Two-stage safety control system and method for mobility scooter for old people
The dual-level safety control system for elderly mobility scooters, which employs graded power supply and NFC identity authentication, solves the safety hazards of traditional control methods, achieves safety protection and identity recognition for electric vehicles, and improves safety and management convenience.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-01-30
- Publication Date
- 2026-04-17
AI Technical Summary
Traditional control methods for electric vehicles such as mobility scooters for the elderly pose safety risks. Mechanical keys are easily copied, cannot distinguish between vehicle power-on and driving permissions, and cannot effectively identify the driver's identity, leading to risks of misoperation and unauthorized driving.
The system employs a two-level safety control system, which integrates the instrument cluster, drive controller, and power supply into a tiered power supply design. Combined with NFC identity authentication, it achieves physical and logical isolation between the vehicle's power supply and drive system, and tiered unlocking ensures safety.
It effectively prevents misoperation and unauthorized use, improves the safety and management convenience of elderly mobility scooters, and ensures that the vehicle can only be driven after legal identity verification.
Smart Images

Figure CN121871401A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of vehicle control technology, specifically to a two-stage safety control system and method for elderly mobility scooters. Background Technology
[0002] Currently, electric vehicles such as mobility scooters and electric wheelchairs typically use traditional mechanical keys or a single power switch to control the power supply to the entire vehicle. Once powered on, the drive system is immediately operable, and the user can drive the vehicle directly by operating a throttle or joystick. This control method presents significant safety hazards: firstly, mechanical keys are easily copied or physically cracked, offering weak anti-theft capabilities; secondly, there is no distinction between vehicle power-on and driving permissions, meaning anyone with access to the power switch could unintentionally start the vehicle, causing it to move unexpectedly, which is particularly dangerous for elderly people with mobility impairments or cognitive decline. Furthermore, traditional solutions cannot effectively identify the driver and manage access permissions, hindering the safe sharing and monitoring of vehicles.
[0003] In the existing technology, although some vehicles have tried to use remote control or simple electronic locks, most still do not completely isolate the power supply of the vehicle's basic functions from the drive system enablement in terms of both physical and logical aspects, and cannot fundamentally prevent misoperation or unauthorized driving. Summary of the Invention
[0004] To address the aforementioned technical problems, this invention proposes a two-stage safety control system and method for elderly mobility scooters.
[0005] To solve the above-mentioned technical problems, the present invention adopts the following technical solution: A two-stage safety control system for an elderly mobility scooter includes an integrated instrument assembly, a drive controller, a motor, and a power supply. The integrated instrument assembly includes a main control microcontroller unit, and connected to it a power control module, an identity information collection module, and a communication module. The power control module is configured to, in response to a power-on signal, sequentially supply power to other modules in the integrated instrument assembly and the drive controller. The main control microcontroller unit is configured to, after the identity information collection module completes identity verification, send a drive enable command to the drive controller via the communication module. The drive controller is connected to both the power supply and the motor, and is configured to drive the motor only when it receives the drive enable command.
[0006] Preferably, the power control module includes a first electronic switch circuit and a second electronic switch circuit; the first electronic switch circuit is connected between the power supply and the integrated instrument assembly, and is used to control the power supply of the integrated instrument assembly; the second electronic switch circuit is connected between the main control microcontroller unit and the drive controller, and is used to output control power to the drive controller.
[0007] Preferably, the identity information collection module is an NFC card reader module, used to read identity information.
[0008] Preferably, the integrated instrument assembly further includes a display module and a USB charging module; the display module is used to provide visual interaction, and the USB charging module is used to provide external charging power.
[0009] Preferably, the drive controller is further configured to control the motor to be in a high-resistance or electric braking state when the drive enable command is not received.
[0010] Preferably, the main control microcontroller unit is connected to a secure memory for storing a list of authorized identity information; the main control microcontroller unit has a preset administrator channel, which supports updating the list of authorized identity information stored in the secure memory through the preset administrator channel.
[0011] Preferably, the main control microcontroller unit stores personalized settings corresponding to the identity information, and the main control microcontroller unit is further configured to: after successful verification, the main control microcontroller unit automatically adjusts the vehicle status according to the corresponding personalized settings.
