A detection method, system, device and medium for emergency path loop in vehicle BMS functional safety architecture
By analog signal triggering the FS0B/FS1B interface in the controller monitoring layer of the BMS, the detection command is sent to the high-voltage relay module, and the emergency path loop self-test is carried out, which solves the problem that the existing technology cannot disconnect the relay under high voltage conditions, and realizes the safety and reliability of the BMS system.
Patent Information
- Application Number
- CN202410935131.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-07-12
- Publication Date
- 2025-05-20
- Estimated Expiration
- 2044-07-12
AI Technical Summary
The prior art cannot ensure that the BMS can disconnect the relay when the internal safety mechanism of the chip fails under the condition that the high-voltage relay is not absorbed, and meets the safety status requirements of the functional safety software.
In the BMS controller monitoring layer, the analog signal triggers the FS0B/FS1B interface to be at a high level, sends detection instructions to the high-voltage relay module, and conducts self-test of the emergency path loop to ensure that the relay can be disconnected under high voltage conditions.
It realizes that when the high-voltage relay is not absorbed, the BMS can enter a safe state within FTTI time to ensure the safety and reliability of system testing.
Smart Images

Figure CN118837733B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of on-vehicle battery pack state monitoring, and specifically relates to a method, system, device and medium for detecting an emergency path loop in an on-vehicle BMS functional safety architecture. Background Art
[0002] In the functional safety project of an on-vehicle battery pack BMS, referring to the ISO 26262-2018 standard and GB / T 39086-2020 "Functional Safety Requirements and Test Methods for Battery Management Systems for Electric Vehicles", in the functional safety project, when a chip internal safety mechanism failure is triggered, the BMS needs to disconnect the relay within a certain time, that is, it needs to enter the safe state within the FTTI time (Fault Tolerant Time Interval), and the safe state is to disconnect the high-voltage relay.
[0003] The functional safety architecture in the BMS mainly refers to the E-GAS three-layer architecture, which includes a function layer, a function monitoring layer, and a controller monitoring layer. Based on the E-GAS three-layer architecture, Level-1 is the function layer, Level-2 is the function monitoring layer, and Level-3 is the controller monitoring layer. The function layer of Level-1 is mainly a combination of software and related hardware resources that can implement the designed functions. The function monitoring layer of Level-2 is mainly responsible for monitoring the output results of the function layer, which is equivalent to software redundancy verification. The controller monitoring layer of Level-3 mainly ensures that the hardware environment for the operation of LV1 and LV2 is normal, that is, mainly monitors the controller. The monitoring of the chip internal safety mechanism failure in the above-mentioned functional safety project is implemented in the controller monitoring layer of Level-3. When a chip internal safety mechanism failure is triggered, such as a failure in triggering program flow monitoring, the BMS needs to disconnect the relay within a certain time, and this problem has become the research focus of those skilled in the art.
[0004] The functional safety requirements of functional safety software are based on the above-mentioned functional safety goals. To ensure that the BMS software has the ability to enter the safe state before software startup, that is, the ability to disconnect the high-voltage relay. Most of the existing technical solutions are to detect the adhesion failure of the relay, the open circuit failure of the high-voltage suction relay, and the three-state diagnosis of the relay drive circuit (including the short circuit to power supply, short circuit to ground, and open circuit of the drive circuit) before power-on. These several fault detection methods detect the available state of the relay during power-on, and the above-mentioned fault detection methods cannot solve the requirement of functional safety software to detect the ability of the relay to disconnect before high-voltage power-on. Summary of the Invention
[0005] The object of the present invention is to provide a detection method, system, device and medium for an emergency path circuit in a vehicle-mounted BMS functional safety architecture, so as to solve the problem that when a hardware safety mechanism failure occurs in the functional safety software, the software can trigger the relay to turn off from the FS0B / FS1B interface of the emergency path circuit, and it is realized under the condition that the high-voltage relay is not attracted, that is, the battery pack has no high voltage, ensuring the safety and reliability during the BMS system test.
