Method, system, and program product for performing rationality verification of electrical signal
The method filters ripple interference in redundant measurement devices by comparing sampling values and adjusting a fault counter, ensuring reliable fault detection and improved system robustness in safety-critical applications.
Patent Information
- Application Number
- PCT/EP2025/068168
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-07-11
- Filing Date
- 2025-06-26
- Publication Date
- 2026-01-15
AI Technical Summary
In safety-critical applications, redundant measurement devices can produce false alarms due to differences in measurement signals caused by interference such as ripple, leading to unnecessary interference and reduced system robustness.
A method and system that filters out ripple interference by comparing sampling values from different sampling apparatuses using predefined thresholds and adjusting a fault counter based on the sign and magnitude of the difference, ensuring reliable fault detection.
The method effectively filters out ripple interference, preventing false alarms and improving system robustness by accurately determining fault conditions.
Smart Images

Figure EP2025068168_15012026_PF_FP_ABST
Abstract
Description
METHOD, SYSTEM, AND PROGRAM PRODUCT FOR PERFORMING RATIONALITY VERIFICATION OF ELECTRICAL SIGNALTECHNICAL FIELD
[0001] The present application relates to a method for performing a rationality check on an electrical signal. In addition, the present application relates to a system for performing a rationality check on an electrical signal and a computer program product.BACKGROUND
[0002] In a safety-critical application scenario, it is often necessary to ensure that related safety-critical parameters can be accurately obtained at any time. For this purpose, a plurality of measurement devices, such as two measurement devices, are generally redundantly arranged to acquire such parameters, so that mutual checking can be performed and a fault condition can be promptly discovered. However, a difference between the measurement devices and a signal characteristic of the measured parameter itself, for example, interference, such as ripple interference, in the signal may lead to a large difference between measurement signals of the two measurement devices, thereby causing a false alarm about a fault condition and causing unnecessary interference.SUMMARY
[0003] A task on which the present application is based is to propose an improved technical solution that can filter out a ripple interference signal, thus avoiding a false alarm about a fault condition and improving system robustness.
[0004] The task is solved by means of a method for performing a rationality check on an electrical signal, a system for performing a rationality check on an electrical signal, and a computer program product. The following further describes in detail preferred implementations of the present application.
[0005] According to a first aspect of the present application, a method for a performing rationality check on an electrical signal is proposed, the method comprising:
[0006] obtaining from a first sampling apparatus a first sampling value of the electrical signal, and obtaining from a second sampling apparatus a second sampling value of the electrical signal, so as to determine a sampling difference value between the first sampling value and the second sampling value;
[0007] performing a first comparison between the sampling difference value and a predefined first threshold; and
[0008] determining, based on the sign of the sampling difference value and a result of the first comparison, a corresponding count operation for a fault counter.
[0009] In the scope of the present application, the first sampling apparatus and the second sampling apparatus are different sampling apparatuses or detection apparatuses arranged redundantly to test a same electrical signal. Herein, the first sampling apparatus and the second sampling apparatus may be detection apparatuses of different types or configurations, or may be detection apparatuses of a same type that are separately arranged. Herein, because of a characteristic difference such as a cut-off frequency and a delay characteristic, and a possible error such as a design error and a measurement error, the first sampling value and the second sampling value that are respectively detected by the first sampling apparatus and the second sampling apparatus have different amplitudes and / or phases for the same electrical signal.
[0010] In the scope of the present application, the predefined first threshold refers to a signal threshold, and is used to represent an allowable range of the sampling difference value in a rationality check. Herein, the predefined first threshold may be understood as a threshold range, or may be understood as a positive upper threshold and a negative lower threshold. The positive upper threshold and the negative lower threshold may be the same or different in terms of absolute value.
[0011] In the scope of the present application, the sampling difference value exceeding the predefined first threshold means that the absolute value of the sampling difference value is, in terms of absolute value, greater than the absolute value of the positive upper threshold or the absolute value of the negative lower threshold.
[0012] In the scope of the present application, the sign of the sampling difference value may be understood as a positive sign and a negative sign. If the sign of the sampling difference value is positive, it indicates that the first sampling value is greater than the second sampling value. If the sign of the sampling difference is negative, it indicates that the first sampling value is less than the second sampling value. Or vice versa.
[0013] In the scope of the present application, fault duration or fault maturity time is measured by using a count value of the fault counter.
[0014] In the present application, in the rationality check on the electrical signal, especially in the determination of the fault maturity time, the positive or negative sign of the sampling difference value are taken into consideration, periodic interference of a ripple signal, such as a (similar) sine-cosine type, is filtered out, a false alarm about a fault in a sampling rationality check on the electrical signal is avoided, and system robustness is improved while safety and reliability are ensured.
[0015] According to a preferred implementation of the present application, if the sign of the sampling difference value is positive, a first count operation is performed on the fault counter, and if the sign of the sampling difference is negative, a second count operation is performed on the fault counter.
[0016] According to a preferred implementation of the present application, if the result of the first comparison indicates that the sampling difference value exceeds the predefined first threshold, a first sub-count operation of a corresponding count operation is performed on the fault counter, and if the result of the comparison indicates that the sampling difference value does not exceed the predefined first threshold, a second sub-count operation of a corresponding count operation is performed on the fault counter.
[0017] According to a preferred implementation of the present application, the corresponding count operations differs in at least one of the following aspects: operation direction, operation target, and operation scale. Herein, the corresponding count operations comprise the first count operation and the second count operation, and the respective first sub-count operation and second sub-count operation thereof.
[0018] In the scope of the present application, the first count operation and the second count operation refer to performing an incremental count operation (the operation direction is positive) or a decremental count operation (the operation direction is negative) on the fault counter, and the incremental count operation or the decremental count operation can have the same step value or different step values (operation scale) depending on a specific situation. For example, the step value may be 1 , 2, or 3, that is, increased by one (decreased by one), increased by two (decreased by two), increased by three (decreased by three), etc. For example, for a same fault counter, the first count operation and the second count operation have different count directions, for example, the first count operation is an incremental count operation, and the second count operation is a decremental count operation, or vice versa. For example, for different fault counters (operation targets), the first count operation and the second count operation may have different count directions or may have the same count direction.
[0019] Advantageously, the fault counter or the fault maturity time is subjected to a corresponding, especially associated, count operation based on the positive or negative sign of the sampling difference value, thereby more reliably determining a fault or the duration thereof.
