New energy vehicle high-voltage safety protection method and system based on multistage linkage power failure
By employing a multi-level linkage power-off method, combined with multi-source data fusion and fault level judgment, the actuator is driven to precisely cut off power, solving the problem of easy paralysis of high-voltage systems in new energy vehicles. This achieves fast and reliable high-voltage electrical safety protection and improves reliability and safety under extreme operating conditions.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-01-06
- Publication Date
- 2026-04-07
AI Technical Summary
In existing technologies, high-voltage systems in new energy vehicles are prone to vehicle failure due to single-point mis-triggering. Single fault diagnosis logic has high response delay, cannot distinguish fault levels, and lacks the ability to isolate local faults, which may expand the scope of the accident's impact.
A multi-level linkage power-off method is adopted. By fusing multi-source data and comparing thresholds, combined with fault codes and timestamps recorded by fault latch memory, the fault level is judged and the actuator is driven to perform corresponding power-off operations, including early warning, partial power-off and global power-off. The CAN bus and hard-wired backup circuit are used to achieve fast and accurate high-voltage safety protection.
It achieves rapid full-domain power outage from minor anomalies to serious faults, improving the reliability and occupant safety of new energy vehicles under extreme conditions, covering 99.99% of extreme scenarios. Under a level 2 fault, the vehicle can still drive away from the danger zone at low speed. The dual-channel redundancy design has passed ASIL-D certification.
Smart Images

Figure CN121799170A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of high-voltage electrical safety technology for new energy vehicles, and in particular to a method and system for high-voltage electrical safety protection of new energy vehicles based on multi-level linkage power outage. Background Technology
[0002] While new energy vehicles offer cleaner transportation, the safety issues of their high-voltage systems cannot be ignored. High-voltage electricity plays a crucial role in vehicle propulsion and energy management; any abnormality can endanger the safety of the driver, passengers, and even on-site rescue personnel. Therefore, a systematic understanding of high-voltage components, mastering correct usage and maintenance methods, and understanding emergency response procedures are fundamental to ensuring safe daily use. Traditional high-voltage power-off solutions are often all-or-nothing, such as immediately disconnecting the main contactor after a collision, which can easily lead to vehicle paralysis due to single-point mis-triggering. Single-fault diagnostic logic has high response delays and cannot distinguish fault levels. The lack of ability to isolate localized faults may expand the scope of an accident's impact.
[0003] Prior art 1, Chinese Patent Application No. 202510136160.7, discloses a circuit and method for improving the robustness of high voltage in new energy vehicles. The circuit includes a high-voltage circuit, the components of which include a pre-charge relay K1, a main positive relay K2, a main negative relay K3, a DC charging positive relay K4, a DC charging negative relay K5, a fuse FUSE, a high-voltage sampling point BAT+ at the positive terminal of the battery pack, a high-voltage sampling point FUSE+ at the rear end of the fuse, a high-voltage sampling point PRE+ at the rear end of the main positive relay, and a high-voltage sampling point BAT at the negative terminal of the battery pack. Rly, the main negative circuit detection point , main and negative high voltage sampling point PRE The system includes a pre-charge resistor, a main negative circuit voltage divider resistor, a Hall sensor, a ignition switch (PSS), and a shunt. While the inputs effectively prevent false alarms that could cause the vehicle to enter an over-protection state, resulting in abnormal high-voltage drops or failures to apply high voltage, thus providing an unpleasant experience for the driver, it lacks multi-source real-time monitoring. It does not continuously collect key parameters such as insulation resistance, impact shock, temperature, and pressure; it lacks fault classification and corresponding execution command sets; and it lacks integration with the vehicle control network.
[0004] Prior art two, Chinese patent application number 201711064765.1, discloses a high-voltage, high-power power supply discharge device, including an auxiliary power supply, a control switch, a switching circuit, and a bleeder resistor. One end of the control switch is connected to the auxiliary power supply, and the other end is connected to the switching circuit, controlling the switching circuit's conduction and cutoff via voltage changes in the auxiliary power supply. One end of the bleeder resistor is connected to the positive terminal of the busbar, and the other end is connected to the negative terminal of the busbar through the switching circuit. When the switching circuit is on, the bleeder resistor is connected in parallel with the busbar, releasing the high voltage on the power busbar; when the switching circuit is off, the bleeder resistor is disconnected from the busbar. Although this device can safely and quickly discharge the high voltage on the busbar when the high-voltage, high-power power supply is de-energized and automatically cut off the discharge circuit when the high-voltage, high-power power supply is restored, without affecting the normal operation of the high-voltage, high-power power supply, it lacks fault classification and response, is not integrated with the vehicle communication network, lacks redundant safety measures, and its response time does not meet extreme safety requirements.
[0005] Current technologies 1 and 2 suffer from several drawbacks: traditional high-voltage power-off schemes are prone to causing vehicle paralysis due to single-point false triggering; single fault diagnosis logic has high response delay and cannot distinguish fault levels; and they lack the ability to isolate local faults, potentially expanding the scope of the accident's impact. Therefore, this invention provides a method and system for high-voltage electrical safety protection of new energy vehicles based on multi-level linkage power-off. Summary of the Invention
[0006] To achieve the above objectives, the present invention adopts the following technical solution: One aspect of the present invention provides a method for high-voltage electrical safety protection of new energy vehicles based on multi-level linkage power-off, comprising the following steps: The raw data stream is processed by a multi-level diagnostic center. Through multi-source data fusion and threshold comparison, combined with fault codes and timestamps recorded by the fault latch memory, the fault level is determined. The fault level is determined to generate an execution command, which drives the actuator to perform the corresponding power-off operation. In the case of a Level 1 fault, a warning and power limitation are implemented: a command is sent via the CAN bus to limit the motor power to 70% and trigger a yellow alarm on the instrument panel; in the case of a Level 2 fault, a partial power cut is implemented: the corresponding branch contactor is disconnected and the 12V backup power supply is activated; in the case of a Level 3 fault, a full power cut is implemented: an emergency CAN signal is broadcast, the main positive and negative contactors are disconnected, and if the voltage does not drop below 60V within 10ms, the blast fuse is detonated and the vehicle rescue system is triggered; if the electronic channel fails, the hard-wired backup circuit directly triggers a Level 3 power cut.
[0007] In one optional implementation, the process of determining the fault level includes the following steps: The similarity between the real-time risk feature vector and the historical fault patterns recorded in the fault latch memory is calculated to generate a matching coefficient between each fault pattern and the current state; at the same time, the frequency and time distribution features of the corresponding fault codes in the fault latch memory are extracted to form a historical fault activity index; and a preliminary fault identifier with matching weight and historical fault activity index is output. By combining the initial fault identification with the timestamp information in the fault latch memory, a time series correlation matrix of fault parameters is constructed to analyze the temporal dependencies and fault evolution trends among the fault parameters. By calculating the cumulative change rate and mutual influence coefficient of the fault parameters, the possible paths and speeds of fault development are deduced. The severity projection results, which include the fault evolution trend and the expected fault development speed, are output. The severity projection results are dynamically adjusted based on historical data of similar faults recorded in the fault latch memory and the current system operating status. The judgment thresholds for each fault level are dynamically adjusted. At the same time, the real-time severity and historical statistical characteristics of the fault are considered, and the comprehensive evaluation results are mapped to specific fault levels through multi-dimensional weight allocation. The fault level judgment is output after verification by historical data and dynamic calibration.
[0008] In one optional implementation, the process of driving the actuator to perform a corresponding power-off operation includes the following steps: Based on the fault level, determine the set of target actuators that need to be operated. Combine the real-time status of each actuator to generate a complete blueprint of execution instruction sequence containing the operation object, action sequence and time node; output a primary execution instruction sequence containing complete timing logic. The primary execution instruction sequence is tested for communication status and load capacity of the main execution channel, and the primary execution instruction sequence is dynamically adjusted according to the test results. When the main channel is unobstructed, the packaging and sending strategy of the primary execution instructions is optimized. When channel delay or blockage is detected, a backup path is activated and the transmission method and parameters of the primary execution instructions are adjusted accordingly. The executable instruction set optimized for channel adaptability is output. The executable instruction set is converted into the physical drive signals required by the corresponding actuator, including the drive current of the contactor coil and the pulse parameters of the fuse ignition signal. After each physical drive signal is issued, the actuator status feedback loop is used to confirm whether the action has been successfully executed and to record the final execution status. The physical signal sequence that drives the actuator to complete the corresponding power-off operation and its execution confirmation result are output.
