Method and apparatus for controlling state of contactor

By combining a low-cost basic power management chip with a controller and high-side and low-side drive units, the problem of contactor state retention during reset of the high-voltage bus power supply controller is solved, achieving safe power supply and fault diagnosis during reset, meeting functional safety standards, and reducing costs.

CN121879209APending Publication Date: 2026-04-17VITESCO TECH INVESTMENT (CHINA) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
VITESCO TECH INVESTMENT (CHINA) CO LTD
Filing Date
2024-10-16
Publication Date
2026-04-17

AI Technical Summary

Technical Problem

In the existing technology, the high-voltage bus power supply controller has difficulty in effectively maintaining the contactor state during the reset period, which causes the vehicle to lose power when driving at high speed, posing a safety risk. At the same time, high-performance power management chips are expensive and difficult to meet the functional safety level requirements under complex operating conditions.

Method used

By combining a low-cost basic power management chip with the controller, the contactor state is controlled through high-side and low-side drive units. Combined with the delay hold function and the delay hold function of the low-side drive unit, the contactor is ensured to maintain the appropriate state during reset, and the fault diagnosis function of functional safety level is used to prevent unexpected contactor state changes.

Benefits of technology

It enables complex control functions during controller reset, meets functional safety level requirements, avoids vehicle power loss due to contactor state changes, ensures safe power supply and fault diagnosis functions for the vehicle during reset, and reduces costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121879209A_ABST
    Figure CN121879209A_ABST
Patent Text Reader

Abstract

A method and an apparatus for controlling the state of a contactor are presented. In the method, the state of the contactor is controlled by a high-side driving unit and a low-side driving unit which are triggered by a controller, the method comprises the following steps: responding to a reset request of the controller; selectively triggering, using the controller, a latency hold function based on at least one of a setting of the latency hold function and a low-side control signal output by the low-side driving unit, wherein the low-side control signal is held at least within a predetermined time in the latency hold function; a turn-off path check is selectively performed for the low side drive unit based on at least one of a setting of a latency hold function and a trigger condition using the reset controller. According to the method and the device, the complex control function in the reset period of the controller can be realized at low cost, and the requirement of the corresponding function safety level is met.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to signal processing and control, and more particularly to methods, apparatus, computer-readable storage media, and computer program products for controlling the state of a contactor during the reset process of a controller. Background Technology

[0002] As the requirements for the design and performance reliability of high-voltage relays used in high-voltage control systems to control the power supply and operation of vehicle high-voltage buses become increasingly stringent, a control method has emerged that uses synchronous drive relays via high-side and low-side drives to control bus contactors. Simultaneously, relay and contactor control strategies need to consider control functionality and safety under extreme failure scenarios. For example, a controller error during high-speed vehicle operation may lead to abnormal signal acquisition (such as an abnormal accelerator pedal signal value of 100%). High-voltage control systems typically use a reset mechanism to quickly repair or clear this signal to avoid unintended prolonged acceleration. However, an unintended system reset may cause the relays used to keep the contactors on the high-voltage bus closed to open, interfering with the normal power supply to the vehicle bus, resulting in a loss of power to the drive motor and causing the vehicle to lose power. This loss of power at high speeds poses a serious risk to vehicle and personnel safety, while failing to reset the controller could also lead to danger due to vehicle speeding.

[0003] Currently, equipment suppliers are proposing to implement relay control hold function during controller restart by using a high-performance power management chip (SBC) with timing function, where the control logic is carried out through the interaction between the vehicle controller and the SBC.

[0004] However, high-performance SBCs with timing functions are expensive and require the design of special relay driver chips and control logic to meet the control reliability and stability under complex multi-operating conditions and multi-application scenarios. Moreover, they cannot coordinate and execute high functional safety levels well.

[0005] Therefore, there is a need to improve the contactor control scheme on the high-voltage bus during the existing controller reset period. Summary of the Invention

[0006] To address at least one of the problems mentioned above, this disclosure proposes methods and apparatus suitable for controlling the state of contactors, such as high-voltage bus power supply and operating signals in vehicles, in order to achieve complex control functions during controller reset at low cost and meet the requirements of the corresponding functional safety level.

[0007] According to one aspect of this disclosure, a method for controlling the state of a contactor is proposed, the state of which is controlled by a high-side drive unit and a low-side drive unit triggered by a controller. The method includes: in response to a reset request of the controller, selectively triggering a delay-hold function using at least one of a controller setting based on a delay-hold function and a low-side control signal output by the low-side drive unit, wherein the low-side control signal is held for at least a predetermined time in the delay-hold function; and selectively performing a shutdown path check using the reset controller for at least one of the low-side drive unit setting based on the delay-hold function and the triggering condition.

[0008] According to another aspect of this disclosure, an apparatus for controlling the state of a contactor is provided, comprising: a controller configured to: trigger a high-side drive unit and a low-side drive unit to control the state of the contactor; in response to a reset request of the controller, selectively triggering a delay-hold function based on at least one of a setting of a delay-hold function and a low-side control signal output by the low-side drive unit, wherein the low-side control signal is held for a predetermined time in the delay-hold function; after a reset, selectively performing a shutdown path check for at least one of the setting of the delay-hold function and the triggering condition of the low-side drive unit; a high-side drive unit and a low-side drive unit; and at least one relay configured to be driven by the high-side drive unit and the low-side drive unit to control the state of the contactor.

[0009] According to another aspect of this disclosure, a computer-readable storage medium is provided on which a computer program is stored, the computer program including executable instructions that, when executed by a processor, implement the method as described above.

[0010] According to another aspect of this disclosure, an electronic device is proposed, including a processor and a memory for storing executable instructions of the processor; wherein the processor is configured to execute the executable instructions to implement the method described above.

[0011] According to another aspect of this disclosure, a computer program product is provided, comprising a computer program that, when executed by a processor, implements the method described above.

[0012] According to another aspect of this disclosure, a vehicle is provided, including means for controlling the state of a contactor as described above.

[0013] By adopting the above-described scheme proposed in the embodiments of this disclosure, a lower-cost basic power management chip (SBC) can be selected and combined with a controller to implement high-side and low-side drive units for relay driving to control the state of contactors, meeting design requirements, especially the complex control functions required for power supply and operation of the high-voltage bus in vehicle high-voltage control systems. This allows the basic SBC to take over the controller's drive and control functions for relays and contactors during various processes, including before, during, and after the controller performs a reset operation in response to a reset request, and during initialization. This provides sufficient time and conditions to decide on the control strategy for the state of contactors on the high-voltage bus, enabling functional safety (e.g., ASIL B) based closing and closing operations of relays and contactors. At the same time, it ensures that the fault diagnosis function of ECM3 (Controller Level 3 Function Monitoring) and controller software errors do not interfere with the normal control of the high-voltage control system, and prevents unexpected relay closing. It also avoids erroneous execution of interface instructions due to control authority takeover between software layers during initialization. Attached Figure Description

[0014] The above and other features and advantages of this disclosure will become more apparent from a detailed description of exemplary embodiments thereof with reference to the accompanying drawings.

[0015] Figure 1 This is a schematic signal connection diagram of an apparatus for controlling the state of a contactor according to an embodiment of the present disclosure.

[0016] Figure 2 This is a schematic logic flowchart of a software-coordinated control strategy related to a controller reset operation, according to embodiments of the present disclosure.

[0017] Figure 3 This is a schematic flowchart of a method for controlling the state of a contactor according to an embodiment of the present disclosure.

[0018] Figure 4 This is a schematic block diagram of an electronic device according to an embodiment of the present disclosure. Detailed Implementation

[0019] Exemplary embodiments will now be described more fully in conjunction with the accompanying drawings. However, these exemplary embodiments can be implemented in many forms and should not be construed as limited to the embodiments set forth herein; rather, these embodiments are provided to make the disclosure comprehensive and complete, and to fully convey the concept of the exemplary embodiments to those skilled in the art. In the drawings, the dimensions of some elements may be exaggerated or modified for clarity. The same reference numerals in the drawings denote the same or similar structures, and therefore their detailed description will be omitted.