[0006] The present invention realizes the above object through the following technical solutions:
[0007] In the first aspect, the present invention proposes a detection method for an emergency path circuit in a vehicle-mounted BMS functional safety architecture, which is applied before the high-voltage power-on of the battery pack. When the controller monitoring layer in the BMS functional safety architecture detects a hardware safety mechanism failure, the controller monitoring layer triggers the FS0B / FS1B interface to be at a high level through an analog signal, and performs self-check on the emergency path circuit of the high-voltage relay module. The detection method includes:
[0008] Send a first detection instruction to the high-voltage relay module, where the first detection instruction includes the following operations in sequence: disconnect the high-side and low-side drives, disconnect the high-side and engage the low-side, disconnect the FS0B / FS1B interface, engage the high-side and disconnect the low-side, disconnect the FS0B / FS1B interface;
[0009] Receive the first detection instruction, retrieve the operation control strategy corresponding to the first detection instruction pre-established in the controller monitoring layer, and after performing detection in response to the detection control strategy, the high-voltage relay module returns the high-side and low-side drive states;
[0010] Read back the high-side and low-side drive states of the high-voltage relay module, and determine the emergency path circuit information of the high-voltage relay module according to the read-back of the high-side and low-side drive states.
[0011] Further, when the controller monitoring layer performs self-check on the emergency path circuit of the high-voltage relay module, the emergency path circuit includes the following configurations:
[0012] (1) The physical contacts of the high-voltage relay module are in an open state;
[0013] (2) The high-side and low-side drives of the high-voltage relay module are powered by 12v low voltage.
[0014] Further, the pre-established operation control strategy corresponding to the first detection instruction includes:
[0015] Receive the read-back of the high-side and low-side drive states of the high-voltage relay module, match the subsequent corresponding operations in the first detection instruction after reading the states, and output an instruction;
[0016] Receive the output instruction and process it into a control instruction;
[0017] Receive the control instruction. After the high-voltage relay module performs a driving operation, data output is carried out;
[0018] Receive the data output and process it into a high and low side drive state status readback.
[0019] Furthermore, before the controller monitoring layer performs self-check on the emergency path circuit of the high-voltage relay module, it includes:
[0020] When the controller monitoring layer monitors that the trigger program flow monitoring is abnormal, or the AFE acquisition chip is abnormal, or the temperature sensor power supply voltage is abnormal, or the SBC power supply voltage is abnormal, the BMS enters the emergency path circuit self-check within the FTTI time.
[0021] Furthermore, determining the emergency path circuit information of the high-voltage relay module according to the high and low side drive state readback includes: determining whether the BMS enters the safe state or the fault state according to the high and low side drive state readback of the high-voltage relay and whether the confirmation state changes within the set time; among them,
[0022] If the drive state readback of all operations in the first detection instruction passes, the BMS enters the safe state;
[0023] If any drive state readback in the first detection instruction triggers a timeout detection, the current safe state is ended and the detection is resumed. The BMS enters the fault state and reports the fault through the CAN protection output.
[0024] In a second aspect, the present invention proposes a detection system for an emergency path circuit in a vehicle-mounted BMS functional safety architecture. The detection system is used to perform self-check on the emergency path circuit of the high-voltage relay module by the controller monitoring layer triggering the FS0B / FS1B interface to be at a high level through an analog signal before the high voltage of the battery pack is powered on and when the controller monitoring layer in the BMS functional safety architecture detects a hardware safety mechanism failure. The detection system includes a controller monitoring module that performs real-time information interaction with the high-voltage relay module:
[0025] The controller monitoring module is used to send a first detection instruction to the high-voltage relay module. Among them, the first detection instruction sequentially includes the following operations: disconnect the high side and the low side drive, disconnect the high side and engage the low side, disconnect the FS0B / FS1B interface, engage the high side and disconnect the low side, disconnect the FS0B / FS1B interface;
[0026] The high-voltage relay module is used to receive the first detection instruction, retrieve the operation control strategy corresponding to the first detection instruction formulated in advance in the controller monitoring layer, and after performing detection in response to the detection control strategy, the high-voltage relay module returns the high-side and low-side drive states;
[0027] The controller monitoring module is also used to read back the high-side and low-side drive states of the high-voltage relay module, and determine the emergency path loop information of the high-voltage relay module according to the read-back of the high-side and low-side drive states.
