Power-off control method, power-off control system and domain controller

By interacting with the GPIO ports between the microcontroller and the microprocessor, the upper-layer and lower-layer applications of the operating system are shut down in sequence, which solves the abnormal problem caused by forced power-off in the power-down control of the vehicle operating system and improves the stability and security of the system.

CN122018380APending Publication Date: 2026-05-12PATEO CONNECT (NANJING) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
PATEO CONNECT (NANJING) CO LTD
Filing Date
2024-11-12
Publication Date
2026-05-12

AI Technical Summary

Technical Problem

Existing vehicle operating systems typically use forced power-off to control power-down, which can lead to system malfunctions and fail to meet safety requirements.

Method used

By interacting with the GPIO ports between the microcontroller and the microprocessor, the upper-layer and lower-layer applications of the operating system are shut down sequentially according to preset rules to ensure system stability. The microcontroller sends a power-down notification message, and the microprocessor responds and replies that the shutdown is complete before performing the power-down operation.

Benefits of technology

It effectively reduces the probability of system malfunction, improves the efficiency and safety of power-down operations, and enhances the reliability and robustness of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122018380A_ABST
    Figure CN122018380A_ABST
Patent Text Reader

Abstract

The invention provides a power-off control method, a power-off control system and a domain controller, and relates to the field of vehicle control. The method comprises the steps that a microcontroller responds to a received power-off instruction and sends a power-off notification message to a first operating system in the microprocessor through a first universal input and output port; the microprocessor responds to the received power-off notification message and executes closing operation on a plurality of upper-layer applications of the first operating system according to a first preset rule; wherein the first preset rule is determined based on at least one of screen related information corresponding to an upper-layer application of the first operating system and an application association number; the microprocessor sends a first response message to the microcontroller through the second universal input / output port in response to the fact that the closing operation of the multiple upper-layer applications and the bottom-layer applications of the first operating system is executed in sequence; and the microcontroller responds to the received first response message and executes a power-off operation on the first operating system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of vehicle control, and more particularly to a power-down control method, a power-down control system, and a domain controller. Background Technology

[0002] Vehicles (such as autonomous vehicles) typically use a forced power-off method to control the power-down of their operating systems. This method is relatively simple and crude. When the system is running, a sudden power-down can easily lead to system abnormalities and cannot meet safety requirements. Summary of the Invention

[0003] This disclosure presents a power-down control method, a power-down control system, and a domain controller.

[0004] In a first aspect, embodiments of this disclosure propose a power-down control method, comprising: a microcontroller, in response to receiving a power-down command, sending a power-down notification message to a first operating system in a microprocessor via a first general-purpose input / output port; the microprocessor, in response to receiving the power-down notification message, performing a shutdown operation on multiple upper-layer applications of the first operating system according to a first preset rule; wherein the first preset rule is determined based on at least one of screen-related information and application association number corresponding to the upper-layer applications of the first operating system; the microprocessor, in response to sequentially performing shutdown operations on multiple upper-layer applications and lower-layer applications of the first operating system, sending a first response message to the microcontroller via a second general-purpose input / output port; and the microcontroller, in response to receiving the first response message, performing a power-down operation on the first operating system.

[0005] Secondly, embodiments of this disclosure propose a power-down control system, comprising: a microcontroller and a microprocessor. The microcontroller is configured to, in response to receiving a power-down command, send a power-down notification message to a first operating system in the microprocessor via a first general-purpose input / output port; the microprocessor is configured to, in response to receiving the power-down notification message, perform a shutdown operation on multiple upper-layer applications of the first operating system according to a first preset rule; wherein the first preset rule is determined based on at least one of screen-related information corresponding to the upper-layer applications of the first operating system and an application association number; the microprocessor is further configured to, in response to sequentially performing shutdown operations on multiple upper-layer and lower-layer applications of the first operating system, send a first response message to the microcontroller via a second general-purpose input / output port; the microcontroller is further configured to, in response to receiving the first response message, perform a power-down operation on the first operating system.

[0006] Thirdly, embodiments of this disclosure provide a domain controller, including a power-down control system as described in any of the implementations of the second aspect above.

[0007] The power-down control method, power-down control system, and domain controller provided in this disclosure enable efficient interaction between the microcontroller and the microprocessor through their respective GPIO ports. Specifically, upon receiving a power-down command, the microcontroller can send a power-down notification message to the microprocessor through its first GPIO port. In response to receiving the power-down notification message, the microprocessor sequentially shuts down the upper-layer and lower-layer applications of its first operating system. Then, it can send feedback (i.e., a first response message) to the microcontroller through its second GPIO port. When the first operating system has multiple upper-layer applications, it can perform a regular shutdown operation on these applications according to a first preset rule determined based on at least one of the screen-related information and application association numbers corresponding to the upper-layer applications. Furthermore, upon receiving the feedback, the microcontroller can determine that the first operating system has essentially entered a stopped state. Performing a power-down operation at this point effectively reduces the probability of system malfunctions caused by direct forced power-off while ensuring the operational stability of the first operating system throughout the power-down process. It also improves the efficiency of the power-down operation and meets safety requirements, thereby enhancing the reliability and robustness of the system operation.

[0008] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of this disclosure, nor is it intended to limit the scope of this disclosure. Other features of this disclosure will become readily apparent from the following description. Attached Figure Description

[0009] Other features, objects, and advantages of this disclosure will become more apparent from the following detailed description of non-limiting embodiments with reference to the accompanying drawings:

[0010] Figure 1 This is an exemplary system architecture to which this disclosure can be applied;

[0011] Figure 2 A flowchart of a power-down control method provided in an embodiment of this disclosure;

[0012] Figure 3 A flowchart of another power-down control method provided in this disclosure embodiment;

[0013] Figure 4 A flowchart illustrating a power-down control method in an application scenario provided by an embodiment of this disclosure;

[0014] Figure 5 A structural block diagram of a power-down control system provided in an embodiment of this disclosure;

[0015] Figure 6 This is a structural block diagram of a domain controller provided in an embodiment of the present disclosure. Detailed Implementation

[0016] The exemplary embodiments of this disclosure are described below with reference to the accompanying drawings, including various details of the embodiments to aid understanding; these should be considered merely exemplary. Therefore, those skilled in the art will recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of this disclosure. Similarly, for clarity and brevity, descriptions of well-known functions and structures are omitted in the following description. It should be noted that, unless otherwise specified, the embodiments and features described in this disclosure can be combined with each other.