[0020] In the scope of the present application, the first sub-count operation and the second sub-count operation of the corresponding count operations (the first count operation and / or the second count operation) refer to, especially, performing an incremental count operation (the operation direction is positive) or a decremental count operation (the operation direction is negative) on the fault counter for a same sign, especially in relation to the amplitude of the sampling difference value. Herein, the first sub-countoperation and the second sub-count operation differ at least in terms of operation direction. Preferably, the first sub-count operation and the second sub-count operation also differ in terms of operation scale. It can be understood that, for a same direction, the first sub-count operation and the second sub-count operation are performed in this way until the count value of the fault counter is zero. For example, for the positive direction, when the count value of the fault counter is currently positive, if the sampling difference value does not exceed the predefined first threshold, a decremental count operation is performed on the count value of the fault counter until the count value of the fault counter is zero. For example, for the negative direction, when the count value of the fault counter is currently negative, if the sampling difference does not exceed the predefined first threshold, an incremental count operation is performed on the count value of the fault counter until the count value of the fault counter is zero. Alternatively or additionally, for the same direction, when the number of times of consecutive execution of the second sub-count operation exceeds a predetermined threshold, a count value of a corresponding fault counter can be zeroed or reset.
[0021] Advantageously, a fault or the duration thereof can be more reliably determined based on a change pattern of the absolute value of the sampling difference value relative to the predefined first threshold.
[0022] According to a preferred implementation of the present application, if the result of the first comparison indicates that the sampling difference value exceeds the predefined first threshold and the sign of the sampling difference value is positive, a first count operation is performed on the fault counter, and if the result of the comparison indicates that the sampling difference value exceeds the predefined first threshold and the sign of the sampling difference value is negative, a second count operation is performed on the fault counter.
[0023] For example, the first count operation (for example, increasing by one) is performed on the fault counter such that faults accumulate by one in the positive direction and are simultaneously reduced by one in the negative direction, and the second count operation (for example, decreasing by one) is performed on the fault counter such that the faults accumulate by one in thenegative direction and are simultaneously reduced by one in the positive direction. Therefore, when the electrical signal is interfered with by a ripple signal, the count value of the fault counter is periodically increased by one or decreased by one, and the absolute value of the fault counter does not present a trend of always accumulating in a certain direction (a positive or negative direction), but, in terms of an overall trend, fluctuates relatively stably within a certain range (for example, within a predefined second threshold), so that a fault in a rationality check on the electrical signal is not misreported.
[0024] Advantageously, the sign of the sampling difference value is taken into account here in association with the absolute value of the sampling difference value, thereby making it possible to more reliably determine a fault or the duration thereof. In addition, only a single fault counter needs to be arranged herein, thereby reducing hardware costs and computational complexity.
[0025] According to a preferred implementation of the present application, if the result of the first comparison indicates that the sampling difference value exceeds the predefined first threshold and the sign of the sampling difference value or the sign of a cumulative value of the fault counter is positive, a first sub-count operation of a first count operation is performed on the fault counter; if the result of the first comparison indicates that the sampling difference value does not exceed the predefined first threshold and the sign of the sampling difference value or the sign of the cumulative value of the fault counter is positive, a second sub-count operation of the first count operation is performed on the fault counter; if the result of the comparison indicates that the sampling difference value exceeds the predefined first threshold and the sign of the sampling difference value or the sign of the cumulative value of the fault counter is negative, a first sub-count operation of a second count operation is performed on the fault counter; and if the result of the comparison indicates that the sampling difference value does not exceed the predefined first threshold and the sign of the sampling difference value or the sign of the cumulative value of the fault counter is negative, a second sub-count operation of the second count operation is performed on the fault counter.
[0026] Advantageously, the sign of the sampling difference value and the absolute value of the sampling difference value are taken into account here in association with the change pattern of the predefined first threshold (greater than the first threshold along with less than the first threshold), so that a fault or the duration thereof can be more reliably determined. In addition, only a single fault counter needs to be arranged herein, thereby reducing hardware costs and computational complexity.
[0027] According to a preferred implementation of the present application, a second comparison is performed between a count value of the fault counter and a predefined second threshold, and rationality verification is performed on the electrical signal based on a result of the second comparison.
[0028] In the scope of the present application, the predefined second threshold refers to a time threshold, and is used to represent an allowable range of fault duration or a critical range of fault maturity time in a rationality check. Herein, the predefined second threshold may be understood as a threshold range, or may be understood as a positive upper threshold and / or a negative lower threshold. The positive upper threshold and / or the negative lower threshold may be the same or different in terms of absolute value.
[0029] According to a preferred implementation of the present application, if the result of the first comparison indicates that the sampling difference value exceeds the predefined first threshold and the sign of the sampling difference value is positive, a corresponding count operation is performed on a first subfault counter of the fault counter, and if the result of the comparison indicates that the sampling difference value exceeds the predefined first threshold and the sign of the sampling difference value is negative, a corresponding count operation is performed on a second sub-fault counter of the fault counter.
[0030] According to a preferred implementation of the present application, if the result of the first comparison indicates that the sampling difference value exceeds the predefined first threshold and the sign of the sampling difference value is positive, a first count operation is performed on a first sub-fault counter of the fault counter; if the result of the first comparison indicates that the sampling difference value does not exceed the predefined first threshold andthe sign of the sampling difference value is positive, a second count operation is performed on the first sub-fault counter of the fault counter; if the result of the comparison indicates that the sampling difference value exceeds the predefined first threshold and the sign of the sampling difference value is negative, a first count operation is performed on a second sub-fault counter of the fault counter; and if the result of the comparison indicates that the sampling difference value does not exceed the predefined first threshold and the sign of the sampling difference value is negative, a second count operation is performed on the second sub-fault counter of the fault counter.
[0031] According to a preferred implementation of the present application, a count difference value between a first count value of the first sub-fault counter and a second count value of the second sub-fault counter is determined as a count value of the fault counter, a second comparison is performed between the count value of the fault counter and the predefined second threshold, and rationality verification is performed on the electrical signal based on a result of the second comparison.
[0032] According to a preferred implementation of the present application, it is determined that the electrical signal is irrational if a result of the second comparison indicates that a count value of the fault counter exceeds the predefined second threshold, and it is determined that the electrical signal is rational if the result of the second comparison indicates that the count value of the fault counter does not exceed the predefined second threshold.
