Fault processing method and vehicle

CN121291472APending Publication Date: 2026-01-09GREAT WALL MOTOR CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511770527.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-28
Publication Date
2026-01-09

AI Technical Summary

Technical Problem

In existing technology, once a vehicle malfunctions, high voltage cannot be applied to ensure safety, resulting in the vehicle becoming completely unable to operate normally and causing customer complaints.

Method used

By detecting faulty components, determining the fault level and duration, and combining this with risk assessment, targeted fault handling measures can be developed to avoid a one-size-fits-all approach and achieve a dynamic balance between driving safety and efficiency.

Benefits of technology

Accurately locate faulty parts, reduce troubleshooting time, avoid safety hazards caused by excessive intervention or insufficient handling, and improve driving safety and efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121291472A_ABST
    Figure CN121291472A_ABST
Patent Text Reader

Abstract

The invention provides a fault processing method and a vehicle, and relates to the technical field of vehicle control. The method comprises the following steps: when a vehicle has a first type of preset fault, detecting whether a fault part exists or not; determining the fault level according to the detection result, and determining the fault duration of the fault part in the preset starting duration when the detection result is that the fault part is detected; according to the fault level and the fault duration, determining a risk value of a second type of preset fault caused by the first type of preset fault; and based on the risk value, determining a fault processing measure so as to carry out fault processing. The problems that in the prior art, once a vehicle breaks down, high voltage cannot be applied to guarantee safety, normal driving cannot be thoroughly achieved, and customer complaints are caused can be solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of vehicle control technology, and in particular to a fault handling method and a vehicle. Background Technology

[0002] Vehicle safety is of paramount importance and directly affects everyone's well-being. If a vehicle malfunctions, it must be investigated and dealt with promptly.

[0003] In related technologies, when a vehicle issues a fault alarm, the usual procedure for the safety of the vehicle and its occupants is as follows: if the vehicle is under high voltage, the Vehicle Control Unit (VCU) will issue a command to reduce the high voltage, causing the vehicle to change from a high voltage state to a low voltage state (with only the battery operating); if the vehicle is under low voltage, even if the driver attempts to increase the high voltage, the VCU will still prevent the vehicle from increasing the high voltage.

[0004] However, not all malfunctions are severe enough to render a vehicle completely inoperable; some malfunctions have a relatively limited impact and severity. If a blanket ban on high-voltage power is adopted, vehicles will become completely unusable due to the inability to access high voltage, easily leading to customer complaints. Summary of the Invention

[0005] This application provides a fault handling method and a vehicle to solve the problem in the prior art where, once a vehicle malfunctions, high voltage cannot be applied to ensure safety, resulting in the vehicle being completely unable to drive normally and causing customer complaints.

[0006] In a first aspect, embodiments of this application provide a fault handling method, including: When a vehicle experiences a Class 1 preset fault, check for faulty components. The fault level is determined based on the test results, and when the test results indicate that a faulty component is detected, the duration of the faulty component within a preset opening time is determined. Based on the fault level and the fault duration, determine the risk value of the first type of preset fault triggering the second type of preset fault; Based on the risk value, fault handling measures are determined for fault handling.

[0007] Based on the above technical solution, when a vehicle experiences a first-type preset fault, this application first detects the presence of a faulty component and determines the fault level based on the detection results, thereby clarifying the severity of the fault. Furthermore, if a faulty component is detected, the duration of the fault within a preset activation time is simultaneously determined. Combining the fault level and duration, the risk value of the first-type preset fault triggering a second-type preset fault is accurately calculated. Finally, based on this risk value, targeted fault handling measures are formulated and implemented. This operation can replace a one-size-fits-all approach, avoiding both excessive intervention disrupting normal driving and insufficient handling leading to safety hazards, effectively achieving a dynamic balance between driving safety and driving efficiency.

[0008] In one possible implementation, the detection of whether a faulty component exists includes: After the vehicle is de-energized, the first type of control components in the vehicle are shut off and the high voltage is re-energized to check for the presence of the first type of preset fault. If the first type of preset fault is detected, the first type of preset fault is determined to be a second type of control component fault; otherwise, the first type of preset fault is determined to be a first type of control component fault. Troubleshoot the faulty component based on either the second category of control component failure or the first category of control component failure.

[0009] Here, the first category of control components specifically refers to fault-related components that can be actively shut down when the vehicle is under high-voltage conditions. This application achieves decoupling of the first category of control components from the vehicle's high-voltage system by precisely executing a standardized operating procedure of reducing high voltage, shutting down the first category of control components, and re-establishing high voltage. If the detection results still show the presence of a first category of pre-defined fault, the source of the fault is directly determined to be a second category of control component; if the detection results return to normal, the fault is clearly attributed to a first category of control component. Based on this, for the clearly identified second category or first category of control component faults, targeted fault component investigation of the corresponding category is initiated, avoiding redundant operations of indiscriminate full-domain investigation. By directly classifying the fault category based on the detection results and initiating targeted investigation processes for the corresponding category of control components, the fault location time is significantly shortened, and the time occupied by the investigation process during vehicle operation is reduced.

[0010] In one possible implementation, based on the first category of control component failures, troubleshooting the faulty component includes: Activate the control components of each first category in a preset order; For each control unit of the first category that is turned on, obtain the power of the control unit of the first category and detect whether there is a preset fault of the first category. The faulty component is determined based on the control component of the first category that is activated when the power is greater than the preset power value and the first type of preset fault is detected.

[0011] In this embodiment, receiving a start command does not equate to actually entering a working state. This asynchrony between command reception and working state can easily lead to missed fault detection. Therefore, this application employs a dual-dimensional collaborative judgment scheme combining power detection and fault presence detection: when the controller's power exceeds a preset power value, it indicates the controller is working; if this is accompanied by a first type of preset fault, the controller is highly likely to be faulty. In this case, by identifying the first type of controller activated when its power exceeds the preset power value and the first type of preset fault is detected, the faulty controller can be determined, effectively avoiding missed fault detection and ensuring the accuracy of fault location.

[0012] In one possible implementation, determining the faulty component based on the first type of control component activated when the power is greater than a preset power value and a first type of preset fault is detected includes: For a first-category control unit that is activated when the power is greater than the preset power value and the first type of preset fault is detected, the control unit is controlled to be turned off after the activation time of the control unit reaches the preset activation duration; if the first type of preset fault disappears after the control unit is turned off, the control unit is determined to be a faulty unit.

