Fault signal processing method and device, controller, vehicle and medium
By discarding the fault signal within the fuel cell vehicle's power down time, the problem of misjudgment and locking in frequent power-off states is solved, ensuring the normal start and operation of the vehicle and improving the driving experience.
Patent Information
- Application Number
- CN202410029844.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-08
- Publication Date
- 2025-07-08
AI Technical Summary
In fuel cell vehicles, frequent up-and-down states lead to misjudgment of fault signals, resulting in unnecessary system locking or function locking, affecting the vehicle's start-up and driving experience.
Within the threshold time when the vehicle is received, the fault signal corresponding to the vehicle target component is discarded to avoid performing unnecessary fault processing strategies.
Avoid misjudgment locking due to frequent power-up and down states, ensure that the fuel cell system can be started normally, and improve the user's driving experience.
Smart Images

Figure CN120270034A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the technical field of vehicles, and more particularly, to a method, an apparatus, a controller, a vehicle, and a medium for processing fault signals. Background Art
[0002] The fuel cell system is the power core of a fuel cell vehicle. In a fuel cell vehicle, the overall process of the fuel cell system is controlled by a fuel cell control unit (FCCU), including the management of hydrogen and air, the management of heat and water, the conversion and supervision of energy, the communication with other systems, and the diagnosis and handling of faults. Among them, the diagnosis and handling of faults is an important function closely related to the safety of the vehicle and the driver.
[0003] During the use of a fuel cell vehicle, faults may occur for various reasons. If not handled, they may cause dangers. For example, an electrical / electronic system fault in the fuel cell system may lead to hydrogen leakage or the generation of high voltage, which can easily cause harm to the driver. To mitigate and avoid these dangers, the fuel cell system is usually provided with a safety protection mechanism. For example, when it is detected that a sensor fails or a current conversion device fails, the FCCU can execute corresponding fault handling strategies, such as locking the fuel cell system or preventing the start of the fuel cell system. Summary of the Invention
[0004] Embodiments of the present disclosure provide a method, an apparatus, a controller, a vehicle, and a medium for processing fault signals. In an embodiment of the present disclosure, within a threshold duration of receiving a power-off signal of the vehicle, if a fault signal corresponding to a target component of the vehicle is detected, the fault signal can be discarded without executing a fault handling strategy corresponding to the fault signal. In this way, it is possible to avoid unnecessary function locking or system locking when the vehicle frequently switches between the power-on and power-off states, so that the vehicle can be guaranteed to start normally next time, thereby improving the user's driving experience.
[0005] In a first aspect of the present disclosure, a method for processing fault signals is provided. The method includes receiving a power-off signal of the vehicle, where the power-off signal is used to turn off the vehicle. The method further includes discarding the fault signal in response to detecting a fault signal corresponding to a target component of the vehicle within a threshold duration after receiving the power-off signal, where the fault signal indicates a fault of the target component.
[0006] In a second aspect of the present disclosure, there is provided an apparatus for processing fault signals. The apparatus includes a receiving module configured to receive a power-down signal of a vehicle, where the power-down signal is used to shut down the vehicle. The apparatus further includes a processing module configured to discard a fault signal in response to detecting a fault signal corresponding to a target component of the vehicle within a threshold duration after receiving the power-down signal, where the fault signal indicates a fault of the target component.
[0007] In a third aspect of the present disclosure, there is provided a controller. The controller includes one or more processors; and a storage device for storing one or more programs, which when executed by the one or more processors, cause the one or more processors to implement the method provided according to the first aspect of the present disclosure.
[0008] In a fourth aspect of the present disclosure, there is provided a vehicle. The vehicle includes the controller provided according to the third aspect of the present disclosure.
[0009] In a fifth aspect of the present disclosure, there is provided a machine-readable storage medium. The machine-readable storage medium stores machine-executable instructions, where the machine-executable instructions are executed by a processor to implement the method provided according to the first aspect of the present disclosure.