[0009] In one optional implementation, the process of converting an executable instruction set into the physical drive signals required by the corresponding actuator includes the following steps: Based on the target actuator type specified in the executable instruction, query its inherent electrical characteristic parameter library, map the abstract logical instruction to specific physical drive waveform parameters, and output the drive instruction sequence with waveform parameters attached. Based on the real-time output capability of the system power supply and the physical response delay of the actuator, the issuance time, duration, and gain of each drive signal in the drive command sequence are finely adjusted; the amplified drive signal is output after time and power calibration. The amplified drive signal, after time and power calibration, is converted into the actual control level required by power devices such as high-side drivers and H-bridge circuits, generating a physical drive signal acting on the actuator. At the same time, a physical drive signal integrity monitoring loop samples the voltage and current waveforms actually output to the actuator in real time, compares them with the expected waveform parameters, and generates a signal integrity report.
[0010] In one alternative implementation, the process of mapping abstract logical instructions to specific physical drive waveform parameters includes the following steps: The logical identifiers in the executable instructions are decoded and converted into a unified type identifier that can be recognized by the internal actuator parameter library; at the same time, the existence and availability of the type identifier in the parameter library are verified. Based on the unified type identification code, the complete steady-state and transient electrical response characteristics of the corresponding actuator are retrieved from the inherent electrical characteristic parameter library of the actuator, which together constitute the electrical characteristic profile of the actuator; Based on the action state required by the original logic instruction, and combined with the boundary conditions and response procedures defined in the electrical characteristic profile, the specific drive waveform parameters that meet the action requirements and do not exceed the electrical tolerance range of the actuator are calculated.
[0011] In one optional implementation, the process of calculating specific drive waveform parameters that meet the action requirements and do not exceed the electrical tolerance range of the actuator includes the following steps: The target action required by the original logic instruction is deconstructed into several consecutive action stages, and the core electrical objectives to be achieved in each action stage are identified; for example, rapid engagement and stable holding in contactor drive; the key time nodes and required energy injection characteristics of each action stage are defined to obtain the action timing blueprint. Based on the steady-state and transient boundary conditions defined in the electrical characteristic profile, for each action stage in the action timing blueprint, the safe operating range of each waveform parameter within the action stage is calculated. The safe operating range constitutes a dynamically changing parameter boundary domain. Under the constraints of the parameter boundary domain, guided by the core electrical objectives of each action stage in the action timing blueprint, a multi-objective optimization strategy is adopted for numerical solution; a set of specific drive waveform parameters is synthesized.
[0012] In one optional implementation, the numerical solution process using a multi-objective optimization strategy includes the following steps: Based on the current security policy priority of the system, a quantitative weight coefficient is assigned to each core electrical target, resulting in a set of quantitative targets with weight coefficients; Within the multidimensional space defined by the dynamic parameter boundary domain, a systematic search is performed in the direction guided by the set of quantization targets, generating a series of exploration trajectories pointing to the optimal region. The exploration trajectories record the degree to which different combinations of driving waveform parameters achieve various quantization targets under the condition of satisfying constraints. Analyze the convergence trend of all exploration trajectories and identify those trajectory convergence points that achieve the best balance among multiple quantification objectives. Trajectory convergence points mean that further optimization of any single objective will come at the expense of other objectives, forming a Pareto optimal solution set for the multi-objective optimization problem. Select a set of specific driving waveform parameters suitable for the current working condition from the Pareto optimal solution set according to the preset decision rules.
[0013] In one alternative implementation, the process of identifying trajectory convergence points that achieve an optimal balance among multiple quantization objectives includes the following steps: For each candidate parameter point on the exploration trajectory, based on the measured or predicted values of its various performance indicators, the normalized achievement degree relative to each quantitative target is obtained, and the achievement degree is combined into a multi-dimensional vector, which is the multi-dimensional target achievement degree vector corresponding to each candidate parameter point. In a multidimensional space composed of multidimensional goal achievement vectors, the dominance relationships between points in the multidimensional space are obtained, and all non-dominated points that are not completely surpassed by other points are identified. The distribution density of non-dominated points in the vector space is analyzed, and points located in low-density regions with relatively balanced achievement in each dimension are selected to form a preliminary Pareto front. The result is a sparse and balanced Pareto optimal solution set. The sparsely distributed and balanced Pareto optimal solution set is used to comprehensively score each point in the Pareto optimal solution set according to a preset decision rule, such as the minimum achievement rule or the weighted sum rule based on weight coefficients; by comparing the comprehensive scores, a trajectory convergence point that achieves the best balance among multiple objectives is identified.
[0014] In one optional implementation, a sensor layer including a high-precision insulation monitor, a triaxial impact acceleration sensor, and a battery pack pressure sensor continuously collects high-voltage system parameters to form a raw data stream; the high-voltage system parameters include insulation resistance, impact acceleration, battery pack pressure, and temperature.
[0015] Another aspect of the present invention provides a high-voltage electric safety protection system for new energy vehicles based on the multi-level linkage power-off safety protection method for new energy vehicles, the high-voltage electric safety protection system for new energy vehicles based on the multi-level linkage power-off safety method for new energy vehicles comprising: The data stream acquisition module is used to continuously collect high-voltage system parameters from the sensor layer, including a high-precision insulation monitor, a triaxial impact acceleration sensor, and a battery pack pressure sensor, to form a raw data stream; the high-voltage system parameters include insulation resistance, impact acceleration, battery pack pressure, and temperature; The diagnostic central processing module is used to process the raw data stream through multiple levels of the diagnostic central processing, and obtain the fault level judgment by combining multi-source data fusion and threshold comparison with fault code and timestamp recorded by the fault latch memory; The power failure operation execution module is used to generate execution instructions based on the fault level and drive the actuator to perform the corresponding power failure operation. In the case of a Level 1 fault, a warning and power limitation are implemented: a command is sent via the CAN bus to limit the motor power to 70% and trigger a yellow alarm on the instrument panel; in the case of a Level 2 fault, a partial power cut is implemented: the corresponding branch contactor is disconnected and the 12V backup power supply is activated; in the case of a Level 3 fault, a full power cut is implemented: an emergency CAN signal is broadcast, the main positive and negative contactors are disconnected, and if the voltage does not drop below 60V within 10ms, the blast fuse is detonated and the vehicle rescue system is triggered; if the electronic channel fails, the hard-wired backup circuit directly triggers a Level 3 power cut.
[0016] This invention's multi-level linkage power-off protection method achieves end-to-end safety protection, from early warning of minor anomalies to rapid, full-domain power-off in response to serious faults, improving the reliability and occupant safety of new energy vehicles under extreme conditions such as collisions, overheating, and insulation failures. High-voltage power-off covers 99.99% of extreme scenarios (compliant with ISO 6469-3:2018); vehicles can still leave the danger zone at low speed under level-two faults; the dual-channel redundancy design is ASIL-D certified; and in the event of abnormal conditions such as vehicle collisions, insulation failures, or short circuits, a fast, accurate, and reliable high-voltage safety protection device is achieved through multi-level collaborative diagnosis and phased power-off. Attached Figure Description
[0017] The accompanying drawings are provided to further illustrate the invention and form part of the specification. They are used in conjunction with embodiments of the invention to explain the invention and do not constitute a limitation thereof. In the drawings: Figure 1 This is a flowchart of the high-voltage electric safety protection method for new energy vehicles based on multi-level linkage power outage provided in Embodiment 1 of the present invention; Figure 2This is a schematic diagram of the high-voltage electric safety protection method for new energy vehicles based on multi-level linkage power-off provided in Embodiment 1 of the present invention; Figure 3 This is a process diagram of forming the original data stream provided in Embodiment 3 of the present invention; Figure 4 This is a flowchart illustrating the process of obtaining the fault level determination provided in Embodiment 4 of the present invention; Figure 5 A process diagram showing the corresponding power-off operation performed on the drive actuator provided in Embodiment 7 of the present invention; Figure 6 This is a block diagram of the high-voltage electric safety protection system for new energy vehicles based on multi-level linkage power-off provided in Embodiment 6 of the present invention; Figure 7 A block diagram of the electronic device provided by the present invention; Figure 8 A block diagram of a computer-readable storage medium provided for this invention. Detailed Implementation
[0018] The technical solutions of the present invention will now be described with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments.
[0019] Hereinafter, the terms "first," "second," etc., are used for descriptive convenience only and should not be construed as indicating or implying relative importance or implicitly specifying the number of indicated technical features. Thus, a feature defined with "first," "second," etc., may explicitly or implicitly include one or more of that feature. In the description of this invention, unless otherwise stated, "a plurality of" means two or more.
