Control method, control device, apparatus, and storage medium of vehicle
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- CHERY AUTOMOBILE CO LTD
- Filing Date
- 2026-06-16
- Publication Date
- 2026-08-04
AI Technical Summary
[0004]然而,上述方法中,由于校验流程的完整执行过程对主控制器不可见,在校验中断时,主控制器仅能获取中断校验流程的子控制器对应的局部校验信息,对导致校验流程中断的故障的定位与溯源能力较差,系统可靠性与可维护性低
[0022]本申请提供的技术方案的有益效果至少包括:
Smart Images

Figure CN122501263A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of vehicle control technology, and in particular to a vehicle control method, control device, equipment and storage medium. Background Technology
[0002] Before a vehicle performs a power supply circuit connection operation, its operating status needs to be verified to ensure the safety and reliability of vehicle operation.
[0003] In related technologies, the verification process for power supply circuit connection operation usually adopts distributed control, with multiple sub-controllers executing sequentially according to preset control logic. Each sub-controller is responsible for its own local verification task and notifies the next sub-controller to continue or interrupt the verification process based on its own verification result. The main controller only obtains the final verification result when the verification process is interrupted or ends.
[0004] However, in the above method, since the complete execution process of the verification process is not visible to the main controller, when the verification is interrupted, the main controller can only obtain the local verification information corresponding to the sub-controller that interrupted the verification process. The ability to locate and trace the fault that caused the verification process to be interrupted is poor, and the system reliability and maintainability are low. Summary of the Invention
[0005] This application provides a vehicle control method, control device, equipment, and storage medium to solve the technical problems existing in related technologies. It includes the following technical solutions: In a first aspect, this application provides a vehicle control method, the method comprising: acquiring a verification process of the vehicle according to a first operation instruction, the first operation instruction being used to indicate an intention for the vehicle to perform a power supply circuit connection operation, the verification process being used to determine whether a first operating state of the vehicle supports a power supply circuit connection operation through multiple verification actions; executing the multiple verification actions according to the execution order indicated by the verification process; after any verification action is executed, updating a global state index of the vehicle according to the execution result of the any verification action, and determining the verification result of the verification process according to the global state index, the global state index indicating a second operating state of multiple subsystems in the vehicle related to the verification process.
[0006] In some possible implementations, the verification process is further used to indicate constraints on the execution process of any verification action, and the verification process is further used to indicate the expected feedback of any verification action. The method further includes: if the execution process of any verification action does not meet the constraints, and / or the feedback information of any verification action does not match the expected feedback, determining that the execution of any verification action has failed.
[0007] In some possible implementations, the global status indicator includes a first global status indicator and a second global status indicator. The execution result of any verification action includes a first execution result indicating that the verification action failed, and the execution result also includes a second execution result indicating that the verification action succeeded. Updating the global status indicator based on the execution result of any verification action includes: if the execution result of any verification action is the second execution result, updating the second global status indicator based on the second execution result, wherein the second global status indicator is used to record the second running state; if the execution result of any verification action is the first execution result, updating the first global status indicator based on the first execution result, wherein the first global status indicator is used to generate an error log corresponding to the first execution result.
[0008] In some possible implementations, the method further includes: if the execution result of any of the verification actions is the first execution result, generating a first prompt message, the first prompt message being used to indicate that the first operating state does not support the power supply circuit access operation and prohibits the execution of the power supply circuit access operation; if the execution results of the plurality of verification actions are all the second execution result, generating a second prompt message, the second prompt message being used to indicate that the first operating state supports the power supply circuit access operation and trigger the power supply circuit access operation.
[0009] In some possible implementations, the verification result includes a first verification result indicating that the verification process has failed. The method further includes: if the execution result of any verification action is the first execution result, then generating the first verification result and stopping the execution of the unexecuted verification actions among the plurality of verification actions.
[0010] In some possible implementations, obtaining the vehicle verification process according to the first operation instruction includes: if a second request is also received upon receiving the first operation instruction, determining the verification process according to the second request; if the second request is not received, determining the verification process according to default settings; wherein the second request is used to indicate the configuration intent for the verification process.
[0011] In some possible implementations, the method further includes: upon receiving the first operation instruction, performing a validity check on the first operation instruction, the validity check being used to determine whether the first operation instruction is allowed to obtain the verification process; and obtaining the verification process based on the first operation instruction after the validity check.
[0012] Secondly, this application provides a vehicle control device, the device comprising a determining module, an executing module, and an updating module; the determining module is configured to acquire a verification process of the vehicle according to a first operation instruction, the first operation instruction being used to indicate an intention for the vehicle to perform a power supply circuit connection operation, the verification process being used to determine whether a first operating state of the vehicle supports a power supply circuit connection operation through multiple verification actions; the executing module is configured to execute the multiple verification actions according to the execution order indicated by the verification process; the updating module is configured to update a global state index of the vehicle according to the execution result of any verification action after the execution of any verification action, the global state index indicating a second operating state of multiple subsystems in the vehicle related to the verification process; the determining module is further configured to determine the verification result of the verification process according to the global state index.
