Electric vehicle power on / off state machine control method with interrupt fault tolerance and bidirectional jump

CN122539896APending Publication Date: 2026-08-11ANHUI JIANGHUAI AUTOMOBILE GRP CORP LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-05-09
Publication Date
2026-08-11

AI Technical Summary

Technical Problem

[0003]然而,现有的上下电控制方法中,直接采用单向线性状态机架构,并没有针对快速上下电极限工况的中断容错与双向跳转机制

Benefits of technology

[0017]本发明实施例的具有以下有益效果:有效解决了快速上下电工况下状态机易死锁的问题,实现了流程的安全中断、双向跳转与断点恢复;显著减少了硬件冲击并缩短上电时间,同时通过双核锁步校验满足了高等级功能安全要求。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122539896A_ABST
    Figure CN122539896A_ABST
Patent Text Reader

Abstract

This invention discloses a power-on / off state machine control method for electric vehicles with interrupt fault tolerance and bidirectional jump capabilities. The method includes: constructing a two-layer state machine architecture that distinguishes between steady-state and transient states; setting execution, interrupt suspension, rollback, and recovery sub-states in the transient state; interrupting the process and saving on-site data when receiving reverse instructions during execution; and implementing state rollback or recovery through safety checks; and simultaneously combining an independent safety monitoring unit to perform real-time verification and anomaly handling for state switching and main state jumps. This invention, by introducing an interrupt fault tolerance mechanism, bidirectional jump capability, and dual-core safety monitoring, achieves safe and controllable switching and flexible transitions during the power-on / off process, solving problems in existing technologies such as uninterrupted power-on / off processes, easy system anomalies due to misoperation, and transient state jamming.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of vehicle power-on / off control technology, and in particular to a power-on / off state machine control method for electric vehicles with interrupt fault tolerance and bidirectional jump. Background Technology

[0002] Power-on / off control of pure electric vehicles, as a core component of vehicle functional safety and user experience, is widely used in the new energy mobility field. With the development of vehicle electronic architecture towards domain control, related technologies have constructed a comprehensive control system covering low-voltage wake-up, high-voltage pre-charging, main circuit closure, and hibernation discharge through the collaborative operation of the vehicle controller, battery management system, and motor controller. Specifically, this system relies on controller area network communication and linear state machine logic, strictly adhering to functional safety standards to achieve orderly linkage of multiple components.

[0003] However, existing power-on / off control methods directly employ a unidirectional linear state machine architecture, lacking interruption tolerance and bidirectional jump mechanisms for extreme conditions of rapid power-on / off operation. Due to the lack of suspension and safe rollback strategies for reverse instructions in the transition state, frequent user operations during the pre-charge or discharge phases can easily lead to state machine logic deadlock, high-voltage contactor switching under load, and repeated hardware impacts. This not only causes the entire vehicle to become unresponsive or require power-off reset but also severely accelerates the lifespan degradation of critical components, making it difficult to meet high-level functional safety requirements. Summary of the Invention

[0004] The main objective of this invention is to provide a power-on / off state machine control method for electric vehicles with interrupt fault tolerance and bidirectional jump.

[0005] To achieve the above objectives, embodiments of the present invention propose a power-on / off state machine control method for electric vehicles with interrupt fault tolerance and bidirectional jump, comprising:

[0006] Construct a two-layer state machine architecture containing multiple main states, and divide each main state into an execution sub-state, an interruption / suspension sub-state, a rollback sub-state, and a recovery sub-state, where the main state is distinguished between a steady state and a transitional state; During the execution sub-state of the state machine in the transition state, if a reverse power-on / off command is received, the process switches to the interrupt suspension sub-state to pause the current process and save the field data, while prohibiting the execution of irreversible high-voltage operations. The interrupt command is subjected to safety verification. If the verification passes, the system switches to the rollback sub-state and performs a safety rollback operation to roll back the vehicle state to the previous safe steady state. Alternatively, when a forward recovery command is received, the system switches to the recovery sub-state and continues the current process from the interruption point based on the saved field data. An independent safety monitoring unit is used to perform real-time verification of the sub-state transitions and main state jumps of the state machine. If the state machine is detected to be stuck in the transition state or the verification is inconsistent, an automatic reset is triggered or the state machine is jumped to a fault-safe steady state.

[0007] In one embodiment of the present invention, the construction of a two-layer state machine architecture comprising multiple main states divides each main state into an execution sub-state, an interruption / suspension sub-state, a rollback sub-state, and a recovery sub-state, wherein the main states distinguish between steady states and transitional states, including: S0 sleep steady state, S2 low-voltage self-test steady state, S4 high-voltage closed steady state, S5 operation-ready steady state and S8 fault-safe steady state are defined as steady state nodes that can be safely rolled back; Define S1 low-voltage wake-up transition state, S3 precharge request transition state, S6 high-voltage discharge transition state and S7 low-voltage sleep transition state as transition state nodes that are currently being executed and cannot be interrupted arbitrarily; For each of the transition states in S1 low-voltage wake-up transition state, S3 precharge request transition state, S6 high-voltage discharge transition state and S7 low-voltage sleep transition state, respectively configure an execution sub-state for performing the core functions of the current main state, an interruption suspension sub-state for pausing the process when a reverse instruction is received, a rollback sub-state for performing rollback operations after safety verification, and a recovery sub-state for continuing execution from the interruption point when a forward recovery instruction is received.

[0008] In one embodiment of the present invention, during the execution sub-state operation of the state machine in a transitional state, if a reverse power-on / off command is received, the process switches to an interruption / suspend sub-state to pause the current process and save the current data, while simultaneously prohibiting irreversible high-voltage operations, including: When the state machine is in the execution sub-state of the S3 precharge request transition state and receives a user active power-down command or an emergency safety power-down command, it immediately switches from the execution sub-state to the interruption suspension sub-state, suspends the process of sending precharge commands to the battery management system, saves the current bus voltage value, contactor opening and closing status and precharge progress parameters, and prohibits irreversible high-voltage operations such as closing or opening of the high-voltage main circuit contactor. When the state machine is in the execution sub-state of the S6 high voltage discharge transition state and receives the user's active power-on command, it immediately switches from the execution sub-state to the interruption suspension sub-state, suspends the process of sending the torque zeroing command to the motor controller and the discharge command to the active discharge unit, saves the current bus voltage discharge progress and contactor disconnection status, and prohibits the execution of the high voltage contactor's re-disconnection action or the pre-charge contactor's closing action.

[0009] In one embodiment of the present invention, when the state machine is in the execution sub-state of the S3 precharge request transition state and receives a user-initiated power-down command or an emergency safety power-down command, it immediately switches from the execution sub-state to the interruption and suspension sub-state, suspends the process of issuing precharge commands to the battery management system, saves the current bus voltage value, contactor opening and closing status, and precharge progress parameters, and prohibits irreversible high-voltage operations such as closing or opening actions of the high-voltage main circuit contactor, including: After switching to the interrupt suspension sub-state, a tiered, variable-duration interrupt command validity confirmation window is initiated. If the interrupt command is detected to be valid within the fixed 150ms of the first-level short window or within the 200ms to 1000ms range of the second-level long window, it is determined to be the user's true operation intention and preparation is made to trigger the rollback sub-state. If the interrupt command is canceled or a new positive command is received within the confirmation window, it is determined to be a momentary accidental touch and preparation is made to trigger the recovery sub-state. This distinguishes between momentary accidental touches and the user's true operation intention to avoid abnormal state machine switching.

[0010] In one embodiment of the present invention, the step of performing a safety check on the interrupt command, and if the check passes, switching to the rollback sub-state to perform a safety rollback operation to roll back the vehicle state to the previous safe steady state, or switching to the recovery sub-state upon receiving a forward recovery command to continue the current process from the interruption point based on the saved field data, includes: If the interruption suspension sub-state of the state machine in the S3 precharge request transition state is verified by the independent safety monitoring unit, it will switch to the rollback sub-state, immediately disconnect the precharge contactor and start the active discharge unit to discharge the bus voltage to below 60V, then disconnect the main negative contactor and roll back the state machine to the execution sub-state of the S2 low voltage self-test steady state. If the interruption suspension sub-state of the state machine in the S6 high-voltage discharge transition state is verified by the independent safety monitoring unit, it will switch to the rollback sub-state, immediately stop the active discharge unit and close the main negative contactor, execute the secondary pre-charge process to re-establish the bus voltage to a stable value, and then roll back the state machine to the execution sub-state of the S4 high-voltage closing steady state.

