Independent control type automobile power supply blocking device and blocking method

Through dual-chip architecture and multi-source data analysis, the single point failure and reliability problems of traditional automotive power blocking devices are solved, and the power blocking with high reliability and dynamic safety control is achieved.

CN120396693AActive Publication Date: 2025-08-01TIANJIN HAISHI INTELLIGENT TECHNOLOGY CO LTD
View PDF 11 Cites 0 Cited by

Patent Information

Application Number
CN202510919410.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-04
Publication Date
2025-08-01
Estimated Expiration
2045-07-04

AI Technical Summary

Technical Problem

Traditional automotive power blocking devices rely on instructions from vehicle control units (ACUs), which have high risk of single point failure and insufficient cross-verification of multi-source data, resulting in poor blocking reliability.

Method used

The decision-making and execution separation is achieved using a dual-chip architecture (main control chip and independent ignition control chip) is achieved, the main control chip performs multi-source data analysis, the independent ignition control chip performs hardware-level verification, transmits signals in parallel through hardware isolation channels, and generates an adaptive safety threshold based on voltage, temperature and gas concentration data, and drives the power supply cut-off module to perform power supply cut-off action.

Benefits of technology

It improves the reliability of vehicle power blocking, reduces the false triggering rate, overcomes the delay problem of power outage operations, supports independent decision-making and dynamic safety regulation of multi-source data, and improves safety performance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120396693A_ABST
    Figure CN120396693A_ABST
Patent Text Reader

Abstract

The invention provides an independent control type automobile power supply blocking device and blocking method, and relates to the technical field of automobile power supply blocking. The independent ignition control chip is connected with the main control chip through a hardware isolation channel, and a verification unit is arranged in the independent ignition control chip; the hardware interface expansion module supports at least one of a CAN bus, linear communication and a Line protocol, and is used for performing multi-source signal interaction with a vehicle battery management system, a vehicle control system or external detection equipment; the decision-making unit is configured to generate a primary decision-making signal according to the multi-source signal; and the independent ignition control chip is configured to drive the power supply cut-off module to execute power supply cut-off action when the primary decision signal represents that the automobile power supply needs to be cut off and the decision verification is passed. The automobile power supply blocking device breaks away from ACU dependence, has a multi-source data autonomous decision-making capability and supports dynamic safety regulation and control, so that the problems of response delay, single-point failure and misoperation of a traditional scheme are solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of automotive power interruption, and particularly to an independent control type automotive power interruption device and an interruption method. Background Art

[0002] Traditional automotive power interruption devices (PBD) completely rely on the instructions of the vehicle control unit (ACU) to perform power-off operations. For example, the application number is 202411285956.0, and the name is a new energy vehicle powertrain collision power-off control method and vehicle, which discloses that its working process is: the ACU detects faults (such as collision or battery overvoltage), and then sends instructions, and the PBD passive executes the power-off operation.

[0003] The following limitations exist in this working process: the risk of single-point failure is relatively high. If the ACU fails or is attacked, the traditional PBD loses its emergency response ability. The traditional solution only receives a single path of instructions from the ACU. In addition, the lack of multi-source data cross-verification results in a relatively high misjudgment rate, all of which lead to poor reliability of the interruption of the automotive power supply. Summary of the Invention ]

[0004] In view of the above defects or deficiencies in the prior art, this application aims to provide an independent control type automotive power interruption device and an interruption method to improve the reliability of the interruption of the automotive power supply; In the first aspect, this application proposes an independent control type automotive power interruption device, including: A main control chip, with a decision-making unit built therein; An independent ignition control chip, which is connected to the main control chip through a hardware isolation channel, and a verification unit is built in the independent ignition control chip; A hardware interface expansion module, which supports at least one of CAN bus, direct communication, and Line protocol, and is used for multi-source signal interaction with the vehicle battery management system, vehicle control system, or external detection equipment; Among them, the decision-making unit is configured to generate a primary decision signal according to the multi-source signals; the independent ignition control chip is configured to drive the power cut-off module to execute the power cut-off action when the primary decision signal indicates that the automotive power supply needs to be interrupted and the decision verification passes.

[0005] According to the technical solution provided by this application, the hardware interface expansion module includes a voltage sampling unit for voltage signals, a reconstruction unit for the temperature field distribution matrix, and a feature extraction unit for the electrolyte gas concentration spectrum.

[0006] According to the technical solution provided by the present application, the verification unit is configured to perform decision verification on the primary decision signal, and the decision verification includes checking the protocol integrity of the data source of the multi-source signal, verifying the physical rationality of the multi-source signal, and confirming the timing consistency between the multi-source signals.