[0010] It should be understood that the content described in the summary of the invention section is not intended to limit the key or important features of the embodiments of the present disclosure, nor to limit the scope of the present disclosure. Other features of the present disclosure will become easily understandable through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0011] In combination with the accompanying drawings and with reference to the following detailed description, the above and other features, advantages, and aspects of the various embodiments of the present disclosure will become more apparent. In the drawings, the same or similar reference numerals denote the same or similar elements, where:
[0012] Figure 1A A schematic diagram of an example vehicle in which multiple embodiments of the present disclosure can be implemented is shown;
[0013] Figure 1B A schematic diagram of a fuel cell system in some embodiments of the present disclosure is shown;
[0014] Figure 2 A schematic flowchart of a method for processing fault signals according to some embodiments of the present disclosure is shown;
[0015] Figure 3 A schematic diagram of a scenario where a controller processes a fault signal corresponding to a target component at different times according to some embodiments of the present disclosure is shown;
[0016] Figure 4Schematic diagram showing a scenario of extending the threshold duration according to some embodiments of the present disclosure;
[0017] Figure 5 Schematic flowchart showing a method for processing a fault signal according to some embodiments of the present disclosure;
[0018] Figure 6 Block diagram showing an apparatus for processing a fault signal according to some embodiments of the present disclosure; and
[0019] Figure 7 Block diagram showing a device that can implement multiple embodiments of the present disclosure. Detailed implementation manners
[0020] Embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although some embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Instead, these embodiments are provided to more thoroughly and completely understand the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are only for exemplary purposes and are not used to limit the protection scope of the present disclosure.
[0021] In the description of the embodiments of the present disclosure, the term "including" and its like should be understood as an open inclusion, that is, "including but not limited to". The term "based on" should be understood as "at least partially based on". The term "one embodiment" or "the embodiment" should be understood as "at least one embodiment". Terms such as "first", "second", etc. may refer to different or the same objects. There may also be other explicit and implicit definitions hereinafter.
[0022] As mentioned above, the FCCU can perform fault detection and processing. The fault detection of the components of the vehicle by the FCCU can be carried out through communication with the components. As the total controller of the fuel cell system, the FCCU has continuous communication with many other components of the vehicle (such as various sensors configured on the vehicle). For example, the FCCU can periodically receive messages from other components of the vehicle. In cases where the communication between the FCCU and the components is interrupted or the message from the component indicates that the component has a fault, etc., the FCCU can generate a fault signal and execute corresponding fault handling strategies.
[0023] When receiving a power - off signal from the vehicle control unit (VCU), the FCCU will control the shutdown of the fuel cell system. Therefore, the FCCU will enter the shutdown state later than some components in the vehicle (such as components in the fuel cell system). In some cases, during the vehicle power - off process, the FCCU has not been completely shut down, but some components of the vehicle may have been shut down, which will lead to the interruption of communication between the FCCU and these components, and then cause the FCCU to generate and record fault signals corresponding to these components, and execute corresponding fault handling strategies, such as locking the fuel cell system of the vehicle. In this case, if the vehicle powers on quickly, it may not be able to start the fuel cell system normally because the fuel cell system has been locked, which will affect the subsequent start and driving of the vehicle and greatly affect the driving experience.
[0024] For this reason, the embodiments of the present disclosure propose a solution for processing fault signals. In the embodiments of the present disclosure, within the threshold duration of receiving the vehicle power - off signal, if a fault signal corresponding to the target component of the vehicle is detected, the fault signal is discarded and the fault handling strategy corresponding to the fault signal is not executed. In this way, within a period of time after the vehicle powers off, the fault signals corresponding to the components can be not processed, for example, the fuel cell system is not locked. Thus, in the case of generating fault signals due to short - term and frequent switching of the vehicle power - on and power - off states, the corresponding fault handling strategies will not be executed, which can avoid processing faults when the judgment of component faults is incorrect, and thus can avoid unnecessary system locking or function locking, such as avoiding incorrect locking of the fuel cell system. This can enable the fuel cell system to start normally under frequent power - on and power - off conditions, and then enable the vehicle to start and drive normally, ensuring the driving experience of users.
[0025] Figure 1AFIG. 0 shows a schematic diagram of an exemplary vehicle 100 in which multiple embodiments of the present disclosure can be implemented. Exemplarily, as shown in FIG. 1, in vehicle 100, components such as a VCU 110, an FCCU 120, a fuel cell stack 130, hydrogen storage tanks 140-1 and 140-2, a direct current / direct current (DC / DC) converter 150, a storage battery 160, and an electric motor 170 can be included. Among them, the FCCU 120 can manage and control the fuel cell system 130. The VCU 110 can communicate with the FCCU 120 to achieve control of the fuel cell system 130. The VCU 110 can also communicate with the DC / DC converter 150, the storage battery 160, and the electric motor 170, thereby controlling the output power of the electric motor 170 and distributing the electric energy output by the fuel cell system 130 and the storage battery 160. In an embodiment of the present disclosure, the VCU 110 can send power-on or power-off signals to the components of the vehicle, thereby controlling the opening and closing of the components of the vehicle. In some embodiments, the power-on or power-off signals sent by the VCU 110 can be generated in response to the driver's operation. In some embodiments, the power-on or power-off signals sent by the VCU 110 can be generated by the VCU 110 based on a predefined program.