[0011] In one embodiment of the present invention, if the interruption-suspended sub-state of the state machine in the S3 pre-charge request transition state passes the verification by the independent safety monitoring unit, then the state machine switches to the rollback sub-state, immediately disconnects the pre-charge contactor and starts the active discharge unit to discharge the bus voltage to below 60V, and then disconnects the main negative contactor and rolls the state machine back to the execution sub-state of the S2 low-voltage self-test steady state, including: During the execution of the rollback sub-state, the bus voltage drop curve is monitored in real time. When the bus voltage value is detected to be lower than the 60V threshold and the precharge contactor feedback signal is in the open state, the safe rollback operation is determined to be completed, the rollback completion flag is automatically generated, and the main state jump pointer is pointed to the S2 low-voltage self-test steady state. At the same time, the execution sub-state of the S2 low-voltage self-test steady state is initialized to wait for the next positive jump instruction.

[0012] In one embodiment of the present invention, if the interruption suspension sub-state of the state machine in the S6 high-voltage discharge transition state passes the verification by the independent safety monitoring unit, it switches to the rollback sub-state, immediately stops the operation of the active discharge unit and closes the main negative contactor, executes the secondary pre-charge process to re-establish the bus voltage to a stable value, and then rolls back the state machine to the execution sub-state of the S4 high-voltage closing stable state, including: During the secondary pre-charge process, the residual bus voltage value stored in the interrupted suspended state is read. If the residual voltage value is higher than the preset secondary pre-charge start threshold, the main positive contactor is closed directly. If the residual voltage value is lower than the preset secondary pre-charge start threshold, the pre-charge contactor is closed first to replenish the voltage. After the bus voltage stabilizes, the main positive contactor is closed and the pre-charge contactor is opened, completing the bidirectional jump from the S6 high-voltage discharge transition state to the S4 high-voltage closing steady state.

[0013] In one embodiment of the present invention, the construction of a two-layer state machine architecture comprising multiple main states, wherein each main state is divided into an execution sub-state, an interruption / suspension sub-state, a rollback sub-state, and a recovery sub-state, wherein the main states distinguish between steady states and transitional states, further includes: Establish an instruction priority interlock rule, setting the priority of emergency safety power-down instructions to be higher than user-initiated power-down instructions, user-initiated power-down instructions to be higher than user-initiated power-on instructions, user-initiated power-on instructions to be higher than charging wake-up power-on instructions, and charging wake-up power-on instructions to be higher than maintenance wake-up power-on instructions. High-priority instructions can interrupt the execution of low-priority instructions, while instructions of the same priority follow the first-in-first-out and closed-loop execution principle. The previous instruction of the same priority must be executed to a complete steady-state closed loop before the next instruction of the same priority can be executed.

[0014] In one embodiment of the present invention, the establishment of the instruction priority interlock rule, which sets the priority of the emergency safety power-down instruction to be higher than the user-initiated power-down instruction, the priority of the user-initiated power-down instruction to be higher than the user-initiated power-on instruction, the priority of the user-initiated power-on instruction to be higher than the charging wake-up power-on instruction, and the priority of the charging wake-up power-on instruction to be higher than the maintenance wake-up power-on instruction, allows high-priority instructions to interrupt the execution of low-priority instructions, while instructions of the same priority follow the first-in-first-out and closed-loop execution principle, requiring the previous instruction of the same priority to be executed to complete a steady-state closed loop before the next instruction of the same priority can be executed, further includes: Implement command debouncing and filtering rules, set an effective debouncing time of 50ms for KL15 hard-wired signals or one-key start signals, filter pulse signals with a duration of less than 50ms, and set the minimum trigger interval of the same type of command to 100ms, directly discarding repeated commands with a duration of less than 100ms to prevent command queue overflow. Implement a minimum state hold time rule, setting a minimum hold time of 100ms or more for the execution sub-states of each main state. Prohibit forward or reverse jumps of the main state before the minimum hold time is reached to avoid logical disorder.

[0015] In one embodiment of the present invention, the method of using an independent safety monitoring unit to perform real-time verification of the sub-state transitions and main state jumps of the state machine, and if it is detected that the state machine is stuck in the transition state or the verification is inconsistent, triggering an automatic reset or jumping the state machine to a fault-safe steady state, includes: It adopts a dual-core lockstep architecture with a main core control unit and an independent safety core unit. The main core control unit is responsible for executing the core control logic and timing scheduling of the state machine, while the independent safety core unit is responsible for the functional safety verification and anomaly monitoring of the entire process. The two use independent hardware and power supplies and do not depend on each other. The independent safety core unit synchronously collects power-on and power-off commands at the command receiving and verification node and compares the legality of the commands with the main core control unit. At the sub-state switching verification node, it performs pre-verification on the logic of switching from the execution sub-state to the interruption-suspended sub-state, switching from the interruption-suspended sub-state to the rollback sub-state, or restoring the sub-state. At the main state jump verification node, it independently verifies the jump conditions and state consistency between the nine main states. Among them, the independent safety core unit opens a graded variable-duration interrupt instruction validity confirmation window at the interrupt handling monitoring node, monitors in real time whether the state machine has successfully paused the process and whether irreversible operations are prohibited, and triggers rollback or recovery of sub-state according to the instruction status when the confirmation window ends; the independent safety core unit monitors the execution duration of the transition state in real time at the abnormal deadlock monitoring node. If the state machine is stuck in the transition state for more than 1 second or the state verification between the main core control unit and the independent safety core unit is inconsistent for more than 3 consecutive communication cycles, the main core control unit is determined to be abnormal.

[0016] When the independent safety core unit determines that the main core control unit is abnormal or detects a fatal fault such as a broken high-voltage interlock circuit or insulation resistance failure, it immediately enters the emergency fallback execution node. Within 50ms, it cuts off the high-voltage contactor drive power and disconnects all high-voltage contactors, locks the high-voltage system, and forces the state machine to jump to the S8 fault-safe steady state. When the independent safety core unit only detects that the state machine is stuck in the transition state for more than 1s but does not detect a fatal fault, it triggers a soft reset of the main core control unit's state machine, resets the state machine to the S0 sleep steady state, and re-executes the power-on and power-off procedures without requiring the user to manually disconnect the 12V battery.

[0017] The embodiments of the present invention have the following beneficial effects: they effectively solve the problem of state machine deadlock under rapid power-on and power-off conditions, realize safe interruption of the process, bidirectional jump and breakpoint recovery; significantly reduce hardware impact and shorten power-on time, and meet high-level functional safety requirements through dual-core lockstep verification. Attached Figure Description

[0018] The above-described and additional aspects and advantages of the present invention will become apparent and readily understood from the following description of the embodiments taken in conjunction with the accompanying drawings, in which: Figure 1 This is a flowchart of an electric vehicle power-on / off control method according to an embodiment of the present invention. Detailed Implementation

[0019] It should be noted that, unless otherwise specified, the embodiments and features described in the present invention can be combined with each other. The present invention will now be described in detail with reference to the accompanying drawings and embodiments.

[0020] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0021] Embodiments of the present invention are described in detail below, examples of which are illustrated in the accompanying drawings, wherein the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and intended to explain the present invention, and should not be construed as limiting the present invention.

[0022] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature. In the description of this invention, "a plurality of" means two or more, unless otherwise explicitly specified.

[0023] Any process or method description in the flowchart or otherwise herein can be understood as representing a module, segment, or portion of code comprising one or more executable instructions for implementing a particular logical function or process, and the scope of the preferred embodiments of the invention includes additional implementations in which functions may be performed not in the order shown or discussed, including substantially simultaneously or in reverse order depending on the functions involved, as will be understood by those skilled in the art to which embodiments of the invention pertain.

[0024] Figure 1 This is a flowchart of an electric vehicle power-on / off control method according to an embodiment of the present invention.

