Charging pile sudden stop reset control method and device, program product and storage medium
By detecting the operating parameters before and after an emergency stop signal in the charging pile, identifying the root cause of the fault and its risk level, generating a differentiated reset strategy and performing safety verification, the problem of low safety after an emergency stop of the charging pile is solved, and the safety of the reset process is improved.
Patent Information
- Application Number
- CN202511910552.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-17
- Publication Date
- 2026-03-06
AI Technical Summary
Using a standardized reset procedure after an emergency stop may not completely eliminate potential safety hazards, leading to repeated malfunctions or even more serious safety accidents.
By detecting the operating parameters within the time window before and after the emergency stop signal, the coupling correlation and abnormal parameter features are extracted to identify the root cause of the fault and its risk level, generate a differentiated charging reset strategy, and perform safety verification during the reset process.
It enables differentiated handling of different emergency stop situations, improves the safety of the charging pile reset process, and avoids the safety hazards caused by a uniform reset process.
Smart Images

Figure CN121608635A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of charging control technology, specifically to a charging pile emergency stop reset control method, device, program product, and storage medium. Background Technology
[0002] With the rapid development of the new energy vehicle industry, the safety and reliability of charging infrastructure have received increasing attention. As a key piece of equipment for charging new energy vehicles, the safety of charging piles directly relates to the safety of users' property and personal safety. Emergency stop is an important safety protection mechanism for charging piles, preventing accidents by stopping charging immediately upon detecting abnormal conditions.
[0003] Currently, charging stations typically employ a standardized reset procedure after an emergency stop. Specifically, upon receiving an emergency stop signal, the charging station control system immediately cuts off charging output and enters a protection state. Once operators confirm the fault has been resolved, a fixed reset procedure is executed manually or automatically to restore the charging station to normal operation. However, because charging station emergency stops can be caused by various factors, such as hardware failures, communication anomalies, or external interference, simply executing a standardized reset procedure may not completely eliminate potential safety hazards. Especially in complex fault scenarios, prematurely resuming charging without accurately identifying the cause of the fault may lead to recurring malfunctions or even more serious safety incidents, thus compromising the safety of the charging station reset process. Summary of the Invention
[0004] In view of this, this application provides a charging pile emergency stop reset control method, device, program product and storage medium.
[0005] Firstly, this application provides a charging pile emergency stop reset control method, the method comprising: Detect the emergency stop signal of the charging pile and obtain the operating parameters of the charging pile within a preset time window before and after the emergency stop signal; Extract the coupling correlation between the operating parameters and the abnormal parameter features, and determine the risk level and root cause of the emergency stop event based on the coupling correlation and the abnormal parameter features; A charging reset strategy is generated based on the risk level and the root cause of the fault, and the charging pile is controlled to execute the reset process according to the charging reset strategy. During the reset process, the reset response parameters of the charging pile are collected in real time, and the charging pile is verified for safety based on the type of the fault root cause and the reset response parameters. The charging recovery strategy for the charging pile is determined based on the safety verification results, and the charging pile is controlled to operate according to the charging recovery strategy.
[0006] By adopting the above technical solution, and by acquiring the operating parameters within the time window before and after the emergency stop signal, and extracting the coupling correlation and abnormal parameter characteristics between the operating parameters, the root cause of the emergency stop and its risk level can be accurately identified. Then, based on the identified risk level and root cause, a corresponding charging reset strategy is generated, avoiding potential safety hazards from using a uniform reset procedure. Simultaneously, during the reset process, the reliability of the reset process is ensured by real-time acquisition of reset response parameters and safety verification. Finally, based on the safety verification results, a corresponding charging recovery strategy is determined, achieving differentiated processing for different emergency stop situations and improving the safety of the charging pile reset process.
[0007] Optionally, extracting the coupling correlation between the working parameters and the abnormal parameter features includes: Identify the first parameter in the operating parameters that exceeds the normal range as the source parameter of the anomaly, and record the time when the anomaly of the source parameter is triggered. Track the response timing of each working parameter relative to the time of the abnormality triggering, and calculate the response delay duration and response amplitude of each working parameter; The temporal dependencies between the working parameters are constructed based on the response delay duration, and the coupling strength between the working parameters is determined based on the response amplitude. An anomaly propagation path is constructed based on the temporal dependency and the coupling strength, and the anomaly propagation path is used as the coupling association. Calculate the jump rate of the anomaly source parameter and the propagation speed of the anomaly propagation path, and use the jump rate and the propagation speed as features of the anomaly parameter.
[0008] Optionally, determining the risk level and root cause of the emergency stop event based on the coupling correlation and the abnormal parameter characteristics includes: Identify the key node parameters of the abnormal propagation path and calculate the propagation complexity index of the abnormal propagation path; The anomaly impact range coefficient is determined based on the propagation complexity index, which includes propagation depth and propagation breadth; The abnormal parameter features are compared with a preset feature risk threshold, and the abnormal evolution risk level is determined based on the comparison results. The comprehensive risk score of the emergency stop event is calculated by combining the abnormal impact range coefficient and the abnormal evolution risk level, and the risk level of the emergency stop event is determined based on the comprehensive risk score. The root cause of the failure is determined based on the correlation characteristics between the key node parameters and the anomaly source parameters.
[0009] Optionally, determining the root cause of the failure based on the correlation characteristics between the key node parameters and the anomaly source parameters includes: The causal correlation strength between the anomaly source parameters and the parameters of each key node is calculated, and the causal correlation strength is determined based on the response delay duration and coupling strength between the parameters. The key node parameters with the strongest causal correlation are identified as core parameters, and the parameter attribute combination patterns of the anomaly source parameters and the core parameters are analyzed. The parameter attribute combination pattern is matched with a preset fault feature library to obtain the fault type corresponding to the fault feature with the highest matching degree. The root cause of the fault is determined according to the fault type and the system module to which the abnormal source parameter belongs.
[0010] Optionally, generating a charging reset strategy based on the risk level and the root cause of the fault includes: The reset execution level is determined based on the risk level, and the reset execution level includes fast reset level, standard reset level, and deep reset level. Based on the root cause of the fault, the target module that needs to be reset is determined from the preset fault module mapping library, and the reset order is determined based on the dependencies between modules. When the reset execution level is fast reset level, a first reset strategy for soft reset of the target module is generated, and the execution time of the first reset strategy does not exceed a first preset time. When the reset execution level is the standard reset level, a second reset strategy is generated to reset the target module and its corresponding associated modules sequentially according to the reset order. The associated modules are determined based on the dependencies between the modules. When the reset execution level is deep reset level, a third reset strategy is generated to perform hardware reset of the entire charging pile system according to a preset safety reset sequence. The third reset strategy includes energy isolation. The corresponding reset strategy is selected as the charging reset strategy according to the reset execution level, and the key parameters and monitoring thresholds that need to be monitored during the reset process are determined according to the root cause of the fault.
[0011] Optionally, the step of performing safety verification on the charging pile based on the type of the fault root cause and the reset response parameters includes: Determine the safety verification items and the corresponding safety threshold ranges for each verification item based on the type of the root cause of the failure. The verification weight of each verification item is adjusted according to the historical recurrence frequency of the root cause of the failure. The higher the historical recurrence frequency of the root cause of the failure, the greater the weight of the verification item corresponding to it. The reset response parameters are compared with the corresponding safety threshold range to determine whether each verification item passes and the deviation of each verification item is recorded. For verified items that pass the verification, the corresponding module is marked as safe. For verified items that fail the verification, the risk contribution value is calculated based on the deviation, and the item with the largest risk contribution value is marked as a critical failure item. A weighted security score is calculated based on the verification weight and verification result of each verification item. When the weighted security score reaches a preset security threshold, the security verification result is determined to be a successful security verification. When the weighted security score is lower than the preset security threshold, the security verification result is determined to be a failed security verification, and a security verification failure prompt containing the key failure items and suggested re-examination strategies is generated.
[0012] Optionally, determining the charging recovery strategy for the charging pile based on the safety verification results includes: When the security verification result is that the security verification is passed, the recovery mode is determined according to the type of the root cause of the failure. The recovery mode includes direct recovery mode, progressive recovery mode and monitoring recovery mode. For the direct recovery mode, a first recovery strategy is generated to restore the charging power to the stable level before the emergency stop signal; For the gradual recovery mode, a second recovery strategy is generated to gradually increase the power from a preset initial power to the target charging power. The second recovery strategy includes multiple power increase stages and stability judgment conditions between each power increase stage. For the monitoring recovery mode, a third recovery strategy is generated that operates at reduced power and continuously monitors key parameters. The reduction ratio in the third recovery strategy is determined based on the risk level of the root cause of the failure. When the security verification result is that the security verification fails, a charging recovery prohibition policy is generated.