[0033] In the scope of the present application, the count value of the fault counter exceeding the predefined second threshold means that the count value of the fault counter is, in terms of absolute value, greater than or equal to the absolute value of the positive upper threshold or the negative lower threshold. In other words, the fault duration is greater than or equal to an allowable duration, or the fault is “mature”. Conversely, the count value of the fault counter not exceeding the predefined second threshold means that the count value of the fault counter is, in terms of absolute value, less than the absolute value of the positive upper threshold or the negative lower threshold.In other words, the fault duration is less than an allowable duration, or the fault is “immature”.
[0034] Advantageously, when the predefined second threshold is reasonably set, a false alarm about a fault can be avoided, so that rationality verification of an electrical signal is safe, reliable, and robust.
[0035] According to a second aspect of the present application, a system for performing a rationality check on an electrical signal is provided, and the system can execute the method according to the present application.
[0036] According to a third aspect of the present application, a computer program product, such as a computer-readable program medium, is provided, the computer program product comprising or storing computer program instructions, and when the computer program instructions are run by a processor, the computer program instructions are capable of executing the method according to the present application.
[0037] Herein, features and details described with reference to the method for performing a rationality check on an electrical signal according to the present application are also applicable to the system for performing a rationality check on an electrical signal according to the present application and the computer program product according to the present application, and vice versa.BRIEF DESCRIPTION OF THE DRAWINGS
[0038] The following describes the present application in more detail with reference to the accompanying drawings. The accompanying drawings show:
[0039] FIG. 1 is a principle flowchart of a method for performing a rationality check on an electrical signal according to the present application;
[0040] FIG. 2 is a principle block diagram of a system for performing a rationality check on an electrical signal according to the present application;
[0041] FIG. 3 is a schematic diagram of a ripple of an electrical signal;
[0042] FIG. 4 is a schematic block diagram of an embodiment of a system for performing a rationality check on an electrical signal according to the present application;
[0043] FIG. 5 is a schematic block diagram of another embodiment of a system for performing a rationality check on an electrical signal according to the present application; and
[0044] FIG. 6 is a schematic block diagram of a computer program product according to the present application.DETAILED DESCRIPTION
[0045] To make the technical tasks, technical solutions, and technical effects of the present application clearer, the following further describes the present application in detail with reference to the accompanying drawings and exemplary embodiments. It should be understood that the exemplary embodiments described herein are used only for illustration, not for limitation.
[0046] In a rationality check on an electrical signal, electrical signals obtained by a plurality of, for example, two measurement devices that are redundantly arranged are usually different. In some cases, this difference is attributed to fault conditions of the measurement devices. In other cases, however, this difference is not attributed to the fault conditions of the measurement devices, but may be attributed to device characteristics of the measurement devices and / or signal characteristics of the electrical signals being measured. In the latter case, it may occur that a large difference exists between electrical signals measured by the two measurement devices, thereby causing a false alarm about a fault condition of the measurement devices, and causing unnecessary interference.
[0047] To resolve the foregoing problem, the present application provides an improved solution for performing a rationality check on an electrical signal, so that signal interference of this type is filtered out in a rationality check on the electrical signal, thereby achieving the purpose of avoiding a false alarm about a fault and improving system robustness.
[0048] The solutions of the present application are described in detail in the following by using specific embodiments. Herein, features and advantages in a specific embodiment and in each specific embodiment may be mutually combined.
[0049] For ease of understanding, a schematic diagram of a ripple of an electrical signal shown in FIG. 3 is first described herein.
[0050] In FIG. 3, time t is drawn on the horizontal axis, and an electrical signal is drawn on the vertical axis, which is a current I herein.
[0051] In FIG. 3, a steady-state current I0 is shown by using a dashed line parallel to the horizontal axis, and two curves 11 and I2 in a sine-cosine (-like) shape are used to indicate change processes of measurement values or sampling values obtained by two different measurement devices or sampling apparatuses over the time t.
[0052] For example, the curve 11 is a current value Ishunt measured by a shunt sensor, and the curve I2 is a current value lHaii measured by a Hall sensor. The two measurement devices (the shunt sensor and the Hall sensor) differ in terms of characteristics such as cut-off frequency and delay. Accordingly, there is also a difference between the curve 11 (represented by a thicker solid line having a larger amplitude) and the curve I2 (represented by a thinner solid line having a smaller amplitude), as shown in FIG. 3, in terms of both amplitude and phase.
[0053] At a time point t1 , it is obtained that Il(tl) - I2(tl) > TH1, where Il(tl) is a first sampling value obtained by the shunt sensor at the time point t1 , 12 (tl) is a second sampling value obtained by the Hall sensor at the time point t1 , and TH1 (positive herein) is an allowable range of a sampling difference value between the first sampling value and the second sampling value. In this case, it is possible to count a fault counter used to represent fault maturity time.
[0054] At a time point t2, it is obtained that Il(t2) - I2(t2) < -TH1 or | Il(t2) - I2(t2) | > TH1, where Il(t2) is a first sampling value obtained by the shunt sensor at the time point t2, I2(t2) is a second sampling value obtained by the Hall sensor at the time point t2, and TH1 (positive herein) is an allowable range of a sampling difference value between the first sampling value and the second sampling value. In this case, it is possible to continue counting the fault counter used to represent the fault maturity time.
[0055] As shown in FIG. 3, the curve 11 fluctuates up and down near the curve I2, so that the difference value between the current value 11 of the shunt sensor and the current value I2 of the Hall sensor periodically switches up and down at a zero point, that is, the difference value periodically switches between a positive value and a negative value. Over time, a count value of the fault counter will exceed a second threshold TH2 used to represent an allowable duration of a fault, which will mean that the fault is “mature” or that a fault has occurred in a measurement device. However, in actuality, this timeout is not caused by the fault of the measurement device, but by a ripple interference signal that occurs in a dynamic change of a current. A sampling value of the current is still rational, and the measurement device is actually fault-free.
[0056] Next, the technical solution according to the present application is described with reference to FIG. 3. Herein, a current signal I is used as an example, and current signals 11 and I2 have a sine-cosine (-like) shape. It should be noted, however, that the technical solutions according to the present application can be applied to various electrical signals and that the electrical signals can have other shapes different from those shown herein.
[0057] FIG. 1 is a principle flowchart of a method 1 for performing a rationality check on an electrical signal according to the present application.