[0017] It should be noted that the collection, acquisition, storage, processing, transmission, provision, disclosure, and application of user personal information (such as information used by the user to log in to the operating system in the vehicle) in the technical solution disclosed herein are all performed with the user's knowledge and explicit authorization, comply with the provisions of relevant laws and regulations, and do not violate public order and good morals.

[0018] Figure 1 An exemplary system architecture 100 is shown, in which embodiments of the power-down control method, power-down control system, and domain controller of this disclosure can be applied to vehicles.

[0019] like Figure 1 As shown, the system architecture 100 may include, but is not limited to, a first domain controller (DCU) 101 and a second domain controller 102 that establish a communication connection. The first domain controller 101 and the second domain controller 102 can establish a communication connection via Ethernet, or other types of network protocols. It should be noted that... Figure 1 The number of first domain controllers 101 and second domain controllers 102 in the system architecture 100 shown is not limited. Depending on specific implementation needs, there can be any number of first domain controllers 101 and second domain controllers 102.

[0020] In some optional implementations of the embodiments of this disclosure, the first domain controller 101 can be implemented as a cockpit domain controller (CDC), and the second domain controller 102 can be implemented as a driver assistance domain controller. The cockpit domain controller can provide infotainment functions, driving data display functions, driver assistance functions, etc., to enhance the user's driving experience. The driver assistance domain controller can integrate and manage the vehicle's autonomous driving-related functions, such as adaptive cruise control, collision warning functions, lane departure warning functions, etc.

[0021] Furthermore, in some optional implementations of the embodiments of this disclosure, the first domain controller 101 and the second domain controller 102 may respectively include a microcontroller (MCU) and a microprocessor unit (MPU) (or system on chips (SoC)) in terms of hardware architecture, and the microcontroller and the microprocessor (or SoC) can communicate and interact with each other.

[0022] In this context, SoC refers to a product, a dedicated integrated circuit containing a complete system and embedded software. In a narrow sense, SoC is a chip integration of the core of an information system, integrating key system components onto a single chip. In a broader sense, SoC is a micro-system, generally defined as integrating a microprocessor, analog IP (Intellectual Property) core, digital IP core, and memory (or off-chip memory control interface) onto a single chip. It is typically user-customized or a standard product for a specific purpose.

[0023] Furthermore, in some optional implementations of the embodiments of this disclosure, at least one of the following operating systems can be deployed and run on the microprocessor or system-on-a-chip: Android, Linux, or Quick UNIX (QNX). In some optional implementations, the microprocessor or system-on-a-chip can run both QNX and Android operating systems. The QNX operating system can primarily handle functions with high real-time and security requirements, such as LCD instrument clusters and head-up displays (HUDs), while the Android operating system can primarily handle functions with high scalability requirements, such as navigation, vehicle settings, and multimedia playback.

[0024] In related technologies, the operating system is typically powered down by a forced power-off using the aforementioned microcontroller. This method is relatively simple and crude; a sudden power-off while the system is running can easily lead to system malfunctions and fails to meet safety requirements. However, the power-down control scheme provided in this disclosure can effectively reduce the probability of system malfunctions caused by direct forced power-offs while ensuring the operational stability of the first operating system throughout the power-down process. It also improves the efficiency of the power-down operation and meets safety requirements, thereby enhancing the reliability and robustness of system operation.

[0025] Please refer to Figure 2 , Figure 2A flowchart of a power-down control method provided in this disclosure embodiment, which can be applied to a vehicle, includes the following steps:

[0026] Step 201: Upon receiving the power-down command, the microcontroller sends a power-down notification message to the first operating system in the microprocessor through the first general-purpose input / output port.

[0027] This step is intended to be performed by a microcontroller (e.g., Figure 1 The MCU deployed in the first domain controller 101 or the second domain controller 102 shown receives a power-down command (e.g., triggered by a vehicle user in a certain way) and, in response to receiving the power-down command, sends a signal to the microprocessor (e.g., via its first general purpose input / output (GPIO) port). Figure 1 The first operating system in the MPU or SoC deployed in the first domain controller 101 or the second domain controller 102 sends a power-down notification message; wherein, the first GPIO port and the first operating system may have a pre-set correspondence to ensure that the power-down command, power-down notification message and other related signals are accurately exchanged between the microcontroller and the microprocessor.

[0028] Step 202: In response to receiving the power-down notification message, the microprocessor performs a shutdown operation on multiple upper-layer applications of the first operating system according to a first preset rule; wherein, the first preset rule is determined based on at least one of the screen-related information corresponding to the upper-layer application of the first operating system and the number of application associations.

[0029] Step 203: In response to the microprocessor having sequentially completed the shutdown operations on multiple upper-layer and lower-layer applications of the first operating system, the microprocessor sends a first response message to the microcontroller through the second general-purpose input / output port.

[0030] Based on step 201, steps 202-203 aim to have the microprocessor, upon receiving a power-down notification message from the microcontroller via the first GPIO port, first shut down the upper-layer and lower-layer applications of the first operating system sequentially in order from upper-layer applications to lower-layer applications, and after completing the sequential shutdown operation (or power-off operation) of the upper-layer and lower-layer applications, provide feedback to the microcontroller via its second GPIO port, that is, to inform the microcontroller via a first response message that the upper-layer and lower-layer applications of the first operating system in the microprocessor have been shut down. Specifically, when there are multiple upper-layer applications in the first operating system, each upper-layer application is closed sequentially according to a pre-set rule, and then the lower-level applications of the first operating system are closed. The first preset rule corresponding to the first operating system is determined based on at least one of the screen-related information and application association number of the upper-layer applications of the first operating system, so that the multiple upper-layer applications are closed in a regular manner, ensuring the stability of the first operating system. The application association number corresponding to the upper-layer application can refer to the total number of other upper-layer applications that are currently running and are opened (or enabled) by the jump (or call) interface (or channel or path or link, etc.) provided by the upper-layer application.

