A dual-path ultrasonic parameter security update control system and method and storage medium
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- NANJING ZHAOSHENG MEDICAL TECHNOLOGY CO LTD
- Filing Date
- 2026-07-13
- Publication Date
- 2026-08-07
AI Technical Summary
[0005]针对现有双路超声参数更新安全性问题,本发明提出一种双路超声参数安全更新控制系统、方法及存储介质
[0030] The beneficial effects of this invention are: It enables phased control of the reception, storage, and execution of new parameters during parameter updates in dual-channel ultrasonic output devices. This prevents new parameters from directly participating in the two ultrasonic drive outputs before meeting preset conditions, thereby reducing the risk of direct execution of new parameters due to communication anomalies, misconfigurations, device incompatibility, or parameter exceeding limits. This improves the safety and controllability of the dual-channel ultrasonic output device during parameter updates. Furthermore, it maintains reliable output control during device restarts, parameter switching failures, or abnormal operational feedback, allowing the device to continue using old or default parameters, or promptly execute protective actions such as derating, pausing, disabling, and stopping. This reduces problems such as sudden changes in dual-channel ultrasonic drive signals, abnormal loads, and abnormal temperature rises, improving the stability, fault tolerance, and operational safety of the device during parameter updates, startup switching, and operational monitoring.
Smart Images

Figure CN122525873A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of ultrasonic output device control technology, and in particular to a dual-channel ultrasonic parameter safety update control system, method and storage medium. Background Technology
[0002] With the increasing application of configurable devices, embedded control devices, and multi-channel execution devices, device operating parameters typically need to be updated via external terminals, configuration platforms, or communication methods to adapt to different operating conditions, working objects, or control requirements. For devices with multiple execution channels, the operating parameters and coordination timing of different channels are often correlated. Therefore, parameter updates not only involve parameter transmission and storage but also the issues of when parameters take effect, how to switch between them, and how to ensure device operational stability under abnormal conditions.
[0003] While some existing devices can modify or update operating parameters online or locally, current parameter update schemes typically focus on parameter transmission efficiency or the parameter writing process, neglecting the security execution mechanisms after parameter updates. For example, after a parameter update, the new parameters may immediately participate in device control, or there may be a lack of sufficient confirmation and isolation mechanisms during device startup, operating state switching, and anomaly recovery. For devices involving multiple execution channels with coupled relationships between parameters, this approach can easily lead to inconsistencies in state or abnormal output during parameter switching.
[0004] Especially in scenarios where multiple execution channels have different operating parameters, different coordination timings, or safety boundary constraints, if there are issues such as parameter transmission errors, device adaptation errors, parameter exceeding limits, abnormal startup states, or parameter switching failures, the device may operate according to abnormal parameters. This can lead to problems such as sudden changes in execution unit output, unstable operating states, delayed device protection responses, or even abnormal device shutdowns, reducing the reliability of parameter updates and the safety of device operation. Therefore, it is necessary to provide a control scheme that can improve the safety of parameter updates and the reliability of execution in multi-channel devices. Summary of the Invention
[0005] To address the security issues associated with existing dual-channel ultrasound parameter updates, this invention proposes a dual-channel ultrasound parameter security update control system, method, and storage medium.
[0006] The present invention achieves the above objectives through the following technical solutions:
[0007] On the one hand, a dual-channel ultrasonic parameter safety update control system is provided for controlling a dual-channel ultrasonic output device with a first ultrasonic load and a second ultrasonic load. The system includes a communication module, a configuration data interface, a non-volatile memory, a power trigger unit, a dual-channel ultrasonic drive module, a status control module, and a feedback acquisition module. The non-volatile memory includes a currently valid parameter area and a parameter area to be activated.
[0008] The communication module is used to receive the confirmed parameter packet sent by the external configuration terminal, and the configuration data interface is used to parse the parameter packet and provide the parsing result to the status control module; the parameter packet includes first channel output parameters, second channel output parameters, channel coordination timing parameters and security boundary parameters;
[0009] The status control module performs integrity verification, device compatibility verification, and security boundary verification on the parameter package. After all three verifications pass, the parameter package is written into the parameter area to be activated and an activation flag is recorded. The module also controls the dual-channel ultrasonic output device to shut down. Before the power trigger unit generates a local start trigger signal, the parameter package in the parameter area to be activated is not used as the basis for output control. After the power trigger unit generates a local start trigger signal and completes the power-on self-test, the parameter package in the parameter area to be activated is switched to the currently valid parameters. The module then controls the dual-channel ultrasonic drive module to generate the first ultrasonic drive signal and the second ultrasonic drive signal according to the currently valid parameters. If verification, power-on self-test, or parameter switching fails, the old parameters or factory default parameters in the currently valid parameter area are retained, and output according to the parameter package in the parameter area to be activated is prohibited.
[0010] The feedback acquisition module is used to acquire work feedback signals, and the status control module performs derating, pausing, prohibiting or stopping output when the work feedback signal is abnormal.
[0011] Preferably, the first channel output parameters include at least one of a first frequency, a first power, a first duty cycle, a first duration, or a first power correction coefficient; the second channel output parameters include at least one of a second frequency, a second power, a second duty cycle, a second duration, or a second power correction coefficient; the channel coordination timing parameters include at least one of synchronous output parameters, alternating output parameters, sequential output parameters, simultaneous start / stop flags, channel start delay, first channel pre-output duration, second channel delayed output duration, single-cycle output duration, alternation interval, or number of cycles; wherein, the synchronous output parameters are used to control the first ultrasonic load and the second ultrasonic load to output simultaneously, the alternating output parameters are used to control the first ultrasonic load and the second ultrasonic load to output alternately at a preset interval, and the sequential output parameters are used to control the first ultrasonic load and the second ultrasonic load to output sequentially in a preset order.
[0012] Preferably, the safety boundary parameters include at least one of the following: power upper limit, frequency allowable range, duty cycle upper limit, single run duration upper limit, temperature upper limit, load impedance threshold, load impedance allowable range, current upper limit, voltage upper limit, power deviation threshold, first channel rated output upper limit, or second channel rated output upper limit; the operating feedback signal includes at least one of the following: operating surface temperature, load impedance, output current, output voltage, output power feedback value, or operating duration; when the operating surface temperature, output current, output voltage, output power feedback value, or operating duration reaches or exceeds the corresponding upper limit, or the load impedance is not within the load impedance allowable range, or the deviation of the output power feedback value from the set output power exceeds the power deviation threshold, the operating feedback signal is determined to be abnormal.
[0013] Preferably, the parameter package further includes a device model identifier, parameter version number, data length, timestamp, integrity check code, confirmation flag, parameter generation rule version, and candidate time series score value;
[0014] The candidate timing score value is calculated by an external configuration terminal according to a preset scoring rule corresponding to the parameter generation rule version. The status control module verifies on the device side whether the candidate timing score value is consistent with the parameter generation rule version. The preset scoring rule includes: ;in, Indicates the first Candidate timing score values for candidate cooperative timing sequences, wherein the candidate cooperative timing sequences include synchronous cooperative timing sequences, alternating cooperative timing sequences, or sequential cooperative timing sequences; Based on the adaptation score; This is a safety margin penalty item; To switch risk penalty items; and Preset weights;
[0015] The device compatibility verification includes determining whether the device model identifier matches the dual-channel ultrasound output device. The safety boundary verification includes determining whether the first channel output parameters, the second channel output parameters, and the channel coordination timing parameters all belong to the corresponding preset allowable range or preset allowable set, and determining whether the channel coordination timing parameters correspond to the candidate coordination timing that meets the preset safety margin condition and has the highest candidate timing score.
[0016] Preferably, the parameter area to be activated also stores an update status flag and a rollback flag; after the parameter package is written, the status control module sets the update status flag to a pending start confirmation state and sets the activation flag to valid; after parameter switching is completed, the update status flag is set to an activated state and the activation flag is cleared; when verification, power-on self-test, or parameter switching fails, the update status flag is set to an abnormal rollback state according to the rollback flag, and the activation flag is set to an inactive state.
[0017] Preferably, the state control module includes an update state machine, which includes at least a parameter receiving state, a verification state, a pending activation write state, an output prohibition state, a start confirmation state, a parameter activation state, an offline start state, and an abnormal rollback state. The update state machine only enters the parameter activation state from the start confirmation state after detecting the local start trigger signal generated by the power trigger unit and completing the power-on self-test. If no new confirmed parameter packet is received and the pending activation flag is inactive, and the local start trigger signal is detected, the machine enters the offline start state and generates the first ultrasonic drive signal and the second ultrasonic drive signal according to the old parameters in the current valid parameter area or the factory default parameters.