[0020] Furthermore, the described features, structures, or characteristics may be combined in any suitable manner in one or more embodiments. Numerous specific details are provided in the following description to enhance a full understanding of embodiments of this disclosure. However, those skilled in the art will recognize that the technical solutions of this disclosure may be practiced without one or more of the specific details described, or other methods, elements, etc., may be employed. In other instances, basic or well-known structures, methods, or operations are not shown or described in detail to avoid obscuring various aspects of this disclosure.

[0021] The control scenarios mentioned in this disclosure can be, for example, in vehicles such as new energy vehicles, where the power supply and operation of vehicle equipment connected to the high-voltage bus are controlled by controlling the contactor state that can turn the high-voltage bus on and off. Depending on the type of vehicle equipment being controlled, the controller implementing the contactor state control function may include a microcontroller (MCU) of the high-voltage control system of the vehicle drive system that manages the power supply to the drive motor, or a controller or microcontroller in another vehicle subsystem. These vehicle subsystems include, but are not limited to, vehicle drive systems, battery charging (fast charging and normal charging) systems, braking systems, safety systems, air conditioning systems, entertainment systems, navigation systems, accessory systems, etc. These high-voltage control systems can respectively control the on / off of the high-voltage bus that supplies power and operates vehicle equipment such as drive motors, power batteries, and charging equipment. Those skilled in the art will understand that the solutions disclosed herein are not limited to maintaining and ensuring functional safety during the reset operation of the vehicle controller; they can also be applied to other vehicles and other devices and systems with controllers that provide control over the power supply and operation of the high-voltage bus. This disclosure uses an MCU in the high-voltage control system of a vehicle drive system as an example of a controller to illustrate the technical details of the solution, but the application scenarios of the solutions disclosed herein are not limited to this.

[0022] Generally, contactor elements are used in high-voltage, high-current environments to connect and disconnect high-voltage buses or lines. In vehicle control systems, controllers (and further microcontrollers) such as application-specific integrated circuits (ASICs), DSPs, etc., are typically used to receive and transmit control and data signals in low-voltage or low-current environments using power supply and drive voltages such as 12V or lower. In the MCU reset scenario of the high-voltage control system of this disclosure, the appropriate type and number of contactors can be selected based on the high-voltage control system and its corresponding bus type and number to isolate the low-voltage and high-voltage environments. According to embodiments of this disclosure, the controller can control and switch the contactor state by driving relays. The relays can be driven synchronously by both high-side and low-side control signals. Generally, when both high-side and low-side control signals drive the relays simultaneously, if both control signals drive the relays to control the contactor to reach the closed state, the contactor will remain or change to the closed state according to the previous state; and if at least one of the two control signals drives the relays to control the contactor to reach the open state, the contactor will remain or change to the open state according to the previous state. For example, when the contactor is previously in a closed state, both high-side and low-side control signals must simultaneously control the contactor to maintain the closed state; otherwise, if at least one control signal drives a relay to open the contactor (especially if both control signals open the contactor), the contactor will be changed to the open state. According to embodiments of this disclosure, the controller can also perform corresponding functions through other components and methods, different from relays, capable of receiving low-voltage control signals to drive contactors in high-voltage environments.

[0023] In this disclosure, controller reset includes software reset, hardware reset, and reset caused by external interference. Software reset includes, for example, abnormal signal acquisition due to controller operational errors (e.g., the accelerator pedal signal being abnormally assigned a value of 100%), or controller software program crashes. In addition to unexpected controller software resets, normal reset operations can also be performed on the controller during system power-on and initialization. When the controller's software initialization fails or initialization leads to interface instruction errors, the corresponding reset operation can also be categorized as an unexpected software reset. Hardware reset includes unexpected controller reset operations caused by hardware failures in the controller chip, chip interface circuit, power supply circuit, etc. Reset caused by external interference is a reset of the controller in response to abnormal external signal input, such as abnormal sensing data from sensors or abnormal signals from other units. Reset requests for controller reset are generally generated by the controller itself, but in specific cases, reset requests can also be issued by external devices. Upon receiving a reset request, the controller will determine whether to respond to the request and perform a reset operation.

[0024] When a controller is present or receives a reset request to perform a reset operation, it will be unable to provide control signals or receive control commands, sensed data, and event information from MCUs or sensors of other vehicle equipment during the period from the start of the reset until the restart is complete and normal control functions are restored. For example, when the controller is responsible for the high-voltage system control of the vehicle's drive system, it needs to continuously maintain the contactor of the bus voltage supplying the vehicle's drive system (e.g., drive motor and / or inverter) in a closed state to maintain normal vehicle operation (especially at high speeds) without losing driving force. Simultaneously, when a functional safety fault event occurs involving abnormal voltage, current (e.g., charging short circuit), or temperature, the controller needs to respond promptly to the safety fault event, such as immediately changing the contactor state to open to stop the bus power supply to the equipment. However, after the controller performs a reset operation, it will be unable to maintain the closed state of the contactor on the bus until the controller successfully restarts and resumes control, and during the reset period, the controller will also be unable to respond to functional safety fault events to immediately drive the relay to open the contactor. Meanwhile, after the controller restarts, the fault diagnosis function within the controller, designed to meet functional safety requirements, should not affect the power supply and operational control of the vehicle equipment previously operating normally on the high-voltage bus. Therefore, how to take over and complete the normal control and safety response of the controller during the reset operation period, as well as the design of control strategies to support fault diagnosis and detection for different vehicle safety levels, are important issues addressed in this disclosure.

[0025] Different controllers have different reset operation durations under different reset types. The ability to flexibly configure, enable, and disable processes or devices that perform normal control functions in place of the controller during the reset operation (e.g., a delay hold setting related to duration) is also a design consideration. Furthermore, to ensure redundancy and verification of control and safe operation, the corresponding processes and devices should provide signal monitoring and diagnostic functions, and be able to promptly achieve corresponding fault handling and functional safety objectives in the event of a failure in the process or device that replaces the controller.

[0026] The introduction of functional safety level coordination and implementation means that the adverse effects of power-on self-tests and other detection and diagnosis performed by the controller before resetting control on normally operating vehicle equipment also need to be considered.

[0027] The power management chip (SBC) is one way to ensure that the controller maintains normal high-voltage bus power supply and operation during a reset operation. After interacting with the controller (e.g., an MCU), the SBC takes over the task of driving relays to control contactor states during controller reset. It triggers the high-side drive (HSD) and low-side drive (LSD) units of the relays respectively, ensuring that the MCU reset does not affect the high-voltage control system's power supply and control of the relays. The SBC can also have a delay function implemented through a timer and an optional functional safety fault response function.

[0028] Building a high- and low-side relay drive holding scheme using a timer-enabled SBC (Self-Balancing Circuit) that can control the closing or opening of a relay-holding contactor requires the following key elements: a high-performance power management chip with timer functionality, specially processed or designed high-side and low-side drive units (chips), reliable latching circuitry, and compliance with functional safety power-on self-test requirements to support functional safety levels. However, the high performance and multi-functionality of a high-performance SBC come at a high cost. To take over the normal control and drive functions of the controller, a high-performance SBC requires specially processed or designed high-side and low-side drive chips. In the SBC, the latching function used to latch various control data and parameters, setting data, and timer data required for the delay holding function of the MCU before restart requires reliable latching circuitry. Latching circuitry is generally implemented using discrete circuitry that supports the relay operating current; however, the coordination and cooperation between discrete circuits is complex, and robustness testing for complex multi-condition and multi-scenario applications also requires special latching circuit design. If the MCU has a functional safety level, the SBC must also support functional safety level-related functions such as safe power-on self-test. In scenarios with high functional safety requirements, the SBC may not be able to effectively coordinate and execute the relevant ECM3 power-on self-test functions, thus affecting the assessment of functional safety levels. The corresponding software design logic is also relatively complex.

