Rear-mounted vehicle-mounted screen safety control method and system based on rigid state grading and hardware forced monitoring, electronic equipment and computer readable storage medium

By adopting a method based on rigid state grading and hardware-forced monitoring, the safety hazards of aftermarket vehicle screens when the main control system fails are solved. This method enables the screen to be forced into a safe state under any circumstances, ensuring traffic safety. The system is highly reliable and easy to authenticate.

CN121893884APending Publication Date: 2026-04-21CHENGDU GUANGQI INTELLIGENT MEDIA TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
CHENGDU GUANGQI INTELLIGENT MEDIA TECHNOLOGY CO LTD
Filing Date
2026-01-14
Publication Date
2026-04-21

AI Technical Summary

Technical Problem

Existing technologies cannot provide mandatory physical safety guarantees through independent hardware circuits when the main control system of an aftermarket in-vehicle screen experiences a complete and overall failure, independent of any software, logic, or computing resources of the failed system, especially in preventing the display screen from interfering with the driver's vision while the vehicle is in motion.

Method used

The method adopts a rigid state classification and hardware-forced monitoring approach. Vehicle state data is acquired through multi-source sensors and mapped to a safety control level based on discrete state classification rules. The status of the main control unit is monitored by a hardware safety monitoring circuit independent of the main control unit. When a failure occurs, the screen is directly driven to a safe state, the main power supply is cut off, and the system switches to the backup path.

Benefits of technology

It enables the screen to be forcibly placed in a safe physical state even when the main control system fails completely, ensuring traffic safety and providing ultimate fail-safe protection. The system is highly reliable and easy to verify and compliant with certification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121893884A_ABST
    Figure CN121893884A_ABST
Patent Text Reader

Abstract

The invention discloses an after-loading vehicle-mounted screen safety control method and system based on rigid state grading and hardware forced monitoring, and relates to the technical field of vehicle-mounted safety. The method comprises the following steps: acquiring vehicle state data through a multi-source sensor; according to a preset discretization state grading rule, the vehicle state is mapped to a limited safety broadcast control grade in a deterministic mode; and calling a pre-bound structured broadcast control instruction to control the screen according to the grade. The core innovation lies in that a hardware security monitoring circuit with independent power supply is arranged to continuously monitor the state of the main control unit; and when the effective survival signal of the main control unit is not received in the preset period, the power switch is directly driven, the main working power supply of the screen is physically cut off, and the standby access which only maintains basic safety is switched. According to the method, the clear safety boundary is determined through rigid grading, the technical defect that a safety chain is broken when a main control system is completely invalid in an existing pure software scheme is overcome through a hardware physical bottom mechanism, real failure-safety is achieved, and ultimate guarantee is provided for compliance safety application of the after-loading vehicle-mounted screen.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of vehicle electronics technology and active vehicle safety, specifically to a safety control system and method for an intelligent display screen installed in a vehicle. It is particularly suitable for ensuring that the external display screen does not interfere with traffic while the vehicle is in motion, and for providing a deterministic safety backup in the event of system failure. Background Technology

[0002] With the development of digital out-of-home advertising, the use of rear-mounted transparent displays on vehicle rear windshields and other locations for advertising is gradually increasing. While these displays have commercial value when the vehicle is stationary, continuously displaying dynamic content while the vehicle is in motion can severely obstruct the view of drivers behind, posing a traffic safety hazard.

[0003] Several existing technologies exist for controlling displays based on vehicle status. One type of solution attempts to integrate sensor information through software algorithms and rely on software or logic gating to constrain the display output; another type integrates monitoring modules (such as watchdogs) within the system to achieve fault diagnosis and recovery. However, the security mechanisms of these existing solutions essentially still rely on the reliable operation of the main control system's hardware and software platform, or their monitoring logic is still embedded within the main control system. They all belong to the "software-dependent" or "in-system monitoring" security paradigm. They share a fundamental technical deficiency: they cannot provide a mandatory physical safety net, implemented through independent hardware circuitry, independent of any software, logic, or computing resources of the failed system, in the extreme case of a complete and overall failure of the main control system of the aftermarket in-vehicle screen. This is a major unresolved security issue for aftermarket equipment with extremely high safety requirements and whose control system reliability is difficult to deeply integrate and certify with the vehicle.

