Passenger car start interlock bypass emergency start control method and system

CN122812781APending Publication Date: 2026-09-25HUANGSHAN XIAOBIDIAN AUTOMOBILE TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202611104562.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-07-24
Publication Date
2026-09-25

AI Technical Summary

Technical Problem

[0003]但车辆长期处于振动、温变、油污侵蚀的复杂工况下,联锁开关触点氧化、线路断路、线圈烧毁等故障频发

Benefits of technology

[0049](1)本申请构建集成双旁路支路的一体化旁路控制链路,同时覆盖前端联锁开关类故障与电池总开关控制回路故障两类核心启动故障,解决了传统单一旁路方案故障覆盖窄的问题;一体化集成架构减少了接线点位,提升了系统可靠性与安装便捷性。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122812781A_ABST
    Figure CN122812781A_ABST
Patent Text Reader

Abstract

The application belongs to the field of electric control of passenger cars, and discloses a passenger car starting interlock bypass emergency starting control method and system, which comprises obtaining an integrated bypass control link integrated with a first bypass control branch and a second bypass control branch; in response to an original vehicle starting instruction, collecting electric characteristic parameters of a starting loop and inputting the pre-trained fault classification identification model to obtain starting loop fault classification labels; collecting vehicle operating state parameters and performing safety verification; after the verification, selectively conducting the corresponding bypass control branch according to the fault classification labels to generate a temporary starting conduction loop; outputting a starting drive electric signal to a starter through the loop to execute the emergency starting of the whole vehicle. Through the cooperative matching of the double-bypass integrated architecture, intelligent fault diagnosis and safety verification mechanism, the application solves the problems of single fault coverage, lack of automatic diagnosis and safety guarantee in the prior art, and realizes the precise coverage and automatic emergency starting of multiple interlock faults.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of bus electrical control technology, and particularly relates to a bus starting interlock bypass emergency start control method and system. Background Technology

[0002] Passenger buses and city buses generally adopt a multi-level series interlocking architecture for their starting circuits. The neutral gear switch, engine compartment door sensor switch, electromagnetic battery master switch and starting relay are connected in series in sequence. The vehicle can only be started when all interlocking conditions are met at the same time, thereby avoiding safety risks such as starting in gear or starting with the door open.

[0003] However, vehicles operate under complex conditions of vibration, temperature changes, and oil contamination for extended periods, leading to frequent malfunctions such as oxidation of interlock switch contacts, circuit breaks, and coil burnout. Because the starting circuit is a series structure, failure of any interlock node will prevent the vehicle from starting. Even if core components such as the battery and starter are intact, the vehicle will still break down on the road, affecting operational efficiency and road safety.

[0004] Currently, emergency response solutions for such faults still have significant shortcomings: First, existing bypass devices are mostly single-node short-circuit structures, which can only cover a single type of fault and cannot simultaneously adapt to front-end interlock switch faults and battery main switch control circuit faults, thus limiting their applicability. Second, pure hardware bypasses lack automated safety verification mechanisms and rely entirely on manual judgment by operators. Misoperation while the vehicle is in motion or not parked can easily lead to safety accidents such as vehicle slippage or sudden movement. Third, there is no automated fault identification capability, and fault location relies entirely on manual segment-by-segment troubleshooting, resulting in time-consuming emergency response and high requirements for personnel expertise. Fourth, overcurrent protection often adopts fixed instantaneous threshold schemes, which cannot distinguish between instantaneous inrush current during startup and continuous fault overcurrent. There are common problems of false protection and protection lag, and the fault judgment logic is based on fixed thresholds, lacking self-learning and iterative capabilities, making it difficult to adapt to differences in parameters of different vehicle models and parameter drift after vehicle aging.

[0005] In summary, existing emergency start technologies for buses generally suffer from technical defects such as narrow fault coverage, weak safety protection capabilities, low fault diagnosis efficiency, and poor electrical protection accuracy. A systematic and intelligent emergency start control solution is urgently needed to address these issues. Summary of the Invention

[0006] This application addresses the problems existing in the prior art by proposing a bus start-up interlock bypass emergency start control method and system. By integrating dual bypass branches to achieve multi-type fault coverage, and combining automated safety verification and intelligent fault identification, it achieves accurate, safe, and efficient emergency start control.

[0007] To achieve the above objectives, this application provides the following technical solution:

[0008] Firstly, a method for emergency start control of a bus starting interlock bypass includes the following steps: S1, acquiring a preset integrated bypass control link, wherein the integrated bypass control link integrates a first bypass control branch and a second bypass control branch that are independent of each other and correspond to two types of interlocking faults respectively; S2, responding to the original vehicle start command, collecting electrical characteristic parameters of the original vehicle start circuit, inputting them into a pre-trained start fault classification and recognition model to determine the fault type, and obtaining a start circuit fault classification label; S3, collecting vehicle operating status parameters in real time, calling a pre-built vehicle start safety verification model to calculate, and obtaining an emergency operation safety verification result; S4, when the emergency operation safety verification result is passed, matching a graded bypass conduction strategy according to the start circuit fault classification label, selectively conducting the first bypass control branch and / or the second bypass control branch in the integrated bypass control link to generate a temporary start conduction circuit after the bypass failure interlocking node; S5, outputting a start drive electrical signal to the starter through the temporary start conduction circuit to drive the bus starter to perform a vehicle emergency start.

[0009] Optionally, step S2 includes:

[0010] S21. After the original vehicle start command is triggered, collect three types of electrical characteristic parameters of the start circuit: no-load voltage timing data, instantaneous start current peak data, and voltage drop recovery time.

[0011] S22. Normalize the three types of electrical characteristic parameters to eliminate dimensional differences and generate standardized feature vectors.

[0012] S23. Input the standardized feature vector into the pre-trained multi-class machine learning model and output the corresponding start-up circuit fault classification label. The start-up circuit fault classification label includes at least three categories: interlock switch faults, battery main switch control circuit faults, and starter / power supply body faults.

[0013] Optionally, step S3 includes:

[0014] S31. The vehicle status acquisition unit synchronously acquires three types of status parameters: vehicle speed signal, handbrake status signal, and ignition lock gear signal.

[0015] S32. Input the three types of state parameters into the multi-dimensional Boolean verification model, and make a judgment on the vehicle stationary state, parking brake state and ignition authorization state respectively.

[0016] S33. When all three states simultaneously meet the preset security conditions, output the security verification result that passes the verification; when any one state fails the condition, output the verification result that fails and lock all bypass control branches in the integrated bypass control link.