[0029] In this disclosure, the vehicle's engine (electronic) control module (ECM) has the function of continuously monitoring and controlling the normal operation of the engine. The ECM is a core control element in modern engine management systems. For internal combustion engines, the ECM can provide the optimal air-fuel ratio and optimal ignition timing based on engine operating conditions characterized by various sensor data (temperature, pressure, etc.), ensuring the engine is always in its optimal operating state to achieve optimal performance (power, economy, emissions). For the electric motor drive system of new energy vehicles (e.g., electric vehicles), the ECM can provide the optimal control signal for the drive motor based on the drive motor operating conditions characterized by sensor data, similarly ensuring the drive motor is in its optimal operating state. The Level 3 functional monitoring controller (ECM3) is a functional module in the underlying software of the ECM, including various fault diagnostic codes related to functional safety levels. Using a high-performance SBC to replace and take over the high-voltage control system MCU, which has powerful processing and computing capabilities, generally makes it difficult to support complex ECM3 fault code diagnosis. At most, it can only implement relay high / low side control functions during MCU restart and simple safety fault responses, making the hardware and design costs of supporting functional safety level SBCs very high.

[0030] A relatively simple general-purpose SBC can be used in conjunction with an LSD unit with a hardware timer to implement relay drive and contactor state control strategies based on functional safety levels (e.g., ASIL B) during MCU restart. ASIL B is a low to medium level of safety integrity functional safety, and general-purpose SBCs offer a better cost advantage than high-performance SBCs. A general-purpose SBC implementing an HSD unit can output relay high-side control signals using only controlled switching elements (e.g., MOSFETs) based on the high-side enable signal received at the enable port (SPI port). Relying on the combination of an LSD unit with delay and latching functions and a general-purpose SBC, the activation of the delay latching function in the current driving cycle is determined by the MCU's pre-setting of the LSD unit, which is simpler than the latching circuits and multi-input and multi-output port configurations in high-performance SBC solutions. The HSD unit and LSD unit, combined with the MCU, handle functions such as restart judgment and software coordination, making the relay high-side and low-side control logic simpler and more efficient. Using the MCU to implement functional safety strategies such as power-on self-test strategies for ECM3 is superior in terms of design ease, integrated chip controllability, and reliability compared to discrete circuit implementations.

[0031] Below, in conjunction with Figure 1 This disclosure provides a detailed description of the signal connection and control method of a device for controlling the state of a contactor according to embodiments of the present disclosure.

[0032] When controller 110 is present or a reset request is received, HSD unit 120 and LSD units 130 and 140 can be used to independently control the contactor state during the reset operation of controller 110, replacing controller 110. The number of drive units can be selected based on the number of signal output channels or ports provided by the ASIC used, the number of contactors and their terminals to be controlled, and the number and type of high-side and low-side control signals required by the corresponding relays. In this example, for cost and power consumption reasons, the chip constituting HSD unit 120 provides two signal outputs, while the chips constituting LSD units 130 and 140, in addition to providing one signal output each, also have a delayed signal output function (e.g., implemented through an on-chip timer). Depending on the applied control scenario, a greater number of chips can be selected to implement HSD and LSD units. Figure 1 In the application scenario of the vehicle high-voltage control system shown, the contactors may include a main contactor 1 for controlling the power battery 171 to supply power and operate the inverter 172 and drive motor 173 in the vehicle drive system through the high-voltage bus; a contactor 3 for controlling the fast charging of the power battery 171 through the high-voltage bus via an external fast charging station; a contactor 4 for controlling the normal charging of the power battery 171 through the high-voltage bus via a normal charging interface; and a contactor 5 for controlling the power battery 171 to supply power and operate vehicle equipment such as the air conditioning system, entertainment system, and accessory system 174 through the high-voltage bus or low-voltage bus. Figure 1 The state control of the contactor is described using the main contactor as an example. The main contactor has a positive main contactor terminal HV+ and a negative main contactor terminal HV-. In the embodiments of this disclosure, the high-side control signals of the relays 151A and 151B corresponding to the positive main contactor terminal HV+ and the negative main contactor terminal HV- always use the signal type used to keep the contactor in the closed state during the reset operation, so the HSD unit 120 can be implemented using a single SBC chip. On the low-side control signal side of the relays 151A and 151B corresponding to the positive main contactor terminal HV+ and the negative main contactor terminal HV-, due to the introduction of the time delay holding function, two signal types are used to keep the contactor in the closed state and the open state. For the above two contactor terminals, in this embodiment, one SBC chip is used to implement the LSD unit 130 that drives the relay 151A at the positive main contactor terminal HV+ and another SBC chip is used to implement the LSD unit 140 that drives the relay 151B at the negative main contactor terminal HV-.

[0033] The high-side driver chip of HSD unit 120 can be selected to not use direct pin control (NON). Its triggering is controlled through the high-side enable signal receiving port 122 (e.g., the SPI port of the MCU), disabling SPI check and connecting to the constant active high-side control drive power supply signal provided by the power control unit through the high-side control signal power supply port 123A. When a reset request is present or received to perform a reset operation, controller 110 transmits a high-side enable signal to the high-side enable signal receiving port 122 of HSD unit 120 through high-side enable signal port 111 to trigger HSD unit 120 to work and instruct HSD unit 120 to output a relay high-side control signal that keeps the contactor closed. When a reset request is present or received by controller 110 to perform a reset operation, low-side enable ports 113 and 115 send low-side enable signals to the low-side enable signal receiving ports 132 and 142 of the two LSD units 130 and 140, respectively, to trigger the two LSD units to work and instruct the LSD units to output a relay low-side control signal that keeps the contactor closed for a certain period of time. The same synchronous low-side enable signal can be sent to two LSD units so that the two LSD units can trigger the control function simultaneously.

[0034] The reset resource signal ports 112 and 114 of controller 110 transmit reset resource signals to the reset resource signal receiving ports 131 and 141 of LSD units 130 and 140, respectively, to set a predetermined time for the LSD unit to control the trigger to maintain the contactor in a closed state during the reset of controller 110 to implement a delay hold function. The predetermined time length data can be in the form of a counting threshold usable by a counter, such that the time from when the low-side enable signal triggers the LSD unit until the counter value reaches the counting threshold is equal to or greater than the predetermined time. The reset resource signal can be sent to the LSD unit at a time before triggering the LSD unit to take over the state control of the contactor by controller 110 (e.g., during power-on initialization of controller 110) to configure the delay hold function of the LSD unit. The predetermined time length data required for the delay hold function of the LSD unit generally remains unchanged during the state control of the contactor by triggering the LSD unit, and can be modified before the next triggering of the LSD unit for different control requirements. According to embodiments of this disclosure, different predetermined times can also be set for different types of reset operations.

[0035] The power supply port 121 of the HSD unit 120 is used to receive a power supply signal that provides power for the unit's operation. This power supply signal can be an HSD unit power supply signal (e.g., 5V DC) provided by a vehicle's power control unit. The HSD unit 120 can provide two relay high-side control signals through high-side control signal ports 124A and 124B to drive the relays and implement relay high-side control functions. The two high-side control signal ports can adopt the same configuration. For example, high-side control signal port 124A can be implemented by a controlled switching element such as a transistor or MOSFET device. Taking a MOSFET as an example, its drain is connected to the high-side control signal power supply port 123A to receive an active high-side control drive power supply signal (e.g., Vbat of 16V DC) provided by the power control unit, its source is connected to the high-side control signal port 124A, and its gate is connected to the high-side enable signal receiving port 122 to instruct the HSD unit 120 to output a first relay high-side control signal through the high-side control signal port 124A to drive the relay to maintain or change the contactor state in response to the received high-side enable signal. When the high-side enable signal is valid, it indicates that the controller 110 has a reset request or has received a reset request to perform a reset operation. This triggers and instructs the HSD unit 120 to output a first-level relay high-side control signal through port 124A to drive the contactor to remain closed. At this time, the high-side control signal power supply port 123A and the high-side control signal port 124A are connected, causing port 124A to output the high-level high-side control drive power supply signal from port 123A as the first-level relay high-side control signal to the corresponding relay. The controller 110 can output an invalid high-side enable signal when the reset operation is completed and the control function is restored, when the HSD unit is not required to take over the relay control function, or during functions such as safety power-on self-test. In these cases, the high-side control signal power supply port 123A and the high-side control signal port 124A are disconnected, causing port 124A to output a low-level first-level relay high-side control signal. The high-side enable signal can be set to active low. When the controller 110 is in a reset operation, the high-side enable signal port 111 is active low, ensuring that the HSD unit 120 always maintains a high-level first-path relay high-side control signal at port 123A, keeping the relay-driven contactor closed. Even if the controller 110 experiences an internal fault, the low-level signal state of the high-side enable signal port 111 can still cause the HSD unit 120 to output a high-level first-path relay high-side control signal, keeping the contactor closed.

