Fault monitoring circuit and method

By introducing fault monitoring circuits with detection and latching units into the DSP system, the problem of ambiguous fault location caused by the limited TZ pins of the DSP is solved, enabling rapid fault response and accurate fault location, and reducing maintenance costs.

CN120949650APending Publication Date: 2025-11-14EAST GRP CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511096278.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-06
Publication Date
2025-11-14

AI Technical Summary

Technical Problem

In existing technologies, the limited number of TZ pins in a digital signal processor (DSP) cannot accurately monitor multiple voltage and current signals simultaneously, leading to ambiguous fault location and increasing maintenance difficulty and time costs.

Method used

A fault monitoring circuit was designed. By combining a detection unit and a latching unit, the independent fault signal detection and latching of each monitored object can be achieved, and the controller can accurately locate the fault source.

Benefits of technology

It enables rapid fault response and precise fault location, reduces maintenance time and costs, and improves system scalability and maintainability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120949650A_ABST
    Figure CN120949650A_ABST
Patent Text Reader

Abstract

The invention discloses a fault monitoring circuit and method, and the monitoring circuit comprises a controller which is provided with a first signal end and a second signal end; the protection circuit comprises a plurality of detection units, the input ends of the detection units are electrically connected with the corresponding monitoring objects respectively, and the output ends of the detection units are electrically connected with the first signal end; the detection unit outputs a corresponding signal to the first signal end according to the size relationship between a monitoring signal output by a monitoring object and a first reference signal; and the monitoring circuit comprises a plurality of latch units electrically connected with the output end of each detection unit, the setting ends of the plurality of latch units are electrically connected with the output end of one detection unit, and the output ends of the plurality of latch units are electrically connected with different second signal ends. The fault monitoring circuit can rapidly trigger a protection mechanism and cut off a fault circuit when a fault occurs, so that a system is prevented from being damaged due to abnormal conditions such as overvoltage or overcurrent, and which monitored object the fault is caused by is accurately judged.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of circuit fault detection technology, and in particular to a fault monitoring circuit and method. Background Technology

[0002] In modern electronic control systems, overvoltage and overcurrent protection is crucial for ensuring safe and reliable system operation. Control systems based on digital signal processors (DSPs) are widely used in industrial control, power electronics, and new energy vehicles. Traditional circuit protection schemes typically utilize the DSP's built-in Trip Zone (TZ) pin in conjunction with a hysteresis comparator to achieve hardware protection. The hysteresis comparator compares the voltage or current signal of the monitored object with a reference signal, outputting a corresponding protection signal to the TZ pin, thereby triggering the DSP's protection mechanism to quickly disconnect the faulty circuit and prevent system damage.

[0003] However, existing technologies have significant limitations. Taking the TMS320F28377S as an example, it only has a limited number of TZ pins (typically three), while actual electronic control systems often require simultaneous monitoring of voltage and current signals from multiple locations. When the number of monitoring points exceeds the number of TZ pins, a common practice is to connect the output signals of multiple hysteresis comparators to the same TZ pin, achieving hardware protection through a logical "OR" operation. Although this method can quickly respond to faults and protect the system at the hardware level, because fault signals from multiple monitoring points are merged, it is impossible to accurately distinguish which specific branch or monitored object caused the fault. This ambiguity in fault location is detrimental to the analysis of system operating status and subsequent troubleshooting, increasing maintenance difficulty and time costs. Summary of the Invention

[0004] The purpose of this invention is to provide a fault monitoring circuit and method that, while ensuring rapid response of hardware protection, achieves accurate location of fault signals and status recording, in order to solve the above-mentioned technical problems.

[0005] To achieve the above objectives, the present invention provides a fault monitoring circuit for an electronic control system, the monitoring circuit comprising: The controller has a first signal terminal for reading fault flags and several second signal terminals for reading fault status. The protection circuit includes several detection units, the input terminals of which are electrically connected to corresponding monitored objects, and the output terminals of which are electrically connected to the first signal terminal; the detection units output corresponding signals to the first signal terminal according to the magnitude relationship between the monitoring signal output by the monitored object and the first reference signal. The monitoring circuit includes a plurality of latching units electrically connected to the output terminal of each of the detection units. The set terminals of the plurality of latching units are electrically connected to the output terminal of one of the detection units. The output terminals of the plurality of latching units are electrically connected to different second signal terminals. The latching units are used to output corresponding signals to the second signal terminals according to the logical relationship between the signals output by the detection units and the second reference signals. When the detection unit outputs a signal indicating that the monitored object is in a fault state, the latching unit generates and latches a fault signal.