[0020] In this invention, unless otherwise explicitly specified and limited, the term "connection" should be interpreted broadly. For example, "connection" can be a fixed mechanical connection, a detachable mechanical connection, or an integral part; or, "connection" can be a direct connection or an indirect connection through an intermediate medium. Furthermore, unless otherwise explicitly specified and limited, the term "coupling" should be interpreted broadly. For example, "coupling" can be a direct electrical connection, such as physical contact and electrical conduction between two components; it can also be understood as an electrical connection between different components in a circuit structure through physical lines capable of transmitting electrical signals, such as copper foil or wires on a printed circuit board (PCB), to transmit electrical signals; or, "coupling" can be an indirect electrical connection between two components through an intermediate medium; or, "coupling" can be an electrical connection between two components in a non-contact manner, such as an electrical connection between two components using capacitive coupling to transmit electrical signals.
[0021] In this embodiment of the invention, directional terms such as "up," "down," "left," and "right" may be defined relative to the orientation of the components shown in the accompanying drawings. It should be understood that these directional terms can be relative concepts, used for relative description and clarification, and can change accordingly depending on the orientation of the components in the accompanying drawings.
[0022] Example 1: As Figure 1 As shown, this embodiment of the invention provides a method for high-voltage electrical safety protection of new energy vehicles based on multi-level linkage power outage, comprising the following steps: Step S100: The sensor layer, including a high-precision insulation monitor, a triaxial collision acceleration sensor, a battery pack pressure sensor, etc., continuously collects high-voltage system parameters to form a raw data stream; the high-voltage system parameters include insulation resistance, collision acceleration, battery pack pressure, and temperature, etc. Step S200: The raw data stream is processed by a multi-level diagnostic center. Through multi-source data fusion and threshold comparison, combined with the fault code and timestamp recorded by the fault latch memory, the fault level is determined. The fault levels include: Level 1 faults: Insulation resistance value 100Ω / V < R < 500Ω / V, single cell temperature difference ΔT > 15℃ for 30s, etc.; Level 2 faults: Branch current > 150% of rated value for 50ms, local temperature > 85℃, single cell voltage difference ΔV > 300mV, etc.; Level 3 faults: Acceleration > 20g or airbag signal trigger, main circuit current > 2000A (cross-verified by Battery Management System BMS + Power Control Unit VCU), battery pack pressure > 5kpa or temperature > 120℃; Step S300: The fault level is determined to generate an execution command, which drives the actuator to perform the corresponding power-off operation; In the case of a Level 1 fault, a warning and power limitation are implemented: a command is sent via the CAN bus to limit the motor power to 70% and trigger a yellow alarm on the instrument panel; in the case of a Level 2 fault, a partial power cut is implemented: the corresponding branch contactor is disconnected and the 12V backup power supply is activated; in the case of a Level 3 fault, a full power cut is implemented: an emergency CAN signal is broadcast, the main positive and negative contactors are disconnected, and if the voltage does not drop below 60V within 10ms, the blast fuse is detonated and the vehicle rescue system is triggered; if the electronic channel fails, the hard-wired backup circuit directly triggers a Level 3 power cut.
[0023] The specific principle in the above embodiments is as follows: Figure 2As shown, this embodiment continuously acquires key parameters of the high-voltage system at the sensor layer and sends this raw data to a multi-level diagnostic center for fusion and threshold comparison. This enables real-time and accurate identification of faults of varying severity. The fault level determination then drives the corresponding actuators. When a minor abnormality occurs, the system issues a command through the vehicle network to reduce the motor output power and display a warning on the instrument panel, preventing further deterioration of the fault and ensuring passenger safety. Local isolation and backup power supply: When an abnormality is detected in a branch circuit or local component, the system can quickly disconnect the affected circuit and simultaneously activate the low-voltage backup power supply to ensure that critical subsystems remain operational, preventing the entire vehicle from losing power or experiencing a wider range of electrical malfunctions. Rapid power outage and rescue activation across the entire system: In the event of a severe impact or high-voltage abnormality, the system immediately broadcasts an emergency signal and disconnects the main positive and negative contactors. If the voltage does not drop to a safe level within a very short time, the blast fuse will be triggered, ensuring rapid elimination of high voltage and activation of the vehicle rescue device, minimizing personal injury and the risk of secondary accidents. Redundant hardware direct intervention: In the event of electronic control channel failure, the hard-wired backup circuit can immediately perform a complete power-off, ensuring reliable and safe disconnection even under the most unfavorable fault conditions. Fault traceability and diagnostic support: Fault codes and timestamps are recorded in latch memory, providing complete data for subsequent maintenance, analysis, and quality improvement.
[0024] In summary, this embodiment's multi-level linkage power-off protection method achieves end-to-end safety protection, from early warning of minor anomalies to rapid, full-domain power-off in the event of serious faults, improving the reliability and occupant safety of new energy vehicles under extreme conditions such as collisions, overheating, and insulation failures. High-voltage power-off covers 99.99% of extreme scenarios (compliant with ISO 6469-3:2018); under secondary faults, the vehicle can still drive away from the danger zone at low speed; the dual-channel redundancy design is ASIL-D certified; and in the event of abnormal conditions such as vehicle collisions, insulation failures, or short circuits, a fast, accurate, and reliable high-voltage safety protection device is achieved through multi-level collaborative diagnosis and phased power-off.
[0025] Example 2: As Figure 3 As shown, based on Embodiment 1, the process of forming the original data stream in step S100 of this embodiment of the invention specifically includes the following steps: Step S101: The initial signals of high-voltage system parameters generated by the sensor layer undergo spatiotemporal alignment and common-mode suppression processing; the parameter sequence of insulation resistance output by the high-precision insulation monitor, the vector of collision acceleration generated by the triaxial collision acceleration sensor, and the waveform and temperature of the voltage pack pressure collected by the battery pack pressure sensor are processed using a hardware timestamp-based interpolation algorithm to unify the data streams of different sampling periods to the same time base, and a common-mode suppression algorithm is used to eliminate the common environmental noise in the signals of each sensor; the aligned multi-channel signal is output. Step S102: After alignment, the multi-channel signals are statistically analyzed using a sliding window method to establish a parameter baseline for each sensing channel that is adaptively adjusted according to the operating conditions. This baseline includes the sliding mean of insulation resistance, the variance envelope of impact acceleration, and the threshold boundaries of battery pack pressure change rate and temperature. Simultaneously, the instantaneous deviation of each high-voltage system parameter from its dynamic baseline is identified. When the instantaneous value of any high-voltage system parameter exceeds the baseline tolerance band, it is marked as a potential anomaly, and the deviation magnitude and duration are recorded. The output is a parameter deviation map with spatiotemporal markers. Step S103: The high-pressure system parameters with different physical dimensions in the parameter deviation spectrum are normalized and transformed into dimensionless feature values. Then, they are weighted and fused according to the preset weight coefficients to form a unified multimodal risk feature vector. At the same time, the risk feature vector is prioritized and encoded according to the deviation degree and duration of each high-pressure system feature parameter to generate a feature sequence with a clear order. The output multimodal feature vector with priority encoding is the original data stream.
[0026] In the above embodiments, this embodiment achieves precise synchronization of raw signals from different sensors and sampling periods on a unified time base through spatiotemporal alignment and common-mode suppression processing, effectively eliminating environmental noise and ensuring that subsequent analysis is based on clean and comparable multi-channel data. Subsequently, a sliding window statistical method is used to dynamically construct the operating baseline of each channel, enabling real-time capture of instantaneous parameter deviations and marking of potential anomalies, ensuring adaptive and timely anomaly detection. Finally, deviation information of different physical dimensions is normalized and weighted fusion according to preset weights to generate a unified multimodal risk feature vector; by prioritizing the deviation amplitude and duration, the risk features possess clear ranking information. This achieves synchronization of high-voltage system parameters, noise suppression, dynamic baseline adaptation, precise anomaly marking, and unified quantification of multimodal risk features, providing a high-quality, comparable, and priority-indicating raw data stream for fault diagnosis and graded power outages.