[0026] The FCCU 120 can communicate with the components in the fuel cell system 130, such as sending control instructions to the components or periodically receiving messages from the components. The FCCU 120 can shut down the fuel cell system 130 in response to the power-off signal sent by the VCU 110, and the FCCU 120 can also start the fuel cell system 130 in response to the power-on signal sent by the VCU 110. In some embodiments, the FCCU 120 can also communicate with other components outside the fuel cell system 130, including but not limited to the pressure sensors configured in the hydrogen storage tanks 140-1 or 140-2, the DC / DC sensor 150, or the storage battery 160, etc. In some embodiments, the FCCU 120 can periodically receive messages from the components of the vehicle 100 and detect whether a component fails based on the reception of the messages or the information carried in the messages. In some embodiments, the FCCU 120 can only detect the faults of specified components, and the specified components can be pre-configured. In some embodiments, the FCCU 120 can generate fault signals corresponding to the components and execute fault handling strategies. In some embodiments, the FCCU 120 can discard the fault signals after generating the fault signals and not execute the fault handling strategies. In some embodiments, the FCCU 120 can shut down or lock the fuel cell system 130 in response to a component failure.
[0027] Exemplarily, the fuel cell system 130 in the vehicle 100 can be as Figure 1B shown. Refer toFigure 1B , the fuel cell system 130 may include components such as a fuel cell stack 1301, a hydrogen injector 1302, a hydrogen circulation pump 1303, a hydrogen discharge valve 1304, an air compressor 1305, an intercooler 1306, a humidifier 1307, an air tail discharge 1308, a thermostat 1309, a radiator 1310, and a cooling pump 1311. The FCCU 120 may send instructions to these components in the fuel cell system 130 to control the behavior of each component. The FCCU 120 may also periodically receive messages from these components. The FCCU 120 may also determine whether these components have failed based on the messages from these components. In some embodiments, the fuel cell system 130 may further include other components, such as a temperature sensor for detecting the temperature of the fuel cell stack 1301, a humidity sensor for detecting the humidity of the cathode air, a voltage sensor for detecting the output voltage of the fuel cell stack 1301, etc. The FCCU 120 may communicate with these sensors respectively and detect whether these sensors have failed. It should be understood that Figure 1A and Figure 1B These are only examples of the present disclosure. The vehicle and the fuel cell system in the embodiments of the present disclosure may include more or fewer components.
[0028] In the embodiments of the present disclosure, the communication between the FCCU 120 and the components of the vehicle 100 may be carried out through an in-vehicle communication link, for example, through a controller area network (CAN) bus. In some embodiments, the components of the vehicle 100 are sensors, such as the sensors in the fuel cell system 130. The communication between the FCCU 120 and these components may be direct communication with the sensors. In some embodiments, the components of the vehicle 100 are actuators, such as a DC / DC converter 150 or a motor 170, etc. The start-up, shutdown, and operation of the components are directly controlled by the electronic control unit (ECU) configured for the components. The communication between the FCCU 120 and these components may be communication with the ECU. It should be understood that the solutions in the embodiments of the present disclosure may be applied to various types of controllers capable of detecting faults, not limited to the FCCU. The fuel cell system and the FCCU in the embodiments of the present disclosure are only for illustration purposes and should not be a limitation to the solutions provided by the present disclosure.
[0029] Figure 2The flowchart of a method 200 for processing a fault signal according to some embodiments of the present disclosure is shown. The method 200 may be executed by a device for processing a fault signal, which may be a controller configured in a vehicle, such as an FCCU. Next, taking the controller as the execution entity as an example, the method 200 will be described. As Figure 2 shown, the method 200 may include block 202 and block 204. In block 202, the controller receives a power-off signal of the vehicle, and the power-off signal is used to shut down the vehicle. The power-off signal of the vehicle may be received by the controller from the VCU of the vehicle. In some embodiments, during the power-off process of the vehicle, when it is detected that the key signal or the network wake-up signal stops being sent, the VCU of the vehicle may send a power-off signal to other controllers or control units in the vehicle through the in-vehicle communication network. These controllers or control units include but are not limited to FCCU, motor controller, control unit of DC / DC converter, battery controller, etc. After receiving the power-off signal, these controllers can control the corresponding components to enter the sleep process. Exemplarily, after receiving the power-off signal, the FCCU may first control the cathode circuit of the fuel cell system to perform air purge and drying, then stop the air supply of the cathode circuit, and control the fuel cell stack to discharge and step down the voltage to deplete the oxygen in the cathode. Finally, after controlling the anode to perform hydrogen purge and drying, the hydrogen supply of the anode is closed.