[0006] Preferably, the detection unit includes a comparator and a diode. The two input terminals of the comparator are used to receive the monitoring signal and the first reference signal, respectively. The output terminal of the comparator is electrically connected to the first signal terminal through the diode, and the positive terminal of the diode is electrically connected to the first signal terminal. The protection circuit further includes a first voltage source, which is electrically connected to the first signal terminal through a first resistor.

[0007] Preferably, the inverting input of the comparator is used to receive the monitoring signal, the non-inverting input of the comparator is used to receive the first reference signal, and a feedback network is provided between the output and the non-inverting input of the comparator.

[0008] Preferably, the latching unit includes an RS flip-flop.

[0009] Preferably, it also includes a second voltage source, which is electrically connected to the set terminal of the corresponding latch unit through a second resistor.

[0010] Preferably, the controller further has a third signal terminal for issuing a reset signal, and the monitoring circuit further includes a reset circuit, one end of which is electrically connected to the third signal terminal, and the other end of which is electrically connected to the reset terminals of a plurality of latch units. The reset circuit is used to reset the latch units according to the reset signal issued by the third signal terminal.

[0011] Preferably, the reset circuit includes a third voltage source and a switching transistor, one of the conducting terminals of the switching transistor is grounded, the other conducting terminal of the switching transistor is electrically connected to the reset terminal of the latch unit and the third voltage source respectively, and the control terminal of the switching transistor is electrically connected to the third signal terminal.

[0012] Preferably, the output terminals of the plurality of latching units are electrically connected to the plurality of second signal terminals through a level conversion circuit.

[0013] The present invention also provides a fault monitoring method for an electronic control system, the monitoring method comprising: A monitoring circuit is constructed, which includes a controller, a protection circuit, and a monitoring circuit; The controller has a first signal terminal for reading fault flags and several second signal terminals for reading fault status. The protection circuit includes several detection units. The input terminals of the detection units are electrically connected to the corresponding monitored objects, and the output terminals of the detection units are electrically connected to the first signal terminal. The detection units output corresponding signals to the first signal terminal according to the relationship between the monitoring signal output by the monitored object and the first reference signal. The monitoring circuit includes several latching units electrically connected to the output terminal of each of the detection units. The set terminals of the several latching units are electrically connected to the output terminal of one of the detection units. The output terminals of the several latching units are electrically connected to different second signal terminals. The latching units are used to output corresponding signals to the second signal terminals according to the logical relationship between the signal output by the detection unit and the second reference signal. When the detection unit outputs a signal indicating that the monitored object is in a fault state, the latching unit generates and latches a fault signal. The controller reads the level state of the first signal terminal in real time. When the first signal terminal flips to the first level state corresponding to the fault state of the monitored object, a preset fault handling operation method is triggered. After the fault handling operation method is triggered, the controller scans the status of each of the second signal terminals and confirms the monitored object that is currently in a fault state based on the level status of each of the second signal terminals.

[0014] Preferably, the controller further has a third signal terminal for issuing a reset signal, and the monitoring circuit further includes a reset circuit, one end of which is electrically connected to the third signal terminal, and the other end of which is electrically connected to the reset terminals of a plurality of the latch units; the monitoring method further includes a reset method for resetting the latch units. The controller reads the level state of the first signal terminal. When the first signal terminal is in the second level state corresponding to the normal state of the monitored object, it sends a reset start signal to the reset circuit through the third signal terminal and starts a preset timer at the same time. The system scans the level states of each of the second signal terminals. If all of them correspond to the normal state of the monitored object, a reset end signal is sent to the reset circuit through the third signal terminal. If the level state of any of the second signal terminals corresponds to the fault state of the monitored object, it determines whether the timer has overflowed. If not, the system rescans the level states of each of the second signal terminals. If so, an indication signal is output, indicating that the current monitoring circuit has an abnormality.

