First-order theory using Boolean algebra provides secure AI systems and new software specification logic

CN122826544APending Publication Date: 2026-09-25ADNI AG
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202580017165.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2024-11-27
Filing Date
2025-01-17
Publication Date
2026-09-25

Smart Images

  • Figure CN122826544A_ABST
    Figure CN122826544A_ABST
Patent Text Reader

Abstract

A method of validating a command for a software platform. The platform receives a user input specifying a command for causing the software platform to perform an action. The command is expressed in an extended formal language comprising elements in Boolean algebra. The platform retrieves a validation rule for the software platform. The validation rule is expressed in the extended formal language. The platform combines the command and the validation rule, thereby constructing a formula in the extended formal language comprising one or more logical quantifiers. The platform expresses the formula as a disjunctive normal form with an existential quantifier as an innermost quantifier and constructs a new formula in the extended formal language that is logically equivalent to the formula and that has no quantifiers. The platform evaluates the new formula for truth and, when the new formula is true, executes the command to perform the action. Otherwise, the platform rejects the command.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Related applications This application is a continuation-to-file of U.S. Patent Application Serial No. 18 / 776,245, filed July 17, 2024, entitled “Using First-Order Theories of Boolean Algebras to Provide Safe AI Systems and a Novel Software Specification Logic,” which is a partial continuation-to-file of European Application No. 24152499.0, filed January 17, 2024, entitled “Validation of Computer Software Updates.” Each of these applications is incorporated herein by reference in its entirety.

[0002] This application claims priority to U.S. Provisional Application No. 63 / 564,501 entitled “Applications of Boolean Algebras”, filed March 12, 2024, which is incorporated herein by reference in its entirety.

[0003] This application claims priority to U.S. Provisional Application No. 63 / 666,656, filed July 1, 2024, entitled “Utilizing a Novel Temporal Logic with Guarded Successor,” which is incorporated herein by reference in its entirety.

[0004] This application claims priority to U.S. Provisional Application No. 63 / 667,692, filed July 3, 2024, entitled “Utilizing a Novel Temporal Logic with Guarded Successor,” which is incorporated herein by reference in its entirety.

[0005] This application claims priority to U.S. Provisional Application No. 63 / 726,231, filed November 27, 2024, entitled “Using First-Order Theories of Boolean Algebras to Provide Safe AI Systems and a Novel Software Specification Logic,” which is incorporated herein by reference in its entirety. Technical Field

[0006] This invention relates to formal languages, and more particularly to the use of Boolean algebra in the context of formal languages.

[0007] background Designing formal or logical languages ​​capable of referring to the truth of their own statements has historically been problematic in the field of logic. Generally, it is impossible to include statements about truth in a formal language, as well as statements about statements in the same language, while maintaining linguistic consistency. This is because including such truth references allows for paradoxical expressions in language. Perhaps the most well-known consequence of this property is Tarski's so-called truth-value undefinability theorem (Tarski's undefinability theorem - Wikipedia).

[0008] This inability to refer to truth within the same formal language is a practical limitation in computation. Specifically, a formal language cannot refer to whether another statement in that language is true, or whether one statement entails another, or other similar logical problems that boil down to discussing truth. Known methods for solving this problem include so-called paraconsistent and multivalued logic; however, all known methods have the property of allowing languages ​​to contain paradoxes. In this way, languages ​​are presented as so-called non-classical logic. Therefore, in these languages, it is no longer the case that every exact statement is either true or false in a classical sense (in a given model, if such a setting even has model theory).

[0009] In computation, the aforementioned problems are problematic for performing automatic updates on computer software systems installed on computing devices, and more generally, for systems implemented in a certain language that can process statements in the same language (where performing software updates is an example of this). In one example, an automatic update function might download a software update, check if the software update satisfies one or more conditions, and then install the software update only if one or more conditions are met. Because the condition checks have the form of logical implication (i.e., "Does the update imply the satisfaction of certain conditions?"), there is currently no formal language that can support such an automatic update function when expressing the current software and the software update in the same formal language, because such a language would contain contradictions. Also, from the perspective of computational implementation, having two languages ​​is not helpful: either the update conditions themselves cannot be updated, or an infinite number of different languages ​​would be needed, one for each update, which introduces even more difficulties.

[0010] Similarly, in computation, the aforementioned problems related to paradoxes in formal languages ​​relate to the computational implementation of Knowledge Representation and Reasoning Systems (KRR), or simply knowledge systems. KRR is a subfield of artificial intelligence that focuses on how knowledge is represented and manipulated to allow computers to reason, infer, and make decisions based on that knowledge. KRR has applications across various fields, including expert systems, decision support systems, robotics, and semantic webs. Common formal systems and languages ​​used in KRR include first-order logic, descriptive logic, semantic networks, and rule-based systems. Once knowledge is represented, KRR systems use various inference mechanisms to derive new information or conclusions from existing knowledge. These mechanisms include deductive reasoning (using logical rules), inductive reasoning (generalizing from specific examples), and probabilistic reasoning (considering uncertainty and probability). An inference engine is the software component responsible for implementing these inference mechanisms, taking formal knowledge representations (i.e., statements in some formal or logical language) as input. Specifically, these inference engines are expected to determine whether statements that can be expressed in any given knowledge representation language are contradictory. Many logical reasoning tasks can be simplified to contradiction detection. For example, to determine whether statement X implies statement Y, we ask whether the statement "X and not Y" is contradictory. If Y contains free variables, finding all assignments that make the implication true is equivalent to answering the query. The KRR language described above deals with objects and the relationships between them. It also deals with the practical necessity of objects as statements within the language itself. For example, in "X said Y," Y is also a statement. However, known KRR languages ​​(or logic in general) cannot consistently handle statements within their own language, their combination with other statements, and other logical problems such as whether they contain contradictions or imply each other.

[0011] This invention was proposed in this context.

[0012] Overview In one aspect of the invention, a computer-implemented method for verifying software updates is provided. This method is performed by a software system or software platform implemented or installed on a computing device having one or more processors and a memory device storing instructions that, when executed by the one or more processors, cause the one or more processors to perform the method described herein.

[0013] The method, executed by the software system, includes receiving candidate software updates for the software system. Both the software system and the candidate software updates are expressed in an extended formal language, which is an extension of one or more basic formal languages. Statements in each basic formal language form elements in a Boolean algebra, up to logical equivalence, having falsity elements (0) representing falsity values ​​and truth elements (1) representing truth values. The extended formal language comprises a many-sorted first-order theory of Boolean algebras interpreted in the Boolean algebras generated by each basic formal language, which is extended to include multiple constant symbols, each corresponding to a corresponding logical equivalence class of statements in each basic formal language. The extended formal language and each basic formal language are considered Boolean algebras under logical equivalence and are elementaryly equivalent under the signature of the Boolean algebra. The candidate software update corresponds to the update statement u in the extended formal language.

[0014] For a condition element c in the extended formal language that specifies the conditions for verifying a candidate software update, the method performed by the software system includes calculating the truth value of uc'=0 in the extended formal language. Here, uc' is the logical conjunction of the logical negation of u and c. This condition can be considered as being implied by the software system as a whole. In particular, the condition element c can be explicitly stated in the extended formal language, or it can be implied by the extended formal language describing the software system. This condition can be any suitable condition, for example, if the new code in the candidate software update implies sending private data over a (public) network, then the update should be rejected. However, note that the specific content / requirement of the condition is irrelevant to the inventive concept disclosed herein.

[0015] Based on the determination that uc'=0 is false, the method includes rejecting the candidate software update. Based on the determination that uc'=0 is true, the method includes accepting the candidate software update and installing the candidate software update on the computing device. In other words, the candidate software update is the updated software of the software system; that is, the software system determines whether to update itself using the candidate software update.

[0016] This aspect of the invention is advantageous because the software system can autonomously accept or reject updates based on certain conditions, including updating those conditions themselves. Existing formal languages ​​do not allow such updates. These advantages are achieved by the fact that the software system and software updates (and further subsequent updates) are expressed in the same formal language, and even if the formal language refers to its own statements and their logical relationships (which might be doubted due to Tarski's results above), the formal language is classical, consistent, and decidable. Specifically, this is achievable in the disclosed method by the fact that statements in the underlying logic (the underlying formal language) are abstracted to be considered only as Boolean algebra elements (or slightly beyond that). Here and throughout, the extended formal language defined benefits from consistency and decidability.

[0017] As defined above, the disclosed method extends to consider multiple underlying formal languages.

[0018] As is known in the art, in logic and computer science, formal languages ​​are languages ​​with mathematically precise rules of construction, such as programming languages. Logic can be considered a formal language because it provides a framework for expressing and reasoning about propositions and their relationships. In (mathematical) logic, a statement (or closed formula) is a well-structured formula of predicate logic without free variables. In this paper, a statement is considered as expressing the set of models it holds. It is important to note that we are considering the full generality of Boolean algebra, not just the algebra of binary values.

[0019] "Logical equivalence" is a well-defined term in this context. As those skilled in the art will understand, two statements are logically equivalent if they have the same truth value in every model. In model theory, a structure consists of sets and collections of functions and relations defined on them. A "logical equivalence class" will similarly be well understood by those skilled in the art (see, for example, "equivalence class" on Wikipedia).

[0020] From the above context, it will become clear that the elements of the Boolean algebra in this article are logical statements in a logically equivalent sense. This is often referred to as the Lindenbaum-Tarski algebra.

[0021] Those skilled in the art will readily understand references to first-order theories of Boolean algebra and elementary equivalent Boolean algebras (see, for example, "List of first-order theories" on Wikipedia). They will also understand references to multi-sorted logic (see, for example, "Many-sorted logic" on Wikipedia). Furthermore, those skilled in the art will similarly readily understand references to the signatures of Boolean algebras (see, for example, "Signature (logic)" on Wikipedia).

[0022] Boolean algebras of each basic formal language can be non-atomic.

[0023] The Boolean algebra of extended form languages ​​and each of the basic form languages ​​can be isomorphic or at least elementaryly equivalent.

[0024] The conditions specified by the condition element c can be a combination of different individual conditions, each of which needs to be met for the candidate software update to be validated and accepted.

[0025] Candidate software updates may include updates to condition element c.

[0026] If a candidate software update is accepted, the step of installing the candidate software update on a computing device may include replacing condition element c with an updated condition element d in the extended formal language, which specifies the updated conditions used to validate subsequent candidate software updates. (Replacing condition c with condition d is part of the candidate software update process.) The updated condition element d may be explicitly stated in the extended formal language, or it may be implied by the extended formal language describing the updated software system.

[0027] This method may include receiving subsequent candidate software updates for a software system, wherein the subsequent candidate software updates are expressed in an extended formal language. Here, the software system may have already been updated with the candidate software updates. In this way, the software system can be considered as the updated software system. The method may include computing the truth value of ud'=0 in the extended formal language, where ud' is the logical conjunction of the logical negation of u and d. Based on the determination that ud'=0 is false, the method may include rejecting the subsequent candidate software updates. Based on the determination that ud'=0 is true, the method may include accepting the subsequent candidate software updates, and may include installing the subsequent candidate software updates on a computing device.

[0028] In some examples, if uc'=0 is false, the method may include identifying a modified software update, i.e., a modification of a candidate software update. A modified software update may correspond to a logically maximum statement v, which logically implies an update statement u, and satisfies vc'=0, where vc' is the logical conjunction of the logical negation of v and c. In such examples, the method may include accepting the modified software update and installing the modified software update on the computing device. In some examples, a modified software update may be accepted only if there exists a unique logically maximum statement that logically implies an update statement u.

[0029] In some examples, prior to the step of calculating the truth value of uc′=0 in the extended formal language, the method may include modifying the candidate software update to obtain another candidate software update corresponding to another update statement w in the extended formal language. The other update statement w may be obtained based on a formula in the extended formal language that associates update statement u with the other update statement w. For example, modifications defined by the software system may be applied to the received candidate software update (e.g., to preserve user preferences or settings as part of the update). Based on the determination that wc′=0 is false, the method may include rejecting the other candidate software update. Based on the determination that wc′=0 is true, the method may include accepting the other candidate software update and installing the other candidate software update on the computing device. In this example where the received candidate software update is modified before evaluation, the steps involving the evaluation of the received candidate software update (e.g., uc′=0) may be suppressed or may not be performed.

[0030] In another aspect of the invention, a computer software system for verifying software updates to a software system is provided. The software system is implemented or installed on a computing device having one or more processors and memory storing one or more programs configured for execution by the one or more processors. The software system is configured to receive candidate software updates for the software system. Both the software system and the candidate software updates are expressed in an extended formal language, which is an extension of one or more basic formal languages. Statements in each basic formal language form elements in a Boolean algebra in a logically equivalent sense, having a false element 0 representing a false value and a true element 1 representing a true value. The extended formal language includes a multi-class first-order theory of Boolean algebras interpreted in the Boolean algebras generated by each basic formal language, which is extended to include a plurality of constant symbols, each constant symbol corresponding to a corresponding logical equivalence class of statements in each basic formal language. The extended formal language and each basic formal language are considered Boolean algebras in a logically equivalent sense and are elementaryly equivalent under the Boolean algebra signature. The candidate software update corresponds to the update statement u in the extended formal language.

[0031] For a condition element c in the Extended Form Language (EPL) that specifies the conditions for verifying candidate software updates, the software system is configured to compute the truth value of uc'=0 in EPL. Here, uc' is the logical conjunction of the logical negation of u and c.

[0032] Based on the determination that uc'=0 is false, the software system is configured to reject candidate software updates. Based on the determination that uc'=0 is true, the software system is configured to accept candidate software updates and is configured to install the candidate software updates on the computing device to update the software system.

[0033] The condition used for the update can be more general than uc'=0. In particular, the condition can be any formula in the extended language that associates u and c.

[0034] In some instances where the condition used for updating is more general than uc'=0, the condition is represented as a disjunction (or any other logical equivalent) of systems of conditions, each of which has the following form: uc[1]=0,…,uc[n]=0 u'd[1]=0,…,u'd[k]=0 up[1] != 0, ..., up[i] != 0 u'q[1] != 0, ..., u'q[j] != 0 Or equivalent terms, whether c, d, p, and q are single elements or the entire formula, and whether the entire condition can include or exclude quantifiers.

[0035] An example of a practical knowledge system, or a system of knowledge representation and reasoning, is a software system that is a function of inputs to outputs at every point in time. In such an example, there exists an infinite number of inputs and outputs. The database of all “runs” would be an infinite sequence of inputs and corresponding infinite sequences of outputs. Such an “infinite” database cannot be computationally (holistically) implemented using previous representations of inputs, outputs, functions, etc. Therefore, it is impossible to analyze and reason about the entire knowledge system. This invention provides a method that allows the implementation of a knowledge system on a computer, enabling the determination of whether any particular “run” (e.g., a combination of inputs and outputs) among all possible runs causes a problem. For example, in the example of a knowledge system describing a nuclear reactor, is there a run that leads to a serious safety vulnerability in the nuclear reactor?

[0036] According to another aspect of the invention, a method is provided for extending a knowledge system to allow or support the storage and reasoning of statements in the same language supported by the knowledge system. The method is executed on a computing device having one or more processors and a memory storing the knowledge system, wherein the knowledge in the knowledge system is encoded as statements in a basic formal language. The method includes storing a plurality of interrelated facts in the knowledge system, these facts being encoded as knowledge statements in the basic formal language, and extending the knowledge statements to be expressed in an extended formal language, which is an extension of the basic formal language, wherein the statements in the basic formal language form elements in a Boolean algebra in a logically equivalent sense, the Boolean algebra having a false element 0 representing a false value and a true element 1 representing a true value, wherein the extended formal language includes a first-order theory of Boolean algebras interpreted in the Boolean algebras generated by the basic formal language, the basic formal language being extended to include a plurality of constant symbols, each constant symbol corresponding to a corresponding logical equivalence class of statements in the extended formal language, wherein the extended formal language and the basic formal language are considered Boolean algebras under logical equivalence and are elementaryly equivalent under the signature of the Boolean algebras. The method includes performing one or more queries on a knowledge system using an extended formal language. In some embodiments, the queries are performed using one or more Boolean algebraic methods as described herein. In some embodiments, the method includes determining logical problems (e.g., consistency and implication) related to the knowledge system to output the extended formal language.

[0037] According to another aspect of the invention, a method for verifying contractual provisions is provided for execution on a computing device having one or more processors and a memory storing one or more programs configured for execution by one or more processors.