[0007] According to the technical solution provided by the present application, the power cut-off module includes a mechanical blasting fuse and an electronic fuse backup unit, and the electronic fuse backup unit is configured to forcibly disconnect the high-voltage circuit through an IGBT device when the mechanical blasting fuse fails.

[0008] According to the technical solution provided by the present application, the hardware isolation channel is a double-verification loop, including an optical isolation channel composed of an optocoupler and an electromagnetic isolation channel composed of a magnetic isolation chip. The two channels transmit the primary decision signal in parallel, and the independent ignition control chip starts the verification unit only when the signal logics transmitted by the two channels are consistent.

[0009] In a second aspect, the present application proposes an independent control type vehicle power cut-off method, which is implemented based on the independent control type vehicle power cut-off device as described above, and includes the following steps: Obtain the voltage gradient time series, temperature field distribution matrix, and electrolyte gas concentration spectrum of the vehicle battery management system in real time and in parallel; Calculate the change rate weight in the time dimension and the distribution correlation weight in the space dimension; Based on the change rate weight and the distribution correlation weight, generate an adaptive safety threshold, and when the voltage gradient is greater than the corresponding adaptive safety threshold for three consecutive sampling periods, obtain the failure probability; Based on the failure probability, generate a comprehensive hazard coefficient in combination with the proportion of the abnormal temperature field distribution area and the gas concentration mutation index; If the comprehensive hazard coefficient is greater than the first preset threshold, trigger the primary decision signal after passing the decision verification by the verification unit; If the primary decision signal indicates that the vehicle power supply needs to be cut off, drive the power cut-off module to perform the power cut-off action.

[0010] According to the technical solution provided by the present application, the primary decision signal includes: When the comprehensive hazard coefficient is in the first preset interval, the primary decision signal indicates a warning to reduce the charging power; When the comprehensive hazard coefficient is in the second preset interval, the primary decision signal indicates that the vehicle power supply needs to be cut off; When the comprehensive hazard coefficient is greater than or equal to the second preset threshold, the primary decision signal indicates that cell-level directional detonation is required; Among them, the lower limit value of the first preset interval is the first preset threshold, the upper limit value of the first preset interval is the lower limit value of the second preset interval, the upper limit value of the second preset interval is the second preset threshold, and the second preset threshold is greater than the first preset threshold.

[0011] According to the technical solution provided by the present application, before generating the adaptive safety threshold based on the change rate weight and the distribution correlation weight, the following steps are included: Obtain the battery health state parameters in real time and calculate the aging compensation coefficient; The generating of the adaptive safety threshold based on the change rate weight and the distribution correlation weight includes the following steps: If the battery health state parameter is greater than the third preset threshold, generate an adaptive safety threshold based on the change rate weight and the distribution correlation weight; After obtaining the battery health state parameters in real time and calculating the aging compensation coefficient, the following steps are further included: If the battery health state parameter is less than or equal to the third preset threshold, generate an adaptive safety threshold based on the change rate weight, the distribution correlation weight, and the aging compensation coefficient.

[0012] According to the technical solution provided by the present application, before generating the comprehensive hazard coefficient based on the failure probability, in combination with the proportion of the abnormal temperature field distribution area and the gas concentration mutation index, the following steps are further included: Monitor the voltage difference between every two adjacent battery cells in real time; The generating of the comprehensive hazard coefficient based on the failure probability, in combination with the proportion of the abnormal temperature field distribution area and the gas concentration mutation index, includes the following steps: If all the voltage differences between the battery cells are less than the fourth preset threshold, generate a comprehensive hazard coefficient based on the failure probability, in combination with the proportion of the abnormal temperature field distribution area and the gas concentration mutation index; After monitoring the voltage difference between every two adjacent battery cells in real time, the following steps are further included: If at least one of the voltage differences between the battery cells is greater than or equal to the fourth preset threshold, take the position corresponding to the voltage difference between the battery cells as the abnormal battery cell position; If the temperature gradient of the local hot spot area obtained through the temperature field distribution matrix is greater than the fifth preset threshold, and the local hot spot area coincides with the abnormal battery cell position, trigger the primary decision signal indicating that the battery cell level needs to be detonated directionally.

[0013] According to the technical solution provided by the present application, the driving power supply cut-off module performs the power cut-off action, including the following steps: Drive the mechanical blasting fuse for mechanical interruption, and collect the residual voltage after interruption after the mechanical interruption; If the residual voltage after interruption is in the primary failure range, activate the electronic fuse backup unit, forcibly disconnect the high-voltage circuit through the IGBT device, and inject a reverse current into the adjacent module to cancel the residual potential.

