowed by the underlying network crystal oscillator, and the minimum number of points to be included in the same cluster is set to 5.
[0096] After clustering, the discrete test data is spatially mapped and projected to form a point cloud distribution within the coordinate system. When the point cloud with logical true values exhibits clustering characteristics, the envelope surface surrounding this region defines the performance bottleneck map of the tested electronic system. The test module extracts micro-jitter quantities and the total width of discrete idle intervals to construct a feature matrix. Lost packet Boolean status codes are used as the target labels for supervised training. A support vector machine (SVM) classification algorithm is used to calculate the classification boundary separating logical true and logical false data clusters. The SVM classification algorithm employs a nonlinear radial basis function (RBF). The values of its kernel function parameters and penalty coefficients are automatically optimized through grid search and ten-fold cross-validation in early multi-round pre-test sample sets. Specifically, the parameter optimization space of the grid search is limited to: the search boundary of the penalty coefficient is... The search boundary for the kernel function parameters is Both employ a grid search approach. Discrete sampling is performed using a logarithmic step size with a base of 0.
[0097] Understandably, the performance bottleneck map is compared with the longest fault tolerance recovery threshold defined in the system security design baseline. The longest fault tolerance recovery threshold is projected onto the space where the performance bottleneck map is located, serving as a reference plane. This longest fault tolerance recovery threshold is extracted from the security constraint indicators in the high-level interface control document of the system under test. Its exact value is equal to half the trigger cycle of the application layer watchdog or bus periodic monitoring task, characterizing the maximum duration of low-level hardware disconnection that the system can withstand without triggering a top-level security reset. If the logical truth cloud cluster crosses the reference plane, it indicates a weakness in the physical layer anti-disturbance design of the current network switching node when handling concurrent requests. Based on the spatial coordinates of the out-of-bounds point cloud, the test host traces back to the corresponding physical medium control chip model and parameter information of the sending port, and summarizes and outputs the verification and evaluation results.
[0098] The reverse tracing execution logic is as follows: a static mapping hash table is pre-set in the non-volatile high-capacity storage component of the test host; the key value of the hash table is a three-dimensional physical coordinate threshold range that divides different chip tolerance levels, the three-dimensional physical coordinates include micro jitter, discrete free interval width, and isolation recovery time; the value of the hash table is the chip model and its internal buffer register depth parameter under the corresponding threshold range; the test host extracts the absolute coordinates of the cloud cluster center of the boundary point, matches the key value range of the hash table, and thus directly indexes and reads the corresponding chip model and parameter information. The verification evaluation results include the associated physical condition boundary indicators that trigger cascading faults. Based on the verification evaluation results, the internal state machine delay value or physical storage depth parameter of the media access control module of the switching node is modified, a bitstream file is generated and burned back to the electronic system under test to achieve closed-loop adjustment. As an example, the static mapping hash table contains at least one mapping record: when the captured three-dimensional physical coordinates satisfy the micro jitter level... The width of the nanosecond interval and the discrete free interval are in The time taken for isolation recovery is in the microsecond range. In the millisecond range, the corresponding hash table value is directly mapped to the chip model MAC-10G-A, with an internal buffer register depth of 32KB.
[0099] Based on the aforementioned intelligent testing and verification method, embodiments of this application also provide an intelligent testing and verification system. For example... Figure 6 As shown, the system is deployed inside a computer chassis and includes interconnected central processing units, data cache units, non-volatile high-capacity storage units, and physical transceiver units.
[0100] The physical transceiver component includes a logic gate array (LGA) network interface card (NIC) supporting the target Ethernet and bus standards. The LGA performs level-state control and clock synchronization control. The LGA is responsible for cabling with the physical switching nodes of the electronic system under test, performing actions such as extracting micro-timeslot topology, synchronously capturing absolute timestamps, and injecting shadow fault frames during nanosecond-level silent protection periods. The data buffer component, constructed using random access storage media, stores timestamp data, providing computational buffer space for calculating micro-jitter quantities and fitting transient anti-collision jitter envelopes. The non-volatile, high-capacity storage component stores the operating system runtime library, the distributed simulation middleware runtime library, the all-digital benchmarking model feature library, and the low-level driver code. The low-level driver code is read and executed by the central processing unit, coordinating the coordinated operation of various components to implement the control steps described in this embodiment.
