A safety torque off circuit, an elevator control system, and a control method
By using a dual-channel safety torque shutdown circuit, and combining the detection module and drive buffer with the fault diagnosis of the monitoring MCU module, the problems of complex STO circuit and insufficient hardware fault margin are solved, thereby simplifying the elevator control circuit and improving safety.
Patent Information
- Application Number
- CN202210912928.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-07-31
- Publication Date
- 2026-02-06
- Estimated Expiration
- 2042-07-31
AI Technical Summary
Existing elevator control schemes have complex STO circuits with many components and large space requirements, making it difficult to adapt to the trend of smaller control cabinets, and the hardware fault margin is insufficient.
A dual-channel safety torque shutdown circuit is adopted, with each channel including a detection module and a drive buffer, which are connected to the elevator motor arm. The detection module controls the enabling and disabling of the drive buffer according to the voltage at the end of the elevator safety circuit, and combines it with the monitoring MCU module for fault diagnosis and control.
This approach achieves a hardware fault margin of 1 while reducing circuit size, simplifies the elevator control circuit structure, and improves safety and reliability.
Smart Images

Figure CN115167237B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of elevator safety, in particular to a safe torque off circuit, an elevator control system, and a control method. BACKGROUND
[0002] Currently, in the elevator control scheme, a STO (Safe Torque Off) with a safety integrity level of SIL3 and a hardware failure margin of at least 1 is allowed to replace the main contactor in the conventional elevator control scheme to reduce elevator noise and reduce costs. The STO circuit in the related art is generally complex, uses many devices, and occupies a large space, which is contrary to the trend of the increasingly reduced electrical control cabinet in the elevator. SUMMARY
[0003] The embodiments of the present application provide a safe torque off circuit, an elevator control system, and a control method, which can reduce the volume while ensuring the hardware failure margin.
[0004] In one aspect, the embodiments of the present application provide a safe torque off circuit, comprising: two channels;
[0005] Each of the channels comprises: a detection module and a drive buffer; wherein the drive buffers of the first channel and the second channel are respectively connected to the drive optocouplers corresponding to the upper bridge arm and the lower bridge arm of the elevator motor;
[0006] The detection module is connected to the end of the elevator safety circuit, and is configured to enable the drive buffer of the channel in the case that the voltage at the end of the elevator safety circuit is normal, and to close the drive buffer of the channel in the case that the voltage at the end of the elevator safety circuit is abnormal;
[0007] The drive buffer is configured to forward the PWM signal received from the outside to the connected drive optocoupler in the enabled case.
[0008] Exemplarily, the detection module comprises: a detection unit and a switching unit;
[0009] The detection unit is configured to detect the voltage at the end of the elevator safety circuit, and to send a first level to the switching unit in the case that the voltage at the end of the elevator safety circuit is normal, and to send a second level to the switching unit in the case that the voltage at the end of the elevator safety circuit is abnormal;
[0010] The switching unit is configured to send a drive enable signal of a first state to the drive buffer of the channel to enable the drive buffer in the case that the first level is received, and to send a drive enable signal of a second state to the drive buffer of the channel to close the drive buffer in the case that the second level is received.
[0011] Exemplarily, each of the channels further comprises a power module and a drive buffer power control module.
[0012] The power module is configured to convert the connected external power into a first control voltage of a predetermined size, and provide the drive buffer power control module and the detection module of the channel.
[0013] The drive buffer power control module is configured to generate a second control voltage of a predetermined size according to the first control voltage, and provide the drive buffer of the channel.
[0014] Exemplarily, the safety torque off circuit further comprises a monitoring MCU module.
[0015] In each channel, the power module is further configured to provide the first control voltage to the monitoring MCU module, the detection module is further configured to provide a detection signal to the monitoring MCU module, and provide a drive enable signal to enable or disable the drive buffer of the channel; and the drive buffer is further configured to send a PWM detection output signal to the monitoring MCU module according to a PWM detection input signal provided by the monitoring MCU module.
[0016] The monitoring MCU module is configured to perform one or more of the following operations on each channel:
[0017] In the case that the first control voltage of the channel is abnormal, the drive buffer of the channel is disabled.
[0018] In the case that the detection signal provided by the channel is inconsistent with the pulse signal, or the drive enable signal is inconsistent with the detection signal, the drive buffer of the channel is disabled.
[0019] In the case that any PWM signal output by the channel is faulty, or the PWM detection output signal provided by the channel is inconsistent with the PWM detection input signal provided to the channel, the drive buffer of the channel is disabled.
[0020] Exemplarily, the pulse signal sent by the monitoring MCU module to the first channel has a phase difference of 180 degrees with the pulse signal sent to the second channel.
[0021] The PWM detection input signal sent by the monitoring MCU module to the first channel has a phase difference of 180 degrees with the PWM detection input signal sent to the second channel.
[0022] Exemplarily, the power module comprises a voltage stabilizer configured to convert the connected external power into a first control voltage output of a predetermined size.
[0023] The monitoring MCU module closes the drive buffer of the channel in the case of abnormality of the first control voltage of the channel.
[0024] The monitoring MCU module monitors the first control voltage output by the voltage regulator, and cuts off the output of the power module in the case of short circuit of the power module according to the first control voltage; in the case of detecting that the first control voltage exceeds a predetermined overvoltage threshold or detecting that the first control voltage is less than a predetermined undervoltage threshold, the drive buffer of the channel is closed by changing the detection enable signal sent to the detection module of the channel.
[0025] Exemplarily, the voltage regulator is a low-dropout linear voltage regulator.
[0026] The power module further comprises a fuse and a clamping diode; one end of the fuse is connected to the output end of the low-dropout linear voltage regulator, and the other end is connected to the detection module, the drive buffer, the monitoring MCU module, and the negative electrode of the clamping diode.
[0027] The positive electrode of the clamping diode is grounded.
[0028] In the case of short circuit of the power module, the fuse performs a self-recovery action to disconnect the output of the power module.
[0029] Exemplarily, the detection module comprises a detection unit and a switching unit.
[0030] The detection unit is used to detect the terminal voltage of the elevator safety circuit, and receives the pulse signal and the detection enable signal output by the monitoring MCU module; the detection signal generated by the detection unit is provided to the monitoring MCU module and the switching unit.
[0031] The switching unit is used to generate a drive enable signal according to the detection signal, and provide the drive enable signal to the monitoring MCU module and the drive buffer of the channel.
[0032] Exemplarily, the monitoring MCU is further used to provide a power supply enable signal to the drive buffer power control module of each of the two channels.
[0033] The drive buffer power control module is used to generate a second control voltage of a predetermined size according to the first control voltage.
[0034] The drive buffer power control module is used to generate a second control voltage of a predetermined size according to the first control voltage and the power supply enable signal sent by the monitoring MCU, and provide the second control voltage to the drive buffer of the channel.
[0035] The monitoring MCU module closes the driving buffer of the channel in the case that the detection signal provided by the channel is inconsistent with the pulse signal, or the driving enable signal is inconsistent with the detection signal.
[0036] The monitoring MCU module stops the power supply of the driving buffer of the channel by changing the power supply enable signal sent to the driving buffer power supply control module of the channel in the case that the detection signal of the channel is inconsistent with the signal parameter of the pulse signal provided to the channel, or the detection signal is consistent with the signal parameter of the pulse signal, but the driving enable signal is not a predetermined waveform; the signal parameter includes one or more of the following: frequency, amplitude, duty cycle.
[0037] Exemplarily, the monitoring MCU module closes the driving buffer of the channel in the case that any one of the PWM signals output by the channel is faulty, or the PWM detection output signal of the channel is inconsistent with the PWM detection input signal provided to the channel.