[0031] Step 204: Upon receiving the first response message, the microcontroller performs a power-down operation on the first operating system.

[0032] Based on step 203, this step aims to have the microcontroller, in response to receiving feedback indicating that the upper-layer and lower-layer applications of the first operating system in the microprocessor have been shut down sequentially, control the execution of a power-down operation on the first operating system.

[0033] The power-down control method provided in this disclosure enables efficient interaction between the microcontroller and the microprocessor through their respective GPIO ports. Specifically, upon receiving a power-down command, the microcontroller can send a power-down notification message to the microprocessor through its first GPIO port. In response to receiving the power-down notification message, the microprocessor sequentially shuts down the upper-layer and lower-layer applications of its first operating system. Then, it sends feedback (i.e., a first response message) to the microcontroller through its second GPIO port. When the first operating system has multiple upper-layer applications, it can perform a regular shutdown operation on these applications according to a first preset rule determined based on at least one of the screen-related information and application association numbers corresponding to the upper-layer applications. Furthermore, upon receiving the feedback, the microcontroller can determine that the first operating system has essentially entered a stopped state. Performing a power-down operation at this point effectively reduces the probability of system malfunctions caused by direct forced power-off while ensuring the operational stability of the first operating system throughout the power-down process. It also improves the efficiency of the power-down operation and meets safety requirements, thereby enhancing the reliability and robustness of the system operation.

[0034] In the above Figure 2 Based on the corresponding embodiment, step 201, sending a power-down notification message to the first operating system in the microprocessor via the first general-purpose input / output port, can be specifically executed as follows: sending the aforementioned power-down notification message to the first operating system by pulling the level of the first GPIO port high. Thus, by sending a level signal by pulling the GPIO port high, the power-down notification message to the first operating system can be sent efficiently. It should be noted that the specific value of pulling the GPIO port high can be set according to specific circumstances and needs, such as pulling it high to 1.8V, and is not specifically limited here.

[0035] In the above Figure 2 Based on the corresponding embodiments, in some optional implementations of the embodiments of this disclosure, the screen-related information mentioned above may include, but is not limited to, at least one of the following: the setting position of the screen in the vehicle, the display position of the application on the screen, and the display area occupied by the application on the screen.

[0036] In some optional implementations of the embodiments of this disclosure, the screens, depending on their placement within the vehicle, may include at least a central control display screen, an instrument panel display screen, and a rear-seat display screen. The central control display screen is typically located between the driver's and passenger's seats and is primarily used to display and control the vehicle's multimedia applications (such as audio / video, games, and other entertainment applications, navigation applications, etc.), instant messaging applications, wireless network applications, office applications, and network service applications. The instrument panel display screen is typically located on the dashboard in front of the driver's seat and is primarily used to display real-time information related to vehicle status, such as speed, fuel consumption, mileage, and alarm applications (such as fault alerts and seatbelt reminders). The rear-seat display screen is typically located behind the headrests of the front seats or behind the center armrest of the front seats; the specific location may vary depending on the vehicle model. It is primarily used to display multimedia applications, office applications, wireless network applications, and alarm applications for rear passengers. It should be noted that the above distinction between the central control display screen, instrument panel display screen, and rear-seat display screen can be based not only on the aforementioned different placement locations but also on the aforementioned functional differences.

[0037] Furthermore, in some optional implementations of the embodiments of this disclosure, when the first preset rule is determined based on the screen's location in the vehicle, the priority order for performing shutdown operations on multiple upper-level applications of the first operating system indicated by the first preset rule may include: upper-level applications displayed on the rear-seat display screen are shut down before upper-level applications displayed on the central control display screen; and upper-level applications displayed on the central control display screen are shut down before upper-level applications displayed on the instrument panel display screen. In this way, while effectively releasing the system resources occupied by the upper-level applications of the first operating system, the safety of operation can be ensured by maximizing the display time of content that helps users understand the real-time status of the vehicle. The upper-level applications of the first operating system displayed on the aforementioned different displays may be the same or different, depending on specific needs.

[0038] In some optional implementations of the embodiments of this disclosure, when classifying applications based on their display positions on the screen, at least two categories can be distinguished: those displayed in the central area of ​​the screen and those displayed in the non-central area. The central and non-central areas can be flexibly divided based on screen size, the display requirements of the application to be displayed (e.g., display size, resolution, etc.). In some optional implementations, a region with a preset shape formed by extending a preset distance from the center point of the screen to different edges in different directions can be defined as the central area, and other areas of the screen besides the central area can be defined as non-central areas. The preset distances extended to the edges in different directions can be the same or different, depending on the screen size, shape, and display requirements of the application to be displayed. For example, the preset shape formed by extending the same distance can include a square, a circle, etc., while the preset shapes formed by extending different distances can include a rectangle, an ellipse, etc. It should be noted that the screen here can refer to any display screen in a vehicle, such as a central control display screen, an instrument display screen, and a rear-seat display screen, etc., and is not specifically limited here.

[0039] Furthermore, in some optional implementations of the embodiments of this disclosure, when the first preset rule is determined based on the display position of the application on the screen, the priority order for performing closing operations on multiple upper-level applications of the first operating system indicated by the first preset rule may include: upper-level applications whose display position is located in the non-central area of ​​the screen are closed before upper-level applications whose display position is located in the central area of ​​the screen. In this way, while effectively releasing the system resources occupied by the upper-level applications of the first operating system, the display time of more important or critical applications displayed in the central area of ​​the screen can be guaranteed as much as possible, thereby ensuring the user's application experience and operational security. The upper-level applications displayed in the aforementioned different display positions of the first operating system are usually different, and the correspondence between upper-level applications and display positions can be determined according to specific display requirements, and is not specifically limited here.

