Fault handling method, device and ship management system

By detecting and processing faults in the ship power station power matching module and utilizing redundant equipment and a high-speed switching mechanism, the problem of the fault handling mechanism in the existing technology not having a fault-tolerant function is solved, ensuring the output of valid data in the event of a fault and improving the reliability and safety of the ship power station.

CN115695151BActive Publication Date: 2025-09-09THE 711TH RES INST OF CHINA STATE SHIPBUILDING CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211369746.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-03
Publication Date
2025-09-09
Estimated Expiration
2042-11-03

AI Technical Summary

Technical Problem

The fault handling mechanism in the existing technology does not have a fault tolerance function, resulting in the inability to output valid data when the ship power station automation equipment fails, affecting the safety of ship navigation.

Method used

By performing input and output fault detection on the power matching module, executing effective data selection strategy and fault handling strategy, and utilizing redundant equipment and high-speed switching mechanism to ensure the output of valid data in the event of a fault, the system can diagnose and handle analog input faults, switch input faults, optical fiber communication faults, Ethernet communication faults, analog output faults, and relay output faults.

Benefits of technology

It achieves the output of valid data even when a fault exists, improves the reliability and safety of the ship power station, and avoids ship position deviation and economic losses caused by data errors.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115695151B_ABST
    Figure CN115695151B_ABST
Patent Text Reader

Abstract

The present invention provides a fault handling method, device, and ship management system. The method includes detecting input faults in a power matching module and implementing a valid data selection strategy. The valid data selection strategy intercepts faulty data and selects fault-free data as valid data, and determines that a module-level fault occurs when no valid data is obtained. The method also includes detecting output faults in the power matching module and implementing a fault handling strategy and outputting a corresponding fault status. The fault handling strategy includes further determining whether a module-level fault occurs based on the output fault. Based on the detection of input and output faults, if a module-level fault occurs, module-level fault handling is performed. The present invention has fault tolerance and can ensure that the system can still output valid data even in the presence of a fault.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of ship management, and in particular to a fault handling method, device and ship management system. Background Art

[0002] The core of ship management lies in the management of the ship's power plant. The power plant is the heart of a modern vessel, directly impacting navigational safety. Reliable power supply from the power plant is essential for the proper operation of all equipment on board. Harsh engine room environments, such as electromagnetic interference, vibration and swaying, and the effects of ambient temperature and sea air, can cause malfunctions in some ship power plant automation equipment. For example, a failure in the power plant management system can cause a complete power outage, shifting the ship's position and course, resulting in significant economic losses and even casualties. Current fault handling mechanisms lack fault tolerance; for example, they simply generate an alarm and control the system to stop outputting erroneous data. Summary of the Invention

[0003] The present invention provides a fault handling method, device and ship management system, which are used to solve the problem that the fault handling mechanism in the prior art does not have a fault tolerance function, and realize that the system can still output valid data even if a fault exists.

[0004] In a first aspect, the present invention provides a fault handling method, applied to a power matching module connected to an external frequency converter, the method comprising:

[0005] Detecting input faults on the power matching module and executing a valid data selection strategy, wherein the valid data selection strategy is to intercept faulty data and select fault-free data as valid data, and to determine that a module-level fault occurs when no valid data can be obtained;

[0006] Detecting output faults of the power matching module and executing a fault handling strategy and outputting a corresponding fault status, wherein the fault handling strategy includes further determining whether the output fault is a module-level fault based on the output fault;

[0007] Based on the detection of the input fault and the output fault, if it is a module-level fault, performing module-level fault processing;

[0008] Among them, input failures include analog input failures, switch input failures, fiber optic communication failures, and Ethernet communication failures; output failures include analog output failures and relay output failures.

[0009] In one embodiment of the present invention, the step of detecting an input fault on the power matching module includes:

[0010] Receive analog input data;

[0011] Determining whether a change in the analog input data from the analog input data received at the previous moment is within a preset range;

[0012] If the variation is within the preset range, the analog input data is determined to be in a stable state and the configured timing mechanism is used to determine whether the preset timing time has been reached. If the preset timing time has been reached or the variation is not within the preset range, the fault monitoring mechanism is triggered and the system's signal superposition circuit is activated to perform fault detection by increasing or decreasing the superposition signal and output the analog input data and the fault result.

[0013] If the preset timing time is not reached, the analog input data and the fault result are directly output.

[0014] In one embodiment of the present invention, the step of executing the effective data selection strategy includes:

[0015] If it is an analog input fault or a switch input fault, valid data provided by the redundant device is obtained from the optical fiber network. If valid data from the redundant device cannot be obtained from the optical fiber network or the obtained data is invalid, it is also determined to be a module-level fault;

[0016] If it is a fiber optic communication failure, valid data will be obtained from another redundant fiber optic network. If valid data cannot be obtained from another redundant fiber optic network or the obtained data is invalid, it will be determined as a module-level failure.

[0017] If the Ethernet communication fails, valid data is obtained from the optical fiber network. If valid data cannot be obtained from the optical fiber network or the obtained data is invalid, it is determined to be a module-level failure.