[0058] In step S1 , a first sampling value 11 of the electrical signal is obtained from a first sampling apparatus 21 , and a second sampling value I2 of the electrical signal is obtained from a second sampling apparatus 22, so as to determine a sampling difference value Al = Il — 12 between the first sampling value and the second sampling value. It can be understood that the first sampling value 11 and the second sampling value I2 are obtained for a same electrical signal, and are especially obtained at a same sampling time point.
[0059] In step S3, a first comparison between the sampling difference value Al and a predefined first threshold TH1 is performed.
[0060] It can be understood that the predefined first threshold TH1 may be a positive value (a positive current value). Alternatively, the predefined first threshold TH1 may be a threshold range defined by a positive upper thresholdTH1_H and a negative lower threshold -TH1_L, that is, represented as (TH1_H, — TH1_L) . The upper threshold TH1_H and the lower threshold - TH1_L can have the same absolute value or different absolute values, which is not limited herein. Alternatively, the predefined first threshold TH1 or the predefined first threshold range can be given as a percentage, for example, as a percentage relative to the steady-state current IO or the first sampling value 11 or the second sampling value I2.
[0061] For simplicity, in the following, the predefined first threshold TH1 may be set to a positive value. Accordingly, Al exceeding the predefined first threshold TH1 refers to Al > TH1 or Al < -TH1, and Al not exceeding the predefined first threshold TH1 refers to - TH1 < Al < TH1.
[0062] In step S5, a corresponding count operation for a fault counter is determined based on the sign of the sampling difference value Al and a result of the first comparison. Herein, based on the sign of the sampling difference value Al and the result of the first comparison, a corresponding count operation can be performed on the fault counter separately or in association.
[0063] Herein, the sign of the sampling difference value Al may be a positive sign or a negative sign. Specifically, when II - 12 > 0, the sign of the sampling difference value Al is the positive sign “+”, and when II - 12 < 0, the sign of the sampling difference value Al is the negative sign
[0064] In an example, if the sign of the sampling difference value Al is positive “+”, a first count operation is performed on the fault counter, such as an increment operation, e.g., +1 , +2, +3, etc. Conversely, if the sign of the sampling difference value Al is negative a second count operation is performed on the fault counter, such as a decrement operation, e.g., -1 , -2, - 3, etc. Advantageously, the sign of the difference value is taken into account to filter out interference of a ripple signal, especially interference of a ripple signal that periodically fluctuates.
[0065] In an example, when the result of the first comparison indicates that the sampling difference value Al exceeds the predefined first threshold TH1 , if the sign of the sampling difference value Al is positive “+”, the first countoperation is performed on the fault counter, such as an increment operation, e.g., +1 , +2, or +3. Conversely, if the sign of the sampling difference value Al is negative a second count operation is performed on the fault counter, such as a decrement operation, e.g., -1 , -2, -3, etc. Advantageously, the sign of the difference value is taken into account to filter out interference of a ripple signal, especially interference of a ripple signal that periodically fluctuates.
[0066] In an example, if the result of the first comparison indicates that the sampling difference value Al exceeds the predefined first threshold TH1 , a first sub-count operation of the first count operation (or a first sub-count operation of the second count operation) is performed on the fault counter, such as an increment operation, e.g., +1 , +3, +6, +9, etc. (or a decrement operation, such as -1 , -3, -6, -9, etc.). Conversely, if the result of the comparison indicates that the sampling difference value Al does not exceed the predefined first threshold TH1 , a second sub-count operation of the first count operation (or a second sub-count operation of the second count operation) is performed on the fault counter, such as a decrement operation, e.g., -1 , -3, -6, -9, etc. (or an increment operation, such as +1 , +3, +6, +9, etc.). Herein, the magnitude of the difference value is taken into account to reduce the impact of accidental exceeding the threshold.
[0067] Herein, the first count operation and the second count operation are different. For example, the first count operation and the second count operation differ in at least one of the following aspects: operation target, such as a counter, for example, a first counter or a second counter; operation direction, for example, increment or decrement; and operation scale, i.e. , step values of incrementing and decrementing. Herein, the first sub-count operation and the second sub-count operation are different, for example, different in terms of in operation direction, such as increment or decrement; and, for example, different in terms of operation scale, that is, step values are different in incrementing and decrementing.
[0068] FIG. 2 is a principle block diagram of a system 10 for performing rationality check on an electrical signal according to the present application.
[0069] The system 10 includes a first module M1 , configured to output an electrical signal S1 to be measured or to be verified for rationality. For example, the electrical signal S1 is herein a current signal to be verified for rationality.
[0070] The system 10 includes a second module M2, configured to measure (sample) or verify the rationality of the electrical signal S1 . Herein, the second module M2 includes a first measurement device or a first sampling apparatus 21 and a second measurement device or a second sampling apparatus 22. For example, the first sampling apparatus 21 is configured as a shunt sensor, and the second sampling apparatus 22 is configured as a Hall sensor. Herein, the first sampling apparatus 21 outputs a first sampling value S2', and the first sampling value is formed as or taken from a curve 11. Herein, the second sampling apparatus 22 outputs a second sampling value S2", and the second sampling value is formed as or taken from a curve I2.
[0071] The system 10 includes a third module M3, configured to perform analysis processing on the first sampling value S2' and the second sampling value S2", so as to verify the rationality of the electrical signal (a current signal).
[0072] For example, the third module M3 includes a fault determination module 31 and a fault accumulation module 32. Herein, the fault determination module 31 is configured to determine whether a sampling difference value Al between the first sampling value S2' and the second sampling value S2" exceeds a predefined first threshold TH1 (a first determination). For example, the fault determination module 31 includes a comparison apparatus (a first comparison apparatus) and may further include a sign determination apparatus. When the sampling difference value Al exceeds the predefined first threshold TH1 , an intermediate signal is outputted, and additionally, when the sampling difference value Al does not exceed the predefined first threshold TH1 , another intermediate signal is outputted, and the fault accumulation module 32 can perform a corresponding count operation, such as accumulation or reduction, in response to the intermediate signal and / or the other intermediate signal. Herein, the fault accumulation module 32 is configured to perform a count operation on a fault counter based on a first determination result of the fault determination module 31 , especially adetermined sign, so as to accumulate or time a fault in a corresponding direction (a positive or negative direction). Herein, the fault accumulation module 32 is further configured to determine, based on a second determination result of the fault accumulation module 32, whether the measurement devices 21 , 22 are faulty, and output a fault signal S3 when faulty. For example, a cumulative number of faults may also be marked with a sign, that is, may be marked with a positive sign or a negative sign. For example, the fault accumulation module 32 includes or is configured as a counting / timing apparatus (e.g., a counter) and a comparison apparatus (a second comparison apparatus), and is configured to determine whether a count value / timed time of the counting / timing apparatus exceeds a predefined second threshold TH2 (a second determination). When the fault is “mature”, that is, when the cumulative number of faults or the timed time of the fault exceeds a predetermined threshold (the second threshold TH2), the fault signal S3 is outputted.
