Power-up control method of vehicle, vehicle and storage medium
By adopting a unified command signal feedback mechanism and delay protection strategy between the vehicle control module and the power system, the coupling problem between the power system and the vehicle control module is solved, thereby improving the vehicle's start-up success rate and driving safety.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- GREAT WALL MOTOR CO LTD
- Filing Date
- 2026-04-24
- Publication Date
- 2026-06-05
Smart Images

Figure CN122143638A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of vehicle technology, and more specifically, to a method for controlling the power-on of a vehicle, a vehicle, and a storage medium in the field of vehicle technology. Background Technology
[0002] With the development of new energy vehicle technology, the functions of hybrid vehicles are becoming increasingly complex. During vehicle startup, the power battery needs to supply power to the motor and high-voltage system to enable the vehicle to enter a drivable state.
[0003] In related technologies, the vehicle control module (such as CEM (Central Electronic Module)) and the powertrain control device usually adopt a closed-loop control method of "send command - return command". That is, after the CEM sends a power-on request, it needs to wait for the powertrain to return a status confirmation signal to determine whether the power-on is successful.
[0004] However, the above method leads to a high degree of coupling between the vehicle control module and the power system. When the power system adds a new state, it needs to be frequently changed. Furthermore, due to timing constraints, it is prone to power-on misjudgment, which urgently needs to be resolved. Summary of the Invention
[0005] This application provides a power-on control method for a vehicle, a vehicle, and a storage medium. The method uses a unified command signal as the only status signal fed back to the vehicle control module and does not transmit intermediate status information back as a terminal status feedback mechanism, thereby decoupling the power system from the vehicle control module. Combined with the delay protection for abnormal power-off during driving and the gear switching strategy, a complete error-proof power-on system is constructed.
[0006] In a first aspect, a power-on control method for a vehicle is provided. The method includes: in response to a start command, acquiring the current low-voltage electrical state of the vehicle; if the current low-voltage electrical state is available, controlling the vehicle to perform a high-voltage power-on operation and identifying whether the vehicle is in a preset ready-to-drive state; if the vehicle is in the preset ready-to-drive state, sending a drivable command to the vehicle's target gateway, so that when the vehicle meets preset driving conditions, a driving permission command is issued through the target gateway.
[0007] By adopting the above technical solution, a terminal status feedback mechanism is established by using a unified command signal as the only status signal fed back to the vehicle control module and without transmitting intermediate status information. This decouples the power system from the vehicle control module. Combined with the time delay protection for abnormal power-down during driving and the gear switching strategy, a complete power-on error prevention system is constructed.
[0008] In conjunction with the first aspect, in some possible implementations, after issuing the driving permission instruction through the target gateway, the method further includes: determining whether a power-off instruction has been received; if the power-off instruction has been received, determining whether the current driving speed of the vehicle is greater than or equal to a preset speed; if the current driving speed of the vehicle is greater than or equal to the preset speed, controlling the vehicle to execute a delayed power-off strategy.
[0009] By introducing a vehicle speed determination mechanism after receiving a power-off command, the above technical solution ensures that power is cut off only when the vehicle speed is below a preset threshold. If the vehicle speed is too high, a delayed power-off strategy is triggered. This effectively avoids accidental power outages in the high-voltage system caused by accidentally triggering the power-off command while driving, thereby preventing safety hazards such as sudden loss of vehicle power and failure of steering / braking assistance, and significantly improving driving safety.
[0010] In combination with the first aspect and the above implementation methods, in some possible implementation methods, controlling the vehicle to execute the delayed power-off strategy includes: starting a delayed power-off timer based on a preset delay interval, controlling the vehicle to switch from the current gear to neutral; and when the delayed power-off timer ends, if the vehicle's current driving speed is less than the preset speed, controlling the vehicle to switch from the current gear to the parking gear.
[0011] Through the above technical solution, by coordinating gear shifting and delayed timing, when the vehicle is accidentally powered off while driving, the gear is first switched from drive to neutral to cut off power transmission, while maintaining high-voltage power supply to ensure the operation of the safety system. After the timing ends and the vehicle speed drops to a safe threshold, the vehicle is switched to park. This not only avoids the risk of power loss caused by directly cutting off the high voltage, but also achieves a smooth transition from driving to parking through phased operation, significantly improving driving safety and handling smoothness in the event of misoperation.
[0012] In conjunction with the first aspect and the above implementation methods, in some possible implementation methods, after controlling the vehicle to execute the delayed power-down strategy, the method further includes: determining whether a restart command for the vehicle has been received; if a restart command for the vehicle has been received, determining whether the current gear of the vehicle is in neutral or in parking; if the current gear is in neutral or in parking, determining whether the vehicle has a high-voltage prohibition fault; if the vehicle does not have the high-voltage prohibition fault, controlling the vehicle to restart.
[0013] By establishing a dual verification mechanism based on gear position and fault status, the vehicle is allowed to use gear safety instead of speed limit as the restart criterion during the delayed power-down period. This avoids the deadlock of "cannot restart if vehicle speed is not reduced below the threshold" in traditional logic, and ensures the safety of the restart process through fault diagnosis. This significantly improves the flexibility of vehicle recovery and system robustness after misoperation.
[0014] In combination with the first aspect and the above implementation methods, in some possible implementation methods, before sending the drivable command to the target gateway of the vehicle, the method further includes: determining whether the high-voltage connection operation was successfully executed within a first preset time period; if the high-voltage connection operation was not successfully executed within the first preset time period, then the high-voltage connection operation is continued.
