IP Library Granted Patent US 7,743,351
Granted Patent B2
US 7,743,351 · App. 11/122,109 · Granted Jun 22, 2010

Checking the robustness of a model of a physical system

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,743,351
App. No.
11/122,109
Granted
Jun 22, 2010
Kind
B2
Abstract

The invention provides a system and a method for verifying the robustness of a model of a physical system, the method comprising the following steps: defining a first model of the physical system comprising a set of components and at least one input interface for inserting input values, said first model being defined in a formal language describing the behavior and the function of each of said components; defining in the formal language a determined property that must be satisfied by the model of the physical system; defining in the formal language a second model corresponding to the first model and enriched by a fault injection mechanism; and using formal proof means to search automatically for a combination of injected faults and/or input values that causes said determined property to fail.

Claims (29)

1. A method of verifying the robustness of a model of a physical system, the method comprising the following steps:

defining a first model of the physical system comprising a set of components and at least one input interface for inserting input values, said first model being defined in a formal language describing the behavior and the function of each of said components;

defining in the formal language a determined property that must be satisfied by the model of the physical system;

using a computer system executing formal proof software stored on computer-readable media to search automatically for a combination of input values that causes said determined property to fail relative to said first model;

providing a diagnosis comprising sequences of input values in case said determined property fails relative to the first model;

correcting the first model so that said determined property is verified to be true relative to the first model;

defining in the formal language a second model of the physical system corresponding to the first model and enriched by a fault injection mechanism if no combination of input values that causes said determined property to fail is found and said determined property has already been verified to be satisfied relative to the first model; and

using a computer system executing formal proof software stored on computer-readable media to search automatically for a combination of injected faults and/or input values that causes said determined property to fail relative to the second model.

2. A method according to claim 1 , wherein the fault injection mechanism comprises injecting at least one fault into the second model via a fault input interface.

3. A method according to claim 2 , wherein the fault injection mechanism further comprises a description in the formal language of at least one effect of said at least one fault on the function or the behavior of each of the components of said physical system.

4. A method according to claim 1 , wherein the determined property is considered as being true relative to the second model when the formal proof software can find no combination of injected faults and/or input values that causes said determined property to fail.

5. A method according to claim 4 , wherein the model of the physical system is considered as being robust relative to said determined property.

6. A method according to claim 1 , wherein the determined property is considered as being false relative to the second model when the formal proof software finds at least one combination of injected faults and/or input values that causes said determined property to fail.

7. A method according to claim 6 , wherein said combination of injected faults and/or input values causing the determined property to fail corresponds to a scenario that can enable the model of the physical system to be corrected to make it more robust.

8. A method according to claim 1 , wherein the combination of faults is selected from a predefined set of faults.

9. A method according to claim 1 , wherein the determined property expresses a state or a behavior of said physical system.

10. A method according to claim 9 , wherein the determined property is a safety property of said physical system.

11. The method of claim 1 , wherein the first model of the physical system is an electronic system comprising at least one computer for controlling an engine.

12. A system for verifying the robustness of a model of a physical system, the system comprising:

a first model defining the physical system and comprising a set of components and at least one input interface for inserting input values, said first model being defined in a formal language describing the behavior and the function of each of said components:

a predetermined property defined in the formal language that must be satisfied by the model of the physical system;

a computer executing formal proof software for searching automatically for a combination of input values that causes said determined property to fail relative to the first model;

means for providing a diagnosis comprising sequences of input values in case said determined property fails relative to the first model;

means for correcting the first model so that said determined property is verified to be true relative to the first model;

a second model of the physical system defined in the formal language, the second model corresponding to the first model enriched by a mechanism for injecting faults, said second model being defined if the computer executing formal proof software finds no combination of input values that causes said determined property to fail and said determined property has already been verified to be satisfied relative to the first model; and

a computer executing formal proof software for searching automatically for a combination of injected faults and/or input values that causes said determined property to fail relative to the second model.

13. A system according to claim 12 , wherein the mechanism for injecting faults comprises a fault input interface and fault applier means.

14. A system according to claim 12 , wherein the physical system is an electronic system comprising two computers for controlling an airplane engine.

15. The system of claim 12 , wherein the first model of the physical system is an electronic system comprising at least one computer for controlling an engine.

Assignments (5)
CORRECTIVE ASSIGNMENT TO CORRECT THE COVER SHEET TO REMOVE APPLICATION NOS. 10250419, 10786507, 10786409, 12416418, 12531115, 12996294, 12094637 12416422 PREVIOUSLY RECORDED ON REEL 046479 FRAME 0807. ASSIGNOR(S) HEREBY CONFIRMS THE CHANGE OF NAME. Recorded Aug 24, 2018
From: SNECMA
To: SAFRAN AIRCRAFT ENGINES
Reel/Frame 046939/0336 →
CHANGE OF NAME Recorded May 23, 2018
From: SNECMA
To: SAFRAN AIRCRAFT ENGINES
Reel/Frame 046479/0807 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 17, 2012
From: SUIZA, HISPANO
To: SNECMA
Reel/Frame 029481/0429 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 4, 2011
From: SUIZA, HISPANO
To: SNECMA
Reel/Frame 027198/0221 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 5, 2005
From: GRANIER, HUGUES; BREGAINT, CHRISTIAN; TONNELIER, PHILIPPE; CROIX MARIE, MARC
To: HISPANO SUIZA
Reel/Frame 016533/0802 →