Hardware logic for protecting power electronic components
By designing a protection system for power electronic devices, the system monitors and compares parameters with hard protection thresholds and activates corresponding protection measures, it solves the problem that it is difficult to effectively protect HLC power electronic devices in railway applications in the prior art, and achieves a fast response and high reliability protection effect.
Patent Information
- Application Number
- CN202380078606.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2022-11-11
- Filing Date
- 2023-11-10
- Publication Date
- 2025-06-20
AI Technical Summary
The prior art is difficult to effectively protect auxiliary load converter (HLC) power electronic devices in railway applications, especially when the parameters are abnormal, the protection measures cannot be activated in time, resulting in equipment failure.
A power electronic device protection system is designed, which includes processing circuits that activate software protection or hardware protection logic by monitoring parameters of power electronic devices to compare with hardware protection thresholds. Specific measures include: monitoring power electronic device parameters, comparing parameters with normal and hardware protection thresholds, and activating software protection or hardware protection based on the comparison results.
It realizes rapid response protection for power electronic devices, avoids equipment failures caused by abnormal parameters, and improves equipment reliability and durability.
Smart Images

Figure CN120188360A_ABST
Abstract
Description
[0001] Cross - Reference to Related Applications
[0002] This application claims the priority benefit of Indian Provisional Patent Application No. 202241064561, filed on November 11, 2022, titled "Hardware Logic to Protect Power Electronics Components", which is incorporated herein by reference in its entirety.
[0003] Background
[0004] The present disclosure generally relates to power electronics protection systems. More specifically, the present disclosure relates to a power electronics protection system for a hotel load converter used in railway applications.
[0005] Overview
[0006] One embodiment relates to a power electronics protection system that includes one or more processing circuits, the one or more processing circuits including one or more memory devices coupled to one or more processors, the one or more memory devices being configured to store instructions thereon, the instructions when executed by the one or more processors cause the one or more processors to: monitor power electronics parameters; compare the parameters with a hardware protection threshold; activate software protection of the power electronics when the parameters are less than the hardware protection threshold; and activate hardware protection logic of the power electronics when the parameters are greater than or equal to the hardware protection threshold.
[0007] At least one aspect of the present disclosure relates to a system for hardware protection in power electronics. The system may include a hotel load converter (HLC) that includes power electronics components and is configured to perform AC / AC conversion of power to provide to a load on a railway car. The system may include a controller configured to be coupled to the HLC. The controller may include a protection circuit. The controller may monitor parameters of the power electronics components of the HLC. The controller may determine that the parameters fail to meet a normal threshold that defines a first limit corresponding to a fault - free condition in the power electronics components for the parameters. The controller may determine that the parameters fail to meet a hardware threshold that defines a second limit corresponding to before a fault in the power electronics components for the parameters. The controller may activate hardware protection for the power electronics components of the HLC in response to determining that the parameters fail to meet the normal threshold and the hardware threshold.
[0008] In some embodiments, the controller may start a timer in response to determining that a parameter meets a hardware threshold. When the timer is below a time threshold, the controller may activate software protection for the power electronic components of the HLC. In some embodiments, the controller may start a timer in response to determining that a parameter meets a hardware threshold while activating software protection for the power electronic components. In some embodiments, the controller may activate hardware protection in response to the timer exceeding the time threshold of the software protection.
[0009] In some embodiments, the controller may activate hardware protection by disconnecting or interrupting the power electronic components of the HLC for a period of time. In some embodiments, the controller may continue to monitor the parameters of the power electronic components of the HLC in response to determining that a parameter meets a normal threshold. In some embodiments, the controller may receive power transmitted via a pantograph from an overhead line outside the rail vehicle. In some embodiments, the controller may supply power to a load on the rail vehicle. The load may include at least one of an entertainment system, kitchen appliances, a refrigeration system, or a heating system for the rail vehicle.
[0010] At least one aspect of the present disclosure relates to a controller. The controller may include a protection circuit that includes one or more processors coupled to a memory. The protection circuit may monitor the parameters of the power electronic components of an auxiliary load converter (HLC) that transfers power from outside the rail vehicle to a load inside the rail vehicle. The protection circuit may compare the parameters of the power electronic components with a normal threshold to identify the presence of a fault condition. The protection circuit may compare the parameters of the power electronic components with a hardware threshold. The protection circuit may activate at least one of software protection or hardware protection for the power electronic components of the HLC based on the comparison between the parameters and the normal threshold and the comparison between the parameters and the hardware threshold.
[0011] In some embodiments, the protection circuit may monitor a plurality of parameters, which may include at least one of the following: voltage, current, or frequency of the power transmitted through the HLC. In some embodiments, the protection circuit may compare the plurality of parameters with a corresponding plurality of thresholds to determine whether to activate one of software protection or hardware protection.
[0012] In some embodiments, the protection circuit may activate a counter in response to determining that a parameter meets a hardware threshold. In some embodiments, software protection for the power electronic components of the converter is activated when the value of the counter is less than a software protection threshold.
[0013] In some embodiments, the protection circuit may activate a counter in response to determining that a parameter meets a hardware threshold, while activating software protection for the power electronic component. In some embodiments, the protection circuit may switch from software protection to hardware protection in response to the value of the counter exceeding a software protection threshold.
[0014] In some embodiments, the protection circuit may identify the absence of an abnormal operating condition in the power electronic component of the HLC in response to determining that a parameter meets a normal threshold. In some embodiments, the protection circuit may continue to monitor the parameters of the power electronic component in response to identifying the absence of an abnormal operating condition.
[0015] In some embodiments, the protection circuit may identify the presence of an abnormal operating condition in the power electronic component of the HLC in response to determining that a parameter fails to meet a normal threshold. In some embodiments, the protection circuit may determine whether to activate one of software protection or hardware protection based on the severity of the abnormal operating condition. In some embodiments, one or more processors and memories of the protection circuit may be provided in a rail vehicle together with the HLC.
[0016] At least one aspect of the present disclosure relates to a method for protecting in a power electronic device. The method may include: monitoring, by a controller, parameters of a power electronic component of an auxiliary load converter (HLC). The method may include: determining, by the controller, that a parameter fails to meet a normal threshold corresponding to a fault-free condition in the power electronic component for the parameter. The method may include: determining, by the controller, that a parameter fails to meet a hardware threshold corresponding to before a fault in the power electronic component for the parameter. The method may include: activating, in response to determining that the parameter fails to meet the normal threshold and the hardware threshold, hardware protection for the power electronic component of the HLC.
[0017] In some embodiments, the method may include: activating, in response to determining that a parameter fails to meet a normal threshold, software protection for the power electronic component of the HLC. In some embodiments, the method may include: monitoring, by the controller, a second parameter of the power electronic component while activating software protection for the power electronic component. In some embodiments, the method may include: deactivating the software protection in response to the second parameter meeting the normal threshold within a time threshold.
[0018] In some embodiments, the method may include: monitoring, by the controller, a second parameter of the power electronic component while activating software protection for the power electronic component. In some embodiments, activating hardware protection may include: switching from software protection to hardware protection in response to the second parameter failing to meet the hardware threshold within a time threshold.
[0019] In some embodiments, the method may include: maintaining, by a controller, activation of software protection for a power electronics component for HLC while hardware protection is deactivated. In some embodiments, the method may include: determining, by the controller, that the urgency to address an abnormal operating condition in a power electronics device for HLC meets a condition for activating hardware protection. In some embodiments, the method may include: activating hardware protection further includes activating hardware protection for a power electronics component for HLC in response to determining that the urgency to address the abnormal operating condition meets the condition.