[0030] In block 204, within a threshold duration after the controller receives the power-off signal, in response to detecting a fault signal corresponding to a target component of the vehicle, the controller discards the fault signal, where the fault signal indicates a fault of the target component of the vehicle. In some embodiments, when a target component fails, the target component will send a fault signal to the controller to indicate the fault that has occurred in the target component. In some embodiments, the target component may periodically send messages to the controller, such as heartbeat packets. The controller may determine whether the target component has failed based on the reception and parsing of these messages. For example, when no message from the target component is received within a period of time, the controller may generate a fault signal indicating the fault of the target component.
[0031] When the controller is in the wake-up state, the controller may continuously detect the faults of the target components in the vehicle. When a fault signal is detected, the controller may determine the moment when the fault signal is detected. In some embodiments, this moment may be the moment indicated in the fault signal received or generated by the controller. If this moment is within the threshold duration after the moment when the controller receives the power-off signal, the controller may discard the fault signal, that is, the controller may ignore the detected fault signal and not execute the fault handling strategy corresponding to the fault signal. In some embodiments, the controller may stop detecting the fault signal within the threshold duration after receiving the power-off signal.
[0032] Traditionally, as long as the controller detects a fault signal of a target component, it will execute the corresponding fault handling strategy. However, the power-down process of the vehicle itself may cause some fault signals to appear. In this case, the target component actually has no fault. If the fault handling strategy is executed, it will increase the energy consumption of the vehicle and may cause unnecessary system locking or function locking, such as locking of the fuel cell system. Through the method 200 in the embodiments of the present disclosure, within a period of time after receiving the power-down signal, the controller can bypass the fault signal and does not execute the fault handling strategy corresponding to the fault signal. In this way, the energy consumption of the controller and the vehicle for handling faults can be saved, and unnecessary system locking or function locking can be avoided, such as avoiding the locking of the fuel cell, so as to ensure that the next start of the vehicle can proceed normally and ensure the driving experience of the user.
[0033] In some embodiments, if the moment when the controller detects a fault signal of the target component is outside the threshold duration after the moment when the power-down signal is received, the controller can execute the fault handling strategy corresponding to the fault signal. Schematically, Figure 3 FIG. shows a schematic diagram of a scenario 300 in which the controller 310 processes a fault signal corresponding to a target component at different times. The scenario 300 may include a controller 310, and the controller 310 may correspond to the FCCU 120 in the vehicle 100, for example. The controller 310 can perform different processing on the fault signal at different times.
[0034] Referring to Figure 3 , at time T1, the controller 310 executes block 302 and receives the power-down signal of the vehicle. During the time period from time T1 to time T2, for example, at time T3, if the controller 310 detects a fault signal of the target component of the vehicle, the controller 310 can execute block 304 to discard the fault signal and does not execute the fault handling strategy corresponding to the fault signal. The time interval between time T2 and time T1 is the threshold duration. At a time outside the time period from time T1 to time T2, such as time T4 before time T1 or time T5 after time T2, if the controller 310 detects a fault signal of the target component of the vehicle, the controller 310 can execute block 306 to execute the fault handling strategy corresponding to the fault signal, such as shutting down or locking the fuel cell system of the vehicle. In some embodiments, the controller 310 can send an indication message that the target component has a fault to the VCU of the vehicle. In some embodiments, the controller 310 can lock the fuel cell system at the software level. In this way, after the time after receiving the power-down signal exceeds the threshold duration, the controller can resume normal detection and handling of faults, so as to ensure the normal operation of the vehicle and avoid possible dangers caused by faults.
[0035] In some embodiments, the controller can detect multiple fault signals. Each fault signal can be generated for different reasons and can indicate different faults of the target component. Exemplarily, some of the fault signals can be fault signals indicating a fault in receiving a message for the target component, which, for the sake of convenience of description, are referred to as first fault signals. Another type of fault signals may indicate a fault of the target component itself, which, for the sake of convenience of description, are referred to as second fault signals. During the power-down process of the vehicle, if the target component enters the sleep state before the controller, the message sent by the target component to the controller will be interrupted, and the controller may generate a first fault signal due to the interruption of message reception. Such a fault signal does not need to be processed.