[0038] The method includes receiving a contract, which is designated as multiple terms represented by corresponding clause statements. The clause statements are expressed in an extended formal language, which is an extension of one or more basic formal languages. The statements in each basic formal language form elements in a Boolean algebra in the sense of logical equivalence, having a false element 0 representing a false value and a true element 1 representing a true value. The extended formal language includes a multi-class first-order theory of Boolean algebras interpreted in the Boolean algebras generated by each basic formal language, which is extended to include multiple constant symbols, each corresponding to a corresponding logical equivalence class of statements in each basic formal language. The extended formal language and each basic formal language are considered Boolean algebras under logical equivalence and are elementaryly equivalent under the Boolean algebra signature.

[0039] For each combination of two or more elements in the extended formal language, where each combination includes an element representing a corresponding clause statement representing a corresponding clause among multiple clauses in a contract, the method includes evaluating whether the expression corresponding to the logical conjunction of each element in the combination is equal to 0. For example, if the combination includes two elements, namely a first element x and a second element y, where the first element x represents a corresponding first clause statement representing a first clause among multiple clauses in the contract, and the second element y represents a corresponding second clause statement representing a second clause among multiple clauses in the contract, then the expression would be xy=0, where xy is the logical conjunction of the logical conjugate of x and y. Similarly, if the combination includes three elements, namely a first element x, a second element y, and a third element z, where the third element z represents a corresponding third clause statement representing a third clause among multiple clauses in the contract, then the expression would be xyz=0.

[0040] Based on determining that there exists a combination of elements satisfying an expression, the method includes determining that the contract has inconsistent provisions. Based on determining that there is no combination of elements satisfying an expression, the method includes determining that the contract has consistent provisions.

[0041] According to another aspect of the invention, a method is provided for verifying commands for an interactive software platform, executed at a computing device having one or more processors and a memory storing one or more programs configured for execution by the processors. This is useful, for example, for providing “secure AI”, as the commands are verified against a set of conditions before execution. The method includes receiving user input at the software platform specifying commands for causing the software platform to perform actions. The method includes retrieving a plurality of defined verification rules for the software platform, wherein each of the plurality of verification rules is represented by a corresponding verification statement. The verification statements are expressed in an extended formal language, which is an extension of a basic formal language. Statements in the basic formal language form elements in a Boolean algebra in the sense of logical equivalence, having a false element 0 representing a false value and a true element 1 representing a true value. The extended formal language includes a first-order theory of Boolean algebras interpreted in Boolean algebras generated by the basic formal language, which is extended to include a plurality of constant symbols, each constant symbol corresponding to a corresponding logical equivalence class of statements in the basic formal language. Extended Form Language (EPL) and Basic Form Language (BSL) are considered Boolean algebras under logical equivalence and are elementaryly equivalent under the Boolean algebra signature. The method includes combining commands and a set of defined verification rules for a software platform to construct a formula f in EPL, where the formula has one or more logical quantifiers. The method includes expressing formula f as a disjunctive normal form, where its innermost quantifier is an existential quantifier. The method includes constructing a new formula g in EPL, where the new formula g (i) is logically equivalent to formula f and (ii) has no quantifiers. The method includes evaluating the truth value of the new formula g. Based on determining that the new formula g is true, the method includes executing the command. Based on determining that the new formula g is false, the method includes rejecting the command.

[0042] The command may include one or more additional validation rules for the software platform. These additional validation rules may update one or more of the defined validation rules.

[0043] If the command is executed, the defined validation rules can be updated based on additional validation rules to provide updated validation rules for the interactive software platform using an extended formal language.

[0044] In some cases, the method includes receiving subsequent user input at the software platform, which specifies a subsequent command to cause the software platform to perform a subsequent action. In some embodiments, the method includes translating the subsequent command into a formula k in a base formal language, wherein the formula (i) includes one or more logical quantifiers and (ii) is expressed in disjunctive normal form. In some embodiments, the method includes constructing a new formula in an extended formal language. The new formula (i) Logically equivalent to formula k and (ii) without quantifiers. In some embodiments, the method includes evaluating the new formula. Does it conform to the multiple updated verification rules used for the software platform? Based on the determined new formula... Consistent with several updated verification rules used for the software platform, this method can execute subsequent commands. Based on the determined new formula... If there are inconsistencies with multiple verification rules used for the software platform, the method may include rejecting subsequent commands.

[0045] According to another aspect of the invention, a non-transitory computer-readable storage medium storing instructions is provided. When executed by one or more processors, the instructions cause one or more processors to perform any one or more of the methods described above.

[0046] According to another aspect of the present invention, a software system implemented or installed on a computing device is provided, the software system being configured to perform the steps of any one or more of the methods described above.

[0047] In a general sense, this invention relates to methods in the field of formal languages, and in particular, it provides methods for solving certain problems expressed in Boolean algebra languages ​​(and some of their extensions). The invention provides a method for extending formal languages, enabling them to refer to their own statements (including those in the extended languages), determine the truth values ​​of their Boolean combinations, and quantize the statements. Brief description of the attached diagram Examples of the invention will now be described with reference to the accompanying drawings, in which: Figure 1 The use of the disclosed techniques to verify commands for a software platform is illustrated according to some embodiments.

[0049] Figure 2 This is a block diagram of a computing device according to some embodiments.

[0050] Figure 3 BNF (Backsnow Normal Form) productions for the basic syntax of the NSO language, according to some embodiments, are provided.

[0051] Figure 4 The use of the disclosed techniques to verify software updates to a software system is illustrated according to some embodiments. Description of the implementation method

[0052] Figure 1The use of the disclosed techniques to verify commands against software platform 100 according to some embodiments is illustrated. Platform 100 receives (102) user input specifying a command for performing an action. In some instances, the command instructs platform 100 to perform tangible and / or visible commands, such as displaying something on a screen, sending a message to a recipient, performing a calculation, or initiating a workflow. In other cases, the command instructs platform 100 to update itself, such as adding or modifying verification rule 242.

[0053] Platform 100 combines commands and a set of validation rules for the software platform (104) to construct formula f using the software platform's language NSO. Formula f includes (104) one or more logical quantifiers ( or ).

[0054] Platform 100 then expresses formula f (106) in disjunctive normal form (DNF), with its innermost quantifier being an existential quantifier. In some embodiments, this is achieved by converting the formula to prenex normal form (PNF, consisting of a prefix and a matrix) or a negative PNF such that the innermost quantifier is an existential quantifier, and then converting the matrix to DNF. In some embodiments, this process identifies the innermost quantifier. If the innermost quantifier is a universal quantifier, it is converted to an existential quantifier by simple negation. Finally, everything under the existential quantifier is converted to DNF.

[0055] Then, the system performs the (108) quantifier elimination process to construct the logically equivalent formula g that eliminates the innermost quantifier. This is described in Sections 5 and 6 below. For example, the technique in Section 5 can be applied when the language NSO is a non-atomic Boolean algebra. This process eliminates the innermost quantifier. The process checks (110) for the presence of an additional quantifier. If so, the process repeats steps 106 and 108 to eliminate the next quantifier (after eliminating the identifier, the resulting formula is usually no longer in disjunctive normal form).

[0056] When all quantifiers are eliminated, evaluating the truth of formula g (114) is a simple matter. If formula g (116) evaluates to true, the software platform executes the requested command (118). If formula g (116) does not evaluate to true, the software platform rejects the requested command (120).

[0057] Typically, validation rules are security-oriented. For example, a platform might refuse to execute actions that would harm others. As mentioned above, executing commands can imply updating compatibility rules themselves.

[0058] Figure 2This is a block diagram illustrating a computing device 200 capable of running software platform 100 to verify and execute commands. In some embodiments, the computing device displays a graphical user interface 224 for software platform 100. Computing device 200 includes desktop computers, laptop computers, tablet computers, and other computing devices having a processor and display capable of running software platform 100. Computing device 200 typically includes one or more processing units / cores (CPUs) 202 for executing modules, programs, and / or instructions stored in memory 214 and thereby performing processing operations; one or more network or other communication interfaces 204; memory 214; and one or more communication buses 212 for interconnecting these components. Communication bus 212 may include circuitry for interconnecting and controlling communication between system components. Computing device 200 includes a user interface 206, which includes a display 208 and one or more input devices or mechanisms 210. In some embodiments, the input device / mechanism includes a keyboard. In some embodiments, the input device / mechanism includes a "soft" keyboard, which is displayed on the display 208 as needed, allowing the user to "press" "keys" appearing on the display 208. In some embodiments, the display 208 and the input device / mechanism 210 include a touchscreen display (also referred to as a touch-sensitive display). In some embodiments, the display is an integrated part of the computing device 200. In some embodiments, the display is a stand-alone display device.

[0059] In some embodiments, memory 214 includes high-speed random access memory, such as DRAM, SRAM, DDR RAM, or other random access solid-state memory devices. In some embodiments, memory 214 includes non-volatile memory, such as one or more disk storage devices, optical disk storage devices, flash memory devices, or other non-volatile solid-state memory devices. In some embodiments, memory 214 includes one or more storage devices located remotely from CPU 202. Memory 214, or alternatively, non-volatile memory devices within memory 214, include non-transitory computer-readable storage media. In some embodiments, memory 214 or the computer-readable storage media of memory 214 stores the following programs, modules, and data structures, or subsets thereof: Operating system 216, which includes processes for handling various basic system services and for performing hardware-related tasks; The communication module 218 is used to connect the computing device 200 to other computers and devices via one or more communication network interfaces 204 (wired or wireless) and one or more communication networks (such as the Internet, other wide area networks, local area networks, metropolitan area networks, etc.). Web browser 220 (or other client applications) enables users to communicate with remote computers or devices over a network; Software platform 100 may have a graphical user interface 224 for verifying and executing commands. In some embodiments, the software platform includes: - Command translator 226, which translates user commands into an internal formal language; - Quantifier elimination procedure 228, which implements the techniques described in Section 5 and / or Section 6 below; - Verification procedure 230, which verifies the command according to a set of verification rules 242; and - A software updater that updates the software platform when specified updates match pre-existing rules; and One or more databases 240 that store data, such as a set of current validation rules 242.

[0060] Each of the executable modules, applications, or processes identified above can be stored in one or more of the aforementioned memory devices and corresponds to an instruction set for performing the functions described above. The modules or programs identified above (i.e., instruction sets) do not need to be implemented as separate software programs, processes, or modules, and therefore, in various embodiments, various subsets of these modules can be combined or otherwise rearranged. In some embodiments, memory 214 stores a subset of the modules and data structures identified above. In some embodiments, memory 214 stores additional modules or data structures not described above.

[0061] although Figure 2 The computing device 200 is shown, but Figure 2 More often than being intended as a functional description of the various features that may exist, rather than as a structural schematic diagram of the embodiments described herein. In practice, and as those skilled in the art will recognize, items shown individually may be combined and some items may be separated.

[0062] Figure 4 The method of verifying software updates to a software system using the disclosed techniques according to some embodiments is illustrated. The method is performed on a software system 100 running on a computing device 200. The software system 100 receives (402) a candidate update, calculates (404) a truth value including a specific formula of the update, and rejects (406) or accepts (408) the update based on the calculated truth value.

[0063] According to some embodiments, a method for verifying software updates is provided as part of the automatic update feature of software system 100. This method is performed by software system 100 installed on computing device 200. Figure 4The steps of the method are summarized. The first step 402 of the method involves receiving or downloading a “candidate” software update for software system 100. Here, both software system 100 and the candidate software update are expressed in an extended formal language (e.g., NSO), which is an extension of one or more basic formal languages. Each basic formal language is any suitable formal language. The extended formal language is obtained or defined as described herein. In particular, the basic formal language is extended to include multiple constant symbols, each constant symbol corresponding to a corresponding logical equivalence class of statements in the basic formal language. Here, the extended formal language and each basic formal language are regarded as Boolean algebras under logical equivalence, and are elementaryly equivalent under the Boolean algebra signature.

[0064] In this example, the candidate software update corresponds to the update statement u in the extended formal language. At the next step 404 of the method, the software system 100 computes the truth value (e.g., 0 or 1) of uc'=0 in the extended formal language. That is, the expression uc'=0 is evaluated. Here, in the extended formal language, the condition element c specifies the condition used to verify the candidate software update, and uc' is the logical conjunction of the logical negation of u and c.

[0065] In the next step 406 of the method, if it is determined that uc'=0 is false, the candidate software update is rejected. On the other hand, if it is determined that uc'=0 is true, the method involves accepting the candidate software update at step 408 and installing the candidate software update on computing device 200 (e.g., to update software system 100).

[0066] This method benefits from supporting or allowing candidate software updates that include updates to condition element c, which must be met for an update to be accepted. In practice, if an update is deemed acceptable and is therefore installed, the condition element is updated such that subsequent candidate software updates are evaluated against the updated condition to determine whether they are acceptable for installation.

[0067] In some embodiments where a candidate software update is rejected, the method includes determining whether a modified version of the candidate software update can be accepted (and installed). For example, the candidate software update may include parts (i), (ii), and (iii), and it can be determined that part (iii) contradicts the conditions that the candidate software update must satisfy to be acceptable. However, parts (i) and (ii) may not contradict the conditions. In this case, the software system may modify the candidate software update to include only parts (i) and (ii), and instead install the modified version of the software update. In extended formal languages, the modified software update may correspond to a logical maximal statement v, which is logically implied by the original update statement u and satisfies vc'=0. The statement vc' is the logical conjunction of v with the logical negation of condition c. It should be noted here that those skilled in the art will understand that logical implication and logical maximal are explicitly defined in mathematical logic.

[0068] This method benefits from allowing software system 100 to modify or adjust the received candidate software update before evaluating it according to conditions to be met. That is, the method may include modifying the received candidate software update to obtain another candidate software update corresponding to another update statement w in an extended formal language. Here, the other update statement w is obtained based on a suitable formula in the extended formal language that associates update statement u with the other update statement w. The modification can be of any suitable form and can be used for any suitable purpose. The modification may be to narrow or expand the scope of the software update in a particular way, such as attempting to ensure that the (modified) update meets conditions to allow its installation.

[0069] The methods disclosed herein can be applied to a variety of problems. In some embodiments, the method can be implemented computationally to determine whether a contract contains inconsistent terms. The disclosed methods are also applicable to software specifications. In large software development projects, it is crucial to first write down detailed descriptions or documentation of the expected functional and non-functional requirements, constraints, and behaviors of the software system. These specifications serve as a blueprint or contract between stakeholders such as software developers, designers, project managers, and clients to ensure everyone clearly understands what the software should do and how it should behave. The software development team then adopts these software specifications (also called “specifications”) and translates them into step-by-step instructions that a computer can execute. This is a typical software development process. This final step can be performed by first expressing all specifications in an NSO language specification. The interpreter is then able to directly “execute” the specifications. The resulting specification is the program to be executed.

[0070] The disclosed methods also apply to computer security. A common challenge in computer security is evolving a computer system while maintaining its security and integrity. This is difficult to achieve in computer systems defined using procedural languages ​​because one must consider the possibility of executing all procedures in any order and on a wide range of inputs. This is practically an impossible task. Conversely, software systems built on the aforementioned specifications are guaranteed to maintain their security after each change or addition of new functionality because all system specifications and constraints are automatically maintained by the runtime of the disclosed system.

[0071] The disclosed methods are also applicable to computer-aided design (CAD) systems. CAD systems are a special case of KRR systems, specifically designed for representation and reasoning in mechanical or electrical engineering design. In this context, the system typically has constraints on the desired output (system performance) while adhering to general engineering constraints such as maximum stress level, maximum temperature, current, etc. As mentioned above, all these requirements and constraints can be captured and maintained as an extended formal language specification.

[0072] As stated above, previously known knowledge representation and reasoning (KRR) system languages ​​(or logic in general) are unable to consistently handle statements in their own language, combine them with other statements, and determine whether they contain contradictions, imply each other, and other logical problems. The NSO language described in this paper is the first language capable of doing so, and not only in a consistent manner but also in a decidable manner.

[0073] The expression "X says Y" can be stated in a language L1, while the expression "Y" can be expressed in a different language L2. In this case, L2 is less expressive than L1. In fact, L2 is much less expressive because L1 can interpret L2. Next, consider the statement "X says 'Y says Z'?". This would require three languages. This pattern leads to impractical results, even to some extent impossible. In the NSO solution described in this paper, languages ​​are provided such that L1 = L2, and this is achieved by abstracting statements only as elements of Boolean algebra (and possibly slightly beyond that).

[0074] To perform logical tasks in the novel language NSO, this paper also describes novel methods in the field of Boolean algebra. Furthermore, NSO is not a language, but a language extension mechanism. This method creates an infinite number of languages ​​that satisfy this unique and novel property. Moreover, NSO can extend multiple languages ​​simultaneously within the same language. Therefore, NSO also provides a novel way to compose logic without violating the properties of consistency and decidability.

