Method for operating a battery memory device and battery memory device
By periodically sending first status messages and high-frequency second status messages by the control unit, combined with voltage drop detection, the reliability problem of defect identification in the energy storage device is solved, unnecessary safety reactions are reduced, and the stability of the energy storage device and the safety of the control unit are improved.
Patent Information
- Application Number
- CN202180058416.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-07-31
- Filing Date
- 2021-07-22
- Publication Date
- 2026-08-25
- Estimated Expiration
- 2041-07-22
AI Technical Summary
Existing technologies struggle to reliably identify defects in energy storage devices, especially in compact configurations, which can lead to damage to control units due to hot gas escape and temporary communication failures causing unnecessary safety incidents.
The control unit periodically sends a first status message, and after a reception interruption, it uses a second status message to send a fault report at a high frequency and with a high priority. Combined with voltage drop detection, the defect of the energy storage device can be quickly identified, and a safety response can be implemented when necessary.
This improves the reliability of identifying defects in the energy storage device, reduces unnecessary security responses, lowers message density, and ensures the safety and stability of the control unit.
Smart Images

Figure CN116194320B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a method and apparatus for operating a device. Background Technology
[0002] JP 2013051762A discloses a vehicle control device.
[0003] WO 2017 / 0143748A1 discloses a power battery and a safety system for the power battery in an electric vehicle. Summary of the Invention
[0004] The core of the present invention lies in the method for operating an energy storage device having a device control unit and a control unit, particularly a means of transport, in which the control unit sends a first status message to the device control unit at regular time intervals, wherein the control unit sends at least one second status message with a second fault report to the device control unit, wherein the device control unit implements a safety response when it has received the second status message and the reception of the first status message is interrupted.
[0005] The background of this invention is the ability to reliably identify defects in the energy storage device that could rapidly damage its control unit. This avoids unnecessary safety responses due to short-term communication failures or faulty second-state messages. Simultaneously, the number or frequency of first-state messages can be reduced, thereby lowering the message density between the device control unit and the control unit.
[0006] In particular, in a compact energy storage unit where the control unit is arranged adjacent to the energy storage unit, there is a risk that the control unit may be damaged shortly after the energy storage unit becomes defective due to hot gas escaping from the energy storage unit.
[0007] Further advantageous embodiments of the invention are the subject of the dependent claims.
[0008] According to an advantageous design, after the reception of the first status message is interrupted, it is checked whether a second status message indicating a voltage drop in the energy storage unit was received within a first time window prior to the interruption of the first status message reception. If a voltage drop exists within the first time window, a safety action is performed. If no voltage drop exists within the first time window, it is checked whether a second status message indicating a fault different from the voltage drop of the energy storage unit was received within a second time window prior to the interruption of the first status message reception. If other faults exist within the second time window, a safety action is performed. The advantage here is a rapid response to a voltage drop in the energy storage unit (which can lead to a critical state of the energy storage unit in a short time). For other faults, the assessment may be longer.
[0009] The second time window is advantageously larger than the first time window, especially by more than ten times, particularly where the first time window is less than 10s, especially 2s, and / or where the second time window is greater than 20s, especially 60s. This reduces the risk of a safety response caused by a voltage drop due to a sensor failure that happens to occur before the first state message is interrupted, since the voltage drop can only cause control unit failure within the first time window.
[0010] Furthermore, it is advantageous that the first status message contains an activity signal. The function of the control unit can therefore be monitored using the first status message.
[0011] Furthermore, it is advantageous that the first status information includes a first fault report, wherein the credibility of the first fault report has been checked, particularly by the monitoring unit of the control unit. Here, the first status message only includes the first fault report if the credibility of the fault has been checked. Therefore, the first status message can trigger a safety response independently of the second status message.
[0012] Advantageously, safety actions are implemented when the first status message contains a first fault report. The first status message here triggers a safety response independently of the second status message.
[0013] The second status message can be sent advantageously without waiting for a credibility check of the second fault report. This allows the second status message to be sent faster than the first status message.
[0014] Furthermore, it is advantageous to resend the second status message until the control unit receives confirmation of receipt of the second status message from the device control unit. This ensures the second status message reaches the device control unit. Nevertheless, the second status message is sent only within the time required to notify the device control unit.
[0015] Advantageously, the second state message is sent at a higher frequency than the first state message, particularly at a frequency at least ten times higher, and especially with a period duration of 2 ms. Therefore, the second state message is received much faster than the first state message.
[0016] It is advantageous here to send the second status message with a higher priority than the first status message.
[0017] The first status message is advantageously sent several times per second, particularly having a period duration of 100ms. The reception of this first status message is monitored by the device control unit, with a 3s dejitter time.
[0018] According to the advantageous design, the safety response is a warning message and / or the shutdown and / or discharge of the energy storage device. Advantageously, the type of safety response can be selected based on the type of fault.
