Vehicle lamp control system based on deep fault safety mode
By monitoring the MCU status and cutting off the power link through the FS65 chip, the headlights are ensured to enter a deep fault-safe mode in case of a fault. This solves the problem of abnormal flickering when the headlights start up, and enables the headlights to be stably lit in fault conditions, thus improving driving safety.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Utility models(China)
- Current Assignee / Owner
- CHANGZHOU XINGYU AUTOMOTIVE LIGHTING SYST CO LTD
- Filing Date
- 2025-04-11
- Publication Date
- 2026-05-05
AI Technical Summary
Existing vehicle lighting control systems may fail to start correctly or even exhibit repeated flashing due to issues such as lost communication between the MCU and SBC, startup program failure, or reset failure during startup, which may affect driving safety.
Design a vehicle lighting control system based on deep fail-safe mode. The system monitors the working status of the MCU through the FS65 chip. When entering deep fail-safe mode, the power link with the MCU controller is cut off to ensure that the low beam headlights are independently powered through the Boost and Buck power management links to maintain stable lighting.
This effectively prevents the headlights from flashing repeatedly due to system reset, ensuring that the low beam headlights remain on in case of a malfunction, thus improving the safety and stability of the vehicle during driving.
Smart Images

Figure CN224205290U_ABST
Abstract
Description
Technical Field
[0001] This utility model relates to the field of vehicle lighting control technology, and in particular to a vehicle lighting control system based on deep fail-safe mode. Background Technology
[0002] With the increasing intelligence and automation of modern automobiles, vehicle lighting control systems are no longer limited to traditional switch control but integrate more intelligent control functions. For example, the on / off state and brightness adjustment of low beam headlights are usually controlled by the vehicle's electronic control unit (ECU). As in-vehicle electronic systems become more complex, vehicle lighting control systems face more challenges, especially regarding potential malfunctions during system startup, reset, and communication.
[0003] Current vehicle lighting control systems often experience problems during startup, such as lost communication between the MCU (Microcontroller Unit) and SBC (Safety Base Circuit), startup program failure, or reset failure. This can lead to the lights failing to start correctly or even exhibiting abnormal flickering. This phenomenon not only affects the external lighting effect of the vehicle but may also impair the driver's vision, thereby affecting driving safety.
[0004] To ensure that vehicle lights can continue to function properly in the event of a malfunction and can safely enter a fault mode, traditional vehicle lighting control systems typically require complex error detection and recovery mechanisms. However, existing technologies are still insufficient in effectively preventing headlights from flickering after multiple restarts or resets and ensuring that the system enters a functional safety mode in case of malfunction.
[0005] Therefore, there is an urgent need for a new vehicle lighting control system that can automatically recover and maintain normal operation of the headlights through a deep failsafe mode when encountering faults such as communication loss or startup failure, avoiding repeated flashing of the low beam headlights due to system reset, and ensuring that the vehicle can provide stable lighting support under any circumstances.
[0006] The above problems urgently need to be solved. Utility Model Content
[0007] The purpose of this invention is to provide a vehicle lighting control system based on deep fail-safe mode, which aims to solve at least one technical problem existing in the prior art.
[0008] This utility model embodiment provides a vehicle lighting control system based on deep failsafe mode. The control system includes: a power input interface, a power management module, a deep failsafe mode control module, an MCU controller, and an SBC module. The input terminal of the power management module is connected to an external vehicle power supply through the power input interface. The output terminal of the power management module is electrically connected to the low beam headlight to provide operating voltage for the low beam headlight. The output terminal of the power management module is electrically connected to the SBC module to provide operating voltage for the deep failsafe mode control module and the MCU controller through the SBC module. The output terminal of the MCU controller is connected to the deep failsafe mode control module. The input terminal of the full-mode control module is electrically connected and used to monitor the system status and send a watchdog signal to the deep fault-safe mode control module. The output terminal of the deep fault-safe mode control module is electrically connected to the input terminal of the SBC module and is used to diagnose the working status of the MCU controller based on the watchdog signal and / or SPI control signal, and to control the system to enter deep fault-safe mode when a fault occurs, sending a safety mode command to the SBC module through the SPI control mechanism. The SBC module is used to stop supplying power to the MCU controller based on the received safety mode command and trigger the default configuration of the power management module to directly supply power to the low beam headlight.
