Driving motor system safety state fault recovery control method and device and vehicle
By acquiring the current speed and temperature of the motor, and using a voltage-temperature-high and low speed threshold table to determine the speed operating conditions, a fault recovery control strategy is formulated. This solves the problem of power interruption and difficult exit from a safe state in the electric vehicle drive system under fault conditions, and achieves rapid power recovery and improved driving experience.
Patent Information
- Application Number
- CN202510810712.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-17
- Publication Date
- 2025-10-31
AI Technical Summary
When an electric vehicle's drive system enters an ASC or SPO safety state due to a fault, it is prone to power interruption, and exiting the safety state is difficult, which seriously affects the driving experience.
By acquiring the motor's current speed, DC bus voltage, and temperature, and using a preset voltage-temperature-high and low speed threshold table, the speed operating condition is determined, and a target fault recovery control strategy is formulated, including IGBT power module bridge arm control signal management and current loop adjustment, to gradually restore the power output of the drive system.
It enables rapid power recovery of the drive system in the event of a fault, allowing it to exit a safe state in a timely manner and improving the driving experience.
Smart Images

Figure CN120879467A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of vehicle control technology, and in particular to a method, device and vehicle for fault recovery control of a drive motor system in a safe state. Background Technology
[0002] With the rapid development of my country's new energy vehicle industry, especially pure electric vehicles, the functions of vehicle electronic and electrical systems are becoming increasingly complex. Ensuring the functional safety of electronic and electrical systems has become a key focus and research hotspot in the industry.
[0003] For vehicle drive systems, the core objective of functional safety is to ensure the safety of occupants in fault conditions. In electric vehicle drive systems where torque safety is the primary functional safety objective, when a fault violating torque functional safety occurs, it is necessary to control the drive system to enter a safe state to avoid safety hazards caused by unexpected torque output from the drive motor, thereby achieving the functional safety objective in fault conditions. For drive systems using permanent magnet synchronous motors as the core of vehicle power, when a fault violating functional safety objectives occurs, the control system needs to enter either an ASC (Active Short Circuit) safe state or an SPO (Stop PWM Output) safe state to meet functional safety design requirements.
[0004] While the above methods can ensure the safety of system hardware and personnel in the event of a fault, the failure will cause the drive system to lose power, preventing the vehicle from continuing to move and severely impacting the driving experience for passengers. Furthermore, there is a difficulty in exiting the drive system after it enters the ASC or SPO safe state. Therefore, the industry standard for handling such faults is to not restore power during the current vehicle power-on cycle, which further compromises the driving experience for passengers in the event of a fault. Summary of the Invention
[0005] This application provides a method, device, and vehicle for fault recovery control of a drive motor system to solve the problem that when the drive system of an electric vehicle enters ASC (Active Short Circuit) or SPO (Power Off PWM Output) state under fault conditions, it is easy to cause interruption of the drive system's output power, difficulty in exiting the safe state, and limitations in fault recovery strategies, which seriously affects the driving experience of the occupants.
[0006] The first aspect of this application provides a method for fault recovery control of a drive motor system, comprising the following steps: acquiring the current speed of the motor, the current DC bus voltage, and the current motor temperature; based on the current DC bus voltage and the current motor temperature, obtaining a speed condition classification threshold from a preset voltage-temperature-high and low speed threshold table according to the current speed, and determining the current speed condition of the motor according to the current speed and the speed condition classification threshold; upon receiving a fault recovery command, determining a target fault recovery control strategy according to the current speed condition, and performing fault recovery according to the target fault recovery control strategy.
[0007] Optionally, the current speed condition is a first speed condition. The step of determining a target fault recovery control strategy based on the current speed condition and performing fault recovery based on the target fault recovery control strategy includes: setting the control signals of the six bridge arms of the IGBT power module to zero, so that the drive motor system enters the SPO safe state, and ensuring that the vector control of the motor is in a stopped state; after a first preset duration, stopping setting the control signals of the six bridge arms of the IGBT power module to zero, and controlling the six bridge arms of the IGBT power module according to the preset control signals of the six bridge arms of the IGBT power module; after a second preset duration, controlling the drive motor system to enter the 0 torque output state through a preset dq axis current loop adjustment; and after a third preset duration, performing fault recovery based on a preset first gradient control strategy.
[0008] Optionally, before controlling the six arms of the IGBT power module according to the preset six-arm control signals of the IGBT power module, the method further includes: acquiring the final torque command issued by the motor controller, the actual d-axis current and the actual q-axis current of the motor; determining the vector control d-axis current and the vector control q-axis current of the motor according to the final torque command and the current speed; obtaining the d-axis voltage command based on the actual d-axis current and the vector control d-axis current using a first pi regulator, and obtaining the q-axis voltage command based on the actual q-axis current and the vector control q-axis current using a second pi regulator; and performing coordinate transformation and space vector pulse width modulation on the d-axis voltage command and the q-axis voltage command to obtain the preset six-arm control signals of the IGBT power module.
[0009] Optionally, the current speed condition is the second speed condition. The step of determining the target fault recovery control strategy based on the current speed condition and performing fault recovery according to the target fault recovery control strategy includes: setting the 6-way bridge arm control signal of the IGBT power module to zero, so that the drive motor system enters the SPO safe state, and ensuring that the vector control of the motor is in a stopped state; after a fourth preset duration, setting the 6-way bridge arm control signal of the IGBT power module to zero, so that the drive motor system enters the SPO safe state; after a fifth preset duration, adjusting the vector control d-axis current according to the actual d-axis current and adjusting the vector control q-axis current according to the actual q-axis current based on a preset current adjustment strategy; after a sixth preset duration, obtaining the d-axis current command and q-axis current command when the final torque command is 0, and transitioning the adjusted vector control d-axis current to the current corresponding to the d-axis current command and the adjusted vector control q-axis current to the current corresponding to the q-axis current command based on a preset gradient limiting strategy; after a seventh preset duration, performing fault recovery based on a preset second gradient control strategy.
[0010] Optionally, when performing fault recovery according to the target fault recovery control strategy, the method further includes: determining whether the current speed meets the first recovery exit condition, or whether the current DC bus voltage meets the second recovery exit condition, or whether the current motor temperature meets the third recovery exit condition; if the current speed meets the first recovery exit condition, or the current DC bus voltage meets the second recovery exit condition, or the current motor temperature meets the third recovery exit condition, then the fault recovery is exited.
[0011] Optionally, the step of obtaining the speed condition classification threshold by looking up a preset voltage-temperature-high / low speed threshold table based on the current DC bus voltage and the current motor temperature includes: determining the first boundary voltage and the second boundary voltage of the voltage range in which the current DC bus voltage is located, and the first boundary temperature and the second boundary temperature of the temperature range in which the current motor temperature is located; obtaining a first intermediate value of the linear difference of speed based on the first high / low speed threshold corresponding to the current DC bus voltage, the first boundary voltage and the first boundary temperature, and the second high / low speed threshold corresponding to the second boundary voltage and the second boundary temperature; obtaining a second intermediate value of the linear difference of speed based on the third high / low speed threshold corresponding to the current DC bus voltage, the first boundary voltage and the first boundary temperature, and the fourth high / low speed threshold corresponding to the second boundary voltage and the second boundary temperature; obtaining an initial value of the speed threshold based on the current motor temperature, the first boundary temperature, the second boundary temperature, the intermediate value of the first linear difference of speed and the intermediate value of the second linear difference of speed; and compensating the initial value of the speed threshold based on a preset compensation strategy to obtain the speed condition classification threshold.
[0012] Optionally, before obtaining the speed condition classification threshold by looking up a preset voltage-temperature-high and low speed threshold table based on the current DC bus voltage and the current motor temperature, the method further includes: determining multiple DC bus voltages at the input terminal of the motor controller based on the lowest and highest output voltages of the power battery; determining multiple test temperatures of the motor based on the lowest and highest operating temperatures of the motor; controlling the drive motor system to enter the SPO safe state; and performing a speed threshold test on the motor based on the multiple DC bus voltages and the multiple test temperatures according to a preset speed threshold test strategy to obtain the preset voltage-temperature-high and low speed threshold table.
[0013] A second aspect of this application provides a drive motor system safety state fault recovery control device, comprising: an acquisition module for acquiring the current speed of the motor, the current DC bus voltage, and the current motor temperature; an operating condition judgment module for obtaining a speed operating condition classification threshold from a preset voltage-temperature-high and low speed threshold table based on the current DC bus voltage and the current motor temperature, and determining the current speed operating condition of the motor based on the current speed and the speed operating condition classification threshold; and a fault recovery control module for determining a target fault recovery control strategy based on the current speed operating condition when a fault recovery command is received, and performing fault recovery according to the target fault recovery control strategy.