[0013] In some possible implementations, the verification process is further configured to indicate constraints on the execution of any verification action, and the verification process is further configured to indicate the expected feedback of any verification action. The determining module is further configured to determine that any verification action has failed if the execution of any verification action does not meet the constraints, and / or the feedback information of any verification action does not match the expected feedback.
[0014] In some possible implementations, the global status indicator includes a first global status indicator and a second global status indicator. The execution result includes a first execution result indicating that any verification action failed, and the execution result also includes a second execution result indicating that any verification action succeeded. The update module is further configured to: if the execution result of any verification action is the second execution result, update the second global status indicator according to the second execution result, the second global status indicator being used to record the second running status; if the execution result of any verification action is the first execution result, update the first global status indicator according to the first execution result, the first global status indicator being used to generate an error log corresponding to the first execution result.
[0015] In some possible implementations, the execution module is further configured to: if the execution result of any of the verification actions is the first execution result, generate a first prompt message, the first prompt message being used to indicate that the first operating state does not support the power supply circuit access operation and prohibit the execution of the power supply circuit access operation; if the execution results of the plurality of verification actions are all the second execution result, generate a second prompt message, the second prompt message being used to indicate that the first operating state supports the power supply circuit access operation and trigger the power supply circuit access operation.
[0016] In some possible implementations, the verification result includes a first verification result indicating that the verification process has failed, and the execution module is further configured to: if the execution result of any verification action is the first execution result, generate the first verification result and stop executing the verification actions that have not been executed among the plurality of verification actions.
[0017] In some possible implementations, the determining module is configured to: upon receiving the first operation instruction, if a second request is also received, determine the verification process based on the second request; if the second request is not received, determine the verification process based on default settings; wherein the second request is used to indicate the configuration intent for the verification process.
[0018] In some possible implementations, the determining module is further configured to: upon receiving the first operation instruction, perform a validity check on the first operation instruction, the validity check being used to determine whether the first operation instruction is allowed to obtain the verification process; and obtain the verification process based on the first operation instruction after the validity check.
[0019] In a third aspect, this application provides an electronic device for controlling a vehicle, comprising: a memory storing at least one program instruction for controlling the vehicle; and a processor, wherein when the program instruction is executed by the processor, the electronic device causes the electronic device to implement the method of the first aspect of this application or any possible embodiment of the first aspect.
[0020] In a fourth aspect, this application provides a computer program (product) comprising computer program / instructions that are executed by a processor to enable a computer to implement the method of the first aspect of this application or any possible implementation thereof.
[0021] In a fifth aspect, this application provides a computer-readable storage medium having stored thereon program instructions for controlling a vehicle, which, when executed by one or more processors, cause a computer to implement the method of the first aspect or any possible implementation of the first aspect.
[0022] The beneficial effects of the technical solution provided in this application include at least the following: The technical solution provided in this application, upon receiving a first operation instruction, can determine whether the user intends to enable the vehicle to perform a power supply circuit connection operation based on the first operation instruction. This allows for the acquisition of the vehicle's verification process to determine whether the vehicle's first operating state supports the power supply circuit connection operation, thus ensuring the safety of the power supply circuit connection and improving the execution efficiency of the verification process. Furthermore, during the verification process, this application embodiment can update the global status indicators based on the execution result of any verification action and determine the verification result of the verification process based on the global status indicators. This makes the verification process globally visible, fault location clear, and significantly improves system reliability and maintainability. Attached Figure Description
[0023] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0024] Figure 1 This is a schematic diagram of an implementation scenario provided in the embodiments of this application; Figure 2 This is a flowchart of a vehicle control method provided in an embodiment of this application; Figure 3 This is a schematic diagram of the architecture of the vehicle control method provided in the embodiments of this application; Figure 4 This is a schematic diagram of the structure of the vehicle control device provided in the embodiments of this application; Figure 5 This is a schematic diagram of the structure of an electronic device for controlling a vehicle provided in an embodiment of this application. Detailed Implementation
[0025] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0026] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.
[0027] The power supply circuit of a vehicle refers to the circuit in the vehicle used to provide a path for the transmission of electrical energy to the power system; it is also called a high-voltage circuit.
[0028] Before connecting to the power supply circuit, a specific verification process needs to be performed to ensure the safety and reliability of vehicle operation. In related technologies, the verification process typically employs distributed control: multiple sub-controllers execute sequentially according to a fixed execution order, and any logical change to any sub-controller will cause the entire verification process to fail, resulting in poor maintainability and scalability.