[0013] In this embodiment, potential faulty components are first screened by power compliance and fault presence, and then a second verification is performed by checking that the fault disappears after shutdown. This further avoids misjudgment caused by a single judgment and ensures accurate location of the faulty component.

[0014] In one possible implementation, based on the second category of control component failures, troubleshooting the faulty component includes: Obtain the troubleshooting strategies for each control component in the second category; Based on the aforementioned troubleshooting strategy, the control components of the second category are investigated; Based on the investigation results, the faulty component was identified.

[0015] For the second category of control components, such as batteries and motors, which are key components of the vehicle's core power and operating system, they cannot be shut down arbitrarily. Faults cannot be diagnosed simply by observing whether the fault disappears after shutting down the component. Therefore, troubleshooting for these control components requires a specially customized troubleshooting strategy. This strategy should be tailored to the component's characteristics, operating principles, and potential fault modes to conduct targeted troubleshooting, ensuring a safe, controllable, accurate, and efficient process.

[0016] In one possible implementation, determining the fault level based on the detection results includes: If the test result indicates that no faulty component is detected, then the fault level is determined to be the first preset fault level; If the detection result indicates the presence of a faulty component, then when the faulty component is a control component of the first category, the fault level is determined to be a second preset fault level; when the faulty component is a control component of the second category, the corresponding fault level is determined based on the faulty component.

[0017] In this embodiment, if the detection result shows no faulty component, it may be an intermittent fault of certain control components, corresponding to a first preset fault level (lower risk). When a faulty component is detected, it is classified differently according to category: the first category of control component faults corresponds to a second preset fault level, while the second category of control component faults has a customized level based on the specific characteristics of the component. By binding the grading standard with the actual risk of the fault, differentiated grading rules are formulated, which not only conforms to the component's operating logic but also makes subsequent fault handling measures more targeted, avoiding over- or under-handling due to improper grading.

[0018] In one possible implementation, determining the risk value of the first type of preset fault triggering the second type of preset fault based on the fault level and the fault duration includes: Obtain the pre-stored risk assessment curve; Based on the fault level, the fault duration, and the risk assessment mapping relationship, determine the risk value of the first type of preset fault triggering the second type of preset fault; The risk assessment mapping relationship is a mapping of the risk values ​​of the second type of preset fault occurring under different fault levels and different fault durations when the first type of preset fault occurs.

[0019] In this embodiment, the risk assessment mapping relationship pre-calculates the probability data of fault escalation under different fault levels and durations, replacing subjective experience-based judgment. By directly matching the risk value with the actual fault level and duration, the objective and accurate risk quantification results can be ensured.

[0020] In one possible implementation, determining fault handling measures based on the risk value includes: Based on the risk value, the maximum amount of electricity charged by the vehicle, the number of times it can be driven, and at least one of the following: opening the high-voltage system; The maximum power consumption is negatively correlated with the risk value; the number of driving attempts is negatively correlated with the risk value; and the high-voltage system is restricted from starting when the risk value exceeds a preset risk threshold or the number of driving attempts reaches a preset number threshold.

[0021] This application's embodiments achieve precise matching between risk and control intensity through logic relating risk value to restriction strength. The greater the risk of escalating faults, the lower the maximum charging capacity, the fewer driving attempts, and even the restriction on high-voltage system startup. This directly reduces the probability of fault escalation from the usage scenario perspective, comprehensively ensuring driving and vehicle system safety. This application's embodiments do not directly prohibit vehicle use upon detecting risk, but rather dynamically adjust the restriction range based on the risk value. For example, low risk only slightly restricts the maximum charging capacity and driving attempts, while high risk strengthens the restrictions, avoiding excessive intervention that would inconvenience users.

[0022] In one possible implementation, prior to detecting whether a faulty component is present, the method further includes: The status of the vehicle is determined based on the vehicle parameters; If the vehicle is in motion, a parking check prompt will be issued; When the vehicle is parked, it is determined whether the vehicle is under high voltage. If the vehicle is under high voltage, the high voltage is reduced.

[0023] In this embodiment, when a vehicle experiences a first-type preset fault, if the vehicle is in motion, a stop and troubleshooting prompt is issued; if the vehicle is parked, it is determined whether the vehicle is under high voltage. If the vehicle is under high voltage, the high voltage is depressurized. This facilitates subsequent fault troubleshooting steps and ensures vehicle safety.

[0024] Secondly, embodiments of this application provide a fault handling apparatus, including: The detection module is used to detect whether there are faulty components when the vehicle experiences a first-class preset fault. The determination module is used to determine the fault level based on the detection result, and when the detection result indicates that a faulty component is detected, to determine the fault duration of the faulty component within a preset opening time. An evaluation module is used to determine the risk value of the first type of preset fault triggering the second type of preset fault based on the fault level and the fault duration; The processing module is used to determine fault handling measures based on the risk value in order to handle the fault.

[0025] In one possible implementation, the detection module is used for: After the vehicle is de-energized, the first type of control components in the vehicle are shut off and the high voltage is re-energized to check for the presence of the first type of preset fault. If the first type of preset fault is detected, the first type of preset fault is determined to be a second type of control component fault; otherwise, the first type of preset fault is determined to be a first type of control component fault. Troubleshoot the faulty component based on either the second category of control component failure or the first category of control component failure.

[0026] In one possible implementation, the detection module is used for: Activate the control components of each first category in a preset order; For each control unit of the first category that is turned on, obtain the power of the control unit of the first category and detect whether there is a preset fault of the first category. The faulty component is determined based on the control component of the first category that is activated when the power is greater than the preset power value and the first type of preset fault is detected.

[0027] In one possible implementation, the detection module is used for: For a first-category control unit that is activated when the power is greater than the preset power value and the first type of preset fault is detected, the control unit is controlled to be turned off after the activation time of the control unit reaches the preset activation duration; if the first type of preset fault disappears after the control unit is turned off, the control unit is determined to be a faulty unit.

[0028] In one possible implementation, the detection module is used for: Obtain the troubleshooting strategies for each control component in the second category; Based on the aforementioned troubleshooting strategy, the control components of the second category are investigated; Based on the investigation results, the faulty component was identified.

[0029] In one possible implementation, the determining module is used to: If the test result indicates that no faulty component is detected, then the fault level is determined to be the first preset fault level; If the detection result indicates the presence of a faulty component, then when the faulty component is a control component of the first category, the fault level is determined to be a second preset fault level; when the faulty component is a control component of the second category, the corresponding fault level is determined based on the faulty component.