[0018] Preferably, when the dual-channel ultrasonic output device is in output state when the parameter packet is received, or when at least one protective shutdown condition exists among drive energy release, storage write submission, and load disconnection confirmation, the state control module first controls the dual-channel ultrasonic drive module to stop generating the first ultrasonic drive signal and the second ultrasonic drive signal or cut off the power drive output before controlling the dual-channel ultrasonic output device to shut down, and then performs shutdown after confirming that the protective shutdown condition is lifted.
[0019] Preferably, the dual-channel ultrasonic drive module includes a signal generation circuit, a channel selection circuit, and a power drive circuit; the signal generation circuit is used to generate a first reference signal and a second reference signal respectively; the channel selection circuit is used to control the output timing of the first reference signal and the second reference signal according to the channel coordination timing parameters; and the power drive circuit is used to drive the first ultrasonic load and the second ultrasonic load respectively.
[0020] On the other hand, a dual-channel ultrasound parameter safe update control method is provided, including:
[0021] The system receives and parses a confirmed parameter packet sent by an external configuration terminal. The parameter packet includes first channel output parameters, second channel output parameters, channel coordination timing parameters, and security boundary parameters.
[0022] Perform integrity checks, device compatibility checks, and security boundary checks on the parameter package;
[0023] After all three types of verifications pass, the parameter package is written into the activation parameter area of the non-volatile memory and the activation flag is recorded, and the dual-channel ultrasonic output device is powered off.
[0024] Before the next detection of a local start-up trigger signal generated by the power trigger unit, the parameter package in the parameter area to be activated will not be used as the basis for output control;
[0025] After detecting that the power trigger unit generates a local start trigger signal and completes the power-on self-test, the parameter package in the parameter area to be activated is switched to the currently valid parameters, and the first ultrasonic drive signal and the second ultrasonic drive signal are generated according to the currently valid parameters.
[0026] When verification, power-on self-test or parameter switching fails, the old parameters or factory default parameters in the current valid parameter area are retained, and the generation of the first ultrasonic drive signal and the second ultrasonic drive signal according to the parameter package in the parameter area to be activated is prohibited.
[0027] If no new confirmed parameter package is received and the activation flag is in an inactive state, if the local start trigger signal is detected, the first ultrasonic drive signal and the second ultrasonic drive signal are generated according to the old parameters in the current valid parameter area or the factory default parameters.
[0028] Collect work feedback signals, and when the work feedback signals are abnormal, perform derating output, pause output, disable output, or stop output.
[0029] In another aspect, a computer-readable storage medium is provided, wherein a computer program is stored therein, and when executed by a processor, the computer program implements the dual-channel ultrasound parameter security update control method as described above.
[0030] The beneficial effects of this invention are: It enables phased control of the reception, storage, and execution of new parameters during parameter updates in dual-channel ultrasonic output devices. This prevents new parameters from directly participating in the two ultrasonic drive outputs before meeting preset conditions, thereby reducing the risk of direct execution of new parameters due to communication anomalies, misconfigurations, device incompatibility, or parameter exceeding limits. This improves the safety and controllability of the dual-channel ultrasonic output device during parameter updates. Furthermore, it maintains reliable output control during device restarts, parameter switching failures, or abnormal operational feedback, allowing the device to continue using old or default parameters, or promptly execute protective actions such as derating, pausing, disabling, and stopping. This reduces problems such as sudden changes in dual-channel ultrasonic drive signals, abnormal loads, and abnormal temperature rises, improving the stability, fault tolerance, and operational safety of the device during parameter updates, startup switching, and operational monitoring. Attached Figure Description
[0031] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort. Wherein: Figure 1 This is a schematic diagram of the system structure according to an embodiment of the present invention; Figure 2 This is a flowchart of a method according to an embodiment of the present invention. Detailed Implementation
[0032] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. All other embodiments obtained by those skilled in the art based on the described embodiments of the present invention are within the scope of protection of the present invention.
[0033] like Figure 1 The illustration shows an embodiment of the present invention, which provides a dual-channel ultrasonic parameter safety update control system for controlling a dual-channel ultrasonic output device with a first ultrasonic load and a second ultrasonic load. The system includes parameter packet reception, parsing, verification, activation storage, power-off, local startup triggering, power-on self-test, parameter switching, failure rollback, offline startup, and feedback protection. The dual-channel ultrasonic output device can be used in scenarios such as media atomization, acoustic coupling, surface treatment, personal care, or beauty penetration enhancement. Regardless of the specific application scenario, the device performs parameter safety updates and dual-channel ultrasonic output control. Both the first and second ultrasonic loads are loads capable of generating ultrasonic vibration or ultrasonic energy output under electrical signal drive. They can be of the same type or different types, used to perform acoustic output tasks at different frequencies, with different power levels, or with different timing sequences.
[0034] In the following embodiments, terms such as external medium, target action state, and action surface are used to summarize the medium to be treated, the contact object, or the action object in different applications. For example, in personal care or beauty penetration-enhancing applications, the external medium can be a beauty care solution, serum, or other topical medium, and the target action state can include the type of action site, contact state, action surface temperature, or the mode preference provided by the user within the authorized range.
[0035] The control system includes a communication module, a configuration data interface, a non-volatile memory, a power trigger unit, a dual-channel ultrasonic drive module, a status control module, and a feedback acquisition module.
[0036] The communication module receives confirmed parameter packets from an external configuration terminal. This external configuration terminal can be a smart terminal, a host computer, a dedicated configurator, or a combination of a cloud platform and a local terminal. A confirmed parameter packet refers to a parameter packet sent to the dual-channel ultrasonic output device only after the external configuration terminal has completed parameter generation, performed confirmation processing based on the parameter display results, and met at least one of the following confirmation conditions: user confirmation, administrator confirmation, authorization code verification, device binding verification, or configuration process completion marker. This prevents unauthorized or unconfirmed parameters from directly entering the device control process.
[0037] The configuration data interface is used to parse the parameter packets received by the communication module and provide the parsing results to the status control module. The configuration data interface can be implemented by a protocol parser in the microcontroller, or by a communication protocol chip, security chip, or gateway module. The parsing process may include steps such as identifying the packet header, reading the data length, extracting parameter fields, extracting checksum fields, and generating an internal parameter cache. The parameter packet includes at least the first channel output parameters, the second channel output parameters, channel coordination timing parameters, and security boundary parameters.
[0038] Non-volatile memory is used to save parameter data after the device is powered off. It can be Flash, EEPROM, FRAM, or other storage media that do not lose data when power is off. Logically, non-volatile memory includes a currently valid parameter area and a parameter area to be activated. The currently valid parameter area stores parameters that have already been allowed to be executed; the parameter area to be activated stores new parameter packets that have been received but not yet allowed to be executed. The currently valid parameter area and the parameter area to be activated can be different address segments in the same memory, or they can be different logical areas in the same memory distinguished by pointers or flags.
[0039] The state control module can be implemented using a microcontroller, digital signal processor, system-on-a-chip, or programmable logic device. After receiving the parsed result, the state control module performs integrity checks, device compatibility checks, and security boundary checks on the parameter packet. Integrity checks determine if the parameter packet has been corrupted during transmission or storage; device compatibility checks determine if the parameter packet is suitable for the current dual-channel ultrasonic output device; and security boundary checks determine if the output parameters and timing parameters in the parameter packet are within the device's allowable range. Only after all three checks pass, the state control module writes the parameter packet into the activation parameter area and records the activation flag. After writing into the activation parameter area, the state control module controls the dual-channel ultrasonic output device to shut down. Shutdown means the device stops outputting the first and second ultrasonic drive signals and enters a shutdown state, a low-power state, or a waiting-to-restart state. Before the next detection of a local startup trigger signal from the power trigger unit, the state control module does not use the parameter packet in the activation parameter area as the basis for output control. In other words, even if a new parameter packet has been written into the device, it cannot immediately change the current output; it must wait for the local startup action on the device side.
[0040] The power trigger unit can be a physical button, touch button, rotary switch, reed switch, or other local triggering component located on the device body. The local start trigger signal is a start signal generated by the power trigger unit, excluding remote start commands sent by the external configuration terminal via a communication link. After detecting the local start trigger signal, the status control module first performs a power-on self-test. The power-on self-test may include power supply voltage detection, non-volatile memory read detection, activation flag detection, dual-channel ultrasonic drive module enable status detection, feedback acquisition module connection status detection, and watchdog status detection. After the power-on self-test passes, the status control module switches the parameter package in the activation parameter area to the currently valid parameters and controls the dual-channel ultrasonic drive module to generate the first and second ultrasonic drive signals according to the currently valid parameters.
[0041] If integrity verification, device compatibility verification, security boundary verification, power-on self-test, or parameter switching fails, the status control module retains the old parameters or factory default parameters in the currently valid parameter area and prohibits the generation of the first and second ultrasonic drive signals according to the parameter package in the parameter area to be activated. If no valid old parameters exist in the currently valid parameter area, the factory default parameters are read. The factory default parameters can be written to non-volatile memory during equipment manufacturing. Their values should be set within the allowable range of the equipment, and it is preferable to use more conservative power, frequency, duty cycle, and operating time.
