Vehicle-mounted black box protection system, control method, storage medium and product

By using the sensor module and latch fuse mechanism of the vehicle-mounted black box protection system, the fuse register and memory are triggered when the casing is illegally opened. Combined with multi-layer potting protection, the problem of data tampering after the vehicle-mounted EDR equipment is disassembled is solved, ensuring the integrity and authenticity of the data.

CN121545244APending Publication Date: 2026-02-17CHONGQING JINKANG NEW ENERGY VEHICLE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511684594.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-17
Publication Date
2026-02-17

AI Technical Summary

Technical Problem

Once existing vehicle-mounted EDR devices are physically dismantled, attackers can use technical means to tamper with the stored data, causing the recorded data to lose its authenticity and reliability, thus affecting the accident investigation results.

Method used

Design an on-board black box protection system, including a housing assembly, a sensor module, a latch fuse mechanism, and a circuit board. The sensor module detects when the housing is illegally opened, triggering the latch fuse mechanism to energize, which then blows the register and memory. Combined with a multi-layer potting protection module, the system increases the difficulty of disassembly, ensuring the integrity and authenticity of the data.

Benefits of technology

Through an automatic fuse mechanism and a multi-layer potting structure, data tampering is prevented, ensuring the integrity and authenticity of the data recording system, increasing the disassembly cost and time cost for attackers, and complying with national standards.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121545244A_ABST
    Figure CN121545244A_ABST
Patent Text Reader

Abstract

The invention provides a vehicle-mounted black box protection system, a control method, a storage medium and a product. The vehicle-mounted black box protection system comprises a shell assembly, a sensor module, a lock catch fusing mechanism and a circuit board, the circuit board comprises a processor, a register, a memory and a power supply; the lock catch fusing mechanism is installed between the inner wall of the shell assembly and the circuit board, and the sensor module is arranged on the shell assembly; the lock catch fusing mechanism is connected with the register and the memory; when the sensor module detects that the shell is opened illegally, a sensing signal is triggered and sent to the processor, the processor controls the lock catch fusing mechanism to be powered on, and therefore the lock catch fusing mechanism works to fuse the register and the storage. Therefore, when the case is detected to be opened illegally, the automatic fusing mechanism of the internal circuit board can destroy the hardware environment for data storage in time, so that the data cannot be tampered, and the integrity and authenticity of the data recorded by the data recording system (EDR) are ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of vehicle black box protection technology, and more specifically, to a vehicle black box protection system, control method, storage medium, and product. Background Technology

[0002] As a critical safety data recording device for vehicles, the Electronic Data Recording (EDR) system plays a vital role in traffic accident analysis and liability determination. However, existing in-vehicle EDR devices suffer from a significant technical weakness: if the device is physically disassembled, attackers may use technical means to tamper with the stored data, causing the recorded data to lose its authenticity and reliability, thereby affecting the accident investigation results.

[0003] Application content The purpose of this application is to provide an in-vehicle black box protection system, control method, storage medium and product to solve the problem that after existing equipment is physically disassembled, attackers may tamper with the stored data through technical means, causing the recorded data to lose its authenticity and reliability.

[0004] In a first aspect, embodiments of this application provide a vehicle-mounted black box protection system, comprising: a housing assembly, a sensor module, a latching fuse mechanism, and a circuit board; the circuit board includes a processor, a register, a memory, and a power supply; the latching fuse mechanism is installed between the inner wall of the housing assembly and the circuit board, and the sensor module is disposed on the housing assembly; the power supply is connected to the processor, the register, and the memory, the processor is connected to the latching fuse mechanism, the register, and the memory, and the latching fuse mechanism is connected to the register and the memory; The processor receives the sensing signal from the sensor module and controls the latch fuse mechanism to be energized according to the signal, so as to control the latch fuse mechanism to melt the register and the memory.

[0005] In the above implementation process, when the sensor module detects that the casing has been illegally opened, it triggers a sensing signal and sends it to the processor. The processor controls the latch fuse mechanism to be energized, so that the latch fuse mechanism works to melt the registers and memory. Thus, when the casing is illegally opened, the mechanism of automatic melting of the internal circuit board can promptly destroy the hardware environment of data storage, so that the data cannot be tampered with, ensuring the integrity and authenticity of the data recorded by the data recording system (EDR).