[0028] Further, the controller monitoring module includes a logic unit, a control unit, a high-low side drive unit, and a state read-back unit;
[0029] The logic unit is used to receive the read-back of the high-side and low-side drive states of the high-voltage relay module, match the subsequent corresponding operations in the first detection instruction after reading the states, and output an instruction, and send the output instruction to the control unit;
[0030] The control unit is used to receive the output instruction and process it into a control instruction, and output it to the high-low side drive unit;
[0031] The high-low side drive unit is used to receive the control instruction, and after the high-voltage relay module performs a drive operation, it outputs data to the state reading unit;
[0032] The state reading unit is used to receive the data output, and process it into a high-side and low-side drive state read-back to the logic unit.
[0033] In a third aspect, the present invention proposes an electronic device, including:
[0034] A processor; a memory for storing instructions executable by the processor;
[0035] Wherein, the processor is configured to execute the instructions to implement the detection method as described above.
[0036] In a fourth aspect, the present invention proposes a computer-readable storage medium, when the instructions in the computer-readable storage medium are executed by a processor of an electronic device, the electronic device can execute the detection method as described above.
[0037] The beneficial effects of the present invention are as follows:
[0038] 1. The detection method in the present invention can solve the ability required by functional safety software to detect that the relay is disconnected before power-on, and it is under the condition that the relay is not attracted, that is, the battery pack has no high voltage, the controller monitoring layer judges to trigger the emergency path loop detection, and verifies that the high-voltage relay state can be normally disconnected, ensuring the safety and reliability during the BMS system test.
[0039] 2. The self - inspection of the emergency path circuit of the high - voltage relay module in the present invention is specifically to detect the pin angles of the FS0B / FS1B interfaces that trigger the emergency path of the high - voltage relay module in the controller monitoring layer, so that the state of the relays on the circuit can reach the off state, including operations such as reading back the state of the relays. In addition, compared with the high - voltage detection in the prior art, the present invention uses 12V low - voltage for the detection and reading back of high - and low - side drive, and the test safety is better. Description of the Drawings
[0040] Figure 1 It is a flowchart of a method for detecting the emergency path circuit in the vehicle - mounted BMS functional safety architecture provided in Embodiment 1 of the present application.
[0041] Figure 2 It is a schematic diagram of a method for detecting the emergency path circuit in the vehicle - mounted BMS functional safety architecture provided in Embodiment 1 of the present application.
[0042] Figure 3 It is a block diagram of the detection control strategy in the method for detecting the emergency path circuit in the vehicle - mounted BMS functional safety architecture provided in Embodiment 1 of the present application.
[0043] Figure 4 It is a specific implementation flowchart of the method for detecting the emergency path circuit in the vehicle - mounted BMS functional safety architecture provided in Embodiment 1 of the present application. Detailed Implementation Manner
[0044] The following further describes the present application in detail with reference to the drawings. It is necessary to point out here that the following specific implementation manners are only used to further illustrate the present application and cannot be understood as limiting the protection scope of the present application. Those skilled in the art can make some non - essential improvements and adjustments to the present application according to the above application content.
[0045] Embodiment 1
[0046] As Figures 1-3 shown, this embodiment proposes a method for detecting the emergency path circuit in the vehicle - mounted BMS functional safety architecture. When applied before the high - voltage power - on of the battery pack and when the controller monitoring layer in the BMS functional safety architecture detects a hardware safety mechanism failure, the controller monitoring layer triggers the FS0B / FS1B interfaces to be at a high level through analog signals to perform self - inspection on the emergency path circuit of the high - voltage relay module.
[0047] It should be noted that in this embodiment, the emergency path circuit mainly refers to that when the controller monitoring layer of the Level-3 layer detects a failure in the internal security mechanism of the trigger chip, such as the failure of program flow monitoring, or the abnormality of the AFE acquisition chip, or the abnormality of the temperature sensor power supply voltage, or the abnormality of the SBC power supply voltage, it triggers the disconnection control instruction of the FS0B / FS1B interface. The actuator (high-voltage controller module) receives the control instruction of the controller monitoring layer and executes the action, and the status of the actuator action execution is read back. The path formed by all the actions on this link is collectively referred to as the emergency path circuit.