[0030] In one possible implementation, the evaluation module is used to: Obtain pre-stored risk assessment mapping relationships; Based on the fault level, the fault duration, and the risk assessment mapping relationship, determine the risk value of the first type of preset fault triggering the second type of preset fault; The risk assessment mapping relationship is a mapping of the risk values ​​of the second type of preset fault occurring under different fault levels and different fault durations when the first type of preset fault occurs.

[0031] In one possible implementation, the processing module is used to: Based on the risk value, the maximum amount of electricity charged by the vehicle, the number of times it can be driven, and at least one of the following: opening the high-voltage system; The maximum power consumption is negatively correlated with the risk value; the number of driving attempts is negatively correlated with the risk value; and the high-voltage system is restricted from starting when the risk value exceeds a preset risk threshold or the number of driving attempts reaches a preset number threshold.

[0032] In one possible implementation, before detecting whether a faulty component is present, the detection module is further configured to: The status of the vehicle is determined based on the vehicle parameters; If the vehicle is in motion, a parking check prompt will be issued; When the vehicle is parked, it is determined whether the vehicle is under high voltage. If the vehicle is under high voltage, the high voltage is reduced.

[0033] Thirdly, embodiments of this application provide a vehicle including a memory and a processor. The memory stores a computer program that can run on the processor, and when the processor executes the computer program, it implements the fault handling method as described in any of the first aspects.

[0034] Fourthly, embodiments of this application provide a computer-readable storage medium storing a computer program that, when executed by a processor, implements the fault handling method as described in any of the first aspects.

[0035] It is understood that the beneficial effects of the second to fourth aspects mentioned above can be found in the relevant descriptions in the first aspect mentioned above, and will not be repeated here.

[0036] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and are not intended to limit this specification. Attached Figure Description

[0037] To more clearly illustrate the technical solutions in the embodiments of this application, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0038] Figure 1 This is a schematic diagram of an application scenario provided by an embodiment of this application; Figure 2 This is a schematic flowchart of a fault handling method provided in an embodiment of this application; Figure 3This is a flowchart illustrating a fault handling method provided in another embodiment of this application; Figure 4 This is a flowchart illustrating a fault handling method provided in another embodiment of this application; Figure 5 This is a schematic diagram of the structure of a fault handling device provided in an embodiment of this application; Figure 6 This is a schematic diagram of the structure of a vehicle provided in one embodiment of this application. Detailed Implementation

[0039] The present application will be described more clearly below with reference to specific embodiments. These embodiments will help those skilled in the art to further understand the function of the present application, but do not limit the present application in any way. It should be noted that those skilled in the art can make several modifications and improvements without departing from the concept of the present application. These all fall within the protection scope of the present application.

[0040] It should be understood that, when used in this application specification and the appended claims, the term "comprising" indicates the presence of the described features, integrals, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, integrals, steps, operations, elements, components and / or a collection thereof.

[0041] It should also be understood that the term “and / or” as used in this application specification and the appended claims means any combination of one or more of the associated listed items and all possible combinations, and includes such combinations.

[0042] In the description of this application and the appended claims, the terms "first," "second," "third," etc., are used only to distinguish descriptions and should not be construed as indicating or implying relative importance.

[0043] References to "one embodiment" or "some embodiments" as described in this specification mean that one or more embodiments of this application include a specific feature, structure, or characteristic described in connection with that embodiment. Therefore, the phrases "in one embodiment," "in some embodiments," "in other embodiments," "in still other embodiments," etc., appearing in different parts of this specification do not necessarily refer to the same embodiment, but rather mean "one or more, but not all, embodiments," unless otherwise specifically emphasized. The terms "comprising," "including," "having," and variations thereof mean "including but not limited to," unless otherwise specifically emphasized.

[0044] Furthermore, the term "multiple" mentioned in the embodiments of this application should be interpreted as two or more.

[0045] The applicant discovered that the electrical circuits in a vehicle's high-voltage system are closely interconnected. When a primary circuit fails, current may leak through unexpected paths, and this abnormal current distribution can lead to secondary circuit failures. For example, a primary circuit failure in the negative terminal can cause local electric field disorder, resulting in the electric field strength experienced by the positive terminal exceeding the design tolerance threshold. This accelerates the aging or damage of the positive terminal's insulation layer, ultimately triggering a secondary circuit failure where both the positive and negative terminals fail simultaneously. Upon a secondary circuit failure, to ensure the safety of the vehicle and its occupants, the VCU (Vehicle Control Unit) will initiate mandatory safety controls: blocking the high-voltage system from starting. For pure electric vehicles, the inability to connect to high voltage will directly result in a loss of driving capability, which will inevitably have a serious impact on user travel, leading to customer dissatisfaction and complaints. Therefore, it is necessary to consider a new method to adaptively limit primary circuit failures in vehicles.

[0046] To mitigate the risk of driving interruption caused by secondary circuit faults and improve the accuracy of fault handling, in this embodiment, after receiving primary circuit fault information, the VCU will first perform a fault location operation and then determine the fault level based on the location results. Simultaneously, the VCU will also statistically analyze the duration of the primary circuit fault. Finally, combining the fault level and duration, it will comprehensively assess the probability of secondary circuit fault occurrence and determine the degree of subsequent impact on the vehicle's driving performance. Based on this, the VCU will formulate and implement an appropriate function degradation strategy according to the assessment results of the impact on driving performance.

[0047] First refer to Figure 1 , Figure 1 The schematic diagram illustrates an application scenario provided according to an embodiment of this application. The devices involved in the application scenario include: a multi-type sensor 11, a VCU 12, an execution module 13, and a human-computer interaction module 14.

[0048] Multi-type sensors 11: Covering various vehicle body status sensors (such as high-voltage system voltage sensors, component temperature sensors), control component operation sensors (such as power sensors, current sensors), etc., responsible for fault signal and status data acquisition, and real-time detection of the first type of preset fault signals, fault component operation parameters (power, duration) and vehicle status (driving / parking, high-voltage status).

[0049] VCU 12: As the core decision-making hub of the process, it coordinates the entire process of calculation and instruction issuance. The VCU receives sensor data, executes faulty component detection and fault level determination logic; calls pre-stored data to calculate the probability of fault escalation; and outputs fault handling instructions based on the probability (such as limiting charging power and driving frequency).