[0006] Furthermore, it also includes a potting protection module, which is located inside the housing assembly and connected to the circuit board.

[0007] In the above implementation process, the potting protection module is set up, which makes it difficult for illegal disassembly and increases the disassembly cost and time cost for attackers.

[0008] Furthermore, the potting protection module includes a polyurethane elastomer layer, a flame-retardant epoxy resin layer, and a thermally conductive silicone layer arranged sequentially from the outside to the inside; the polyurethane elastomer layer is bonded to the outer shell assembly, and the thermally conductive silicone layer is bonded to the circuit board.

[0009] In the above implementation process, setting up a multi-layered potting structure makes illegal disassembly extremely difficult, increasing the disassembly cost and time cost for attackers.

[0010] Furthermore, the housing assembly includes a housing having a housing coating.

[0011] In the above implementation process, the outer shell is provided with an outer shell coating. When the outer shell coating is damaged, it indicates that the integrity of the equipment has been compromised.

[0012] Furthermore, the sensor module includes: a micro-switch array, a conductive coating monitoring circuit, and a photosensitive sensor; the micro-switch array is located at the seam of the housing and is used to detect the separation displacement of the housing; the conductive coating monitoring circuit is used to detect the resistance of the coating of the housing in real time; the photosensitive sensor is located at the potting protection module and is used to detect external light.

[0013] In the above implementation process, the outer shell is provided with an outer shell coating. When the outer shell coating is damaged, it indicates that the integrity of the device has been compromised, and a sensing signal is sent to the processor through the sensor module.

[0014] Secondly, embodiments of this application provide a vehicle-mounted black box protection control method, implemented based on the aforementioned vehicle-mounted black box protection system, the method specifically including: When the housing assembly is in a normal state, the sensor module outputs a low-level signal to the processor, so that the processor controls the latch fuse mechanism to cut off power. If the sensor module detects that the housing assembly is in an abnormal state, it outputs a high-level signal to the processor so that the processor controls the latch fuse mechanism to be energized; The memory and the register are melted by the locking fuse mechanism.

[0015] Furthermore, before outputting the high-level signal to the processor, the method further includes: If the sensor module detects that the housing assembly is in an abnormal state, it determines whether the vehicle is in an ignition state. If the vehicle is in the ignition state, the fuse blow command will be blocked; If the vehicle is not in the ignition state, a delayed verification signal is activated for a set time. When the delayed verification signal reaches the set time, the latch fuse mechanism is activated; If the delayed verification signal does not reach the set time and the delayed verification signal is detected to have terminated, the sensor module is reset.

[0016] Furthermore, the step of melting the memory and the register through the locking fuse mechanism includes: The write enable pin trace of the memory is cut off by the latching fuse mechanism; The dedicated power supply line for write access in the register is cut off by the latching fuse mechanism.

[0017] Furthermore, it also includes: The locking and fusion mechanism remains in a retracted state to form a permanent mechanical lock.

[0018] Furthermore, it also includes: The processor's clock signal is triggered, and data is written to a one-time programmable memory via the communication interface and data bus.

[0019] Thirdly, embodiments of this application provide a computer-readable storage medium storing a computer program that, when executed by a server, implements the method described above.

[0020] Fourthly, embodiments of this application provide a computer program product, the computer program product including instructions, which, when executed by a computer, cause the computer to perform the method described above. Attached Figure Description

[0021] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments of this application will be briefly introduced below. It should be understood that the following drawings only show some embodiments of this application and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.

[0022] Figure 1 This is a schematic diagram of the structure of a vehicle-mounted black box protection system provided in the first embodiment of this application; Figure 2 A schematic diagram of the housing assembly structure of a vehicle-mounted black box protection system provided in the first embodiment of this application; Figure 3 A schematic diagram of the potting protection module structure of a vehicle-mounted black box protection system provided in the first embodiment of this application; Figure 4 This is a flowchart illustrating a vehicle-mounted black box protection and control method provided in the second embodiment of this application. Detailed Implementation

[0023] The technical solutions in the embodiments of this application will now be described with reference to the accompanying drawings.