[0017] Optionally, step S3 further includes:

[0018] S34. Receive authorization verification information from external input and call the preset permission verification algorithm to verify the identity legitimacy.

[0019] S35. After successful verification, unlock the emergency start operation permission; if the verification fails, maintain the locked state of the bypass control branch.

[0020] Optionally, step S4 includes:

[0021] S41. After receiving the successful security verification result, retrieve the fault classification label of the current startup circuit;

[0022] S42. If the fault classification label is an interlock switch type fault, only the first bypass control branch is connected in the integrated bypass control link, and the series control circuit of the bypass gear interlock switch and the door sensing interlock switch is connected.

[0023] S43. If the fault classification label is a fault in the battery main switch control circuit, only the second bypass control branch is connected in the integrated bypass control link to bypass the original control coil circuit of the battery main switch.

[0024] S44. If the fault classification label is starter / power supply body fault, do not connect any bypass control branch, and directly output the body fault prompt information.

[0025] Optionally, step S4 also includes:

[0026] S45. If the starter motor still does not start after the single-circuit bypass is activated, the secondary fault verification process will be automatically triggered.

[0027] S46. Sequentially connect the remaining unused bypass control branches in the integrated bypass control link, re-collect the electrical characteristic parameters of the start-up circuit and update the fault classification label;

[0028] S47. If there is still no start response after all bypass control branches are turned on, it is finally determined that the starter / power supply body is faulty and a first-level alarm message is output.

[0029] Optionally, step S5 includes:

[0030] S51. Real-time acquisition of operating current timing data of the temporary start-up conduction circuit;

[0031] S52. Compare the real-time operating current with the preset overcurrent threshold. If the duration of the operating current exceeding the threshold reaches the preset duration threshold, trigger the overcurrent protection algorithm.

[0032] S53, the overcurrent protection algorithm outputs a circuit cutoff command, disconnecting the conduction state of all bypass control branches in the integrated bypass control link, and simultaneously outputs an overcurrent fault alarm message.

[0033] Optionally, the method also includes in-vehicle data interaction, which is executed throughout the emergency start-up process:

[0034] Simultaneously collect four types of operational data: safety verification results, fault classification labels, bypass conduction status, and emergency start operation records;

[0035] The vehicle-mounted multi-source data fusion model is invoked to perform standardized format conversion and data association mapping on four types of operating data, generating standardized interactive data compatible with the vehicle's CAN bus protocol;

[0036] Standardized interactive data is synchronously uploaded to the vehicle controller and the cab display terminal to complete the visualization of fault information and local storage of operation logs.

[0037] Optionally, the method also includes a clutch failure shifting emergency start bypass function, specifically including:

[0038] Receives the signal to activate the emergency start switch;

[0039] The bypass gear interlock switch's gear lock-up logic removes the interlock restriction that the gear can only be started in neutral.

[0040] It allows the vehicle to directly output a start drive electrical signal to drive the starter motor while the engine is off and gear is engaged, enabling emergency starting when the clutch fails.

[0041] In a second aspect, the present invention provides a bus starting interlock bypass emergency start control system for implementing the bus starting interlock bypass emergency start control method as described in the first aspect, comprising:

[0042] The integrated emergency control module has two independent bypass control branches built in, and an additional gear-shifting emergency bypass branch is added to form an integrated bypass control link covering multiple interlocking nodes.

[0043] The status acquisition unit is used to collect vehicle operating status parameters and electrical characteristic parameters of the start-up circuit in real time.

[0044] The data processing unit has a built-in vehicle start-up safety verification model, start-up fault classification and identification model, and hierarchical bypass conduction strategy module, which are used to output safety verification results, fault classification labels and bypass conduction control commands.

[0045] The drive execution unit receives the bypass conduction control command, generates a temporary start conduction circuit, and outputs a start drive electrical signal to the starter motor.

[0046] The interactive output unit is used to output fault prompts, alarms, and visualized operating data.

[0047] The integrated emergency control module is equipped with an independent physical switch for emergency gear shifting. When the switch is turned on, it triggers the gear shifting bypass control logic and releases the gear interlock restriction.

[0048] The beneficial effects of this application are as follows:

[0049] (1) This application constructs an integrated bypass control link with dual bypass branches, which covers two types of core start-up faults: front-end interlocking switch faults and battery main switch control circuit faults. This solves the problem of narrow fault coverage in traditional single bypass schemes. The integrated architecture reduces wiring points and improves system reliability and ease of installation.

[0050] (2) This application uses a multi-dimensional Boolean joint judgment security verification model to automatically determine the legality of the operation from three dimensions: vehicle stationary, parking brake, and legal authorization. In non-safe scenarios, it automatically locks all bypass branches, thus eliminating the risk of misoperation from a technical perspective. The supporting authorization verification mechanism further enhances the anti-theft and unauthorized operation protection capabilities, achieving a qualitative improvement in safety and reliability.

[0051] (3) Based on the multi-dimensional electrical characteristics of the starting circuit, this application automatically identifies the fault type through a weighted multi-classification decision model. The fault category can be determined within a few seconds, eliminating the need for manual inspection and significantly shortening the fault location time. With the graded bypass conduction strategy, the fault and bypass are accurately matched. Following the principle of minimum intervention, the original vehicle protection mechanism is preserved to the greatest extent while ensuring the emergency effect.

[0052] (4) This application adopts an integral overcurrent judgment algorithm, which can distinguish between instantaneous inrush current and continuous fault overcurrent. It avoids emergency failure caused by false protection at the moment of startup and can cut off the circuit in time when there is continuous fault overcurrent. Combined with the backup protection of the hardware fuse, a dual protection architecture is formed to effectively protect the safety of the original vehicle electrical components and devices themselves. Attached Figure Description

[0053] Figure 1 A schematic diagram of an emergency response scenario for a faulty interlocking system in an existing passenger vehicle.

[0054] Figure 2 This is a schematic diagram of the bus start-up interlock bypass emergency start control method according to Embodiment 1 of this application;

[0055] Figure 3 This is a schematic diagram of the bus start-up interlock bypass emergency start control system according to Embodiment 2 of this application.

[0056] Figure label:

[0057] 100. Integrated emergency control module; 200. Status acquisition unit; 300. Data processing unit; 400. Drive execution unit; 500. Interactive output unit. Detailed Implementation

[0058] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description of this application is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely one preferred embodiment of this application and are only used to explain this application. They do not limit the scope of protection of this application. All other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0059] like Figure 1 The diagram illustrates an emergency response scenario for a starting interlock failure in an existing passenger bus. Current passenger buses generally employ a multi-stage series starting interlock architecture. The starting circuit sequentially connects the neutral gear switch, door sensor switch, battery master switch, and starting relay to jointly control the starter motor power supply path, thereby mitigating the safety risks of unauthorized starting. When any interlock node in the circuit experiences an open circuit failure, the vehicle cannot start normally, even if the battery and starter motor are intact. After a failure occurs, maintenance personnel must manually troubleshoot and locate the fault point segment by segment, using temporary wires to short-circuit the faulty node to complete an emergency start. This approach suffers from drawbacks such as low fault location efficiency, limited coverage of scenarios, high risk of misoperation, and lack of automatic diagnostic capabilities.