[0040] In some optional implementations of the embodiments of this disclosure, when classifying applications based on the display area occupied by the application on the screen, the first preset rule can be specifically set according to the ratio of the display area occupied by the application on the same screen to the total area of ​​the screen, i.e., the area ratio. The priority order for performing closing operations on multiple upper-level applications of the first operating system indicated by the first preset rule may include: upper-level applications with smaller area ratios are closed before those with larger area ratios. This effectively releases system resources occupied by upper-level applications of the first operating system while ensuring the display time of more important or critical applications occupying a larger display area on the screen, thereby protecting the user's application experience and operational security. The upper-level applications occupying different display areas of the first operating system are usually different, and the correspondence between upper-level applications and their occupied areas can be determined according to specific display requirements, and is not specifically limited here.

[0041] In some optional implementations of this disclosure, where the first preset rule is determined based on the number of application associations of the upper-layer applications of the first operating system, the priority ordering for performing shutdown operations on multiple upper-layer applications of the first operating system indicated by the first preset rule may include: upper-layer applications with fewer application associations are shut down before those with more application associations. This effectively releases system resources occupied by the upper-layer applications of the first operating system while ensuring the display time of upper-layer applications with more associations with other upper-layer applications, thereby guaranteeing the user's application experience.

[0042] It should be noted that the above implementation methods are described from the perspective that the first preset rule is determined based on one of the factors: the number of application associations corresponding to the upper-layer applications of the first operating system or various different screen-related information. In some other optional implementation methods of this disclosure, the first preset rule can be determined based on a combination of one or more of the application associations corresponding to the upper-layer applications of the first operating system and the screen-related information. In one example, the priority order for performing a closing operation on multiple upper-layer applications of the first operating system indicated by the first preset rule may include: among the multiple upper-layer applications of the first operating system, those with smaller area and fewer application associations are given priority over those with larger area and more application associations. In one example, the priority order for closing multiple upper-layer applications of the first operating system indicated by the first preset rule may include: upper-layer applications of the first operating system that occupy a smaller area, have fewer application associations, and are displayed in a non-central area of ​​the screen are closed in priority over upper-layer applications that occupy a larger area, have more application associations, and are displayed in the central area of ​​the screen; however, it is not limited to these two examples. Rules determined based on any combination of application associations and one or more of the above-mentioned screen-related information can fall within the protection scope of this disclosure embodiment, and will not be listed one by one here. The specific rules can be set according to the specific needs of the user, the specific configuration of the vehicle, etc. Alternatively, the aforementioned first preset rule can be determined based on at least two of the screen-related information corresponding to the upper-layer applications of the first operating system. In one example, the priority order for performing a closing operation on multiple upper-layer applications of the first operating system indicated by the first preset rule may include: upper-layer applications of the first operating system that occupy a smaller area and are displayed in a non-central area of ​​the screen are closed in priority over upper-layer applications that occupy a larger area and are displayed in a central area of ​​the screen. However, this is not limited to this example. Rules determined based on any combination of the aforementioned screen-related information can fall within the protection scope of this disclosure embodiment. They will not be listed one by one here, and the specific rules can be set according to the user's specific needs, the specific configuration of the vehicle, etc.

[0043] In the above Figure 2Based on the corresponding embodiments, the aforementioned first operating system includes a real-time operating system or an Android operating system. Specifically, when the first operating system is a real-time operating system, its multiple upper-layer applications include at least two of instrument applications, network service applications, and alarm applications, and its lower-layer applications include a real-time operating system driver. Alternatively, when the first operating system is an Android operating system, its multiple upper-layer applications include at least two of multimedia applications, wireless network applications, office applications, instant messaging applications, and data storage applications, and its lower-layer applications include an Android operating system driver. The aforementioned network service applications include, but are not limited to, Ethernet-related applications; the aforementioned multimedia applications may include, but are not limited to, audio applications, video applications, navigation applications, and camera applications; the aforementioned wireless network applications include, but are not limited to, Wireless Fidelity (Wi-Fi) connection applications, Bluetooth connection applications, and wireless connection applications implemented based on StarFlash technology. Further, in one example, the aforementioned application association count may be the total number of navigation applications, multimedia applications, and office applications that are opened and running through links contained in the session messages of an instant messaging application.

[0044] Please refer to Figure 3 , Figure 3 A flowchart of another power-down control method provided in this disclosure embodiment, which can be applied to a vehicle, includes the following steps in process 300:

[0045] Step 301: Upon receiving the power-down command, the microcontroller sends a power-down notification message to the first operating system and the second operating system in the microprocessor by pulling the level of the first general-purpose input / output port high.

[0046] This step is intended to be performed by a microcontroller (e.g., Figure 1 The MCU deployed in the first domain controller 101 or the second domain controller 102 shown receives a power-down command (e.g., triggered by a vehicle user in a certain way), and in response to receiving the power-down command, pulls high the level of its first GPIO port, while simultaneously sending a signal to the microprocessor (e.g., ...). Figure 1 The first and second operating systems in the MPU or SoC deployed in the first domain controller 101 or the second domain controller 102 respectively send power-down notification messages. In this way, by pulling the level of the same GPIO port high to send a level signal, power-down notification messages for different operating systems within it are efficiently sent to the microprocessor simultaneously. The first GPIO can have a pre-defined correspondence with the first and second operating systems to ensure accurate and effective interaction between the power-down command, power-down notification message, and other related signals between the microcontroller and the microprocessor.

[0047] Step 302: In response to receiving the power-down notification message, the microprocessor performs a shutdown operation on multiple upper-layer applications of the second operating system according to the second preset rule; wherein, the second preset rule is determined based on at least one of the screen-related information corresponding to the upper-layer application of the second operating system and the number of application associations.

[0048] Step 303: After the microprocessor has sequentially completed the shutdown operations on multiple upper-layer applications and lower-layer applications of the second operating system, and has detected the second response message sent by the second operating system to the first operating system, it performs shutdown operations on multiple upper-layer applications of the first operating system according to the first preset rule; wherein, the first preset rule is determined based on at least one of the screen-related information and the number of application associations corresponding to the upper-layer applications of the first operating system.