[0018] In one embodiment of the present invention, the step of detecting an output fault of the power matching module includes:

[0019] Obtain the calculated output value of the first analog quantity at a certain moment and the actual recovered value of the first analog quantity at a certain moment;

[0020] Determine whether the second analog output calculated value at the next moment is equal to the first analog output calculated value;

[0021] If the second analog output calculated value is not equal to the first analog output calculated value, then it is determined whether the second analog actual sampling value at the next moment is obtained within a preset time; if the second analog actual sampling value is obtained within the preset time, then it is determined whether the second analog output calculated value is equal to the second analog actual sampling value; if they are not equal, it is determined to be an analog output fault, indicating that there is a fault in the analog output;

[0022] If the second analog output calculated value is equal to the first analog output calculated value, then continue to determine whether the second analog actual value obtained at the next moment is equal to the first analog actual value. If they are not equal, it is determined to be an analog output failure.

[0023] In one embodiment of the present invention, the step of detecting an output fault of the power matching module and executing a fault handling strategy further includes:

[0024] According to the execution time of the relay output, when the system calculates that the relay output result has changed, it will execute the following steps after the preset waiting time:

[0025] When the relay output is a fast unloading signal relay output, if the previous fault diagnosis structure is a relay output fault, the relay output fault will be changed to a module-level fault;

[0026] When the relay output is a fault signal relay output, if the output function of any fault relay or two fault signal relays belonging to the same channel fails, it is determined to be a fault warning, and the corresponding warning is completed through Ethernet communication; if the output function of any three fault signal relays or two relays belonging to different channels fails, it is determined to be a module-level fault, and at this time the module-level fault cannot be correctly output through the fault signal relay channel, and the corresponding alarm is completed through Ethernet external communication. The system is composed of four fault signal relays with common output control, and the two fault signal relays are connected in series and then in parallel.

[0027] In one embodiment of the present invention, if the detection of the input fault and the output fault is a module-level fault, the step of performing module-level fault processing includes:

[0028] Configuring a high-speed switching mechanism;

[0029] According to the high-speed switching mechanism, if any one channel of the two-channel relays connected in parallel is valid, it means that the relay output is valid to achieve redundant output.

[0030] In a second aspect, the present invention further provides a fault handling device, which includes at least two power matching modules, each two power matching modules are redundant modules, and the power matching modules are used to execute the fault handling method as described in any one of the first aspects.

[0031] In one embodiment of the present invention, each power matching module includes a first input end, a second input end, a third input and output end, a first output end, and a second output end. The first input end and the second input end are both connected to two redundant optical fibers, and the third input and output end is connected to Ethernet. The power matching modules are connected through two redundant optical fibers, and the two redundant optical fibers are two redundant ring communication networks and both are unidirectional communications.

[0032] In one embodiment of the present invention, each power matching module includes a programmable array logic device and a plurality of relays, and the programmable array logic device is connected to an external frequency converter through the plurality of relays.

[0033] In a third aspect, the present invention further provides a ship management system, which is used to execute the fault handling method as described in any one of the first aspects.

[0034] The fault handling method, device and ship management system provided by the present invention provide different fault handling strategies by determining different fault states existing in the fault diagnosis results, thereby being able to quickly control the output of erroneous data when a fault occurs and switch to the correct data output. It has a fault tolerance function and can ensure that the system can still output valid data even if a fault exists. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] In order to more clearly illustrate the technical solutions in the present invention or the prior art, a brief introduction will be given below to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0036] Figure 1 It is a flowchart of the fault handling method provided by the present invention;

[0037] Figure 2 It is a schematic diagram of the flow of analog input fault detection provided by the present invention;

[0038] Figure 3 It is a schematic diagram of the effective data selection strategy under the fault state provided by the present invention;

[0039] Figure 4 It is a schematic diagram of the flow of analog output fault detection provided by the present invention;

[0040] Figure 5 It is a schematic diagram of analog output fault data comparison provided by the present invention;

[0041] Figure 6 is a schematic diagram of multiple fault signal relays provided by the present invention;

[0042] Figure 7 This is a flowchart of module-level fault processing provided by the present invention;

[0043] Figure 8 This is a flowchart of a fault handling method provided by an embodiment of the present invention;

[0044] Figure 9 It is a structural schematic diagram of the fault handling device provided by the present invention. DETAILED DESCRIPTION

[0045] To make the objectives, technical solutions, and advantages of the present invention more clear, the technical solutions of the present invention will be clearly and completely described below in conjunction with the accompanying drawings. Obviously, the embodiments described are only some of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.

[0046] The terms "first," "second," and the like in the description and claims of the present invention and the accompanying drawings are used to distinguish similar objects and are not necessarily used to describe a particular order or precedence. It should be understood that the terms used in this manner are interchangeable where appropriate, such that the embodiments described herein can be practiced in an order other than that shown or described herein.

[0047] The technical terms involved in the present invention are described below:

[0048] As ship management gradually develops towards digitalization, informatization and intelligence, the digital and intelligent application of ship energy management systems has gradually become a trend in future ship development.