[0015] Compared with existing technologies, the fault monitoring circuit provided by the present invention, through a detection unit in the protection circuit, compares the signal of the monitored object with a first reference signal and outputs the result to the first signal terminal of the controller. This enables the protection mechanism to be triggered quickly when a fault occurs, cutting off the faulty circuit and preventing system damage due to abnormal conditions such as overvoltage or overcurrent. Furthermore, when the detection unit outputs a signal indicating a fault state, the latching unit generates and latches the fault signal, and simultaneously outputs this signal to the second signal terminal of the controller. Since each latching unit corresponds to a specific monitored object or branch and outputs to different second signal terminals, the controller can accurately determine which monitored object caused the fault by reading the signal status of each second signal terminal. This precise fault location capability significantly improves the efficiency of system operation status analysis and fault diagnosis, reducing maintenance time and costs. Attached Figure Description

[0016] Figure 1 This is a block diagram of the fault monitoring circuit in an embodiment of the present invention.

[0017] Figure 2 This is a schematic diagram of the fault monitoring circuit in an embodiment of the present invention.

[0018] Figure 3 This is a flowchart of the reset method in an embodiment of the present invention. Detailed Implementation

[0019] To illustrate the technical content, structural features, objectives, and effects of the present invention in detail, the following description is provided in conjunction with the embodiments and accompanying drawings.

[0020] This embodiment discloses a fault monitoring circuit for use in an electronic control system, such as... Figure 1 and Figure 2 The monitoring circuit includes a controller KC, a protection circuit 10, and a monitoring circuit 11.

[0021] The controller KC has a first signal terminal TZ for reading fault flags and several second signal terminals IOX for reading fault status. Figure 1 It has three second signal terminals IOX, namely IO1, IO2, and IO3.

[0022] The protection circuit 10 includes several detection units 100. The input terminals of each detection unit 100 are electrically connected to a corresponding monitored object, and the output terminals of each detection unit 100 are electrically connected to a first signal terminal TZ. Each detection unit 100 outputs a corresponding signal to the first signal terminal TZ based on the magnitude relationship between the monitoring signal output by the monitored object and the first reference signal. Figure 1 and Figure 2The system has three detection units 100, each corresponding to a monitored object. Therefore, there are three monitoring signals, namely V1, V2, and V3, and correspondingly, there are three first reference signals, namely C1, C2, and C3.

[0023] The monitoring circuit 11 includes several latching units U2 that are electrically connected to the output terminal of each detection unit 100. The set terminal S of the several latching units U2 is electrically connected to the output terminal of one of the detection units 100. The output terminals of the several latching units U2 are electrically connected to different second signal terminals IOX. The latching unit U2 is used to output a corresponding signal to the second signal terminal IOX according to the logical relationship between the signal output by the detection unit 100 and the second reference signal. When the detection unit 100 outputs a signal that the monitored object is in a fault state, the latching unit U2 generates and latches the fault signal to ensure continuous indication of the fault state.

[0024] The fault monitoring circuit provided in this embodiment compares the signal of the monitored object with the first reference signal through the detection unit 100 in the protection circuit 10, and outputs the result to the first signal terminal TZ of the controller KC. It can quickly trigger the protection mechanism when a fault occurs, cut off the fault circuit, and avoid damage to the system due to abnormal conditions such as overvoltage or overcurrent.

[0025] When the detection unit 100 outputs a signal indicating a fault state, the latching unit U2 generates and latches the fault signal, and simultaneously outputs the signal to the second signal terminal IOX of the controller KC.

[0026] Since each latch unit U2 corresponds to a specific monitored object or branch and outputs to different second signal terminals IOX, the controller KC can accurately determine which monitored object caused the fault by reading the signal status of each second signal terminal IOX. This precise fault location capability significantly improves the efficiency of system operation status analysis and fault diagnosis, and reduces maintenance time and costs.

[0027] Because the second signal terminal IOX can use a low-speed interface or a general-purpose I / O port, without relying on the DSP's high-speed dedicated pins, this solution overcomes the limitations of chip hardware resources, allowing system designers to flexibly increase the number of monitoring points according to actual needs. This design flexibility reduces hardware design difficulty and cost, while improving system scalability.