[0038] The monitoring MCU module stops the power supply of the driving buffer of the channel by changing the power supply enable signal and the detection enable signal provided to the channel in the case that any one of the PWM signals output by the channel is faulty, or the signal parameter of the PWM detection output signal of the channel is inconsistent with the PWM detection input signal provided to the channel; the signal parameter includes one or more of the following: frequency, amplitude, duty cycle.
[0039] Exemplarily, the detection unit is an optocoupler, and the switching unit is a triode.
[0040] The output end of the optocoupler is connected to the base of the triode, the emitter of the triode is grounded, and the collector is connected to a first control voltage of a predetermined size to output the driving enable signal.
[0041] In another aspect, the embodiments of the present application provide an elevator control system, comprising:
[0042] The safety torque off circuit, the elevator safety circuit, the driving MCU module, and the driving optocoupler in any of the above embodiments;
[0043] The safety torque off circuit is configured to receive a PWM signal output by the driving MCU module, and determine whether to forward or not to forward the PWM signal to the driving optocoupler according to the end voltage of the elevator safety circuit.
[0044] The driving optocoupler drives the elevator motor when receiving the PWM signal.
[0045] In still another aspect, the embodiments of the present application provide a control method, based on the safety torque off circuit implementation of any of the above embodiments, comprising:
[0046] In the case of normal end voltage of the elevator safety circuit, output the received PWM signal to a driving optocoupler for driving the elevator motor; in the case of abnormal end voltage of the elevator safety circuit, close the output of the PWM signal.
[0047] Exemplarily, the control method further comprises:
[0048] For each channel, one or more of the following operations are performed:
[0049] In the case of abnormal first control voltage of the channel, close the PWM signal output of the channel; wherein the first control voltage is a predetermined size of voltage converted from an external power supply;
[0050] In the case of inconsistency between the detection signal generated by the channel and the pulse signal input to the channel, or inconsistency between the driving enable signal and the detection signal, close the PWM signal output of the channel; wherein the detection signal is generated according to the end voltage of the elevator safety circuit and the pulse voltage received by the channel; the driving enable signal is generated according to the detection signal;
[0051] In the case of any PWM signal fault output by the channel, or inconsistency between the PWM detection output signal generated by the channel and the PWM detection input signal provided to the channel, close the PWM signal output of the channel.
[0052] Exemplarily, the closing of the PWM signal output of the channel comprises one or more of the following ways:
[0053] Disconnect the total power supply in the channel;
[0054] Disconnect the power supply provided to the driving buffer in the channel;
[0055] Change the detection enable signal in the channel, thereby changing the driving enable signal.
[0056] Compared with the related art, the embodiment of the application sets two channels in the safety torque off circuit, sets a detection module and a drive buffer in each channel, the drive buffers of the first channel and the second channel are respectively connected with the drive optocoupler corresponding to the upper bridge arm and the lower bridge arm of the elevator motor, and the detection module is connected with the end of the elevator safety circuit. In the case that the voltage at the end of the elevator safety circuit is normal, the drive buffer of the channel is enabled, and in the case that the voltage at the end of the elevator safety circuit is abnormal, the drive buffer of the channel is closed. The scheme that the drive buffer forwards the PWM signal received from the outside to the connected drive optocoupler in the enabled case can realize the safety torque off for the elevator with a relatively simple circuit structure, and the design of the double channels can ensure that the hardware safety margin is 1.
[0057] Other features and advantages of the application will be set forth in the following description, and in part will become apparent from the description, or can be learned by practice of the application. Other advantages of the application will be realized and attained by the embodiments of the application described in the specification and claims. BRIEF DESCRIPTION OF DRAWINGS
[0058] The accompanying drawings are included to provide an understanding of the application, and constitute a part of the specification, together with the embodiments of the application, to explain the technical scheme of the application, and do not constitute a limitation on the technical scheme of the application.
[0059] Figure 1 is a schematic diagram of the safety torque off circuit provided by the embodiment 1 of the application;
[0060] Figure 2 is a schematic diagram of the safety torque off circuit provided by the embodiment 2 of the application;
[0061] Figure 3 is a schematic diagram of the safety torque off circuit provided by the embodiment 3 of the application;
[0062] Figure 4 is a schematic diagram of the example of the embodiment 3 of the application;
[0063] Figure 5 is a schematic diagram of the power supply module in the example of the embodiment 4 of the application;
[0064] Figure 6 is a schematic diagram of the drive buffer power supply control module in the example of the embodiment 4 of the application;
[0065] Figure 7 is a schematic diagram of the detection module in the example of the embodiment 5 of the application;
[0066] Figure 8 is a schematic diagram of the drive buffer in the example of the embodiment 6 of the application;
[0067] Figure 9 is a schematic diagram of an elevator control system provided by Embodiment 7 of the present application;
[0068] Figure 10 is a flowchart of a control method provided by Embodiment 8 of the present application. DETAILED DESCRIPTION
[0069] The present application describes multiple embodiments, but the description is exemplary rather than limiting, and it will be apparent to those of ordinary skill in the art that many more embodiments and implementations are possible within the scope of the embodiments described in the present application. Although many combinations of possible features are shown in the drawings and discussed in the detailed description, many other combinations of the disclosed features are possible. Unless specifically limited, any feature or element of any embodiment can be utilized with any other feature or element of any other embodiment, or can replace any other feature or element in any other embodiment.
[0070] The present application includes and contemplates combinations of features and elements known to those of ordinary skill in the art. The embodiments, features, and elements disclosed in the present application can also be combined with any conventional features or elements to form unique inventive solutions defined by the claims. Any feature or element of any embodiment can also be combined with features or elements from other inventive solutions to form another unique inventive solution defined by the claims. Therefore, it should be understood that any feature shown and / or discussed in the present application can be implemented alone or in any appropriate combination. Accordingly, the embodiments are not to be restricted, except as by the appended claims and their equivalents. Furthermore, various modifications and changes can be made within the scope of the appended claims.
[0071] Furthermore, in describing representative embodiments, the specification can have presented the method and / or process as a particular sequence of steps. However, to the extent that the method or process depends on more than one step, the method or process should not be limited to the particular sequence of steps described. Other sequences of steps can be possible, depending on the particular implementation, and the sequence of steps need not be performed in the order presented in this specification. The specific order of steps presented in the specification should not be construed as a limitation on the claims. Furthermore, the claims should not be limited to the steps of the method and / or process in the order presented in this specification. Those of ordinary skill in the art will readily recognize that the order of steps can be varied, and still remain within the spirit and scope of the embodiments of the present application.
[0072] The description used herein with respect to "first", "second", etc. is only for the purpose of description and should not be understood as indicating or implying relative importance or implicitly indicating the number of the technical features indicated. Therefore, the features defined as "first", "second" can explicitly or implicitly include at least one of the features. In the description of the present application, the meaning of "a plurality of" is at least two, such as two, three, etc., unless otherwise explicitly specified and limited.
[0073] In the present application, unless otherwise explicitly specified and limited, the terms "connection", "fixing" and the like should be understood broadly, for example, "fixing" can be fixed connection, or detachable connection, or integral; can be mechanical connection, or electrical connection; can be direct connection, or indirect connection through intermediate medium; can be internal connection of two elements or interaction relationship between two elements, unless otherwise explicitly limited. For those skilled in the art, the specific meaning of the above terms in the present application can be understood according to the specific circumstances.