[0050] Execution Module 13: Responds to control unit commands and performs specific fault handling operations. This includes the high-voltage system control component (implementing high-voltage reduction / limiting high-voltage start-up), the charging system controller (adjusting the maximum charging capacity), and the body control module (recording driving frequency and enforcing restrictions), etc.

[0051] Human-computer interaction module 14: It outputs parking inspection prompts and other information through the instrument panel and central control screen to guide users to cooperate in the operation, ensuring the visualization of the process execution and driving safety.

[0052] In this application scenario, the fault handling method is executed by the VCU. It should be noted that the fault handling method can also be executed by other processors or servers, and this application does not limit this. The fault handling method provided according to the exemplary embodiments of this application can be executed on the same device or on different devices.

[0053] The following is combined Figure 1 Application scenarios, refer to Figure 2 and Figure 3 This application describes a fault handling method provided according to exemplary embodiments. It should be noted that the above application scenarios are shown only to facilitate understanding of the spirit and principles of this application, and the embodiments of this application are not limited in any way. Rather, the embodiments of this application can be applied to any applicable scenario.

[0054] Figure 2 This is a schematic diagram illustrating the implementation flow of a fault handling method provided in an embodiment of this application. See also... Figure 2 As shown, the method includes: Step S201: When the vehicle experiences a first-type preset fault, check for faulty components.

[0055] The first type of pre-defined fault here refers to low-level circuit faults, which are the first-level circuit faults mentioned above, such as a fault in the negative circuit of a certain control component.

[0056] The vehicle's high-voltage system is equipped with hardware such as voltage sensors, current sensors, and insulation monitoring sensors to collect circuit parameters (such as line voltage, operating current, and insulation resistance values) in real time. When a fault occurs in a control component's negative terminal line or other location, it will cause abnormal parameters (such as local voltage fluctuations, current leakage, and decreased insulation resistance). The sensors will transmit the abnormal data to the VCU in real time. The VCU will determine that a first-class preset fault has occurred and can output visual alarm information through the instrument panel and central control screen, such as a fault prompt pop-up window or the illumination of a dedicated fault indicator light, so that the driver can intuitively understand the fault situation.

[0057] Furthermore, the vehicle will use pre-set standard detection logic to locate the specific faulty component that causes the first type of preset fault. The entire process is automated and highly targeted, requiring no manual intervention.

[0058] Step S202: Determine the fault level based on the detection results, and when the detection results indicate that a faulty component is detected, determine the fault duration of the faulty component within the preset opening time.

[0059] In this embodiment, the vehicle first determines the fault level based on the faulty component detection results. If a specific faulty component is detected, the actual fault duration of that component within a preset activation time is also simultaneously calculated, providing accurate data support for subsequent risk assessment. The fault level (reflecting the severity of the fault) and the fault duration (reflecting the duration of the fault's impact) form two-dimensional data, jointly providing the core basis for calculating the risk value of the first type of fault leading to the second type of fault, making subsequent fault handling measures more targeted.

[0060] Step S203: Determine the risk value of the first type of preset fault triggering the second type of preset fault based on the fault level and fault duration.

[0061] The second type of pre-defined fault is the high-level circuit fault, which is the secondary circuit fault mentioned above. The fault level directly corresponds to the severity of the fault, and the fault duration reflects the cumulative impact of the fault on the system. Combining the two can comprehensively characterize the potential risk of fault escalation.

[0062] In one possible implementation, systematic testing can be conducted beforehand to generate a corresponding risk value reference data carrier. This can be either a two-dimensional risk value table (covering the risk value correspondence between the first type of preset fault and the second type of preset fault under different fault levels and durations) or a risk assessment curve (visually presenting the dynamic correlation trend between different fault levels, durations, and the risk of the second type of preset fault). In practical applications, by combining the fault level and duration obtained from actual vehicle testing, and by querying this two-dimensional risk value table or matching the risk assessment curve, the risk value of the first type of preset fault escalating into the second type of preset fault can be accurately determined.

[0063] In this embodiment, a two-dimensional risk value table or risk assessment curve is used to pre-calculate the probability of fault escalation under different fault levels and durations, replacing subjective experience-based judgment. The risk value is directly matched with the actual fault level and duration, ensuring that the risk quantification results are objective and accurate.

[0064] Step S204: Based on the risk value, determine the fault handling measures to carry out fault handling.

[0065] In this embodiment, the vehicle has preset risk thresholds (such as low, medium, and high risk ranges), with different risk value ranges corresponding to different intensities of handling measures. The lower the risk value, the milder the measures; the higher the risk value, the stricter the measures, to avoid under- or over-handling. For example, based on the risk value, at least one of the following can be limited: the maximum battery level during vehicle charging, the number of driving sessions, and the activation of the high-voltage system; wherein, the maximum battery level is negatively correlated with the risk value; the number of driving sessions is negatively correlated with the risk value; and the high-voltage system is restricted from activation when the risk value exceeds the preset risk threshold or the number of driving sessions reaches the preset number of driving sessions threshold.

[0066] By employing a logic of negative correlation between risk value and restriction intensity, a precise match between risk and control strength can be achieved. The greater the risk of escalating faults, the lower the maximum charging capacity, the fewer driving attempts, and even the restriction on high-voltage system startup. This directly reduces the probability of fault escalation from the usage scenario perspective, comprehensively ensuring driving and vehicle system safety. This application's embodiments do not directly prohibit vehicle use upon detecting risk, but rather dynamically adjust the restriction range based on the risk value. For example, low risk only slightly restricts the maximum charging capacity and driving attempts, while high risk strengthens the restrictions, avoiding excessive intervention that would inconvenience users.

[0067] Based on the above technical solution, when a vehicle experiences a first-type preset fault (usually a less serious fault), this application first detects the presence of a faulty component and determines the fault level based on the detection results, thereby clarifying the severity of the fault. Furthermore, if a faulty component is detected, the duration of the fault within a preset activation time is simultaneously determined. Combining the fault level and duration, the risk value of the first-type preset fault triggering a second-type preset fault (a more serious fault) is accurately calculated. Finally, based on this risk value, targeted fault handling measures are formulated and implemented. This operation can replace a one-size-fits-all approach, avoiding both excessive intervention disrupting normal driving and insufficient handling leading to safety hazards, effectively achieving a dynamic balance between driving safety and driving efficiency.

[0068] In some embodiments, in order to improve the efficiency and accuracy of faulty component detection, this application also designs a faulty component detection process.

