A method and apparatus for security detection

CN114375443BActive Publication Date: 2026-09-08HUAWEI TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN201980100088.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2019-09-11
Publication Date
2026-09-08
Estimated Expiration
2039-09-11

AI Technical Summary

Technical Problem

但是,传感器的预设阈值难以确定,如果预设阈值设置太小,可能由于环境因素导致错误告警;如果阈值设置太大,则导致传感器安全检测的灵敏度不高

Benefits of technology

[0032] Understandably, any of the security testing methods, devices, computer storage media, and computer program products provided above can be implemented by the corresponding methods provided above. Therefore, the beneficial effects they can achieve can be referred to the beneficial effects of the corresponding methods provided above, and will not be repeated here.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114375443B_ABST
    Figure CN114375443B_ABST
Patent Text Reader

Abstract

The application relates to a security detection method and device, relates to the chip technical field, and can improve the accuracy and sensitivity of security protection of a chip system (200) and effectively control the cost. The security detection method is applied to a system on chip (SoC) (101), the SoC (101) comprises an intelligent monitoring module (201) and a security subsystem (202), and the specific method comprises the following steps: the intelligent monitoring module (201) acquires security monitoring data, the security monitoring data comprises environment parameters (301) of the security subsystem acquired by a sensor; the intelligent monitoring module (201) matches the security monitoring data with preconfigured offline training data to obtain a target data type (302) matched with the security monitoring data; if the target data type belongs to a preset data type, the intelligent monitoring module (201) generates an alarm information (303), so as to protect the security of the SoC (101).
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of chip technology, and in particular to a method and apparatus for security detection. Background Technology

[0002] Chips and devices require specific environmental parameters to function properly, such as temperature, voltage, power consumption, and electromagnetic radiation. If these parameters are exceeded, for example, due to clock or voltage failures, or malicious attacks, glitches may occur momentarily (e.g., lasting in nanoseconds). These parameter-related glitches can cause the chip or device to malfunction at that instant. Therefore, for chips or devices with safety requirements, it is necessary to monitor these glitches to prevent operational errors.

[0003] Current security protection methods mainly fall into two categories. One is passive protection, which enhances protection by identifying important modules, processes, or vulnerabilities and performing multiple checks and verifications. However, since there are many types of security services running on a chip, and each security service may rely on different modules, it is necessary to manually identify the important modules, processes, or vulnerabilities that require security protection. This process is difficult to guarantee comprehensive identification and is prone to omissions.

[0004] Another type is active protection, which uses sensors to detect parameters and compare them with preset thresholds for judgment. Specifically, if the parameters detected by the sensor are within the preset threshold range, it is judged as a normal working state; if the detected parameters are greater than the preset threshold, it is judged as a fault or attack state, thereby generating an alarm signal or resetting the chip to prevent operational errors. However, the preset threshold of the sensor is difficult to determine. If the preset threshold is set too low, environmental factors may cause false alarms; if the threshold is set too high, the sensitivity of the sensor's safety detection will be low. Summary of the Invention

[0005] This application provides a method and apparatus for security detection, which can improve the accuracy and sensitivity of security protection for chip systems.

[0006] To achieve the above objectives, this application adopts the following technical solution:

[0007] Firstly, a security detection method is provided, applied to a system-on-chip (SoC). The SoC includes an intelligent monitoring module and a security subsystem, wherein the security subsystem includes modules with security requirements. The intelligent monitoring module acquires security monitoring data, which includes environmental parameters of the security subsystem acquired by sensors. The intelligent monitoring module matches the security monitoring data with pre-configured offline training data to obtain a target data type that matches the security monitoring data. If the target data type belongs to a preset data type, the intelligent monitoring module generates an alarm message.

[0008] In the above technical solution, the safety monitoring module matches and compares the safety monitoring data of the safety subsystem acquired by the sensors with pre-configured offline training data to obtain the data type corresponding to the safety monitoring data. In other words, by determining the characteristics of the environmental parameters of the current safety subsystem, it judges the current operating status of the chip and thus determines whether an alarm is needed. By matching and calculating the safety monitoring data acquired by the sensors with the preset offline training data, the problem of difficulty in determining the preset threshold of the sensors is solved, resulting in more accurate safety detection and improved accuracy and sensitivity of safety protection.

[0009] For example, the sensor may be integrated into the security subsystem, or it may be located on the SOC but not in the security subsystem.

[0010] In one possible design approach, the intelligent monitoring module uses artificial intelligence algorithms to match security monitoring data with pre-configured offline training data to obtain a target data type that matches the security monitoring data.

[0011] In one possible design, the safety subsystem includes a True Random Number Generator (TRNG), and the safety monitoring data also includes random numbers generated by the TRNG. In this possible implementation, the safety monitoring data also includes random numbers generated by the TRNG, avoiding the limitations and simplification of relying solely on environmental parameters acquired by sensors for safety detection. By utilizing random numbers generated by the TRNG, an existing component in the safety subsystem, as an auxiliary judgment, the accuracy and sensitivity of safety protection are improved. Furthermore, by using existing modules as an auxiliary component, the number of sensors integrated into the safety subsystem can be appropriately reduced, solving the overhead problem caused by deploying a large number of sensors.

[0012] In one possible design, the SoC also includes a temperature sensor, a pulse width modulation (PWM) module, and a high-performance monitoring (HPM) module. The safety monitoring data includes at least one of the following: temperature parameters acquired by the temperature sensor, factory process deviation data acquired by the HPM module, and power supply regulation parameters acquired by the PWM module. This possible implementation avoids the limitations and simplification of relying solely on sensor-acquired environmental parameters for safety detection. By utilizing data generated by existing on-chip devices such as the temperature sensor, PWM module, and HPM module as auxiliary judgments, the accuracy and sensitivity of safety protection are improved. Simultaneously, it solves the overhead problem caused by deploying a large number of sensors.

[0013] In one possible design, the SoC also includes a clock reset generator (CRG), with alarm information used to instruct the CRG to reset the SoC; alternatively, the alarm information can instruct the CRG to disable the clock drive, or the alarm information can instruct the SoC to power off. In these possible implementations, when the intelligent monitoring module generates alarm information, the alarm information can be used to instruct the chip to reset, disable the clock drive, or power off, thereby providing safety protection for the chip system and effectively improving the efficiency of chip safety protection.