[0015] By using the above technical solution, and by setting a first preset time as an intermediate monitoring node, the system does not immediately report an error when the high voltage is not successfully applied after the timeout, but continues to execute the operation. This effectively solves the problem of the mismatch between the fixed time limit of the CEM for the CRANK state and the actual physical start-up time of the power system (such as the longer time required for cold start). This avoids false alarms that could lead to start-up interruption, ensures the integrity of the vehicle's high voltage power-up process and the start-up success rate, and does not affect the timing logic of the CEM, thus achieving decoupling between the power system and the gateway control logic.
[0016] In combination with the first aspect and the above implementation methods, in some possible implementation methods, after the high-voltage operation is not successfully executed within the first preset time period, the method further includes: determining whether the high-voltage operation is successfully executed within a second preset time period, wherein the second preset time period is longer than the first preset time period; if the high-voltage operation is successfully executed within the second preset time period, then a drivable command is sent to the target gateway of the vehicle.
[0017] By using the above technical solution, a second preset time (e.g., 15 seconds) is set as a global limit threshold. If the high voltage is not successfully applied after the first preset time, no error is immediately reported. Instead, the operation continues until the second preset time. This avoids false alarms caused by the fixed timing limit of CEM and prevents indefinite waiting through the global time limit. At the same time, the actual physical start-up success is used as the final judgment criterion. This achieves complete decoupling between the power system start-up logic and CEM parameters, significantly improving the vehicle's start-up success rate and system fault tolerance under special operating conditions.
[0018] In combination with the first aspect and the above implementation methods, in some possible implementation methods, after determining whether the high-voltage operation was successfully executed within the second preset time period, the method further includes: if the high-voltage operation was not successfully executed within the second preset time period, then the current high-voltage operation is stopped and a high-voltage failure reminder is generated.
[0019] By using the above technical solution and stopping the timeout operation, the power battery and engine and other hardware can be protected from overload damage after a single start failure, thus achieving a balance between hardware safety and system availability.
[0020] In combination with the first aspect and the above implementation methods, in some possible implementation methods, after the vehicle is in the preset ready-to-drive state, the method further includes: illuminating the vehicle's drivable status indicator light based on the drivable command.
[0021] By illuminating the driving status indicator light, the user is provided with a clear and intuitive visual feedback that "the vehicle is ready." This illumination signal is used as the sole status feedback signal to the CEM, thereby improving the human-machine interaction experience while achieving efficient reuse of power system status information and decoupling of system interaction.
[0022] Secondly, a vehicle power-on control device is provided, the device comprising: The acquisition module is used to acquire the vehicle's current low-voltage electrical state in response to the start command; The control module is used to control the vehicle to perform a high-voltage connection operation when the current low-voltage electrical state is available, and to identify whether the vehicle is in a preset ready-to-drive state. The execution module is used to send a driving command to the vehicle's target gateway when the vehicle is in the preset driving ready state, so that when the vehicle meets the preset driving conditions, a driving permission command is issued through the target gateway.
[0023] Thirdly, a vehicle is provided, including the power-on control method for the vehicle described in the above embodiments.
[0024] Fourthly, a computer program product is provided, comprising: computer program code, which, when run on a computer, causes the computer to perform the methods described in the first aspect or any possible implementation thereof.
[0025] Fifthly, a computer-readable storage medium is provided that stores computer program code, which, when executed on a computer, causes the computer to perform the methods described in the first aspect or any possible implementation thereof. Attached Figure Description
[0026] Figure 1 A flowchart of a vehicle power-on control method provided in an embodiment of this application; Figure 2This is a schematic diagram of the high-voltage power-on timing according to an embodiment of this application; Figure 3 A block diagram of a vehicle power-on control device provided in an embodiment of this application; Figure 4 This is a schematic diagram of the vehicle structure according to an embodiment of this application. Detailed Implementation
[0027] The technical solutions in this application will be clearly and thoroughly described below with reference to the accompanying drawings. In the description of the embodiments of this application, unless otherwise stated, " / " means "or," for example, A / B can mean A or B. "And / or" in the text is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, and B existing alone. Furthermore, in the description of the embodiments of this application, "multiple" refers to two or more than two.
[0028] Hereinafter, the terms "first" and "second" are used for descriptive purposes only and should not be construed as implying or suggesting relative importance or implicitly indicating the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature.
[0029] With the increasing popularity of hybrid and electric vehicles, the reliability of high-voltage management in the powertrain has become a key factor affecting user experience and safety. Hybrid vehicles have various functional modes, such as remote start, cold start, and restart while driving, all of which depend on the accurate establishment of high-voltage conditions in the powertrain.
[0030] In related technologies, the control system (CEM) and the power system control device typically employ a closed-loop control method of "send command - return command confirmation". That is, after the CEM sends a power-on request, it needs to wait for the power system to return a status confirmation signal to determine whether the power-on was successful. However, the above method has the following problems: (1) Poor scalability: When the power system adds a "preset ready state for driving" (such as limp mode), the CEM needs to update the recognition logic synchronously, resulting in a large number of settings changes; (2) Tight timing coupling: The CEM usually sets a time limit requirement for the CRANK state (such as 3 seconds). If the power system exceeds the time limit due to special working conditions such as cold start, it may lead to misjudgment of power-on failure; (3) Risk of abnormal power-off: If the driver accidentally touches the one-button start button while driving, the system may immediately power off, which poses a safety hazard; (4) Difficulty in re-energizing: After an abnormal power-off, the vehicle may not be able to re-energize due to gear or speed limitations, affecting user use.