[0036] In some embodiments, within a threshold duration after receiving the power-down signal of the vehicle, the controller can only execute Method 200 for the first fault signals and does not execute Method 200 for the second fault signals. That is to say, the controller can discard the first fault signal when detecting the first fault signal, and normally execute the fault handling strategy corresponding to the second fault signal when detecting the second fault signal. In this way, the controller can adopt different processing methods for different types of fault signals, so as to avoid processing the fault signals caused by the power-down process itself while maintaining the processing of necessary fault signals. In this way, the consumption of executing unnecessary fault handling strategies can be reduced while ensuring the safe operation of the vehicle, and unnecessary system locking or function locking can also be avoided, ensuring the normal start of the vehicle next time.
[0037] In some embodiments, the first fault signal can include a timeout fault signal. When the target component is operating normally, it can periodically send messages to the controller. In the case where the duration during which the controller does not receive a message from the target component exceeds a predefined duration, the controller can generate a timeout fault signal. In some embodiments, the first fault signal includes a count fault signal. The periodic messages sent by the target component to the controller during normal operation can include consecutive numbers. In the case where the controller detects that the numbers of the periodic messages from the target component are not consecutive, the controller can determine that there are missed messages, and the controller can generate a count fault signal. In some embodiments, the second fault signal includes a checksum fault signal. In the case where the controller determines that the checksum of the message from the target component is abnormal, the controller can generate a checksum fault signal.
[0038] In some embodiments, the controller may detect faults of multiple components of the vehicle. For each component, there may be a corresponding threshold duration. The threshold duration may be predefined and stored in the memory of the controller. After receiving the power-off signal of the vehicle, if a fault signal from a target component is received, the controller may first determine the threshold duration corresponding to the target component. Exemplarily, among the multiple components, there may be a first target component. When a fault signal corresponding to the first target component is detected, the controller may determine the first threshold duration corresponding to the first target component. The fault signal corresponding to the first target component may be detected at a first moment. If it is determined that the first moment is within the first threshold duration after receiving the power-off signal of the vehicle, the controller may discard the detected fault signal corresponding to the first target component.
[0039] In some embodiments, among the multiple components, there may be a second target component different from the first target component. When a fault signal corresponding to the second target component is detected, the controller may determine the second threshold duration corresponding to the second target component. The fault signal corresponding to the second target component may be detected at a second moment. If it is determined that the second moment is within the second threshold duration after receiving the power-off signal of the vehicle, the controller may discard the detected fault signal corresponding to the second target component. In some embodiments, the second threshold duration is different from the first threshold duration. In some embodiments, the second threshold duration is the same as the first duration. That is to say, the threshold durations corresponding to each component may be the same or different.
[0040] In some embodiments, after receiving the power-off signal of the vehicle, the controller may detect multiple fault signals corresponding to a component. For example, it may include a first fault signal and a second fault signal. The controller may process them separately. For example, the controller may execute method 200 for the first fault signal and not execute method 200 for the second fault signal. In some embodiments, the controller may detect fault signals corresponding to multiple components. The controller may process the fault signals of multiple components in parallel. The controller may execute method 200 for the fault signals corresponding to some components and not execute method 200 for the fault signals corresponding to some other components.
[0041] In some embodiments, the vehicle frequently changes its power-on and power-off states within a short period of time. The controller may receive a power-on signal and then receive a power-off signal again within a short time after receiving the power-off signal. In some embodiments, the controller may extend the value of the threshold duration if it receives the power-off signal again within the threshold duration of receiving the vehicle's power-off signal. Exemplarily, the predefined threshold duration corresponding to the target component may be a first value. After receiving the vehicle's power-off signal, the controller determines that the threshold duration corresponding to the target component is the first value and discards the fault signals detected within the threshold duration after the moment of receiving the power-off signal. If the controller receives the power-off signal again within the threshold duration, the controller may extend the threshold duration from the first value to a second value. The difference between the second value and the first value may be predefined. For example, the controller may extend the threshold duration by adding a predefined difference to the first value. In some embodiments, if the controller receives the power-off signal again within the threshold duration, the controller may recalculate the threshold duration. That is, the controller may use the moment of receiving the power-off signal again as the starting point and discard the fault signals detected within the threshold duration after the moment of receiving the power-off signal again.
[0042] Exemplarily, Figure 4 FIG. 400 shows a schematic diagram of a scenario 400 for extending the threshold duration in some embodiments of the present disclosure. In scenario 400, it may include a controller 410, which may correspond to the controller 310 in scenario 300 or the FCCU 120 in vehicle 100, for example. Referring to Figure 4 , at time T6, the controller 410 executes block 402 and receives the vehicle's power-off signal. If the controller 410 detects a fault signal from the target component within the threshold duration after time T6, the controller 410 may discard the target signal. If the controller 410 receives the vehicle's power-off signal again within the threshold duration after time T6, for example, at time T8, the controller 410 may execute block 404 to extend the threshold duration. Exemplarily, before executing block 404, the threshold duration is the first value, and after executing block 404, the threshold duration may be extended to the second value.