[0025] like Figure 1 As shown, the electric vehicle power-on / off control method includes the following steps: Step 1: Construct a two-layer state machine architecture containing multiple main states. Divide each main state into an execution sub-state, an interruption / suspension sub-state, a rollback sub-state, and a recovery sub-state. The main states are distinguished between steady state and transitional state.

[0026] In one embodiment of the present invention, a two-layer state machine architecture containing multiple main states is constructed, aiming to manage the complex state transitions and interruption tolerance requirements in the power-on and power-off process of electric vehicles through layered logic. The core of this architecture lies in decoupling the control flow into two levels: the main state that defines the macroscopic stage and the sub-state that implements microscopic behavioral control. The main state is divided into two categories, steady state and transitional state, based on whether the process is closed-loop and whether safe interruption is allowed, so as to clarify the control strategy and safety boundary of different stages.

[0027] Within each main state, four functional modes are further configured: execution sub-state, interruption suspension sub-state, rollback sub-state, and recovery sub-state. These correspond to four control behaviors: normal process advancement, abnormal instruction pause, safety logic rollback, and breakpoint resumption. This endows the state machine with the ability to respond to reverse instructions and perform bidirectional jumps at any stage of operation, breaking through the limitation of unidirectional sequential execution of traditional linear state machines.

[0028] As a specific implementation method, the vehicle power-on and power-off process can be divided into multiple main states such as hibernation, low-voltage wake-up, self-test, pre-charge, high-voltage closure, operation ready, high-voltage discharge, and low-voltage hibernation. In critical transition states such as pre-charge request or high-voltage discharge, the interruption suspension sub-state is used to temporarily store field data. The system can be safely reset to the previous steady state by rolling back the sub-state, or the execution can continue from the interruption point by restoring the sub-state, thereby realizing the interruption-tolerant control of the entire process.

[0029] This two-layer state machine architecture effectively solves the technical problem of state machine jamming under rapid power-on and power-off conditions by distinguishing between steady state and transition state and coordinating four types of sub-states. It realizes flexible bidirectional jump and breakpoint recovery of the process, significantly reduces the number of repeated impacts on high-voltage components, and improves the system's response speed and operational reliability.

[0030] Step 2: During the execution sub-state of the state machine in the transition state, if a reverse power-on / off command is received, switch to the interrupt suspension sub-state to pause the current process and save the field data, while prohibiting the execution of irreversible high-voltage operations.

[0031] During the power-on / off control of electric vehicles, when the two-layer state machine architecture operates to a transitional state that is distinct from the steady state and is in the execution sub-state, the system needs to have an immediate response to reverse power-on / off commands and an interruption fault tolerance mechanism.

[0032] The core of this step lies in establishing a state suspension strategy. Once a control instruction opposite to the current execution direction is captured during the transitional process before it is closed, the state machine immediately switches from the execution sub-state to the interrupt suspension sub-state. During this switch, the primary execution flow of the control logic is paused, the current timing progression is frozen, and all field data, including hardware switch states, bus voltage values, and internal register parameters, are fully saved to ensure the integrity of the context information.

[0033] More importantly, after entering the interrupt suspend state, the system forcibly locks all irreversible high-voltage operation execution permissions, physically blocking actions that may cause electrical shocks or logical conflicts, such as the closing or opening of high-voltage contactors and the enabling or shutting down of IGBTs. This creates a safe isolation zone within the transient window of instruction conflict, preventing hardware damage caused by forced process jumps or terminations.

[0034] As a specific implementation method, when the state machine is in the execution sub-state of the precharge request transition state or the high voltage discharge transition state, if a reverse instruction is received, the controller immediately suspends the current precharge or discharge process, records the current bus voltage and contactor status, and prohibits the execution of the main circuit switching operation, waiting for the subsequent safety verification results to determine the backtracking or recovery path.

[0035] This step, by introducing an interrupt suspending sub-state and a state saving mechanism, effectively solves the logic deadlock problem caused by the inability of traditional linear state machines to handle mid-process reverse instructions under rapid power-on and power-off conditions. Its strategy of immediately prohibiting irreversible high-voltage operations in the transition state fundamentally eliminates the risk of burn-in and adhesion caused by contactor switching under load, significantly reducing hardware impact and laying the necessary state foundation for subsequent safe bidirectional switching and breakpoint recovery.

[0036] Step 3: Perform a safety check on the interrupt command. If the check passes, switch to the rollback sub-state and perform a safety rollback operation to roll back the vehicle state to the previous safe steady state. Alternatively, when a forward recovery command is received, switch to the recovery sub-state and continue the current process from the interruption point based on the saved field data.

[0037] After suspending the process in the interrupted state and saving the field data, the system needs to perform a safety check on the interruption command to determine whether the current operating environment of the vehicle allows the execution of state rollback or process recovery operations. This safety check process aims to distinguish between transient interference signals and the user's continuous and valid operating intentions, ensuring the legality of the state machine transition logic and the safety of the high-voltage system.

[0038] If the safety check confirms that the interrupt command is valid and the rollback conditions are met, the state machine will switch to the rollback sub-state and perform a targeted safety rollback operation. By reverse-controlling the high-voltage execution module, the vehicle state will be safely transferred to the previous safe steady state, thereby avoiding logical conflicts or hardware damage caused by forced jumps in the transition state. Conversely, if a forward recovery command is received within the interrupt waiting window and passes the safety check, the state machine will switch to the recovery sub-state, call the previously saved field data, and seamlessly continue the execution flow of the current main state from the interrupt point without re-initializing or repeating the completed previous steps.

[0039] As a specific implementation method, safety verification may include hierarchical confirmation of the duration of the instruction. For example, a first-level short window may be set to filter out momentary accidental touches, or a second-level long window may be set to accommodate scenarios where the user actively cancels the operation. The fallback sub-state is triggered to perform contactor disconnection or bus discharge operation only when the instruction remains valid within the window period, or the recovery sub-state is triggered to continue the pre-charging process when the instruction is canceled.

[0040] This step introduces a bidirectional branch decision-making mechanism based on safety verification, enabling the state machine to respond flexibly and control in abnormal interruption scenarios. It ensures that the state machine can quickly return to a safe steady state to eliminate high voltage risks under dangerous conditions, and also supports continuing execution from the breakpoint when the instruction is restored. This significantly reduces unnecessary repeated hardware actions and process restart time, and effectively improves the robustness, response speed, and service life of key electrical components in power-on and power-off control.

[0041] Step 4: Use an independent safety monitoring unit to perform real-time verification of the sub-state transitions and main state jumps of the state machine. If the state machine is detected to be stuck in the transition state or the verification is inconsistent, an automatic reset is triggered or the state machine is jumped to a fault-safe steady state.

[0042] In this embodiment of the invention, an independent security monitoring unit is used to perform real-time verification of sub-state transitions and main state jumps of the state machine, aiming to ensure the functional safety and reliability of the control logic through a redundant architecture. The core of this step lies in building a monitoring mechanism independent of the main control logic, which continuously collects the state machine's operating data, instruction signals, and hardware feedback, and independently performs legality and consistency verification when each sub-state transition request or main state jump condition is triggered.

[0043] The real-time verification encompasses instruction priority determination, compliance checks of state transition logic, and comparison of dual-core computation results. The state machine is only allowed to execute the corresponding state transition when the monitoring unit confirms that the verification has passed. If the execution time of the state machine in the transition state exceeds a preset threshold and exhibits a stuck characteristic, or if the verification results of the monitoring unit and the main control unit are inconsistent within a continuous period, an anomaly handling mechanism is immediately triggered. This mechanism includes an automatic soft reset of the main control unit to reset the state machine to its initial steady state, or, upon detecting a fatal safety risk, forcibly transitioning the state machine to a fault-safe steady state, thereby cutting off the high-voltage circuit and locking the system.

[0044] As one implementation method, the independent safety monitoring unit can use a safety core that is hardware isolated from the main control unit. Before the sub-state switches from the execution state to the interruption suspension state, or the main state jumps from the precharge request state to the high voltage closed steady state, a communication delay margin is reserved for double verification. If the transition state is stuck for more than 1 second or the verification is inconsistent for three consecutive communication cycles, the safety core directly takes over the control and executes an emergency power-off.

