Driveback mining system, method, apparatus, and media for vehicle safety output
By using a 2oo2 structure drive feedback system and employing dual-channel cross detection and dynamic loop detection modes, the problems of long fault response time and high false alarm rate in traditional vehicle-mounted safety output systems are solved, achieving rapid fault response and high-reliability output.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-08
- Publication Date
- 2026-04-07
AI Technical Summary
Traditional vehicle safety output systems suffer from long fault response times and high false alarm rates. Existing patents have failed to effectively address the dynamic detection of contacts and the inspection of drive feedback circuits.
The drive acquisition system with a 2oo2 structure includes a relay module, a drive acquisition module, an FPGA module, an MCU module, and a CPLD module. It enhances system safety and fault response speed through dual-channel cross detection and dynamic loop detection modes.
It significantly improves fault handling response speed, reduces false alarm rate, enhances system security and reliability, has strong compatibility, and is suitable for multi-output systems.
Smart Images

Figure CN119459805B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to rail transit signal systems, in particular to a drive back mining system, method, device and medium for on-board safety output. BACKGROUND
[0002] In the rail transit signal industry, the input and output subsystem provides a safe connection with the vehicle for the on-board ATC system to realize train automatic protection and automatic driving, and the safety output module is an important component. The safety output module drives the output of control commands, including EB (emergency brake) output, door opening enable output, train zero speed state output, etc. The implementation must meet the fail-safe principle. Currently, the output of the traditional on-board system has the problems of long fault reaction time and high false alarm rate.
[0003] After searching, Chinese patent publication No. CN116540520A discloses a safety output system based on forced direction type relays, which adopts two processors to control the driving ends of two forced direction type relays, and the two forced direction type relays are connected in series and then output. The output signal of each single stable circuit and the fixed level output signal of the corresponding two processors pass through a logic circuit, and the result is used as the driving control signal of the forced direction type relay coil power supply. In addition, each of the other two processors detects the power-on state of the two forced direction type relay coils through a drive back mining circuit. Each of the two processors detects the output state of the two forced direction type relays through two node back mining circuits. However, the existing patent does not involve the contact dynamic detection process, and the drive back mining circuit cannot be tested. Therefore, how to further enhance the safety of the system and improve the fault handling response speed becomes a technical problem to be solved. SUMMARY
[0004] The purpose of the present application is to overcome the defects of the prior art and provide a drive back mining system, method, device and medium for on-board safety output.
[0005] The purpose of the present application can be achieved by the following technical solutions:
[0006] According to a first aspect of the present application, a drive back mining system for on-board safety output is provided, comprising:
[0007] The relay module adopts a 2-to-2 structure;
[0008] The drive back mining module adopts a 2-to-2 structure, is used for controlling the relay module, and has a back mining detection function;
[0009] FPGA module, for communicating with external system, decoding the command of external system to get driving instruction, and sending the state information of the system to external system;
[0010] MCU module, using 2-to-2 structure, for receiving the driving instruction sent by FPGA module, and sending the driving instruction to the driving backhaul module of the system;
[0011] CPLD module, for comparing the information of the double channel of MCU module, and cutting off the power supply of the coil of the relay module if the information is inconsistent.
[0012] As a preferred technical solution, the driving backhaul module comprises:
[0013] The coil driving circuit is used for isolating and amplifying the driving signal sent by the MCU module, and generating the coil driving signal DRIVE_A according to the amplified signal, and controlling whether the power supply of the relay coil is grounded through RELAYDRIVE_A, so as to control the attraction and disconnection of the relay;
[0014] The state backhaul circuit is used for isolating the RELAYDRIVE_A signal, and connecting the relay state RELAYSTATE_A signal to the digital ground through the normally closed contact of the relay.
[0015] As a preferred technical solution, the relay is attracted when the DRIVE_A is low, and the relay is disconnected when the DRIVE_A is high;
[0016] The RELAYSTATE_A is in high impedance state when the relay is attracted, and the RELAYSTATE_A is in low level when the relay is disconnected.
[0017] As a preferred technical solution, the state backhaul circuit gets the READBACK_A signal by performing exclusive OR operation on the RELAYDRIVE_A and RELAYSTATE_A signals, and the MCU module reads the READBACK_A signal;
[0018] The state backhaul circuit uses the power supply negative state signal of the relay coil for the input of the LED circuit, and observes the state of the relay through the LED, the LED is on when the relay is attracted, and the LED is off when the relay is disconnected.
