Data security monitoring system and data security monitoring method
By adding a monitoring module during the data transmission between the sensor chip and the ECU, and using verification codes to monitor faults during the data transmission process, data errors caused by signal interference are solved, and the security and reliability of the system are improved.
Patent Information
- Application Number
- CN202510570812.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-30
- Publication Date
- 2025-08-12
AI Technical Summary
During the data transmission process between the sensor chip and the ECU, signal interference leads to data transmission errors, affecting the system's safety performance, making it difficult to meet the high automotive safety integrity level, and the overall failure efficiency of the output stage is high.
The monitoring module is added during the data transmission process, and the verification code is inserted through the receiving module, the framing module generates the verification code, and calculates the monitoring information to generate a fault signal to monitor the fault during the data transmission process.
It achieves a high coverage of fault diagnosis for the data transmission process, improves the security and reliability of system data transmission, reduces failure efficiency, and ensures the security of the overall output stage.
Smart Images

Figure CN120474957A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of data security monitoring, and in particular to a data security monitoring system and a data security monitoring method. Background Art
[0002] During the transmission of sensor chip data to the upper-level Electronic Control Unit (ECU), if data transmission errors occur due to signal interference, the overall safety performance of the system will be affected. In the automotive electronics field, sensor data output by sensor chips is typically transmitted to the ECU via the PSI5 (Peripheral Sensor Interface 5) protocol. PSI5 is a communication protocol designed specifically for automotive sensors and is widely used in automotive sensors such as speed, position, and angle sensors. It supports both synchronous and asynchronous communication modes.
[0003] The PSI5 module in the chip is located at the output stage. It receives digital data uploaded by the sensor, fills the data to the specified length in the framing module, frames the data with related fields, and then encodes it through the conversion module and sends it from the digital domain to the analog domain. The current source in the analog domain completes the output of analog data according to the PSI5 protocol. The correct operation of the output stage (including the digital and analog parts of PSI5) has a direct impact on ensuring the correctness of data transmission. Data transmission errors in any part may cause the output message to deviate from the expected, affecting the execution of the upper-level ECU safety function, and thus causing a hazardous event. From a chip level, the overall failure rate of the output stage is relatively high, making it difficult to meet high Automotive Safety Integrity Level (ASIL) requirements. Summary of the Invention
[0004] The present application provides a data security monitoring system and a data security monitoring method, aiming to improve the security and reliability of data transmission between sensor chips and ECUs.
[0005] According to the first aspect of the present application, the present application provides a data security monitoring system, including: a receiving module, which is configured to receive first data and determine the data type of the first data, and if the data type of the first data is sensor data, output a first check code; a framing module, which is configured to generate second data based on the first data, wherein the second data includes a second check code; a monitoring module, which is configured to calculate first monitoring information based on the first check code and the second check code, and generate a fault signal based on the first monitoring information, wherein the first monitoring information indicates whether the first check code and the second check code are the same.
[0006] According to the second aspect of the present application, the present application provides a data security monitoring method, including: receiving first data and determining the data type of the first data, and if the data type of the first data is sensor data, outputting a first check code; generating second data based on the first data, wherein the second data includes a second check code; calculating first monitoring information based on the first check code and the second check code, wherein the first monitoring information indicates whether the first check code and the second check code are the same; and generating a fault signal based on the first monitoring information.
[0007] Through one or more of the above embodiments of the present application, at least the following technical effects can be achieved:
[0008] This application implements monitoring of data correctness during transmission from the receiving module to the framing module by adding a monitoring module that calculates and generates a fault signal based on first monitoring information indicating whether the first check code and the second check code are identical. When a fault signal is generated, it indicates a fault in the data transmission process, achieving high fault diagnosis coverage, ensuring the safety of the overall output level, effectively reducing the failure rate, and improving the security and reliability of the system data transmission process. BRIEF DESCRIPTION OF THE DRAWINGS
[0009] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For those skilled in the art, other drawings can be obtained based on these drawings without creative work.
[0010] Figure 1 A schematic diagram of the data transmission structure between the sensor and the ECU is given;
[0011] Figure 2 A structural diagram of a data security monitoring system according to an embodiment of the present application is provided;
[0012] Figure 3 A structural diagram of a data security monitoring system according to an embodiment of the present application is provided;
[0013] Figure 4 A flow chart of a data security monitoring method according to an embodiment of the present application is provided. DETAILED DESCRIPTION
[0014] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the embodiments described are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without making creative efforts are within the scope of protection of this application.