[0004] There is an urgent need in this field for a new paradigm of vehicle screen control that is fundamentally different in principle and can provide deterministic ultimate safety assurance. That is, a rigid control scheme that can fundamentally isolate the risk of failure of the main control system and achieve "failure-physical safety" through independent hardware entities. Summary of the Invention

[0005] (a) Technical problems to be solved This invention aims to overcome the inherent defects of existing technologies that rely entirely on software algorithms or internal system logic monitoring and cannot cope with overall failures at the main control system level. It provides an aftermarket vehicle screen safety control method and system that can absolutely force the screen to a certain safe physical state through a hardware mechanism that is completely independent of the main control unit in terms of power supply and logic, even when the main control unit fails completely for any reason (such as a crash, power failure, or program disorder) and all its software functions (including internal monitoring and watchdog services) fail.

[0006] (II) Technical Solution To achieve the above objectives, the present invention adopts the following technical solution: In a first aspect, the present invention provides a safety control method for aftermarket vehicle screens based on rigid state grading and hardware-mandated monitoring, comprising the following steps: S1. Acquire vehicle status data through multiple source sensors; S2. Based on the data, according to the preset discretization and discontinuous state classification rules, the vehicle state is deterministically and stepwise mapped to a finite number of mutually exclusive safety control levels. S3. Based on the security broadcast control license level, generate and issue structured screen broadcast control instructions uniquely bound to each level; S4. A hardware safety monitoring circuit, which is independent of the main control unit in terms of power supply path and signal logic, continuously monitors the survival status of the main control unit. When the circuit does not receive a valid survival signal in a predetermined format within a preset time, it directly drives the physical power switch unit it controls to bypass any software processing flow of the main control unit, physically cut off the main working power of the screen, and switch the screen power supply to a backup path that only maintains the basic safe display state.

[0007] Furthermore, in step S2, the judgment threshold or the security control level mapped by the discretized state classification rule can be dynamically selected and matched according to at least one contextual information among the road type, geofence area, or specific instructions received by the vehicle, but always maintains the deterministic, discontinuous mapping relationship.

[0008] Furthermore, in step S2, the discretization state classification rule is as follows: if the vehicle speed is continuously higher than the first threshold, it is determined to be a prohibited display state; if the vehicle speed is continuously lower than the second threshold, and at the same time it is verified that the vehicle gear is park / neutral and it is not a tunnel scenario, it is determined to be a safe stationary state; otherwise, it is determined to be a restricted low speed state.

[0009] Furthermore, in step S4, the hardware security monitoring circuit is directly powered by an independent power supply, and includes a window watchdog timer and a power switching device (such as a MOSFET); the effective survival signal is a specific heartbeat message periodically sent by the main control unit; the physical cutoff refers to the watchdog timer directly changing the control level of the power switching device by its output pin after the watchdog timeout, so as to shut down the main power supply circuit of the screen.

[0010] Furthermore, the backup path is configured to provide the screen with the minimum power required to bring it into an optically transparent or physically closed state.

[0011] In a second aspect, the present invention provides a system for implementing the above method, comprising: The data acquisition and fusion module is used to acquire vehicle status data; The state classification determination module is used to execute the discretized state classification rules; The instruction generation and issuance module is used to generate structured instructions corresponding to the level; The screen driver module is used to execute instructions to control the screen; The independent hardware safety backup module is an independently powered circuit unit used to monitor the status of the main control unit and, in the event of failure, directly control the physical switch to cut off the main power supply to the screen and switch to the backup path.

[0012] (III) Beneficial Effects Compared with the prior art, the present invention has the following significant advantages: 1. Achieves true fail-safe: By introducing a hardware monitoring circuit that is completely independent of the main control system in terms of power supply and logic, and enabling it to directly control the physical switching of the screen power supply, this invention establishes an ultimate safety fallback layer. This mechanism does not depend on any software, power supply, or computing resources of the main control system. Therefore, even if the main control system experiences any form of overall functional loss (such as a crash, power outage, or program crash), this independent hardware layer can deterministically trigger an action to force the screen into a preset safe physical state. This fundamentally overcomes the fundamental defect of existing "software-dependent" or "intra-system monitoring" safety schemes where the protection chain breaks synchronously in the face of system-level failures.