[0009] Furthermore, the power management module integrates Boost and Buck power management links, including a Boost boost circuit and a Buck buck circuit. The Boost boost circuit is connected in series with the input power supply to boost the power supply voltage via the power input interface. The Buck buck circuit is used to buck the voltage and output a stable voltage adapted to the operation of the low beam headlights.
[0010] Furthermore, the deep failsafe mode control module integrates an FS65 chip; the FS65 chip integrates a fault monitoring module, the input of which is electrically connected to the output of the MCU controller, and is used to diagnose the working status of the MCU controller through the SPI control signal sent by the MCU controller, and to control the system to enter deep failsafe mode when a fault occurs.
[0011] Furthermore, the FS65 chip also integrates a fault counting module. The input terminal of the fault monitoring module is electrically connected to the output terminal of the MCU controller, and is used to diagnose the working status of the MCU controller through the watchdog signal sent by the MCU controller, and send a fault signal to the fault counting module when a fault occurs. The input terminal of the fault counting module is electrically connected to the output terminal of the fault monitoring module, and is used to count the fault signals sent by the fault monitoring module.
[0012] Furthermore, the fault monitoring module is used to send a fault signal to the fault counting module if it does not receive a watchdog signal from the MCU controller within a certain period.
[0013] Furthermore, the fault counting module is also used to control the system to enter a deep fault-safe mode and send a safety mode command to the SBC module when the count value exceeds a preset threshold.
[0014] Furthermore, the FS65 chip is also used to send a safe mode command to the MCU controller via the SPI control mechanism when the system is in a deep failsafe mode, so that the MCU controller can shut down all regulators.
[0015] Furthermore, the deep fault-safe mode control module is connected to the power input interface via an IO pin. When the system is in deep fault-safe mode, the deep fault-safe mode control module can be powered on again via the IO pin to exit deep fault-safe mode and restore power supply to the MCU controller.
[0016] Furthermore, the SBC module is used to completely isolate all power links associated with the MCU controller based on the received safety mode instruction, and to enable the Boost and Buck power management links to operate according to the preset default configuration parameters so that they directly power the low beam headlights.
[0017] Furthermore, the Boost and Buck power management links have independent power sustainment paths, enabling them to continue operating according to their default configurations even after being disconnected from the MCU controller.
[0018] The beneficial effects of the technical solution provided by this utility model embodiment are as follows: This application provides a vehicle lighting control system based on deep fail-safe mode. Through the design of a power management module, a deep fail-safe mode control module, an MCU controller, and an SBC module, the problem of low beam headlight flickering during system malfunctions is solved. Specifically:
[0019] (1) Accurate fault diagnosis and rapid response are achieved by using the FS65 chip.
[0020] (2) By designing an independent power supply link for the low beam headlights in deep failsafe mode, it is ensured that the headlights can still be turned on normally when a fault occurs, thus avoiding the situation where the low beam headlights repeatedly flicker due to system reset.
[0021] (3) The vehicle lighting control system is prevented from entering an unstable state through a hardware-level power isolation mechanism.
[0022] (4) The recovery logic of this system is simple and reliable, which effectively reduces the operation and maintenance costs. Attached Figure Description
[0023] To more clearly illustrate the technical solutions in the embodiments of this utility model, the drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this utility model. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0024] Figure 1 This is a schematic diagram of a vehicle lighting control system based on deep fail-safe mode provided by an embodiment of this utility model.
[0025] Figure 2 This is a schematic diagram of a deep fault-safe mode control module provided in an embodiment of the present invention.
