Vehicle connection management system, vehicle, interaction management system and method

By combining electronic fuses and a connection management unit, the system monitors load current and performs legitimacy authentication, solving the problem of fuses being unable to restore connections. This enables flexible electrical connection management, reduces costs, improves safety and user experience, and ensures the safety and privacy of vehicles and external devices.

CN121772033APending Publication Date: 2026-03-31Z-ONE TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-09-30
Publication Date
2026-03-31

AI Technical Summary

Technical Problem

In existing technologies, once a vehicle's external interface is connected to an external device, the fuse cannot be restored after it blows, resulting in high replacement costs, cumbersome operation, and an inability to effectively control the electrical connection of unauthorized devices, posing safety hazards and a poor user experience.

Method used

Employing electronic fuses and a connection management unit, the system flexibly controls the electrical connection status between the external interface and external devices by monitoring load current and authentication. The electronic fuse remains connected or disconnected within a preset current range, and the connection management unit sends a disconnect command based on the authentication status of the external device, ensuring both security and authentication.

Benefits of technology

It enables load current control and management between external interfaces and external devices, reduces the cost of replacing fuses, improves user experience, ensures the connection security between the vehicle and external devices, prevents data leakage and tampering by unauthorized devices, and enhances vehicle safety and privacy protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121772033A_ABST
    Figure CN121772033A_ABST
Patent Text Reader

Abstract

The invention discloses a vehicle connection management system, a vehicle and an interaction management system and method.The vehicle comprises an external interface and the vehicle connection management system, the vehicle is electrically connected with external equipment through the external interface, and the vehicle connection management system comprises an electronic fuse and a connection management unit; the electronic fuse is electrically connected with a power pin of the external interface and the connection management unit, and the electronic fuse is electrically connected with the connection management unit based on whether the load current between the external interface and the external device is within a preset current range. And based on whether a disconnection instruction sent by the connection management unit when the external device is illegal is received, whether the vehicle is in a connected state or not is determined, so that the electric connection between the vehicle and the external device is in a connected state or a disconnected state. Therefore, the fuse does not need to be replaced when the connection between the vehicle and the external equipment needs to be cut off every time, the cost is reduced, and manual operation is reduced. And the safety of interface connection is improved based on the judgment of legal equipment, and the vehicle use safety and the user experience are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of vehicle connectivity management technology, and in particular to a vehicle connectivity management system, a vehicle, an interactive management system, and a method. Background Technology

[0002] During vehicle use, there are frequent situations where vehicles establish wired electrical connections with external devices through external interfaces to supply power and exchange information. Currently, if an overcurrent or short circuit occurs between the external interface and the external device, it is necessary to disconnect the electrical connection between the external interface and the external device to protect both the vehicle and the external device.

[0003] In existing technologies, a fusible fuse is used on the power pin of the external interface. In the event of an overcurrent or short circuit between the external interface and the external device, the fuse blows, cutting off the connection. While this method provides connection protection during overcurrent or short circuits, once the fuse blows, the connection cannot be restored. The external interface will no longer be able to establish a normal electrical connection with the external device, requiring the user to drive to an authorized service center to replace the fuse circuit. Therefore, this connection management method suffers from high fuse replacement costs, cumbersome operation, potential vehicle safety hazards, and a poor user experience. Summary of the Invention

[0004] This application provides a vehicle connection management system, a vehicle, an interaction management system, and a method to solve the problem that in the prior art, once the fuse blows after the vehicle's external interface and external device are electrically connected, the connection cannot be restored, and replacing the fuse is costly and cumbersome, resulting in vehicle safety hazards and a poor user experience.

[0005] The electronic fuse, based on the load current between the external interface and the external device, can flexibly manage the connection between them. Furthermore, the connection management unit can control the electronic fuse based on whether the external device is legitimate, eliminating the need to replace the fuse every time the connection between the vehicle's external interface and the external device needs to be disconnected, thus reducing costs and manual operation. The legitimacy determination also enhances the security of the interface connection, improving vehicle safety and user experience.

[0006] To address the aforementioned technical problems, in a first aspect, this application discloses a vehicle connectivity management system. The vehicle includes an external interface, through which it establishes an electrical connection with an external device. The vehicle connectivity management system includes an electronic fuse and a connectivity management unit. The electronic fuse is electrically connected to both the power pin of the external interface and the connectivity management unit. When the load current between the external interface and the external device is within a preset current range and no disconnection command is received from the connectivity management unit, the electronic fuse is in a connected state, ensuring the electrical connection between the vehicle and the external device is established. When the load current is not within the preset current range, or when a disconnection command is received from the connectivity management unit, the electronic fuse is in a disconnected state, ensuring the electrical connection between the vehicle and the external device is broken. The connectivity management unit, when the electronic fuse is in a connected state, determines whether to send a disconnection command to the electronic fuse based on whether the external device is a legitimate device. Specifically, when the external device is a legitimate device, the connectivity management unit does not send a disconnection command to the electronic fuse; when the external device is not a legitimate device, it sends a disconnection command to the electronic fuse.

[0007] The connection management system provided in this application includes an electronic fuse electrically connected to both the power pin of the external interface and the connection management unit. When the load current between the external interface and the external device is within a preset current range and no disconnection command is received from the connection management unit, the electronic fuse is in a connected state, ensuring the electrical connection between the vehicle and the external device is established. When the load current is not within the preset current range, or when a disconnection command is received from the connection management unit, the electronic fuse is in a disconnected state, ensuring the electrical connection between the vehicle and the external device is broken. Furthermore, the connection management unit determines whether to send a disconnection command to the electronic fuse based on whether the external device is a legitimate device. Thus, the electronic fuse enables both control and management of the load current between the external interface and the external device, and the connection management unit ensures the safety of the connection between the vehicle and the external device. The electronic fuse provides flexible control over the electrical connection status between the external interface and the external device, eliminating the need to replace the fuse every time the connection between the vehicle's external interface and the external device needs to be disconnected, reducing costs and ensuring the safety of the connection between the external device and the vehicle. Moreover, electronic fuses can self-reset, eliminating the need for manual reconnection between external interfaces and devices, reducing human intervention and improving the user experience.

[0008] Furthermore, by determining whether an external device is legitimate through the connection management unit, the electronic fuse can be in an open state when it receives a disconnect command from the connection management unit. Thus, by controlling the electronic fuse to be in an open or open state, the load current between the external interface and the external device is controlled and managed. The connection management unit also ensures the security of the connection between the vehicle and the external device, guaranteeing communication security between the external device and the vehicle. This prevents the possibility of unauthorized devices writing or reading vehicle data, thus improving vehicle safety, protecting user safety and privacy, and enhancing the user experience.

[0009] According to another specific implementation of this application, the vehicle connection management system disclosed in this implementation includes an electronic fuse and a connection management unit installed in the vehicle.

[0010] According to another specific implementation of this application, the vehicle connection management system disclosed in this implementation includes an electronic fuse comprising a control terminal and an output terminal. The electronic fuse is electrically connected to the power pin of an external interface through the output terminal and electrically connected to the connection management unit through the control terminal.

[0011] According to another specific implementation of this application, the vehicle connection management system disclosed in this implementation has an external interface as an on-board diagnostic system interface.

[0012] By adopting the above technical solution, a connection management system installed in the vehicle, including an electronic fuse and a connection management unit, provides connection protection when the vehicle's on-board diagnostic system interface and external devices are electrically connected, making it safer for the vehicle to connect to external devices for power supply and communication.

[0013] Secondly, this application also discloses an interactive management system, including a vehicle and external devices. The vehicle includes an external interface, through which it establishes an electrical connection with the external devices. The vehicle also includes a vehicle connection management system, which includes an electronic fuse and a connection management unit. The electronic fuse is electrically connected to the power pin of the external interface and the connection management unit. When the load current between the external interface and the external devices is within a preset current range and no disconnection command is received from the connection management unit, the electronic fuse is in a connected state, ensuring the electrical connection between the vehicle and the external devices is established. When the load current is not within the preset current range or a disconnection command is received from the connection management unit, the electronic fuse is in a disconnected state, ensuring the electrical connection between the vehicle and the external devices is broken. The connection management unit, when the electronic fuse is in a connected state, determines whether to send a disconnection command to the electronic fuse based on whether the external devices are legitimate. Specifically, the connection management unit does not send a disconnection command to the electronic fuse when the external devices are legitimate, and sends a disconnection command to the electronic fuse when the external devices are not legitimate.