[0073] In the following, an implementation and an action method of the technical solution according to the present application are described in detail with reference to FIG. 4 and FIG. 5.
[0074] FIG. 4 is a schematic block diagram of an embodiment of a system 10 for performing a rationality check on an electrical signal according to the present application. The difference between FIG. 4 and FIG. 2 mainly lies in the third module M3. The following describes the third module M3 in detail.
[0075] The third module M3 includes a fault determination module 31. The fault determination module 31 is configured to determine a sampling difference value Al = 11 - I2 between a first sampling value S2' and a second sampling value S2". The fault determination module 31 is further configured to determine whether the sampling difference value Al exceeds a predefined first threshold TH1 , Al > TH1 or Al < -TH1. The fault determination module 31 is further configured to determine a direction in which the sampling difference value Al is located (whether the sampling difference value is positive or negative), that is, Al > 0 or Al < 0. Correspondingly, the fault determination module 31 includes or is configured as a difference calculation apparatus, a firstcomparison apparatus, and a sign determination apparatus. The fault determination module 31 is further configured to output a first determination result or a first comparison result to a first fault accumulation module 32-1 , as shown by a signal S3-1 .
[0076] The third module M3 further includes the first fault accumulation module 32-1 and a second fault accumulation module 32-2.
[0077] The first fault accumulation module 32-1 is configured to determine a corresponding count operation for a fault counter CNT based on the first determination result or the signal S3-1 , the fault counter, for example, including or being configured as a single counter of which a count value is referred to as ent.
[0078] In an example, if a result of a first comparison indicates that the sampling difference value exceeds the predefined first threshold and the sign of the sampling difference value is positive, that is, Al > TH1, a first count operation is performed on the fault counter CNT, that is, an increment operation, +1 or cnt++, indicating that the fault accumulates by one in the positive direction and reduces by one in the negative direction. If the result of the comparison indicates that the sampling difference value exceeds the predefined first threshold and the sign of the sampling difference value is negative, that is, Al < -TH1, a second count operation is performed on the fault counter CNT, that is, a decrement operation, -1 or ent — , indicating that the fault accumulates by one in the negative direction and reduces by one in the positive direction.
[0079] In an example, if the result of the first comparison indicates that the sampling difference value exceeds the predefined first threshold and that the sign of the sampling difference value or the sign of a cumulative value of the fault counter is positive, that is, Al > TH1, a first sub-count operation of the first count operation is performed on the fault counter, that is, cnt++ (that is, ent = ent + 1 ) or another step value (for example, ent = ent + 3, ent = ent + 5, etc.) is used. If the result of the first comparison indicates that the sampling difference value does not exceed the predefined first threshold and the sign of the sampling difference value is positive, that is, 0 < Al < TH1 , or if the signof the cumulative value of the fault counter is positive, a second sub-count operation of the first count operation is performed on the fault counter, that is, ent — (that is, ent = ent - 1 ) or another step value is used. Count operations are performed in the positive direction in this way until the count value ent is zero. In other words, if ent decrements from a positive value (e.g., +15) to 0 in the positive direction, ent remains zero when it is determined again that 0 < Al < TH1 , and, for example, a minus one operation is not then performed. In the foregoing case, it may be further understood that if the result of the first comparison indicates that the sampling difference value does not exceed the predefined first threshold and the sign of the cumulative value of the fault counter is negative, another sub-count operation of the first count operation and different from the second sub-count operation may also be performed on the fault counter, for example, cnt++ (that is, ent = ent + 1 ) or another step value is used. If the result of the comparison indicates that the sampling difference value exceeds the predefined first threshold and that the sign of the sampling difference value or the sign of the cumulative value of the fault counter is negative, that is, Al < -TH1, a first sub-count operation of the second count operation is performed on the fault counter, that is, ent — (that is, ent = ent - 1 ) or another step value (for example, ent = ent - 3, ent = ent - 5, etc.) is used. If the result of the comparison indicates that the sampling difference value does not exceed the predefined first threshold and the sign of the sampling difference value is negative, that is, -TH1 < Al < 0, or if the sign of the cumulative value of the fault counter is negative, a second sub-count operation of the second count operation is performed on the fault counter, that is, cnt++ (that is, ent = ent + 1 ) or another step value is used. Count operations are performed in the negative direction in this way until the count value ent is zero. In other words, if ent increments from a negative value (e.g., -15) to 0 in the negative direction, ent remains zero when it is determined again that - TH1 < Al < 0, and, for example, a plus one operation is not then performed. In the foregoing case, it may be further understood that if the result of the first comparison indicates that the sampling difference value does not exceed the predefined first threshold and the sign of the cumulative value of the faultcounter is positive, another sub-count operation of the second count operation and different from the second sub-count operation may also be performed on the fault counter, for example, ent — (that is, ent = ent - 1 ) or another step value is used.
[0080] If the current signal I is always interfered with by a ripple signal and a systematic fault does not exist, as shown in FIG. 3, the count value ent of the fault counter CNT used for a rationality check of the current signal I will undergo a periodic plus and minus one operation, thereby having a pattern, for example, of 1 , 0, 1 , 0, ... or 0, -1 , 0, -1 , .... Herein, when a ripple interference signal exists, when the sign is considered, the count value ent does not present a trend of always accumulating in a certain direction (the positive or negative direction), but, in terms of an overall trend, fluctuates relatively stably within a certain range (for example, within the predefined second threshold). When the fault maturity time, that is, the second threshold used for the fault counter CNT, used for the rationality check of the current signal is reasonably designed, when there is a ripple interference signal, the absolute value of the count value ent of the fault counter CNT, that is, in both the positive direction and the negative direction, does not exceed the designed second threshold, so as to avoid misreporting a fault in the rationality check of the electrical signal.
