Intrinsic safety power supply control method for explosion-proof robot
By using electrical isolation and hardware current limiting technology, battery energy is discretized into energy packets, and constrained energy storage shaping and time window energy barrier control are performed in the intrinsically safe domain. This solves the problem of insufficient energy constraint in traditional power supply control methods and realizes safe and reliable energy management and fault tracing.
Patent Information
- Application Number
- CN202511418330.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-30
- Publication Date
- 2026-01-20
AI Technical Summary
Traditional power supply control methods for explosion-proof robots are difficult to achieve verifiable constraints on short-term and long-term energy while meeting operational load requirements. Furthermore, fault location and compliance review lack a complete chain of evidence, making it impossible to effectively address the ignition risk of explosive gases such as methane.
By employing electrical isolation and cycle-by-cycle hardware current limiting technology, battery energy is discretized into discrete energy packets. Within the intrinsic safety domain, energy is controlled by limited energy storage shaping and time window energy barrier values. A dual-chain safety path is formed through an active shutdown chain and a passive energy limiting chain, achieving energy limitation, uninterrupted supply, and traceability.
It achieves a hardware upper limit on single-packet energy and bounded output of cross-domain energy, ensuring dual constraints on short-term energy and long-term average energy, providing fast disconnection, controlled clamping and hierarchical security, and supporting fault recovery and compliance auditing.
Smart Images

Figure CN121367286A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of coal mine safety and intrinsically safe power supply control, and particularly relates to an intrinsically safe power supply control method for an explosion-proof robot. BACKGROUND
[0002] Mine intelligence promotes robots to replace high-risk jobs underground, but explosive gases such as gas make power supply the main ignition risk source. The traditional method relies on batteries plus conventional protection or single chain power failure, which is difficult to meet the operating load while realizing the verifiable constraint of short-term and long-term energy, and lacks complete evidence chain for fault positioning and compliance review. With the improvement of robot operation rhythm and the intensification of load fluctuation, the power supply side needs to shift from "voltage and current protection" to "energy bounded and auditable" systematic control to maintain the safety boundary and stable power supply in continuous operation, abnormal impact and maintenance reset scenarios. SUMMARY
[0003] In view of the problems existing in the prior art, the present application provides an intrinsically safe power supply control method for an explosion-proof robot. In the non-intrinsically safe domain, the battery electric energy is electrically isolated and discretized into discrete energy packets constrained by hardware current limiting according to the switching period, and energy packet record data is generated. In the intrinsically safe domain, the energy is shaped by limited energy storage, and the time window energy barrier value is calculated. According to the task power and the energy barrier value, the energy scheduling based on tokens is executed to output the energy packet rate instruction. The double-chain safety path composed of active shutdown chain and passive energy limiting chain realizes energy limiting, uninterrupted power supply and traceability.
[0004] An intrinsically safe power supply control method for an explosion-proof robot, comprising the following steps:
[0005] In the non-intrinsically safe domain, the battery electric energy is electrically isolated and discretized into discrete energy packets constrained by hardware current limiting according to the switching period, and energy packet record data is generated.
[0006] In the intrinsically safe domain, the energy is shaped by limited energy storage, and the time window energy barrier value is calculated. When the energy barrier value is exceeded, a hardware shutdown instruction is generated.
[0007] According to the task power demand and the energy barrier value, the energy scheduling based on tokens is executed to generate the energy packet rate instruction and send it to the non-intrinsically safe domain.
[0008] A double-chain safety path composed of active shutdown chain and passive energy limiting chain is established to respond to the hardware shutdown instruction or the hardware abnormal detection signal to implement rapid disconnection and clamping, and form event record data.
[0009] Preferably, the electrical isolation in the non-intrinsically safe domain is realized by an isolation transformer, the periodic hardware current limiting is realized by a current sampling resistor and a comparator to control the on-time of the main switch, and the energy packet record data includes serial number, time stamp and single packet energy estimation.
[0010] Preferably, the restricted energy storage in the intrinsic safety domain includes a super capacitor and a series inductor, and the output shaping includes reverse current blocking and soft start pre-charge of an ideal diode controller, and the peak-shaving charging and discharging is realized by a switched capacitor circuit.
[0011] Preferably, in the output shaping process, a correlation calculation is performed on the energy packet arrival sequence and a pseudo-random sequence to verify the consistency of the cross-domain link, and a hardware shutdown instruction is generated when the correlation coefficient is lower than a threshold value.
[0012] Preferably, the time window energy barrier value includes an instantaneous window energy barrier value and a thermal window energy barrier value, the instantaneous window energy barrier value is calculated based on the energy packet record data and the restricted energy storage voltage in the recent time window, and the thermal window energy barrier value is calculated based on the energy packet record data in the long time window.
[0013] Preferably, the equivalent resistance, the equivalent inductance and the equivalent capacitance are calculated by the amplitude and phase response of the preset test frequency point, and the equivalent parameters and the arc characteristic parameters are extracted as the input of the token-based energy scheduling.
[0014] Preferably, the token-based energy scheduling respectively limits the energy packet rate instruction and the number of energy packets in the instantaneous window according to the instantaneous window energy barrier value and the thermal window energy barrier value.
[0015] Preferably, the time window energy barrier value of the next time window is extrapolated according to the historical energy packet record data and the current energy allocation plan before the energy packet rate instruction is generated, and when the extrapolation result approaches a threshold value, the energy packet rate instruction is reduced and the energy allocation of the low-priority subsystem is stopped.
[0016] Preferably, the active shutdown chain includes power switch gate shutdown and silicon controlled short circuit clamping, and the passive energy limiting chain includes transient voltage suppressor, positive temperature coefficient thermistor, saturable inductor and fuse, and is executed in the order of shutdown, clamping and fusing.
[0017] Preferably, the event record data includes trigger source, hardware shutdown time, silicon controlled silicon conduction time, fuse melting time, time window energy barrier value snapshot and energy packet record data segment, and is used for fault review and recovery process.
[0018] Compared with the prior art, the advantages and beneficial effects of the present application are as follows:
[0019] Through the electrical isolation and the periodic hardware current limiting technology means, the hardware upper limit of the single packet energy and the bounded output of the cross-domain energy are realized;
[0020] Through the restricted energy storage and the time window energy barrier value calculation technology means, the dual constraints of short-time energy and long-term average energy are realized;
[0021] Through the token-based energy scheduling technical means, the adaptive control of the task-oriented energy quota and the energy packet rate instruction is realized.
[0022] Through the double-chain technical means of active shutdown chain and passive energy limiting chain, the layered safety of fast disconnection, controlled clamping and final physical isolation is realized.
[0023] Through the forensics technical means of event record data, the complete retention of trigger source and action timing is realized, supporting fault review and compliance audit.
[0024] Through the energy packet record data and instruction closed loop technical means, the energy supply continuity is realized while the intrinsic safety boundary is maintained. BRIEF DESCRIPTION OF DRAWINGS
[0025] Figure 1 The flowchart of the method of the present application is shown. DETAILED DESCRIPTION
[0026] Hereinafter, embodiments of the present disclosure will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are merely exemplary and are not intended to limit the scope of the present disclosure. In the following detailed description, numerous specific details are set forth in order to provide a thorough understanding of the embodiments of the present disclosure. However, it will be apparent to one of ordinary skill in the art that one or more embodiments can be practiced without these specific details. In addition, in the following description, descriptions of well-known structures and techniques have been omitted to avoid unnecessarily obscuring the concept of the present disclosure.
[0027] The terms used herein are merely used to describe specific embodiments and are not intended to limit the present disclosure. The terms "include", "comprise" and the like used herein indicate the presence of the described features, steps, operations and / or components, but do not exclude the presence or addition of one or more other features, steps, operations or components.