[0043] As an example, in Figure 4Among them, the time interval between time T7 after time T6 and time T6 can be a first value, and the time interval between time T9 after time T6 and time T6 can be a second value. After executing block 402, the controller 410 can discard the detected fault signal from the target component within the time period between time T6 and time T7. After executing block 404, the controller can discard the detected fault signal from the target component within the time period between time T6 and time T9. It should be understood that the moments in scenario 400 can correspond to the moments in scenario 300. For example, time T1 can correspond to time T6, and time T2 can correspond to time T7 or time T9. When time T1 corresponds to time T6 and time T2 corresponds to time T7 or time T9, time T8 can be before time T3, after time T3, or the same as time T3.
[0044] In some embodiments, if the controller receives a power-down signal of the vehicle again after receiving the power-down signal, for example, within the threshold duration after the first reception of the power-down signal or outside the threshold duration after the first reception of the power-down signal, the controller can process the fault signal through method 200 based on the latest received power-down signal moment. In some embodiments, the controller can execute method 200 when it determines that no component of the vehicle has failed. That is to say, in method 200, within the specified threshold duration before receiving the power-down signal of the vehicle, the controller does not detect a fault signal corresponding to the target component. It should be understood that the specified threshold duration and the aforementioned threshold duration can be independent duration values, which can be equal or unequal.
[0045] In some embodiments, the controller can also determine whether the fault signal is within the threshold duration after receiving the power-down signal of the vehicle in the form of countdown. Exemplarily, Figure 5 FIG. shows a schematic flowchart of a method 500 for processing a fault signal according to some embodiments of the present disclosure. Figure 5 The illustrated method 500 can be executed by a controller, which can detect faults of multiple components. The controller can be, for example, the controller 410 in scenario 400, the controller 310 in scenario 300, or the FCCU 120 in the vehicle 100. As Figure 5 shown, method 500 can include block 502 to block 518. In block 502, when the controller receives a power-down signal of the vehicle, it starts multiple countdowns respectively corresponding to multiple components. The values of the respective countdowns can be the same or different, and the starting value of each countdown is the value of the threshold duration corresponding to the component.
[0046] In block 504, the controller detects a fault signal from a target component. In block 506, the controller determines a countdown corresponding to the target component. In block 508, the controller determines whether the moment when the fault signal from the target component is detected is before the end of the countdown. If not, block 510 is executed; if so, block 512 is executed. In block 510, the controller executes a fault handling strategy corresponding to the fault signal, such as locking the fuel cell system of the vehicle. In block 512, the controller determines whether the fault signal is a predefined first fault signal, and the first fault signal may include a timeout fault signal or a count - over fault signal. If not, block 510 is executed; if so, block 514 is executed. In block 514, the controller discards the fault signal and does not execute the fault handling strategy corresponding to the fault signal. In block 516, the controller receives a power - off signal again before the end of the countdown corresponding to the target component. In block 518, the controller extends the countdown corresponding to the target component, such as adding a predefined value to the current value of the countdown. Then the controller continues to detect the fault signal, and when a fault signal from the target component is detected, it returns to block 504.
[0047] It should be understood that Figure 5 The method 500 shown is only an example of an embodiment of the present disclosure and cannot be a limitation on the solutions provided by the present disclosure. For example, in some embodiments, the order of block 508 and block 512 can be swapped. In some embodiments, block 508 and block 512 can be executed simultaneously. In some embodiments, block 516 can be executed before or after block 508, 512 or 514, or can be executed simultaneously with block 508, 512 or 514. In some embodiments, in the method 500, the controller may not execute block 516 and block 518, that is, it returns to block 504 after block 514. Through the method 500, fault signals can be ignored and the corresponding fault handling strategies are not executed within a period of time after the vehicle is powered off, so as to avoid incorrect system locking or function locking in the case where the vehicle is powered on and off frequently in a short time, enabling the vehicle to start smoothly during the subsequent power - on process.
[0048] Figure 6 The block diagram of a device 600 for processing fault signals according to some embodiments of the present disclosure is shown. Exemplarily, as Figure 6 shown, the device 600 may include a receiving module 602 configured to receive a power - off signal of the vehicle, where the power - off signal is used to turn off the vehicle. The device 600 may further include a processing module 604 configured to discard a fault signal corresponding to a target component of the vehicle in response to detecting the fault signal within a threshold duration after receiving the power - off signal, where the fault signal indicates a fault of the target component.