[0031] Therefore, based on the aforementioned problems, this application focuses on how to ensure that users of "high-voltage power system" can accurately "use the high-voltage state". Thus, a high-voltage power-on control strategy that can decouple the interaction between CEM and power system and has error prevention capabilities is needed. By replacing process state feedback with terminal result feedback, the problem of start-up failure caused by abnormal state feedback in traditional logic can be solved, and the risk of power-off due to misoperation during driving can be effectively prevented.
[0032] Figure 1 This is a schematic flowchart of a vehicle power-on control method provided in an embodiment of this application.
[0033] For example, such as Figure 1 As shown, the method includes: In step S101, in response to the start command, the current low voltage electrical state of the vehicle is obtained.
[0034] Specifically, this application mainly adopts a hybrid architecture, using a hybrid engine to drive the electric motor to rotate through a closed clutch, which in turn drives the transmission to rotate, in order to achieve efficient power transmission and mode switching.
[0035] Specifically, such as Figure 2 As shown, firstly, the user initiates a vehicle control request through a mobile terminal APP (Application), such as clicking a remote start command or a local one-click start command. This command is first transmitted to the vehicle via a wireless network through the T-BOX (Telematics BOX). After receiving the remote start command or local one-click start command, the T-BOX forwards it to the CEM through the vehicle bus (such as CAN (Controller Area Network)). The CEM, as the core gateway of the vehicle network, is responsible for parsing the remote start command or local one-click start command, verifying permissions (such as user identity authentication and vehicle status verification), and routing the command. The legitimate remote start command or local one-click start command is then transmitted to the powertrain control unit through an internal communication link (such as a high-speed CAN bus).
[0036] Secondly, after receiving a remote start command or a local one-button start command, the powertrain control unit executes a vehicle status self-check process. At this time, it needs to obtain the vehicle's current low-voltage electrical status, which is whether the vehicle is in the "15ON" state. When the vehicle is in the 15ON state, it means that the vehicle is in a low-voltage electrical available state. The 15ON state refers to the vehicle's low-voltage electrical system (usually powered by a 12V battery) which supplies voltage to the various ECUs (Electronic Control Units) of the vehicle. If 15ON fails, the vehicle will power down and go into sleep mode. If the system detects that the vehicle is in the 15ON state, the vehicle is in a low-voltage electrical available state, and the powertrain control unit can proceed to the next step of the start logic, such as waking up the high-voltage system, pre-charging, starting the engine or drive motor, etc. If the system detects that the vehicle is not in the 15ON state, the system will refuse to execute the start command and can send an error message "Low-voltage power supply abnormal, unable to start" to the user's APP through the CEM. At the same time, it can trigger a low battery alarm or suggest that the user check the battery status.
[0037] Therefore, the above process ensures that the vehicle has sufficient low-voltage power supply before starting, avoiding starting failure or system damage due to insufficient power. In addition, the mechanism also supports remote diagnostic functions. For example, when the user fails to start the vehicle multiple times, the system can automatically record the "15ON" status abnormality log and upload it to the cloud platform, which is convenient for after-sales personnel to remotely analyze the cause of the fault.
[0038] It should be noted that in this application embodiment, "15ON" represents the availability of low-voltage electricity in the vehicle, and serves as one of the conditions for determining whether to execute the CEM start request.
[0039] In step S102, if the current low voltage electrical state is available, the vehicle is controlled to perform a high voltage operation, and it is identified whether the vehicle is in a preset ready-to-drive state.
[0040] The preset ready-to-drive state is when the vehicle is in a state where the power system high voltage has been established, the key is within the effective range of the vehicle, and the vehicle can be driven by pressing the brake.
[0041] Specifically, after confirming that the vehicle's low-voltage electrical system is available and has a stable power supply, the powertrain control unit will trigger the high-voltage system power-on process. This includes closing the pre-charge relay, monitoring the bus voltage rise curve, and closing the main positive / main negative relay after pre-charging, thereby establishing the high-voltage circuit. After the high-voltage power-on is completed, the system will further identify whether the vehicle has entered the preset ready-to-drive state. That is, after receiving the remote start command or local one-button start command sent by the CEM, the powertrain control unit will check whether it will apply high voltage to the state of "high voltage power is available, the key is inside the vehicle, and the brake is applied to drive". If the powertrain control unit applies high voltage to the state of "high voltage power is available, the key is inside the vehicle, and the brake is applied to drive", the power mode is CRANK (vehicle is starting). At this time, drive enable is activated, allowing the motor to output torque. If any of the above conditions are not met, the system will maintain the high-voltage standby state and simultaneously provide specific fault codes or prompts to the user's APP or instrument panel through the CEM to ensure that the vehicle enters the driveable mode under safe conditions.
[0042] In step S103, when the vehicle is in a preset ready-to-drive state, a driving command is sent to the vehicle's target gateway so that when the vehicle meets the preset driving conditions, a driving permission command is issued through the target gateway.
[0043] The preset driving conditions are those that meet the safety requirements for vehicle operation, such as the vehicle being in neutral or park, the brake pedal being released, and there being no malfunctions that prohibit driving.
[0044] Specifically, in response to the vehicle's powertrain control unit determining that the vehicle has entered a preset ready-to-drive state—that is, a state where the vehicle is powered by high voltage, has the key inside, and can be driven by pressing the brake—the powertrain control unit no longer relies on the independent state feedback signals of multiple subsystems in a traditional distributed architecture (such as the dispersed feedback signals of motor speed, battery voltage, etc.). Instead, the powertrain control unit generates a dedicated driving command based on this preset ready-to-drive state. In other words, regardless of how many different states the powertrain control unit has for "powered by high voltage, has the key inside, and has the brake pressed," it will not rely on these signals. The "ready to drive" status is uniformly transmitted using a generated drivable command. This drivable command serves as the sole comprehensive representation of the vehicle's high-voltage readiness and drivable state and is sent to the target gateway CEM. Upon receiving this dedicated drivable command, the CEM parses and confirms that it represents the successful establishment of high-voltage power supply for the vehicle and the fulfillment of all preset driving conditions. This clearly informs the user and the vehicle network that the vehicle is currently in a "drivable state with high-voltage power." Then, when the vehicle meets the preset driving conditions, the CEM issues a driving permission command, authorizing the vehicle's drive system to respond to the driver's driving operations.