[0013] 2. Clear and rigid security boundaries: By adopting discrete hierarchical rules, a rigid security permission premise of "black and white" is established, rather than continuous parameter optimization. The rules are simple and clear, and easy to verify and comply with certification.

[0014] 3. High system reliability: The hardware monitoring circuit is simple and reliable, and its independent power supply is unaffected by the main system. The state classification rules are based on multi-source sensor fusion and multiple verifications, resulting in strong robustness in judgment.

[0015] 4. Excellent aftermarket compatibility: As an independent "security fortress" module, this solution does not heavily rely on the vehicle's original network or software architecture, providing a simple solution to the high security requirements of aftermarket devices. It can disconnect the screen's main power supply and switch to an alternate path. Attached Figure Description

[0016] Figure 1 The flowchart illustrates the overall process of the safety control method provided in this embodiment of the invention.

[0017] Figure 2 This is a schematic diagram of the system hardware architecture and security monitoring principle provided in an embodiment of the present invention. Detailed Implementation

[0018] The present invention will now be described in detail with reference to the accompanying drawings and embodiments. The following description is merely illustrative and is not intended to limit the scope of protection of the present invention. It should be noted that although the grading rules of the present invention are preset, their thresholds or output results can be dynamically selected and switched according to contextual information such as road type and regulatory region, but this does not change the core features of "discrete licensing" and "hardware physical fallback".

[0019] Example 1: Core Control Flow like Figure 1 As shown, the security control method in this embodiment includes the following steps: Step S101: Data Acquisition. The main control unit acquires vehicle speed V_gps and position through the GPS / BeiDou module, acceleration and angular velocity through the inertial measurement unit, and gear position signal through the vehicle CAN bus.

[0020] Step S102: Data Fusion and State Classification. A Kalman filter is used to fuse V_gps and IMU data to calculate the vehicle speed V_imu, resulting in a reliable vehicle speed V_fuse. Then, rigid classification rules are executed: Rule A: If V_fuse continues to exceed 30km / h for 10 seconds, it is immediately determined to be in a SAFE state.

[0021] Rule B: If V_fuse remains below 2km / h for 5 seconds, proceed to the verification sub-process: verify if the gear is P / N; simultaneously check GPS signal strength and historical trajectory, excluding tunnel scenarios. If all conditions are met, the system is determined to be in FULL state.

[0022] Rule C: If A and B are not satisfied, the default state is LIMITED.

[0023] Step S103: Instruction Generation and Issuance. Based on the determined level (FULL / LIMITED / SAFE), generate the corresponding instruction package. The FULL instruction allows dynamic playback; the LIMITED instruction prohibits dynamic content and limits brightness; the SAFE instruction includes a "switch to transparent" command.

[0024] Step S104: Hardware security monitoring and forced power-off (core function). For example... Figure 2As shown, an independent hardware safety monitoring circuit 200 is integrated on the screen driver board. This circuit draws power directly from the car battery and its core components include a window watchdog chip 201 and a P-MOSFET 202. The main control unit 100 needs to send a specific formatted "survival heartbeat" message to the watchdog 201 every 200ms. The normal operating power of the screen is provided by the main power supply path 203, while the safety backup path 204 only provides a microcurrent to maintain the transparency of the PDLC film.

[0025] If the watchdog timer 201 does not receive a valid heartbeat within 400ms, it determines that the main control unit has failed, and its output pin is immediately pulled low, turning on MOSFET 202. This action physically switches the power supply to the screen from the main power supply path 203 to the safety backup path 204, forcing the screen to become transparent. This process does not involve any software processing by the main control unit 100.

[0026] Example 2: System Hardware Architecture and Independent Hardware Security Backup Principle like Figure 2 As shown, the system implementing this invention adopts a physical and logical layered architecture. Its core innovation lies in the introduction of a hardware security fallback module that is completely independent of the main control system in terms of power supply and logic.

[0027] 1. Overall architecture layering: Data perception and decision-making layer: This mainly includes the intelligent in-vehicle terminal (IVT), which integrates a data acquisition and fusion module, a rigid state classification determination module, and an instruction generation and issuance module. This layer is responsible for acquiring data from vehicle sensors and the bus, executing the state classification logic of this invention, and generating corresponding broadcast control instructions and survival heartbeat signals.