[0014] Optionally, the current speed condition is the first speed condition, and the fault recovery control module is further configured to: set the 6-way bridge arm control signal of the IGBT power module to zero, so that the drive motor system enters the SPO safety state, and ensure that the vector control of the motor is in a stopped state; after a first preset duration, stop setting the 6-way bridge arm control signal of the IGBT power module to zero, and control the 6-way bridge arm of the IGBT power module according to the preset 6-way bridge arm control signal of the IGBT power module; after a second preset duration, control the drive motor system to enter the 0 torque output state through the preset dq axis current loop adjustment; after a third preset duration, perform fault recovery based on the preset first gradient control strategy.
[0015] Optionally, before controlling the six bridge arms of the IGBT power module according to the preset six-bridge arm control signals of the IGBT power module, the fault recovery control module is further configured to: acquire the final torque command issued by the motor controller, the actual d-axis current and the actual q-axis current of the motor; determine the vector control d-axis current and the vector control q-axis current of the motor according to the final torque command and the current speed; obtain the d-axis voltage command based on the actual d-axis current and the vector control d-axis current using a first pi regulator, and obtain the q-axis voltage command based on the actual q-axis current and the vector control q-axis current using a second pi regulator; and perform coordinate transformation and space vector pulse width modulation on the d-axis voltage command and the q-axis voltage command to obtain the preset six-bridge arm control signals of the IGBT power module.
[0016] Optionally, the current speed condition is the second speed condition, and the fault recovery control module is further configured to: set the 6-way bridge arm control signal of the IGBT power module to zero, so that the drive motor system enters the SPO safe state, and ensure that the vector control of the motor is in a stopped state; after a fourth preset duration, set the 6-way bridge arm control signal of the IGBT power module to zero, so that the drive motor system enters the SPO safe state; after a fifth preset duration, adjust the vector control d-axis current according to the actual d-axis current and the vector control q-axis current according to the actual q-axis current based on a preset current adjustment strategy; after a sixth preset duration, obtain the d-axis current command and q-axis current command when the final torque command is 0, and based on a preset gradient limiting strategy, transition the adjusted vector control d-axis current to the current corresponding to the d-axis current command and the adjusted vector control q-axis current to the current corresponding to the q-axis current command; after a seventh preset duration, perform fault recovery based on a preset second gradient control strategy.
[0017] Optionally, when performing fault recovery according to the target fault recovery control strategy, the fault recovery control module is further configured to: determine whether the current speed meets the first recovery exit condition, or whether the current DC bus voltage meets the second recovery exit condition, or whether the current motor temperature meets the third recovery exit condition; if the current speed meets the first recovery exit condition, or the current DC bus voltage meets the second recovery exit condition, or the current motor temperature meets the third recovery exit condition, then the fault recovery is exited.
[0018] Optionally, the operating condition judgment module is further configured to: determine the first boundary voltage and the second boundary voltage of the voltage range in which the current DC bus voltage is located, and the first boundary temperature and the second boundary temperature of the temperature range in which the current motor temperature is located; obtain a first speed linear difference intermediate value based on the current DC bus voltage, the first boundary voltage, the first high and low speed thresholds corresponding to the first boundary voltage and the first boundary temperature, and the second high and low speed thresholds corresponding to the second boundary voltage and the first boundary temperature; obtain a second speed linear difference intermediate value based on the current DC bus voltage, the second boundary voltage, the second boundary voltage and the second boundary temperature, and the second high and low speed thresholds corresponding to the second boundary voltage and the second boundary temperature; obtain an initial value of the speed threshold based on the current motor temperature, the first boundary temperature, the second boundary temperature, the first speed linear difference intermediate value, and the second speed linear difference intermediate value; and compensate the initial value of the speed threshold based on a preset compensation strategy to obtain the speed operating condition division threshold.
[0019] Optionally, before obtaining the speed condition classification threshold by looking up a preset voltage-temperature-high and low speed threshold table based on the current DC bus voltage and the current motor temperature, the condition judgment module is further configured to: determine multiple DC bus voltages at the input terminal of the motor controller based on the lowest and highest output voltages of the power battery; determine multiple test temperatures of the motor based on the lowest and highest operating temperatures of the motor; control the drive motor system to enter the SPO safe state, and perform speed threshold tests on the motor based on the multiple DC bus voltages and the multiple test temperatures according to a preset speed threshold test strategy, thereby obtaining the preset voltage-temperature-high and low speed threshold table.
[0020] A third aspect of this application provides a vehicle, including: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the drive motor system safety state fault recovery control method as described in the above embodiments.
[0021] A fourth aspect of this application provides a computer-readable storage medium having a computer program stored thereon, which is executed by a processor to implement the drive motor system safety state fault recovery control method as described in the above embodiments.
[0022] In the above implementation, the current motor speed, current DC bus voltage, and current motor temperature are acquired. Based on the current DC bus voltage and current motor temperature, a speed condition classification threshold is obtained by looking up a preset voltage-temperature-high / low speed threshold table according to the current speed. The current speed condition of the motor is then determined based on the current speed and the speed condition classification threshold. Upon receiving a fault recovery command, a target fault recovery control strategy is determined based on the current speed condition, and fault recovery is performed according to the target fault recovery control strategy. This solves the problem that when the drive system of an electric vehicle enters ASC (Active Short Circuit) or SPO (PWM Output Off) states under fault conditions, it easily causes interruption of drive system output power, makes it difficult to exit the safe state, and restricts fault recovery strategies, severely affecting the driving experience of passengers. It achieves rapid recovery of drive system power output and rapid recovery after a fault, enabling timely exit from the safe state and improving the driving experience of passengers while ensuring driving safety.
[0023] Additional aspects and advantages of this application will be set forth in part in the description which follows, and in part will be obvious from the description, or may be learned by practice of this application. Attached Figure Description
[0024] The above and / or additional aspects and advantages of this application will become apparent and readily understood from the following description of the embodiments taken in conjunction with the accompanying drawings, wherein:
[0025] Figure 1 This is a flowchart of a drive motor system safety state fault recovery control method according to an embodiment of this application;
[0026] Figure 2 This is a schematic diagram of the vector control principle architecture of a permanent magnet synchronous motor according to an embodiment of this application;
[0027] Figure 3 This is a schematic diagram of a hardware architecture for safety state control of a motor vehicle drive system according to an embodiment of this application;
[0028] Figure 4 This is a schematic diagram of SPO safety state control of an electric vehicle drive system according to an embodiment of this application;
[0029] Figure 5 This is a schematic diagram of a three-phase ASC safety state control (down-bridge ASC) for an electric vehicle drive system according to an embodiment of this application;
[0030] Figure 6 A flowchart illustrating the implementation of a motor system safety state fault recovery control according to an embodiment of this application;
[0031] Figure 7 This is a schematic diagram of vector control fault recovery for a permanent magnet synchronous motor according to an embodiment of this application;
[0032] Figure 8 This is a schematic diagram of a current command gradient limitation according to an embodiment of this application;
[0033] Figure 9 A flowchart of a fast-condition fault recovery and exit mechanism according to an embodiment of this application;
[0034] Figure 10 This is an example diagram of a drive motor system safety state fault recovery control device according to an embodiment of this application;
[0035] Figure 11 This is a schematic diagram of a vehicle structure according to an embodiment of this application. Detailed Implementation
[0036] The embodiments of this application are described in detail below. Examples of these embodiments are shown in the accompanying drawings, wherein the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and intended to explain this application, and should not be construed as limiting this application.
[0037] The following description, with reference to the accompanying drawings, outlines a drive motor system safety state fault recovery control method, apparatus, and vehicle according to embodiments of this application. Addressing the issues mentioned in the background art, where the drive system of an electric vehicle enters ASC (Active Short Circuit) or SPO (Power Off PWM Output) states during a fault, easily causing power interruption, difficulty in exiting the safety state, and limitations on fault recovery strategies, severely impacting the driving experience for occupants, this application provides a drive motor system safety state fault recovery control method. In this method, the current motor speed, current DC bus voltage, and current motor temperature are obtained. Based on the current DC bus voltage and current motor temperature, a speed condition classification threshold is obtained by looking up a preset voltage-temperature-high / low speed threshold table according to the current speed. The current speed condition of the motor is then determined based on the current speed and the speed condition classification threshold. Upon receiving a fault recovery command, a target fault recovery control strategy is determined based on the current speed condition, and fault recovery is performed according to the target fault recovery control strategy. This solves the problem that when the drive system of an electric vehicle enters ASC (Active Short Circuit) or SPO (Power Off PWM Output) state under fault conditions, it can easily cause interruption of the drive system's power output, make it difficult to exit the safe state, and limit the fault recovery strategy, which seriously affects the driving experience of the passengers. It enables rapid recovery of the drive system's power output and rapid recovery after a fault, and can exit the safe state in a timely manner, thereby improving the driving experience of the passengers while ensuring driving safety.
[0038] Specifically, Figure 1 This is a flowchart illustrating a method for restoring the safety status of a drive motor system to faults, as provided in an embodiment of this application.