[0045] By introducing a real-time verification and automatic anomaly reset mechanism through an independent safety monitoring unit, this step effectively identifies and prevents state machine deadlocks caused by logical errors or hardware failures, ensuring that the vehicle still meets high-level functional safety requirements under extreme conditions such as rapid power-on and power-off. This approach not only avoids the risk of high-voltage components switching on and off under load due to state machine malfunctions but also eliminates the need for manual power-off reset, significantly improving system robustness and user experience.

[0046] Example 2 Based on the above embodiments, this embodiment provides a detailed description of the specific implementation of step 1 in the electric vehicle power-on / off control method: "Constructing a two-layer state machine architecture containing multiple main states, dividing each main state into an execution sub-state, an interruption / suspend sub-state, a rollback sub-state, and a recovery sub-state, wherein the main states distinguish between steady state and transitional state".

[0047] In this embodiment, when constructing a two-layer state machine architecture, the main state is first clearly divided into two types of nodes: steady state and transition state.

[0048] Specifically, S0 sleep steady state, S2 low-pressure self-test steady state, S4 high-pressure closing steady state, S5 running ready steady state, and S8 fault-safe steady state are defined as steady state nodes that can be safely rolled back. In these states, the vehicle's high-pressure circuit is in a stable closed or completely open state. At the same time, S1 low-pressure wake-up transition state, S3 pre-charge request transition state, S6 high-pressure discharge transition state, and S7 low-pressure sleep transition state are defined as transition state nodes that are being executed and cannot be interrupted arbitrarily.

[0049] For each of the four transition states mentioned above, an execution sub-state, an interruption suspension sub-state, a rollback sub-state, and a recovery sub-state are configured respectively. Taking the S3 precharge request transition state as an example, its input sources are the precharge command received by the VCU and the status feedback of the high-voltage components. The processing action is to send a precharge command to the battery management system and monitor the bus voltage rise curve in the execution sub-state. The output result is a precharge completion signal or a jump request to enter the next steady state. When the state machine is in the execution sub-state of the S3 precharge request transition state and receives a user active power-down command or an emergency safety power-down command, it immediately switches from the execution sub-state to the interrupt suspension sub-state. At this time, the input source is a high-priority reverse power-up / down command. The processing action includes pausing the process of sending the precharge command to the battery management system, saving the current bus voltage value, contactor opening and closing status, and precharge progress parameters to non-volatile memory, and logically locking the closing or opening drive signal of the high-voltage main circuit contactor to prevent irreversible high-voltage operation. The output result is the state machine suspension flag and the queue of interrupt events to be processed.

[0050] Similarly, when the state machine is in the execution sub-state of the S6 high-voltage discharge transition state and receives the user's active power-on command, the input source is the user's active power-on command, the processing action is to pause the issuance of the torque zeroing command to the motor controller and the discharge command to the active discharge unit, save the current bus voltage discharge progress and contactor disconnection status, prohibit the re-disconnection of the high-voltage contactor or the closing of the pre-charge contactor, and the output result is the suspended status and the snapshot of the field data.

[0051] Furthermore, the architecture establishes an instruction priority interlocking rule. The input sources are various wake-up and power-down signals. The processing action is to compare instruction priorities, setting the priority of emergency safety power-down instructions to be higher than user-initiated power-down instructions, user-initiated power-down instructions to be higher than user-initiated power-on instructions, user-initiated power-on instructions to be higher than charging wake-up power-on instructions, and charging wake-up power-on instructions to be higher than maintenance wake-up power-on instructions. High-priority instructions can interrupt the execution of low-priority instructions. Instructions of the same priority follow the first-in-first-out and closed-loop execution principle, that is, the previous instruction of the same priority must be executed to a complete steady-state closed loop before the next instruction of the same priority can be executed. The output result is a unique valid sequence of executed instructions after arbitration, ensuring the logical determinism of the state machine under complex working conditions.

[0052] This implementation clearly distinguishes between steady state and transient state and configures four sub-states for transient state. Combined with a strict instruction priority interlocking mechanism, it effectively avoids state machine deadlock and logic conflict under rapid power-on and power-off conditions, significantly improving the robustness and safety of the vehicle control system.

[0053] Furthermore, in this embodiment, regarding the specific implementation of instruction priority interlocking, anti-shake filtering, and minimum state retention time, the main control unit of the vehicle controller (VCU) first receives the KL15 hard-wire signal from the low-voltage wake-up module, the one-button start signal, the charging wake-up signal, and the emergency safety power-down command from the fault diagnosis module as input sources. In terms of processing, the VCU arbitrates according to a preset priority hierarchy, setting the emergency safety power-down command to have the highest priority, followed by user-initiated power-down, user-initiated power-on, charging wake-up power-on, and maintenance wake-up power-on commands. When a high-priority command arrives, the currently executing low-priority command flow is immediately interrupted; for commands of the same priority, the first-in-first-out and closed-loop execution principle is followed, responding only to the next command of the same priority after the previous command has completed a complete steady-state closed loop. The output result is a queue of valid commands sorted by arbitration, which is directly sent to the state machine logic judgment unit.

[0054] Subsequently, the system performs debouncing and filtering on valid input commands, with the input source being the arbitrated raw pulse signal. The processing includes setting a 50ms effective debouncing time window, filtering out interference pulses with a duration less than 50ms, and starting a timer to monitor the trigger interval of similar commands. If the interval is less than 100ms, the duplicate command is discarded to prevent command queue overflow. The output is a denoised, stable trigger signal. Further, after the state machine enters an execution sub-state of any main state, the system initiates a minimum hold time verification mechanism, with the input source being the dwell time count of the current sub-state. The processing involves comparing this count with a set 100ms threshold in real time. Before reaching this minimum hold time, the state transition logic is forcibly locked, prohibiting any forward or reverse main state transition. The output is a state hold signal that meets timing stability requirements, ensuring that the state machine can only switch to the next sub-state or main state when timing is compliant, thus forming a complete logical closed loop from command input, arbitration filtering to timing locking.

[0055] This implementation effectively prevents logic deadlocks and high-voltage component malfunctions caused by instruction conflicts or signal jitter under rapid power-on and power-off conditions by establishing a multi-level instruction priority interlock and dual timing filtering mechanism, significantly improving the robustness and safety of the state machine under extreme conditions.

[0056] Example 3 Based on the above embodiments, this embodiment provides a detailed description of the specific implementation of step 2 in the electric vehicle power-on / off control method: "During the execution sub-state operation when the state machine is in the transition state, if a reverse power-on / off command is received, switch to the interruption suspension sub-state to pause the current process and save the field data, while prohibiting the execution of irreversible high-voltage operations."

[0057] In this embodiment, when the dual-layer state machine runs to the execution sub-state of the S3 precharge request transition state, the vehicle controller master verifies the instruction signal from the CAN communication module in real time. If it receives a user-initiated power-down instruction or an emergency safety power-down instruction, it immediately triggers the state transition logic and switches from the execution sub-state to the interruption suspension sub-state.

[0058] At the instant the switching action is executed, the processing unit first pauses the data stream sending pre-charge commands to the battery management system, then reads and saves the current bus voltage value, high-voltage contactor open / close status, and pre-charge progress parameters to the non-volatile storage area. Simultaneously, it sets the hardware interlock flag, physically prohibiting the output of the high-voltage main circuit contactor's closing or opening drive signal, ensuring that no irreversible high-voltage operations are performed during the pending state. Upon entering the interrupt suspension state, the independent safety monitoring unit immediately activates a tiered, variable-duration interrupt command validity verification window to perform secondary verification of the input interrupt command.

[0059] Specifically, the system first opens a primary short window with a fixed duration of 150ms, covering a 50ms signal anti-jitter time, a 30ms bus transmission delay margin, and a 70ms user operation cancellation window. If the application scenario requires adaptation to active operation cancellation scenarios such as turning a mechanical key or long-pressing to start, a secondary long window is activated, with its duration flexibly adjustable from 200ms to 1000ms through vehicle calibration. During the confirmation window, the processing unit samples the command signal status in real time. If an interrupt command is detected to be valid before the window ends, it is determined that the command represents the user's true operation intention, and a control signal is output to trigger the rollback sub-state, preparing to execute the bus discharge and contactor disconnection process. Conversely, if an interrupt command cancellation is detected or a new positive power-up command is received within the window, it is determined to be a momentary mis-touch, and a control signal is output to trigger the recovery sub-state, so as to read the previously saved pre-charge progress parameters and continue the pre-charge process from the breakpoint. Through the above-mentioned hierarchical confirmation mechanism, the system can accurately distinguish between momentary mis-touches and true operation intentions, avoiding abnormal switching of the state machine due to interference signals.