[0028] All terms used herein (including technical and scientific terms) have meanings commonly understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein should be interpreted to have meanings consistent with the context of the present specification, and should not be interpreted in an idealized or overly formal manner.
[0029] As Figure 1 An intrinsic safety power supply control method for an explosion-proof robot, comprising the following steps:
[0030] In the non-intrinsic safety domain, the battery electric energy is electrically isolated and output as discrete energy packets after limiting single packet energy by cycle-by-cycle hardware current limiting, generating energy packet record data;
[0031] The electrical isolation in the non-intrinsic domain is preferably achieved by an isolation transformer, the per-cycle hardware current limiting is achieved by a current sampling resistor and a comparator controlling the on-time of the main switch, and the energy packet recording data includes a serial number, a time stamp, and a single packet energy estimate.
[0032] The system structure is composed of a battery power supply, an input protection and electromagnetic compatibility unit, an isolated flyback power stage, a main switch and gate drive, a current sampling resistor, a hardware comparator, a pulse width modulation controller, and a recording and communication unit. The isolated flyback power stage uses an isolation transformer to achieve electrical isolation, the primary magnetization energy is limited in each switching cycle and crosses the isolation boundary as a single energy packet. The main switch is a metal oxide semiconductor field effect transistor, the current sampling resistor is connected to the comparator input in a Kelvin lead-out manner, the comparator output directly controls the main switch to turn off, and the gate drive has an under-voltage lock function.
[0033] The working principle of per-cycle energy limitation is that after the controller receives the energy packet rate command, the main switch is triggered only once in the permitted cycle. During the on period, the comparator compares the current sampling voltage with the threshold voltage in real time, and turns off immediately when the threshold is reached, and then waits for the completion of the isolation transformer reset before entering the next cycle. The magnetization energy transferred across a single switching cycle satisfies:
[0034]
[0035] E pkt is the upper limit of the single packet energy, L p is the inductance of the primary side of the isolation transformer, I p,max is the peak current of the primary side.
[0036] The peak current of the primary side is determined by the comparator threshold and the current sampling resistor:
[0037]
[0038] V th is the comparator threshold voltage, R sense is the resistance of the current sampling resistor.
[0039] The above two formulas together ensure that the single packet energy is limited by hardware, and any software instruction cannot exceed this upper limit. To avoid false triggering caused by opening transient glitches, a fixed blanking time is set for the comparator input, which covers the gate charging and current establishment process. To prevent sub-synchronous oscillation at large duty cycle operating points, the controller superimposes a fixed slope compensation on the current signal, thereby maintaining cycle stability.
[0040] The energy packet record data is generated and saved locally in the non-intrinsic domain. The recording process is as follows: at the end of each allowed switching cycle, the controller reads the primary side peak current and estimates the single packet energy, and constructs a record entry containing the serial number, timestamp and single packet energy estimate. The single packet energy estimate uses the following formula:
[0041]
[0042] is the single packet energy estimate, I peak is the primary side peak current of the current cycle. The serial number is generated by a monotonically increasing counter, and the timestamp is derived from a hardware timer synchronized with the pulse width modulation cycle. The recording unit uses a ring buffer structure, and the buffer depth is set to cover the time window required by the intrinsic domain for energy statistics. When the buffer overflows, an alarm is triggered and the subsequent packet sending permission is suspended.
[0043] The key details of the hardware implementation include: the length of the lead between the current sampling resistor and the comparator is controlled within a short path range, differential distribution lines are used and small capacitance filters are set to suppress electromagnetic interference; the sum of the comparator propagation delay and the gate drive shutdown delay is less than the characteristic time of one current rising edge, to ensure that the current limiting action is completed before the peak; the number of turns on the primary side of the isolation transformer and the working point of the magnetic core are selected to meet the unsaturated condition, and triple insulation wires and shielding layers are used to meet the isolation and creepage distance requirements; an absorption network is configured to limit the voltage rise rate when the main switch is turned off, reducing the coupling effect on the comparator input.
[0044] The working sequence is as follows: after the power-on self-test, the controller keeps the main switch closed and starts the timer; when the upper control generates an energy packet rate command, the timer triggers the main switch to turn on at the target cycle, and the comparator turns off the main switch at the moment when the peak current reaches the threshold; after the reset detection circuit confirms that the reset of the isolation transformer is complete, it allows the next cycle to enter; at the end of each cycle, a record data is generated and written into the ring buffer, and the buffer state is monitored. If the comparator is abnormal, the gate drive is abnormal, or the recording buffer is unavailable, the subsequent cycle is stopped and the fault is reported.
[0045] The effect of the embodiment is: electrical isolation is achieved through the isolation transformer, and continuous electrical energy is discretized into energy packets in the non-intrinsic domain through hardware current limiting by cycle; the upper limit of the energy of the energy packet is determined by hardware and can be verified through record data; the energy packet record data provides input for energy statistics and boundary crossing determination in the intrinsic domain, and is generated on the source side, avoiding the risk caused by estimation error on the target side. This structure reduces the dependence on processor algorithms while keeping the implementation difficulty controllable, and is suitable for deployment as a pre-stage link for intrinsic power supply in coal mine explosive gas environment.
[0046] In the intrinsic safety domain, the output shaping is performed by a limited energy storage, and the time window energy barrier value is calculated according to the energy package record data, and a hardware shutdown instruction is generated when the barrier is crossed.
[0047] The intrinsic safety side power shaping unit is composed of four parts: limited energy storage, output current limiting and reverse blocking, sampling and calculation, and shutdown driving. The limited energy storage uses a super capacitor and a series inductor to form an energy storage and filtering circuit, which is used to convert discrete energy packages from the non-intrinsic safety domain into continuous output. The output current limiting and reverse blocking is realized by using ideal diode controllers and back-to-back switching devices, which not only avoids backflow from the intrinsic safety port to the non-intrinsic safety side, but also provides soft start pre-charging during power-on. To reduce the voltage fluctuation when the energy package arrives, a switched capacitor circuit is set before the limited energy storage, which disperses the energy to multiple capacitor units in a time sequence, and then releases it to the limited energy storage in an interleaved manner, thereby reducing the output ripple caused by single energy injection.
[0048] The sampling and calculation part uses an isolated sampler to collect the intrinsic safety output voltage and current, and receives energy package record data from the non-intrinsic safety domain. The energy package record data at least includes serial number, time stamp and single package energy estimation. The calculation processor maintains two sliding time windows for energy evaluation of the instantaneous window and the hot window. The instantaneous window covers the millisecond level safety examination, and the hot window covers the second level average energy examination. Each time an energy package record data is received, the processor writes the record data to a ring buffer and updates the energy accumulation in the two time windows. The processor synchronously reads the intrinsic safety output voltage for estimating the current energy storage of the limited energy storage, and checks the energy margin of the instantaneous window accordingly.
[0049] The calculation of the time window energy barrier value uses the following expression:
[0050]
[0051] is the energy estimation value of the kth energy package, C isa is the capacitance value of the limited energy storage, V out is the intrinsic safety output voltage, is the upper limit of the instantaneous window safety energy, is the upper limit of the hot window safety energy, W ms is the energy package index set in the instantaneous window, W s is the energy package index set in the hot window.
[0052] When the instantaneous window energy barrier value is greater than zero or the thermal window energy barrier value is greater than zero, the system determines that there is an energy out-of-limit risk. The out-of-limit processing is divided into two levels: the first level is a hardware shutdown instruction output in the intrinsically safe domain, that is, the shutdown pin is pulled down, so that the ideal diode controller closes the intrinsically safe output and freezes the switching sequence of the previous stage; the second level is a power stage shutdown signal in the non-intrinsically safe domain, which is used to block the subsequent energy package from entering. The current level is simultaneously issued through the isolation communication and the hard line, so as to ensure that the shutdown can still be completed when the communication is abnormal.