[0048] In this embodiment, the detection method includes the following steps:
[0049] S1. Send a first detection instruction to the high-voltage relay module. Among them, the first detection instruction sequentially includes the following operations: disconnect the high-side and low-side drives, disconnect the high-side and engage the low-side, disconnect the FS0B / FS1B interface, engage the high-side and disconnect the low-side, disconnect the FS0B / FS1B interface;
[0050] S2. Receive the first detection instruction, retrieve the operation control strategy corresponding to the first detection instruction pre-established in the controller monitoring layer, and after detecting in response to the detection control strategy, the high-voltage relay module returns the high-side and low-side drive states;
[0051] S3. Read back the high-side and low-side drive states of the high-voltage relay module, and determine the emergency path circuit information of the high-voltage relay module according to the read-back of the high-side and low-side drive states.
[0052] It can be understood that when making functional safety software, when a failure occurs in the internal security mechanism of the trigger chip, such as a failure in triggering program flow monitoring, the BMS needs to be able to disconnect the relay within a certain time. When the vehicle is just powered on, a signal in a safe state needs to be simulated, and the interface for simulating entering the emergency path is FS0B / FS1B; when the LV3 controller monitoring layer triggers the self-check of the emergency path circuit when it is just powered on, the LV3 controller monitoring layer simulates the triggering of the emergency path state and triggers the pin of the emergency path, named FS0B / FS1B; when the FS0B / FS1B pin triggers a high level, the emergency path is detected, and the specific detection path is as Figure 2 shown.
[0053] Further preferably, when the controller monitoring layer performs self-check on the emergency path circuit of the high-voltage relay module, the emergency path circuit includes the following configurations:
[0054] (1) The physical contacts of the high-voltage relay module are in the disconnected state;
[0055] (2) The high-side and low-side drives of the high-voltage relay module are powered by 12v low voltage.
[0056] In this embodiment, the self - inspection of the emergency path circuit of the high - voltage relay module is different from the prior art of detecting the switch closing ability of the relay. Instead, it is to detect the pin angles of the FS0B / FS1B interfaces of the high - voltage relay module triggering the emergency path circuit in the controller monitoring layer, so that the state of the relay on the circuit can reach the off state, including operations such as reading back the state of the relay. In addition, compared with the high - voltage detection in the prior art, the present invention uses 12V low - voltage for the detection and read - back of high - and low - side drive (non - high - voltage detection), and the test safety is better.
[0057] Further preferably, the operation control strategy corresponding to the first detection instruction formulated in advance includes:
[0058] Receive the high - and low - side drive state read - back of the high - voltage relay module, match the subsequent corresponding operations in the first detection instruction after reading the state, and output the instruction;
[0059] Receive the output instruction and process it into a control instruction;
[0060] Receive the control instruction, after the high - voltage relay module performs the drive operation, perform data output;
[0061] Receive the data output and process it into a high - and low - side drive state read - back.
[0062] Combined with Figure 4 , the first detection instruction in step S1 above includes the following steps:
[0063] Step1: Disconnect the high - side drive of the relay and disconnect the low - side drive of the relay;
[0064] Step2: Disconnect the high - side drive of the relay and engage the low - side drive of the relay;
[0065] Step3: Trigger an emergency path fault and disconnect the FS0B / FS1B interface;
[0066] Step4: Restore the emergency path fault, engage the high - side drive of the relay, and disconnect the low - side drive of the relay;
[0067] Step5: Trigger an emergency path fault and disconnect the FS0B / FS1B interface;
[0068] Step6: Restore the emergency path fault, Success enter the safe state success flag;
[0069] ERR: Fault state;
[0070] The connection between Step and Step and the ERR state is connected by arrow states, including:
[0071] Relay high and low side drive status readback Condition-11;
[0072] Timeout detection Condition-12;
[0073] Relay high and low side drive status readback Condition-21;
[0074] Timeout detection Condition-22;
[0075] Relay high and low side drive status readback Condition-31; Readback that the high side drive of the relay is disconnected and the low side drive of the relay is disconnected;
[0076] Timeout detection Condition-32;
[0077] Relay high and low side drive status readback Condition-41;
[0078] Timeout detection Condition-42;
[0079] Relay high and low side drive status readback Condition-51; Readback that the high side drive of the relay is disconnected and the low side drive of the relay is disconnected;
[0080] Timeout detection Condition-52;
[0081] The prerequisite for entering the emergency path detection is that the BMS software unit performs detection before initial self-check and high-voltage power-on. The relays detected include the main positive relay, the main negative relay, etc., which are collectively referred to as relays below.