[0060] This implementation effectively filters out false interruption commands caused by user mis-touch or signal interference by setting a confirmation window with variable duration in stages, preventing hardware impact caused by frequent start-stop of the high-voltage system during the critical pre-charging stage, while retaining the user's right to cancel the operation in a short time, significantly improving the robustness of power-on and power-off control and user experience.

[0061] Example 4 Based on the above embodiments, this embodiment provides a detailed description of the specific implementation of step 3 in the electric vehicle power-on / off control method: "to perform a safety check on the interrupt command, and if the check passes, switch to the rollback sub-state and perform a safety rollback operation to roll back the vehicle state to the previous safe steady state, or switch to the recovery sub-state when a positive recovery command is received and continue to execute the current process from the interruption point based on the saved field data."

[0062] In this embodiment, the security verification of interrupt instructions and the subsequent state transition process are specifically implemented as follows: When the main control unit of the vehicle controller determines that the state machine is in the interrupted suspended sub-state of the S3 pre-charge request transition state, and the independent safety monitoring unit completes the dual verification of the continued validity of the interrupt command and outputs a verification pass signal, the main control unit immediately switches the sub-state to the rollback sub-state. At this time, the input source is the verification pass command issued by the independent safety monitoring unit and the currently saved bus voltage data. The processing action is that the main control unit first sends a drive signal to the high-voltage execution module to disconnect the pre-charge contactor, then starts the active discharge unit, and monitors the bus voltage drop curve in real time. When the bus voltage value is detected to be lower than the 60V threshold and the feedback signal of the pre-charge contactor confirms that it is in the disconnected state, the safe rollback operation is determined to be completed, and then a command to disconnect the main negative contactor is issued. The output result is an automatically generated rollback completion flag bit, the main state jump pointer is pointed to the S2 low-voltage self-test steady state, and the execution sub-state of the S2 low-voltage self-test steady state is initialized to wait for the next positive jump command, thereby realizing the safe rollback from the pre-charge stage to the low-voltage self-test stage.

[0063] When the state machine is in the S6 high-voltage discharge transition state (interruption suspension sub-state) and passes the verification by the independent safety monitoring unit, the main core control unit switches to the rollback sub-state. The input sources are the verification pass signal and the residual bus voltage value stored in the interrupt suspension sub-state. The processing action is to immediately stop the active discharge unit and close the main negative contactor. Then, the stored residual bus voltage value is read and compared with the preset secondary pre-charge start threshold. If the residual voltage value is higher than the preset secondary pre-charge start threshold, the main positive contactor is directly closed. If the residual voltage value is lower than the preset secondary pre-charge start threshold, the pre-charge contactor is closed first to replenish the voltage. After the bus voltage is re-established to a stable value, the main positive contactor is closed and the pre-charge contactor is opened. The output result is a bidirectional jump from the S6 high-voltage discharge transition state to the S4 high-voltage closing steady state, and the state machine is placed into the execution sub-state of the S4 high-voltage closing steady state, ensuring that the vehicle's high-voltage circuit is restored to readiness without impact.

[0064] This specific implementation method, through hierarchical verification and refined rollback strategy, ensures that when critical transition states such as pre-charging or discharging are interrupted, differentiated safety operations can be performed based on the real-time bus voltage status. This avoids the risk of burn-out caused by high-voltage components being switched on and off under load, and eliminates the hardware impact caused by repeatedly executing the complete process through the breakpoint recovery mechanism, significantly improving the robustness and response speed of power-on and power-off control.

[0065] Example 5 Based on the above embodiments, this embodiment provides a detailed description of the specific implementation of step 4 in the electric vehicle power-on / off control method: "Using an independent safety monitoring unit to perform real-time verification of the sub-state switching and main state jump of the state machine; if the state machine is detected to be stuck in the transition state or the verification is inconsistent, an automatic reset is triggered or the state machine is jumped to the fault-safe steady state."

[0066] In this embodiment, the real-time verification of the state machine using an independent safety monitoring unit is based on a dual-core lockstep architecture consisting of a main core control unit and an independent safety core unit. The two units use independent hardware circuits and power supplies to ensure that they are independent of each other.

[0067] Specifically, at the instruction receiving and verification node, the input source for the independent safety core unit is the KL15 signal or one-key start signal collected by the low-voltage wake-up module. The processing action involves synchronously collecting instructions with the main core control unit and comparing their validity. The output result is an instruction consistency verification flag; if inconsistent, subsequent processes are prohibited. At the sub-state switching verification node, the input source is the current sub-state data and switching request reported by the main core control unit. The processing action involves pre-verifying the logic for switching from an interrupted suspended sub-state to a rollback sub-state or restoring a sub-state. After confirming that no irreversible high-voltage operation is being executed, a switching permission signal is output. At the main state jump verification node, the input source is the jump condition parameters between the nine main states and hardware status feedback. The processing action involves independently verifying whether the jump conditions are met and whether the status data of the main core and the safety core are consistent. The output result is a control instruction allowing the jump or forcibly entering the S8 fault-safe steady state.

[0068] Furthermore, at the interrupt handling monitoring node, after detecting that the state machine has entered the interrupt suspension sub-state, the independent safety core unit opens a tiered, variable-duration interrupt instruction persistence validity confirmation window. The input source is the real-time instruction status within the window, and the processing action is to monitor the process pause status and irreversible operation prohibition status. At the end of the first-level short window (150ms) or the second-level long window (500ms), a decision to trigger a rollback sub-state or restore the sub-state is output based on the instruction persistence validity. Simultaneously, at the abnormal deadlock monitoring node, the input source is the continuous running timestamp of the transition state and the dual-core state comparison result. The processing action is to time in real time and count the number of consecutive inconsistent frames. If the state machine is stuck in the transition state for more than 1 second or the state verification between the main core control unit and the independent safety core unit is inconsistent for more than 3 consecutive communication cycles, the main core control unit is determined to be abnormal and an automatic reset instruction is output or the state machine is switched to a fault-safe steady state, thereby realizing closed-loop monitoring of functional safety throughout the entire process.

[0069] This implementation method, through a dual-core lockstep architecture and a hierarchical monitoring mechanism, achieves comprehensive real-time verification of instructions, state switching, and jumps during the power-on and power-off process. It effectively avoids high-voltage safety risks caused by single-point failures or logic deadlocks, and ensures that the functional safety level of the system meets the ISO26262ASIL-D requirements under rapid power-on and power-off conditions.

[0070] Furthermore, in this embodiment, the independent safety core unit serves as the core execution entity of the abnormal deadlock monitoring node, and its input sources include real-time collected state machine operation data of the main core control unit, high-voltage interlock circuit signals, insulation resistance detection values, and CAN bus communication frames.

[0071] Specifically, the independent security core unit continuously monitors the execution duration of the S1 low-voltage wake-up transition state, S3 precharge request transition state, S6 high-voltage discharge transition state, and S7 low-voltage sleep transition state in the main state, and synchronously compares the status data and calculation results of the main core control unit and the independent security core unit in each communication cycle.

[0072] The handling actions are divided into two paths based on the detected anomaly type: When the independent safety core unit determines that the main core control unit has an anomaly, such as the state machine being stuck in any transition state for more than 1 second, or the state verification between the main core control unit and the independent safety core unit being inconsistent for more than 3 consecutive communication cycles, or a fatal fault such as a broken high-voltage interlock circuit or insulation resistance failure being directly detected, it immediately enters the emergency fallback execution node. At this node, the independent safety core unit directly takes over control, cuts off the high-voltage contactor drive power supply within 50ms, forcibly disconnects all high-voltage contactors, locks the high-voltage system, and forces the state machine to jump to the S8 fault-safe steady state.