[0081] Conversely, if the current signal I is not interfered with by a ripple signal, but experiences a real systematic fault, the difference value between the current values 11 and I2 of the two measurement devices will be continuously greater than the predefined first threshold in one direction (in the positive or negative direction). That is, the count value ent of the fault counter ent will continuously accumulate in one direction (for example, continuously only increase by one or continuously only decrease by one) until the absolute value of the count value ent (a positive value or a negative value) exceeds a specific range (for example, exceeds the predefined second threshold), thereby triggering the fault signal S3, and determining that the sampling value of the current signal is irrational.
[0082] Therefore, the ripple interference signal is filtered out in the rationality check, and an irrational current caused by a systematic fault can still be detected. The system is safe, reliable, and robust.
[0083] The second fault accumulation module 32-2 is configured to determine whether the count value ent of the fault counter CNT exceeds the predefined second threshold TH2 based on the count value ent from the fault counter CNT 32-1 (as shown by the signal S3-2). Correspondingly, the second fault accumulation module 32-2 includes or is configured as a second comparison apparatus. The second comparison apparatus is configured to perform a second comparison between the count value ent of the fault counter CNT and the predefined second threshold TH2, so as to determine whether the count value ent of the fault counter CNT exceeds the predefined second threshold TH2. The second fault accumulation module 32-2 is further configured to perform rationality verification on the electrical signal based on a result of the second comparison. Specifically, if the result of the second comparison indicates that the count value of the fault counter exceeds the predefined second threshold, that is, ent > TH2 or ent < -TH2 , it is determined that the electrical signal is irrational and the fault signal S3 is outputted. Conversely, if the result of the second comparison indicates that the count value of the fault counter does not exceed the predefined second threshold, that is, -TH2 < ent < TH2 , it is determined that the electrical signal is rational and the fault signal S3 is not outputted.
[0084] FIG. 5 is a schematic block diagram of another embodiment of a system 10 for performing a rationality check on an electrical signal according to the present application. The difference between FIG. 5 and FIG. 2 mainly lies in the third module M3, and the difference between FIG. 5 and FIG. 4 mainly lies in the third module M3, especially the first fault accumulation module 32-1 and the second fault accumulation module 32-2. The following describes the third module M3, especially the first fault accumulation module 32-1 and the second fault accumulation module 32-2.
[0085] The third module M3 includes a fault determination module 31. For details, refer to the foregoing description. Details are not described herein again.
[0086] The third module M3 further includes the first fault accumulation module 32-1 and the second fault accumulation module 32-2.
[0087] The first fault accumulation module 32-1 is configured to determine a corresponding count operation for a fault counter CNT based on a first determination result or a signal S3-1. Here, unlike in FIG. 4, the first fault accumulation module 32-1 includes or is configured as two counters 32-T and 32-1 " (also referred to as a first sub-fault counter CNT 1 and a second sub-fault counter CNT2), and count values of the two counters are respectively referred to as cnt1 and cnt2.
[0088] In an example, if a result of a first comparison indicates that a sampling difference value exceeds a predefined first threshold and the sign of the sampling difference value is positive, that is, Al > TH1 , a first count operation is performed on the first sub-fault counter CNT1 , that is, an increment operation, +1 (or cnt1 ++, that is, cnt1 = cnt1 + 1 ), + 3 (that is, cnt1 = cnt1 + 3), + 5 (that is, cnt1 = cnt1 + 5), etc., indicating that the fault accumulates in the positive direction. If the result of the comparison indicates that the sampling difference value exceeds the predefined first threshold and the sign of the sampling difference value is negative, that is, Al < -TH1, a second count operation is performed on the second sub-fault counter CNT2, and the second count operation may be a decrement operation, -1 (or cnt2- -, that is, cnt2 = cnt2 - 1 ), -3 (that is, cnt2 = cnt2 - 3), -5 (that is, cnt2 = cnt2 - 5), etc., or an increment operation, +1 (or cnt2++, that is, cnt2 = cnt2 + 1 ), + 3 (that is, cnt2 = cnt2 + 3), + 5 (that is, cnt2 = cnt2 + 5), etc., indicating that the fault accumulates in the negative direction.
[0089] In an example, if the result of the first comparison indicates that the sampling difference value exceeds the predefined first threshold and the sign of the sampling difference value is positive, that is, Al > TH1, a first sub-count operation of the first count operation is performed on the first sub-fault counter CNT1 , that is, an increment operation, +1 (or cnt1 ++, that is, cnt1 = cnt1 + 1 ),+3 (that is, cnt1 = cnt1 + 3), etc., and a second sub-count operation of the second count operation is performed on the second sub-fault counter CNT2 (counting in the same direction as the first sub-fault counter CNT1 , for example, both counting in the positive direction), that is, a decrement operation, -1 (or cnt2 — , that is, cnt2 = cnt2 - 1 ), -3 (that is, cnt2 = cnt2 - 3), etc., indicating that the fault accumulates in the positive direction and reduces in the negative direction at the same time. If the result of the comparison indicates that the sampling difference value exceeds the predefined first threshold and that the sign of the sampling difference value is negative, that is, Al < — TH1, a first sub-count operation of the second count operation is performed on the second sub-fault counter CNT2, that is, an increment operation, +1 (or cnt2++, that is, cnt2 = cnt2 + 1 ), + 3 (that is, cnt2 = cnt2 + 3), etc. , and a second sub-count operation of the first count operation is performed on the first sub-fault counter CNT1 , that is, a decrement operation, -1 (or cnt1 - -, that is, cnt1 = cnt1 - 1 ), -3 (that is, cnt1 = cnt1 - 3), etc., indicating that the fault accumulates in the negative direction and reduces in the positive direction at the same time. Alternatively, in an example, if the result of the first comparison indicates that the sampling difference value exceeds the predefined first threshold and the sign of the sampling difference value is positive, that is, Al > TH1, the first sub-count operation of the first count operation is performed on the first sub-fault counter CNT1 , that is, an increment operation, +1 (or cnt1 ++, that is, cnt1 = cnt1 + 1 ), +3 (that is, cnt1 = cnt1 + 3), etc., and the second sub-count operation of the second count operation is performed on the second sub-fault counter CNT2 (counting in the opposite direction from the first sub-fault counter CNT1 , for example, counting in the negative direction), that is, an increment operation, +1 (or cnt2++, that is, cnt2 = cnt2 + 1 ), +3 (that is, cnt2 = cnt2 + 3), etc., indicating that the fault accumulates in the positive direction and reduces in the negative direction at the same time. If the result of the comparison indicates that the sampling difference value exceeds the predefined first threshold and that the sign of the sampling difference value is negative, that is, Al < -TH1, the first sub-count operation of the second count operation is performed on the second sub-faultcounter CNT2, that is, a decrement operation, -1 (or cnt2 — , that is, cnt2 = cnt2 - 1 ), -3 (that is, cnt2 = cnt2 - 3), etc., and the second sub-count operation of the first count operation is performed on the first sub-fault counter CNT1 , that is, a decrement operation, -1 (or cnt1 — , that is, cnt1 = cnt1 - 1 ), -3 (cnt1 = cnt1 - 3), etc., indicating that the fault accumulates in the negative direction and reduces in the positive direction at the same time.