[0049] Step 304: In response to the microprocessor having sequentially completed the shutdown operations on multiple upper-layer and lower-layer applications of the first operating system, the microprocessor sends a first response message to the microcontroller through the second general-purpose input / output port.

[0050] Based on step 301, steps 302-303 aim to have the microprocessor, upon receiving a power-down notification message from the microcontroller via the first GPIO port for the first and second operating systems, first sequentially shut down the upper-level and lower-level applications of the second operating system in order from upper-level applications to lower-level applications. After completing the sequential shutdown operation (or shutdown operation) for the upper-level and lower-level applications of the second operating system and detecting a second response message sent by the second operating system to the first operating system indicating that its upper-level and lower-level applications have been shut down, the microprocessor then sequentially shuts down the upper-level and lower-level applications of the first operating system in order from upper-level applications to lower-level applications. After completing the sequential shutdown operation (or shutdown operation) for the upper-level and lower-level applications of the first operating system, the microprocessor then provides feedback to the microcontroller via the second GPIO port, that is, by informing the microcontroller via the first response message that the upper-level and lower-level applications of the first operating system in the microprocessor have been shut down.

[0051] In the case of multiple upper-layer applications in the second operating system, each upper-layer application is closed sequentially according to a pre-set second rule, and then the underlying applications of the second operating system are closed. The second pre-set rule is determined based on at least one of the screen-related information and application association number of the upper-layer applications in the second operating system, so that the multiple upper-layer applications are closed systematically, ensuring the stability of the second operating system. The application association number of an upper-layer application can refer to the total number of other upper-layer applications that are currently running and have been opened (or enabled) by the jump (or call) interface (or channel, path, or link, etc.) provided by the upper-layer application. In the case of multiple upper-layer applications in the first operating system, each upper-layer application is closed sequentially according to a pre-set first rule, and then the underlying applications of the first operating system are closed. A description of the first rule can be found above. Figure 2 The relevant descriptions in the corresponding embodiments will not be repeated here.

[0052] Step 305: Upon receiving the first response message, the microcontroller performs a power-down operation on the first operating system and the second operating system.

[0053] Based on step 305, this step aims to enable the microcontroller to control the power-down operation of the first operating system and the second operating system in response to feedback that the upper-level and lower-level applications of the first operating system in the microprocessor have been shut down in sequence after the upper-level and lower-level applications of the second operating system have been shut down.

[0054] The power-down control method provided in this disclosure enables efficient interaction between a microcontroller and a microprocessor through their respective GPIO ports. Specifically, upon receiving a power-down command, the microcontroller can send a power-down notification message to the microprocessor through its first GPIO port. In response to receiving this notification message, the microprocessor sequentially shuts down the upper-layer and lower-layer applications of its second operating system, and then sequentially shuts down the upper-layer and lower-layer applications of its first operating system. The microprocessor can then send feedback (i.e., a first response message) to the microcontroller through its second GPIO port. Multiple upper-layer applications exist in both the first and second operating systems. At this time, according to the corresponding preset rules determined based on at least one of the screen-related information and application association number of their respective upper-layer applications, the regular shutdown operation of multiple upper-layer applications can be realized. Furthermore, after receiving the above feedback, the microcontroller can know that the first operating system and the second operating system have basically entered the state of stopping operation. At this time, the power-down operation is performed on both of them. While ensuring the operational stability of the first operating system and the second operating system throughout the power-down process, the probability of system operation abnormality caused by direct forced power-off can be effectively reduced. At the same time, the efficiency of the power-down operation can be improved, and the security requirements can be met, thereby improving the reliability and robustness of system operation.

[0055] In the above Figure 3 Based on the corresponding embodiments, in some optional implementations of the embodiments of this disclosure, the screen-related information corresponding to the upper-layer application of the second operating system and the screen-related information corresponding to the upper-layer application of the first operating system may include, but are not limited to, at least one of the following: the screen's location in the vehicle, the application's display location on the screen, and the display area occupied by the application on the screen. Further, specific limitations regarding the screen's location in the vehicle, the application's display location on the screen, the display area occupied by the application on the screen, and the application's associated number can be found above. Figure 2 The relevant descriptions in the corresponding embodiments will not be repeated here. Furthermore, regarding the implementation method of setting the second preset rule corresponding to the second operating system based on at least one of the above-mentioned application association number, screen location in the vehicle, application display location on the screen, and display area occupied by the application on the screen, please refer to the above description. Figure 2 The description of the implementation method of the first preset rule corresponding to the first operating system in the corresponding embodiments will not be repeated here; and the relevant description of the implementation method of the first preset rule corresponding to the first operating system can be referred to the above. Figure 2 The relevant descriptions in the corresponding embodiments will not be repeated here.

[0056] In the above Figure 3 Based on the corresponding embodiments, the first operating system includes a real-time operating system, and the second operating system includes an Android operating system. Specific limitations regarding the real-time operating system and the Android operating system can be found above. Figure 2 The relevant descriptions in the corresponding embodiments will not be repeated here.

[0057] Regarding the above Figure 2 Step 203 in the corresponding embodiment and Figure 3 In the corresponding embodiment, step 304, sending the first response message to the microcontroller via the second general-purpose input / output port, can be specifically executed as follows: sending the aforementioned first response message to the microcontroller by pulling the level of the second GPIO port high. Thus, by sending a level signal by pulling the GPIO port high, feedback can be efficiently provided regarding the completion of the corresponding shutdown operation of the first and second operating systems. It should be noted that the specific value of the GPIO port level can be set according to specific circumstances and needs, such as pulling it high to 1.8V; no specific limitation is made here.

[0058] Regarding the above Figure 2 Step 201 in the corresponding embodiment and Figure 3 In the corresponding embodiment, the power-down command in step 301 is sent in response to triggering multiple buttons on the steering wheel of the vehicle. In this embodiment, the power-down command can be sent to the vehicle's MCU by simultaneously triggering (or pressing) multiple buttons on the steering wheel of the vehicle. In this way, while effectively triggering the power-down operation of the operating system, the utilization rate of the buttons on the steering wheel of the vehicle can also be improved. Moreover, triggering through a combination of keys will not affect the implementation of the functions already set for each button.