[0082] Further preferably, before the controller monitoring layer performs self-check on the emergency path circuit of the high-voltage relay module, it includes:
[0083] When the controller monitoring layer monitors that the trigger program flow monitoring is abnormal, or the AFE acquisition chip is abnormal, or the temperature sensor power supply voltage is abnormal, or the SBC power supply voltage is abnormal, the BMS enters the self-check of the emergency path circuit within the FTTI time. That is, the internal safety mechanism failure of the trigger chip proposed in this embodiment.
[0084] Further preferably, determining the emergency path circuit information of the high-voltage relay module according to the high and low side drive status readback includes: determining whether the BMS enters the safe state or the fault state according to the high and low side drive status readback of the high-voltage relay and whether the status changes within the set time; among them, if the drive status readback of all operations in the first detection instruction passes, the BMS enters the safe state; if any drive status readback in the first detection instruction triggers timeout detection, the current safe state is ended and the detection is resumed, the BMS enters the fault state, and reports the fault through the CAN protection output.
[0085] Combined with Figure 3 and Figure 4 , in order to more clearly describe the technical solution of the present invention, the content of the present invention will be elaborated in detail. The emergency path loop detection specifically includes the following steps:
[0086] Enter the Step1 state and issue the command: disconnect the high-side drive of the relay and disconnect the low-side drive of the relay; the command is sent to the actuator module (high-voltage relay module) through the controller module (controller monitoring module in this embodiment), and the functional safety software logic module reads back the status, that is, the relay high- and low-side drive status readback Condition-11. It is confirmed that the high-side drive of the relay is disconnected and the low-side drive of the relay is disconnected. If the detection time between the detected relay high- and low-side drive status and the actually read-back status is too long, trigger the timeout detection Condition-12, that is, the detection time is too long, and the system enters the ERR fault state, ending the detection of the current safety state.
[0087] In the Step1 state, the relay high- and low-side drive status readback Condition-11 indeed reads that the high-side drive of the relay is disconnected and the low-side drive of the relay is disconnected. Meeting the conditions, enter the next stage. Enter the Step2 state and issue the command: disconnect the high-side drive of the relay and engage the low-side drive of the relay; the functional safety software logic module reads back the status, that is, the relay high- and low-side drive status readback Condition-21. It is confirmed that the high-side drive of the relay is disconnected and the low-side drive of the relay is engaged. If the detection time between the detected relay high- and low-side drive status and the actually read-back status is too long, trigger the timeout detection Condition-22, that is, the detection time is too long, and the system enters the ERR fault state, ending the detection of the current safety state.
[0088] In the Step2 state, the relay high- and low-side drive status readback Condition-21 indeed reads that the high-side drive of the relay is disconnected and the low-side drive of the relay is engaged. Meeting the conditions, enter the next stage. Enter the Step3 state and issue the command: trigger an emergency path fault and disconnect the FS0B / FS1B interface; the functional safety software logic module reads back the status, that is, the relay high- and low-side drive status readback Condition-31. Since triggering the emergency path fault causes both the high- and low-sides of the relay to be in the disconnected state, it is read that the high-side drive of the relay is disconnected and the low-side drive of the relay is disconnected. If the detection time between the detected relay high- and low-side drive status and the actually read-back status is too long, trigger the timeout detection Condition-32, that is, the detection time is too long, and the system enters the ERR fault state, ending the detection of the current safety state.
[0089] In the Step3 state, the relay high and low side drive status is read back as Condition-31. Triggering the emergency path fault causes both the high and low sides of the relay to be in the off state. It is indeed read that the high side drive of the relay is off and the low side drive of the relay is off, meeting the conditions to enter the next stage. Enter the Step4 state and issue the command: Emergency path fault recovery, activate the high side drive of the relay, and deactivate the low side drive of the relay; the functional safety software logic module reads back the status, that is, the relay high and low side drive status is read back as Condition-41. It is indeed read that the high side drive of the relay is activated and the low side drive of the relay is off. If the detection time between the detected relay high and low side drive status and the actually read back status is too long, trigger the timeout detection Condition-42, that is, the detection time is too long, and the system enters the ERR fault state, ending the detection of the current safety state.
