A fault detection protection method, computer device and readable storage medium
Patent Information
- Application Number
- CN202211494228.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-25
- Publication Date
- 2026-09-04
- Estimated Expiration
- 2042-11-25
AI Technical Summary
而现有技术大多在控制器主控芯片内设计硬件故障检测及保护逻辑,因主控芯片执行周期的局限性,无法做到快速响应
[0007]本发明所提供的故障检测保护方法,利用可编程逻辑门阵列响应迅速的特点,使检测到故障后进行保护的速度大大提高,减小了因故障造成控制器不可逆损伤的概率。
Smart Images

Figure CN115904786B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of new energy vehicle technology, specifically to a fault detection and protection method, a computer device, and a readable storage medium. Background Technology
[0002] The electric drive system is a core component of new energy vehicles, providing them with power. As the control unit of the electric drive system, the motor controller plays a crucial role in safety and stability; fault detection and protection are important safety functions.
[0003] Timeliness is a crucial indicator in motor controller fault protection. In certain severe faults, slow protection can cause irreversible damage to the motor controller, while timely protection can effectively reduce the risk of failure. Programmable gate arrays (PGAs), due to their programmability and rapid response, are used in hardware fault detection and protection design. They can function as independent devices for designing fault detection and protection logic, providing fault protection with nanosecond-level response times.
[0004] Hardware failures are serious faults that affect the vehicle's power and driving safety. Therefore, the logic design for hardware failure detection and protection needs to be timely and accurate while also having a certain degree of compatibility. However, most existing technologies design hardware failure detection and protection logic within the main control chip of the controller. Due to the limitations of the main control chip's execution cycle, a rapid response is not possible. Furthermore, existing technologies often rely on direct voltage level judgments for hardware failure detection, resulting in immediate shutdown upon failure, which is overly stringent and does not adequately consider the possibility of false alarms. Moreover, during vehicle operation, factors such as low-voltage fluctuations and electromagnetic interference can sometimes cause false alarms in the hardware failure detection circuit. Summary of the Invention
[0005] To address the aforementioned problems, this invention provides a fault detection and protection method that monitors and latches fault signals, and quickly executes relevant protection actions upon fault detection to protect the controller from damage.
[0006] To achieve the above objectives, the present invention adopts the following technical solution: A fault detection and protection method, based on a programmable gate array (PGA), is used for hardware fault detection and MCU protection of the electric drive assembly of new energy vehicles. The fault detection and protection method includes the following steps: The programmable gate array (PLA) receives and filters fault signals, and latches the filtered results. In response to the fault latch or a protection request initiated by the MCU, the PLA executes fault protection.
[0007] The fault detection and protection method provided by this invention utilizes the rapid response of programmable gate arrays to greatly improve the speed of protection after fault detection and reduce the probability of irreversible damage to the controller caused by the fault.
[0008] Optionally, the programmable gate array (PGA) filters the fault signal, including the following sub-steps: Determine if the level of the current fault signal is valid. If not, clear the counter and output a level opposite to the valid level of the current fault signal. If yes, proceed to the next determination step. Determine if the count is greater than the set value. If it is, output a level that is the same as the effective level of the current fault signal. If not, increment the count by 1 and output a level that is opposite to the effective level of the current fault signal.
[0009] By filtering the fault signal, false fault detection caused by glitch patterns can be avoided.
[0010] Optionally, fault latching of the filtered result involves taking the OR operation between the filtered result and the fault state at the previous time step, and outputting the current fault state. This includes the following sub-steps: If the filtered result is a fault-free state and the MCU issues a first fault clear command, then in response to the first fault clear command issued by the MCU, the fault-free state is output as the current fault state. If the filtered result is a fault-free state and the MCU does not issue the first fault clear command, the fault state of the previous moment is output as the current fault state to complete the latching. If the filtered result indicates a fault state, regardless of whether the MCU issues the first clear fault command, the fault state will be output as the current fault state to complete the latching.