[0060] Example 1:

[0061] like Figure 2 As shown, a method for emergency start control of bus start interlock bypass includes the following steps:

[0062] S1. Obtain the preset integrated bypass control link. The integrated bypass control link integrates the first bypass control branch and the second bypass control branch, which are independent of each other and correspond to the two types of interlocking faults respectively.

[0063] S2. In response to the original vehicle start command, collect the electrical characteristic parameters of the original vehicle start circuit, input them into the pre-trained start fault classification and recognition model to determine the fault type, and obtain the start circuit fault classification label;

[0064] S3. Collect vehicle operating status parameters in real time, call the pre-built vehicle start-up safety verification model to calculate, and obtain emergency operation safety verification results;

[0065] S4. When the emergency operation safety verification result is passed, the graded bypass conduction strategy is matched according to the fault classification label of the start-up circuit. The first bypass control branch and / or the second bypass control branch are selectively conducted in the integrated bypass control link to generate a temporary start-up conduction circuit after the bypass failure interlock node.

[0066] S5. Output a start drive electrical signal to the starter motor through the temporary start conduction circuit to drive the bus starter motor to perform emergency start of the whole vehicle.

[0067] In this embodiment, in step S1, the original bus starting interlock circuit is a 24V low-voltage series multi-level protection architecture. The interlocking limiting nodes in the circuit can be divided into two main categories according to their functions and electrical characteristics. The first category is the front-end control interlocking node, which includes the gear position interlocking switch and the door sensor interlocking switch. These two are connected in series in the low-voltage starting control circuit. Their function is to verify the mechanical safety status of the vehicle before starting. The fault manifestation of this is that the control circuit signal is broken, and the starter motor does not receive the starting command. The second category is the power supply main control interlocking node, namely the battery main switch control circuit. Its function is to control the on / off of the vehicle's high-voltage main power supply. The fault manifestation of this is that the main power supply cannot be connected, and the entire vehicle has no starting power supply. The fault locations, electrical levels, and fault mechanisms of the two types of nodes are completely different, and a single bypass branch cannot simultaneously adapt to both types of fault scenarios.

[0068] Based on this, the pre-designed integrated bypass control link integrates two electrically isolated and functionally independent bypass control branches. The first bypass control branch corresponds to the front-end control interlocking node and is connected in parallel across the series circuit of the gear position interlocking switch and the door sensor interlocking switch. Once the branch is active, the current can directly bypass the failed interlocking switch, restoring the low-voltage start control circuit and allowing the original vehicle start relay and starter control to receive the start signal normally. This branch is a low-voltage signal level branch with low operating current, effectively resolving the fault scenario of having power but no start signal. The second bypass control branch corresponds to the power master control interlocking node and is connected to the power input terminal and coil control terminal of the battery master switch using a bridging connection. Once the branch is active, the battery power can directly supply the drive coil of the battery master switch, forcibly driving the main contacts to close and restoring the vehicle's main power supply. This branch is a power control level branch, effectively resolving the fault scenario of no main power and no power to the entire vehicle.

[0069] Integrating two bypass control branches into a single integrated bypass control link, specifically within the same flame-retardant and waterproof control box, and uniformly configuring input / output terminals, controllable switching elements, and common protection components, can reduce the number of wiring points on the vehicle side, lower installation complexity, avoid the problems of messy wiring and excessive connectors caused by scattered wiring, and improve the overall reliability of the system. It also enables centralized management of the two branches, facilitating unified execution of safety verification, fault identification, and conduction strategies, reducing control signal transmission paths, and improving response speed. Furthermore, it allows for unified configuration of protection components, simplifying the hardware architecture and reducing costs and maintenance difficulty.

[0070] The integrated bypass control link constructed simultaneously covers two types of core interlocking faults: low-voltage control and power supply control. This significantly broadens the applicable scenarios for emergency start-up and solves the problem of single fault coverage in traditional solutions. Furthermore, the integrated architecture provides a unified hardware execution platform for subsequent intelligent algorithm control, which is the hardware foundation for this method to achieve accurate adaptation to multiple faults.

[0071] In this embodiment, in step S2, the electrical characteristics of the starting circuit will exhibit different behaviors depending on the type of fault. Interlock switch faults indicate a control circuit break; in this case, the main power supply and no-load voltage are normal, but there is no current output during startup. Battery main switch control circuit faults indicate that the main power supply is not connected, the no-load voltage is low or zero, and there is no electrical response during startup. Starter / power supply body faults manifest as normal power supply, but abnormal starting current (too high or too low) and abnormal voltage drop. Based on these differences, this step selects three core electrical characteristic parameters as inputs for fault identification: starting circuit no-load voltage, peak instantaneous starting current, and voltage drop recovery time. These three characteristics reflect the essence of the fault from three dimensions: power supply basic state, starting load characteristics, and circuit impedance characteristics, respectively, and their combination provides strong fault differentiation.

[0072] Specifically, step S2 includes:

[0073] S21. After the original vehicle start command is triggered, collect three types of electrical characteristic parameters from the start circuit: no-load voltage timing data, instantaneous start current peak data, and voltage drop recovery time. The no-load voltage is the battery static voltage under stable, unloaded conditions without start-up. The instantaneous start current peak is the maximum current value sampled at the moment the starter motor engages. Standardized collection and determination rules for voltage drop recovery time:

[0074] The timing start point is the instant when the voltage curve is collected at the lowest point of the drop, and the moment when the voltage begins to rise is not used;

[0075] The threshold determination benchmark is set at 90% of the no-load static voltage, which is the reset threshold. ,in, This is the no-load static voltage;

[0076] Oscillation filtering steady-state conditions: Voltage spikes and small oscillations are common during the start-up voltage recovery process; therefore, single voltage exceeding [a certain value] is not used. Recovery is determined by continuously collecting voltage values ​​within the window, ensuring all values ​​remain consistently above a certain level. Furthermore, the voltage is considered fully recovered only after the preset steady-state holding time of 50ms is reached.

[0077] Duration calculation: The time difference between the start of timing from the lowest point of the drop and the end point when the steady-state condition is met is the voltage drop recovery time.