[0014] According to another specific implementation of this application, the interactive management system disclosed in this implementation further includes an authentication server. The authentication server establishes a communication connection with the connection management unit, wherein the authentication server is used to generate a legality authentication result of the external device and send the legality authentication result to the connection management unit so that the connection management unit determines whether the external device is a legal device based on the legality authentication result.

[0015] By adopting the above technical solution, the authentication server generates a validity authentication result for the external device. This result enables the connection management unit to determine whether the external device is legitimate and, based on the authentication result, whether to send a disconnect command to the electronic fuse. In this way, the electronic fuse controls the load current between the external interface and the external device, while the connection management unit ensures the security of the connection between the vehicle and the external device. This guarantees the communication security between the external device and the vehicle, prevents unauthorized devices from writing or reading vehicle data, and protects user safety and privacy.

[0016] According to another specific implementation of this application, the interactive management system disclosed in this implementation further includes a cloud server. The cloud server establishes a communication connection with the connection management unit, wherein the connection management unit is further used to generate alarm information and fault codes when the external device is not an illegitimate device, present the alarm information, and send the fault codes to the cloud server; the cloud server is used to store the fault codes.

[0017] By adopting the above technical solution, the cloud server stores fault codes, which facilitates subsequent after-sales tracking and problem troubleshooting.

[0018] According to another specific implementation of this application, the interactive management system disclosed in this implementation includes an electronic fuse comprising a control terminal and an output terminal. The electronic fuse is electrically connected to the power pin of an external interface through the output terminal and electrically connected to a connection management unit through the control terminal.

[0019] According to another specific implementation of this application, the interactive management system disclosed in this implementation includes an external device with a power pin, and an external interface with a power pin electrically connected to the power pin of the external device; or the external interface further includes at least one first CAN communication pin and at least one first Ethernet communication pin, the external device with a power pin, and at least one second CAN communication pin and at least one second Ethernet communication pin, the power pin of the external interface with the power pin of the external device electrically connected, the first CAN communication pin and the second CAN communication pin electrically connected, and the first Ethernet communication pin and the second Ethernet communication pin electrically connected.

[0020] Using the above technical solution, external devices can establish an electrical connection with the vehicle based on the power pins of the external interface and the power pins of the external device. They can also establish a communication connection and an electrical connection with the vehicle based on the power pins of the external interface, the first CAN communication pin, and the first Ethernet communication pin, thereby enabling data interaction while ensuring power supply.

[0021] Thirdly, this application also discloses an interactive management method. This method is applied to an interactive management system, which includes a vehicle and external devices. The vehicle includes an external interface through which it establishes an electrical connection with the external devices. The vehicle also includes a vehicle connection management system, which includes an electronic fuse and a connection management unit. The electronic fuse is electrically connected to the power pin of the external interface and the connection management unit. When the load current between the external interface and the external devices is within a preset current range and no disconnection command is received from the connection management unit, the electronic fuse is in a connected state, ensuring the electrical connection between the vehicle and the external devices is established. When the load current is not within the preset current range or a disconnection command is received from the connection management unit, the electronic fuse is in a disconnected state, ensuring the electrical connection between the vehicle and the external devices is broken. When the electronic fuse is in a connected state, the connection management unit determines whether to send a disconnection command to the electronic fuse based on whether the external devices are legitimate. Specifically, the connection management unit does not send a disconnection command to the electronic fuse when the external devices are legitimate, and sends a disconnection command to the electronic fuse when the external devices are not legitimate.

[0022] According to another specific implementation of this application, the interactive management method disclosed in this implementation further includes an authentication server. The method further includes a connection management unit determining whether an external device is a legitimate device in the following manner: the connection management unit determines the device identification information of the external device and sends an authentication request containing the device identification information and the vehicle identification information to the authentication server; the authentication server generates a first random code based on the authentication request and sends it to the connection management unit; the connection management unit sends the first random code to the external device; the external device determines a first key, generates first authentication information based on the first key and the first random code, and sends the first authentication information to the connection management unit. The connection management unit determines a second key, generates second authentication information based on the second key and a first random code, and sends the first and second authentication information to the authentication server. The authentication server determines a second random code based on the first authentication information and the first key, and determines a third random code based on the second authentication information and the second key. It then generates a legitimacy authentication result for the external device based on the first, second, and third random codes, and sends the legitimacy authentication result to the connection management unit. If the connection management unit determines that the legitimacy authentication result is successful, it determines that the external device is a legitimate device; if it determines that the legitimacy authentication result is unsuccessful, it determines that the external device is an illegitimate device.

[0023] By adopting the above technical solution, the authentication server generates a validity authentication result for external devices. This result enables the connection management unit to determine whether the external device is legitimate and, based on the authentication result, whether to send a disconnect command to the electronic fuse. In this way, the electronic fuse controls the load current between the external interface and the external device, while the connection management unit ensures the security of the connection between the vehicle and the external device. This guarantees the communication security between the external device and the vehicle, prevents unauthorized devices from writing or reading vehicle data, thus protecting user safety and privacy and enhancing the user experience.

[0024] According to another specific implementation of this application, the interactive management method disclosed in this implementation further includes the following steps: the connection management unit determines whether an external device is a legitimate device by: the connection management unit determining response conditions and sending the response conditions to the external device; the external device sending a response to the connection management unit according to the response conditions; the connection management unit determining that the external device is a legitimate device if it determines that the response meets the response conditions, and determining that the external device is an illegitimate device if it determines that the response does not meet the response conditions.

[0025] By adopting the above technical solution, the connection management unit determines whether an external device is legitimate based on the response conditions and the response of the external device. This ensures the security of the connection between the vehicle and the external device, guarantees the communication security between the external device and the vehicle, avoids the possibility of unauthorized devices writing or reading vehicle data, and protects user safety and privacy.

[0026] According to another specific implementation of this application, the interactive management method disclosed in this implementation further includes, if the external device is a legitimate device, the method further includes: the connection management unit determining the power consumption information of the external device and presenting the power consumption information of the external device.

[0027] Using the above technical solution, if the connection management unit determines that the external device is a legitimate device, it can display the current power consumption information of the external device, which can assist the vehicle owner in managing the power consumption of the external device.

[0028] According to another specific implementation of this application, the interactive management method disclosed in this implementation further includes a cloud server. If the external device is not an illegitimate device, the method further includes: the connection management unit generating alarm information and fault codes, presenting the alarm information, and sending the fault codes to the cloud server.

[0029] Using the above technical solution, the connection management unit generates an alarm message to alert the user when an external device is not an authorized device. Furthermore, the connection management unit records the fault code of the unauthorized device and uploads it to the cloud server. The cloud server stores the fault code for easy after-sales tracking and troubleshooting.

[0030] According to another specific implementation of this application, the interactive management method disclosed in this application, when the vehicle is in factory mode, further includes: calibrating the current resistance value of the electronic fuse based on software, so that the electronic fuse can determine whether the load current between the external interface and the external device is within a preset current range based on the current resistance value.

[0031] By calibrating the current resistance value of the electronic fuse, the fuse can determine whether the load current is within a preset current range based on its current resistance value. This allows for flexible control of the electrical connection between the external interface and external devices, eliminating the need to replace the fuse every time the connection needs to be disconnected, reducing costs and ensuring the safety of the connection between the external devices and the vehicle. Furthermore, the electronic fuse is self-resetting, eliminating the need for manual reconnection between the external interface and external devices, reducing human intervention and improving the user experience.

[0032] Fourthly, this application also discloses a vehicle, which includes an external interface, through which the vehicle establishes an electrical connection with an external device, and the vehicle also includes a vehicle connection management system as provided in any of the implementations of the first aspect above.

[0033] Fifthly, an implementation of this application provides a computer-readable storage medium storing a computer program, which, when executed by a processor, is used to implement the interactive management method provided by any of the implementations of the third aspect above.

[0034] Sixthly, an implementation of this application provides a computer program product, including a computer program that, when executed by a processor, implements the interactive management method provided by any of the implementations of the third aspect above.

[0035] It is understandable that the beneficial effects of the fourth to sixth aspects mentioned above can also be found in the relevant descriptions of the first to third aspects mentioned above, and will not be repeated here. Attached Figure Description

[0036] Figure 1 This is a schematic diagram of an interactive management system provided in an embodiment of this application;

[0037] Figure 2This is a schematic diagram of another interactive management system provided in an embodiment of this application;

[0038] Figure 3 This is a schematic diagram of another interactive management system provided in an embodiment of this application;

[0039] Figure 4 This is a schematic diagram of an external interface provided in an embodiment of this application;

[0040] Figure 5 This is a schematic diagram of another interactive management system provided in an embodiment of this application;

[0041] Figure 6 This is a flowchart illustrating an interactive management method provided in an embodiment of this application;

[0042] Figure 7 This is a schematic diagram of a process for determining whether an external device is a legitimate device, provided in an embodiment of this application.