[0015] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequential order. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in a sequence other than those illustrated or described herein. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0016] It should be understood that in the following description, a "circuit" refers to a conductive loop formed by at least one element or subcircuit connected electrically or electromagnetically. When an element or circuit is said to be "connected to" another element or an element / circuit is said to be "connected" between two nodes, it can be directly coupled or connected to the other element or there can be intermediate elements. The connection between the elements can be physical, logical, or a combination thereof. Conversely, when an element is said to be "directly coupled to" or "directly connected to" another element, it means that there are no intermediate elements between the two elements.
[0017] Figure 1 A schematic diagram of the data transmission structure between sensors and ECU is given. Figure 1The ECU chip's output stage is equipped with a PSI5 module. External sensors connect to the PSI5 module via twisted-pair cables for data transmission. Sensors, such as the collision pressure sensor shown in the figure, can connect directly to the PSI5 module for data transmission. Alternatively, they can be connected to other sensors first, using the other sensors as an intermediary for data transmission with the PSI5 module. A twisted-pair cable is a cable consisting of two insulated copper wires twisted together at a certain density. When used for data transmission, the radio waves radiated by one wire are offset by those on the other wire. Differential circuitry eliminates common-mode signals and extracts differential-mode signals. Transmission over twisted-pair cables suppresses common-mode interference, minimizing the impact of external electromagnetic interference on signals and ensuring stable signal transmission even in high-interference environments. Within the ECU chip, the PSI5 module uses a bidirectional receive (RX) and transmit (TX) channel to communicate with upper-layer units. The PSI5 module and upper-layer units are also connected via the SPI bus, which transmits a clock signal to ensure accurate and reliable data transmission between master and slave devices.
[0018] In the ECU chip and sensor, the PSI5 module can be divided into a digital domain and an analog domain. The digital domain receives data frames sent by the sensor. These data frames follow the format defined by the PSI5 protocol to ensure data consistency and standardization. The data types output by the sensor can include sensor data, initialization data, and status data. The sensor data is valid sensor data after being processed by a digital signal processor (DSP). The initialization data can be the product ID and related configuration information of the sensor. The status data is the status information of the sensor, including the corresponding fault code. Among them, the transmission of initialization data is only enabled in the initialization phase after the sensor is connected. After the initialization is completed and enters the normal operating mode, the sensor data processed by the DSP will be output to the outside.
[0019] If a sensor fails during operation, the fault handling unit assigns a fault code based on the failure type and transmits it to the PSI5 module for an alert. After receiving the three types of raw data, the PSI5 module performs data truncation, padding, and Manchester encoding according to pre-set configuration information. The encoded data is then passed to the analog current source for output as current. During the transmission process from the digital to the analog domain, interference at any point can cause signal errors, resulting in invalid output messages.
[0020] In response to the above problems, the present application provides a data security monitoring system, which can improve the security and reliability of system data transmission and monitor data transmission errors.
[0021] Figure 2A structural diagram of a data security monitoring system according to an embodiment of the present application is given. The data security monitoring system includes a receiving module, a framing module and a monitoring module. The receiving module is configured to receive first data and determine the data type of the first data. If the data type of the first data is sensor data, a first check code is output. The framing module is configured to generate second data based on the first data, wherein the second data includes a second check code. The monitoring module is configured to calculate first monitoring information based on the first check code and the second check code, and generate a fault signal based on the first monitoring information, wherein the first monitoring information indicates whether the first check code and the second check code are the same.
[0022] Figure 3 A structural diagram of a data security monitoring system according to an embodiment of the present application is given. Figure 3 In the embodiment shown, the receiving module sends data in sequence according to the pre-assigned time slots. The receiving module can receive multiple groups of data at the same time and insert a check code into each group of data. During the data communication process, the time slots are counted sequentially. When the specified time slot is reached, a corresponding group of data is selected and output as the first data. If the data type of the group of data is sensor data, the check code corresponding to the group of data is output as the first check code at the same time. The framing module generates the second data based on the first data, and encodes and sends it bit by bit in a specific order, and calculates the check code bit by bit synchronously. When the last 1 bit of data is sent, the second check code can be obtained and output to the monitoring module. The first monitoring information is calculated by the first check code and the second check code. For example, the first monitoring information indicates whether the first check code and the second check code are the same. The fault signal is generated based on the calculation of the first monitoring information, and it can monitor whether a fault occurs in the transmission path from data input to data encoding, thereby realizing the monitoring of data correctness and improving the security and reliability of the system data transmission process.