[0024] It should be noted that in the description of this application, the terms "first," "second," etc., are used only for distinguishing descriptions and should not be construed as indicating or implying relative importance. Furthermore, the step numbers in the text are only for the convenience of explaining the embodiments of this application and are not intended to limit the order in which the steps are performed. The methods provided in the embodiments of this application can be executed by relevant terminal devices, and the following description uses an in-vehicle black box protection system as the execution subject.

[0025] As a critical safety data recording device for vehicles, the data recorded by the Electronic Data Recording (EDR) system plays a vital role in traffic accident analysis and liability determination.

[0026] Unauthorized access to a vehicle's black box refers to the act of reading, altering, or destroying data stored in the vehicle's event data recording system through technical or physical means without legal authorization or in violation of legal procedures. The core of this act lies in its "illegality," meaning it violates legal provisions regarding EDR data protection, privacy guarantees, or accident investigation procedures.

[0027] Currently, event recorders rely on passive protection and cannot withstand malicious disassembly. When the casing is illegally opened, attackers can directly access the circuit board to tamper with or erase data. They lack an integrated active data destruction mechanism; data integrity depends solely on physical isolation, which does not meet the mandatory national standards for data tamper protection. Even if read-only memory is used to prevent data tampering, the exposed circuit board can still be physically accessed and the storage chip tampered with. The root cause of these problems is a lack of consideration for the integrity of data within EDR devices.

[0028] Based on this, embodiments of this application propose an on-board black box protection system, control method, storage medium, and product to solve the above-mentioned problems.

[0029] EDR (Event Data Recorder) is an electronic system installed in a car to record critical operational data of the vehicle before, during, and after a collision.

[0030] Please refer to Figure 1 , Figure 1This is a schematic diagram of a vehicle-mounted black box protection system according to the first embodiment of this application. The first embodiment of this application provides a vehicle-mounted black box protection system, including: a housing assembly, a sensor module, a latching fuse mechanism, and a circuit board; the circuit board includes a processor, a register, a memory, and a power supply; the latching fuse mechanism is installed between the inner wall of the housing assembly and the circuit board; the sensor module is disposed on the housing assembly; the power supply is connected to the processor, the register, and the memory; the processor is connected to the latching fuse mechanism, the register, and the memory; and the latching fuse mechanism is connected to the register and the memory.

[0031] The processor receives the sensing signal from the sensor module and controls the latching fuse mechanism to be energized according to the signal, so as to control the latching fuse mechanism to melt the register and the memory.

[0032] As described above, in this embodiment of the application, when the sensor module detects that the casing has been illegally opened, it triggers a sensing signal and sends it to the processor. The processor controls the latch fuse mechanism to be energized, thereby causing the latch fuse mechanism to work and melt the registers and memory. Thus, when the casing is detected to be illegally opened, the mechanism of automatic melting of the internal circuit board can promptly destroy the hardware environment for data storage, making the data tamper-proof and ensuring the integrity and authenticity of the data recorded by the data recording system (EDR).

[0033] Specifically, when the housing assembly is in a normal state, the sensor module outputs a low-level signal to the processor, causing the processor to control the latch fuse to cut off power; if the sensor module detects that the housing assembly is in an abnormal state, it outputs a high-level signal to the processor, causing the processor to control the latch fuse to be powered on; the latch fuse then melts the memory and the register.

[0034] The latching fuse mechanism melts the write enable pin of the memory, that is, the latching fuse mechanism cuts off the WE (write enable) pin trace of the memory, thereby physically prohibiting the write operation. Optionally, the memory is a Flash chip.

[0035] The latching fuse mechanism melts the control register circuit, that is, the latching fuse mechanism cuts off the dedicated power supply line of the write permission register circuit, thereby locking the write function of the register from the logical level.

[0036] More specifically, when the vehicle-mounted black box protection system is in normal condition, that is, when the outer casing is intact, the sensor module outputs a low level, and the locking fuse mechanism is de-energized. When the vehicle black box protection system is detected to have been illegally disassembled, if the disassembly tool causes the housing displacement to be greater than 0.3mm, the coating to break, or light to intrude, the sensor module outputs a high-level trigger signal; the vehicle black box protection system's fuse activation: the trigger signal conducts power from the circuit board to the latch fuse mechanism, and the latch fuse mechanism contracts and deforms within 150ms; the vehicle black box protection system's data write protection: the latch fuse mechanism physically destroys the fuse target; the vehicle black box protection system's status lock: after the fuse is blown, the latch fuse mechanism remains in the contracted state, forming a permanent mechanical lock.