[0013] A second aspect of this application provides an electronic device for emergency stop and reset control of a charging pile, the electronic device comprising: one or more processors and a memory; the memory being coupled to the one or more processors, the memory being used to store computer program code including computer instructions, the one or more processors calling the computer instructions to cause the electronic device for emergency stop and reset control of the charging pile to perform the method described in the first aspect and any possible implementation thereof.
[0014] A third aspect of this application provides a computer program product containing instructions that, when run on an electronic device for emergency stop reset control of a charging pile, causes the electronic device to perform the method described in the first aspect and any possible implementation thereof.
[0015] A fourth aspect of this application provides a computer-readable storage medium including instructions that, when executed on an electronic device for emergency stop reset control of a charging station, cause the electronic device to perform the method described in the first aspect and any possible implementation thereof.
[0016] In summary, one or more technical solutions provided in the embodiments of this application have at least the following technical effects or advantages: This application acquires operating parameters within the time window before and after an emergency stop signal, and extracts the coupling correlation and abnormal parameter characteristics between these parameters. This allows for the accurate identification of the root cause of the emergency stop and its risk level. Based on the identified risk level and root cause, a corresponding charging reset strategy is generated, avoiding potential safety hazards from a uniform reset procedure. Furthermore, during the reset process, real-time acquisition and safety verification of reset response parameters ensure the reliability of the reset process. Finally, based on the safety verification results, a corresponding charging recovery strategy is determined, achieving differentiated handling for different emergency stop situations and improving the safety of the charging pile reset process. Attached Figure Description
[0017] Figure 1 This is a flowchart illustrating a charging pile emergency stop reset control method provided in an embodiment of this application; Figure 2 This is a timing diagram illustrating the changes in operating parameters before and after an emergency stop event, provided in an embodiment of this application. Figure 3 This is a logical diagram illustrating the generation of a differentiated reset and recovery strategy provided in an embodiment of this application; Figure 4 This is a schematic diagram of an exemplary hardware structure of an electronic device provided in an embodiment of this application. Detailed Implementation
[0018] To enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in the embodiments of this specification will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments.
[0019] In the description of the embodiments of this application, the words "for example" or "for instance" are used to indicate examples, illustrations, or explanations. Any embodiment or design that is described as "for example" or "for instance" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or design options. Rather, the use of the words "for example" or "for instance" is intended to present the relevant concepts in a specific manner.
[0020] In the description of the embodiments of this application, the term "multiple" means two or more. For example, multiple systems means two or more systems, and multiple screen terminals means two or more screen terminals. Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the indicated technical features. Thus, a feature defined with "first" or "second" may explicitly or implicitly include one or more of that feature. The terms "comprising," "including," "having," and variations thereof all mean "including but not limited to," unless otherwise specifically emphasized.
[0021] Please refer to Figure 1 A flowchart illustrating a charging pile emergency stop reset control method is presented. This method can be implemented using a computer program, a microcontroller, or run within a charging pile emergency stop reset control device. The computer program can be integrated into the computer device or run as a standalone utility application. Specifically, the method includes steps 10 to 50, as follows: Step 10: Detect the emergency stop signal of the charging pile and obtain the operating parameters of the charging pile within the preset time window before and after the emergency stop signal.
[0022] The emergency stop signal is an emergency stop signal triggered by the charging pile when it detects an abnormal situation. It is used to indicate that the charging pile needs to immediately interrupt the charging process and enter a protection state.
[0023] Operating parameters refer to various monitoring data that reflect the operating status of charging piles, including but not limited to parameters such as charging voltage, charging current, temperature, and communication status, which are used to analyze the operating status and fault conditions of charging piles.
[0024] Specifically, the charging pile control system continuously monitors the emergency stop signal status through emergency stop detection sensors deployed at key nodes. These sensors include physical emergency stop button sensors, software protection module status sensors, and communication anomaly detection sensors. When an emergency stop signal is detected to transition from a logic "0" state to a logic "1" state, the system immediately records the current time as the emergency stop signal trigger time T0 and sets preset time windows before and after it, for example, the first preset time window is set to 60 seconds before T0, and the second preset time window is set to 30 seconds after T0. Simultaneously with detecting the emergency stop signal, the system immediately initiates the operating parameter acquisition program, obtaining operating parameters from the charging pile's electrical system, thermal management system, communication system, and safety system through a distributed data acquisition module. These parameters include key parameters such as output voltage, output current, power module temperature, radiator temperature, communication handshake status, insulation resistance value, grounding resistance value, and ambient temperature and humidity.
[0025] Within a pre-set time window, the system retrieves historical operating parameter data from a local circular cache. This cache continuously stores all operating parameters from the most recent 120 seconds using a first-in, first-out (FIFO) principle, ensuring complete coverage of data requirements within any pre-set time window. Simultaneously, the system continues to collect operating parameters in real-time within the subsequent pre-set time window. The sampling frequency is differentiated based on parameter type: 100Hz for electrical parameters, 10Hz for temperature parameters, and 50Hz for communication parameters. To ensure data time synchronization, all collected operating parameters are marked with precise timestamps, achieving millisecond-level accuracy. The system uses a data integrity verification algorithm to assess the quality of the acquired operating parameters, calculating the data integrity rate for each parameter within the pre-set time window. When the integrity rate falls below 95%, a data compensation mechanism is automatically triggered, using interpolation algorithms to fill in missing data points.
[0026] The acquired operating parameters are structured and stored according to time series, forming a dataset containing the complete system state within a preset time window before and after the emergency stop signal. Through this time-window-based method of acquiring operating parameters, the system can comprehensively record the changes in operating parameters throughout the entire process from the appearance of fault symptoms, abnormal development, emergency stop triggering to system response. This provides a rich and accurate data foundation for subsequent extraction of coupling correlations and analysis of abnormal parameter features. Please see Figure 2 This is a timing diagram illustrating the changes in operating parameters before and after an emergency stop event, provided in an embodiment of this application. Figure 2 As shown, the horizontal axis represents time (t), and the vertical axis represents the values of various operating parameters of the charging pile. It includes the following key elements: Time markers: The diagram shows two key time points: the anomaly trigger moment T1 and the emergency stop signal T0. The anomaly trigger moment T1 is the instant when the first operating parameter (in this example, "power module temperature") deviates from its normal range, marking the initial nascent stage of a fault. The emergency stop signal T0 is the moment when the charging pile's protection mechanism is activated, formally executing an emergency stop.
[0027] Data Acquisition Window: The system defines a pre-set time window and a post-set time window around the emergency stop signal T0. By acquiring data within these two time windows, a complete data chain can be obtained from the appearance and development of fault symptoms to the triggering of emergency stop and subsequent response.
[0028] Parameter Variation Curves: The figure uses two curves as examples to illustrate the changes of two operating parameters, power module temperature and output current, over time. The power module temperature curve first exceeds the upper limit of the normal range (shown in green shading) at time T1, making it the anomaly source parameter for this event. Subsequently, the output current curve also changed significantly, but its change occurred later than T1, reflecting the response delay and coupling correlation between the parameters. This time-series data plot allows for a visual tracking of the origin and propagation process of the anomaly, providing a solid data foundation for accurately extracting coupling correlations, calculating anomaly parameter characteristics, and ultimately determining the root cause and risk level of the fault.
[0029] Step 20: Extract the coupling relationships between working parameters and abnormal parameter features, and determine the risk level and root cause of the emergency stop event based on the coupling relationships and abnormal parameter features.
[0030] The coupling correlation refers to the mutual influence and dependency between various operating parameters of the charging pile. Specifically, it manifests as the temporal dependency and influence strength relationship of other parameters responding when one parameter becomes abnormal. The coupling correlation is determined by analyzing the response delay duration and response amplitude of each operating parameter relative to the time of the abnormality trigger. The temporal dependency between operating parameters is constructed based on the response delay duration, and the coupling strength between operating parameters is determined based on the response amplitude. Finally, an abnormality propagation path is formed to describe the coupling correlation between parameters.