[0019] As a preferred technical solution, the driving backhaul module comprises two working modes, which are steady-state output backhaul mode and dynamic loop detection mode.
[0020] As a preferred technical scheme, in the steady-state output recovery mode, the relay output is driven according to the state of DRIVE_A, and after waiting for a set time, the relay state is stable, at this time, the RELAYSTATE_A state is stable, and the READBACK_A signal is read back.
[0021] As a preferred technical scheme, in the dynamic loop detection mode, the state of DRIVE_A is flipped, and the relay contact state and the relay drive loop are read back when the relay has not yet acted, and after the read back is completed, the original DRIVE_A state is restored.
[0022] As a preferred technical scheme, the MCU module obtains the relay contact state of the system through the steady-state output recovery detection of the drive recovery module, and obtains the health state of the drive circuit of the system through the dynamic loop detection of the drive recovery module, and obtains the relay contact state of the other system through the relay circuit of the other system, and the collection results of the system and the other system are sent to the CPLD module for double-system comparison, if the comparison is wrong, the CPLD module immediately cuts off the relay power supply, and notifies the CPU module to close the relay output of the system, and the system is guided to the safe side.
[0023] As a preferred technical scheme, the MCU module comprises:
[0024] An initialization and self-checking module is configured to initialize each internal and external device and global variable used in the MCU module during power-on process of the MCU module, and check the initial state of the relay;
[0025] A command acquisition and checking module is configured to cyclically check whether a control command sent by the FPGA is received, if yes, read the control command and check the safety of the control command, if the checking is wrong, enter an error and alarm module, and if the checking is passed, generate a drive instruction;
[0026] An output and recovery module is configured to output the command passed by the safety checking, and recover the relay output state after the output circuit is actuated, and encode the recovery data and write the recovery data into a specified register of the FPGA for reading by other systems;
[0027] A dynamic self-checking module is configured to check the state of the MCU and the state of the relay during running process.
[0028] As a preferred technical scheme, the relay module adopts a forced guiding type safety relay, the power supply of the coil of the relay is controlled by a coil power supply control circuit of the CPLD module, receives a control signal sent by the drive recovery module to drive the normally open contact output of the relay, and recovers through the normally closed contact of the relay.
[0029] According to a second aspect of the present application, a method for using the drive back-off system for vehicle safety output is provided, comprising the following steps:
[0030] Step S1, receiving and decoding the control instruction from the external system;
[0031] Step S2, checking the safety of the instruction, and generating the output command of the relay according to the passed instruction to drive the relay output;
[0032] Step S3, performing the steady-state output back-off on the circuit after the action, and performing the dynamic loop detection on the drive back-off circuit;
[0033] Step S4, processing the back-off signal from the drive back-off circuit and making a judgment;
[0034] Step S5, completing the loop control, and writing the system state into the designated register.
[0035] According to a third aspect of the present application, an electronic device is provided, comprising a memory and a processor, wherein the memory stores a computer program, and the processor executes the program to realize the method.
[0036] According to a fourth aspect of the present application, a computer readable storage medium is provided, which stores a computer program, and the program is executed by a processor to realize the method.
[0037] Compared with the prior art, the present application has the following advantages:
[0038] 1) The drive back-off system of the present application can back off the state of the output relay in the steady state, and can periodically use the dynamic loop detection mode to check the health of the drive back-off circuit. When there is a fault such as state lock or drive circuit break in the output back-off path, the loop problem can be found before the attraction instruction is received, avoiding the system working with a fault, and significantly improving the fault handling response speed.
[0039] 2) The drive back-off system of the present application adopts the architecture of 2oo2, which checks the output state of the other system while checking the output state of the system, thereby enhancing the safety of the system.
[0040] 3) The detection method of the relay contact of the present application introduces the KO mechanism, which can effectively avoid the false report of the high-sensitivity acquisition mechanism caused by the external high-frequency interference, and improves the reliability of the system.
[0041] 4) The present application describes the design of a drive back-off circuit of a vehicle safety output relay, which can be actually expanded to multiple outputs, and all are dry contact outputs, which has strong compatibility. BRIEF DESCRIPTION OF DRAWINGS
[0042] Figure 1 Structure diagram of the system of the present application;
[0043] Figure 2 Structure diagram of the A system driving recovery module of the present application;
[0044] Figure 3 Data flow diagram of the system of the present application;
[0045] Figure 4 Software module diagram of the MCU module of the present application;
[0046] Figure 5 Flow chart of the method of the present application;
[0047] Figure 6 Signal timing waveform diagram of the present application. DETAILED DESCRIPTION
[0048] The technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative work should fall within the protection scope of the present application.