[0069] See Figure 3 As shown, the inspection includes checking for faulty components, including: Step S2011: After the vehicle is de-energized, the first type of control unit in the vehicle is turned off and the high voltage is re-energized to check for the presence of a first type of preset fault.

[0070] Here, the first category of control components specifically refers to fault-related components that can be actively shut down when the vehicle is under high voltage. Examples include air conditioning compressors and heating bridges, which are non-mode control components. These control components can be actively shut down when the vehicle is under high voltage. Therefore, a standardized operating procedure of lowering the high voltage, shutting down the first category of control components, and then re-establishing the high voltage can be used to simultaneously initiate the first category of preset fault detection, thereby decoupling the first category of control components from the vehicle's high voltage system.

[0071] Step S2012: If a first-type preset fault is detected, the first-type preset fault is determined to be a second-type control component fault; otherwise, the first-type preset fault is determined to be a first-type control component fault.

[0072] The second category of control components may include, but is not limited to, mode control components such as batteries, motors, DC-DC converters, and on-board chargers. It is understood that if, after the first category of control components is turned off, the test results still show a first-category preset fault, the source of the fault is directly determined to be a second-category control component; if the test results return to normal, the fault is clearly attributed to a first-category control component.

[0073] Step S2013: Based on the second category of control component failure or the first category of control component failure, troubleshoot the faulty component.

[0074] In one possible implementation, troubleshooting faulty components based on a first category of control component faults includes: activating each first category of control components in a preset order; for each activated first category of control component, obtaining the power of that first category of control component and detecting whether a first category of preset fault exists; and identifying the faulty component based on the first category of control components activated when the power is greater than a preset power value and a first category of preset fault is detected.

[0075] In this embodiment, receiving a start command does not equate to actually entering a working state. This asynchrony between command reception and working state can easily lead to missed fault detection. Therefore, this application employs a dual-dimensional collaborative judgment scheme combining power detection and fault presence detection: when the controller's power is greater than a preset power value, it indicates that the controller is working (e.g., power value > 0 indicates the controller is in a working state, power = 0 indicates the controller is not working). If this is accompanied by a first type of preset fault, it is determined to be a faulty component. This scheme effectively avoids the problem of missed fault detection and ensures the accuracy of faulty component location.

[0076] Furthermore, based on the first category of control components activated when the power exceeds a preset power value and a first type of preset fault is detected, a faulty component is identified. This includes: for a first category of control component activated when the power exceeds a preset power value and a first type of preset fault is detected, controlling the control component to shut down after the activation time reaches a preset activation duration; if the first type of preset fault disappears after the control component is shut down, then the control component is identified as a faulty component. In this embodiment, potential faulty components are initially screened based on power compliance and fault presence, and then a secondary verification is performed based on the disappearance of the fault after shutdown, further avoiding misjudgment caused by a single determination and ensuring accurate faulty component location.

[0077] In one possible implementation, troubleshooting the faulty component based on the second category of control component faults includes: obtaining the troubleshooting strategy corresponding to each second category of control component; troubleshooting the second category of control components based on the troubleshooting strategy; and determining the faulty component based on the troubleshooting results.

[0078] For the second category of control components, such as batteries, motors, DC-DC converters, and on-board chargers, these are key components of the vehicle's core power and operating system and cannot be shut down arbitrarily. Faults cannot be diagnosed simply by observing whether the fault disappears after shutting down the component. Therefore, troubleshooting for these control components requires a specially customized troubleshooting strategy. This strategy should be tailored to the component's characteristics, operating principles, and potential fault modes to conduct targeted troubleshooting, ensuring a safe, controllable, accurate, and efficient process.

[0079] For example, for DC-DC converters, measuring the battery voltage should show a normal reading of 12.3-12.7V before startup. If the voltage remains below 13V after startup, the DC-DC converter is likely faulty. For on-board chargers, monitor the input voltage / current and output high voltage during charging; if no data is available, the on-board charger is not activated. Some Category II control components may require manual assistance for troubleshooting.

[0080] This application addresses the definitive attribution of control component faults in either the second or first category by initiating targeted faulty component investigations for the corresponding category, avoiding redundant operations from indiscriminate, comprehensive investigations. Based on the test results, fault attribution is directly determined, and the corresponding category of control component investigation process is initiated, significantly shortening fault location time and reducing the time spent on vehicle operation during the investigation process.

[0081] Figure 4 This is a schematic diagram illustrating the implementation flow of a fault handling method provided in another embodiment of this application. This embodiment describes the overall flow of the method.

[0082] See Figure 4 As shown, the fault handling methods include: In step S401, the VCU acquires data from various sensors and analyzes the data to discover that the vehicle has encountered a first-type preset fault.

[0083] The vehicle's high-voltage system utilizes core hardware such as voltage sensors, current sensors, and insulation monitoring sensors to construct a real-time monitoring network covering the entire circuit. Voltage sensors accurately capture voltage changes at both ends of the line, current sensors continuously track the stability of the loop current, and insulation monitoring sensors monitor the insulation resistance between the circuit and the vehicle body in real time. These three sensors work together to collect key circuit parameters such as line voltage, operating current, and insulation resistance values, ensuring comprehensive detection of abnormal signals.

[0084] When a first-class preset fault occurs in the negative circuit of a control component, such as poor contact or minor damage, it will directly cause characteristic anomalies in the corresponding circuit parameters. For example, poor contact in the negative circuit will cause a sudden drop in local voltage or fluctuations exceeding the preset range; minor damage to the circuit may cause unexpected micro-current leakage; and aging of the insulation layer will cause the insulation resistance value to fall below the safety threshold. These abnormal data will be captured by the sensor in real time and transmitted to the VCU at millisecond speeds.

[0085] After receiving abnormal data, the VCU will immediately compare it with the pre-stored first-type preset fault feature library (including parameter abnormal thresholds and signal change patterns of various minor circuit faults). If the abnormality is confirmed to meet the judgment criteria of the first-type preset fault, the first-type preset fault will be quickly determined to have occurred.

[0086] Simultaneously, the VCU can activate a multi-channel alarm mechanism: a clear fault prompt pop-up window appears on the instrument panel (such as "XX control component circuit abnormal, please pay attention to subsequent troubleshooting"), the dedicated yellow fault indicator light is illuminated, and the central control screen simultaneously displays the location of the fault and the preliminary risk level, allowing the driver to intuitively understand the fault situation; some models will also trigger voice broadcast from the central control speaker, using a combination of beeping prompts and voice reminders to enhance the alarm effect and prevent the driver from ignoring it; in addition, the VCU will automatically record data such as the fault occurrence time, abnormal parameter peaks, and fault-related components, providing accurate basis for subsequent targeted troubleshooting.