[0031] Anomaly parameter characteristics refer to the characteristic indicators used to describe and quantify the changing patterns of anomaly parameters. These mainly include the jump rate of the anomaly source parameter and the propagation speed of the anomaly propagation path. The jump rate reflects how quickly the anomaly source parameter deviates from its normal value, while the propagation speed reflects how quickly the anomaly's impact spreads among various operating parameters. These characteristics are used to assess the severity and scope of anomaly evolution and are important bases for determining the risk level of emergency shutdown events.
[0032] The root cause of a fault refers to the fundamental reason that leads to an emergency stop at a charging station. It is determined by analyzing the strength of the causal relationship between abnormal source parameters and key node parameters. Specifically, the key node parameters with the strongest causal relationship are identified as core parameters. The combination patterns of parameter attributes of the abnormal source parameters and core parameters are analyzed and matched with a pre-set fault feature library to obtain the fault type corresponding to the fault feature with the highest matching degree. Finally, the root cause of the fault is determined by combining the system module to which the abnormal source parameters belong, providing a basis for developing targeted reset strategies.
[0033] As an optional embodiment, the step of extracting the coupling correlation between working parameters and the characteristics of abnormal parameters may further include the following steps: Step 101: Identify the first parameter in the working parameters that exceeds the normal range as the source parameter of the anomaly, and record the time when the anomaly of the source parameter is triggered.
[0034] Specifically, the system first establishes a normal range threshold library for each operating parameter, including a normal output voltage range of 200V-240V, a normal output current range of 0A-63A, a normal power module temperature range of -10℃-70℃, a normal communication handshake status value of 1, and a normal insulation resistance range of 1MΩ or higher. The system uses a sliding window detection algorithm to scan all operating parameters one by one within a preset time window before and after the emergency stop signal. The scan proceeds backward from the emergency stop signal trigger time. When a parameter's value exceeds its corresponding normal range threshold for the first time, it is immediately marked as an abnormal source parameter, and the precise moment when the parameter exceeds the normal range is recorded as the abnormal trigger time. For example, in an emergency stop event, the system scan finds that the power module temperature rises from 69℃ to 71℃ 18 seconds before the emergency stop signal, exceeding the normal range upper limit of 70℃ for the first time. Therefore, the power module temperature is identified as an abnormal source parameter, and this moment is recorded as the abnormal trigger time T1. Through this method of identifying abnormal source parameters and recording abnormal trigger times, the system can accurately pinpoint the true origin of the fault.
[0035] Step 102: Track the response timing of each working parameter relative to the time of the abnormal trigger, and calculate the response delay duration and response amplitude of each working parameter.
[0036] Specifically, the system uses the anomaly trigger time T1 as the starting reference and performs time-series scanning analysis on all operating parameters except for the anomaly source parameter. For each operating parameter, the system uses a change point detection algorithm to identify the time point at which the parameter first undergoes a significant change after time T1, and calculates the time difference between this time point and the anomaly trigger time T1 as the response delay duration of the operating parameter. Simultaneously, the system calculates the magnitude of the change in the operating parameter from the normal state to the abnormal state as the response amplitude. The specific calculation formulas are: Response Delay Duration = Parameter Anomaly Time - Anomaly Trigger Time T1, Response Amplitude = |Parameter Anomaly Value - Parameter Normal Baseline Value| / Parameter Normal Baseline Value × 100%. For example, if the output current rises from 30A to 45A at T1+5 seconds, its response delay duration is 5 seconds, and its response amplitude is 50%; if the output voltage drops from 220V to 200V at T1+8 seconds, its response delay duration is 8 seconds, and its response amplitude is 9.1%.
[0037] Step 103: Construct the temporal dependency relationship between working parameters based on the response delay duration, and determine the coupling strength between working parameters based on the response amplitude.
[0038] Specifically, the system sorts the parameters according to their response delay duration. A shorter response delay indicates a stronger temporal dependency between the parameter and the anomaly source parameter. Using response delay duration as the weight, a directed temporal dependency graph is constructed using graph theory. Nodes in the graph represent working parameters, and directed edges represent temporal dependencies. The weight of each edge is the reciprocal of its response delay duration. Simultaneously, the system calculates the coupling strength between working parameters based on the response amplitude. The coupling strength is normalized and calculated using the formula: Coupling Strength = Response Amplitude / (1 + Response Delay Duration). This formula comprehensively considers both response amplitude and response speed. For example, the coupling strength between power module temperature and output current is 50% / (1 + 5 seconds) = 8.33%, and the coupling strength between power module temperature and output voltage is 9.1% / (1 + 8 seconds) = 1.01%.
[0039] Step 104: Construct anomaly propagation paths based on temporal dependencies and coupling strength, and treat the anomaly propagation paths as coupling relationships.
[0040] Specifically, the system employs a shortest path search algorithm, using the anomaly source parameter as the starting node and coupling strength as the edge weight, to search for the optimal propagation path from the anomaly source parameter to each target parameter. The algorithm prioritizes paths with high coupling strength and short response delays to construct an anomaly propagation path network. In cases with multiple propagation paths, the system retains all paths with coupling strength exceeding a preset threshold of 5% as valid anomaly propagation paths. For example, the constructed anomaly propagation path is: power module temperature (anomaly source) → output current (delay 5 seconds, coupling strength 8.33%) → output voltage (delay 8 seconds, coupling strength 1.01%) → communication handshake state (delay 12 seconds, coupling strength 0.5%). The system integrates these anomaly propagation paths and their corresponding temporal dependencies and coupling strength information to form a complete coupling relationship data structure.
[0041] Step 105: Calculate the jump rate of the anomaly source parameters and the propagation speed of the anomaly propagation path, and use the jump rate and propagation speed as anomaly parameter characteristics.
[0042] Specifically, the system calculates the jump rate by analyzing the numerical changes of the anomaly source parameters before and after the anomaly trigger moment. It uses a numerical differential algorithm to calculate the instantaneous rate of change of the anomaly source parameters: Jump Rate = |Anomalous Peak Value - Normal Baseline Value| / Anomaly Duration. For example, if the power module temperature jumps from 69℃ to 75℃ within 2 seconds, the jump rate = (75℃ - 69℃) / 2 seconds = 3℃ / second. Simultaneously, the system calculates the propagation speed of the anomaly propagation path: Propagation Speed = Propagation Path Length / Total Propagation Duration. The propagation path length is the number of parameter nodes in the path, and the total propagation duration is the total time span from the anomaly source parameter to the last response parameter. For example, if the anomaly propagation path contains 4 parameter nodes and the total propagation duration is 12 seconds, then the propagation speed = 4 nodes / 12 seconds = 0.33 nodes / second. The system stores the calculated jump rate and propagation speed as anomaly parameter features, providing quantitative characteristic indicators for subsequent risk level assessment and root cause analysis.
[0043] As an optional embodiment, the step of determining the risk level and root cause of an emergency stop event based on coupling correlation and abnormal parameter characteristics may further include the following steps: Step 201: Identify the key node parameters of the abnormal propagation path and calculate the propagation complexity index of the abnormal propagation path.
[0044] Specifically, the system employs graph theory analysis to perform structured analysis of anomaly propagation paths, treating each operating parameter as a node in the graph and coupling relationships as directed edges. The system traverses all nodes in the anomaly propagation path, calculating the in-degree and out-degree of each node. The in-degree indicates how many parameters affect that node, and the out-degree indicates how many other parameters that node affects. Simultaneously, the system analyzes the path traversal frequency of each node within the anomaly propagation path, i.e., how many propagation paths from the anomaly source parameter to other parameters pass through that node. The system identifies parameter nodes that simultaneously meet the following three conditions as critical node parameters: in-degree greater than or equal to 2, out-degree greater than or equal to 2, and path traversal frequency accounting for more than 50% of the total number of propagation paths. For example, in anomaly propagation paths including power module temperature, output current, output voltage, communication handshake status, and insulation resistance, the output current node has an in-degree of 2 (affected by power module temperature and insulation resistance), an out-degree of 3 (affecting output voltage, communication handshake status, and insulation resistance), and a path traversal frequency of 3 out of 4 paths, meeting the critical node condition and being identified as a critical node parameter.