[0059] Furthermore, in some optional implementations of the embodiments of this disclosure, the aforementioned plurality of buttons can be buttons located in different areas of the vehicle's steering wheel, so that different buttons are spaced a certain distance apart, to avoid accidentally starting the power-down operation of the aforementioned operating system due to operational errors.

[0060] It should be noted that, in the embodiments of this disclosure, the specific combination scheme of the above-mentioned multiple buttons can be selected and set as needed according to the arrangement of the buttons on the steering wheel of different vehicle models, and is not specifically limited here. For example, in an exemplary embodiment, the above-mentioned power-down command is sent in response to triggering 2-4 buttons, some of which can be conveniently triggered (or pressed) by one hand when the user is holding the steering wheel, and others can be conveniently triggered (or pressed) by the other hand.

[0061] In the above Figure 2Corresponding embodiments and Figure 3 Based on the corresponding embodiments, to ensure the smooth execution of the power-down operation for the aforementioned operating system, the following can also be included: A timeout protection mechanism is employed to ensure the smooth execution of the power-down operation, i.e., a forced power-down can be used as a fallback. Specifically, the microcontroller can monitor whether the aforementioned feedback has been received after sending a power-down notification message. If the cumulative time after sending the power-down notification message reaches a preset duration, and no feedback is received from the microprocessor side indicating that the shutdown operation for the aforementioned operating system has been completed within the preset duration, the microcontroller can continue to forcibly power down the aforementioned operating system. It should be noted that the specific value of the preset duration can be set according to specific circumstances and needs, such as 5 seconds or 10 seconds, etc., and can be controlled by starting a corresponding timer; no specific limitation is made here.

[0062] In the above Figure 2 Corresponding embodiments and Figure 3 Based on the corresponding embodiments, in any of the above embodiments, the power-down control method can, after performing the above-mentioned safe power-down operation, also send a power-on notification message to the first operating system, or to the first operating system and the second operating system respectively, in combination with specific application scenarios (such as scenarios where the vehicle needs to be driven out of the parking space for travel), to perform a reset, thereby satisfying the user experience.

[0063] To enhance understanding, this disclosure also provides a specific implementation scheme in conjunction with a particular application scenario. The example uses an Android (operating) system (corresponding to the second operating system shown in any of the above embodiments) and a QNX (operating) system (corresponding to the first operating system shown in any of the above embodiments) running on or mounted on the MPU 403 (corresponding to the microprocessor shown in any of the above embodiments) as illustrations. Please refer to [link / reference needed]. Figure 4 ,like Figure 4 As shown, the following steps may be included:

[0064] Step 4-1: User 401 sends a command to MCU 402 (corresponding to the microcontroller shown in any of the above embodiments) by pressing the steering wheel combination keys to initiate a restart.

[0065] Step 4-2: MCU 402 notifies MPU 403's Android system and QNX system user 401 of a system reboot command by pulling its GPIO1 port (corresponding to the first GPIO port shown in any of the above embodiments) high.

[0066] Step 4-3: The underlying Android system of MPU 403 notifies all services and applications on the upper layer of the Android system of MPU 403 to shut down.

[0067] Step 4-4: The upper-layer applications and services of the Android system in MPU 403 save data, release resources, stop reading and writing disk data, etc., to perform the corresponding shutdown operation. Then, in step 4-5, a message is sent back to the lower layer of the Android system in MPU 403 to indicate that the upper-layer shutdown operation has been completed.

[0068] Steps 4-6: The underlying Android system of MPU 403 shuts down and releases driver resources, saves buffer data, and disables interrupts to perform the corresponding shutdown operation. Then, in step 4-7, it replies to the underlying QNX system of MPU 403 to indicate that the corresponding shutdown operation of the Android system has been completed.

[0069] Steps 4-8: The upper-layer applications and services of the MPU 403 QNX system save data, release resources, stop reading and writing disk data, etc., to perform the corresponding shutdown operation. Then, in step 4-9, a message is sent back to the lower layer of the MPU 403 QNX system to indicate that the upper-layer shutdown operation has been completed.

[0070] Step 4-10: The QNX system layer of MPU 403 shuts down and releases drive resources, saves buffer data, and disables interrupts to perform the corresponding shutdown operation. Then, in step 4-11, it sends a message back to the QNX system layer of MCU 402 to indicate that the corresponding shutdown operation of the QNX system has been completed by pulling its GPIO2 port (corresponding to the second GPIO port shown in any of the above embodiments) high.

[0071] Step 4-12: MCU 402 controls the power-down of MPU 403; further, depending on the specific application scenario, step 4-13 controls the power-up of MPU 403 to perform a reset and restart.

[0072] It should be noted that if the MCU 402 does not receive the feedback shown in steps 4-11 after the cumulative duration of the notification issued in step 402 reaches the preset duration, it can control the MPU 403 to be forcibly powered down, that is, to ensure the smooth execution of the power-down operation by activating the timeout protection mechanism; and further, it can control the MPU 403 to be powered on to achieve a restart when needed.

[0073] Further reference Figure 5 As an implementation of the methods shown in the above figures, this disclosure provides an embodiment of a power-down control system, which is similar to... Figure 2-3 Corresponding to the method embodiments shown, the system can be specifically applied to various electronic devices, such as domain controllers in vehicles.

[0074] like Figure 5As shown, the power-down control system 500 of this embodiment may include a microcontroller 501 and a microprocessor 502.

[0075] The microcontroller 501 is configured to, in response to receiving a power-down command, send a power-down notification message to the first operating system in the microprocessor 502 via a first general-purpose input / output port; the microprocessor 502 is configured to, in response to receiving the power-down notification message, perform a shutdown operation on multiple upper-layer applications of the first operating system according to a first preset rule; wherein the first preset rule is determined based on at least one of screen-related information and application association number corresponding to the upper-layer applications of the first operating system; and the microprocessor 502 is further configured to, in response to sequentially performing shutdown operations on multiple upper-layer applications and lower-layer applications of the first operating system, send a first response message to the microcontroller 501 via a second general-purpose input / output port; the microcontroller 501 is further configured to, in response to receiving the first response message, perform a power-down operation on the first operating system.