[0020] In some embodiments, the method may include: monitoring, by a controller, a second parameter of the power electronics component while hardware protection is activated. In some embodiments, the method may include: switching, by the controller, hardware protection for a power electronics component for HLC to software protection in response to determining that the second parameter meets a normal threshold and a hardware threshold.
[0021] This summary is merely illustrative and is not intended to limit in any way. In the detailed description set forth herein, in conjunction with the accompanying drawings, other aspects, inventive features, and advantages of the devices or processes described herein will become apparent, where like reference numerals refer to like elements. Brief Description of the Drawings
[0023] Figure 1 is a perspective view of a rail vehicle including a pantograph and an auxiliary load converter according to some embodiments.
[0024] Figure 2 is according to some embodiments Figure 1 of the auxiliary load converter.
[0025] Figure 3 is according to some embodiments Figure 1 of the auxiliary load converter.
[0026] Figure 4 is according to some embodiments Figure 1 of the auxiliary load converter.
[0027] Figure 5 is according to some embodiments Figure 1 of the controller of the auxiliary load converter.
[0028] Figures 6A - 6C is a flowchart of a method of operating Figure 5 the controller according to some embodiments.
[0029] Figure 7 is according to some embodiments Figure 5 of the hardware logic architecture of the controller.
[0030] Detailed Description
[0031] The following is a more detailed description of various concepts related to methods, apparatuses, and systems for hardware protection logic for power electronic devices, as well as the implementation of these methods, apparatuses, and systems. Before turning to the drawings that illustrate certain exemplary embodiments in detail, it should be understood that the present disclosure is not limited to the details or methods set forth in the specification or shown in the drawings. It should also be understood that the terms used herein are for descriptive purposes only and should not be considered limiting.
[0032] Generally referring to the drawings, various embodiments disclosed herein relate to systems, apparatuses, and methods for protecting power electronic devices of an auxiliary load converter (HLC). A software-based protection algorithm can be used when abnormal current and / or voltage is below a hardware power threshold within less than a predetermined hardware time threshold. If the current and / or voltage is above the hardware power threshold or the time during which the current and / or voltage is abnormal is longer than the hardware time threshold, the hardware protection logic is activated. In the case of transient and / or abnormal operating conditions, the hardware protection logic protects the power electronic components of the inverter and converter by re-acting within a few microseconds.
[0033] As Figure 1 shown, a railway vehicle 10 includes a body 14 that supports a pantograph 18. The pantograph 18 includes a set of articulated arms that are fixed to the body 14 (e.g., the roof) of the railway vehicle 10 and that deploy and extend along a vertical axis. The head of the pantograph 18 is fitted with carbon strips that are configured to engage a contact wire 22. The number and type of carbon strips can be adjusted based on the nature and intensity of the current to be transmitted (e.g., AC or DC). The pantograph 18 transmits power from the contact wire 22 to a traction motor and an auxiliary load converter (HLC) 26.
[0034] The HLC 26 is a two-stage 500KW high-voltage high-power AC-to-AC converter. The first stage converts AC to DC power, and the second stage converts the DC power received from the first stage to three-phase AC power. Both the first stage and the second stage include power electronic modules that are composed of high-power high-current insulated gate bipolar transistor (IGBT) modules, high-power large-capacity capacitors, current and voltage sensors, power electronic devices, and control boards. The HLC 26 is generally configured to receive power from the pantograph 18 and regulate the power for use on the railway vehicle 10 rather than driving the traction motor. For example, the HLC 26 can provide power to climate control (e.g., HVAC), kitchens, washing machines, entertainment systems, lighting, refrigeration systems, water heating systems, etc.
[0035] As Figure 2As shown, the HLC 26 includes a frame 30 that is configured to support a controller 34 that controls the operation of the HLC 26, a connector 38 that supplies power from the HLC 26 to an external system of the railway vehicle 10, and a human-machine interface (HMI) 42 that allows an operator to interact with the HLC 26.
[0036] As Figure 3 shown, the HLC 26 also includes a capacitor bank 46 and an inductor 50 supported by a base plate 54, and a cooling system for the capacitor bank 46 and the inductor 50 that includes a radiator 58, ducts 62, and a blower 66. The HLC 26 also includes a fan 70 for ventilating the HLC 26 and a hook 74 for facilitating the movement of the HLC 26. In some embodiments, a different number of capacitors or inductors may be included. Similarly, the number and arrangement of the radiator 58, ducts 62, and blower 66 may be adjusted as needed.
[0037] As Figure 4 shown, the pantograph 18 supplies power to the main transformer 78 of the railway vehicle 10, and AC power is supplied to the HLC 26. A rectifier 82 receives the AC power from the main transformer 78 and supplies DC power to an inverter 86. The inverter 86 converts the DC from the rectifier 82 into three-phase AC power that is supplied to a protection contactor 90. The protection contactor 90 is arranged to communicate with a load 98 via the connector 38. The controller 34 communicates with the rectifier 82, the inverter 86, and the protection contactor 90 and controls the rectifier 82, the inverter 86, and the protection contactor 90. The HLC 26 additionally includes instruments (e.g., sensors, shunts, actuators, switches, etc.) that communicate with the controller 34. The HMI 42 provides a display and a user interface for interacting with the controller 34. In some embodiments, as needed, the HMI 42 includes a network connection such as a modem, a network switch, a wireless network, a cloud-based service accessible by an application, or another interface.
[0038] In some embodiments, the input voltage received by the rectifier 82 defines a minimum voltage of 633 VAC, a nominal voltage of 960 VAC, and a maximum voltage of 1190 VAC. In some embodiments, the DC bus voltage output by the rectifier 82 is ideally 1800 VDC. In some embodiments, the line voltage of each phase of the three-phase AC output from the inverter 86 is 750 Vrms. In some embodiments, the frequency output of the inverter 86 is 50 Hz. In some embodiments, the voltage output of the inverter 86 is 500 KVA.
[0039] It is necessary to protect the power system components of the HLC 26 from various faults to ensure the reliability and durability of the equipment and to ensure the uninterrupted operation of the HLC 26. Exemplary faults include input AC current faults, input AC voltage faults, output DC voltage faults, output DC current faults, output AC current (for each three-phase) faults, output AC voltage (for each three-phase) faults, input ground faults, output ground faults, 110V battery faults, rectifier gate faults, and inverter gate faults. In some embodiments, some of the listed faults are eliminated from the protection scheme. In some embodiments, other faults can be detected and protected against.
[0040] Since Figure 1 the components of are shown as implemented in the railway vehicle 10, the controller 34 can be separated from or included in at least one railway vehicle controller located outside the HLC 26. The functions and structure of the controller 34 are described in more detail in Figure 5 .
[0041] Now referring to Figure 5 , a schematic diagram of a system 35 for protecting power electronic devices is shown. The system 35 can include the controller 34 of the railway vehicle 10 and Figure 1 the HLC 26 of. As shown, the controller 34 includes a processing circuit 102 having a processor 106 and a memory device 110, a control system 114 having a protection circuit 118, and a communication interface 122. The protection circuit 118 can include at least one processor 119, at least one memory device 120, and at least one timer 121 (or counter), etc. The controller 34 can be configured to be coupled to the HLC 26. The HLC 26 can include a set of power electronic components 26 (e.g., a rectifier 82, an inverter 86, or a contactor 90), an instrument 94, and an HMI 42, etc. The communication interface 122 can communicate with or exchange data with one or more components of the HLC 26, such as the rectifier 82, the inverter 86, the contactor 90, the instrument 94, and the HMI 42, etc. Generally, the controller 34 is configured to implement software fault protection and implement hardware protection logic to provide protection to the electronic power system of the HLC 26.