[0078] S22. Normalize the three types of electrical characteristic parameters to eliminate dimensional differences and generate standardized feature vectors; the calculation formula is shown below:

[0079]

[0080] in, These are the normalized, standardized eigenvalues; These are the original electrical characteristic parameters of the i-th type; , These are the preset minimum and maximum values ​​for the corresponding feature parameters.

[0081] S23. Input the standardized feature vector into the pre-trained multi-class machine learning model and output the corresponding start-up circuit fault classification label. The start-up circuit fault classification label should include at least three categories: interlock switch faults, battery main switch control circuit faults, and starter / power supply body faults. The calculation formula is as follows:

[0082]

[0083] Where j is the fault category number, with values ​​1, 2, and 3 corresponding to interlock switch faults, battery main switch control circuit faults, and starter / power supply body faults, respectively. denoted as the confidence level for the j-th type of fault; a higher value indicates a greater likelihood of this type of fault. is the weight coefficient of the electrical feature corresponding to the j-th type of fault. This coefficient is obtained through training with a large number of fault samples in the early stage and reflects the contribution of the corresponding feature to the fault type; n is the total number of electrical features.

[0084] Furthermore, the multi-class machine learning model employs a support vector machine (RBF-SVM) multi-classifier based on radial basis function kernel functions. A one-vs-one strategy decomposes the three-class fault classification problem into three binary sub-problems. Each binary sub-problem is trained with its own SVM classifier, and the fault classification label is output through a voting mechanism. The model's training data comes from real-vehicle starting fault data collection from no fewer than 300 buses of different models (including city buses, tour buses, school buses, etc.). For each vehicle, under simulated fault conditions, three electrical characteristic parameters are collected: starting circuit no-load voltage, peak instantaneous starting current, and voltage drop recovery time. After normalization, standardized feature vectors are formed, and professional maintenance personnel label the corresponding actual fault types (interlock switch faults, battery main switch control circuit faults, starter / power supply body faults). A total of no fewer than 900 sets of labeled sample data are obtained, with no fewer than 300 sets of samples for each fault type to ensure sample class balance.

[0085] The model was trained using supervised learning, with the labeled sample dataset divided into training and test sets in a 7:3 ratio. During training, a combination of grid search and 5-fold cross-validation was used to globally optimize the SVM penalty parameter C and the radial basis function kernel width parameter γ. The cross-entropy loss function was used as the objective function for model optimization, and the average classification accuracy on the test set was used as the model performance evaluation metric.

[0086] After training, the optimized model parameters (including the support vectors, Lagrange multipliers, bias terms, and optimal C and γ parameters of each binary SVM) are stored in the non-volatile memory inside the data processing unit for use during actual vehicle operation.

[0087] In this embodiment, step S3 selects three core vehicle operating status parameters as inputs: vehicle speed signal, handbrake status signal, and ignition lock position signal. These three parameters, from three independent dimensions, together constitute the safety prerequisites for emergency start-up. The vehicle speed signal is used to determine whether the vehicle is stationary, which is the core basis for preventing accidental start-up while driving. The handbrake status signal is used to determine whether the vehicle is in a stable parking state, preventing the vehicle from rolling after starting. The ignition lock position signal is used to determine whether the operation comes from the driver's legitimate authorization, preventing unauthorized personnel from accidentally touching the device. All three parameters can be obtained in real time through the vehicle's CAN bus, without the need for the installation of a large number of additional sensors, resulting in strong adaptability and low installation cost.

[0088] The vehicle startup safety verification model employs a multi-dimensional Boolean joint decision formula. After converting continuous state parameters into binary flag bits, a logical AND operation is performed. Only when all safety conditions are simultaneously met is the verification result output. Specific step S3 includes:

[0089] S31. The vehicle status acquisition unit synchronously acquires three types of status parameters: vehicle speed signal, handbrake status signal, and ignition lock gear signal. A synchronous sampling mechanism is adopted to ensure that the three types of status parameters are taken from the same moment, avoiding judgment errors caused by sampling time difference. The acquired raw signals are first filtered to remove noise caused by CAN bus interference and signal jitter, ensuring the accuracy of status parameters.

[0090] S32. Input the three types of state parameters into the multi-dimensional Boolean verification model, and determine the vehicle stationary state, parking brake state, and ignition authorization state item by item; the specific calculation formula is as follows:

[0091]

[0092] in, The result of the emergency operation safety verification is 1, which means the verification passed and 0 means the verification failed. This is the vehicle stationary marker position; the value is 1 when the vehicle speed is 0, and 0 otherwise. This is the parking brake indicator. The value is 1 when the handbrake is locked, and 0 otherwise. This is the ignition authorization flag; it has a value of 1 when the key is in the ignition position, and 0 otherwise. For logical AND operation.

[0093] S33. When all three states simultaneously meet the preset security conditions, output the security verification result that passes the verification; when any one state fails the condition, output the verification result that fails and lock all bypass control branches in the integrated bypass control link.

[0094] Furthermore, step S3 also includes:

[0095] S34. Receive externally input authorization verification information and call a preset permission verification algorithm to verify identity legitimacy. The authorization verification information can take various forms, such as physical key verification, password verification, or vehicle key chip recognition, to meet the needs of vehicles with different security levels. The permission verification algorithm uses SHA-256 irreversible encryption verification, stores the authorization key hash value locally, and does not store the plaintext key to avoid the risk of key leakage.

[0096] Specifically, in step S34, the authorization verification information is entered in any of the following ways: Method 1: Password input, the user enters a 6-12 digit / letter combination authorization password through the touch screen or physical button of the driver's cab display terminal; Method 2: Physical key, the user brings the dedicated RFID chip key close to the sensing area installed in the driver's cab, and the system reads the unique identification code stored in the key chip through the RFID reader; Method 3: Vehicle key chip identification, the system obtains the original vehicle key's fixed identification information through the chip anti-theft reading coil when the original vehicle key is inserted into the ignition lock.

[0097] The complete permission verification process is as follows:

[0098] Receive authorization verification information (password string, RFID identification code or key chip identification code) input by the user, and convert it into a byte sequence of uniform length according to a preset data format;

[0099] The SHA-256 hash algorithm is called to perform an irreversible hash operation on the byte sequence, generating a 64-bit hexadecimal hash value;

[0100] The calculated hash value is compared bit by bit with the authorized key hash value pre-stored in the local non-volatile memory; if the two are completely consistent, the identity verification is deemed successful; if any bit is inconsistent, the verification is deemed unsuccessful.