[0053] In order to ensure reliable operation and easy implementation, the time window maintenance adopts a ring buffer and a sliding accumulation mode. The processor only updates the in-window and out-window of each energy package record data in constant time, avoiding competition with the energy package arrival frequency. In order to deal with transmission jitter, the processor performs in-window judgment based on the timestamp of the record data, and the timestamp is derived from the unified clock in the non-intrinsically safe domain and is subjected to single offset calibration on the intrinsically safe side. In order to prevent the judgment from being affected by the voltage measurement error of the limited energy storage, the voltage sampling channel is subjected to a static calibration after the soft start is completed, and the calibration parameters are stored in the non-volatile memory and read out during the power-on self-test.
[0054] The working process of the output shaping is as follows: in the soft start stage, the ideal diode controller gradually charges the limited energy storage to the working point by controlling the slope of the intrinsically safe output voltage. In the normal power supply stage, the switched capacitor circuit selects the capacitor unit to charge when the energy package arrives, and then releases the charge to the limited energy storage in a rotation order; the limited energy storage and the series inductor jointly suppress the output voltage fluctuation, so as to ensure the continuity of the port power supply. In the fault stage, once the time window energy barrier value is greater than zero, the processor outputs the hardware shutdown instruction, and records a plurality of energy package record data and the intrinsically safe output voltage before and after the out-of-limit, which are used for post-analysis.
[0055] The effect of the embodiment is that: through the limited energy storage and the output shaping, the discrete energy package is converted into usable continuous electric energy, and at the same time, the energy entering the intrinsically safe domain is accounted online by the time window energy barrier value. Any energy accumulation exceeding the preset limit value in a short time or a long time will be immediately identified and trigger the hardware shutdown, so as to meet the energy limit requirement of the intrinsically safe power supply. The method only relies on common capacitors, inductors, ideal diode controllers, isolation sampling and simple sliding accumulation algorithm, and the hardware and software are easy to implement, which is suitable for popularization and application in the coal mine explosive gas environment.
[0056] Preferably, the limited energy storage in the intrinsically safe domain includes a super capacitor and a series inductor, the output shaping includes reverse current blocking and soft start pre-charging of the ideal diode controller, and the peak-shaving charging and discharging is realized through the switched capacitor circuit.
[0057] The limited energy storage is composed of supercapacitor and series inductor. Supercapacitor is responsible for energy storage and voltage maintenance, and series inductor is used to suppress the current transition caused by the injection of energy packet and cooperate with the subsequent switched capacitor circuit to reduce the ripple. The ideal diode controller drives back-to-back metal oxide semiconductor field effect transistors to form a one-way conduction path. The forward voltage drop is close to zero and has a current-limiting soft-start function, and the reverse direction is turned off as soon as the port voltage is inverted, blocking the current from the load side back to the non-intrinsic side.
[0058] The soft-start pre-charge process is as follows. First, make the ideal diode controller enter the controlled slope mode, and through the internal error amplifier and current limiting loop, the intrinsic output voltage is raised from zero to the preset working interval. After reaching the working interval, enter the steady-state conduction. The voltage slope control of the soft-start process satisfies:
[0059]
[0060] V out is the intrinsic output voltage, r ss is the soft-start slope setting value. By setting the soft-start slope, the supercapacitor charging current is limited to avoid triggering the energy barrier out-of-bounds. The judgment condition for completing the soft-start is that the output voltage reaches the target ratio and the reverse current detection is zero, and then the pre-charge completion flag is returned to the upper control.
[0061] The reverse current blocking is detected by the comparator of the ideal diode controller. When the output voltage is higher than the input voltage and exceeds the reverse threshold, the controller immediately pulls down the gate to achieve shutdown. To avoid false action caused by noise jitter, the comparator input is configured with fixed hysteresis and a short-term blanking is enabled during switch transient. The above action does not depend on the processor, and even if the communication is abnormal, it can also maintain one-way power supply.
[0062] The peak-shaving charging and discharging is realized by the switched capacitor circuit. The switched capacitor circuit is composed of multiple capacitor units and corresponding power switches, and each capacitor unit has voltage sampling and temperature monitoring. The controller reads the voltage of each capacitor unit at a fixed sampling period, calculates the deviation from the average value, selects the unit suitable for energy storage and release, and sets the dead time between adjacent switches to avoid simultaneous conduction and cause impact current. To make the injected energy evenly distributed in time, the scheduling adopts the minimum deviation priority strategy. The selection cost of the current time slot is defined as:
[0063]
[0064] J is the selection cost, S is the set of capacitor units selected in the current time slot, ΔV iThe voltage deviation of the ith capacitor unit. The controller selects the combination that minimizes the selection cost under the premise of meeting the dead zone and the upper and lower limits of the unit voltage, thereby reducing the voltage imbalance in the next time slot and reducing the ripple injected into the limited energy storage. The scheduling result is issued in the form of a timing table to the gate drive, and the charging and discharging stages are executed in reverse order to prevent peak current overlap.
[0065] The working point of the limited energy storage is estimated online by output voltage sampling and known capacitor value to calculate the energy storage:
[0066]
[0067] E cap The current energy storage of the super capacitor is C isa The nominal capacitance value of the super capacitor. The controller updates the energy storage at each sampling period to determine whether to allow the switched capacitor circuit to continue to discharge energy to the limited energy storage, avoiding continued charging when the voltage of the limited energy storage approaches the upper limit.
[0068] To ensure the timeliness and implementability of the above process, the processor uses a double-buffer data structure to manage the capacitor unit voltage queue and the gate timing table. Sampling and scheduling run at different interrupt priorities, with the sampling task only responsible for updating the measured value and calculating the voltage deviation, and the scheduling task reading the latest deviation to complete combination selection and refreshing the gate timing at a fixed time base. The interface between the ideal diode controller, the switched capacitor circuit, and the series inductor is decoupled in hardware, and any single module exception will not cause energy backflow or overshoot.
[0069] The overall effect is reflected in three aspects. First, discrete energy packets from the non-intrinsic domain are converted into continuous output on the intrinsic side, and the output ripple is suppressed by the interleaved release of the series inductor and the switched capacitor circuit. Second, through soft start and reverse blocking, reliable control of current direction and amplitude is achieved in two key scenarios: power-up and load feedback. Third, by online estimation of energy storage and minimum deviation priority scheduling, energy is dynamically balanced within the switched capacitor circuit, extending the life of the elements and reducing the transient stress on the intrinsic output side. The devices and algorithms used in this embodiment are common means in the art, and parameter setting can be completed through type test calibration, making it easy to engineer in the coal mine explosive gas environment.
[0070] Preferably, in the output shaping process, the energy packet arrival sequence and the pseudo-random sequence are correlated to verify the consistency of the cross-domain link, and a hardware shutdown instruction is generated when the correlation coefficient is below a threshold.
[0071] The system structure consists of four units: 1) arrival detection and buffering unit, which is used to generate arrival sequence from energy packet record data and write it into a circular buffer in time sequence; 2) pseudo-random sequence receiving unit, which is used to receive pseudo-random sequence sent by non-intrinsic domain and complete alignment with arrival sequence; 3) correlation calculation and decision unit, which is used to complete sliding window correlation coefficient calculation and threshold decision; 4) shutdown execution unit, which is used to shut down and freeze output shaping through isolated driving hardware. The hardware platform can adopt a microcontroller plus a small-scale programmable logic device, the microcontroller is responsible for buffer management and decision, and the programmable logic device is responsible for timing alignment and multiplication and addition operation.