[0014] In one possible design, the SoC also includes a processor. Before acquiring security monitoring data, the processor loads offline training data into the storage unit of the intelligent monitoring module. The processor can be a security processor or an application processor. Alternatively, the intelligent monitoring module can load offline training data into its storage unit via Direct Memory Access (DMA). In these possible implementations, the intelligent monitoring module can actively acquire offline training data via DMA or passively load data through the processor. This allows the intelligent monitoring module to perform security detection based on the matching and comparison between the security monitoring data and the offline training data, improving the accuracy and sensitivity of chip security protection.

[0015] In one possible design approach, if the offline training data is compressed, before matching the security monitoring data with the pre-configured offline training data, the method further includes: the intelligent monitoring module decompressing the offline training data to obtain decompressed offline training data. In the above possible implementations, when the offline training data obtained by the intelligent monitoring module is compressed, the intelligent monitoring module can decompress the offline training data to obtain decompressed offline training data, so that the offline training data can be subsequently retrieved from the storage unit for security detection, thereby improving the accuracy and sensitivity of chip security protection.

[0016] In one possible design approach, the intelligent monitoring module acquires security monitoring data, specifically by: determining the frequency of acquiring security monitoring data based on different business scenarios of the SoC; and acquiring security monitoring data according to the frequency. In this possible implementation, the intelligent monitoring module determines the frequency of acquiring security monitoring data based on different business scenarios of the SoC, thereby adaptively adjusting the frequency of acquiring security monitoring data and effectively controlling the power consumption of the intelligent monitoring module's security detection.

[0017] In one possible design approach, the offline training data is obtained by offline training on multiple security monitoring data of the SoC based on artificial intelligence (AI) algorithms. The data types of the offline training data include at least one of the following: attacked, normal operation, low-power voltage regulation, high-temperature protection, high-voltage protection, overcurrent protection, and false triggering. In the above possible implementations, the offline training data is obtained based on AI algorithms, and different data types are pre-configured according to the chip's business needs during training to meet the different security requirements of the chip system, thereby improving the accuracy and sensitivity of chip security protection.

[0018] In one possible design approach, the intelligent monitoring module matches security monitoring data with pre-configured offline training data to obtain the target data type that matches the security monitoring data. This includes: the intelligent monitoring module selecting a target AI algorithm from multiple AI algorithms that is suitable for the business scenario of the SoC; and the intelligent monitoring module matching the security monitoring data with the offline training data based on the target AI algorithm to obtain the target data type. In the above possible implementations, the intelligent monitoring module can select the offline training data corresponding to the matching AI algorithm for matching calculations according to different business scenarios of the SoC, thereby adaptively adjusting the AI ​​algorithm and improving the accuracy and sensitivity of chip security protection.

[0019] In one possible design, the intelligent monitoring module includes a data backup program or a security verification and protection program. The data backup program is used to back up control signals, which are used by the processor to select functions for the intelligent monitoring module. The security verification and protection program is used to protect the intelligent monitoring module from acquiring security monitoring data. These possible implementations can provide security protection for the intelligent monitoring module and improve the accuracy of chip security protection.

[0020] Secondly, a security detection device is provided, comprising an intelligent monitoring module and a security subsystem. The security subsystem includes modules with security requirements. The intelligent monitoring module is used to: acquire security monitoring data, including environmental parameters of the security subsystem acquired by sensors; match the security monitoring data with pre-configured offline training data to obtain a target data type that matches the security monitoring data; and if the target data type belongs to a preset data type, the intelligent monitoring module generates an alarm message.

[0021] In one possible design, the security subsystem includes a true random number generator (TRNG), and the security monitoring data also includes random numbers generated by the TRNG.

[0022] In one possible design, the device further includes a temperature sensor, a pulse width modulation (PWM) module, and a high-performance monitoring (HPM) module. The safety monitoring data also includes at least one of the following: temperature parameters acquired by the temperature sensor, factory process deviation data acquired by the HPM, and power supply regulation parameters acquired by the PWM.

[0023] In one possible design, the device also includes a clock reset generator (CRG), with an alarm message indicating that the CRG resets the device; or, the alarm message indicates that the CRG disables the clock drive; or, the alarm message indicates that the device is powered off.

[0024] In one possible design, the device further includes a processor, which, before acquiring security monitoring data, loads offline training data into the storage unit of the intelligent monitoring module, wherein the processor is a security processor or an application processor; or, the intelligent monitoring module loads offline training data into its storage unit via direct memory access (DMA).

[0025] In one possible design, if the offline training data is compressed, before matching the security monitoring data with the pre-configured offline training data, the intelligent monitoring module is also used to: decompress the offline training data to obtain decompressed offline training data.

[0026] In one possible design approach, the intelligent monitoring module is specifically used to: determine the frequency of acquiring security monitoring data based on different business scenarios of the device; and acquire security monitoring data according to the frequency.

[0027] In one possible design approach, the offline training data is obtained by offline training of multiple security monitoring data of the device based on artificial intelligence (AI) algorithms. The data types of the offline training data include at least one of the following: attacked type, normal operation type, low power voltage regulation type, high temperature protection type, high voltage protection type, overcurrent protection type, and false trigger type.

[0028] In one possible design approach, the intelligent monitoring module is specifically used to: select a target AI algorithm from multiple AI algorithms that is suitable for the business scenario of the device; and match the security monitoring data with the offline training data based on the target AI algorithm to obtain the target data type.

[0029] In one possible design, the intelligent monitoring module includes a data backup program or a security verification and protection program. The data backup program is used to back up control signals, which are used to enable the processor to select functions for the intelligent monitoring module. The security verification and protection program is used to protect the intelligent monitoring module from acquiring security monitoring data.

[0030] Thirdly, a readable storage medium is provided, which stores instructions that, when executed on a computer or processor, cause the computer or processor to perform a security detection method in any of the possible design embodiments of the first aspect described above.

[0031] Fourthly, a computer program product is provided that, when the computer program product is run on a computer, causes the computer to perform a security detection method in any of the possible design schemes of the first aspect above.