[0028] The design of latch unit U2 allows fault signals to be latched and held after triggering. Even if the fault signal disappears briefly, operators can still obtain historical fault information by reading the output status of the second signal terminal IOX. This feature avoids the problem of difficulty in capturing fault signals due to their transient nature in traditional solutions, providing operators with ample time for fault analysis and handling, and further improving the maintainability of the system.

[0029] In the above embodiments, the controller KC can be a variety of microcontrollers or digital signal processors (DSPs), such as TMSFS or other processors with similar functions. Its first signal terminal TZ can correspond to the hardware protection interface such as the TZ pin of the DSP, while the second signal terminal IOX can correspond to a low-speed interface or a general-purpose I / O port.

[0030] The monitored object can be any physical quantity in the electrical control system that needs to be monitored, such as voltage, current, and temperature. The first reference signal can be adjusted according to actual conditions to adapt to different fault thresholds. The power supply method for the entire circuit can also adopt different voltage sources and power management schemes according to system requirements.

[0031] Based on the above monitoring circuit, the present invention also discloses a fault monitoring method, the process of which is as follows: The controller KC reads the level state of the first signal terminal TZ in real time. When the first signal terminal TZ flips to the first level state (such as high level) corresponding to the fault state of the monitored object, the preset fault handling operation method is triggered. After the fault handling operation method is triggered, the controller KC scans the status of each second signal terminal IOX and confirms the monitored object that is currently in a fault state based on the level status of each second signal terminal IOX.

[0032] In the fault monitoring method provided in this embodiment, the controller KC reads the level state of the first signal terminal TZ in real time, realizing rapid fault response and hardware-level protection. When the first signal terminal TZ indicates a fault, the controller KC can quickly trigger preset fault handling operations, such as cutting off the power or issuing an alarm, thereby preventing further damage to the system. More importantly, after confirming the occurrence of a fault, the controller KC can further scan the state of each second signal terminal IOX.

[0033] In the above embodiments, fault handling methods may include, but are not limited to: immediately shutting off the relevant power supply, switching to the backup system, issuing audible and visual alarms, recording fault logs, and sending data to the remote monitoring center. The controller KC can scan the status of the second signal terminal IOX using polling, interruption, or other real-time data acquisition methods to ensure timely acquisition of fault information.

[0034] On the other hand, such as Figure 2The detection unit 100 includes a comparator U1 and a diode D1. The two input terminals of the comparator U1 are used to receive a monitoring signal and a first reference signal, respectively. The output terminal of the comparator U1 is electrically connected to the first signal terminal TZ through the diode D1, and the positive terminal of the diode D1 is electrically connected to the first signal terminal TZ. The protection circuit 10 also includes a first voltage source VCC1, which is electrically connected to the first signal terminal TZ through a first resistor R1.

[0035] In this embodiment, when all monitored objects are in a normal state, the outputs of all detection units 100 are in a high-impedance state or at a high level, and the first signal terminal TZ is pulled up to a high level under the action of the first voltage source VCC1 and the first resistor R1. When any monitored object is in a fault state, the comparator U1 of the corresponding detection unit 100 outputs a low level, which pulls the first signal terminal TZ low through the diode D1, thereby indicating to the controller KC that a fault has occurred.

[0036] This invention achieves effective detection and transmission of fault signals by introducing a comparator U1 and a diode D1 into the detection unit 100, along with a first voltage source VCC1 and a first resistor R1. Diode D1 effectively prevents interference to the first signal terminal TZ when the comparator U1 outputs a high-level signal, ensuring the unidirectionality and stability of the signal. The cooperation of the first voltage source VCC1 and the first resistor R1 ensures that the first signal terminal TZ remains at a high level when there is no fault, providing a clear reference for the low-level indication of the fault signal. This design not only improves the response speed and accuracy of fault detection but also enhances the robustness and reliability of the circuit, avoiding signal interference problems that may occur in traditional solutions.

[0037] In the above implementation, comparator U1 can be a high-speed, low-power voltage comparator, such as an LM or TLV, to ensure a fast response to monitoring signals. Diode D1 can be a Schottky diode or a common silicon diode, and its forward voltage drop and reverse leakage current should meet the circuit design requirements to ensure signal transmission efficiency and isolation. The voltage value of the first voltage source VCC1 should be compatible with the logic level of the first signal terminal TZ of the controller KC, for example, 3.3V. The resistance value of the first resistor R1 should be reasonably selected to provide sufficient pull-up current without causing excessive power consumption, generally between several thousand ohms and tens of thousands of ohms.