[0072] Arrival detection and buffering: after detecting the completion of energy packet injection each time, the output shaping layer generates an arrival mark and writes it into the arrival sequence buffer together with the single packet energy estimation of this time. The arrival mark takes a value to represent "detecting a packet" and takes a zero value to represent "empty time slot". In order to eliminate jitter, a packet completion interrupt with fixed width is used and a jitter removal delay is added; in order to prevent miscounting in the pre-charge stage, the mark before the completion of pre-charge does not enter the buffer.
[0073] Pseudo-random sequence receiving and alignment: the non-intrinsic domain sends pseudo-random sequence with tokens, including sequence length and starting sequence number. The intrinsic side aligns the pseudo-random symbol with the arrival mark according to the sequence number; when the sequence number continuity is destroyed, the resynchronization process is started, the position of the maximum correlation peak is used to complete phase reset, and a step loss event is recorded.
[0074] The core correlation calculation adopts normalized cross-correlation, and the sliding window length is consistent with the energy packet time granularity:
[0075]
[0076] y k is the arrival mark of the kth time slot in the window or the arrival quantity normalized by single packet energy, is the window average value of the arrival quantity, s k is the kth pseudo-random symbol in the window, L is the window length, and p is the correlation coefficient. In order to suppress the influence of occasional empty packets, the arrival quantity can be limited and normalized before entering the calculation.
[0077] The decision and shutdown execution follow a two-level strategy. The first level is running decision: when the correlation coefficients of consecutive windows are all lower than the threshold value, it is considered that the consistency of the cross-domain link is invalid, and the hardware shutdown instruction is output immediately and the output shaping timing is frozen; the second level is recovery decision: after shutdown, it enters the diagnosis state, only a small energy test sequence is reserved, and when the correlation coefficients of consecutive windows are higher than the recovery threshold value, it is allowed to enter the controlled recovery process. In order to avoid threshold edge fluctuation, upper and lower thresholds are used and a minimum holding time is set.
[0078] The shutdown execution unit drives the shutdown pin low by isolation, the ideal diode controller shuts down the intrinsic safety output, and sends a shutdown signal to the non-intrinsic safety domain to prevent new energy packets from entering. To ensure traceability, the system saves the arrival sequence, pseudo-random sequence and correlation coefficient of several windows before and after shutdown for subsequent verification.
[0079] Parameter and resource configuration suggestions: the sequence buffer depth covers at least the number of windows required for recovery decision; the window length is set according to the energy packet time granularity, which ensures statistical stability and quickly gives a decision in the case of link exception; the multiplication and addition operation can be completed by programmable logic device pipeline, and the microcontroller only processes threshold comparison and state machine switching. The state machine includes tracking, out-of-step, diagnosis and recovery four states, and the state transition is driven by the correlation coefficient and out-of-step count.
[0080] The effect of the embodiment is that the correlation calculation converts "whether to arrive at the intrinsic safety side along the original path" into an online calculable quantity, and any bypass, short circuit or incorrect routing will make the arrival sequence and pseudo-random sequence lose correlation, thereby triggering a quick shutdown; the resynchronization and double threshold strategy balances false alarm control and fault response speed; the required devices and algorithms are commonly used in the field, and are easy to be deployed in the intrinsic safety power supply system in the coal mine explosive gas environment.
[0081] Preferably, the time window energy barrier value includes an instantaneous window energy barrier value and a hot window energy barrier value, the instantaneous window energy barrier value is calculated based on the energy packet record data in the recent time window and the limited energy storage voltage, and the hot window energy barrier value is calculated based on the energy packet record data in the long time window.
[0082] The system consists of three parts: one is the data inlet, which receives the energy packet record data and samples the intrinsic safety output voltage; the second is the sliding window and barrier calculation logic, which maintains the energy accumulation of the instantaneous window and the hot window and calculates the barrier value; the third is the decision and execution, which is responsible for the out-of-limit shutdown and event recording. The data inlet writes the energy packet record data from the non-intrinsic safety domain into the ring buffer, and the fields include the serial number, timestamp and single packet energy estimation. The intrinsic safety output voltage is sampled by an isolated analog-to-digital converter, and a one-time finite impulse response filter is used to remove the switching ripple. The sampling results are aligned with the same timestamp and then enter the calculation logic.
[0083] The instantaneous window energy barrier value is used to constrain the superposition of short time energy and limited energy storage, and the calculation formula is:
[0084]
[0085] B ms For the instantaneous window energy barrier value, is the energy estimation value of the kth energy packet, W ms is the energy packet index set in the instantaneous window, C isaV is the limited energy storage capacitor, out V is the intrinsic safety output voltage, V is the upper limit of the instantaneous window safety energy. The thermal window energy barrier value is used to constrain the input energy on a longer time scale, and the calculation formula is:
[0086]
[0087] B s V is the thermal window energy barrier value, W s V is the energy packet index set in the thermal window, V is the upper limit of the thermal window safety energy.
[0088] The implementation points are as follows. First, the window maintenance adopts a sliding mode of “in-window accumulation and out-window deduction”. The ring buffer is written in timestamp order; when a new record enters, its energy is added to the corresponding window accumulation, and records with timestamps earlier than the window start point are removed, realizing constant time complexity update. Second, the timestamp is based on the energy packet record data, and the intrinsic safety side only makes a one-time offset calibration, ensuring consistent time base on both sides. Third, the capacitance value of the limited energy storage is obtained through factory discharge calibration, and the calibration coefficient is stored in the non-volatile memory, which is verified for validity during power-on self-test; the voltage sampling channel is calibrated for zero and proportion after the soft start is completed. Fourth, to avoid false judgments caused by occasional jitter, the instantaneous window and the thermal window maintain barrier values independently, and a double-threshold and holding time strategy is adopted at the decision end: when the instantaneous window energy barrier value is greater than zero or the thermal window energy barrier value is greater than zero, the shutdown is triggered immediately; when the instantaneous window energy barrier value or the thermal window energy barrier value is close to zero but has not crossed the boundary, the pre-warning state is entered and the power reduction suggestion is sent to the dispatching layer.
[0089] The execution logic is: the isolation drive is pulled down to the shutdown pin immediately when the boundary determination is established, the ideal diode controller output is turned off and the switch capacitor circuit timing is frozen, and at the same time a shutdown signal is sent to the non-intrinsic safety domain to prevent new energy packets from entering. To ensure traceability, the system saves a fixed number of energy packet record data and intrinsic safety output voltage samples before and after shutdown, forming a barrier event record.
[0090] To improve robustness, the algorithm is still stable in the following scenarios: when the energy packet arrival interval is uneven in a short time, the sliding accumulation is judged by timestamp to enter and exit the window, and does not depend on fixed period; when the intrinsic safety output voltage appears transient drop, the voltage filter provides a smoothed value matching the time granularity of the energy packet, avoiding the error of counting high-frequency ripple into the energy storage item. The abnormal processing includes record buffer overflow, invalid sampling and missing calibration parameters, any of which enters the conservative mode, only retaining the barrier calculation and shutdown functions.
[0091] Through the above structure, the instantaneous window energy barrier value covers the short-time spark risk, and the thermal window energy barrier value covers the average power consumption and temperature rise risk, and the two together form an online energy limit evidence chain of the intrinsic safety domain. The required devices are common super capacitors, isolated analog-to-digital converters and microcontrollers, and the algorithm is a sliding window and double threshold judgment, which has strong engineering realizability and is easy to deploy in an intrinsic safety power supply system in a coal mine explosive gas environment.
[0092] According to the task power demand and the energy barrier value, token-based energy scheduling is performed, energy packet rate instructions are generated and issued to the non-intrinsic safety domain;
[0093] The system architecture is composed of a task power acquisition unit, an energy window evaluation unit, a token scheduling unit and an issuing execution unit. The task power acquisition unit obtains the power demand curve from the robot subsystem controller, and establishes a power demand queue according to a fixed scheduling period. The energy window evaluation unit obtains the instantaneous window energy barrier value and the thermal window energy barrier value from the intrinsic safety side, and reads the energy packet record data for verification. The token scheduling unit calculates the required token number and the upper limit of the available token in each scheduling period, and generates the energy packet rate instruction. The issuing execution unit issues the energy packet rate instruction to the power stage in the non-intrinsic safety domain through an optoelectronic isolation interface, and records the instruction issue time stamp for subsequent verification.