[0045] The system then calculates the propagation complexity index of the anomaly propagation path, traversing the entire anomaly propagation path network using a depth-first search algorithm. The propagation depth is determined by performing a depth-first search starting from the anomaly source parameters, recording the maximum search depth reached during the search as the propagation depth, which reflects the number of propagation levels of the anomaly's impact. The propagation breadth is determined by counting the number of charging pile subsystem types involved in the anomaly propagation path. The system pre-establishes a mapping table between operating parameters and subsystems, including electrical subsystems mapping output voltage and output current, thermal management subsystems mapping power module temperature and radiator temperature, communication subsystems mapping communication handshake status and data transmission status, safety subsystems mapping insulation resistance and grounding resistance, and mechanical subsystems mapping charging gun status and door lock status. The system scans all parameter nodes in the anomaly propagation path, queries their corresponding subsystem types, and counts the number of different subsystem types involved as the propagation breadth. For example, an anomaly propagation path involving power module temperature (thermal management subsystem), output current (electrical subsystem), output voltage (electrical subsystem), and communication handshake status (communication subsystem) has a propagation depth of 4 layers and a propagation breadth of 3 subsystem types.
[0046] Step 202: Determine the anomaly impact range coefficient based on the propagation complexity index, which includes propagation depth and propagation breadth.
[0047] Specifically, the system uses an influence range matrix mapping method to determine the anomaly influence range coefficient. First, a two-dimensional mapping matrix of propagation depth and propagation breadth is established. This matrix divides propagation depth into four levels: layers 1-2 (shallow propagation), layers 3-4 (medium propagation), layers 5-6 (deep propagation), and layers 7 and above (extremely deep propagation). It also divides propagation breadth into four levels: involving one subsystem (local propagation), involving two subsystems (localized propagation), involving three-4 subsystems (wide-area propagation), and involving five subsystems (global propagation). The system pre-defines 16 combinations of propagation depth and propagation breadth in the matrix, each corresponding to a specific anomaly influence range coefficient value. For example, when the propagation depth is medium propagation and the propagation breadth is wide-area propagation, the corresponding anomaly influence range coefficient is 0.65; when the propagation depth is deep propagation and the propagation breadth is localized, the corresponding anomaly influence range coefficient is 0.55.
[0048] Based on the calculated propagation depth and breadth values, the system first determines the corresponding level interval in the mapping matrix, and then queries the anomaly impact range coefficient corresponding to that interval combination. For cases at level boundaries, the system uses interpolation methods for precise calculation. For example, if an anomaly event has a propagation depth of 4 layers, exactly at the upper boundary of the middle-level propagation, and a propagation breadth of 3 subsystems, belonging to the wide-area propagation range, the anomaly impact range coefficient is determined to be 0.65 by querying the mapping matrix. The system also establishes a verification mechanism for the anomaly impact range coefficient, automatically triggering a recalculation process when the calculation result exceeds a reasonable range, ensuring the accuracy and consistency of the results.
[0049] Step 203: Compare the abnormal parameter features with the preset feature risk threshold, and determine the abnormal evolution risk level based on the comparison results.
[0050] Specifically, the system establishes a hierarchical threshold determination mechanism to identify the risk level of abnormal evolution. First, it establishes differentiated jump rate threshold standards for different types of abnormal source parameters. For temperature parameters, the jump rate thresholds are set as follows: slow jump range 0-2℃ / second, medium jump range 2-5℃ / second, and rapid jump range above 5℃ / second; for voltage parameters, the jump rate thresholds are set as follows: slow jump range 0-20V / second, medium jump range 20-50V / second, and rapid jump range above 50V / second; for current parameters, the jump rate thresholds are set as follows: slow jump range 0-10A / second, medium jump range 10-25A / second, and rapid jump range above 25A / second. The system compares the actual jump rate of the abnormal source parameter with the threshold range of its corresponding parameter type to determine the jump rate risk classification.
[0051] Simultaneously, the system establishes a unified threshold judgment standard for the propagation speed of abnormal propagation paths. The propagation speed thresholds are set as follows: slow propagation range 0-0.3 nodes / second, medium propagation range 0.3-0.6 nodes / second, and fast propagation range above 0.6 nodes / second. The system compares the actual calculated propagation speed with the threshold ranges to determine the risk level of propagation speed. Then, a risk level decision tree method is used to determine the final abnormal evolution risk level. The decision rules are as follows: when both the jump rate and propagation speed are in the slow range, the abnormal evolution risk level is low risk; when the jump rate is medium and the propagation speed is slow, or the jump rate is slow and the propagation speed is medium, the abnormal evolution risk level is medium risk; when at least one of the jump rate and propagation speed is in the fast range, the abnormal evolution risk level is high risk. For example, the jump rate of the power module temperature is 3.5℃ / second, which belongs to the medium-speed jump range, and the propagation speed is 0.25 nodes / second, which belongs to the slow propagation range. According to the decision rules, the abnormal evolution risk level is determined to be medium risk.
[0052] Step 204: Calculate the comprehensive risk score of the emergency stop event by combining the comprehensive impact range coefficient and the risk level of the abnormal evolution, and determine the risk level of the emergency stop event based on the comprehensive risk score.
[0053] Specifically, the system employs a risk assessment matrix method to calculate a comprehensive risk score. First, a two-dimensional risk assessment matrix is established, consisting of an anomaly impact range coefficient and an anomaly evolution risk level. This matrix divides the anomaly impact range coefficient into three intervals: 0-0.4 for limited impact, 0.4-0.7 for moderate impact, and 0.7-1.0 for widespread impact. The anomaly evolution risk level remains at its original three levels: low, medium, and high. The matrix sets nine combinations of impact range and evolution risk, each directly corresponding to a comprehensive risk score and a corresponding emergency stop event risk level. For example, when the anomaly impact range coefficient is in the moderate impact interval and the anomaly evolution risk level is medium, the corresponding comprehensive risk score is 55 points, and the emergency stop event risk level is medium. When the anomaly impact range coefficient is in the widespread impact interval and the anomaly evolution risk level is high, the corresponding comprehensive risk score is 85 points, and the emergency stop event risk level is high.
[0054] Step 205: Determine the root cause of the failure based on the correlation characteristics between the key node parameters and the anomaly source parameters.
[0055] Specifically, the system uses pattern matching to determine the root cause of the fault. First, it extracts the correlation characteristics between the abnormal source parameters and the key node parameters, including parameter type, subsystem, anomaly direction, and anomaly magnitude. For example, the correlation characteristic between the abnormal source parameter (power module temperature) and the key node parameter (output current) is "moderate positive thermal management temperature → severe positive electrical current". The system establishes a fault feature library covering typical fault types such as power device overheating, heat dissipation system blockage, electrical insulation aging, and contactor adhesion. Each fault corresponds to a specific parameter correlation characteristic template. The template for a power device overheating fault is "moderate positive thermal management temperature → severe positive electrical current → moderate negative electrical voltage", and the template for a heat dissipation system blockage fault is "severe positive thermal management temperature → slight positive thermal management fan → moderate negative electrical power". The system calculates the matching degree between the actual correlation characteristics and the templates in the fault feature library, selecting the fault type corresponding to the template with the highest matching degree as the root cause.
[0056] As an optional embodiment, the step of determining the root cause of the failure based on the correlation characteristics between the critical node parameters and the anomaly source parameters may further include the following steps: Step 301: Calculate the causal correlation strength between the anomaly source parameters and the parameters of each key node. The causal correlation strength is determined based on the response delay time and coupling strength between the parameters.
[0057] Specifically, the system employs a two-factor analysis method, combining response delay duration and coupling strength, to calculate the strength of causal relationships. First, the system processes the timestamp sequence of parameters in the anomaly propagation path using a time-series analysis module, employing a sliding time window algorithm to scan the numerical change trajectories of the anomaly source parameters and parameters at each key node. The system identifies the starting point when the anomaly source parameters begin to deviate from the normal range as the anomaly occurrence baseline. Then, it detects the moment when each key node parameter begins to respond to the anomaly changes, calculating the response delay duration by measuring the time difference between these two moments. The system establishes a quantitative evaluation mechanism for response delay duration, converting the delay duration into a delay factor. The delay factor uses a negative exponential decay function; the shorter the delay duration, the larger the corresponding delay factor value, reflecting a stronger causal relationship.