[0026] Figure 3 This is a flowchart of a vehicle lighting control system based on deep fail-safe mode provided by an embodiment of this utility model. Detailed Implementation
[0027] To make the objectives, technical solutions, and advantages of this utility model clearer, the embodiments of this utility model will be described in further detail below with reference to the accompanying drawings.
[0028] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains; the terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the invention. For example, terms such as “length,” “width,” “upper,” “lower,” “left,” “right,” “front,” “rear,” “vertical,” “horizontal,” “top,” “bottom,” “inner,” “outer,” “upper end,” “lower end,” and “middle” indicate orientations or positions based on the orientations or positions shown in the accompanying drawings and are merely for ease of description and should not be construed as limiting the invention.
[0029] The terms "comprising" and "having," and any variations thereof, in the specification, claims, and accompanying drawings of this utility model are intended to cover non-exclusive inclusion; the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this utility model are used to distinguish different objects, not to describe a specific order. "A plurality of" means two or more, unless otherwise explicitly specified.
[0030] Furthermore, the reference to "embodiment" herein means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of the present invention. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments. Example
[0031] For ease of understanding, the overall inventive concept of this utility model is described below: This utility model provides a vehicle lighting control system based on deep fail-safe mode to prevent vehicle lights from flickering or failing to illuminate properly due to system malfunctions during vehicle startup or reset. The FS65 chip is responsible for monitoring system faults. When the system resets or the MCU controller enters a fault state, the FS65 chip performs fault diagnosis by monitoring the MCU controller's watchdog signal and / or SPI control signal. If the MCU controller fails to feed the watchdog (i.e., fails to send a normal operation signal to the FS65 on time) or other faults are detected, the system enters deep fail-safe mode and cuts off the power link associated with the MCU controller to prevent the vehicle lighting control system from entering an unstable state. After entering this mode, all regulators are turned off to ensure the system no longer operates, avoiding misoperation of the low beam headlights. When the system enters deep fail-safe mode, the low beam headlights are continuously powered through the Boost and Buck power management links. This system, through deep fail-safe mode, ensures that the low beam headlights remain in a functionally safe state when communication is lost or startup fails, ensuring continuous illumination of the low beam headlights, thereby improving the safety and stability of the vehicle during operation.
[0032] For ease of understanding, the technical terms appearing in the following embodiments are explained here:
[0033] A watchdog timer is essentially a timer with the characteristics of a regular timer. When it times out, it triggers an event, which can be either a system interrupt or a system reset signal. In other words, a timer that can send a system reset signal is called a watchdog. When a hardware system has its watchdog function enabled, the software running on that hardware system must send a signal to the watchdog at specified time intervals. This behavior is simply called "feeding the dog" to prevent the watchdog timeout from triggering a system restart.
[0034] The specific implementation method is as follows:
[0035] like Figure 1-2 The diagram shown is a schematic diagram of a vehicle lighting control system based on deep fail-safe mode provided in an embodiment of this utility model.
[0036] As an example, the control system includes: a power input interface 1, a power management module 2, a deep failsafe mode control module 3, an MCU controller 4, and an SBC module 5; the input terminal of the power management module 2 is connected to an external vehicle power supply through the power input interface 1, and the output terminal of the power management module 2 is electrically connected to the low beam headlight 6 to provide operating voltage for the low beam headlight 6; the output terminal of the power management module 2 is electrically connected to the SBC module 5 to provide operating voltage for the deep failsafe mode control module 3 and the MCU controller 4 through the SBC module 5; the output terminal of the MCU controller 4 is connected to the input terminal of the deep failsafe mode control module 3. The terminal is electrically connected to monitor the system status and send a watchdog signal to the deep fault-safe mode control module 3; the output terminal of the deep fault-safe mode control module 3 is electrically connected to the input terminal of the SBC module 5, and is used to diagnose the working status of the MCU controller 4 based on the watchdog signal and / or SPI control signal, and control the system to enter deep fault-safe mode when a fault occurs, and send a safety mode command to the SBC module 5 through the SPI control mechanism; the SBC module 5 is used to stop supplying power to the MCU controller 4 based on the received safety mode command and trigger the default configuration of the power management module 2 to directly supply power to the low beam headlight 6.