[0038] On the other hand, the inverting input of comparator U1 is used to receive the monitoring signal, the non-inverting input of comparator U1 is used to receive the first reference signal, and a feedback network is also provided between the output of comparator U1 and the non-inverting input.

[0039] This feedback network typically introduces hysteresis characteristics into comparator U1 through positive feedback, so that when the monitoring signal crosses the protection threshold (i.e., the first reference signal), the comparator output will flip instantly and will not recover immediately, preventing the comparator output from continuously flipping and jumping around the protection value.

[0040] In the above implementation, the feedback network typically consists of one or more resistors, the value of which determines the range of the hysteresis voltage. The hysteresis voltage setting should be optimized based on the characteristics of the monitored signal and the system's tolerance to noise. For different monitored objects and application scenarios, the parameters of the feedback network can be adjusted to achieve the best hysteresis effect.

[0041] Specifically, the feedback network includes a third resistor R3 and a fourth resistor R4 connected in series. The third resistor R3 is grounded, and the fourth resistor R4 is connected to the output of comparator U1. The node between the third resistor R3 and the fourth resistor R4 is connected to the non-inverting input of comparator U1. In addition, the non-inverting input of comparator U1 also receives a first reference signal through a fifth resistor R5.

[0042] On the other hand, latch unit U2 includes an RS flip-flop.

[0043] The RS flip-flop has two inputs: a set input S and a reset input R, and one output Q and an inverting output QNOT.

[0044] In this embodiment, the set terminal S of the RS flip-flop is electrically connected to the output terminal of the corresponding detection unit 100. When the detection unit 100 outputs a signal indicating that the monitored object is in a fault state (e.g., a low level), this signal triggers the set terminal S of the RS flip-flop, causing the output terminal Q of the RS flip-flop to flip and remain in a high level state, thereby generating and latching a fault signal. Even if the output signal of the detection unit 100 returns to normal (e.g., a high level), as long as the reset terminal R of the RS flip-flop is not activated, its output terminal Q will remain in the fault state until it is cleared by an external reset signal.

[0045] Specifically, for any latch unit U2, its operating state is as follows: When the reset terminal R is high and the set terminal S is high, the output terminal Q of the latch unit U2 remains in the previous state; When the reset terminal R is high and the set terminal S is low, the output terminal Q is high. When the reset terminal R is low and the set terminal S is high, the output terminal Q is low. When the reset terminal R is low and the set terminal S is low, the output terminal Q is high.

[0046] Therefore, for any latch unit U2, when it receives a low-level signal from the comparator U1, the output terminal Q flips to a high level. Subsequently, when the reset terminal R does not change, even if the comparator U1 outputs a high level to the set terminal S, the output terminal Q will remain in the previous state, that is, a high level, thus locking the fault state.

[0047] On the other hand, the fault monitoring circuit also includes a second voltage source VCC2. The second voltage source VCC2 is electrically connected to the set terminal S of the corresponding latch unit U2 through a second resistor R2, so that the output terminal of the detection unit 100 and the second resistor R2 are connected in parallel to the set terminal S of the latch unit U2.

[0048] Specifically, the second voltage source VCC2 is electrically connected to the set terminal S of each latching unit U2 through a second resistor R2. In this way, the output terminal of the detection unit 100 and the second resistor R2 form a parallel structure and are connected together to the set terminal S of the latching unit U2.

[0049] When the detection unit 100 outputs a high level or is in a high impedance state (indicating that the monitored object is normal), the second voltage source VCC2 pulls the set terminal S of the latch unit U2 to a high level through the second resistor R2.

[0050] When the detection unit 100 outputs a low level (indicating a fault in the monitored object), it pulls down the set terminal S of the latch unit U2, causing it to enter the fault trigger state.

[0051] This embodiment effectively solves the problem of uncertain or floating voltage levels at the set terminal S by connecting a second voltage source VCC2 and a second resistor R2 in parallel with the set terminal S of the latch unit U2. When the monitored object is normal, the output of the detection unit 100 may be in a high-impedance state or a high level. At this time, the second voltage source VCC2 ensures that the set terminal S of the latch unit U2 remains at a high level through the second resistor R2, thereby avoiding false triggering.