[0023] exist Figure 3 In the illustrated embodiment, the monitoring module includes a first checking module, the first checking module being configured to receive a first check code and a second check code, and calculate first monitoring information based on the first check code and the second check code. The monitoring module also includes a fault counting module, the fault counting module performing fault counting based on the first monitoring information. Exemplarily, the first check code and the second check code are compared, and when the first check code and the second check code are inconsistent, the fault count is increased by a preset value based on the first monitoring information. When the first check code and the second check code are consistent, the fault count is decreased by a preset value based on the first monitoring information. When the value of the fault count is greater than a fault count threshold, a fault signal is generated. The fault count threshold can be set according to the requirements of the system safety level.
[0024] In some embodiments, the monitoring module further includes a counting module configured to generate a first selection signal and a second selection signal based on a preset synchronization cycle. Within a synchronization cycle, the data security monitoring system can send multiple messages (slots), and the data sent in different slots may be different types of sensor data, such as angle and angular velocity. The counting module is used to verify the slot data allocation to prevent the transmission of unexpected data. A synchronization cycle is divided into multiple time slots. Counting begins at the initial time of the synchronization cycle and obtains the count value for each time slot in the synchronization cycle. When the count value equals the time slot initial time value slotx start time, the first selection signal and the second selection signal are generated. In some embodiments, the counting module may include a first counter. When the count value equals the time slot initial time value slotx start time, the value of the first counter is updated to x, thereby selecting the xth group of data in the input data bus as the data to be transmitted. A second counter is generated by retaining a redundant circuit. When the count value equals the time slot initial time value slotx start time, the values of the first counter and the second counter are compared to ensure consistency, thereby monitoring the correctness of the data type.
[0025] In some embodiments, the monitoring module further includes a second checking module configured to receive the first and second selection signals and calculate second monitoring information based on the first and second selection signals, wherein the second monitoring information indicates whether the first and second selection signals are identical. The monitoring module is configured to generate a fault signal based on the first and second monitoring information. Specifically, the fault counting module generates the fault signal based on the first and second monitoring information. The module compares the first and second check codes. If the first and second check codes do not match, the fault count is incremented by a preset value based on the first monitoring information. If the first and second check codes match, the fault count is decremented by a preset value based on the first monitoring information. The module compares the first and second selection signals. If the first and second selection signals do not match, the fault count is incremented by a preset value based on the second monitoring information. If the first and second selection signals match, the fault count is decremented by a preset value based on the second monitoring information. A fault signal is generated when the fault count exceeds a fault count threshold. A fault signal is generated based on the first monitoring information and the second monitoring information, which can monitor whether there is a fault in the data path from data input to data encoding, thereby monitoring the correctness of the data, and can also monitor whether the data type in the data distribution is consistent, thereby monitoring the correctness of the data type.
[0026] In some embodiments, the system further includes a conversion module configured to generate third data based on the second data, wherein the third data includes a third checksum. In some embodiments, the first data is a digital signal, the second data is a digital signal, and the third data is an analog signal. The conversion module generates the third data based on the second data to achieve signal conversion from the digital domain to the analog domain. In this process, in addition to faults caused by circuit failure, faults caused by environmental interference may also occur, ultimately resulting in the output of an unexpected current waveform.
[0027] In some embodiments, the monitoring module may further include a third checking module configured to receive the second and third check codes and calculate third monitoring information based on the second and third check codes, wherein the third monitoring information indicates whether the second and third check codes are identical. The monitoring module is configured to generate a fault signal based on the first, second, and third monitoring information. Specifically, the fault counting module generates the fault signal based on the first, second, and third monitoring information. The module compares the first and second check codes. If the first and second check codes are inconsistent, the fault count is incremented by a preset value based on the first monitoring information. If the first and second check codes are consistent, the fault count is decremented by a preset value based on the first monitoring information. The module compares the first and second selection signals. If the first and second selection signals are inconsistent, the fault count is incremented by a preset value based on the second monitoring information. If the first and second selection signals are consistent, the fault count is decremented by a preset value based on the second monitoring information. The module compares the second and third check codes. If the second and third check codes are inconsistent, the fault count is incremented by a preset value based on the third monitoring information. When the second check code and the third check code match, the fault count is reduced by a preset value based on the third monitoring information. When the fault count exceeds the fault count threshold, a fault signal is generated. Generating a fault signal based on the first, second, and third monitoring information allows for simultaneous monitoring of data accuracy and data type correctness, while also enabling loop monitoring of the conversion between the digital and analog domains.