[0049] The ship's energy management system is a core component of the ship's integrated power system. With the rapid development of ship power system computing, the capacity of ship power plants and the network structure of power systems have undergone significant changes. Based on a computer monitoring network, the ship's energy management system provides comprehensive management of the ship's propulsion system, power system, and other electrical equipment. It monitors and protects the operating status of the ship's power system, enabling intelligent control of energy flow throughout the ship, ensuring reliable energy supply during operation and improving overall ship performance.

[0050] In order to solve the problem that the fault handling mechanism in the prior art does not have a fault tolerance function, resulting in an unreliable ship management system, the present invention provides a fault handling method, device and ship management system. By determining different fault states of the fault in the fault diagnosis results, different fault handling strategies are provided, so that the output of erroneous data when a fault occurs can be quickly controlled and the correct data output can be switched. The method has a fault tolerance function and can ensure that the system can still output valid data even if a fault exists.

[0051] The following combination Figures 1-9 The present invention describes a fault handling method, a fault handling device, and a ship management system.

[0052] Please refer to Figure 1 , Figure 1 A fault handling method is applied to a power matching module connected to an external frequency converter, and the method includes:

[0053] Step 110, detect input faults in the power matching module, execute a valid data selection strategy, and output valid data and corresponding fault status. The valid data selection strategy is to intercept faulty data and select fault-free data as valid data, and determine it as a module-level fault when no valid data can be obtained.

[0054] Among them, input failures include analog input failures, switch input failures, fiber optic communication failures, and Ethernet communication failures; output failures include analog output failures and relay output failures.

[0055] Since input failures are related to input data and can result in inaccurate data, a valid data selection strategy is required to control the processing of inaccurate data and prevent erroneous data from being output through the output channel. If an input failure is detected and valid data cannot be obtained from the backup channel, it is reclassified as a module-level failure.

[0056] The fault status refers to whether a fault exists. For example, if the fault status is "fault present," the fault status can be any one of, or a combination of, an analog input fault, a switch input fault, a fiber optic communication fault, an Ethernet communication fault, an analog output fault, a relay output fault, and a module-level fault. Furthermore, the faults described in the present invention are not limited to the aforementioned types and may also be other types.

[0057] In addition, for example, if the fault status is a fiber communication fault, it can mean that fiber channel A is faulty, or both fiber channel A and fiber channel B are faulty. Fiber channel A is the default main channel, and fiber channel B is the backup channel. Fiber A and fiber B are two redundant fibers, both for unidirectional communication.

[0058] Step 120 , detecting output faults of the power matching module, executing a fault handling strategy and outputting a corresponding fault status, wherein the fault handling strategy includes further determining whether the output fault is a module-level fault based on the output fault.

[0059] Step 130 : Based on the detection of input fault and output fault, if it is a module-level fault, module-level fault processing is performed.

[0060] It should be noted that a module-level fault is one that prevents the module from delivering correct output. A module-level fault can be diagnosed based on a secondary diagnosis of both input and output faults. For example, if the fault diagnosis indicates an input fault, the fault can be further diagnosed as a module-level fault based on the input fault.

[0061] The above steps 110 to 130 are described in detail below.

[0062] (1) Diagnosis of analog input fault:

[0063] Please refer to Figure 2 , Figure 2 The figure is a flow chart of the analog input fault detection provided by the present invention. In the above step 110, the step of detecting the input fault of the power matching module includes: detecting the fault of the analog input signal, specifically including:

[0064] Step 210: Receive analog input data.

[0065] When testing analog input data, due to the uncertainty of external input analog data, it may be in a normal stable numerical state (called a stable state) or in an abnormal rapidly changing state (called a changing state). Therefore, for fault diagnosis of analog input signals, it is necessary to first determine whether the analog input data is in a stable state or a changing state.

[0066] Step 220 , determining whether the change range between the analog input data and the analog input data received at the last moment is within a preset range.

[0067] If the variation range is within the preset range, it indicates that the analog input data is in a stable state, and step 240 is executed.

[0068] That is to say, when the data change range is within a certain range, it can be considered that there is no abnormal data. According to the regular monitoring at preset time periods, data stuck caused by hardware failure can also be detected. That is, whether the data is stuck can be discovered in time in the stable state, and the correct data source can be switched to in time for subsequent calculation and processing.

[0069] Furthermore, since switching the steady-state data to the correct data source does not result in outputting erroneous data, but only delays the response time according to the timing diagnosis interval, the present invention can flexibly and reasonably allocate hardware resources according to the system response requirements.

[0070] If the change amplitude is not within the preset range, it indicates that the analog input data is in a changing state, and step 230 is executed.