[0042] In one configuration, the protection circuit 118 is implemented as a machine or computer-readable medium executable by a processor, such as processor 119. As described herein and in other uses, the machine-readable medium facilitates performing certain operations to enable receipt and transmission of data. For example, the machine-readable medium can provide instructions (e.g., commands, etc.) to, for example, collect data. In this regard, the machine-readable medium can include programmable logic that defines the data collection (or data transmission) frequency. The computer-readable medium instructions can include code, which can be written in any programming language, including but not limited to Java, etc., and any conventional procedural programming language, such as the "C" programming language or similar programming languages. The computer-readable program code can be executed on one processor or multiple remote processors. In the latter case, the remote processors can be interconnected via any type of network (e.g., CAN bus, etc.).
[0043] In another configuration, the protection circuit 118 is implemented as a hardware unit, such as an electronic control unit. Thus, the protection circuit 118 can be implemented as one or more circuit components, including but not limited to processing circuits, network interfaces, peripherals, input devices, output devices, sensors, etc. In some embodiments, the protection circuit 118 can take the form of one or more analog circuits, electronic circuits (e.g., integrated circuits (ICs), discrete circuits, system-on-chip (SOC) circuits, microcontrollers, etc.), telecommunication circuits, hybrid circuits, and any other type of "circuit". In this regard, the protection circuit 118 can include any type of component for accomplishing or facilitating the operations described herein. For example, the circuits described herein can include one or more transistors, logic gates (e.g., NAND, AND, NOR, OR, XOR, NOT, XNOR, etc.), resistors, multiplexers, registers, capacitors, inductors, diodes, wiring, etc. The timer 121 of the protection circuit 118 can be implemented using any one or more of the circuit components detailed herein. The protection circuit 118 can also include programmable hardware devices, such as field-programmable gate arrays, programmable array logic, programmable logic devices, etc.
[0044] The protection circuit 118 can include one or more memory devices for storing instructions executable by a processor of the protection circuit 118. The one or more memory devices and the processor can have the same definitions as provided below for the memory device 120 and the processor 119. In some hardware unit configurations, the protection circuit 118 can be geographically dispersed in separate locations in a vehicle (e.g., a railway vehicle). Alternatively and as shown, the protection circuit 118 can be implemented in or within a single unit / case (which is shown as controller 34).
[0045] In the illustrated example, controller 34 includes processing circuitry 102 having a processor 106 and a memory device 110. The processing circuitry 102 may be constructed or configured to execute or implement the instructions, commands, and / or control processes described herein with respect to protection circuitry 118. The depicted configuration represents the protection circuitry 118 as a machine or computer-readable medium. However, as noted above, this illustration is not meant to be limiting, as the present disclosure contemplates other embodiments in which the protection circuitry 118 or at least one circuit of the protection circuitry 118 is configured as a hardware unit. All such combinations and variations are intended to fall within the scope of the present disclosure.
[0046] The hardware and data processing components (e.g., processor 106 or 119) for implementing the various processes, operations, illustrative logic, logic blocks, modules, and circuits described in connection with the embodiments disclosed herein may be implemented or performed with one of the following: a general-purpose single-chip or multi-chip processor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other programmable logic device, discrete gate or transistor logic, discrete hardware components, or any combination thereof designed to perform the functions described herein. A general-purpose processor may be a microprocessor, or any conventional processor or state machine. The processor may also be implemented as a combination of computing devices, such as a combination of a DSP and a microprocessor, multiple microprocessors, one or more microprocessors in conjunction with a DSP core, or any other such configuration. In some embodiments, one or more processors may be shared by multiple circuits (e.g., the protection circuitry 118 may include or otherwise share the same processor, which in some example embodiments may execute instructions stored or otherwise accessed via different regions of memory). Alternatively or additionally, the one or more processors may be configured to perform or otherwise execute certain operations independently of one or more coprocessors. In other example embodiments, two or more processors may be coupled via a bus to enable independent, parallel, pipelined, or multi-threaded instruction execution. All such variations are intended to fall within the scope of the present disclosure.
[0047] The memory device 110 (e.g., memory, memory cell, storage device) may include one or more devices (e.g., RAM, ROM, flash memory, hard disk storage) for storing data and / or computer code for accomplishing or facilitating the various processes, layers, and modules described in this disclosure. The memory device 110 may be communicatively coupled to the processor 106 to provide computer code or instructions to the processor 106 for performing at least some of the processes described herein. Additionally, the memory device 110 may be or include tangible, non-transitory volatile or non-volatile memory. Thus, the memory device 110 may include database components, object code components, script components, or any other type of information structure for supporting the various activities and information structures described herein. The protection circuit 118 (or the control system 114 or the controller 34 of which the bounce circuit 118 is a part) is configured to implement the logic described below.
[0048] The protection circuit 118 is configured to monitor parameters (e.g., frequency, current, and / or voltage) of the rectifier 82, the inverter 86, the contactor 90, and / or other components of the HLC 26 using the instrument 94. The protection circuit 118 compares the monitored parameters with a threshold or range and determines whether an operating anomaly exists. For example, if the voltage, current, or frequency operates outside the range, the protection circuit 118 will determine an anomaly. If an anomaly is determined to exist, the protection circuit 118 will determine whether the severity of the anomaly is below a hardware threshold. If the anomaly is determined to be less than the hardware threshold (e.g., the voltage is below the hardware voltage threshold), software protection is implemented by the protection circuit 118, and a timer (e.g., a counter, a real-time clock, etc.) is started.
[0049] The software protection is implemented by the protection circuit 118 for a predetermined time. If the anomaly is corrected within the predetermined time, the software protection is successful, and the normal operation of the HLC 26 can continue. However, if the anomaly is not corrected within the predetermined time, or if the severity of the anomaly becomes greater than the hardware threshold (e.g., the voltage exceeds the hardware voltage threshold before the predetermined time has elapsed), the protection circuit 118 activates the hardware protection logic, and the HLC 26 is quickly protected to prevent faults and / or anomalies.
[0050] The software protection implemented by protection circuit 118 defines a response time and a fault latched response time between approximately 40 μS and approximately 20 mS. The hardware protection logic defines a response time and a fault latched response time of less than approximately 1 μS. The hardware protection logic is structural and does not rely on software processing to achieve latching. In other words, the hardware protection logic does not have a built-in delay for fault scanning and / or processing, and thus provides an extremely fast response time. The software protection and the hardware protection logic of protection circuit 118 provide redundant protection for the HLC 26 power electronic device.
[0051] Controller 34 can monitor parameters, which include the frequency, current, and voltage of the power electronic components of HLC 26 (e.g., any one or more of rectifier 82, inverter 86, or contactor 90). These parameters are then compared with normal operation thresholds or normal operation threshold ranges. If the parameters are less than the normal operation threshold or within the normal operation threshold range, the normal operation of HLC 26 continues and protection circuit 118 continues to monitor the parameters. The normal operation threshold and / or the normal operation threshold range define the limits of voltage and / or current when the power electronic device operates under normal operating conditions (e.g., in the absence of fault conditions).