[0045] To further explain, in the traditional architecture, the logic by which the CEM determines whether a vehicle is drivable is often hard-coded and singular. Once a special state that also meets the conditions of "high voltage power, key inside the vehicle, and braking action to drive" (such as "limp mode") is added, it will cause a large number of configuration changes. In other words, since the old logic is incompatible with the new state, those skilled in the art need to modify the underlying judgment code of the gateway and instrument to explicitly add "limp mode" to the judgment conditions. This is a modification, verification, and release process that affects the whole system.
[0046] This application decouples the drivability result from the specific internal mode through a dedicated signal. Regardless of whether the power system is in normal mode or limp mode, as long as the driving conditions are met, the same "dedicated signal" is sent. At this time, CEM only needs to identify the dedicated signal and does not need to care about the specific mode behind it. Therefore, when adding a "limp mode", there is no need to modify the gateway logic, thus avoiding the cumbersome configuration process.
[0047] Therefore, the above process achieves centralized and standardized status feedback through dedicated signals, effectively avoiding feedback delays or false alarms caused by asynchronous or misjudged status signals from multiple subsystems, and improving the reliability and consistency of system response.
[0048] Optionally, in one embodiment of this application, after the vehicle is in a preset ready-to-drive state, the method further includes: illuminating the vehicle's drivable status indicator light based on a drivable command.
[0049] Specifically, since the driving status indicator light, i.e. the READY light, is already a standard configuration in the instrument panel or indicator light system in the current vehicle electrical architecture, and its lighting signal path has been pre-wired, there is no need to design a dedicated signal feedback channel for the purpose of status feedback, and it can be used directly. Therefore, this application takes the dedicated signal of the READY light as an example for explanation. The dedicated signal of the READY light is used as a driving command. When the power system control device determines that the vehicle is in a state of "high voltage electricity, key inside the vehicle, and braking action to drive", based on the driving command, the dedicated signal of the READY light is immediately lit and sent to the CEM.
[0050] Therefore, by illuminating the drivable status indicator, a clear and intuitive visual feedback that "the vehicle is ready" is provided to the user. This illumination signal is used as the sole status feedback signal to the CEM, thereby improving the human-machine interaction experience while achieving efficient reuse of power system status information and decoupling of system interaction.
[0051] Optionally, in one embodiment of this application, before sending the drivable command to the target gateway of the vehicle, the method further includes: determining whether the high-voltage connection operation was successfully performed within a first preset time period; if the high-voltage connection operation was not successfully performed within the first preset time period, then the high-voltage connection operation is continued.
[0052] The first preset duration is the timing monitoring duration of the target gateway for the startup state. It can be set according to the actual power-on performance of the vehicle, or it can be obtained through a limited number of computer simulations. No specific limitation is made here.
[0053] Specifically, before sending the drivable command to the CEM, the powertrain control unit must also perform a critical fault-tolerant judgment process to deal with timing fluctuations or special operating conditions that may occur during the high-voltage power-on process.
[0054] In the high-voltage operation process of this application embodiment, two starting methods are mainly involved: one is starting the engine with a power battery, and the other is starting the engine with a 12V starter system. Since the power battery has better start-up smoothness, this application prioritizes starting with the power battery. When the power battery is depleted, the engine is started with a 12V starter system. However, both of the above starting methods have a certain delay, which will be explained in detail below.
[0055] Specifically, the powertrain control unit first determines whether the high-voltage power-on operation has been successfully completed within a first preset time period (e.g., the 3-second time requirement set by CEM for the CRANK state). If no feedback of successful high-voltage power-on is received within the first preset time period, the traditional architecture would usually determine that the start-up has failed and trigger a fault alarm. However, this application adopts a goal-oriented fault-tolerant strategy, that is, the system will not immediately interrupt the power-on process or report a fault, but will continue to maintain the high-voltage power-on operation. The powertrain control unit is allowed to extend the power-on time according to the actual physical process (e.g., low battery activity in low temperature environment, high resistance to engine cold start, etc.). In other words, if CEM does not receive the signal to turn on the READY light for more than 3 seconds, this is normal and has no substantial impact on the whole vehicle. Just continue to wait. If the high-voltage power-on operation is successfully completed within the first preset time period, a dedicated signal to turn on the READY light is directly generated and sent to CEM.
[0056] Therefore, by setting a first preset duration (e.g., 3s) as an intermediate monitoring node, the system does not immediately report an error when the high voltage is not successfully applied after the timeout, but continues to execute the operation. This effectively solves the problem of the mismatch between the fixed time limit of the CEM for the CRANK state and the actual physical start-up time of the power system (e.g., cold start requires a longer time). This avoids false alarms that could cause start-up interruption, ensures the integrity of the vehicle's high voltage power-up process and the start-up success rate, and does not affect the timing logic of the CEM, thus achieving decoupling between the power system and the gateway control logic.
[0057] Optionally, in one embodiment of this application, after the high-voltage connection operation is not successfully performed within the first preset time period, the method further includes: determining whether the high-voltage connection operation is successfully performed within the second preset time period, wherein the second preset time period is longer than the first preset time period; if the high-voltage connection operation is successfully performed within the second preset time period, then a drivable command is sent to the vehicle's target gateway.