[0101] The central processing unit (CPU) contains multiple concurrent execution kernels, handling data transmission and reception scheduling logic and scatter plotting rendering logic. When the CPU detects that the micro-jitter exceeds the anti-collision preset threshold, it sends a delay offset value to the registers inside the physical transceiver unit, controlling the rate-constrained packet transmission phase shift process and forming a reconstructed timing vulnerability boundary. Based on the collected associated silent packet loss phenomena, the CPU integrates test data to generate verification and evaluation results and stores them in the archive path of the non-volatile high-capacity storage component.
[0102] To ensure hardware and software synergy, the intelligent testing and verification system employs a continuous memory transfer mechanism in its architecture design. When the bypass monitoring module captures incoming and outgoing status words and service feedback data packets, the underlying hardware requests continuous access to memory data blocks from the host system. Network protocol data units, after being disconnected from the physical cable, are written into the memory data block by the bus controller. When the central processing unit initiates the sliding window comparison algorithm, it reads the starting pointer address and offset length of the memory data block to address and parse the packet header sequence number. This continuous memory transfer mechanism reduces the data read / write overhead of the system bus.
[0103] Obviously, those skilled in the art can make various modifications and variations to this invention without departing from its spirit and scope. Therefore, if these modifications and variations fall within the scope of the claims of this invention and their equivalents, this invention also intends to include these modifications and variations.
Claims
1. A smart test and verification method for complex electronic systems in aerospace, characterized in that, include: The interface control document of the electronic system under test is parsed, the micro-time slot topology defined by the underlying communication protocol is extracted, an initial scheduling sequence is generated, and various test messages are sent out. The test messages include rate constraint messages, and the absolute timestamps fed back by the physical layer are captured synchronously. Extract the micro jitter when adjacent test messages arrive. If the micro jitter exceeds the anti-collision preset threshold, shift the transmission phase of the affected rate-constrained message to a discrete idle interval to compress the idle communication gap, thereby constructing a reconstructed time-sensitive boundary and generating a corresponding transmission phase shift record. Extract the preset high-security-level node identifier recorded in the interface control document to construct a shadow fault frame. Fit the shadow fault frame into the tail critical protection margin of the reconstruction timing vulnerability boundary and perform interleaving injection to induce the bus protection mechanism to trigger hardware-level electrical isolation. Monitor whether the rate-constrained packets located inside the reconfiguration timing vulnerability boundary experience cascading silent packet loss during the hardware-level electrical isolation period; By integrating the micro-jitter amount, the transmitted phase shift record, and the associated silent packet loss phenomenon, the verification and evaluation results for the overall communication architecture are quantitatively output.
2. The intelligent test and verification method for complex aerospace electronic systems according to claim 1, characterized in that, The interface control document of the electronic system under test is parsed, the micro-time slot topology defined by the underlying communication protocol is extracted, an initial scheduling sequence is generated, and various test messages are sent out, including: The distributed simulation middleware is invoked to read the physical node matrix and bandwidth allocation ratio recorded in the interface control document; Based on the physical node matrix and the bandwidth allocation ratio, the triggering order of various service data packets is arranged to establish the initial scheduling sequence; Each service data packet in the initial scheduling sequence is encapsulated into a network protocol data unit and injected into the electronic system under test as a test message.
3. The intelligent test and verification method for complex aerospace electronic systems according to claim 1, characterized in that, The absolute timestamp of the synchronous capture of physical layer feedback includes: Using a high-frequency crystal clock deployed at the pins inside the electronic system under test, the network response flag is captured at the moment when the underlying level state flips. The local inherent transmission delay consumed by the interrupt triggered by the test hardware is deducted from the time count value when the network response flag is captured; The valid network response flag, after deducting the local inherent transmission delay, is bound to a value with global absolute time base significance and stored in the cache queue as the absolute timestamp.
4. The intelligent test and verification method for complex aerospace electronic systems according to claim 3, characterized in that, The extraction of the micro-jitter amount when adjacent test messages arrive includes: Extract the absolute timestamps corresponding to the consecutively arriving pre-test messages and post-test messages from the cache queue; Subtract the absolute timestamp of the preceding test message from the absolute timestamp of the subsequent test message to obtain the actual flow interval. Calculate the absolute value of the difference between the actual flow interval and the theoretical transmission interval, and define the absolute value of the difference as the micro jitter amount.