[0049] The present application provides a driving recovery system for vehicle safety output to solve the problems of long fault reaction time and high false alarm rate of the output of the traditional vehicle system.
[0050] The present application adopts a combined fault safety technology to ensure the safety of system operation, adopts a 2oo2 double system architecture, recovery of the system while increasing AB system mutual detection to enhance the safety of the system, the recovery module has self-checking function in addition to checking the state of the relay contact, improves the fault reaction time of the system, adopts the control technology of double sets of single-chip microcomputer+FPGA+CPLD, and can filter the collected signals, and reduces the false alarm rate.
[0051] As shown in Figure 1 The driving recovery system of the present application mainly includes the following modules:
[0052] 1. Relay module: The power supply of the coil of the relay module is controlled by the coil power supply control circuit of the CPLD module, receives the control signal sent by the driving recovery module to drive the normally open contact of the relay to output, and recovers through the normally closed contact of the relay; the normally open contacts of the A\B system relays are connected in series to realize 2-to-2 control; the contact recovery signal is sent to the A\B system at the same time to realize cross detection; the relay is a forced direction safety relay, which ensures that the normally open and normally closed contacts cannot be closed at the same time, prevents the adhesion of the electric shock, and meets the safety direction;
[0053] 2. Drive feedback module: This module controls the relays and serves as a relay execution module for controlling high-voltage electricity from low-voltage electricity. It also has feedback detection function, which determines whether the relay coil is energized and whether the drive module itself is functioning properly by checking the normally closed contact state of the relay and the state of the coil drive circuit.
[0054] 3. MCU Module: Receives drive commands from the FPGA and forwards them to the drive feedback module of this system; receives and processes contact feedback signals from systems A and B, as well as drive circuit feedback signals from this system, and simultaneously sends the judgment results to the CPLD modules of systems A and B for cross-detection. If a circuit status error is detected, the output command is disabled.
[0055] 4. CPLD Module: Performs a secure comparison of information from both channels. If they are inconsistent, the relay coil power supply is cut off via the coil power control circuit. An independent secure comparison unit ensures the reliability of the comparison results.
[0056] 5. FPGA module: Responsible for communicating with external systems, decoding commands from external systems to obtain drive instructions, and sending the status information of this system to external systems.
[0057] like Figure 2 The diagram shown is a block diagram of the A-series drive recovery module circuit. The design of the B-series drive recovery module circuit is the same as that of the A-series drive recovery module circuit. The main focus here is on... Figure 2 The circuit design of the A-series drive acquisition module is explained.
[0058] The drive acquisition module consists of two parts: a coil drive circuit and a status acquisition circuit. The main function of the coil drive circuit is to isolate and amplify the drive signal from the MCU. The amplified signal is then sent to the drive circuit to generate the drive signal for MOSFET Q1, which controls whether the negative power supply RELAYDRIVE_A of the relay coil is grounded, thereby controlling the relay's activation and deactivation. The relay is activated when DRIVE_A is low and deactivated when DRIVE_A is high.
[0059] The main function of the status feedback circuit is to isolate the RELAYDRIVE_A signal. The RELAYSTATE_A signal is connected to digital ground through the normally closed contact of the relay; that is, RELAYSTATE_A is in a high-impedance state when the relay is energized and in a low-level state when the relay is de-energized. The feedback circuit performs a XOR operation on the RELAYDRIVE_A and RELAYSTATE_A signals to obtain the READBACK_A signal for the MCU module to read. The negative state signal of the relay coil power supply is used as the input to the LED circuit. The state of the relay can be observed through the LED; the LED lights up when the relay is energized and turns off when the relay is de-energized.
[0060] The drive recovery module has two working modes: steady-state output recovery and dynamic loop detection. In the steady-state output recovery mode, the relay output is driven according to the state of DRIVE_A, and after waiting for 30 ms, the state of the relay is stable, at which time the state of RELAYSTATE_A is stable, and the READBACK_A signal is read back.