[0039] The drive motor system safety state fault recovery control method of this application is based on the vector control principle of permanent magnet synchronous motor. Therefore, the vector control principle will be briefly introduced first. Figure 2 This is a schematic diagram of the vector control principle architecture of a permanent magnet synchronous motor, where IGBT is the power conversion module in the motor controller; PMSM (Permanent Magnet Synchronous Motor) is the permanent magnet synchronous motor; i d * with i q * This refers to the dq-axis current command given in vector control. This current command is determined based on the vehicle's required torque and the drive system status through maximum torque current ratio control, maximum torque voltage ratio control, and field weakening control (how the dq-axis current command is determined is not within the scope of this application); the three-phase current i of the permanent magnet synchronous motor A i B i CAfter two coordinate transformations (Clark transformation and Park transformation), the actual dq-axis current i is obtained. d with i q The difference between the commanded dq-axis current and the actual current is used as the input to the PI controller for current loop adjustment. The purpose is to ensure that the actual output dq-axis current of the motor matches the commanded current through PI control. The dq-axis voltage command U is obtained through two PI controllers. d with U q U d with U q After coordinate transformation, the six bridge arm control signals of the IGBT module are obtained through space vector pulse width modulation. The DC bus voltage U at the motor controller input is then used. DC Under the action of , current (i) is generated in the three-phase windings of the motor. A i B i C This allows the motor to output torque as expected.
[0040] Figure 3 The diagram illustrates the hardware architecture for electric vehicle safety status control. The dashed box represents the IGBT power conversion module within the Motor Control Unit (MCU). "DC+" indicates the positive terminal of the DC bus connected to the motor controller, and "DC-" indicates the negative terminal. The IGBT module contains six arms (U, V, W) across three phases. U1 and U2 represent the control signals for the upper and lower arms of phase U, V1 and V2 represent the control signals for the upper and lower arms of phase V, and W1 and W2 represent the control signals for the upper and lower arms of phase W. These six control signals control the state (on / off) of the six arms of the IGBT module.
[0041] SPO safety status corresponding to Figure 3 With all the upper, lower, and lower bridge arms (U, V, W) of the IGBT module disconnected, the current in the motor windings will flow through the freewheeling diode in the IGBT module. Figure 3 Can be converted Figure 4 form.
[0042] SPO safety state control generates back electromotive force under steady-state system conditions. The magnitude of the back electromotive force is related to the motor speed; the higher the speed, the greater the back electromotive force. In addition, under high motor speed conditions, SPO control generates a large negative braking torque, which decreases as the motor speed decreases.
[0043] The ASC safety state is achieved by turning on all bridge arms on one side of the IGBT power module while turning off all bridge arms on the other side. Figure 3 Points U, V, and W in the diagram represent the actual short-circuit state, as shown in the diagram. Figure 5 As shown.
[0044] Once the ASC (Automatic Safety Control) state is entered, the current in the motor windings will flow inside the motor and will eventually be dissipated as heat. ASC does not generate back electromotive force, and the negative braking torque produced at high motor speeds is relatively small, preventing unintended deceleration of the vehicle.
[0045] The core content of this application is a recovery method for the drive motor system in an electric vehicle after a fault occurs and it enters a safe state. Therefore, before introducing the implementation logic of the fault recovery control for the motor system in a safe state, it is assumed that the system has already entered a safe state due to the fault. The safe state can be either the SPO safe state or the ASC safe state, and fault recovery is allowed at this time. Fault recovery control is implemented under the above conditions.
[0046] Specifically, such as Figure 1 As shown, the method for restoring the safety status of the drive motor system to fault includes the following steps:
[0047] In step S101, the current speed of the motor, the current DC bus voltage, and the current motor temperature are obtained.
[0048] In step S102, based on the current DC bus voltage and the current motor temperature, the speed condition classification threshold is obtained by looking up the preset voltage-temperature-high and low speed threshold table according to the current speed, and the current speed condition of the motor is determined according to the current speed and the speed condition classification threshold.
[0049] It is understandable that, such as Figure 6 As shown, the current speed, current DC bus voltage, and current motor temperature of the motor are first obtained. Based on the obtained current speed, current DC bus voltage, and current motor temperature, the speed judgment threshold for whether the motor is in a high-speed or low-speed operating condition is calculated to obtain the speed operating condition classification threshold. The speed operating condition classification threshold can also be understood as the judgment threshold for classifying the motor into a high-speed or low-speed operating condition.
[0050] The current operating speed of the motor (low speed or high speed) can be determined by classifying the operating speed threshold. After determining the current operating speed of the motor, corresponding fault recovery control is implemented according to the different speed ranges in which it is located, as follows:
[0051] ① Fault recovery control for safety conditions under low-speed operation;
[0052] ② Fault recovery control for safety conditions under high-speed operation.
[0053] Optionally, in some embodiments, before obtaining the speed condition classification threshold by looking up a preset voltage-temperature-high and low speed threshold table based on the current DC bus voltage and current motor temperature, the method further includes: determining multiple DC bus voltages at the input terminal of the motor controller based on the lowest and highest output voltages of the power battery; determining multiple test temperatures of the motor based on the lowest and highest operating temperatures of the motor; controlling the drive motor system to enter the SPO safe state, and performing speed threshold tests on the motor based on multiple DC bus voltages and multiple test temperatures according to a preset speed threshold test strategy to obtain a preset voltage-temperature-high and low speed threshold table.
[0054] This application calculates Figure 6 The purpose of the speed condition threshold is to distinguish the freewheeling state of a permanent magnet synchronous motor (PMSM) under SPO (Safe Point of Purchase) conditions. At low speeds, the back electromotive force (EMF) generated by the PSM to enter the SPO safe state does not exceed the DC bus voltage of the vehicle's high-voltage power battery, thus no freewheeling current is generated. At high speeds, because the back EMF generated by the PPO safe state is higher than the DC bus voltage, unexpected freewheeling current will occur.
[0055] For permanent magnet synchronous motors, their no-load back electromotive force is not only closely related to the motor speed but also affected by the motor flux linkage. Permanent magnet synchronous motors in electric vehicles operate over long periods within a wide speed range and large temperature variation range, resulting in complex and variable operating conditions. Motor parameters are significantly affected by these operating conditions. To address this issue, this application proposes a method for determining the speed condition classification threshold based on bench testing. The specific implementation process is as follows:
[0056] (1) Install the permanent magnet synchronous motor under test and the motor controller into the motor-drive test platform, control the speed of the motor through the dynamometer, and regulate the temperature of the motor through the cooling system;
[0057] (2) Adjust the DC voltage input to the motor controller using a battery simulator;
[0058] (3) Establish the preset voltage-temperature-high and low speed threshold table shown in Table 1;
[0059] Table 1
[0060]
[0061] In Table 1, the horizontal axis is U1, U2, U3...U max These are multiple DC bus voltages at the input of the motor controller, which are adjusted via a battery simulator, where U1 and U... max These correspond to the lowest and highest output voltages of the high-voltage power battery in electric vehicles, U1, U2, U3...Umax The step size between changes is 20V. Table 1 shows the T1, T2, T3...T... values on the vertical axis. max This represents the current temperature of the motor, which is regulated by the cooling system. T1 corresponds to the minimum operating temperature of the drive system, and T... max For the maximum allowable operating temperature of the drive motor, T1 can generally be selected as -40℃, T max The temperature is 160℃, T1, T2, T3...T max The temperature change interval is 10℃.
[0062] R in Table 1 1-1 R 1-2 R 1-3 ...R max-max This indicates the high and low speed thresholds of the motor under the corresponding DC bus voltage and motor temperature conditions. These thresholds are obtained through bench testing.
[0063] Optionally, in some embodiments, based on the current DC bus voltage and the current motor temperature, the speed condition classification threshold is obtained by looking up a preset voltage-temperature-high and low speed threshold table according to the current speed. This includes: determining the first boundary voltage and the second boundary voltage of the voltage range in which the current DC bus voltage is located, and the first boundary temperature and the second boundary temperature of the temperature range in which the current motor temperature is located; obtaining a first speed linear difference intermediate value based on the first high and low speed thresholds corresponding to the current DC bus voltage, the first boundary voltage, and the first boundary temperature, and the second high and low speed thresholds corresponding to the second boundary voltage and the second boundary temperature; obtaining a second speed linear difference intermediate value based on the third high and low speed thresholds corresponding to the current DC bus voltage, the first boundary voltage, and the first boundary temperature, and the fourth high and low speed thresholds corresponding to the second boundary voltage and the second boundary temperature; obtaining an initial value of the speed threshold based on the current motor temperature, the first boundary temperature, the second boundary temperature, the first speed linear difference intermediate value, and the second speed linear difference intermediate value; and compensating the initial value of the speed threshold based on a preset compensation strategy to obtain the speed condition classification threshold.
[0064] Specifically, this application obtains the high and low speed thresholds of the motor in Table 1 through the following steps, specifically using the threshold R under operating conditions U2 and T3. 3-2 The determination method will be explained using the following example:
[0065] Step a) Adjust the battery simulator and cooling system to stabilize the motor under U2 and T3 conditions, and control the system to enter the SPO safe state through the motor controller;
[0066] Step b) Adjust the motor-driven test platform so that the motor speed gradually increases from 0 rpm in increments of 1000 rpm / min. During this process, the U, V, and W phase currents of the motor are collected in real time. If the motor current meets any of the following conditions, record the current speed as the speed threshold R under the current operating condition. 3-2 :
[0067] Condition ①: The motor's U-phase current exceeds 10A;
[0068] Condition ②: The V-phase current of the motor exceeds 10A;
[0069] Condition ③: The W-phase current of the motor exceeds 10A.