[0071] If the amplitude of the change is not within the preset range, it means that the amplitude of the data change is large, which may cause the data output result to change greatly. From a safety perspective, the fault monitoring mechanism is triggered at this time, but the data with a large amplitude of change will not be defined as valid data before the fault state is confirmed. The fault monitoring is combined with the hardware response time to be controlled within the preset time (for example, 1ms). If it is determined that there is no fault, the data is defined as valid data. The preset delay time (for example, 1ms) set by the present invention has no effect on the overall required response time of the device. If it is determined to be an analog input fault, the data is defined as invalid data, but valid data provided by redundant equipment can be obtained from the optical fiber network (see Figure 3 shown).

[0072] Step 230: Determine whether the analog input data is in a stable state and continue to determine whether a preset timing time has arrived through the configured timing mechanism.

[0073] Even if no out-of-range data is detected, the present invention will determine whether the fault monitoring mechanism needs to be triggered based on whether the timing time is reached through the configured timing mechanism.

[0074] If the preset time arrives, step 240 is executed.

[0075] If the preset time has not arrived, step 250 is executed.

[0076] Step 240 : triggering the fault monitoring mechanism and starting the system's signal superposition circuit to perform fault detection by increasing or decreasing the superposition signal.

[0077] That is to say, the present invention determines whether there is an analog input fault by forcibly adding increments or canceling increments to analog input data through a hardware signal superposition circuit.

[0078] Step 250: output analog input data and fault results.

[0079] (2) Diagnosis of switch input failure:

[0080] In the above step 110, the step of detecting an input fault of the power matching module includes: detecting a fault of a switch input signal.

[0081] For example, fault detection for digital input signals can be implemented using hardware circuitry. For example, this hardware circuitry converts fault information into binary level states and outputs them to FPGA (Field Programmable Gate Array) software. This software can achieve the highest level of real-time diagnosis. The FPGA serves as the processor of the fault handling device described herein. The digital input data received by the software contains both the digital input signal state and the fault state, thus enabling complete real-time fault status monitoring without passing erroneous data to subsequent processing modules.

[0082] (3) Diagnosis of fiber optic communication faults and Ethernet communication faults:

[0083] In the above step 110, the step of detecting input faults of the power matching module includes: fault diagnosis of optical fiber communication and Ethernet communication.

[0084] For example, Ethernet and fiber optic communication fault diagnosis is performed based on whether diagnostic data is received. Because the data transmission frequency is predetermined, the software initialization phase determines whether the first data has been received. Once the first batch of data is received, normal operation begins. The system then determines the network communication status based on the predetermined data transmission frequency, providing real-time updates on channel fault status.

[0085] Please refer to Figure 3 , Figure 3 Schematic diagram of the effective data selection strategy under fault conditions provided by the present invention. In the above step 110, the steps of detecting input faults in the power matching module and executing the effective data selection strategy include:

[0086] Step 310: If it is an analog input fault or a switch input fault, valid data provided by the redundant device is obtained from the optical fiber network. If valid data from the redundant device cannot be obtained from the optical fiber network or the obtained data is invalid, it is determined to be a module-level fault.

[0087] For example, if the analog input channel fault status is no fault, it means that the channel acquisition data is valid. If the analog input channel fault status is faulty, that is, it is determined to be an analog input fault, it means

[0088] In step 320 , if the optical fiber communication fails, valid data is obtained from another redundant optical fiber network. If valid data cannot be obtained from the other redundant optical fiber network or the obtained data is invalid, it is determined to be a module-level failure.

[0089] For example, if the fiber channel fault status is "No Fault," meaning the fiber communication channel is not faulty, the data on Fiber Channel A is valid, and the system outputs valid data transmitted through Fiber Network Channel A. If the fiber channel status is "Faulted," meaning Fiber Channel A is faulty, the system selects another backup channel, Fiber Channel B, for transmission. The data on Fiber Channel B is valid. If no valid data can be obtained from Fiber Channel B, or the data obtained is invalid, this indicates a fault on Fiber Channel B, and a module-level failure is determined.

[0090] Fiber A is the default data receiving channel for this module (closer to the module), and Fiber B is the data receiving channel farther away from the module. Fiber A and Fiber B form a redundant fiber network pair.

[0091] Data availability refers to whether local channel data or network data is valid based on channel fault status detection. By default, in a fault-free state, local channel data is used as the data source, and fiber network data is the corresponding channel data parsed from the fiber network. It should be understood that fiber network data can come from both fiber channel A and fiber channel B, and the appropriate data source should be selected based on the fiber network fault status.

[0092] For example, in data transmission over an optical fiber network, each channel of data has a fault identification bit. When the data fault identification bit indicates a fault, it can be identified and the input of erroneous data can be controlled.

[0093] Step 330: If the Ethernet communication failure occurs, valid data is obtained from the optical fiber network. If valid data cannot be obtained from the optical fiber network or the obtained data is invalid, it is determined to be a module-level failure.

[0094] Therefore, by executing the above-mentioned effective data selection strategy, while selecting the correct data, the erroneous data can also be controlled through protocol analysis. On the premise of meeting the functional performance requirements, the erroneous data output when a fault occurs can be quickly controlled and the correct data output can be switched, which greatly reduces the impact of data jitter on the external inverter.