[0037] Optionally, the latching fuse mechanism adopts an SMA latching fuse mechanism, utilizing the shape memory effect of SMA wires to achieve the connection and separation of the latch. In the vehicle black box protection system, SMA wires are used as driving elements. By heating the SMA latching fuse mechanism, the SMA wires undergo a phase change, thereby generating huge recovery stress. This recovery stress can overcome the constraint force in the latch, and fuse the registers and memory of the circuit board to separate them.

[0038] The SMA (Shape Memory Alloy) locking and fusion mechanism is an intelligent mechanical structure based on shape memory alloy (SMA) and is widely used in aerospace, satellite, robotics, and other fields. Its core principle is based on the phase transition that occurs when SMA material is heated by electricity, generating a restoring force to achieve locking or unlocking. This mechanism has advantages such as small size, light weight, reusability, low impact, and no pollution, making it of significant application value in space engineering.

[0039] For example, the wire diameter of the SMA latching fuse mechanism is 0.5~1.0mm, ensuring a contraction force of greater than or equal to 150N, which can break the copper trace; the fuse response time of the SMA latching fuse mechanism is less than or equal to 500ms, which is lower than the time required for manual disassembly in a single step; the temperature resistance of the potting layer of the SMA latching fuse mechanism is -40℃~150℃, meeting the automotive-grade temperature shock standard; the backup power maintenance time of the SMA latching fuse mechanism is greater than or equal to 500ms, covering the entire operation time of the SMA latching fuse mechanism; the power maintenance time is greater than or equal to 500ms, covering the entire operation time of the SMA; the height of the cavity reserved in the potting layer of the SMA latching fuse mechanism is 0.7mm, realizing low-temperature redundancy design: the cavity expands to 0.7mm at -40℃.

[0040] In some embodiments, a potting protection module is also included, which is disposed inside the housing assembly and connected to the circuit board.

[0041] Specifically, the potting and protective module is filled inside the housing assembly and wraps the circuit board; the SMA locking and fusion mechanism is installed between the inner wall of the housing assembly and the circuit board; and the sensor module is placed at the seam of the housing assembly.

[0042] Optional, please refer to Figure 2 The potting protection module includes a polyurethane elastomer layer, a flame-retardant epoxy resin layer, and a thermally conductive silicone layer arranged sequentially from the outside to the inside; the polyurethane elastomer layer is bonded to the outer shell assembly, and the thermally conductive silicone layer is bonded to the circuit board; thus, the multi-layer potting structure makes illegal disassembly extremely difficult, increasing the disassembly cost and time cost for attackers.

[0043] For example, the three-layer potting structure includes an inner layer (thermal conductive silicone layer), a middle layer (flammable epoxy resin layer), and an outer layer (polyurethane elastomer layer). The thermal conductive silicone layer uses thermally conductive silicone with a thermal conductivity greater than or equal to 3 W / mK to achieve shock absorption and uniform heat dissipation; the thickness of the thermal conductive silicone layer is 2 mm. The flame-retardant epoxy resin layer uses UL94 V-0 flame-retardant epoxy resin to achieve oxygen isolation, fireproofing, and moisture resistance; the thickness of the flame-retardant epoxy resin layer is 5 mm. The polyurethane elastomer layer uses polyurethane elastomer with a Shore hardness of 85A to achieve impact resistance and adaptability to temperature deformation (-40℃~125℃); the thickness of the polyurethane elastomer layer is 3 mm.

[0044] It should be noted that during the potting process of the protective module, a deformation cavity (cavity height 0.5mm) is reserved around the circuit board and the SMA locking fuse mechanism to ensure that the fuse action is not obstructed.

[0045] In some embodiments, the housing assembly includes a housing having a housing coating; the housing having a housing coating indicates that damage to the integrity of the device is caused by the damage to the housing coating.

[0046] For example, please refer to Figure 3 The outer shell is designed in layers. The outer layer is a 1.5mm thick 304 stainless steel stamped shell with a laser-etched conductive coating (coating resistance ≤5Ω) for integrity testing. The inner layer is a glass fiber reinforced nylon frame with pre-embedded SMA latch mounting grooves and fusion mechanism guide rails at the four corners. The connection method is that the shell is fastened with hexagonal anti-tamper screws, and thermosetting epoxy glue is injected into the screw holes to form a double locking of physical and chemical properties.