[0101] After successful verification, an authorization unlock signal is output to the data processing unit to unlock the emergency start operation permission, and the authorization success indicator light on the cab display terminal is illuminated at the same time.

[0102] If the verification fails, the bypass control branch remains locked, and a message indicating that the authorization verification failed and to re-enter the information is displayed on the driver's cab terminal. If the number of consecutive verification failures reaches a preset threshold (e.g., 5 times), the system enters a locked state. During the locked period (e.g., 30 minutes), any new authorization verification request is rejected, and an anti-theft alarm message is output.

[0103] The initial configuration method for the authorization key is as follows: When this system is first installed on a vehicle, the authorized administrator connects to the system's configuration interface via a dedicated configuration tool (handheld configuration terminal or laptop). The administrator enters the initial authorization password or records the physical key identification code. The system performs a SHA-256 hash operation on this initial information, stores the hash value in local non-volatile memory, and simultaneously backs it up to the vehicle controller's secure storage area via a secure channel (encrypted transmission). If the authorization key needs to be changed subsequently, both the old and new keys must be verified. Only after successful dual verification can the stored hash value be overwritten and updated.

[0104] S35. Upon successful verification, the emergency start operation permission is unlocked; if verification fails, the bypass control branch remains locked. Authorization verification, as a supplementary step to safety verification, further prevents unauthorized operation of the emergency device by non-maintenance or non-driving personnel, avoiding vehicle theft or misoperation, and improving the device's safety.

[0105] In this embodiment, step S4 includes:

[0106] S41. After receiving the successful safety verification result, retrieve the fault classification tag of the current startup circuit. First, verify the safety verification result; only if the verification passes will the fault tag be retrieved and subsequent conduction operations executed. If the verification fails, skip all conduction steps to ensure the pre-constraint effect of safety verification and prevent the possibility of bypassing safety verification. This design ensures that all bypass conduction operations must be performed under safe conditions, eliminating the possibility of bypassing safety verification.

[0107] S42. If the fault classification label is an interlock switch fault, only the first bypass control branch is activated in the integrated bypass control link, bypassing the series control circuit of the bypass gear interlock switch and the door sensor interlock switch. When the fault is determined to be an interlock switch fault, the fault point is located in the low-voltage control circuit, while the main power supply and battery master switch are normal. In this case, only the first bypass control branch needs to be activated to restore the start control signal path, allowing the original vehicle start system to drive the starter motor according to normal logic. In this mode, only the failed interlock switch is bypassed; the battery master switch, starter relay, and other protective components still operate normally, preserving the original vehicle's protection mechanism to the greatest extent possible, resulting in higher safety during emergency operations.

[0108] S43. If the fault classification label is a battery master switch control circuit fault, only the second bypass control branch is activated in the integrated bypass control link, bypassing the original control coil circuit of the battery master switch. Specifically, when the fault is determined to be a battery master switch control circuit fault, the fault point is the battery master switch coil control line. In this case, the front-end interlock switch and starter relay are normal. Only the second bypass control branch needs to be activated to force the battery master switch to engage. After restoring the main power supply, the vehicle can be started normally with the original key. In this mode, the original vehicle's gear position and door interlock protection remain effective; only the power master control fault is repaired, also following the principle of minimal intervention.

[0109] S44. If the fault classification label is starter / power supply unit fault, no bypass control branch will be activated, and a unit fault prompt message will be output directly. Specifically, when the fault is determined to be a starter or battery unit fault, the bypass interlock node cannot resolve the issue. Activating the bypass in this case would not only be ineffective but could also increase electrical risks. Therefore, the system will not perform any bypass activation operation and will directly output a unit fault prompt, informing the operator that the fault is due to damage to a core power component, requiring replacement of the component or other methods such as jump-starting, to avoid ineffective operations and secondary faults.

[0110] Furthermore, step S4 also includes:

[0111] S45. After the single-circuit bypass is activated, if the starter still does not respond, the secondary fault verification process is automatically triggered. Specifically, after the single-circuit bypass is activated, the working status of the starter and the circuit current are monitored in real time. If no starting current or starter speed signal is detected for a preset duration (e.g., 2 seconds, which can be calibrated according to the starting characteristics of different vehicle models), it is determined that the single-circuit bypass has not solved the problem, and the secondary verification is triggered.

[0112] S46. Sequentially activate the remaining unused bypass control branches in the integrated bypass control link, re-collect the electrical characteristic parameters of the startup circuit, and update the fault classification label. The secondary verification adopts a step-by-step activation method, first activating the remaining bypass branch to form a dual-path simultaneous activation state, and then attempting startup again. Simultaneously, electrical characteristic parameters are re-collected, and the fault classification result is updated. This process is equivalent to reverse-verifying the fault determination result through the actual activation effect, compensating for errors in a single model identification.

[0113] S47. If there is still no starting response after all bypass control branches are connected, the fault is ultimately determined to be a starter / power supply unit failure, and a Level 1 alarm message is output. If the vehicle still cannot start after both bypasses are connected, all interlocking node faults can be ruled out, and the fault is confirmed to be a damage to the starter or battery unit. In this case, the highest level fault alarm is output to guide the operator to take the corresponding handling measures.

[0114] The secondary verification and iteration mechanism significantly improves the fault tolerance rate of emergency startup. Even if there is a deviation in the initial fault identification, emergency startup can be achieved through trial and error at each level. At the same time, more accurate fault location is achieved, balancing the success rate of emergency response and the accuracy of fault diagnosis.

[0115] In this embodiment, after the temporary starting conduction circuit is formed in step S5, the starting current can be transmitted to the starter motor through this circuit, driving the starter motor to rotate and ignite the engine. In this step, the maximum duration of continuous output of the starting drive electrical signal is set to 5 seconds. If the engine fails to ignite within 5 seconds, the output is automatically cut off to prevent the starter motor from burning out due to prolonged power supply. To ensure electrical safety during the starting process, an overcurrent protection control sub-step is also included in step S5, using an integral overcurrent judgment algorithm to achieve refined protection. Traditional overcurrent protection uses a single instantaneous threshold, cutting off the current immediately when it exceeds the threshold. However, the starter motor generates an inrush current several times the rated value at the moment of starting, which is a normal phenomenon, and the instantaneous threshold judgment is prone to false protection; if the threshold is set too high, the protection will not be timely when a real fault overcurrent occurs. Integral judgment perfectly solves this contradiction. Specifically, step S5 includes:

[0116] S51. Real-time acquisition of operating current timing data of the temporary start-up conduction circuit; a high-speed current sampling circuit is used to acquire the circuit operating current in real time at a frequency of 1kHz, forming continuous current timing data, which provides a basis for integral calculation.