[0014] Compared with the prior art, the beneficial effects of the present application are as follows: The present application realizes the separation of decision-making and execution through a dual-chip architecture (MCU + ignition chip). The main control chip is responsible for multi-source data analysis, and the ignition chip implements hardware-level verification, reducing the mis-trigger rate and improving the safety performance; at the same time, the hardware isolation channel and parallel data processing effectively overcome the problem of trigger delay in the power-off action and contain the spread of battery thermal runaway; in addition, the decision-making unit can adapt to programmable logic thresholds and support real-time adjustment of safety thresholds according to parameters such as battery SOH (state of health) and ambient temperature, optimizing dynamic adaptability; through the hardware interface expansion module, it is compatible with multi-source instructions such as BUD, ACU, and user terminals, and can still trigger power-off through direct connection of BUD or user APP when the ACU fails, supporting the expansion of scenario compatibility. Thus, the automotive power interruption device can be independent of ACU dependence, have the ability of multi-source data autonomous decision-making, and support dynamic safety regulation to solve the problems of response delay, single-point failure, and misoperation in the traditional solution. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] Figure 1 It is a schematic structural diagram of an independent control type automotive power interruption device provided by the present application; Figure 2 It is a step flow chart of an independent control type automotive power interruption method provided by the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0016] The present application will be further described in detail below with reference to the drawings and embodiments. It can be understood that the specific embodiments described herein are only used to explain the related invention, rather than limiting the invention. Additionally, it should be noted that for the sake of description, only parts related to the invention are shown in the drawings.

[0017] It should be noted that, without conflict, the embodiments in the present application and the features in the embodiments can be combined with each other. The present application will be described in detail below with reference to the drawings and embodiments.

[0018] Embodiment 1 As mentioned in the background art, in view of the problems in the prior art, the present application proposes an independent control type automotive power interruption device and interruption device, as Figure 1 shown, including: A main control chip, and a decision-making unit is built in the main control chip; An independent ignition control chip, which is connected to the main control chip through a hardware isolation channel, and a verification unit is built in the independent ignition control chip; A hardware interface expansion module, which supports at least one of CAN bus, direct communication, and Line protocol, and is used for multi-source signal interaction with a vehicle battery management system, a vehicle control system, or an external detection device; Wherein, the decision-making unit is configured to generate a primary decision signal according to the multi-source signals; the independent ignition control chip is configured to drive the power cut-off module to perform a power cut-off action when the primary decision signal indicates that the vehicle power supply needs to be blocked and the decision verification is passed.

[0019] Further, the hardware isolation channel is a double-verification loop, including an optical isolation channel composed of an optocoupler and an electromagnetic isolation channel composed of a magnetic isolation chip. The two channels transmit the primary decision signal in parallel, and the independent ignition control chip only starts the verification unit when the signal logics transmitted by the two channels are consistent.

[0020] Optionally, the main control chip adopts a Cortex-M7 core MCU and runs the FreeRTOS system. The decision-making unit is an algorithm module based on an LSTM neural network, and the input dimension is a spatio-temporal matrix of voltage / temperature / gas concentration. The independent ignition control chip selects an ASIL D-level safety chip (such as Infineon Aurix TC397), and a physical rule library (such as the temperature change rate ≤ 50 °C / s) is built in the verification unit. The hardware interface expansion module includes a CAN bus interface: connected to the vehicle network through a TJA1042 transceiver; a direct communication interface: adopting an RS-485 physical layer and directly connecting to the ADC sampling unit of the BUD; a Line protocol interface: realizing Manchester encoding and decoding through an optocoupler isolation circuit. The hardware isolation channel: double isolation is realized between the main control chip and the ignition chip through ADuM3160 (magnetic isolation) and HCPL-0723 (optical isolation), and the transmission rate is 10 Mbps. The multi-source signal interaction includes synchronous data processing of at least two heterogeneous protocols (such as CAN + direct).

[0021] In a preferred embodiment, the hardware interface expansion module includes a voltage sampling unit for voltage signals, a reconstruction unit for the temperature field distribution matrix, and a feature extraction unit for the electrolyte gas concentration spectrum.