[0032] Understandably, any of the security testing methods, devices, computer storage media, and computer program products provided above can be implemented by the corresponding methods provided above. Therefore, the beneficial effects they can achieve can be referred to the beneficial effects of the corresponding methods provided above, and will not be repeated here. Attached Figure Description

[0033] Figure 1 A schematic diagram of the hardware structure of an electronic device provided in an embodiment of this application;

[0034] Figure 2 A schematic diagram of the hardware structure of a security detection chip system provided in this application embodiment;

[0035] Figure 3 A flowchart illustrating a security detection method provided in an embodiment of this application;

[0036] Figure 4 This application provides a schematic diagram of the hardware structure of a security detection chip system;

[0037] Figure 5 This application provides a schematic diagram of the hardware structure of an intelligent monitoring module for security detection. Detailed Implementation

[0038] Hereinafter, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature. In the description of this embodiment, unless otherwise stated, "a plurality of" means two or more.

[0039] It should be noted that, in this application, the terms "exemplary" or "for example" are used to indicate that something is being described as an example, illustration, or illustration. Any embodiment or design described as "exemplary" or "for example" in this application should not be construed as being more preferred or advantageous than other embodiments or design solutions. Specifically, the use of terms such as "exemplary" or "for example" is intended to present the relevant concepts in a concrete manner.

[0040] Before introducing the embodiments of this application, a brief introduction to the design technology will be given first:

[0041] Artificial Intelligence (AI) is a branch of computer science that studies and develops theories, methods, technologies, and application systems to simulate, extend, and expand human intelligence. Research in this field includes robotics, speech recognition, image recognition, natural language processing, and expert systems.

[0042] A sensor is a detection device that senses the information being measured and transforms that information into an electrical signal or other required form of output according to a certain rule, in order to meet the requirements of information transmission, processing, storage, display, recording, and control. Sensors are generally classified into ten major categories based on their basic sensing functions: thermal sensors, photosensors, gas sensors, force sensors, magnetic sensors, humidity sensors, acoustic sensors, radiation sensors, color sensors, and taste sensors.

[0043] Temperature sensor (T-sensor): refers to a sensor that can sense temperature and convert it into a usable output signal.

[0044] Application processor (AP): The operating system, user interface, and user applications on an electronic device all run on the application processor.

[0045] Security processors: Security processors can be two processors that are physically independent of the application processor. A processor can also be considered a security processor when it runs in a trusted environment; that is, the application processor and the security processor can be logically isolated. Verified programs run on the security processor.

[0046] A True Random Number Generator (TRNG) is a device that generates random numbers through physical processes rather than computer programs. It typically relies on microscopic phenomena that produce randomness, such as thermal noise, the photoelectric effect involving beam splitters, and other quantum phenomena. Theoretically, these random processes are completely unpredictable.

[0047] Pulse width modulation (PWM): An analog control method that modulates the bias of the base of a transistor or the gate of a MOSFET according to changes in the load, thereby changing the conduction time of the transistor or MOSFET and thus changing the output of the switching power supply. This method allows the power supply output voltage to remain constant under changing operating conditions. It is a very effective technique for controlling analog circuits using digital signals from a microprocessor and can be used as a voltage regulation module in a chip.

[0048] This application provides a security detection method that can be applied to chip systems requiring security protection, or electronic devices including such chip systems.

[0049] Figure 1 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. The electronic device can be a mobile phone, tablet computer, computer, laptop computer, or other terminal device. For ease of description, the devices mentioned above are collectively referred to as electronic devices in this application. This embodiment of the application uses a mobile phone as an example for illustration; see [link to documentation]. Figure 1 The phone includes a system-on-chip (SoC) 101 and a memory 102 coupled to the SoC 101.

[0050] The SoC 101 serves as the control center of the mobile phone, connecting various parts of the device via various interfaces and lines. It executes software programs and / or software modules stored in memory, and accesses data stored in memory to perform various functions and process data, thereby providing overall monitoring of the phone. In some feasible embodiments, the SoC 101 may include a central processing unit (CPU), other general-purpose processors such as digital signal processors, artificial intelligence processors, microcontrollers, or microprocessors. In addition, the SoC 101 may include an application processor, a security processor, a graphics processing unit (GPU), an image signal processor (ISP), or a voice processor. The SoC 101 may further include other hardware circuits or accelerators, such as application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof.

[0051] In this embodiment, the memory 102 may include different types of memory, and the SoC 101 can be used to access any type of memory or storage medium in the memory 102. Figure 1 The example of memory 102 comprising a Double Data Rate (DDR) Synchronous Dynamic Random Access Memory (SDRAM) (DDR SDRAM), a Non-Volatile Random Access Memory (NVRAM), and a NAND flash memory, with the DDR SDRAM, NVRAM, and NAND flash memory integrated together, will be used for illustration.

[0052] Figure 1The memory 102 integrates different types of memory, such as DDR SDRAM, NVRAM, and NAND flash memory, and may further include other types of memory. Specific details can be found in the following embodiments. At least one memory or storage medium in memory 102 can be used to store data, software programs, and modules. For example, each memory may include a program storage area and a data storage area, wherein the program storage area may store software programs, including instructions formed by code, including but not limited to an operating system and applications required for at least one function, such as sound playback functionality, image playback functionality, etc.; the data storage area may store data created based on the use of the mobile phone, such as audio data, image data, phonebook, etc.

[0053] Further, see Figure 1 The mobile phone may also include a sensor assembly 103, a multimedia assembly 104, and an input / output interface 105, etc. The following is a detailed introduction to each of the above components.

[0054] The sensor assembly 103 includes one or more sensors for providing various aspects of the phone's status assessment. For example, the sensor assembly 103 may include a light sensor, such as a CMOS or CCD image sensor, for use in imaging applications, i.e., as part of a camera or webcam. Furthermore, the sensor assembly 103 may also include an accelerometer, gyroscope, magnetometer, pressure sensor, or temperature sensor. Through the sensor assembly 103, the phone's acceleration / deceleration, orientation, on / off state, relative positioning of components, or temperature changes can be detected.

[0055] Multimedia component 104 provides a screen as an output interface between the mobile phone and the user. This screen can be a display panel or a touch panel, and when it is a touch panel, it can be implemented as a touchscreen to receive input signals from the user. The touch panel includes one or more touch sensors to sense touches, swipes, and gestures on the touch panel. The touch sensors can sense not only the boundaries of touch or swipe actions but also the duration and pressure associated with the touch or swipe operation. Furthermore, multimedia component 104 includes at least one camera, for example, a front-facing camera and / or a rear-facing camera. When the mobile phone is in an operating mode, such as shooting mode or video mode, the front-facing camera and / or rear-facing camera can sense external multimedia signals used to form image frames. Each front-facing and rear-facing camera can be a fixed optical lens system or have focal length and optical zoom capabilities.