[0049] In some embodiments, the processing module 604 includes a first processing unit configured to discard a first fault signal in response to detecting the first fault signal corresponding to a target component of the vehicle within a threshold duration after receiving a power-down signal, where the first fault signal indicates a fault in receiving a message of the target component; and the apparatus 600 further includes a second processing module configured to execute a fault handling strategy corresponding to a second fault signal in response to detecting the second fault signal, where the second fault signal is different from the fault indicated by the first fault signal.
[0050] In some embodiments, the apparatus 600 further includes a third processing module configured to execute a fault handling strategy corresponding to a fault signal in response to detecting the fault signal after the threshold duration after receiving the power-down signal.
[0051] In some embodiments, the fault handling strategy includes locking the fuel cell system of the vehicle.
[0052] In some embodiments, the vehicle includes a plurality of target components, where the plurality of target components respectively correspond to a plurality of threshold durations, and the processing module 604 of the apparatus 600 further includes: a first duration determination unit configured to determine a first threshold duration corresponding to a first target component in response to detecting a fault signal corresponding to the first target component at a first moment; and a first signal discarding unit configured to discard the fault signal corresponding to the first target component in response to determining that the first moment is within the first threshold duration after receiving the power-down signal.
[0053] In some embodiments, the processing module 604 further includes: a second duration determination unit configured to determine a second threshold duration corresponding to a second target component in response to detecting a fault signal corresponding to the second target component at a second moment, where the second threshold duration is different from the first threshold duration; and a second signal discarding unit configured to discard the fault signal corresponding to the second target component in response to determining that the second moment is within the second threshold duration after receiving the power-down signal.
[0054] In some embodiments, the threshold duration is a first value, and the apparatus 600 further includes a duration extension module configured to extend the threshold duration from the first value to a second value in response to receiving a power-down signal again within the threshold duration after receiving the power-down signal.
[0055] In some embodiments, within a third threshold duration before the receiving module 602 receives the power-down signal, the apparatus 600 does not detect a fault signal corresponding to the target component.
[0056] In some embodiments, the fault signal includes a timeout fault signal, and the apparatus 600 further includes a first detection module configured to generate a timeout fault signal in response to the duration of not receiving a message from a target component exceeding a third threshold duration.
[0057] In some embodiments, the fault signal includes a count fault signal, and the apparatus 600 further includes a second detection module configured to generate a count fault signal in response to detecting that the numbers of messages from a target component are discontinuous.
[0058] Figure 7 FIG. shows a schematic block diagram of an exemplary device 700 that may be used to implement embodiments of the present disclosure. The device 700 may correspond to the controller in the foregoing method embodiments, for example, it may be the FCCU 120 in the vehicle 100, the controller 310 in the scenario 300, or the controller 410 in the scenario 400. As Figure 7 shown, the device 700 includes a computing unit 701, which can perform various appropriate actions and processes according to machine-executable instructions stored in a read-only memory (ROM) 702 or machine-executable instructions loaded from a storage unit 708 into a random-access memory (RAM) 703. In the RAM 703, various programs and data required for the operation of the device 700 can also be stored. The computing unit 701, the ROM 702, and the RAM 703 are connected to each other via a bus 704. An input / output (I / O) interface 705 is also connected to the bus 704.
[0059] Multiple components in the device 700 are connected to the I / O interface 705, including: an input unit 706; an output unit 707; a storage unit 708, such as a magnetic disk, an optical disc, a flash memory, etc.; and a communication unit 709, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 709 allows the device 700 to exchange information / data with other devices through an in-vehicle communication link such as a CAN bus and / or various telecommunication networks.
[0060] The computing unit 701 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 701 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The computing unit 701 executes the various methods and processes described above, such as method 200 or method 500. For example, in some embodiments, method 200 or method 500 may be implemented as a computer software program tangibly embodied in a machine-readable medium, such as the storage unit 708. In some embodiments, part or all of the computer program may be loaded and / or installed onto the device 700 via the ROM 702 and / or the communication unit 709. When the computer program is loaded into the RAM 703 and executed by the computing unit 701, one or more steps of method 200 or method 500 described above may be executed. Alternatively, in other embodiments, the computing unit 701 may be configured to execute method 200 or method 500 in any other suitable manner (e.g., by means of firmware).
[0061] The functions described above herein can be performed at least in part by one or more hardware logic components. By way of example and not limitation, the types of hardware logic components that may be used include: field programmable gate arrays (FPGA), application specific integrated circuits (ASIC), application specific standard products (ASSP), system on a chip systems (SOC), complex programmable logic devices (CPLD), and the like.