[0058] Optionally, in one embodiment of this application, after determining whether the high-voltage operation was successfully performed within the second preset time period, the method further includes: if the high-voltage operation was not successfully performed within the second preset time period, stopping the current high-voltage operation and generating a high-voltage failure reminder.
[0059] The second preset duration is the upper limit of the start-up duration autonomously controlled by the power system control device. It can be set according to the start-up attributes of the starter, and is not specifically limited here. In this application, it is preferably 15 seconds.
[0060] Specifically, based on the above discussion, in the case where the high-voltage operation is not successfully executed within the first preset time period in this application embodiment, that is, the execution time of the high-voltage operation exceeds the first preset time period, the power system control device does not report the execution failure status to the CEM, but continues to execute the high-voltage operation and determines whether the high-voltage operation is successfully executed within the second preset time period (e.g., 15s). If the high-voltage operation is successfully executed within the second preset time period, that is, within 15s, for example, within 14s, the power system control device sends a drivable command to the CEM, that is, it illuminates and sends a dedicated signal of the READY indicator light to indicate that the vehicle has entered the drivable state. Furthermore, if the high-voltage operation is not successfully executed within the second preset time period, it indicates that the attempt to execute the high-voltage operation has reached the upper limit of the safe working time. In order to avoid damage to the starter motor due to overheating caused by prolonged operation, the power system control device needs to stop the current high-voltage operation, generate a high-voltage failure reminder, and then wait for the user to re-initiate the vehicle control request so as to respond to the start command again when the user re-initiates the vehicle control request.
[0061] It should be noted that the second preset duration is set based on the starting attributes of the starter in this application embodiment. Since the starter may overheat if the starter exceeds 15 seconds, the second preset duration in this application embodiment is preferably 15 seconds.
[0062] Therefore, this embodiment sets a second preset time that is longer than the first preset time. After the first time expires, it does not determine failure and continues to execute until the second preset time. If the execution is successful within the second preset time, a driving command is sent. If the execution expires within the second preset time, the current operation is stopped and the restart command is allowed to be responded to again. This decouples the CEM timing parameters from the power system execution process to prevent errors, avoids false start failures caused by CEM timing limitations, and ensures hardware safety and the continuity of start opportunities.
[0063] Furthermore, during startup using a power battery, each startup consumes a significant amount of battery power and generates heat. If startups occur repeatedly, the continuous high-current discharge causes a rapid increase in battery temperature, leading to rapid softening and shedding of the active material on the plates, resulting in irreversible capacity decay. Therefore, to avoid these problems, this application embodiment also requires setting global limitations on the high-voltage power-on process: on the one hand, limiting the number of consecutive startups and the duration of each startup. For example, based on the power battery hardware protection principle, to comprehensively consider the upper limit of power battery safety protection... The number of consecutive starts of the power battery is set to 3 times, with each start lasting 900 milliseconds. The start duration is determined based on the pre-charging resistance of the pre-charging circuit inside the power battery. The magnitude of the pre-charging resistance determines the pre-charging time for each start, which is usually set to within 1 second per start to prevent over-discharge or thermal runaway of the battery. On the other hand, the number of starts and the duration of engine starts via the 12V starter system are set to independent limits. The engine can be started once or multiple times via the 12V starter system, but based on the starting properties of the starter, to avoid overheating of the starter, the duration of a single start does not exceed 15 seconds.
[0064] For example, in a low-temperature scenario during a cold start, the engine is started using a 12V system. At this time, the engine oil viscosity is high in the low-temperature scenario, requiring a longer start time. Therefore, the maximum start time can be set to 15 seconds. If the engine needs 14 seconds to successfully ignite and establish high voltage under the drive of the 12V low-voltage system, even though it exceeds the 3-second timeout threshold of CEM, the power system will still continue to execute the power-on process until the engine successfully starts in the 14th second. Then, a special signal to illuminate the READY light is generated and sent to CEM.
[0065] Furthermore, if the number of consecutive starts exceeds 3, in order to prevent the power battery from being cumulatively damaged due to frequent start attempts, a fault warning is generated and the response to the start command is terminated, thus forming a double protection with the time limit (15 seconds) to fully cover the start risk.
[0066] The core significance of the above mechanism lies in the fact that by decoupling the determination of "successful high-voltage power-on" from the fixed timing constraints of CEM and entrusting it to the power system control device to make autonomous decisions based on the actual physical state, the adjustment of CEM parameters will not affect the long-term power-on requirements of the power system during cold starts. Thus, under the premise of ensuring system safety, the vehicle's adaptability to complex operating conditions and the start-up success rate are significantly improved.
[0067] Therefore, by determining the number of consecutive starts before each start and terminating the response and reporting a fault when the number of starts is exceeded, hardware damage such as over-discharge of the power battery and overheating of the starter motor caused by frequent invalid starts can be effectively prevented. This achieves the goal of blocking dangerous operations from the source and improving system safety and hardware durability.
[0068] Optionally, in one embodiment of this application, after issuing the driving permission instruction through the target gateway, the method further includes: determining whether a power-off instruction has been received; if a power-off instruction has been received, determining whether the current driving speed of the vehicle is greater than or equal to a preset speed; if the current driving speed of the vehicle is greater than or equal to the preset speed, controlling the vehicle to execute a delayed power-off strategy.