[0022] Specifically, a 64-channel PT100 thermocouple array is adopted, covering the upper and lower surfaces of each battery module in a 5×5 matrix form (32 sensors on each surface), and auxiliary sensors are arranged at the module gaps (2 sensors per gap, a total of 16). The spacing between the sensors on the module surface is ≤2 cm to ensure that adjacent sensors can cross-verify in case of a single-point failure. Module gap: A flexible thermocouple tape is inserted between adjacent modules, with a spacing ≤1 cm to detect the heat conduction path. The reconstruction unit of the temperature field distribution matrix receives a temperature spatio-temporal matrix composed of real-time readings of all temperature sensors; Specifically, 9 TGS8100 sensors are deployed inside the battery pack to form a 3×3 monitoring grid: 4 sensors are deployed in the module gaps (spacing ≤5 cm), and 5 sensors are deployed in the top space (center + four corners). The readings of these 9 sensors form a gas spatio-temporal matrix; The electrolyte gas concentration spectrum mainly detects the gas concentrations of gas types such as H2, CO, and C2H4; Feature extraction: Perform wavelet packet transform on the sensor response curve and extract the 3-5th order coefficients as feature vectors; Specifically, the layout of the voltage sensor array: Each battery module is configured with 24 voltage sampling points, evenly distributed in a 6×4 matrix (spacing ≤3 cm), covering the positive / negative electrode tabs and the module center area, obtaining 24 voltage signals, generating a data frame every 10 ms, and obtaining a voltage spatio-temporal matrix.

[0023] In a preferred embodiment, the verification unit is configured to perform decision verification on the primary decision signal, and the decision verification includes checking the protocol integrity of the data source of the multi-source signal, verifying the physical rationality of the multi-source signal, and confirming the timing consistency between the multi-source signals.

[0024] Specifically, the protocol integrity check includes verifying the packet header identifier (such as CAN ID 0x18FFA1B2) and the payload length, and verifying the digital signature (ECDSA algorithm, key length 256 bit). The physical rationality verification includes checking the sudden change rate of the temperature signal: if ΔT / Δt>100℃ / s, it is determined as abnormal; and checking the voltage-gas concentration correlation: calculating the theoretical gas concentration according to the Nernst equation, and if the deviation from the measured value is >20%, it is abnormal. The timing consistency confirmation (the quantization standard is that the time difference between signals needs to be less than 1 ms) includes aligning the timestamps of the multi-source signals: achieving μs-level synchronization based on the PTP protocol, and verifying the causal logic: the temperature rise must precede the gas concentration mutation (delay ≤50 ms).

[0025] This embodiment can solve the false triggering caused by the tampering of sensor data (such as forging temperature signals) and the decision conflicts caused by the transmission delay differences of multi-source signals.

[0026] In a preferred embodiment, the power cut-off module includes a mechanical blasting fuse and an electronic fuse backup unit, and the electronic fuse backup unit is configured to forcibly disconnect the high-voltage circuit through an IGBT device when the mechanical blasting fuse fails.

[0027] Specifically, the mechanical blasting fuse uses gunpowder to drive a copper blade to cut the busbar, with an operating time ≤ 0.5 ms; the blasting pressure is 50 MPa, triggered by a piezoelectric ceramic sensor. The electronic fuse backup unit uses an Infineon FF600R12ME4 IGBT module with a rated voltage of 1200 V; the drive circuit is based on gate charge pump technology, with a turn-off time ≤ 10 μs. The determination of fuse failure is that the residual voltage after the mechanical blasting fuse melts > 60 V.

[0028] Embodiment 2 This embodiment proposes an independent control type automotive power supply blocking method, which is implemented based on the independent control type automotive power supply blocking device described in Embodiment 1, as Figure 2 shown, and includes the following steps: S1. Real-time and parallel acquisition of the voltage gradient time series sequence, temperature field distribution matrix, and electrolyte gas concentration spectrum of the vehicle battery management system; Specifically, the voltage gradient time series sequence is obtained by calculating dV / dt through a sliding window (length 100 ms) with a window step size of 10 ms; the temperature field distribution matrix is updated every 50 ms, and the gas concentration spectrum: the sampling rate of each channel is 500 Hz.

[0029] S2. Calculate the change rate weight in the time dimension and the distribution correlation weight in the space dimension; Specifically, through the formula the change rate weight in the time dimension is obtained, where W t represents the change rate weight in the time dimension, used to quantify the urgency of the voltage gradient change, dV / dt represents the voltage gradient (the rate of change of voltage with time), obtained through the above sliding window, k is the slope adjustment coefficient of the Sigmoid function, controlling the sensitivity of the weight to the voltage gradient change, k = 0.1; through the formula , where W s represents the distribution correlation weight in the space dimension, represents the difference between the temperature of the pixel at the i-th row and j-th column in the temperature field matrix and the reference temperature, N represents the total number of pixels in the abnormal area (i.e., the number of pixels determined as "abnormal"), T avg represents the average temperature of the temperature field (global or local background).