[0029] Furthermore, if a verification task from any sub-controller fails, the cause of the failure may be hidden within the internal logic of that sub-controller or within the interaction logic between multiple sub-controllers. When a verification task at any sub-controller fails and reports to the main controller, the main controller's ability to trace the cause of the failure is poor because the interaction logic between multiple sub-controllers is not visible to the main controller. In view of this, embodiments of this application provide a vehicle control method, which includes: determining a vehicle verification process based on a first request, wherein the first request causes the vehicle to perform a power supply circuit connection operation, and the verification process is used to determine whether a first operating state of the vehicle supports the power supply circuit connection operation through multiple verification actions; executing multiple verification actions according to the execution order indicated by the verification process; after any verification action is executed, updating the vehicle's global state index based on the execution result of any verification action, wherein the global state index indicates the second operating state of multiple subsystems related to the verification process in the vehicle; and determining the verification result of the verification process based on the global state index.
[0030] Figure 1 This is a schematic diagram of an implementation scenario provided in an embodiment of this application. (Reference) Figure 1 The implementation scenarios provided in this application include a power supply circuit 11 and a control unit 12.
[0031] The power supply circuit 11 includes, for example, one or more of the following sub-circuits: an energy storage access circuit, used for, but not limited to, being responsible for the output of electrical energy from the power battery in the vehicle and the pre-charging of the circuit; an energy conversion sub-circuit, used for, but not limited to, being responsible for the conversion between DC and AC, and between high voltage and low voltage in the power supply circuit 11; a power output sub-circuit, used for, but not limited to, converting the electrical energy output from the power battery into the kinetic energy of the vehicle; and a safety detection sub-circuit, used for, but not limited to, being responsible for detecting information related to the safety status of the power drive circuit 11, such as voltage and current in the power supply circuit 11.
[0032] The control unit 12 is connected to the power supply circuit 11, for example, via a wired or wireless means, to detect the vehicle's operating status before the vehicle performs a power drive circuit connection operation, in order to ensure the safety of the power drive circuit connection operation. The drive circuit connection operation, also known as a high-voltage power-on operation, is used to indicate the switching of the power drive circuit from a non-conducting state to a conducting state, so that the power battery can provide electrical energy to the power drive system.
[0033] Optionally, the control unit 12 may be, for example, a terminal controller, a server, a server cluster, or any other type of device capable of performing control functions, and this application makes no limitation in this regard.
[0034] Those skilled in the art should understand that the above-described power supply circuit 11 and control unit 12 are merely examples. Other existing or future power supply circuits and control units that are applicable to this application should also be included within the scope of protection of this application, and are hereby incorporated by reference.
[0035] Figure 2 This is a flowchart of a vehicle control method provided in an embodiment of this application. This method can, for example, be... Figure 1 The control unit in the system executes this. See also Figure 2 The vehicle control method provided in this application embodiment may include steps S210-S230 as shown below.
[0036] Step S210: Obtain the vehicle's verification process according to the first operation instruction. The first operation instruction is used to indicate the intention to make the vehicle perform a power supply circuit connection operation. The verification process is used to determine whether the vehicle's first operating state supports the power supply circuit connection operation through multiple verification actions.
[0037] For example, the first operation instruction may be any type of information that can be used to identify whether the user intends to turn on the vehicle's power drive circuit, that is, any type of information that can be used to identify whether the user intends to cause the vehicle to perform a power drive circuit connection operation. This application does not make any limitations in this regard.
[0038] For example, the first operation command might be a user's command to control the vehicle to enter an initial standby state via inserting the vehicle key or a remote app. When the vehicle enters this initial standby state, it indicates that the user may intend to drive and requires the vehicle's drive power circuit to be activated. In other words, after the vehicle enters the initial standby state according to the first operation command, it signifies that the user intends to activate the vehicle's power supply circuit. This initial standby state is also known as the vehicle power-on ready state, vehicle wake-up ready state, or mortgage initialization complete state, and it indicates the state when the vehicle's auxiliary power supply circuit is activated.
[0039] The first operating state of the vehicle can be any information that can be used to determine whether the vehicle is capable of performing the power supply circuit connection operation, such as including but not limited to the vehicle's operating condition, the circuit status of the power supply circuit, and the environmental conditions of the vehicle's environment. This application does not impose any restrictions in this regard.
[0040] Multiple verification actions are, for example, any action used to collect, detect, and / or determine the first operating state of the vehicle, or a process formed by the orderly arrangement of multiple actions. Multiple verification actions may be selected from some or all of the preset verification actions supported by the vehicle. These preset verification actions supported by the vehicle include, but are not limited to: lock verification actions, used to collect, detect, and determine the status of the high-voltage interlock circuit and electrical connection structure in the power supply circuit; insulation verification actions, used to collect, detect, and determine the electrical insulation and leakage protection status in the power supply circuit; relay status verification actions, used to collect, detect, and determine the status of the power supply circuit switching devices in the power supply circuit; and vehicle operating condition verification actions, used to collect, detect, and determine the vehicle's speed, gear position, brake pedal status, and parking status, etc.