[0019] The core of the present invention lies in the fact that in a device, particularly a transport vehicle, having a device control unit and an energy storage unit, the device is configured to operate by means of the method described above or according to one of the claims with reference to the method described above.
[0020] The background of this invention is the ability to reliably identify defects in the energy storage device that could rapidly damage its control unit. This avoids unnecessary safety responses due to short-term communication failures or faulty second-state messages. Simultaneously, the number or frequency of first-state messages can be reduced, thereby lowering the message density between the device control unit and the control unit.
[0021] The above-described design schemes and improvements can be combined arbitrarily as long as they are meaningful. Further possible design schemes, improvements, and implementation schemes of the present invention include combinations of features of the invention described above or below with reference to the embodiments, not explicitly mentioned. In particular, those skilled in the art will add various aspects as improvements or supplements to the corresponding basic forms of the invention. Attached Figure Description
[0022] The invention is explained in the following sections with the aid of embodiments, from which further inventive features can be derived, but the scope of the invention is not limited thereto. The embodiments are shown in the accompanying drawings.
[0023] Figure 1 The voltage trend U2(t) over time for the damaged energy storage cell and the voltage trend U1(t) over time for another energy storage cell are shown.
[0024] Figure 2 The timeline of events following the failure of a power storage cell is shown.
[0025] Figure 3 The diagnostic path and the resulting status messages during method 200 according to the invention are shown, as well as
[0026] Figure 4 A schematic flowchart of a method 200 for operating a device according to the present invention is shown. Detailed Implementation
[0027] exist Figure 1 The voltage trend U2(t) of a damaged energy storage cell is shown in the diagram. Additionally, the voltage trend U1(t) of at least one other energy storage cell is shown.
[0028] The energy storage device is compact and has a nominal voltage of less than 60V, preferably 48V, 24V, or 12V. Therefore, the energy storage device has fewer than twenty energy storage cells, preferably between four and sixteen.
[0029] In addition to the energy storage unit, the energy storage unit includes a control unit 10, sensors, and a communication interface 11. The control unit 10, which has the communication interface 11, has a circuit board arranged adjacent to the energy storage unit.
[0030] Sensors, particularly current and / or voltage and / or temperature sensors, are provided for detecting measurement data from the energy storage unit. The sensors are connected to the control unit 10 via data transmission. The control unit 10 is configured to evaluate the measurement data, particularly comparing it with stored limit values, and to transmit status messages (103, 102) to the device control unit 12 via the communication interface 11. The control unit 10 of the energy storage unit is located in close proximity to the energy storage unit.
[0031] At the first time point t1, the energy storage cell was damaged, specifically by being pierced by a nail. Shortly after the first time point t1, the voltage U2 of the energy storage cell began to drop slightly, while the voltage U1 of the other energy storage cell initially remained constant. Simultaneously, the damaged energy storage cell began to degas.
[0032] At the second time point t2, the voltage U2 of the damaged energy storage unit has either the maximum drop or the maximum negative rise.
[0033] At the third time point t3, the voltage U2 of the damaged energy storage unit and the voltage U1 of the other energy storage unit drop. At time point t3, the control unit 10 experiences its first failure, thus becoming unable to reliably evaluate the sensor's measurement data. At the fourth time point t4, communication between the communication interface 11 of the control unit 10 and the device control unit is interrupted.
[0034] exist Figure 2 In the diagram, events following the failure of a power storage unit are shown on the timeline.
[0035] The first time point t1 when the energy storage unit fails corresponds to 0ms in this diagram.
[0036] 300ms later, a second time point t2 appears, at which point the voltage U2 of the damaged energy storage unit has its maximum negative slope.
[0037] 400ms later, the third time point t3 appears, at which point the voltages (U1, U2) drop.
[0038] Only 500ms had passed by the fourth time point t4 when the communication ended.
[0039] The first time interval Δt1 extends from approximately 250 ms to approximately 310 ms after the first energy storage cell fails, during which the voltage drop of the failed energy storage cell can be identified. The first time interval Δt1 therefore includes the second time point t2.
[0040] The second time interval Δt2 extends from the first time interval Δt1 to the third time point t3, during which a fault report can be sent to the device control unit 12. Therefore, the second time interval Δt2 extends from approximately 310 ms to 400 ms.
[0041] Figure 3 The diagnostic path and the resulting status messages of the control unit 10 are shown in the diagram.
[0042] The control unit 10 includes a monitoring unit 100, which is configured to receive, evaluate, and check the reliability of measurement data from the sensors of the energy storage unit. The monitoring unit 100 is connected to the communication interface 11 of the control unit 10 via data transmission.
[0043] If the monitoring unit 100 identifies an error in the measurement data and is able to check its reliability, the monitoring unit 100 sends a first fault report 103 to the communication interface 11.