[0075] 1 - Background Automated theorem proving and equation solving have wide applications in engineering, such as formal methods (e.g., formal verification), knowledge representation and reasoning (KRR), artificial intelligence (AI), and more. It is useful to find algorithms that allow solving for solutions and / or truth values ​​of statements in various formal languages ​​and / or to determine the existence of such solutions and / or truth values. This application uses Boolean algebra languages ​​under some generalized definitions of such languages ​​and proposes various methods to solve problems that can be expressed using Boolean algebra. These techniques can be applied to all the aforementioned industries as well as many others.

[0076] The decidability of Boolean algebras according to the standard theory was proposed long ago by Tarski. The method here utilizes extensions of the standard theory, including: 1) Constants are allowed to be any element, and are not limited to the values ​​0 and 1; 2) Quantization of Boolean functions, simple Boolean functions, and their higher-order counterparts; 3) Cartesian product; 4) Homomorphisms; 5) Recursive relation; and 6) The converse of a binary relation.

[0077] The technologies used here also include: 1) Find the explicit zeros of the Boolean function; 2) Optimization of Boolean functions induced by Boolean algebra for cardinality and order; and 3) Elimination of classifiers.

[0078] 2 - Terms, Symbols and Basic Definitions A Boolean ring is a ring with unity where x ∈ X and x ∈ X is equal to x. A Boolean function (BF) is a polynomial over a Boolean ring. A Boolean function is called a simple Boolean function (SBF) if its coefficients are only 0 or 1. Boolean algebra is a Boolean ring where the operations are ∧, ∨, and '. These operations are interpreted in the language of the ring as... x ∧ y ≡ xy , x ∨ y ≡ x + y + xy as well as x' ≡ 1+ x .same, x + y = xy' ∨ x'y Note that the symbol "+" represents a symmetric difference, which corresponds to the XOR (Exclusive OR) expression.

[0079] The symbols ∧ and ∨ are also used as logical connectors. Their use as operators or logical connectors will be clear from the context. For example, in... x ∨ y = 0 ∨ y In ≠ 0, the first “∨” is a function symbol in Boolean algebra theory, and the second “∨” is a logical connector.

[0080] The Boolean derivative of a Boolean function is derived from... definition.

[0081] Depend on X A The minterm among the n variables is the product. ,in A ∈ {0, 1} n It is a tuple A = a 1 , . . . , a n , and when a i When = 1, , and when a i When = 0, As is well known, any Boolean function can be written as a sum of minterms multiplied by their corresponding constant coefficients (equivalently, disjunctive). As used in this paper, this is called "minterm normal form," although some authors refer to it as "canonical DNF." As should be clear from the context, the term "minterm" can refer to a minterm coupled with constant coefficients.

[0082] The [first-order] theory of Boolean algebra is always considered to be interpreted within a particular Boolean algebra, and the language extends with constant symbols for all Boolean algebra elements. The interpretation matches each constant symbol with its corresponding Boolean algebra element. This differs from other mainstream authors on the subject. Typically, authors consider the first-order theory of Boolean algebra (whether general or specific or of some class thereof), where the only constant symbols are 0 and 1. This application deals with quantification systems of equations and inequalities. While in the formal systems of other authors, atomic formulas take the form "a simple Boolean function equals zero," this application deals with a more general construction that determines when "a Boolean function" "equals zero."

[0083] Furthermore, this application considers a multi-class theory of Boolean algebras. That is, by fixing some Boolean algebras, a first-order theory is obtained, in which each variable has a type representing the Boolean algebra from which it should come (which can also be easily understood without explicit typing and with the formula interpreted as appropriate). This theory is interpreted using the product of structures. The variables and constants in a single atomic formula may involve only one Boolean algebra, but combinations of atomic formulas from various Boolean algebras are possible.

[0084] By convention, a partial order in Boolean algebra can be defined as x ≤ y if and only if xy = x. For all x in a Boolean algebra, if 0 ≤ x ≤ a means x = 0 or x = a, then element a is defined as an atom. If a Boolean algebra has no atoms, then it is atomless.

[0085] As an example of the above, consider a non-atomic Boolean algebra, such as a finite union of left-closed, right-open intervals over rational numbers. The Boolean functions in this algebra have coefficients written in some explicit form, such as [a, b), where a and b are rational numbers. An example of a first-order formula (in the generalized manner disclosed) is... .

[0086] It is sometimes useful to call the elements of a Boolean algebra a set (e.g., when discussing their cardinality). This representation is guaranteed by the Stone representation theorem for Boolean algebras. In fact, an equivalent way to define a Boolean algebra is to define it as a set of sets closed under finite unions, finite intersections, and complements. Therefore, every power set is a Boolean algebra, but there exist Boolean algebras that are not power sets. Such a latter Boolean algebra must be infinite.

[0087] Just as Boolean functions described above can have minterm normal forms, formulas can also have similar forms. Any atomic formula has the form f(X) = 0, therefore writing f as a disjunction of minterms allows us to consider only the form X A = 0 is the atomic formula because x ∨ y = 0 is the same as x = 0 ∧ y = 0.

[0088] 3 - Methods for finding the zeros of a formula Consider Boolean functions in Boolean normal form (sometimes called Shannon decomposition). This can be written as or equivalent Let X be a tuple of n variables. Assuming it has zeros, the Boolean consistency condition holds: .

[0089] The specific zero point is identified inductively as follows. Let Z be... g ( Z )h ( Z The zero of ) (which is guaranteed to exist by the Boolean consistency condition). Then, f (h( Z ), Z ) = 0 and f ( g '( Z ), Z ) = 0. Therefore, a zero can be found inductively by arbitrarily choosing one of these two (or by choosing the shortest case or any other optimization). Finding a single zero makes it possible to characterize all zeros by Lowenheim's General Reproductive Solution.

[0090] 4 - Optimization Methods Confirm | f ( x Whether n has a solution for some Boolean function f and finding its minimum and maximum cardinality (which happens to coincide with the minimum and maximum values ​​induced by Boolean algebra) can be done as follows.

[0091] If and only if | f (0) f (1)| ≤ n ≤ | f (0) ∨ f (1) When | , the equation | f ( x )| = n It has a solution. More generally, let f ( x Let be a Boolean function. Then when f (0) f’ (1) ≤ x ≤ f (0) ∨ f ' ’ When (1), it reaches the minimum value of |f(x)| (and its minimum value relative to the order induced by Boolean algebra, which always exists), and when f ' ’ (0) f (1) ≤ x ≤ f ' ’ (0) ∨ f (1) The maximum value is reached exactly.

[0092] 5 - Quantifier Elimination Methods in Atomless Boolean Algebras Given a formula in a non-atomic Boolean algebraic language, first select the innermost quantifier and assume it is an existential quantifier (otherwise, convert it to an existential quantifier by negation). Consider the corresponding subformulation and assume it is in disjunctive normal form (DNF): , Each of them f ij and g ik It is a Boolean function (not necessarily a simple Boolean function) that is interpreted within a fixed, non-atomic Boolean algebra (which is fixed so that constants not equal to 0 or 1 are correctly interpreted). First, it is transformed into the following form: , (Where f is not the original f), note that, as is well known, for all Boolean functions... h i , If and only if hour, .

[0093] The resulting formula is logically equivalent to each of the following: , as well as , as well as .

[0094] 6 - Quantifier Elimination Methods in Boolean Algebras with Atomic Elements Existence quantifiers can also be eliminated in Boolean algebras with atomic elements. In this case, each element can be written as a (potentially infinite) disjunction of atoms. Power set algebras are a prime example of this type of algebra. Note that the cardinality here is consistent with the number of distinct atoms required to construct a given element.

[0095] First, as shown above, the sub-formula is transformed into the following form: .

[0096] Then, rewrite it as .

[0097] Next, the formula is transformed into minterm normal form. By simply converting to disjunctive normal form (DNF) and noting that such a transformation does not require negation (only the conjunction and disjunction need to be assigned to each other), we obtain the form a 1 x ≠ 0 , a 2 x ≠0, …, a N x ≠ 0 , b 1 x' ≠ 0 , b 2 x' ≠ 0 , …, b K x' ≠ 0 A series of inequalities, therefore no inequalities are transformed into equalities. Note that here... a i and b j It is the minterm in X, but a more general form also applies to this treatment.

[0098] system a 1 x ≠ 0 , a 2 x ≠ 0, …, a N x ≠ 0 , b 1 x' ≠ 0 , b 2 x' ≠ 0 , …, b K x' ≠ 0 A solution exists on any Boolean algebra if and only if it has a cardinality of at most 1. N The solution (and if) K Smaller, then it can have for x' (The solution). Therefore, the method is to transform the formula into a formula on a finite Boolean algebra, and possibly subsequently into a binary Boolean algebra. When a single quantifier When x is eliminated, it can therefore be written as a logarithm in the range only between 0 and 1. N A quantifier can be eliminated as a disjunction, thus generating appropriate quantifier elimination as needed.

[0099] make yes n The minterm of each variable, and The element resides in a BA. Therefore, if and only if whenever A i ≠ A j exist b i b j When =0, .

[0100] Algorithm: First assume They are all distinct, therefore non-zero b are all disjoint; otherwise, any two equations of the following form would be disjoint: , Convert to equivalent form It is now necessary to immediately recall that two distinct minterms are always disjoint, and subsets of disjoint sets are necessarily disjoint as well. Regarding sufficiency and... n = 1, the equation takes the form x ≥ b 1 and x' ≥ b 2 This is actually if and only if b 1 b 2 = 0 This holds true at that time. Assume that for... n And consider additional variables. x Then we can break down the equation into... p + q = m The equations are rewritten as follows: , , And by ensuring all A i , B i After disjointness, an inductive hypothesis is made (while if) p+q=1 (Then the solution exists in a trivial way), let X It is a solution to the following equation: , .

[0101] if p ≠ 0 ,set up x = Therefore, due to the disjoint assumption, .therefore , .

[0102] Similarly, if p = 0, then set Or simply set x = 0.

[0103] If and only if there exists 0 < c i ≤b i So that whenever A i ≠ A j All satisfied c i c j When =0, the system There is a solution.

[0104] In the absence of atoms BA In, if and only if When a solution exists, the system There is a solution.

[0105] In atomless BA, if and only if When a solution exists, the system There is a solution.

[0106] In any BA, x It is the elementary GSBE. Solution If and only if it is The solution for GSBE: (2.1.1) , If and only if it is a solution to the following GSBE: (2.1.2) , .

[0107] In the absence of atoms BA middle, If and only if hour ,system It has a solution.

[0108] In the absence of atoms BA middle, If and only if hour ,system It has a solution.

[0109] If and only if atoms exist s i 、t j Make satisfy At that time, the system It has a solution. In this case, any All That's the solution.

[0110] system A solution exists if and only if it has a cardinality of at most 1. N The solution.

[0111] Included B The above explanation n 1 variable BA A formula in a language is true if and only if it is of size . It is true in algebra.

[0112] Therefore, we relativize quantifiers sequentially as follows. Without loss of generality, we deal only with single DNF clauses of the form of existential quantification: , It can be written as: , And it can be converted into the following form: , in, a i , b i It is the smallest term among the remaining variables. Since it does not include... x of n There are no more than 2 variables. n-1 There are several minterms, therefore the formula can be relativized to: .

[0113] system , , , A solution exists in a non-atomic BA if and only if all of the following conditions are true: 1. There is no A. i Equals C i , 2. No B i Equals D i , 3. None Zero, 4. Whenever A i = B j hour, , In this case, for any The solution is 。

[0114] If and only if , Equivalently, , system , Has a solution .

[0115] If and only if X satisfies , , X satisfy , .

[0116] if , It has a solution, that is, if The solution can be obtained in the following way: Choose , in: , Then solve , .

[0117] The strong normalization algorithm will follow this principle: given a quantifierless formula, convert it to MNF+BDD form, which means that the atomic formula has the form: And this formula is a BDD of atomic formulas. Now we iterate through all paths in this BDD. For each path: (1) The squeeze merge form is as follows: and The formula for positive atoms, that is, the formula with equal exponents.

[0118] (2) Apply normalization in inference 3.1.

[0119] (3) Process all atomic formulas with zero coefficients.

[0120] (4) If a path forms an unsatisfiable system of equations, then discard the path.

[0121] In the atomless BA, there exists x , making If and only if for all i, j : , satisfy , , .

[0122] In the system In the middle, for a certain BFf , x = f(C,D) The necessary and sufficient condition for it to be a solution is: (1) For all i∈I, there exists such that p i = 1 and f(P) i ,Q i ) ≠ 1, and (2) For all j∈J , exist , so that v j = 0 and f(U) j ,V j ) ≠ 0 .

[0123] If the system It has a solution, and if x satisfy , alternative , So, x is the solution.

[0124] If the system It has a solution, and if x satisfy , when When it is a set of paired bit strings, it contains each c in the forward direction. i Each is included at least once and negatively. d j At least once, and such that for all A, B∈ , C A D B If x is non-empty, then x is a solution. Furthermore, such a x always exists. exist.

[0125] cardinality In the following text, f(x) = ax + bx' It can be any Boolean function.

[0126] If and only if |ab| ≤ n ≤ |a ∪ b| When, equation |f(x)| = n It has a solution.

[0127] The following theorem is a powerful and useful generalization of the Boolean consistency condition: Let f(x) be a Boolean function. Then, when Just reached The minimum value, and when Just reached The maximum value.

[0128] Cartesian product Given the elements ∪, ∩, Expressions of constants and variables, where × is interpreted on the set underlying the elements of a BA (as guaranteed by the Stone representation theorem for BAs, alternatively on any BA interpreted on a fixed set), and whenever the expression is type-checked such that, for example, a Cartesian product of two elements cannot interact as is with, for example, a Cartesian product of three elements, we can use the well-known identity: (Or a similar identity widely found in the literature) to push × to the innermost layer of the expression. Then, given a first-order formula, we can make the BF appearing in each atomic formula take the disjunctive form of, for example, the Cartesian product of minterms. We now transform the formula into minterm normal form (or a weaker form of DNF based on BF). Now taking the × on the conjunction in each clause, we know that the product equals the empty set if and only if at least one multiplicand is empty, which would be the disjunction of the formula without the ×.

[0129] Note that this allows for Cartesian products of elements from different BAs, as in the multiclass theory of BA.

[0130] Higher-order Boolean functions The following methods can be used to quantize BF, SBF, and certain CBFs (conditional BF below) and their higher-order counterparts, obtaining equivalent formulas that do not require quantization of the functions. Consider the quantization involving the existence (or universal name, with necessary modifications) of such functions. The formula. Each n The BF of 2 variables can be written as a Boolean expression, which involves 2 n A constant (e.g., considering each subexpression of a single variable by using Boolean normal form, algebraic normal form, or minterm normal form, or for the entire expression considering all variables), so the quantization of BF is transformed into 2. n A first-order quantifier. Similarly, with SBF, we quantize constants and require them to be 0 or 1. CBF is a Boolean expression that involves a ceiling function defined by taking zero as zero and all other BA elements as 1, or even more generally, a formula in the BA language that is interpreted as the values ​​0 and 1 in BA (this is the same as quantifiers and equations / inequalities that allow ceiling functions). In their full generalization, CBF can involve an infinite number of coefficients. For example, restricting them by requiring expressions under a ceiling function (or in a formula) to be SBF, or requiring constants to be derived from a fixed finite set, allows quantifiers to be eliminated to first order in the same way as above.

[0131] Higher-order functions (BF, SBF, and restricted CBF) are considered as operations on the coefficients and return coefficients of their input (potentially higher-order) functions, and are therefore transformed accordingly, making them take-off. n The BF of each variable is returned. n A higher-order function of BF with 2 variables will be written as using 2 n Find BA elements and return 2. nA function of elements, and makes necessary adjustments and changes for all cases, and similarly makes necessary adjustments for a function that uses a function of multiple functions, and so on.

[0132] For efficiency, it is not necessary to expand the formula exponentially (or in the form of a pyramid) at the beginning, but it can be done step by step, taking advantage of opportunities to simplify and eliminate at each step, as follows: simply by writing down the Boolean normal form (or any other form, such as Reed-Muller) of the quantized function with respect to a (potentially cleverly chosen) variable. n The quantifiers on the BF of each variable can be converted to the quantifiers for the two BA elements and the quantifiers for the two BA elements. n Quantization of BF over -1 variables.

[0133] The second-order finite model check can be rewritten as a quantization of the SBF.

[0134] Homomorphism and Hemimorphism The multiclass theory of Boolean algebras allows interactions between different Boolean algebras solely through the combination of atomic formulas. Even the aforementioned Cartesian product, which allows mixing different Boolean algebras, still permits very shallow interactions between them. However, using the decision method now described, deeper interactions are possible, and these interactions remain decidable. This is useful not only for interactions between Boolean algebras but also even as an extension of the theory of individual Boolean algebras. Furthermore, it clearly has applications in various languages ​​called descriptive logic (DL), including decision procedures, which are commonly used in KRR.