[0043] Figure 8 This is a schematic diagram of another process for determining whether an external device is a legitimate device, provided in an embodiment of this application.

[0044] Figure 9 This is a flowchart illustrating another interactive management method provided in an embodiment of this application. Attached image description:

[0046] 10. Vehicle; 110. External interface; 120. Vehicle connection management system; 121. Electronic fuse; 122. Connection management unit;

[0047] 20. External equipment;

[0048] 30. Authentication server;

[0049] 40. Cloud server.

[0050] Specific implementation method

[0051] As mentioned earlier, existing vehicles use ordinary fuses that do not support self-resetting to power the interface and control the connection circuit after establishing a wired electrical connection with the external interface and external devices. Although this method provides circuit connection protection in case of overcurrent or short circuit, once the fuse blows, it cannot self-reset in case of overcurrent or short circuit. The external interface will no longer be able to establish a normal electrical connection with the external device. Users need to drive to a 4S store or other after-sales service center for after-sales repair to replace the relevant fuse circuit before the connection can be restored.

[0052] When this type of connection management system protects external interfaces, it suffers from high costs and cumbersome operations when replacing fuses, resulting in a poor user experience.

[0053] Furthermore, circuit protection based on ordinary fuses can only protect against overcurrent or short circuits in the load current between the external interface and external devices. It cannot monitor or control the power supply to external devices without authorization, making it impossible to actively control the power supply from the external interface to external devices. Moreover, the inability to control power supply also allows external devices to arbitrarily read and write relevant vehicle data information based on electrical connections, posing data leakage and functional safety risks.

[0054] Based on this, this application provides a vehicle connection management system, an interaction management system, a method, and a vehicle. When the load current between the external interface and the external device is within a preset current range and no disconnection command is received from the connection management unit, the electronic fuse is in a connected state, ensuring the electrical connection between the vehicle and the external device is established. When the load current is not within the preset current range, or when a disconnection command is received from the connection management unit, the electronic fuse is in a disconnected state, ensuring the electrical connection between the vehicle and the external device is broken. The connection management unit does not send a disconnection command to the electronic fuse when the electronic fuse is in a connected state and the external device is a legitimate device; however, it sends a disconnection command to the electronic fuse when the external device is not a legitimate device.

[0055] In this way, the electronic fuse determines its state of connection or disconnection based on the load current between the external interface and the external device, and whether it has received a disconnect command from the connection management unit (which determines whether the external device is legitimate). This provides circuit and communication protection between the external interface and the external device. This reduces circuit protection costs, eliminates the need for user fuse replacements, minimizes user operations, and, by controlling the electronic fuse's state based on the legitimacy of the external device, ensures power-off protection if an unauthorized device is connected to the vehicle. This prevents unauthorized devices from arbitrarily reading or writing vehicle data, avoids data leaks, and ensures vehicle safety.

[0056] Next, the vehicle connection management system and vehicle and interaction management system disclosed in this application will be described in detail.

[0057] In the implementation method of this application, such as Figure 1 As shown, the interactive management system includes a vehicle 10 and an external device 20. The vehicle 10 includes an external interface 110, through which the vehicle 10 establishes an electrical connection with the external device 20. Furthermore, the vehicle 10 includes a vehicle connectivity management system 120.

[0058] The external interface 110 establishes an electrical connection with the external device 20 to supply power to the external device 20, or to power on the external device 20 and transmit information to the external device 20.

[0059] In one implementation of this application, the external interface 110 may specifically be an on-board diagnostic interface (i.e., an OBD interface, where OBD stands for On-Board Diagnostics), or it may be any other interface that is electrically connected to the external device 20.

[0060] In this implementation, the external device 20 can specifically be a professional after-sales diagnostic device, a user's mobile phone, computer, headphones, or other electronic devices. The external interface 110 and the external device 20 are connected via a wired electrical connection, meaning that both the external interface 110 and the external device 20 establish a connection based on their respective interfaces.

[0061] Furthermore, such as Figure 2 As shown, the vehicle connectivity management system 120 provided in this application includes an electronic fuse 121 (eFuse) and a connectivity management unit 122.

[0062] The electronic fuse 121 is electrically connected to the power pin of the external interface 110 and the connection management unit 122, respectively.

[0063] When the load current between the external interface 110 and the external device 20 is within a preset current range and no disconnection command is received from the connection management unit 122, the electronic fuse 121 is in a connected state, so that the electrical connection between the vehicle and the external device 20 is connected. When the load current is not within the preset current range or a disconnection command is received from the connection management unit 122, the electronic fuse 121 is in a disconnected state, so that the electrical connection between the vehicle and the external device 20 is disconnected.

[0064] The connection management unit 122 is used to determine whether to send a disconnect command to the electronic fuse 121 based on whether the external device 20 is a legitimate device when the electronic fuse 121 is in a connected state. Specifically, the connection management unit 122 does not send a disconnect command to the electronic fuse 121 when the external device 20 is a legitimate device, and sends a disconnect command to the electronic fuse 121 when the external device 20 is not a legitimate device.

[0065] That is, in the implementation of this application, after the external device 20 and the external interface 110 establish an electrical connection, power is supplied based on the electronic fuse 121. At this time, the electronic fuse 121 determines the load current between the external interface 110 and the external device 20 and determines whether the load current between the external interface 110 and the external device 20 is within the preset current range. Furthermore, when the connection management unit 122 detects that an external device 20 is connected to the external interface 110, it communicates with the external device 20 to determine whether the external device 20 is a legitimate device. If the external device 20 is determined to be a legitimate device, it does not send a disconnect command to the electronic fuse 121. When the electronic fuse 121 determines that the load current is within the preset current range and has not received a disconnect command from the connection management unit 122, it is in a connected state, so that the electrical connection between the vehicle and the external device 20 is in a connected state. When the load current is not within the preset current range, or when the electronic fuse 121 is within the preset current range and has received a disconnect command from the connection management unit 122, it is in a disconnected state, so that the electrical connection between the vehicle and the external device 20 is in a disconnected state.

[0066] Therefore, in the implementation of this application, the electronic fuse 121 and the connection management unit 122 are installed in the vehicle 10.

[0067] In one implementation of this application, the connection management unit 122 can be a processor of the vehicle 10, an electronic control unit (ECU) of the vehicle 10, or a microprocessor unit (MCU) of the vehicle 10.

[0068] The electronic fuse 121 includes a control terminal and an output terminal. The electronic fuse 121 is electrically connected to the power pin of the external interface 110 through the output terminal and electrically connected to the connection management unit 122 through the control terminal.

[0069] For example, the electronic fuse 121 is connected to the power pin of the external interface 110 via a wired cable through its output terminal, and to the interface of the connection management unit 122 via an inter-board trace through its control terminal.

[0070] It should be noted that, considering the usage scenarios of vehicle 10, there are instances where vehicle 10, during the production and assembly process, performs calibration of the Electrical Check Out System (ECOS) via external interface 110, i.e., determining the external devices 20 that can be connected; this stage is defined as factory mode. Secondly, when delivered to the end user, vehicle 10 can be used by the owner; this scenario is defined as user mode. These different modes are combined to assist the intelligent power distribution strategy and achieve vehicle connectivity management.

[0071] In this implementation, when vehicle 10 is in factory mode, the power supply current (i.e., load current) of legitimate equipment in working condition (i.e., when external device 20 and vehicle 10 are electrically connected) is monitored. The current resistance value (i.e., output current) of electronic fuse 121 is calibrated via software to ensure that the power value of the external electrical equipment is within a safe preset range. Thus, when vehicle 10 is in user mode (i.e., usage mode), if electronic fuse 121 determines that the load current exceeds the current resistance value, it determines that the load current is not within the preset current range (i.e., the power of external device 20 is not within the safe preset range), and actively cuts off the power supply from vehicle 10 to external device 20, implementing power supply protection.

[0072] Furthermore, in the implementation of this application, in factory mode, the connection management unit 122 can store the device identification information of the legitimate device so that when the external device 20 is connected to the vehicle 10, the device identification information of the external device 20 can be obtained and the external device 20 can be determined by querying to determine whether the external device 20 is a legitimate device.