[0058] Simultaneously, a coupling strength assessment system is established to determine the basic values of coupling strength by analyzing the physical coupling mechanisms and transmission paths between parameters. The system pre-constructs a parameter coupling relationship knowledge base based on the electrical schematic and thermodynamic model of the charging pile system, recording the coupling types and strength levels between different parameter pairs. Based on the coupling mechanisms between parameters, the system categorizes coupling relationships into four types: direct electrical coupling, thermal conduction coupling, control logic coupling, and indirect influence coupling. Each coupling type corresponds to a different range of basic coupling strength values. The system retrieves the basic coupling strength values between the anomaly source parameters and the parameters of each key node by querying the coupling relationship knowledge base. Then, it multiplies these basic coupling strength values by a delay factor to obtain the final causal correlation strength value. This two-factor calculation method considers both the degree of physical coupling between parameters and the timeliness of the response, accurately quantifying the comprehensive influence of the anomaly source parameters on the parameters of each key node.
[0059] Step 302: Identify the key node parameters with the strongest causal relationship as core parameters, and analyze the parameter attribute combination patterns of the anomaly source parameters and core parameters.
[0060] Specifically, the system employs a causal correlation strength ranking and filtering mechanism to identify core parameters. It ranks and compares the calculated causal correlation strength values of all key node parameters, identifying the key node parameter with the strongest causal correlation strength as the core parameter. When multiple parameters have the same maximum strength value, the system uses parameter type priority rules for filtering: electrical parameters have higher priority than thermal management parameters, and thermal management parameters have higher priority than communication parameters. Subsequently, a parameter attribute combination pattern analysis process is executed to obtain complete attribute information for both the anomaly source parameter and the core parameter. Basic attribute information of the parameters is read from the system's parameter configuration database, including static attributes such as parameter name, parameter type, subsystem, measurement unit, and normal operating range. The system also analyzes the dynamic behavior characteristics of the parameters in the current anomaly event, determining the direction of the anomaly through an anomaly detection algorithm—whether the parameter value deviates upwards or downwards from the normal range. The system calculates the parameter anomaly magnitude level, classifying it into three levels: minor, moderate, and severe anomalies, based on the degree of deviation from the normal range. The system also analyzes the parameter's response timing characteristics to determine whether the parameter is a dominant or reactive parameter during anomaly propagation. The system organizes all attribute information of the anomaly source parameters and core parameters in a structured manner according to a predefined combination pattern template, forming a standardized parameter attribute combination pattern description. This description uses a hierarchical structure to express the correlation and feature differences between the anomaly source parameters and core parameters.
[0061] Step 303: Perform pattern matching between the parameter attribute combination pattern and the preset fault feature library to obtain the fault type corresponding to the fault feature with the highest matching degree, and determine the root cause of the fault based on the fault type and the system module to which the abnormal source parameter belongs.
[0062] Specifically, the system establishes a multi-level fault feature matching architecture, first loading pre-set fault feature database data. The fault feature database adopts a hierarchical storage structure, categorized firstly by the system module where the fault occurs, including electrical system fault feature databases, thermal management system fault feature databases, communication system fault feature databases, etc. Each system-level feature database is further categorized secondly by fault type. Each fault type corresponds to one or more typical parameter attribute combination pattern templates, which record the typical performance characteristics of that fault type under different operating conditions. The system establishes a standardized description format for fault feature templates, ensuring that the template information and actual parameter attribute combination patterns correspond structurally, facilitating subsequent automated matching processing.
[0063] The system employs a multi-dimensional feature similarity calculation algorithm to implement the pattern matching process, comparing the obtained parameter attribute combination patterns with all templates in the fault feature database one by one. The similarity calculation algorithm uses a weighted scoring mechanism, calculating matching scores for five dimensions: parameter type matching degree, subsystem matching degree, anomaly direction matching degree, anomaly amplitude matching degree, and temporal relationship matching degree. The system assigns different weight coefficients to each matching dimension, with higher weights for parameter type and anomaly direction because these two features play a decisive role in fault identification, while the weight for anomaly amplitude is relatively low because the same fault may exhibit different amplitude characteristics at different severity levels. The system comprehensively calculates the matching scores of each dimension according to their weights to obtain the overall similarity value between each fault feature template and the actual combination pattern. The system selects the fault feature template with the highest similarity as the best matching result and extracts the corresponding fault type information. The system further combines the specific system module to which the anomaly source parameters belong to accurately locate the root cause of the fault. By querying the mapping relationship table between system modules and fault root causes, the abstract fault type is converted into a specific description of the fault root cause.
[0064] Step 30: Generate a charging reset strategy based on the risk level and root cause of the fault, and control the charging pile to execute the reset process according to the charging reset strategy.
[0065] Among them, the charging reset strategy refers to the system recovery plan customized according to the risk level and root cause of the emergency stop event. The strategy includes complete elements such as the specific steps of the reset operation, the execution sequence, safety measures, monitoring requirements and time control, which are used to guide the charging pile to safely and orderly restore from the emergency stop state to the normal charging state.
[0066] Specifically, the system generates a charging reset strategy using a two-factor decision matrix, determining the reset depth based on risk level and the reset range based on root cause of the fault. The system determines the reset intensity level based on risk level and identifies the specific module requiring reset using a fault module mapping table based on root cause of the fault. The system combines reset intensity and reset range to generate a specific operation sequence, employing a standardized description format including strategy identifier, operation steps, safety requirements, and monitoring parameters. The system converts the charging reset strategy into a sequence of control commands executable by the device through a reset execution controller, implementing the reset process using a phased execution control mechanism. The system first checks safety conditions; once met, it sends control commands sequentially according to the operation sequence, monitoring key parameter changes in real time. If parameters exceed safety limits, the system immediately pauses and activates protection measures. After reset, a self-test program verifies the reset effect; upon success, the device status is updated to normal operation and the emergency stop protection is deactivated.
[0067] As an optional embodiment, the step of generating a charging reset strategy based on the risk level and root cause of the fault may further include the following steps: Step 401: Determine the reset execution level based on the risk level. The reset execution levels include fast reset level, standard reset level, and deep reset level.
[0068] Specifically, the system establishes a mapping rule between risk levels and reset execution levels, mapping low-risk levels to the fast reset level, medium-risk levels to the standard reset level, and high-risk levels to the deep reset level. The system reads the risk level value determined in the preceding steps through a risk level determiner and directly determines the corresponding reset execution level according to the preset mapping rule. The fast reset level is suitable for emergency stop events caused by minor anomalies or transient interference; the standard reset level is suitable for situations where a specific module fails but the overall system remains stable; and the deep reset level is suitable for situations involving severe faults or multi-module cascading failures. Through this tiered reset mechanism, the system can optimize reset time and reset effectiveness while ensuring safety.
[0069] Step 402: Determine the target module that needs to be reset from the preset fault module mapping library according to the root cause of the fault, and determine the reset order based on the dependencies between modules.
[0070] Specifically, the system uses a fault module mapping library query mechanism to determine the target module. This library records the mapping relationship between various root causes of faults and their corresponding fault modules. Based on the root causes determined in previous steps, the system queries the mapping library for the corresponding target module identifier to obtain the specific module information that needs to be reset. The system then analyzes the dependency network between modules, loading the system module dependency graph through a dependency resolver. This graph describes the startup dependencies, communication dependencies, and functional dependencies between modules. The system uses a topology sorting algorithm to sort the modules involved in the reset, ensuring that dependent modules are reset before their dependent modules, avoiding communication anomalies or functional conflicts between modules during the reset process. Through this dependency-based reset sequence planning, the system can ensure the stability and reliability of the reset process.
[0071] Step 403: When the reset execution level is fast reset level, generate a first reset strategy to perform a soft reset on the target module. The execution time of the first reset strategy shall not exceed a first preset time.
[0072] Specifically, the system generates a first reset strategy for a soft reset of the target module. Soft reset resets the target module's operating state via software commands without cutting off hardware power. The system establishes a soft reset command library, containing the command format and execution parameters for each module. The system selects the appropriate soft reset command based on the target module type and sends the reset command to the target module via the internal communication bus. The system sets a first preset duration as the upper limit for fast reset, typically set to within 30 seconds, to ensure the fast reset strategy can be completed quickly. During the soft reset process, the system continuously monitors the target module's status feedback signals, and terminates the reset process after confirming that the module has successfully restarted and restored its normal operating parameters. Through this soft reset method, the system can restore charging functionality in the shortest possible time.
[0073] Step 404: When the reset execution level is the standard reset level, a second reset strategy is generated to reset the target module and its corresponding associated modules in the order of reset. The associated modules are determined based on the dependencies between modules.