[0027] Example 3: Based on Example 2, the process of outputting the aligned multi-channel signal in step S101 of this embodiment of the invention specifically includes the following steps: Step S1011: The clock unit built into each sensor generates a hardware timestamp sequence corresponding to its respective sampling pulse as the original time reference; according to the system's highest sampling rate requirement, a global time grid with fixed intervals is created, and the hardware timestamp sequence of each sensor is mapped and allocated to the periodic time slots of the global time grid; output the periodic time frame with completed time slot allocation. Step S1012: Using a periodic time frame, interpolate the data collected by each sensor at non-uniform times. For each global time grid point, obtain the virtual sampled value at a uniform time based on the nearest actual sampled data points before and after it; output a multi-channel synchronous data stream with a uniform time base. Step S1013: Identify signal components that are highly correlated in amplitude and phase in the multi-channel synchronous data stream and determine them as common environmental noise; subtract the extracted common-mode noise reference from the initial signal of each sensing channel and retain the effective signal components; the output result is the aligned multi-channel signal after eliminating common environmental noise.
[0028] In the above embodiments, this embodiment constructs a periodic time frame by generating hardware timestamps for each sensor and mapping them to a unified global time grid, enabling sampling data from different sources to be aligned on the same time reference. Subsequently, interpolation is performed on asynchronous sampling points within the time frame to obtain virtual sampling values at a unified time, achieving synchronization of multi-channel data and eliminating time-domain misalignment caused by differences in sampling timing. Furthermore, common-mode components with highly correlated amplitude and phase are extracted from the synchronized multi-channel signals, and this common-mode noise reference is subtracted from the original signals of each channel, preserving the effective information of each sensor. This embodiment achieves time alignment, sampling unification, and common-mode noise suppression of multi-source high-voltage system parameters, providing a clean, comparable, and synchronized multi-channel signal foundation for anomaly detection and risk assessment.
[0029] Example 4: Figure 4 As shown, based on Embodiment 1, the process of determining the fault level in step S200 of this embodiment of the invention specifically includes the following steps: Step S201: Calculate the similarity between the real-time risk feature vector and the historical fault patterns recorded in the fault latch memory to generate a matching coefficient between each fault pattern and the current state; at the same time, extract the frequency and time distribution features of the corresponding fault codes in the fault latch memory to form a historical fault activity index; output a preliminary fault identifier with matching weight and historical fault activity index. Step S202: Combine the initial fault identifier with the timestamp information in the fault latch memory to construct a time series correlation matrix of the fault parameters, analyze the temporal dependency relationship and fault evolution trend among the fault parameters; by calculating the cumulative change rate and mutual influence coefficient of the fault parameters, deduce the possible path and speed of fault development; output the severity deduction result containing the fault evolution trend and the expected fault development speed. Step S203: Based on the historical data of similar faults recorded in the fault latch memory and combined with the current system operating status, dynamically adjust the judgment threshold of each fault level according to the severity extrapolation results; at the same time, consider the real-time severity of the fault and historical statistical characteristics, and map the comprehensive evaluation results to specific fault levels through multi-dimensional weight allocation; output the fault level judgment after historical data verification and dynamic calibration.
[0030] In the above embodiments, this embodiment compares the real-time risk feature vector with historical failure modes for similarity and combines the frequency and temporal distribution of failure codes to form a preliminary identification of the current state, enabling the system to quickly locate possible failure types in massive historical data. Subsequently, a parameter correlation matrix is constructed using timestamp information to analyze the temporal dependence and evolution trend of each failure parameter, calculate the cumulative change rate and mutual influence coefficient, thereby deducing the possible evolution path and development speed of the failure and providing a forward-looking prediction of the failure process. Finally, based on the statistical characteristics of similar historical failures and the current operating status, the judgment threshold is dynamically calibrated, and the comprehensive evaluation is mapped to a specific failure level through multi-dimensional weight allocation. This embodiment combines past fault experience with current risk characteristics to improve the accuracy and reliability of fault identification. Time series analysis captures the causal relationships between fault parameters, predicting the evolution direction and acceleration of faults in advance. Judgment criteria are dynamically adjusted based on real-time severity and historical statistics to avoid misjudgments or omissions caused by fixed thresholds. A historically validated fault level judgment is generated through weighted analysis of multiple indicators such as similarity, activity, and evolution trend, providing a reliable basis for subsequent graded power outages. This approach ensures high-precision identification while predicting fault development trends and dynamically correcting adaptive thresholds, significantly improving the safety protection level of high-voltage systems in new energy vehicles.
[0031] Example 5: Based on Example 4, the output of severity projection results including fault evolution trend and expected fault development speed in step S202 of this embodiment of the invention specifically includes the following steps: Step S2021: For each pair of fault parameters in the initial fault identification, calculate the correlation strength within a set time lag range, and find the correlation pair where the change of one fault parameter leads the change of another fault parameter in time; output the set of fault parameter correlation pairs with significant time lead-lag relationship identified. Step S2022: For each fault parameter association pair, analyze the quantitative relationship between the change magnitude of the leading fault parameter and the change magnitude of the lagging fault parameter within its change window, and obtain the causal transmission weight of the unit change of the leading fault parameter on the lagging fault parameter; output the fault parameter influence relationship network with precise causal transmission weight. Step S2023: Utilize the fault parameter influence relationship network to start the multi-path state chain inferencer. Starting from the current active fault parameter state, simulate the process of fault energy transmission and evolution along different paths based on the connections and weights in the influence relationship network, and calculate the trigger probability and state transmission speed of each potential path.
[0032] In the above embodiments, this embodiment identifies fault parameters with significant time-leading characteristics by calculating the correlation strength between them within a set time lag range. The system first identifies the parameter pairs of the lag relationship; then, it quantifies the impact of changes in the leading parameter on the lag parameter, obtaining accurate causal propagation weights and forming a complete fault parameter influence relationship network. Finally, starting from the current active fault parameter state, it uses the connections and weights of this network to simulate the propagation of fault energy in a multi-path state chain inferrer, calculating the trigger probability and state propagation speed of each potential propagation path. This embodiment achieves accurate capture of the temporal causal relationship of fault parameters, quantification of influence intensity, and multi-path evolution prediction based on causal networks. This enables the system to predict possible fault propagation paths and assess their development speed in the early stages, providing a reliable trend basis for graded power outage decisions.
[0033] Example 6: Based on Example 5, the process of calculating the correlation strength in step S2021 provided in this embodiment of the invention specifically includes the following steps: Step S20211: Take the time series of the pair of fault parameters to be analyzed in the preliminary fault identification, and cut the two fault parameters into multiple overlapping data segments at different lag time points within the set time lag range; each data segment contains the corresponding data segments of the two fault parameters under the time offset; output multiple sets of parameter sequence data segment pairs that are precisely aligned on the time axis. Step S20212: Obtain the covariant energy density of one fault parameter changing when the other fault parameter changes in a pair of parameter sequence data segments aligned on the time axis; output the covariant energy density value at each lag time point; Step S20213: Find the peak value in the covariant energy density distribution for a series of lag time points. The lag time corresponding to the peak value is determined as the most important response delay between the two fault parameters. At the same time, the covariant energy density value of the peak value is normalized and defined as the mutual correlation strength between the two fault parameters under the lag relationship. Output the set of fault parameter correlation pairs with significant time-series lead-lag relationship.
[0034] In the above embodiments, this embodiment segments the time series of the fault parameter pairs to be analyzed, ensuring precise alignment of each data segment on the time axis within a set time lag range. Subsequently, the covariant energy density of parameter changes is calculated within the aligned segments to obtain the energy correlation at different time lag points. Peak values are identified in the energy density distribution across the entire time lag range; the time lag corresponding to the peak value is considered the primary response delay between the two parameters, and the peak energy, after normalization, is defined as the correlation strength. This embodiment achieves fine-grained segmented alignment of the time series relationship of fault parameters, ensuring the consistency of the comparison benchmark; it quantifies the degree of synchronous change of parameters under different time lags using covariant energy density, providing an objective measure of correlation; and it automatically identifies the most significant leading factor through peak detection. The lag relationship is established and the correlation strength is expressed by a normalized energy value, forming a comparable causal correlation index. This embodiment can accurately capture the temporal causal characteristics between fault parameters, providing a reliable time-lag correlation basis for fault evolution path deduction and severity assessment.