[0062] The program code for implementing the methods of the present disclosure can be written in any combination of one or more programming languages. These program codes can be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the program codes are executed by the processor or controller, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The program code can be executed entirely on the machine, partially on the machine, as a stand-alone software package partially on the machine and partially on a remote machine, or entirely on a remote machine or server.
[0063] In the context of the present disclosure, a machine-readable medium can be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of a machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing. Further, although the operations are depicted in a particular order, this should be understood as requiring that such operations be performed in the particular order shown or in a sequential order, or that all illustrated operations be performed to achieve the desired result. In certain environments, multitasking and parallel processing may be advantageous. Similarly, although several specific implementation details are included in the foregoing discussion, these should not be construed as limiting the scope of the present disclosure. Certain features that are described in the context of separate embodiments can also be implemented in combination in a single implementation. Conversely, the various features that are described in the context of a single implementation can also be implemented separately or in any suitable sub-combination in multiple implementations.
[0064] Although the subject matter has been described in language specific to structural features and / or methodological acts, it is to be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or acts described above. Rather, the specific features and acts described above are merely example forms of implementing the claims.
Claims
1. A method for processing a fault signal, comprising: Receiving a power-off signal of a vehicle, wherein the power-off signal is used to turn off the vehicle; And Within a threshold duration after receiving the power-off signal, in response to detecting a fault signal corresponding to a target component of the vehicle, discarding the fault signal, wherein the fault signal indicates a fault of the target component.
2. The method according to claim 1, wherein discarding the fault signal in response to detecting a fault signal corresponding to a target component of the vehicle comprises: Within a threshold duration after receiving the power-off signal, in response to detecting a first fault signal corresponding to a target component of the vehicle, discarding the first fault signal, wherein the first fault signal indicates a fault in receiving a message of the target component; And Wherein the method further comprises: In response to detecting a second fault signal, executing a fault handling strategy corresponding to the second fault signal, wherein the second fault signal is different from the fault indicated by the first fault signal.
3. The method according to claim 1, further comprising: After the threshold duration after receiving the power-off signal, in response to detecting the fault signal, executing a fault handling strategy corresponding to the fault signal.
4. The method according to claim 2 or 3, wherein the fault handling strategy comprises: Locking the fuel cell system of the vehicle.
5. The method according to claim 1, wherein the vehicle comprises a plurality of target components, wherein the plurality of target components respectively correspond to a plurality of threshold durations, and wherein discarding the fault signal in response to detecting a fault signal corresponding to a target component of the vehicle comprises: In response to detecting a fault signal corresponding to a first target component at a first moment, determining a first threshold duration corresponding to the first target component; And In response to determining that the first moment is within the first threshold duration after receiving the power-off signal, discarding the fault signal corresponding to the first target component.
6. The method according to claim 5, wherein discarding the fault signal in response to detecting a fault signal corresponding to a target component of the vehicle further comprises: In response to detecting a fault signal corresponding to a second target component at a second moment, determining a second threshold duration corresponding to the second target component, wherein the second threshold duration is different from the first threshold duration; And In response to determining that the second moment is within the second threshold duration after receiving the power-off signal, discarding the fault signal corresponding to the second target component.
7. The method according to claim 1, wherein the threshold duration is a first value, and the method further comprises: In response to receiving the power-off signal again within the threshold duration after receiving the power-off signal, extending the threshold duration from the first value to a second value.
8. The method according to claim 1, wherein within a third threshold duration before receiving the power-off signal, no fault signal corresponding to the target component is detected.
9. The method according to claim 1, wherein the fault signal includes a timeout fault signal, and the method further comprises: generating the timeout fault signal in response to a duration during which a message from the target component is not received exceeding a third threshold duration.
10. The method according to claim 1, wherein the fault signal includes a count fault signal, and the method further comprises: generating the count fault signal in response to detecting that the numbers of messages from the target component are not consecutive.
11. An apparatus for processing a fault signal, comprising: a receiving module configured to receive a power-off signal of a vehicle, wherein the power-off signal is used to turn off the vehicle; and a processing module configured to discard the fault signal in response to detecting a fault signal corresponding to a target component of the vehicle within a threshold duration after receiving the power-off signal, wherein the fault signal indicates a fault of the target component.
12. A controller, comprising: at least one processor; and a memory coupled to the at least one processor and having instructions stored thereon, the instructions, when executed by the at least one processor, cause the controller to execute the method according to any one of claims 1-10.
13. A vehicle, comprising the controller according to claim 12.
14. A machine-readable storage medium having machine-executable instructions stored thereon, wherein the machine-executable instructions are executed by a processor to implement the method according to any one of claims 1 to 10.