[0073] In another implementation of this application, the connection management unit 122 may perform encryption and decryption authentication based on the symmetric keys stored by the external device 20 and the connection management unit 122 respectively, and obtain the authentication result to determine whether the external device 20 is a legitimate device based on the authentication result.

[0074] The vehicle connectivity management system 120 provided in this application, when a customer installs an external device 20, uses an electronic fuse 121 to determine whether the current load current is within the preset current range of the legitimate device, thereby achieving electrical protection between the external device 20 and the vehicle 10. Furthermore, the connectivity management unit 122 filters out illegitimate devices by verifying the legitimacy of the external device 20 and controls the electronic fuse 121 to disconnect, thus severing the electrical connection between the external device 20 and the vehicle 10. This prevents the possibility of unauthorized devices (i.e., illegitimate devices) writing or reading vehicle data and causing security issues while the vehicle 10 is sold, protecting user safety and privacy, and providing basic support for subsequent value-added services such as the external device 20 provided by the vehicle 10. In this way, the connectivity management unit 122 verifies the legitimacy of the external device 20, enabling electrical protection between the external device 20 and the vehicle 10 through the eFuse electronic fuse 121.

[0075] Further, see Figure 3 The interactive management system provided in this application includes a vehicle 10 and external devices 20.

[0076] The vehicle 10 includes an external interface 110, through which the vehicle 10 establishes an electrical connection with an external device 20. The vehicle 10 also includes a vehicle connection management system 120, which includes an electronic fuse 121 and a connection management unit 122. The electronic fuse 121 is electrically connected to the power pin of the external interface 110 and the connection management unit 122, respectively.

[0077] When the load current between the external interface 110 and the external device 20 is within a preset current range and no disconnection command is received from the connection management unit 122, the electronic fuse 121 is in a connected state, so that the electrical connection between the vehicle 10 and the external device 20 is connected. When the load current is not within the preset current range or a disconnection command is received from the connection management unit 122, the electronic fuse 121 is in a disconnected state, so that the electrical connection between the vehicle 10 and the external device 20 is disconnected.

[0078] The connection management unit 122 is used to determine whether to send a disconnect command to the electronic fuse 121 based on whether the external device 20 is a legitimate device when the electronic fuse 121 is in a connected state. Specifically, the connection management unit 122 does not send a disconnect command to the electronic fuse 121 when the external device 20 is a legitimate device, and sends a disconnect command to the electronic fuse 121 when the external device 20 is not a legitimate device.

[0079] Furthermore, in another implementation of this application, the interactive management system further includes an authentication server 30, which establishes a communication connection with the connection management unit 122, wherein the communication connection can be a wireless communication connection based on 4G, 5G, or other methods.

[0080] The authentication server 30 generates the validity authentication result of the external device 20 and sends the validity authentication result to the connection management unit 122 so that the connection management unit 122 can determine whether the external device 20 is a valid device based on the validity authentication result.

[0081] For example, after the vehicle 10 and the external device 20 establish an electrical connection, the authentication server 30 generates a validity authentication result for the external device 20 and sends the validity authentication result to the connection management unit 122. The connection management unit 122 determines whether the external device 20 is a valid device based on the validity authentication result. If the validity authentication result is that the authentication is successful, the external device 20 is determined to be a valid device. If the validity authentication result is that the authentication is unsuccessful, the external device 20 is determined to be an invalid device.

[0082] Furthermore, in one implementation of this application, if the external device 20 involves highly secure device interaction that rewrites data on the vehicle 10, i.e., if the external device 20 and the external interface 110 establish an electrical connection based on their respective power pins, CAN communication pins, and Ethernet pins, then the connection management unit 122, upon determining that the external device 20 and the vehicle 10 have established an electrical connection, receives the device identification information sent by the external device 20 and sends an authentication request containing the device identification information and the vehicle identification information of the vehicle 10 to the authentication server 30. The authentication server 30 generates a first random code based on the authentication request and sends it to the connection management unit 122. The first random code may include the device identification information of the external device 20 and the vehicle identification information of the vehicle 10. The connection management unit 122 sends the first random code to the external device 20, the external device 20 determines a first key, generates first authentication information based on the first key and the first random code, and sends the first authentication information to the connection management unit 122. The connection management unit 122 determines a second key, generates second authentication information based on the second key and a first random code, and sends the first and second authentication information to the authentication server 30. The authentication server 30 determines a second random code based on the first authentication information and the first key, and determines a third random code based on the second authentication information and the second key. It then generates a legitimacy authentication result for the external device 20 based on the first, second, and third random codes, and sends the legitimacy authentication result to the connection management unit 122. If the connection management unit 122 determines that the legitimacy authentication result is successful, it determines that the external device 20 is a legitimate device; if it determines that the legitimacy authentication result is unsuccessful, it determines that the external device 20 is an illegitimate device.

[0083] In one implementation of this application, the first key and the second key can be the same symmetric key or different asymmetric keys. The first key and the second key can be pre-stored in the external device 20 and the connection management unit 122, respectively. Alternatively, when the connection management unit 122 initiates an authentication request, the authentication server 30 can send the first key to the external device 20 and the second key to the connection management unit 122, respectively. Of course, the connection management unit 122 can also send the first key to the external device 20 when sending the first random code.

[0084] Furthermore, in another implementation of this application, taking the first key and the second key as symmetric keys as an example, the authentication server 30 can directly perform legitimacy authentication with the external device 20.

[0085] Specifically, the authentication server 30 first generates a symmetric key in a secure environment and distributes it to legitimate devices. Legitimate devices register and store the key. When an external device 20 requests authentication from the connection management unit 122, the authentication server 30 generates a random challenge value (i.e., a first random code) and sends it to the external device 20. The external device 20 encrypts the random challenge value using its stored symmetric key and generates authentication information as a response, which it sends back to the authentication server 30. The authentication server 30 decrypts the response (i.e., decrypts the authentication information) using the same symmetric key to obtain a challenge code (i.e., a second random code). If the decrypted challenge code matches the generated challenge value, authentication is successful, and the server sends a successful authentication (i.e., authentication passed) result to the connection management unit 122, allowing the external device 20 to access resources or perform operations. Otherwise, if authentication fails, the server sends a failed authentication (i.e., authentication not passed) result to the connection management unit 122 to take security measures (e.g., controlling the electronic fuse 121 to be in an open state).

[0086] Furthermore, in one implementation of this application, if the external device 20 is a read-only device containing rear-drive vehicle information but cannot be tampered with (i.e., if the external device 20 and the external interface 110 are electrically connected based on their respective power pins), then the connection management unit 122 initiates an active heartbeat request to determine whether the external device 20 is a legitimate device. For example, the connection management unit 122 determines the response conditions and sends them to the external device 20. The external device 20 sends a response to the connection management unit 122 based on the response conditions. If the connection management unit 122 determines that the response meets the response conditions, it determines that the external device 20 is a legitimate device. If it determines that the response does not meet the response conditions, it determines that the external device 20 is an illegitimate device.

[0087] In one implementation, the response conditions may specifically include a response time request (e.g., a timeout mechanism for receiving a response within a specified time) and heartbeat cycle activation. For example, the connection management unit 122 requests to send a request command to the external device 20 with a heartbeat cycle of any time value, such as 10s or 20s. After receiving the response time request and heartbeat cycle, the external device 20 sends a response to the connection management unit 122 according to a fixed heartbeat cycle within a specified response time (e.g., 1ms to 100s). If a response is not sent within the set response time, it is considered a timeout (i.e., the external device 20 has not met the response conditions) and is determined to be an illegitimate device. Alternatively, if the heartbeat is not sent within the specified response time according to the specified cycle, it is also considered an illegitimate device. If it is determined to be an illegitimate device, the connection management unit 122 sends a disconnect command to the electronic fuse 121 to initiate a strategy to disconnect the external device 20 from the vehicle 10.

[0088] Therefore, in the implementation of this application, the connection management unit 122 and the external device 20 can use either one of the following methods for authentication: encryption and decryption confirmation based on symmetric keys or authentication through an active heartbeat establishment request. Of course, dual authentication can also be performed based on both methods.

[0089] Furthermore, in another implementation of this application, the interactive management system further includes a cloud server 40, which establishes a communication connection with the connection management unit 122, wherein the communication connection can be a wireless communication connection based on 4G, 5G, or other methods.

[0090] The connection management unit 122 is also used to generate alarm information and fault codes when the external device 20 is not an authorized device, to present the alarm information, and to send the fault codes to the cloud server 40.

[0091] Cloud server 40 is used to store fault codes.