[0094] The power demand is converted into the energy demand of the current period, using the following formula:
[0095]
[0096] E req is the energy demand of the current period, P(τ) is the task power demand curve, and Δt is the scheduling period. The energy demand is mapped to the required token number, using the following formula:
[0097]
[0098] n req is the required token number, E pkt is the upper limit of the single packet energy. To ensure that the energy boundary is not touched, the token upper limit is jointly constrained by two time windows. Based on the instantaneous window energy barrier value and the thermal window energy barrier value, the available token upper limit is calculated as follows:
[0099]
[0100] n allow = min(n ms ,n s ,n hw )
[0101] n ms is the instantaneous window available token upper limit, n s is the thermal window available token upper limit, and Bms B is the instantaneous window energy barrier value, n s n is the thermal window energy barrier value, n allow n is the upper limit of tokens available for issuance in the current period hw n is the maximum number of tokens supported by the hardware in the current period.
[0102] When there are multiple parallel subsystems, tokens are allocated among the subsystems according to weights. The scheduling unit maintains a weight table and a demand queue, and high-priority subsystems related to safety are preferentially satisfied. In each period, the global upper limit is first calculated as the upper limit of tokens available for issuance, and then allocated to each subsystem in proportion to the weights, and the allocation value of a single subsystem does not exceed the number of tokens required. After the allocation is completed, the remaining tokens are again allocated in the order of weights according to the unmet demand, until they are exhausted or all demands are met.
[0103] To avoid sudden changes in rate causing output ripple and mechanical impact, the energy packet rate command uses first-order smoothing before being issued:
[0104]
[0105] r cmd r is the energy packet rate command in the current period, n cmd r is the energy packet rate command in the previous period, and λ is the smoothing coefficient, n plan n is the number of tokens planned to be issued in the current period.
[0106] The scheduling process is as follows. First, collect the power demand in the current period and calculate the energy demand and the number of tokens required. Second, read the instantaneous window energy barrier value and the thermal window energy barrier value, and calculate the upper limit of tokens available for issuance according to the two time windows, while reading the hardware support upper limit to obtain the global upper limit. Third, perform token allocation and smoothing to obtain the energy packet rate command and the subsystem token allocation table. Fourth, issue the energy packet rate command through the isolation interface, and record the command and timestamp on the safety side. Fifth, receive the non-safety domain feedback, and if there is an unexecuted alarm, tighten the global upper limit to the feedback executable value in the next period, and trigger a fault record.
[0107] In order to maintain safety when approaching the boundary, the scheduling unit sets a warning threshold. When the instantaneous window energy barrier value or the thermal window energy barrier value approaches zero, the energy packet rate command is automatically reduced, and the token allocation of low-priority subsystems is suspended. If either energy barrier value is greater than zero, immediately set the energy packet rate command to zero and send a shutdown request to the safety side shutdown channel to prevent new energy packets from entering.
[0108] The implementation points are as follows. Time synchronization is based on the periodic trigger of the non-intrinsically safe domain, and the intrinsically safe side performs one-time offset calibration at power-on. The power demand queue uses a fixed-length array to ensure that memory allocation does not occur under high load. The weight table and priority are configured by the task manager and can be updated online, and when updating, double-buffer switching is used to avoid interrupt conflicts. The execution unit uses a frame structure, including energy packet rate instructions, cycle numbers, and check codes, which are effective within the same cycle after being received by the non-intrinsically safe domain. To improve traceability, the scheduling unit saves the input and output snapshots of multiple cycles, including power demand, energy barrier values of the two time windows, required token quantity, upper limit of available tokens, and energy packet rate instructions, for consistency checking with energy packet record data.
[0109] Through the above method, energy scheduling is driven by task demand and constrained by the energy boundaries of the two time windows. The generated energy packet rate instructions ensure that the tasks are met while not exceeding the energy limit requirements of the intrinsically safe side, and have predictable derating behavior near the boundaries. The entire process only relies on common microcontrollers and isolation communication devices, has small computational complexity, and is easy to engineer in intrinsically safe power supply systems in coal mine explosive gas environments.
[0110] Preferably, the equivalent resistance, equivalent inductance, and equivalent capacitance are calculated by the amplitude and phase response of the preset test frequency point, and the arc characteristic parameters are extracted, and the equivalent parameters and the arc characteristic parameters are taken as inputs of the token-based energy scheduling.
[0111] The system structure is composed of a test signal injection unit, a synchronous sampling and demodulation unit, an equivalent parameter estimation unit, an arc feature extraction unit, and a data publishing interface. The test signal injection unit shares the time base with the output shaping, superimposes a small-amplitude sinusoidal excitation in the space-time slot of the energy packet, and the frequency point comes from the preset test frequency point table. The excitation amplitude is limited to a small proportion of the rated output, and is isolated from the soft start and reverse blocking logic of the output shaping, avoiding affecting the judgment of the limited energy storage and time window energy barrier value. The synchronous sampling and demodulation unit simultaneously collects the intrinsically safe output voltage and intrinsically safe output current at a fixed sampling rate, uses a phase-locked window function, and extracts amplitude and phase at each frequency point using a discrete frequency demodulator based on coefficient pre-computation. To suppress the influence of power frequency and switching ripple, band-limited and one-time digital calibration are performed before demodulation.
[0112] The amplitude and phase of the voltage and current are obtained at each test frequency point, the port complex impedance is calculated, and the real part and imaginary part are decomposed:
[0113]
[0114]
[0115] Z k Zk is the complex impedance of the kth test frequency point, V kV is the voltage amplitude of the frequency point, I k I is the current amplitude of the frequency point, φ k φ is the phase difference between voltage and current, Re represents the real part, Im represents the imaginary part.
[0116] The small signal model of the port is equivalent to a series resistance, a series inductance, and a series capacitance. The real part is approximately equal to the equivalent resistance, and the imaginary part approximately satisfies a linear relationship:
[0117]
[0118] ω k is the angular frequency of the kth test frequency point, L is the equivalent inductance, and C is the equivalent capacitance. The parameters are solved by multi-frequency point least squares. First, the equivalent resistance is obtained by using the median of the real part, and then the imaginary part of all frequency points is used to fit the equivalent inductance and the equivalent capacitance. The fitting process contains three engineering constraints: discarding abnormal frequency points when the fitting residual exceeds the limit, keeping the last stable value when the parameters jump significantly, and delaying the release of equivalent parameters in the output shaping soft start stage.
[0119] The arc feature extraction unit extracts three types of indicators from the high-frequency components of the current and voltage: the first type is the short-time energy indicator, which calculates the window energy of the bandpass signal of the demodulation residual, reflecting the rapid pulse activity:
[0120]
[0121] A1 is the short-time energy indicator, i bp [n] is the current sequence after bandpass, and N is the window length. The second type is the phase jitter indicator, which calculates the variance of the phase difference between adjacent sampling windows, reflecting the randomness of the phase caused by unstable contact:
[0122] A2 = Var(Δφ k )
[0123] A2 is the phase jitter indicator, Δφ k is the phase difference between adjacent windows of the same frequency point. The third type is the harmonic ratio indicator, which extracts the ratio of the fundamental and third harmonic amplitudes near the target frequency point, reflecting the influence of nonlinear discharge on the frequency spectrum. The three types of indicators set threshold values and form an arc feature parameter set combined with consistency rules. The threshold values are written in the read-only area after the factory type test and field calibration, and only reading is allowed during operation.