[0042] The feedback acquisition module is used to collect operational feedback signals and provide them to the status control module. The feedback acquisition module may include a temperature detection element, impedance detection circuit, voltage sampling circuit, current sampling circuit, power detection circuit, or timer. When the operational feedback signal is abnormal, the status control module performs derating, pause, disable, or stop output.
[0043] For ease of explanation, the process of "receiving the confirmed parameter packet, parsing the parameter packet, performing integrity verification, device compatibility verification and security boundary verification, writing to the parameter area to be activated, recording the activation flag, powering off, triggering local startup, power-on self-test, and switching parameters" will be referred to as the aforementioned parameter security update process. Through this process, new parameter packets sent by the external configuration terminal will not immediately change the device output; they must undergo activation and local startup confirmation before becoming valid parameters. This reduces the risk of sudden output changes in dual-channel ultrasonic output devices due to parameter updates.
[0044] Based on the above system, the first channel output parameters in the parameter package are used to define the output state of the first ultrasonic drive signal, and may include at least one of the following: first frequency, first power, first duty cycle, first duration, or first power correction coefficient. The first frequency is stored in Hz, kHz, or MHz and expressed in W, mW, or as a percentage of rated power; the first duty cycle represents the proportion of the first ultrasonic drive signal in an effective output state within one control cycle; the first duration represents the duration of continuous operation of the first channel within one output phase; the first power correction coefficient is used to proportionally correct the first power, for example, the final output power of the first channel may be equal to the product of the first power and the first power correction coefficient.
[0045] The second channel output parameters are used to define the output state of the second ultrasonic drive signal, and may include at least one of the following: second frequency, second power, second duty cycle, second duration, or second power correction coefficient. The meaning of the second channel output parameters is the same as that of the first channel output parameters, but their numerical range can be set independently according to the rated frequency, rated power, and operating characteristics of the second ultrasonic load. The first frequency and the second frequency can be the same or different; the first power and the second power can also have different rated upper limits.
[0046] Channel coordination timing parameters are used to define the output relationship between the first and second ultrasonic loads. These parameters may include at least one of the following: synchronous output parameters, alternating output parameters, sequential output parameters, simultaneous start / stop flags, channel start delay, first channel pre-output duration, second channel delayed output duration, single-cycle output duration, alternation interval, or number of cycles. The synchronous output parameters control the simultaneous output of the first and second ultrasonic loads. In synchronous output mode, the state control module simultaneously enables the first and second ultrasonic drive signals at the same start time or within the allowable error range. The two signals may have different frequencies, different powers, or different duty cycles, but their start / stop relationship is uniformly controlled by the synchronous output parameters. The alternating output parameters control the first and second ultrasonic loads to output alternately at preset intervals. For example, the state control module first enables the first ultrasonic drive signal and disables the second ultrasonic drive signal. After a first duration, it disables the first ultrasonic drive signal. After an alternation interval, it enables the second ultrasonic drive signal and disables it after a second duration. This process constitutes a coordination cycle and can be repeated according to the number of cycles. The sequential output parameters are used to control the first and second ultrasonic loads to output in a preset order. For example, the status control module can first control the first ultrasonic load to output the first channel for a pre-output duration, and then control the second ultrasonic load to output after the second channel has been delayed for a certain duration; alternatively, it can control the second ultrasonic load to output first, and then control the first ultrasonic load to output, according to the order specified in the parameter package. The first channel pre-output duration and the second channel delayed output duration can be used to avoid both loads from simultaneously increasing their power at startup, reducing the risk of power surges and sudden output changes.
[0047] Taking personal care or beauty penetration enhancement applications as an example, if the first ultrasonic load is an ultrasonic atomization load and the second ultrasonic load is an ultrasonic action load, then synchronous output can be used to allow the external medium supply and the ultrasonic action of the second channel to occur simultaneously; alternating output can be used to form a cycle of external medium supply—ultrasonic action of the second channel; sequential output can be used to first form an external medium film on the action surface by the first channel, and then output ultrasonic energy by the second channel. The external medium film can serve as an acoustic coupling layer to reduce ultrasonic energy attenuation caused by air gaps.
[0048] In one specific implementation, the channel coordination timing parameters can be encoded as a mode field and multiple time fields. A mode field value of 0 indicates synchronous output, 1 indicates alternating output, and 2 indicates sequential output. The time fields include the first duration, the second duration, the alternation interval, the start delay, the single-cycle output duration, and the number of cycles. The status control module selects the appropriate timer control logic based on the mode field and sets the timer comparison value based on the time fields, thereby controlling the output of the dual-channel ultrasonic drive module.
[0049] The safety boundary parameters in the parameter package are used to define the safety boundaries for the operation of the dual-channel ultrasonic output device, and may include at least one of the following: power limit, frequency allowable range, duty cycle limit, single run duration limit, temperature limit, load impedance threshold, load impedance allowable range, current limit, voltage limit, power deviation threshold, first channel rated output limit or second channel rated output limit. Among them, the power limit is used to limit the total output power of the device or the output power of a single channel; the rated output limit of the first channel and the rated output limit of the second channel are used to limit the maximum allowable output of the first ultrasonic load and the second ultrasonic load, respectively; the frequency allowable range is used to limit the allowable frequency range of the first or second ultrasonic drive signal, which can be stored as the minimum frequency and the maximum frequency, or as a set of available frequency ranges; the duty cycle limit is used to limit the maximum effective output ratio of the ultrasonic drive signal within one control cycle; the single run time limit is used to limit the longest run time after one start; the temperature limit is used to limit the maximum allowable temperature of the action surface or key components; the current limit and voltage limit are used to limit the operating current and operating voltage of the power drive circuit; the load impedance threshold and the load impedance allowable range are used to determine whether the load connection status, load contact status or drive circuit status is abnormal; the load impedance allowable range can include a lower limit and an upper limit. When the load impedance is lower than the lower limit, it can indicate a short circuit or overload. When the load impedance is higher than the upper limit, it can indicate that the load is not connected, has poor contact, or the circuit is broken; the load impedance threshold can also be used to detect impedance changes, for example, when the current impedance changes by more than a preset ratio relative to the previous sampling period, it is judged as abnormal.
[0050] The feedback signals acquired by the feedback acquisition module can include the operating surface temperature, load impedance, output current, output voltage, output power feedback value, or operating time. The output power feedback value can be calculated from the output voltage and output current, or it can be directly output by the power detection circuit.
[0051] In one implementation, the output power feedback value can be calculated using the following formula: ;in, This is the output power feedback value, in watts (W). This is the output voltage feedback value, in volts (V). This is the output current feedback value, in amperes (A). This is a power conversion factor or calibration factor, dimensionless. When using RMS values for calculation... and These can be the RMS values of voltage and current, respectively. Relative power deviation. It can be calculated using the following formula: ;in, To set the output power, the unit is... Consistent. If If the power deviation exceeds the threshold, the operating feedback signal is considered abnormal. When setting the output power... At that time, the state control module does not use the above relative deviation formula, but instead judges the output power feedback value. Is it greater than the preset zero-power residual threshold? If it is, then the corresponding channel is determined to have abnormal output.
[0052] The status control module can read the operating feedback signal at a fixed sampling period, ranging from 10ms to 1000ms. To avoid misjudgment caused by single noise, moving average, median filtering, or continuous anomaly counting can be used. For example, a temperature anomaly is determined when three consecutive samples exceed the upper temperature limit, and a power anomaly is determined when five consecutive power deviations exceed the threshold. When the operating surface temperature, output current, output voltage, output power feedback value, or operating time reaches or exceeds the corresponding upper limit, or the load impedance is not within the allowable range, or the deviation of the output power feedback value from the set output power exceeds the power deviation threshold, the status control module determines that the operating feedback signal is abnormal.
[0053] Upon detecting an abnormal feedback signal, the status control module performs derating, pausing, disabling, or stopping output. Derating refers to reducing output power, reducing duty cycle, or shortening output duration; pausing refers to temporarily stopping output and waiting for the feedback signal to recover; disabling output refers to setting the fault latch flag, preventing output until the fault is cleared, power is restored, or an authorized reset command is received; stopping output refers to terminating the current working process and shutting down the dual-channel ultrasonic drive module. In personal care or beauty penetration enhancement applications, the surface temperature can be understood as the temperature of the device's action head or target surface, and the load impedance can be used to indirectly reflect the load connection, contact, or acoustic coupling status.