[0069] Optionally, in one embodiment of this application, controlling the vehicle to execute a delayed power-off strategy includes: starting a delayed power-off timer based on a preset delay interval, controlling the vehicle to switch from the current gear to neutral; and when the delayed power-off timer ends, if the vehicle's current driving speed is less than a preset speed, controlling the vehicle to switch from the current gear to the parking gear.
[0070] The preset speed and preset delay range can both be set based on the vehicle's safety performance, and no specific limitations are made here.
[0071] Specifically, during normal vehicle operation, if a user accidentally touches the one-button start button on the dashboard, this operation will trigger a power-off command. This power-off command is first sent to the CEM (Controlled Energy Management System), which interprets it as a "Power Mode = OFF" status signal and broadcasts it to the vehicle network. Upon receiving the power-off command, the powertrain control unit does not immediately execute the traditional high-voltage power-off procedure. Instead, it first determines whether the vehicle's current speed is greater than or equal to a preset speed (e.g., 2 km / h). If the current speed is detected to be ≥2 km / h, it indicates that the vehicle is still in motion. In this case, directly cutting off the high-voltage power supply will cause the drive motor to lose power output and may also cause critical safety systems such as electric power steering and electronic brake assist to fail, leading to serious driving risks.
[0072] Therefore, the powertrain control unit will automatically trigger a delayed power-off strategy, which mainly includes, on the one hand, controlling the transmission to switch from the current gear D to neutral N, cutting off the power transmission path, and avoiding abnormal acceleration or jerking of the vehicle due to misoperation. For example, delaying for 1 second before shifting into N gear, so that when the user presses the one-button start button again, the vehicle can be powered on again.
[0073] On the other hand, a preset delay timer is activated (e.g., a delay of 180 seconds, the specific duration of which can be adjusted according to calibration). During this period, the high-voltage system is maintained to ensure that the steering, braking and other auxiliary systems continue to work and ensure driving safety. Only when the delay ends and the vehicle speed has dropped below the preset speed (e.g., <2km / h) will the system further control the vehicle's current gear to switch from neutral to parking gear (e.g., P gear) and finally perform the high-voltage power-off operation. At this time, the vehicle enters the P gear for parking safety to prevent rolling back.
[0074] Therefore, by introducing a vehicle speed determination mechanism after receiving the power-off command, the power is only cut off when the vehicle speed is below a preset threshold. If the vehicle speed is high, a delayed power-off strategy is triggered, which effectively avoids accidental power failure of the high-voltage system due to accidental power-off command during driving. This prevents safety hazards such as sudden loss of vehicle power and failure of steering / braking assistance, and significantly improves driving safety.
[0075] Optionally, in one embodiment of this application, after controlling the vehicle to execute the delayed power-down strategy, the method further includes: determining whether a vehicle restart command has been received; if a vehicle restart command has been received, determining whether the vehicle's current gear is in neutral or in park; if the current gear is in neutral or in park, determining whether the vehicle has a high-voltage prohibition fault; if the vehicle does not have a high-voltage prohibition fault, controlling the vehicle to restart.
[0076] Specifically, after controlling the vehicle to execute the delayed power-down strategy, the powertrain control unit enters a dynamic recovery monitoring phase. At this time, the powertrain control unit continuously monitors whether there is a vehicle restart command. This command may come from the user pressing the one-button start button again, the system's automatic reset request after releasing the accidentally pressed button, or a recovery command initiated through the APP / remote terminal. Once a restart command is received, the system will not directly perform high-voltage operation, but will first perform a gear safety check, that is, determine whether the vehicle's current gear is in neutral or parking gear. The purpose is to ensure that the vehicle is in a non-driving gear and avoid accidental starting in drive gears such as D gear, which could cause the vehicle to lurch forward.
[0077] If the current gear meets the conditions of neutral or park, the system will further determine whether the vehicle has a fault that prohibits high voltage (such as high voltage insulation fault, severe battery depletion, motor controller fault, etc.). Only when it is confirmed that the vehicle does not have any fault that prohibits high voltage will the power system control device start the high voltage power-on process, close the main relay again, activate the drive system, and light up the READY light again, so that the vehicle returns to the preset ready-to-drive state.
[0078] Therefore, the above mechanism abandons the traditional limitation of "vehicle speed < 2km / h to start" and instead uses gear position and fault status as the core criteria for starting. This means that even if the vehicle speed is still higher than 2km / h due to inertia during the delayed power-off period (such as when the vehicle is coasting), as long as the gear is in N or P and there is no high voltage fault, the system can safely restart. This avoids starting failure or dangerous waiting caused by vehicle speed limitation and significantly improves the recovery efficiency and safety after accidental operation while driving.
[0079] Therefore, based on the above discussion, the embodiments of this application break away from the traditional method of sending and receiving commands. The terminal return check during the power-on process in power mode does not interfere with the normal power-on / starting state of the power system, achieving mutual non-interference and mutual agreement between the two parties. Furthermore, in abnormal power-off conditions during driving, the high voltage can be applied for starting through clever gear shifting, which can safely park the vehicle without affecting the "re-application of high voltage".