[0124] The data publishing interface generates a data object at each scheduling cycle, containing equivalent resistance, equivalent inductance, equivalent capacitance and arc characteristic parameters, and is accompanied by a timestamp and a quality mark. The token-based energy scheduling reads the data object: when the equivalent resistance increases and the arc characteristic parameter does not trigger, the energy packet rate instruction is reduced according to the temperature rise risk; when the phase jitter index or the short-time energy index exceeds the threshold, the energy packet rate instruction is reduced to zero and a shutdown request is sent to the shutdown link; when the equivalent inductance and the equivalent capacitance change cause the port resonance frequency to approach the test frequency point, the test frequency point is automatically migrated to avoid coupling interference, and the token upper limit is temporarily tightened.
[0125] The implementation details are as follows. The test signal injection unit adopts two ways of digital-to-analog converter plus isolated drive or uses the micro-amplitude duty disturbance of the power stage, and preferentially selects to insert several cycles of sine signals in the space time slot; the synchronous sampling channel uses the same reference clock, and the voltage and current channels are cross-calibrated, and the calibration coefficients are saved in the non-volatile memory; the demodulation adopts block processing, and the block length and the frequency point period number are aligned to obtain stable amplitude and phase estimation; the parameter publishing adopts double buffering to avoid the scheduled thread from reading the intermediate state; when the sampling is out of step, the noise is too high or the amplitude and phase demodulation fails, the quality mark of the data object is invalid, and the scheduling enters the conservative mode, and only the energy barrier value in the time window is used for limiting.
[0126] Through the process, the amplitude and phase response of the preset test frequency point is converted into stable, interpretable equivalent resistance, equivalent inductance and equivalent capacitance, and at the same time, three types of physical intuitive indicators are used to characterize potential arc activity. The two types of results are used as inputs for energy scheduling, so that the scheduling no longer relies only on energy accumulation, but also considers the port state and discharge risk, to achieve more stable intrinsic safety power supply control. The entire implementation relies on common digital-to-analog converters, isolated samplers, microcontrollers, and simple demodulation and least squares operations, and both hardware and software are easy to deploy in coal mine explosive gas environments.
[0127] Preferably, the token-based energy scheduling limits the energy packet rate instruction and the number of energy packets in the instantaneous window according to the instantaneous window energy barrier value and the thermal window energy barrier value, respectively.
[0128] The scheduling architecture includes three parts: data entry, token calculation and instruction issuance. The data entry reads the task power demand, the instantaneous window energy barrier value and the thermal window energy barrier value on the intrinsic safety side every scheduling cycle, and receives the energy packet receipt of the last cycle and the number of instantaneous window used packets. The token calculation completes the quota conversion, allocation and smoothing in a fixed period, and the instruction issuance synchronizes the energy packet rate instruction to the non-intrinsic safety domain power stage through isolated communication.
[0129] In order to directly constrain the energy boundary to "rate" and "number", the following core calculation is used in this embodiment. The thermal window side converts the thermal window energy barrier value into a rate upper limit:
[0130]
[0131] r lim is the rate upper limit of the hot window, B s is the hot window energy barrier value, E pkt is the single packet energy upper limit, T s is the hot window duration, r hw is the maximum packet sending rate supported by hardware. The instantaneous window side converts the instantaneous window energy barrier value into the remaining number of packets that the current instantaneous window can accommodate:
[0132]
[0133] n win is the remaining number of packets that the instantaneous window can send, B ms is the instantaneous window energy barrier value. Then generate the planned packet number in each scheduling period:
[0134]
[0135] n plan is the planned packet number in this period, Δt is the scheduling period, n used is the number of packets used in the current instantaneous window, n req is the demand packet number converted according to the task power.
[0136] The implementation process is as follows. First, the data inlet calculates the energy demand in this period according to the task power curve and converts it into the demand packet number; at the same time, the instantaneous window energy barrier value and the hot window energy barrier value are read, and the rate upper limit and the remaining number of packets in the instantaneous window are calculated. Second, the token calculation unit obtains the planned packet number in this period according to the rate upper limit and the remaining number of packets in the instantaneous window, and distributes it according to the subsystem priority in weighted round robin; in order to avoid the ripple and execution impact caused by rate jump, the energy packet rate instruction is smoothed by first order after output. Third, the instruction issuing unit sends the energy packet rate instruction together with the cycle serial number and the check code to the non-safety domain, and when the reply is abnormal, the rate upper limit is automatically tightened in the next period and an event is recorded. Finally, the statistical unit updates the number of packets used in the instantaneous window and rolls the window start and end time, realizing the constant time update of “in-window accumulation and out-window deduction”.
[0137] The key engineering points include: 1. Calibration of threshold and time base. The start and end of the instantaneous window and the thermal window are based on the energy packet record timestamp. The intrinsically safe side only needs single offset calibration; 2. Protection near the boundary. If any barrier value is close to zero, the energy packet rate command is immediately reduced, and the allocation of low-priority subsystems is suspended; if any barrier value is greater than zero, the energy packet rate command is directly set to zero and a request is made to shut down the channel for execution; 3. Data quality control. When the barrier value, receipt or timestamp is abnormal, the quality flag is set to invalid, the system enters a conservative mode, only allowing very low rate diagnostic packet sending and limiting the number of packets in the instantaneous window to zero.
[0138] Through this method, the thermal window energy barrier value stably constrains the long-term average energy, which is directly mapped to the hard upper limit of the energy packet rate command; the instantaneous window energy barrier value constrains the short-term energy, not only reducing the planned packet number in each cycle, but also setting the "maximum remaining packet number" in the window dimension. The superposition of the two makes the token scheduling have the characteristics of "not exceeding long-term" and "not short-term impact". The required hardware is a common microcontroller and isolated communication device, and the software only includes a sliding window, a minimum operation and a first-order smoothing, which is easy to implement in an intrinsically safe power supply system in a coal mine explosive gas environment.
[0139] Preferably, the time window energy barrier value of the next time window is extrapolated according to the historical energy packet record data and the current energy allocation plan before the energy packet rate command is generated, and when the extrapolation result approaches the threshold, the energy packet rate command is reduced and the energy allocation of the low-priority subsystem is stopped.
[0140] The system consists of four units: historical data management, extrapolation calculation, power reduction and stop allocation decision, and instruction linkage. The historical data management maintains two ring buffers corresponding to the instantaneous window and the thermal window, the buffer elements come from the energy packet record data, are written in order according to the timestamp, and perform "window accumulation and window deduction" at each scheduling cycle. At the same time, the intrinsically safe output voltage is collected for the estimation of the limited energy storage item. The current energy allocation plan is given by the token allocation result of the last cycle and the demand queue of the current cycle, including the planned number of tokens and the priority of the subsystem.
[0141] The extrapolation calculation takes the next cycle as the prediction point and estimates the two barrier values in advance:
[0142]
[0143] For the next cycle's instantaneous window barrier prediction value, For the next cycle's thermal window barrier prediction value, For the energy estimation of the kth energy packet, And The record set to be reserved in the corresponding window of the next period is merged with the energy corresponding to the tokens planned to be issued in the current period, C isa V is the capacitance of the limited energy storage out V is the intrinsic output voltage V is the upper limit of the instantaneous window safety energy V is the upper limit of the thermal window safety energy, and Δt is the scheduling period. Set updates are achieved by comparing timestamps, and do not depend on fixed arrival periods. The prediction results are converted into feasible upper limits for the next period:
[0144]
[0145] V is the upper limit of the number of remaining packets that can be issued in the next period instantaneous window V is the upper limit of the rate in the next period, E pkt V is the upper limit of the single packet energy, T s V is the length of the thermal window
[0146] The derating and stop distribution decisions follow a two-level rule. The first level is a linear retreat near the threshold: when any predicted barrier value is near the upper boundary above zero, the rate is tightened in proportion to the amplitude and the number of packets in the instantaneous window is limited:
[0147]
[0148] r cmd V is the energy packet rate instruction, n plan V is the number of packets planned in the current period. The second level is priority clipping: if the prediction is still close to the threshold after the above tightening, the token quota of the subsystem is set to zero according to the priority from low to high, until both predicted barrier values are less than zero and a safety margin is left. The priority table is configured in the task manager, including safety-related, motion-related and general load. The clipping action records events for subsequent task layer adjustment.