[0054] Furthermore, the parameter package may also include, in addition to the device model identifier, parameter version number, data length, timestamp, integrity check code, confirmation flag, parameter generation rule version, and candidate timing score value. Among these, the device model identifier indicates the applicable device model, hardware version, or load configuration; the parameter version number distinguishes parameters from different batches or generation times; the data length identifies the number of data bytes in the parameter package; the timestamp records the parameter package generation or confirmation time; the integrity check code verifies the completeness of the parameter package; the confirmation flag indicates that the parameter package has been authorized or confirmed by the user; the parameter generation rule version indicates the scoring rule version used when generating candidate timing score values; and the candidate timing score value represents the candidate scores for synchronous coordination timing, alternating coordination timing, and sequential coordination timing under the current parameter generation conditions.
[0055] The parameter packet can use the following field order: packet header, data length, device model identifier, parameter version number, timestamp, parameter generation rule version, first channel output parameters, second channel output parameters, channel coordination timing parameters, security boundary parameters, candidate timing score value, acknowledgment flag, and integrity check code. The above field order is only an example; in actual implementations, other field orders can be used as long as the configured data interface can correctly parse the fields according to the preset protocol.
[0056] In one implementation of parameter package generation by an external configuration terminal, the external configuration terminal can obtain external media information by scanning a QR code, barcode, or electronic tag on the external media container, and retrieve media characteristic parameters, candidate coordination timing, and suggested output parameters corresponding to the external media from a local database or server. The external configuration terminal can also provide a manual configuration interface, allowing users or administrators to select synchronous, alternating, or sequential coordination timing within authorized limits, and input the first channel output parameters, the second channel output parameters, the total runtime, and the time allocation for each stage. After generating the parameter package, the external configuration terminal displays a parameter summary and risk warning to the user, and after user confirmation or authorization confirmation, sends the confirmed parameter package to the dual-channel ultrasound output device. Upon receiving the parameter package, the dual-channel ultrasound output device still processes it according to the aforementioned parameter security update procedure; the parameters generated by the external configuration terminal must not directly bypass device-side verification to control the dual-channel output.
[0057] Integrity check codes can be implemented using CRC16, CRC32, hash digests, or message authentication codes. For example, when using CRC32, the external configuration terminal calculates the CRC32 value based on the parameter packet fields other than the integrity check code field and writes it into the integrity check code field. After receiving the parameter packet, the status control module recalculates the CRC32 value using the same algorithm. If the calculated result matches the integrity check code carried in the parameter packet, the integrity check passes; otherwise, the integrity check fails.
[0058] Candidate timing scores include synchronous scores, alternating scores, and sequential scores. Candidate collaborative timing sequences include synchronous collaborative timing sequences, alternating collaborative timing sequences, or sequential collaborative timing sequences. Specifically, synchronous scores correspond to synchronous collaborative timing sequences, alternating scores correspond to alternating collaborative timing sequences, and sequential scores correspond to sequential collaborative timing sequences. These scores are calculated by the external configuration terminal according to preset scoring rules corresponding to the parameter generation rule version and then written into the parameter package. The status control module does not directly generate new candidate timing score values on the device side. Instead, it verifies whether the received candidate timing score values are consistent with the parameter generation rule version and further determines whether the channel collaborative timing parameters in the parameter package correspond to the candidate collaborative timing sequence with the highest candidate timing score value that meets the preset safety margin conditions.
[0059] The preset scoring rules include: ;in, Indicates the first Candidate time series score values for candidate collaborative time series. The values can be sync, alt, or seq, representing synchronous coordination timing, alternating coordination timing, and sequential coordination timing, respectively; or they can be set to... These represent the three types of candidate collaborative timing sequences, respectively.
[0060] Based on the adaptation score, used to represent the first The degree of compatibility of candidate collaborative timing with respect to the basic parameters of external media characteristics (including viscosity grade, particle size grade, stability grade, volatility grade, shear sensitivity grade, etc.), target action state parameters (including target action surface type, contact state grade, target area tolerance grade, target action surface temperature grade, etc.) and equipment capability parameters (including first channel rated power, second channel rated power, frequency allowable range, duty cycle upper limit, power output capability, continuous operation time upper limit, etc.). It can be obtained by summing according to the rules, or by using a normalized weighted average. For example: ;in, These are the conditional judgment values or normalized values corresponding to the characteristic parameters of the external medium. The conditional judgment value or normalized value corresponding to the target's state parameters. These are the conditional judgment values or normalized values corresponding to the equipment capability parameters; , , The preset weights correspond to the parameter generation rule version. Taking personal care or beauty penetration-enhancing applications as an example, external medium characteristic parameters may also include the composition grade, molecular weight grade, particle size grade, thermal stability grade, or cavitation sensitivity grade of the topical medium; target action state parameters may include the type of action site, the tolerance grade of the action surface, the temperature grade of the action surface, or the mode preference selected by the user within the authorized range. The above parameters are preferably expressed as grade values, coded values, or normalized values, and are not directly used as identification information.
[0061] For example: when the external medium corresponds to the macromolecular or large particle size level, the basic adaptation score of the synchronous coordination timing is increased; when the external medium corresponds to the medium molecular or medium particle size level, the basic adaptation score of the alternating coordination timing is increased; when the external medium corresponds to the thermal sensitivity level, cavitation sensitivity level, or the target action state corresponds to the high sensitivity level, the basic adaptation score of the sequential coordination timing is increased and the basic adaptation score of the synchronous coordination timing is decreased; when the equipment capability parameters indicate that the second channel frequency and maximum output power both meet the high output condition, the basic adaptation score of the synchronous coordination timing is increased. These scoring or deduction rules can be stored in a rule table corresponding to the parameter generation rule version and used to calculate the basic adaptation score. .
[0062] When generating specific output parameters, the external configuration terminal can determine the power ratio of the first channel, the power ratio of the second channel, the total runtime, and special timing based on the candidate collaborative timing type. For example, synchronous collaborative timing can correspond to the simultaneous start and stop of the first and second channels; alternating collaborative timing can correspond to the first channel outputting a preset millisecond duration, the second channel outputting a preset millisecond duration, and then cycling; sequential collaborative timing can correspond to the first channel first outputting a preset second duration to form an external dielectric film, and then the second channel outputting a preset duration and cycling. The external configuration terminal can also modify the power based on target action state parameters or external medium characteristic parameters. For example, when the target action state corresponds to a high sensitivity level, the power correction coefficient of the first or second channel can be reduced; when the target action state corresponds to a high tolerance level or a high action surface thickness level, the power correction coefficient can be increased but not exceeding the corresponding power upper limit; when the external medium corresponds to a carrier vulnerability level, the power correction coefficient of the second channel can be reduced. After the above generated results are written into the parameter package, the dual-channel ultrasonic output device still needs to perform integrity verification, device adaptation verification, safety boundary verification, and activation control.
[0063] For safety margin penalty term, used to represent the first... The degree to which the output parameters of candidate cooperative timing models approach the safety boundary. The closer the candidate parameters are to the safety boundary, the better. The larger the value, the lower the score. For example:
[0064] ;
[0065] in, and The first Power settings for the first and second channels under candidate collaborative timing; and These are the rated output limits for the first and second channels, respectively. and These are the duty cycles of the first and second channels, respectively. and These are the corresponding upper limits of the duty cycle; For the first The single runtime corresponding to the candidate collaborative timing sequence; This represents the upper limit of a single run duration. All the above fractions are dimensionless values resulting from the division of quantities with the same dimension; therefore... It is a dimensionless numerical value.
[0066] To switch risk penalty items, this indicates the degree of abrupt change between the parameter package to be written to the parameter area to be activated and the parameters in the currently valid parameter area. For example:
[0067] ;
[0068] in, and These are the power of the first channel and the power of the second channel in the current valid parameter area, respectively. and The first The first and second channel frequencies under candidate collaborative timing; and These are the first channel frequency and the second channel frequency in the current valid parameter area, respectively. and These represent the allowable range width for the corresponding frequency; This is the cooperative timing difference value. If the cooperative timing type of the parameter to be activated is the same as that of the currently valid parameter, then... If they are different, then You can choose 1 or a preset difference value between 0 and 1. All of the above are dimensionless values, therefore... It is a dimensionless numerical value. to Preset weights for dimensionless quantities.
[0069] When the allowed frequency range of a certain channel is zero, if the frequency to be activated is the same as the current valid frequency, the corresponding frequency difference normalization term is set to 0; if they are different, the corresponding frequency difference normalization term is set to 1, or the frequency parameter is directly determined not to be within the preset allowed range. When there are no valid old parameters in the current valid parameter area, the external configuration terminal can use the factory default parameters as the current valid parameters for calculation. If the external configuration terminal cannot obtain valid old parameters or factory default parameters, then... Set to the preset default value, or do not generate the corresponding parameter package. When the status control module verifies on the device side, if it finds that the current valid parameter version on which the candidate timing score value is based is inconsistent with the current valid parameter version of the device, it can determine that the parameter package verification fails.