[0061] In the dynamic loop detection mode, since the relay action needs time, when the DRIVE_A instruction changes, the state of RELAYSTATE_A usually needs more than 10 ms to start responding, while the recovery circuit can be completed in the microsecond level, so the state of DRIVE_A can be flipped to read back the state of the relay contact and the relay drive loop before the relay is actuated, and after the read back is completed, the original DRIVE_A state is restored. This step can detect the state of the relay contact and the health of the drive loop in real time.
[0062] As shown in Figure 3 The data flow of the system of the application is as follows:
[0063] The execution of the drive detection is mainly completed by the MCU, the safety comparison and the control of the coil power supply are completed by the CPLD, and the FPGA is mainly responsible for external communication and decoding of the drive command. In each cycle, the MCU obtains the state of the relay contact of the system through the steady-state output recovery detection of the drive recovery module, obtains the health state of the drive circuit of the system through the dynamic loop detection of the drive recovery module, and obtains the state of the relay contact of the other system through the relay circuit of the other system. The acquisition results of the system and the other system are sent to the CPLD for double-system comparison. If the comparison is wrong, the CPLD immediately cuts off the power supply of the relay, and notifies the CPU to close the relay output of the system, so that the system is directed to the safe side, realizing the combined fault safety. The double-system acquisition at the same time increases the cross-acquisition, improving the safety and reaction speed of the circuit.
[0064] As shown in Figure 4 The software inside MCU_A specifically includes: Initialization & self check: initialization and self-check module; Command get & verify: command acquisition and verification module; Output & readback: output and recovery module; BIT: dynamic self-check module; Error handle & alarm: error handling and alarm module.
[0065] Initialization & self check: In the power-on process of the MCU, all the internal and external devices and global variables used are initialized, and the initial state of the relay is checked. The initial state of all relays should be the open state. If the state is not consistent, the error handling and alarm module is entered.
[0066] Command get&verify: Loop to check if control commands have been received from the FPGA. If so, read the control commands and check their security. If the check fails, enter the error alarm module. If the check passes, generate the drive instructions.
[0067] Output & readback: Output the command that passes the safety check, and after the output circuit has completed its operation, sample the relay output state (steady-state output sampling), and encode the sampled data and write it into the designated register of the FPGA for other systems to read.
[0068] BIT: During operation, the MCU's own status and the relay status are checked (dynamic loop detection). Since the relay status feedback is mainly achieved by collecting data from the normally closed contacts of the relays, and high-frequency interference on the line may cause false alarms in the highly sensitive acquisition mechanism, if the first dynamic loop detection feedback result does not match the expectation, the KO mechanism is activated: that is, the operation is performed three more times. If the feedback judgment passes all three times, the check passes; otherwise, the KO count is incremented by 1, and the aforementioned operation continues. If the KO count exceeds 2 times, an error is detected, and the error handling and alarm module is entered.
[0069] Error handle & alarm: After the MCU detects an error, it shuts down all outputs, redirects the system to the safe side, and encodes the error status and writes it to a designated register on the FPGA for other systems to read.
[0070] The above is an introduction to the system embodiments. The following method embodiments will further illustrate the solution of the present invention.
[0071] like Figure 5 As shown, the working method of a drive feedback system for vehicle-mounted safety output according to the present invention includes the following steps:
[0072] Step 1: Receive and decode control commands sent from external systems.
[0073] Step 2: Check the safety of the instruction and generate the relay output command according to the instruction that has passed the check to drive the relay output.
[0074] Step 3: Perform steady-state output sampling on the circuit after the action, and perform dynamic loop detection on the drive sampling circuit.
[0075] Step 4: Process and judge the acquisition signal sent from the drive acquisition circuit.
[0076] Step 5: Complete loop control and write the system status to the designated register.
[0077] Taking the A series as an example, the timing relationship of the relay output signal (DRIVE_A), relay contact status signal (RELAYSTATE_A), and retrieval signal (READBACK_A) is as follows: Figure 6 As shown:
[0078] like Figure 6 As shown, the drive command DRIVE_A is issued at time T1. By time T2, the relay has completed its action (engaged or disengaged). A TE SR6 series safety relay with forced contact guidance is selected. The time difference between T1 and T2 is within 30ms. Steady-state data retrieval begins after time T2. After steady-state data retrieval is completed, the DRIVE_A signal is toggled at time T3, held for 0.3ms, and then restored to its original state, yielding a DRIVE_A pulse signal. This pulse signal can trigger the same READBACK_A pulse signal. Dynamic loop checks are performed between times T3 and T4, and all drive data retrieval is completed at time T4.