[0087] Step S402: Determine the vehicle status based on vehicle parameters; if the vehicle is in driving mode, issue a parking check prompt; if the vehicle is parked in parking mode, determine whether the vehicle is in high-voltage mode; if the vehicle is in high-voltage mode, control the vehicle to depressurize.

[0088] In this embodiment, the vehicle first determines its current state through vehicle parameters, such as vehicle speed sensor data, parking brake signal, gear position signal, and vehicle posture sensor data, to confirm whether the vehicle is in a driving state (vehicle speed > 0, gear is driving, parking brake not activated) or a parking state (vehicle speed = 0, gear is P / N, parking brake is activated).

[0089] If the vehicle is determined to be in a driving state, the VCU will immediately issue a clear stop and troubleshooting prompt through a pop-up window on the instrument panel, a voice broadcast on the central control (such as "A potential fault has been detected. You need to stop and troubleshoot. Please park safely as soon as possible"), and a flashing fault indicator light, to avoid interfering with driving safety during troubleshooting operations. Once the vehicle has safely stopped and is in a stable parking state, the VCU will further determine whether the vehicle is in a high-voltage operating state (i.e., the high-voltage circuit is closed and the bus voltage has reached the preset high-voltage threshold) by using status signals from the high-voltage system controller and data detected by the bus voltage sensor. If the detection confirms that the vehicle is in a high-voltage state, the VCU will issue a high-voltage command according to a preset safety procedure: first, disconnect the high-voltage contactor to break the main circuit; then, shut down the high-voltage system auxiliary power supply; and finally, confirm that the low-voltage battery (12V) is supplying power normally, ensuring that the vehicle is completely switched to a low-voltage safe state, eliminating the risks of high-voltage electric shock and short circuits during fault troubleshooting. This facilitates the execution of subsequent fault troubleshooting steps and ensures vehicle safety.

[0090] High-voltage status represents the energy-ready state for vehicle power output, but in a fault scenario, it equates to a state of safety hazard. Reducing high voltage involves a controlled and orderly process to switch the vehicle from a high-risk, energy-ready state to a low-risk, safe state. Firstly, the safe voltage limit for the human body is 36V (DC), while the voltage of a vehicle's high-voltage system (200V-800V) far exceeds this threshold. If maintenance personnel touch exposed parts of the high-voltage circuit, it could result in electric shock. Secondly, maintaining high voltage during troubleshooting could accidentally trigger high-voltage components (such as accidentally touching a contactor causing a sudden high-voltage connection), escalating the potential fault into a hardware failure. Therefore, reducing high voltage is not only a necessary step before troubleshooting but also a core safety measure to ensure personnel safety and prevent the fault from escalating.

[0091] Step S403: Check for faulty parts.

[0092] (1) Decouple the first category of control components and start fault detection. Definition: Category I control components specifically refer to fault-related components that can be actively shut down under high-voltage conditions on a vehicle. They are non-mode control components (such as air conditioning compressors, heating bridges, etc.), and their shutdown will not affect the core power and safety architecture of the entire vehicle.

[0093] Operating procedure: First, control the vehicle to reduce the high voltage, then shut down all Category 1 control components, then re-energize the high voltage and simultaneously start the Category 1 preset fault detection.

[0094] (2) Determine the category of fault control component based on the test results. Judgment logic: If the first type of preset fault is still detected after re-energizing the high voltage, it means that the fault is not related to the first type of control component and is directly judged as a second type of control component fault; if the fault disappears, it is determined that the fault belongs to the first type of control component.

[0095] Description of Category 2 Control Components: These components are key parts of the vehicle's core power and operating system and belong to mode control components, including but not limited to batteries, motors, DC-DC converters, on-board chargers, etc. Their characteristic is that they cannot be turned off at will (turning them off may cause system paralysis or driving safety risks).

[0096] (3) Conduct targeted investigations by category to accurately identify faulty parts. Scenario 1: Troubleshooting of Category I control components (shutdownable components) employs a closed-loop approach of sequential activation + dual-dimensional judgment + secondary verification to avoid missed or false diagnoses. Components are activated in an orderly manner: The first category of control components are activated one by one in a preset order (such as by component importance or working logic).

[0097] Dual-dimensional collaborative judgment: For each activated control component, two indicators are detected simultaneously: one is the component power (power > preset value indicates that it has actually entered the working state, power = 0 indicates that it is not working), and the other is whether there is a first type of preset fault; only when both indicators are met (power meets the standard + fault exists) is it listed as a potential fault component.

[0098] Secondary verification and confirmation: For potentially faulty components, control them to shut down after the on-time reaches a preset value; if the first type of preset fault disappears after shutting down, the component can be finally determined to be a faulty component.

[0099] Scenario 2: Troubleshooting for Category II Control Components (Core Non-Disableable Components) Each Category II control component has a pre-stored fault diagnosis strategy tailored to its characteristics, rather than a general procedure. Testing must be conducted in conjunction with the component's operating principles and potential fault modes. For deeper faults in some core components, manual testing tools (such as multimeters and diagnostic instruments) are required to assist in the diagnosis, ensuring no faults are overlooked.

[0100] Step S404: Determine the fault level based on the detection results, and when the detection results indicate that a faulty component is detected, determine the duration of the fault within the preset opening time.

[0101] For example, primary circuit faults are classified into five levels: intermittent faults are level 1, non-mode control unit faults are level 2, DC-DC converter and on-board charger faults in mode control units are level 3, external faults in the battery management system of mode control units are level 4, and internal faults in the battery management system of mode control units are level 5. The higher the level, the more severe the fault.

[0102] The longest detection time is set to T. After the faulty component is turned on, the duration of the primary circuit fault within time T can be recorded to obtain the fault duration corresponding to the faulty component.

[0103] Step S405: Determine the risk value of the first type of preset fault triggering the second type of preset fault based on the fault level and fault duration.

[0104] For example, a two-dimensional risk value table is shown in Table 1.

[0105] Table 1

[0106] In Table 1, the risk coefficient gradually increases from left to right as the fault duration increases, and from top to bottom as the fault level increases. If the duration of the detected primary circuit fault falls between two time points, the risk of secondary circuit fault occurrence can be determined using interpolation.

[0107] Step S406: Based on the risk value, determine the fault handling measures to carry out fault handling.