[0095] (4) Diagnosis of analog output fault:

[0096] Please refer to Figure 4 , Figure 4 The figure is a flow chart of the analog output fault detection provided by the present invention. In the above step 120, the step of detecting the output fault of the power matching module includes: diagnosing the fault of the analog output.

[0097] The judgment of analog output fault requires analog sampling of the data of the analog execution circuit. During this process, a time difference will be generated. In order to accurately and quickly judge whether there is a fault in the analog output, the following steps are specifically required:

[0098] Step 410: Obtain the calculated output value of the first analog quantity at a certain moment and the actual recovered value of the first analog quantity at a certain moment.

[0099] Assume that the calculated output value of the first analog quantity at time T0 is AO_Cal_T0, and the actual retrieved value of the first analog quantity at time T0 is AO_Get_T0.

[0100] Step 420: Determine whether the second analog output calculated value at the next moment is equal to the first analog output calculated value.

[0101] Assume that the calculated value of the second analog output at the next moment T1 is AO_Cal_T1, that is, determine whether AO_Cal_T1 is equal to AO_Cal_T0.

[0102] Step 430: If the second analog output calculated value is not equal to the first analog output calculated value, then continue to determine whether the second analog actual value at the next moment is obtained within a preset time.

[0103] Assume that the actual sampled value of the second analog quantity at the next moment T1 is AO_Get_T1.

[0104] Step 440: If the actual recovered value of the second analog quantity is obtained within the preset time, it is determined whether the second analog quantity output calculated value is equal to the actual recovered value of the second analog quantity.

[0105] That is, determine whether AO_Cal_T1 is equal to AO_Get_T1.

[0106] In step 450 , if the calculated value of the second analog output is not equal to the actual sampled value of the second analog, it is determined to be an analog output fault, indicating that the analog output has a fault.

[0107] That is, if AO_Cal_T1≠AO_Get_T1, it is determined that the analog output is faulty.

[0108] Step 460: If the calculated value of the second analog output is equal to the actual value of the second analog output, it is determined that the analog output has no fault.

[0109] That is, if AO_Cal_T1 = AO_Get_T1, it is determined that the analog output has no fault.

[0110] Step 470: If the second analog output calculated value is equal to the first analog output calculated value, determine whether the second analog actual value obtained at the next moment is equal to the first analog actual value.

[0111] That is, if AO_Cal_T1=AO_Cal_T1, then it is determined whether AO_Get_T1 is equal to AO_Get_T0.

[0112] In step 480, if the actual sampled value of the second analog quantity is not equal to the actual sampled value of the first analog quantity, it is determined that the analog quantity output has a fault.

[0113] That is, if AO_Get_T1≠AO_Get_T0, it is determined to be an analog output fault, indicating that the analog output has a fault.

[0114] In step 490, if the actual sampled value of the second analog quantity is equal to the actual sampled value of the first analog quantity, it is determined that the analog quantity output has no fault.

[0115] That is, if AO_Get_T1 = AO_Get_T0, it is determined that the analog output has no fault;

[0116] By adopting Figure 4 The analog output fault detection method shown here can detect faults within the shortest possible time of analog output transmission deviation. The module-level fault signal relay outputs the fault status, allowing the external inverter device to quickly switch to a backup analog output channel. This short-term fault diagnosis is the goal of high-frequency fault diagnosis.

[0117] Moreover, the present invention retrieves data after waiting for a fixed time after the analog output data is calculated, and can wait for the entire comparison process to be completed before performing the next calculation. However, since the system response time requirement is relatively high, the present invention can change the fixed time to a dynamic time, thereby optimizing the response time of continuously changing data and better meeting actual application requirements.

[0118] For example, please refer to Figure 5 , Figure 5 This is a schematic diagram of the analog output fault data comparison provided by the present invention. Analog output fault determination requires analog sampling of the analog execution circuit data. Since analog output faults are compared using the sampled data values, and due to the uncertainty of data changes, time control can be used to obtain accurate results, as shown in the following table:

[0119]

[0120]

[0121] (5) Diagnosis of relay output fault:

[0122] In the above step 120, the step of detecting output faults of the power matching module and executing a fault handling strategy includes: diagnosing faults of the relay output.

[0123] Relay output fault diagnosis is based on the execution time after the relay output, accurately controlling the loop detection time and achieving fault status detection in the shortest time. Relay output fault diagnosis can be achieved through hardware circuits.

[0124] Specifically, according to the execution time T of the relay output, when the system calculates that the relay output result has changed, the following steps are executed after the preset waiting time T:

[0125] When the relay output is a fast unloading signal relay output, if the previous fault diagnosis structure is a relay output fault, the relay output fault will be changed to a module-level fault.

[0126] When the relay output is a fault signal relay output, if the output function of any one fault relay or two fault signal relays belonging to the same channel fails, it is determined to be a fault warning, and the corresponding warning is completed through Ethernet communication; if the output function of any three fault signal relays or two relays belonging to different channels fails, it is determined to be a module-level fault, and at this time the module-level fault cannot be correctly output through the fault signal relay channel, and the corresponding alarm is completed through Ethernet external communication. The system is composed of four fault signal relays with common output control, and the two fault signal relays are connected in series and then in parallel (such as Figure 6 shown).