[0070] This application determines whether freewheeling occurs based on whether the three-phase current of the motor exceeds a specified threshold (10A). If the back electromotive force (EMF) of the motor does not exceed the DC voltage at the input terminal of the motor controller under the SPO safe state, freewheeling will not occur, and the U, V, and W phase currents of the motor will be 0. If the back EMF exceeds the DC voltage at the input terminal of the motor controller, freewheeling current will be generated in the U, V, and W phases of the motor. This application obtains the speed condition classification threshold under different operating conditions based on this principle.
[0071] Step c) Complete the operation in step b) in Table 1 for R. 1-1 R 1-2 R 1-3 ...R max-max The threshold for classifying operating speed conditions is determined.
[0072] Furthermore, Table 1 records the speed condition classification thresholds under different operating conditions. This table is stored in the motor controller. In practical applications, the motor temperature and the DC bus voltage of the motor controller are used as inputs. The speed condition classification thresholds under the current operating condition are obtained through difference lookup and speed compensation. The specific method is as follows:
[0073] a) Calculation of the initial value of the motor speed threshold
[0074] This application obtains the initial values R of the high and low speed thresholds of the motor through a difference lookup table. int Specifically, based on the current DC bus voltage U a The current motor temperature is T. a Taking the working condition of R as an example int The calculation method is explained below, where the first boundary voltage U2 < the current DC bus voltage U a <Second boundary voltage U3, first boundary temperature T1 <Current motor temperature T a <The second boundary temperature T2, thus determining the first high and low speed threshold as R 1-3 The second high and low speed threshold is R. 1-2The third high and low speed threshold is R. 2-3 The fourth high and low speed threshold is R. 2-2 .
[0075] Further, based on the current DC bus voltage, the first boundary voltage, and the first boundary temperature, the corresponding first high and low speed threshold R... 1-3 The second high and low speed threshold R corresponding to the second boundary voltage and the first boundary temperature 1-2 The intermediate value of the first linear difference in rotational speed is obtained; based on the current DC bus voltage, the second boundary voltage, the second boundary voltage, and the second boundary temperature, the third high and low rotational speed threshold R is obtained. 2-3 The fourth high and low speed threshold R corresponding to the second boundary voltage and the second boundary temperature 2-2 The intermediate value of the linear difference of the second rotational speed is obtained:
[0076]
[0077] R in equations (1) and (2) 1a R 2a These are the intermediate values of the first linear speed difference and the second linear speed difference, obtained based on the first boundary voltage U2 and the second boundary voltage U3, respectively. These intermediate values are used to calculate the initial value R of the speed threshold. int .
[0078]
[0079] The initial value R of the motor speed threshold obtained by linear interpolation can be calculated using equation (3). int .
[0080] b) Based on the preset compensation strategy, the initial value of the compensation speed threshold is used to obtain the speed condition division threshold.
[0081] This application uses equation (4) to set the initial value R of the speed threshold. int Compensation is performed to ultimately obtain the speed condition classification threshold R. N Thus, the threshold R is divided according to the operating speed. N It can determine the current operating speed.
[0082] R N =0.95·R int (4)
[0083] This application designs fault recovery strategies for low-speed and high-speed operating conditions, respectively, based on whether the drive system is in a freewheeling state. These two fault recovery methods cannot be used interchangeably to achieve the desired control effect. The fault recovery strategy for low-speed conditions cannot be used for fault recovery in high-speed freewheeling states, otherwise it will cause other system faults, such as overcurrent in the motor controller hardware. However, the fault recovery strategy for high-speed conditions can be used for fault recovery in low-speed states, but the impact on the driving comfort of passengers during the fault recovery process is greater. Considering the characteristics of the two control methods and the difficulty in judging the motor freewheeling state due to speed fluctuations during actual fault recovery, this application uses the initial values R of the motor high and low speed thresholds obtained through linear interpolation. int Based on this, the speed is further reduced through compensation to obtain the final speed condition classification threshold R under the current operating conditions. N By using the threshold value for this speed condition to determine the high and low speed conditions of the motor, the above problems can be solved.
[0084] The above provides a detailed explanation of the method for determining the high and low speed thresholds of a motor. The following section will explain the specific fault recovery methods.
[0085] In step S103, upon receiving a fault recovery command, a target fault recovery control strategy is determined based on the current speed condition, and fault recovery is performed according to the target fault recovery control strategy.
[0086] Optionally, in some embodiments, the current speed condition is a first speed condition. A target fault recovery control strategy is determined based on the current speed condition, and fault recovery is performed according to the target fault recovery control strategy. This includes: setting the control signals of the six bridge arms of the IGBT power module to zero, so that the drive motor system enters the SPO safe state, and ensuring that the vector control of the motor is in a stopped state; after a first preset duration, stopping the setting of the control signals of the six bridge arms of the IGBT power module to zero, and controlling the six bridge arms of the IGBT power module according to the preset control signals of the six bridge arms of the IGBT power module; after a second preset duration, adjusting the drive motor system to enter the 0 torque output state through a preset dq axis current loop; and after a third preset duration, performing fault recovery based on a preset first gradient control strategy.
[0087] Optionally, in some embodiments, before controlling the six arms of the IGBT power module according to the preset six-arm control signals of the IGBT power module, the method further includes: acquiring the final torque command issued by the motor controller, the actual d-axis current of the motor, and the actual q-axis current; determining the vector control d-axis current and vector control q-axis current of the motor according to the final torque command and the current speed; obtaining the d-axis voltage command based on the actual d-axis current and the vector control d-axis current using a first pi regulator, and obtaining the q-axis voltage command based on the actual q-axis current and the vector control q-axis current using a second pi regulator; and performing coordinate transformation and space vector pulse width modulation on the d-axis voltage command and the q-axis voltage command to obtain the preset six-arm control signals of the IGBT power module.
[0088] The first speed condition is the low speed condition.
[0089] This application achieves fault recovery under safe conditions by using dq-axis current loop feedforward control in vector control combined with motor output torque gradient limiting. The fault recovery control for low-speed operating conditions under safe conditions comprises two parts: pre-fault recovery control and recovery process control, which will be described separately below.
[0090] (1) Control before fault recovery under low speed operating conditions
[0091] After a fault, the drive motor system enters a safe state, which may be either the SPO safe state or the ASC safe state. In this application, fault recovery refers to the control of the motor controller to restart, exit the safe state, and ensure the safe and stable power output of the motor throughout the process.
[0092] Figure 7 This represents the content related to fault recovery in the vector control of a permanent magnet synchronous motor, where T cmd This represents the final torque command determined by the motor controller, which is specifically determined based on the torque command output by the vehicle and the operating state of the motor controller; ω represents the current speed of the motor, while the current management module uses T... cmd With ω as input, the d-axis current command i in the vector control of the permanent magnet synchronous motor is determined by methods such as maximum torque-current ratio or field weakening control. d * Vector control q-axis current command i q *( Figure 7 The current management module is a mature existing technology, and this application will not describe it in detail, but only use the dq-axis current command output by the module. This current command is related to the actual d-axis current i of the motor. d q-axis current i q The deviation between the two is used as the input to the first and second pi regulators for current loop control, and the d-axis voltage command U is obtained respectively. dq-axis voltage command U q The voltage command, after coordinate transformation and space vector pulse width modulation, outputs control signals for the six bridge arms of the IGBT power module, specifically:
[0093] ①U-phase upper arm control signal: Ctrl-UH (0-arm disconnected; 1-arm connected);
[0094] ②U-phase lower arm control signal: Ctrl-UL (0-arm disconnected; 1-arm connected);
[0095] ③V-phase upper arm control signal: Ctrl-VH (0-arm disconnected; 1-arm connected);
[0096] ④V-phase lower arm control signal: Ctrl-VL (0-arm disconnected; 1-arm connected);
[0097] ⑤ W-phase upper arm control signal: Ctrl-WH (0-arm disconnected; 1-arm connected);
[0098] ⑥W-phase lower arm control signal: Ctrl-WL (0-arm disconnected; 1-arm connected).
[0099] Upon receiving the fault recovery command, this application first forcibly sets the six bridge arm control signals (Ctrl-UH, Ctrl-UL, Ctrl-VH, Ctrl-VL, Ctrl-WH, Ctrl-WL) of the IGBT power module to zero, thus putting the system into the SPO safe state; simultaneously, it applies the d-axis current command i. d q-axis current command i q With d-axis voltage command U d q-axis voltage command U q All values are 0, which puts the vector control in the permanent magnet synchronous motor into a stopped state. After a 20ms delay (first preset duration), it enters the "low speed condition fault recovery process control".