[0108] In this embodiment, based on the risk value, the maximum amount of electricity charged by the vehicle, the number of times it is driven, and at least one of the following can be limited: the maximum amount of electricity charged by the vehicle, the number of times it is driven, and the activation of the high-voltage system.

[0109] When the risk level is low (e.g., below the first threshold), the maximum charging capacity is limited first. By controlling the upper limit of battery energy, the probability of battery overload and short circuit in high-risk conditions (e.g., poor circuit insulation, component aging) is reduced, which is a form of energy source control.

[0110] As the risk level increases (e.g., between the first and second thresholds), limiting the number of times a vehicle can be considered. Reducing vehicle usage lowers the probability of escalation.

[0111] When the risk value is very high (e.g., greater than the second threshold), consider prohibiting the activation of high-voltage systems. Restricting the activation of high-voltage systems can fundamentally avoid fatal risks such as fire and power interruption, and is the highest level of safety barrier. The above measures can also be used in combination. For example: When the risk value is less than the first threshold, the maximum power consumption is limited to the first target value; When the risk value is between the first threshold and the second threshold, the maximum battery level is first limited to the second target value; after 10 driving cycles, the maximum battery level is adjusted to the third target value; after 20 driving cycles, the vehicle's high-voltage system is restricted from starting. When the risk value is between the second and third thresholds, the maximum battery charge is limited to the third target value; after 10 driving cycles, the vehicle's high-voltage system is restricted from starting. When the risk value exceeds the third threshold, the vehicle's high-voltage system is directly restricted from starting.

[0112] It should be understood that the sequence number of each step in the above embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.

[0113] Figure 5 This is a schematic diagram of the structure of a fault handling device provided in an embodiment of this application. Figure 5 As shown, the fault handling device 5 provided in this embodiment may include: Detection module 51 is used to detect whether there is a faulty component when the vehicle experiences a first-type preset fault; The determination module 52 is used to determine the fault level based on the detection result, and when the detection result indicates that a faulty component is detected, to determine the fault duration of the faulty component within a preset opening time. The evaluation module 53 is used to determine the risk value of the first type of preset fault causing the second type of preset fault based on the fault level and the fault duration; The processing module 54 is used to determine fault handling measures based on the risk value in order to carry out fault handling.

[0114] In one possible implementation, the detection module 51 is used for: After the vehicle is de-energized, the first type of control components in the vehicle are shut off and the high voltage is re-energized to check for the presence of the first type of preset fault. If the first type of preset fault is detected, the first type of preset fault is determined to be a second type of control component fault; otherwise, the first type of preset fault is determined to be a first type of control component fault. Troubleshoot the faulty component based on either the second category of control component failure or the first category of control component failure.

[0115] In one possible implementation, the detection module 51 is used for: Activate the control components of each first category in a preset order; For each control unit of the first category that is turned on, obtain the power of the control unit of the first category and detect whether there is a preset fault of the first category. The faulty component is determined based on the control component of the first category that is activated when the power is greater than the preset power value and the first type of preset fault is detected.

[0116] In one possible implementation, the detection module 51 is used for: For a first-category control unit that is activated when the power is greater than the preset power value and the first type of preset fault is detected, the control unit is controlled to be turned off after the activation time of the control unit reaches the preset activation duration; if the first type of preset fault disappears after the control unit is turned off, the control unit is determined to be a faulty unit.

[0117] In one possible implementation, the detection module 51 is used for: Obtain the troubleshooting strategies for each control component in the second category; Based on the aforementioned troubleshooting strategy, the control components of the second category are investigated; Based on the investigation results, the faulty component was identified.

[0118] In one possible implementation, the determining module 52 is used to: If the test result indicates that no faulty component is detected, then the fault level is determined to be the first preset fault level; If the detection result indicates the presence of a faulty component, then when the faulty component is a control component of the first category, the fault level is determined to be a second preset fault level; when the faulty component is a control component of the second category, the corresponding fault level is determined based on the faulty component.

[0119] In one possible implementation, the evaluation module 53 is used to: Obtain pre-stored risk assessment mapping relationships; Based on the fault level, the fault duration, and the risk assessment curve, determine the risk value of the first type of preset fault triggering the second type of preset fault; The risk assessment mapping relationship is a mapping of the risk values ​​of the second type of preset fault occurring under different fault levels and different fault durations when the first type of preset fault occurs.

[0120] In one possible implementation, the processing module 54 is used to: Based on the risk value, the maximum amount of electricity charged by the vehicle, the number of times it can be driven, and at least one of the following: opening the high-voltage system; The maximum power consumption is negatively correlated with the risk value; the number of driving attempts is negatively correlated with the risk value; and the high-voltage system is restricted from starting when the risk value exceeds a preset risk threshold or the number of driving attempts reaches a preset number threshold.

[0121] In one possible implementation, before detecting whether a faulty component is present, the detection module 51 is further configured to: The status of the vehicle is determined based on the vehicle parameters; If the vehicle is in motion, a parking check prompt will be issued; When the vehicle is parked, it is determined whether the vehicle is under high voltage. If the vehicle is under high voltage, the high voltage is reduced.

[0122] Based on the above technical solution, when a vehicle experiences a first-type preset fault (usually a less serious fault), this application first detects the presence of a faulty component and determines the fault level based on the detection results, thereby clarifying the severity of the fault. Furthermore, if a faulty component is detected, the duration of the fault within a preset activation time is simultaneously determined. Combining the fault level and duration, the risk value of the first-type preset fault triggering a second-type preset fault (a more serious fault) is accurately calculated. Finally, based on this risk value, targeted fault handling measures are formulated and implemented. This operation can replace a one-size-fits-all approach, avoiding both excessive intervention disrupting normal driving and insufficient handling leading to safety hazards, effectively achieving a dynamic balance between driving safety and driving efficiency.

[0123] It should be noted that the information interaction and execution process between the above-mentioned devices / units are based on the same concept as the method embodiments of this application. For details on their specific functions and technical effects, please refer to the method embodiments section, and they will not be repeated here.

[0124] Figure 6 This is a schematic diagram of the structure of a vehicle provided in one embodiment of this application. Figure 6 As shown, the vehicle 600 in this embodiment includes a processor 610 and a memory 620, wherein the memory 620 stores a computer program 621 that can run on the processor 610. When the processor 610 executes the computer program 621, it implements the steps in any of the above method embodiments, for example... Figure 2 The steps S201-S204 are shown. Alternatively, when the processor 610 executes the computer program 621, it implements the functions of each module in the above-described device embodiments, for example... Figure 5 The functions of modules 51-54 are shown.