[0052] If it is determined that the parameters are greater than the normal threshold or outside the normal threshold range, the parameters are compared with hardware thresholds or hardware threshold ranges. The hardware thresholds and / or the hardware threshold ranges define the limits of voltage and / or current beyond which the power electronic device can only withstand a short operating duration (e.g., a few hundred μS to a few hundred mS) before a catastrophic failure.
[0053] If the parameters are less than the hardware threshold, a timer is activated (e.g., starting a counter, creating a timestamp based on a real-time clock, etc.). If the timer value is less than the software protection time threshold, protection circuit 118 activates the software protection of HLC 26. During software protection, protection circuit 118 continues to compare the parameters with the hardware threshold. If the parameters become greater than the hardware threshold or the timer exceeds the software protection time, protection circuit 118 immediately activates the hardware protection logic to quickly protect HLC 26. Once the current and / or voltage crosses the hardware threshold, the hardware protection logic shuts off the power electronic device within a few microseconds (μS) to inhibit a catastrophic failure of the power electronic device. In some embodiments, the hardware control logic also provides an interrupt for microcontroller fault identification.
[0054] The protection circuit 118 is an example of a power electronics device protection system that includes one or more processing circuits, the one or more processing circuits including one or more memory devices coupled to one or more processors, the one or more memory devices configured to store instructions thereon that, when executed by the one or more processors, cause the one or more processors to: monitor power electronics device parameters, compare the parameters to hardware protection thresholds, activate software protection of the power electronics device when the parameters are less than the hardware protection thresholds, and activate hardware protection logic of the power electronics device when the parameters are greater than or equal to the hardware protection thresholds.
[0055] The one or more memory devices are further configured to store instructions thereon that, when executed by the one or more processors, cause the one or more processors to: compare the parameters to normal operation thresholds and activate software protection of the power electronics device when the parameters are greater than the normal operation thresholds and less than the hardware protection thresholds. The one or more memory devices are further configured to store instructions thereon that, when executed by the one or more processors, cause the one or more processors to: start a timer when software protection is activated, compare the timer to a software protection time threshold, and activate hardware protection logic of the power electronics device when the timer is greater than the software protection time threshold.
[0056] In some embodiments, the system 35 may include the HLC 26. The HLC 26 may include power electronics components (e.g., the rectifier 82) to perform AC / AC conversion of power to provide to a load on a rail vehicle. The system 35 may include a controller configured to be coupled to the HLC. The controller 34 may include the protection circuit 118. The controller 34 may monitor parameters of the power electronics components of the HLC 26. The controller 34 may determine that the parameters fail to meet a normal threshold that defines a first limit corresponding to a fault-free condition in the power electronics components for the parameters. The controller 34 may determine that the parameters fail to meet a hardware threshold that defines a second limit corresponding to before a fault in the power electronics components for the parameters. In response to determining that the parameters fail to meet the normal threshold and the hardware threshold, the controller 34 may activate hardware protection for the power electronics components of the HLC 26.
[0057] In some embodiments, the controller 34 may start the timer 121 in response to determining that a parameter meets a hardware threshold. When the timer 121 is below the time threshold, the controller 34 may activate software protection for the power electronic components of the HLC 26. In some embodiments, in response to determining that a parameter meets a hardware threshold, the controller 34 may start the timer 121 while activating software protection for the power electronic components. In some embodiments, the controller 34 may activate hardware protection in response to the timer 121 exceeding the time threshold for software protection.
[0058] In some embodiments, the controller 34 may activate hardware protection by disconnecting or interrupting the power electronic components of the HLC 26 for a period of time. In some embodiments, the controller 34 may continue to monitor the parameters of the power electronic components of the HLC 26 in response to determining that a parameter meets a normal threshold. In some embodiments, the controller 34 may receive power transmitted via a pantograph from an overhead line external to the rail vehicle. In some embodiments, the controller 34 may supply power to a load on the rail vehicle. The load may include at least one of an entertainment system, kitchen appliances, a refrigeration system, or a heating system for the rail vehicle.
[0059] At least one aspect of the present disclosure relates to a controller. The controller 34 may include a protection circuit 118 that includes one or more processors 119 coupled to a memory 120. The protection circuit 118 may monitor the parameters of the power electronic components of the HLC 26 that transfers power from outside the rail vehicle to a load inside the rail vehicle. The protection circuit 118 may compare the parameters of the power electronic components with a normal threshold to identify the presence of a fault condition. The protection circuit 118 may compare the parameters of the power electronic components with a hardware threshold. The protection circuit 118 may activate at least one of software protection or hardware protection for the power electronic components of the HLC 26 based on the comparison between the parameters and the normal threshold and the comparison between the parameters and the hardware threshold.
[0060] In some embodiments, the protection circuit 118 may monitor a plurality of parameters including at least one of the following: voltage, current, or frequency of the power transmitted through the HLC 26. In some embodiments, the protection circuit 118 may compare the plurality of parameters with corresponding multiple thresholds to determine whether to activate one of software protection or hardware protection.
[0061] In some embodiments, in response to determining that a parameter meets a hardware threshold, the protection circuit 118 may activate the counter 121. In some embodiments, when the value of the counter 121 is less than the software protection threshold, software protection for the power electronic components of the converter is activated.
[0062] In some embodiments, in response to determining that a parameter meets a hardware threshold, protection circuit 118 may activate counter 121 while activating software protection for the power electronic component. In some embodiments, in response to the value of counter 121 exceeding a software protection threshold, protection circuit 118 may switch from software protection to hardware protection.
[0063] In some embodiments, in response to determining that a parameter meets a normal threshold, protection circuit 118 may identify that there are no abnormal operating conditions in the power electronic components of HLC 26. In some embodiments, in response to identifying that there are no abnormal operating conditions, protection circuit 118 may continue to monitor the parameters of the power electronic components.
[0064] In some embodiments, in response to determining that a parameter fails to meet a normal threshold, protection circuit 118 may identify the presence of abnormal operating conditions in the power electronic components of HLC 26. In some embodiments, protection circuit 118 may determine whether to activate one of software protection or hardware protection based on the severity of the abnormal operating conditions. In some embodiments, one or more processors 119 and memory 120 of protection circuit 118 may be provided in a railway vehicle together with HLC 26.
[0065] Now referring Figures 6A - 6C , a flowchart of a method 600 for protecting a power electronic device is depicted. Method 600 may be implemented or executed using any of the components described herein, such as controller 34 of system 35, protection circuit 118, and HLC 26. Method 600 may omit or skip one or more of the steps described herein. According to method 600, at step 602, a controller (e.g., controller 34) may identify, measure, or otherwise monitor parameters of at least one power electronic component (e.g., rectifier 82, inverter 86, or contactor 88) of an auxiliary load converter (e.g., HLC 26). The HLC may receive power transmitted via a pantograph from an overhead line external to the railway vehicle. In some embodiments, the controller may monitor a set of parameters of the power electronic components in the HLC. The parameters may define or identify the characteristics of the power transmitted from a source external to the railway vehicle to a load within the railway vehicle via the HLC. The parameters may include at least one of the following: voltage, current, or frequency of the power transmitted through the HLC. In some embodiments, the controller may measure the parameters at the input of the power electronic components of the HLC.
[0066] At step 604, the controller can identify or determine whether the parameter meets a normal threshold (sometimes referred to herein as a software threshold). The normal threshold can depict, define, or otherwise identify the value that triggers or activates software protection for the power electronics components of the HLC. In some embodiments, the normal threshold can identify the first limit corresponding to a fault-free condition in the power electronics components for the parameter. In some embodiments, the normal threshold can be used to identify the presence of an abnormal operating condition (sometimes also referred to herein as a fault condition or an abnormal condition) in the power electronics device.