[0011] Optionally, the programmable gate array (PGA) performs fault protection by including the following sub-steps: The power device IGBT is turned off for a first preset duration; a drive bridge arm is selected, and ASC protection is performed by the selected drive bridge arm for a second preset duration. After the ASC state ends, it continues to maintain the ASC state until the MCU sends an exit protection command; in response to the exit protection command sent by the MCU, the ASC state is exited, and the drive bridge arm is turned off for a third preset duration; the programmable logic array judges the current fault state and the second clear fault command issued by the MCU. If and only if the current fault state is a fault-free state and the second clear fault command issued by the MCU is met, the fault protection ends and the next round of fault protection is allowed. Otherwise, the drive bridge arm is turned off and the second clear fault command is not responded to.
[0012] Optionally, the drive arm includes an upper three-bridge and a lower three-bridge. When selecting a drive arm, first determine whether there is a fault in the lower three-bridge. If there is no fault in the lower three-bridge, the lower three-bridge will perform ASC protection. If there is a fault in the lower three-bridge, determine whether there is a fault in the upper three-bridge. If there is no fault in the upper three-bridge, the upper three-bridge will perform ASC protection. If there is a fault in the upper three-bridge, the power device drive arm will directly perform the shut-off action.
[0013] Optionally, the programmable gate array has several pins, and different types of fault signals are received by different pins; the programmable gate array determines the type of fault based on the pins of the received signals.
[0014] Optionally, the programmable gate array can be an FPGA or a CPLD.
[0015] Optionally, the first preset duration is 4μs, the second preset duration is 60μs, and the third preset duration is 60μs.
[0016] Furthermore, the present invention also provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the method described in any of the preceding claims.
[0017] In addition, the present invention also provides a computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the method described in any of the above-mentioned embodiments.
[0018] These features and advantages of the present invention will be disclosed in detail in the following specific embodiments and accompanying drawings. The preferred embodiments or means of the present invention will be shown in detail in conjunction with the accompanying drawings, but are not intended to limit the technical solutions of the present invention. In addition, each of these features, elements and components appearing in the following text and drawings is a plurality of, and different symbols or numbers are used for convenience of representation, but all represent parts with the same or similar construction or function. Attached Figure Description
[0019] The present invention will be further described below with reference to the accompanying drawings: Figure 1 This is a flowchart of the filtering process in an embodiment of the present invention; Figure 2 This is a flowchart of fault latching in an embodiment of the present invention; Figure 3 This is a flowchart illustrating fault protection in an embodiment of the present invention. Detailed Implementation
[0020] The technical solutions of the embodiments of the present invention will be explained and described below with reference to the accompanying drawings. However, the following embodiments are only preferred embodiments of the present invention and not all of them. Other embodiments obtained by those skilled in the art based on the embodiments in the implementation methods without creative effort are all within the protection scope of the present invention.
[0021] The terms "an embodiment," "example," or "trademark" used in this specification refer to a particular feature, structure, or characteristic described in connection with the embodiment itself that may be included in at least one embodiment disclosed in this patent. The phrase "in an embodiment" appearing in various places throughout the specification does not necessarily refer to the same embodiment.
[0022] Example: This embodiment provides a fault detection and protection method for fault recovery of the electric drive assembly of new energy vehicles. This embodiment addresses circuit faults in the new energy vehicle controller. The fault detection and protection method provided in this embodiment is applied to fault recovery, and the fault recovery method includes the following steps: The MCU determines whether a fault does not require exiting protection. The MCU also checks whether the judgment time and recovery attempts have reached their limits. If all three are negative, the MCU checks whether the programmable gate array (FPGA) has latched the fault. The FPGA can be either an FPGA or a CPLD, which is not limited here. In this embodiment, a CPLD is preferred. If the CPLD latches the fault, it executes or maintains the corresponding protection action. Simultaneously, the MCU's strategy action pin is set, the judgment timer starts, and a first fault clearing command is sent to the CPLD. If the CPLD does not latch the fault, the MCU checks whether its strategy action pin is set. If not, the fault recovery method ends. If it is set, the MCU sends an exit protection command to the CPLD. At this point, the MCU verifies the authenticity of the fault latched by the CPLD and attempts to reset the fault. If the fault reset is successful, it is a false alarm. The MCU then performs protection exit and fault recovery, performs feedforward compensation, and restores the vehicle's power.
[0023] The fault detection and protection method provided in this embodiment is applied to the fault latching and CPLD execution or maintenance of corresponding protection actions in the aforementioned fault recovery method, specifically including: The CPLD receives and filters fault signals to eliminate false alarms caused by glitches. The CPLD has several pins, and different types of fault signals are received by different pins. The CPLD determines the type of fault based on the pin of the received signal, including overvoltage faults, overcurrent faults, and drive bridge faults.