[0028] In some embodiments, the system further includes a conversion module configured to generate third data based on the second data, wherein the third data includes a third check code. The monitoring module further includes a third check module configured to receive the second check code and the third check code and calculate third monitoring information based on the second check code and the third check code, wherein the third monitoring information indicates whether the second check code and the third check code are identical. The monitoring module is configured to generate a fault signal based on the first monitoring information and the third monitoring information. The monitoring module may only include the first check module, the third check module, and the fault counting module. The first check module is configured to compare whether the first check code and the second check code are identical, and based on the comparison result, increase or decrease the fault count by a preset value. The third check module is configured to compare whether the second check code and the third check code are identical, and based on the comparison result, increase or decrease the fault count by a preset value. When the fault count exceeds a fault count threshold, a fault signal is generated. Generating a fault signal based on the first and third monitoring information can monitor whether a fault occurs in the data path from data input to data encoding, as well as in the data path after data encoding and conversion to analog signals.
[0029] In some embodiments, the monitoring module further includes a current detector configured to sample the third data to obtain a third check code, and transmit the third check code to the third checking module. The current detector can collect the actual output current waveform and return it to the digital domain, decode it to obtain the third check code, and then perform a bit-by-bit comparison of the second check code and the third check code in the third checking module.
[0030] The third data sampled by the current detector is Manchester code. Manchester code, also known as digital bidirectional code, phase-split code, or phase encoding (PE), is a commonly used baseband signal encoding scheme. A Manchester code symbol period consists of a first half-period and a second half-period. For a logic "1," the signal transitions from a low level to a high level at half a symbol. For a logic "0," the signal transitions from a high level to a low level at half a symbol. The transition edges within each symbol period are identified to determine whether the decoding result is 0 or 1. Two samplings are performed within each symbol period. If the two sampled values are 0 and 1, respectively, the decoding is 0; if the two sampled values are 1 and 0, respectively, the decoding is 1; and if the two sampled values are 00 or 11, respectively, a Manchester code error occurs. While the third data is being transmitted, the current detector decodes the sampled third data to generate a third check code. Comparing the third check code with the second check code enables monitoring of the data path between the data encoding and the analog current modulation circuit. In some embodiments, the PSI5 current protocol standard stipulates that the start bits of each data frame must first be sent as 2 bits of 0 data. This means that the start bits of the data frame must be checked separately to see if the first 2 bits of sampled data are both 0. Furthermore, the timing of the Manchester code can also be checked. The transition edge of the standard Manchester code occurs at 1 / 2 of each symbol period. If no transition edge is detected at 1 / 2 of the symbol period, the Manchester code timing is considered to be incorrect.
[0031] This application also provides a data security monitoring method. Figure 4 A flow chart of a data security monitoring method according to an embodiment of the present application is provided. The monitoring method includes steps 101 to 104.
[0032] Step 101: Receive first data, insert a first check code into the first data, and determine the data type of the first data. If the data type of the first data is sensor data, output the first check code.
[0033] Step 102: Generate second data based on the first data, wherein the second data includes a second check code.
[0034] Step 103: Calculate first monitoring information according to the first check code and the second check code, wherein the first monitoring information indicates whether the first check code and the second check code are the same.
[0035] Step 104: Generate a fault signal based on the first monitoring information.
[0036] The first monitoring information represents whether the first check code and the second check code are the same. Based on the first monitoring information, a fault signal is calculated and generated, so as to monitor whether a fault occurs in the transmission path from data input to data encoding, thereby realizing the monitoring of data correctness and improving the security and reliability of the system data transmission process.
[0037] In some embodiments, the monitoring method may further include: generating a first selection signal and a second selection signal according to a preset synchronization period, and calculating second monitoring information based on the first selection signal and the second selection signal. The second monitoring information represents whether the first selection signal and the second selection signal are the same. The step of generating a fault signal based on the first monitoring information may include: generating a fault signal based on the first monitoring information and the second monitoring information. Generating a fault signal based on the first monitoring information and the second monitoring information can not only monitor whether a fault occurs in the data path from data input to data encoding, thereby monitoring the correctness of the data, but also monitor whether the data types in data allocation are consistent, thereby monitoring the correctness of the data types.