[0074] Embodiment 1
[0075] The present embodiment provides an STO circuit, as shown in Figure 1 including: channel A and channel B; channel A includes: detection module 231 and drive buffer 241; channel B includes: detection module 232 and drive buffer 242;
[0076] The detection module 231 is connected to the end of the elevator safety circuit, and if the end voltage is normal, the drive buffer 241 is enabled; if the end voltage is abnormal, the drive buffer 241 is closed;
[0077] The detection module 232 is also connected to the end of the elevator safety circuit, and if the end voltage is normal, the drive buffer 242 is enabled; if the end voltage is abnormal, the drive buffer 242 is closed;
[0078] The drive buffer 241 and the drive buffer 242 receive a PWM (Pulse Width Modulation) signal from the outside of the STO circuit, and output the PWM signal when enabled; specifically, the drive buffer 241 outputs to the drive optocoupler 41 corresponding to the upper bridge arm of the elevator motor; the drive buffer 242 outputs to the drive optocoupler 42 corresponding to the lower bridge arm of the elevator motor.
[0079] In the embodiment, the STO can be realized by fewer devices, the volume of the STO circuit can be reduced, and thus the trend of the smaller electric control cabinet of the elevator can be met; two channels are provided, channel A is used for controlling three IGBTs (Insulated Gate Bipolar Transistor) of the upper bridge arm, and channel B is used for controlling three IGBTs of the lower bridge arm, so that the elevator motor cannot run when only the upper bridge arm IGBT is turned on or only the lower bridge arm IGBT is turned on; therefore, channel A and channel B realize two-way redundancy, and the hardware failure margin is ensured to be 1.
[0080] In the embodiment, the PWM signal received from the outside can come from a driving MCU (Micro Controller Unit) module, and there are six channels in total, three of which correspond to the three inputs of the driving buffer 241 of channel A corresponding to the upper bridge arm, and the other three correspond to the three inputs of the driving buffer 242 of channel B corresponding to the lower bridge arm.
[0081] In the embodiment, the optocoupler can also be called a photoelectric coupler or a photoelectric isolator; the driving optocoupler is used for driving the elevator, and there are six in total, three of which correspond to the upper bridge arm, and the other three correspond to the lower bridge arm.
[0082] In the embodiment, closing the driving buffer can mean, but is not limited to, that the driving buffer cannot output the PWM signal due to no power supply or no enablement, or can mean that the driving buffer outputs a low-level PWM signal, which cannot allow the driving optocoupler to drive the elevator motor to work.
[0083] The "channel" in the embodiment is to distinguish different circuit paths, so as to distinguish the components belonging to different circuit paths; one channel can be regarded as a plurality of components in the channel.
[0084] Exemplarily, the detection module 231 can include a detection unit and a switching unit;
[0085] The detection unit is used for detecting the terminal voltage of the elevator safety circuit, and if the terminal voltage is normal, a first level is sent to the switching unit; if the terminal voltage is abnormal, a second level is sent to the switching unit;
[0086] The switching unit receives the first level and sends a driving enable signal that can enable the driving buffer 241 to the driving buffer 241; and receives the second level and sends a driving enable signal that can close the driving buffer 241 to the driving buffer 241.
[0087] The structure of the detection module 241 is the same as that of the detection module 231.
[0088] One of the first level and the second level is high level, and the other is low level.
[0089] The driving enable signal of the driving buffer 241 can be enabled in the first state, and the driving enable signal of the driving buffer 241 can be disabled in the second state. The first and second states can be represented by a high level and a low level, respectively, depending on the enable condition of the driving buffer. For example, the driving buffer is enabled at a low level, and the first state is low and the second state is high.
[0090] Embodiment 2
[0091] The embodiment also provides an STO circuit, as shown in the figure, in addition to the structure in Embodiment 1, the channel A further comprises a power module 211 and a driving buffer power control module 221 (hereinafter referred to as a power control module 221); the channel B further comprises a power module 212 and a driving buffer power control module 222 (hereinafter referred to as a power control module 222). Figure 2 The power module is connected to a power source outside the STO circuit (i.e. an external power source in the figure), and functions to convert a first control voltage of a predetermined size to provide the detection module and the power control module in the channel; wherein the predetermined size can be, but is not limited to, 3.3V;
[0092] Figure 2 The power control module is used to generate a second control voltage according to the first control voltage; the second control voltage is also of a predetermined size, which can be, but is not limited to, the same size as the first control voltage. The second control voltage is provided to the driving buffer in the channel as power supply for the driving buffer, and if the second control voltage is stopped, the driving buffer will be closed and unable to output a PWM signal. The second control voltage will be closed in two cases, one is that the power module stops outputting, i.e. the first control voltage is closed; the other is that the power control module can receive the output of the power module, but itself stops working.
[0093] For the sake of simplicity and clarity, the power supply of the driving buffer in the channel by the power module and the power supply of the driving buffer in the channel by the power control module are not shown in the figure.
[0094] Exemplarily, the first control voltage output by the power module 211 is referred to as 3.3VA, and the first control voltage converted by the power module 212 is referred to as 3.3VB; the second control voltage output by the power control module 221 is referred to as 3.3VAA, and the second control voltage output by the power control module 222 is referred to as 222. Figure 2 Embodiment 3
[0095] The embodiment provides an STO circuit, as shown in the figure, in addition to the structure in Embodiment 1, the channel A further comprises a power module 211 and a driving buffer power control module 221 (hereinafter referred to as a power control module 221); the channel B further comprises a power module 212 and a driving buffer power control module 222 (hereinafter referred to as a power control module 222).
[0096]
[0097] The embodiment provides an STO circuit, as shown in the figure, in addition to the structure in Embodiment 1, the channel A further comprises a power module 211 and a driving buffer power control module 221 (hereinafter referred to as a power control module 221); the channel B further comprises a power module 212 and a driving buffer power control module 222 (hereinafter referred to as a power control module 222).Figure 3 As shown, the safety torque off circuit further comprises a monitoring MCU module 25 based on the embodiment of the application in embodiment 2;
[0098] The monitoring MCU module 25 receives the first control voltage output by the power module in the two channels; sends a pulse signal and a detection enable signal to the detection module in the two channels, and receives the detection signal generated by the detection module according to the pulse signal and the terminal voltage, and further receives the drive enable signal sent by the detection module to the drive buffer; sends a PWM detection input signal to the drive buffer in the two channels, and receives the PWM detection output signal output by the drive buffer according to the PWM detection input signal.
[0099] In addition, the monitoring MCU module 25 further receives the PWM signal output by the drive buffer in the two channels, a total of six channels.
[0100] For the sake of simplicity and clarity, the connection relationship between the monitoring MCU module 25 and other modules in the STO is not shown in FIG. 3.
[0101] The monitoring MCU module 25 can diagnose one or more modules in each channel in the STO according to the received signals as follows:
[0102] If the first control voltage of a channel is abnormal, the drive buffer of the channel is closed;
[0103] If the detection signal output by the detection module in a channel is inconsistent with the pulse signal sent to the detection module, or the drive enable signal is inconsistent with the detection signal, the drive buffer of the channel is closed;
[0104] If any one of the PWM signals output by the drive buffer in a channel is faulty, or the PWM detection output signal provided by the channel is inconsistent with the PWM detection input signal provided to the channel, the drive buffer of the channel is closed.
[0105] For example, the pulse signal sent by the monitoring MCU module 25 to the detection module 231 is 180 degrees out of phase with the pulse signal sent to the detection module 232; the PWM detection input signal sent to the drive buffer 241 and the drive buffer 232 can be 180 degrees out of phase; such design can realize time sequence difference and reduce CCF (Common Cause Failure).
[0106] An example is as follows: Figure 4As shown, it comprises: channel A and channel B; in this example, channel A and channel B have the same structure, channel A comprises power module A, drive buffer power control module A (hereinafter referred to as power control module A), detection module A, and drive buffer A; channel B comprises power module B, drive buffer power control module B (hereinafter referred to as power control module B), detection module B, and drive buffer B.