[0080] Therefore, this application can achieve the following beneficial effects: (1) By using dedicated signal interaction between CEM and power system control device, the decoupling of vehicle gateway and power system control logic is realized, so that the parameter adjustment of CEM will not interfere with the actual physical operation of power system, reducing the coupling between systems and improving the efficiency and stability of vehicle network communication; (2) In response to the problem of long high voltage power-on or engine start-up time under special working conditions such as low temperature, this application abandons the traditional fixed time one-size-fits-all judgment method and instead adopts a fault-tolerant strategy based on the final target state, which effectively avoids the situation where the system misjudges the start-up failure due to the long cold start time, and significantly improves the start-up success rate and user satisfaction of the vehicle in extreme environments. (3) The defensive control logic against accidental touch of the "one-button start" button during driving eliminates the safety hazards caused by direct high voltage cut-off by combining vehicle speed and gear position judgment, prevents instantaneous high voltage cut-off and power loss caused by misoperation, avoids the risk of vehicle loss of control, and greatly improves driving safety. (4) In the process of vehicle restart, this application innovatively eliminates the restrictive condition that the vehicle speed must be lower than the threshold (such as 2km / h), and instead uses the gear status (N gear / P gear) and fault status as the core criteria, which solves the deadlock in the traditional logic that the vehicle cannot be restarted because the vehicle speed has not dropped below the threshold, making the recovery after misoperation more flexible and efficient, and further enhancing the robustness of the system.
[0081] In summary, the vehicle power-on control method according to the embodiments of this application, in response to a start command, obtains the current low-voltage electrical state of the vehicle. If the current low-voltage electrical state is available, the method controls the vehicle to perform a high-voltage power-on operation and identifies whether the vehicle is in a preset ready-to-drive state. If the vehicle is in the preset ready-to-drive state, a drivable command is sent to the vehicle's target gateway so that when the vehicle meets preset driving conditions, a driving permission command is issued through the target gateway. This method uses a unified command signal as the only status signal fed back to the vehicle control module and does not transmit intermediate status information back as a terminal status feedback mechanism, thereby decoupling the power system from the vehicle control module. Combined with delay protection for abnormal power-down during driving and gear shifting strategies, a complete error-proof power-on system is constructed.
[0082] Figure 3 This is a schematic diagram of the structure of a vehicle power-on control device provided in an embodiment of this application.
[0083] For example, such as Figure 3 As shown, the device may include: an acquisition module 100, a control module 200, and an execution module 300.
[0084] The acquisition module 100 is used to acquire the current low-voltage electrical state of the vehicle in response to the start command. The control module 200 is used to control the vehicle to perform a high-voltage operation when the current low-voltage electrical state is available, and to identify whether the vehicle is in a preset ready-to-drive state. The execution module 300 is used to send a driving command to the vehicle's target gateway when the vehicle is in a preset driving ready state, so that when the vehicle meets the preset driving conditions, the target gateway will issue a driving permission command.
[0085] Optionally, in one embodiment of this application, after the driving permission instruction is issued through the target gateway, the execution module 300 further includes: The first judgment unit is used to determine whether a power-off command has been received; The second judgment unit is used to determine whether the current driving speed of the vehicle is greater than or equal to the preset speed if a power-off command is received. The first control unit is used to control the vehicle to execute a delayed power-down strategy if the vehicle's current driving speed is greater than or equal to a preset speed.
[0086] Optionally, in one embodiment of this application, the first control unit includes: The first control subunit is used to start a delayed power-down timer based on a preset delay interval and control the vehicle to switch from the current gear to neutral. The second control subunit is used to control the vehicle to switch from the current gear to the parking gear if the vehicle's current driving speed is less than the preset speed when the power-down delay timer ends.
[0087] Optionally, in one embodiment of this application, after controlling the vehicle to execute the delayed power-down strategy, the first control unit further includes: The first judgment subunit is used to determine whether a vehicle restart command has been received; The second judgment subunit is used to determine whether the vehicle's current gear is in neutral or in parking gear if a vehicle restart command is received. The third judgment subunit is used to determine whether the vehicle has a high voltage prohibition fault if the current gear is in neutral or in parking gear. The second control unit is used to restart the vehicle if there is no fault prohibiting high voltage access.
[0088] Optionally, in one embodiment of this application, before sending the drivable command to the vehicle's target gateway, the execution module 300 further includes: The third judgment unit is used to determine whether the high-voltage operation was successfully performed within the first preset time period; The execution unit is used to continue performing the high-voltage operation if the high-voltage operation is not successfully performed within the first preset time period.
[0089] Optionally, in one embodiment of this application, after the high-voltage operation is not successfully performed within a first preset time period, the execution unit further includes: The fourth judgment subunit is used to determine whether the high voltage operation was successfully performed within the second preset time period, wherein the second preset time period is longer than the first preset time period; The generation subunit is used to send a driving command to the vehicle's target gateway if the high-voltage operation is successfully performed within a second preset time period.
[0090] Optionally, in one embodiment of this application, after determining whether the high-voltage operation was successfully performed within the second preset time period, the fourth determination subunit further includes: The generator is used to stop the current high-voltage operation and generate a high-voltage failure reminder if the high-voltage operation is not successfully executed within a second preset time period.
[0091] Optionally, in one embodiment of this application, after the vehicle is in a preset ready-to-drive state, the execution module 300 further includes: The third control unit is used to illuminate the vehicle's drivability indicator light based on a drivability command.
[0092] In summary, the vehicle power-on control device according to the embodiments of this application, in response to a start command, obtains the current low-voltage electrical state of the vehicle. If the current low-voltage electrical state is available, it controls the vehicle to perform a high-voltage power-on operation and identifies whether the vehicle is in a preset ready-to-drive state. If the vehicle is in the preset ready-to-drive state, it sends a drivable command to the vehicle's target gateway, so that when the vehicle meets preset driving conditions, a driving permission command is issued through the target gateway. This method uses a unified command signal as the only status signal fed back to the vehicle control module and does not transmit intermediate status information back as a terminal status feedback mechanism, thereby decoupling the power system from the vehicle control module. Combined with delay protection for abnormal power-down during driving and gear shifting strategies, it constructs a complete error-proof power-on system.
[0093] Figure 4 This is a schematic diagram of the structure of a vehicle provided in an embodiment of this application.