[0076] In this embodiment, the specific processing of the microcontroller 501 and the microprocessor 502 in the power-down control system 500 and the resulting technical effects can be found in the following references: Figure 2 The relevant descriptions of steps 201-204 in the corresponding embodiments will not be repeated here.

[0077] In some optional implementations of the embodiments of this disclosure, the microcontroller 501 is further configured to send a power-down notification message to the first operating system by pulling the level of the first general-purpose input / output port high.

[0078] In some optional implementations of the embodiments of this disclosure, the microcontroller 501 is further configured to: in response to receiving a power-down command, send a power-down notification message to the second operating system in the microprocessor 502 by pulling up the level of the first general-purpose input / output port; and in response to receiving a first response message, perform a power-down operation on the first operating system and the second operating system.

[0079] In some optional implementations of the embodiments of this disclosure, the microprocessor 502 is further configured to: in response to receiving a power-down notification message, perform a shutdown operation on a plurality of upper-layer applications of the second operating system according to a second preset rule; wherein the second preset rule is determined based on at least one of screen-related information and application association number corresponding to the upper-layer applications of the second operating system; and in response to after sequentially performing shutdown operations on a plurality of upper-layer applications and lower-layer applications of the second operating system, and detecting a second response message sent by the second operating system to the first operating system, perform a shutdown operation on a plurality of upper-layer applications of the first operating system according to a first preset rule.

[0080] In this embodiment, the specific processing of the microcontroller 501 and the microprocessor 502 in the power-down control system 500 and the resulting technical effects can be found in the following references: Figure 3 The relevant descriptions of steps 301-305 in the corresponding embodiments will not be repeated here.

[0081] In some optional implementations of the embodiments of this disclosure, the screen-related information mentioned above includes at least one of the following: the screen's location in the vehicle, the application's display location on the screen, and the display area occupied by the application on the screen.

[0082] In some optional implementations of the embodiments of this disclosure, the first operating system includes a real-time operating system, and the second operating system includes the Android operating system.

[0083] In some optional implementations of the embodiments of this disclosure, the plurality of upper-layer applications of the first operating system include at least two of instrument applications, network service applications, and alarm applications; the lower-layer applications of the first operating system include a real-time operating system driver; the plurality of upper-layer applications of the second operating system include at least two of multimedia applications, wireless connection applications, and data storage applications; and the lower-layer applications of the second operating system include an Android operating system driver.

[0084] In some optional implementations of the embodiments of this disclosure, the power-down command is sent in response to triggering multiple buttons on the steering wheel of the vehicle.

[0085] This embodiment exists as a system embodiment corresponding to the above method embodiment. The power-down control system 500 provided in this embodiment enables the microcontroller 501 and the microprocessor 502 to achieve efficient interaction through their respective GPIO ports. Specifically, when the microcontroller 501 receives a power-down command, it can send a power-down notification message to the microprocessor 502 through its first GPIO port. In response to receiving the power-down notification message, the microprocessor 502 sequentially shuts down the upper-layer application and the lower-layer application of its first operating system, and then sends feedback (i.e., a first response message) to the microcontroller 501 through its second GPIO port. When there are multiple upper-layer applications, the system can perform regular shutdown operations on these applications according to a first preset rule determined based on at least one of the screen-related information and application association number of the upper-layer applications. Furthermore, after receiving the above feedback, the microcontroller 501 can know that the first operating system has basically entered a state of shutdown. At this time, the power-down operation can be performed on it. This can effectively reduce the probability of system malfunction caused by direct forced power-off while ensuring the stability of the first operating system during the entire power-down process. At the same time, it can improve the efficiency of the power-down operation and meet the security requirements, thereby improving the reliability and robustness of the system operation.

[0086] Further reference Figure 6 Corresponding to the implementation of the system shown in the above embodiments, this disclosure provides an embodiment of a domain controller, which is similar to the one described above. Figure 5 Corresponding to the system embodiment shown, this domain controller can be specifically applied to various vehicles. For example... Figure 6 As shown, the domain controller 600 in this embodiment may include: as described above. Figure 5 The technical effects of the power-down control system 500 shown in any of the corresponding embodiments can be referred to... Figure 5 The relevant descriptions in the corresponding embodiments will not be repeated here. In specific implementations, the domain controller 600 may include the components described above. Figure 1 The corresponding embodiments show a first domain controller 101 (e.g., a cockpit domain controller) or a second domain controller 102 (e.g., a smart driving domain controller).

[0087] Furthermore, corresponding to the implementation of the domain controller shown in the above embodiments, this disclosure provides an embodiment of a vehicle. Specifically, the vehicle includes: the domain controller 600 provided in the above embodiments, and the technical effects it brings can be referred to... Figure 6 The relevant descriptions in the corresponding embodiments will not be repeated here.

[0088] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transferring data and instructions to the storage system, the at least one input device, and the at least one output device.

[0089] The program code used to implement the methods of this disclosure may be written in any combination of one or more programming languages. This program code may be provided to a processor or controller of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus, such that when executed by the processor or controller, the program code causes the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code may be executed entirely on a machine, partially on a machine, as a standalone software package partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0090] In the context of this disclosure, a machine-readable medium can be a tangible medium that may contain or store the aforementioned program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0091] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device for displaying information to the user (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor); and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the computer. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).

[0092] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as a data server), or computing systems that include middleware components (e.g., an application server), or computing systems that include frontend components (e.g., a user computer with a graphical user interface or web browser through which a user can interact with embodiments of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., a communication network). Examples of communication networks include local area networks (LANs), wide area networks (WANs), and the Internet.

[0093] Computer systems can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and Virtual Private Server (VPS) services, such as high management difficulty and weak business scalability.