[0012] Secondly, a two-level safety control method for elderly mobility scooters based on the above system is provided, including the following steps: S1: The system is locked; S2: In the locked state, when the user triggers the power-on signal, the following control process is executed: S201: The main control microcontroller unit of the integrated instrument assembly controls the power control module to turn on the first electronic switch circuit, so that the power supply provides power to the integrated instrument assembly itself and completes the initialization; S202: The main control microcontroller unit controls the power control module to turn on the second electronic switch circuit, outputs control power to the drive controller, so that the drive controller is powered on and starts, but the motor start is locked, and the system enters the first level of unlocking state. S2. In the first-level unlocked state, execute the following control procedure: S301: The main control microcontroller unit drives the identity information collection module to read identity information; S302: The main control microcontroller unit compares and verifies the read identity information with the authorization information pre-stored in the secure memory; S303: If the verification is successful, the main control microcontroller unit sends a drive enable command to the drive controller through the communication module; after receiving the command, the drive controller unlocks the motor and the vehicle enters a drivable state; if the verification fails, the main control microcontroller unit does not send the drive enable command.
[0013] Preferably, the method further includes step S4, which includes: when the power-on signal is triggered again in the second-level unlocked state, the main control microcontroller unit controls the power control module to sequentially disconnect the second electronic switch circuit and the first electronic switch circuit.
[0014] Preferably, step S2 further includes: maintaining periodic heartbeat communication between the integrated instrument assembly and the drive controller; if the heartbeat communication is abnormally interrupted for more than a preset time, the system returns to the first-level unlock state, and the drive controller controls the motor to enter the braking state.
[0015] This invention decomposes vehicle control into a first-level unlock and a second-level unlock, completely separating the vehicle's power supply and motor drive enablement physically and logically, achieving progressive safety protection from general functions to exclusive driving rights. The first-level unlock only provides power for basic functions, posing no driving risk; the second-level unlock requires NFC authentication to release drive permissions, effectively preventing misoperation, unauthorized use, and theft. Hardware and communication isolation between the two levels ensures that no fault or illegal operation at either level can trigger vehicle operation, greatly improving the safety and management convenience of electric vehicles such as elderly mobility scooters. Attached Figure Description
[0016] Figure 1 This is a schematic diagram of the structure of the dual-level safety control system for elderly mobility scooters provided in an embodiment of the present invention. Detailed Implementation
[0017] To further illustrate the technical means and effects of the present invention in achieving its intended purpose, the following detailed description of the specific implementation methods, structures, features, and effects of the present invention, in conjunction with the accompanying drawings and preferred embodiments, is provided below.
[0018] This invention provides a two-level safety control system and method for elderly mobility scooters, aiming to solve safety problems that may be caused by accidental power-on or unauthorized operation of electric vehicles through a two-level control that combines physical isolation and logical authentication.
[0019] See Figure 1In one embodiment, the dual-level safety control system 100 for the elderly mobility scooter mainly includes an integrated instrument assembly 10, a drive controller 20, a power supply 30, and a motor 40.
[0020] The integrated instrument cluster 10 serves as the user interaction and primary control center, including a main control microcontroller unit 11, a power control module 12, an NFC card reader module 13, a display module 14, a USB charging module 15, a communication module 16, and a button module 17. The main control microcontroller unit 11 connects to and controls the other modules.
[0021] The power control module 12 receives instructions from the main microcontroller unit 11 and controls the power supply to the entire control system. Specifically, it includes a first electronic switch circuit composed of transistors Q1 and Q2, and a second electronic switch circuit composed of transistors Q3 and Q4. The first electronic switch circuit controls the connection and disconnection between the vehicle power supply 30 and the integrated instrument assembly 10, enabling the instrument to power itself. In this embodiment, the power supply 30 is connected to the first electronic switch circuit through internal wiring of the drive controller 20, but does not directly supply power to the drive controller 20. The second electronic switch circuit controls the connection and disconnection between the drive controller 20 and the control power supply ACC, thereby completing the power supply control for the entire control system.
[0022] The NFC reader module 13 is used for contactless reading of the encrypted identity information of NFC smart keys. The main control microcontroller unit 11 has a secure memory internally or externally configured to store a list of one or more authorized NFC key identity information.
[0023] The display module 14 is used to display vehicle status information such as vehicle speed, battery level, fault codes, and system status, including system statuses such as "waiting for authentication" and "authentication successful".
[0024] After completing the first-level lock, the USB charging module 15 obtains power from the vehicle battery to provide charging power for external devices.
[0025] The communication module 16 is used to send drive enable commands to the drive controller 20, using UART (such as RX / TX), CAN or LIN bus protocols.
[0026] The button module 17 provides a physical input interface for users, including at least a power button for triggering the first level of unlocking, and may also include auxiliary function buttons such as gear switching and lighting control.