[0094] It should be understood that the methods described above can be applied to... Figure 4 In the vehicle with the structure shown.
[0095] Furthermore, embodiments of this application also protect an apparatus that may include a memory and a processor, wherein the memory stores executable program code, and the processor is used to call and execute the executable program code to perform the vehicle power-on control method provided in embodiments of this application.
[0096] Furthermore, the device also includes a communication interface 403 for communication between the memory 401 and the processor 402.
[0097] This embodiment can divide the device into functional modules based on the above method example. For example, each module can correspond to a separate function, or two or more functions can be integrated into one processing module. The integrated module can be implemented in hardware. It should be noted that the module division in this embodiment is illustrative and only represents one logical functional division. In actual implementation, there may be other division methods.
[0098] It should be noted that all relevant content of each step involved in the above method embodiments can be referenced from the functional description of the corresponding functional module, and will not be repeated here.
[0099] It should be understood that the device provided in this embodiment is used to execute the above-described vehicle power-on control method, and therefore can achieve the same effect as the above-described implementation method.
[0100] When using an integrated unit, the device may include a processing module and a storage module. When the device is applied to a vehicle, the processing module can be used to control and manage the vehicle's movements. The storage module can be used to support the vehicle in executing program code, etc.
[0101] The processing module may be a processor 402 or a controller, which may implement or execute various exemplary logic blocks, modules, and circuits as disclosed herein. The processor 402 may also be a combination of computing functions, such as a combination of one or more microprocessors, a combination of digital signal processing (DSP) and microprocessors, etc., and the storage module may be a memory 401.
[0102] In addition, the device provided in the embodiments of this application may specifically be a chip, component or module. The chip may include a connected processor 402 and a memory 401. The memory 401 is used to store instructions. When the processor calls and executes the instructions, the chip can execute the vehicle power-on control method provided in the above embodiments.
[0103] This embodiment also provides a computer-readable storage medium storing computer program code. When the computer program code is run on a computer, the computer executes the above-described related method steps to implement the vehicle power-on control method provided in the above embodiment.
[0104] This embodiment also provides a computer program product that, when run on a computer, causes the computer to perform the aforementioned related steps to implement a vehicle power-on control method provided in the above embodiment.
[0105] In this embodiment, the device, computer-readable storage medium, computer program product, or chip are all used to execute the corresponding methods provided above. Therefore, the beneficial effects they can achieve can be referred to the beneficial effects in the corresponding methods provided above, and will not be repeated here.
[0106] Through the above description of the embodiments, those skilled in the art will understand that, for the sake of convenience and brevity, only the division of the above functional modules is used as an example. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above.
[0107] In the embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of modules or units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another device, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between devices or units may be electrical, mechanical, or other forms.
[0108] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A method for controlling the power-on of a vehicle, characterized in that, The method includes: In response to the start command, obtain the vehicle's current low-voltage electrical state; When the current low-voltage electrical state is available, control the vehicle to perform a high-voltage connection operation and identify whether the vehicle is in a preset ready-to-drive state. When the vehicle is in the preset ready-to-drive state, a driving command is sent to the vehicle's target gateway so that when the vehicle meets the preset driving conditions, a driving permission command is issued through the target gateway.
2. The method according to claim 1, characterized in that, After issuing the driving permit instruction through the target gateway, the process also includes: Determine if a power-off command has been received; If the power-off command is received, determine whether the current driving speed of the vehicle is greater than or equal to the preset speed; If the current driving speed of the vehicle is greater than or equal to the preset speed, the vehicle is controlled to execute a delayed power-off strategy.
3. The method according to claim 2, characterized in that, The control of the vehicle to execute a delayed power-down strategy includes: Based on a preset delay interval, the delayed power-down timer is started to control the vehicle to switch from the current gear to neutral. When the delayed power-off timer ends, if the vehicle's current speed is less than the preset speed, the vehicle is controlled to switch from the current gear to the parking gear.
4. The method according to claim 3, characterized in that, After controlling the vehicle to execute the delayed power-down strategy, the method further includes: Determine whether a restart command for the vehicle has been received; If a restart command for the vehicle is received, it is determined whether the vehicle's current gear is in neutral or in park. If the current gear is in neutral or in park, then determine whether the vehicle has a fault that prohibits high voltage access; If the vehicle does not have the high-voltage prohibition fault, then control the vehicle to restart.
5. The method according to claim 1, characterized in that, Before sending drivable commands to the vehicle's target gateway, the process also includes: Determine whether the high-voltage operation was successfully executed within the first preset time period; If the high-voltage operation is not successfully executed within the first preset time period, the high-voltage operation will continue to be executed.
6. The method according to claim 5, characterized in that, After failing to successfully perform the high-voltage operation within the first preset time period, the process also includes: Determine whether the high-voltage operation was successfully performed within a second preset time period, wherein the second preset time period is longer than the first preset time period; If the high-voltage operation is successfully executed within the second preset time period, a driving command is sent to the vehicle's target gateway.
7. The method according to claim 6, characterized in that, After determining whether the high-voltage operation was successfully performed within the second preset time period, the process further includes: If the high-voltage operation is not successfully executed within the second preset time period, the current high-voltage operation will be stopped and a high-voltage failure reminder will be generated.
8. The method according to claim 1, characterized in that, After the vehicle is in the preset ready-to-drive state, the method further includes: Based on the driving command, the driving status indicator light of the vehicle is illuminated.
9. A vehicle, characterized in that, The vehicle includes: a power-on control method for a vehicle as described in any one of claims 1-8.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed, implements the method as described in any one of claims 1 to 8.