[0067] In some embodiments, the controller can determine a set of parameters with a corresponding set of normal thresholds. For each parameter, the controller can compare the parameter with the corresponding threshold. The value of the normal threshold can depend on the type of parameter (e.g., voltage, current, or frequency) being compared with the threshold. Upon determination, the controller can compare the parameter with the normal threshold. When the parameter is less than the normal threshold, the controller can determine that the parameter meets the normal threshold. Conversely, when the parameter is greater than or equal to the threshold, the controller can determine that the parameter fails to meet the normal threshold.
[0068] At step 606, if it is determined that the parameter meets the normal threshold, the controller can determine, detect, or otherwise identify the absence of an abnormal operating condition (or fault condition). The absence of an abnormal operating condition can correspond to a situation where the power electronics components of the HLC are in a healthy or normal state of supplying power from outside the railway vehicle to the loads inside the railway vehicle. The loads inside the railway vehicle can include, for example, at least one of the following: an entertainment system for the railway vehicle, a personal electronic device, a kitchen appliance, a refrigeration system, or a heating system. In some embodiments, the load can include propulsion components inside the railway vehicle. The loads inside the railway vehicle can be electrically coupled to the HLC. Upon identifying the absence of an abnormal operating condition, the controller can continue method 600 from step 602 and can continue to monitor the parameters of the power electronics components of the HLC. In some embodiments, if software activation is activated, the controller can disable, turn off, or otherwise deactivate the software protection.
[0069] At step 608, if it is determined that the parameter fails to meet the normal threshold, the controller can determine, detect, or otherwise identify the presence of an abnormal operating condition. The presence of an abnormal operating condition can correspond to a situation where the power electronics components of the HLC are in an unhealthy or faulty state (e.g., an undesired shutdown or trip). The abnormal operating condition can also correspond to the state of the power electronics components at a fault point (e.g., due to a more severe event). The controller can use software protection or hardware protection as detailed herein to provide countermeasures to address the abnormal operating condition.
[0070] At step 610, the controller may identify or determine the urgency to resolve an abnormal operating condition. The urgency may identify, indicate, or otherwise define the degree of importance (e.g., a numerical value or a score) with which the abnormal operating condition in the power electronic components in the HLC should be resolved. For example, the urgency may be determined based on the values of voltage, current, or frequency, or any combination thereof. In some embodiments, the controller may calculate, identify, or otherwise determine the severity of the abnormal operating condition based on parameters. The severity may identify, indicate, or otherwise define the severity level (e.g., a numerical value or a score) of the abnormal operating condition in the power electronic components in the HLC. For example, the severity may be determined based on the values of voltage, current, or frequency, or the type of the abnormal operating condition, or any combination thereof. In some embodiments, method 600 may omit step 610.
[0071] At step 612, the controller may identify or determine whether the urgency to resolve an abnormal operating condition meets a threshold. The controller may compare the urgency to resolve the condition with the threshold to determine whether to trigger or activate at least one of software protection or hardware protection of the power electronic components of the HLC. The threshold may depict, identify, or otherwise define the value for the urgency for activating at least one of software protection or hardware protection. When the urgency is greater than or equal to the threshold, the controller may determine that the urgency meets the threshold. The controller may determine to trigger or activate hardware protection. Conversely, when the urgency is less than the threshold, the controller may determine that the urgency fails to meet the threshold. The controller may also determine to trigger or activate software protection. In some embodiments, method 600 may omit step 612.
[0072] In some embodiments, the controller may identify or determine whether the severity of the abnormal operating condition meets a threshold. The controller may compare the severity of the condition with the threshold to determine whether to trigger or activate at least one of software protection or hardware protection of the power electronic components of the HLC. The threshold may depict, identify, or otherwise define the value for the severity for activating at least one of software protection or hardware protection. When the severity is greater than or equal to the threshold, the controller may determine that the severity fails to meet the threshold. The controller may determine to trigger or activate hardware protection. Conversely, when the severity is less than the threshold, the controller may determine that the severity meets the threshold. The controller may also determine to trigger or activate software protection.
[0073] At step 614, if it is determined that the urgency does not meet (e.g., is less than) the threshold, the controller may identify or determine whether software protection is activated. In some embodiments, if it is determined that the severity meets (e.g., is less than) the threshold, the controller may determine whether software protection is activated. The controller may identify the activation status of the software protection on the power electronic components on the HLC. When the status indicates that the software protection is activated, the controller may determine that the software protection is activated. On the other hand, when the status indicates that the software protection is not activated, the controller may determine that the software protection is not activated. In some embodiments, method 600 may omit step 614.
[0074] At step 616, if it is determined that the software protection is not activated, the controller may enable, apply, or otherwise activate the software protection on the power electronic components of the HLC. In some embodiments, when it is determined that the parameters of the power electronic components fail to meet the normal threshold, the controller may activate the software protection. The software protection may be provided on the power electronic components via computer-readable instructions stored on the protection circuit of the controller. The software protection may include, for example: overvoltage protection, overcurrent protection, and isolation such as shutdown, fault, or trip on the rectifier or inverter of the HLC and other power electronic components. The software protection may have a lower response time compared to hardware protection. In some embodiments, the controller may maintain or sustain the application of the software protection while the hardware protection is deactivated.
[0075] In some embodiments, method 600 may include activating, by the controller, the software protection for the power electronic components of the HLC in response to determining that the parameters fail to meet the normal threshold. In some embodiments, method 600 may include the controller monitoring a second parameter of the power electronic components while activating the software protection for the power electronic components. In some embodiments, method 600 may include deactivating, by the controller, the software protection in response to the second parameter meeting the normal threshold within a time threshold.
[0076] At step 618, the controller may turn on, activate, or otherwise start a timer or counter (e.g., timer 121). The timer (or counter) may be activated when it is determined that the parameters of the power electronic component meet normal thresholds or when software protection is activated. The timer (or counter) may maintain or track the amount of time that software protection has been applied to the power electronic component of the HLC. In some embodiments, the timer may be started and maintained by the controller while activating software protection for the power electronic component. When the timer is below the time threshold, the controller may maintain or continue the activation of software protection. With the start of the timer, the controller continues method 600 from step 602 and may continue to monitor the parameters of the power electronic component of the HLC while activating and applying software protection. In some embodiments, if the parameters of the power electronic component subsequently meet normal thresholds, the controller may disable, turn off, or otherwise deactivate the software protection.
[0077] At step 620, if it is determined that software protection is activated, the controller may identify or determine whether the timer has exceeded a threshold time. Based on the timer (or counter), the controller may measure, determine, or otherwise identify the amount of time that software protection has been applied to the power electronic component of the HLC. By identifying, the controller may compare the timer with the threshold time. The threshold time may depict, identify, or otherwise define the value of the amount of time that is expected for software protection to resolve an abnormal operating condition. In some embodiments, the threshold time may define the value of the amount of time that triggers hardware protection or switches from software protection to hardware protection. When the time of the timer is greater than the threshold time, the controller may determine that the timer has exceeded the threshold time. The controller may also determine to activate hardware protection or switch from software protection to hardware protection and may continue method 600 from step 626. In other cases, when the time of the timer is less than or equal to the threshold time, the controller may determine that the timer has not exceeded the threshold time.