[0100] (2) Control during fault recovery under low-speed operating conditions
[0101] When the drive motor system enters the "fault recovery process" control phase, the forced zeroing operation of the six bridge arm control signals (Ctrl-UH, Ctrl-UL, Ctrl-VH, Ctrl-VL, Ctrl-WH, Ctrl-WL) of the IGBT power module is first cancelled. These six control signals are then processed through... Figure 7 The space vector pulse width modulation module in the middle is based on the dq axis voltage command U d U q It is determined that space vector pulse width modulation is a mature existing technology, and this application will not elaborate on it, but only introduce the dq axis voltage command U. dU q The method for determining it.
[0102] The forced zeroing operation of the 6-way bridge arm control signal of the IGBT power module is cancelled. The IGBT power module is turned on via feedforward control. This application completes the feedforward turn-on control by giving a feedforward dq-axis voltage command. The dq-axis voltage command at this time is:
[0103]
[0104] Where, ω r L represents the electric angular velocity of the motor. d L q Ψ represents the dq axis inductance of the motor. s This indicates the magnetic flux linkage of the permanent magnet in the motor. This application first achieves the restart of the IGBT power module after a fault through the above method. According to equation (5), the d-axis voltage command U in the vector control of the permanent magnet synchronous motor is given. d q-axis voltage command U q And continue for 50ms (i.e., the second preset duration) to allow the system to restart and reach steady state, during which time the following parameters are given: Figure 7 Torque command T in cmd It is always 0.
[0105] After a 50ms wait, this application provides the torque command T. cmd It is 0, then use Figure 7 The "Current Management" module determines the dq axis current command and controls the drive system to enter the 0 torque output state through the normal dq axis current loop adjustment.
[0106] The system is kept in a zero torque state for 50ms (i.e., the third preset duration) to make the system stable. Then, the torque recovery after the fault is finally achieved by torque command gradient control, as shown in Equation (6).
[0107]
[0108] In equation (6), T cmd (n) represents the motor torque command after gradient limiting in this control cycle; T cmd (n-1) represents the motor torque command after gradient limiting in the previous control cycle; sign represents the sign function; T rel This indicates the actual torque command for the entire vehicle; T s Indicates the control period; K cmd K represents the torque gradient coefficient. cmd >0. According to this formula, if the vehicle torque command T rel If the value is positive (the sign function is positive), then Tcmd starts from 0 torque and increases by K per control cycle.cmd The gradient increases until the vehicle torque command T is reached. rel If the vehicle torque command T rel If it is less than zero (the sign function is negative), then T cmd Starting from 0 torque, according to K per control cycle cmd The gradient decreases until the vehicle torque command T is reached. rel .
[0109] This application stipulates T cmd The change does not exceed 50 Nm / s, corresponding to the torque gradient coefficient K. cmd The restrictions are as follows:
[0110]
[0111] This concludes the introduction to the fault recovery control method for low-speed operating conditions provided in this application.
[0112] Furthermore, in some embodiments, the current speed condition is the second speed condition. A target fault recovery control strategy is determined based on the current speed condition, and fault recovery is performed according to the target fault recovery control strategy. This includes: setting the control signals of the six bridge arms of the IGBT power module to zero, so that the drive motor system enters the SPO safe state, and ensuring that the vector control of the motor is in a stopped state; after a fourth preset duration, setting the control signals of the six bridge arms of the IGBT power module to zero, so that the drive motor system enters the SPO safe state; after a fifth preset duration, adjusting the d-axis current of the vector control according to the actual d-axis current and the q-axis current of the vector control according to the actual q-axis current based on a preset current adjustment strategy; after a sixth preset duration, obtaining the d-axis current command and q-axis current command when the final torque command is 0, and transitioning the adjusted vector control d-axis current to the current corresponding to the d-axis current command and the adjusted vector control q-axis current to the current corresponding to the q-axis current command based on a preset gradient limiting strategy; and after a seventh preset duration, performing fault recovery based on a preset second gradient control strategy.
[0113] The second speed condition is the high speed condition.
[0114] Compared to fault recovery under low-speed conditions, fault recovery under high-speed conditions is more complex. Therefore, in addition to control before and during fault recovery, it also includes a fault recovery control exit protection mechanism, which will be explained separately below.
[0115] After a fault, the drive motor system enters a safe state, either the SPO safe state or the ASC safe state. Under high-speed conditions, to meet the vehicle's functional safety design requirements, the ASC safe state is generally used to achieve the safety objective after a fault. In the ASC safe state, one side of the IGBT power module's bridge is in a conducting state, making it extremely difficult to restart the transistors. To address this issue, this application, upon receiving a fault recovery command, first forcibly resets the six bridge arm control signals (Ctrl-UH, Ctrl-UL, Ctrl-VH, Ctrl-VL, Ctrl-WH, Ctrl-WL) of the IGBT power module to zero after entering the ASC safe state for a fourth preset duration, thus putting the system into the SPO safe state. After a 30ms delay (i.e., a fifth preset duration), control during the high-speed fault recovery process is implemented.
[0116] When the drive motor system enters the "fault recovery process" control phase, the drive system has been in a safe state for 30ms under SPO conditions. During this time, the freewheeling current has been established and reached a stable changing state. In this case, this application obtains the actual dq axis current value of the motor through coordinate transformation based on the U, V, and W three-phase currents of the motor. Figure 7 i in d i q Coordinate transformation is a well-established technology and will not be discussed in detail here; only the final transformed result will be used.
[0117] During the fault recovery process, this application first cancels the forced zeroing operation of the 6-channel bridge arm control signals (Ctrl-UH, Ctrl-UL, Ctrl-VH, Ctrl-VL, Ctrl-WH, Ctrl-WL) of the IGBT power module, and then performs vector control dq-axis current command i d *、i q *With actual dq axis current i d i q To maintain a consistent approach to enabling IGBT power module activation, the specific method is as follows:
[0118]
[0119] According to equation (8), the d-axis current command and q-axis current command of the current control cycle are equal to the actual dq-axis current of the motor obtained through coordinate transformation in the previous control cycle, that is, the current command follows the actual dq-axis current change of the motor. The dq-axis current loop is adjusted in the vector control of the permanent magnet synchronous motor according to equation (8) to obtain the d-axis voltage command U. d q-axis voltage command U q Implemented using this voltage command Figure 6The space vector pulse width modulation in this application is precisely the method used to achieve IGBT power module turn-on control after a fault.
[0120] The above process lasts for 50ms (i.e., the sixth preset duration) to ensure that the system reaches a stable state after the pipes are turned on, after which the following is given. Figure 7 Torque command T in cmd If the value is 0, the dq-axis current command corresponding to the 0 torque condition under the current state is obtained through the "Current Management" module, and this command is defined as the d-axis current command i. d0 q-axis current command i q0 This application designs a gradient control method to... Figure 7 The actual d-axis current i in the vector control of the permanent magnet synchronous motor d * Vector control of q-axis current i q * Current command corresponding to transition to 0 torque condition i d0 i q0 This brings the drive motor to a zero-torque condition, as described above. Figure 8 As shown.
[0121]
[0122] Equation (9) is the method for implementing the gradient constraint of the d-axis current command, where i d *(n) represents the d-axis current command after gradient limiting in the current control cycle; i d0 (n) represents the actual d-axis current command for torque control in the current control cycle 0; sign is the sign function; T s Indicates the control period; K id K represents the d-axis current transformation gradient coefficient. id >0. According to this formula, if i d * with i d0 When the deviation between them does not exceed 10A, i can be used directly. d0 Perform d-axis current loop adjustment in vector control; i d * with i d0 If the deviation exceeds 10A, then the d-axis current command i after gradient limiting from the previous control cycle is used. d *(n-1) Gradient constraint values are stacked progressively towards i d0 Approximation is used to achieve gradient limitation of the d-axis current during fault recovery.
[0123]
[0124] Equation (10) is the method for implementing the gradient constraint of the q-axis current command, where i q *(n) represents the q-axis current command after gradient limiting in the current control cycle; i q0(n) represents the actual q-axis current command for torque control in the current control cycle 0; sign is the sign function; T s Indicates the control period; K iq K represents the q-axis current transformation gradient coefficient. iq >0. The method for limiting the gradient of the q-axis current command is exactly the same as that for the q-axis, so it will not be repeated.
[0125] The system is stabilized after 50ms of continuous operation at 0 torque (i.e., after the seventh preset duration). Finally, the torque is restored after the fault is recovered by the torque command gradient control method. The specific process of this part is the same as the torque command recovery under low speed conditions, as shown in equations (6) and (7), which will not be repeated here.
[0126] Optionally, in some embodiments, when performing fault recovery according to the target fault recovery control strategy, the method further includes: determining whether the current speed meets the first recovery exit condition, or whether the current DC bus voltage meets the second recovery exit condition, or whether the current motor temperature meets the third recovery exit condition; if the current speed meets the first recovery exit condition, or the current DC bus voltage meets the second recovery exit condition, or the current motor temperature meets the third recovery exit condition, then the fault recovery is exited.