[0117] S52. Compare the real-time operating current with the preset overcurrent threshold. If the duration of the operating current exceeding the threshold reaches the preset duration threshold, the overcurrent protection algorithm is triggered. The calculation formula is as follows:

[0118]

[0119] in, The overcurrent accumulation judgment value represents the degree of accumulation of overcurrent; t is the current startup duration. The preset overcurrent threshold is set according to the vehicle's rated starting current; For integration time; for Real-time operating current of the circuit; This is a time-dependent integral operator. The preset duration threshold is calibrated based on measured data of the vehicle's rated starting current and the duration of the starting inrush current, typically set to 100ms to 300ms. This ensures that it can withstand normal starting inrush current while also triggering protection in a timely manner during continuous fault overcurrent.

[0120] Accumulation only begins when the current exceeds the threshold. The more the current exceeds the threshold and the longer the duration, the faster the accumulated value increases. Although the inrush current at startup is large, its duration is very short, and the accumulated value will not reach the trigger threshold, thus not triggering the protection. However, continuous overcurrent caused by faults such as short circuits or jamming will cause the accumulated value to continue to grow, eventually triggering the protection.

[0121] The duration threshold can be adjusted according to the vehicle model, balancing shock resistance and protection response speed. The integral overcurrent protection can withstand the normal high current surge at startup, avoiding false protection and emergency failure, and can also cut off the circuit in time during continuous fault overcurrent, protecting the original vehicle electrical components, greatly improving the accuracy and reliability of electrical protection.

[0122] S53, the overcurrent protection algorithm output circuit cutoff command disconnects the conduction state of all bypass control branches in the integrated bypass control link, and simultaneously outputs overcurrent fault alarm information. After the engine starts successfully, all bypass control branches are automatically disconnected, restoring the original state of the original vehicle starting circuit, avoiding long-term connection of bypass branches from affecting the normal protection function of the original vehicle; at the same time, the complete data of this emergency start is recorded for subsequent model iteration and fault analysis.

[0123] In this embodiment, the method is also configured with a clutch failure gear shifting emergency start bypass function, specifically including:

[0124] When the driver / maintenance personnel activate the independent emergency start physical switch in the cab, the system receives the switch activation signal.

[0125] The data processing unit triggers the gear shift bypass control logic, and the locking determination link of the separate bypass gear interlock switch completely removes the original vehicle's hard interlock restriction that only allows starting in neutral.

[0126] At this time, the vehicle does not need to be in neutral. Even if the engine is off and forward / reverse gear is engaged, the system can still output a start drive electrical signal according to the temporary start conduction circuit to drive the starter motor to complete the gear engagement and emergency start. This is suitable for fault scenarios where the clutch release bearing or release fork is damaged and cannot be switched to neutral.

[0127] Meanwhile, this gear shift bypass function has safety constraints: the switch only takes effect when the vehicle's handbrake is locked and the vehicle speed is 0. Turning on the switch while the vehicle is in motion will not disengage the gear interlock, preventing safety hazards caused by accidental operation while driving, and taking into account both emergency functions and driving safety.

[0128] In this embodiment, the method is also equipped with an in-vehicle multi-source data fusion and interaction mechanism to solve the problem of disconnection between traditional devices and the vehicle system. Specifically, it is executed throughout the emergency start-up process:

[0129] The system simultaneously collects four types of operational data: safety verification results, fault classification labels, bypass conduction status, and emergency start operation records. These four types of data cover all dimensions of information, including safety status, fault diagnosis, execution status, and operation history, comprehensively reflecting the operational status of the emergency device.

[0130] The vehicle-mounted multi-source data fusion model is invoked to perform standardized format conversion and data association mapping on four types of operational data, generating standardized interactive data compatible with the vehicle's CAN bus protocol; the specific processing is divided into two steps:

[0131] Standardized conversion: Unified update cycle, all data is output at a fixed 100ms cycle, and the window average is used to align the time of sporadic instantaneous data collection; Unified data bit width, Boolean on / off signals occupy 1 bit, voltage and current values ​​are converted to 2-byte integers, and all data is adapted to the CAN bus single frame length of 8 bytes; Unified data frame, adopting the bus general SAEJ1939 standard bus frame, with fixed storage areas within the frame to store fault, switch, and alarm data respectively, and overly long data is automatically packetized for transmission.

[0132] Data association mapping: Fault tags are converted to vehicle fault codes using a fixed numbering correspondence rule. Each type of fault is matched with a unique standard diagnostic fault code (DTC), which can be directly identified by the vehicle diagnostic tool; mapping calculation formula:

[0133]

[0134] SPN stands for Suspicious Parameter Number; FMI stands for Fault Mode Identifier. Different faults have pre-defined SPN numbers, while open circuit faults have a uniform and fixed FMI value.

[0135] The bypass on / off status is converted into a switch quantity. Each of the two bypasses occupies 1 bit of binary signal. On is recorded as 1 and off is recorded as 0. The status is packaged and stored in a fixed byte of the bus frame, and the vehicle controller can directly read the on / off status.

[0136] The processed standardized interactive data is uploaded to the vehicle controller and the cab display terminal to visualize fault information and store operation logs locally.

[0137] Standardized interactive data is synchronously uploaded to the vehicle controller and the cab display terminal, enabling visualized display of fault information and local storage of operation logs. After data upload, the driver can directly view the fault type, bypass status, and alarm information on the cab instrument panel without leaving the vehicle to check the device status, significantly improving ease of use. Simultaneously, operation logs and fault data are stored in the vehicle diagnostic system for easy retrieval and analysis during subsequent maintenance, improving repair efficiency. This mechanism transforms emergency devices from isolated equipment into an integral part of the vehicle's electronic control system, significantly enhancing the intelligence and integration level of the solution.

[0138] In this embodiment, to improve the model's adaptability to multiple vehicle models and its long-term accuracy, this method also sets up a model incremental iterative optimization mechanism, which is executed after each emergency startup:

[0139] The system obtains the actual fault type confirmation information from external input, combines it with the fault classification label of the starting circuit, completes the data labeling to form a sample dataset, and obtains a fault sample dataset with real labels. After each emergency response, the maintenance personnel confirm the actual fault type and enter it into the system. The system automatically associates the electrical characteristic parameters at the corresponding time to form a fault sample with real labels and stores it in the local sample library.