[0094] According to the power-down control scheme of this disclosure, the microcontroller and microprocessor can achieve efficient interaction through their respective GPIO ports. Specifically, when the microcontroller receives a power-down command, it can send a power-down notification message to the microprocessor through its first GPIO port. In response to receiving the power-down notification message, the microprocessor sequentially shuts down the upper-layer applications and lower-layer applications of its first operating system. Then, it can send feedback (i.e., a first response message) to the microcontroller through its second GPIO port. When the first operating system has multiple upper-layer applications, it can perform a regular shutdown operation on these multiple upper-layer applications according to a first preset rule determined based on at least one of the screen-related information and application association number corresponding to the upper-layer applications. Furthermore, after receiving the above feedback, the microcontroller can know that the first operating system has basically entered a stopped state. At this time, the power-down operation is performed on it. This can effectively reduce the probability of system malfunction caused by direct forced power-off while ensuring the operational stability of the first operating system throughout the power-down process. At the same time, it can improve the efficiency of the power-down operation and meet the safety requirements, thereby improving the reliability and robustness of the system operation.

[0095] It should be understood that the various forms of processes shown above can be used to rearrange, add, or delete steps. For example, the steps described in this disclosure can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution disclosed in this disclosure can be achieved, and this is not a limitation herein; and the terms "first," "second," "third," "fourth," etc. (if present) in this disclosure are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence, nor do they constitute a specific limitation.

[0096] It should also be understood that expressions such as "comprising," "including," "having," "containing," and / or "comprising" are open-ended rather than closed-ended expressions in this disclosure, indicating the presence of the stated features, elements, and / or components, but not excluding the presence of one or more other features, elements, components, and / or combinations thereof. Furthermore, when expressions such as "at least one of..." appear after a list of listed features, they modify the entire list of features, not just individual elements in the list. Additionally, when describing embodiments of this disclosure, the word "may" is used to mean "one or more embodiments of this disclosure." And the term "exemplary" is intended to refer to an example or illustration.

[0097] Unless otherwise specified, all terms used herein (including engineering and technical terms) shall have the same meaning as commonly understood by one of ordinary skill in the art to which this disclosure pertains. It should also be understood that, unless expressly stated in this disclosure, terms as defined in common dictionaries shall be interpreted as having the meaning consistent with their meaning in the context of the relevant art, and not as having an idealized or overly formalized meaning.

[0098] The specific embodiments described above do not constitute a limitation on the scope of protection of this disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure should be included within the scope of protection of this disclosure.

Claims

1. A power-down control method, comprising: Upon receiving a power-down command, the microcontroller sends a power-down notification message to the first operating system in the microprocessor via the first general-purpose input / output port. In response to receiving the power-down notification message, the microprocessor performs a shutdown operation on multiple upper-layer applications of the first operating system according to a first preset rule; wherein, the first preset rule is determined based on at least one of screen-related information corresponding to the upper-layer applications of the first operating system and the number of application associations; In response to the microprocessor sequentially completing the shutdown operations on multiple upper-layer and lower-layer applications of the first operating system, the microprocessor sends a first response message to the microcontroller through the second general-purpose input / output port. In response to receiving the first response message, the microcontroller performs a power-down operation on the first operating system.

2. The method according to claim 1, wherein, The step of sending a power-down notification message to the first operating system in the microprocessor through the first general-purpose input / output port includes: The power-down notification message is sent to the first operating system by raising the level of the first general-purpose input / output port.

3. The method according to claim 2, wherein, The method further includes: In response to receiving the power-down command, the microcontroller sends the power-down notification message to the second operating system in the microprocessor by pulling the level of the first general-purpose input / output port high; and In response to receiving the first response message, the microcontroller performs a power-down operation on the first operating system, including: In response to receiving the first response message, the microcontroller performs a power-down operation on the first operating system and the second operating system.

4. The method according to claim 3, wherein, In response to receiving the power-down notification message, the microprocessor performs a shutdown operation on multiple upper-layer applications of the first operating system according to a first preset rule, including: In response to receiving the power-down notification message, the microprocessor performs a shutdown operation on multiple upper-layer applications of the second operating system according to a second preset rule; wherein, the second preset rule is determined based on at least one of the screen-related information corresponding to the upper-layer application of the second operating system and the number of application associations; In response to the microprocessor sequentially executing shutdown operations on multiple upper-layer and lower-layer applications of the second operating system and detecting a second response message sent by the second operating system to the first operating system, the microprocessor performs shutdown operations on multiple upper-layer applications of the first operating system according to the first preset rule.

5. The method according to claim 1 or 4, wherein, The screen-related information includes at least one of the following: the screen's location in the vehicle, the application's display location on the screen, and the display area occupied by the application on the screen.

6. The method according to claim 4, wherein, The first operating system includes a real-time operating system, and the second operating system includes the Android operating system.

7. The method according to claim 6, wherein, The first operating system has multiple upper-layer applications including at least two of instrument applications, network service applications, and alarm applications, and the first operating system has lower-layer applications including real-time operating system drivers. The upper-layer applications of the second operating system include at least two of the following: multimedia applications, wireless connectivity applications, office applications, instant messaging applications, and data storage applications. The lower-layer applications of the second operating system include Android operating system drivers.

8. The method according to claim 1, wherein, The power-down command is sent in response to triggering settings on multiple buttons on the vehicle's steering wheel.

9. A power-down control system, comprising a microcontroller and a microprocessor, wherein, The microcontroller is configured to send a power-down notification message to a first operating system in the microprocessor via a first general-purpose input / output port in response to receiving a power-down command. The microprocessor is configured to, in response to receiving the power-down notification message, perform a shutdown operation on multiple upper-layer applications of the first operating system according to a first preset rule; wherein the first preset rule is determined based on at least one of screen-related information corresponding to the upper-layer applications of the first operating system and the number of application associations; The microprocessor is also configured to send a first response message to the microcontroller via a second general-purpose input / output port in response to the sequential completion of shutdown operations on multiple upper-layer and lower-layer applications of the first operating system. The microcontroller is also configured to perform a power-down operation on the first operating system in response to receiving the first response message.

10. A domain controller comprising the power-down control system as described in claim 9.