[0056] Input / output interface 105 provides an interface between SoC 101 and peripheral interface modules, such as keyboards, mice, or USB (Universal Serial Bus) devices. In one possible implementation, input / output interface 105 may have only one input / output interface or multiple input / output interfaces.

[0057] Although not shown, the mobile phone may also include audio components and communication components, such as a microphone for the audio components and a Wireless Fidelity (WiFi) module and a Bluetooth module for the communication components. These will not be elaborated further in the embodiments of this application. Those skilled in the art will understand that... Figure 1 The mobile phone structure shown does not constitute a limitation on the mobile phone and may include more or fewer components than illustrated, or combine certain components, or have different component arrangements. It is understood that... Figure 1 All the components shown can be located on the same circuit board; this embodiment does not impose any limitations.

[0058] Using the above network architecture, the SoC101 of the electronic device can be used as follows: Figure 2 Chip systems, chip systems can be such as Figure 2 The hardware architecture shown includes a chip system 200 that may include an intelligent monitoring module 201 and a security subsystem 202. It should be understood that the intelligent monitoring module 201 may be a hardware module, such as an application-specific integrated circuit (ASIC) or a embedded intellectual property (IP) core, or it may be a software module.

[0059] The intelligent monitoring module 201 is used to acquire security monitoring data from the security subsystem 202 and match the acquired security monitoring data with the pre-configured offline training data in the intelligent monitoring module 201 to obtain the target data type that matches the security monitoring data.

[0060] Specifically, the intelligent monitor 201 can be configured in training mode to acquire and save security monitoring data detected by the security subsystem 202; then, it uses artificial intelligence algorithms to train the acquired large amount of security monitoring data to obtain training data. It should be noted that the training process can also be performed offline by other chips or electronic devices, generating offline training data which is then sent to the intelligent monitoring module 201 for storage. In this case, the intelligent monitor 201 only needs to collect the security monitoring data from the chip system 200.

[0061] Furthermore, the intelligent monitor 201 can also be configured in a predictive mode. It can compare the real-time collected security monitoring data with the aforementioned offline training data, and make predictions based on the matched data type to determine the current operating state of the chip system 200. This utilizes artificial intelligence technology to achieve security protection for the chip system 200. For example, if the data type matched based on the real-time security monitoring data is classified as "attack-prone," it indicates that the chip system 200 may be in an abnormal operating state. The intelligent monitor 201 can generate an alarm signal to instruct the reset chip to reset, thereby protecting the chip system 200 and preventing losses caused by malicious attacks.

[0062] The intelligent monitor 201 can perform training and prediction modes simultaneously or separately. Simultaneous data training and prediction may take a long time, reducing the real-time performance of the prediction. Furthermore, if the intelligent monitor 201 or the chip system 200 is attacked during training mode, the accuracy of the training results may be affected. Therefore, selecting separate training modes or using other electronic devices for data training is more effective.

[0063] The security subsystem 202 is primarily used to run security-related programs and tasks. It includes modules with security requirements, such as those closely related to security, including key generation and storage modules, scrambling calculation modules, and the intelligent monitor 201 and security processor. Therefore, special protection is needed for the security modules in the security subsystem 202. This could be achieved by adding one or more sensors to detect environmental parameters, or by adding chip synthesis and back-end processing to enhance security. Chip synthesis and back-end processing are processes in chip development and design. Chip synthesis converts abstract code into gate-level circuits, while back-end processing converts these gate-level circuits into physical implementation parameters. For example, anti-optimization processing can be added during chip synthesis to prevent security logic circuits from being deemed invalid and optimized away. Special back-end processing can also be used to determine sensor placement requirements based on security considerations.

[0064] In addition, when the chip system 200 is a Trusted Execution Environment (TEE), security requirements involve most of the modules on the chip system 200, so some high-security modules can be placed in the security subsystem.

[0065] This application provides a security detection method applied to the aforementioned chip system. The specific method includes: acquiring current detection data from at least one sensor, comparing it with data obtained through offline training using a training algorithm to obtain a matching data type, and determining whether an alarm signal needs to be generated based on the data type, thereby providing security protection for the chip system or electronic device.

[0066] Furthermore, the technical solution of this application integrates some modules with safety requirements into a safety subsystem. Modules in the safety subsystem require special protection. This application integrates sensors into the safety subsystem to acquire environmental parameters of modules with safety requirements. In addition, it can also acquire data from other existing detection modules, inspection logic, or temperature sensors in the chip system. By combining multiple detection data, predictions can be made, improving the accuracy and flexibility of safety detection. At the same time, by combining data from some existing modules in the chip system, the number of sensors integrated on the chip system can be reduced, thereby reducing the device cost of safety detection.

[0067] like Figure 3 As shown, the method may include:

[0068] 301: The intelligent monitoring module acquires safety monitoring data, which includes environmental parameters of the safety subsystem acquired by sensors.

[0069] The sensors are used to acquire environmental parameters of modules with safety requirements on the safety subsystem 202. The chip system 200 may be equipped with multiple sensors, such as sensor 1, sensor 2, ... sensor n. In one optional case, the multiple sensors are integrated inside the safety subsystem to acquire environmental parameters of modules with safety requirements within the safety subsystem. Alternatively, the multiple sensors may also be distributed in other locations outside the safety subsystem on the chip system 200.

[0070] This sensor can be a digital integrated sensor that can acquire various environmental parameters such as temperature, voltage, current, and oscillation frequency. Specifically, it can use the sensor's sensing function to process the various data such as temperature, voltage, current, and oscillation frequency detected on the safety subsystem 202, convert them into digital signals, and use them to represent the magnitude of the aforementioned environmental parameters.

[0071] As described above, the security monitoring data can be the environmental parameters of the security subsystem obtained by the multiple sensors. When the chip system 200 or the security subsystem 202 is subjected to fault injection or human attack, the sensors can detect changes in the current environmental parameters. Therefore, the intelligent monitoring module 201 can determine the current operating status of the chip system 200 based on the security monitoring data obtained by the sensors.

[0072] Furthermore, the security subsystem 202 may also include a true random number generator (TRNG) or other checking logic.

[0073] TRNG is used to generate random numbers, which can be used by chip system 200 to create random encryption keys to encrypt data. When security subsystem 202 or TRNG is subjected to fault injection or human attack, the randomness of the random numbers generated by TRNG will be affected. Therefore, the data generated by TRNG can also be used as security monitoring data to help determine the current working status of chip system 200.