[0024] The filtering process is as follows Figure 1 As shown: Determine if the level of the current fault signal is valid. If not, clear the count and output a level opposite to the valid level of the current fault signal. If yes, proceed to the next determination step. Determine if the count is greater than the set value. If yes, output a level the same as the valid level of the current fault signal. If not, increment the count by 1 and output a level opposite to the valid level of the current fault signal.
[0025] Specifically, if the fault signal is active low, then determine whether the current fault signal is low. If not, the count is cleared and a high level is output. If yes, proceed to the next judgment step. Determine whether the count is greater than the set value. If yes, output a low level. If not, increment the count by 1 and output a high level. If the fault signal is active high, determine if the current fault signal is high. If not, clear the count and output a low level. If yes, proceed to the next judgment step. Determine if the count is greater than the set value. If yes, output a high level. If not, increment the count by 1 and output a low level.
[0026] In this embodiment, the count setting is preferably 32 times. In other embodiments, the count setting can be flexibly selected by those skilled in the art according to the actual situation, and is not limited here.
[0027] The CPLD performs fault latching on the filtered result. Fault latching involves taking the OR operation between the filtered result and the previous fault state, and outputting the result as the current fault state. Fault latching includes two judgment conditions, resulting in four combinations, but ultimately only three output states. Figure 2 As shown: If the filtered result is a fault-free state and the MCU issues a first fault clear command, then in response to the first fault clear command issued by the MCU, the fault-free state is output as the current fault state. If the filtered result is a fault-free state and the MCU does not issue the first fault clear command, the fault state of the previous moment is output as the current fault state to complete the latching. If the filtered result indicates a fault state, regardless of whether the MCU issues the first clear fault command, the fault state will be output as the current fault state to complete the latching.
[0028] If a latching failure occurs, the MCU sends a fault protection command to the CPLD. In response to the fault latching or the protection request initiated by the MCU, the CPLD executes the corresponding protection action according to the fault type. For example... Figure 3 As shown, the entire protection framework of the CPLD is based on a state machine, and faults are handled step by step through state transitions, including: The power device IGBT is turned off according to a first preset duration, preferably 4μs in this embodiment, to protect the device. A drive bridge arm is selected. The drive bridge arm is a six-arm design, including three upper bridges and three lower bridges. When selecting a drive bridge arm, it is first determined whether the lower three bridges are faulty. If the lower three bridges are not faulty, ASC protection is performed on them. If the lower three bridges are faulty, it is determined whether the upper three bridges are faulty. If the upper three bridges are not faulty, ASC protection is performed on them. If the upper three bridges are faulty, it means that both the upper and lower three bridges are faulty, so the power device drive bridge arm is directly turned off. ASC protection is performed by the selected drive bridge arm according to a second preset duration, preferably 60μs in this embodiment. In this embodiment, ASC protection is active short-circuit protection. The three drive bridge arms in the same direction of the IGBT are simultaneously turned on, while the three drive bridge arms in the other direction are simultaneously turned off, to release the rotational energy of the motor and avoid damaging the IGBT. The triggering condition for the CPLD to actively initiate ASC protection action does not include "drive fault". Therefore, after detecting a hardware fault, the CPLD must actively request to enter ASC to ensure that the reset actions for drive, overvoltage, and overcurrent faults are consistent. After the forced timeout ends, the ASC state is maintained until the MCU sends an exit protection command. In response to the exit protection command sent by the MCU, the ASC state is exited, and the drive bridge arm shut-off action is performed according to the third preset duration. In this embodiment, the third preset duration is preferably 60μs. The CPLD judges the current fault state and the second clear fault command issued by the MCU. If and only if the current fault state is a fault-free state and the second clear fault command issued by the MCU is met, the fault protection ends and the next round of fault protection is allowed. Otherwise, the drive bridge arm shut-off action is maintained, and the second clear fault command is not responded to.
[0029] The fault detection and protection method provided in this embodiment utilizes the rapid response of programmable gate arrays to greatly improve the speed of protection after fault detection and reduce the probability of irreversible damage to the controller caused by the fault.