[0074] Specifically, the system determines the scope of associated modules based on inter-module dependencies. It analyzes the upstream and downstream dependencies of the target module using an associated module identifier, identifying all modules with direct or indirect dependencies on the target module as associated modules. The system generates a second reset strategy that sequentially resets the target module and associated modules according to the reset order, using a combination of soft reset and module-level hard reset. The system first performs a reset operation on the module with the lowest dependency level, then resets dependent modules layer by layer upwards, ensuring that inter-module dependencies do not conflict during the reset process. The system sets independent timeout and status confirmation mechanisms for the reset operation of each module, ensuring that the reset process of the next module is initiated only after the previous module has been successfully reset. Through this hierarchical and orderly reset method, the system can thoroughly eliminate the impact of faults and restore the normal operation of related subsystems.
[0075] Step 405: When the reset execution level is deep reset level, a third reset strategy is generated to perform hardware reset of the entire charging pile system according to a preset safe reset sequence. The third reset strategy includes energy isolation.
[0076] Specifically, the system performs a hardware reset of the entire charging pile system according to a preset safety reset sequence, which follows the basic principle of power disconnection, reset, and then power restoration. The system first performs an energy isolation operation, disconnecting the electrical connection between the charging pile and the power grid via the main circuit breaker and various disconnect switches, while simultaneously disconnecting the charging connection between the charging pile and the electric vehicle, ensuring no dangerous voltage occurs during the reset process. After waiting for a preset discharge time to allow the internal capacitors to fully discharge, the system initiates the hardware reset sequence. Hardware reset is achieved by disconnecting and restoring the power supply to each module, with the system performing hardware resets sequentially in the order of power module, control module, communication module, and detection module. After each module is reset, the system executes a self-test program to confirm that the module's hardware and software are normal before proceeding to the next module. After completing the full system reset, the system reinitializes all modules according to the standard startup procedure and performs a system self-test. Through this deep reset method, the system can completely eliminate the impact of serious faults and restore the system to a safe and reliable operating state.
[0077] Step 406: Select the corresponding reset strategy as the charging reset strategy according to the reset execution level, and determine the key parameters and monitoring thresholds that need to be monitored during the reset process according to the root cause of the fault.
[0078] Specifically, the system uses a reset strategy selector to choose the appropriate strategy from the first, second, and third reset strategies as the final charging reset strategy based on the reset execution level. Simultaneously, the system determines the key parameters to be monitored during the reset process based on the root cause of the fault, and uses a fault root cause analyzer to identify system parameters directly related to the fault as key monitoring targets. The system establishes a monitoring threshold configuration mechanism, setting reasonable monitoring threshold ranges for each key parameter based on the characteristics of the fault root cause, including normal operation thresholds, warning thresholds, and abnormal thresholds. The setting of monitoring thresholds considers the characteristics of the fault type and the dynamic characteristics of the reset process, ensuring timely detection of abnormal situations during the reset process. The system integrates the determined reset strategy and monitoring parameter configuration information to form a complete charging reset strategy scheme, which includes complete information such as the reset operation sequence, execution parameters, monitoring requirements, and safety measures.
[0079] Step 40: During the reset process, the reset response parameters of the charging pile are collected in real time, and the charging pile is verified for safety based on the type of fault root cause and the reset response parameters.
[0080] Among them, the reset response parameters refer to the status feedback signals and operating characteristic data generated by each module and system during the reset operation of the charging pile, including real-time data that can reflect the reset effect and system health status, such as module start-up status, changes in electrical parameters, temperature response, communication handshake signals, and self-test results.
[0081] Specifically, the system establishes a real-time acquisition mechanism for reset response parameters, collecting these parameters from various sensors and monitoring points within the charging pile via a distributed data acquisition network. The system determines key acquisition points based on the target modules involved in the reset strategy, including the output voltage and current of the power module, the processor status of the control module, the handshake signal of the communication module, and the switching status of the protection module. The system employs high-frequency sampling to acquire reset response parameters, with the sampling frequency differentiated according to parameter type: electrical parameters are sampled at millisecond levels, temperature parameters at second levels, and status signals using event-triggered sampling. The system establishes a safety verification rule base based on fault root cause types, with different verification focuses and judgment criteria corresponding to different fault root causes. The system loads corresponding verification rules from the verification rule base based on the previously determined fault root cause types. These rules define the normal range, abnormal characteristics, and verification process for key reset response parameters. The system uses a real-time parameter analyzer to compare and analyze the collected reset response parameters with the verification rules, identifying whether the parameters are within the normal range and whether abnormal fluctuations exist. When reset response parameters exceed the expected range or exhibit abnormal patterns, the system immediately activates a safety protection mechanism to suspend the reset process and generate a safety alarm. The system evaluates the overall effectiveness of the reset operation through a multi-parameter comprehensive verification method to ensure that the charging pile can safely and stably resume normal operation after the reset is completed.
[0082] As an optional embodiment, the step of verifying the safety of the charging station based on the type of fault root cause and reset response parameters may further include the following steps: Step 501: Determine the safety verification items and the corresponding safety threshold ranges for each verification item based on the type of root cause of the failure.
[0083] Specifically, the system establishes a mapping database between root causes of failures and verification items. This database, built based on failure mechanism analysis and historical maintenance experience, records the system functions and parameters that require key verification for each type of root cause. The system extracts a list of corresponding safety verification items from the database based on the pre-determined root cause types. These verification items include categories such as electrical safety verification, thermal safety verification, mechanical safety verification, communication function verification, and control logic verification. The system configures a specific safety threshold range for each verification item, determined based on equipment technical specifications, safety standards, and operational experience data. The system employs a multi-level threshold setting mechanism, setting three levels for each verification item: optimal operating range, acceptable range, and hazardous range, ensuring the accuracy and safety of verification judgments.
[0084] Step 502: Adjust the verification weight of each verification item according to the historical recurrence frequency of the root cause of the failure. The higher the historical recurrence frequency of the root cause of the failure, the greater the weight of the corresponding verification item.
[0085] Specifically, the system retrieves historical occurrence and recurrence frequency data for various root causes of failures by querying the charging pile operation and maintenance database. It calculates the recurrence frequency of each root cause within a specified time period, employing a sliding time window method to ensure the timeliness and representativeness of the statistical data. The system establishes a frequency-weighted mapping algorithm, converting historical recurrence frequencies into verification weight coefficients; higher recurrence frequencies correspond to larger weight coefficients. The system uses a dynamic weight adjustment mechanism, periodically updating the weight values of each verification item based on the latest failure statistics to ensure that the verification weights always reflect the current distribution characteristics of failure risks. Through this weight adjustment method based on historical data, the system can prioritize verification resources for high-risk verification projects.
[0086] Step 503: Compare the reset response parameters with the corresponding safety threshold range to determine whether each verification item passes and record the deviation of each verification item.
[0087] Specifically, the system uses a parameter comparison module to compare the real-time collected reset response parameters with the corresponding safety threshold ranges item by item, employing a numerical range judgment algorithm to determine whether the parameters fall within the safety range. When the reset response parameter is within the safety threshold range, the system determines that the verification item passes; when the parameter exceeds the safety range, it fails. The system also calculates the deviation value for each verification item, defined as the percentage of the distance between the actual parameter value and the safety threshold boundary relative to the width of the safety range. The system uses a standardized deviation calculation method to convert the degree of deviation of parameters with different dimensions and numerical ranges into comparable standardized values. The system establishes a deviation recording mechanism, storing the deviation value of each verification item in the verification result database to provide data support for subsequent risk analysis and trend judgment.
[0088] Step 504: For the verified items that pass, mark the corresponding modules as safe. For the verified items that fail, calculate the risk contribution value based on the deviation and mark the item with the largest risk contribution value as a critical failure item.
[0089] Specifically, for projects that pass verification, a security status marking process is executed. The module status manager marks the corresponding module as safe, indicating that the module has passed reset verification and is ready for normal use. For projects that fail verification, the system calculates a risk contribution value based on deviation, taking into account both the magnitude of the deviation and the importance level of the verification project. The system uses a risk contribution value sorting algorithm to rank all failed verification projects, marking the project with the highest risk contribution value as a critical failure. Critical failures represent the most serious security risks and require priority handling and focused attention. The system establishes a failure classification mechanism, categorizing failed verification projects into different types based on the cause of failure, such as parameter anomalies, missing functions, and response timeouts, providing classification guidance for subsequent targeted handling.