[0070] and Dimensionless weights are preset to adjust the impact of safety margin penalties and risk switching penalties on the overall score. Because , and All are dimensionless values, therefore It is also a dimensionless score. For example, if Normalized to 0 to 10, and Normalized to 0 to 1, then and It can take values in the range of 0 to 10; if Normalized to 0 to 1, then and It should also be set according to a 0 to 1 rating scale.
[0071] The preset safety margin condition can be set to Safety margin penalty threshold A value of 0.8 can be used, indicating that the key output parameters under the candidate collaborative timing do not exceed 80% of the corresponding safety boundary. When performing safety boundary verification, the state control module first determines whether the output parameters of the first channel, the output parameters of the second channel, and the channel collaborative timing parameters belong to the corresponding preset allowable range or preset allowable set. Then, it determines the candidate collaborative timing with the highest candidate timing score from the candidate collaborative timing set that meets the preset safety margin conditions, and determines whether the channel collaborative timing parameters in the parameter package correspond to the candidate collaborative timing. If there is no candidate collaborative timing that meets the preset safety margin conditions, the safety boundary verification is deemed to have failed.
[0072] For example, in parameter generation rule version V1, the basic adaptation scores calculated by the external configuration terminal for synchronous coordination timing, alternating coordination timing, and sequential coordination timing are respectively... , , Based on the degree of similarity between each candidate parameter and the safety boundary parameter, the following is obtained: , , Based on the change between the parameter to be activated and the currently valid parameter, we obtain... , , .set up , ,but: , , .
[0073] In this example, if the preset safety margin condition is Then, due to the synchronous coordination timing If the preset safety margin conditions are not met, the sequence is excluded; if the alternating and sequential coordination timings meet the preset safety margin conditions, and the alternating coordination timing has the highest candidate timing score, then the channel coordination timing parameters in the parameter package should correspond to the alternating coordination timing. If the parameter package actually carries synchronous or sequential coordination timing, the state control module can determine that the consistency check has failed.
[0074] When two or more candidate collaborative timing scores that meet the preset safety margin conditions are the same or the difference is less than the preset difference threshold, the state control module preferentially selects the safety margin penalty item. Smaller candidate collaborative timing; if If they are still the same, then prioritize switching the risk penalty item. If the smaller candidate coordination sequence is still indistinguishable, then the candidate coordination sequence is selected according to the preset priority corresponding to the parameter generation rule version.
[0075] When the candidate timing score is calculated by an external configuration terminal, the external configuration terminal can read the parameter summary, version number, or necessary parameter fields from the currently valid parameter area through the communication module before generating the parameter package. On the device side, the status control module can perform consistency checks based on the locally stored parameter generation rule version, the currently valid parameter version, and the scoring fields in the parameter package. Consistency checks may include: determining whether the parameter generation rule version is supported by the device; determining whether the currently valid parameter version corresponding to the candidate timing score is consistent with the device's currently valid parameter version; determining whether the candidate timing score is within the scoring range allowed by the corresponding rule version; and determining whether the channel coordination timing parameters in the parameter package correspond to the candidate coordination timing that meets the preset security margin conditions and has the highest candidate timing score. If any of the above checks fails, the status control module determines that the security boundary check or consistency check has failed.
[0076] If the external configuration or server uses a machine learning model to assist in generating the basic adaptation score This model is only used to generate candidate scores and is not directly used as the output control basis for the dual-channel ultrasonic drive module. The model may include a data input module, a feature processing module, a model calculation module, and a parameter package generation module. The data input module receives external medium characteristic parameters, target action state parameters, and equipment capability parameters; the feature processing module handles missing values, encodes discrete features, and normalizes continuous features; the model calculation module outputs basic scores for synchronous, alternating, and sequential candidate coordinated timing sequences; the parameter package generation module writes the score values, safety margin penalty terms, switching risk penalty terms, and final coordinated timing sequence parameters into the parameter package. During model training, input samples may include external medium characteristics, target action state, equipment capability parameters, historical channel output parameters, and historical feedback signals. Labels can be operational stability scores, anomaly markers, or normalized comprehensive evaluation values. The training process includes sample cleaning, feature encoding, normalization processing, training and validation set partitioning, model training, validation, testing, and model version finalization. If user behavior data, target status data, or information that may be associated with individuals are involved, it should be done with the user's consent and in compliance with laws and regulations. Algorithms must not contain discriminatory rules based on irrelevant sensitive attributes such as gender, ethnicity, age, or region. Regardless of whether the basic adaptation score is generated by the model, the model output must be confirmed through the parameter package and the aforementioned parameter security update process before it can be allowed to form the currently valid parameters.
[0077] In addition to storing parameter packages, the parameter area to be activated can also store update status flags and rollback flags. The update status flags indicate the current stage of the parameter update process, while the rollback flags indicate whether it is permissible to revert to old parameters or factory default parameters if an error occurs during the update process.
[0078] In one implementation, the update status flag can take the following values: 00 indicates no update, 01 indicates pending confirmation, 02 indicates activated, and 03 indicates an abnormal rollback. The pending activation flag can be 0 or 1, where 0 indicates the pending parameter is invalid and 1 indicates the pending parameter is valid. The rollback flag can be 0 or 1, where 0 indicates automatic rollback is not allowed and 1 indicates automatic rollback is allowed. More detailed status values can also be used to represent subdivided states such as "writing," "writing complete," and "switching."
[0079] After the parameter package is written, the status control module sets the update status flag to the pending confirmation state and the pending activation flag to valid. Writing completion means that all fields of the parameter package, integrity check code, version information, and flag information have been written to non-volatile memory and verified through post-write read-verification. Post-write read-verification can be achieved by the status control module rereading the pending activation parameter area and recalculating the integrity check code. After parameter switching is completed, the status control module sets the update status flag to the activated state and clears the pending activation flag. Parameter switching can be performed using copy switching, pointer switching, or flag bit switching. Copy switching copies the parameter package from the pending activation parameter area to the currently valid parameter area; pointer switching changes the pointer of the currently valid parameter from the old parameter address to the pending activation parameter address; flag bit switching determines the currently executed parameter by updating the valid area flag. In the event of integrity verification, device adaptation verification, security boundary verification, power-on self-test, or parameter switching failure, the status control module sets the update status flag to the abnormal rollback state and the pending activation flag to the inactive state based on the rollback flag. If the rollback flag indicates that automatic rollback is allowed, the old parameters in the currently valid parameter area will continue to be used; if no valid old parameters exist in the currently valid parameter area, the factory default parameters will be read. If the rollback flag indicates that automatic rollback is not allowed, the dual-channel ultrasonic drive module output will be disabled, and a parameter update failure will be indicated via the communication module or indicator signal.
[0080] To avoid inconsistencies caused by power outages, the state control module can employ dual-copy storage, log-based writing, or transactional writing. Taking transactional writing as an example, the parameter packet body is written first, followed by the integrity checksum, then the update status flag, and finally the activation flag. After the device is powered on again, if it detects that the parameter packet body exists but the activation flag is invalid, it considers the previous write incomplete and does not allow activation of the parameter packet; if it detects that the activation flag is valid but the integrity check fails, it enters an abnormal rollback state.
[0081] The state control module includes an update state machine, which includes at least the following states: parameter receiving state, verification state, pending activation write state, output inhibit state, start confirmation state, parameter activation state, offline start state, and abnormal rollback state. The update state machine can be implemented by microcontroller software or by a hardware state machine in a programmable logic device. The parameter receiving state waits for the communication module to receive a confirmed parameter packet from an external configuration terminal. Once the communication module has completed data reception and the configuration data interface has parsed the complete parameter packet, the state machine enters the verification state. The verification state performs integrity verification, device adaptation verification, and security boundary verification. If any verification fails, the state machine enters the abnormal rollback state or maintains the current valid parameters; if all three verifications pass, the state machine enters the pending activation write state. The pending activation write state writes the parameter packet to the pending activation parameter area of the non-volatile memory and writes the pending activation flag, update status flag, and rollback flag. After writing, the state machine enters the output inhibit state. The output inhibit state ensures that the first and second ultrasonic drive signals are not directly generated from the pending activation parameter packet. In this state, the enable pin of the dual-channel ultrasonic drive module is turned off, the power drive output is disabled, and the device subsequently enters a shutdown state or a low-power state. The startup confirmation state is used to wait for the power trigger unit to generate a local startup trigger signal. The update state machine only enters the parameter activation state from the startup confirmation state after detecting the local startup trigger signal generated by the power trigger unit and completing the power-on self-test. The parameter activation state is used to switch the parameter packets in the parameter area to be activated to the currently valid parameters, and control the dual-channel ultrasonic drive module to generate the first and second ultrasonic drive signals according to the currently valid parameters. The offline startup state is used to directly start the device using the parameters in the currently valid parameter area when there are no parameters to be activated. If the state control module detects a local startup trigger signal when no new confirmed parameter packet is received and the activation flag is inactive, it enters the offline startup state and generates the first and second ultrasonic drive signals according to the old parameters in the currently valid parameter area or the factory default parameters. The conditions of not receiving a new confirmed parameter packet and the activation flag being inactive must be met simultaneously. If the activation flag is valid, even if no new parameter packet was received before this startup, the system should first enter the startup confirmation state and attempt to activate the parameters to be activated, rather than entering the offline startup state. The abnormal rollback state is used to handle exceptions such as verification failure, self-test failure, switchover failure, or incomplete writing. After entering the abnormal rollback state, the status control module retains the old parameters or factory default parameters in the currently valid parameter area, prohibits the use of abnormal parameter packets in the activation parameter area, and can clear the activation flag or set it to an inactive state.