[0037] In some feasible implementations, the power management module 2 integrates Boost and Buck power management links, including a Boost converter and a Buck converter. The Boost converter is connected in series with the input power supply to boost the power supply voltage via the power input interface 1. The Buck converter is used to step down the voltage and output a stable voltage adapted to the operation of the low beam headlight 6. Preferably, the Boost and Buck power management links are powered by two paths: one path directly powers the low beam headlight 6, and the other path powers the deep failsafe mode control module 3 and the MCU controller 4 via the SBC module. Specifically, the Boost and Buck power management links have independent power supply maintenance paths, allowing them to continue operating according to their default configuration even after disconnection from the MCU controller. More specifically, when the system enters deep failsafe mode, the low beam headlights will be continuously powered through the Boost and Buck power management links to ensure that the low beam headlights remain on and will not turn off even if the system malfunctions. This design meets the functional safety requirements of vehicle lights, ensuring that the low beam headlights remain usable even if the system malfunctions. This is because the Boost and Buck power management links operate independently and are no longer controlled by the MCU. Specifically, during circuit design, independent power sustainment paths are set up for the Boost and Buck power management links, allowing them to continue operating according to their default configurations even after being disconnected from the MCU.
[0038] In some feasible implementations, the deep fault-safe mode control module 3 integrates an FS65 chip; the FS65 chip integrates a fault monitoring module 300, the input of which is electrically connected to the output of the MCU controller 4, for diagnosing the operating state of the MCU controller 4 through the SPI control signal sent by the MCU controller 4, and controlling the system to enter deep fault-safe mode when a fault occurs. Specifically, diagnosing the operating state of the MCU controller 4 through the SPI control signal sent by the MCU controller 4 and controlling the system to enter deep fault-safe mode when a fault occurs includes: when the SPI control signal is the power supply voltage (VCC): monitoring whether the power supply to the MCU controller 4 is stable, such as determining whether the voltage is between 9V and 16V; if not, a fault is diagnosed; when the SPI control signal is temperature sensor data: to prevent the MCU controller from overheating, determining whether the temperature sensor data is >125℃; if so, a fault is diagnosed. When the SPI control signal is the output drive current: To avoid overload, it checks if the current value is greater than 150% of the rated value. If so, a fault is diagnosed. When detecting SPI control signal communication timeout: If the FS65 does not receive a response from the MCU within a specified time (e.g., SPI timeout > 100ms), a communication fault is diagnosed. When a fault is diagnosed, the control system enters deep failsafe mode.
[0039] In some feasible implementations, the FS65 chip also integrates a fault counting module 310. The input terminal of the fault monitoring module 300 is electrically connected to the output terminal of the MCU controller 4, used to diagnose the operating status of the MCU controller 4 through the watchdog signal sent by the MCU controller 4, and to send a fault signal to the fault counting module 310 when a fault occurs. The input terminal of the fault counting module 310 is electrically connected to the output terminal of the fault monitoring module 300, used to count the fault signals sent by the fault monitoring module 300. Specifically, the fault monitoring module 300 sends a fault signal to the fault counting module 310 if it does not receive a watchdog signal from the MCU controller 4 within a specific period. For example, if it detects a failure to feed the watchdog (i.e., failure to send a normal operation signal to the FS65 chip on time), it sends a pulse signal to the fault counting module 310. The fault counting module 310 is also used to control the system to enter a deep failsafe mode and send a safety mode command to the SBC module 5 when the count value exceeds a preset threshold. Specifically, when the accumulated count value of the fault counting module 310 exceeds 5, the control system enters a deep failsafe mode and sends a safety mode command to the SBC module 5. Simultaneously with sending the safety mode command to the SBC module 5, the fault counting module 310 initializes its internal counter.