[0073] Another approach is to determine a logical deadlock rather than a hardware emergency when the independent safety core unit detects that the state machine is stuck in the transition state for more than 1 second but does not detect the aforementioned fatal fault. In this case, a soft reset command for the main core control unit's state machine is triggered. The output is as follows: In an emergency fallback scenario, the vehicle's high-voltage circuit is physically disconnected and the system is locked in the S8 fault-safe steady state to prevent high-voltage arcing or leakage risks; in a soft reset scenario, the state machine is automatically reset to the S0 sleep steady state and immediately restarts the complete power-on / off process starting from low-voltage wake-up, without requiring the user to manually disconnect the 12V battery for a hardware reset, thus achieving automatic recovery and closed-loop control under abnormal operating conditions.

[0074] This implementation method employs a tiered anomaly handling mechanism, which can quickly cut off high voltage within 50ms to ensure functional safety in the event of a fatal fault, and can also automatically soft reset for non-fatal logic deadlocks, completely eliminating the need for users to manually power off and reset, and significantly improving the robustness of the system and the user experience.

[0075] Example 6 This embodiment will describe in detail the complete implementation of the electric vehicle power-on / off control method, focusing on the specific control logic, data flow path, security verification mechanism and parameter configuration details based on the two-layer state machine architecture.

[0076] In this embodiment, the hardware architecture of the electric vehicle power-on / off control system is based on the vehicle control unit (VCU) as the core operating platform, employing a dual-core lockstep architecture consisting of a main core control unit and an independent safety core unit. The main core control unit is responsible for executing the core control logic, timing scheduling, and instruction processing of the state machine; the independent safety core unit is responsible for full-process functional safety verification, anomaly monitoring, and emergency fallback control. Both use independent hardware circuits and power supplies, ensuring that a single fault will not lead to system failure. The system uses a CAN communication module to realize signal interaction between the VCU and all ECUs in the vehicle, such as the battery management system (BMS) and the motor controller (MCU). The communication bus adopts the CANFD protocol, and the communication cycle is adjustable from 10ms to 50ms. The high-voltage execution module includes the BMS, MCU, high-voltage contactor unit, and active discharge unit, responsible for executing the high-voltage circuit control commands issued by the VCU and feeding back the component status. The low-voltage wake-up module collects the KL15 hard wire signal, one-button start signal, key sensing signal, and charging wake-up signal as the trigger source for the state machine. The fault diagnosis module collects vehicle fault signals in real time and performs hierarchical diagnosis, while the instrument human-machine interaction module is responsible for displaying the vehicle's power-on / off status, READY signal, and fault prompt information to the user.

[0077] This embodiment constructs a two-layer state machine architecture with nine main states. The main states are distinguished as steady state and transitional state. Each main state is further divided into four sub-states: execution sub-state, interruption suspension sub-state, rollback sub-state, and recovery sub-state, so as to realize interrupt fault tolerance and bidirectional jump capability. Among them, S0 sleep steady state is defined as the initial state in which the vehicle's low-voltage system is shut down, all ECUs are in deep sleep, the high-voltage circuit is completely disconnected, and the bus voltage is discharged to below 60V; S2 low-voltage self-test steady state is defined as the state in which all ECUs of the vehicle complete low-voltage hardware and communication self-tests, and the VCU completes high-voltage access condition verification. The high-voltage access conditions include P / N gear being active, brake pedal being triggered, the high-voltage interlock circuit HVIL being normal, insulation resistance being greater than or equal to 100Ω / V, and no Level 1 fatal faults; S4 high-voltage closing steady state is defined as the state in which the high-voltage main circuit is completely closed, the bus voltage is stable, the DC-DC converter is working normally, and the high-voltage auxiliary control has completed initialization; S5 running ready steady state is defined as the state in which the vehicle enters the READY state, and the VCU grants torque enable permission to the MCU; S8 fault-safe steady state is defined as the protection state in which an emergency power-off is executed after a fatal fault is detected, all high-voltage contactors are disconnected, and the high-voltage system is locked. The above S0, S2, S4, S5, and S8 are steady-state nodes that can be safely rolled back. S1 low-voltage wake-up transition state, S3 precharge request transition state, S6 high-voltage discharge transition state and S7 low-voltage sleep transition state are defined as transition state nodes that are being executed and cannot be interrupted arbitrarily. Among them, S3 precharge request transition state is the state with the highest frequency of rapid power-on and power-off interruption.

[0078] In the specific operational logic of the state machine, the execution sub-state of each main state serves as the default sub-state, responsible for executing the core functions of the current main state. A forward transition to the main state can only be triggered in this sub-state. When the state machine is running in a transitional execution sub-state, if a reverse power-on / off command is received, the system immediately switches to the interrupt suspension sub-state. In the interrupt suspension sub-state, the current process is paused, the system saves all state data, parameters, and hardware states, and strictly prohibits irreversible operations such as contactor closing, contactor opening, or IGBT enabling. Simultaneously, the system reports the interrupt status to the independent safety core unit for verification. If the interrupt command is confirmed valid through safety verification, the system switches to the rollback sub-state and performs a safety rollback operation to revert the vehicle state to the previous safe steady state. For example, if the state machine is interrupted in the S3 precharge request transition state, the rollback sub-state will immediately disconnect the precharge contactor, activate the active discharge unit to discharge the bus voltage to below 60V, then disconnect the main negative contactor, and roll back the state machine to the S2 low-voltage self-test steady state execution sub-state. If the state machine is interrupted in the S6 high-voltage discharge transition state, the rollback sub-state will immediately stop the active discharge, close the main negative contactor, execute the secondary precharge process to re-establish the bus voltage to a stable value, and then roll back to the S4 high-voltage closing steady state execution sub-state. If the interrupt command is revoked or a new positive command is received, the system switches to the recovery sub-state, reads the field data saved before the interruption, and continues to execute the core process of the current main state from the interruption point without repeating the entire process from the beginning. After execution, a positive state jump is triggered.

[0079] To address the issues of command conflicts and logical disorder, this embodiment establishes a strict command priority interlocking rule. The command priority order is set as follows: emergency safety power-down commands have the highest priority, followed by user-initiated power-down commands, then user-initiated power-on commands, followed by charging wake-up power-on commands, and maintenance wake-up power-on commands have the lowest priority. High-priority commands can interrupt the execution of low-priority commands, while low-priority commands cannot interrupt the execution of high-priority commands. For commands of the same priority, the "first-in, first-out, closed-loop execution" principle is followed; the previous command of the same priority must be executed to a complete steady-state closed loop before the next command of the same priority can be executed. At the same time, command debouncing and filtering rules are implemented. A 50ms effective debouncing time is set for KL15 hard-wired signals or one-button start signals, and pulse signals with a duration of less than 50ms are directly filtered. The minimum trigger interval for commands of the same type is set to 100ms, and repeated commands with a duration of less than 100ms are directly discarded to avoid command queue overflow. In addition, a minimum hold time is set for the execution sub-state of each main state, which is greater than or equal to 100ms. Before the minimum hold time is reached, forward or reverse jumps of the main state are prohibited, thereby avoiding logical disorder caused by frequent jumps.

[0080] The independent safety core unit performs real-time monitoring and verification of the entire state machine process, specifically through six core functional nodes. At the instruction receiving and verification node, the independent safety core synchronously collects power-on / off instruction signals and performs instruction validity verification simultaneously with the main core control unit. The verification process reserves a transmission delay margin of less than or equal to 30ms for onboard hardwired or CAN bus transmission to ensure the instruction reflects the user's true intent. At the sub-state switching verification node, before any sub-state switch in a main state, the main core reports the switching instruction and current state data. The independent safety core independently verifies the validity of the switching logic and ensures there are no currently executing irreversible high-voltage operations. Switching can only proceed if the verification passes. At the main state transition verification node, before transitions between the nine main states, the independent safety core independently verifies the transition conditions and state consistency. If the hardware states collected by the main core and the safety core are inconsistent, or if the transition conditions are not met, transitioning is prohibited, and the system directly enters the S8 fault-safe steady state.