[0107] The STO circuit receives DC 5V from an external power supply through a transformer and provides it to the two power modules; receives six PWM signals PWM_HU, PWM_HV, PWM_HW, PWM_LU, PWM_LV, and PWM_LW from an external drive MCU module and inputs them to the two drive buffers; drive buffer A outputs PWM_HU, PWM_HV, and PWM_HW to the drive optocoupler corresponding to the upper bridge arm, and drive buffer A outputs PWM_LU, PWM_LV, and PWM_LW to the drive optocoupler corresponding to the lower bridge arm; the drive optocoupler drives the inverter and thus drives the elevator motor; the power source for driving the motor is an AC power source of 380V.
[0108] In the following, the case of channel A will be mainly described, and the case of channel B can be referred to for implementation.
[0109] The power module A comprises a fuse, a clamping diode, and an LDO; the input end of the LDO is connected to a 5V power source; the output end outputs a first control voltage 3.3VA to the power control module A and the monitoring MCU module through a series-connected fuse; the positive electrode of the clamping diode is grounded, and the negative electrode is connected between the fuse and the power control module A.
[0110] The drive buffer power control module A receives the first control voltage 3.3VA and a power supply enable signal POWER_EN_ provided by the monitoring MCU module, and outputs a second control voltage 3.3VAA to the drive buffer A in the enabled state.
[0111] The detection module A comprises a resistor, a triode, and two optocouplers connected to each other, the two optocouplers are respectively connected to the positive and negative electrodes of the terminal voltage, the optocoupler connected to the positive electrode receives a pulse signal PLUSE_A provided by the monitoring MCU module, the optocoupler connected to the negative electrode receives the first control voltage 3.3VA and a detection enable signal EN_A provided by the monitoring MCU module, outputs a detection signal DETECT_A to the base of the triode, and the emitter of the triode can be grounded; the collector receives the first control voltage 3.3VA through the resistor and outputs a drive enable signal DRIVE_EN_A to the drive buffer A. The monitoring MCU module monitors the detection signal DETECT_A and the drive enable signal DRIVE_EN_A.
[0112] The drive buffer A receives the PWM detection input signal PWM_detect_A_I provided by the monitoring MCU module and the second control voltage 3.3VAA provided by the power control module A in addition to the transmission and reception of the PWM signal described above, and outputs the PWM detection output signal PWM_detect_A_O to the monitoring MCU module.
[0113] The channel B is the same as the channel A, and the "A" in the name of each signal and each part in the description of the example is replaced with "B" to obtain the channel B.
[0114] The example is only one of the implementation manners, and does not limit the STO circuit of the example.
[0115] The control principle of the example is as follows:
[0116] The operation of the elevator motor is controlled by the PWM signal. In the example, the PWM signal output by the drive MCU module is input to two drive buffers, and the two drive buffers output the PWM signal respectively to drive the elevator motor. The example controls the drive buffer to output / stop outputting the PWM signal to control the elevator motor and realize the STO function by judging the state of the elevator safety circuit through the hardware circuit.
[0117] The ends of the elevator safety circuit are connected to two detection modules respectively. When all the switches on the elevator safety circuit are closed, the voltage at the end of the elevator safety circuit is 48V, which is input to the two detection modules respectively. The high-level output of the optocoupler in the detection module drives the transistor, so that the output (i.e., the drive enable signal) of the collector of the transistor becomes low level, and the output level of the collector of the transistor is connected to the enable pin of the drive buffer. When the output level is less than the low-level threshold voltage (such as 0.9V) of the enable pin of the drive buffer, the drive buffer outputs the PWM signal to the drive optocoupler, and the elevator motor operates normally.
[0118] When a switch on the elevator safety circuit is open, the voltage at the end of the elevator safety circuit is 0V, which is input to the two detection modules respectively. The low-level output of the optocoupler in the detection module drives the transistor, so that the transistor becomes open-drain output, and the 3.3V high-level output of the collector is connected to the enable pin of the drive buffer. The level is greater than the high-level threshold voltage (such as 2.2V) of the enable pin of the drive buffer, so the output PWM signal of the drive buffer is cut off, the drive optocoupler is disconnected, and the motor stops operating.
[0119] Channel A is used to control 3 IGBTs of upper bridge arm, Channel B is used to control 3 IGBTs of lower bridge arm, and the elevator motor will not run when only the upper bridge arm IGBT or the lower bridge arm IGBT is turned on. Therefore, Channel A and Channel B achieve 2-way redundancy, and the hardware failure margin is 1.
[0120] In this example, Channel A is designed as follows for the diagnosis process inside STO, and Channel B is the same as Channel A, which will not be described here:
[0121] (I) Power module diagnosis
[0122] Power short circuit: The monitoring MCU module monitors the first control voltage 3.3VA output by the power module LDO, and when a short circuit fault is judged, the self-restoring fuse acts, the output voltage of the power module is disconnected, the drive buffer has no power supply, and the output PWM signal is stopped or the output PWM signal is low. On the other hand, when the monitoring MCU module detects that the voltage of 3.3VA is lower than the set threshold (3V), the monitoring MCU module outputs a low-level detection enable signal, i.e. EN_A is low, at this time the drive enable signal DRIVE_EN_A is correspondingly high, and the drive buffer A outputs is disconnected.
[0123] Power overvoltage: When overvoltage occurs, assume the worst case, at this time the first control voltage is 5V. The clamping diode or TVS (Transient Voltage Suppressor) will act to protect and clamp, the clamping voltage is 3.42V-3.78V, at this time the monitoring MCU module is still in the working voltage area, when the monitoring MCU module detects that the voltage of the first control voltage is greater than the set threshold (3.6V), the monitoring MCU module outputs low, i.e. EN_A is low, at this time DRIVE_EN_A is high, and the drive buffer A output is disconnected.
[0124] Power under-voltage: When under-voltage occurs, assume the worst case, at this time the first control voltage is 0V. The first control voltage voltage from the normal working voltage to 0V will take a period of time, the working voltage of the monitoring MCU module is 2.8V-4.6V, so when 3.3VA becomes 3V, the monitoring MCU module is still working, the monitoring MCU module detects that the voltage of 3.3VA is lower than the set threshold (<3V), the monitoring MCU module outputs low, i.e. EN_A is low, at this time DRIVE_EN_A is high, and the drive buffer A output is disconnected. And when the voltage is lower than 2.93V, the reset chip will generate a reset signal to the MCU to remind the MCU of the under-voltage condition. On the other hand, when under-voltage occurs, i.e. the drive buffer has no power supply, the output PWM signal is low.
[0125] (II) Detection module diagnosis
[0126] Detection module input diagnosis: The monitoring MCU module outputs a pulse signal Pluse_A to a photo-coupler in the detection module A, and monitors the detection signal DETECT_A output by another photo-coupler, and compares the signals Pluse_A and DETECT_A. When at least one of the frequency, amplitude, and duty cycle is inconsistent, it is considered that there is an abnormality in the input end of the detection module, i.e., there is an abnormality in the circuit between the signals Pluse_A and DETECT_A. At this time, the monitoring MCU module changes the power enable signal POWER_EN_A to low level, disconnects the power supply of the drive buffer A, and makes the output signal of the drive buffer A low level. In order to realize the time sequence difference and reduce the CCF, the phase between the pulse signals Pluse_A and Pluse_B of the channel A and the channel B needs to be 180 degrees.