[0149] In order to avoid jitter, the extrapolation calculation output is marked with a quality flag. If the energy packet record data is missing, the timestamp is not continuous, or the limited energy storage voltage sampling is invalid, the flag is set to invalid, the scheduling enters a conservative mode, only allowing a very low rate of diagnostic tokens and stopping all low-priority subsystem distribution. After the quality is restored, gradually release the rate instruction according to the smoothing strategy. Smoothing uses a first-order filter to prevent rate surges from causing ripple and mechanism impact.
[0150] In a specific implementation, the historical data management and extrapolation calculation run in a high-priority timing interrupt, ensuring completion within the scheduling period; the derating and stop-distribution decision runs in the main loop, reading the latest prediction and quality flag and updating the token plan; the instruction linkage issues the new rate instruction and subsystem quota to the non-intrinsic domain through isolated communication, while feeding back the clipping result to the task manager. All key variables are saved in a black box for the basis of the prediction and decision chain.
[0151] Through the above method, the system performs foresight control on the energy boundary of the next window in each cycle, converts potential boundary crossing into rate and quota constraints in advance, and ensures that safety-related loads are prioritized for power supply in a priority clipping manner. This process only relies on common microcontrollers, isolated sampling, and ring buffer structures, has small computational load, and can be calibrated through type tests, making it suitable for engineering application in intrinsic safety power supply systems in coal mine explosive gas environments.
[0152] A dual-chain safety path of active shutdown chain and passive energy limiting chain is established to implement rapid disconnection and clamping in response to a hardware shutdown instruction or a hardware abnormality detection signal, and to form event record data.
[0153] The system structure consists of four parts: trigger acquisition and arbitration unit, active shutdown chain, passive energy limiting chain, and event record and reset unit. The trigger acquisition and arbitration unit receives hardware shutdown instructions and hardware abnormality detection signals, and the signal sources include overvoltage comparators, overcurrent comparators, reverse current comparators, temperature sensors, correlation coefficient determination circuits, and time window energy barrier crossing determination outputs. The arbitration rule is that any hardware abnormality detection signal is valid to enter the shutdown process, and the hardware path has priority over any software instruction.
[0154] The active shutdown chain drives three types of actions with an isolated shutdown line: first, the power stage gate drive is discharged quickly to make the main power switch cut off; second, the ideal diode controller is shut down to block the backflow from the intrinsic port to the non-intrinsic side; third, the trigger thyristor is short-circuited to clamp, pulling the intrinsic port to a controlled low resistance state to create conditions for subsequent fusing. The clamping trigger uses isolated driving, with a short gate loop wiring and independent power supply, ensuring reliable conduction even when the main power supply fluctuates. To suppress shutdown overshoot, transient voltage suppressors are connected in parallel with the power stage and the port to absorb sharp peaks of energy at the moment of shutdown.
[0155] The passive energy limiting chain and the active shutdown chain work in parallel, including positive temperature coefficient thermistor, saturable inductor, transient voltage suppressor and fuse. The positive temperature coefficient thermistor limits the continuous current under abnormal current; the saturable inductor suppresses the current rise rate at the initial stage of the fault to gain time for the active shutdown; the transient voltage suppressor is responsible for clamping the port overvoltage; the fuse physically disconnects after the energy integral reaches the set value, realizing the final isolation. The two chains are independent of each other, and when either one fails, the other can still limit the releasable energy to the outside.
[0156] To verify the energy limiting effect and guide the selection of the device, the released energy during the shutdown process is estimated as follows:
[0157]
[0158] E let The energy released to the load and the port during the shutdown process, t0 is the fault trigger time, t off is the completion time of the active shutdown, v(t) is the port voltage, i(t) is the port current, C isa is the capacitance value of the limited energy storage, V out is the intrinsic safety output voltage at the shutdown time. The action of the fuse is checked by energy-time integral calculation:
[0159]
[0160] I 2 t is the fuse criterion, t fuse is the open circuit time of the fuse. The above two formulas are used for type test and parameter setting, and the recorded data are indirectly verified during operation.
[0161] The event recording and reset unit saves the data before and after shutdown in a double buffering manner. The recorded content includes trigger source identification, trigger timestamp, main power switch cutoff timestamp, silicon controlled rectifier conduction timestamp, fuse open circuit timestamp, and a number of sampling points of intrinsic safety output voltage and current, time window energy barrier value and related coefficient before and after shutdown. The recorded entries are accompanied by check codes and written into non-volatile memory. The reset process requires replacing the fuse, checking the appearance and parameters of the transient voltage suppressor and the positive temperature coefficient thermistor, performing limited energy storage discharge and soft start pre-charging, and finally manually unlocking the system to restore the permission state.
[0162] The hardware implementation points are as follows: the comparator and the gate drive common loop adopt single-point grounding and the shortest loop wiring; the thyristor gate series resistance and the gate protection network are set according to the device application notes, to ensure that the thyristor remains continuously conductive in the clamping stage; the saturated inductor selects a direct current bias point at the nonlinear steep section of the magnetic core to obtain greater rising edge suppression; the rated energy-time product of the fuse has a margin, and is placed in a position easy to replace. The software only undertakes event recording and state machine switching, and does not participate in the shutdown decision, avoiding competitive timing.
[0163] The running process is as follows: when any hardware abnormality detection signal is valid, the arbitration unit immediately issues a shutdown line; the gate drive discharges and closes the ideal diode controller, the thyristor is conductive in the order of microseconds, and the transient voltage suppressor absorbs the sharp peak; if the fault persists, the positive temperature coefficient thermistor increases the resistance, and the saturated inductor provides current limiting time after entering saturation, and finally the fuse is opened, and the system enters the latch-off. A complete event record data is formed throughout the process, providing evidence chain for subsequent review. The double-chain path is mainly hardware and supplemented by software, with clear structure and general devices, which is easy to implement in the intrinsic safety power supply system in the coal mine explosive gas environment.
[0164] Preferably, the active shutdown chain includes power switch gate shutdown and thyristor short circuit clamping, and the passive energy limiting chain includes transient voltage suppressor, positive temperature coefficient thermistor, saturated inductor and fuse, which are executed in the order of shutdown, clamping and fusing.
[0165] The system as a whole is a double-chain parallel, hardware-priority safety path. The trigger sources include overvoltage comparator, overcurrent comparator, reverse current comparator, temperature sensor and hardware shutdown instructions from energy barrier and related judgment. Any trigger is valid to enter the shutdown process, which proceeds in the order of shutdown, clamping and fusing; the software is only responsible for recording and resetting, and cannot block the hardware action.
[0166] The active shutdown chain is composed of gate drive, shutdown line and thyristor short circuit unit. The gate drive has under-voltage lock and Miller clamp, the shutdown line is directly connected to the shutdown pin of the gate drive through optical coupling isolation, and after triggering, the gate charge is quickly evacuated to make the main power switch cut off. The ideal diode controller receives the shutdown line at the same time, closes the unidirectional conduction of the intrinsic safety port, and prevents backflow. Then the thyristor short circuit unit is triggered to pull the intrinsic safety port into a controlled low resistance state to limit the port overvoltage and transient energy. The gate of the thyristor adopts isolated drive, the gate loop is decoupled in place and a gate protection network is set; to suppress false triggering, a resistance-capacitance absorption network is connected in parallel to the port to reduce the rising edge stress.