[0135] In the following text, we will deal with the existence formula of the following form: , Each of them ψ i Having form x = h j ( y ),in, x , y It can be a constant or taken from x 1 , … x n , here h j It is a BA homomorphism or a monoid homomorphism (as we will briefly describe), and This is the general form of the DNF clause in the BA language. We will... Convert to not contain h j The formula.

[0136] Here we support a multi-class theory of BAs, so it is interpreted in the product of multiple BAs, and homomorphisms can exist between different BAs. In particular, we can support ultrafilters, which are essentially homomorphisms to binary BAs.

[0137] Here, homomorphism is simply cyclic homomorphism. The term semi-homomorphism is used by Halmos and is defined as follows: if h (0) = 0, and for all x, y , h ( x ∪ y ) = h ( x )∪ h ( y Then the function between the two BAs. h:B 1 →B 2 yes Semi-homogeneous.

[0138] Any semi-homomorphism gives rise to a monoid homomorphism, where the monoid is the multiplicative monoid in BR. Let... g ( x ) =h' ( x' ).So g (1) = 1, and .

[0139] This is the same as existential and universal quantifiers in descriptive logic, where... h The relationship is considered a binary relation, and the BA element is considered a unary relation. We will emphasize this connection later.

[0140] Therefore, we assume that each of the original formulas h j It is either homomorphic or semi-homomorphic, including the case of monoid homomorphism. Furthermore, by modifying the following technique, we can also override homomorphism by requiring the homomorphism to have an empty kernel and that it maps 1 to 1.

[0141] First we will Convert to the following form: , in, c A , d k It is a constant. This is achieved by writing each element as a disjoint union of minterms, and depends on... hj The distribution lies on the union, and this transformation is direct.

[0142] We now have a finite partition of the BA, where the disjoint parts are minterms. We can iterate through which minterm is mapped to which defined graph. The only additional condition we must add is... , The initial conditions are given by f ( X The rule specifies which minterms must be zero, which easily boils down to a method for eliminating semi-homogeneities.

[0143] For homomorphism, we add the following condition: disjoint elements are mapped to disjoint elements, that is... xy = 0 → h (x)h(y) = 0. This can be checked again by traversing the graph to which minterm is mapped to which term.

[0144] However, in BAs that are not non-atomic, another cardinality condition must be added. This and other results required by these algorithms are summarized in the following theorem: If x 1 , …, x n If are non-zero and disjoint, then there exists a semi-homogeneous state h such that for any y 1 , …, y n , Under the same conditions, and if BA is complete or countable non-atomic, then if and only if for All i ≠ j, y i y j = 0 And |x i | ≤ |y i When |, homomorphism exists.

[0145] |x| This refers to the cardinality, and in pure BA terms, how many of them are disjoint. x It can be written as the supremum of its union.

[0146] Will h Set to Any term in the matrix maps to zero, and for a semi-homomorphism, for all... 0 < t i ≤ x i ,set up h ( t i ) = y i The rest is done immediately. For homomorphisms, this follows Theorem 5.13 in [kop] if BA is complete. We use the duality of Stone in its topological setting, recalling that a homomorphism is the [set] inverse of a continuous function (in Stone topology), and vice versa. We must find the continuous function f , making However, this has shown that some closed open sets are mapped to closed open sets, and disjoint sets are mapped to disjoint sets, so as long as the preimage of each set is not less than (in terms of cardinality) the original set (and all closed open sets are infinite in atomless BA), there exists a continuous extension of the function over the entire space. In particular, we can again... h Set to Any item in the mapping is zero.

[0147] In the above algorithm, the cardinality constraint must be clearly addressed, for example by not fixing the underlying BA and allowing it to be infinite (this will require careful consideration of constants), or by considering BAs without atoms, such that the cardinality of each element is zero or infinite.

[0148] Consider a special case of the Tarski relational calculus as follows. Consider the power set algebra of pairs of sets over a field D. This algebra is P(D × D). Consider using another operation R... - This enhances the Boolean algebra theory of the algebra, the other operation R - Take the binary relation R as its inverse proposition (also called the inverse or transpose). That is, .

[0149] Consider two types of algebra: general algebras and diagonal-free algebras. Diagonal-free algebras mean that no binary relation has diagonal elements. Then, correspondingly, we understand the complement, taking the complement while leaving the diagonal elements empty. In general, R... d Let R be a diagonal element of R, and R -d Yes (R) d A polynomial is any finite combination of elements obtained through Boolean operations and inverse propositions. A method for determining whether such a polynomial has zeros is now described.

[0150] An inverse propositional algebra is defined as "complete" if every diagonal element relation has a maximal asymmetric part. Every power set algebra as defined above is complete, and this method also extends to other complete inverse propositional algebras.

[0151] Note that the polynomial in R is of the form f(R, R) -A Boolean function for A = f(1,1), B = f(1,0), C = f(0,1), and D = f(0,0). Then, determine... Rf (R, R - The method to check if (A ∨ A) = 0 is true is to check if (A ∨ A) is true. - ) (B ∨ C - ) (C ∨ B - ) (D ∨ D - Whether R = 0 holds true, and this only applies to algebras without diagonal elements. In this case, any R = A′A - ′ ∨ T are solutions, where T is B′C - The maximal asymmetric part of ′.

[0152] In general, we also consider problems involving functions that depend on the diagonal elements, and even more generalized ones. The general form of such a function is: .

[0153] A method for determining Rf (R d , R, R - The method to determine if A = 0 is true is to check A. d E d = 0 and (B ∨ B - (C ∨ D) - (C) - ∨ D) E -d Is the value 0 true?

[0154] In the above notation, there is an expression that satisfies f ( R, R - ) = All of 0 (possibly infinitely many) R' The expression for the intersection of these is useful, and for... f ( R d , R, R - ) = 0 is similar. For the first case, it is simply ( D ∨ D - ) ( B - ∨ C ), and for the second case, it is ( D ∨ D - ) -d (B - ∨ C ) ∨ D d .

[0155] Here, we will define a non-standard concept of query response. In the field of knowledge representation (KR), the query will be an open formula, and the answer will be derived from KB. Contains All substitutions. Another way to put it is that it refers to the parts common to all models. Therefore, if the query is merely a form... Rxy atoms , The answer is similar to There are a few things to note, but the main points are actually about what's common to all models. Note that this doesn't have to be a model: consider the formula. C ( a )∧ ( C ( b ) ∨ C ( c )),in C It is a unary relation, and a, b, c It is a constant. Therefore, the part common to all models is only... C ( a However, it is not a model, because every model will have to include... C ( b )or C ( c ).

[0156] Our modified query response concept is as follows. Initially, the query was a form... Rxy A single atom. The answer will be a formula with two free variables, where R It does not appear, and for each substitution of the variable, it occurs if and only if the substitution occurs in... R When the formula holds true in all models, it is a tautology. For example, in two formulas... and Each query in Rxy The answer will be Sxy One intuitive way to look at it is that the answer provides an "explanation," and that "explanation"... R But do not quote R。

[0157] We model KB as a form f ( R, R - ) = The statement is 0. The reason for this will be explained later. Coefficient A、 B, C, D [、E This can depend on other variables and constants. We want to get the query answer. α Expressed as none R The expression that satisfies .

[0158] In DFCA, if R. f ( R, R - ) = 0, then .

[0159] Infinite operations The goal of this chapter is to propose a method for explicitly evaluating expressions. and , in, X It is a tuple of variables. f He is my boyfriend, and Therefore X GSBE as its unknown. We focus on the atomless BA, while the treatment of the general BA is similar but more complex, as will be seen from some of the lemmas in the following general lemmas.

[0160] The method proposed here is particularly applicable to the first-order theory of BA enhanced by the above operations (which may be interpreted in a particular BA using special constant notation for each element), while maintaining decidability by simplifying it to standard BA theory.

[0161] It is already surprising that BA, especially atomless BA, is even closed under the above [possibly] infinite operations. As we will see, the result takes an even more surprising, simple form.

[0162] Obviously, calculation It is enough, because , Conversely, the same applies. Additionally, note: Among them, in the last two equations x 1. Clearly depends on x 2, …, x n This indicates that only the univariate case is being handled. That's enough.

[0163] For simplicity, we assume that all BAs in this chapter are infinite. Finite case treatment can proceed along the same route. However, at one point, we will strongly use the no-atomic assumption, in which case our main and final results will be based on... f Under the mild assumption (i.e., it has no unique zero, otherwise the answer is trivial), it is , Most notably, it is not only a simple closed form, but also independent of... g i The intuition behind this latter point will become clear later.

[0164] make a∈B ,but .

[0165] We assume that the null disjunction is 0 and the null conjunction is 1. For the disjunction assertion, the case is... a = 1 is ordinary. a ≠ Case 1 from 1 a It is also ordinary. Regarding the conjunction assertion, a = 1 is also ordinary. Assume... a' It is a non-atom. Write it down. a' = b ∨ c ,in b , c It is non-zero and bc = 0. Therefore b a and c a .therefore , Now assume a' It is an atom. Therefore, according to Proposition 1.4, it is true if and only if... a' ≤ x When, if and only if a' x' hour, x a .so .but a' a ,so ,therefore .

[0166] Let a ∈ B, then , .

[0167] if Then disjunction and conjunction are empty. If a = 1, then all x ≠ 1. Satisfy x a Assuming a , a' All are non-atomic. Therefore, there exists... c , d , making 0 < c < a ∧ 0 < d < a' .set up x = c ∨ d .So, x a Because and x' a ,because( c ∨ d ) a = c ≠ 0 and ac' d' = ac' d + ac' = acd + ad + ac + a = a + c ≠ 0, therefore, in this case, the large union is 1, and the large intersection is 0. If a Since they are atoms, we can write the two equations as follows: , According to Theorem 1.3, they are respectively equal to a' And 0. If a' It's an atom, we noticed. , The last equation is similarly based on 4.1. .

[0168] make f For BF, and a ∈ B .So .

[0169] Write Then, use the formula above: , Similarly , And the intersection points are dual, for example .

[0170] make a 1 , …, a n yes B The elements, none of which are 0 or 1, and among them B It is non-atomic, and n > 1. Let .then and .

[0171] Will X writing .make .

[0172] If we show Y If it is non-empty, then the lemma is proved, because then... X It contains elements and their complement, but Y The non-emptiness is directly derived from Corollary 2.2.

[0173] An interesting property of atomless BA comes from the proof. In any BA, if... f ( x If ) = 0, then unless f ≡ 0 ,otherwise f ( x' ) ≠ 0. This is because for all f , x , f ( x ) ∪ f ( x' ) = f (0) ∪ f (1). However, in atomless BA g 1( x ) ≠ 0, … g n ( x In cases where ≠ 0, there always exists a satisfactory result. x , making x' It also satisfies the inequality.

[0174] For making f (0) f (1) = 0 If BF and g satisfy (otherwise they are trivial), then we obtain .

[0175] This is a direct application of the above proof.

[0176] Now, by taking into account the following formula and the above content, It can be easily evaluated: .

[0177] In atomless BA and for making f (0) f (1) = 0 satisfies (otherwise use 4.3) BF , g We got , , And use the lemma above.

[0178] if f (0) f (1) = 0 and Then the univariate BF f Known as Widespread .

[0179] Note that this means f It has more than one zero and is not identically equal to zero. Clearly, if f Depending on several variables, we can define "about x Wide wrt x Recall that the Boolean derivative is... .

[0180] make B For BA, and f Let its width be BF. Then, B / f The element is located in the interval The BA is within this interval. All BA operations are relative to this interval, therefore x' yes x' f' (1), and xy yes xy ∪ f (0). We also through h f ( x ) = a ∨ bx Epimorphism is defined. h f : B → B / f .

[0181] Let B be countable and atomless, and let f be the width BF on it. Then B and B / f are isomorphic.

[0182] It is easy to see that B / f It is both countable and non-atomic. But all countable non-atomic BAs are isomorphic.

[0183] Let B be countable and atomless, and let f be the width BF on it. If and only if When there is a solution in B / f univariate elementary GSBE It has a solution.

[0184] Let B be countable and atomless, and let f be the width BF on it. Let It is a univariate BF, in which none of the variables are constant. It equals zero. Therefore... .

[0185] Consider the expression , This is the same as considering the following formula: , According to Lemma 4.4, the first one easily equals 1, and the second one equals 0. However, 1 in B / f The preimage in the image is greater than or equal to f' (1) can have any value. But obviously , Therefore, the equation holds true. Similarly, the preimage of 0 is less than... f (0) for any value, but satisfying f ( x All of ) = 0 x At least for f (0), therefore the second equation is true.

[0186] if f If the union is not wide, the result can be calculated immediately because the union is either empty or contains one element.

[0187] Let B be countable and atomless, and let f be the width BF on it. Let It is a univariate BF, in which none of the variables are constant. It equals zero, and h is some arbitrary BF. Therefore... .

[0188] Simply , And we will use the previous reasoning.

[0189] Model definability in LTA Assuming a certain logic The LTA constitutes an atomless BA. Consider a single free variable in the BA theory of this LTA. The formula. Then Let L define a set of formulas. In other words, it defines a set of models. If we want to query whether a model is in this set, we can take the union of these sets. Previous results allow us to do this. BA is non-atomic, so we can assume... It is without quantifiers and is further given in DNF. The expected model set. The following formula can be used to calculate: .

[0190] We conclude that the negation literal of each DNF clause contributes nothing to this model set. It is noteworthy that if... It contains only negative statements, that is, statements in the form of " x Not containing y "or" x Not implied in y "We got" , This means that for each model, there exists a satisfying condition. formula x。

[0191] In the later GSSOTC processing, the model will become the program, and the formula will become the specification. If GSSOTC states its own BA and has uninterpreted constant symbols of that type, then any program will accept that interpretation as long as there are no positive constraints, and it doesn't matter even if such negative constraints exist. This is very counterintuitive. Furthermore, the union only concerns the "positive part of the positive part," i.e. f (1) rather than f (0). Therefore, f It can be done in form f = ax Therefore, any way of expressing an assembly using the interpretation of constant symbols in GSSOTC can be simplified to merely formal... x ≤ a The formula for a single atom.

[0192] 11 - Univariate Algebra Jonsson, Tarski, Halmos, and others have extensively studied unary algebra, which uses operators called quantifiers. Extended Boolean algebra. Given any operator that satisfies the axioms of univariate algebra, for f(x, x) = 0, where f is a Boolean function on a univariate algebra, for example Does there exist f(x, The necessary and sufficient condition for a solution to x) = 0 is that ,in .

[0193] 12 - Logical language that refers to truth Designing a logical language capable of referring to truths in its own statements is a long journey in the fields of mathematical and philosophical logic. The results have been predominantly negative: in a certain, but very broad, sense, it is impossible to include statements about truths in a language, statements about statements in the same language, while maintaining linguistic consistency. Including such truth references allows for paradoxes in language expression. Perhaps the most well-known consequence of this property is Tarski's undefinability of truth.

[0194] In this age of computation, this inability becomes a practical limitation. A formal language cannot specify whether another statement in that language is true, or whether one statement implies another, or other similar logical problems that boil down to discussing truth. Many remedies have been proposed in the literature (e.g., sub-coherence and multivalued logic), but they all have the property of allowing the language to contain paradoxes, thus making the language what is called "non-classical logic." Therefore, in these languages, it is no longer the case that every precise statement is either true or false in a classical sense (in a given model, if such a setting even has model theory).

[0195] It is generally accepted that, although not yet proven, classical logic cannot have truth predicates. This application proposes a method to extend almost any language to possess the ability to refer to the truth of other statements and to quantify its own statements, while maintaining the classical and consistent nature of the original language (here, "basic logic"). Even more surprisingly, this construction generally preserves decidability. If basic logic is decidable, then the extended language is also decidable. This avoids Tarski's impossibility result, because it does not allow syntactic representation of statements as required by Tarski, but rather deals with them purely semantically, and further allows only specific operations on them.

[0196] Specifically, consider a Lindenbaum-Tarski algebra (LTA) of a certain language L. It is a Boolean algebra (BA) generated by statements (or formulas) in L in a logically equivalent sense. Therefore, it is assumed that L constitutes a Boolean algebra. In some embodiments, it is further assumed that this Boolean algebra is non-atomic. In particular, almost any language on an infinite number of signatures that constitute a Boolean algebra constitutes a non-atomic algebra.

[0197] The method is as follows: Consider a first-order theory of Boolean algebra, interpreted in Boolean algebra and extended with the corresponding constant notation for each Boolean algebra element. In other words, constants are simply formulas in the underlying logic. The resulting language is trivial, consistent, and classical, just like any first-order theory of Boolean algebra. Mentioning unsatisfiability and tautologies (as truth predicates above) is merely asking whether a constant or variable is equal to zero or one. Furthermore, formulas can be quantized as usual, just as Boolean algebra elements are quantified.