[0044] If the monitoring unit 100 identifies an error in the measurement data and is unable or unwilling to check its reliability, the monitoring unit 100 sends a second fault report 101 to the communication interface 11.
[0045] The communication interface 11 is connected to the device control unit 12 via data transmission.
[0046] Communication interface 11 sends a first status message 104 to device control unit 12 at regular time intervals, preferably every 100ms. The corresponding first status message 104 has an activity signal and may have a first fault report 103. The first status message 104 is sent with medium priority. The reception of the first status message 104 is monitored or monitored by device control unit 12 with a dejitter time of 3s.
[0047] If communication interface 11 receives a second fault report 101, it immediately sends a second status message 102 to device control unit 12. The second status message 102 is sent with high priority and at least once until communication interface 11 receives an acknowledgment of receipt of the second status message 102 from device control unit 12. As long as communication interface 11 does not receive an acknowledgment, it continues to send the second status message 102. The frequency of the second status message 102 is higher than that of the first status message 104, specifically ten times higher; preferably, the second status message 102 is sent every 2 ms.
[0048] Figure 4 A flowchart of a method 200 for operating a means of transport according to the present invention is shown.
[0049] In the first method step 201, the first status message 104 is sent from the control unit 10 to the device control unit 12 via the communication interface 11. The first status message 104 is sent periodically, preferably with a period duration of 100 ms. The first status message 104 is sent with medium priority. The first status message 104 is monitored or monitored by the device control unit 12 with a dejittering time of 3 seconds.
[0050] The first status message 104 may include a first fault report 103 from the energy storage sensor. The energy storage is classified as fault-free by the device control unit 12 as long as the first status message 104 arrives periodically and does not contain a first fault report 103. If the first status message 104 contains a first fault report 103, the device control unit 12 identifies the fault condition and implements a safety response, preferably generating a warning message, particularly for the user of the device or for the occupants of the vehicle and / or for the fleet owner.
[0051] The first fault report 103 indicates a fault in the energy storage unit whose reliability has been checked, such as a short circuit and / or overvoltage and / or overheating and / or increased self-discharge and / or undervoltage in the energy storage unit. For this purpose, the corresponding sensor data is compared with the limit values stored in the storage unit of the control unit.
[0052] In step 202 of the second method, it is checked whether the periodic reception of the first status message 104 has been interrupted.
[0053] If the reception of the first status message 104 is not interrupted, then in the third method step 203, it is checked whether the first status message 104 contains the first fault report 103.
[0054] If the first status message 104 does not contain the first fault report 103, the operation of the transport vehicle continues unchanged in the fourth method step 204.
[0055] If the first status message 104 contains a first fault report 103, a safety response is implemented in the fifth method step 205, preferably generating a warning message, particularly for the user of the device or for the occupants of the vehicle and / or for the fleet owner.
[0056] In the sixth method step 206, the second status message 102 is sent from the control unit 10 to the device control unit 12 via the communication interface 11. The second status message 102 is sent with high priority. The second status message 102 is sent at least once. If the control unit 10 does not receive a receipt confirmation from the transport control unit 12, the second status message 102 is retransmitted until the control unit 10 receives a receipt confirmation from the device control unit 12. In particular, the period duration of the second status message 102 is shorter than the period duration of the first status message 104, preferably less than one-tenth, and in particular, the period duration of the second status message is 2 ms.
[0057] The second status message 102 includes a second fault report 101. The second fault report 101 indicates a fault in the sensor signal of the energy storage device's sensor, such as sensor malfunction and / or exceeding or falling below limit values and / or the sensor signal being unmeasurable. Alternatively or additionally, the second fault report 101 indicates a short circuit and / or overvoltage and / or undervoltage and / or overheating and / or voltage drop in the energy storage cell. The second status message 102 is sent immediately upon the occurrence of the second fault report 101. The reliability of the second fault report 101 is not checked here.
[0058] If the second status message 102 is received and the periodic reception of the first status message 104 is not interrupted, the second status message 102 is ignored and the operation of the transport vehicle continues unchanged in the fourth method step 204.
[0059] If the periodic reception of the first status message 104 is interrupted, then in the seventh method step 207, it is checked whether the second status message 102 indicating the voltage drop was received within the first time window before the periodic reception of the first status message 104 was interrupted. Preferably, the first time window is shorter than 10 seconds, and in particular, the first time window is 2 seconds long.
[0060] In step 208 of the eighth method, check whether a voltage drop is detected within the first time window.
[0061] If a voltage drop is detected in the eighth method step 208, a safety response is implemented in the fifth method step 205, preferably generating a warning message, particularly for the user of the device or the occupants of the vehicle.