[0090] In an example, if the result of the first comparison indicates that the sampling difference value exceeds the predefined first threshold and the sign of the sampling difference value is positive, that is, Al > TH1, the first subcount operation of the first count operation is performed on the first sub-fault counter, that is, +1 (or cnt1 ++, that is, cnt1 = cnt1 + 1 ), +3 (that is, cnt1 = cnt1 + 3), etc. If the result of the first comparison indicates that the sampling difference value does not exceed the predefined first threshold and that the sign of the sampling difference value is positive, that is, 0 < Al < TH1 , the second sub-count operation of the first count operation is performed on the first sub-fault counter, that is, -1 (or cnt1 — , that is, cnt1 = cnt1 - 1 ) or another step value is used, for example, a smaller step value compared with that in the first sub-count operation of the first count operation. Count operations are performed in the positive direction in this way until the count value cnt1 is zero. In other words, if cnt1 decrements from a positive value (e.g., +15) to 0 in the positive direction, cnt1 remains zero when it is determined again that 0 < Al < TH1 , and, for example, a minus one operation is not then performed. If the result of the comparison indicates that the sampling difference value exceeds the predefined first threshold and the sign of the sampling difference value is negative, that is, Al < -TH1, the first sub-count operation of the second count operation is performed on the second sub-fault counter, for example, -1 (or cnt2 — , that is, cnt2 = cnt2 - 1 ), -3 (that is, cnt2 = cnt2 - 3), etc. If the result of the comparison indicates that the sampling difference value does not exceed the predefined first threshold and that the sign of the sampling difference value is negative, that is, -TH1 < Al < 0, the second sub-count operation of the second count operation is performed on the second sub-fault counter, forexample, +1 (or cnt2++, that is, cnt2 = cnt2 + 1 ) or another step value is used, for example, a smaller step value compared with that in the first sub-count operation of the second count operation. Count operations are performed in the negative direction in this way until the count value cnt2 is zero. In other words, if cnt2 increments from a negative value (e.g., -15) to 0 in the negative direction, cnt2 remains zero when it is determined again that -TH1 < Al < 0, and, for example, a plus one operation is not then performed.
[0091] If the current signal I is always interfered with by a ripple signal and a systematic fault does not exist, as shown in FIG. 3, the count values cnt1 and cnt2 of the fault counters CNT1 and CNT2 used for the rationality check on the current signal I or the difference value between the absolute values of the two count values cnt1 and cnt2 will undergo periodic increment and decrement operations, for example, in an oscillating pattern. Herein, when a ripple interference signal exists, when the sign is considered, the count values cnt1 and cnt2, or the difference value between their absolute values does not present a trend of always accumulating in a certain direction (the positive or negative direction), but, in terms of an overall trend, fluctuates relatively stably within a certain range (for example, within a predefined second threshold). When fault maturity time, that is, the second threshold used for the fault counters CNT1 and CNT2, used for the rationality check of the current signal is designed reasonably, the absolute values of the count values cnt1 and cnt2 of the fault counters CNT1 and CNT2 or the difference value between the absolute values thereof, that is, in both the positive direction and the negative direction, do not exceed the designed second threshold, so as to avoid misreporting a fault in the rationality check of the electrical signal.
[0092] Conversely, if the current signal I is not interfered with by a ripple signal, but experiences a real systematic fault, the difference value between the current values 11 and I2 of the two measurement devices will be continuously greater than the predefined first threshold in one direction (in the positive or negative direction). That is, the count values cnt1 and cnt2 of the fault counters CNT1 and CNT2 or the difference value between the absolute values thereof will continuously accumulate in one direction (for example,continuously only increase by one or continuously only decrease by one) until the absolute values of the count values cnt1 and cnt2 (positive or negative values) or the difference value between the absolute values thereof exceed a certain range (for example, exceed the predefined second threshold), thereby triggering the fault signal S3, and determining that the sampling values of the current signal are irrational.
[0093] Therefore, the ripple interference signal is filtered out in a rationality check, and an irrational current caused by a systematic fault can still be detected. The system is safe, reliable, and robust.
[0094] The second fault accumulation module 32-2 is configured to determine whether the count values cnt1 and / or cnt2 of the fault counters CNT1 and / or CNT2 exceed the predefined second threshold TH2 based on the count value cnt1 from the first sub-fault counter CNT1 32-T (as indicated by the signal S3-2') and / or the count value cnt2 from the second sub-fault counter CNT1 32-1" (as indicated by the signal S3-2"). Correspondingly, the second fault accumulation module 32-2 includes or is configured as a second comparison apparatus. The second comparison apparatus is configured to perform a second comparison between the count values cnt1 and / or cnt2 of the fault counters CNT1 and / or CNT2 and the predefined second threshold TH2 to determine whether the count values cnt1 and / or cnt2 of the fault counters CNT1 and / or CNT2 exceed the predefined second threshold TH2. Alternatively, the second fault accumulation module 32-2 is configured to determine whether a difference value Acnt = |cntl| - |cnt2| between the absolute values of the count value cnt1 of the first sub-fault counter CNT 1 and the count value cnt2 of the second sub-fault counter CNT1 exceeds the predefined second threshold TH2 based on the count value cnt1 from the first sub-fault counter CNT1 32-T (as indicated by the signal S3-2') and the count value cnt2 from the second sub-fault counter CNT1 32-1" (as indicated by the signal S3-2"). Accordingly, the second fault accumulation module 32-2 includes or is configured as a difference calculation apparatus and a second comparison apparatus. The difference calculation apparatus is configured to determine the difference value Acnt = |cntl| - |cnt2| between the absolutevalues of the count value cnt1 of the first sub-fault counter CNT 1 and the count value cnt2 of the second sub-fault counter CNT1. The second comparison apparatus is configured to compare the determined difference value Acnt with the predefined second threshold TH2, so as to determine whether the difference value Acnt exceeds the predefined second threshold TH2.