[0092] For example, when the external device 20 is an illegitimate device, the connection management unit 122 generates an alarm message to notify the user that the currently connected device is illegitimate. Specifically, the alarm message could be a voice prompt from the vehicle 10 saying "Illegitimate device access, security protection activated," or it could be displayed on the vehicle 10's central control screen or instrument panel, indicating "Illegitimate device access, security protection activated." Furthermore, the connection management unit 122 records the fault code of the illegitimate device access and uploads it to the cloud server 40. The cloud server 40 stores the fault code for future after-sales tracking and troubleshooting.

[0093] Furthermore, if the connection management unit 122 determines that an unauthorized device has been removed from the external interface 110 (i.e., the external device and the vehicle are disconnected from power), the connection management unit 122 monitors the abnormal contact, performs self-recovery from the abnormality, clears the alarm information, and removes the local fault code. Clearing the alarm information may involve canceling the voice broadcast or canceling the display.

[0094] In this way, when the connection management unit 122 detects an unauthorized device access, it will implement safety protection for the vehicle malfunction caused by the external device 20. When the overcurrent (i.e., overload) is restored or the unauthorized device is removed from the external interface 110, the connection management unit 122 will monitor the abnormality and control the electronic fuse 121 to achieve fault self-recovery, thereby reducing the vehicle failure rate and after-sales costs.

[0095] In the implementation method of this application, the fault code may include the device identification information of the external device, the timestamp information of the external device connection, etc.

[0096] Furthermore, in one implementation of this application, if the connection management unit 122 determines that the external device 20 is a legitimate device, it can display the current power consumption information of the external device 20 on the central control or instrument panel to assist the vehicle owner in managing the power consumption of the external device 20.

[0097] In one implementation of this application, the electronic fuse 121 includes a control terminal and an output terminal. The electronic fuse 121 is electrically connected to the power pin of the external interface 110 through the output terminal and electrically connected to the connection management unit 122 through the control terminal.

[0098] In one implementation of this application, the external device 20 includes a power supply pin, and the power supply pin of the external interface 110 is electrically connected to the power supply pin of the external device 20. That is, the power supply pin of the external device 20 interface is connected to the power supply pin of the external interface 110.

[0099] In another implementation of this application, the external interface 110 further includes at least one first CAN communication pin and at least one first Ethernet communication pin, and the external device 20 includes a power supply pin of the external device 20, as well as at least one second CAN communication pin and at least one second Ethernet communication pin. The power supply pin of the external interface 110 and the power supply pin of the external device 20 are electrically connected, the first CAN communication pin and the second CAN communication pin are electrically connected, and the first Ethernet communication pin and the second Ethernet communication pin are electrically connected.

[0100] For example, such as Figure 4As shown, taking the external interface 121 as an OBD interface as an example, the external device 20 currently communicates with the vehicle 10 (e.g., an intelligent electric vehicle) via the OBD interface in two ways: CAN communication and Ethernet communication. CAN communication uses pin 6 (e.g., to implement CAN_H communication) and pin 14 (e.g., to implement CAN_L communication) of the OBD interface (as an example of the first CAN communication pin). Ethernet communication uses pins of the OBD interface that are usually customized by the OEM, but the customization basically follows the scheme in ISO 13400-4, that is, using pins 3 (e.g., to implement Ethernet Rx+), 11 (e.g., to implement Ethernet Rx-), 12 (e.g., to implement Ethernet Tx+), and 13 (e.g., to implement Ethernet Tx-) of the OBD interface (as an example of the first Ethernet communication). Furthermore, pin 16 of the OBD interface (as an example of the power pin) serves as the power source to supply power to the external device 20.

[0101] Furthermore, pin 4 of the OBD interface is used as chassis ground (i.e., vehicle ground). Alternatively, pin 5 is used as chassis ground (i.e., signal ground). Of course, depending on the external device, the pin connections between the external device and the external interface may also differ.

[0102] This connection method may expose power supply capabilities to the outside, and could lead to data leaks due to illegal data attacks, indirectly affecting driving safety, posing security risks, and increasing the frequency of after-sales service. Therefore, it is necessary to manage and protect the connection between vehicle 10 and external device 20.

[0103] Furthermore, such as Figure 5 As shown, the interactive management system provided in this application includes an electronic fuse 121 that can be a smart power distribution eFuse, and a connection management unit 122 that can be a smart power distribution system. This system is used to determine whether an external device is a legitimate device, and when the external device is not a legitimate device, it sends a disconnect command to the smart power distribution eFuse so that the smart power distribution eFuse is in a disconnected state when it receives the disconnect command, thereby cutting off the electrical connection between the vehicle and the external device.

[0104] The external device (i.e., external device 20) is connected to the power pin 16 of the external interface 110 via a power pin. The output of the eFuse (as an example of electronic fuse 121) is connected to the power pin 16 of the external interface 110. The control terminal is connected to the intelligent power distribution system (as an example of connection management unit 122). The eFuse and the intelligent power distribution system are located inside the vehicle.

[0105] In user mode, when an external electrical device (such as external device 20) is connected to the OBD interface of vehicle 10 (as an example of external interface 110), if the load current between external interface 110 and external device 20 does not exceed (i.e., does not exceed) the safety preset range, the electronic fuse 121 remains connected. The intelligent power distribution system monitors the purported external device by sending and receiving messages to determine its legitimacy. Thus, based on the determination of whether the load current is within the safety preset range and whether external device 20 is a legitimate device, the power safety and communication security of external device 20 after it is connected to vehicle 10 can be ensured.

[0106] Furthermore, in this implementation, the maximum output power is selected based on the output capability of the intelligent power distribution system and the eFuse electronic fuse 121 to ensure that the intelligent power distribution system and the eFuse electronic fuse 121 can meet the power supply requirements of the vehicle to the external equipment 20.

[0107] Furthermore, this application also provides an interaction management method, which is applied to an interaction management system.

[0108] Specifically, when the load current between the external interface 110 and the external device 20 is within a preset current range and no disconnection command is received from the connection management unit 122, the electronic fuse 121 is in a connected state, so that the electrical connection between the vehicle 10 and the external device 20 is in a connected state. When the load current is not within the preset current range or a disconnection command is received from the connection management unit 122, the electronic fuse 121 is in a disconnected state, so that the electrical connection between the vehicle 10 and the external device 20 is in a disconnected state.

[0109] Furthermore, when the electronic fuse 121 is in a connected state, the connection management unit 122 determines whether to send a disconnect command to the electronic fuse 121 based on whether the external device 20 is a legitimate device. Specifically, the connection management unit 122 does not send a disconnect command to the electronic fuse 121 when the external device 20 is a legitimate device, and sends a disconnect command to the electronic fuse 121 when the external device 20 is not a legitimate device.

[0110] like Figure 6 As shown, in one implementation of this application, the interaction management method specifically includes the following steps.

[0111] S110, electronic fuse 121 determines whether the load current between external interface 110 and external device 20 is within the preset current range. If it is, step S120 is executed; if not, step S130 is executed.

[0112] S120, the electronic fuse 121 is in the connected state, so that the electrical connection between the vehicle 10 and the external device 20 is in the connected state.

[0113] S130, the electronic fuse 121 is in the open state, so that the electrical connection between the vehicle 10 and the external device 20 is disconnected.

[0114] S140, when the electronic fuse 121 is in the connected state, the connection management unit 122 determines whether the external device 20 is a legitimate device. If it is a legitimate device, step S150 is executed; if it is an illegitimate device, step S160 is executed.

[0115] S150, no disconnection command is sent to electronic fuse 121, so that electronic fuse 121 is in the connected state, so that the electrical connection between vehicle 10 and external device 20 is in the connected state.

[0116] S160, a disconnection command is sent to the electronic fuse 121 to put the electronic fuse 121 in an open state, so that the electrical connection between the vehicle 10 and the external device 20 is disconnected.

[0117] In one implementation of this application, when the vehicle 10 is in factory mode, the resistance value of the electronic fuse 121 is calibrated by software so that the electronic fuse 121 determines whether the load current between the external interface 110 and the external device 20 is within a preset current range based on the resistance value and the voltage value of the electronic fuse 121.

[0118] For example, when vehicle 10 is in factory mode, a safe current range (i.e., a preset current range) is predefined. When a valid device is connected to the OBD interface, the load current between the OBD interface and the valid device is measured by an external current detector under normal operating conditions. It is then determined whether the measured load current is within the predefined safe current range. If the load current is not within the predefined safe current range, the eFuse electronic fuse 121 is considered to be non-compliant. The current resistance value of the eFuse electronic fuse 121 needs to be dynamically calibrated to constrain the load current to be within the safe current range based on the current resistance value of the electronic fuse 121.