[0028] Independent Hardware Security Bottom Layer: This is the core of the security guarantee of this invention, consisting of an independently powered hardware circuit. This circuit contains two key components: a window watchdog chip and a power switch. Both are powered by an independent power source (such as a dedicated power supply path directly connected to the vehicle's constant-voltage battery), ensuring that their operation is completely independent of the power status of the main control system.

[0029] Screen execution layer: mainly includes screen driver chip and display panel, responsible for receiving and executing broadcast control commands to realize content display.

[0030] 2. Workflow of the safety backup mechanism: During normal operation, the main control unit (IVT) needs to periodically (e.g., every 200ms) send a "survival heartbeat" message in a specific format to the window watchdog chip in the independent hardware security fallback module.

[0031] The screen is powered by two physically isolated paths: a main operating path and a backup safety path. A power switch (such as a P-MOSFET) acts as a "power switching point," controlling the physical connection between these two paths. By default, the power switch connects the screen to the main operating path, allowing the screen to operate at full capacity.

[0032] If the watchdog chip does not receive a valid heartbeat signal within a preset timeout period (e.g., 400ms), it determines that the main control unit has failed (e.g., crashed or lost power). At this time, the output pin of the watchdog chip will immediately change its level, directly driving the power switch to operate.

[0033] This action produces a "physical switch" effect: forcibly and physically cutting off the screen's power supply from the main operating path and simultaneously switching to a backup safety path. The backup safety path is pre-configured to provide only the minimum power required to maintain the screen's basic safety state (e.g., making a transparent film display completely transparent).

[0034] 3. The essential differences from existing technologies: The key to this architecture lies in "independence" and "physical": Independent power supply: The safety backup module has a dedicated power supply, so even if the main control system crashes due to power problems, the backup module still has the energy to perform safety actions.

[0035] Logically independent: Its judgment is based solely on the presence or absence of a heartbeat signal, and does not depend on any complex software algorithms or decisions within the main control system.

[0036] Physical Actions: The actions performed are physical switching of power supply, rather than gating the content of data signals. This ensures that control over the screen state is ultimate and cannot be bypassed by software.

[0037] Through the above design, this invention creates an ultimate hardware protection layer that can be reliably triggered under any circumstances (including complete failure of the main control system) and forces the screen to a known safe physical state, thus achieving true "failure-safety".

[0038] Example 3: Dynamic Classification Based on Road Type This embodiment demonstrates how the classification rules are dynamically adjusted based on road type. The system pre-stores or acquires road type information (such as highways and urban roads) in real time. For example, when the system determines that a vehicle is on a highway, it can use a first set of speed thresholds (e.g., the SAFE level trigger threshold is set to 80 km / h); when it determines that the vehicle is on an urban road, it uses a second set of speed thresholds (e.g., the SAFE level trigger threshold is set to 30 km / h). Although the determination thresholds change dynamically, their mapping relationship remains deterministic and discontinuous: once the vehicle speed exceeds the current threshold, it jumps to the SAFE level. This ensures that in scenarios such as highways, different broadcast control permissions can be granted when more stringent safety conditions are met, providing a foundation for realizing functions such as emergency information broadcasting, while the core hardware security fallback mechanism of this invention remains effective at all times.

[0039] It is particularly noteworthy that this invention clearly demonstrates two parallel control lines: one is a rigid state classification and command execution line based on conditions such as vehicle speed; the other is a "survival heartbeat" monitoring and forced power-off switching line executed by an independent hardware safety monitoring circuit. These two lines are physically and logically independent. The state classification line is responsible for achieving intelligent and compliant broadcast control when the system is normal; while the hardware monitoring line acts as a silent guardian, intervening only when the main control system fails, executing the simplest and most reliable physical safety actions. This two-layer architecture design of "intelligent control during normal operation and physical fallback during failure" is the core of this application's achievement of ultra-high reliability.