[0074] Other checking logic is used to perform security verification on certain operations on the chip system 200. For example, this could include Cyclic Redundancy Check (CRC), parity check, or signature verification. When the security subsystem 202 or this checking logic is subjected to fault injection or human attack, the accuracy of the checking logic verification will be affected. For example, it will affect the accuracy of the CRC check. Therefore, the intelligent monitoring module can also obtain the verification data of the CRC check and the aforementioned other checking logic as security monitoring data to assist in determining the current operating status of the chip system 200.

[0075] Security monitoring data may also include random numbers generated by the aforementioned TRNG, or verification data generated by other inspection logic.

[0076] 302: The intelligent monitoring module matches the security monitoring data with the pre-configured offline training data to obtain the target data type that matches the security monitoring data.

[0077] The offline training data is obtained by offline training on a large amount of security monitoring data of various data types acquired by the intelligent monitoring module, based on artificial intelligence (AI) algorithms.

[0078] The data type of offline training data can be manually configured by those skilled in the art based on factors such as security level, security detection accuracy, or possible operating states of the chip system. For example, the data type of offline training data can be configured as at least one of the following: attacked, normal operation, low-power voltage regulation, high-temperature protection, high-voltage protection, overcurrent protection, and false triggering.

[0079] Among them, the "attacked" type refers to data types that match the characteristics of security monitoring data acquired under conditions of malicious attack on the chip. When the security monitoring data acquired by the intelligent monitoring module matches the characteristics of data under "malicious attack" conditions, the target data type matching the security monitoring data is classified as "attacked." In this case, the chip may have been subjected to a malicious attack, and a security warning needs to be issued to the chip. Correspondingly, the "high temperature protection," "high voltage protection," and "overcurrent protection" types refer to data types that match the characteristics of security monitoring data acquired when the chip is under conditions of excessively high temperature, excessively high voltage, or excessively high current. Once the above data exceeds the corresponding safety threshold, the chip may malfunction or burn out, thus requiring a security warning to be issued to the chip.

[0080] Normal operation data refers to safety monitoring data when the chip is operating normally. Accidental trigger data refers to chip safety monitoring data when the chip is subjected to accidental triggering operations; this may include accidental triggering operations that do not affect normal chip operation, or it may include accidental triggering operations that do affect normal chip operation, requiring configuration based on specific circumstances. Low-power voltage regulation data refers to safety monitoring data when the chip adjusts its supply voltage according to the service type. For example, when the chip detects that the current service power consumption is low, it can appropriately reduce the supply voltage to save power; when the chip detects that the current service power consumption is high, it can restore the supply voltage to meet the power supply requirements of the service.

[0081] For example, the offline training data processing process can be as follows: the intelligent monitoring module acquires several sets of security monitoring data when the chip is under attack, and uses AI algorithms to train the security monitoring data to obtain at least one set of offline training data corresponding to the attacked class, which can also be called the data model corresponding to the attacked class.

[0082] The AI ​​algorithm can be a neural network algorithm, a linear classification algorithm, a support vector machine (SVM) algorithm, a Gaussian SVM algorithm, etc. This application does not specify the algorithm for offline training.

[0083] The intelligent monitoring module matches the security monitoring data obtained in step 301 with the pre-configured offline training data to obtain the offline training data with the highest matching degree. The data type corresponding to the offline training data with the highest matching degree is the target data type that matches the security monitoring data.

[0084] 303: If the target data type belongs to the preset data type, the intelligent monitoring module will generate an alarm message.

[0085] The preset data types can be pre-configured by those skilled in the art as needed. For example, attack-prone, high-temperature protection, high-voltage protection, and overcurrent protection types can be configured as preset data types. The intelligent monitoring module then determines that these data types require alarm information generation. When, according to step 302 above, the intelligent monitoring module obtains that the matched target data type is any one of the attack-prone, high-temperature protection, high-voltage protection, and overcurrent protection types, the intelligent monitoring module generates alarm information.

[0086] In the embodiments described above, a smart monitoring module acquires security monitoring data, including at least one sensor, random numbers generated by a TRNG, and verification data from other inspection logic. This security monitoring data is then matched with pre-configured offline training data. Based on the matched data type, it is determined whether an alarm signal needs to be generated, thereby protecting the chip's security. By comparing the security monitoring data with offline training data of different data types, the data type of the current security monitoring data is determined, solving the problem of difficulty in setting preset thresholds for sensor detection in existing technologies. Furthermore, by acquiring data from TRNG and other inspection logic and combining it with sensor detection data for comprehensive judgment, the limitations of existing technologies, such as low sensitivity of sensor detection, inability of a single sensor to form an overall judgment, insufficient detection, or the overhead of configuring a large number of sensors, are addressed. This improves the accuracy and sensitivity of the chip system's security protection while effectively controlling costs.

[0087] In the above embodiments, such as Figure 4 The chip system 200 may also include a processor 203 and a clock reset generator 204. The processor 203 is used to perform scheduling and control of the programs running on the chip system 200.

[0088] In some embodiments, before the intelligent monitoring module 201 acquires the security monitoring data of each module in step 301 above, it may specifically include: the processor 203 loading offline training data into the storage unit of the intelligent monitoring module 201. The processor 203 may be a security processor or an application processor; for a description of security processors and application processors, please refer to the above introduction, which will not be repeated here.

[0089] The aforementioned security processor can be a processor used to run verified or encrypted security programs. Alternatively, a processor running in a TEE can be defined as a security processor. In the above embodiments of this application, offline training data can be loaded into the storage unit of the intelligent monitoring module 201 using a security processor. For example, the storage unit of the intelligent monitoring module can be a static random access memory (SRAM).

[0090] An application processor is a processor that runs user programs, allowing users to perceive or observe the operation of applications through their interaction with electronic devices. In this application, while ensuring the security of the application processor's running programs, offline training data can also be loaded into the storage unit of the intelligent monitoring module 201 via the application processor.

[0091] In addition, before the intelligent monitoring module 201 obtains the security monitoring data of each module in step 301 above, it may also include: the intelligent monitoring module 201 directly loading the offline training data into the storage unit of the intelligent monitoring module 201 through the Direct Memory Access (DMA) method.