[0127] Detection module output diagnosis: The monitoring MCU module outputs a Pluse_A to a photo-coupler in the detection module A, and the filtered DRIVE_EN_A signal output by the collector of the triode should be a triangular wave signal at this time. If the frequency, amplitude, or duty cycle of DETECT_A is consistent after comparison with Pluse_A, but the DRIVE_EN_A signal is not a triangular wave signal, it is considered that there is an abnormality in the output circuit of the detection module A, i.e., there is an abnormality in the circuit between the signals DETECT_A and DRIVE_EN_A. At this time, the monitoring MCU module changes the POWER_EN_A to low level, disconnects the power supply of the drive buffer A, and makes the output signal of the drive buffer A low level.
[0128] (III) Drive buffer module diagnosis
[0129] Drive buffer diagnosis: monitor the MCU module output PWM_detect_A_I to the drive buffer A, and monitor the PWM_detect_A_O signal generated by the drive buffer A, and compare the PWM_detect_A_O signal and the PWM_detect_A_I, when at least one of the frequency, amplitude, duty cycle is inconsistent, it is considered that the drive buffer A exists abnormal, that is, the circuit between the signal PWM_detect_A_I and PWM_detect_A_O is abnormal, at this time the monitoring MCU module will change EN_A and POWER_EN_A to low level, disconnect the enable and power supply of the drive buffer A, so that the output signal of the drive buffer A is low. In addition, the monitoring MCU module also monitors all the PWM signals output by the drive buffer A, and when any one of the PWM signals fails, the monitoring MCU will change EN_A and POWER_EN_A to low level, disconnect the enable and power supply of the drive buffer A, so that the output signal of the drive buffer A is low. In order to realize the time sequence difference, reduce the CCF, the phase between the signals PWM_detect_A_I and PWM_detect_B_I of channel A and channel B needs to be 180 degrees.
[0130] The safety integrity level of the present example can reach SIL3, and the safety failure fraction SFF can reach more than 98%.
[0131] Embodiment 4
[0132] In this embodiment, the structure of the circuit module is further expanded on the basis of the STO circuit provided in embodiment 3; this embodiment takes circuit module 211 as an example for description, and the structure of circuit module 212 is the same as that of circuit module 211, which will not be described again.
[0133] In this embodiment, the power module 211 can include a voltage stabilizer, which can convert the external power input into a first control voltage.
[0134] In this embodiment, the monitoring MCU module monitors the first control voltage output by the voltage stabilizer of the two channels, and if the first control voltage of any channel is found to be short-circuited, the output of the short-circuited power module is cut off; if the first control voltage is overvoltage (i.e. exceeds the predetermined overvoltage threshold) or undervoltage (i.e. less than the predetermined undervoltage threshold), the detection enable signal sent to the channel is changed, so that the detection module of the channel will be closed, thereby indirectly closing the drive buffer of the channel.
[0135] Exemplarily, the voltage stabilizer can adopt an LDO (Low Dropout Regulator). The power module can further include a fuse. The fuse is connected in series between the output end of the voltage stabilizer and the output end of the power module. The output end of the power module provides the first control voltage, which is input to the monitoring MCU module in addition to being used to power other modules in the channel.
[0136] Exemplarily, the power module can further include a clamping diode. The anode of the clamping diode is connected to the ground, and the cathode of the clamping diode is connected between the fuse and the output end of the power module. In the case of a short circuit of the power module, the fuse performs a self-recovery action to disconnect the output of the power module.
[0137] In one example, the structure of the power module of the channel A is as shown in Figure 5 The power module includes a fuse F13, four capacitors, a resistor R309 and a resistor R314, a clamping diode D16, and a chip IC27, which is of the type LM1117IMP-3.3.
[0138] The first end of the fuse F13 is connected to pin 2 of the chip IC27. The second end of the fuse F13 is used as an output end of the first control voltage (e.g., 3.3VA), and is connected to the cathode of the clamping diode D16 and the first end of the resistor R309.
[0139] The first end of the capacitor C194 is connected to pin 3 of the chip IC27, and the second end of the capacitor C194 is connected to the ground.
[0140] The first end of the capacitor C195 is connected to pin 3 of the chip IC27, and the second end of the capacitor C195 is connected to the ground.
[0141] The first end of the capacitor C196 is connected to pin 2 of the chip IC27, and the second end of the capacitor C196 is connected to the ground.
[0142] The first end of the capacitor C197 is connected to pin 2 of the chip IC27, and the second end of the capacitor C197 is connected to the ground.
[0143] The first end of the resistor R309 is connected to the second end of the fuse F13 and the cathode of the clamping diode D16, and the second end of the resistor R309 is connected to the first end of the resistor R314. A signal Detect0 can be obtained from the second end of the resistor R309.
[0144] The first end of the resistor R314 is connected to the second end of the resistor R309, and the second end of the resistor R314 is connected to the ground.
[0145] The anode of the clamping diode D16 is connected to the ground.
[0146] The chip IC27 includes pins 1-4, which are as follows:
[0147] GND, connected to the ground.
[0148] Vout, the first end of the capacitor C196 and the first end of the capacitor C197, and the first end of the fuse F13;
[0149] Vin, the first end of the capacitor C194 and the first end of the capacitor C195, and the external power supply +5V;
[0150] GND, ground.
[0151] In one example, the power supply control module of the channel A has a structure as shown in Figure 6 which includes the capacitor C1 and the chip IC1.
[0152] The model of the chip IC1 is TPS22860, which includes the pins 1-6, respectively as follows:
[0153] Vout, the output end of the second control voltage (3.3VAA);
[0154] GND, ground.
[0155] NC, suspended.
[0156] Vin and VBIAS, the input end of the first control voltage (3.3VA);
[0157] ON, receiving the power enable signal (such as POWER_EN_A);
[0158] The first end of the capacitor C1 is connected to the pins 4 and 5 of the chip IC1, and the second end is grounded.
[0159] Figure 5 , Figure 6 The structure shown in can be applied to the channel B, the first control signal is 3.3VB, and the second control signal is 3.3VBB; in actual application, in addition to the circuit shown in Figure 5 , Figure 6 other circuits / components that can achieve the same effect can also be used to build the power supply module and the power supply control module.
[0160] Embodiment 5
[0161] The other contents of this embodiment are the same as any of the above embodiments, and mainly describe the detection module. The structures of the detection modules in the channel A and the channel B can be the same, and this embodiment describes the case of one channel. The implementation details described below in this embodiment can be applied to any channel.
[0162] In this embodiment, the detection module can include a detection unit and a switching unit:
[0163] The detection unit detects the terminal voltage, receives the pulse signal and the detection enable signal output by the monitoring MCU module, and generates a detection signal according to the pulse signal and the terminal voltage under the condition of being enabled, and inputs the detection signal to the switching power supply and monitors the detection signal by the monitoring MCU module.
[0164] The switching unit generates a driving enable signal for the driving buffer according to the received detection signal, and the monitoring MCU module also monitors the driving enable signal.
[0165] For example, the monitoring MCU module can compare the detection signal and the pulse signal, and stop supplying power to the driving buffer if the signal parameters are inconsistent; the signal parameters include one or more of the following: frequency, amplitude, and duty cycle.
[0166] For example, the monitoring MCU module can also compare the driving enable signal and the pulse signal, and stop supplying power to the driving buffer if the signal parameters are inconsistent; the signal parameters include one or more of the following: frequency, amplitude, and duty cycle. In addition, if the waveform of the driving enable signal is inconsistent with the pulse signal, such as not a triangular wave, the driving buffer is also stopped.
[0167] For example, the monitoring MCU module can provide a power enable signal to the power control module, and the power control module will output a second control voltage to the driving buffer only when it is enabled; in this embodiment, the monitoring MCU can turn off the output of the power control module by changing the power enable signal, thereby turning off the driving buffer. For example, the power enable signal is changed from high level to low level, or the power enable signal is cut off, and the purpose of the change is to make the power control module unable to output the second control voltage.