[0078] At step 622, if it is determined that the timer has not exceeded the threshold time, the controller may continue to apply software protection. The controller may continue to maintain the amount of time that software protection is effective for the power electronic component of the HLC using the timer (or counter). Additionally, the controller continues method 600 from step 602 and may continue to monitor the parameters of the power electronic component of the HLC. In some embodiments, if the parameters of the power electronic component subsequently meet normal thresholds within the threshold time, the controller may disable, turn off, or otherwise deactivate the software protection.
[0079] At step 624, the controller may identify or determine whether the parameter meets a hardware threshold. In some embodiments, when it is determined that the parameter fails to meet the normal threshold, the controller may determine whether the parameter of the power electronic component meets the hardware threshold. In some embodiments, when the urgency meets the threshold, the controller may omit or skip determining whether the parameter meets the hardware threshold. In some embodiments, when the severity of the abnormal operating condition fails to meet the threshold, the controller may determine whether the parameter meets the hardware threshold.
[0080] Upon determination, the controller may compare the parameter of the power electronic component with the hardware threshold. The hardware threshold may depict, define, or otherwise identify the value that triggers or activates the hardware protection of the power electronic component of the HLC or switches from software protection to activate hardware protection. In some embodiments, the hardware threshold may identify a second limit corresponding to the parameter of the power electronic component before a failure (e.g., within a time limit ranging from picoseconds to a fraction of a second). In some embodiments, the hardware threshold may be used to identify the presence of an abnormal operating condition (sometimes also referred to herein as a fault condition or an abnormal condition) in the power electronic device.
[0081] In some embodiments, the controller may determine a set of parameters with a corresponding set of hardware thresholds. For each parameter, the controller may compare the parameter with the corresponding threshold. The value of the hardware threshold may depend on the type of parameter (e.g., voltage, current, or frequency) being compared with the threshold. In some embodiments, the controller may compare the parameter with the hardware threshold. When the parameter is less than the hardware threshold, the controller may determine that the parameter meets the hardware threshold. Additionally, the controller may continue method 600 from step 602 and may continue to monitor the parameter of the power electronic component of the HLC while activating and applying software protection. Conversely, when the parameter is greater than or equal to the hardware threshold, the controller may determine that the parameter fails to meet the hardware threshold.
[0082] At step 626, if the parameter fails to meet the hardware threshold, the controller may enable, apply, or otherwise activate the hardware protection on the power electronic component of the HLC. The hardware protection may be provided via components (e.g., logic circuits or other protection circuits) in the power electronic component of the HLC. The components for applying the hardware protection may include, for example: fuses, circuit breakers, surge suppressors, current limiters, voltage limiters, transformers, or reverse polarity protection circuits, etc. When applying the hardware protection, the controller may (e.g., using the components) disconnect or interrupt the power flow through the power electronic component of the HLC for a period of time.
[0083] In some embodiments, when it is determined that the parameters of a power electronic component fail to meet the normal threshold and the hardware threshold, the controller may activate hardware protection. In some embodiments, when the urgency of the solution condition meets the condition, the controller may activate hardware protection. In some embodiments, when the timer exceeds the threshold time of software protection, the controller may activate hardware protection. In some embodiments, the controller may switch from software protection to hardware protection by deactivating software protection and activating hardware protection.
[0084] In some embodiments, method 600 may include the controller monitoring parameters of a power electronic component of an auxiliary load converter (HLC). Method 600 may include the controller determining that the parameters fail to meet a normal threshold corresponding to a fault-free condition in the power electronic component for the parameters. Method 600 may include the controller determining that the parameters fail to meet a hardware threshold corresponding to before a fault in the power electronic component for the parameters. Method 600 may include the controller activating hardware protection for the power electronic component of the HLC in response to determining that the parameters fail to meet the normal threshold and the hardware threshold.
[0085] In some embodiments, method 600 may include the controller monitoring a second parameter of the power electronic component while activating software protection for the power electronic component. In some embodiments, activating hardware protection may include switching from software protection to hardware protection in response to the second parameter failing to meet the hardware threshold within a time threshold.
[0086] In some embodiments, method 600 may include the controller maintaining the activation of software protection for the power electronic component of the HLC while hardware protection is deactivated. In some embodiments, method 600 may include the controller determining that the urgency of resolving an abnormal operating condition in the power electronic device of the HLC meets the condition for activating hardware protection. In some embodiments, method 600 may include: activating hardware protection may further include activating hardware protection for the power electronic component of the HLC in response to determining that the urgency of resolving the abnormal operating condition meets the condition.
[0087] At step 628, the controller may identify, measure, or otherwise monitor parameters of at least one power electronic component of the HLC when applying hardware protection. Step 628 may be similar in function to step 602. In some embodiments, the controller may monitor a set of parameters of the power electronic components in the HLC while applying hardware protection. The parameters may define or identify characteristics of the power transmitted from a source external to the rail vehicle to a load within the rail vehicle via the HLC. The parameters may include at least one of the following: voltage, current, or frequency of the power transmitted through the HLC. In some embodiments, when applying hardware protection, the controller may measure the parameters at the input of the power electronic component of the HLC.
[0088] At step 630, the controller may identify or determine whether the parameter has returned within the normal threshold (or within the hardware threshold). In some embodiments, when applying hardware protection, the controller may identify or determine whether the parameter meets the normal threshold. In some embodiments, the controller may determine a set of parameters having a corresponding set of normal thresholds. For each parameter, the controller may compare the parameter with the corresponding threshold. The value of the normal threshold may depend on the type of parameter (e.g., voltage, current, or frequency) being compared with the threshold.
[0089] Upon determination, the controller may compare the parameter with the normal threshold (or hardware threshold). When the parameter is less than the normal threshold, the controller may determine that the parameter has returned within the normal threshold and meets the normal threshold. At step 632, if the parameter has not returned within the normal threshold, the controller may continue to apply hardware protection. The controller may maintain the activation of the hardware protection on the power electronic components of the HLC. The controller may continue method 600 from step 628 and may continue to monitor the parameters of the power electronic components of the HLC.
[0090] Conversely, when the parameter is greater than or equal to the threshold, the controller may determine that the parameter fails to meet the normal threshold and has not returned within the normal threshold. At step 634, if the parameter has returned within the normal threshold, the controller may disable, stop applying, or otherwise deactivate the hardware protection. The controller may continue method 600 from step 606 and, if the parameter has returned within the normal threshold, the controller may identify the resolution or absence of the abnormal operating condition of the power electronic components of the HLC.
[0091] In some embodiments, method 600 may include the controller monitoring a second parameter of the power electronic components while the hardware protection is activated. In some embodiments, method 600 may include the controller switching the hardware protection for the power electronic components of the HLC to software protection in response to determining that the second parameter meets the normal threshold and the hardware threshold.
[0092] In some embodiments, if the parameter has returned within the hardware threshold (but outside the normal threshold), the controller may switch from hardware protection to software protection. The controller may perform the switch by deactivating the hardware protection and by activating the software protection, and may continue method 600 from step 602 and may continue to monitor the parameters of the power electronic components in the HLC.
[0093] As Figure 7As shown, the hardware protection logic 154 includes a comparator stack 158 that receives inputs from the IGBT drivers. In some embodiments, the comparator stack 158 receives six IGBT fault status codes from the inverter 86 and four IGBT fault status codes from the rectifier 82. In some embodiments, a different number of IGBT fault status codes are received.