[0082] When a parameter packet is received, the dual-channel ultrasonic output device may be in output mode or standby mode. If the device is in output mode, directly writing new parameters and immediately shutting down may result in residual energy in the power drive circuit not being released, memory writing not being completed, or the load not being safely disconnected. Therefore, the status control module can execute a protective shutdown procedure before controlling the device to shut down. Protective shutdown conditions may include at least one of the following: the device is in output mode, there is a need to release drive energy, there is a need to submit a memory write request, or there is a need to confirm load disconnection.
[0083] In this context, "device in output state" refers to either the first or second ultrasonic drive signal being enabled, or the power drive circuit being in output state. The status control module can determine whether the device is in output state by reading the drive enable bit, power drive feedback bit, output current feedback value, or output power feedback value. "Drive energy release" refers to the presence of residual electrical energy in the power drive circuit, inductor, capacitor, or ultrasonic load. The status control module can confirm the completion of drive energy release by turning off the PWM output, pulling the drive enable terminal low, connecting the bleeder resistor, waiting for a preset bleeder time, or detecting that the bus voltage is below a threshold. "Storage write commit" means that a non-volatile memory write operation needs to wait for a completion flag or busy signal to be released. "Load disconnection confirmation" confirms that the first and second ultrasonic loads are no longer receiving valid drive signals.
[0084] During the protective shutdown process, the state control module first controls the dual-channel ultrasonic drive module to stop generating the first and second ultrasonic drive signals, or to cut off the power drive output. Stopping drive signal generation can be achieved by shutting down the signal generation circuit, stopping the timer PWM, disabling the DDS output, or shielding the drive clock. Cutting off the power drive output can be achieved by disabling the power drive chip enable pin, disconnecting the MOSFET, disconnecting the relay, or disabling the power management chip output.
[0085] The status control module performs a shutdown after confirming that the protective shutdown conditions have been released. Confirmation of release may include: both the first and second drive enable bits being invalid, the output current being lower than a preset current threshold, the bus voltage being lower than a preset voltage threshold, the non-volatile memory write being complete, and the load disconnection feedback signal being valid. If the protective shutdown conditions are not confirmed to be released within a preset time, the status control module may enter an abnormal rollback state and disable output.
[0086] In one optional implementation, the status control module generates an operation record after a run ends, is paused, stopped, or is shut down protectively. The operation record may include actual running time, actual output power of the first channel, actual output power of the second channel, highest operating surface temperature, average output power, number of load impedance anomalies, number of power fluctuations, parameter version number, candidate coordination timing type, and stop reason or exception code. If the communication module maintains a connection with an external configuration terminal, the status control module can send the operation record to the external configuration terminal for display or archiving; if not connected, it can be stored in non-volatile memory and uploaded when a connection is established later. In personal care or beauty penetration enhancement applications, the operation record can also be displayed to the user as a usage summary, such as displaying actual running time, highest temperature, the synchronous, alternating, or sequential coordination timing used, whether derating or pausing occurred, and parameter suggestions for the next use. The operation record can serve as the basis for subsequent parameter generation rule calibration, equipment maintenance, or recommended parameter updates from external configuration terminals. However, the operation record itself does not directly change the currently valid parameters. If a new parameter package needs to be generated based on the operation record, the external configuration terminal should still generate a confirmed parameter package, which will only take effect after going through the aforementioned parameter security update process.
[0087] When parameter generation rules require iterative optimization, the external configuration terminal or server can generate a rule calibration dataset based on runtime records. This dataset may include external medium characteristic parameters, target action status parameters, device capability parameters, actual collaborative timing type, actual output power of the first channel, actual output power of the second channel, actual runtime, temperature curve, impedance curve, number of power fluctuations, and feedback markers provided by the user within the authorized range. The external configuration terminal or server can adjust the thresholds or weights in the parameter generation rule version based on the rule calibration dataset and use the updated parameter generation rule version when generating new, confirmed parameter packages. The updated parameter packages still need to go through the aforementioned parameter security update process before they take effect.
[0088] The dual-channel ultrasonic drive module includes a signal generation circuit, a channel selection circuit, and a power drive circuit. The signal generation circuit generates a first reference signal and a second reference signal, respectively. The channel selection circuit controls the output timing of the first and second reference signals according to channel coordination timing parameters. The power drive circuit drives a first ultrasonic load and a second ultrasonic load, respectively.
[0089] The signal generation circuit can be implemented using a microcontroller timer PWM module, a direct digital synthesis circuit, a crystal oscillator frequency divider circuit, a programmable waveform generator, or a dedicated driver chip. The first and second reference signals can be square waves, sine waves, pulse waves, or modulated waves. If PWM is used, the state control module sets the timer period according to the first and second frequencies, and sets the comparison register according to the first and second duty cycles. If direct digital synthesis is used, the state control module generates a reference signal of the corresponding frequency based on the frequency control word.
[0090] The channel selection circuit can be implemented using analog switches, digital logic gates, timer output gates, driver chip enable terminals, relays, or MOSFET switches. The channel selection circuit determines when the first and second reference signals enter the power drive circuit based on synchronous, alternating, or sequential timing parameters. In synchronous mode, the channel selection circuit simultaneously opens the first and second channels; in alternating mode, it alternately opens the first and second channels at preset intervals; in sequential mode, it opens one channel first, and then opens the other channel based on the channel start-up delay or pre-output duration.
[0091] The power drive circuit amplifies the reference signal into an electrical signal capable of driving the ultrasonic load. The power drive circuit can employ a half-bridge drive, full-bridge drive, push-pull drive, or other power amplification structure capable of driving the ultrasonic load, and can be used in conjunction with boost, resonant matching, current detection, or overcurrent protection circuits. The first power drive branch is connected to the first ultrasonic load, and the second power drive branch is connected to the second ultrasonic load. The two branches can share a portion of the power supply circuit, or they can each have independent power supplies and independent drive chips.
[0092] In one specific implementation, the state control module outputs two PWM control signals to the signal generation circuit, which generates a first reference signal and a second reference signal, respectively. The channel selection circuit controls the gating of the two reference signals according to channel coordination timing parameters. The power drive circuit amplifies the gated reference signals and outputs them to the first and second ultrasonic loads, respectively. The feedback acquisition module synchronously acquires the output current, output voltage, output power feedback value, and load impedance, and returns the feedback results to the state control module.
[0093] To improve reliability, the dual-channel ultrasonic drive module can be equipped with hardware interlocks. These hardware interlocks are used to disable power drive output when the status control module is disabled, or to forcibly shut down the power drive circuit when a fault latch flag is valid. The hardware interlocks can be implemented using AND gates, latches, drive enable pins, or power switch circuits. Therefore, even if the software execution malfunctions, the dual-channel ultrasonic drive module will not output in an unauthorized state. In a personal care or beauty penetration enhancement application, the first reference signal, after being driven by the power drive, drives the ultrasonic atomizing plate, causing the external medium to form an atomized output. The second reference signal, after being driven by the power drive, drives the ultrasonic transducer, causing it to output ultrasonic energy to the action surface. The above hardware structure is still controlled by the currently valid parameters, and new parameters must undergo the aforementioned parameter security update process before taking effect.
[0094] Through the cooperation of the above-mentioned signal generation circuit, channel selection circuit and power drive circuit, the dual-channel ultrasonic drive module can generate two independent and collaboratively controllable ultrasonic drive signals according to the current effective parameters, and provide a hardware foundation for parameter safe updating, timing control and feedback anomaly handling.
[0095] like Figure 2 As shown, another embodiment of the present invention provides a dual-channel ultrasonic parameter safe update control method. This method can be executed by the aforementioned dual-channel ultrasonic parameter safe update control system, or by a controller having a communication interface, non-volatile memory, power trigger detection interface, dual-channel ultrasonic drive interface, and feedback acquisition interface. The controller can be a microcontroller, digital signal processor, system-on-a-chip, or other processor capable of executing control programs.