5. The intelligent test and verification method for complex aerospace electronic systems according to claim 1, characterized in that, Determining that the micro-jitter amount crosses the anti-collision preset threshold includes: The micro-jitter values obtained in multiple rounds are statistically analyzed, and a transient anti-collision jitter envelope is plotted using a curve fitting algorithm. An alarm baseline value representing the limit of network deterministic degradation is set as the anti-collision preset threshold. When the peak of the transient anti-collision jitter envelope exceeds the alarm reference value, it is determined that the micro jitter amount exceeds the anti-collision preset threshold.
6. The intelligent test and verification method for complex aerospace electronic systems according to claim 1, characterized in that, The step of shifting the transmission phase of the affected rate-constrained messages into a discrete idle interval to compress idle communication gaps, thereby constructing a reconstructed temporally vulnerable boundary, includes: Traverse the micro-time slot topology and find the continuous blank communication segments that have not been occupied by high-priority tasks in the current macro-period polling process as the discrete free intervals. The delay offset value of the affected rate constraint message within the underlying drive queue is dynamically adjusted so that the level transmission start point of the affected rate constraint message is aligned with the starting edge of the discrete idle interval. The start and end edges of the discrete free intervals are extracted and solidified as the reconstructed temporal fragile boundaries.
7. The intelligent test and verification method for complex aerospace electronic systems according to claim 6, characterized in that, The dynamic adjustment of the delay offset value of the affected rate-constrained message within the underlying driver queue includes: The estimated transmission time of the affected rate constraint message in the physical cable medium is determined. If the transmission duration exceeds the total time span of the discrete free interval, the affected rate-constrained message will be truncated and fragmented at the application layer to generate multiple independent sub-messages. The multiple independent sub-messages are shifted to multiple adjacent blank communication segments for decentralized transmission.
8. The intelligent test and verification method for complex aerospace electronic systems according to claim 1, characterized in that, The step of extracting the preset high-security-level node identifiers recorded in the interface control document to construct a shadow fault frame includes: Extract the original media access control address and sequence number increment rule of the communication node with a preset high security level defined in the interface control document; Generate an identity tag that is of the same origin as the original media access control address, and construct a distorted sequence number whose jump range exceeds the sequence number increment rule; The identity tag is concatenated with the distorted sequence number, and a frame check sequence polarity reversal error is introduced, which is then encapsulated to form the shadow fault frame.
9. The intelligent test and verification method for complex aerospace electronic systems according to claim 8, characterized in that, The step of inserting the shadow fault frame into the tail critical protection margin of the reconstruction timing vulnerability boundary and inducing the bus guardian mechanism to trigger hardware-level electrical isolation includes: Listen to the reference synchronization waveform on the backbone network inside the electronic system under test, and lock the absolute position of the reconstructed timing vulnerability boundary on the global time axis; During the nanosecond-level silent protection period immediately outside the reconstructed timing vulnerable boundary, the carrier sense backoff constraint is skipped, and the shadow fault frame is injected into the bus as the interleaved injection. The monitoring network switching node in the electronic system under test performs a physical disconnection action when it detects a polarity reversal error between the distorted sequence number carried by the shadow fault frame and the frame check sequence, as a hardware-level electrical isolation.
10. The intelligent test and verification method for complex aerospace electronic systems according to claim 1, characterized in that, The system integrates the micro-jitter, the transmitted phase shift record, and the associated silent packet loss phenomenon to quantify and output the verification and evaluation results for the overall communication architecture, including: Multiple sets of test data accumulated from multiple loop tests are retrieved. Each set of test data includes the micro jitter amount when the phase shift recording is triggered, as well as the associated silent packet loss phenomenon induced when the phase shift recording is transmitted. By using a multi-dimensional coordinate system to perform scatter projection on the test data of each group, a performance bottleneck map reflecting the coupling relationship between the network deterministic deterioration trend and the hardware error isolation boundary is drawn; The performance bottleneck map is compared with the longest fault tolerance recovery threshold defined in the system safety design baseline, and the verification and evaluation results are summarized and output.