[0035] Example 7: Figure 5 As shown, based on Embodiment 1, the process of driving the actuator to perform a corresponding power-off operation in step S300 of this embodiment of the invention includes the following steps: Step S301: Determine the set of target actuators to be operated based on the fault level, and generate a complete blueprint of execution instruction sequence containing the operation object, action sequence and time node by combining the real-time status of each actuator; output a primary execution instruction sequence containing complete timing logic; Step S302: Detect the communication status and load capacity of the main execution channel by the primary execution instruction sequence, and dynamically adjust the primary execution instruction sequence according to the detection results; when the main channel is unobstructed, optimize the packaging and sending strategy of the primary execution instructions; when channel delay or blockage is detected, start the backup path and adjust the transmission method and parameters of the primary execution instructions accordingly; output the executable instruction set after channel adaptive optimization. Step S303: Convert the executable instruction set into the physical drive signals required by the corresponding actuator, including the drive current of the contactor coil, the pulse parameters of the fuse ignition signal, etc.; after each physical drive signal is issued, confirm whether the action is successfully executed through the actuator status feedback loop, and record the final execution status; output the physical signal sequence that drives the actuator to complete the corresponding power-off operation and its execution confirmation result.
[0036] In the above embodiments, this embodiment determines the set of actuators that need to be driven through fault level mapping, and generates a complete instruction blueprint containing the operation object, action sequence, and time node by combining the real-time status of each actuator, realizing a direct mapping from diagnostic results to execution plan. Subsequently, the instruction blueprint is subjected to communication channel status detection and load capacity assessment. Based on the availability of the main channel, the instruction packaging and sending strategy is dynamically adjusted or switched to a backup path to ensure reliable transmission of instructions under different network conditions. Finally, the adapted instructions are converted into the physical drive signals required by each actuator, and the completion status of the action is confirmed in real time through a feedback loop, and the execution status is recorded. This embodiment achieves a precise mapping from fault level to actuator, forming a clear timing control logic; adaptive instruction optimization based on the real-time status of the communication channel ensures that instructions can be delivered in a timely and reliable manner in any network environment; and the precise generation and closed-loop feedback of physical drive signals provide verifiable execution results for power-off operations. Thus, a full-link, real-time, and reliable execution mechanism from fault determination to safe power-off is constructed, improving the safety response capability of the high-voltage system of new energy vehicles under various fault conditions.
[0037] Example 8: Based on Example 7, the process of converting the executable instruction set into the physical drive signals required by the corresponding actuator in step S303 of this embodiment of the invention specifically includes the following steps: S3031: Based on the target actuator type specified in the executable instruction, query its inherent electrical characteristic parameter library and map the abstract logical instruction to specific physical drive waveform parameters; for example, for a contactor coil, map the required drive current amplitude, rise slope, and holding level; for a blown fuse, map the voltage peak, pulse width, and energy threshold of the high-energy ignition pulse; output a drive instruction sequence with precise waveform parameters; S3032: Based on the real-time output capability of the system power supply and the physical response delay of the actuator, fine-tune the issuance time, duration, and gain of each drive signal in the drive command sequence; output the drive signal to be amplified after time and power calibration. S3033: Converts the time- and power-calibrated drive signal to be amplified into the actual control level required by power devices such as high-side drivers and H-bridge circuits, and generates a physical drive signal acting on the actuator; at the same time, a physical drive signal integrity monitoring loop samples the voltage and current waveforms actually output to the actuator in real time, compares them with the expected waveform parameters, and generates a signal integrity report.
[0038] In the above embodiments, this embodiment maps abstract logical instructions to precise drive waveforms required by various actuators by querying an electrical characteristic parameter library, achieving seamless conversion from instructions to the physical layer. Subsequently, based on the system's real-time power capability and the actuator's response delay, the transmission time, duration, and power amplifier gain of the drive signal are finely adjusted to ensure that the signal matches the actual power supply conditions in terms of timing and power. Finally, the calibrated signal is converted into the control level of power devices such as high-side drivers and H-bridges, and the output waveform is sampled in real time through an integrity monitoring loop, compared with a preset waveform, and an integrity report is generated. This embodiment achieves: precise mapping from instructions to waveforms, ensuring that different actuators receive drive signals that conform to their electrical characteristics; adaptive calibration of timing and power, ensuring that the drive signal still meets response requirements under actual power supply constraints; and real-time integrity monitoring and feedback, comparing and verifying the output waveform to provide reliable signal quality assessment. This forms a high-precision, real-time, and verifiable conversion link from logical instructions to physical drive signals, providing robust and controllable hardware execution guarantees for safe power-off operations.
[0039] Example 9: Based on the example, the process of mapping abstract logical instructions to specific physical drive waveform parameters in step S3031 of the present invention specifically includes the following steps: Step S30311: Decode the logical identifiers in the executable instructions and convert them into a unified type identifier that can be recognized by the internal execution mechanism parameter library; at the same time, verify the existence and availability of the type identifier in the parameter library; Step S30312: Based on the unified type identification code, retrieve the complete steady-state and transient electrical response characteristics of the corresponding actuator from the inherent electrical characteristic parameter library of the actuator, which together constitute the electrical characteristic profile of the actuator; Step S30313: Based on the action state required by the original logic instruction, and in conjunction with the boundary conditions and response program defined in the electrical characteristic profile, calculate the specific drive waveform parameters that meet the action requirements and do not exceed the electrical tolerance range of the actuator; for example, synthesize the drive current amplitude, rising slope, and holding level for the contactor coil that take into account both speed and avoidance of inrush current.
[0040] In the above embodiments, this embodiment achieves a direct correspondence between executable instructions and the internal actuator parameter library by decoding and mapping logical identifiers to a unified type identification code. The validity of the type code is verified during the mapping process to ensure reliable retrieval. Subsequently, using the unified identification code as an index, the complete steady-state and transient response characteristics of the actuator are extracted from the electrical characteristic parameter library to form a complete electrical characteristic profile, providing complete physical constraint information for waveform calculation. Finally, based on the action state required by the logical instruction, combined with the boundary conditions and response procedures defined in the electrical characteristic profile, specific drive waveform parameters that meet the action requirements and do not exceed the device's tolerance range are calculated, realizing accurate waveform generation from abstract instructions to those conforming to the device's electrical limitations. This embodiment completes the reliable mapping from instruction to physical waveform, the complete acquisition of characteristic constraints, and the safe and feasible solution of waveform parameters, providing a high-precision, constrained, and verifiable foundation for drive signal generation.
[0041] Example 10: Based on Example 9, the process of calculating the specific drive waveform parameters that meet the action requirements and do not exceed the electrical tolerance range of the actuator in step S30313 of this embodiment of the invention specifically includes the following steps: Step S303131: Deconstruct the target action required by the original logic instruction, break it down into several consecutive action stages, and identify the core electrical objectives to be achieved in each action stage; for example, rapid engagement and stable holding in contactor drive; define the key time nodes and required energy injection characteristics for each action stage to obtain the action timing blueprint. Step S303132: Based on the steady-state and transient boundary conditions defined in the electrical characteristic profile, calculate the safe operating range of each waveform parameter within each action stage in the action timing blueprint. The safe operating range constitutes a dynamically changing parameter boundary domain. Step S303133: Under the constraints of the parameter boundary domain, take the core electrical objectives of each action stage in the action timing blueprint as the guide, and use a multi-objective optimization strategy to perform numerical solution; synthesize a set of specific drive waveform parameters.
[0042] In the above embodiments, this embodiment constructs an action timing blueprint that includes key electrical objectives, time nodes, and energy injection characteristics by decomposing the target action. Then, based on the steady-state and transient boundary conditions of the actuator, the parameter range for safe operation is calculated for each stage in the action timing blueprint, forming a boundary domain that dynamically changes over time. Finally, within this constraint domain, waveform parameters are solved using a multi-objective optimization approach, ensuring that the core electrical objectives of each stage are achieved without violating safety restrictions. This embodiment achieves fine-grained timing decomposition of actions and clear definition of key electrical requirements, ensuring that the objectives of each step are clear and quantifiable. Based on the boundary constraints of device electrical characteristics, the range of parameters such as current, voltage, and slope for each stage is dynamically limited, ensuring that the driving process is always within a safe operating range. Through multi-objective optimization, the optimal waveform is solved within the constraint space, achieving performance optimization for stages such as rapid engagement and stable holding, while simultaneously meeting multiple requirements such as energy, response speed, and device lifespan. Generating a high-precision drive waveform that meets the action timing requirements within the safety boundary provides a verifiable physical implementation scheme for reliable, fast, and safe power-off operation of the actuator.