[0040] In other words, the system continuously detects whether the MCU has experienced a program fault by feeding a watchdog timer to the FS65. Once a program fault occurs, if the MCU's application fails to feed the watchdog timer, the FS65 will generate a watchdog failure count. When this count exceeds a set threshold (default is 5 times), the SBC (System Basis Chip) will enter a deep fault state and will no longer supply power to the MCU controller 4. At this time, the Boost and Buck power management links bypass the MCU's logic control and illuminate the low beam headlights according to the default configuration, ensuring that the system does not enter an unstable flickering state due to multiple resets or startup failures. Specifically, the Boost and Buck power management links operate according to pre-set default configuration parameters. These parameters are determined during the design phase to ensure that a stable voltage and current sufficient for the low beam headlights to operate normally in deep fault-safe mode, allowing the low beam headlights to remain illuminated. For example, the Boost circuit maintains a certain fixed boost ratio, and the Buck circuit maintains a specific buck output.
[0041] In some feasible implementations, the FS65 chip is also used to send a safety mode command to the MCU controller 4 via the SPI control mechanism when the system is in a deep failsafe mode, causing the MCU controller 4 to shut down all regulators. Specifically, the FS65 chip sends a safety mode command to the MCU controller via SPI, forcing it to shut down all regulators, such as PWM output and GPIO control. For example, the FS65 sends a 0x5A command, and upon receiving it, the MCU controller immediately stops outputting the low beam headlight drive signal. This ensures that the system no longer operates and avoids accidental operation of the low beam headlights.
[0042] In some feasible implementations, the deep fault-safe mode control module 3 is connected to the power input interface 1 via an I / O pin. When the system is in deep fault-safe mode, it can be powered on again via the I / O pin to exit deep fault-safe mode and restore power to the MCU controller 4. Specifically, as shown... Figure 2 The IO_0 pin shown is connected to the vehicle's power supply as the control interface for deep fault-safe mode. If the system is in a deep fault state, resetting it requires powering it back on. At this point, the FS65 exits deep fault mode and begins supplying power to the MCU. If the system remains unstable after restarting, it will remain in deep fault-safe mode to avoid unnecessary malfunctions caused by repeated restarts. More specifically, the IO_0 pin is used to control system power recovery. When entering deep fault-safe mode, the IO_0 pin remains low; after system recovery, it is set high to resume normal operation.
[0043] In some feasible implementations, the CAN interface of SBC module 5 is used to communicate with external devices, ensuring that the MCU can exchange data and transmit control commands with other systems after a reset or fault recovery. For example, it can communicate with the BCM.
[0044] Combination Figure 3 As shown, the system's workflow is as follows: Power on; the FS65 chip resets the MCU controller; initially, the low beam headlights are off; it checks if the MCU controller has malfunctioned and the watchdog timer has failed to feed; if no MCU controller malfunction is detected and the watchdog timer fails to feed, the lighting logic is executed based on the CAN signal; if the MCU controller malfunction is detected and the watchdog timer fails to feed, the fault counter in the FS65 chip starts counting; it checks if the accumulated value of the fault counter exceeds a preset threshold; if the accumulated value of the fault counter exceeds the preset threshold, the SBC module shuts down all power supplies to the backend; the MCU processor is completely off; the Boost and Buck power management links directly supply power to the low beam headlights according to the preset default configuration parameters; the low beam headlights are now on.
[0045] The above embodiments ensure that the low beam headlights remain in a functionally safe state when communication is lost or startup fails through deep fail-safe mode, thereby ensuring the continuous illumination of the low beam headlights and improving the safety and stability of the vehicle during driving.
[0046] The above description is only a preferred embodiment of the present utility model, but the protection scope of the present utility model is not limited thereto. Any equivalent substitutions or changes made by those skilled in the art within the technical scope disclosed in the present utility model, based on the technical solution and the inventive concept of the present utility model, should be included within the protection scope of the present utility model.