[0081] At the interrupt handling monitoring node, after the state machine enters the interrupt suspension sub-state, the independent security core immediately opens a tiered, variable-duration interrupt command persistence validity confirmation window. This window is divided into a first-level short window and a second-level long window. The first-level short window is fixed at 150ms, adapting to instantaneous accidental touch scenarios such as one-key start, covering 50ms anti-jitter verification, 30ms fixed transmission delay margin, and a 70ms user-operable cancellation window. The second-level long window can be calibrated from 200ms to 1000ms, with a default of 500ms, adapting to active operation regret scenarios such as turning a mechanical key or long-press start. Within the confirmation window, the independent security core monitors the interrupt status during verification. If the interrupt command is detected to be persistently valid, it is determined to be the user's true operation intention, and preparation is made to trigger the rollback sub-state; if the interrupt command cancellation is detected or a new positive command is received within the window, it is determined to be an instantaneous accidental touch, and preparation is made to trigger the recovery sub-state. At the abnormal deadlock monitoring node, the execution duration of the transition state is monitored during independent safety verification. If the state machine is stuck in the transition state for more than 1 second, or if the state verification between the main core control unit and the independent safety core unit is inconsistent for more than 3 consecutive communication cycles (i.e., less than or equal to 150ms), the main core control unit is determined to be abnormal. At the emergency fallback execution node, when a fatal fault such as HVIL disconnection or insulation failure is detected, or when the main core is abnormal, the independent safety core directly takes over the vehicle control, cuts off the high-voltage contactor drive power within 50ms, disconnects all high-voltage contactors, locks the high-voltage system, and forces the state machine to jump to the S8 fault-safe steady state. If only the state machine is stuck but no fatal fault is detected, the main core control unit's state machine is triggered to soft reset, resetting the state machine to the S0 sleep steady state and re-executing the power-on / off process, without requiring the user to manually disconnect the 12V battery.

[0082] Regarding the specific data flow and processing details, when the state machine is in the execution sub-state of the S3 pre-charge request transition state and receives a user-initiated power-off command, the main core immediately suspends the process of sending pre-charge commands to the BMS, saves the current bus voltage value, contactor opening and closing status, and pre-charge progress parameters to non-volatile memory, and prohibits the execution of the closing or opening action of the high-voltage main circuit contactor. Subsequently, a hierarchical confirmation window is started. If the command is still valid when the window ends, and the independent safety core verification passes, the main core switches to the rollback sub-state, immediately disconnects the pre-charge contactor, and starts the active discharge unit. During the rollback process, the system monitors the bus voltage drop curve in real time. When the bus voltage value is detected to be below the 60V threshold and the pre-charge contactor feedback signal is in the open state, the safe rollback operation is determined to be completed, a rollback completion flag is automatically generated, the main state jump pointer is pointed to the S2 low-voltage self-test steady state, and the execution sub-state of S2 is initialized. When the state machine is in the execution sub-state of the S6 high-voltage discharge transition state and receives a user-initiated power-on command, the main core suspends sending torque zeroing commands to the MCU and discharge commands to the active discharge unit, and saves the current bus voltage discharge progress and contactor disconnection status. If it is verified that it needs to return to the S4 high-voltage closing steady state, the system reads the bus voltage residual value saved in the interrupt suspend sub-state. If the residual value is higher than the preset secondary pre-charge start threshold, the main positive contactor is closed directly. If the residual value is lower than the preset secondary pre-charge start threshold, the pre-charge contactor is closed first to replenish the voltage. After the bus voltage stabilizes, the main positive contactor is closed and the pre-charge contactor is opened, completing the bidirectional jump.

[0083] This embodiment, through a two-layer state machine architecture consisting of a main state and sub-states, combined with a dual-core lockstep verification mechanism with an independent safety core, completely solves the problem of state machine jamming under rapid power-up and power-down conditions. Through closed-loop control of suspension, rollback, and recovery, it achieves safe handling of interruptions at any stage and breakpoint recovery, significantly improving power-up speed, greatly reducing hardware impact, and effectively extending the lifespan of contactors, capacitors, and resistors. The triple strategy of instruction priority, debouncing, and minimum hold time eliminates logical conflicts, while the full-coverage safety verification and automatic reset mechanism of the transition state ensures that the system meets the functional safety requirements of ISO26262 ASIL-D level, greatly improving user experience and reducing after-sales maintenance costs.

[0084] The above description is merely a preferred embodiment of the present invention and is not intended to limit the invention. Various modifications and variations can be made to the present invention by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.

[0085] In the description of this specification, the references to terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., refer to specific features, structures, materials, or characteristics described in connection with that embodiment or example, which are included in at least one embodiment or example of the present invention. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples. Moreover, without contradiction, those skilled in the art can combine and integrate the different embodiments or examples described in this specification, as well as the features of different embodiments or examples.

[0086] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one of that feature. In the description of this invention, "a plurality of" means at least two, such as two, three, etc., unless otherwise explicitly specified.

Claims

1. An electric vehicle on-off power state machine control method with interrupt fault tolerance and bidirectional jump, characterized in that, Includes the following steps: Construct a two-layer state machine architecture containing multiple main states, and divide each main state into an execution sub-state, an interruption / suspension sub-state, a rollback sub-state, and a recovery sub-state, where the main state is distinguished between a steady state and a transitional state; During the execution sub-state of the state machine in the transition state, if a reverse power-on / off command is received, the process switches to the interrupt suspension sub-state to pause the current process and save the field data, while prohibiting the execution of irreversible high-voltage operations. The interrupt command is subjected to safety verification. If the verification passes, the system switches to the rollback sub-state and performs a safety rollback operation to roll back the vehicle state to the previous safe steady state. Alternatively, when a forward recovery command is received, the system switches to the recovery sub-state and continues the current process from the interruption point based on the saved field data. An independent safety monitoring unit is used to perform real-time verification of the sub-state transitions and main state jumps of the state machine. If the state machine is detected to be stuck in the transition state or the verification is inconsistent, an automatic reset is triggered or the state machine is jumped to a fault-safe steady state.

2. The electric vehicle on-off control method according to claim 1, wherein The constructed two-layer state machine architecture includes multiple main states, each of which is divided into an execution sub-state, an interruption / suspension sub-state, a rollback sub-state, and a recovery sub-state. The main states are distinguished between steady states and transitional states, including: S0 sleep steady state, S2 low-voltage self-test steady state, S4 high-voltage closed steady state, S5 operation-ready steady state and S8 fault-safe steady state are defined as steady state nodes that can be safely rolled back; Define S1 low-voltage wake-up transition state, S3 precharge request transition state, S6 high-voltage discharge transition state and S7 low-voltage sleep transition state as transition state nodes that are currently being executed and cannot be interrupted arbitrarily; For each of the transition states in S1 low-voltage wake-up transition state, S3 precharge request transition state, S6 high-voltage discharge transition state and S7 low-voltage sleep transition state, respectively configure an execution sub-state for performing the core functions of the current main state, an interruption suspension sub-state for pausing the process when a reverse instruction is received, a rollback sub-state for performing rollback operations after safety verification, and a recovery sub-state for continuing execution from the interruption point when a forward recovery instruction is received.

3. The method of claim 2, wherein the method further comprises: During the execution sub-state operation of the state machine in a transitional state, if a reverse power-on / off command is received, the process switches to the interrupt suspension sub-state to pause the current process and save the current data. Simultaneously, irreversible high-voltage operations are prohibited, including: When the state machine is in the execution sub-state of the S3 precharge request transition state and receives a user active power-down command or an emergency safety power-down command, it immediately switches from the execution sub-state to the interruption suspension sub-state, suspends the process of sending precharge commands to the battery management system, saves the current bus voltage value, contactor opening and closing status and precharge progress parameters, and prohibits irreversible high-voltage operations such as closing or opening of the high-voltage main circuit contactor. When the state machine is in the execution sub-state of the S6 high voltage discharge transition state and receives the user's active power-on command, it immediately switches from the execution sub-state to the interruption suspension sub-state, suspends the process of sending the torque zeroing command to the motor controller and the discharge command to the active discharge unit, saves the current bus voltage discharge progress and contactor disconnection status, and prohibits the execution of the high voltage contactor's re-disconnection action or the pre-charge contactor's closing action.