[0041] Based on this, when the user causes the vehicle to enter the initial standby state through the first operation command, it indicates that the user may have the intention to drive and the power supply circuit of the vehicle needs to be connected. At this time, before the power supply circuit connection operation is performed, the first operating state of the vehicle is verified through the verification process to ensure the safety and reliability of the vehicle operation.
[0042] In some embodiments, obtaining the vehicle verification process according to the first operation instruction includes: if a second request is also received when the first operation instruction is received, determining the verification process according to the second request; if the second request is not received, determining the verification process according to the default settings.
[0043] The second request is used to indicate the user's configuration intent for the verification process, or to indicate the user's configuration intent for multiple verification actions corresponding to the verification process. For example, the second request is used to indicate the user's intent to select preset verification actions supported by the vehicle. In this case, some or all of the preset verification actions selected by the user from the preset verification actions supported by the vehicle constitute the multiple verification actions of the verification process.
[0044] Alternatively, if no second request is received, some or all of the verification actions supported by the vehicle can be selected from the default settings. The default settings may be, for example, multiple verification actions corresponding to the vehicle's last verification process, or all of the preset verification actions supported by the vehicle can be selected by default; this application makes no restrictions in this regard.
[0045] Considering that in real-world applications, after a user initiates the vehicle into initial standby mode via the first operation command, the user may not intend to activate the power drive circuit. For example, the user may not have fastened their seatbelt, released the handbrake, or engaged a valid gear after entering standby mode. Alternatively, the vehicle's initial operating state may not support the initiation of the verification process, such as due to unresolved system faults, abnormal power supply, or incomplete initialization of critical components. Therefore, it is necessary to verify the validity of the received first operation command to ensure the effective initiation of the verification process and improve control efficiency.
[0046] In some embodiments, upon receiving a first operation instruction, the first operation instruction undergoes a validity check; based on the validity-checked first operation instruction, it is determined whether to obtain a verification process. The validity check determines whether the first operation instruction is allowed to obtain the verification process. For example, if the first operation instruction passes the validity check, it means that obtaining the verification process based on the first operation instruction is allowed, i.e., triggering subsequent verification processes is permitted; if the first operation instruction fails the validity check, it means that obtaining the verification process based on the first operation instruction is not allowed, i.e., triggering subsequent verification processes is not permitted.
[0047] For example, upon receiving the first operation command, the system determines whether there is an intention to drive the vehicle based on its operating status. If no driving intention is detected, the first operation command fails the validity check, and the verification process is prohibited. If a driving intention is detected, the first operation command passes the validity check, and the verification process is allowed. The vehicle's operating status includes, but is not limited to, any information indicating the user's driving intention, such as seatbelt status, handbrake status, and gear position. When the vehicle's operating status indicates one or more of the following phenomena: seatbelt not fastened, handbrake not released, or vehicle not engaged in a valid gear, it suggests that the user may not have a driving intention.
[0048] Alternatively, the first operating state may include vehicle system faults, power supply status, critical component initialization status, etc. Upon receiving the first operation command, it is determined whether the vehicle's first operating state supports the start verification process. If the vehicle's first operating state does not support the start verification process, the first operation command fails the validity check, and the verification process is rejected. For example, if after receiving the first operation command, one or more of the following phenomena exist in the vehicle: an uncleared system fault, abnormal power supply status, or incomplete initialization of critical components, it indicates that the vehicle's first operating state does not support the start verification process, and the first operation command fails the validity check.
[0049] Step S220: Perform multiple verification actions according to the execution order indicated by the verification process.
[0050] For example, the execution order may be the order in which multiple verification actions are executed sequentially, or the order in which some or all of the multiple verification actions are executed in parallel. This application does not impose any restrictions in this regard. For example, if there is no execution time dependency between multiple verification actions, the multiple verification actions are executed in parallel to improve the verification efficiency of the verification process; or, if there is an execution time dependency between multiple verification actions, the verification actions with time dependencies are executed sequentially, and the verification actions without time dependencies are executed in parallel.
[0051] In some embodiments, the verification process is further used to indicate the constraints on the execution process of any verification action and the expected feedback of any verification action. The method further includes: if the execution process of any verification action does not meet the constraints, and / or the feedback information of any verification action does not match the expected feedback, determining that the execution of any verification action has failed.
[0052] For example, the constraint indicated by the verification process is a duration threshold for any verification action. If the execution time of any verification action exceeds the corresponding duration threshold, then the execution of any verification action is determined to have failed. The execution process of any verification action may include multiple stages, each corresponding to a different duration threshold, to allow for more granular monitoring of the execution process of any verification action using multiple duration thresholds.