[0030] S3. Generate an adaptive safety threshold based on the change rate weight and the distribution correlation weight, and obtain the failure probability when the voltage gradient is greater than the corresponding adaptive safety threshold for three consecutive sampling periods. Specifically, through the formula the adaptive safety threshold is obtained, where V base Set according to the battery type (e.g., set to 4.2V for ternary lithium batteries), with each 10 ms as a sampling period, and the time range of three consecutive sampling periods is 30 ms.

[0031] Specifically, the Bayesian conditional probability is used to calculate the single failure probability of each single sampling period, and weights are assigned to each exceeded sampling period to reflect its risk contribution, and then the failure probability is obtained based on the single failure probability and the assigned weights of each exceeded sampling period.

[0032] Exemplarily, the historical database records 1000 voltage gradient exceedance events, of which 200 finally lead to failures (N fault = 200, N total = 1000). The current exceeded values for three consecutive periods: Period 1: dV1 / dt = 0.6 V / s, Vth(t1) = 0.5 V / s; Period 2: dV2 / dt = 0.7 V / s, Vth(t2) = 0.55 V / s; Period 3: dV3 / dt = 0.8 V / s, Vth(t3) = 0.6 V / s. Calculation of single-period probability: The single failure probability of Period 1 , and similarly, the single failure probability of Period 2 is 0.253, and the single failure probability of Period 3 is 0.291. The time weight calculation is: The assigned weight of Period 1 = 0.606, the assigned weight of Period 2 is 0.779, and the assigned weight of Period 3 is 0.882. The normalized weights: Period 1 = 0.267, Period 2 = 0.343, Period 3 = 0.390, and the final failure probability is 0.259.

[0033] S4. Generate a comprehensive hazard coefficient based on the failure probability, combined with the proportion of the abnormal temperature field distribution area and the gas concentration mutation index. Specifically, the area with abnormal temperature field distribution is defined as a continuous 3×3 pixel block with a temperature difference > 15°C; the gas concentration mutation index = the logarithmic change rate of the current concentration / the baseline concentration, and the baseline concentration is determined by the average value of continuous 24-hour sampling in the battery's static state. The comprehensive hazard coefficient is a normalized risk assessment value (range: 0 to 1), which is used to quantify the overall safety risk level of the battery system. It generates a single decision-making index by integrating the abnormal characteristics of multi-source heterogeneous data (voltage, temperature, gas concentration). The comprehensive hazard coefficient = 0.6A + 0.3B + 0.1C, where A represents the voltage failure probability, and the current failure possibility is calculated based on the historical statistics (Bayesian probability model) of voltage gradient exceeding the standard; B is the proportion of the area with abnormal temperature field distribution, which is the proportion of the area of the continuous 3×3 pixel block with a temperature difference > 15°C in the total monitored area; C is the gas concentration mutation index. The basis for weight allocation is that the voltage failure probability (60%) has the highest weight because voltage mutation is the most direct precursor of thermal runaway; temperature anomaly (30%) reflects the risk of thermal diffusion; gas concentration (10%) is used as an indicator of early chemical by-products, with relatively low sensitivity but being supplementary.

[0034] S5. If the comprehensive hazard coefficient is greater than the first preset threshold, after the decision verification by the verification unit is passed, a primary decision signal is triggered; S6. If the primary decision signal indicates that the vehicle power supply needs to be blocked, the power supply cut-off module is driven to perform the power cut-off action.

[0035] Further, the primary decision signal includes: When the comprehensive hazard coefficient is within the first preset interval, the primary decision signal indicates a warning to reduce the charging power; When the comprehensive hazard coefficient is within the second preset interval, the primary decision signal indicates that the vehicle power supply needs to be blocked; When the comprehensive hazard coefficient is greater than or equal to the second preset threshold, the primary decision signal indicates that cell-level directional detonation is required; Among them, the lower limit value of the first preset interval is the first preset threshold, the upper limit value of the first preset interval is the lower limit value of the second preset interval, the upper limit value of the second preset interval is the second preset threshold, and the second preset threshold is greater than the first preset threshold.

[0036] Specifically, the first preset threshold is the safety baseline of the comprehensive hazard coefficient, which is used to divide the "normal state" and the "warning state". When it is lower than this threshold, the battery state is stable and no active intervention is required, avoiding frequent false triggers and reducing the user experience. The second preset threshold is the emergency action line of the comprehensive hazard coefficient, which is used to divide the "power-off state" and the "detonation state". When it is higher than this threshold, the strictest measures (such as cell-level directional detonation) must be immediately implemented to contain the chain reaction.