4. The electric vehicle on-off control method according to claim 3, wherein When the state machine is in the execution sub-state of the S3 precharge request transition state and receives a user-initiated power-down command or an emergency safety power-down command, it immediately switches from the execution sub-state to the interruption / suspend sub-state, suspending the process of sending precharge commands to the battery management system, saving the current bus voltage value, contactor opening / closing status, and precharge progress parameters, and prohibiting irreversible high-voltage operations such as closing or opening actions of the high-voltage main circuit contactor, including: After switching to the interrupt suspension sub-state, a tiered, variable-duration interrupt command validity confirmation window is initiated. If the interrupt command is detected to be valid within the fixed 150ms of the first-level short window or within the 200ms to 1000ms range of the second-level long window, it is determined to be the user's true operation intention and preparation is made to trigger the rollback sub-state. If the interrupt command is canceled or a new positive command is received within the confirmation window, it is determined to be a momentary accidental touch and preparation is made to trigger the recovery sub-state. This distinguishes between momentary accidental touches and the user's true operation intention to avoid abnormal state machine switching.

5. The method of claim 2, wherein the method further comprises: The interrupt command undergoes a safety check. If the check passes, the system switches to a rollback sub-state and performs a safety rollback operation to restore the vehicle's state to the previous safe steady state. Alternatively, upon receiving a forward recovery command, the system switches to a recovery sub-state and continues the current process from the interruption point based on saved field data, including: If the interruption suspension sub-state of the state machine in the S3 precharge request transition state is verified by the independent safety monitoring unit, it will switch to the rollback sub-state, immediately disconnect the precharge contactor and start the active discharge unit to discharge the bus voltage to below 60V, then disconnect the main negative contactor and roll back the state machine to the execution sub-state of the S2 low voltage self-test steady state. If the interruption suspension sub-state of the state machine in the S6 high-voltage discharge transition state is verified by the independent safety monitoring unit, it will switch to the rollback sub-state, immediately stop the active discharge unit and close the main negative contactor, execute the secondary pre-charge process to re-establish the bus voltage to a stable value, and then roll back the state machine to the execution sub-state of the S4 high-voltage closing steady state.

6. The electric vehicle on-off control method according to claim 5, wherein If the interruption-suspended sub-state of the state machine in the S3 pre-charge request transition state passes the verification by the independent safety monitoring unit, then it switches to the rollback sub-state, immediately disconnects the pre-charge contactor and starts the active discharge unit to discharge the bus voltage to below 60V, then disconnects the main negative contactor and rolls the state machine back to the execution sub-state of the S2 low-voltage self-test steady state, including: During the execution of the rollback sub-state, the bus voltage drop curve is monitored in real time. When the bus voltage value is detected to be lower than the 60V threshold and the precharge contactor feedback signal is in the open state, the safe rollback operation is determined to be completed, the rollback completion flag is automatically generated, and the main state jump pointer is pointed to the S2 low-voltage self-test steady state. At the same time, the execution sub-state of the S2 low-voltage self-test steady state is initialized to wait for the next positive jump instruction.

7. The electric vehicle on-off control method according to claim 5, wherein If the interruption suspension sub-state of the state machine in the S6 high-voltage discharge transition state passes the verification by the independent safety monitoring unit, it switches to the rollback sub-state, immediately stops the operation of the active discharge unit and closes the main negative contactor, executes the secondary pre-charge process to re-establish the bus voltage to a stable value, and then rolls back the state machine to the execution sub-state of the S4 high-voltage closing stable state, including: During the secondary pre-charge process, the residual bus voltage value stored in the interrupted suspended state is read. If the residual voltage value is higher than the preset secondary pre-charge start threshold, the main positive contactor is closed directly. If the residual voltage value is lower than the preset secondary pre-charge start threshold, the pre-charge contactor is closed first to replenish the voltage. After the bus voltage stabilizes, the main positive contactor is closed and the pre-charge contactor is opened, completing the bidirectional jump from the S6 high-voltage discharge transition state to the S4 high-voltage closing steady state.

8. The electric vehicle on-off control method according to claim 2, wherein The constructed two-layer state machine architecture includes multiple main states, each of which is divided into an execution sub-state, an interruption / suspension sub-state, a rollback sub-state, and a recovery sub-state. The main states distinguish between steady states and transitional states, and also include: Establish an instruction priority interlock rule, setting the priority of emergency safety power-down instructions to be higher than user-initiated power-down instructions, user-initiated power-down instructions to be higher than user-initiated power-on instructions, user-initiated power-on instructions to be higher than charging wake-up power-on instructions, and charging wake-up power-on instructions to be higher than maintenance wake-up power-on instructions. High-priority instructions can interrupt the execution of low-priority instructions, while instructions of the same priority follow the first-in-first-out and closed-loop execution principle. The previous instruction of the same priority must be executed to a complete steady-state closed loop before the next instruction of the same priority can be executed.

9. The electric vehicle on-off control method according to claim 8, wherein The established instruction priority interlocking rule sets the priority of emergency safety power-down instructions higher than user-initiated power-down instructions, user-initiated power-down instructions higher than user-initiated power-on instructions, user-initiated power-on instructions higher than charging wake-up power-on instructions, and charging wake-up power-on instructions higher than maintenance wake-up power-on instructions. Higher-priority instructions can interrupt the execution of lower-priority instructions. Instructions of the same priority follow a first-in-first-out and closed-loop execution principle; a preceding instruction of the same priority must complete a full steady-state closed loop before a subsequent instruction of the same priority can be executed. This also includes: Implement command debouncing and filtering rules, set an effective debouncing time of 50ms for KL15 hard-wired signals or one-key start signals, filter pulse signals with a duration of less than 50ms, and set the minimum trigger interval of the same type of command to 100ms, directly discarding repeated commands with a duration of less than 100ms to prevent command queue overflow. Implement a minimum state hold time rule, setting a minimum hold time of 100ms or more for the execution sub-states of each main state. Prohibit forward or reverse jumps of the main state before the minimum hold time is reached to avoid logical disorder.

10. The electric vehicle on-off control method of claim 1, wherein The method of using an independent safety monitoring unit to perform real-time verification of sub-state transitions and main state jumps of the state machine, and if it is detected that the state machine is stuck in the transition state or the verification is inconsistent, an automatic reset is triggered or the state machine is jumped to a fault-safe steady state, including: It adopts a dual-core lockstep architecture with a main core control unit and an independent safety core unit. The main core control unit is responsible for executing the core control logic and timing scheduling of the state machine, while the independent safety core unit is responsible for the functional safety verification and anomaly monitoring of the entire process. The two use independent hardware and power supplies and do not depend on each other. The independent safety core unit synchronously collects power-on and power-off commands at the command receiving and verification node and compares the legality of the commands with the main core control unit. At the sub-state switching verification node, it performs pre-verification on the logic of switching from the execution sub-state to the interruption-suspended sub-state, switching from the interruption-suspended sub-state to the rollback sub-state, or restoring the sub-state. At the main state jump verification node, it independently verifies the jump conditions and state consistency between the nine main states. Among them, the independent safety core unit opens a graded variable-duration interrupt instruction validity confirmation window at the interrupt handling monitoring node, monitors in real time whether the state machine has successfully paused the process and whether irreversible operations are prohibited, and triggers rollback or recovery of sub-state according to the instruction status when the confirmation window ends; the independent safety core unit monitors the execution duration of the transition state in real time at the abnormal deadlock monitoring node. If the state machine is stuck in the transition state for more than 1 second or the state verification between the main core control unit and the independent safety core unit is inconsistent for more than 3 consecutive communication cycles, the main core control unit is determined to be abnormal. When the independent safety core unit determines that the main core control unit is abnormal or detects a fatal fault such as a broken high-voltage interlock circuit or insulation resistance failure, it immediately enters the emergency fallback execution node. Within 50ms, it cuts off the high-voltage contactor drive power and disconnects all high-voltage contactors, locks the high-voltage system, and forces the state machine to jump to the S8 fault-safe steady state. When the independent safety core unit only detects that the state machine is stuck in the transition state for more than 1s but does not detect a fatal fault, it triggers a soft reset of the main core control unit's state machine, resets the state machine to the S0 sleep steady state, and re-executes the power-on and power-off procedures without requiring the user to manually disconnect the 12V battery.