[0119] In this implementation, the resistance value of the eFuse electronic fuse 121 can be calibrated to constrain the load current to a safe current range based on the resistance value of the electronic fuse 121 and the voltage value through the electronic fuse 121.

[0120] Furthermore, in this implementation, when the user installs an OBD external device (i.e., external device 20), the eFuse electronic fuse 121 first determines the load current between the external device 20 and the external interface 110. If the load current does not exceed a preset current range, the electronic fuse 121 remains connected, ensuring the electrical connection between the vehicle 10 and the external device 20 is established. If the load current is not within the preset current range, the electronic fuse 121 is disconnected, ensuring the electrical connection between the vehicle 10 and the external device 20 is broken. This enables active control of the power output from the vehicle 10 to the external device 20 via the OBD external interface 110.

[0121] Furthermore, in the implementation of this application, when the electronic fuse 121 is in a connected state (i.e., when the load current is within a preset current range), the connection management unit 122 determines whether the external device 20 is a legitimate device. If the external device 20 is a legitimate device, it does not send a disconnect command to the electronic fuse 121, so that the electronic fuse 121 remains in a connected state, thereby keeping the electrical connection between the vehicle 10 and the external device 20 connected. If the external device 20 is not a legitimate device, it sends a disconnect command to the electronic fuse 121, so that the electronic fuse 121 is in a disconnected state, thereby keeping the electrical connection between the vehicle 10 and the external device 20 disconnected.

[0122] Furthermore, in one implementation of this application, the connection management unit 122 determines whether the external device 20 is a legitimate device by using symmetric key encryption and decryption to determine the legitimacy of the external device 20. This avoids vehicle security issues caused by illegitimate devices writing malicious data into the vehicle ECU, and also avoids user data security and privacy leaks caused by illegitimate devices maliciously reading vehicle data.

[0123] For example, such as Figure 7 As shown, the connection management unit 122 determines whether the external device 20 is a legitimate device by the following steps.

[0124] S210, the connection management unit 122 determines the device identification information of the external device 20 and sends an authentication request containing the device identification information and the vehicle identification information to the authentication server 30.

[0125] For example, preparation and initialization are performed first. In a secure environment, the authentication server 30 generates a second key corresponding to the connection management unit 122 (i.e., the master device) and a first key corresponding to the external device 20 (i.e., the slave device). This key will be used for encryption and decryption authentication during communication between the connection management unit 122 (e.g., a smart power distribution system) and the external device 20, as well as between the connection management unit 122, the external device 20, and the authentication server 30. The first and second keys can be sent in advance to the corresponding connection management unit 122 and external device 20. Alternatively, when authentication is required, the first and second keys can be sent to the connection management unit 122 first, and then the connection management unit 122 will send the first key of the external device 20 to the external device 20.

[0126] The first key and the second key can be either symmetric or asymmetric keys. If they are symmetric keys, the authentication server 30 can send the symmetric keys to the connection management unit 122 and the external device 20 in advance, or it can send the symmetric keys to the connection management unit 122 first when authentication is required, and then the connection management unit 122 will send the symmetric keys to the external device 20.

[0127] Furthermore, the authentication server 30 is communicatively connected to the connection management unit 122, receives vehicle identification information (such as vehicle VIN code) sent by the connection management unit 122, performs identity registration, and stores the relevant information of the connection management unit 122 in the authentication server 30.

[0128] After the external device 20 and the vehicle establish an electrical connection through the vehicle's external interface 110, the external device 20 sends an association request to the connection management unit 122. The association request carries its own unique identifier (i.e., device identification information) and other information. The connection management unit 122 verifies the association request of the external device 20. If it meets the requirements, it accepts the association and records the device identification information of the external device 20 locally.

[0129] S220, the authentication server 30 generates a first random code based on the authentication request and sends it to the connection management unit 122.

[0130] Furthermore, the connection management unit 122 sends an authentication request to the authentication server 30, which includes its own vehicle identification information and the device identification information of the external device 20. If the authentication server 30 determines that it has stored the relevant information of the connection management unit 122, it generates a random challenge code (as an example of the first random code) and sends it to the connection management unit 122.

[0131] S230, the connection management unit 122 sends the first random code to the external device 20.

[0132] For example, the connection management unit 122 forwards the first random code received from the authentication server 30 to the associated external device 20.

[0133] S240, external device 20 determines the first key, generates first authentication information based on the first key and the first random code, and sends the first authentication information to connection management unit 122.

[0134] For example, the external device 20 uses a pre-configured or first key sent by the connection management unit 122 to encrypt the first random code, and sends the encrypted response information (i.e., the first authentication information) back to the connection management unit 122.

[0135] S250, the connection management unit 122 determines the second key, generates the second authentication information based on the second key and the first random code, and sends the first authentication information and the second authentication information to the authentication server 30.

[0136] For example, the connection management unit 122 collects the encryption response information of the external device 20, and encrypts the first data code based on the second key to obtain the encryption response information (i.e. the second authentication information), and sends the first authentication information and the second authentication information together to the authentication server 30.

[0137] S260, the authentication server 30 determines the second random code based on the first authentication information and the first key, and determines the third random code based on the second authentication information and the second key. Based on the first random code, the second random code and the third random code, it generates the legitimacy authentication result of the external device 20 and sends the legitimacy authentication result to the connection management unit 122.

[0138] The authentication server 30 uses the first key to decrypt the first authentication information to obtain a second random code, and uses the second key to decrypt the second authentication information to obtain a third random code. Based on the decrypted second and third random codes and the pre-generated first random code, it generates a validity authentication result and sends the validity authentication result to the connection management unit 122. If the decrypted second and third random codes match the pre-generated first random code, the validity authentication result is considered successful; otherwise, the validity authentication result is considered unsuccessful.

[0139] In this implementation, if the first key and the second key are symmetric keys, the authentication server 30 uses the symmetric key to decrypt the first authentication information to obtain the second random code, and uses the symmetric key to decrypt the second authentication information to obtain the third random code.

[0140] S270, if the connection management unit 122 determines that the authentication result is successful, then the external device 20 is determined to be a legitimate device; if the authentication result is unsuccessful, then the external device 20 is determined to be an illegitimate device.

[0141] For example, if the connection management unit 122 determines that the authentication is successful, it determines that the external device 20 is a legitimate device, controls the electronic fuse 121 to be in a connected state, and allows the external device 20 to access protected resources or perform specific operations. If the authentication is unsuccessful, it determines that the external device 20 is an illegitimate device, rejects the access request of the external device 20, and takes appropriate security measures (e.g., controls the electronic fuse 121 to be in a disconnected state).

[0142] Furthermore, in another implementation of this application, taking the first key and the second key as symmetric keys as an example, the authentication server 30 can directly perform legitimacy authentication with the external device 20.

[0143] Specifically, the authentication server 30 first generates a symmetric key in a secure environment and distributes it to legitimate devices. Legitimate devices register and store the key. When an external device 20 requests authentication from the connection management unit 122, the authentication server 30 generates a random challenge value (i.e., a first random code) and sends it to the external device 20. The external device 20 encrypts the random challenge value using its stored symmetric key and generates authentication information as a response, which it sends back to the authentication server 30. The authentication server 30 decrypts the response (i.e., decrypts the authentication information) using the same symmetric key to obtain a challenge code (i.e., a second random code). If the decrypted challenge code matches the generated challenge value, authentication is successful, and the server sends a successful authentication (i.e., authentication passed) result to the connection management unit 122, allowing the external device 20 to access resources or perform operations. Otherwise, if authentication fails, the server sends a failed authentication (i.e., authentication not passed) result to the connection management unit 122 to take security measures (e.g., controlling the electronic fuse 121 to be in an open state).

[0144] Furthermore, in another implementation of this application, the validity of the external device 20 can be determined based on an active heartbeat request. For example... Figure 8 As shown, the connection management unit 122 determines whether the external device 20 is a legitimate device by the following steps.

[0145] S310, the connection management unit 122 determines the response conditions and sends the response conditions to the external device 20.

[0146] For example, the connection management unit 122 determines the response conditions, which may specifically include a response time request (e.g., a timeout mechanism for receiving a response within a specified time) and heartbeat cycle activation. For example, the connection management unit 122 requests to send a request command to the external device 20 with a heartbeat cycle of any time value such as 10s or 20s.

[0147] S320, external device 20 sends a response to connection management unit 122 according to the response conditions.