[0125] For example, computer program 621 may be divided into one or more modules / units, one or more of which are stored in memory 620 and executed by processor 610 to complete this application. The one or more modules / units may be a series of computer program instruction segments capable of performing a specific function, which describe the execution process of computer program 621 in vehicle 600.

[0126] Those skilled in the art will understand that Figure 6 This is merely an example of a vehicle and does not constitute a limitation on the vehicle. It may include more or fewer components than shown, or combinations of certain components, or different components, such as input / output devices, network access devices, buses, etc.

[0127] The processor 610 can be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or any conventional processor.

[0128] The memory 620 can be an internal storage unit of the vehicle, such as a hard drive or memory, or an external storage device, such as a plug-in hard drive, smart media card (SMC), secure digital (SD) card, flash card, etc. The memory 620 can also include both internal and external storage devices. The memory 620 is used to store computer programs and other programs and data required by the vehicle. The memory 620 can also be used to temporarily store data that has been output or will be output.

[0129] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional units and modules is merely an example. In practical applications, the above functions can be assigned to different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiments can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit. Furthermore, the specific names of the functional units and modules are only for easy differentiation and are not intended to limit the scope of protection of this application. The specific working process of the units and modules in the above system can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.

[0130] An embodiment of this application also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the above-described fault handling method.

[0131] In the above embodiments, the descriptions of each embodiment have different focuses. For parts that are not described in detail or recorded in a certain embodiment, please refer to the relevant descriptions of other embodiments.

[0132] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0133] In the embodiments provided in this application, it should be understood that the disclosed devices / vehicles and methods can be implemented in other ways. For example, the device / vehicle embodiments described above are merely illustrative. For instance, the division of modules or units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the mutual coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between devices or units may be electrical, mechanical, or other forms.

[0134] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0135] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0136] If the integrated module / unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the methods of the above embodiments can also be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when executed by a processor, it can implement the steps of the various method embodiments described above. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or certain intermediate forms. The computer-readable medium can include: any entity or device capable of carrying the computer program code, a recording medium, a USB flash drive, a portable hard drive, a magnetic disk, an optical disk, a computer memory, a read-only memory (ROM), a random access memory (RAM), an electrical carrier signal, a telecommunication signal, and a software distribution medium, etc.

[0137] The above-described embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application, and should all be included within the protection scope of this application.

Claims

1. A fault handling method, characterized in that, include: When a vehicle experiences a first-class preset fault, check for faulty components. The fault level is determined based on the test results, and when the test results indicate that a faulty component is detected, the duration of the faulty component within a preset opening time is determined. Based on the fault level and the fault duration, determine the risk value of the first type of preset fault triggering the second type of preset fault; Based on the risk value, fault handling measures are determined for fault handling.

2. The fault handling method according to claim 1, characterized in that, The detection of whether there are faulty components includes: After the vehicle is de-energized, the first type of control components in the vehicle are shut off and the high voltage is re-energized to check for the presence of the first type of preset fault. If the first type of preset fault is detected, the first type of preset fault is determined to be a second type of control component fault; otherwise, the first type of preset fault is determined to be a first type of control component fault. Troubleshoot the faulty component based on either the second category of control component failure or the first category of control component failure.

3. The fault handling method according to claim 2, characterized in that, Based on the first category of control component failures, troubleshoot the faulty components, including: Activate the control components of each first category in a preset order; For each control unit of the first category that is turned on, obtain the power of the control unit of the first category and detect whether there is a preset fault of the first category. The faulty component is determined based on the control component of the first category that is activated when the power is greater than the preset power value and the first type of preset fault is detected.

4. The fault handling method according to claim 3, characterized in that, The step of determining the faulty component by activating a first-category control component when the power exceeds a preset power value and a first-category preset fault is detected includes: For a first-category control unit that is activated when the power is greater than the preset power value and the first type of preset fault is detected, the control unit is controlled to be turned off after the activation time of the control unit reaches the preset activation duration; if the first type of preset fault disappears after the control unit is turned off, the control unit is determined to be a faulty unit.

5. The fault handling method according to claim 2, characterized in that, Based on the second category of control component failures, troubleshoot the faulty components, including: Obtain the troubleshooting strategies for each control component in the second category; Based on the aforementioned troubleshooting strategy, the control components of the second category are investigated; Based on the investigation results, the faulty component was identified.

6. The fault handling method according to any one of claims 1 to 5, characterized in that, The process of determining the fault level based on the test results includes: If the test result indicates that no faulty component is detected, then the fault level is determined to be the first preset fault level; If the detection result indicates the presence of a faulty component, then when the faulty component is a control component of the first category, the fault level is determined to be a second preset fault level; when the faulty component is a control component of the second category, the corresponding fault level is determined based on the faulty component.

7. The fault handling method according to any one of claims 1 to 5, characterized in that, The step of determining the risk value of the first type of preset fault triggering the second type of preset fault based on the fault level and the fault duration includes: Obtain pre-stored risk assessment mapping relationships; Based on the fault level, the fault duration, and the risk assessment mapping relationship, determine the risk value of the first type of preset fault triggering the second type of preset fault; The risk assessment mapping relationship is a mapping of the risk values ​​of the second type of preset fault occurring under different fault levels and different fault durations when the first type of preset fault occurs.

8. The fault handling method according to any one of claims 1 to 5, characterized in that, The determination of fault handling measures based on the risk value includes: Based on the risk value, the maximum amount of electricity charged by the vehicle, the number of times it can be driven, and at least one of the following: opening the high-voltage system; The maximum power consumption is negatively correlated with the risk value; the number of driving attempts is negatively correlated with the risk value; and the high-voltage system is restricted from starting when the risk value exceeds a preset risk threshold or the number of driving attempts reaches a preset number threshold.

9. The fault handling method according to claim 2, characterized in that, Before detecting whether a faulty component is present, the method further includes: The status of the vehicle is determined based on the vehicle parameters; If the vehicle is in motion, a parking check prompt will be issued; When the vehicle is parked, it is determined whether the vehicle is under high voltage. If the vehicle is under high voltage, the high voltage is reduced.

10. A vehicle comprising a memory and a processor, the memory storing a computer program executable on the processor, characterized in that, When the processor executes the computer program, it implements the fault handling method as described in any one of claims 1 to 9.