[0092] DMA is an access function provided by the computer bus architecture, enabling data to be sent directly from other devices to the computer motherboard's memory. For example, DMA can be used to send offline training data generated on other devices to the storage unit of the intelligent monitoring module 201 on the chip system 200. The specific data connection can be achieved through direct memory access using a bus master controller or through a Programming Input / Output Model (PIO) interface. This application does not limit the specific implementation method of this direct memory access.

[0093] In some embodiments, in step 301 above, the intelligent monitoring module 201 can obtain the security monitoring data of each module by actively reading, passively reading, or accessing through a public bus or a private interface. This application embodiment does not limit the method of obtaining security monitoring data.

[0094] In addition, the intelligent monitoring module 201 can determine the frequency of acquiring security monitoring data based on different business scenarios of the chip system 200, and acquire security monitoring data at different frequencies. For example, the intelligent monitoring module 201 can determine the frequency of acquiring security monitoring data based on the current business type of the chip system 200. For instance, if the current business of the chip system 200 is a high-security business such as payment, the intelligent monitoring module 201 can adjust the frequency of acquiring security monitoring data to a higher level. A higher frequency of acquiring security monitoring data by the intelligent monitoring module 201 can effectively protect the business security of the security chip 200.

[0095] For example, the intelligent monitoring module 201 can determine the frequency of acquiring security monitoring data based on the current service power consumption of the chip system 200. For instance, if the current service power consumption of the chip system 200 is high, the intelligent monitoring module 201 can adjust the frequency of acquiring security monitoring data to a relatively low level, thereby saving power.

[0096] In some embodiments, the chip system 200 may further include a clock and reset generator (CRG) 204. The CRG, also called a reset chip, is used to generate clock signals for the chip system 200 and to perform reset operations on other modules or devices on the chip system 200.

[0097] The intelligent monitoring module 201 can send the alarm information generated in step 303 to the clock reset generator 204 to instruct the clock reset generator 204 to perform a clock reset on the chip system 200; or, the alarm information can be used to instruct the clock reset generator 204 to turn off the clock drive of the chip system 200. Alternatively, the intelligent monitoring module 201 can send the alarm information to the power control module on the chip system 200 to instruct it to turn off the power to the chip system 200.

[0098] Furthermore, the aforementioned intelligent monitoring module 201 may include a data backup program or a security verification and protection program. To ensure the reliability of the security monitoring data input into the intelligent monitoring module 201, a verification value can be added to the read security monitoring data. That is, when the intelligent monitoring module 201 acquires security monitoring data, it will first determine whether the data is valid based on the security verification and protection program. If the data is valid, it will continue to perform matching calculations. If the data is invalid, the intelligent monitoring module 201 can process the acquired data, such as discarding the data or resetting it.

[0099] In addition, the intelligent monitoring module 201 may also include a data backup program for backing up the control signals of the intelligent monitoring module 201. These control signals can be used to enable the processor to select functions for the intelligent monitoring module 201, thereby improving security. For example, the data backup program can be used for control signals configured by the processor to select the AI ​​algorithm for the intelligent monitoring module 201, or for control signals to decompress offline training data. If the control signals and backup data match, the control signals are considered reliable; if they do not match, they are discarded or reset.

[0100] In some embodiments, the chip system 200 may further include a temperature sensor, a pulse width modulation (PWM) module, and a high performance monitor (HPM) module. Alternatively, the chip system 200 may include a peripheral module controller 205, on which the aforementioned temperature sensor, PWM module, and HPM module can be integrated, such as... Figure 4 As shown.

[0101] The peripheral module controller 205 can be used to manage and control other devices or related modules involved in the safety parameters of the chip system 200.

[0102] Based on this, the safety monitoring data acquired by the intelligent monitoring module 201 in step 301 above may also include at least one of the following: temperature parameters acquired by the temperature sensor, factory process deviation data acquired by HPM, and power supply regulation parameters acquired by PWM.

[0103] The temperature sensor can acquire the temperature parameters of the chip system 200, which indicates the current operating temperature of the chip. Operating the chip in an excessively high-temperature environment may cause chip malfunction or even burn-out.

[0104] The HPM module can be used to measure the factory process deviation parameters of the chip system 200 and identify erroneous parameters based on the range of process deviation. Some process deviation parameters are within the normal and acceptable range and belong to the parameters under normal working conditions; some chip process deviation parameters exceed the preset range and are considered unacceptable chip process deviations that affect the normal working conditions of the chip, requiring an early warning for chips of this type under working conditions.

[0105] The PWM module is used to adjust the power supply according to the service requirements. For example, it adjusts the power supply voltage based on the power consumption of the chip system 200. If the chip system 200 is currently playing video and generating high power consumption, the PWM module will adjust the power supply voltage to be higher; if the chip system 200 is in standby mode and generating low power consumption, the PWM module will adjust the power supply voltage to be lower. Therefore, based on the detection data provided by the PWM module, data misjudgments caused by the PWM module adjusting the voltage can be eliminated.

[0106] It should be noted that, Figure 4 The illustrated chip system 200 is merely an example illustrating a possible hardware structure. In actual applications, it may include more or fewer components than illustrated, or combine or separate certain components, or have different component arrangements. The components illustrated may be implemented in hardware, software, or a combination of both.

[0107] The composition and structure of the intelligent monitoring module 201 in the above embodiments of this application will be briefly described below with reference to the above embodiments. For example, as shown below... Figure 5 As shown, the internal structure of the aforementioned intelligent monitoring module 201 may include a data processing module 1, an AI control module 2, an AI algorithm engine 3, an AI algorithm engine 4, a storage unit 5, a parameter decompression module 6, a calculation module 7, a register configuration module 8, and a bus control module 9.

[0108] The data processing module 1 is used to preprocess the acquired security monitoring data, which includes, but is not limited to, security monitoring data obtained from at least one sensor, TRNG, other inspection logic, T-Sensor, PWM, and HPM. The preprocessing of the security monitoring data may include packaging and conversion. Specifically, the acquired security monitoring data may be packaged according to a certain format and converted into a certain vector format. For example, all the acquired security monitoring data may be packaged and converted into a pre-defined data format.