[0040] Comparative Conclusion: The above comparison shows that the security boundary of existing technical solutions stops at the software reliability of the main control system or the effectiveness of the monitoring module within the system. This invention, by introducing a hardware monitoring layer that is completely independent in power supply and logic and capable of performing physical power-off actions, creatively extends the security boundary to the point of complete failure of the main control system, achieving a qualitative leap in security level and solving a long-standing technical problem.

[0041] It should be noted that the above embodiments are mainly described for aftermarket applications. Those skilled in the art will understand that the "rigid state grading" safety control concept and the "independent hardware monitoring" fallback mechanism proposed in this invention are also applicable to in-vehicle pre-installed display systems with extremely high requirements for safety and reliability. In pre-installed applications, the hardware safety monitoring circuit can be directly integrated into the vehicle domain controller or display driver module, and its independent power supply can be specially allocated by the vehicle power management unit. Such variant embodiments based on the same inventive concept should also be considered to fall within the scope of this invention.

Claims

1. A rigid safety clearance and hardware fallback control method for aftermarket vehicle screens, characterized in that, The method is based on a rigid safety clearance determination of the vehicle's operating status and performs hardware-level mandatory safety control on the screen, independent of the software system, including: Step S1: Acquire real-time vehicle operating status data through multi-source sensors; Step S2: Based on a preset discretized state permission rule that makes a binary decision based on at least one explicit threshold, the real-time operating state of the vehicle is deterministically and discontinuously mapped to a finite number of mutually exclusive security broadcast control permission levels. Step S3: Based on the security broadcast control license level, generate and issue structured screen broadcast control instructions uniquely bound to each level; Step S4: A hardware security monitoring circuit, which is independent of the main control system in both power supply and logic, continuously monitors the survival status of the main control system. When the circuit does not receive a valid survival signal from the main control system within a preset period, it bypasses any software processing flow of the main control system, directly drives the physical switch connected to it, cuts off the main power supply of the screen, and forces the screen power supply to switch to a backup path that only maintains a basic safety state. The hardware security monitoring circuit has a dedicated power supply path that is isolated from the main control system's power supply.

2. The method according to claim 1, characterized in that, In step S2, the discretization state permission rule is as follows: if the fused vehicle speed is continuously higher than the first speed threshold, it is mapped to the prohibition of display permission level; if the fused vehicle speed is continuously lower than the second speed threshold, and at the same time it is verified that the vehicle is in parking gear or neutral gear, and the tunnel scenario is excluded, it is mapped to the safe stationary permission level; otherwise, it is mapped to the restricted low speed permission level.

3. The method according to claim 1 or 2, characterized in that, The at least one judgment threshold on which the discretized state permission rule is based can be dynamically switched according to the road type where the vehicle is currently located.

4. The method according to claim 1, characterized in that, The hardware security monitoring circuit has a dedicated power supply path connected to the vehicle's constant-charge battery or an independent backup power source, which is isolated from the main control system's operating power supply.

5. The method according to claim 1, characterized in that, The effective survival signal is a periodic digital heartbeat message or a pulse signal in a specific format.

6. The method according to claim 1, characterized in that, The physical switch is a metal-oxide-semiconductor field-effect transistor or a relay.

7. The method according to claim 1, characterized in that, The backup path is configured to provide the screen with the minimum power required to bring it into an optically transparent or physically off state.

8. A vehicle-mounted screen safety control system for implementing the method of any one of claims 1-7, characterized in that, include: The data acquisition and fusion module is used to acquire real-time vehicle operating status data; The rigid state permission determination module is used to run the discretized state permission rules and output the security broadcast control permission level; The instruction generation module is used to generate structured broadcast control instructions based on the level. The screen driver module is used to execute instructions; the independent hardware safety backup module is a hardware circuit with independent power supply, used to monitor the status of the main control system, and in the event of its failure, directly operate the physical switch to cut off the main power supply to the screen and switch to the backup safety path.

9. The system according to claim 8, characterized in that, The independent hardware safety fallback module includes a window watchdog timer and a power switch device, and its power input terminal constitutes the dedicated power supply path.

10. The system according to claim 8, characterized in that, The system is configured as an aftermarket installation, with all its modules integrated into a control box. This control box has an interface for connecting to the screen and does not require connection to the vehicle's core control network.

11. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the method as described in any one of claims 1 to 7.

12. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the method as described in any one of claims 1 to 7.