[0168] For example, the detection unit can be an optocoupler, and the switching unit can be a transistor.
[0169] The output end of the optocoupler is connected to the base of the transistor, the emitter of the transistor can be grounded; the collector can be connected to the first control voltage, such as but not limited to through a resistor; in addition, the collector outputs the driving enable signal.
[0170] The optocoupler can be two optocouplers connected to each other, connected to the positive and negative terminals of the terminal voltage respectively, the optocoupler connected to the positive terminal receives the pulse signal, and the optocoupler connected to the negative terminal receives the first control voltage and the detection enable signal and outputs the detection signal.
[0171] An example of the detection module is shown in Figure 7 , Figure 7 is a circuit diagram of the detection module of channel A, and the detection module of channel B has the same structure; Figure 7 The detection module includes:
[0172] Resistors R283, R285, R286, R287, R289, R292, R293, R294, R296, R71, R403 and R404, capacitors C199, C201, C82 and C83, optocoupler Q37, MOSFET Q38, NPN transistor Q42, and chip IC28.
[0173] Chip IC28 can be a device of model ISO1211, including pins 1-6.
[0174] Optocoupler Q37 can include an NPN phototriac and a diode, forming pins 1-4. In which, the collector of the phototriac of Q37 is pin 4, the emitter of the phototriac is pin 3; the anode of the diode is pin 1, the cathode of the diode is pin 2. Pin 1 of Q37 is connected to the first end of R286 and the first end of R287, the second end of R286 is the input of pulse signal Pluse_A, pin 2 of Q37 is connected to the second end of R287 and grounded.
[0175] MOSFET Q38 can include a diode and a P-channel enhancement mode insulated gate field effect transistor (MOSFET), the cathode of the diode is connected to the substrate and the source of the MOSFET, together connected to the first end of R283; the anode of the diode is connected to the drain of the MOSFET, the first end of R289 and the first end of R292; the gate of the MOSFET is connected to the second end of R283 and the first end of R285.
[0176] The first end of R238 and pin 3 of Q37 are connected to the end of the safety circuit of the elevator.
[0177] The second end of R285 is connected to pin 4 of Q37, the second end of R292 is connected to the first end of C201, the first end of R294 and pin 8 (SENSE) of IC28; the second end of R289 is connected to pin 3 of Q37, the second end of C201 and pin 6 (FGND) of IC28; the second end of R294 is connected to pin 7 (IN) of IC28.
[0178] The pin 1 (power supply end Vcc1) of the chip IC28 is connected to one end of the capacitor C199 and serves as an input end of a first control voltage (3.3VA); the other end of the capacitor C199 is grounded; the pin 2 of the chip IC28 is connected to the resistor R404 in parallel and serves as a receiving end of a detection enable signal EN_A to control the chip IC28 to start working, and the other end of the resistor R404 is grounded; the pin 3 (output end OUT) of the chip IC28 outputs a detection signal (DETECT_A) and is connected to the first end of the resistor R296; and the pin 4 (GND1) of the chip IC28 is grounded.
[0179] The base of the NPN type triode Q42 is connected to the second end of the resistor R296 and the first end of the resistor R293; the emitter is connected to the second end of the resistor R293 and grounded; the first end of the resistor R71 is connected to the first control voltage, the second end is connected to the collector of the Q42 and the first end of the resistor R403; the second end of the resistor R403 serves as an output end of a driving enable signal (DRIVE_EN_A) and is connected to the first end of the capacitor C82 and the capacitor C83, and the second ends of the capacitor C82 and the capacitor C83 are both grounded.
[0180] In actual application, the detection modules of the channel A and the channel B adopt different circuits Figure 7 but circuits capable of achieving the same effect can also be used.
[0181] Embodiment 6
[0182] The embodiment can be implemented on the basis of any of the above-mentioned embodiments, and the following description is made from the perspective of one channel, which can be applied to the channel A and the channel B.
[0183] In the embodiment, when any one of the PWM signals output by the driving buffer is faulty or the PWM detection input signal provided to the driving buffer is inconsistent with the PWM detection output signal output by the driving buffer, the monitoring MCU module changes the power supply enable signal and the detection enable signal provided, so as to stop the power supply to the driving buffer and close the driving buffer to make it unable to output, thereby achieving a double insurance effect; the signal parameters include one or more of the following: frequency, amplitude, duty cycle.
[0184] One example of the driving buffer of the channel A is shown in Figure 8 The driving buffer of the channel B can adopt the same circuit as Figure 8 but receives a PWM signal different from that of the channel A; Figure 8 The circuit of the driving buffer of the channel A includes:
[0185] Figure 5 The circuit diagram of the STO driving buffer module (channel A) provided according to the embodiment of the application is shown in Figure 5The resistors R297, R298, R303, R304, R305, R306, R307, R308, R311, R312, R1, R2, R3, R4 and R5, the capacitors C185, C186, C187, C198, C202 and C184 and the chip IC12 are shown in the figure.
[0186] The chip IC12 can be a device of model 74VHCV244FT, including pins 1-20. The pin 1 (1G) and the pin 19 (2G) are used as inputs of a driving enable signal (DRIVE_EN_A), which can be used as an enable signal of the chip.
[0187] The pin 2 (IA1) of the chip IC12 receives an input PWM signal (PWM_HU_I). A resistor R297 is connected in series in front of the pin 2 of the chip IC12, with a first end receiving the PWM signal (PWM_HU_I) and a second end connected to the pin 2 of the chip IC12 and an RC filter circuit composed of a resistor R312 and a capacitor C202. In the RC filter circuit, the resistor R312 and the capacitor C202 are connected in parallel, with one end connected to the pin 2 of the chip IC12 and the other end grounded.
[0188] The pin 4 (IA2) of the chip IC12 receives another input PWM signal (PWM_HV_I). A resistor R298 is connected in series in front of the pin 4 of the chip IC12, with a first end receiving the PWM signal (PWM_HV_I) and a second end connected to the pin 4 of the chip IC12 and an RC filter circuit composed of a resistor R311 and a capacitor C198. In the RC filter circuit, the resistor R311 and the capacitor C198 are connected in parallel, with one end connected to the pin 4 of the chip IC12 and the other end grounded.
[0189] The pin 6 (IA3) of the chip IC12 receives still another input PWM signal (PWM_HW_I). A resistor R303 is connected in series in front of the pin 6 of the chip IC12, with a first end receiving the PWM signal (PWM_HW_I) and a second end connected to the pin 6 of the chip IC12 and an RC filter circuit composed of a resistor R308 and a capacitor C187. In the RC filter circuit, the resistor R308 and the capacitor C187 are connected in parallel, with one end connected to the pin 6 of the chip IC12 and the other end grounded.
[0190] The pin 8 (IA4) of the chip IC 12 receives the PWM detection input signal (PWM_DETECT_A_I). A resistor R304 is connected in series in front of the pin 8 of the chip IC 12, with the first end receiving the PWM detection input signal (PWM_DETECT_A_I) and the second end connected to the pin 8 of the chip IC 12 and an RC filter circuit composed of a resistor R307 and a capacitor C186. In the RC filter circuit, the resistor R307 and the capacitor C186 are connected in parallel, with one end connected to the pin 8 of the chip IC 12 and the other end grounded.
[0191] The pin 11 (2A1) of the chip IC 12 receives the input signal DBC_I. Specifically, a resistor R305 is connected in series in front of the pin 11 of the chip IC 12, with the first end receiving the input signal DBC_I and the second end connected to the pin 11 of the chip IC 12 and an RC filter circuit composed of a resistor R306 and a capacitor C185. In the RC filter circuit, the resistor R306 and the capacitor are connected in parallel, with one end connected to the pin 11 of the chip IC 12 and the other end grounded.