[0053] Alternatively, if the feedback information of any verification action does not match the expected feedback, then that verification action is determined to have failed. This mismatch between feedback information and expected feedback includes, but is not limited to, no feedback information being returned, the content of the feedback information not matching the content of the expected feedback, or the value of the feedback information not matching the value of the expected feedback, etc. This application does not impose any limitations in this regard.
[0054] Alternatively, if the execution time of any verification action exceeds the corresponding time threshold, and the feedback information of any verification action does not match the expected feedback, then it is determined that the execution of any verification action has failed.
[0055] It should be noted that, in addition to the duration thresholds mentioned above, the constraints indicated in the verification process can be flexibly set in various ways based on the type of verification action, the actual operating scenario of the vehicle, and safety requirements, to ensure that the execution of the verification action complies with safety specifications and business logic. For example, for lock verification actions, the constraints may also include the execution timing, meaning that the verification action can only be initiated when the vehicle enters the initial standby state, the auxiliary power supply circuit is on, and no other high-priority operations are being performed; for insulation verification actions, the constraints may also include ambient temperature constraints and power supply voltage constraints, meaning that the verification action is executed when the ambient temperature of the vehicle is within a preset temperature range and the power supply voltage of the auxiliary power supply circuit is stable within a preset voltage range.
[0056] In some embodiments, the vehicle control method provided in this application further includes: if any verification action fails, performing a limited number of retries on the failed verification action, so as to effectively avoid accidental interruption of the verification process due to transient faults, reduce unnecessary troubleshooting operations, and improve the success rate of the verification process and the stability of the system. The number of retries and the retry interval can be adjusted according to the actual application scenario, and this application does not impose specific limitations here.
[0057] Step S230: After any verification action is executed, the vehicle's global status index is updated according to the execution result of any verification action, and the verification result of the verification process is determined according to the global status index. The global status index is used to indicate the second operating status of multiple subsystems related to the verification process in the vehicle.
[0058] For example, multiple subsystems related to the verification process are used to indicate the systems that need to collect, detect, and / or determine the second operating state after the verification process is started. For instance, when multiple verification actions in the verification process include lock verification actions, insulation verification actions, and relay status verification actions, it is desirable to detect the second operating state of the high-voltage interlock subsystem, insulation detection subsystem, and circuit on / off control subsystem. In this case, the multiple subsystems are the high-voltage interlock subsystem, insulation detection subsystem, and circuit on / off control subsystem.
[0059] Based on this, the global status indicators include, for example, multiple status variables corresponding one-to-one with multiple subsystems, and there is a one-to-one correspondence between multiple verification actions, multiple subsystems, and multiple status variables. Each verification action is used to collect, detect, and / or determine the second operating state of the corresponding subsystem, and after the execution of any verification action is completed, the corresponding status variable is updated according to the execution result of the verification action to form the real-time global status of the entire vehicle.
[0060] For example, in a verification process involving multiple verification actions, including lock verification, insulation verification, and relay status verification, and where these actions are executed serially, after any verification action is completed, the updated status variables in the global status index can indicate the second operating state of the subsystem corresponding to the executed verification action. At the same time, the unupdated status variables in the global status index indicate the current progress of the verification process, i.e., which verification actions have not yet been executed, or which subsystems' second operating states have not been updated.
[0061] As mentioned above, if the execution result of any verification action does not meet the constraints, and / or the feedback information of any verification action does not match the expected feedback, then the execution of any verification action is determined to have failed. Therefore, the execution result of any verification action includes a first execution result indicating that the verification action has failed, and the execution result of any verification action also includes a second execution result indicating that the verification action has been successfully executed.
[0062] Considering that in practical applications, the power supply circuit connection operation is a high-safety-level operation for the entire vehicle, the failure of any verification action indicates that the current operating state of the vehicle, such as the overall vehicle condition, power supply circuit status, and controller interaction state, no longer meets the safe connection conditions for the power supply circuit. Continuing to execute the remaining verification actions is meaningless and may lead to problems such as false power supply circuit continuity, abnormal device engagement, and electrical safety hazards. Therefore, the verification process needs to be interrupted after any verification action fails.
[0063] In some embodiments, the verification result of the verification process may include a first verification result indicating that the verification process has failed. The vehicle control method provided in this application embodiment further includes: if the execution result of any verification action is a first execution result, then generating a first verification result and stopping the execution of the verification actions that have not been executed among the multiple verification actions.
[0064] In other embodiments, the verification result of the verification process may include a second verification result indicating that the verification process has passed. The vehicle control method provided in this application embodiment further includes: if the execution results of multiple verification actions are all second execution results, then a second verification result is generated.