[0036] Based on a similar configuration to the MOSFETs corresponding to ports 123A and 124A, the gates of the MOSFETs in HSD unit 120 corresponding to high-side control signal power supply port 123B and high-side control signal port 124B are connected to the high-side enable signal receiving port 122. In response to the received high-side enable signal, HSD unit 120 is instructed to output a second relay high-side control signal to drive the relay to maintain or change the contactor state. The signal logic of ports 123B and 124B, which output the second relay high-side control signal, is similar to that of ports 123A and 124A. That is, when the high-side enable signal is valid, it triggers and instructs HSD unit 120 to output a high-level second relay high-side control signal through port 124B to drive the contactor to remain closed; when the high-side enable signal is invalid, port 124B outputs a low-level second relay high-side control signal. Even when controller 110 is in a reset operation or experiencing an internal fault, HSD unit 120 can still output a low-level second relay high-side control signal to keep the contactor closed.

[0037] The first high-side relay control signal is used to drive the positive main contactor terminal control relay 151A, which controls the positive main contactor terminal HV+, to control the state of the main contactor. The second high-side relay control signal is used to drive the negative main contactor terminal control relay 151B, which controls the negative main contactor terminal HV-, to control the state of the main contactor. According to embodiments of this disclosure, the first and second high-side relay control signals use the same synchronous control signal, which can simultaneously drive the corresponding contactors to maintain a closed / open state or change from one state to another. The HSD unit 120 mainly provides the function of driving relays to control the state of the corresponding contactors. The delay holding function is implemented in the LSD units 130 and 140. Therefore, ports 124A and 124B can synchronously maintain the closed / open state of the positive main contactor terminal HV+ and the negative main contactor terminal HV- or synchronously change their state to an open or closed state by receiving the same high-side enable signal at the high-side enable signal receiving port 122.

[0038] To provide feedback signals for monitoring and diagnosing the high-side control function of relays, the first and second relay high-side control signals output from ports 124A and 124B are respectively converted into an active first relay high-side control feedback signal 125A and a second relay high-side control feedback signal 125B. Both feedback signals can be input to controller 110 or other controllers to monitor and diagnose the relay high-side control function and obtain the current status of the main contactor and its relays. Analog current signals of the relay high-side control signals can be used as feedback signals because the relays are driven by current signals, making the monitored current signals more accurate than voltage signals. Ports 124A and 124B of the HSD unit 120 can also be connected to the corresponding relay high-side control side using a standardized signal interface 160.

[0039] On the low-side control side of the relay, LSD units 130 and 140 are used to implement the low-side control function and the delay holding function of the relay.

[0040] The required number of LSD units can be determined based on the number of relays being controlled, the type of control signal, and the specifications of the driver chip used (e.g., whether it has a delay hold function, and the number of drive signal channels / ports it can provide). Figure 1 The embodiment shown employs two LSD units, wherein LSD unit 130 may be referred to as the first LSD unit and LSD unit 140 may be referred to as the second LSD unit.

[0041] The first LSD unit 130 is mainly used to provide the first relay low-side control signal for driving the main contactor terminal drive relay 151A. The relay 151A is used to control and change the state of the main contactor terminal HV+.

[0042] The reset resource signal receiving port 131 of the first LSD unit 130 is used to receive a reset resource signal from the controller 110 for setting a predetermined time. Simultaneously, port 131 can also be multiplexed to receive the power supply signal required for the operation of the SBC chip. The power supply signal can come from the vehicle's power control unit (e.g., 5V DC). The low-side enable signal receiving port 132 of the first LSD unit 130 receives a first low-side enable signal from the controller 110. In response to the received low-side enable signal, the first LSD unit 130 outputs a first relay low-side control signal through the low-side control signal port 134 to drive the relay 151A, thereby realizing the first relay low-side control function of maintaining or changing the state of the corresponding positive main contactor terminal HV+.

[0043] Similar to the HSD unit 120, the low-side control signal port 134 of the first LSD unit 130 can be implemented using a controlled switching element. In the example using a MOSFET as the controlled switching element, the drain of the MOSFET is connected to the low-side control signal power supply port 133 to receive an active low-side control drive power supply signal (e.g., 16V DC Vbat) provided by the power control unit, the source of the MOSFET is connected to the low-side control signal port 134, and its gate is connected to the low-side enable signal receiving port 132. Unlike the HSD unit 120, the first relay low-side control signal output from port 134 of the first LSD unit 130 can support a time-delay hold function, i.e., driving the relay to keep the state of the corresponding positive main contactor terminal HV+ unchanged for a period of time indicated by a predetermined time, or driving the relay to change the state of the corresponding contactor terminal directly without holding it for a period of time. The time-delay hold function can be implemented using a timer within the first LSD unit 130 based on a predetermined time length set by a reset resource signal. For example, the first LSD unit 130 can be configured such that when the controller 110 is present or receives a reset request to perform a reset operation, a valid first low-side enable signal indicates that the delay hold function of the LSD unit is triggered. The gate of the MOSFET controls the low-side control signal power supply port 133 and the low-side control signal port 134 to be turned on, so that port 134 outputs a high-level active low-side control drive power supply signal from port 133 to port 134 of the positive main contactor terminal drive relay 152A, as a high-level first relay low-side control signal that keeps the positive main contactor terminal HV+ closed and maintains this closed state for at least a predetermined time. In this way, during the reset operation of the controller 110, the first LSD unit triggers and takes over the relay low-side control function of the contactor until the controller 110 restarts and restores control. Maintaining the closed state of the contactor allows the bus circuit controlled by the contactor to be turned on, and the high-voltage drive system powered and operated by the bus circuit can work normally, avoiding damage to personnel and vehicles caused by loss of power during normal driving (especially high-speed driving).

[0044] The first low-side enable signal can be set to active low. When the controller 110 is in a reset operation, the low-side enable signal port 133 remains low, ensuring that the first LSD unit 130 always maintains a high-level first relay low-side control signal output from port 134 to drive the relay and keep the contactor closed for at least a predetermined time. Even if the controller 110 experiences an internal fault, the low-level signal state of the low-side enable signal port 113 can still cause the first LSD unit 130 to output a high-level first relay low-side control signal that keeps the contactor closed for a predetermined time.

[0045] When the first low-side enable signal is an invalid high level, the first LSD unit 130 does not trigger the delay hold function. The low-side control signal power supply port 133 is disconnected from the low-side control signal port 134, causing port 134 to output a low-level first relay low-side control signal to drive relay 152A at the positive main contactor terminal, directly changing the state of the HV+ terminal of the positive main contactor to open. The invalid first low-side enable signal can be used to instruct the controller 110 to disconnect the main contactor through software control or during power-on self-test, or to indicate the presence of a functional safety fault event such as voltage, current, or temperature. Unlike the active control command to disconnect the main contactor from the controller 110, the invalid first low-side enable signal indicating a functional safety fault event can come from port 113 of the controller 110, or from other control devices or signal buses. The first LSD unit 130 does not trigger the delay hold function (i.e., disables contactor delay) to respond to functional safety fault events and accurately control the contactor's state change, immediately switching from the closed state to the open state to protect the vehicle, battery, and personnel.

[0046] In this way, the first LSD unit 130 can use the corresponding relay low-side control signal to perform a reset operation in response to the presence or receipt of a reset request by the controller 110, and to respond to events such as functional safety faults during the reset operation, thereby realizing normal control of the contactor state and safety fault protection, as shown by the dashed line between the controller 110 and port 134 of the first LSD unit 130.

[0047] To monitor and diagnose whether the relay low-side control function implemented by the first relay low-side control signal output from the low-side control signal port 134 of the first LSD unit 130 is normal, an active first relay low-side control feedback signal 135 can be generated from the first relay low-side control signal output from port 134. Similar to the HSD unit 120, the feedback signal 135 can be an analog current signal. Similarly, a standardized signal interface 160 can be provided between port 134 and the corresponding relay low-side control side.