[0090] In the Step4 state, the relay high and low side drive status read back as Condition-41 indeed reads that the emergency path fault has been recovered, the high side drive of the relay is activated, and the low side drive of the relay is off, meeting the conditions to enter the next stage. Enter the Step5 state and issue the command: Trigger the emergency path fault, disconnect the FS0B / FS1B interface; the functional safety software logic module reads back the status, that is, the relay high and low side drive status is read back as Condition-51. Since triggering the emergency path fault causes both the high and low sides of the relay to be in the off state, it is read that the high side drive of the relay is off and the low side drive of the relay is off. If the detection time between the detected relay high and low side drive status and the actually read back status is too long, trigger the timeout detection Condition-52, that is, the detection time is too long, and the system enters the ERR fault state, ending the detection of the current safety state.
[0091] In the Step5 state, the relay high and low side drive status read back as Condition-51 indeed reads that triggering the emergency path fault causes both the high and low sides of the relay to be in the off state, that is, the high side drive of the relay is off and the low side drive of the relay is off, meeting the conditions to enter the next stage. Enter the Step6 state, the emergency path fault is recovered, the Step6 state is Success and enters the safety state success flag. Entering this state represents the successful detection of the emergency path loop, sending the detection success flag bit of the emergency path loop. The detection of the emergency path loop is successful this time, and the test ends.
[0092] The frequency of the detection method for this emergency path loop is only once before power-on.
[0093] Embodiment 2
[0094] Based on the same inventive concept, this embodiment proposes a detection system for the emergency path circuit in the in-vehicle BMS functional safety architecture. The detection system is used to self-check the emergency path circuit of the high-voltage relay module by triggering the FS0B / FS1B interface to be at a high level through an analog signal when the controller monitoring layer in the BMS functional safety architecture detects a hardware safety mechanism failure before the high-voltage power-on of the battery pack. The detection system includes a controller monitoring module that interacts with the high-voltage relay module in real time for information.
[0095] The controller monitoring module is used to send a first detection instruction to the high-voltage relay module. Among them, the first detection instruction sequentially includes the following operations: disconnect the high-side and low-side drives, disconnect the high-side and engage the low-side, disconnect the FS0B / FS1B interface, engage the high-side and disconnect the low-side, and disconnect the FS0B / FS1B interface.
[0096] The high-voltage relay module is used to receive the first detection instruction, retrieve the operation control strategy corresponding to the first detection instruction formulated in advance in the controller monitoring layer, and after performing detection in response to the detection control strategy, the high-voltage relay module returns the high- and low-side drive states.
[0097] The controller monitoring module is also used to read back the high- and low-side drive states of the high-voltage relay module, and determine the emergency path circuit information of the high-voltage relay module according to the read-back of the high- and low-side drive states.
[0098] Further preferably, the controller monitoring module includes a logic unit, a control unit, a high- and low-side drive unit, and a state read-back unit; the logic unit is used to receive the read-back of the high- and low-side drive states of the high-voltage relay module, match the subsequent corresponding operations in the first detection instruction after reading the states, and output an instruction, and output the instruction to the control unit; the control unit is used to receive the output instruction and process it into a control instruction, and output it to the high- and low-side drive unit; the high- and low-side drive unit is used to receive the control instruction, and after the high-voltage relay module performs a drive operation, output data to the state reading unit; the state reading unit is used to receive the data output, and process it into a high- and low-side drive state read-back to the logic unit.
[0099] The above units all exist in the functional safety software. Refer to Figure 3 , M0 is the logic unit; M1 is the control unit; M2 is the relay high- and low-side drive unit; M3 is the state reading unit; C0 is the output instruction processed by the logic unit; C1 is the control instruction of the control unit; C2 is the data output of the relay high- and low-side drive unit; C3 is the state read-back of the state reading unit.
[0100] M0 is a logic unit, which mainly receives the status feedback C3 from the status reading unit M3, processes the control logic of the high and low side drives of the relay after reading the status, and outputs the result after the control logic of the high and low side drives of the relay to the control unit M1 through the output instruction C0.
[0101] The control unit M1 receives the output instruction C0 from the logic unit M0, processes the output instruction C0 into a control instruction C1, and outputs the control instruction C1 to the high and low side drive unit M2 of the relay.
[0102] The high and low side drive unit M2 of the relay receives the control instruction C1 from the control unit M1, and outputs the data output C2 to the status reading unit M3 after executing and processing the control instruction;
[0103] The status reading unit M3 mainly receives the data output C2 after the execution status of the high and low side drives of the relay processed by the high and low side drive unit M2 of the relay, processes the data output C2, and outputs the status feedback C3 to the logic unit M0; the entire fault handling logic is as described above.