Claims
1. A vehicle lighting control system based on deep fail-safe mode, characterized in that, The control system includes: a power input interface, a power management module, a deep fault-safe mode control module, an MCU controller, and an SBC module; The power management module input terminal is connected to the vehicle power supply through the power input interface, and the power management module output terminal is electrically connected to the low beam headlight to provide the working voltage for the low beam headlight. The output terminal of the power management module is electrically connected to the SBC module, and is used to provide operating voltage to the deep fault-safe mode control module and the MCU controller through the SBC module; The output terminal of the MCU controller is electrically connected to the input terminal of the deep fault-safe mode control module, and is used to monitor the system status and send a watchdog signal to the deep fault-safe mode control module. The output of the deep fault-safe mode control module is electrically connected to the input of the SBC module. It is used to diagnose the working state of the MCU controller based on the watchdog signal and / or SPI control signal, and to control the system to enter deep fault-safe mode when a fault occurs, and to send a safety mode command to the SBC module through the SPI control mechanism. The SBC module is used to stop supplying power to the MCU controller based on the received safe mode command and trigger the default configuration of the power management module to directly supply power to the low beam headlight.
2. The vehicle lighting control system based on deep fail-safe mode as described in claim 1, characterized in that, The power management module integrates Boost and Buck power management links, including a Boost boost circuit and a Buck buck circuit. The Boost boost circuit is connected in series with the input power supply to boost the power supply voltage via the power input interface. The Buck buck circuit is used to buck the voltage and output a stable voltage adapted to the operation of the low beam headlights.
3. The vehicle lighting control system based on deep fail-safe mode as described in claim 1, characterized in that, The deep fault-safe mode control module integrates an FS65 chip. The FS65 chip integrates a fault monitoring module. The input terminal of the fault monitoring module is electrically connected to the output terminal of the MCU controller. It is used to diagnose the working status of the MCU controller through the SPI control signal sent by the MCU controller, and to control the system to enter a deep fault-safe mode when a fault occurs.
4. The vehicle lighting control system based on deep fail-safe mode as described in claim 3, characterized in that, The FS65 chip also integrates a fault counting module. The input terminal of the fault monitoring module is electrically connected to the output terminal of the MCU controller. It is used to diagnose the working status of the MCU controller through the watchdog signal sent by the MCU controller, and to send a fault signal to the fault counting module when a fault occurs. The input terminal of the fault counting module is electrically connected to the output terminal of the fault monitoring module, and is used to count the fault signals sent by the fault monitoring module.
5. The vehicle lighting control system based on deep fail-safe mode as described in claim 4, characterized in that, The fault monitoring module is used to send a fault signal to the fault counting module if it does not receive a watchdog signal from the MCU controller within a certain period.
6. The vehicle lighting control system based on deep fail-safe mode according to claim 4, characterized in that, The fault counting module is also used to control the system to enter a deep fault-safe mode and send a safety mode command to the SBC module when the count value exceeds a preset threshold.
7. The vehicle lighting control system based on deep fail-safe mode according to claim 3, characterized in that, The FS65 chip is also used to send a safe mode command to the MCU controller via the SPI control mechanism when the system is in a deep failsafe mode, so that the MCU controller can shut down all regulators.
8. The vehicle lighting control system based on deep fail-safe mode as described in claim 1, characterized in that, The deep fault-safe mode control module is connected to the power input interface via an IO pin. When the system is in deep fault-safe mode, the deep fault-safe mode control module can be powered back on via the IO pin to exit deep fault-safe mode and restore power to the MCU controller.
9. The vehicle lighting control system based on deep fail-safe mode as described in claim 1, characterized in that, The SBC module is used to completely isolate all power links supplying power to the MCU controller based on the received safety mode command, and to enable the Boost and Buck power management links to operate according to the preset default configuration parameters so that they directly supply power to the low beam headlights.
10. The vehicle lighting control system based on deep fail-safe mode according to claim 9, characterized in that, The Boost and Buck power management links have independent power sustainment paths, enabling them to continue operating according to their default configurations even after being disconnected from the MCU controller.