[0065] Furthermore, considering that in practical application scenarios, during the execution of the verification process, the system needs to determine in real time whether to continue to execute the next verification action. At the same time, after each verification action is completed, the system needs to determine the process direction, switch the running logic, and classify and store the corresponding status information based on different verification results. If all kinds of execution results are uniformly summarized into the same status system, it is easy to cause the status data to be messy and mixed. It is not possible to quickly determine whether the process can continue based on the valid status information, nor is it easy to sort out and retain abnormal situations separately. This is not conducive to the accurate control of the verification process and the review of problems later.
[0066] Therefore, in some embodiments, when the execution result of any verification action includes a first execution result and a second execution result, the global state index includes, for example, a first global state index and a second global state index. The vehicle control method provided in this application further includes: if the execution result is a second execution result, updating the second global state index according to the second execution result. In this case, the second global state index is used to record the second operating state. The second global state can form the real-time global state of multiple subsystems, providing complete and accurate global data support for the power supply circuit access operation.
[0067] If the execution result is the first execution result, the first global status indicator is updated based on the first execution result. In this case, the first global status indicator is used to generate the error log corresponding to the first execution result. For example, the first global status indicator can completely record the execution order, execution process, feedback information, and execution result of each verification action, so that if any verification action fails, the corresponding error log is generated through the first global status indicator, which facilitates fault tracing and location.
[0068] For example, the error log content corresponding to any failed verification action may include, but is not limited to: the identification information of any failed verification action; the reason for failure, such as unmet constraints, mismatched feedback information, or the specific value of the execution time exceeding the time threshold, the difference between the feedback information and the expected feedback, etc.; and troubleshooting suggestions, so as to make fault handling more targeted, shorten the time for fault troubleshooting and resolution, and improve the maintainability of the system.
[0069] As described above, if any verification action fails, resulting in the first verification result, it indicates that the vehicle's first operating state no longer meets the safe access conditions for the power supply circuit. If multiple verification actions succeed, resulting in the second verification result, it indicates that the vehicle's first operating state meets the safe access conditions for the power supply circuit.
[0070] Based on this, the vehicle control method provided in this application embodiment further includes: if the execution result of any verification action is a first execution result, generating a first prompt message, the first prompt message being used to indicate that the first operating state does not support the power supply circuit access operation and prohibits the execution of the power supply circuit access operation; if the execution results of multiple verification actions are all second execution results, generating a second prompt message, the second prompt message being used to indicate that the first operating state supports the power supply circuit access operation and trigger the power supply circuit access operation.
[0071] Figure 3This is a schematic diagram of the architecture of the vehicle control method provided in the embodiments of this application.
[0072] like Figure 3 As shown, the vehicle control method provided in this application embodiment is configured in the vehicle in the form of service encapsulation. For example, the verification process and the multiple verification actions corresponding to the verification process are encapsulated into different atomic services, i.e., independent verification actions, or encapsulated into combined services, i.e., functional modules formed by the orderly arrangement of multiple verification actions, so that after the verification process is triggered by a remote APP, automatic verification is completed by calling different encapsulated services.
[0073] For example, the remote APP, serving as the scenario entry point for the vehicle control method provided in this application embodiment, is responsible for receiving user operations, invoking the high-voltage power-on management service, and subscribing to power domain status information. When the power domain meets the conditions for high-voltage connection, the APP further invokes the high-voltage relay control service and, in conjunction with the bus voltage detection service, monitors the execution process, handles anomalies, and reports the final status, thereby completing the complete high-voltage connection process.
[0074] The high-voltage power-on management service is a combined encapsulated service. As the scheduling hub in the architecture, it is responsible for managing the various encapsulated services and coordinating the execution of the verification process. For example, during the execution of the verification process, it manages the power supply sequence of high-voltage components in the power supply circuit, realizes the pre-charge management and system status maintenance of the power supply circuit, and uniformly receives multi-source requests from the vehicle's charging and discharging system, air conditioning system, thermal management system, etc., and performs unified arbitration and distribution for the verification, verification anomalies, and access of the power supply circuit.
[0075] Among them, the high-voltage relay control service is a combined service used, but not limited to, controlling the closing or opening of the main positive, main negative, and pre-charge relays in the power supply circuit, and detecting their sticking status. The bus voltage detection service is an atomic service used, but not limited to, verifying whether the pre-charge bus voltage in the power supply circuit meets specified conditions. The motor status request service is an atomic service used, but not limited to, sending status requests to the front and rear motor controllers in the power supply circuit respectively, and obtaining motor voltage and status information through the front-drive status service or the rear-drive status service. The power system status service is a combined service used, but not limited to, determining whether there is a fault in the power domain by calling atomic services such as fault diagnosis service, interlock detection service, and insulation detection service, providing a safety basis for power-on.
[0076] Meanwhile, the system also synchronizes the vehicle power mode status through the vehicle power mode service and realizes the status feedback on the user side through the human-machine interaction service, thus realizing a complete closed loop of the verification process.