[0037] Optionally, the first preset threshold is 0.5 and the second preset threshold is 0.9. The primary decision signal classifies the battery safety state into four levels (normal, warning, power-off, detonation), corresponding to different control responses. Normal state (coefficient < 0.5): Maintain routine monitoring and collect data every 100 ms. Warning state (0.5 ≤ coefficient < 0.7): Activate the thermal management system, reduce the charging power to 50% of the rated value, and at the same time increase the data sampling frequency to 10 ms. State where the vehicle power supply needs to be blocked (0.7 ≤ coefficient < 0.9): Trigger the main relay to disconnect, and at the same time start the backup power supply to maintain the operation of critical systems. Detonation state (coefficient ≥ 0.9): Send a 12V trigger signal to the EBF device of the corresponding battery cell through the ASIC chip.

[0038] In a preferred embodiment, before generating the adaptive safety threshold based on the rate-of-change weight and the distribution correlation weight, the following steps are included: Obtain the battery health state parameters in real time and calculate the aging compensation coefficient; Specifically, the battery health state parameter (SOH) represents the percentage of the current battery capacity relative to the initial capacity; the aging compensation coefficient (β) is a scaling factor used to correct the safety threshold to adapt to the battery aging state. When SOH > 85%, the aging compensation coefficient is 1 (i.e., no compensation is required). When 70% < SOH ≤ 85%, the aging compensation coefficient is , and when SOH ≤ 70%, the aging compensation coefficient is 0.5; The calculation formula integrates a coulomb meter (such as TI BQ34Z100) in the BMS, and statistically accumulates the charge and discharge power. When the cumulative cycle capacity reaches 85% of C initial, it is determined that SOH = 85%; Generating the adaptive safety threshold based on the rate-of-change weight and the distribution correlation weight includes the following steps: If the battery health state parameter is greater than the third preset threshold, then generate the adaptive safety threshold based on the rate-of-change weight and the distribution correlation weight; After obtaining the battery health state parameters in real time and calculating the aging compensation coefficient, the following steps are further included: If the battery health state parameter is less than or equal to the third preset threshold, then generate the adaptive safety threshold based on the rate-of-change weight, the distribution correlation weight, and the aging compensation coefficient.

[0039] Specifically, the adaptive safety threshold is a dynamically adjusted voltage gradient threshold. After every 24 hours or each charge and discharge cycle, update the battery health state parameter (SOH value) through the BMS; The third preset threshold is set to 85%. When the SOH value > 85%, obtain the adaptive safety threshold through the formula When SOH ≤ 85%, activate the compensation logic and obtain it through the formula Obtain an adaptive safety threshold.

[0040] In a preferred embodiment, before generating a comprehensive hazard coefficient based on the failure probability, in combination with the proportion of the abnormal distribution area of the temperature field and the gas concentration mutation index, the following steps are further included: Real-time monitor the voltage difference between every two adjacent battery cells. Specifically, the voltage difference between battery cells refers to the absolute value difference of the voltages between adjacent battery cells. Use an AD7779 ADC chip (24-bit resolution, 8-channel synchronous sampling) to collect the voltage of the battery cells once every 1 ms. Establish a battery cell topology relationship matrix in the MCU, automatically identify adjacent battery cell pairs, and calculate the voltage difference between battery cells in real time through a hardware subtractor. Generating a comprehensive hazard coefficient based on the failure probability, in combination with the proportion of the abnormal distribution area of the temperature field and the gas concentration mutation index, includes the following steps: If all the voltage differences between the battery cells are less than a fourth preset threshold, then generate a comprehensive hazard coefficient based on the failure probability, in combination with the proportion of the abnormal distribution area of the temperature field and the gas concentration mutation index. Specifically, the fourth preset threshold is set according to the battery type. The fourth preset threshold for ternary lithium batteries is 0.3 V, and the fourth preset threshold for lithium iron phosphate batteries is 0.2 V. All the voltage differences between the battery cells being less than the fourth preset threshold indicates that the following problems do not exist: aging or damage of the battery cells; unbalanced charge and discharge caused by internal resistance differences; local short circuit: a sudden voltage drop caused by an internal short circuit of a certain battery cell; connection failure: abnormal voltage drop caused by poor contact of the bus bar or welding point.

[0041] After the real-time monitoring of the voltage difference between every two adjacent battery cells, the following steps are further included: If at least one of the voltage differences between the battery cells is greater than or equal to the fourth preset threshold, then use the position corresponding to the voltage difference between the battery cells as the position of the abnormal battery cell. If the temperature gradient of the local hot spot area obtained through the temperature field distribution matrix is greater than a fifth preset threshold, and the local hot spot area coincides with the position of the abnormal battery cell, then trigger a primary decision signal indicating that the battery cell level needs to be detonated directionally.