[0038] In some embodiments, the synchronization period includes multiple time slots, and the step of generating the first selection signal and the second selection signal according to the preset synchronization period may include: starting counting at an initial time of the synchronization period, obtaining a count value for each time slot in the synchronization period, and generating the first selection signal and the second selection signal when the count value equals the value at the initial time of the time slot.
[0039] In some embodiments, the monitoring method may further include: generating third data based on the second data, wherein the third data includes a third check code. Calculating third monitoring information based on the second check code and the third check code, wherein the third monitoring information indicates whether the second check code and the third check code are the same. The step of generating a fault signal based on the first monitoring information may include: generating a fault signal based on the first monitoring information, the second monitoring information, and the third monitoring information. Generating a fault signal based on the first monitoring information, the second monitoring information, and the third monitoring information can simultaneously monitor data correctness and data type correctness, and implement loop monitoring for the conversion portion of the digital domain and the analog domain.
[0040] In some embodiments, the third data is an analog signal, and the third check code is obtained based on the third data.
[0041] In some embodiments, the monitoring method may further include: generating third data based on the second data, wherein the third data includes a third check code. Calculating third monitoring information based on the second check code and the third check code, wherein the third monitoring information indicates whether the second check code and the third check code are the same. The step of generating a fault signal based on the first monitoring information may include: generating a fault signal based on the first monitoring information and the third monitoring information. Generating a fault signal based on the first monitoring information and the third monitoring information can monitor whether a fault occurs in the data path from data input to data encoding, and can also monitor whether a fault occurs in the data path from data encoding to conversion to an analog signal.
[0042] In some embodiments, the data type of the first data includes sensor data, initialization data and status data. When the first data is sensor data, the data security monitoring method provided in the above embodiment can achieve end-to-end protection between the receiving module and the framing module and end-to-end protection between the framing module and the conversion module. When the first data is initialization data, its sending scenario is limited to power-on initialization. If an error occurs in the transmission, the upper-level ECU can effectively identify this type of failure by distinguishing the data range. When the first data is status data, the status data represents the chip status, which includes the corresponding fault code (in the case of a failure inside the chip). When no failure occurs inside the chip, a default value different from the valid data area should be set for the corresponding status code. For the third type of data and its path, corresponding safety analysis needs to be performed based on circuit design and application scenarios.
[0043] In some embodiments, the monitoring method further includes monitoring the timing of data transmission to ensure that an alarm signal is output in a timely manner. When the above-mentioned monitoring method is applied to the PSI5 module, the PSI5 protocol standard stipulates that overlap between time slots and time slots, or between time slots and synchronization pulses, is prohibited to avoid bus data confusion. If the counter reaches the next initial moment value during data transmission, it is considered that overlap between time slots has occurred. When this occurs, the data transmission of the current time slot is terminated, and the transmission of the next time slot data is started after a preset time interval, and a fault signal is output at the same time. If a legal synchronization cycle is detected during data transmission, it is considered that overlap between time slots and synchronization cycles has occurred. When this occurs, the data transmission of the current time slot is terminated, the timing of the next counter is restarted, and a fault signal is output at the same time.
[0044] This application realizes the monitoring of data correctness during the data transmission process by adding a monitoring module, and generates a fault signal based on the monitoring information. When the fault signal is generated, it indicates that a fault has occurred in the data transmission process, achieving a high fault diagnosis coverage rate, ensuring the safety of the overall output level, effectively reducing single-point and residual failure rates, and maximizing the reliability of the chip.
[0045] The above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. These modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present application, and should all be included in the scope of protection of the present application.
Claims
1. A data security monitoring system, characterized in that: include: a receiving module configured to receive first data and insert a first check code into the first data, and to determine a data type of the first data and output the first check code if the data type of the first data is sensor data; a framing module, configured to generate second data based on the first data, wherein the second data includes a second check code; The monitoring module is configured to calculate first monitoring information according to the first check code and the second check code, and generate a fault signal based on the first monitoring information, wherein the first monitoring information indicates whether the first check code and the second check code are the same.
2. The data security monitoring system according to claim 1, characterized in that: The monitoring module includes a first checking module, which is configured to receive a first check code and a second check code, and calculate first monitoring information according to the first check code and the second check code.