[0104] It should be noted here that the above controller monitoring module and high-voltage relay module correspond to steps S1 to S3 in implementing the above detection method. The instances and application scenarios implemented by multiple modules and the corresponding steps are the same, but are not limited to the content disclosed in the above Embodiment 1.
[0105] According to the above embodiments of the present invention, in the functional safety software, when the detection system is for an electric vehicle before power-on (non-high-voltage detection) and a fault that triggers the internal safety mechanism of the chip occurs in the functional safety software, it enters a safe state. For example, when a fault in the program flow monitoring is triggered, the BMS needs to be able to disconnect the relay within a certain time. When the vehicle starts to power on, a signal of a safe state needs to be simulated, and the interfaces for simulating entering the emergency path are FS0B / FS1B; when the LV3 controller monitoring layer triggers the loop self-check of the emergency path when it is just powered on, the LV3 controller monitoring layer simulates the trigger of the emergency path state and triggers the pin of the emergency path, named FS0B / FS1B; when the FS0B / FS1B pin triggers a high level, the detection of the emergency path is performed. On the premise that the high-voltage relay is not closed, it is judged that the trigger of the emergency path loop detection is verified, and the state of the high-voltage relay can be normally disconnected.
[0106] Embodiment 3
[0107] This embodiment proposes an electronic device, including:
[0108] A processor; a memory for storing instructions executable by the processor;
[0109] Wherein, the processor is configured to execute instructions to implement the detection method as described above.
[0110] Example 4
[0111] This embodiment provides a computer-readable storage medium. When the instructions in the computer-readable storage medium are executed by a processor of an electronic device, the electronic device can execute the detection method as described above.
[0112] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed in this article can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.
[0113] In addition, in each embodiment of this application, the functional modules can be integrated into a processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit.
[0114] If the above functions are implemented in the form of software function modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in the embodiments of the present invention. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs that can store program codes.
[0115] The above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them; although this application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of each embodiment of this application.
Claims
1. A method for detecting an emergency path loop in a vehicle-mounted BMS functional safety architecture, characterized in that: Applied to before the high voltage of the battery pack is powered on, when the controller monitoring layer in the BMS functional safety architecture detects a hardware safety mechanism failure, the controller monitoring layer triggers the FS0B / FS1B interface to a high level through an analog signal, and performs a self-check on the emergency path circuit of the high-voltage relay module. The detection method includes: Sending a first detection instruction to the high-voltage relay module, wherein the first detection instruction includes the following operations in sequence: disconnecting the high-side and low-side drivers, disconnecting the high-side and attracting the low-side, disconnecting the FS0B / FS1B interface, attracting the high-side and disconnecting the low-side, and disconnecting the FS0B / FS1B interface; Receiving the first detection instruction, calling the operation control strategy corresponding to the first detection instruction pre-formulated in the controller monitoring layer, and after performing detection in response to the operation control strategy, the high-voltage relay module returns the high-side and low-side drive states; Reading back the high-side and low-side driving states of the high-voltage relay module, and determining the emergency path loop information of the high-voltage relay module according to the reading back of the high-side and low-side driving states; Among them, when the controller monitoring layer in the BMS functional safety architecture detects a hardware safety mechanism failure, it triggers the disconnection control instruction of the FS0B / FS1B interface, the high-voltage relay module receives the action execution of the control instruction of the controller monitoring layer, and the status of the action execution of the high-voltage relay module is read back. The path formed by all actions on this link is the emergency path loop.
2. The method for detecting an emergency path loop in a vehicle-mounted BMS functional safety architecture according to claim 1, characterized in that: When the controller monitoring layer performs self-inspection on the emergency path loop of the high-voltage relay module, the emergency path loop includes the following configuration: (1) The physical contacts of the high-voltage relay module are in a disconnected state; (2) The high-side and low-side drivers of the high-voltage relay module are powered by a 12V low-voltage power supply.