[0198] So far, this has created a language that can talk about another language, but still cannot talk about itself. A language that talks about the truth of statements in other languages ​​is the only known remedy, and it is a common practice for the widespread use of defining and referring to truth (though not usually through Boolean algebra). However, there are additional steps to elevate this Boolean algebraic construction to a language that talks about itself.

[0199] Therefore, the first-order theory of Boolean algebra can be the LTA of L, and itself has an LTA that is elementaryly equivalent to the Boolean algebra of L. A simple case is when the Boolean algebra is non-atomic, because, as Tarski proved, all non-atomic Boolean algebras are elementaryly equivalent (and all infinitely atomic Boolean algebras are also elementaryly equivalent). For this, one only needs to augment the extended language with an infinite number of additional uninterpreted constants, relations, or function notations. There are many ways to do this, both artificial and non-artificial. In languages ​​that are extended to an even greater extent (e.g., for software specifications), the non-atomic property can be obtained by allowing an infinite number of input and output streams.

[0200] This method creates a logic that discusses the truth of its own statements and quantifies them. Furthermore, there are an infinite number of such logics, with each basic logic choice corresponding to one. However, the constants need to come from the extended language. This is described in the construction below.

[0201] The following sections provide a more precise description of this construct. This considers extending multiple languages ​​at once, and one feature of this construct is that it allows languages ​​to coexist in a novel approach to combinational logic.

[0202] 13 - Language NSO A fixed set of languages ​​(“basic logics”, which need not be related in any way) is defined, where their formulas constitute Boolean algebras. (The formulas are considered in the sense of logical equivalence, in which case it is called the LTA (Lindenbaum-Tarski algebra) of the language, or the formulas are according to any other chosen equivalence relation.) The theory of multi-class Boolean algebras of these Boolean algebras can then be considered. The constants in the language are the formulas in the basic logics. Quantization employs the same semantics as quantization on any element of a Boolean algebra. If the basic logics constitute non-atomic Boolean algebras, then the extended language is decidably satisfiable if and only if the basic logics are decidably satisfiable. Otherwise, a decidable model count is required. More precisely, when considered as Boolean algebras, it is necessary to know whether an element is at least... n The precipitation of different atoms.

[0203] Use NSO[L 1, … ,L n ] represents an extended language, where NSO stands for zero-ary second order (although not under the usual semantics of zero-ary relations). A language can be obtained that quantifies its own formulas (through quotient operations via logical equivalence) as follows. First, NSO[L 1, … ,L n The formula L, which can already be quantized in the standard way of quantization in Boolean algebra, is now available. 1, …, L n In this setting, each NSO formula is either true or false because it is interpreted in a fixed model (which is the Boolean algebra of the LTA as the underlying logic) and thus constitutes a small (two-element) Boolean algebra. This is generally still far from being equivalent to the Boolean algebraic elementary equivalence of the underlying logic. To obtain NSO[L...] 1, … ,L n The formula in [] can be used to obtain a richer Boolean algebra, which can be enhanced with an infinite number of relational and / or functional symbols, possibly in a way that preserves decidability (e.g., as described above). Assume NSO[L] 1, … ,L n The expression is appropriately extended so that it now constitutes a non-atomic Boolean algebra (and similarly treats other types of Boolean algebras). The constant can now be NSO[L]. 1, The formula in […,Ln] is enclosed in curly braces to avoid syntactic ambiguity. The handling of quantifiers for the decision-making process can be accomplished using the quantifier elimination determination method described in Sections 5 and 6 above. NSO[L 1, … ,L nThe basic syntax of [] (before being extended in any way that makes it a non-atomic Boolean algebra) can be expressed as a set of three BNF productions, such as Figure 3 As shown in box 302.

[0204] In these production rules, Representation Language L Any formula within. Each bf It may only contain variables and constants from the same class. The formula at the deepest level of the nested curly braces will be L. 1, … ,L n The formulas in the Boolean algebra language, where the constants appearing in the formula can only be 0 or 1, are then interpreted as formulas on any non-atomic Boolean algebra, since they are all elementaryly equivalent.

[0205] Consider the LTA (Limited Area of ​​Expression) of a statement in a logic language. This LTA is a BA (Balanced Logic) theory. Statements in the BA language interpreted within a given LTA are... This will mean "for all statements" x Existing statement y , making x Contains y Therefore, we can immediately see how LTA's BA theory serves as a theory of statements in a language that are grammatically inaccessible but are abstracted into mere BA elements.

[0206] Countable non-atomic (CA) BAs arise naturally in logical languages. See remark 1.4 and recall that almost all languages ​​of interest are countable. Therefore, all CA BAs are isomorphic, and all non-atomic BAs are elementaryly equivalent.

[0207] Therefore, if we manage to adopt a language that constitutes CA BA (or at least has no atomic BA), and we are also able to make the BA language be interpreted as CA BA in the LTA, then we have a language that can refer to the statements of the language itself, their Boolean combinations, logical equivalences, and truths.

[0208] This contrasts sharply with Tarski's assumption of the undefinability of truth: this impossibility result presupposes that we have direct access to the syntax of statements, for example, represented by Gödel numbers. However, in our assumption, statements are abstracted to the point that they constitute only BA elements.

[0209] How can we have our own LTAs constituting a BA theory without atoms? A trivial, and not very useful, example is to take all formulas with an infinite number of free variables. A more useful approach is to add an infinite number of uninterpreted constants. Another approach would be to combine an infinite number of homomorphic and semi-homomorphic symbols in the signature. It would be even easier if the language were further extended to have a time dimension.

[0210] 14 - Examples of software updates Suppose a software system has the feature of automatic updates. It downloads updates, performs certain checks on the new code (update), and installs it if the checks pass. It is useful to write both the current software and the update in the same language. Otherwise, many languages ​​would be needed (one language for each update). If the checks have the form of logical implication (e.g., "reject the update if the new code implies sending private data over the network"), then there exists a language that talks about the consistency of Boolean combinations of statements in the same language. No previously existing language can support this. But for NSO, it takes the form uc′ = 0, where u is the update, c is the condition, and the formula is true if and only if u implies c.

[0211] 15 - Using recursive relations to extend language In fields related to computational logic, such as automated reasoning, automated theorem proving, knowledge representation and reasoning, and formal verification, designing richer formal languages ​​that remain decidable is of great interest. In particular, algorithms that allow determining whether statements in such languages ​​contain contradictions are valuable. The disclosed techniques demonstrate how to enrich a class of languages ​​using recursive relations (RR). This enrichment includes forms with recursive and fixed-point operators, while preserving the algorithmic properties of the original language by demonstrating how statements in the extended language can be transformed into statements in the original language.

[0212] The construction here uses the concept of "weak ω-category theory." In mathematical logic, a "theory" is a set of statements in a formal language. In many deductive systems, there exists a set of "axioms" for the theory, and other statements are derived from these axioms according to a set of inference rules. A first-order theory is a set of first-order statements recursively obtained from a set of axioms according to inference rules.

[0213] ω-category theory is a first-order theory in which all its countable models are isomorphic. The Ryll-Nardzewski theorem states that this definition is equivalent to another definition. That is, ω-category theory is a theory in which, under logical equivalence, only a finite number of formulas have a fixed number of free variables. This leads to the definition of weak ω-category theory. Weak ω-category theory is that which has a finite set of formulas. The formulas to be counted are formulas with a fixed number of variables, where all constants appearing in them are taken from a fixed finite subset of all constants in the language (under logical equivalence). Furthermore, even when the theory is not weak ω-category, the language can have computable functions that reduce every statement in the language to an equivalent satisfiable statement in some fragment of the original language of the weak ω-category. Note that it is not important whether the language is interpreted in some model.

[0214] Any theory of the ω-category is a weakly ω-category theory, but the reverse is not true. For example, a theory of atomless Boolean algebras (due to their aforementioned quantifier elimination property), where the atomic formulas are Boolean functions rather than just simple Boolean functions, is weakly ω-category rather than ω-category because the constants can be interpreted in an infinite number of ways. If the atomic formulas are limited to simple Boolean formulas, the theory will be ω-category (and there is no further distinction regarding the choice of which atomless Boolean algebras to use, since, according to Tarski, they are all elementaryly equivalent).

[0215] It is readily apparent that theories of non-atomic BAs and theories of fixed finite BAs are both weak ω-categories (see Note 1.3). In the following sections, we will only deal with those BA theories. However, the constructions in this section can be implemented as any weak ω-category theory. Furthermore, in BAs, we have an additional aspect not covered by this concept: the above principle applies not only to formulas but also to terms. Specifically, there exist only a finite number of BFs with specified finite sets of constants and variables.

[0216] The floor operator is a function defined by the following formula: .

[0217] Conditional Boolean function (CBG) It is a finite combination of constants and variables obtained through Boolean operations and the floor operator.

[0218] Note that under the floor operator, we can have the entire expression, i.e., the entire CBF. Therefore, for example, It is CBF, which is equivalent to .

[0219] The equivalent definition of CBF is a function of the following form: in, It refers to any formula in the BA language. In the case of a non-atomic or finite BA, it is calculated by allowing rounding up. Sub-acceptance formula To obtain another equivalent definition, the floor operator returns 0 or 1 depending on whether the formula is false or true.

[0220] We are now going to define a formula in the BA language, which is enhanced with recurrence relations. It is a list of the following form: .

[0221] This confusing definition is actually quite simple. We can simply define the formula using a recursive relation ( ) and CBF ( f They can depend on each other. ψ It is the "master" formula. For example: .

[0222] Here f ( x , y As expected, it is understood naturally: f n The limit to which it converges. For The situation is similar. Obviously, it doesn't always converge, but it's easy to determine all cases, as shown below: (1) The dependencies between functions, formulas, and their initial conditions must be well established. Therefore, in g n (or ) depends on f n In this case, f n Cannot rely on g n (or ).but, f n Can rely on g n-1 And so on. This boils down to verifying that a directed graph is acyclic.

[0223] (2) The initial conditions should also be sufficient to allow for any given n To calculate f n , .

[0224] (3) And most importantly: in calculation f 1 , f 2 , f 3 ,… as well as At that time, we guarantee that a cycle will be found, that is, for some... n ≠ k , (Logical equivalence), and for f The situation is similar. If n = k -1, then it is a fixed point, and the result is well-defined. Otherwise, we can do it in almost any way: we can return 0 or ⊥, or the first recurring expression, or we can enhance the language to incorporate "fallbacks" that return a default answer when there is no fixed point.

[0225] This, together with the properties of language, should be sufficient to show that a BA with a recursive relation can be written in an equivalent form in a pure BA without a recursive relation.

[0226] Multi-indices recursion is supported in the same way, i.e., recursion in the following form: .

[0227] Clearly, the same construction can be performed when dealing with higher-order BFs.

[0228] 16 - GSSOTC: Novel Temporal Logic In fields related to computational logic, such as automated reasoning, automated theorem proving, knowledge representation and reasoning, and formal verification, designing richer formal languages ​​that remain decidable is highly useful. In particular, algorithms that allow determining whether statements in such languages ​​contain contradictions are valuable. In many logic languages, the temporal aspect is important. For example, in software and procedural specification languages, the ability to express statements of the form "first do this, then do that" is crucial. Furthermore, in many cases, distinguishing between input and output is essential.

[0229] Many temporal logics have existed since the early days of computer science and computational logic. One of their main limitations is that they often become undecidable when the number of possible states is not finite or unbounded. Additionally, many temporal logics have limited ability (if any) to distinguish between inputs and outputs. Overcoming the decidability problem is a major active area of ​​research, sometimes referred to as temporal logic over infinite data values. Data elements are typically equipped with only very simple operations, usually limited to checking equality. Furthermore, these logics and other similar mechanisms are often not closed under Boolean combination.

[0230] This paper discloses a new, decidable family of temporal logics over infinite data values, where these values ​​possess a theory far richer than mere equality. Some embodiments are equipped with Boolean algebra theory. Furthermore, this language has the unique ability to verify statements of the form "for all inputs, there exists a well-defined output." Moreover, this logic transcends the scope of mere temporal logic. It is a highly expressive and decidable language.

[0231] In the following text, L Represents arbitrary logic (possibly with specified additional conditions), and D Indicate its domain (i.e., D It is the set of elements that represent the range of values ​​for a first-order quantifier. For each formula, there may be many interpretations, each with a different domain. D。

[0232] Given language L It can be extended to be composed of GS[ in the following way] L The language is represented by ], where GS stands for "Guarded Successor". This will be further extended to the language GSSOTC[ L The symbol ] represents "Guarded Successor Second Order Time Compatible". The determination process is then described using this language.

[0233] We propose a novel decidable temporal logic, GS (Guardian Successor), with several distinctive features. First, it allows an infinite number of data values ​​that are not only equal but also possess a rich theory: a first-order theory of atomless Boolean algebra. The language also distinguishes between inputs and outputs and has a decision process for determining at each time point whether an output exists for all inputs. Furthermore, and perhaps most surprisingly, data values ​​can simply be statements within GS itself. We also propose non-temporal segments called NSO (Null-Element Second Order), which exclusively enjoy this last property. These results are essential and crucial elements for any meaningful design of secure AI. Finally, all these results are derived from a novel treatment of a first-order theory of atomless Boolean algebra.

[0234] Traditional computation is a manipulation of bits in time. Bits are elements of the least possible Boolean algebra. The construction here can be viewed as a generalization to working with certain infinite Boolean algebras. In this model, the decidability of the canonical language is certainly not so trivial. Furthermore, we will show how this generalization can support some very surprising capabilities.

[0235] The following section introduces GS (Guardian Successor), a novel and decidable temporal logic that offers several distinctive features. First, it accommodates an infinite number of data values, enhanced by a complex theory: first-order theory of atomless Boolean algebra. Second, the language distinguishes between input and output variables and allows the decision process to prove that at every time point, for all inputs, there exists an output. Third, and perhaps most surprisingly, data values ​​can be statements within GS itself. The language is closed under Boolean combination and allows for the quantization of both data values ​​and time points. Its decision process possesses unique simplification and elegance, and differs significantly from other common decision processes. It relies on the ability to enhance certain languages ​​with recursive relations (a form of fixed-point operator), specifically an extension of first-order theory of atomless Boolean algebra.

[0236] We also propose NSO (Null-Element Second-Order Logic, a name chosen during the first incarnation of the idea, and perhaps needing to be reconsidered), a non-temporal segment that preserves the aforementioned third property. All these findings stem from a novel approach to first-order theory for atomless Boolean algebras. These results are essential for designing safe AI systems.

[0237] For ease of understanding, we will first introduce non-temporal NSO logic, and then we will introduce GS, which can be viewed as a temporal extension of NSO. All nontrivial proofs not appearing in the main text are provided in the appendix.

[0238] The ongoing implementation of the language described in this article is available in the repository https: / / github.com / idni / tau-lang.

[0239] The goal of the NSO is to have a language that can speak its own words in a consistent and decidable manner. Tarski's Truth Undefinability This demonstrates that this is impossible under certain broad settings. The key to NSO is the abstraction of statements to the point that they constitute only Boolean algebra (BA) elements. In particular, the syntax of the statements is inaccessible (as opposed to Tarski's setting, which relies on Gödel numbers), and logically equivalent statements are not identified.

[0240] Any classical logic closed under Boolean combinatorial rules will have BA called the logic. LindenbaumTarski Algebra (LTA) Recall that this is only in the sense of logical equivalence. Now consider two important points: 1. Any such logic with an infinite number of signatures (whether constant, relational, or functional symbols) constitutes a non-atomic BA. 2. All countable non-atomic BAs are isomorphic (this is a well-known theorem), and as Tarski proved, all non-atomic BAs are elementaryly equivalent. Clearly, all statements in the language of interest are finite strings on a finite alphabet, and therefore countable. Thus, countable non-atomic BAs are the LTAs of the principal logic of interest.

[0241] When we say "in fixed BA" B When explaining the BA theory in the text, we not only refer to... B The explanation of the first-order theory of BA (recall that an explanation is a mapping from a signature to an actual object in a structure), and we also point out that its signature is equipped with... B Each element is interpreted as a constant, therefore each element has a unique constant assigned to it. We call these constants... Explain constants .

[0242] Fixed language The LTA of this language constitutes a non-atomic BA. Let NSO[ [This is the first-order theory of BA explained in this LTA, therefore] Each statement in is NSO[ The constant symbol in ]]. So far, NSO[ [A type of discussion] But we still don't discuss our own language. Therefore, we first make NSO[ The LTA of ] is also a non-atomic BA (because currently it is just a two-element BA, as any logic can be interpreted in a fixed structure). This can be achieved by adding an infinite number of uninterpreted constant symbols ( Unexplained constants This can be accomplished using any of these techniques. Then, the interpretation constant is expanded to include NSO[ The statements within [] (well-founded by introducing curly braces as follows). Because and NSO[ All of them constitute atomless BA, therefore they are elementaryly equivalent under the BA signature. Thus, we can make NSO[ ] Discuss its own statements (including quantification). Furthermore, if and only if When it is decidable, NSO[ It is determinate.