[0095] The second fault accumulation module 32-2 is further configured to perform rationality verification on the electrical signal based on a result of the second comparison. Specifically, if the result of the second comparison indicates that the difference value Acnt between the absolute values of the count value cnt1 of the first sub-fault counter CNT1 and the count value cnt2 of the second sub-fault counter CNT1 exceeds the predefined second threshold, that is, Acnt > TH2 or Acnt < - TH2, it is determined that the electrical signal is irrational and the fault signal S3 is outputted. Conversely, if the result of the second comparison indicates that the count value of the fault counter does not exceed the predefined second threshold, that is, -TH2 < Acnt < TH2, it is determined that the electrical signal is rational and the fault signal S3 is not outputted.
[0096] FIG. 6 is a schematic block diagram of a computer program product 100 according to the present application.
[0097] The computer program product 100, such as a computer-readable program medium, includes or stores computer program instructions. When the computer program instructions are run by a processor or a controller, the computer program instructions can perform the method 1 according to the present application. For example, the processor may be a central processing unit (CPU), or may be another general-purpose processor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), or the like. The general-purpose processor may be a microprocessor, or may be any conventional processor or the like.
[0098] Although the specific implementations of the present application are described in detail herein, they are provided for the purposes of explanation only, and should not be considered as limiting the scope of the presentapplication. Various replacement solutions and modification solutions may be provided without departing from the core and scope of the present application.
Claims
CLAIMS1 . A method for performing a rationality check on an electrical signal, the method comprising: obtaining from a first sampling apparatus a first sampling value of the electrical signal, and obtaining from a second sampling apparatus a second sampling value of the electrical signal, so as to determine a sampling difference value between the first sampling value and the second sampling value; performing a first comparison between the sampling difference value and a predefined first threshold; and determining, based on the sign of the sampling difference value and a result of the first comparison, a corresponding count operation for a fault counter.
2. The method according to claim 1 , wherein if the sign of the sampling difference value is positive, a first count operation is performed on the fault counter, and if the sign of the sampling difference value is negative, a second count operation is performed on the fault counter.
3. The method according to any one of the preceding claims, wherein if the result of the first comparison indicates that the sampling difference value exceeds the predefined first threshold, a first sub-count operation of a corresponding count operation is performed on the fault counter, and if the result of the comparison indicates that the sampling difference value does not exceed the predefined first threshold, a second sub-count operation of a corresponding count operation is performed on the fault counter.
4. The method according to any one of the preceding claims, wherein the corresponding count operations differ in at least one of the following aspects: operation direction, operation target, and operation scale.
5. The method according to any one of the preceding claims, wherein if the result of the first comparison indicates that the sampling difference value exceeds the predefined first threshold and the sign of the sampling difference value is positive, a first count operation is performed on the fault counter, and if the result of the comparison indicates that the sampling difference value exceeds the predefined first threshold and the sign of the sampling difference value is negative, a second count operation is performed on the fault counter.
6. The method according to any one of the preceding claims, wherein if the result of the first comparison indicates that the sampling difference value exceeds the predefined first threshold and the sign of the sampling difference value or the sign of a cumulative value of the fault counter is positive, a first sub-count operation of a first count operation is performed on the fault counter; if the result of the first comparison indicates that the sampling difference value does not exceed the predefined first threshold and the sign of the sampling difference value or the sign of the cumulative value of the fault counter is positive, a second sub-count operation of the first count operation is performed on the fault counter; if the result of the comparison indicates that the sampling difference value exceeds the predefined first threshold and the sign of the sampling difference value or the sign of the cumulative value of the fault counter is negative, a first sub-count operation of a second count operation is performed on the fault counter; and if the result of the comparison indicates that the sampling difference value does not exceed the predefined first threshold and the sign of the sampling difference value or the sign of the cumulative value of the fault counter is negative, a second sub-count operation of the second count operation is performed on the fault counter.
7. The method according to any one of the preceding claims, wherein a second comparison is performed between a count value of the fault counter and a predefined second threshold, and rationality verification is performed on the electrical signal based on a result of the second comparison.
8. The method according to any one of the preceding claims, wherein if the result of the first comparison indicates that the sampling difference value exceeds the predefined first threshold and the sign of the sampling difference value is positive, a corresponding count operation is performed on a first subfault counter of the fault counter, and if the result of the comparison indicates that the sampling difference value exceeds the predefined first threshold and the sign of the sampling difference value is negative, a corresponding count operation is performed on a second sub-fault counter of the fault counter.
9. The method according to any one of the preceding claims, wherein if the result of the first comparison indicates that the sampling difference value exceeds the predefined first threshold and the sign of the sampling difference value is positive, a first sub-count operation of a first count operation is performed on a first sub-fault counter of the fault counter; if the result of the first comparison indicates that the sampling difference value does not exceed the predefined first threshold and the sign of the sampling difference value is positive, a second sub-count operation of the first count operation is performed on the first sub-fault counter of the fault counter; if the result of the comparison indicates that the sampling difference value exceeds the predefined first threshold and the sign of the sampling difference value is negative, a first subcount operation of a second count operation is performed on a second subfault counter of the fault counter; and if the result of the comparison indicates that the sampling difference value does not exceed the predefined first threshold and the sign of the sampling difference value is negative, a second sub-count operation of the second count operation is performed on the second sub-fault counter of the fault counter.
10. The method according to any one of the preceding claims, wherein a count difference value between a first count value of the first sub-fault counter and a second count value of the second sub-fault counter is determined as a count value of the fault counter, a second comparison is performed between the count value of the fault counter and a predefined second threshold, andrationality verification is performed on the electrical signal based on the result of the second comparison.11 . The method according to any one of the preceding claims, wherein it is determined that the electrical signal is irrational if a result of the second comparison indicates that a count value of the fault counter exceeds the predefined second threshold, and it is determined that the electrical signal is rational if the result of the second comparison indicates that the count value of the fault counter does not exceed the predefined second threshold.
12. A system for performing a rationality check on an electrical signal, the system being capable of executing the method according to any one of claims 1 to 11.
13. A computer program product, such as a computer-readable program medium, the computer program product comprising or storing computer program instructions, and when the computer program instructions are run by a processor, the computer program instructions are capable of executing the method according to any one of claims 1 to 11 .