[0048] The second LSD unit 140 is mainly used to provide a second relay low-side control signal for driving the relay 151B at the negative main contactor terminal. The relay 151B is used to control and change the state of the HV- terminal of the negative main contactor.

[0049] The reset resource signal receiving port 141 of the second LSD unit 140 is used to receive a reset resource signal from the controller 110 for setting a predetermined time. Simultaneously, port 141 can also be multiplexed to receive the power supply signal required for the SBC chip to operate. The power supply signal can come from the vehicle's power control unit (e.g., 5V DC). The low-side enable signal receiving port 142 of the second LSD unit 140 receives a second low-side enable signal from the controller 110. In response to the received low-side enable signal, the second LSD unit 130 outputs a second relay low-side control signal through the low-side control signal port 144 to drive the relay 151B, thereby achieving the function of maintaining or changing the second relay low-side control of the corresponding negative main contactor terminal HV-. The first and second low-side enable signals can be the same synchronization signal, so that the relay low-side control of the positive and negative main contactor terminals is synchronized.

[0050] Similar to the first LSD unit 130, the low-side control signal port 144 of the second LSD unit 140 can be implemented using a controlled switching element. In the example using a MOSFET as the controlled switch, the drain of the MOSFET is connected to the low-side control signal power supply port 143 to receive an active low-side control drive power supply signal (e.g., 16V DC Vbat) provided by the power control unit, its source is connected to the low-side control signal port 144, and its gate is connected to the low-side enable signal receiving port 142. The second relay low-side control signal output from port 144 of the second LSD unit 140 can support a time-delay hold function, i.e., driving the relay to keep the state of the corresponding negative main contactor terminal HV- unchanged for a period of time indicated by a predetermined time, or driving the relay to change the state of the corresponding contactor terminal directly without holding it for a period of time. The time-delay hold function can be implemented by a timer within the second LSD unit 140 based on a predetermined time length data set by a reset resource signal. For example, the second LSD unit 140 can be configured such that when the controller 110 is present or receives a reset request to perform a reset operation, a valid second low-side enable signal indicates that the delay hold function of the LSD unit is triggered. The gate of the MOSFET controls the low-side control signal power supply port 143 and the low-side control signal port 144 to be turned on, so that port 144 outputs a high-level active low-side control drive power supply signal from port 143 to drive the relay 152B at the negative main contactor terminal as a high-level second relay low-side control signal that keeps the HV- terminal of the negative main contactor closed, and maintains this closed state for at least a predetermined time. In this way, during the reset operation of the controller 110, the second LSD unit triggers and takes over the relay low-side control function of the contactor until the controller 110 restarts and restores control. Maintaining the closed state of the contactor allows the bus circuit controlled by the contactor to be turned on, and the high-voltage drive system powered and operated by the bus circuit can work normally, avoiding the loss of power of the vehicle during normal driving (especially high-speed driving) and thus preventing safety hazards to personnel and vehicles.

[0051] The second low-side enable signal can be set to active low. When the controller 110 is in a reset operation, the low-side enable signal port 143 remains low, ensuring that the second LSD unit 140 always maintains a high-level second relay low-side control signal output from port 144 to drive the relay and keep the contactor closed for at least a predetermined time. Even if the controller 110 experiences an internal fault, the low-level signal state of the low-side enable signal port 115 can still cause the second LSD unit 140 to output a high-level second relay low-side control signal that keeps the contactor closed for a predetermined time.

[0052] When the second low-side enable signal is an invalid high level, the second LSD unit 140 does not trigger the delay hold function. The low-side control signal power supply port 143 is disconnected from the low-side control signal port 144, causing port 144 to output a low-level second relay low-side control signal to drive relay 152B at the negative main contactor terminal, directly changing the state of the negative main contactor terminal HV- to open. The invalid second low-side enable signal can be used to instruct the controller 110 to disconnect the main contactor via software control or during power-on self-test, or to indicate the presence of a functional safety fault event. The invalid second low-side enable signal indicating a functional safety fault event can come from port 115 of the controller 110, or from other control devices or signal buses. The second LSD unit 140 does not trigger the delay hold function (i.e., disables contactor delay) to respond to functional safety fault events and accurately control the contactor's state change, immediately switching from the closed state to the open state to protect the vehicle, battery, and personnel.

[0053] Similar to the first LSD unit 130, the second LSD unit 140 can use the corresponding relay low-side control signal to perform a reset operation in response to the presence or receipt of a reset request by the controller 110, and to respond to events such as functional safety faults during the reset operation, thereby realizing the normal control function of the contactor state and safety fault protection, as shown by the dashed line between the controller 110 and port 144 of the second LSD unit 140.

[0054] To monitor and diagnose whether the relay low-side control function implemented by the second relay low-side control signal output from the low-side control signal port 144 of the second LSD unit 140 is normal, an active second relay low-side control feedback signal 145 can be generated from the second relay low-side control signal output from port 144. The feedback signal 145 can be an analog current signal. Similarly, a standardized signal interface 160 can be set between port 145 and the corresponding relay low-side control side.

[0055] According to embodiments of this disclosure, the relay on the low-side control side of the relay is connected to the corresponding contactor terminal using a Crash hard-wire signal connection, so that when it is determined that the state of the contactor terminal needs to be changed to open, the contactor terminal can be immediately disconnected.

[0056] As described above, when the delay hold function is triggered, the high-side enable signal provided by the controller 110 to the HSD unit 120 causes the high-side control signal port 124 of the HSD unit 120 to continuously output a high-level valid high-side control signal to drive relays 151A and 151B to control the contactor terminals HV+ and HV- to remain closed during the reset operation of the controller 110. Whether these contactor terminals remain closed or change to open is mainly determined by the signal type of the first and second relay low-side control signals output from the first and second LSD units 130 and 140. When the first and second low-side enable signals indicate that the controller 110 has or has received a restart request (valid low-side enable signal), the first and second LSD units 130 and 140 will respond to the valid low-side enable signal by outputting high-level first and second relay low-side control signals to drive the relays to control the corresponding contactor terminals HV+ and HV- to remain closed to achieve the delay hold function, ultimately keeping the contactor terminals closed for a preset time. When the first and second low-side enable signals indicate that the controller 110 needs to control the main contactor to disconnect or there is a functional safety fault (invalid low-side enable signal), even if the controller 110 is in a restart operation and cannot respond to the safety fault event to control the contactor, the first and second LSD units 130 and 140 can take over the control function of the controller 110. In response to the invalid low-side enable signal, they output a low-level relay low-side control signal to drive the relay to control the corresponding contactor terminals HV+ and HV- to be in the open state, ultimately causing the contactor terminals to be directly changed to the open state.

[0057] Next, we will combine Figure 2 This invention introduces a software-coordinated control strategy related to a controller reset operation performed jointly by the controller and high-side and low-side control units according to embodiments of the present disclosure.

[0058] After the controller receives a reset request information generated by itself or received from other vehicle equipment or controllers, it identifies a control scenario that requires activating the delay hold function to drive the relay to keep the contactor closed. For example, this control scenario might be during vehicle operation (especially at high speeds), where the relay controls the main contactor on the bus supplying power to the drive system to remain closed. If an unexpected reset request occurs (e.g., an unexpected software reset, an unexpected hardware reset, or a reset caused by unexpected interference), the control software within the controller will collaboratively determine whether to drive the relay to keep the contactor closed or to directly disconnect it without maintaining its closed state. For control scenarios that do not require driving the relay to keep the contactor closed, it can be further determined whether the control scenario belongs to the controller's normal control function or a fault response to a functional safety malfunction. Normal control functions include, for example, a normal power-on reset, a predictable normal high-voltage reduction (normal disconnection of the vehicle equipment's bus power supply) in the application layer of the control software, or a normal sleep / wake-up event causing the control system to reinitialize.

[0059] The controller's control software executes the corresponding control strategy based on the actual detection and judgment results of the current control scenario.