3. The method for detecting an emergency path loop in a vehicle-mounted BMS functional safety architecture according to claim 1, characterized in that: The pre-formulated operation control strategy corresponding to the first detection instruction includes: Receive the high-side and low-side drive status of the high-voltage relay module and read back the status, match the subsequent corresponding operation in the first detection instruction after reading the status, and output the instruction; receiving the output instruction and processing it into a control instruction; After receiving the control instruction, the high-voltage relay module performs a driving operation and then outputs data; The data output is received and processed as high and low side driver status state readback.
4. The method for detecting an emergency path loop in a vehicle-mounted BMS functional safety architecture according to claim 1, characterized in that: Before the controller monitoring layer performs self-test on the emergency path circuit of the high-voltage relay module, it includes: When the controller monitoring layer detects an abnormality in the program flow monitoring, or an abnormality in the AFE acquisition chip, or an abnormality in the temperature sensing power supply voltage, or an abnormality in the SBC power supply voltage, the BMS enters the emergency path loop self-check within the FTTI time.
5. The method for detecting an emergency path loop in a vehicle-mounted BMS functional safety architecture according to claim 1, characterized in that: The method of determining the emergency path loop information of the high-voltage relay module according to the high-side and low-side drive state readback includes: determining whether the BMS enters a safe state or a fault state according to the high-side and low-side drive state readback of the high-voltage relay and confirming whether the state changes within a set time; wherein, If the drive status readback of all operations in the first detection instruction passes, the BMS enters a safe state; If any drive state readback of all operations in the first detection instruction triggers a timeout detection, the current safe state is terminated and the detection is returned, the BMS enters a fault state, and reports the fault through the CAN protection output.
6. A detection system for emergency path loop in a vehicle-mounted BMS functional safety architecture, characterized in that: The detection system is used before the battery pack is powered on at high voltage. When the controller monitoring layer in the BMS functional safety architecture detects a hardware safety mechanism failure, the controller monitoring layer triggers the FS0B / FS1B interface to be at a high level through an analog signal, and performs a self-check on the emergency path loop of the high-voltage relay module. The detection system includes a controller monitoring module that interacts with the high-voltage relay module in real time: The controller monitoring module is used to send a first detection instruction to the high-voltage relay module, wherein the first detection instruction includes the following operations in sequence: disconnecting the high-side and low-side drivers, disconnecting the high-side and attracting the low-side, disconnecting the FS0B / FS1B interface, attracting the high-side and disconnecting the low-side, and disconnecting the FS0B / FS1B interface; The high-voltage relay module is used to receive the first detection instruction, call the operation control strategy corresponding to the first detection instruction pre-formulated in the controller monitoring layer, and after performing detection in response to the operation control strategy, the high-voltage relay module returns the high and low side drive states; The controller monitoring module is also used to read back the high-side and low-side driving states of the high-voltage relay module, and determine the emergency path loop information of the high-voltage relay module according to the high-side and low-side driving states; Among them, when the controller monitoring layer in the BMS functional safety architecture detects a hardware safety mechanism failure, it triggers the disconnection control instruction of the FS0B / FS1B interface, the high-voltage relay module receives the action execution of the control instruction of the controller monitoring layer, and the status of the action execution of the high-voltage relay module is read back. The path formed by all actions on this link is the emergency path loop.
7. The detection system for emergency path loop in the vehicle BMS functional safety architecture according to claim 6 is characterized in that: The controller monitoring module includes a logic unit, a control unit, a high-side and low-side driving unit and a status readback unit; The logic unit is used to receive the high and low side drive status of the high voltage relay module and read back the status, match the subsequent corresponding operation in the first detection instruction after reading the status, and output the instruction to the control unit; The control unit is used to receive the output instruction and process it into a control instruction, and output it to the high-side and low-side driving units; The high-side and low-side driving units are used to receive the control instructions, and after the high-voltage relay module performs the driving operation, the data is output to the status reading unit; The state reading unit is used to receive the data output, process it into high-side and low-side driving states, and read it back to the logic unit.
8. An electronic device, characterized in that: include: processor; a memory for storing instructions executable by the processor; The processor is configured to execute the instructions to implement the detection method according to any one of claims 1 to 5.
9. A computer-readable storage medium, characterized in that: When the instructions in the computer-readable storage medium are executed by a processor of an electronic device, the electronic device is enabled to perform the detection method as claimed in any one of claims 1 to 5.
Citation Information
Patent Citations
Detection method, system and device for safety state loop in vehicle-mounted BMS function safety architecture and medium
CN118837732A