[0094] The NOT gate 162 is configured to receive inputs of input AC current fault, input AC voltage fault, output DC current fault, output AC current (for each three-phase) fault, output AC voltage (for each three-phase) fault, input ground fault, and output ground fault. In some embodiments, other parameters and / or faults are considered as needed.
[0095] The outputs from the comparator stack 158 and the NOT gate 162 include binary outputs (e.g., high or low). In some embodiments, if a fault exists in the comparator stack 158 inputs, a low output will be provided (e.g., indicating that a fault has occurred). In some embodiments, if a fault exists in the NOT gate 162 inputs, a low output will be provided (e.g., indicating that a fault has occurred). In some embodiments, as needed, a fault can be identified by a high output or another control output.
[0096] The outputs from the comparator stack 158 and the NOT gate 162 are provided to the NAND gate stage 166, where all the outputs from the comparator stack 158 and the NOT gate 162 are processed. If a fault exists, the NAND gate stage 166 receives a low output from the comparator stack 158 and / or the NOT gate 162, and then the NAND gate stage 166 outputs a high output.
[0097] Then, the NAND gate stage 166 provides an output to the OR gate stage 170. The OR gate stage 170 combines the outputs of the NAND gate stage 166. If a fault is indicated by any one of the operators in the NAND gate stage 166, the OR gate stage 170 passes a high output.
[0098] The D flip-flop stage 174 inverts the output from the OR gate stage 170. Thus, if a fault exists, the D flip-flop stage 174 will receive a high input and provide a low output.
[0099] The dual-input NAND gate 178 receives the output from the D flip-flop stage 174 and also receives the inverter control input from the controller 34. If the dual-input NAND gate 178 receives a low signal from the D flip-flop stage 174 indicating a detected fault and the inverter control input does not inhibit shutdown or latching, the dual-input NAND gate 178 outputs a high output to both the control gate 182 and the IGBT enable pin of the controller 34. The control gate 182 communicates with the rectifier 82 and the inverter 86 to disable the digital buffer state and establish protection for the power electronics. The above signal flow is represented in Table 1 below.
[0100]
[0101] Table 1
[0102] The output of the control gate 182 can be defined as shown in Table 2 below.
[0103]
[0104]
[0105] Table 2
[0106] Some advantages of the protection circuit 118 include: independent functions of both software protection and hardware protection logic; a very fast response time of the hardware protection logic of less than 1 microsecond (1 uS) (e.g., calculated value = 0.6308 uS); providing all AC and DC current and voltage protection in a single hardware protection logic circuit; latching logic included in the hardware protection logic to prevent subsequent damage to the HLC 26; the protection circuit 118 includes hysteresis logic for automatically restarting the HLC 26 once the voltage or other parameters return to the normal range; providing a dedicated fault interrupt to the microcontroller to understand and identify faults; and configurable fault levels of logic low or logic high in a single hardware protection logic circuit.
[0107] As used herein, the terms "approximate", "about", "substantially" and similar terms are intended to have a broad meaning consistent with the common and accepted usage of those of ordinary skill in the art to which the subject matter of this disclosure pertains. Those skilled in the art reviewing this disclosure should understand that these terms are intended to allow the description of certain features being described and claimed without restricting the scope of these features to the precise numerical ranges provided. Accordingly, these terms should be interpreted as indicating that non-substantive or immaterial modifications or variations to the subject matter being described and claimed are considered to be within the scope of the disclosure as set forth in the appended claims.
[0108] It should be noted that, as used herein, the term "exemplary" and its variants, used to describe various embodiments, are intended to indicate that these embodiments are possible examples, representations, or illustrations of possible embodiments (and these terms are not intended to imply that these embodiments are necessarily particular or optimal examples).
[0109] As used herein, the term "coupled" and its variants refer to two components being directly or indirectly connected to each other. Such a connection can be stationary (e.g., permanent or fixed) or movable (e.g., removable or releasable). Such a connection can be achieved by directly coupling the two components to each other, by using one or more separate intervening components to couple the two components to each other, or by using an intervening component that is integrally formed with one of the two components into a single integral body to couple the two components to each other. If "coupled" or its variants are modified by additional terms (e.g., directly coupled), then the general definition of "coupled" provided above is modified by the plain language meaning of the additional term (e.g., "directly coupled" means a connection between two components without any separate intermediate component), resulting in a narrower definition than the general definition of "coupled" provided above. Such coupling can be mechanical, electrical, or fluidic. For example, circuit A being communicatively "coupled" to circuit B can mean that circuit A communicates directly with circuit B (i.e., without an intermediary) or indirectly with circuit B (e.g., through one or more intermediaries).
[0110] References herein to the positions of elements (e.g., "top", "bottom", "above", "below") are only for describing the orientations of the various elements in the drawings. It should be noted that, according to other exemplary embodiments, the orientations of the various elements can be different, and such variations are intended to be included in the present disclosure.
[0111] Although Figures 5 - 7 while various circuits having specific functions are shown, it should be understood that the controller 34 can include any number of circuits for performing the functions described herein. For example, the activities and functions of the protection circuit 118 can be combined in multiple circuits or as a single circuit. Additional circuits having additional functions can also be included. Furthermore, the controller 34 can further control other activities beyond the scope of the present disclosure.
[0112] As described above, in one configuration, a "circuit" can be implemented in a machine-readable medium for use by, such as Figure 5executed by various types of processors 106 of the processor. The recognition circuit of the executable code may include, for example, one or more physical or logical blocks of computer instructions, which may be organized as objects, procedures, or functions, for example. However, the executable files of the recognized circuit are not necessarily physically located together, but may include different instructions stored in different locations, which, when logically linked together, include the circuit and achieve the purpose of the circuit. In fact, the circuit of the computer-readable program code may be a single instruction or multiple instructions, and may even be distributed over several different code segments, different programs, and across several memory devices. Similarly, the operation data may be recognized and shown in the circuit herein, and may be embodied in any suitable form and organized in any suitable type of data structure. The operation data may be collected as a single data set, or may be distributed in different locations, including on different storage devices, and may exist at least partially only as electronic signals on a system or network.
[0113] Although the term "processor" was briefly defined above, the terms "processor" and "processing circuit" should be interpreted broadly. In this regard, as described above, a "processor" may be implemented as one or more general-purpose processors, application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), digital signal processors (DSPs), or other suitable electronic data processing components configured to execute instructions provided by a memory. One or more processors may take the form of a single-core processor, a multi-core processor (e.g., a dual-core processor, a triple-core processor, a quad-core processor, etc.), a microprocessor, etc. In some embodiments, one or more processors may be external to the device, e.g., one or more processors may be remote processors (e.g., cloud-based processors). Alternatively or additionally, one or more processors may be internal and / or local to the device. In this regard, a given circuit or its components may be arranged locally (e.g., as part of a local server, a local computing system, etc.) or remotely (e.g., as part of a remote server such as a cloud-based server). For this purpose, a "circuit" as described herein may include components distributed over one or more locations.
[0114] Embodiments within the scope of the present disclosure include a program product that includes a machine-readable medium for carrying or having machine-executable instructions or data structures stored thereon. Such a machine-readable medium can be any available medium that can be accessed by a general-purpose or special-purpose computer or other machine with a processor. By way of example, such a machine-readable medium can include RAM, ROM, EPROM, EEPROM, or other optical disk storage devices, magnetic disk storage devices, or other magnetic storage devices, or any other medium that can be used to carry or store desired program code in the form of machine-executable instructions or data structures and that can be accessed by a general-purpose or special-purpose computer or other machine with a processor. Combinations of the above are also included within the scope of machine-readable medium. Machine-executable instructions include, for example, instructions and data that cause a general-purpose computer, special-purpose computer, or special-purpose processing machine to perform a certain function or a set of functions.