[0079] The logical relationships of the relay output signal (DRIVE_A), relay contact status signal (RELAYSTATE_A / RELAYSTATE_B), and retrieval signal (READBACK_A) in steady-state output retrieval mode are shown in Table 1, and the logical relationships in dynamic loop detection mode are shown in Table 2.
[0080] Table 1
[0081] Signal Steady state Steady state DRIVE_A 1 0 RELAYSTATE_A 0 High impedance RELAYSTATE_B 0 High impedance READBACK_A 0 0
[0082] Table 2
[0083] Signal Steady state Dynamic transient Steady state Dynamic transient DRIVE_A 1 0 0 1 RELAYSTATE_A 0 0 High impedance High impedance READBACK_A 0 1 0 1
[0084] As shown in Tables 1 and 2, in steady-state output retrieval mode, READBACK_A is always low. If it is low, the acquisition is normal; if it is high, the acquisition will report an error. When DRIVE_A is 1, RELAYSTATE_A / RELAYSTATE_B is 0, the relay is in normal condition; if it is in a high-impedance state, the acquisition will report an error. When DRIVE_A is 0, RELAYSTATE_A / RELAYSTATE_B is in a high-impedance state, the relay is in normal condition; if it is 0, the acquisition will report an error.
[0085] In dynamic loop check mode, by flipping the pulse signal of the steady-state output command DRIVE_A, a high-level pulse of READBACK_A can be acquired. If a high level is acquired, the acquisition loop is healthy; if a low level is acquired, the acquisition loop detection reports an error.
[0086] Therefore, the relay's operating status can be determined by checking the READBACK and RELAYSTATE signals during steady-state dual-output checks, and the health of the drive feedback circuit can be determined by checking the READBACK signal during dynamic loop checks.
[0087] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific structure of the described module can be referred to the corresponding content in the foregoing system embodiments, and will not be repeated here.
[0088] This invention also provides an electronic device including a central processing unit (CPU), which can perform various appropriate actions and processes according to computer program instructions stored in a read-only memory (ROM) or loaded from a storage unit into a random access memory (RAM). The RAM may also store various programs and data required for device operation. The CPU, ROM, and RAM are interconnected via a bus. Input / output (I / O) interfaces are also connected to the bus.
[0089] Multiple components in the device are connected to the I / O interface, including: input units such as keyboards and mice; output units such as various types of displays and speakers; storage units such as disks and optical discs; and communication units such as network interface cards (NICs), modems, and wireless transceivers. The communication unit allows the device to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.
[0090] The processing unit performs the various methods and processes described above, such as the methods of the present invention. For example, in some embodiments, the methods of the present invention may be implemented as computer software programs tangibly contained in a machine-readable medium, such as a storage unit. In some embodiments, part or all of the computer program may be loaded and / or installed on the device via ROM and / or a communication unit. When the computer program is loaded into RAM and executed by the CPU, one or more steps of the methods of the present invention described above may be performed. Alternatively, in other embodiments, the CPU may be configured to execute the methods of the present invention by any other suitable means (e.g., by means of firmware).
[0091] The functions described above in this document can be performed, at least in part, by one or more hardware logic components. For example, exemplary types of hardware logic components that can be used, without limitation, include: Field Programmable Gate Arrays (FPGAs), Application-Specific Integrated Circuits (ASICs), Application Standard Products (ASSPs), System-on-Chip (SoCs), Complex Programmable Logic Devices (CPLDs), and so on.
[0092] The program code used to implement the methods of the present invention can be written in any combination of one or more programming languages. This program code can be provided to a processor or controller of a general-purpose computer, special-purpose computer, or other programmable data processing device, such that when executed by the processor or controller, the program code causes the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code can be executed entirely on the machine, partially on the machine, as a standalone software package partially on the machine and partially on a remote machine, or entirely on a remote machine or server.
[0093] In the context of this invention, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. Machine-readable media can include, but are not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0094] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in the present invention, and these modifications or substitutions should all be covered within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.