[0043] Example 11, based on Example 10, provides a numerical solution process using a multi-objective optimization strategy in step S303133 of this embodiment, specifically including the following steps: Step S3031331: Based on the current security policy priority of the system, assign a quantized weight coefficient to each core electrical target to obtain a set of quantized targets with weight coefficients; Step S3031332: Within the multidimensional space defined by the dynamic parameter boundary domain, a systematic search is performed according to the direction indicated by the quantization target set to generate a series of exploration trajectories pointing to the optimal region. The exploration trajectory records the degree to which different combinations of driving waveform parameters achieve various quantization targets under the condition of satisfying constraints. Step S3031333: Analyze the convergence trend of all exploration trajectories and identify those trajectory convergence points that achieve the best balance among multiple quantification objectives; trajectory convergence points mean that further optimization of any single objective will come at the expense of other objectives, forming a Pareto optimal solution set for the multi-objective optimization problem; select a set of specific driving waveform parameters suitable for the current working condition from the Pareto optimal solution set according to the preset decision rules.
[0044] In the above embodiments, this embodiment assigns quantized weights to each core electrical objective to form a target set reflecting the priority of the safety strategy. Then, within a multi-dimensional parameter space defined by the safety boundary, a systematic search is performed based on the weights to generate exploration trajectories covering different waveform combinations, and the degree to which each combination achieves each objective under the constraints is recorded. Finally, the convergence behavior of all trajectories is analyzed to identify the convergence point that achieves the best balance among multiple objectives, forming a Pareto optimal solution set. The most suitable drive waveform parameters for the current operating condition are selected from this set according to preset decision rules. This embodiment achieves quantized trade-offs, systematic search, and Pareto optimal solution selection for multiple objectives within safety constraints, ensuring that the generated drive waveform satisfies both the safety boundary and multiple performance requirements such as response speed, energy consumption, and device lifespan, providing the actuator with optimal and verifiable physical drive parameters.
[0045] Example 12: Based on Example 10, the process of identifying trajectory convergence points that achieve the optimal balance among multiple quantization targets in step S3031333 of this embodiment of the invention specifically includes the following steps: Step S30313331: For each candidate parameter point on the exploration trajectory, based on the measured or predicted values of its various performance indicators, obtain the normalized achievement degree relative to each quantitative target, and combine the achievement degrees into a multi-dimensional vector, and combine the multi-dimensional target achievement degree vector corresponding to each candidate parameter point. Step S30313332: In the multidimensional space formed by the multidimensional goal achievement vector, obtain the dominance relationship between each point in the multidimensional space, identify all non-dominated points that are not completely surpassed by other points; analyze the distribution density of non-dominated points in the vector space, screen out points located in low-density regions and with relatively balanced achievement in each dimension, form a preliminary Pareto front, and obtain a sparse and balanced Pareto optimal solution set. Step S30313333: Take the sparse and balanced Pareto optimal solution set, and give a comprehensive score to each point in the Pareto optimal solution set according to the preset decision rules, such as the minimum achievement rule or the weighted sum rule based on the weight coefficients; by comparing the comprehensive scores, confirm a trajectory convergence point that achieves the best balance among multiple objectives.
[0046] In the above embodiments, this embodiment normalizes the performance indicators of each candidate parameter point on the exploration trajectory to form a multi-dimensional target achievement vector, thus achieving a unified quantitative expression of the degree of achievement of different targets. Subsequently, it analyzes the dominance relationships in the multi-dimensional vector space, filters out all non-dominated points that are not comprehensively surpassed by other points, and further extracts preliminary Pareto fronts in low-density regions with relatively balanced achievement degrees across dimensions, constructing a sparse and balanced set of optimal solutions. Finally, based on preset decision rules, it comprehensively scores each solution in the Pareto front, selecting the trajectory convergence point that achieves the best balance among multiple quantified targets. This embodiment achieves unified quantization of multi-target driving waveform parameters, dominance relationship filtering, and sparse and balanced Pareto front construction, and determines the optimal solution through decision rules, thereby obtaining optimal driving waveform parameters that balance multiple performance aspects such as response speed, energy consumption, and device lifetime while meeting safety constraints.
[0047] Example 13: As Figure 6 As shown, based on Embodiments 1-12, the high-voltage electric safety protection system for new energy vehicles based on multi-level linkage power-off provided in this embodiment of the invention includes: The data stream acquisition module 1 is used to continuously collect high-voltage system parameters from the sensor layer, including a high-precision insulation monitor, a triaxial impact acceleration sensor, and a battery pack pressure sensor, to form a raw data stream; the high-voltage system parameters include insulation resistance, impact acceleration, battery pack pressure, and temperature, etc. The diagnostic central processing module 2 is used to process the raw data stream through multiple levels of the diagnostic central processing, and obtain the fault level judgment by combining multi-source data fusion and threshold comparison with fault code and timestamp recorded by the fault latch memory; The power failure operation execution module 3 is used to generate execution instructions based on the fault level judgment, and drive the actuator to perform the corresponding power failure operation. In the case of a Level 1 fault, a warning and power limitation are implemented: a command is sent via the CAN bus to limit the motor power to 70% and trigger a yellow alarm on the instrument panel; in the case of a Level 2 fault, a partial power cut is implemented: the corresponding branch contactor is disconnected and the 12V backup power supply is activated; in the case of a Level 3 fault, a full power cut is implemented: an emergency CAN signal is broadcast, the main positive and negative contactors are disconnected, and if the voltage does not drop below 60V within 10ms, the blast fuse is detonated and the vehicle rescue system is triggered; if the electronic channel fails, the hard-wired backup circuit directly triggers a Level 3 power cut.
[0048] In the above embodiments, this embodiment continuously collects key parameters of the high-voltage system through a data stream acquisition module and sends this raw data to the diagnostic central processing module to achieve real-time monitoring and fusion analysis of multi-dimensional information such as insulation status, impact, pressure, and temperature. Based on threshold comparisons and the codes and timestamps recorded in the fault latch memory, the diagnostic central processing module can quickly and accurately determine the severity of the fault. Subsequently, the power-off operation execution module generates corresponding instructions based on the determination results, driving the corresponding actuators to complete the corresponding safety measures.
[0049] This embodiment achieves end-to-end early warning and protection: When a minor anomaly occurs, the system issues a power limiting command through the vehicle network and displays a warning on the instrument panel to prevent the fault from escalating and ensure passenger safety. It achieves local isolation while maintaining critical functions: When an anomaly is detected in a branch circuit or local component, the system can quickly disconnect the affected circuit and simultaneously activate the low-voltage backup power supply to ensure that critical subsystems can still operate normally, preventing the entire vehicle from losing power. It achieves rapid power-off across the entire system in extreme situations: In the event of a severe impact or high-voltage anomaly, the system immediately broadcasts an emergency signal and disconnects the main positive and negative contactors; if the voltage does not drop to a safe level within a very short time, the blast fuse will be triggered to ensure rapid elimination of high voltage and activation of the vehicle rescue device, minimizing personal injury and the risk of secondary accidents. This embodiment provides hardware redundancy for reliability: In the event of electronic control channel failure, the hard-wired backup circuit can directly intervene and immediately execute a full-domain power-off, ensuring reliable and safe disconnection even under the most unfavorable fault conditions; it achieves fault traceability and subsequent diagnostic support: Fault codes and timestamps are recorded in a latch memory, providing complete data for maintenance, analysis, and quality improvement.
[0050] In summary, this embodiment forms a complete closed loop from real-time monitoring and accurate diagnosis to layered power-off, significantly improving the safety and reliability of new energy vehicles under extreme conditions such as collisions, overheating, and insulation failure; it realizes a coherent multi-level linkage protection from sensor data acquisition to fault diagnosis and power-off execution, ensuring high-voltage electrical safety and reducing the risk of electric shock and the impact of system failures.
[0051] This embodiment implements a three-level power failure execution circuit topology: battery positive terminal → explosion fuse or parallel main contactor → branch power distribution box → branch contactor group or DC-DC / OBC / PTC, etc. → load. Table 1 Hardware Composition and Technical Requirements
[0052] The hierarchical response logic and parameter thresholds in this embodiment are as follows: Level 1 Response (Early Warning and Power Limitation): 1) Triggering conditions: Insulation resistance value: 100Ω / <R<500Ω / V (national standard requires ≥500Ω / V); Individual cell temperature difference: ΔT>15℃; Duration:>30s (to prevent transient interference).
[0053] 2) Perform the action: if (R_insulation<500&&R_insulation>100) limit_motor_power(70%); / / Limit motor power to 70% dashboard_alert(YELLOW); / / Yellow alert on the dashboard To avoid accidental power outages, the vehicle can continue to be driven to the repair shop, reducing the fault misdiagnosis rate by 83%.