[0243] 17 - Language GS As an intuitive starting point, in any logic, any formula with two free variables can be considered as defining a sequence: we believe that a sequence is defined if and only if any two consecutive elements in the sequence are... s i-1 , s i satisfy Time (which we can interpret in a fixed model) (or one can appeal to any suitable concept of satisfiability), sequence s right Modeling. Then we write... Now consider a logic class with the following property: a finite set of fixed constants and variable symbols. Then, the set of formulas using only those constants and free variable symbols (we allow and require any number of quantized variables) is finite in the sense of logical equivalence. Here, the most relevant logic of this kind is the theory of non-atomic BAs (whether or not it is interpreted in a fixed BA, and when it is interpreted in a fixed BA, it is equipped with an infinite number of interpreting constants as above, and this is a nontrivial case).

[0244] Depend on |s| express s The length. Given Consider the following process: Query whether it exists. s , making |s| = 2 and Then ask if it exists. s , making |s| = 3 and And so on. This series of problems can be approached using a recursive relationship. In the form of, where the base case is: (Although our preferred form will be slightly different). So, It refers to "existence length is n The beginning ofx "the sequence", then, in order to obtain (for each n The final answer, of course, we need to consider. Due to the finiteness property mentioned above, this series of problems will cycle (i.e., at a point, logically equivalent formulas will appear), and even reach a fixed point due to the monotonicity property set forth. We obtain a result of the following form: "If there exists a length of..." N "If there is a sequence of length '0', then there exists a sequence of length '0'." It is easy to see that this also implies the existence of infinite sequences.

[0245] We will now only mention two additional points, which are clearly unique to this language in the case of decidable time logic: 1. Considered a programming specification language, these sequences are actually Output or state However, we also want to support lose enter This means we want to prove that for every input, there exists an output at every time point that is independent of future inputs. Time compatibility Therefore, we can deal with the form. The formula, where, x n , x n-1 These are the current input and the previous input, respectively, and for the output y... n , y n-1 The situation is similar. Observe the formula... Bounded backtracking (lookback) And observed n It can be viewed as a type The free variables are implicitly universally quantized. The quantifier patterns used for input and output will look like... It can be easily represented as a recursive relation similar to that described above, and the finiteness mentioned above is used again.

[0246] 2. GS is allowed to operate on the LTA of its own statements in the manner of NSO, therefore In a language without atomic business logic (BA), we are given a software specification language where inputs and outputs can be statements in that same language. This allows, for the first time, the support for implementations like, "If a software update does not meet certain expected properties, then reject the software update," where the currently running program is written in the same language as the update and supports those "expected properties." Therefore, it is a key factor in AI security. Fortunately, even decidability is preserved.

[0247] NSO: Zero-element second-order logic Based on what we have discussed above, we will present not only a language, but also a language extension mechanism, though this extension is not in the standard sense; that is, as we will see, formulas in the base language are not formulas in the extended language, but rather constant symbols within them. This extension preserves decidability, not to mention consistency. Further considering the extension of multiple languages ​​at once, and allowing languages ​​to coexist in a unified language, is indeed another feature of our construct, although of course, the interaction between these languages ​​is very limited. Multiple BAs can be easily referenced at once by considering the multi-class theory of BAs or product algebra.

[0248] Fixed arbitrary language ( Basic Logic The formulas (or statements) of these BAs constitute a BA in the sense of logical equivalence. We can then consider the theory of multiple classes of BAs interpreted in those BAs. The constants in the language are the formulas in the underlying logic. Quantization employs the same semantics as quantization of any element of a BA. If the underlying logic constitutes a non-atomic BA, then the extended language is decidably satisfiable if and only if the underlying logic is decidably satisfiable. Otherwise, a decidable model count is required, or more precisely, when considered as a BA, to determine whether an element is at least... n The precipitation of different atoms.

[0249] Depend on This indicates an extended language. We show... It can be used as the underlying logic. So far, every NSO formula is either true or false because it is interpreted within a fixed model (it is a BA, and the BA is the LTA of the underlying logic), and thus constitutes a small BA (with only two elements). To get from To obtain the atomless BA from the formula, we can simply enhance it with an infinite number of uninterpreted constant symbols. Having done this, we now let the interpreted constant be... Formulas appearing within curly braces (to avoid syntactic ambiguity) and quantifiers processed for decision-making can be handled using the non-atomic BA quantifier elimination algorithm. The basic syntax is therefore , in, Representation Language Any formula within it. Clearly, each bf can contain only variables and constants of the same type. const This refers to unexplained constants. The deepest formula within the nested curly braces will be... The formulas in the BA language, where the constants appearing are only 0 and 1, are then interpreted as formulas on any non-atomic BA, since they are all elementaryly equivalent. It is easy to see that by inductively traversing the depth of the curly braces, the decision-making process and semantics of the language are given.

[0250] 18 - Languages ​​GSSOTC We design a new, decidable family of time-series logics over infinite data values, where these values ​​possess a theory far richer than mere equality, particularly a theory of atomless Boolean algebras (and fixed finite Boolean algebras, although this does not imply significant novelty). Furthermore, the language possesses the unique ability to verify statements of the form "at every time point, for all inputs there exists a well-defined output / state that may depend on previous outputs / states." It also proposes a novel decision process independent of automata, tables, or any other decision method known to the inventors.

[0251] To describe the language in simple, intuitive terms: fix the atomless BA and consider the BA theory interpreted in this structure (with the interpretation constants as above, therefore the LTA of this logic is a countable atomless BA). Consider having free variables. The formula, where x It is understood as input, and y It is understood as output, and n It is any point in time (therefore it can be considered a type) (The free variables). Therefore, it describes the connections between current and previous inputs and outputs at each point in time. This is essentially a complete language.

[0252] This technology is applicable to any weak... - A categorical language, provided it supports conjunction and quantization. However, in the absence of atomic BAs, we acquire a unique property of the language: in the spirit of NSO, it can speak its own statements.

[0253] Time-compatible structure From a certain domain D The sequence of elements can be regarded as a function Therefore, the functions between sequences have type. As is the convention in many texts, [ k ] will represent a set .

[0254] If for all sequences p , s Functions between sequences yes Prefix (prefix-preserving) (or time-compatible, TC) ,if p yes s of strict prefix, then f ( p )yes f ( s ) strict Prefix. We also extend this concept to... .

[0255] length Time Compatibility (TC) architecture It is a prefix-preserving function domain D .

[0256] It should be clear that any computer program is a TC (Transcript-Cost) structure: at each point in time, it takes in input and outputs output, and the output may depend only on past and present inputs and outputs, not on future inputs and outputs. This is why we keep the prefix TC.

[0257] Because of the ability to “backtrack,” that is, to rely on previous inputs and outputs, we do not need the concept of a reference state, as it is contained within the concept of the output.

[0258] In the following text, unless otherwise stated, we will only deal with infinite-time TC structures (therefore, in the above definition) N = ∞).

[0259] We will eventually be interested in functions that convert from sequence tuples to sequence tuples (all tuples have a fixed finite size, but input tuples can have different sizes than output tuples). All definitions and results should be adapted as necessary.

[0260] This setting can be easily extended to trees rather than sequences. This is done by allowing more than one successor relationship, and the same approach applies.

[0261] If it exists m ≥ k ( recursion point ), so that for each n > m ,point n The output sequence at point depends only on point n -1, …, n - k The input and output sequences at the point and the points n If the input is at a certain point, then the TC function has a length of [value missing]. k ∈ Bounded backtracking (BL) (or simply BL)k ]).

[0262] If f is BL[k], then it can be represented as a pair of functions, one of which is the type. The function, another One is type The function, the other one, needs to be TC.

[0263] According to the definition of the BL function, we can... f Writing recursive relationship: , (in x (is the input sequence), and its initial condition is for 1 ≤ i ≤ k Having form .this g Has type And it is fully encoded along with the initial conditions (the behavior prior to the specified recursion point). f .

[0264] Given a pair of functions, one is of type The function, another (as) TC ) is a type For a function, we can uniquely assign it. BL [ k The function of ].

[0265] Bounded backtracking and recursive relations With 2 k Any formula with +2 free variables (in almost any logic) defines BL [ k The set of functions that may be empty.

[0266] For simplicity, assume k = 1. Consider .we will This can be understood as defining the input and output at the current time (respectively). x n , y n ) and the input and output of the previous time. x n-1 , y n-1 The relationship between them. Intuitively, if the expression is infinite... It is satisfiable, and alternatively, if it is true in the chosen model, then it defines at least one BL[ k The function. By considering the inclusion of all N , in the form of The first-order theory of all formulas can give the specific meaning of this infinite expression.

[0267] Note that in the infinite expression obtained in the proof, quantifiers can be pushed inside. This is a property of TC, and this ability is a key point in the upcoming construction. Also note that skolemization of this expression will produce something similar to the type described above.

[0268] The initial conditions are not expressed in the subsequent corollaries. However, the corollaries still hold. They define a set of functions, which includes functions for every possible initial condition. This is not an inherent limitation. We use this form at this stage only for simplicity.

[0269] Fixed backtracking parameters k ≥ 0. X j This will represent backtracking. k A tuple of variables, so it is of the form of k A tuple with +1 variable. We assume the first time coordinate is 0.

[0270] Given 2 k + 2 free variables formula (In almost any logic), by having a baseline case of Define recurrence relation .

[0271] Observed This actually indicates that the length is n + k There are BL[ between the sequences] k The function, where the sequence contains k The initial positions are reserved as free variables.

[0272] Notice, Having about n The form of monotonicity: if in length of n There exists a TC function between the sequences of +1, and this function satisfies Then for a length of n For a sequence of , such a function clearly exists.

[0273] Obviously, if for all n Established ,So Define the non-empty set of functions in the spirit of Corollary 29. The key to our construction lies in the following observation: if the underlying logic is weak... w- If it is a category, then under the sense of logical equivalence, there are only a finite number of... Therefore, the determineability and the determination process are instantaneous.

[0274] Guard the successors It was observed that by adding a class with successor relationships... s Natural numbers and function symbols and ,form The formula can also be given directly as BL[ k Semantics, where F It is required to preserve the prefix, and will writing .

[0275] Fixed Logic And make D It refers to the category it operates on. First, use function notation. and Expand it, where F Prefix preservation is required. If ψ If it is any formula in that extended language, then This defines the second extension of the language, which we should call... of Guardian Successor Expansion Sublanguages ​​of the following forms: Will be called Collapsed fragment Its sub-languages ​​in the following forms: Will be called Normalized fragment In all cases, the protector Each needs to be uniquely identified t i , t j The relative positions between them, and Only through application f , F (or several such functions) and involve At the same time, it can also f、F Applied to from The constant.

[0276] Will f、F Applied to from The constant corresponds to the initial conditions mentioned above.

[0277] Any formula in the guardian successor extension can be written as an equivalent satisfiable formula in the normalized fragment.

[0278] It is easy to see that we can always simplify this to folding fragments: this comes directly from the uniqueness of the successor, for example... and The same applies. For the normalized form, the formula is first converted to DNF at its outermost layer, so each literal can be a complex quantified formula. Then, quantifier alternation is folded as described above, so each quantified formula is either universal or existential. Moving to NNF, we can consider universal and existential literals instead of positive and negative literals. In each DNF clause, we can fold the universal part into a single part because the universal part is distributed on conjunction. Given an existential literal... At the same time, it means We introduce a flag as an additional output variable. e And write down , Where, assuming Therefore, the existence part is simplified to a single atom at the cost of introducing a new output stream and new universal literals, which can then be folded into a single literal as described above. Given multiple single-atom existence parts... We can easily see that they are equivalent to This is because each flag remains zero once it becomes zero, so there exists a point in time when all flags eventually become zero. Therefore, by qualifying this additional flag in the universal part, the existence part can be simply a single flag. In this way, we simplify both the universal part and the existential part into a single part.

[0279] Note that here we must use the infinite time structure we are dealing with (i.e.) N The assumption of (= ∞) is also required. In the case of finite time, we will also need an end-of-sequence predicate. This leads to a slightly more complex quantifier folding. For the sake of brevity, we have omitted this simple derivation here.

[0280] Any formula in the guardian successor extension of a time-existing quantifier can be expressed using the free variable BL. [ k ] form write.

[0281] We must, of course, remember that if a language is decidable and weak... w If the category is defined, then its extension using recursive relations is also decidable. Together with the methods for handling existential parts described in the next chapter, we arrive at the following conclusion: If the segment is from a determinable language The obtained, determineable language It is a weak w-category, so use categories. , guard Wei Houji, Function symbols and BL [ k ] By enhancing the function notation, the satisfiability of the formulas in the guardian successor extension is ensured. Sexuality is determinable.

[0282] We call this extended language GSSOTC[ ], where GSSOTC represents second-order time compatibility of the guardian successor. The second-order part is due to the following: given two sequences We can declare non-standard quantifier alternation. It will be translated into (So ​​far, it's just standard higher-order Scolemization), where F These are TC functions between sequences. When the formula is converted to free variable form, these functional quantifiers are eliminated, and then the free variable form is converted to a function-free recursive relation form.

[0283] The above describes some simple extensions of this language; we reiterate them and add more: string termination predicates. It has multiple successor relationships and therefore considers a tree rather than a sequence, has constant positions, and is therefore not, for example... Rather, we have, for example It has explicit second-order quantifiers, which are eliminated by simplification to recursive relations, and finally has richer quantifier alternation, such as for time. n All keyboard inputs at this location, duration n The memory state at that location makes it possible to determine the time... n All network inputs at that location, and so on, result in the form Quantification.

[0284] Judgment Method and Execution In the spirit of Note 24, we will have several input and output sequences, each sequence being called... flow (stream).

[0285] Given Where X is the input, Y is the output, and i represents the stream number, the following recurrence relation is defined: , so This refers to the existence of time points 0, …, n + k, starting from The model. Therefore, the recurrence relation. It is monotonous, that is And therefore has a fixed point. Using surface Show it. Given a time point with m time points. The model, given each input X at point m + 1. i Then output Y i will have There exists unbounded continuation if and only if Timely satisfaction 。

[0286] If and only if At that time, the size was n The +1 model exists. Release the first one. k With one more time point, we can write... , Because Chinese k + 1 Replace k get .exist In this case, then due to monotonicity, each time point k The +1 subsequence must satisfy Furthermore, any such subsequence can be arbitrarily expanded because it is indeed a fixed point.

[0287] The above formula shows that, when interpreted as defining the TC model, yes The paradigm.

[0288] When interpreted as a formula in the BA language, it is true if and only if any subsequence satisfies At that time, the TC structure is The model.

[0289] Given the input at each time point, we can substitute the known variables... This is used to calculate satisfactory output and resolve missing output. This is how the software specification in this language is executed. The software specification in this language can therefore be executed directly as is, using Oracle to determine satisfactory assignments to formulas in a non-atomic BA language. Finding satisfactory assignments to formulas in a non-atomic BA language is a topic in itself and is omitted here for brevity.

[0290] Given two formulas Then if and only if hour, The TC model set is ψA subset of the TC model set.

[0291] This provides us with a method for determining whether The algorithm, in which, , ψ It is considered a TC model set.

[0292] Combining this with the above, this inference provides us with a process for determining the empty state of a complete language GS. Each DNF clause will have a single universal and a single existence (which is a negative universal), so determining the emptiness of each clause boils down to the final inference.

[0293] because This refers only to the universal part, while the existential part can certainly constrain the model, so we should check at each time point during execution whether we can satisfy the existential part. If so, we have indeed satisfied them, but only once. If the formula is satisfiable, then such time points are guaranteed to exist. If there are multiple existential parts in the DNF clause, then for execution, we must compress them into one using the flags in the proof of 35, because those existential parts may depend on each other.

[0294] when It is understood as the GS formula, and In a non-atomic BA language interpreted within this BA of the GS formula (potentially having more algebraic meaning since the construction is closed under products), then NSO is a sub-language of this language. That would be a software specification language where inputs and outputs are simply statements in this language. In this way, we can support the software update mechanism described in the introduction as a key component of safe AI. Another way to look at it is: the robot is using a language... Programmed, and accepts the same language from the user. The command within the program now needs to check if the command conforms to, for example, security conditions. Unless It is a The input must be equipped with time logic based on BA theory; otherwise, it cannot do this.