[0127] Compared to fault recovery under low-speed conditions, fault recovery under high-speed conditions is more complex. To avoid triggering other faults (such as three-phase current overcurrent faults in the motor controller, DC bus overvoltage faults in the motor controller, etc.) or unexpected torque output from the motor during the fault recovery process, this application uses the monitoring of the motor's three-phase current, the DC bus voltage of the motor controller, and the motor speed to determine the conditions for exiting fault recovery control. When any fault recovery condition is not met, the fault recovery control is exited to protect driving safety.
[0128] Figure 9 The implementation logic of the high-speed operating condition fault recovery and exit mechanism provided in this application, according to the diagram, uses three parallel decision paths to determine the fault exit conditions, namely:
[0129] ① Fault recovery exit condition judgment based on motor three-phase current detection, that is, judging whether the current speed meets the first recovery exit condition;
[0130] ② Fault recovery exit condition judgment based on DC bus voltage detection, that is, judging whether the current DC bus voltage meets the second recovery exit condition;
[0131] ③ Fault recovery exit condition judgment based on motor speed fluctuation detection, that is, judging whether the current motor temperature meets the third recovery exit condition.
[0132] Entering a safe state avoids system instability caused by fault recovery control. Next, based on... Figure 9 The exit conditions for fault recovery provided in this application are explained.
[0133] (1) Fault recovery exit conditions based on motor three-phase current detection
[0134] according to Figure 1 The diagram shown is a vector control principle architecture diagram of a permanent magnet synchronous motor. The three-phase currents of the motor are i... A i B i C This application determines whether the conditions for exiting fault recovery control are met by detecting the peak value and gradient of the three-phase current. This application stipulates that the conditions for exiting fault recovery control are met when any of the following conditions are satisfied:
[0135] Condition ①: During fault recovery, the three-phase current i of the motor A i B i C If any phase exceeds the specified threshold ±I R-max And the cumulative number of times exceeds 3, I R-max >0;
[0136] Condition ②: During fault recovery, the three-phase current i of the motor A i B i C The gradient of any phase change exceeds ±I T-max / Control cycle, I T-max >0.
[0137] Current threshold I in condition ① R-max The value should be lower than the overcurrent fault judgment threshold of the motor controller software. When the three-phase current of the motor exceeds this threshold, it indicates that the system is in a critical unstable state. In this case, this application ensures the safety of the system and the personnel on the vehicle by exiting the fault recovery control. The current change gradient threshold I in condition ② T-max The gradient condition is determined through actual calibration, and equation (11) is the specific method for judging the gradient condition:
[0138]
[0139] In equation (11), i A (n), i B (n), i C (n) represents the three-phase current value of the motor in this control cycle, i A (n-1), i B (n-1), i C(n-1) represents the three-phase current value of the motor in the previous control cycle. When the change in current of any one phase exceeds ±I... T-max This indicates that the system has entered a critical unstable state. In this case, this application also ensures the safety of the system and the personnel on board by exiting the fault recovery method.
[0140] (2) Fault recovery exit condition judgment based on DC bus voltage detection
[0141] During high-speed fault recovery, the system must first be brought into a SPO safe state, and the transistor switching operation must be performed in the SPO safe state. To avoid triggering system instability during this process, this application monitors the DC bus voltage of the motor controller. If the DC bus voltage exceeds the specified threshold U... max If the system is considered to be in an unstable state during fault recovery, continuing fault recovery poses a risk of triggering system hardware overvoltage. Therefore, in this case, this application ensures the safety of the system and the personnel on board by exiting fault recovery control. The threshold U is... max The selected value should be lower than the overvoltage fault threshold of the motor controller software, and the specific value should be determined through actual calibration.
[0142] (3) Fault recovery exit condition judgment based on motor speed fluctuation detection
[0143] For drive motor systems in electric vehicles, torque safety is the core of functional safety design and development. To avoid triggering system instability during fault recovery and causing the drive motor to produce unexpected torque output, this application detects unexpected torque output during fault recovery by monitoring motor speed fluctuations. The reason for using motor speed monitoring to determine whether the motor is outputting unexpected torque is that existing methods for estimating the output torque of permanent magnet synchronous motors cannot accurately estimate the motor output torque during the transition of the drive system from the SPO safe state to normal operation. Considering that unexpected torque output will cause changes in motor speed, this application extracts parameters from the motor speed signal during fault recovery based on this characteristic, and uses this to indirectly detect unexpected torque output, thus determining the exit condition for fault recovery control.
[0144] Based on the motor speed, this application performs speed change gradient detection and motor speed fluctuation detection respectively. When any of the following conditions are met, the fault recovery control exit condition is determined to be met:
[0145] Condition ①: During the fault recovery process, the gradient of the motor speed change exceeds ±R. max / Control cycle, R max >0.
[0146] |R(n)-R(n-1)|>|R max|; (12)
[0147] In equation (12), R(n) represents the motor speed in the current control cycle, and R(n-1) represents the motor speed in the previous control cycle, where the gradient threshold R max Determined through actual vehicle calibration. When the motor speed change gradient exceeds ±R... max This indicates that the motor is experiencing unexpected torque output. In this case, this application ensures the safety of the system and the personnel on board by exiting the fault recovery method.
[0148] Condition ②: During the fault recovery process, the motor speed fluctuation coefficient K R Exceeding the specified threshold K R-max K R-max >0.
[0149] Among them, the motor speed fluctuation coefficient K R The expression is as follows:
[0150]
[0151] Where R represents the current motor speed, R int This represents the motor speed value before fault recovery. According to equation (13), this application compares the motor speed R within k control cycles during the fault recovery process with the motor speed R before fault recovery. int The average of the sum of squared deviations is used to represent the motor speed fluctuation coefficient K. R The more drastic the fluctuation in motor speed, the more K... R The larger the value, the greater the value.
[0152] This application utilizes the motor speed fluctuation coefficient K R This characterizes the unexpected output of motor torque during fault recovery. When K... R Exceeding threshold K R-max When this occurs, it indicates that the motor is experiencing unexpected torque output. In this case, this application ensures the safety of the system and the personnel on board by exiting the fault recovery control. The threshold K in equation (13) R-max Determined through actual vehicle calibration.
[0153] In summary, the technical effects of the embodiments of this application are as follows:
[0154] 1. This application applies to drive systems that use permanent magnet synchronous motors as the core of vehicle power. It solves the industry problem of rapid recovery of the drive system after it enters the ASC or SPO safe state due to a fault. While ensuring that the whole vehicle does not violate the safety objectives and meets the driving safety requirements, the fault recovery mechanism realizes the rapid recovery of the drive system power output within the current power-on cycle of the vehicle, which greatly improves the driving experience of the vehicle after a fault.
[0155] 2. Based on the motor speed and the DC voltage output by the vehicle's high-voltage power battery at the time of the fault, this application divides the electric vehicle safety state fault recovery control into fault recovery under low-speed conditions and fault recovery under high-speed conditions. Based on the vector control principle of permanent magnet synchronous motor, fault recovery strategies are designed for each condition to achieve rapid recovery of the drive system after a fault in the full speed range.
[0156] When the motor is operating at low speed, considering that the back electromotive force generated in the SPO safe state will not generate freewheeling current in the drive system and at both ends of the DC bus connected to the power battery, this application realizes fault recovery in the safe state by using dq axis current loop feedforward control in vector control plus motor output torque gradient limitation, thereby improving the driving experience of the passengers while ensuring driving safety.
[0157] Under high-speed operation, the back electromotive force generated by the drive system in the SPO safe state is higher than the output voltage of the vehicle's power battery. This causes unexpected freewheeling current to be generated inside the motor controller, in the three-phase windings of the motor, and in the high-voltage DC bus. Addressing the industry-wide challenge of the IGBT power module opening under freewheeling current conditions, this application obtains the dq-axis current of the motor under freewheeling conditions through coordinate transformation. This current is then used as the dq-axis current command in vector control for current loop control, enabling normal opening of the IGBT power module. With normal IGBT power module opening achieved, the dq-axis current is controlled according to a certain gradient to bring the motor to a zero-torque state. After achieving normal zero-torque control of the motor output, this application uses torque command gradient limiting to control the motor to restore power output according to the vehicle's commands, thus recovering from the fault.
[0158] 3. Compared to fault recovery under low-speed conditions, fault recovery under high-speed conditions is more complex. To avoid triggering system instability during fault recovery, this application uses monitoring of the motor's three-phase current, the motor controller's DC bus voltage, and the motor speed to determine the conditions for exiting fault recovery control. When the fault recovery conditions are not met, a designed exit mechanism stops fault recovery control, thereby protecting driving safety. The electric vehicle drive motor system safety state fault recovery control method provided in this application is implemented based on the motor controller, without involving changes to the system hardware, and does not increase system design and manufacturing costs. It also has advantages such as simple implementation, strong portability, and wide applicability, thus possessing good engineering application value.