[0054] Level 2 response (partial power outage): Triggering conditions: Branch battery abnormality: I > 150% of rated value for 50ms; Local temperature exceeds limit: T > 85℃ (e.g., charger / PTC heater); Battery cell voltage difference: ΔV > 300mV.
[0055] Perform the following actions: if (detect_fault_circuit() == DC_DC_CONVERTER) open_contactor(CIRCUIT_DCDC); / / Disconnect the DC-DC contactor enable_backup_12V_supply(); / / Enable 12V backup power supply When only the faulty subsystem loses power (e.g., the vehicle can still run after the charger is disconnected), system availability is improved by 90%.
[0056] Level 3 Response (Citywide Emergency Power Outage) Table 2 trigger conditions require dual-condition verification:
[0057] Perform the following actions: void emergency_shutdown() send_signal(CAN_ID_EMG, 0xFF); / / Broadcast emergency status open_main_contactor(POS_NEG); / / Disconnect the main contactor (within 5ms) if (voltage_drop_time>10ms) / / Voltage has not dropped below 60V ignite_pyro_fuse(); / / Detonate the fuse (<3ms) activate_SOS_system(); / / Trigger the vehicle rescue system The power outage time of the high-voltage system is ≤10ms, reducing the risk of electric shock by 99.97%.
[0058] Table 3 Key Processes and Time Series
[0059] Table 4 Multi-level Fault Diagnosis Module
[0060] The linkage execution mechanism in this embodiment Main control unit: integrates multi-source data fusion decision-making from BMS, VCU, and collision sensors.
[0061] Tiered enforcement agencies: Level 1: Solid State Relay (Fast On / Off); Secondary: Branch contactors (such as air conditioner compressors, chargers); Level 3: Main contactor + explosion-proof fuse (breaks off in <3ms).
[0062] Redundant channel: Independent hard-wire backup (CAN failure directly triggers three-level power failure).
[0063] Fail-safe and redundant design Dual protection mechanism, electronic channel failure: if the CAN bus does not respond within t=4ms → the hard-wired backup circuit directly drives the fuse to ignite.
[0064] If the contactor is stuck together, check the voltage after the main contactor disconnects: if the voltage is >60V at t=10ms → force the fuse to detonate.
[0065] Table 5 Parameter Requirements
[0066] The workflow of this embodiment Real-time monitoring: Simultaneously collects voltage, current, temperature, insulation resistance, collision acceleration (G-value), airbag signals, etc.
[0067] Fault classification: If the airbag ignition signal is detected and the collision G-value is greater than 15g, a level 3 power failure is triggered directly; if the insulation resistance drops suddenly and the local temperature is greater than 80°C, a level 2 power failure is triggered (isolation of the fault module).
[0068] Linked execution, code example: if fault_level == 3: # Emergency fault activate_pyro_fuse() # Detonate the fuse open_main_contactor() # Disconnect the main circuit send_emergency_signal() # Upload an alarm to the cloud elif fault_level == 2:# Moderate fault disable_subsystem(affected_circuit) # Only disable the faulty subsystem maintain_main_power() # Keep the main drive powered Fault latching and reporting The fault code is recorded to the EEPROM and uploaded to the cloud platform via TBOX.
[0069] The application scenario of this embodiment is: a short circuit occurs in the AC charging gun during charging; Fault process: t=0: An internal short circuit in the charging gun causes a short circuit between the L line and the PE line; t=5ms: The insulation tester detected a resistance drop to 50Ω / V; t=10ms: OBC temperature sensor reports 120℃ over-temperature.
[0070] System Response t=12ms: Level 2 fault determination, charging circuit abnormality; t=15ms: Disconnect the charger contactor; t=20ms: Power supply to the drive system is maintained, and the vehicle can be driven away.
[0071] This embodiment avoids a complete vehicle power outage, reducing maintenance costs by 70%.
[0072] Figure 7 A block diagram of an exemplary electronic device suitable for implementing embodiments of the present invention is shown.
[0073] The electronic device may include a central processing unit / microprocessor / main control chip, etc. 4; and a storage medium 5, coupled to the central processing unit / microprocessor / main control chip, etc. 4, and storing computer-executable instructions therein for performing the steps of various methods of embodiments of the present invention when executed by the processor.
[0074] The central processing unit / microprocessor / main control chip, etc., can include, but are not limited to, one or more processors or microprocessors.
[0075] Storage medium 5 may include, but is not limited to, random access memory (RAM), read-only memory (ROM), flash memory, EPROM memory, EEPROM memory, registers, computer storage media (e.g., hard disk, floppy disk, solid-state drive, removable disk, CD-ROM, DVD-ROM, Blu-ray disc, etc.).
[0076] In addition, the electronic device may also include (but is not limited to) a data bus 6, an input / output bus / external bus / device bus 7, a display 8, and input / output devices 9 (e.g., keyboard, mouse, speaker, etc.).
[0077] The central processing unit / microprocessor / main control chip, etc. 4 can communicate with external devices (8, 9, etc.) via wired or wireless networks (not shown) through input / output buses / external buses / device buses, etc. 7.
[0078] The storage medium 5 may also store at least one computer-executable instruction for performing the steps of various functions and / or methods in the embodiments described herein when the central processing unit / microprocessor / main control chip, etc., 4 is running.
[0079] In one embodiment, the at least one computer-executable instruction may also be compiled into or comprise a software product, wherein one or more computer-executable instructions are executed by a processor to perform the steps of the various functions and / or methods in the embodiments described herein.
[0080] Figure 8 A schematic diagram of a computer-readable storage medium according to an embodiment of the present invention is shown.
[0081] like Figure 8 As shown, the non-transitory computer-readable storage medium 11 stores instructions, such as computer-readable instructions 10. When the computer-readable instructions 10 are executed by a processor, the various methods described above can be performed. The non-transitory computer-readable storage medium 11 includes, but is not limited to, volatile memory and / or non-volatile memory. Volatile memory may include, for example, random access memory (RAM) and / or cache memory. Non-transitory non-volatile memory may include, for example, read-only memory (ROM), hard disk, flash memory, etc. For example, the non-transitory computer-readable storage medium 11 can be connected to a computing device such as a computer, and then, when the computing device executes the computer-readable instructions 10 stored on the non-transitory computer-readable storage medium 11, the various methods described above can be performed.
[0082] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for executing all or part of the steps of the methods of the various embodiments of this invention through a computer device (which may be a personal computer, server, or network device, etc.). The aforementioned storage medium includes: USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, optical disks, and other media capable of storing program code.
[0083] The above embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit it. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A method for high-voltage electrical safety protection of new energy vehicles based on multi-level linkage power-off, characterized in that, Includes the following steps: The raw data stream is processed by a multi-level diagnostic center. Through multi-source data fusion and threshold comparison, combined with fault codes and timestamps recorded by the fault latch memory, the fault level is determined. The fault level is determined to generate an execution command, which drives the actuator to perform the corresponding power-off operation. In the case of a Level 1 fault, a warning and power limitation are implemented: a command is sent via the CAN bus to limit the motor power to 70% and trigger a yellow alarm on the instrument panel; in the case of a Level 2 fault, a partial power cut is implemented: the corresponding branch contactor is disconnected and the 12V backup power supply is activated; in the case of a Level 3 fault, a full power cut is implemented: an emergency CAN signal is broadcast, the main positive and negative contactors are disconnected, and if the voltage does not drop below 60V within 10ms, the blast fuse is detonated and the vehicle rescue system is triggered; if the electronic channel fails, the hard-wired backup circuit directly triggers a Level 3 power cut.
2. The method for high-voltage electrical safety protection of new energy vehicles based on multi-level linkage power outage as described in claim 1, characterized in that, The process of determining the fault level includes the following steps: The similarity between the real-time risk feature vector and the historical fault patterns recorded in the fault latch memory is calculated to generate a matching coefficient between each fault pattern and the current state; at the same time, the frequency and time distribution features of the corresponding fault codes in the fault latch memory are extracted to form a historical fault activity index. Output preliminary fault identifiers with matching degree weights and historical fault activity metrics; By combining the initial fault identification with the timestamp information in the fault latch memory, a time series correlation matrix of fault parameters is constructed to analyze the temporal dependencies and fault evolution trends among the fault parameters. By calculating the cumulative change rate and mutual influence coefficient of the fault parameters, the possible paths and speeds of fault development are deduced. The severity projection results, which include the fault evolution trend and the expected fault development speed, are output. The severity projection results are dynamically adjusted based on historical data of similar faults recorded in the fault latch memory and the current system operating status. The judgment thresholds for each fault level are dynamically adjusted. At the same time, the real-time severity and historical statistical characteristics of the fault are considered, and the comprehensive evaluation results are mapped to specific fault levels through multi-dimensional weight allocation. The fault level judgment is output after verification by historical data and dynamic calibration.