[0148] For example, after receiving the response time request and heartbeat cycle, the external device 20 sends a response to the connection management unit 122 within a specified response time (e.g., 1ms to 100s) according to a fixed heartbeat cycle.

[0149] S330, if the connection management unit 122 determines that the external device 20 is a legitimate device if the response meets the response conditions, and determines that the external device 20 is an illegitimate device if the response does not meet the response conditions.

[0150] For example, if external device 20 fails to send a response within the set response time, the connection management unit 122 considers it a timeout (i.e., external device 20 has not met the response conditions) and determines it to be an illegitimate device. Alternatively, if external device 20 fails to send a heartbeat within the specified response time according to the specified cycle, the connection management unit 122 also determines that external device 20 is an illegitimate device. If determined to be an illegitimate device, the connection management unit 122 sends a disconnect command to the electronic fuse 121 to initiate the strategy of disconnecting external device 20 from vehicle 10.

[0151] Furthermore, in another implementation of this application, if the external device 20 is not a legitimate device, the connection management unit 122 generates alarm information and fault codes, presents the alarm information, and sends the fault codes to the cloud server 40.

[0152] For example, when the external device 20 is an illegitimate device, the connection management unit 122 generates an alarm message to notify the user that the currently connected device is illegitimate. Specifically, the alarm message may be a voice prompt from the vehicle saying "Illegitimate device access, security protection activated," or it may be displayed on the central control panel or instrument panel, indicating "Illegitimate device access, security protection activated." Furthermore, the connection management unit 122 records the fault code of the illegitimate device access and uploads it to the cloud server 40. The cloud server 40 stores the fault code for future after-sales tracking and troubleshooting.

[0153] Furthermore, in another implementation of this application, if the external device 20 is a legitimate device, the connection management unit 122 determines the power consumption information of the external device 20 and presents the power consumption information of the external device 20.

[0154] For example, if the connection management unit 122 determines that the external device 20 is a legitimate device, it can display the current power consumption information of the external device 20 on the central control or instrument panel to assist the vehicle owner in managing the power consumption of the external device 20.

[0155] The interactive management method provided in this application uses an electronic fuse 121 to determine whether the load current between the external device 20 and the external interface 110 is within a preset safe current range (i.e., a preset current range). Furthermore, the OBD intelligent power distribution system (i.e., the connection management unit 122) performs authentication between the external device and the OBD external interface 110 using encryption and decryption methods such as symmetric keys. This achieves the authentication of the external device 20 and enables active control of the vehicle's power output to the external device 20 via the OBD interface. Moreover, based on the electronic fuse 121 and the connection management unit 122, it provides basic support for subsequent value-added services such as external devices provided by the vehicle.

[0156] Furthermore, such as Figure 9 As shown, the interactive management method provided in this application for managing the connection between a vehicle and external devices specifically includes the following steps.

[0157] 1. Predefined safe current range.

[0158] For example, when the vehicle is in factory mode, the safe current range (i.e., the preset current range) when the external interface 110 is connected to the external device 20 is predefined.

[0159] 2. In factory mode, connect a valid device to the OBD interface and measure the load current under normal operating conditions.

[0160] For example, when an OBD interface is connected to a legitimate device, the load current between the OBD interface and the external legitimate device is measured by an external current sensor under normal operating conditions.

[0161] 3. Determine whether the currently measured load current is within the predefined safe range.

[0162] For example, determine whether the currently measured load current is within the predefined safe current range.

[0163] 4. If the current is not within the predefined safe range, the eFuse is considered to be non-compliant and the current eFuse resistance value needs to be dynamically calibrated to ensure that the load current is within the safe range.

[0164] For example, if the load current is not within the predefined safe range, the eFuse electronic fuse 121 is considered to be non-compliant, and the current resistance value of the current eFuse electronic fuse 121 needs to be dynamically calibrated so that the load current is constrained to be within the safe current range based on the current resistance value of the electronic fuse 121.

[0165] 5. In user mode, the user connects to an external OBD device.

[0166] 6. After the OBD device is connected to an external device, it checks whether the load current exceeds the predefined safety range to prevent the external device from causing a short circuit. If it does not exceed the predefined safety range, proceed to step 8; if it exceeds the predefined safety range, proceed to step 7.

[0167] For example, when a user installs an OBD external device (i.e., external device 20), the user first uses the eFuse electronic fuse 121 to determine the magnitude of the load current between the external device 20 and the external interface 110.

[0168] 7. If the load current exceeds the safe current range, eFuse will cut off the power supply to the OBD circuit.

[0169] For example, if the load current is not within the preset current range, the electronic fuse 121 is in the open state, so that the electrical connection between the vehicle 10 and the external device 20 is disconnected.

[0170] 8. The OBD intelligent power distribution system and external devices connected to the OBD port use symmetric key encryption and decryption for confirmation or active addressing to determine the legitimate device through active heartbeat establishment requests.

[0171] 9. Verify the device's legitimacy by checking if the keys match. If the device is legitimate, proceed to step 11; otherwise, proceed to step 10.

[0172] For example, if the load current does not exceed the preset current range, the electronic fuse 121 remains connected so that the electrical connection between the vehicle 10 and the external device 20 is connected. Furthermore, the connection management unit 122 determines whether the external device 20 is a legitimate device when the electronic fuse 121 is connected (i.e., when the load current is within the preset current range).

[0173] 10. The illegal device's OBD intelligent power distribution (eFuse electronic fuse 121) actively cuts off the power supply.

[0174] For example, if the external device 20 is not a legitimate device, a disconnect command is sent to the electronic fuse 121 to control the electronic fuse 121 to be in an open state, so that the electrical connection between the vehicle 10 and the external device 20 is disconnected.

[0175] 11. Legitimate equipment is powered and communicating normally.

[0176] For example, if the external device 20 is a legitimate device, no disconnection command is sent to the electronic fuse 121 to control the electronic fuse 121 to remain in the connected state so that the electrical connection between the vehicle 10 and the external device 20 remains connected.

[0177] 12. Unplug the OBD connection device.

[0178] For example, external device 20 is unplugged.

[0179] 13. After the abnormality monitoring of the OBD intelligent power distribution system is resolved, the OBD intelligent power distribution (eFuse electronic fuse 121) will automatically recover.

[0180] For example, if the electronic fuse 121 determines that the load current is within a preset current range, it performs self-reset to restore the electrical connection between the vehicle and the external device 20. Alternatively, when the connection management unit 122 determines that the device is a legitimate device, it sends a connection command to the electronic fuse 121 to control the electronic fuse 121 to re-enter the connection state, so that the electrical connection between the vehicle 10 and the external device 20 is restored.

[0181] The interactive management system and method provided in this application are essentially an intelligent monitoring and control system and method for connecting external devices to the vehicle's OBD interface. It can be applied to vehicles equipped with an OBD intelligent power distribution system (i.e., a vehicle connection management system) using an eFuse electronic fuse. The OBD intelligent power distribution system monitors the power-on status of external devices connected to the OBD interface and provides circuit protection. When an external device is connected to the OBD interface, the intelligent power distribution (eFuse electronic fuse) monitors the load current of the OBD interface to determine if the current is within the safe preset current range for legitimate devices. It performs overcurrent and short-circuit anomaly detection on the external device and takes safety precautions. Simultaneously, through symmetric key encryption and decryption between the OBD intelligent power distribution system (i.e., the connection management unit) and the external device connected to the OBD port, it achieves secure, effective, and legitimate access monitoring of the external device and controls power-on / off, preventing security issues caused by data leakage.

[0182] This application also provides a chip for executing instructions, which is used to execute the technical solution of the interactive management method in the above embodiments.

[0183] This application also provides a computer-readable storage medium storing computer instructions. When the computer instructions are executed on the processor of an electronic device, the processor of the electronic device performs the technical solution of the interactive management method described in the above embodiments.

[0184] This application also provides a computer program product, which includes a computer program stored in a computer-readable storage medium. At least one processor can read the computer program from the computer-readable storage medium, and when the at least one processor executes the computer program, it can implement the technical solution of the interactive management method in the above embodiments.

[0185] This application is described with reference to flowchart illustrations and / or block diagrams of the methods, apparatus, and computer program products according to this application. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable information processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable information processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0186] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable information processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0187] These computer program instructions may also be loaded onto a computer or other programmable information processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0188] The terms “first”, “second”, etc., are used only to distinguish descriptions and should not be interpreted as indicating or implying relative importance.