[0077] The technical solution provided in this application, upon receiving a first operation instruction, can determine whether the user intends to enable the vehicle to perform a power supply circuit connection operation based on the first operation instruction. This allows for the acquisition of the vehicle's verification process to determine whether the vehicle's first operating state supports the power supply circuit connection operation, thus ensuring the safety of the power supply circuit connection and improving the execution efficiency of the verification process. Furthermore, during the verification process, this application embodiment can update the global status indicators based on the execution result of any verification action and determine the verification result of the verification process based on the global status indicators. This makes the verification process globally visible, fault location clear, and significantly improves system reliability and maintainability.
[0078] In some other possible implementations, this application also provides a vehicle control device. Figure 4 This is a schematic diagram of the structure of the vehicle control device provided in the embodiments of this application. See also: Figure 4 The vehicle control device provided in this application embodiment includes: a determination module 410, an execution module 420, and an update module 430.
[0079] The determination module 410 is configured to obtain the vehicle's verification process according to a first operation instruction. The first operation instruction is used to indicate the intention to cause the vehicle to perform a power supply circuit connection operation. The verification process is used to determine whether the vehicle's first operating state supports the power supply circuit connection operation through multiple verification actions.
[0080] The execution module 420 is configured to perform multiple verification actions in the order indicated by the verification process.
[0081] The update module 430 is configured to update the vehicle's global status index based on the execution result of any verification action after the execution of any verification action. The global status index is used to indicate the second operating status of multiple subsystems in the vehicle that are related to the verification process.
[0082] The determination module 410 is also configured to determine the verification result of the verification process based on global status indicators.
[0083] In some possible implementations, the verification process is also used to indicate the constraints on the execution process of any verification action, and the verification process is also used to indicate the expected feedback of any verification action. The determination module 410 is further configured to determine that any verification action has failed if the execution process of any verification action does not meet the constraints, and / or if the feedback information of any verification action does not match the expected feedback.
[0084] In some possible implementations, the global status indicators include a first global status indicator and a second global status indicator. The execution result includes a first execution result indicating that any verification action failed, and a second execution result indicating that any verification action succeeded. The update module 430 is further configured to: if the execution result of any verification action is the second execution result, update the second global status indicator according to the second execution result, and the second global status indicator is used to record the second running state; if the execution result of any verification action is the first execution result, update the first global status indicator according to the first execution result, and the first global status indicator is used to generate the corresponding error log.
[0085] In some possible implementations, the execution module 420 is further configured to: generate a first prompt message if the execution result of any verification action is a first execution result, the first prompt message being used to indicate that the first operating state does not support the power supply circuit access operation and prohibits the execution of the power supply circuit access operation; and generate a second prompt message if the execution results of multiple verification actions are all second execution results, the second prompt message being used to indicate that the first operating state supports the power supply circuit access operation and trigger the power supply circuit access operation.
[0086] In some possible implementations, the verification result includes a first verification result indicating that the verification process has failed. The execution module 420 is also configured to generate the first verification result and stop executing the unexecuted verification actions among the multiple verification actions if the execution result of any verification action is the first execution result.
[0087] In some possible implementations, the determining module 410 is configured to: upon receiving a first operation instruction, if a second request is also received, determine a verification process based on the second request; if no second request is received, determine a verification process based on default settings; wherein the second request is used to indicate the configuration intent for the verification process.
[0088] In some possible implementations, the determining module 410 is further configured to: upon receiving a first operation instruction, perform a validity check on the first operation instruction, the validity check being used to determine whether the first operation instruction is allowed to obtain the verification process; and obtain the verification process based on the first operation instruction after the validity check.
[0089] It should be understood that the vehicle control device and the vehicle control method provided in the above embodiments belong to the same concept, and the specific implementation process can be found in the vehicle control method embodiments.
[0090] In some other possible implementations, this application also provides an electronic device for controlling a vehicle. Figure 5 This is a schematic diagram of the structure of an electronic device for controlling a vehicle provided in an embodiment of this application. See also...Figure 5 The electronic device for controlling a vehicle provided in this application includes: The memory 510 stores at least one program instruction for controlling the vehicle.
[0091] When the processor 520 executes the above program instructions, it enables the vehicle to achieve the above-mentioned combination. Figure 2 The steps of the described method and its various embodiments are described below. Depending on the implementation, the processor 520 may be one or more types of processors, including but not limited to DSP (digital signal processor), ASIC (application specific integrated circuit), FPGA (field-programmable gate array), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc., and the number of such devices may be determined according to actual needs.
[0092] In some other possible implementations, this application also provides a computer program (product) comprising computer programs / instructions, which are executed by a processor to enable the computer to perform the above-described combination. Figure 2 The steps of the described method and its various embodiments.