[0060] The controller's control software includes base software (BSW) and application software (ASW). The BSW, similar to a driver, receives and interprets instructions and data from the ASW to drive hardware operations, processes detection and feedback data from hardware (e.g., actuators and sensors), and / or provides this data to the upper-level ASW. Design optimization and coordination between the BSW and ASW can include checking preconditions during controller initialization to mitigate the impact of Shut-Off Path Check (SOPC) (especially the ECM3 interface instruction mistransmission problem), and ensuring that the transfer of control authority from the controller's BSW to the ASW for high-side and low-side drive units does not cause unexpected effects or disrupt the current delay hold function to maintain the robustness of high-voltage bus power supply.

[0061] Control software for controllers supporting ASIL B functional safety level performs hardware-level checks during system initialization, including a shutdown path check (SOPC) for functional safety components. The purpose of SOPC is to ensure the system can enter a safe state in the event of a functional safety fault during normal control system operation. The SOPC function is implemented by including a pulse control signal for closing or closing the high-voltage bus (on / off) in the output of the controller's ASW via BSW to the HSD and LSD units during the power-on phase, and then checking whether the high-voltage control system controller executes the closing or closing command accordingly. If the command execution fails, an SOPC failure signal is fed back, and the entire control system is then restarted to attempt to restore hardware control.

[0062] Specifically, to implement the SOPC function, SOPC is executed during the controller's power-on initialization process, especially during BSW initialization, to ensure that the drive relay to control the contactor's shut-off path is effective. Typically, in the LSD unit, in addition to the low-side enable signal port, a disable signal port is added to ensure that the system can immediately shut down the external load (relay) in response to a functional safety event to protect the user and vehicle. Alternatively, the low-side enable signal and disable signal can be treated as two states of the low-side enable signal (effective enable signal and ineffective enable signal) to output relay low-side control signals that trigger the time-delay hold function and immediately disconnect the contactor, respectively.

[0063] While SOPC is necessary in functional safety design, if the delay hold function is triggered during the period from the start of the controller reset operation until restart completion, the relays need to be kept in normal drive to close the high-voltage bus before the ASW in the control software takes over the normal control functions of the controller. This conflicts with the SOPC function during the controller's power-on initialization process, because the SOPC function attempts to drive the relays to change the contactor from closed to open to verify the validity of the shutdown path, for example, by assigning an invalid signal of 0 to a valid signal with a value of 1 through an interface to indicate that the contactor is open. Therefore, in the event of an unexpected controller reset, the high-low side control function of the relays still needs to keep the contactor in the closed state without performing or bypassing the detection and verification task of the SOPC function. This requires the ASW and BSW to be designed to work together based on the state of the relays and / or contactors indicated by the high-low side control feedback signals of the monitored high-low side drive units.

[0064] exist Figure 2First, the controller sets the delay hold function at block 201, for example, by setting a predetermined time for the delay hold function through a reset resource signal. Next, at block 202, it determines whether the ASW (Automatic Switching SW) activates the delay hold function. This triggers the HSD (Hyper-Signaling Module) and LSD (Low-Signaling Module) units to drive relays and control contactors to close, ensuring the high-voltage bus maintains power supply and operation to the vehicle equipment for at least a preset time, in the presence of the controller or upon receiving a reset request. If the ASW in the control software activates the delay hold function, it indicates that there may be vehicle equipment currently operating and powered by the high-voltage bus (e.g., the high-voltage drive system is supplying power to the drive motor and controlling the vehicle's normal operation). In the event of an unexpected reset request, further judgment is needed based on feedback signals from the HSD and LSD units to determine whether to trigger the delay hold function and whether SOPC (Service Control Program) has caused command errors that interfere with the normal operation of the vehicle equipment. If the ASW does not activate the delay hold function, it indicates that there is no vehicle equipment currently being normally controlled and operated by the controller, and the delay hold function does not need to be triggered in the event of an unexpected reset request.

[0065] If the judgment result of block 202 is yes, it indicates that the delay hold function has been activated by ASW. If the control strategy detects an unexpected reset request in block 203, it will further determine in block 211 whether the LSD unit drives the relay to control the contactor to be in a closed or open state. The state of the contactor can be determined by detecting the value of the LSD flag bit generated based on the feedback signal provided by the LSD unit. A value of 1 for the LSD flag bit indicates that the current LSD unit is outputting a low-side control signal that drives the relay to control the contactor to close, and at least one vehicle device is in operation under the normal control of the controller. A value of 0 for the flag bit indicates that the low-side control signal output by the current LSD unit causes the controller to open, and no vehicle device is in operation in response to normal control. According to embodiments of this disclosure, after activating the delay hold function, the HSD unit will always output a high-side drive signal that keeps the contactor in a closed state; therefore, the value of the HSD flag bit is 1 by default, indicating that the current HSD unit is outputting a high-side control signal that drives the relay to control the contactor to close.

[0066] If the judgment result of block 211 is yes, indicating that at least one vehicle device in the current vehicle is operating, the delay holding function is triggered in block 212. Both the HSD unit and the LSD unit output a high-level high-side control signal, and the relay is driven to control the contactor to maintain the high-voltage bus supply to the vehicle device for power supply and operation (HSD=1 and LSD=1). During the controller reset operation, the system can still respond to a functional safety fault event by immediately disconnecting the contactor. At the same time, the control strategy determines that the SOPC function of ECM3 executed during ASW initialization after the controller reset operation is completed will affect the current contactor (relay) delay holding function, causing command misoperation and unexpected contactor disconnection, resulting in loss of power supply to the operating vehicle device. In this case, during the initialization period after the controller reset operation is completed, the control strategy first initializes the BSW in the control software during the controller startup process in the following blocks 213 and 215. If, as shown in box 213, the BSW starts normally (while still maintaining HSD=1 and LSD=1), then in box 214, the ECM3 will exit the SOPC function for the LSD unit path, and will no longer add pulse control signals to the low-side enable signal and / or relay low-side control signal for hardware layer detection and verification. Next, during controller initialization, especially during the later stages of BSW initialization or after ASW initialization, a control strategy for transferring control authority between ASW and BSW is implemented (as shown in box 240). If, as shown in box 215, the BSW fails to start (while still maintaining HSD=1 and LSD=1), then the control flow enters the "Stay-in-Boot" mode in box 216 and the control authority transfer strategy is no longer executed.

[0067] The implementation of the control transfer strategy specifically includes verifying in block 241 whether the ASW has successfully completed its startup execution. If the ASW starts successfully (result "Yes"), the ASW will work with the BSW to determine whether to trigger the controller to transfer control to the ASW through the BSW to regain control of the relay (contactor) high-side and low-side control functions performed by the HSD and LSD units. If the ASW fails to start, and the ASW still cannot start successfully after the preset timer expires, the controller will remain in the default mode (block 246), and the controller will not be able to regain control of the relay high-side and low-side control.

[0068] ASW initialization and SOPC control set initialization control commands to shut down relays. To prevent unexpected contactor shutdown due to SOPC functions from causing interface command errors, a flag code (key) can be superimposed on the control commands sent by ASW to the relays before being sent to BSW (Box 242). This ensures that the commands sent by ASW are genuine, normal contactor disconnection functions and not erroneous commands caused by ASW's own function initialization. For example, a value of 1 for the flag code key indicates the existence of a genuine contactor disconnection control command, while a value of 0 indicates that the control command is an erroneous command caused by initialization, such as originating from ASW executing the SOPC function of ECM3. BSW can perform precondition checks on SOPC function commands from ASW based on both the flag code key and the control command provided by ASW to avoid the influence of SOPC (Box 243). For example, the precondition check can be implemented using logical AND. If a control command exists and the flag code indicates a genuine control command to disconnect the contactor (control command is true and flag code is true / value 1), the BSW verification in box 243 passes (the result of box 243 is "Yes"). The BSW then transfers control of the relays in the HSD and LSD units to the ASW, allowing the ASW's control commands to be executed by the HSD and LSD units, and the controller takeover is successful. If the control command does not exist (false) and the flag code indicates a command mis-sent due to ASW's own function initialization (flag code is false / value 0), the result of box 243 is "No". The BSW will not transfer control of the relays in the corresponding HSD and LSD units to the ASW. Control commands from the ASW cannot be executed by the HSD and LSD units, the controller takeover fails, and the controller must wait for the predetermined time of the delay hold function to expire before proceeding to the next step (e.g., re-performing or continuing the control transfer strategy).