Claims
1. A drive feedback system for vehicle-mounted safety output, characterized in that, include: The relay module adopts a 2-out-of-2 structure; The drive acquisition module adopts a 2-out-of-2 structure, which is used to control the relay module and has acquisition detection function; The FPGA module is responsible for communicating with external systems, decoding commands from external systems to obtain drive instructions, and sending the status information of this system to external systems. The MCU module adopts a 2-to-2 structure to receive drive instructions from the FPGA module and send the drive instructions to the drive feedback module of this system. The CPLD module is used to perform a secure comparison of the information from the two channels of the MCU module. If they are inconsistent, the power supply to the relay module coil is cut off. The drive feedback module includes two operating modes: steady-state output feedback mode and dynamic loop detection mode. In the steady-state output feedback mode, the relay output is driven according to the state of DRIVE_A. After waiting for a set time, the relay state stabilizes, and the RELAYSTATE_A state stabilizes. The READBACK_A signal is then read back. In the dynamic loop detection mode, the DRIVE_A state is toggled, and the relay contact state and relay drive circuit are read back before the relay operates. After the readback is completed, the original DRIVE_A state is restored.
2. The drive feedback system for vehicle-mounted safety output according to claim 1, characterized in that, The drive acquisition module includes: The coil drive circuit is used to isolate and amplify the drive signal sent by the MCU module, and generate the coil drive signal DRIVE_A based on the amplified signal. It controls whether the power supply negative RELAYDRIVE_A of the relay coil is grounded, thereby controlling the relay to open and close. The status retrieval circuit is used to isolate the RELAYDRIVE_A signal and connect the relay status RELAYSTATE_A signal to digital ground through the normally closed contact of the relay.
3. The drive feedback system for vehicle-mounted safety output according to claim 2, characterized in that, The relay is activated when DRIVE_A is low and deactivated when DRIVE_A is high. When the relay is energized, RELAYSTATE_A is in a high-impedance state; when the relay is de-energized, RELAYSTATE_A is in a low-level state.
4. The drive feedback system for vehicle-mounted safety output according to claim 2, characterized in that, The status retrieval circuit performs a XOR operation on the RELAYDRIVE_A and RELAYSTATE_A signals to obtain the READBACK_A signal for the MCU module to read. The status feedback circuit uses the negative state signal of the relay coil as the input to the LED circuit. The status of the relay is observed through the LED. The LED lights up when the relay is energized and turns off when the relay is de-energized.
5. The drive feedback system for vehicle-mounted safety output according to claim 1, characterized in that, In each cycle, the MCU module obtains the relay contact status of its own system through steady-state output retrieval detection of the drive retrieval module, and obtains the health status of its own system's drive circuit through dynamic loop detection of the drive retrieval module. At the same time, it obtains the relay contact status of another system through the relay circuit of another system. The acquisition results of both the own system and the other system are sent to the CPLD module for dual-system comparison. If the comparison fails, the CPLD module immediately cuts off the relay power supply and notifies the CPU module to shut down the relay output of its own system, and the system is redirected to the safe side.
6. The drive feedback system for vehicle-mounted safety output according to claim 1, characterized in that, The MCU module includes: The initialization and self-test module is used to initialize all on-chip peripherals and global variables used during the MCU module power-on process, and to check the initial state of the relays. The command acquisition and verification module is used to cyclically check whether control commands sent by the FPGA have been received. If so, the control command is read and its security is checked. If the check fails, the error alarm module is entered. If the check passes, the drive instruction is generated. The output and data acquisition module is used to output commands that have passed the safety check, and to acquire the relay output status after the output circuit has completed its operation. At the same time, the acquired data is encoded and written into a designated register of the FPGA for other systems to read. The dynamic self-test module is used to check the status of the MCU itself and the relays during operation.
7. The drive feedback system for vehicle-mounted safety output according to claim 1, characterized in that, The relay module adopts a forced-guided safety relay. The power supply of its coil is controlled by the coil power supply control circuit of the CPLD module. It receives the control signal sent by the drive acquisition module to drive the normally open contact of the relay to output, and acquires data through the normally closed contact of the relay.
8. A method for using the drive feedback system for vehicle-mounted safety output as described in claim 1, characterized in that, Includes the following steps: Step S1: Receive and decode control commands sent from an external system; Step S2: Check the safety of the instruction and generate the relay output command according to the instruction that has passed the check to drive the relay output; Step S3: Perform steady-state output retrieval on the circuit after the action and perform dynamic loop detection on the drive retrieval circuit; Step S4: Process the acquisition signal sent from the drive acquisition circuit and make a judgment. Step S5: Complete loop control and write the system status into the designated register.
9. An electronic device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the program, it implements the method as described in claim 8.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the method as described in claim 8.
Citation Information
Patent Citations
Safe output system realized based on forced guiding type relay
CN116540520A