[0295] complexity Tarski studied quantifier elimination in BA theory with constants of 0 and 1 by introducing what he called invariants. Kozen[3] extended the concept of these invariants and derived a complexity representation for decision problems. For infinite BA, it is for It is complete. Roughly speaking, this means that anything can be done in exponential time by means of an alternating Turing machine with a linear number of alternations. For a binary BA, it is simply a QBF, which is probably the most well-known PSPACE complete problem. For GS, we see that the number of formulas with a fixed number of free variables and constants is cubically exponential with respect to the number of free variables. This gives the upper bound of GS on atomless BAs.

[0296] We have proposed a novel approach in atomless BA theory that extends existing results from SBF to general BF. We also introduce the concept of weak ω-category theories and how these theories relate to the extension of decidable recurrence relations. Using these ideas, we construct a language that can speak about itself by abstracting its own statements into mere BA elements. We further extend this construction to novel temporal logic with several distinguishing capabilities.

[0297] 19 - Methods for eliminating functional quantifiers Now consider an algorithm that takes the formula from GSSOTC[L] and uses the algorithm from L[RR] (language L is enhanced with recurrence relations and potential additional extensions, as described above) to determine whether there exists some natural number N such that for all K ≥ N, there exists a sequence of length K satisfying the original formula. In particular, this will guarantee the existence of infinite sequences (or functions between sequences, e.g., from input to output in a time-compatible manner). Such an L[RR] algorithm can be used when language L is a weak ω-category.

[0298] The formulas in GSSOTC[L] are prefixes of time-compatible functional quantifiers, followed by the parent expression. For simplicity (and without loss of generality), we assume the parent expression is in disjunctive normal form (DNF). Therefore, its general form is: Each character Having form or form Additionally, each Q is " "or" "each" γ ij It is s, The conjunction of atoms on the surface uniquely determines their relative positions as described above, and It is any formula in language L. Each formula can depend on the application to... Univariate function Therefore, each function has a type. Note that functional quantifiers must appear as the outermost quantifier. This section deals with the universal case, and the existence of such quantifiers will be discussed in the next chapter.

[0299] The method here determines this by generating an equivalently satisfyable formula in L[RR]. Satisfactionability. This method produces a recurrence relation indexed by n, expressing "there exists a string of length n that satisfies the formula", and has free variables representing the first elements of the sequence (which will be quantized later to obtain the final answer). It is a recurrence relation because the existence of a string of length n can be derived from the expression of a string of length n. n The formula for the existence of strings containing -1 is recursively expressed, and this observation is crucial. In its simplest case, it can be expressed in the form... And other possible forms. If L is a weak ω-category, then the L[RR] formula, which is essentially equivalent to the L formula, can be obtained by definition.

[0300] When a constant appears in the formula, for example s (5, n ), The number of free variables in the sequence cannot be less than the maximum constant, because these free variables represent the beginning of the sequence. Then, a join operation is performed. With those conditions, and then quantifying the free variables, we can implement the initial conditions for the sequence from the original formula. This should happen for each n in the cyclic sequence of the formula. In particular, due to the weak ω-category assumption, there exist positive integers N and K such that Therefore, they should be addressed separately. Verify these initial conditions.

[0301] The formula can be interpreted as discussing finite or infinite strings. If the symbols... If not used, then an infinite string exists if and only if there exists any finite string of sufficiently large length. Given the method here, this is easily checked. If the symbol... If used, it can be used to check whether the formula requires the string to be finite. Specifically, it can be used to check whether the formula implies another formula. This is because the methods described here (including in the following sections) can be used to determine logical results. Furthermore, the original formula can be concatenated with the negation of the subsequent formula, thus implementing only infinite strings.

[0302] 20 - Boolean Combinations of Model Sets Given the form and The two formulas have simple disjunctions. .

[0303] This disjunction is not The latter formula expresses "there exists a string such that, at any position, Establishment or ψConditions of the form "true". However, it is sometimes useful to express a Boolean combination of model sets (strings) as in the previous formula and ask whether that Boolean combination is empty. The intersection corresponds exactly to the conjunction of the formula, but not for negation and disjunction.

[0304] Determining whether a Boolean combination of model sets (each model set expressed as a formula) is empty can be done as follows. Assume the formulas are given in DNF. Then, the intersection of the literals collapses into individual literals (i.e., literals represented by a single formula). The emptiness of this DNF can be determined by checking whether each individual DNF clause is empty. Therefore, it is sufficient to determine the emptiness of combinations of the following forms: ,in The formula is interpreted as a set of models. This is also done by converting it to L[RR]. For each ,Will Defined as a recursive relation indexed by n, it expresses "there exists a string of length n such that..." It holds true at every position, and for all i, if i ∈ S ,but ψ i "Failed at some point." In some embodiments, The free variables are the values ​​at the initial positions (all as described above), and there may be N constrained variables. Potential additional variables must be 0 or 1. Additional variables do not need to be... Only η n Because those variables encode S. Then by checking... The satisfiability of a function is used to determine its emptiness. In its simplest form, and in the case of a function symbol having one input and one output, and a backtracking function having a single input and a single output, η look like , in, Partially indicating the relevant ψ It failed at the initial position, and partially This indicates that they failed at some other location.

[0305] 21 - Revision and Enforcement Consider the following example: A program collects knowledge from a user (as input) and adds it to an internal knowledge base. Sometimes, the user might input a piece of knowledge that is inconsistent with previous knowledge. However, in GSSOTC, backtracking is bounded, making it impossible to express backtracking to all past inputs and making decisions based on them. A remedy for this is introduced by extending the language with what can be called a "forcing operator."

[0306] First, consider the procedure for adding knowledge to the knowledge base: , in, x n This is the current knowledge base. x n-1 It is the previous knowledge base, and y n This is the current input. The goal is to force the knowledge base to remain consistent, which can be written as: , It uses forced operators F This means that during execution, the extra-logical engine (when a mandatory condition needs to be met) will be invoked to perform an arbitrary operation (e.g., displaying all previous inputs to the user and asking the user to edit them to satisfy the condition). x n ≠ 0). In the consistency check of this GSSOTC formula, it is assumed that... x n ≠ 0, which relies on super-logic operations (whatever they may be) to force the condition to be true.

[0307] In a more general sense, formulas that include the coercive operator F, for example , Consistency is checked by simplifying it to examine the consistency of the following expression: .

[0308] 22 - Embedded Execution Based on the teachings of NSO above, GSSOTC can take statements from within GSSOTC itself as input and output. Sometimes, it is useful to take a GSSOTC program as input and execute it. This can be expressed in the following form: This means "execute input" x n However, execution itself is clearly not expressible in GSSOTC and needs to be treated as a superlogic operation. Therefore, assume E returns 0 or 1, depending on whether the execution succeeded. Note that... x n It may be traced back to what has already been done. At the computational state, consistency is therefore relative to higher-level procedures. The consistency check is now straightforward: simply rewrite the formula so that E returns either 0 or 1, and check for consistency as usual. The hyperlogic engine executes this and returns either 0 or 1.

[0309] 23 - Examples of Software Specification Languages Consider the example given in the NSO discussion above (sections 11-13). It involves the conditions for accepting software updates. However, the language in this case needs not only to support the checking of updates but also to be rich enough to serve as a software specification language. A key point about what constitutes a software specification language is the so-called "temporal logic," which is capable of expressing things in the form of "do this first, then do that." Furthermore, inputs and outputs should be considered and distinguished from each other (something not supported in many temporal logics). The temporal logic here allows for the description of processes with inputs and outputs (e.g., software) and further verifies that a [temporally compatible] output exists for each input. Moreover, this temporal logic supports specification languages ​​that can process statements themselves, as it can be readily considered as a non-atomic Boolean algebra. Using the techniques in the NSO example allows for checkable updates in a language rich enough to express software.

[0310] 24 - Tau 1.0 Language Overview We are now going to define a language that includes all the extensions in this monograph, namely the Tau language. The Tau language is not a single language: it depends on which fundamental logic we extend. Therefore, it consists of the following: (1) Take GSSOTC on BA as: (a) Basic logic, (b) The Tau formula itself (where the model is a time-compatible function between sequences). (c) The NSO formula in basic logic, (d) Having a free variable that makes its quantifier simple, as described above. (e) All BF, SBF and their higher-order counterparts in those BAs.

[0311] (2) In the GSSOTC layer and NSO layer, the following is supported: (a) Cartesian product, (b) Relationship with the converse proposition, (c) Simple quantifiers, (d) An infinite number of homomorphic and semi-homomorphic symbols in the signature. (e) Infinite operations as described, (f) Recurrence relation, (g) An unlimited number of uninterpreted constant symbols to allow the definition of “terms”.

[0312] (3) The most important basic BA is: (a) All finite BAs whose bitwise operations are encoded as integers and logically implement addition. (b) All finite BAs of order 22n encoded as a finite number of variables, while syntactically supporting substitution and combination. (c) Their higher-order counterparts, (d) Countable non-atomic BA SBF.

[0313] table The basic idea is to support functions. 2 n → B ,in B It is any BA supported in the Tau language (including product algebras of its algebras). This encodes a set of tuples (in the case of products, or 1-tuples if no products are used), where each tuple has n The identifier for the bit (possibly taken from the prefix code). Since all keys in this formula have values, we set the default value to zero. It's easy to see how this could be implemented directly in the Tau language, but we're interested in fixing some syntactic sugar that would lead to implementation optimizations. The first type of atomic formula has the following form: , This means the table T 1 is just a table T 2, where the key k The value in was set to v It overwrites any previous value. It is a conservative extension because it can be expressed as , in, T 1. T 2 has the BF type.

[0314] Even a more concise way to express it is that it has a form. , so key It has n The SBF of each variable. Then, the above atomic formula can be expressed as .

[0315] For another atomic formula: , This means T 1 contains T 2 satisfies the formula All values v This can be easily expressed again as .

[0316] Another atom formula will be , This is an abuse of symbols, and is intended to indicate: take T China satisfies All values v and equate their conjunction with u Therefore, we first use select, and then we are left with the calculation. It can be expressed as , However, to avoid formulas of exponential length, we can write out the recurrence relation. , Furthermore, if the implementation allows users to specify that certain recurrence relations will only be expanded during runtime, it is easy to see that in many cases, the execution of such recurrence relations will not take exponential time. Clearly, the recurrence relations will have to be expanded to also iterate over a fixed span of the argument identifier.

[0317] Next, we turn to the intersection and symmetric difference of tables that are considered sets of tuples. For the intersection: , We can express it as And the situation is similar for symmetric differences. Next, we turn to point-by-point Boolean operations in the table. This is easily achieved through simple... This can be achieved through methods such as... Even key quantization is unnecessary, as this aligns with typical Boolean operations on BF.

[0318] For internal optimization, we transform the formulas into implication form, where these new atomic formulas are the only formulas in the implication terms. This can be done in CNF and BDD form. When the condition is triggered, the internal table modification is performed.

[0319] Point-by-point correction Given a Tau specification (spec), we can execute candidate programs that satisfy that specification. Suppose we want to support a "software update" feature. Another use case for this scenario is a bot that accepts commands from users, which are simply changes to the specification, and the bot itself is programmed in Tau. To support this, we add an update hyperlogic operation: whenever an output stream is assigned a non-zero Tau BA element, it automatically becomes the new specification, and the execution backend stops executing the current specification and continues running the new specification ("update").

[0320] However, each specification may have many programs that satisfy it. How do we choose a program? We combine the answer to this question with the answer to another question: Suppose that the update (or the bot's command) is only intended to make a certain change or addition, and we don't want users to specify the entire program or bot behavior from scratch with every update. This situation is mitigated through what we call pointwise modification. Given two Tau formulas... and ,in x It is an input stream, and y It's an output stream (and there's no backtracking, but this is for the sake of generality (wlog) and for simplicity), through... To define , This is read as follows: at each time point n At this point, there may be many possible outputs that satisfy the specification. y n We choose to always meet ψ The output is what we prefer and are satisfied with. The output of the new specification. This means that, as long as the new specification is satisfied, it will take as much of the behavior from the old specification as possible, and in fact, this retention can easily be considered to be the maximum.

[0321] The above setup is further enhanced in the appropriate place. Instead of assigning the new specification to the output stream, we assign it a formula with a dedicated uninterpreted constant, which is typed as an element of Tau BA. Then, all possible interpretations of that constant are acceptable updates. To perform pointwise correction, we need to choose an interpretation. We are free to choose either [close to] the maximum solution or [close to] the minimum solution (see, for example, Lemma 3.4). The former will preserve as much of the previous specification as possible, while the latter will preserve as little of the previous specification as possible.

[0322] A broad extension of this concept is as follows. From the perspective that the situation does not present a time-compatible output for every input, it is possible... ψ It's unsatisfactory. However, it's possible that for some inputs, there are indeed outputs, in which case we would prefer them over others. The output of , but in addition to that we can use Therefore, the extended operator is .

[0323] Example Implementation (A1) In some embodiments, a method is performed at a computing device having one or more processors and memory. The memory stores computer instructions configured for execution by one or more processors. The method includes: (i) receiving user input specifying software requirements for a program, the software requirements being expressed as statements in a time-form language with guarded successor GSSOTC(L). , among the statements Includes time input variables; (ii) determines whether for each time input y n Existence satisfies Corresponding output x n ,in x n-1 It is the output from a previous time point; and (iii) according to the determination for each input y n Existence satisfies Corresponding output x n An instance of executing a program that meets the software requirements.

[0324] (A2) In some embodiments of (A1), L is the base formal language, and GSSOTC(L) is an extension of L with a guarded successor.

[0325] (A3) In some embodiments of (A1) or (A2), each input y n These are statements in the formal language GSSOTC(L).

[0326] (A4) In some embodiments of any of (A1)-(A3), one or more inputs y n These are statements in the basic language L.

[0327] (A5) In some embodiments of any of (A1)-(A4), each output x n These are statements in the formal language GSSOTC(L).

[0328] (A6) In some embodiments of any of (A1)-(A5), one or more outputs x n These are statements in the basic language L.

[0329] (A7) In some embodiments of any of (A1)-(A6), an instance of the executing program includes receiving input from a user for a certain positive integer m. y 1 , y2 , …, y m .

[0330] (A8) In some embodiments of any of (A1)-(A7), instances of executing the program include displaying data on a display screen of a computing device, storing output data in a memory of a computing device, or transmitting output data to a remote device using a network interface of a computing device.

[0331] (A9) In some embodiments of any of (A1)-(A8), each statement in GSSOTC(L) includes a prefix of a time-compatible functional quantifier, followed by a formal language mother formula consisting of quantifierless formulas.

[0332] (A10) In some embodiments of (A9), the method further includes placing the statement Equivalent statements in GSSOTC(L) as disjunctive normal form .

[0333] (A11) In some embodiments of (A10), equivalent statements Having form Each function quantifier yes" "or" ", each function It is a unary function whose domain is the set of consecutive positive integers at specified positions, and each literal... Having form or .

[0334] (A12) In some embodiments of (A11), each formula γ ij It is the conjunction of positive atomic formulas using the successor predicate s() and / or the last position predicate #(), where the successor predicate s() is defined by s(a,b) if and only if a = b+1, and the last position predicate #() is defined by #(a) if and only if a is in the last position in the sequence.

[0335] (A13) In some embodiments of (A12), for each formula γ ij ,formula γ ij The successor predicate s() used uniquely determines the position indicator. The relative position.

[0336] (A14) In some embodiments of (A11), each formula It is a formula in the formal language L, which can depend on the position identifier applied. Univariate function .

[0337] (A15) In some embodiments of any of (A1)-(A14), it is determined whether for each time input y n Existence satisfies Corresponding output x n include: For the statement , exist L Constructing equivalent satisfiable formulas in [RR] based on recurrence relations in formal language L. ;and Determine if the equivalent can satisfy the formula Satisfactionability.

[0338] (A16) In some embodiments of (A15), it is determined that the equivalent formula can be satisfied. Satisfiability includes expanding the equivalent satisfiability formula. The recursive relationship in the text.

[0339] (A17) In some embodiments of (A16), expanding the recursive relationship includes identifying fixed points.

[0340] (A18) In some embodiments of any of (A1)-(A17), it is determined whether for each time input y n Existence satisfies Corresponding output x n include: For the statement , exist L Construct a set of recursive relations in [RR]; and The statement is determined based on this set of recursive relations. Satisfactionability.

[0341] (A19) In some embodiments of any of (A1)-(A18), the statement Including conditions The forced function F, and F performs a superlogic operation on the computing device to guarantee the condition. Established.