[0069] Continuing with the judgment result in box 211 above, if the result is "No," it indicates that the contactor delay hold function is not activated in the current vehicle. The LSD unit drives the relay to keep the contactor in the open state (HSD=1 and LSD=0 at this time). For example, due to the control function previously indicated by the control software being completed or other reasons, the equipment in the current vehicle is not being powered and operated by the high-voltage bus, i.e., the high-voltage bus has been disconnected by the contactor. The control strategy in box 223 does not trigger the delay hold function. At the same time, it can be determined that after the controller reset operation is completed, the SOPC function of ECM3 will not affect the current contactor (relay) control of the high-voltage bus, and will not cause unexpected contactor disconnection leading to a loss of power supply to the operating vehicle equipment. In the controller startup process in the following boxes 224 and 227, the BSW in the control software is initialized first. If the BSW starts normally as shown in box 224 (while still maintaining HSD=1 and LSD=0), then in box 225, the BSW controls the HSD unit to output a high-side control signal that disconnects the contactor. Then, in box 226, the ECM3 is instructed to perform normal SOPC functions for hardware layer detection and verification. Next, the control authority transfer control strategy is implemented. In embodiments of this disclosure, the control authority transfer control strategy can employ the same logic (as shown in the leftmost box 240). If the BSW startup fails as shown in box 227 (while still maintaining HSD=1 and LSD=0), then the control flow enters box 228 in "Stay-in-Boot" mode and the control authority transfer control strategy is no longer executed.

[0070] Continuing from the judgment result in box 202 above, if the result is "No," it indicates that the unexpected reset operation did not originate from the ASW. When an unexpected reset request occurs in box 204, it can be determined that the contactor delay hold function is not activated in the current vehicle, and the LSD unit is driving the relay to keep the contactor in the open state. Similar to the control logic after box 223, the delay hold function is not triggered in box 233 (at this time, HSD=1 and LSD=0). At the same time, it can be determined that after the controller reset operation is completed, the SOPC function of ECM3 will not affect the current contactor (relay) control of the high-voltage bus, and will not cause unexpected contactor disconnection leading to a loss of power supply to the operating vehicle equipment. In the controller startup process of the following boxes 234 and 237, the underlying BSW in the control software is initialized first. If the BSW starts normally as shown in box 234 (while still maintaining HSD=1 and LSD=0), then in box 235, the BSW controls the HSD unit to output a high-side control signal to disconnect the contactor. Then, in box 236, the ECM3 is instructed to perform normal SOPC functions for hardware layer detection and verification. Next, the control strategy for transferring control authority is executed. The control strategy for transferring control authority can also use the same logic (as shown in the leftmost box 240). If the BSW fails to start as shown in box 237 (while still maintaining HSD=1 and LSD=0), then the control flow enters box 238 in "Stay-in-Boot" mode and the control strategy for transferring control authority is no longer executed.

[0071] Figure 3 A method for controlling the state of a contactor according to an embodiment of the present disclosure is shown.

[0072] The method mainly includes step S310, which, in response to a controller reset request 301, selectively triggers the delay hold function based on at least one of the setting of the delay hold function and the low-side control signal output by the low-side drive unit, and step S320, after the controller is reset, selectively performs a shutdown path check to support functional safety requirements for at least one of the setting of the delay hold function and the triggering of the delay hold function for the low-side drive unit.

[0073] Step S310 further includes determining whether to trigger the delay holding function based on a condition 311 that the delay holding function is activated and a condition 312 that the low-side control signal of the LSD causes the contactor to close. For example, the delay holding function is triggered when the delay holding function is activated and the low-side control signal causes the contactor to be in a closed state; the delay holding function is not triggered when the delay holding function is activated and the low-side control signal causes the contactor to be in a closed state; and the delay holding function is not triggered when it is not activated.

[0074] In the triggered delay hold function, the HSD unit, triggered by a valid high-side enable signal, drives the relay control contactor to remain closed (or at least for a predetermined time) with a high-side control signal, and the LSD unit, triggered by a valid low-side enable signal, drives the relay control contactor to remain closed for at least a predetermined time with a low-side control signal.

[0075] Step S320 further includes, during the control software startup after the controller reset operation is completed, deciding whether to skip the hardware layer detection and verification of the path for the LSD unit in the SOPC function of ECM3 executed by the ASW based on the triggering of the delay hold function; and during the initialization of the ASW in the later stage of BSW initialization or after completion, in the control strategy for the transfer of control authority, determining whether the ASW in the reset controller can obtain the control authority for the HSD unit and LSD unit transferred by the BSW based on the authenticity of the control command sent by the ASW (e.g., to disconnect the contactor), and executing the control signal of the SOPC function to complete the controller's takeover of the relay drive function.

[0076] This method is combined with the above. Figure 1 and Figure 2 The detailed steps will not be repeated here.

[0077] The controller, HSD and LSD units, and the driven relays of this disclosure together constitute the state of the control contactor to achieve a time delay hold function during controller reset and normal execution of the ECM3 (SOPC) function for functional safety ASIL B.

[0078] By adopting the above-described scheme proposed in the embodiments of this disclosure, a lower-cost basic power management chip (SBC) can be selected and combined with a controller to implement high-side and low-side drive units for relay driving to control the state of contactors, meeting design requirements, especially the complex control functions required for power supply and operation of the high-voltage bus in vehicle high-voltage control systems. This allows the basic SBC to take over the controller's drive and control functions for relays and contactors during various processes, including before, during, and after the controller performs a reset operation in response to a reset request, and during initialization. This provides sufficient time and conditions to decide on the control strategy for the state of contactors on the high-voltage bus, enabling functional safety (e.g., ASIL B) based closing and closing operations of relays and contactors. At the same time, it ensures that the fault diagnosis function of ECM3 and controller software errors will not interfere with the normal control of the high-voltage control system, and that unexpected relay closing will not occur. It also avoids erroneous execution of interface instructions due to control authority takeover between software layers during initialization.

[0079] It should be noted that although several modules or units of the system for controlling the state of the contactor have been mentioned in the detailed description above, this division is not mandatory. In fact, according to embodiments of this disclosure, the features and functions of two or more modules or units described above can be embodied in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided and embodied by multiple modules or units. Components shown as modules or units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this disclosure according to actual needs. Those skilled in the art can understand and implement this without any inventive effort.

[0080] In exemplary embodiments of this disclosure, a computer-readable storage medium is also provided, having stored thereon a computer program including executable instructions that, when executed by, for example, a processor, can implement the steps of the method for controlling the state of a contactor as described in any of the above embodiments. In some possible implementations, aspects of this disclosure can also be implemented as a program product including program code that, when run on a terminal device, causes the terminal device to perform the steps described in the various exemplary embodiments of this disclosure for controlling the state of a contactor.

[0081] The program product for implementing the above-described method according to embodiments of this disclosure may employ a portable compact disc read-only memory (CD-ROM) and include program code, and may run on a terminal device, such as a personal computer. However, the program product of this disclosure is not limited thereto. In this document, a readable storage medium may be any tangible medium that contains or stores a program that may be used by or in conjunction with an instruction execution system, apparatus, or device.

[0082] The program product may employ any combination of one or more readable media. A readable medium may be a readable signal medium or a readable storage medium. A readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of readable storage media (a non-exhaustive list) include: an electrical connection having one or more wires, a portable disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0083] The computer-readable storage medium may include data signals propagated in baseband or as part of a carrier wave, carrying readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. The readable storage medium may also be any readable medium other than a readable storage medium, capable of transmitting, propagating, or transmitting programs for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the readable storage medium may be transmitted using any suitable medium, including but not limited to wireless, wired, optical fiber, RF, etc., or any suitable combination thereof.