[0090] Step 505: Calculate the weighted security score based on the verification weight and verification result of each verification item. When the weighted security score reaches the preset security threshold, the security verification result is determined to be a security verification pass. When the weighted security score is lower than the preset security threshold, the security verification result is determined to be a security verification fail, and a security verification failure prompt containing key failure items and suggested re-examination strategies is generated.
[0091] Specifically, the system uses a weighted scoring algorithm to calculate a weighted security score, converting the verification results of each verification item into numerical scores. Items that pass verification receive full marks, while those that fail receive partial scores based on their deviation. The system multiplies each item's score by its corresponding verification weight and then sums the results to obtain the total weighted security score. A preset security threshold is set as the criterion for passing security verification. When the weighted security score reaches or exceeds the preset threshold, the security verification is considered passed, and the system can proceed with the reset process and resume normal operation. When the weighted security score is below the preset threshold, the security verification is considered failed, and the system generates a security verification failure message. This message includes a detailed description of the key failure items and suggested re-examination strategies based on the failure cause analysis, guiding maintenance personnel to take appropriate measures. The system records the verification results and related data in a security verification log, providing historical data support for subsequent fault analysis and system optimization.
[0092] Step 50: Determine the charging recovery strategy for the charging pile based on the safety verification results, and control the charging pile to operate according to the charging recovery strategy.
[0093] Specifically, different verification results require different recovery strategies to ensure the charging piles can be safely and reliably put back into operation. The system establishes a mapping decision mechanism between safety verification results and charging recovery strategies. When the safety verification result is "safe," the system generates a standard charging recovery strategy, which includes steps such as disabling emergency stop protection, restoring charging function, and initiating normal operation monitoring. When the safety verification result is "unsafe," the system generates a restrictive recovery strategy or a maintenance waiting strategy based on the type and severity of the critical failure. The restrictive recovery strategy allows partial functional recovery but limits charging power or operating mode, while the maintenance waiting strategy keeps the equipment in a safe state awaiting manual maintenance.
[0094] As an optional embodiment, the step of determining the charging recovery strategy of the charging station based on the safety verification results may further include the following steps: Step 601: When the security verification result is that the security verification is passed, determine the recovery mode according to the type of the root cause of the failure. The recovery modes include direct recovery mode, progressive recovery mode and monitored recovery mode.
[0095] Specifically, the system establishes a mapping rule base between fault root causes and recovery modes, classifying fault root causes according to their recurrence probability and severity. The system maps low-recurrence-risk fault root causes such as transient interference and software anomalies to direct recovery modes; medium-recurrence-risk fault root causes such as temperature anomalies and voltage fluctuations to progressive recovery modes; and high-recurrence-risk fault root causes such as hardware aging and insulation degradation to monitoring recovery modes. The system uses a fault root cause analyzer to read the previously determined fault root cause types and queries the mapping rule base for the corresponding recovery modes, ensuring that the recovery strategy matches the fault characteristics.
[0096] Step 602: For the direct recovery mode, generate a first recovery strategy to restore the charging power to a stable level before the emergency stop signal.
[0097] Specifically, a first recovery strategy is generated for the direct recovery mode. The goal is to quickly restore charging functionality to maximize device utilization efficiency, as an overly conservative recovery approach would reduce charging efficiency without providing significant safety benefits for low-risk fault causes. The system generates a first recovery strategy to restore the stable charging power before the emergency stop signal, obtaining the stable charging power value before the emergency stop event through a historical data query tool. The system verifies whether this power value is within the device's rated power range to ensure the rationality of the recovery target. The system generates a sequence of control commands including steps such as disabling emergency stop protection, setting the target charging power, and starting charging output, enabling rapid restoration to the pre-fault operating state through a single setting.
[0098] Step 603: For the gradual recovery mode, generate a second recovery strategy that gradually increases the power from a preset initial power to the target charging power. The second recovery strategy includes multiple power increase stages and stability judgment conditions between each power increase stage.
[0099] Specifically, a second recovery strategy is generated for the gradual recovery mode. The aim is to safely restore charging functionality through phased power increases. For medium-risk faults, direct recovery may trigger fault recurrence; a gradual approach is needed to verify system stability at various power levels. The system generates a second recovery strategy that gradually increases the power from a preset initial power to the target charging power, setting the preset initial power at 30% of the rated power as a safe starting point. The system divides the power recovery process into multiple power increase stages, with each stage increasing the power by 20% of the previous stage to ensure smooth power increases. The system sets stability criteria for each power increase stage, including key parameter stability requirements and minimum stabilization time requirements. During each power increase stage, the system continuously monitors key parameters such as voltage, current, and temperature. When these parameters remain stable within a preset time without abnormal fluctuations, the stage is considered passed, and the next stage of power increase is executed.
[0100] Step 604: For the monitoring recovery mode, generate a third recovery strategy that operates at derating power and continuously monitors key parameters. The derating ratio in the third recovery strategy is determined based on the risk level of the root cause of the failure.
[0101] Specifically, a third recovery strategy is generated for the monitoring and recovery mode. The aim is to provide limited charging service while ensuring safety, as full recovery may pose safety risks for high-risk root causes of failure. Therefore, derating operation and continuous monitoring are needed to balance service availability and safety. The system generates a third recovery strategy that operates at dated power and continuously monitors key parameters, determining the derating percentage based on the risk level of the root cause of the failure. The system establishes a mapping relationship between risk level and derating percentage: 70% derating for medium risk and 50% derating for high risk. The system calculates the derating power value and sets it as the maximum allowable charging power after recovery. The system configures a continuous monitoring mechanism, selecting parameters directly related to the root cause of the failure as key monitoring targets and setting monitoring thresholds that are more stringent than those for normal operation. The system establishes a real-time risk assessment mechanism; when monitored parameters show abnormal trends, the charging power is immediately reduced or the charging service is suspended.
[0102] Step 605: When the security verification result is that the security verification fails, generate a policy to prevent charging recovery.
[0103] Specifically, when the safety verification fails, the system generates a policy to prevent charging recovery. This policy includes maintaining the emergency stop protection state, disabling the charging output function, and generating a fault report. The system uses a safety lock mechanism to set the charging pile to maintenance mode, preventing any charging recovery operation from being executed. The system generates a fault report containing detailed information on key failure items and recommended maintenance measures, and sends the report to the operation and maintenance management center via the communication module. The system activates the fault indication function, clearly displaying the equipment fault status to the user through LED indicators and the display screen to avoid user misoperation.
[0104] Please see Figure 3 This is a logical diagram illustrating the generation of a differentiated reset and recovery strategy provided in an embodiment of this application. Figure 3 This application demonstrates that through a two-stage, multi-dimensional intelligent decision-making process, it achieves refined, differentiated, and safe control over the entire process from "emergency stop" to "recovery."
[0105] like Figure 3 As shown, the logic is divided into two parts: A. Charging reset strategy generation: This part describes how to determine the reset operation itself.
[0106] Input: The input for decision-making is the risk level and root cause of failure obtained from the analysis of the preceding steps; Processing: The reset strategy generation logic module receives these two inputs; Output: Based on the input, the module will output a specific charging reset strategy; Differentiated Logic: As shown in the example, decisions are highly differentiated. For instance, when a fault is determined to be "high-risk" and the root cause is "power device overheating," the system will generate the most cautious "deep reset strategy" (which may include hardware power-off, energy isolation, etc.). Conversely, if a fault is determined to be "low-risk" and the root cause is "communication interruption," a "fast reset strategy" (which may only involve software restarting of the target module) will be generated to restore service as quickly as possible.
[0107] B. Charging Recovery Strategy Generation: This section describes how to safely restore the charging function after a successful reset; Inputs: The decision inputs at this stage include the safety verification results after executing the reset procedure, as well as the original root cause of the failure; Processing: The recovery strategy generation logic module comprehensively judges these inputs; Output: The module ultimately outputs a charging recovery strategy; Safety gatekeeping logic: As shown in the example, if the "safety verification result" is "failed," the strategy is directly "prohibit charging recovery" and a manual inspection is prompted. This is the most basic safety guarantee. If the verification passes, the system will not blindly recover but will refer to the "root cause of the fault" again. For example, for a root cause of "abnormal temperature," even if the reset verification passes, the system may choose a "gradual recovery strategy" (gradually increasing from low power) to monitor system stability and prevent fault recurrence.