[0140] The incremental learning algorithm is invoked to perform lightweight iterative training of the fault classification and identification model based on the newly added fault sample dataset; the calculation formula is shown below:

[0141]

[0142] in, The original weight coefficients of the j-th type of fault and the ith feature before the iterative update; These are the new weight coefficients after the lightweight iteration update, which are overwritten and stored after the iteration is complete. Set the learning rate; This is the one-hot encoded value of the actual fault label, where 1 corresponds to the category of the actual fault and 0 for the rest. This represents the confidence level of the model's original prediction. These are the standardized feature values ​​corresponding to this fault; To predict the error term, the feature weights are corrected in reverse based on the error, thereby continuously improving the accuracy of fault identification.

[0143] The model's internal classification weight parameters and decision thresholds are updated to improve fault classification and recognition accuracy under different vehicle models and operating conditions. As usage increases and sample data accumulates, the model weights are continuously optimized, and the fault recognition accuracy gradually improves. At the same time, the model will gradually adapt to the parameter differences of different vehicle models, eventually forming a dedicated fault recognition model adapted to the target vehicle, solving the problems of poor adaptability and decreased accuracy with use of fixed threshold models.

[0144] Example 2:

[0145] like Figure 3 As shown, this embodiment provides a bus starting interlock bypass emergency start control system for implementing the bus starting interlock bypass emergency start control method as described in Embodiment 1, including:

[0146] The integrated emergency control module 100 incorporates two independent bypass control branches, forming an integrated bypass control link covering multiple interlocking nodes. It also integrates an independent gear shifting emergency bypass branch, equipped with an external independent control switch outside the driver's cab, for bypass gear interlocking in case of clutch failure. The integrated emergency control module is equipped with an independent gear shifting emergency start physical switch; when the switch is turned on, it triggers the gear shifting bypass control logic, releasing the gear interlocking restriction. Both branches use high-power controllable relays as switching elements, featuring strong current carrying capacity, fast response, and long lifespan, meeting the high current switching requirements of the starting circuit. The module shell is made of flame-retardant and waterproof engineering material, with a protection level of no less than IP65, suitable for the harsh conditions of a bus engine compartment. The module's exterior features standardized quick-connect terminals, corresponding to the two ends of the gear interlocking switch, the battery master switch input, and the control terminal. The quick-connect structure eliminates the need for wire cutting during installation, adapting to different bus models' original wiring harnesses, making installation convenient and without damaging the original vehicle wiring.

[0147] Furthermore, the integrated emergency control module incorporates an electrical protection sub-circuit, which includes an overcurrent fuse, a reverse connection protection diode, and a controllable disconnect relay. The overcurrent fuse serves as hardware-level backup protection, rapidly blowing under extreme short-circuit faults to provide a final safety line. The reverse connection protection diode prevents the module from burning out due to reversed wiring. The controllable disconnect relay receives overcurrent protection commands from the data processing unit and executes circuit disconnection based on integral overcurrent judgment logic, serving as software-level active protection. This dual architecture of hardware and software protection significantly improves the system's electrical safety and reliability.

[0148] The status acquisition unit 200 is responsible for collecting various input parameters required for system operation. Its output is electrically connected to the input interface of the data processing unit. It includes a vehicle status acquisition subunit and an electrical parameter acquisition subunit. The vehicle status acquisition subunit interfaces with the vehicle's CAN bus, using a CAN transceiver to read three types of vehicle operating status parameters in real time: vehicle speed signal, handbrake status signal, and ignition lock gear signal. It employs opto-isolation design to prevent bus interference from affecting system operation. The electrical parameter acquisition subunit is connected in series in the main circuit of the starter circuit. It uses high-precision voltage and current sensors to collect three types of electrical characteristic parameters: no-load voltage of the starter circuit, instantaneous current peak value, and voltage drop duration. The sampling accuracy meets the parameter accuracy requirements for fault identification.

[0149] The data processing unit 300 incorporates a vehicle startup safety verification model, a startup fault classification and identification model, and a hierarchical bypass conduction strategy module. Its input is connected to the status acquisition unit, and its output is connected to the drive execution unit and the interactive output unit. It outputs safety verification results, fault classification labels, and bypass conduction control commands. The data processing unit uses an automotive-grade microcontroller as its core, featuring strong computing power, good anti-interference capabilities, and a wide operating temperature range, making it suitable for complex automotive operating conditions.

[0150] Specifically, the data processing unit includes a parameter preprocessing submodule, a model computation submodule, and an instruction output submodule. The parameter preprocessing submodule incorporates max-min normalization calculation logic to perform dimensionless processing on the collected raw electrical characteristic parameters, generating standardized feature vectors to provide standardized input for model computation. The model computation submodule runs the vehicle startup safety verification model and the startup fault classification and identification model, performing calculations based on Boolean joint decision formulas and weighted multi-classification decision formulas, and outputting the corresponding safety verification results and fault classification labels; model parameters are stored in internal non-volatile memory and are not lost when power is off. The instruction output submodule matches a graded conduction strategy based on the safety verification results and fault classification labels, generates and outputs bypass conduction control commands to control the actions of the drive execution unit.

[0151] Furthermore, the data processing unit also includes a model storage and update submodule, used to locally store labeled fault sample datasets and call incremental learning algorithms and gradient descent weight update formulas to complete parameter iteration and threshold updates for starting the fault classification and recognition model. This submodule is equipped with a dedicated storage chip, capable of storing thousands of fault sample data points to meet the needs of long-term iterative use; it supports offline updating of model parameters and can also import sample data through the vehicle diagnostic interface, offering flexible use.

[0152] The drive execution unit 400 connects to the data processing unit at its input and to the controllable switching element of the integrated emergency control module at its output. It receives bypass control commands from the data processing unit, generates a temporary start-up circuit in the integrated bypass control link, and outputs a start-up drive electrical signal to the starter motor. The drive execution unit employs an opto-isolated drive circuit to completely isolate the low-voltage control side from the high-voltage power side, preventing large current interference with the control circuit. The drive circuit also features freewheeling protection to suppress the back electromotive force when the relay disconnects, protecting the control elements from damage.

[0153] The interactive output unit 500 is used to output fault prompts, alarms, and visualized operating data, including a CAN bus interactive subunit and a driver's cab display terminal. The CAN bus interactive subunit incorporates an onboard multi-source data fusion model, converting system operating data into standardized data compatible with the vehicle's communication protocol and uploading it to the vehicle network to achieve data interaction with the vehicle's electronic control system. The driver's cab display terminal uses an LCD screen, installed on the center console for easy driver viewing, to visually display fault classification labels, bypass connectivity status, alarm information, and operation logs; it is also equipped with operation buttons for authorization verification, manual triggering of emergency start, and other operations.