[0189] In the description of this embodiment, it should also be noted that, unless otherwise explicitly specified and limited, the terms "set up," "connected," and "linked" should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral connection; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; and they can refer to the internal connection of two components. Those skilled in the art can understand the specific meaning of the above terms in this embodiment based on the specific circumstances.

[0190] Other embodiments of this application will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein.

[0191] It should be noted that, in addition to the specific embodiments described above, those skilled in the art can easily understand other advantages and effects of this application from the content disclosed in this specification. Although the description of this application is presented in conjunction with preferred embodiments, this does not mean that the features of this invention are limited to this implementation. On the contrary, the purpose of describing the invention in conjunction with the implementation is to cover other options or modifications that may be derived based on the claims of this application. To provide a thorough understanding of this application, many specific details are included in the above description, and this application may also be implemented without using these details. Furthermore, to avoid confusion or obscuring the focus of this application, some specific details will be omitted in the description. It should be noted that, unless otherwise specified, the embodiments and features in the embodiments of this application can be combined with each other.

[0192] It should be noted that in this specification, similar reference numerals and letters in the following figures indicate similar items. Therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures.

[0193] Although this application has been illustrated and described with reference to certain preferred embodiments, those skilled in the art should understand that the above description is a further detailed explanation of the application in conjunction with specific implementations, and should not be construed as limiting the specific implementation of the application to these descriptions. Those skilled in the art can make various changes in form and detail, including some simple deductions or substitutions, without departing from the spirit and scope of this application.

Claims

1. A vehicle connection management system, characterized by, The vehicle comprises an external interface through which the vehicle establishes an electrical connection with an external device, and the vehicle connection management system comprises an electronic fuse and a connection management unit, the electronic fuse is electrically connected with a power pin of the external interface and the connection management unit respectively, The electronic fuse is in a connected state when a load current between the external interface and the external device is within a preset current range and no disconnection instruction is received from the connection management unit, so that the electrical connection between the vehicle and the external device is in a connected state, and the electronic fuse is in a disconnected state when the load current is not within the preset current range or the disconnection instruction is received from the connection management unit, so that the electrical connection between the vehicle and the external device is in a disconnected state; The connection management unit is configured to determine whether to send the disconnection instruction to the electronic fuse according to whether the external device is a legal device when the electronic fuse is in the connected state, wherein the connection management unit does not send the disconnection instruction to the electronic fuse when the external device is the legal device, and sends the disconnection instruction to the electronic fuse when the external device is not the legal device.

2. The vehicle connection management system of claim 1, wherein, The electronic fuse comprises a control end and an output end, the electronic fuse is electrically connected with the power pin of the external interface through the output end and is electrically connected with the connection management unit through the control end.

3. The vehicle connection management system of claim 1 or 2, wherein, The external interface is an on-board diagnostic system interface.

4. A vehicle characterized by comprising: The vehicle comprises an external interface through which the vehicle establishes an electrical connection with an external device, and the vehicle further comprises the vehicle connection management system according to any one of claims 1-3.

5. An interaction management system, characterized by The vehicle and the external device, the vehicle comprises an external interface through which the vehicle establishes an electrical connection with the external device, and the vehicle further comprises a vehicle connection management system, the vehicle connection management system comprises an electronic fuse and a connection management unit, the electronic fuse is electrically connected with a power pin of the external interface and the connection management unit respectively, The electronic fuse is in a connected state when a load current between the external interface and the external device is within a preset current range and no disconnection instruction is received from the connection management unit, so that the electrical connection between the vehicle and the external device is in a connected state, and the electronic fuse is in a disconnected state when the load current is not within the preset current range or the disconnection instruction is received from the connection management unit, so that the electrical connection between the vehicle and the external device is in a disconnected state; The connection management unit is configured to determine whether to send the disconnection instruction to the electronic fuse according to whether the external device is a legal device when the electronic fuse is in a connected state, wherein the connection management unit does not send the disconnection instruction to the electronic fuse when the external device is the legal device, and sends the disconnection instruction to the electronic fuse when the external device is not the legal device.

6. The interaction management system of claim 5, wherein, The interaction management system further comprises an authentication server in communication connection with the connection management unit, wherein The authentication server is configured to generate a legality authentication result of the external device, and send the legality authentication result to the connection management unit, so that the connection management unit determines whether the external device is the legal device based on the legality authentication result.

7. The interaction management system of claim 5 or 6, wherein, The interaction management system further comprises a cloud server in communication connection with the connection management unit, wherein The connection management unit is further configured to generate an alarm information and a fault code when the external device is not the legal device, present the alarm information, and send the fault code to the cloud server; The cloud server is configured to store the fault code.

8. The interaction management system of any of claims 5-7, wherein, The electronic fuse comprises a control end and an output end, and the electronic fuse is electrically connected with the power pin of the external interface through the output end and electrically connected with the connection management unit through the control end.

9. The interaction management system according to any one of claims 5-8, wherein The external device comprises a power pin of the external device, and the power pin of the external interface is electrically connected with the power pin of the external device; or The external interface further comprises at least one first CAN communication pin and at least one first Ethernet communication pin, and the external device comprises a power pin of the external device, at least one second CAN communication pin and at least one second Ethernet communication pin, the power pin of the external interface is electrically connected with the power pin of the external device, the first CAN communication pin is electrically connected with the second CAN communication pin, and the first Ethernet communication pin is electrically connected with the second Ethernet communication pin.

10. An interaction management method, characterized by, The method is applied to an interaction management system, the interaction management system comprising a vehicle and an external device, the vehicle comprising an external interface, the vehicle being electrically connected with the external device through the external interface, the vehicle further comprising a vehicle connection management system, the vehicle connection management system comprising an electronic fuse and a connection management unit, the electronic fuse being electrically connected with a power pin of the external interface and the connection management unit respectively, The electronic fuse is in a connected state when the load current between the external interface and the external device is in a preset current range and no disconnection instruction is received from the connection management unit, so as to keep the electrical connection between the vehicle and the external device in a connected state; and the electronic fuse is in a disconnected state when the load current is not in the preset current range or the disconnection instruction is received from the connection management unit, so as to keep the electrical connection between the vehicle and the external device in a disconnected state. The connection management unit determines whether to send the disconnection instruction to the electronic fuse according to whether the external device is a legal device when the electronic fuse is in the connected state, wherein the connection management unit does not send the disconnection instruction to the electronic fuse when the external device is the legal device, and sends the disconnection instruction to the electronic fuse when the external device is not the legal device.

11. The interaction management method of claim 10, wherein, The interaction management system further comprises an authentication server, and the method further comprises that the connection management unit determines whether the external device is the legal device by the following manner: The connection management unit determines device identification information of the external device, and sends an authentication request comprising the device identification information and vehicle identification information of the vehicle to the authentication server; The authentication server generates a first random code according to the authentication request and sends the first random code to the connection management unit; The connection management unit sends the first random code to the external device; The external device determines a first key, generates first authentication information according to the first key and the first random code, and sends the first authentication information to the connection management unit; The connection management unit determines a second key, generates second authentication information according to the second key and the first random code, and sends the first authentication information and the second authentication information to the authentication server; The authentication server determines a second random code according to the first authentication information and the first key, and determines a third random code according to the second authentication information and the second key, generates a legality authentication result of the external device according to the first random code, the second random code and the third random code, and sends the legality authentication result to the connection management unit; The connection management unit determines that the external device is the legal device when the legality authentication result is authentication passed, and determines that the external device is not the legal device when the legality authentication result is authentication failed.

12. The interaction management method of claim 10, wherein, The method further comprises that the connection management unit determines whether the external device is the legal device by the following manner: The connection management unit determines a response condition, and sends the response condition to the external device; The external device sends a response to the connection management unit according to the response condition. The connection management unit determines that the external device is the legal device if the response response satisfies the response condition, and determines that the external device is not the legal device if the response response does not satisfy the response condition.

13. The interaction management method according to any of claims 11-12, characterized by, If the external device is the legal device, the method further comprises: The connection management unit determines the power consumption information of the external device, and presents the power consumption information of the external device.

14. The interaction management method according to any one of claims 10 to 13, characterized in that, The interaction management system further comprises a cloud server, and if the external device is not the legal device, the method further comprises: The connection management unit generates alarm information and a fault code, presents the alarm information, and sends the fault code to the cloud server.

15. The interaction management method according to any one of claims 10 to 14, characterized in that, If the vehicle is in a factory mode, the method further comprises: The current resistance value of the electronic fuse is calibrated based on software, so that the electronic fuse determines whether the load current between the external interface and the external device is within the preset current range according to the current resistance value.