[0108] This application also provides a computer storage medium that can store multiple instructions. The instructions are adapted to be loaded and executed by a processor as described in the above embodiment of a charging pile emergency stop reset control method. For the specific execution process, please refer to the detailed description of the above embodiment, which will not be repeated here.
[0109] The following describes an electronic device for emergency stop reset control of a charging pile, provided by an embodiment of this application. Figure 4 This is a schematic diagram of an exemplary hardware structure of an electronic device provided in an embodiment of this application.
[0110] In some embodiments, the electronic device for controlling the emergency stop and reset of the charging pile is a computer device, or the electronic device for controlling the emergency stop and reset of the charging pile includes a computer device. The computer device includes a processor, memory, and a network interface connected via a system bus. The processor of the computer device provides computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and internal memory. The non-volatile storage medium stores an operating system, computer programs, and a database. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage medium. The database of the computer device stores data. The network interface of the computer device is used to communicate with other external terminals or servers via a network connection. In some embodiments, the network interface can be a wired network interface; in some embodiments, the network interface can also be a wireless network interface. When the computer program is executed by the processor, it implements the methods in the embodiments of this application.
[0111] Those skilled in the art will understand that Figure 4 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.
[0112] The above-described embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit it. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of this application.
[0113] In the above embodiments, implementation can be achieved entirely or partially through software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented entirely or partially in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state drive), etc.
[0114] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. This program can be stored in a computer-readable storage medium, and when executed, it can include the processes described in the above method embodiments. The aforementioned storage medium includes various media capable of storing program code, such as ROM or random access memory (RAM), magnetic disks, or optical disks.
Claims
1. A charging pile emergency stop reset control method, characterized in that, The method comprises: detecting an emergency stop signal of the charging pile and acquiring working parameters of the charging pile within a preset time window before and after the emergency stop signal; extracting coupling correlation between the working parameters and abnormal parameter characteristics, determining a risk level and a fault root cause of the emergency stop event based on the coupling correlation and the abnormal parameter characteristics; generating a charging reset strategy according to the risk level and the fault root cause, and controlling the charging pile to execute a reset process according to the charging reset strategy; in the process of executing the reset process, real-time acquisition of reset response parameters of the charging pile, and safety verification of the charging pile according to the type of the fault root cause and the reset response parameters; determining a charging recovery strategy of the charging pile according to the safety verification result, and controlling the charging pile to operate according to the charging recovery strategy.
2. The charging pile emergency stop reset control method according to claim 1, characterized in that, The extraction of the coupling correlation between the working parameters and the abnormal parameter characteristics comprises: identifying a first parameter exceeding a normal range in the working parameters as an abnormal source parameter, and recording an abnormal trigger time of the abnormal source parameter; tracking the response time sequence of each working parameter relative to the abnormal trigger time, and calculating the response delay duration and response amplitude of each working parameter; constructing a time sequence dependency relationship between the working parameters based on the response delay duration, and determining the coupling strength between the working parameters according to the response amplitude; constructing an abnormal propagation path according to the time sequence dependency relationship and the coupling strength, and taking the abnormal propagation path as the coupling correlation; calculating the jump rate of the abnormal source parameter and the propagation speed of the abnormal propagation path, and taking the jump rate and the propagation speed as the abnormal parameter characteristics.
3. The charging pile emergency stop reset control method according to claim 2, characterized in that, The determination of the risk level and the fault root cause of the emergency stop event based on the coupling correlation and the abnormal parameter characteristics comprises: identifying a key node parameter of the abnormal propagation path, and calculating a propagation complexity index of the abnormal propagation path; determining an abnormal influence range coefficient based on the propagation complexity index, the propagation complexity index including propagation depth and propagation breadth; comparing the abnormal parameter characteristics with a preset characteristic risk threshold, and determining an abnormal evolution risk level according to the comparison result; calculating a comprehensive risk score of the emergency stop event by integrating the abnormal influence range coefficient and the abnormal evolution risk level, and determining the risk level of the emergency stop event according to the comprehensive risk score; determining the fault root cause according to the association characteristics of the key node parameters and the abnormal source parameter.
4. The charging pile emergency stop reset control method according to claim 3, characterized in that, The determination of the fault root cause according to the association characteristics of the key node parameters and the abnormal source parameter comprises: calculating the causal correlation strength between the abnormal source parameter and each key node parameter, the causal correlation strength being determined based on the response delay duration and the coupling strength between the parameters; identifying a key node parameter with the maximum causal correlation strength as a core parameter, and analyzing a parameter attribute combination mode of the abnormal source parameter and the core parameter; performing mode matching on the parameter attribute combination mode and a preset fault feature library, obtaining a fault type corresponding to a fault feature with the highest matching degree, and determining a fault root cause according to the fault type and a system module to which the abnormal source parameter belongs.
5. The charging pile emergency stop reset control method according to claim 1, characterized in that, The generating a charging reset strategy according to the risk level and the fault root cause comprises: determining a reset execution level according to the risk level, the reset execution level comprising a fast reset level, a standard reset level, and a deep reset level; determining a target module needing reset from a preset fault module mapping library according to the fault root cause, and determining a reset order based on a dependency relationship between modules; when the reset execution level is the fast reset level, generating a first reset strategy of performing a soft reset on the target module, an execution time length of the first reset strategy being not more than a first preset time length; when the reset execution level is the standard reset level, generating a second reset strategy of performing reset on the target module and corresponding associated modules in sequence according to the reset order, the associated modules being determined based on the dependency relationship between the modules; when the reset execution level is the deep reset level, generating a third reset strategy of performing a hardware reset on a charging pile whole system according to a preset safe reset sequence, the third reset strategy comprising energy isolation; selecting a corresponding reset strategy as the charging reset strategy according to the reset execution level, and determining key parameters needing monitoring and monitoring thresholds in a reset process according to the fault root cause. 6.The charging pile emergency stop reset control method according to claim 1, characterized in that, The performing safety verification on the charging pile according to the type of the fault root cause and the reset response parameter comprises: determining safety verification items and safety threshold ranges corresponding to each verification item according to the type of the fault root cause; adjusting verification weights of each verification item according to a historical recurrence frequency of the fault root cause, a verification item weight corresponding to a fault root cause with a higher historical recurrence frequency being greater; comparing the reset response parameter with a corresponding safety threshold range, judging whether each verification item passes, and recording a deviation degree of each verification item; for a verification item that passes, marking a corresponding module as a safe state, and for a verification item that does not pass, calculating a risk contribution value based on the deviation degree, and marking an item with the greatest risk contribution value as a key failure item; calculating a weighted safety score based on verification weights and verification results of each verification item, determining that a safety verification result is safety verification passing when the weighted safety score reaches a preset safety threshold, and determining that the safety verification result is safety verification not passing when the weighted safety score is lower than the preset safety threshold, and generating a safety verification failure prompt containing the key failure item and a recommended review strategy.
7. The charging pile emergency stop reset control method according to claim 1, characterized in that, The determining a charging recovery strategy of the charging pile according to the safety verification result comprises: when the safety verification result is safety verification passing, determining a recovery mode according to the type of the fault root cause, the recovery mode comprising a direct recovery mode, a gradual recovery mode, and a monitoring recovery mode; for the direct recovery mode, generating a first recovery strategy of recovering to a stable charging power before the emergency stop signal; for the gradual recovery mode, generating a second recovery strategy of starting from a preset initial power and gradually increasing to a target charging power, the second recovery strategy comprising a plurality of power increase stages and stability determination conditions between the power increase stages; For the monitoring recovery mode, a third recovery strategy running at a reduced power and continuously monitoring key parameters is generated, and a derating ratio in the third recovery strategy is determined according to the risk level of the fault root cause; When the safety verification result is safety verification failure, a charging prohibition recovery strategy is generated.
8. Electronic equipment for emergency stop reset control of a charging pile, characterized by, The electronic device includes one or more processors and a memory; the memory is coupled with the one or more processors, the memory is used to store computer program code, the computer program code includes computer instructions, and the one or more processors invoke the computer instructions to enable the electronic device to execute the method in any one of claims 1-7.
9. A computer program product comprising instructions, characterized in that, When the computer program product runs on the electronic device for charging pile emergency stop reset control, the electronic device executes the method in any one of claims 1-7.
10. A computer-readable storage medium comprising instructions, characterized in that, When the instructions run on the electronic device for charging pile emergency stop reset control, the electronic device executes the method in any one of claims 1-7.