[0047] In some embodiments, the sensor module includes: a micro-switch array, a conductive coating monitoring circuit, and a photosensitive sensor; the micro-switch array is disposed at the seam of the housing and is used to detect the separation displacement of the housing; the conductive coating monitoring circuit is used to detect the resistance of the housing coating in real time; the photosensitive sensor is disposed at the potting protection module and is used to detect external light; thus, the housing is provided with a housing coating, and when the housing coating is damaged, it indicates that the integrity of the device has been compromised, and a sensing signal is sent to the processor through the sensor module.

[0048] Specifically, a triple sensor linkage is used: a micro-switch array deployed at the seams of the outer casing (spacing ≤ 10mm) to detect casing separation displacement (trigger threshold ≥ 0.3mm); a conductive coating monitoring circuit that detects the resistance of the outer casing coating in real time, determining coating damage if the resistance change is > 10Ω; and a photosensitive sensor embedded in the potting layer to detect external light intrusion (illuminance threshold > 10 lux). Understandably, triggering any sensor sends an activation signal to the SMA locking fuse mechanism, i.e., sends a sensing signal to the processor, which then controls the on / off state of the SMA locking fuse mechanism to activate it.

[0049] In some embodiments, the system of this application is a dual-mode power supply, with the main power supply being the vehicle's 12V / 24V DC power; the backup power supply (power supply on the circuit board) is a supercapacitor module (capacity 5F, temperature resistance 125℃) or a thermal battery (lithium thionyl chloride, activation time <50ms). The backup power supply is independently connected to the SMA locking fuse mechanism, meaning that the fuse can still be triggered even when the vehicle is powered off.

[0050] The above-mentioned embodiments of this application provide the following destructive protection: multi-layer potting makes illegal disassembly extremely difficult, increasing the disassembly cost and time cost for attackers; data integrity guarantee: when the outer shell is detected to be illegally opened, the mechanism of automatic melting of the internal circuit board can promptly destroy the hardware environment for data storage, making the data tamper-proof and ensuring the integrity and authenticity of the data recorded by the data recording system (EDR), providing reliable data support for traffic accident analysis, etc.; compliance with standards: the design of this anti-disassembly vehicle black box structure complies with national standards and has high compliance and market application value.

[0051] Understandably, the methods of illegally opening the vehicle's black box casing include physical theft and tampering. For example, illegally dismantling the EDR device: criminals physically dismantle the vehicle's EDR device to directly read or tamper with the stored data.

[0052] Secondly, please refer to Figure 4 This application provides a vehicle-mounted black box protection control method, implemented based on the aforementioned vehicle-mounted black box protection system. The method specifically includes: 100. When the housing assembly is in normal condition, the sensor module outputs a low-level signal to the processor so that the processor controls the latch fuse mechanism to cut off power.

[0053] For example, sensor modules such as pressure sensors, displacement sensors, temperature sensors, and infrared sensors monitor the status of the housing assembly in real time, including its closure status, sealing performance, and temperature. When the housing assembly is in a normal state, the sensor module outputs a low-level signal, typically 0V or close to 0V; if an abnormality is detected, such as damage to the housing or excessively high temperature, it outputs a high-level signal, such as 3.3V or 5V.

[0054] Optionally, multiple sensors can be deployed on the housing assembly for redundant monitoring to avoid misjudgment caused by a single point of failure.

[0055] The processor receives the level signals from the sensor module via GPIO pins and continuously monitors the sensor signals. If a low level is detected (normal state), a preset instruction is executed; if a high level is detected (abnormal state), a safety response is triggered. Specifically, the processor outputs control signals (such as PWM or digital signals) to the drive circuit of the latching fuse mechanism to achieve power-off or power-on operations.

[0056] When the processor receives a low-level signal, it outputs a power-off command to the drive circuit (such as a relay or MOSFET switch) of the latch fuse mechanism. The drive circuit cuts off the power to the latch fuse mechanism, making it unable to operate (such as keeping the latch closed to prevent accidental melting). After the power is off, the latch fuse mechanism is in a safe locked state to avoid damage to the equipment due to misoperation or external interference.