[0342] (B1) In some embodiments, a method for verifying software updates is performed by a software system installed on a computing device having one or more processors and a memory storing one or more programs configured for execution by the one or more processors. The method includes: (i) receiving candidate software updates for a software system, wherein both the software system and the candidate software updates are expressed in an extended formal language, which is an extension of one or more basic formal languages, wherein statements in each basic formal language form elements in a Boolean algebra in a logically equivalent sense, the Boolean algebra having a false element 0 representing a false value and a true element 1 representing a true value, wherein the extended formal language includes a first-order theory of Boolean algebras interpreted in the Boolean algebras generated by each basic formal language, the basic formal languages ​​being extended to include a plurality of constant symbols, each constant symbol corresponding to a corresponding logical expression in each basic formal language. Equivalence class, wherein the extended formal language and each basic formal language are regarded as Boolean algebras under logical equivalence, and are elementaryly equivalent under the Boolean algebra signature, wherein the candidate software update corresponds to the update statement u in the extended formal language; (ii) compute the truth value of uc'=0 in the extended formal language for the condition element c that specifies the condition for verifying the candidate software update, wherein uc' is the logical conjunction of the logical negation of u and c; (iii) reject the candidate software update based on the determination that uc'=0 is false; and (iv) accept the candidate software update based on the determination that uc'=0 is true, and install the candidate software update on the computing device.

[0343] (B2) In some embodiments of (B1), the Boolean algebra for each basic formal language is non-atomic.

[0344] (B3) In some embodiments of (B1) or (B2), the Boolean algebra of the extended formal language and each of the basic formal languages ​​are isomorphic.

[0345] (B4) In some embodiments of any of (B1)-(B3), condition c is a combination of different individual conditions, each of which needs to be satisfied so that the candidate software update is verified and accepted.

[0346] (B5) In some embodiments of any of (B1)-(B4), the candidate software update includes an update of condition element c.

[0347] (B6) In some embodiments of (B5), if a candidate software update is accepted, the step of installing the candidate software update on the computing device includes replacing condition element c with an updated condition element d in the extended formal language, which specifies the updated conditions for verifying subsequent candidate software updates.

[0348] (B7) In some embodiments of (B6), the method further includes: (i) receiving a subsequent candidate software update for the software system, wherein the subsequent candidate software update is expressed in an extended formal language; (ii) calculating the truth value of ud'=0 in the extended formal language, wherein ud' is the logical conjunction of the logical negation of u and d; (iii) rejecting the subsequent candidate software update based on the determination that ud'=0 is false; and (iv) accepting the subsequent candidate software update based on the determination that ud'=0 is true, and installing the subsequent candidate software update on a computing device.

[0349] (B8) In some embodiments, a non-transitory computer-readable storage medium stores instructions thereon that, when executed by one or more processors of a computing device, cause the one or more processors to perform any one of (B1)-(B7) of the method.

[0350] (C1) In some embodiments, a software system verifies software updates to the software system, the software system being installed on a computing device having one or more processors and memory, the memory storing one or more programs configured for execution by one or more processors. The software system is configured to: (i) receive candidate software updates for the software system, wherein both the software system and the candidate software updates are expressed in an extended formal language, which is an extension of one or more basic formal languages, wherein statements in each basic formal language form elements in a Boolean algebra in a logically equivalent sense, the Boolean algebra having a false element 0 representing a false value and a true element 1 representing a true value, wherein the extended formal language includes a first-order theory of Boolean algebras interpreted in the Boolean algebras generated by each basic formal language, the basic formal language being extended to include a plurality of constant symbols, each constant symbol corresponding to a statement in each basic formal language. (i) Logically equivalence class, where the extended formal language and each basic formal language are considered Boolean algebras under logical equivalence, and are elementaryly equivalent under the Boolean algebra signature, where the candidate software update corresponds to the update statement u in the extended formal language; (ii) compute the truth value of uc'=0 in the extended formal language for the condition element c that specifies the condition for verifying the candidate software update, where uc' is the logical conjunction of the logical negation of u and c; (iii) reject the candidate software update based on the determination that uc'=0 is false; and (i) accept the candidate software update based on the determination that uc'=0 is true, and install the candidate software update on the computing device.

[0351] (D1) In some embodiments, a method verifies a knowledge system. The method is executed at a computing device having one or more processors and a memory storing one or more programs configured for execution by the one or more processors. The method includes: (i) storing a plurality of interrelated facts represented by various knowledge statements in the knowledge system, wherein the knowledge statements are expressed in an extended formal language, which is an extension of one or more basic formal languages, wherein the statements in each basic formal language form elements in a Boolean algebra in a logically equivalent sense, the Boolean algebra having a false element 0 representing a false value and a true element 1 representing a true value, wherein the extended formal language includes a first-order theory of Boolean algebras interpreted in the Boolean algebras generated by each basic formal language, the basic formal language being extended to include a plurality of constant symbols, each constant symbol corresponding to a corresponding logical equivalence class of the statements in each basic formal language, wherein the extended formal language and Each basic formal language is considered a Boolean algebra under logical equivalence and is elementaryly equivalent under the Boolean algebra signature; (ii) for each of multiple pairs of elements in an extended formal language, wherein each pair includes a first element x representing a corresponding first knowledge statement and a second element y representing a corresponding second knowledge statement, the corresponding first knowledge statement representing a first fact among multiple interrelated facts in the knowledge system, and the corresponding second knowledge statement representing a corresponding second fact among multiple interrelated facts in the knowledge system, evaluate the expression xy=0, where xy is the logical conjunction of x and y; and (iii) based on the determination that there exists a pair of elements satisfying xy=0, determine that the knowledge system has stored inconsistent facts.

[0352] (E1) In some embodiments, a method for verifying contract stipulations is executed at a computing device having one or more processors and a memory storing one or more programs configured for execution by one or more processors. The method includes: (i) receiving a contract specified as a plurality of terms represented by various clause statements, wherein the clause statements are expressed in an extended formal language, which is an extension of one or more basic formal languages, wherein the statements in each basic formal language form elements in a Boolean algebra in a logically equivalent sense, the Boolean algebra having a false element 0 representing a false value and a true element 1 representing a true value, wherein the extended formal language includes a first-order theory of Boolean algebras interpreted in the Boolean algebras generated by each basic formal language, the basic formal language being extended to include a plurality of constant symbols, each constant symbol corresponding to a corresponding logical equivalence class of the statements in each basic formal language, wherein... The extended formal language and each of the basic formal languages ​​are considered Boolean algebras under logical equivalence and are elementaryly equivalent under the Boolean algebra signature; (ii) for each of multiple pairs of elements in the extended formal language, wherein each pair includes a first element x representing a corresponding first clause statement and a second element y representing a corresponding second clause statement, the corresponding first clause statement representing a first clause in a contract and the corresponding second clause statement representing a corresponding second clause in a contract, the expression xy=0 is evaluated, where xy is the logical conjunction of x and y; and (iii) based on the determination that there exists a pair of elements satisfying xy=0, it is determined that the contract has inconsistent provisions.

[0353] Many modifications may be made to the described examples without departing from the scope of the appended claims.

[0354] The terminology used in the description of the invention herein is for the purpose of describing particular embodiments only and is not intended to limit the invention. As used in the description of the invention and the appended claims, the singular forms “a,” “an,” and “the” are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will also be understood that the term “and / or” as used herein refers to any and all possible combinations of one or more of the associated listed items and includes such combinations. It will also be understood that the terms “comprises” and / or “comprising,” when used in this specification, specify the presence of the stated features, steps, operations, elements, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, elements, components, and / or groups thereof.

[0355] For purposes of explanation, the foregoing description has been given with reference to specific embodiments. However, the illustrative discussion above is not intended to be exhaustive or to limit the invention to the precise forms disclosed. Many modifications and variations are possible in light of the above teachings. The embodiments have been chosen and described in order to best explain the principles of the invention and its practical application, thereby enabling those skilled in the art to best utilize the invention and its various embodiments with various modifications suited to the particular intended use.

Claims

1. A symbolic artificial intelligence method executed at a computing device having one or more processors and a memory, the memory storing one or more programs configured for execution by the one or more processors, the method comprising: A first-order language (logic) that recognizes atomless Boolean algebra B and Boolean algebras, the language having constant symbols 0 and 1 and extended with multiple additional constant symbols, each of which is uniquely interpreted as a corresponding element of B; Access expressions written in an extended first-order language, wherein the expressions have one or more logical quantifiers; Select the innermost quantifier with the quantified variable x, and if necessary, transform the expression such that the innermost quantifier is an existential quantifier; Identify the subexpression f to which the innermost quantifier of the expression is applied; The subexpression f is considered as having one or more DNF clauses. c i The disjunctive normal form, where each DNF clause consists of a conjunction of one or more literals, each literal being (a) a literal. p ij ( x (a) = 0 or (b) negative literal n ij ( x )≠0; For each DNF clause c i : - Form a single alternative body text using the following methods p i ( x =0: (a) When there is at least one literal, all literals in the corresponding DNF clause will be... p ij ( x )=0 combined into a single body character (a) or (b) when there is no at least one literal, designate the single substituted literal as 0=0; - Construct the corresponding output clause in the following form: , or , or ; The innermost quantifier is eliminated by constructing a modified expression by replacing the innermost quantifier and the subexpression f with the disjunction of the DNF output clause; and The computing device provides output showing the modified expression with fewer quantifiers than the original expression.

2. The method according to claim 1, wherein: When the modified expression contains one or more quantifiers, the selection, identification, consideration, formation, and construction are repeated for each DNF clause, and construction is performed until the modified expression no longer has any remaining quantifiers, thereby producing a final modified expression without quantifiers. and Providing the output on the computing device includes showing the final modified expression without quantifiers.

3. The method according to claim 2, wherein, The final modified expression is logically equivalent to the expression in question.

4. The method of claim 2, further comprising calculating the truth value of the final modified expression and displaying the truth value of the final modified expression on a display of the computing device.

5. The method according to claim 1, wherein, The method includes displaying data on the display screen of the computing device, storing output data in the memory of the computing device, and / or transmitting the output data to a remote device using the network interface of the computing device.

6. The method according to claim 1, wherein, The plurality of additional constant symbols includes an infinite number of symbols.

7. The method of claim 1, further comprising identifying a method for determining whether a Boolean combination of elements of B corresponding to constant symbols of the language results in 0.

8. The method according to claim 1, wherein, Each of the one or more logical quantifiers is an existential quantifier or a universal quantifier.

9. The method of claim 8, comprising: Transform the expression when the innermost quantifier selected is a universal quantifier.

10. The method according to claim 1, wherein, Each text p ij ( x )=0 and each negative literal n ij ( x )≠0 including the first part p ij ( x )or n ij ( x The first part p ij ( x )or n ij ( x ) is the corresponding Boolean combination of the following items: (a) a variable, (b) the constant symbols 0 and 1, and (c) the additional constant symbols.

11. The method according to claim 1, wherein, The disjunction normal form of the subexpression f is: 。 12. A computing device having one or more processors and a memory, the memory storing one or more programs configured to be executed by the one or more processors, the one or more programs including instructions for: A first-order language (logic) that recognizes atomless Boolean algebra B and Boolean algebras, the language having constant symbols 0 and 1 and being extended with multiple additional constant symbols, each of which is uniquely interpreted as a corresponding element of B; Access expressions written in an extended first-order language, wherein the expressions have one or more logical quantifiers; Select the innermost quantifier with the quantified variable x, and if necessary, transform the expression such that the innermost quantifier is an existential quantifier; Identify the subexpression f to which the innermost quantifier of the expression is applied; The subexpression f is considered as having one or more DNF clauses. c i The disjunctive normal form, where each DNF clause consists of a conjunction of one or more literals, each literal being (a) a literal. p ij ( x (a) = 0 or (b) negative literal n ij ( x ) ≠ 0; For each DNF clause c i : - Form a single alternative body text using the following methods p i ( x =0: (a) When there is at least one literal, all literals in the corresponding DNF clause will be... p ij ( x )=0 combined into a single body character (a) or (b) when there is no at least one literal, designate the single substituted literal as 0=0; - Construct the corresponding output clause in the following form: , or , or ; The innermost quantifier is eliminated by constructing a modified expression by replacing the innermost quantifier and the subexpression f with the disjunction of the DNF output clause; and The computing device provides output showing the modified expression with fewer quantifiers than the original expression.

13. The computing device according to claim 12, wherein: When the modified expression contains one or more quantifiers, the selection, identification, consideration, formation, and construction are repeated for each DNF clause, and construction is performed until the modified expression no longer has any remaining quantifiers, thereby producing a final modified expression without quantifiers. and Providing the output on the computing device includes showing the final modified expression without quantifiers.

14. The computing device according to claim 13, wherein, The final modified expression is logically equivalent to the expression in question.

15. The computing device according to claim 13, wherein, The one or more programs further include instructions for: calculating the truth value of the final modified expression and displaying the truth value of the final modified expression on a display of the computing device.

16. The computing device according to claim 12, wherein, The one or more programs also include instructions for: displaying data on the display screen of the computing device, storing output data in the memory of the computing device, and / or transmitting output data to a remote device using the network interface of the computing device.

17. The computing device according to claim 12, wherein, The plurality of additional constant symbols includes an infinite number of symbols.

18. The computing device according to claim 12, wherein, Each of the one or more logical quantifiers is an existential quantifier or a universal quantifier, and the one or more procedures include instructions for transforming the expression when the innermost selected quantifier is a universal quantifier.

19. The computing device according to claim 12, wherein, Each text p ij ( x )=0 and each negative literal n ij ( x )≠0 including the first part p ij ( x )or n ij ( x The first part p ij ( x )or n ij ( x ) is the corresponding Boolean combination of the following items: (a) a variable, (b) the constant symbols 0 and 1, and (c) the additional constant symbols.

20. The computing device according to claim 12, wherein, The disjunction normal form of the subexpression f is: 。 21. A symbolic artificial intelligence method executed at a computing device having one or more processors and a memory, the memory storing one or more programs configured for execution by the one or more processors, the method comprising: A first-order language (logic) that recognizes atomless Boolean algebra B and Boolean algebras, the language having constant symbols 0 and 1 and being extended with multiple additional constant symbols, each of which is uniquely interpreted as a corresponding element of B; Access expressions written in an extended first-order language, wherein the expressions have one or more logical quantifiers; Select the innermost quantifier with the quantified variable x, and when the innermost quantifier is not an existential quantifier, transform the expression such that the innermost quantifier is an existential quantifier; Identify the subexpression f to which the innermost quantifier of the expression is applied; The subexpression f is considered as having one or more DNF clauses. c i The disjunctive normal form, where each DNF clause consists of a conjunction of one or more literals, each literal being (a) a literal. p ij ( x (a) = 0 or (b) negative literal n ij ( x )≠0; For each DNF clause c i : - Form a single alternative body text using the following methods p i ( x =0: (a) When there is at least one literal, all literals in the corresponding DNF clause will be... p ij ( x )=0 combined into a single body character (a) or (b) when there is no at least one literal, designate the single substituted literal as 0=0; - Construct the corresponding output clause in the following form: , or , or ; The innermost quantifier is eliminated by constructing a modified expression by replacing the innermost quantifier and the subexpression f with the disjunction of the DNF output clause; and The truth value t of the modified expression is calculated, and when t is true, a command corresponding to the expression is executed, wherein executing the command includes providing output on the computing device, performing a calculation, initiating a workflow, and / or modifying the verification rules for the computing device.

22. A symbolic artificial intelligence method executed at a computing device having one or more processors and a memory, the memory storing one or more programs configured for execution by the one or more processors, the method comprising: A first-order language (logic) that recognizes atomless Boolean algebra B and Boolean algebras, the language having constant symbols 0 and 1 and being extended with multiple additional constant symbols, each of which is uniquely interpreted as a corresponding element of B; Access expressions written in an extended first-order language, wherein the expressions have one or more logical quantifiers and specify whether to accept software updates on the computing device; Select the innermost quantifier with the quantified variable x, and when the innermost quantifier is not an existential quantifier, transform the expression such that the innermost quantifier is an existential quantifier; Identify the subexpression f to which the innermost quantifier of the expression is applied; The subexpression f is considered as having one or more DNF clauses. c i disjunctive paradigm , i∈I Each DNF clause consists of a conjunction of one or more literals, each literal being (a) a literal. p ij ( x )=0, j∈J 1 , or (b) negative text n ij ( x )≠ 0, j∈J 2 ; For each DNF clause c i : - Form a single alternative body text using the following methods p i ( x =0: (a) When there is at least one literal, all literals in the corresponding DNF clause will be... p ij ( x )=0, j∈J 1 Combined into a single body text (a) or (b) when there is no at least one literal, designate the single substituted literal as 0=0; - Construct the corresponding output clause in the following form: , or , or ; The innermost quantifier is eliminated by constructing a modified expression by replacing the innermost quantifier and the subexpression f with the disjunction of the DNF output clause; and The truth value t of the modified expression is calculated, and when t is true, the software update is installed on the computing device.