[0096] In one implementation, the method includes the following steps:
[0097] S1: The controller receives the confirmed parameter packet sent by the external configuration terminal through the communication interface and parses the parameter packet. During parsing, the controller reads the fields in the parameter packet according to the preset communication protocol, obtaining at least the first channel output parameters, the second channel output parameters, the channel coordination timing parameters, and the security boundary parameters. If the parameter packet also includes the device model identifier, parameter version number, data length, timestamp, integrity check code, confirmation flag, parameter generation rule version, or candidate timing score value, the controller synchronously reads the above fields and temporarily stores them in the parameter buffer.
[0098] S2: The controller performs integrity verification, device compatibility verification, and safety boundary verification on the parameter package. Integrity verification can be achieved by recalculating the checksum and comparing it with the integrity checksum carried in the parameter package; device compatibility verification can be achieved by determining whether the device model identifier, hardware version number, or load configuration identifier matches the current dual-channel ultrasonic output device; safety boundary verification can be achieved by determining whether the first channel output parameters, the second channel output parameters, and the channel coordination timing parameters fall within a preset allowable range or a preset allowable set. If the parameter package contains candidate timing score values, the controller can also determine whether the channel coordination timing parameters correspond to the candidate coordination timing that meets the preset safety margin conditions and has the highest candidate timing score value, according to the aforementioned candidate timing score verification method.
[0099] S3: After the integrity check, device compatibility check, and security boundary check all pass, the controller writes the parameter packet to the activation parameter area of the non-volatile memory and records the activation flag. The writing process can use a transactional writing method, that is, first write the parameter packet body, then write the integrity check code or digest information, then write the update status flag, and finally write the activation flag. After the writing is completed, the controller can perform a post-write read verification to confirm that the data in the activation parameter area is consistent with the data to be written.
[0100] S4: After the parameter package is written to the parameter area to be activated and the activation flag is recorded, the controller controls the dual-channel ultrasonic output device to shut down. If the device is in output mode at this time, the controller can first stop generating the first and second ultrasonic drive signals, or cut off the power drive output, and then execute the shutdown only after confirming that the protective shutdown conditions such as drive energy release, storage write submission, or load disconnection have been released. After shutdown, the parameter package in the parameter area to be activated is only saved as parameters to be confirmed and is not yet used as the basis for output control.
[0101] S5: Before the next detection of a local start-up trigger signal from the power trigger unit, the controller will not use the parameter package in the parameter area to be activated as the basis for output control. That is to say, even if the external configuration terminal has sent and written a new parameter package, the controller will not generate the first ultrasonic drive signal and the second ultrasonic drive signal according to the new parameter package if a local start-up trigger has not occurred.
[0102] S6: When the controller detects that the power trigger unit has generated a local start trigger signal, the controller performs a power-on self-test. The power-on self-test may include power supply voltage detection, non-volatile memory read detection, activation flag detection, drive module enable status detection, and feedback acquisition interface status detection. After the power-on self-test passes, the controller switches the parameter package in the activation parameter area to the currently valid parameters and generates the first and second ultrasonic drive signals according to the currently valid parameters. Parameter switching can be performed using copy switching, pointer switching, or valid flag switching, as long as the controller can clearly identify the parameters on which the current output control is based after the switching is completed.
[0103] S7: If integrity verification, device adaptation verification, security boundary verification, power-on self-test, or parameter switching fails, the controller retains the old parameters or factory default parameters in the currently valid parameter area and prohibits the generation of the first and second ultrasonic drive signals according to the parameter package in the parameter area to be activated. If valid old parameters exist in the currently valid parameter area, the old parameters will continue to be used; if no valid old parameters exist, the factory default parameters will be used; if the factory default parameters are also unavailable, the controller will disable dual-channel output and enter an abnormal state.
[0104] S8: If no new confirmed parameter package is received and the activation flag is inactive, the controller will enter the offline startup process if it detects a local startup trigger signal. During the offline startup process, the controller reads the old parameters from the currently valid parameter area; if no old parameters exist in the currently valid parameter area, it reads the factory default parameters and generates the first and second ultrasonic drive signals according to the read old parameters or the factory default parameters. This offline startup process does not require real-time participation from an external configuration terminal and is suitable for situations where the device is not connected to an external configuration terminal or has not received a new parameter package.
[0105] S9: During the operation of the dual-channel ultrasonic output device, the controller collects operational feedback signals. These signals may include the operating surface temperature, load impedance, output current, output voltage, output power feedback value, or operating duration. The controller compares the collected operational feedback signals with the corresponding safety boundary parameters. When the operational feedback signal is abnormal, it executes derating output, pauses output, disables output, or stops output. Derating output can reduce the power of the first or second channel, reduce the duty cycle, or shorten the output duration; pausing output can temporarily shut down both channels and resume operation after the feedback signal recovers; disabling output can lock the fault state and wait for reset or reauthorization; stopping output can terminate the current operation and shut down the power drive output.
[0106] The above method establishes a physical start confirmation interval between parameter updates and parameter execution, preventing new parameter packets sent by the external configuration terminal from directly changing the dual-channel ultrasound output status. At the same time, through verification, activation pending, rollback, and feedback protection, the risk of unexpected output caused by parameter errors, parameter mutations, or operational abnormalities is reduced.
[0107] Embodiments of the present invention also provide a computer-readable storage medium. The computer-readable storage medium stores a computer program, which, when executed by a processor, implements the above-described dual-channel ultrasound parameter security update control method.
[0108] Computer-readable storage media can be non-volatile memory, read-only memory, flash memory, EEPROM, FRAM, memory cards, solid-state memory, or other storage media capable of storing program instructions and being read by a processor. The processor can be a state control module in a dual-channel ultrasonic output device, or a controller connected to the dual-channel ultrasonic output device. The computer program can be stored in the form of firmware, embedded programs, control tasks, state machine programs, or multiple functional modules.
[0109] In one implementation, the computer program includes a receiving and parsing segment, a verification segment, a pending activation writing segment, a startup confirmation segment, a parameter switching segment, an offline startup segment, a feedback protection segment, and an exception rollback segment. The receiving and parsing segment controls the communication interface to receive confirmed parameter packets sent by an external configuration terminal and calls the configuration data interface to parse the parameter packet fields. The verification segment performs integrity verification, device compatibility verification, and security boundary verification. The pending activation writing segment, after all three verifications pass, writes the parameter packet to the pending activation parameter area of non-volatile memory and records the pending activation flag. The startup confirmation segment detects the local startup trigger signal generated by the power trigger unit and performs a power-on self-test upon detection. The parameter switching segment, after the power-on self-test passes, switches the parameter packet in the pending activation parameter area to the currently valid parameters. The offline startup segment, when no new confirmed parameter packet is received and the pending activation flag is inactive, generates dual-channel ultrasonic drive signals according to the old parameters in the currently valid parameter area or the factory default parameters. The feedback protection program segment is used to collect the working feedback signal and execute derating output, pause output, disable output, or stop output when the working feedback signal is abnormal. The abnormal rollback program segment is used to maintain the old parameters or factory default parameters when verification, power-on self-test, or parameter switching fails, and to prevent the generation of the first ultrasonic drive signal and the second ultrasonic drive signal according to the parameter package in the parameter area to be activated.
[0110] In an embedded implementation, the above program can be divided into initialization tasks, communication tasks, parameter update tasks, startup detection tasks, drive control tasks, and feedback monitoring tasks. The initialization task reads the currently valid parameter area, the parameter area to be activated, and related flag bits after the device is powered on; the communication task is responsible for receiving data sent by the external configuration terminal; the parameter update task is responsible for parsing, verifying, and writing data to the parameter area to be activated; the startup detection task is responsible for identifying the local startup trigger signal and the power-on self-test result; the drive control task is responsible for generating the first and second ultrasonic drive signals based on the currently valid parameters; and the feedback monitoring task is responsible for collecting working feedback signals and triggering derating, pause, disable, or stop output.
[0111] In another implementation, the above program can be stored and run as a state machine. The state machine includes at least the following states: parameter receiving state, verification state, pending activation write state, output disabled state, start confirmation state, parameter activation state, offline start state, and exception rollback state. When the processor executes the state machine program, it switches between these states based on the communication reception result, verification result, pending activation flag, local start trigger signal, power-on self-test result, and feedback exception result, thereby realizing the above dual-channel ultrasonic parameter safe update control method.
[0112] When a computer program executes, it can call the memory read / write interface, communication interface, timer interface, analog-to-digital converter interface, drive enable interface, and fault latch interface. The memory read / write interface is used to read or write the currently valid parameter area, the parameter area to be activated, the activation flag, the update status flag, and the rollback flag; the communication interface is used to receive confirmed parameter packets or upload running records; the timer interface is used to generate the first and second reference control signals; the analog-to-digital converter interface is used to read temperature, current, voltage, impedance, or power feedback signals; the drive enable interface is used to control the enabling or disabling of the dual-channel ultrasonic drive module; and the fault latch interface is used to maintain an output-prohibited state when feedback is abnormal or verification fails.