[0057] 200. If the sensor module detects that the housing assembly is in an abnormal state, it outputs a high-level signal to the processor so that the processor controls the latch fuse mechanism to be energized.

[0058] The sensor module detects that the housing component is in an abnormal state, that is, it detects that the housing has been illegally opened. For example, when the vehicle's EDR equipment is disassembled by physical means, such as illegal opening or violent damage, the sensor module detects the touch-sensitive physical quantity of the housing component.

[0059] Specifically, the sensor converts physical quantities into high / low level signals. A high level corresponds to an abnormal state, and the sensor output level must be compatible with the processor input pins.

[0060] The processor outputs control signals to the drive circuit (such as relays or MOSFET switches) through GPIO pins. When the processor outputs a high level, the latching fuse mechanism is energized, and the latching fuse mechanism performs a preset fuse-breaking action after being energized.

[0061] For example, the pressure sensor monitors the sealing pressure of the housing. When the pressure is lower than the threshold, a high level is triggered. The processor outputs a control signal to the relay through the GPIO pin. When the processor outputs a high level, the relay coil is energized, the contacts close, the latch fuse mechanism is energized, and the latch fuse mechanism performs a preset fuse action after being energized.

[0062] 300. The memory and the register are melted by the locking fuse mechanism.

[0063] Specifically, when the sensor detects an abnormality in the housing components (such as unauthorized opening or violent damage) or the system triggers a self-destruct command, the latch fuse mechanism is energized to release mechanical energy and melt the registers and memory.

[0064] Understandably, by blowing the fuse register and critical circuits of the memory (such as the data bus, address bus, and control lines), the data is permanently disabled to prevent it from being read or modified. Once the fuse is blown, it cannot be recovered, ensuring that the core data or functions of the device are completely destroyed in abnormal conditions.

[0065] In some embodiments, before outputting the high-level signal to the processor, the method further includes: If the sensor module detects that the housing assembly is in an abnormal state, it determines whether the vehicle is in an ignition state. If the vehicle is in the ignition state, the fuse blow command will be blocked; If the vehicle is not in the ignition state, a delayed verification signal is activated for a set time. When the delayed verification signal reaches the set time, the latch fuse mechanism is activated; If the delayed verification signal does not reach the set time and the delayed verification signal is detected to have terminated, the sensor module is reset.

[0066] Specifically, when the sensor module detects that the housing assembly is in an abnormal state, it determines whether the vehicle is in ignition mode. This avoids misjudgments caused by accidental triggering of the sensor module by vibration or other reasons. If the vehicle is in ignition mode, it indicates that there is indeed an accidental triggering. The processor's sensor signal is a normal write signal, so the fuse instruction is blocked. That is, the processor does not control the power supply of the latch fuse mechanism, and the latch fuse mechanism does not need to fuse the registers and memory of the circuit board.

[0067] If the vehicle is not in ignition mode, a delayed verification signal is activated for a set time. This delayed verification signal is a safety control signal that, after a specific operation is triggered, does not immediately execute the operation but instead confirms its legitimacy through a set time delay combined with a verification mechanism. When the vehicle is not in ignition mode, a verification signal for a set time is set to ensure that the vehicle is indeed not in ignition mode, avoiding misjudgments of ignition status. If the delayed verification signal lasts for the set time, it indicates no accidental touch, and the processor energizes the latch-on fuse mechanism based on the sensor signal to melt the registers and memory of the circuit board. If the delayed verification signal terminates before the set time, it indicates an accidental touch, the vehicle is indeed in ignition mode, and the processor's sensor signal is a normal write signal; in this case, the fuse-breaking command is blocked, meaning the processor does not control the energization of the latch-on fuse mechanism, and the latch-on fuse mechanism does not need to melt the registers and memory of the circuit board. For example, the set time for the delayed verification signal can be 30 seconds or 1 minute, meaning the latch-on fuse mechanism is activated after a 30-second or 1-minute delay to avoid misjudgments.

[0068] In some embodiments, the step of melting the memory and the register through the latching fuse mechanism includes: The write enable pin trace of the memory is cut off by the latching fuse mechanism; the dedicated power supply line for write permission in the register is also cut off by the latching fuse mechanism.

[0069] For example, the latching fuse mechanism may include an SMA drive unit, a fuse actuator, and a self-locking structure. The SMA drive unit triggers contraction by heating with an electric current.