3. The method for high-voltage electrical safety protection of new energy vehicles based on multi-level linkage power outage as described in claim 1, characterized in that, The process of driving the actuator to perform the corresponding power-off operation includes the following steps: Based on the fault level, determine the set of target actuators that need to be operated. Combine the real-time status of each actuator to generate a complete blueprint of execution instruction sequence containing the operation object, action sequence and time node; output a primary execution instruction sequence containing complete timing logic. The primary execution instruction sequence is tested for communication status and load capacity of the main execution channel, and the primary execution instruction sequence is dynamically adjusted according to the test results. When the main channel is unobstructed, the packaging and sending strategy of the primary execution instructions is optimized. When channel delay or blockage is detected, a backup path is activated and the transmission method and parameters of the primary execution instructions are adjusted accordingly. The executable instruction set optimized for channel adaptability is output. The executable instruction set is converted into the physical drive signals required by the corresponding actuator, including the drive current of the contactor coil and the pulse parameters of the fuse ignition signal. After each physical drive signal is issued, the actuator status feedback loop is used to confirm whether the action has been successfully executed and to record the final execution status. The physical signal sequence that drives the actuator to complete the corresponding power-off operation and its execution confirmation result are output.
4. The high-voltage electrical safety protection method for new energy vehicles based on multi-level linkage power outage as described in claim 3, characterized in that, The process of converting an executable instruction set into the physical drive signals required by the corresponding actuator includes the following steps: Based on the target actuator type specified in the executable instruction, its inherent electrical characteristic parameter library is queried, and the abstract logical instruction is mapped to specific physical drive waveform parameters. Output a sequence of drive instructions with waveform parameters; Based on the real-time output capability of the system power supply and the physical response delay of the actuator, the issuance time, duration, and gain of each drive signal in the drive command sequence are finely adjusted; the amplified drive signal is output after time and power calibration. The amplified drive signal, after time and power calibration, is converted into the actual control level required by the high-side driver and H-bridge circuit power devices to generate the physical drive signal acting on the actuator. At the same time, a physical drive signal integrity monitoring loop samples the voltage and current waveforms actually output to the actuator in real time, compares them with the expected waveform parameters, and generates a signal integrity report.
5. The method for high-voltage electrical safety protection of new energy vehicles based on multi-level linkage power-off as described in claim 4, characterized in that, The process of mapping abstract logical instructions to specific physical drive waveform parameters includes the following steps: The logical identifiers in the executable instructions are decoded and converted into a unified type identifier that can be recognized by the internal actuator parameter library; at the same time, the existence and availability of the type identifier in the parameter library are verified. Based on the unified type identification code, the complete steady-state and transient electrical response characteristics of the corresponding actuator are retrieved from the inherent electrical characteristic parameter library of the actuator, which together constitute the electrical characteristic profile of the actuator; Based on the action state required by the original logic instruction, and combined with the boundary conditions and response procedures defined in the electrical characteristic profile, the specific drive waveform parameters that meet the action requirements and do not exceed the electrical tolerance range of the actuator are calculated.
6. The method for high-voltage electrical safety protection of new energy vehicles based on multi-level linkage power outage as described in claim 5, characterized in that, The process of calculating the specific drive waveform parameters that meet the action requirements and do not exceed the electrical tolerance range of the actuator includes the following steps: The target action required by the original logic instruction is deconstructed into several consecutive action stages, and the core electrical objective to be achieved in each action stage is identified. The key time nodes and required energy injection characteristics of each action stage are defined to obtain the action timing blueprint. Based on the steady-state and transient boundary conditions defined in the electrical characteristic profile, for each action stage in the action timing blueprint, the safe operating range of each waveform parameter within the action stage is calculated. The safe operating range constitutes a dynamically changing parameter boundary domain. Under the constraints of the parameter boundary domain, guided by the core electrical objectives of each action stage in the action timing blueprint, a multi-objective optimization strategy is adopted for numerical solution; a set of specific drive waveform parameters is synthesized.
7. The method for high-voltage electrical safety protection of new energy vehicles based on multi-level linkage power outage as described in claim 6, characterized in that, The process of numerically solving using a multi-objective optimization strategy includes the following steps: Based on the current security policy priority of the system, a quantitative weight coefficient is assigned to each core electrical target, resulting in a set of quantitative targets with weight coefficients; Within the multidimensional space defined by the dynamic parameter boundary domain, a systematic search is performed in the direction guided by the set of quantization targets, generating a series of exploration trajectories pointing to the optimal region. The exploration trajectories record the degree to which different combinations of driving waveform parameters achieve various quantization targets under the condition of satisfying constraints. Analyze the convergence trend of all exploration trajectories and identify those trajectory convergence points that achieve the best balance among multiple quantification objectives. Trajectory convergence points mean that further optimization of any single objective will come at the expense of other objectives, forming a Pareto optimal solution set for the multi-objective optimization problem. Select a set of specific driving waveform parameters suitable for the current working condition from the Pareto optimal solution set according to the preset decision rules.
8. The method for high-voltage electrical safety protection of new energy vehicles based on multi-level linkage power outage as described in claim 7, characterized in that, The process of identifying trajectory convergence points that achieve an optimal balance among multiple quantization objectives includes the following steps: For each candidate parameter point on the exploration trajectory, based on the measured or predicted values of its various performance indicators, the normalized achievement degree relative to each quantitative target is obtained, and the achievement degree is combined into a multi-dimensional vector, which is the multi-dimensional target achievement degree vector corresponding to each candidate parameter point. In a multidimensional space composed of multidimensional goal achievement vectors, the dominance relationships between points in the multidimensional space are obtained, and all non-dominated points that are not completely surpassed by other points are identified. The distribution density of non-dominated points in the vector space is analyzed, and points located in low-density regions with relatively balanced achievement in each dimension are selected to form a preliminary Pareto front. The result is a sparse and balanced Pareto optimal solution set. The Pareto optimal solution set, which is sparsely and evenly distributed, is comprehensively scored for each point in the Pareto optimal solution set according to the preset decision rules. By comparing comprehensive scores, a trajectory convergence point that achieves the best balance among multiple objectives is identified.
9. The method for high-voltage electrical safety protection of new energy vehicles based on multi-level linkage power outage as described in claim 1, characterized in that, The sensor layer, including a high-precision insulation monitor, a triaxial impact acceleration sensor, and a battery pack pressure sensor, continuously collects high-voltage system parameters to form a raw data stream; the high-voltage system parameters include insulation resistance, impact acceleration, battery pack pressure, and temperature.
10. A high-voltage electric safety protection system for new energy vehicles based on a multi-level linkage power-off method as described in any one of claims 1 to 9, characterized in that, The high-voltage electrical safety protection system for new energy vehicles based on multi-level linkage power outage includes: Data stream acquisition module 1 is used to continuously collect high-voltage system parameters from the sensor layer, which includes a high-precision insulation monitor, a triaxial impact acceleration sensor, and a battery pack pressure sensor, to form a raw data stream; the high-voltage system parameters include insulation resistance, impact acceleration, battery pack pressure, and temperature; The diagnostic central processing module is used to process the raw data stream through multiple levels of the diagnostic central processing, and obtain the fault level judgment by combining multi-source data fusion and threshold comparison with fault code and timestamp recorded by the fault latch memory; The power failure operation execution module is used to generate execution instructions based on the fault level and drive the actuator to perform the corresponding power failure operation. In the case of a Level 1 fault, a warning and power limitation are implemented: a command is sent via the CAN bus to limit the motor power to 70% and trigger a yellow alarm on the instrument panel; in the case of a Level 2 fault, a partial power cut is implemented: the corresponding branch contactor is disconnected and the 12V backup power supply is activated; in the case of a Level 3 fault, a full power cut is implemented: an emergency CAN signal is broadcast, the main positive and negative contactors are disconnected, and if the voltage does not drop below 60V within 10ms, the blast fuse is detonated and the vehicle rescue system is triggered; if the electronic channel fails, the hard-wired backup circuit directly triggers a Level 3 power cut.
Citation Information
Patent Citations
High-voltage high-power supply discharging device
CN107888062A
Circuit and method for improving robustness of up-down high voltage of new energy automobile
CN120096484A
Cited By
Hierarchical control method and system for safe shutdown of hydrogen-electricity hybrid electric vehicle
CN122100854A