[0052] When a monitored object malfunctions, the detection unit 100 outputs a low-level signal. This low level can effectively pull down the set terminal S, triggering the latch unit U2 to latch the fault state.

[0053] This design improves the reliability and stability of the latch unit U2, ensuring the accurate capture and retention of fault signals. Even when the detection unit 100 outputs a non-strong drive signal, the latch unit U2 can still operate normally.

[0054] In the above implementation, the voltage value of the second voltage source VCC2 should be compatible with the logic level of the latch unit U2, for example, 5V. The resistance value of the second resistor R2 should be reasonably selected so as to provide sufficient pull-up current without placing an excessive burden on the output capability of the detection unit 100, generally between several thousand ohms and tens of thousands of ohms.

[0055] On the other hand, the controller KC also has a third signal terminal IO4 for issuing a reset signal. The monitoring circuit 11 also includes a reset circuit 110. One end of the reset circuit 110 is electrically connected to the third signal terminal IO4, and the other end of the reset circuit 110 is electrically connected to the reset terminal R of a plurality of latch units U2. The reset circuit 110 is used to reset the latch unit U2 according to the reset signal issued by the third signal terminal IO4.

[0056] Once the fault is cleared, the controller KC can send a reset signal via the third signal terminal IO4. Upon receiving this signal, the reset circuit 110 can simultaneously reset multiple latch units U2, restoring them to their initial normal state. This design significantly improves the system's maintainability and operational efficiency. It avoids the tediousness of manual reset and allows the system to quickly and accurately return to normal monitoring mode after fault clearance, preparing for the next fault detection. Simultaneously, the controller KC's control over the reset process enhances the system's automation and intelligence.

[0057] In the above implementation, the third signal terminal IO4 can be a general-purpose I / O port of the controller KC. The duration of the reset signal should be long enough to ensure that all latch units U2 can be effectively reset.

[0058] Furthermore, the reset circuit 110 includes a third voltage source VCC3 and a switching transistor K. One of the conducting terminals of the switching transistor K is grounded, and the other conducting terminal of the switching transistor K is electrically connected to the reset terminal R of the latch unit U2 and the third voltage source VCC3, respectively. In addition, the control terminal of the switching transistor K is electrically connected to the third signal terminal IO4 through the sixth resistor R6.

[0059] In this embodiment, the switching transistor K can be an NPN transistor or an N-type MOSFET. The third voltage source VCC3 is connected to the reset terminal R of the latch unit U2 through a pull-up resistor R7, ensuring that the reset terminal R is in a normal operating high-level state when the switching transistor K is not conducting. The control terminal of the switching transistor K (e.g., the base of the transistor or the gate of the MOSFET) is electrically connected to the third signal terminal IO4 of the controller KC.

[0060] When the controller KC sends a reset signal (e.g., high level) through the third signal terminal IO4, the switch K turns on, pulling the reset terminal R of the latch unit U2 low, thereby realizing the reset operation.

[0061] This invention utilizes a third voltage source VCC3 and a switching transistor K to construct a reset circuit 110, achieving effective control of the reset terminal R of the latch unit U2. This design offers advantages such as simple structure, low cost, and ease of integration. The switching characteristics of the switching transistor K ensure fast response and stable transmission of the reset signal, avoiding signal jitter during the reset process.

[0062] In this regard, please refer to another preferred embodiment of the present invention. Figure 2 and Figure 3 A reset method was also disclosed: S1: Controller KC reads the level state of the first signal terminal TZ; S2: Determine whether the first signal terminal TZ is in the second level state (such as low level) corresponding to the normal state of the monitored object. If yes, return to S1; otherwise, proceed to S3. S3: Send a reset start signal to the reset circuit 110 through the third signal terminal IO4, and start the preset timer (e.g., 1s) at the same time. S4: Scan the level status of each second signal terminal IOX; S5: Determine whether all second signal terminals IOX are in a state corresponding to the normal state of the monitored object. For example, all of them are low. If so, proceed to S6. If not, for example, if at least one second signal terminal IOX is high, proceed to S7. S6: Send a reset end signal to the reset circuit 110 through the third signal terminal IO4 to complete the reset action of the latch circuit; S7: Determine if the timer has overflowed. If not, return to S4; if yes, proceed to S8.