[0115] Although the figures and the description may show a particular order of method steps, the order of these steps may be different from that depicted and described, unless stated otherwise above. In addition, two or more steps may be performed simultaneously or partially simultaneously, unless otherwise specified above. For example, such variations may depend on the software and hardware systems selected and the choices of the designer. All such variations are within the scope of the present disclosure. Similarly, the software implementation of the described methods can be accomplished with standard programming techniques with rule-based logic and other logic to perform various connection steps, processing steps, comparison steps, and decision steps.
[0116] It is important to note that the construction and arrangement of the HLC 26 as shown in the various exemplary embodiments are merely illustrative. In addition, any element disclosed in one embodiment can be combined with or used together with any other embodiment disclosed herein. Although only one example of an element from one embodiment that can be combined or utilized in another embodiment has been described above, it should be understood that other elements of the various embodiments can be combined with or used together with any other embodiment disclosed herein.
Claims
1. A system for hardware protection in power electronic devices, comprising: Auxiliary Load Converter (HLC), the Auxiliary Load Converter (HLC) includes power electronic components, and the Auxiliary Load Converter (HLC) is configured to perform alternating current to alternating current (AC / AC) conversion on electric power to supply a load on a railway vehicle; A controller, the controller is configured to be coupled with the HLC, the controller includes a protection circuit, and the controller is configured to: Monitor parameters of the power electronic components of the HLC; Determine that the parameters fail to meet a normal threshold, the normal threshold defining a first limit corresponding to a fault-free condition in the power electronic components for the parameters; Determine that the parameters fail to meet a hardware threshold, the hardware threshold defining a second limit corresponding to before a fault in the power electronic components for the parameters; and In response to determining that the parameters fail to meet the normal threshold and the hardware threshold, activate hardware protection for the power electronic components of the HLC.
2. The system according to claim 1, wherein, The controller is further configured to: In response to determining that the parameters meet the hardware threshold, start a timer; and When the timer is below a time threshold, activate software protection for the power electronic components of the HLC.
3. The system according to any one of claims 1 or 2, wherein, The controller is further configured to: In response to determining that the parameters meet the hardware threshold, start a timer while activating software protection for the power electronic components; and In response to the timer exceeding the time threshold of the software protection, activate the hardware protection.
4. The system according to any one or more of the preceding claims, wherein, The controller is further configured to: activate the hardware protection by disconnecting or interrupting the power electronic components of the HLC for a period of time.
5. The system according to any one or more of the preceding claims, wherein, The controller is further configured to: in response to determining that the parameters meet the normal threshold, continue to monitor the parameters of the power electronic components of the HLC.
6. The system according to any one or more of the preceding claims, wherein, The HLC is further configured to receive power transmitted via a pantograph from a catenary outside the railway vehicle.
7. The system according to any one or more of the preceding claims, wherein, The HLC is further configured to supply power to the load on the railway vehicle, where the load includes at least one of an entertainment system, kitchen appliances, a refrigeration system, or a heating system for the railway vehicle.
8. A controller, comprising: A protection circuit, the protection circuit includes one or more processors coupled with a memory, and the protection circuit is configured to: Monitor parameters of the power electronic components of an Auxiliary Load Converter (HLC) that transmits power from outside the railway vehicle to a load inside the railway vehicle; Compare the parameters of the power electronic components with a normal threshold to identify the presence of a fault condition; Compare the parameters of the power electronic components with a hardware threshold; and Based on the comparison between the parameters and the normal threshold and the comparison between the parameters and the hardware threshold, activate at least one of software protection or hardware protection for the power electronic components of the HLC.
9. The controller according to claim 8, wherein, The protection circuit is further configured to: Monitor a plurality of parameters, the plurality of parameters including at least one of the following: voltage, current, or frequency of the power transmitted through the HLC; and Compare the plurality of parameters with a corresponding plurality of thresholds to determine whether to activate one of the software protection or the hardware protection.
10. The controller according to any one of claims 8 or 9, wherein, The protection circuit is further configured to: Activate a counter in response to determining that the parameter meets the hardware threshold; and Activate the software protection for the power electronic component of the converter when the value of the counter is less than the software protection threshold.
11. The controller according to any one or more of claims 8 - 10, wherein, The protection circuit is further configured to: Activate a counter in response to determining that the parameter meets the hardware threshold, and at the same time activate the software protection for the power electronic component; and Switch from the software protection to the hardware protection in response to the value of the counter exceeding the software protection threshold.
12. The controller according to any one or more of claims 8 - 11, wherein, The protection circuit is further configured to: Identify that there is no abnormal operating condition in the power electronic component of the HLC in response to determining that the parameter meets the normal threshold; and Continue to monitor the parameter of the power electronic component in response to identifying that there is no abnormal operating condition.
13. The controller according to any one or more of claims 8 - 13, wherein, The protection circuit is further configured to: Identify the existence of an abnormal operating condition in the power electronic component of the HLC in response to determining that the parameter fails to meet the normal threshold; and Determine whether to activate one of the software protection or the hardware protection based on the severity of the abnormal operating condition.
14. The controller according to any one or more of claims 8 - 14, wherein, The one or more processors and the memory of the protection circuit are provided in the railway vehicle together with the HLC.
15. A method for protecting a power electronic device, comprising: The controller monitors the parameters of the power electronic component of the auxiliary load converter (HLC); The controller determines that the parameter fails to meet the normal threshold corresponding to the fault-free condition in the power electronic component for the parameter; The controller determines that the parameter fails to meet the hardware threshold corresponding to before the fault in the power electronic component for the parameter; and In response to determining that the parameter fails to meet the normal threshold and the hardware threshold, the controller activates the hardware protection for the power electronic component of the HLC.
16. The method according to claim 15, further comprising: In response to determining that the parameter fails to meet the normal threshold, the controller activates the software protection for the power electronic component of the HLC.
17. The method according to any one of claims 15 or 16, further comprising: The controller monitors the second parameter of the power electronic component while activating the software protection for the power electronic component.
18. The method according to any one or more of claims 15 - 17, further comprising: In response to the second parameter meeting the normal threshold within the time threshold, the controller deactivates the software protection.
19. The method according to any one or more of claims 15 - 18, further comprising: The controller monitors the second parameter of the power electronic component while activating the software protection for the power electronic component; and wherein, activating the hardware protection further includes: switching from the software protection to the hardware protection in response to the second parameter failing to meet the hardware threshold within the time threshold.
20. The method according to any one or more of claims 15 - 19, further comprising: The controller maintains the activation of the software protection for the power electronic component of the HLC while the hardware protection is deactivated.
21. The method according to any one or more of claims 15 - 20, further comprising: The controller determines that the urgency of resolving the abnormal operating condition in the power electronic device of the HLC meets the condition for activating the hardware protection; and Among them, activating the hardware protection further includes: in response to determining that the urgency of resolving the abnormal operating condition meets the condition, activating the hardware protection for the power electronic component of the HLC.
22. The method according to any one or more of claims 15 - 21, further comprising: The controller monitors a second parameter of the power electronic component while the hardware protection is activated; and in response to determining that the second parameter meets the normal threshold and the hardware threshold, the controller switches the hardware protection for the power electronic component of the HLC to software protection.