[0042] Specifically, if at least one of the cell voltage differences is greater than or equal to the fourth preset threshold, it indicates that at least one of the above problems exists. For safety reasons, it is necessary to determine whether to trigger cell-level directional detonation; the local hot spot area is a continuous 3×3 pixel area in the temperature field matrix, and the single-point temperature gradient is 12 °C / cm². Use a FLIR A315 infrared camera (resolution 320×240), with a spatial resolution of 1 mm / pixel. Identify the coordinates of the hot spot area through an image processing algorithm (OpenCV contour detection), map the abnormal position of the cell voltage difference (such as cell 5) to the thermal imaging coordinates. If the deviation between the center coordinates of the hot spot and the position of the tab of cell 5 is ≤2 mm, it is determined as "matched". The fifth preset threshold is a temperature gradient equal to 10 °C / cm² (set according to battery thermal runaway experimental data. When the local temperature gradient >10 °C / cm², the probability of cell short-circuit risk exceeds 95%).

[0043] In a preferred embodiment, the driving power cut-off module performs a power cut-off action, including the following steps: Drive a mechanical blasting fuse for mechanical interruption, and collect the residual voltage after interruption after the mechanical interruption; If the residual voltage after interruption is in the first-level failure interval, activate the electronic fuse backup unit, forcibly disconnect the high-voltage circuit through an IGBT device, and inject a reverse current into the adjacent module to cancel the residual electromotive force.

[0044] Specifically, the first-level failure interval refers to the interval where the residual voltage after mechanical fusing is between 5–60 V. The first-level failure interval is 5-60 V. If the residual voltage after interruption is in the first-level failure interval, the electronic fuse backup unit needs to be activated. The second-level failure interval is when the residual voltage ≥60 V. When the residual voltage is between 5-60 V, injecting a reverse current into the adjacent module is based on an H-bridge circuit: using a CREE CAS300M12BM2 SiC module, and the control logic is that a PID regulator dynamically adjusts the amplitude of the reverse current according to the residual voltage value; when the residual voltage ≥60 V and the temperature >150 °C, the residual voltage after interruption is in the second-level failure interval, and the injection valve is opened for liquid nitrogen injection cooling.

[0045] In this article, specific examples are used to elaborate on the principles and implementation methods of this application. The descriptions of the above embodiments are only used to help understand the method and its core idea of this application. The above are only the preferred implementation methods of this application. It should be noted that due to the limited nature of written expression and objectively infinite specific structures, for those of ordinary skill in the art in this technical field, without departing from the principle of the present invention, several improvements, refinements or changes can also be made, or the above technical features can be combined in an appropriate manner; these improvements, refinements, changes or combinations, or directly applying the concept and technical solution of the invention to other occasions without improvement, should all be regarded as the protection scope of this application.

Claims

1. An independent control type vehicle power supply interruption device, characterized in that, Including: A main control chip, with a decision-making unit built therein; An independent ignition control chip, which is connected to the main control chip through a hardware isolation channel, and a verification unit is built in the independent ignition control chip; A hardware interface expansion module, which supports at least one of CAN bus, direct communication, and Line protocol, and is used for multi-source signal interaction with a vehicle battery management system, a vehicle control system, or an external detection device; Among them, the decision-making unit is configured to generate a primary decision signal according to the multi-source signals; The independent ignition control chip is configured to drive a power cut-off module to perform a power cut-off action when the primary decision signal indicates that the vehicle power supply needs to be blocked and the decision verification is passed.

2. The independent control type automotive power source interruption device according to claim 1, characterized in that: The hardware interface expansion module includes a voltage sampling unit for voltage signals, a reconstruction unit for a temperature field distribution matrix, and a feature extraction unit for an electrolyte gas concentration spectrum.

3. The independent control type automotive power supply interruption device according to claim 1, characterized in that: The verification unit is configured to perform decision verification on the primary decision signal, and the decision verification includes checking the protocol integrity of the data source of the multi-source signals, verifying the physical rationality of the multi-source signals, and confirming the timing consistency among the multi-source signals.

4. The independent control type vehicle power supply blocking device according to claim 1, characterized in that: The power cut-off module includes a mechanical blasting fuse and an electronic fuse backup unit, and the electronic fuse backup unit is configured to forcibly disconnect the high-voltage circuit through an IGBT device when the mechanical blasting fuse fails.

5. The independent control type automotive power supply interruption device according to claim 1, wherein: The hardware isolation channel is a double-verification loop, including an optical isolation channel composed of optocouplers and an electromagnetic isolation channel composed of magnetic isolation chips. The two channels transmit the primary decision signal in parallel, and the independent ignition control chip starts the verification unit only when the signal logics transmitted by the two channels are consistent.