[0109] AI control module 2 can be used to control different AI algorithm engines to perform read and write operations on storage unit 5, and to control the access of different AI algorithm engines to computing resources in computing module 7. For example, AI control module 2 can control the selection of different AI algorithm engines, choosing which AI algorithm engine to read and write data in storage unit 5, and which AI algorithm engine to access computing resources in computing module 7. Exemplarily, the selection of AI algorithm engines is achieved by the processor configuration register and passed to the AI ​​control module. Exemplarily, AI control module 2 can also be used to select different AI algorithm engines for matching calculations, select the connectivity of the parameter decompression module, select the connectivity of the data processing module, and send pre-processed security monitoring data to AI algorithm engine 3 for data matching calculations, etc. AI control module 2 can also be used to automatically manage read and write operations on storage unit 5.

[0110] In addition, the AI ​​control module 2 can also be used to determine whether the target data type matched by the AI ​​algorithm engine 3 is a preset data type. If it is determined that the security monitoring data belongs to a preset data type that needs to be alarmed, the AI ​​control module 2 generates an alarm signal and sends it to the CRG reset chip.

[0111] AI algorithm engine 3 is used to match and calculate the received security monitoring data with the offline training data in storage unit 5 to generate matching results. AI algorithm engine 3 is mainly used to continue calculation tasks according to AI algorithms, generate calculation instructions, and schedule computing resources in computing module 7 to complete specific data calculation tasks, obtaining the matched data type. Optionally, it may also include the accuracy of the corresponding prediction results. The execution of the specific calculation process of its AI algorithm is implemented by computing module 7. In some embodiments, the intelligent monitor 201 may optionally include more than one AI algorithm engine 3, such as AI algorithm engine 4, etc., which can be used to match and calculate the acquired security monitoring data with different offline training data according to different artificial intelligence algorithm engines. Different AI algorithm engines can be selected according to chip requirements, thereby improving the accuracy and flexibility of security detection. For example, the AI ​​algorithm engine is a hardware module, such as an integrated hardware logic circuit or a dedicated solidified hardware core. Computing module 7 includes computing resources for integer or decimal addition, subtraction, multiplication, division, and exponential operations. For example, subtraction can be converted to addition with two's complement, and division can be converted to fixed-point or floating-point multiplication. The computing module 7 can be a hardware module, and the computing resources within it can be reused by multiple AI algorithm engines. For example, the AI ​​control module 2 controls different AI algorithm engines to access the computing resources in the computing module 7.

[0112] For example, AI algorithm engine 3 could be a neural network-based algorithm used to match security monitoring data with offline training data, or to train security monitoring data using a neural network algorithm to generate offline training data. AI algorithm engine 4 could be a linear classification-based algorithm used to match security monitoring data with offline training data, or to train security monitoring data using a linear classification algorithm to generate offline training data. Since two different algorithm engines can generate different offline training data, different data types may be obtained depending on the algorithm engine used when the intelligent monitoring module matches security monitoring data with pre-configured offline training data.

[0113] In some embodiments, the intelligent monitoring module can select a target AI algorithm from multiple AI algorithms that is suitable for different business scenarios of the chip system. Based on the target AI algorithm, the intelligent monitoring module matches security monitoring data with offline training data to obtain the target data type. For example, the intelligent monitoring module can select a highly accurate AI algorithm for data matching calculation based on the security level of the chip system's business. Alternatively, the intelligent monitoring module can select a computationally simpler AI algorithm with lower power consumption for data matching calculation based on the chip system's business power consumption.

[0114] like Figure 5 As shown, the internal structure of the intelligent monitoring module may include a storage unit 5 for storing offline training data. Specifically, it can store offline training data generated based on more than one AI algorithm. For example, this storage unit may be SRAM.

[0115] Alternatively, the intelligent monitoring module may also include a parameter decompression module 6, which is used to decompress the offline training data stored in the storage unit 5 when the stored offline training data is compressed.

[0116] If the offline training data generated by other electronic devices occupies a large amount of storage space, it can be compressed before being sent to the intelligent monitoring module 201. Therefore, the offline training data received by the intelligent monitoring module 201 is compressed data. Before matching the security monitoring data with the pre-configured offline training data, the intelligent monitoring module 201 needs to decompress the offline training data to obtain the decompressed offline training data.

[0117] The calculation module 7 is a basic calculation unit used to execute data calculation tasks sent by the AI ​​algorithm engine 3 or the AI ​​algorithm engine 4. For example, this calculation module 7 can specifically implement addition and multiplication operations, and may also include exponentiation operations. Because subtraction can be converted into addition with two's complement, and division can be converted into fixed-point or floating-point multiplication, this calculation module 5 can meet the calculation requirements of the AI ​​algorithm engine 3.

[0118] Register configuration module 8 is used for pre-storing data, specifically for storing intermediate data during the data matching calculation process of intelligent monitoring module 201. For example, different prediction results generated by different AI algorithm engines 3 or 4 are stored in register configuration module 8, and the final prediction result can be selected by the processor through bus control module 9 for output.

[0119] The bus control module 9 is used to execute access and data transmission between the intelligent monitoring module and the processor. The bus control module 9 can also be used to configure the parameters of the intelligent monitoring module. Specifically, this may include the storage configuration of the storage unit 5 in the intelligent monitoring module, the configuration of the data type of the prediction results generated by the AI ​​algorithm engine 3, and, optionally, the processor can select different AI algorithm engines through the bus control module 9.

[0120] In addition, the processor can select the prediction results generated by different AI algorithms through the bus control module 9. It can select based on the matched data type and the corresponding accuracy, and output the prediction results.

[0121] It should be noted that, Figure 5 This illustration merely demonstrates the possible hardware structure of the intelligent monitoring module. In actual applications, it may include more or fewer components than shown, or combine some components, or split some components, or arrange the components differently. Figure 5 Each module shown can be implemented entirely in hardware, entirely in software, or partially in hardware and partially in software.

[0122] This application embodiment also provides a security detection device, which includes an intelligent monitoring module and a security subsystem. The intelligent monitoring module can be used to: acquire security monitoring data; match the security monitoring data with pre-configured offline training data to obtain a target data type that matches the security monitoring data; if the target data type belongs to a preset data type, the intelligent monitoring module generates alarm information. Specifically, the intelligent monitoring module can be used to execute steps 301-303 in the above method embodiment. For specific implementation methods and possible exemplary descriptions, please refer to the relevant content of the above method embodiment, which will not be repeated here.