[0154] The above-described specific embodiments are preferred embodiments of the bus start interlock bypass emergency start control method and system of this application, and are not intended to limit the specific implementation scope of this application. The scope of this application includes but is not limited to the specific embodiments described above. All equivalent changes made in accordance with the shape and structure of this application are within the protection scope of this application.

Claims

1. A method for emergency start control of a bus starting interlock bypass, characterized in that, Includes the following steps: S1. Obtain a preset integrated bypass control link, wherein the integrated bypass control link integrates a first bypass control branch and a second bypass control branch that are independent of each other and correspond to two types of interlocking faults respectively. S2. In response to the original vehicle start command, collect the electrical characteristic parameters of the original vehicle start circuit, input them into the pre-trained start fault classification and recognition model to determine the fault type, and obtain the start circuit fault classification label; S3. Collect vehicle operating status parameters in real time, call the pre-built vehicle start-up safety verification model to calculate, and obtain emergency operation safety verification results; S4. When the emergency operation safety verification result is passed, according to the fault classification label of the start-up circuit, the first bypass control branch and / or the second bypass control branch are selectively connected in the integrated bypass control link to generate a temporary start-up circuit after the bypass failure interlock node. S5. Output a start drive electrical signal to the starter motor through the temporary start conduction circuit to drive the bus starter motor to perform emergency start of the whole vehicle.

2. The bus start-stop interlocking bypass emergency start control method according to claim 1, characterized in that, Step S2 includes: S21. After the original vehicle start command is triggered, collect three types of electrical characteristic parameters of the start circuit: no-load voltage timing data, instantaneous start current peak data, and voltage drop recovery time. S22. Normalize the three types of electrical characteristic parameters to eliminate dimensional differences and generate standardized feature vectors. S23. Input the standardized feature vector into the pre-trained multi-class machine learning model and output the corresponding start-up circuit fault classification label. The start-up circuit fault classification label includes at least three categories: interlock switch faults, battery main switch control circuit faults, and starter / power supply body faults.

3. The bus start-stop interlock emergency start control method according to claim 1, characterized in that, Step S3 includes: S31. The vehicle status acquisition unit synchronously acquires three types of status parameters: vehicle speed signal, handbrake status signal, and ignition lock gear signal. S32. Input the three types of state parameters into the multi-dimensional Boolean verification model, and make a judgment on the vehicle stationary state, parking brake state and ignition authorization state respectively. S33. When all three states simultaneously meet the preset security conditions, output the security verification result that passes the verification; when any one state fails the condition, output the verification result that fails and lock all bypass control branches in the integrated bypass control link.

4. The bus start-stop interlock emergency start control method according to claim 3, characterized in that, Step S3 also includes: S34. Receive authorization verification information from external input and call the preset permission verification algorithm to verify the identity legitimacy. S35. After successful verification, unlock the emergency start operation permission; if the verification fails, maintain the locked state of the bypass control branch.

5. The bus start-stop interlock emergency start control method according to claim 1, characterized in that, Step S4 includes: S41. After receiving the successful security verification result, retrieve the fault classification label of the current startup circuit; S42. If the fault classification label is an interlock switch type fault, only the first bypass control branch is connected in the integrated bypass control link, and the series control circuit of the bypass gear interlock switch and the door sensing interlock switch is connected. S43. If the fault classification label is a fault in the battery main switch control circuit, only the second bypass control branch is connected in the integrated bypass control link to bypass the original control coil circuit of the battery main switch. S44. If the fault classification label is starter / power supply body fault, do not connect any bypass control branch, and directly output the body fault prompt information.

6. The bus starting interlock bypass emergency start control method according to claim 5, characterized in that, Step S4 also includes: S45. If the starter motor still does not start after the single-circuit bypass is activated, the secondary fault verification process will be automatically triggered. S46. Sequentially connect the remaining unused bypass control branches in the integrated bypass control link, re-collect the electrical characteristic parameters of the start-up circuit and update the fault classification label; S47. If there is still no start response after all bypass control branches are turned on, it is finally determined that the starter / power supply body is faulty and a first-level alarm message is output.

7. The bus starting interlock bypass emergency start control method according to claim 1, characterized in that, Step S5 includes: S51. Real-time acquisition of operating current timing data of the temporary start-up conduction circuit; S52. Compare the real-time operating current with the preset overcurrent threshold. If the duration of the operating current exceeding the threshold reaches the preset duration threshold, trigger the overcurrent protection algorithm. S53, the overcurrent protection algorithm outputs a circuit cutoff command, disconnecting the conduction state of all bypass control branches in the integrated bypass control link, and simultaneously outputs an overcurrent fault alarm message.

8. The bus starting interlock bypass emergency start control method according to claim 1, characterized in that, This method also includes in-vehicle data interaction, which is executed throughout the emergency start-up process: Simultaneously collect four types of operational data: safety verification results, fault classification labels, bypass conduction status, and emergency start operation records; The vehicle-mounted multi-source data fusion model is invoked to perform standardized format conversion and data association mapping on four types of operating data, generating standardized interactive data compatible with the vehicle's CAN bus protocol; Standardized interactive data is synchronously uploaded to the vehicle controller and the cab display terminal to complete the visualization of fault information and local storage of operation logs.

9. The bus starting interlock bypass emergency start control method according to claim 1, characterized in that, The method also includes an emergency start bypass function for clutch failure gear shifting, specifically including: Receives the signal to activate the emergency start switch; The bypass gear interlock switch's gear lock-up logic removes the interlock restriction that the gear can only be started in neutral. It allows the vehicle to directly output a start drive electrical signal to drive the starter motor while the engine is off and gear is engaged, enabling emergency starting when the clutch fails.

10. A bus starting interlock bypass emergency start control system, characterized in that, The method for implementing the bus start-up interlock bypass emergency start control method as described in any one of claims 1-9 includes: The integrated emergency control module has two independent bypass control branches built in, and an additional gear-shifting emergency bypass branch is added to form an integrated bypass control link covering multiple interlocking nodes. The status acquisition unit is used to collect vehicle operating status parameters and electrical characteristic parameters of the start-up circuit in real time. The data processing unit has a built-in vehicle start-up safety verification model, start-up fault classification and identification model, and hierarchical bypass conduction strategy module, which are used to output safety verification results, fault classification labels and bypass conduction control commands. The drive execution unit receives the bypass conduction control command, generates a temporary start conduction circuit, and outputs a start drive electrical signal to the starter motor. The interactive output unit is used to output fault prompts, alarms, and visualized operating data. The integrated emergency control module is equipped with an independent gear shift emergency start physical switch. When the switch is turned on, it triggers the gear shift bypass control logic and releases the gear interlock restriction.