[0192] The pin 9 (2Y1) of the chip IC 12 outputs the DBC signal and is also connected to the first end of a resistor R1, with the second end of the resistor R1 grounded; the pin 12 (1Y4) of the chip IC 12 outputs the PWM detection output signal (PWM_DETECT_A_O) and is also connected to the first end of a resistor R2, with the second end of the resistor R2 grounded; the pins 14, 16 and 18 (1Y3, 1Y2, 1Y3) of the chip IC 12 respectively output three PWM signals (PWM_HW, PWM_HV, PWM_HU) and are respectively connected to the first ends of resistors R3, R4 and R5, with the other ends of the resistors R3, R4 and R5 grounded.
[0193] The pin 20 (VCC) of the chip IC 12 is connected to the first end of a capacitor C184, serving as the input end of the second control voltage (3.3VAA), with the second end of the capacitor C184 grounded. The pin 10 (GND), the pin 13 (2A2), the pin 15 (2A3) and the pin 17 (2A4) of the chip IC 12 are grounded. The pin 11 (2A1) of the chip IC 12 is connected to the pin 9 (2Y1).
[0194] Figure 8 The circuit can be applied to channels A and B; in actual application, other circuits capable of achieving the same effect can also be used.
[0195] Exemplarily, the TMS320F280025 chip can be used in the monitoring MCU module, but the chip is not limited thereto, and other types of chips that can be used in STO can also be used.
[0196] Example 7
[0197] The embodiment provides an elevator control system, as shown in the accompanying drawings: Figure 9
[0198] The elevator safety circuit 1, the STO circuit 2 provided by any of the above embodiments, the driving MCU module 3 and the driving optocoupler 4.
[0199] The STO circuit 2 receives the PWM signal from the driving MCU module 3, and determines whether to forward the PWM signal to the driving optocoupler 4 according to the terminal voltage of the elevator safety circuit 1.
[0200] The driving optocoupler 4 can drive the elevator motor after receiving the PWM signal. The driving optocoupler can have two groups, each group having three, one group driving the upper bridge arm and the other group driving the lower bridge arm. The driving MCU module 3 can send six PWM signals, three corresponding to the upper bridge arm and the other three corresponding to the lower bridge arm.
[0201] Figure 9 The STO circuit is the STO circuit provided in Embodiment 3 ( Figure 3 ), and the STO circuit provided in Embodiment 1 ( Figure 1 ) or Embodiment 2 ( Figure 2 ) can also be replaced.
[0202] Embodiment 8
[0203] The embodiment provides a control method, as shown in the accompanying drawings: Figure 10 The control method is realized based on the STO circuit of any of the above embodiments, and comprises the following steps:
[0204] In S110, the PWM signal received by the driving optocoupler is forwarded when the terminal voltage is normal, and the forwarding of the PWM signal is stopped when the terminal voltage is abnormal, i.e., the output of the PWM signal is stopped.
[0205] Exemplarily, the control method can further comprise the following steps:
[0206] The following one or more operations are performed on each channel respectively:
[0207] When the first control voltage provided by the power module of the channel is abnormal, the output of the driving buffer in the channel is closed;
[0208] When it is monitored that the detection signal of the detection module of the channel is inconsistent with the pulse signal provided to the detection module, or the driving enable signal is inconsistent with the detection signal, the PWM signal output of the channel is closed;
[0209] When any one of the PWM signals output by the channel is found to be faulty, or the PWM detection output signal provided by the driving buffer in the channel is inconsistent with the PWM detection input signal provided to the driving buffer, the PWM signal output of the channel is closed.
[0210] That is, one or more of the power module, the detection module, the drive buffer can be diagnosed.
[0211] Exemplarily, the first control voltage abnormality can represent a short circuit, an under-voltage or an over-voltage of the power module; in the case of under-voltage, the monitoring MCU module can receive a reset signal from an internal reset chip or externally.
[0212] Exemplarily, the following any one or a combination of multiple ways can be adopted to close the PWM signal output of the channel:
[0213] disconnecting the total power supply in the channel, i.e. closing the output of the power module;
[0214] disconnecting the power supply provided to the drive buffer in the channel, such as no longer enabling the power control module;
[0215] changing (such as level flipping or stopping, etc.) the detection enable signal to the detection module of the channel, the detection signal of the detection module will change (such as level flipping or stopping, etc.), and the drive enable signal generated based on the detection signal will also change accordingly, so that the drive buffer is no longer enabled.
[0216] Those of ordinary skill in the art will realize and understand that all or some of the steps in the methods disclosed above and the functional modules / units in the systems and devices can be implemented as software, firmware, hardware, and appropriate combinations thereof. In hardware implementation, the division between the functional modules / units mentioned in the above description does not necessarily correspond to the division of physical components; for example, one physical component can have multiple functions, or one function or step can be performed by several physical components in cooperation. Some or all of the components can be implemented as software executed by a processor, such as a digital signal processor or a microprocessor, or as hardware, or as an integrated circuit, such as an application-specific integrated circuit. Such software can be distributed on computer-readable media, which can include computer storage media (or non-transitory media) and communication media (or transitory media). As is well known to those of ordinary skill in the art, the term computer storage media includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storage of information such as computer readable instructions, data structures, program modules or other data. Computer storage media includes, but is not limited to, RAM, ROM, EEPROM, flash memory or other memory technology, CD-ROM, digital versatile disks (DVD) or other optical disk storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired information and that can be accessed by a computer. Furthermore, it is common and well understood by those of ordinary skill in the art that communication media typically embodies computer readable instructions, data structures, program modules or other data in a modulated data signal such as a carrier wave or other transport mechanism and can include any information delivery media.
Claims
1. A safe torque off circuit, characterized by, The application relates to an elevator motor drive system, which comprises: two channels and a monitoring MCU module; each of the channels comprises a detection module, a drive buffer, a power module and a drive buffer power control module; the drive buffers of the first and second channels are respectively connected with drive optocouplers corresponding to upper bridge arms and lower bridge arms of elevator motors; the monitoring MCU module is used for providing a power supply enable signal to the drive buffer power control module and providing a detection enable signal to the detection module; the detection module is connected with the end of an elevator safety circuit and is used for detecting the end voltage of the elevator safety circuit; in an enabled state, the detection module outputs a drive enable signal; in the case that the end voltage of the elevator safety circuit is normal, the drive enable signal is used for enabling the drive buffer of the channel; in the case that the end voltage of the elevator safety circuit is abnormal, the drive enable signal is used for closing the drive buffer of the channel; the drive buffer is used for forwarding a PWM signal received from outside to the connected drive optocoupler in an enabled state; the power module is used for converting an external power supply connected therewith into a first control voltage of a predetermined size and providing the first control voltage to the drive buffer power control module and the detection module of the channel; the drive buffer power control module is used for generating a second control voltage of a predetermined size according to the first control voltage in an enabled state and providing the second control voltage to the drive buffer of the channel.
2. The STO circuit of claim 1, wherein, the detection module comprises a detection unit and a switching unit; the detection unit is used for detecting the end voltage of the elevator safety circuit; in the case that the end voltage of the elevator safety circuit is normal, the detection unit sends a first level to the switching unit; in the case that the end voltage of the elevator safety circuit is abnormal, the detection unit sends a second level to the switching unit; the switching unit sends a drive enable signal of a first state to the drive buffer of the channel to enable the drive buffer in the case that the first level is received; the switching unit sends a drive enable signal of a second state to the drive buffer of the channel to close the drive buffer in the case that the second level is received.