[0113] By storing the above program in a computer-readable storage medium, the processor can execute the dual-channel ultrasonic parameter security update control method without changing the hardware structure, thereby realizing the secure reception, secure storage, delayed activation, local startup confirmation, failure rollback, and feedback protection of parameter packets.
[0114] In summary, this invention can securely separate the receiving, storage, activation, and execution processes of dual-channel ultrasonic parameters, preventing new parameters from directly participating in output control after being received. At the same time, it provides rollback and protection processing in case of start-up confirmation, parameter switching failure, and abnormal operation feedback, thereby improving the security, execution reliability, and operational stability of parameter updates for dual-channel ultrasonic output devices.
[0115] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any person skilled in the art can easily conceive of various variations or substitutions within the technical scope disclosed in this application, and these should all be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A dual-channel ultrasonic parameter safety update control system, used to control a dual-channel ultrasonic output device having a first ultrasonic load and a second ultrasonic load, characterized in that, It includes a communication module, a configuration data interface, a non-volatile memory, a power trigger unit, a dual-channel ultrasonic drive module, a status control module, and a feedback acquisition module. The non-volatile memory includes a currently valid parameter area and a parameter area to be activated. The communication module is used to receive the confirmed parameter packet sent by the external configuration terminal, and the configuration data interface is used to parse the parameter packet and provide the parsing result to the status control module; the parameter packet includes first channel output parameters, second channel output parameters, channel coordination timing parameters and security boundary parameters; The state control module performs integrity verification, device compatibility verification, and security boundary verification on the parameter package. After all three verifications pass, the parameter package is written into the parameter area to be activated and the activation flag is recorded. The module also controls the dual-channel ultrasonic output device to shut down. Before the power trigger unit generates a local start trigger signal, the parameter package in the parameter area to be activated is not used as the basis for output control. After the power trigger unit generates a local start trigger signal and completes the power-on self-test, the parameter package in the parameter area to be activated is switched to the currently valid parameters. The module also controls the dual-channel ultrasonic drive module to generate the first ultrasonic drive signal and the second ultrasonic drive signal according to the currently valid parameters. When verification, power-on self-test or parameter switching fails, retain the old parameters or factory default parameters in the current valid parameter area, and prohibit outputting the parameter package in the parameter area to be activated; The feedback acquisition module is used to acquire work feedback signals, and the status control module performs derating, pausing, prohibiting or stopping output when the work feedback signal is abnormal.
2. The dual-channel ultrasonic parameter safety update control system according to claim 1, characterized in that, The first channel output parameters include at least one of a first frequency, a first power, a first duty cycle, a first duration, or a first power correction coefficient; the second channel output parameters include at least one of a second frequency, a second power, a second duty cycle, a second duration, or a second power correction coefficient; the channel coordination timing parameters include at least one of synchronous output parameters, alternating output parameters, sequential output parameters, simultaneous start / stop flags, channel start delay, first channel pre-output duration, second channel delayed output duration, single-cycle output duration, alternation interval, or number of cycles; wherein, the synchronous output parameters are used to control the first ultrasonic load and the second ultrasonic load to output simultaneously, the alternating output parameters are used to control the first ultrasonic load and the second ultrasonic load to output alternately at a preset interval, and the sequential output parameters are used to control the first ultrasonic load and the second ultrasonic load to output sequentially in a preset order.
3. The dual-channel ultrasonic parameter safety update control system according to claim 1, characterized in that, The safety boundary parameters include at least one of the following: power limit, frequency allowable range, duty cycle limit, single run duration limit, temperature limit, load impedance threshold, load impedance allowable range, current limit, voltage limit, power deviation threshold, first channel rated output limit, or second channel rated output limit; the operating feedback signal includes at least one of the following: operating surface temperature, load impedance, output current, output voltage, output power feedback value, or operating duration; when the operating surface temperature, output current, output voltage, output power feedback value, or operating duration reaches or exceeds the corresponding limit, or the load impedance is not within the load impedance allowable range, or the deviation of the output power feedback value from the set output power exceeds the power deviation threshold, the operating feedback signal is determined to be abnormal.
4. The dual-channel ultrasonic parameter safety update control system according to claim 1, characterized in that, The parameter package also includes device model identifier, parameter version number, data length, timestamp, integrity check code, confirmation flag, parameter generation rule version, and candidate time series score value; The candidate timing score value is calculated by the external configuration terminal according to the preset score rule corresponding to the parameter generation rule version. The status control module verifies on the device side whether the candidate timing score value is consistent with the parameter generation rule version. The preset scoring rules include: ;in, Indicates the first Candidate timing score values for candidate cooperative timing sequences, wherein the candidate cooperative timing sequences include synchronous cooperative timing sequences, alternating cooperative timing sequences, or sequential cooperative timing sequences; Based on the adaptation score; This is a safety margin penalty item; To switch risk penalty items; and Preset weights; The device compatibility verification includes determining whether the device model identifier matches the dual-channel ultrasound output device. The safety boundary verification includes determining whether the first channel output parameters, the second channel output parameters, and the channel coordination timing parameters all belong to the corresponding preset allowable range or preset allowable set, and determining whether the channel coordination timing parameters correspond to the candidate coordination timing that meets the preset safety margin condition and has the highest candidate timing score.
5. The dual-channel ultrasonic parameter safety update control system according to claim 1, characterized in that, The parameter area to be activated also stores an update status flag and a rollback flag; after the parameter package is written, the status control module sets the update status flag to the pending start confirmation state and sets the pending activation flag to valid; after the parameter switching is completed, the update status flag is set to the activated state and the pending activation flag is cleared. When verification, power-on self-test, or parameter switching fails, the update status flag is set to an abnormal rollback state according to the rollback flag, and the activation flag is set to an inactive state.
6. The dual-channel ultrasonic parameter safety update control system according to claim 1, characterized in that, The state control module includes an update state machine, which includes at least a parameter receiving state, a verification state, a pending activation write state, an output prohibition state, a start confirmation state, a parameter activation state, an offline start state, and an abnormal rollback state. The update state machine only enters the parameter activation state from the start confirmation state after detecting the local start trigger signal generated by the power trigger unit and completing the power-on self-test. If no new confirmed parameter package is received and the activation flag is inactive, if the local startup trigger signal is detected, the system enters the offline startup state and generates the first and second ultrasonic drive signals according to the old parameters in the current valid parameter area or the factory default parameters.
7. The dual-channel ultrasonic parameter safety update control system according to claim 1, characterized in that, When the dual-channel ultrasonic output device is in output state when the parameter packet is received, or when at least one protective shutdown condition exists, such as drive energy release, storage write submission, or load disconnection confirmation, the status control module controls the dual-channel ultrasonic drive module to stop generating the first ultrasonic drive signal and the second ultrasonic drive signal or cut off the power drive output before controlling the dual-channel ultrasonic output device to shut down, and performs shutdown after confirming that the protective shutdown condition is lifted.
8. The dual-channel ultrasonic parameter safety update control system according to claim 1, characterized in that, The dual-channel ultrasonic drive module includes a signal generation circuit, a channel selection circuit, and a power drive circuit. The signal generation circuit generates a first reference signal and a second reference signal, respectively. The channel selection circuit controls the output timing of the first reference signal and the second reference signal according to the channel coordination timing parameters. The power drive circuit drives the first ultrasonic load and the second ultrasonic load, respectively.
9. A method for safe updating and controlling dual-channel ultrasonic parameters, characterized in that, include: The system receives and parses a confirmed parameter packet sent by an external configuration terminal. The parameter packet includes first channel output parameters, second channel output parameters, channel coordination timing parameters, and security boundary parameters. Perform integrity checks, device compatibility checks, and security boundary checks on the parameter package; After all three types of verifications pass, the parameter package is written into the activation parameter area of the non-volatile memory and the activation flag is recorded, and the dual-channel ultrasonic output device is powered off. Before the next detection of a local start-up trigger signal generated by the power trigger unit, the parameter package in the parameter area to be activated will not be used as the basis for output control; After detecting that the power trigger unit generates a local start trigger signal and completes the power-on self-test, the parameter package in the parameter area to be activated is switched to the currently valid parameters, and the first ultrasonic drive signal and the second ultrasonic drive signal are generated according to the currently valid parameters. When verification, power-on self-test or parameter switching fails, the old parameters or factory default parameters in the current valid parameter area are retained, and the generation of the first ultrasonic drive signal and the second ultrasonic drive signal according to the parameter package in the parameter area to be activated is prohibited. If no new confirmed parameter package is received and the activation flag is in an inactive state, if the local start trigger signal is detected, the first ultrasonic drive signal and the second ultrasonic drive signal are generated according to the old parameters in the current valid parameter area or the factory default parameters. Collect work feedback signals, and when the work feedback signals are abnormal, perform derating output, pause output, disable output, or stop output.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the dual-channel ultrasound parameter security update control method as described in claim 9.