[0084] Program code for performing the operations of this disclosure can be written in any combination of one or more programming languages, including object-oriented programming languages ​​such as Java and C++, and conventional procedural programming languages ​​such as C or similar languages. The program code can execute entirely on the user's computing device, partially on the user's computing device, as a standalone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server. In cases involving remote computing devices, the remote computing device can be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., via the Internet using an Internet service provider).

[0085] In exemplary embodiments of this disclosure, an electronic device is also provided, which may include a processor and a memory for storing executable instructions of the processor. The processor is configured to perform steps of the method for controlling the state of a contactor in any of the above embodiments by executing the executable instructions.

[0086] Those skilled in the art will understand that various aspects of this disclosure can be implemented as a system, method, or program product. Therefore, various aspects of this disclosure can be specifically implemented in the following forms: a completely hardware implementation, a completely software implementation (including firmware, microcode, etc.), or a combination of hardware and software aspects, collectively referred to herein as a "circuit," "module," or "system."

[0087] The following reference Figure 4 To describe an electronic device 400 according to such an embodiment of the present disclosure. Figure 4 The electronic device 400 shown is merely an example and should not be construed as limiting the functionality and scope of the embodiments of this disclosure.

[0088] like Figure 4As shown, the electronic device 400 is presented in the form of a general-purpose computing device. The components of the electronic device 400 may include, but are not limited to: at least one processing unit 410, at least one storage unit 420, a bus 430 connecting different system components (including storage unit 420 and processing unit 410), a display unit 440, etc.

[0089] The storage unit stores program code that can be executed by the processing unit 410, causing the processing unit 410 to perform the steps described in the method for controlling the state of a contactor according to various exemplary embodiments of this disclosure. For example, the processing unit 410 can perform actions such as... Figures 2 to 3 The steps are shown in the figure.

[0090] The storage unit 420 may include a readable medium in the form of a volatile storage unit, such as a random access memory unit (RAM) 4201 and / or a cache storage unit 4202, and may further include a read-only memory unit (ROM) 4203.

[0091] The storage unit 420 may also include a program / utility 4204 having a set (at least one) program module 4205, such program module 4205 including but not limited to: an operating system, one or more application programs, other program modules and program data, each or some combination of these examples may include an implementation of a network environment.

[0092] Bus 430 can represent one or more of several types of bus structures, including a memory cell bus or memory cell controller, a peripheral bus, a graphics acceleration port, a processing unit, or a local bus using any of the various bus structures.

[0093] Electronic device 400 can also communicate with one or more external devices 500 (e.g., keyboard, pointing device, Bluetooth device, etc.), and with one or more devices that enable a user to interact with electronic device 400, and / or with any device that enables electronic device 400 to communicate with one or more other computing devices (e.g., router, modem, etc.). This communication can be performed via input / output (I / O) interface 450. Furthermore, electronic device 400 can also communicate with one or more networks (e.g., local area network (LAN), wide area network (WAN), and / or public networks, such as the Internet) via network adapter 460. Network adapter 460 can communicate with other modules of electronic device 400 via bus 430. It should be understood that, although not shown in the figures, other hardware and / or software modules can be used in conjunction with electronic device 400, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.

[0094] From the above description of the embodiments, those skilled in the art will readily understand that the exemplary embodiments described herein can be implemented by software or by combining software with necessary hardware. Therefore, the technical solutions according to the embodiments of this disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, USB flash drive, external hard drive, etc.) or on a network, including several instructions to cause a computing device (such as a personal computer, server, or network device, etc.) to execute the method for controlling the state of a contactor according to the embodiments of this disclosure.

[0095] Other embodiments of this disclosure will readily occur to those skilled in the art upon consideration of the specification and practice of the disclosure herein. This disclosure is intended to cover any variations, uses, or adaptations of this disclosure that follow the general principles of this disclosure and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this disclosure are indicated by the appended claims.

Claims

1. A method for controlling the state of a contactor, the state of the contactor being controlled by a high-side drive unit and a low-side drive unit triggered by a controller, the method comprising: In response to a reset request from the controller, the delay hold function is selectively triggered using at least one of the controller's settings based on the delay hold function and the low-side control signal output by the low-side drive unit, wherein the low-side control signal is held for at least a predetermined time in the delay hold function; The reset controller is used to selectively perform a shutdown path check on the low-side drive unit based on at least one of the settings and trigger conditions of the delay hold function.

2. The method of claim 1, wherein, The settings for the delay hold function include: Activate the delay hold function; and The delay hold function is not activated.

3. The method of claim 2, wherein, Selectively triggering the delay hold function includes: The delay hold function is triggered when the delay hold function is activated and the low-side control signal causes the contactor to be in a closed state. The delay hold function is not triggered when the delay hold function is activated and the low-side control signal puts the contactor in an open state. If the delay hold function is not activated, the delay hold function will not be triggered.

4. The method according to any one of claims 1 to 3, characterized in that, In the delay hold function, the high-side enable signal used to trigger the high-side drive unit instructs the high-side control signal output by the high-side drive unit to control the state of the contactor to remain closed for at least the predetermined time, and the low-side enable signal used to trigger the low-side drive unit instructs the low-side control signal output by the low-side drive unit to control the state of the contactor to remain closed for at least the predetermined time.

5. The method of claim 4, wherein, The scheduled time is set by the controller.

6. The method according to any one of claims 1 to 3, characterized in that, If the delay hold function is not triggered during the controller reset operation, the high-side enable signal for triggering the high-side drive unit instructs the high-side control signal output by the high-side drive unit to put the contactor in or change its state to open, and the low-side enable signal for triggering the low-side drive unit instructs the low-side control signal output by the low-side drive unit to put the contactor in or change its state to open.

7. The method according to any one of claims 1 to 3, characterized in that, Using a reset controller, selectively performing a shutdown path check on the low-side drive unit based on at least one of the settings and trigger conditions of the delay hold function includes: When the delay hold function is triggered, the reset controller skips the low-side drive unit in the shutdown path check; If the delay hold function is not triggered, the reset controller does not skip the low-side drive unit during the shutdown path check.

8. The method of claim 2 or 3, wherein, Using a reset controller to selectively perform a shutdown path check on the low-side drive unit based on at least one of the settings and triggering conditions of the delay hold function further includes: When the reset controller sends a real control signal, the reset controller acquires control authority over the high-side drive unit and the low-side drive unit. If the reset controller sends a false control signal, the reset controller will not acquire control authority over the high-side drive unit and the low-side drive unit.

9. The method according to any one of claims 1 to 3, characterized in that, The state of the contactor is controlled by a relay driven by the high-side drive unit and the low-side drive unit.

10. The method according to any one of claims 1 to 3, characterized in that, The method also includes: In the time-delay hold function, in response to a functional safety fault event, the low-side drive unit outputs a low-side control signal that changes the state of the contactor to open.

11. The method of claim 1, wherein, The reset includes at least one of hardware reset, software reset, and reset caused by interference.

12. The method of claim 1, wherein, The controller includes a microcontroller for the vehicle's high-voltage control system.

13. An apparatus for controlling the state of a contactor, comprising: The controller is configured as follows: Trigger the high-side drive unit and the low-side drive unit to control the state of the contactor; In response to a reset request from the controller, the delay hold function is selectively triggered based on at least one of the settings of the delay hold function and the low-side control signal output by the low-side drive unit, wherein the low-side control signal is held for a predetermined time in the delay hold function; After reset, a shutdown path check is selectively performed on the low-side drive unit based on at least one of the settings and triggering conditions of the delay hold function; The high-side driving unit and the low-side driving unit; as well as At least one relay is configured to be driven by the high-side drive unit and the low-side drive unit to control the state of the contactor.

14. The apparatus of claim 13, wherein, The apparatus is configured to implement the method according to claims 2 to 12.

15. A computer-readable storage medium having a computer program stored thereon, the computer program including executable instructions that, when executed by a processor, implement the method according to any one of claims 1 to 12.

16. An electronic device, comprising: include: processor; as well as Memory for storing the executable instructions of the processor; The processor is configured to execute the executable instructions to implement the method according to any one of claims 1 to 12.

17. A computer program product comprising a computer program that, when executed by a processor, performs the method according to any one of claims 1 to 12.

18. A vehicle comprising means for controlling the state of a contactor as described in claim 13 or 14.