[0063] S8: Output indicator signal, indicating that there is an abnormality in the current monitoring circuit 11.

[0064] The fault monitoring method provided in this embodiment significantly improves the reliability and security of the system by introducing an intelligent reset process. After fault handling is completed, the system does not immediately reset, but first confirms that the first signal terminal TZ has returned to normal, which ensures that the fault at the hardware level has been resolved. Subsequently, by starting a timer and scanning the second signal terminal IOX multiple times, the system can accurately determine whether all latched faults have been truly resolved, avoiding false resets caused by instantaneous recovery or misjudgment. If a fault signal still exists after the timer overflows, the system will output an abnormality indication, diagnosing the abnormality of the monitoring circuit 11 itself, thereby preventing the system from continuing to operate in an unsafe state, greatly enhancing the overall stability and intelligence level of the system, and reducing potential risks and maintenance costs.

[0065] The preset timer duration should be reasonably set based on the system's required response speed for fault recovery and the duration of the fault, such as from several hundred milliseconds to several seconds. The frequency of scanning the second signal terminal IOX should also be adjusted according to actual needs. Indication signals can manifest as audible and visual alarms, error code displays, log recordings, or uploads to the host computer via a communication interface. To further improve the robustness of the reset method, a limit on the number of retries after a reset failure can be added, or a forced entry into safe mode can be implemented after multiple failed retries.

[0066] On the other hand, the output terminals of several latch units U2 are electrically connected to several second signal terminals IOX through a level conversion circuit U3.

[0067] In this embodiment, to address the mismatch between the output level of latch unit U2 and the input level of the second signal terminal IOX of controller KC, the output terminals of several latch units U2 are electrically connected to their respective second signal terminals IOX via a level conversion circuit U3. The level conversion circuit U3 is a circuit used to convert one logic level signal to another. For example, if latch unit U2 operates at a 5V logic level, while the second signal terminal IOX of controller KC requires a 3.3V logic level, then the level conversion circuit U3 will convert the 5V high level to a 3.3V high level. This conversion ensures that fault signals output by latch unit U2 can be correctly identified and processed by controller KC, without causing errors due to level mismatch.

[0068] This invention effectively solves the compatibility problem between different logic levels by setting a level conversion circuit U3 between the output of the latch unit U2 and the second signal terminal IOX of the controller KC. This allows system designers to more flexibly select devices with different voltage standards without worrying about signal transmission errors or device damage caused by level mismatch. This design improves the system's versatility and interoperability, reduces the complexity of hardware design, and facilitates future system upgrades and expansions.

[0069] In the above embodiments, the level conversion circuit U3 can be implemented in various ways, such as: using a level conversion circuit U3 built with discrete transistors, resistors, and diodes D1; ​​using a dedicated level conversion chip (such as TXSE, SNLVCT, etc.); or using logic gate devices with level conversion functions. The specific selection of the level conversion circuit U3 should be evaluated based on factors such as the required conversion direction (high to low, low to high), signal rate, power consumption, and cost.

[0070] The above-disclosed embodiments are merely preferred embodiments of the present invention and should not be construed as limiting the scope of the present invention. Therefore, any equivalent variations made in accordance with the claims of the present invention are still within the scope of the present invention.

Claims

1. A fault monitoring circuit for use in an electronic control system, characterized in that, The monitoring circuit includes: The controller has a first signal terminal for reading fault flags and several second signal terminals for reading fault status. The protection circuit includes several detection units, the input terminals of which are electrically connected to corresponding monitored objects, and the output terminals of which are electrically connected to the first signal terminal. The detection units output corresponding signals to the first signal terminal according to the magnitude relationship between the monitoring signal output by the monitored object and the first reference signal. The monitoring circuit includes a plurality of latching units electrically connected to the output terminal of each of the detection units. The set terminals of the plurality of latching units are electrically connected to the output terminal of one of the detection units. The output terminals of the plurality of latching units are electrically connected to different second signal terminals. The latching units are used to output corresponding signals to the second signal terminals according to the logical relationship between the signals output by the detection units and the second reference signals. When the detection unit outputs a signal indicating that the monitored object is in a fault state, the latching unit generates and latches a fault signal.