[0127] Figure 6 The power matching module shown includes an FPGA and four fault signal relays (610, 620, 630, 640). Fault signal relay 610 is connected to the Out1 pin of the FPGA, while fault signal relay 620 is connected to the Out2 pin of the FPGA. Fault signal relay 610 and fault signal relay 620 are connected in series. Fault signal relay 630 is connected to the Out3 pin of the FPGA, while fault signal relay 640 is connected to the Out4 pin of the FPGA. Fault signal relay 630 and fault signal relay 640 are connected in series. A first channel formed by the series connection of fault signal relay 610 and fault signal relay 620 and a second channel formed by the series connection of fault signal relay 630 and fault signal relay 640 are connected in parallel. After the parallel connection, they are connected to an external inverter.

[0128] Figure 6The validity of any one of the relay outputs shown will not cause the fault signal output to be valid. The four relays can be controlled separately through software to output valid in turn. For example, when the relay output is a fault signal relay output, if any one fault relay or two fault signal relays belonging to the same channel fail to output, it is determined to be a fault warning, and the corresponding warning is completed through Ethernet communication; if any three fault signal relays or two relays belonging to different channels fail to output, it is determined to be a module-level fault, and at this time the module-level fault cannot be correctly output through the fault signal relay channel, and the corresponding alarm is completed through Ethernet external communication. The system is composed of four fault signal relays with common output control, and two fault signal relays are connected in series and then in parallel. Because when three fault signal relays fail, it is considered to be at the zero limit point of relay combination output failure, the module-level fault output can be directly reported and the user can be prompted to avoid risks.

[0129] In addition, the interval of the timed detection can be determined based on the service life of the hardware system and the number of operations of the relay.

[0130] For example, please refer to Figure 7 In step 130, based on the detection of the input fault and the output fault, if it is a module-level fault, the steps of performing module-level fault processing include:

[0131] Step 710: Configure a high-speed switching mechanism.

[0132] Step 720 , according to the high-speed switching mechanism, triggering the fault signal relay output and switching to control any one of the parallel relays to be valid, indicating that the relay output is valid to achieve redundant output.

[0133] The structural diagram of the relay described in step 720 is as follows: Figure 6 As shown, when a module-level fault is triggered, all four fault signal relays are triggered to change from an open state to a closed state, fault signal relay 610 and fault signal relay 620 form output channel 1, fault signal relay 630 and fault signal relay 640 form output channel 2, and channel 1 and channel 2 realize redundant output.

[0134] The above conditions for triggering module-level faults are summarized in the following table:

[0135]

[0136] The design principle of the present invention is that any single point failure will not cause output failure. In addition to the various input data having backup input data that can be quickly selected in the fault state, when a module-level fault occurs, the module fault signal relay can be used to quickly output the module fault signal through the fault strategy, and the external inverter uses the backup module output signal in the system.

[0137] Please refer to Figure 8 , Figure 8 The figure is a flowchart of a fault handling method provided by an embodiment of the present invention. A fault handling method includes:

[0138] Step 811: Detect the power matching module for faults and obtain a fault diagnosis result.

[0139] Step 812: Determine whether there is a fault based on the fault diagnosis result.

[0140] If there is a fault, execute step 813;

[0141] If there is no fault, execute step 822.

[0142] Step 813: Determine whether the fault is an input fault.

[0143] If it is an input fault, execute step 814. The input fault may refer to a fault related to the input data.

[0144] If it is not an input failure, execute step 815.

[0145] Step 814: Execute the valid data selection strategy. The valid data selection strategy is to intercept faulty data and select fault-free data as valid data output. Figure 3 As shown, no further details are given here.

[0146] Step 815: Determine whether the fault is an analog output fault. Output faults include analog output faults and relay output faults, and relay output faults include fast unloading relay output faults and fault signal relay output faults.

[0147] If the analog output fails, execute step 816.

[0148] If it is not an analog output fault, execute step 817.

[0149] Step 816: If the analog output fails and the analog output is invalid, it is also determined to be a module-level failure.

[0150] In other words, the system determines that the analog output is faulty, and there is no backup output channel for output, resulting in invalid analog output.

[0151] However, if the analog output fails, but the analog output can be made valid through the backup output channel, it is considered to be able to output normally (not shown in the figure).

[0152] Step 817: Determine whether the fault is a fast unloading relay output fault.

[0153] If the fast unloading relay output is faulty, execute step 818 .

[0154] If it is not a quick unloading relay output fault, but a fault signal relay output fault, execute step 819.

[0155] Step 818: If the fast unloading relay output is faulty and the fast unloading relay output is invalid, it is determined to be a module-level fault.

[0156] That is to say, the system determines that the quick unloading relay output is faulty and there is no spare output channel for output, resulting in the quick unloading relay output being invalid.

[0157] However, if the quick unloading relay output fails, but the quick unloading relay output can be valid through the backup output channel, it is considered to be able to output normally (not shown in the figure).