[0070] The fuse actuator can be a pin cutter or a power supply cutter; the pin cutter has a miniature scissor structure, and when the SMA retracts, the driving blade cuts the register write enable pin; the power supply cutter adopts a wedge block design, and when the SMA retracts, the wedge block is pushed into the gap of the power supply line to physically separate the copper foil trace.

[0071] The self-locking structure is used to lock the actuator position via a ratchet or snap-lock mechanism after the fuse is broken, preventing reset.

[0072] Understandably, after the write enable WE pin trace is cut off, the memory cannot receive a valid write signal. Even if the correct data is transmitted through the data pin, the memory will not perform a write operation due to the missing WE signal, resulting in the data not being stored and preventing the data in the registers in the black box from being modified.

[0073] Understandably, write permission registers typically receive control signals via a dedicated power supply line to determine whether data writing to memory is permitted. If the power supply line is cut off, the register will not receive a valid write permission signal, causing data write operations to be prohibited or unable to execute correctly. In scenarios requiring dynamic updates to register contents (such as caches, register files, etc.), cutting off the power supply line prevents data from being written in a timely manner, potentially leading to data loss or corruption, thus hindering the reading of data from registers within the black box.

[0074] In some embodiments, it also includes: The locking and fusion mechanism remains in a retracted state to form a permanent mechanical lock.

[0075] For example, the latch is typically made of a low-melting-point alloy or a shape memory alloy. When a specific temperature is reached (such as heat generated by overcurrent / overvoltage) or when triggered by an external signal, the material melts or undergoes irreversible deformation, causing the latch to shrink. The shrunken latch then engages in a pre-set groove or blocking structure, creating mechanical interference that prevents the mechanism from resetting or unlocking. For instance, in a circuit protector, a melted latch may jam the contact separation mechanism, preventing it from re-closing.

[0076] It is understandable that the melting or deformation process is irreversible. Even if external conditions are restored (such as a decrease in temperature), the latch cannot return to its original state, ensuring that the locked state is permanently effective.

[0077] Optionally, the latch-off mechanism can be further reinforced with a destructive structure (such as a plastic latch that breaks after melting) to ensure permanence and prevent forced reset.

[0078] In some embodiments, it also includes: The processor's clock signal is triggered, and data is written into a one-time programmable memory through the communication interface and data bus.

[0079] Optionally, when the processor receives a sensor signal, it triggers an internal clock signal and writes data into a one-time programmable memory (OTP ROM) via a communication interface and data bus to ensure compliant data reading after the fuse is tripped.

[0080] OTP ROM (One-Time Programmable Read-Only Memory) is a type of read-only memory that can only be programmed once. Specific storage cells are reserved during manufacturing, allowing users to program it once using specialized equipment before the product leaves the factory. Once data is written to the OTP ROM, it is permanently stored and cannot be altered, making it extremely useful in applications requiring high reliability and stability.

[0081] Thirdly, embodiments of this application also provide a computer-readable storage medium, which includes a stored computer program; wherein, when the computer program is running, it controls the device where the computer-readable storage medium is located to execute the vehicle exterior fire detection and early warning method as described above, and can achieve the same beneficial effects.

[0082] Of course, the computer-executable instructions provided in the embodiments of this application are not limited to the vehicle exterior fire detection and early warning method described above, but can also perform related operations in the vehicle exterior fire detection and early warning method provided in any embodiment of this application.

[0083] Fourthly, embodiments of this application also provide a computer program product. The methods described in the various embodiments of this application can be implemented entirely or partially through software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented entirely or partially in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed on a computer, the processes or functions described in the various embodiments of this application are executed entirely or partially. The computer can be a general-purpose computer, a special-purpose computer, a computer network, network equipment, user equipment, core network equipment, OAM (Open Application Model), or other programmable devices.

[0084] The computer program or instructions may be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another. For example, the computer program or instructions may be transferred from one website, computer, server, or data center to another website, computer, server, or data center via wired or wireless means. The computer-readable storage medium may be any available medium that a computer can access, or a data storage device such as a server or data center that integrates one or more available media. The available medium may be a magnetic medium, such as a floppy disk, hard disk, or magnetic tape; or an optical medium, such as a digital video optical disc; or a semiconductor medium, such as a solid-state drive. The computer-readable storage medium may be a volatile or non-volatile storage medium, or may include both volatile and non-volatile types of storage media.