3. The STO circuit of claim 1, wherein: in each channel, the power module is further used for providing the first control voltage to the monitoring MCU module, the detection module is further used for providing a detection signal to the monitoring MCU module, and the drive buffer is further used for sending a PWM detection output signal to the monitoring MCU module according to a PWM detection input signal provided by the monitoring MCU module; the monitoring MCU module is further used for performing one or more of the following operations on each channel: closing the drive buffer of the channel in the case that the first control voltage of the channel is abnormal; outputting a pulse signal to the detection module of the channel and closing the drive buffer of the channel in the case that the detection signal provided by the channel is inconsistent with the pulse signal or the drive enable signal is inconsistent with the detection signal; The PWM detection input signal is provided to the drive buffer of the channel; in case of any fault of the PWM signal output of the channel, or the PWM detection output signal provided by the channel is inconsistent with the PWM detection input signal provided to the channel, the drive buffer of the channel is closed.
4. The safety torque off circuit according to claim 3, wherein: The pulse signal sent by the monitoring MCU module to the first channel is 180 degrees out of phase with the pulse signal sent to the second channel; The PWM detection input signal sent by the monitoring MCU module to the first channel is 180 degrees out of phase with the PWM detection input signal sent to the second channel.
5. The safety torque off circuit according to claim 3, wherein: The power module comprises a voltage stabilizer for converting the connected external power supply into a first control voltage output of a predetermined size; The monitoring MCU module closes the drive buffer of the channel in case of abnormality of the first control voltage of the channel comprises: The monitoring MCU module monitors the first control voltage output by the voltage stabilizer, and in case of short circuit of the power module of the channel, cuts off the output of the power module; in case of detecting that the first control voltage exceeds a predetermined overvoltage threshold, or detecting that the first control voltage is less than a predetermined undervoltage threshold, the drive buffer of the channel is closed by changing the detection enable signal sent to the detection module of the channel.
6. The safety torque off circuit according to claim 5, wherein: The voltage stabilizer is a low dropout linear voltage stabilizer; The power module further comprises a fuse and a clamping diode; one end of the fuse is connected to the output end of the low dropout linear voltage stabilizer, and the other end is connected to the detection module, the drive buffer, the monitoring MCU module, and the negative electrode of the clamping diode; The positive electrode of the clamping diode is grounded; In case of short circuit of the power module, the fuse performs self-recovery action to disconnect the output of the power module.
7. The safety torque off circuit according to claim 3, wherein: The detection module comprises a detection unit and a switching unit; The detection unit is used for detecting the terminal voltage of the elevator safety circuit, and receiving the pulse signal and the detection enable signal output by the monitoring MCU module; the detection signal is generated and provided to the monitoring MCU module and the switching unit; The switching unit is used for generating a drive enable signal according to the detection signal, and providing the drive enable signal to the monitoring MCU module and the drive buffer of the channel.
8. The safety torque off circuit according to claim 7, wherein: The drive buffer power control module is used for generating a second control voltage of a predetermined size according to the first control voltage in the enabled state comprises: The drive buffer power control module is used for generating a second control voltage of a predetermined size according to the first control voltage and the power supply enable signal sent by the monitoring MCU, and providing the second control voltage to the drive buffer of the channel; The monitoring MCU module closes the driving buffer of the channel in the case that the detection signal provided by the channel is inconsistent with the pulse signal, or the driving enable signal is inconsistent with the detection signal. The monitoring MCU module stops the power supply of the driving buffer of the channel by changing the power supply enable signal sent to the driving buffer power supply control module of the channel in the case that the detection signal of the channel is inconsistent with the signal parameter of the pulse signal provided to the channel, or the detection signal is consistent with the signal parameter of the pulse signal, but the driving enable signal is not the predetermined waveform; the signal parameter includes one or more of the following: frequency, amplitude, duty cycle.
9. The STO circuit of claim 3, wherein, The monitoring MCU module closes the driving buffer of the channel in the case that any PWM signal output by the channel is faulty, or the PWM detection output signal of the channel is inconsistent with the PWM detection input signal provided to the channel. The monitoring MCU module stops the power supply of the driving buffer of the channel and closes the driving buffer of the channel by changing the power supply enable signal and the detection enable signal provided to the channel in the case that any PWM signal output by the channel is faulty, or the PWM detection output signal of the channel is inconsistent with the signal parameter of the PWM detection input signal provided to the channel; the signal parameter includes one or more of the following: frequency, amplitude, duty cycle.
10. The safety torque off circuit of claim 2 or 7, wherein: The detection unit is an optocoupler, and the switching unit is a transistor; The output end of the optocoupler is connected to the base of the transistor, the emitter of the transistor is grounded, and the collector is connected to a first control voltage of a predetermined size, outputting the driving enable signal.
11. An elevator control system, comprising: The safety torque off circuit, the elevator safety circuit, the driving MCU module, and the driving optocoupler of any one of claims 1-10; The safety torque off circuit is configured to receive a PWM signal output by the driving MCU module, and determine whether to forward or not to forward the PWM signal to the driving optocoupler according to the terminal voltage of the elevator safety circuit; The driving optocoupler drives the elevator motor upon receiving the PWM signal.
12. A control method based on the safety torque off circuit of any one of claims 1-10, comprising: In the case that the terminal voltage of the elevator safety circuit is normal, output the received PWM signal to the driving optocoupler for driving the elevator motor; In the case that the terminal voltage of the elevator safety circuit is abnormal, close the output of the PWM signal.
13. The control method according to claim 12, characterized by, Further comprising: One or more of the following operations are performed on each channel respectively: In the case that the first control voltage of the channel is abnormal, close the PWM signal output of the channel; wherein the first control voltage is a predetermined size voltage converted from an external power supply. The PWM signal output of the channel is closed in the case that a detection signal generated in the channel is inconsistent with a pulse signal input to the channel, or the driving enable signal is inconsistent with the detection signal; wherein the detection signal is generated according to a terminal voltage of an elevator safety circuit and a pulse voltage received by the channel; and the driving enable signal is generated according to the detection signal; The PWM signal output of the channel is closed in the case that any one of the PWM signals output by the channel is faulty, or a PWM detection output signal generated by the channel is inconsistent with a PWM detection input signal provided to the channel.
14. The control method according to claim 13, characterized by, The PWM signal output of the channel is closed in the case that any one of the PWM signals output by the channel is faulty, or a PWM detection output signal generated by the channel is inconsistent with a PWM detection input signal provided to the channel. The PWM signal output of the channel is closed in the case that any one of the PWM signals output by the channel is faulty, or a PWM detection output signal generated by the channel is inconsistent with a PWM detection input signal provided to the channel. The PWM signal output of the channel is closed in the case that any one of the PWM signals output by the channel is faulty, or a PWM detection output signal generated by the channel is inconsistent with a PWM detection input signal provided to the channel. The PWM signal output of the channel is closed in the case that any one of the PWM signals output by the channel is faulty, or a PWM detection output signal generated by the channel is inconsistent with a PWM detection input signal provided to the channel. The PWM signal output of the channel is closed in the case that any one of the PWM signals output by the channel is faulty, or a PWM detection output signal generated by the channel is inconsistent with a PWM detection input signal provided to the channel. The PWM signal output of the channel is closed in the case that any one of the PWM signals output by the channel is faulty, or a PWM detection output signal generated by the channel is inconsistent with a PWM detection input signal provided to the channel. The PWM signal output of the channel is closed in the case that any one of the PWM signals output
Citation Information
Patent Citations
Safe torque turn-off circuit and system
CN106877291A
Implementation method of safe torque turn-off
CN114421814A
Safe torque turn-off and star sealing control circuit and elevator equipment
CN117088211A
Safe torque off circuit and elevator safety control system
CN205170091U
Safe torque off and short winding braking control circuit and elevator equipment
WO2025025752A1