[0158] Step 819: Determine whether the fault signal relay output fault constitutes a module-level fault.

[0159] Based on the aforementioned conditions for triggering a module-level fault, it can be known that a module-level fault may be triggered when output function failures of any three fault signal relays or two fault signal relays belonging to different channels are detected.

[0160] If it constitutes a module-level failure, execute step 824.

[0161] If it does not constitute a module-level fault, execute step 820.

[0162] Step 820: If the fault signal relay output is faulty and the fault signal relay output is invalid, it is determined to be a module-level fault.

[0163] That is to say, the system determines that the fault signal relay output is faulty and there is no backup output channel for output, resulting in the fault signal relay output being invalid.

[0164] However, if the fault signal relay output fails, but the fault signal relay output can be valid through the standby output channel, it is considered to be able to output normally (not shown in the figure).

[0165] Step 821, determine whether valid data is obtained.

[0166] Since it is determined to be an input failure, the system can provide a backup input channel to obtain valid data.

[0167] If valid data can be obtained through the backup input channel, step 822 is executed.

[0168] If no valid data can be obtained through the backup input channel, step 823 is executed.

[0169] Step 822: Output valid data and corresponding fault status. For example, output valid data and corresponding fault status, where the corresponding fault status is an analog input fault.

[0170] In step 823, it is determined to be a module-level failure.

[0171] Step 824: Output the corresponding fault status and perform module fault processing.

[0172] Exemplarily, module-level fault processing includes actuating and outputting a module-level fault relay and outputting a fault alarm externally via Ethernet.

[0173] For example, the fault state corresponding to the output may be a module-level fault, a combination of an analog input fault and a module-level fault, or a combination of an analog output fault and a module-level fault.

[0174] The steps for performing module-level fault handling are as follows Figure 7 As shown, no further details are given here.

[0175] The fault handling device provided by the present invention is described below. The fault handling device described below and the fault handling method described above can be referenced to each other.

[0176] See also Figure 9 , Figure 9 The figure is a schematic diagram of the structure of the fault handling device provided by the present invention. A fault handling device comprises at least two power matching modules, each of which is a redundant module, and the power matching modules are used to execute the fault handling method described above.

[0177] The power matching module is a key component of the energy management controller, requiring high response time and fault tolerance. To achieve faster response times, the power matching module's core processor uses a field-programmable logic device (FPGA), and an additional fiber optic network is added to implement a dual-ring network data communication mode.

[0178] For example, Figure 9The fault handling device is shown to include a power matching module 910, a power matching module 920, a power matching module 930, and a power matching module 940. The power matching module 910 and the power matching module 920 are mutually redundant power modules. The power matching module 930 and the power matching module 940 are also mutually redundant power modules. It is understandable that Figure 9 Four power matching modules are shown, but in actual application, only two modules, power matching module 910 and power matching module 920 , may be used.

[0179] Two redundant power matching modules simultaneously output independent analog signals and switch signals to the inverter. When a main module (such as power matching module 910) fails, the switch signal outputs fault information. After receiving the fault information, the inverter automatically switches to the other power matching module (such as power matching module 920) to output the signal.

[0180] Exemplarily, each power matching module includes a first input terminal AI (representing receiving analog input, the input of AI can be input from the channel of the power matching module 910 as the default main module, or from the channel of the power matching module 920 as the backup module), a second input terminal DI (representing switch input, the input of DI can be input from the channel of the power matching module 910 as the default main module, or from the channel of the power matching module 920 as the backup module), a third input terminal (representing Ethernet input and output), a first output terminal AO (representing analog output) and a second output terminal DO (representing switch output).

[0181] The first input AI and the second input DI are both connected to two redundant optical fibers (fiber A and fiber B). The third input is connected to Ethernet communication, and RS485 is a debugging signal. The power matching modules are connected to each other via two redundant optical fibers (fiber A and fiber B). Fiber A and fiber B form a redundant, unidirectional ring communication network.

[0182] The power matching module of this invention ensures that even if any of the AI, DI, Ethernet, fiber A, or fiber B fails, the AI ​​and DO output signals remain correct and meet system response time requirements. If a fault is detected in the AO output channel, an alarm signal can be quickly output to external devices via the DO output channel. The DO output channel is an external alarm output channel, and timed detection of the output channel enables pre-alarms before any action is required.

[0183] Furthermore, each power matching module includes a programmable array logic device (FPGA) and multiple relays, and the programmable array logic device is connected to an external frequency converter (such as Figure 6 shown).

[0184] In addition, the present invention also provides a ship management system, which is used to execute the fault handling method described above.

[0185] It should be noted here that the above-mentioned fault handling device and ship management system provided by the embodiment of the present invention can implement all the method steps implemented by the above-mentioned method embodiment, and can achieve the same technical effect. The parts and beneficial effects that are the same as those in the method embodiment will not be described in detail here.

[0186] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present invention.