[0085] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can also be implemented in other ways. The apparatus embodiments described above are merely illustrative; for example, the flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of apparatus, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than those marked in the drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram and / or flowchart, and combinations of blocks in block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or action, or using a combination of dedicated hardware and computer instructions.

[0086] In addition, the functional modules in the various embodiments of this application can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.

[0087] If the aforementioned functions are implemented as software functional modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0088] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A vehicle-mounted black box protection system, characterized in that, include: The system comprises a housing assembly, a sensor module, a latching fuse mechanism, and a circuit board; the circuit board includes a processor, a register, a memory, and a power supply; the latching fuse mechanism is installed between the inner wall of the housing assembly and the circuit board, and the sensor module is disposed on the housing assembly; the power supply is connected to the processor, the register, and the memory, the processor is connected to the latching fuse mechanism, the register, and the memory, and the latching fuse mechanism is connected to the register and the memory; The processor receives the sensing signal from the sensor module and controls the latch fuse mechanism to be energized according to the signal, so as to control the latch fuse mechanism to melt the register and the memory.

2. The vehicle-mounted black box protection system according to claim 1, characterized in that, It also includes a potting protection module, which is located inside the housing assembly and connected to the circuit board.

3. The vehicle-mounted black box protection system according to claim 2, characterized in that, The potting protection module includes a polyurethane elastomer layer, a flame-retardant epoxy resin layer, and a thermally conductive silicone layer arranged sequentially from the outside to the inside; the polyurethane elastomer layer is bonded to the outer shell assembly, and the thermally conductive silicone layer is bonded to the circuit board.

4. The vehicle-mounted black box protection system according to claim 1, characterized in that, The housing assembly includes a housing, on which a housing coating is provided.

5. The vehicle-mounted black box protection system according to claim 4, characterized in that, The sensor module includes: a micro-switch array, a conductive coating monitoring circuit, and a photosensitive sensor; the micro-switch array is located at the seam of the housing and is used to detect the separation displacement of the housing; the conductive coating monitoring circuit is used to detect the resistance of the coating of the housing in real time; the photosensitive sensor is located at the potting protection module and is used to detect external light.

6. A method for protecting and controlling a vehicle-mounted black box, characterized in that, Based on the vehicle-mounted black box protection system according to any one of claims 1 to 5, the method specifically includes: When the housing assembly is in a normal state, the sensor module outputs a low-level signal to the processor, so that the processor controls the latch fuse mechanism to cut off power. If the sensor module detects that the housing assembly is in an abnormal state, it outputs a high-level signal to the processor so that the processor controls the latch fuse mechanism to be energized; The memory and the register are melted by the locking fuse mechanism.

7. The vehicle-mounted black box protection and control method according to claim 6, characterized in that, Before the high-level signal is output to the processor, the method further includes: If the sensor module detects that the housing assembly is in an abnormal state, it determines whether the vehicle is in an ignition state. If the vehicle is in the ignition state, the fuse blow command will be blocked; If the vehicle is not in the ignition state, a delayed verification signal is activated for a set time. When the delayed verification signal reaches the set time, the latch fuse mechanism is activated; If the delayed verification signal does not reach the set time and the delayed verification signal is detected to have terminated, the sensor module is reset.

8. The vehicle-mounted black box protection and control method according to claim 6, characterized in that, The step of fusing the memory and the register through the locking fuse mechanism includes: The write enable pin trace of the memory is cut off by the latching fuse mechanism; The dedicated power supply line for write access in the register is cut off by the latching fuse mechanism.

9. The vehicle-mounted black box protection and control method according to claim 6, characterized in that, Also includes: The locking and fusion mechanism remains in a retracted state to form a permanent mechanical lock.

10. The vehicle-mounted black box protection and control method according to claim 6, characterized in that, Also includes: The processor's clock signal is triggered, and data is written to a one-time programmable memory via the communication interface and data bus.

11. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by the server, implements the method as described in any one of claims 6-10.

12. A computer program product, characterized in that, The computer program product includes instructions that, when executed by a computer, cause the computer to perform the method according to any one of claims 6-10.