3. The data security monitoring system according to claim 1, characterized in that: The monitoring module further includes a counting module configured to generate a first selection signal and a second selection signal according to a preset synchronization period.
4. The data security monitoring system according to claim 3, characterized in that: The monitoring module further includes a second checking module, the second checking module being configured to receive the first selection signal and the second selection signal, and calculate second monitoring information based on the first selection signal and the second selection signal, wherein the second monitoring information indicates whether the first selection signal and the second selection signal are the same; The monitoring module is configured to generate a fault signal based on the first monitoring information and the second monitoring information.
5. The data security monitoring system according to claim 4, characterized in that: The system further includes a conversion module configured to generate third data based on the second data, wherein the third data includes a third check code; The monitoring module further includes a third checking module, configured to receive the second check code and the third check code, and calculate third monitoring information based on the second check code and the third check code, wherein the third monitoring information indicates whether the second check code and the third check code are the same; The monitoring module is configured to generate a fault signal based on the first monitoring information, the second monitoring information, and the third monitoring information.
6. The data security monitoring system according to claim 1, characterized in that: The system further includes a conversion module configured to generate third data based on the second data, wherein the third data includes a third check code; The monitoring module further includes a third checking module, configured to receive the second check code and the third check code, and calculate third monitoring information based on the second check code and the third check code, wherein the third monitoring information indicates whether the second check code and the third check code are the same; The monitoring module is configured to generate a fault signal based on the first monitoring information and the third monitoring information.
7. The data security monitoring system according to claim 5 or 6, characterized in that: The third data is an analog signal. The monitoring module further includes a current detector, which is used to sample the third data to obtain the third check code and send the third check code to the third checking module.
8. A data security monitoring method, characterized in that: include: receiving first data, inserting a first check code into the first data, and determining a data type of the first data, and outputting a first check code if the data type of the first data is sensor data; generating second data based on the first data, wherein the second data includes a second check code; Calculating first monitoring information according to the first check code and the second check code, wherein the first monitoring information indicates whether the first check code and the second check code are the same; A fault signal is generated based on the first monitoring information.
9. The data security monitoring method according to claim 8, characterized in that: generating a first selection signal and a second selection signal according to a preset synchronization period; calculating second monitoring information according to the first selection signal and the second selection signal, wherein the second monitoring information indicates whether the first selection signal and the second selection signal are the same; Wherein, the step of generating a fault signal based on the first monitoring information includes: generating the fault signal based on the first monitoring information and the second monitoring information.
10. The data security monitoring method according to claim 9, characterized in that: The method further comprises: generating third data based on the second data, wherein the third data includes a third check code; Calculating third monitoring information based on the second check code and the third check code, wherein the third monitoring information indicates whether the second check code and the third check code are the same; Wherein, the step of generating a fault signal based on the first monitoring information includes: generating the fault signal based on the first monitoring information, the second monitoring information and the third monitoring information.
11. The data security monitoring method according to claim 8, characterized in that: The method further comprises: generating third data based on the second data, wherein the third data includes a third check code; Calculating third monitoring information based on the second check code and the third check code, wherein the third monitoring information indicates whether the second check code and the third check code are the same; Wherein, the step of generating a fault signal based on the first monitoring information includes: generating the fault signal based on the first monitoring information and the third monitoring information.
12. The data security monitoring method according to claim 8, characterized in that: The step of calculating the first monitoring information according to the first check code and the second check code includes: Comparing the first check code and the second check code, when the first check code and the second check code are inconsistent, increasing the fault count by a preset value; when the first check code and the second check code are consistent, decreasing the fault count by a preset value; The step of generating a fault signal based on the first monitoring information includes: generating the fault signal when the value of the fault count is greater than a fault count threshold.
13. The data security monitoring method according to claim 9, characterized in that: The synchronization period includes a plurality of time slots, and the step of generating the first selection signal and the second selection signal according to the preset synchronization period includes: Start counting at the initial moment of the synchronization cycle and obtain the count value of each time slot in the synchronization cycle; When the count value is equal to the time slot initial time value, a first selection signal and a second selection signal are generated.
14. The data security monitoring method according to claim 8, characterized in that: The data types of the first data include sensing data, initialization data and status data.
15. The data security monitoring method according to claim 10, characterized in that: The third data is an analog signal, and the third check code is obtained based on the third data.