[0030] Meanwhile, this embodiment provides a computer device, including a memory and a processor. The memory stores a computer program, and the processor executes the computer program to implement the methods in any of the above embodiments. Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. Accordingly, the computer program can be stored in a non-volatile computer-readable storage medium, and when executed, the computer program can implement the methods of any of the above embodiments. Any references to memory, storage, database, or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory. Non-volatile memory may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory may include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in a variety of forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), dual data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), RAMbus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM).
[0031] The above are merely specific embodiments of the present invention, but the scope of protection of the present invention is not limited thereto. Those skilled in the art should understand that the present invention includes, but is not limited to, the contents described in the accompanying drawings and the specific embodiments above. Any modifications that do not depart from the functional and structural principles of the present invention will be included within the scope of the claims.
Claims
1. A fault detection and protection method, said fault detection and protection method based on a programmable gate array, used for hardware fault detection and MCU protection of the electric drive assembly of new energy vehicles, characterized in that, The fault detection and protection method includes the following steps: The programmable gate array receives and filters fault signals, and latches the filtered results; in response to the fault latch or a protection request initiated by the MCU, the programmable gate array performs fault protection. The fault protection process performed by the programmable gate array includes the following sub-steps: The power device IGBT is turned off according to the first preset duration; a drive bridge arm is selected, and ASC protection is performed by the selected drive bridge arm according to the second preset duration. ASC protection is active short circuit protection. After the ASC protection ends, the ASC protection state is maintained until the MCU sends an exit protection command; in response to the exit protection command sent by the MCU, the ASC protection state is exited, and the drive bridge arm is turned off according to the third preset duration; the programmable gate array judges the current fault state and the second clear fault command issued by the MCU. If and only if the current fault state is a fault-free state and the second clear fault command issued by the MCU is met, the fault protection ends and the next round of fault protection is allowed. Otherwise, the drive bridge arm is turned off and the second clear fault command is not responded to.
2. The fault detection and protection method according to claim 1, characterized in that, The filtering of fault signals by a programmable gate array includes the following sub-steps: Determine if the level of the current fault signal is valid. If not, clear the counter and output a level opposite to the valid level of the current fault signal. If yes, proceed to the next determination step. Determine if the count is greater than the set value. If it is, output a level that is the same as the effective level of the current fault signal. If not, increment the count by 1 and output a level that is opposite to the effective level of the current fault signal.
3. The fault detection and protection method according to claim 1, characterized in that, Fault latching of the filtered result involves taking the OR operation between the filtered result and the fault state at the previous time step, and outputting the current fault state. This includes the following sub-steps: If the filtered result is a fault-free state and the MCU issues a first fault clear command, then in response to the first fault clear command issued by the MCU, the fault-free state is output as the current fault state. If the filtered result is a fault-free state and the MCU does not issue the first fault clear command, the fault state of the previous moment is output as the current fault state to complete the latching. If the filtered result indicates a fault state, regardless of whether the MCU issues the first clear fault command, the fault state will be output as the current fault state to complete the latching.
4. The fault detection and protection method according to claim 1, characterized in that, The drive arm includes the upper three bridges and the lower three bridges. When selecting the drive arm, first determine whether there is a fault in the lower three bridges. If there is no fault in the lower three bridges, the lower three bridges will perform ASC protection. If there is a fault in the lower three bridges, determine whether there is a fault in the upper three bridges. If there is no fault in the upper three bridges, the upper three bridges will perform ASC protection. If there is a fault in the upper three bridges, the power device drive arm will directly shut down.
5. The fault detection and protection method according to any one of claims 1 to 4, characterized in that, A programmable gate array (PGA) has several pins, and different types of fault signals are received by different pins; the PGA determines the type of fault based on the pins on which the received signals are received.
6. The fault detection and protection method according to any one of claims 1 to 4, characterized in that, The programmable logic gate array is either an FPGA or a CPLD.
7. The fault detection and protection method according to claim 1, characterized in that, The first preset duration is 4μs, the second preset duration is 60μs, and the third preset duration is 60μs.
8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the method of any one of claims 1 to 7.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the method of any one of claims 1 to 7.
Citation Information
Patent Citations
Motor monitoring method and device, electronic equipment and storage medium
CN113253110A
Fault latch protection circuit used for electric vehicle inverter control circuit
CN113328678A