[0093] In some other possible implementations, this application also provides a computer-readable storage medium storing program instructions for controlling a vehicle, which, when executed by one or more processors, implement the above-described combination. Figure 2 The steps of the described method and its various embodiments are described. The computer-readable storage medium can be a readable signal medium or a readable storage medium. A readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of readable storage media (a non-exhaustive list) include: an electrical connection having one or more wires, a portable disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof.
[0094] In the embodiments of this application, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance. The term "multiple" refers to two or more unless otherwise expressly defined.
[0095] The term "and / or" in the embodiments of this application is merely a description of the relationship between related objects, indicating that there can be three relationships. For example, A and / or B can represent three situations: A exists alone, A and B exist simultaneously, and B exists alone.
[0096] The above description is only for the purpose of enabling those skilled in the art to understand the technical solution of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the principles of this application shall be included within the scope of protection of this application.
Claims
1. A method for controlling a vehicle, characterized in that, The method includes: The vehicle's verification process is obtained according to the first operation instruction, which indicates the intention for the vehicle to perform a power supply circuit connection operation. The verification process is used to determine whether the vehicle's first operating state supports the power supply circuit connection operation through multiple verification actions. The plurality of verification actions are executed in the order indicated by the verification process. After any verification action is executed, the global status index is updated according to the execution result of the verification action, and the verification result of the verification process is determined according to the global status index. The global status index indicates the second operating status of multiple subsystems related to the verification process in the vehicle.
2. The method according to claim 1, characterized in that, The verification process also indicates the constraints on the execution of any verification action and the expected feedback for any verification action. The method further includes: If the execution process of any of the verification actions does not meet the constraints, and / or the feedback information of any of the verification actions does not match the expected feedback, it is determined that the execution of any of the verification actions has failed.
3. The method according to claim 1, characterized in that, The global status indicators include a first global status indicator and a second global status indicator. The execution result of any verification action includes a first execution result indicating that the verification action failed, and a second execution result indicating that the verification action succeeded. Updating the global status indicators based on the execution result of any verification action includes: If the execution result of any of the verification actions is the second execution result, the second global state indicator is updated according to the second execution result. The second global state indicator is used to record the second running state. If the execution result of any of the verification actions is the first execution result, the first global status indicator is updated according to the first execution result. The first global status indicator is used to generate the error log corresponding to the first execution result.
4. The method according to claim 3, characterized in that, The method further includes: If the execution result of any of the verification actions is the first execution result, a first prompt message is generated. The first prompt message is used to indicate that the first operating state does not support the power supply circuit access operation and prohibits the execution of the power supply circuit access operation. If the execution results of the multiple verification actions are all the second execution result, a second prompt message is generated. The second prompt message is used to prompt the first operating state to support the power supply circuit access operation and to trigger the power supply circuit access operation.
5. The method according to claim 3, characterized in that, The verification result includes a first verification result indicating that the verification process failed, and the method further includes: If the execution result of any of the verification actions is the first execution result, then the first verification result is generated and the execution of the verification actions that have not been executed among the plurality of verification actions is stopped.
6. The method according to any one of claims 1-5, characterized in that, The verification process for obtaining the vehicle according to the first operation instruction includes: If a second request is also received upon receiving the first operation instruction, the verification process is determined based on the second request. If the second request is not received, the verification process is determined according to the default settings; The second request is used to indicate the configuration intent for the verification process.
7. The method according to any one of claims 1-5, characterized in that, The method further includes: Upon receiving the first operation instruction, a validity check is performed on the first operation instruction, the validity check being used to determine whether the first operation instruction is allowed to access the verification process; The verification process is obtained based on the first operation instruction following the validity verification.
8. A vehicle control device, characterized in that, The device includes a determining module, an execution module, and an updating module; The determining module is configured to obtain the vehicle's verification process according to a first operation instruction, the first operation instruction indicating the intention for the vehicle to perform a power supply circuit connection operation, and the verification process being used to determine whether the vehicle's first operating state supports the power supply circuit connection operation through multiple verification actions. The execution module is configured to execute the plurality of verification actions according to the execution order indicated by the verification process; The update module is configured to update the global status index of the vehicle based on the execution result of any one of the plurality of verification actions after the execution of any one of the verification actions. The global status index is used to indicate the second operating status of a plurality of subsystems in the vehicle that are related to the verification process. The determining module is further configured to determine the verification result of the verification process based on the global state index.
9. An electronic device, characterized in that, include: A memory that stores program instructions for controlling the vehicle; as well as A processor, when the program instructions are executed by the processor, causes the vehicle to perform the method described in any one of claims 1-7.
10. A computer-readable storage medium, characterized in that, It stores program instructions for controlling the vehicle, which, when executed by one or more processors, cause the vehicle to perform the method described in any one of claims 1-7.