Claims

1. A fault handling method, applied to a power matching module connected to an external frequency converter, characterized in that: The method comprises: Detecting input faults in the power matching module and executing a valid data selection strategy, the valid data selection strategy including: if an analog input fault or a switch input fault occurs, obtaining valid data provided by a redundant device from the optical fiber network; if valid data from the redundant device cannot be obtained from the optical fiber network or the obtained data is invalid, determining it as a module-level fault; if an optical fiber communication fault occurs, obtaining valid data from another redundant optical fiber network; if valid data cannot be obtained from another redundant optical fiber network or the obtained data is invalid, determining it as a module-level fault; if an Ethernet communication fault occurs, obtaining valid data from the optical fiber network; if valid data cannot be obtained from the optical fiber network or the obtained data is invalid, determining it as a module-level fault; Detecting output faults of the power matching module and executing a fault handling strategy and outputting a corresponding fault status, wherein the fault handling strategy includes further determining whether the output fault is a module-level fault based on the output fault; Based on the detection of the input fault and the output fault, if it is a module-level fault, performing module-level fault processing; Among them, input failures include analog input failures, switch input failures, fiber optic communication failures, and Ethernet communication failures; output failures include analog output failures and relay output failures.

2. The fault handling method according to claim 1, characterized in that: The step of detecting an input fault on the power matching module includes: Receive analog input data; Determining whether a change in the analog input data from the analog input data received at the previous moment is within a preset range; If the variation is within the preset range, the analog input data is determined to be in a stable state and the configured timing mechanism is used to determine whether the preset timing time has been reached. If the preset timing time has been reached or the variation is not within the preset range, the fault monitoring mechanism is triggered and the system's signal superposition circuit is activated to perform fault detection by increasing or decreasing the superposition signal and output the analog input data and the fault result. If the preset timing time is not reached, the analog input data and the fault result are directly output.

3. The fault handling method according to claim 1 or 2, characterized in that: The effective data selection strategy is to intercept faulty data and select non-faulty data as effective data, and determine that it is a module-level fault when no effective data can be obtained.

4. The fault handling method according to claim 1, characterized in that: The step of detecting an output fault of the power matching module includes: Obtain the calculated output value of the first analog quantity at a certain moment and the actual recovered value of the first analog quantity at a certain moment; Determine whether the second analog output calculated value at the next moment is equal to the first analog output calculated value; If the second analog output calculated value is not equal to the first analog output calculated value, then it is determined whether the second analog actual sampling value at the next moment is obtained within a preset time; if the second analog actual sampling value is obtained within the preset time, then it is determined whether the second analog output calculated value is equal to the second analog actual sampling value; if they are not equal, it is determined to be an analog output fault, indicating that there is a fault in the analog output; If the second analog output calculated value is equal to the first analog output calculated value, then continue to determine whether the second analog actual value obtained at the next moment is equal to the first analog actual value. If they are not equal, it is determined to be an analog output failure.

5. The fault handling method according to claim 1, characterized in that: The step of detecting an output fault of the power matching module and executing a fault handling strategy further includes: According to the execution time of the relay output, when the system calculates that the relay output result has changed, it will execute the following steps after the preset waiting time: When the relay output is a fast unloading signal relay output, if the previous fault diagnosis structure is a relay output fault, the relay output fault will be changed to a module-level fault; When the relay output is a fault signal relay output, if the output function of any fault relay or two fault signal relays belonging to the same channel fails, it is determined to be a fault warning, and the corresponding warning is completed through Ethernet communication; if the output function of any three fault signal relays or two relays belonging to different channels fails, it is determined to be a module-level fault, and at this time the module-level fault cannot be correctly output through the fault signal relay channel, and the corresponding alarm is completed through Ethernet external communication. The system is composed of four fault signal relays with common output control, and the two fault signal relays are connected in series and then in parallel.

6. The fault handling method according to claim 1, characterized in that: Based on the detection of the input fault and the output fault, if the fault is a module-level fault, the step of performing module-level fault processing includes: Configuring a high-speed switching mechanism; According to the high-speed switching mechanism, if any one channel of the two-channel relays connected in parallel is valid, it means that the relay output is valid to achieve redundant output.

7. A fault handling device, characterized in that: The device includes at least two power matching modules, each two power matching modules are redundant modules, and the power matching modules are used to execute the fault handling method according to any one of claims 1 to 6.

8. The fault handling device according to claim 7, characterized in that: Each power matching module includes a first input end, a second input end, a third input and output end, a first output end, and a second output end. The first input end and the second input end are both connected to two redundant optical fibers, and the third input and output end is connected to Ethernet. The power matching modules are connected through two redundant optical fibers. The two redundant optical fibers form two redundant ring communication networks and are both unidirectional communications.

9. The fault handling device according to claim 7, characterized in that: Each power matching module includes a programmable array logic device and a plurality of relays. The programmable array logic device is connected to an external frequency converter through the plurality of relays.

10. A ship management system, characterized in that: The system is used to execute the fault handling method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Control system IO fault control method and control system

    CN115237099A

  • Dual power supply automatic switching circuit

    CN202282640U