[0159] The drive motor system safety state fault recovery control method proposed in this application obtains the current motor speed, current DC bus voltage, and current motor temperature. Based on the current DC bus voltage and current motor temperature, a speed condition classification threshold is obtained by looking up a preset voltage-temperature-high and low speed threshold table according to the current speed. The current speed condition of the motor is determined based on the current speed and the speed condition classification threshold. Upon receiving a fault recovery command, a target fault recovery control strategy is determined based on the current speed condition, and fault recovery is performed according to the target fault recovery control strategy. This solves the problem that when the drive system of an electric vehicle enters ASC (Active Short Circuit) or SPO (Power Off PWM Output) state under fault conditions, it easily causes interruption of drive system output power, makes it difficult to exit the safe state, and limits the fault recovery strategy, seriously affecting the driving experience of the occupants. It achieves rapid recovery of drive system power output and rapid recovery after a fault, enabling timely exit from the safe state and improving the driving experience of the occupants while ensuring driving safety.
[0160] Next, with reference to the accompanying drawings, the drive motor system safety state fault recovery control device proposed according to the embodiments of this application is described.
[0161] Figure 10 This is a block diagram of a drive motor system safety state fault recovery control device according to an embodiment of this application.
[0162] like Figure 10 As shown, the drive motor system safety status fault recovery control device 10 includes: an acquisition module 100, an operating condition judgment module 200, and a fault recovery control module 300.
[0163] The system includes: an acquisition module 100 for acquiring the current motor speed, current DC bus voltage, and current motor temperature; an operating condition judgment module 200 for obtaining a speed operating condition classification threshold from a preset voltage-temperature-high / low speed threshold table based on the current DC bus voltage and current motor temperature, and determining the current motor speed operating condition based on the current speed and the speed operating condition classification threshold; and a fault recovery control module 300 for determining a target fault recovery control strategy based on the current speed operating condition when a fault recovery command is received, and performing fault recovery based on the target fault recovery control strategy.
[0164] Optionally, in some embodiments, the current speed condition is the first speed condition, and the fault recovery control module 300 is further configured to: set the control signals of the six bridge arms of the IGBT power module to zero, so that the drive motor system enters the SPO safety state, and ensure that the vector control of the motor is in a stopped state; after a first preset duration, stop setting the control signals of the six bridge arms of the IGBT power module to zero, and control the six bridge arms of the IGBT power module according to the preset control signals of the six bridge arms of the IGBT power module; after a second preset duration, control the drive motor system to enter the 0 torque output state through the preset dq axis current loop adjustment; and after a third preset duration, perform fault recovery based on the preset first gradient control strategy.
[0165] Optionally, in some embodiments, before controlling the six arms of the IGBT power module according to the preset six-arm control signals of the IGBT power module, the fault recovery control module 300 is further configured to: acquire the final torque command issued by the motor controller, the actual d-axis current and the actual q-axis current of the motor; determine the vector control d-axis current and the vector control q-axis current of the motor according to the final torque command and the current speed; obtain the d-axis voltage command based on the actual d-axis current and the vector control d-axis current based on the first pi regulator, and obtain the q-axis voltage command based on the actual q-axis current and the vector control q-axis current based on the second pi regulator; and perform coordinate transformation and space vector pulse width modulation on the d-axis voltage command and the q-axis voltage command to obtain the preset six-arm control signals of the IGBT power module.
[0166] Optionally, in some embodiments, where the current speed condition is the second speed condition, the fault recovery control module 300 is further configured to: set the six-way bridge arm control signals of the IGBT power module to zero, enabling the drive motor system to enter the SPO safe state, and ensuring that the vector control of the motor is in a stopped state; after a fourth preset duration, set the six-way bridge arm control signals of the IGBT power module to zero, enabling the drive motor system to enter the SPO safe state; after a fifth preset duration, adjust the d-axis current of the vector control according to the actual d-axis current based on a preset current adjustment strategy, and adjust the q-axis current of the vector control according to the actual q-axis current; after a sixth preset duration, obtain the d-axis current command and q-axis current command when the final torque command is 0, and based on a preset gradient limiting strategy, transition the adjusted vector control d-axis current to the current corresponding to the d-axis current command, and transition the adjusted vector control q-axis current to the current corresponding to the q-axis current command; after a seventh preset duration, perform fault recovery based on a preset second gradient control strategy.
[0167] Optionally, in some embodiments, the fault recovery control module 300 is further configured to: determine whether the current speed meets the first recovery exit condition, or whether the current DC bus voltage meets the second recovery exit condition, or whether the current motor temperature meets the third recovery exit condition; if the current speed meets the first recovery exit condition, or the current DC bus voltage meets the second recovery exit condition, or the current motor temperature meets the third recovery exit condition, then exit the fault recovery.
[0168] Optionally, in some embodiments, the operating condition judgment module 200 is further configured to: determine the first boundary voltage and the second boundary voltage of the voltage range in which the current DC bus voltage is located, and the first boundary temperature and the second boundary temperature of the temperature range in which the current motor temperature is located; obtain a first speed linear difference intermediate value based on the first high and low speed thresholds corresponding to the current DC bus voltage, the first boundary voltage, and the first boundary temperature, and the second high and low speed thresholds corresponding to the second boundary voltage and the second boundary temperature; obtain a second speed linear difference intermediate value based on the third high and low speed thresholds corresponding to the current DC bus voltage, the first boundary voltage, and the first boundary temperature, and the fourth high and low speed thresholds corresponding to the second boundary voltage and the second boundary temperature; obtain an initial value of the speed threshold based on the current motor temperature, the first boundary temperature, the second boundary temperature, the first speed linear difference intermediate value, and the second speed linear difference intermediate value; and obtain a speed operating condition division threshold by compensating the initial value of the speed threshold based on a preset compensation strategy.
[0169] Optionally, in some embodiments, before obtaining the speed condition classification threshold by looking up a preset voltage-temperature-high and low speed threshold table based on the current DC bus voltage and current motor temperature, the operating condition judgment module 200 is further configured to: determine multiple DC bus voltages at the input terminal of the motor controller based on the minimum and maximum output voltages of the power battery; determine multiple test temperatures of the motor based on the minimum and maximum operating temperatures of the motor; control the drive motor system to enter the SPO safe state, and perform speed threshold tests on the motor based on multiple DC bus voltages and multiple test temperatures according to a preset speed threshold test strategy to obtain a preset voltage-temperature-high and low speed threshold table.
[0170] It should be noted that the foregoing explanation of the embodiment of the drive motor system safety state fault recovery control method also applies to the drive motor system safety state fault recovery control device of this embodiment, and will not be repeated here.
[0171] The drive motor system safety state fault recovery control device proposed in this application acquires the current motor speed, current DC bus voltage, and current motor temperature. Based on the current DC bus voltage and current motor temperature, it looks up a preset voltage-temperature-high / low speed threshold table to obtain a speed condition classification threshold, and determines the current motor speed condition based on the current speed and the speed condition classification threshold. Upon receiving a fault recovery command, it determines a target fault recovery control strategy based on the current speed condition and performs fault recovery according to the target fault recovery control strategy. This solves the problem that when the drive system of an electric vehicle enters ASC (Active Short Circuit) or SPO (Power Off PWM Output) state under fault conditions, it easily causes interruption of drive system output power, makes it difficult to exit the safe state, and limits the fault recovery strategy, seriously affecting the driving experience of the occupants. It achieves rapid recovery of drive system power output and rapid recovery after a fault, enabling timely exit from the safe state and improving the driving experience of the occupants while ensuring driving safety.
[0172] Figure 11 A schematic diagram of the structure of a vehicle provided in an embodiment of this application. The vehicle may include:
[0173] The memory 1101, the processor 1102, and the computer program stored on the memory 1101 and executable on the processor 1102.
[0174] When the processor 1102 executes the program, it implements the drive motor system safety state fault recovery control method provided in the above embodiments.
[0175] Furthermore, the vehicle also includes:
[0176] Communication interface 1103 is used for communication between memory 1101 and processor 1102.
[0177] The memory 1101 is used to store computer programs that can run on the processor 1102.
[0178] The memory 1101 may include high-speed RAM memory, and may also include non-volatile memory, such as at least one disk storage device.
[0179] If the memory 1101, processor 1102, and communication interface 1103 are implemented independently, then the communication interface 1103, memory 1101, and processor 1102 can be interconnected via a bus to complete communication between them. The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. The bus can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 11 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.
[0180] Optionally, in a specific implementation, if the memory 1101, processor 1102, and communication interface 1103 are integrated on a single chip, then the memory 1101, processor 1102, and communication interface 1103 can communicate with each other through an internal interface.
[0181] The processor 1102 may be a central processing unit (CPU), an application specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of this application.
[0182] This application also provides a computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the above-described drive motor system safety state fault recovery control method.
[0183] In the description of this specification, the references to terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of this application. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples. Moreover, without contradiction, those skilled in the art can combine and integrate the different embodiments or examples described in this specification, as well as the features of different embodiments or examples.
[0184] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one of that feature. In the description of this application, "N" means at least two, such as two, three, etc., unless otherwise explicitly specified.