[0027] The drive controller 20, as the core of the vehicle's power control, is connected to the integrated instrument cluster 10 via a wiring harness. The wiring harness includes at least a positive power line (B+), a negative power line (GND), a control power line (ACC), and communication lines (RX, TX). The drive controller 20 internally contains motor control logic, including: when powered on by the ACC but without a drive enable command, it performs a self-test but immediately enters a power-unlocked state. In this state, the drive controller 20 does not respond to any driving commands from the operating interface. The drive controller 20 continuously listens for commands from the communication module 16, and only upon receiving a drive enable command will it unlock its internal lock and enter a state where it can normally control the motor's operation.
[0028] The following is combined Figure 1 The workflow of the dual-level security control method of this invention is described in detail. The system has three states: locked state, first-level unlocked state, and second-level unlocked state.
[0029] S1: Before the power button 171 is pressed, the system is in a locked state. In this state, the vehicle is not powered and all functions that require power to drive are unavailable.
[0030] S201: When the user presses the power button 171 on the button module 17, the main control microcontroller unit 11 of the integrated instrument assembly 10 detects the button signal and turns on the first electronic switch circuit in the power control module 12 to connect the vehicle's main power supply B+, thus powering the integrated instrument assembly 10 itself. The instrument completes startup and initialization.
[0031] S202: The main control microcontroller unit 11 controls the second electronic switch circuit in the power control module 12 to conduct, outputting an effective voltage to the control power line ACC, allowing power to be supplied to the drive controller 20. The drive controller 20 is powered on and completes self-test, and the system enters the first-level unlocked state.
[0032] At this time, the motor is de-energized, the vehicle is powered on but cannot be driven, the instrument screen is lit, the USB charging module 15 can charge mobile phones and other devices, and accessories such as lights and horns can be used. However, since the drive controller 20 is locked, the vehicle will not move even if the throttle is accidentally operated, thus eliminating the safety risks that may be caused by accidental operation.
[0033] S301: In the first-level unlock state, the main control microcontroller unit 11 continuously or periodically drives the NFC reader module 13 to attempt to read nearby NFC smart keys.
[0034] S302: When a legitimate NFC smart key enters the reader's sensing area, the NFC reader module 13 reads the key's identity information, such as UID or encrypted data of a specific sector.
[0035] S303: The main microcontroller unit 11 compares and verifies the read information with a list of authorized key information pre-stored in its secure storage. Verification can be a simple UID match or a more advanced cryptographic challenge-response verification.
[0036] S304: Perform the corresponding operation based on the verification result: a) If verification is successful, the main control microcontroller unit 11 determines that the identity information is valid and then sends a drive enable command to the drive controller 20 through the communication module 16. After the drive controller 20 receives and confirms the command, it supplies power to the motor and allows the drive controller to send control signals to the motor, enabling the motor to respond to driving operations. At the same time, the main control microcontroller unit 11 can control the display module 14 to display prompts such as "Authentication successful, ready to drive". At this time, the system enters the second-level unlock state.
[0037] b) If verification fails, the main microcontroller unit 11 will not send a drive enable command and will not perform any operations related to driving permissions. The drive controller 20 will remain locked due to the lack of a command, and the vehicle will be absolutely prohibited from driving. The display module 14 may display "Authentication failed" or remain unresponsive.
[0038] S4: After the system enters the second-level unlock state, it can be driven normally. When the user presses the power button 171 again, the main control microcontroller unit 11 will sequentially disconnect the second electronic switch circuit and the first electronic switch circuit, thereby cutting off the power line ACC to the output of the drive controller 20 and the power connection of the integrated instrument assembly. The system is completely powered down and returns to the locked state.
[0039] To further enhance safety, the control system also includes the following functions: 1) The system supports NFC key authorization and deregistration on vehicles through a specific administrator channel, which greatly improves the convenience and security of vehicle sharing and care handover.
[0040] 2) The drive enable command sent by the communication module adopts a reliable communication format including a checksum. During driving, the integrated instrument cluster 10 and the drive controller 20 maintain periodic heartbeat communication. If the communication is abnormally interrupted for more than a preset time, the drive controller 20 automatically triggers the safety strategy, cancels the enable and re-enters the locked state, and controls the motor to perform smooth braking to ensure that the vehicle will not lose control due to system failure.
[0041] 3) The system can bind the identity information of different NFC keys with personalized settings, including maximum speed limit, acceleration curve, seat preset, etc. After the main control microcontroller unit 11 successfully verifies the identity information and enters the second-level unlocking state, the system controls the vehicle to make automatic adjustments according to the corresponding personalized settings, realizing one person, one key, one mode.