[0062] If no voltage drop is detected in step 208 of the eighth method, step 209 of the ninth method checks whether a second status message 102 indicating another fault is received within a second time window before the periodic reception of the first status message 104 is interrupted. The second time window is preferably larger than the first time window, particularly more than ten times the size of the first time window, and in particular, the second time window is 60 seconds long.
[0063] In the tenth method step 210, check whether a fault other than voltage drop is identified within the second time window.
[0064] If a fault other than voltage drop is identified in the second status message 102 in the tenth method step 210, a safety response is implemented in the fifth method step 205, preferably generating a warning message, particularly for the occupants of the transport vehicle.
[0065] If no fault is identified in the second status message 102 in the tenth method step 210, the operation of the transport vehicle continues unchanged in the fourth method step 204.
[0066] Energy storage is understood herein as a rechargeable energy storage device, particularly an energy storage unit having electrochemical properties and / or an energy storage module having at least one electrochemical energy storage unit and / or an energy storage package having at least one energy storage module. The energy storage unit can be implemented as a lithium-based battery unit, particularly a lithium-ion battery unit. Alternatively, the energy storage unit can be implemented as a lithium polymer battery unit, a nickel-metal hydride battery unit, a lead-acid battery unit, a lithium-air battery unit, or a lithium-sulfur battery unit.
[0067] The term "vehicle" is understood herein to mean a land vehicle, such as a bus or truck, an airplane or a ship, and especially a vehicle that is at least partially electric. Such a vehicle is, for example, a battery-powered vehicle with a purely electric drive, or a hybrid vehicle with both an electric drive and an internal combustion engine.
Claims
1. A method (200) for operating a battery storage device, comprising a device control unit (12) and an energy storage device having a control unit (10): in, The control unit (10) sends a first status message (104) to the device control unit (12) at regular time intervals, wherein the first status message contains a first fault report. The control unit (10) sends at least one second status message (102) to the device control unit (12), which has a second fault report (101). The device control unit (12) implements a safety response when it has received the second status message (102) and the reception of the first status message (104) is interrupted. After the reception of the first status message (104) is interrupted, check whether a second status message (102) indicating the voltage drop of the energy storage unit was received within the first time window before the reception of the first status message (104) was interrupted. If a voltage drop exists within the first time window, a safety action will be taken. If there is no voltage drop in the first time window, then check whether a second state message (102) indicating a fault different from the voltage drop of the energy storage is received in the second time window before the reception of the first state message (104) is interrupted. If a fault different from the voltage drop exists within the second time window, a safety action will be taken.
2. The method (200) according to claim 1. Its features are, The second time window is larger than the first time window.
3. The method (200) according to any one of the preceding claims. Its features are, The first status message (104) has an activity signal. and / or The first status message (104) has a first fault report (103), wherein the first fault report (103) has been checked for credibility.
4. The method (200) according to claim 3. Its features are, If the first status message (104) has a first fault report (103), then a safety action is performed.
5. The method (200) according to any one of the preceding claims. Its features are, Send a second status message (102) without waiting for a credibility check of the second fault report (101).
6. The method (200) according to any one of the preceding claims. Its features are, The second status message (102) is resent until the control unit (10) receives a confirmation of receipt of the second status message from the device control unit (12).
7. The method (200) according to any one of the preceding claims. Its features are, Send the second status message (102) with a higher priority than the first status message (104).
8. The method (200) according to any one of the preceding claims. Its features are, Send a first status message (104) several times per second.
9. The method (200) according to any one of the preceding claims. Its features are, The safety response is a warning message and / or the shutdown of the energy storage device and / or the discharge of the energy storage device.
10. The method (200) according to claim 2. Its features are, The second time window is more than ten times larger than the first time window.
11. The method (200) according to claim 2 or 10. Its features are, Wherein the first time window is less than 10s, and / or wherein the second time window is greater than 20s.
12. The method (200) according to claim 2 or 10. Its features are, The first time window is 2 seconds, and / or the second time window is 60 seconds.
13. The method (200) according to claim 3. Its features are, The reliability of the first fault report (103) has been checked by the monitoring unit (100) of the control unit (10).
14. The method (200) according to claim 6. Its features are, The second status message (102) is sent at a higher frequency than the first status message (104).
15. The method (200) according to claim 6 or 14. Its features are, The second status message (102) is sent at a frequency at least ten times higher than the first status message (104).
16. The method (200) according to claim 6 or 14. Its features are, The second status message (102) is sent with a period of 2ms.
17. The method (200) according to claim 8. Its features are, The first status message (104) has a period duration of 100ms.
18. A means of transport, having a device control unit (12) and an energy storage device having a control unit (10), Its features are, The means of transport is configured to operate by means of the method (200) according to any one of the preceding claims.
Citation Information
Patent Citations
Vehicle control device
JP2013051762A
Power battery, protection system thereof, and electric vehicle
WO2017143748A1
Battery Control System, and Battery System
US20160325626A1