[0185] Any process or method described in the flowchart or otherwise herein can be understood as representing a module, segment, or portion of code comprising one or more N executable instructions for implementing custom logic functions or processes, and the scope of the preferred embodiments of this application includes additional implementations in which functions may be performed not in the order shown or discussed, including substantially simultaneously or in reverse order depending on the functions involved, as should be understood by those skilled in the art to which embodiments of this application pertain.
[0186] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as a sequenced list of executable instructions for implementing logical functions, and can be embodied in any computer-readable storage medium for use by, or in conjunction with, an instruction execution system, apparatus, or device (such as a computer-based system, a processor-included system, or other system that can fetch and execute instructions from, an instruction execution system, apparatus, or device). For the purposes of this specification, "computer-readable storage medium" can be any means that can contain, store, communicate, propagate, or transmit programs for use by, or in conjunction with, an instruction execution system, apparatus, or device. More specific examples (a non-exhaustive list) of computer-readable storage media include: an electrical connection having one or more wires (electronic device), a portable computer disk drive (magnetic device), random access memory (RAM), read-only memory (ROM), erasable and editable read-only memory (EPROM or flash memory), fiber optic devices, and portable optical disc read-only memory (CDROM). Alternatively, the computer-readable storage medium could be paper or other suitable media on which the program can be printed, since the program can be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, interpreting, or otherwise processing as necessary, and then stored in a computer memory.
[0187] It should be understood that the various parts of this application can be implemented using hardware, software, firmware, or a combination thereof. In the above embodiments, the N steps or methods can be implemented using software or firmware stored in memory and executed by a suitable instruction execution system. For example, if implemented in hardware as in another embodiment, it can be implemented using any one or a combination of the following techniques known in the art: discrete logic circuits having logic gates for implementing logical functions on data signals, application-specific integrated circuits (ASICs) having suitable combinational logic gates, programmable gate arrays (PGAs), field-programmable gate arrays (FPGAs), etc.
[0188] Those skilled in the art will understand that all or part of the steps of the methods in the above embodiments can be implemented by a program instructing related hardware. The program can be stored in a computer-readable storage medium, and when executed, the program includes one or a combination of the steps of the method embodiments.
[0189] Furthermore, the functional units in the various embodiments of this application can be integrated into a processing module, or each unit can exist physically separately, or two or more units can be integrated into a module. The integrated module can be implemented in hardware or as a software functional module. If the integrated module is implemented as a software functional module and sold or used as an independent product, it can also be stored in a computer-readable storage medium.
[0190] The computer-readable storage medium mentioned above may be a read-only memory, a magnetic disk, or an optical disk, etc. Although embodiments of this application have been shown and described above, it is understood that the above embodiments are exemplary and should not be construed as limiting this application. Those skilled in the art can make changes, modifications, substitutions, and variations to the above embodiments within the scope of this application.
Claims
1. A method for restoring safety status fault control of a drive motor system, characterized in that, Includes the following steps: Obtain the current motor speed, current DC bus voltage, and current motor temperature; Based on the current DC bus voltage and the current motor temperature, the speed condition classification threshold is obtained by looking up the current speed from the preset voltage-temperature-high and low speed threshold table, and the current speed condition of the motor is determined based on the current speed and the speed condition classification threshold. Upon receiving a fault recovery command, a target fault recovery control strategy is determined based on the current operating speed, and fault recovery is performed according to the target fault recovery control strategy.
2. The method according to claim 1, characterized in that, The current operating speed condition is the first operating speed condition. The step of determining a target fault recovery control strategy based on the current operating speed condition and performing fault recovery according to the target fault recovery control strategy includes: Set the 6-way bridge arm control signal of the IGBT power module to zero, so that the drive motor system enters the SPO safe state, and ensure that the vector control of the motor is in the stopped state. After a first preset duration, the control signals of the 6 bridge arms of the IGBT power module are stopped from being set to zero, and the 6 bridge arms of the IGBT power module are controlled according to the preset control signals of the 6 bridge arms of the IGBT power module. After a second preset duration, the drive motor system is adjusted and controlled to enter a 0 torque output state through a preset dq axis current loop. After a third preset duration, fault recovery is performed based on the preset first gradient control strategy.
3. The method according to claim 2, characterized in that, Before controlling the six bridge arms of the IGBT power module according to the preset six-bridge arm control signals of the IGBT power module, the following steps are also included: Obtain the final torque command issued by the motor controller, the actual d-axis current and the actual q-axis current of the motor; The vector control d-axis current and vector control q-axis current of the motor are determined based on the final torque command and the current speed. Based on the first pi regulator, a d-axis voltage command is obtained according to the actual d-axis current and the vector control d-axis current; and based on the second pi regulator, a q-axis voltage command is obtained according to the actual q-axis current and the vector control q-axis current. The d-axis voltage command and the q-axis voltage command are subjected to coordinate transformation and space vector pulse width modulation to obtain the preset 6-arm control signals of the IGBT power module.
4. The method according to claim 3, characterized in that, The current operating speed condition is the second operating speed condition. The step of determining a target fault recovery control strategy based on the current operating speed condition and performing fault recovery according to the target fault recovery control strategy includes: Set the 6-way bridge arm control signal of the IGBT power module to zero, so that the drive motor system enters the SPO safe state, and ensure that the vector control of the motor is in the stopped state. After a fourth preset duration, the control signals of the 6 bridge arms of the IGBT power module are set to zero, so that the drive motor system enters the SPO safe state. After a fifth preset time delay, based on a preset current adjustment strategy, the vector control d-axis current is adjusted according to the actual d-axis current, and the vector control q-axis current is adjusted according to the actual q-axis current. After a sixth preset duration, the d-axis current command and q-axis current command when the final torque command is 0 are obtained. Based on a preset gradient limiting strategy, the adjusted vector control d-axis current is transitioned to the current corresponding to the d-axis current command, and the adjusted vector control q-axis current is transitioned to the current corresponding to the q-axis current command. After a seventh preset duration, fault recovery is performed based on the preset second gradient control strategy.
5. The method according to claim 4, characterized in that, When performing fault recovery according to the target fault recovery control strategy, the method further includes: Determine whether the current rotational speed meets the first recovery exit condition, or whether the current DC bus voltage meets the second recovery exit condition, or whether the current motor temperature meets the third recovery exit condition; If the current rotational speed meets the first recovery exit condition, or the current DC bus voltage meets the second recovery exit condition, or the current motor temperature meets the third recovery exit condition, then the fault recovery process exits.
6. The method according to claim 1, characterized in that, The step of obtaining the speed condition classification threshold based on the current DC bus voltage and the current motor temperature, and by looking up the current speed from a preset voltage-temperature-high / low speed threshold table, includes: Determine the first boundary voltage and the second boundary voltage of the voltage range in which the current DC bus voltage is located, and the first boundary temperature and the second boundary temperature of the temperature range in which the current motor temperature is located; Based on the current DC bus voltage, the first boundary voltage and the first boundary temperature corresponding to the first high and low speed thresholds, and the second boundary voltage and the second boundary temperature corresponding to the second high and low speed thresholds, the intermediate value of the first speed linear difference is obtained; Based on the current DC bus voltage, the third high and low speed threshold corresponding to the first boundary voltage and the first boundary temperature, and the fourth high and low speed threshold corresponding to the second boundary voltage and the second boundary temperature, the intermediate value of the second speed linear difference is obtained. The initial value of the speed threshold is obtained based on the current motor temperature, the first boundary temperature, the second boundary temperature, the intermediate value of the first linear difference of speed, and the intermediate value of the second linear difference of speed. Based on a preset compensation strategy, the initial value of the rotational speed threshold is compensated to obtain the rotational speed condition division threshold.
7. The method according to claim 1 or 6, characterized in that, Before obtaining the speed condition classification threshold from a preset voltage-temperature-high / low speed threshold table based on the current DC bus voltage and the current motor temperature, the process also includes: Based on the minimum and maximum output voltage of the power battery, determine the multiple DC bus voltages at the input of the motor controller; Based on the motor's minimum and maximum operating temperatures, multiple test temperatures for the motor are determined. The drive motor system is controlled to enter the SPO safe state, and based on the preset speed threshold test strategy, the speed threshold test is performed on the motor based on the multiple DC bus voltages and the multiple test temperatures to obtain the preset voltage-temperature-high and low speed threshold table.
8. A safety state fault recovery control device for a drive motor system, characterized in that, include: The acquisition module is used to acquire the current motor speed, current DC bus voltage, and current motor temperature; The operating condition judgment module is used to obtain the speed operating condition classification threshold by looking up a table from a preset voltage-temperature-high and low speed threshold table based on the current DC bus voltage and the current motor temperature, and to determine the current speed operating condition of the motor based on the current speed and the speed operating condition classification threshold. The fault recovery module is used to determine a target fault recovery control strategy based on the current speed condition when a fault recovery command is received, and to perform fault recovery according to the target fault recovery control strategy.
9. A vehicle, characterized in that, include: The system includes a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the drive motor system safety state fault recovery control method as described in any one of claims 1-7.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, The program is executed by the processor to implement the drive motor system safety state fault recovery control method as described in any one of claims 1-7.