[0042] This invention employs a two-stage power unlocking architecture to separate power on / off from drive enable, and introduces NFC-based identity authentication as the sole credential for driving rights, thus constructing a safety control system with clear permissions, preventing accidental operation and unauthorized use. This solution is particularly suitable for electric vehicles used by the elderly and people with mobility impairments where safety requirements are extremely high, and has significant practical value.
[0043] The above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention in any way. Although the present invention has been disclosed above with reference to preferred embodiments, it is not intended to limit the present invention. Any person skilled in the art can make some modifications or alterations to the above-disclosed technical content to create equivalent embodiments without departing from the scope of the present invention. Any brief modifications, equivalent changes and alterations made to the above embodiments based on the technical essence of the present invention without departing from the scope of the present invention shall still fall within the scope of the present invention.
Claims
1. A two-stage safety control system for elderly mobility scooters, characterized in that, It includes an integrated instrument assembly, a drive controller, a motor, and a power supply; the integrated instrument assembly includes a main control microcontroller unit, and a power control module, an identity information collection module, and a communication module connected thereto; the power control module is configured to, in response to a power-on signal, sequentially supply power to other modules in the integrated instrument assembly and the drive controller; The main control microcontroller unit is configured to send a drive enable command to the drive controller through the communication module after the identity information collection module completes the identity verification; the drive controller is connected to the power supply and the motor respectively, and is configured to drive the motor to run only when the drive enable command is received.
2. The system according to claim 1, characterized in that, The power control module includes a first electronic switch circuit and a second electronic switch circuit; the first electronic switch circuit is connected between the power supply and the integrated instrument assembly, and is used to control the power supply of the integrated instrument assembly. The second electronic switch circuit is connected between the main control microcontroller unit and the drive controller, and is used to output control power to the drive controller.
3. The system according to claim 1, characterized in that, The identity information collection module is an NFC card reader module, used to read identity information.
4. The system according to claim 1, characterized in that, The integrated instrument assembly also includes a display module and a USB charging module; the display module is used to provide visual interaction, and the USB charging module is used to provide external charging power.
5. The system according to claim 1, characterized in that, The drive controller is further configured to control the motor to be in a high-resistance or electric braking state when the drive enable command is not received.
6. The system according to claim 1, characterized in that, The main control microcontroller unit is connected to a secure memory for storing a list of authorized identity information; the main control microcontroller unit has a preset administrator channel, which supports updating the list of authorized identity information stored in the secure memory through the preset administrator channel.
7. The system according to claim 1, characterized in that, The main control microcontroller unit stores personalized settings corresponding to the identity information, and the main control microcontroller unit is further configured to automatically adjust the vehicle status according to the corresponding personalized settings after the verification is successful.
8. A two-stage safety control method for an elderly mobility scooter based on the system described in any one of claims 1 to 7, characterized in that, Includes the following steps: S1: The system is locked; S2: In the locked state, when the user triggers the power-on signal, the following control process is executed: S201: The main control microcontroller unit of the integrated instrument assembly controls the power control module to turn on the first electronic switch circuit, so that the power supply provides power to the integrated instrument assembly itself and completes the initialization; S202: The main control microcontroller unit controls the power control module to turn on the second electronic switch circuit, outputs control power to the drive controller, so that the drive controller is powered on and starts, but the motor start is locked, and the system enters the first level of unlocking state. S3: In the first-level unlock state, the following control procedure is executed: S301: The main control microcontroller unit drives the identity information collection module to read identity information; S302: The main control microcontroller unit compares and verifies the read identity information with the authorization information pre-stored in the secure memory; S303: If the verification is successful, the main control microcontroller unit sends a drive enable command to the drive controller through the communication module; After receiving the instruction, the drive controller unlocks the motor, and the vehicle enters the second-level unlock state. If the verification fails, the main microcontroller unit will not send the drive enable command.
9. The method according to claim 8, characterized in that, It also includes step S4, which includes: when the power-on signal is triggered again in the second-level unlock state, the main control microcontroller unit controls the power control module to sequentially disconnect the second electronic switch circuit and the first electronic switch circuit.
10. The method according to claim 8, characterized in that, Step S2 further includes: maintaining periodic heartbeat communication between the integrated instrument assembly and the drive controller; if the heartbeat communication is abnormally interrupted for more than a preset time, the system returns to the first-level unlock state, and the drive controller controls the motor to enter the braking state.