2. The fault monitoring circuit according to claim 1, characterized in that, The detection unit includes a comparator and a diode. The two input terminals of the comparator are used to receive the monitoring signal and the first reference signal, respectively. The output terminal of the comparator is electrically connected to the first signal terminal through the diode, and the positive terminal of the diode is electrically connected to the first signal terminal. The protection circuit also includes a first voltage source, which is electrically connected to the first signal terminal through a first resistor.

3. The fault monitoring circuit according to claim 2, characterized in that, The inverting input of the comparator is used to receive the monitoring signal, the non-inverting input of the comparator is used to receive the first reference signal, and a feedback network is provided between the output and the non-inverting input of the comparator.

4. The fault monitoring circuit according to claim 1, characterized in that, The latch unit includes an RS flip-flop.

5. The fault monitoring circuit according to claim 1, characterized in that, It also includes a second voltage source, which is electrically connected to the set terminal of the corresponding latch unit through a second resistor.

6. The fault monitoring circuit according to claim 1, characterized in that, The controller also has a third signal terminal for issuing a reset signal. The monitoring circuit further includes a reset circuit, one end of which is electrically connected to the third signal terminal, and the other end of which is electrically connected to the reset terminals of a plurality of latch units. The reset circuit is used to reset the latch units according to the reset signal issued by the third signal terminal.

7. The fault monitoring circuit according to claim 6, characterized in that, The reset circuit includes a third voltage source and a switching transistor. One of the conducting terminals of the switching transistor is grounded, and the other conducting terminal of the switching transistor is electrically connected to the reset terminal of the latch unit and the third voltage source, respectively. Furthermore, the control terminal of the switching transistor is electrically connected to the third signal terminal.

8. The fault monitoring circuit according to claim 1, characterized in that, The output terminals of several latch units are electrically connected to several second signal terminals through a level conversion circuit.

9. A fault monitoring method for an electronic control system, characterized in that, The monitoring method includes: A monitoring circuit is constructed, which includes a controller, a protection circuit, and a monitoring circuit; The controller has a first signal terminal for reading fault flags and several second signal terminals for reading fault status. The protection circuit includes several detection units. The input terminals of the detection units are electrically connected to the corresponding monitored objects, and the output terminals of the detection units are electrically connected to the first signal terminal. The detection units output corresponding signals to the first signal terminal according to the relationship between the monitoring signal output by the monitored object and the first reference signal. The monitoring circuit includes several latching units electrically connected to the output terminal of each of the detection units. The set terminals of the several latching units are electrically connected to the output terminal of one of the detection units. The output terminals of the several latching units are electrically connected to different second signal terminals. The latching units are used to output corresponding signals to the second signal terminals according to the logical relationship between the signal output by the detection unit and the second reference signal. When the detection unit outputs a signal indicating that the monitored object is in a fault state, the latching unit generates and latches a fault signal. The controller reads the level state of the first signal terminal in real time. When the first signal terminal flips to the first level state corresponding to the fault state of the monitored object, a preset fault handling operation method is triggered. After the fault handling operation method is triggered, the controller scans the status of each of the second signal terminals and confirms the monitored object that is currently in a fault state based on the level status of each of the second signal terminals.

10. The fault monitoring method according to claim 9, characterized in that, The controller further includes a third signal terminal for issuing a reset signal; the monitoring circuit further includes a reset circuit, one end of which is electrically connected to the third signal terminal, and the other end of which is electrically connected to the reset terminals of a plurality of the latch units; the monitoring method further includes a reset method for resetting the latch units. The controller reads the level state of the first signal terminal. When the first signal terminal is in the second level state corresponding to the normal state of the monitored object, it sends a reset start signal to the reset circuit through the third signal terminal and starts a preset timer at the same time. The system scans the level states of each of the second signal terminals. If all of them correspond to the normal state of the monitored object, a reset end signal is sent to the reset circuit through the third signal terminal. If the level state of any of the second signal terminals corresponds to the fault state of the monitored object, it determines whether the timer has overflowed. If not, the system rescans the level states of each of the second signal terminals. If so, an indication signal is output, indicating that the current monitoring circuit has an abnormality.