[0123] Finally, it should be noted that the above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A security detection method applied to a system-on-a-chip (SoC), characterized in that, The SoC includes an intelligent monitoring module and a security subsystem, wherein the security subsystem includes a security-required module and a True Random Number Generator (TRNG), and the method includes: The intelligent monitoring module acquires safety monitoring data, which includes environmental parameters of the safety subsystem acquired by the sensors and random numbers generated by the TRNG. The intelligent monitoring module matches the security monitoring data with pre-configured offline training data to obtain a target data type that matches the security monitoring data. If the target data type belongs to a preset data type, the intelligent monitoring module generates an alarm message.

2. The method according to claim 1, characterized in that, The SoC also includes a temperature sensor, a pulse width modulation (PWM) module, and a high-performance monitoring (HPM) module. The security monitoring data also includes: At least one of the temperature parameters acquired by the temperature sensor, the factory process deviation data acquired by the HPM, and the power supply adjustment parameters acquired by the PWM.

3. The method according to claim 1, characterized in that, The SoC also includes a clock reset generator (CRG), and the alarm information is used to instruct the CRG to reset the SoC; or, the alarm information is used to instruct the CRG to disable clock driving; or, the alarm information is used to instruct the SoC to power off.

4. The method according to any one of claims 1 to 3, characterized in that, The SoC also includes a processor, and the method further includes, prior to acquiring the security monitoring data: The processor loads the offline training data into the storage unit of the intelligent monitoring module, wherein the processor is a security processor or an application processor; Alternatively, the intelligent monitoring module can load the offline training data into its storage unit via Direct Memory Access (DMA).

5. The method according to any one of claims 1 to 3, characterized in that, If the offline training data is compressed data, before matching the security monitoring data with the pre-configured offline training data, the method further includes: The intelligent monitoring module decompresses the offline training data to obtain the decompressed offline training data.

6. The method according to any one of claims 1 to 3, characterized in that, The intelligent monitoring module acquires security monitoring data, specifically including: The intelligent monitoring module determines the frequency of acquiring the security monitoring data based on the different business scenarios of the SoC; The intelligent monitoring module acquires the security monitoring data according to the frequency.

7. The method according to any one of claims 1 to 3, characterized in that, The offline training data is obtained by offline training of multiple security monitoring data of the SoC based on artificial intelligence (AI) algorithms. The data types of the offline training data include at least one of the following: attacked, normal operation, overcurrent protection, and false trigger.

8. The method according to any one of claims 1 to 3, characterized in that, The intelligent monitoring module matches the security monitoring data with pre-configured offline training data to obtain target data types that match the security monitoring data, including: The intelligent monitoring module selects a target AI algorithm from multiple AI algorithms that is suitable for the business scenario of the SoC. The intelligent monitoring module matches the security monitoring data with the offline training data based on the target AI algorithm to obtain the target data type.

9. The method according to any one of claims 1 to 3, characterized in that, The intelligent monitoring module includes a data backup program or a security verification and protection program. The data backup program is used to back up the control signals, wherein the control signals are used to enable the processor to select the function of the intelligent monitoring module. The security verification and protection program is used to protect the intelligent monitoring module from acquiring the security monitoring data.

10. A security detection device, characterized in that, The device includes an intelligent monitoring module and a security subsystem, wherein the security subsystem includes a security-required module and a True Random Number Generator (TRNG), and the intelligent monitoring module is used for: Acquire security monitoring data, wherein the security monitoring data includes environmental parameters of the security subsystem acquired by sensors and random numbers generated by the TRNG; The security monitoring data is matched with pre-configured offline training data to obtain a target data type that matches the security monitoring data. If the target data type belongs to a preset data type, the intelligent monitoring module generates an alarm message.

11. The apparatus according to claim 10, characterized in that, The device also includes a temperature sensor, a pulse width modulation (PWM) module, and a high-performance monitoring (HPM) module. The safety monitoring data also includes: At least one of the temperature parameters acquired by the temperature sensor, the factory process deviation data acquired by the HPM, and the power supply adjustment parameters acquired by the PWM.

12. The apparatus according to claim 10, characterized in that, The device also includes a clock reset generator (CRG), the alarm information being used to instruct the CRG to reset the device; or, the alarm information being used to instruct the CRG to disable clock driving; or, the alarm information being used to instruct the device to turn off power.

13. The apparatus according to any one of claims 10 to 12, characterized in that, The device also includes a processor, prior to acquiring the security monitoring data: The processor is used to load the offline training data into the storage unit of the intelligent monitoring module, wherein the processor is a security processor or an application processor; Alternatively, the intelligent monitoring module can be used to load the offline training data into the storage unit of the intelligent monitoring module via direct storage access (DMA).

14. The apparatus according to any one of claims 10 to 12, characterized in that, If the offline training data is compressed data, before matching the security monitoring data with the pre-configured offline training data, the intelligent monitoring module is further configured to: The offline training data is decompressed to obtain the decompressed offline training data.

15. The apparatus according to any one of claims 10 to 12, characterized in that, The intelligent monitoring module is specifically used for: The frequency of acquiring the security monitoring data is determined based on the different business scenarios of the device; The security monitoring data is obtained based on the frequency.

16. The apparatus according to any one of claims 10 to 12, characterized in that, The offline training data is obtained by offline training of multiple security monitoring data of the device based on artificial intelligence (AI) algorithms. The data types of the offline training data include at least one of the following: attacked type, normal operation type, overcurrent protection type, and false trigger type.

17. The apparatus according to any one of claims 10 to 12, characterized in that, The intelligent monitoring module is specifically used for: Based on the business scenario of the device, a target AI algorithm that is suitable for the business scenario is selected from multiple AI algorithms; The target data type is obtained by matching the security monitoring data with the offline training data based on the target AI algorithm.

18. The apparatus according to any one of claims 10 to 12, characterized in that, The intelligent monitoring module includes a data backup program or a security verification and protection program. The data backup program is used to back up the control signals, wherein the control signals are used to enable the processor to select the function of the intelligent monitoring module. The security verification and protection program is used to protect the intelligent monitoring module from acquiring the security monitoring data.

19. A readable storage medium, characterized in that, The readable storage medium stores instructions that, when executed on a computer or processor, cause the computer or processor to perform the security detection method as described in any one of claims 1-9.

20. A computer program product, characterized in that, When the computer program product is run on a computer, the computer performs the security detection method according to any one of claims 1-9.

Citation Information

Patent Citations

  • Electrical fire hazard intelligent detection method, system, device and medium

    CN109920193A