6. An independent control type vehicle power supply interruption method, implemented based on the independent control type vehicle power supply interruption device according to any one of claims 1-5, characterized in that: Including the following steps: Obtain the voltage gradient time series, temperature field distribution matrix, and electrolyte gas concentration spectrum of the vehicle battery management system in real time and in parallel; Calculate the change rate weight in the time dimension and the distribution correlation weight in the space dimension; Generate an adaptive safety threshold based on the change rate weight and the distribution correlation weight, and obtain a failure probability when the voltage gradient is greater than the corresponding adaptive safety threshold for three consecutive sampling periods; Generate a comprehensive hazard coefficient based on the failure probability, combined with the proportion of the abnormal temperature field distribution area and the gas concentration mutation index; If the comprehensive hazard coefficient is greater than a first preset threshold, trigger a primary decision signal after the decision verification by the verification unit is passed; If the primary decision signal indicates that the vehicle power supply needs to be blocked, drive the power cut-off module to perform a power cut-off action.

7. The independent control type vehicle power supply interruption method according to claim 6, characterized in that: The primary decision signal includes: When the comprehensive hazard coefficient is in a first preset interval, the primary decision signal indicates a warning to reduce the charging power; When the comprehensive hazard coefficient is in a second preset interval, the primary decision signal indicates that the vehicle power supply needs to be blocked; When the comprehensive hazard coefficient is greater than or equal to a second preset threshold, the primary decision signal indicates that cell-level directional detonation is required. Among them, the lower limit value of the first preset interval is the first preset threshold, the upper limit value of the first preset interval is the lower limit value of the second preset interval, the upper limit value of the second preset interval is the second preset threshold, and the second preset threshold is greater than the first preset threshold.

8. The independent control type vehicle power supply interruption method according to claim 6, characterized in that: Before generating the adaptive safety threshold based on the change rate weight and the distribution correlation weight, the following steps are included: Obtain the battery health state parameters in real time and calculate the aging compensation coefficient; Generating the adaptive safety threshold based on the change rate weight and the distribution correlation weight includes the following steps: If the battery health state parameter is greater than the third preset threshold, generate the adaptive safety threshold based on the change rate weight and the distribution correlation weight; After obtaining the battery health state parameters in real time and calculating the aging compensation coefficient, the following steps are further included: If the battery health state parameter is less than or equal to the third preset threshold, generate the adaptive safety threshold based on the change rate weight, the distribution correlation weight, and the aging compensation coefficient.

9. The independent control type vehicle power supply interruption method according to claim 6, characterized in that: Before generating the comprehensive hazard coefficient based on the failure probability, in combination with the proportion of the abnormally distributed area of the temperature field and the gas concentration mutation index, the following steps are included: Monitor the voltage difference between every two adjacent battery cells in real time; Generating the comprehensive hazard coefficient based on the failure probability, in combination with the proportion of the abnormally distributed area of the temperature field and the gas concentration mutation index, includes the following steps: If all the voltage differences between the battery cells are less than the fourth preset threshold, generate the comprehensive hazard coefficient based on the failure probability, in combination with the proportion of the abnormally distributed area of the temperature field and the gas concentration mutation index; After monitoring the voltage difference between every two adjacent battery cells in real time, the following steps are further included: If at least one of the voltage differences between the battery cells is greater than or equal to the fourth preset threshold, take the position corresponding to the voltage difference between the battery cells as the abnormal battery cell position; If the temperature gradient of the local hot spot area obtained through the temperature field distribution matrix is greater than the fifth preset threshold, and the local hot spot area coincides with the abnormal battery cell position, trigger the primary decision signal indicating that the battery cell-level directional point explosion is required.

10. The independent control type vehicle power supply interruption method according to claim 6, characterized in that: The power cut-off action performed by the drive power cut-off module includes the following steps: Drive the mechanical blasting fuse for mechanical blocking, and collect the residual voltage after the mechanical blocking; If the residual voltage after the blocking is in the first-level failure interval, activate the electronic fuse backup unit, forcibly disconnect the high-voltage circuit through the IGBT device, and inject a reverse current into the adjacent module to offset the residual potential.

Citation Information

Patent Citations

  • Double-redundancy switch value PLC control system reliable fault-tolerant controller realization method

    CN105278516A

  • Chassis domain controller for intelligent vehicle, vehicle control method and vehicle

    CN111976623A

  • Protection method and protection device for collision safety of power battery and vehicle

    CN116118512A

  • Cross-platform database synchronization method

    CN117743466A

  • Data risk identification method and identification device based on enterprise credit

    CN118761835A