[0167] The passive energy limiting chain and the active shutdown chain are placed in parallel and independent of each other. The transient voltage suppressor is connected to the port to absorb the peak voltage; the positive temperature coefficient thermistor is connected in series to the output path to limit the continuous current under abnormal current; the saturable inductor is connected in series near the port to provide a higher inductance to suppress the current rise rate at the initial stage of failure; the fuse is connected in series at the end of the power supply path to physically open the circuit when the energy integral reaches the set value, thereby realizing the final isolation. The device arrangement follows the principles of short circuit, single-point grounding, and local absorption, with the transient voltage suppressor and the thyristor being placed as close to the port as possible, and the fuse being placed in a position convenient for maintenance.
[0168] The energy of the shutdown process and the fuse are calculated as follows for type setting and on-site verification:
[0169]
[0170] E let The energy released to the load and the port during the shutdown process is E = 1 / 2 C V2, t0 is the moment of fault triggering, t off is the moment when the active shutdown is completed, v(t) is the port voltage, i(t) is the port current, C isa is the capacitance value of the limited energy storage, V out is the intrinsic safety output voltage at the moment of shutdown.
[0171]
[0172] I 2 t is the fuse criterion, t fuse is the moment when the fuse is opened. Through testing, the energy-time integral of the fuse under the condition of continuous conduction of the thyristor is earlier than the thermal limit of the key device, and is matched with the on-state energy capacity of the transient voltage suppressor.
[0173] The execution timing is as follows: after the trigger acquisition and arbitration unit detects a valid signal, the first step is to pull down the shutdown line, and the gate drive forces the main power switch to shut down and the ideal diode controller to be closed; the second step is to trigger the thyristor short circuit unit, and the port is quickly pulled to a controlled low resistance state, and the transient voltage suppressor absorbs the peak; the third step is to provide a rising edge suppression under abnormal continuous conditions after the positive temperature coefficient thermistor and the saturable inductor gradually enter saturation, and finally the fuse is opened to form permanent isolation. If any step is not achieved, the other link still provides energy limiting effect to ensure that the releasable energy of the port does not exceed the safe upper limit.
[0174] Event record and reset adopt black box structure. Record items include trigger source, off-line pull-down time, main power switch off time, thyristor on time, fuse open time, and intrinsic safety output voltage and current at several points before and after off. Record with check code is written into non-volatile memory. Reset replaces fuse, checks appearance and parameters of transient voltage suppressor and positive temperature coefficient thermistor, discharges limited energy storage and performs soft start pre-charge, and restores permission after manual release of latch.
[0175] Engineering points: the common loop of comparator and gate drive keeps the shortest path; the selection of thyristor focuses on holding current and rising edge immunity; the DC bias point of saturable inductor is set at the nonlinear steep section to obtain effective rising edge suppression; the thermal capacity and action characteristics of positive temperature coefficient thermistor and fuse are coordinated with the conduction capacity of thyristor. The above structure and process are based on common devices and technology, and can be directly implemented in the intrinsic safety power supply system in the explosive gas environment of coal mine.
[0176] Preferably, event record data includes trigger source, hardware off time, thyristor on time, fuse melting time, time window energy barrier value snapshot and energy package record data segment, which is used for fault review and recovery process.
[0177] Event record adopts intrinsic safety side black box structure, which is composed of isolated sampling, independent clock, non-volatile memory and power supply for power failure. Independent clock is composed of temperature compensated crystal oscillator and counter, and power failure supply is provided by small super capacitor, which ensures one atomic write after shutdown. Non-volatile memory preferably ferroelectric random access memory or equivalent level of storage memory with high endurance, which manages multiple records in a ring way.
[0178] The data structure is divided into two layers. The first layer is event header, which includes event number, trigger source, hardware off time, thyristor on time, fuse melting time, record start and end index and check code. The second layer is event load, which includes time window energy barrier value snapshot and energy package record data segment. Time window energy barrier value snapshot is composed of transient window energy barrier value and thermal window energy barrier value, each of which saves several sampling points before and after triggering. Energy package record data segment is a sequence centered on the triggering time, which includes serial number, time stamp and single package energy estimation.
[0179] To unify the time reference, all time fields are generated by the same hardware timer, and are aligned to the reference clock during power-on self-test. The key time difference is used to judge the response speed of the link, and the calculation formula is as follows:
[0180] Δt cut =t cut -t trigger
[0181] Δtscr = t scr -t cut
[0182] Δt fuse = t fuse -t scr
[0183] Δt cut is the time delay from trigger to hardware shutdown, Δt scr is the time delay from hardware shutdown to SCR turn-on, Δt fuse is the time delay from SCR turn-on to fuse blow, Δt trigger is the trigger timestamp, t cut is the hardware shutdown timestamp, t scr is the SCR turn-on timestamp, t fuse is the fuse blow timestamp. For fast assessment of the out-of-limit energy, the recording unit gives the energy accumulation within the window simultaneously:
[0184]
[0185] E ∑ is the energy accumulation within the window, is the energy packet index set within the selected time window, is the energy estimation value of the kth energy packet.
[0186] The determination of the trigger source is completed by the hardware logic, including the overvoltage comparator, the overcurrent comparator, the reverse current comparator, the temperature sensor, the correlation calculation mismatch, and the time window energy barrier value out-of-limit. Immediately after the trigger, the write pointer of the ring buffer is frozen, and the data within the preset time before and after the trigger is copied to the event load; at the same time, the snapshot of the instantaneous window energy barrier value and the hot window energy barrier value is captured and written into the timestamp of the event header. In order to prevent the recording from being interrupted due to power drop, the black box first writes the necessary minimum set after the trigger, including the event number, the trigger source, and the hardware shutdown time, and then completes the writing of the remaining fields under the support of the power drop holding power.
[0187] The implementation of the acquisition channel is as follows. The intrinsically safe output voltage and the intrinsically safe output current are sampled by the isolated analog-to-digital converter, and the sampling is aligned with the energy packet recording timestamp; the SCR turn-on time is determined by detecting the voltage step of the port and cooperating with the gate drive feedback; the fuse blow time is determined by the joint determination of the voltage loss between the series resistors and the continuous open circuit criterion. All digital quantities are de-bounced and consistency checked, and then written into the cache after passing.
[0188] The write and protection mechanism adopts double buffering and check code. The event load is first written to a temporary page, and after being filled, the check code is calculated and submitted at one time; if the submission fails, retry in the next page and mark the bad page count. When the ring is rolled back, the strategy of "deleting the oldest complete record first and writing a new record" is adopted to ensure that the black box contains only complete records at any time.
[0189] The fault recovery process includes three steps. First, read the energy barrier value snapshot and energy package record data segment within the time window, check whether the energy accumulation trend before triggering and the energy decay after triggering meet the energy limit strategy. Second, calculate the three delay times to determine whether the hardware link meets the expected response budget; if any delay exceeds the limit, enter the hardware self-check and parameter setting. Third, combine the trigger source and energy segment to locate the fault type, such as short-time impact out-of-limit, continuous overload or backflow caused by reverse current.
[0190] The recovery process is executed after the on-site safety is confirmed by the human. Replace the fuse and check the appearance and parameters of the silicon-controlled rectifier, transient voltage suppressor and positive temperature coefficient thermistor, discharge the limited energy storage, and perform soft start pre-charging. Before recovery, the controller performs read-only verification on the latest event record, and after verification, the latch is released, the token allocation is restarted, and the cross-domain link consistency is verified in low-speed diagnosis mode, and then gradually recover to the target energy package rate command.
[0191] Through the above design, the event record solidifies the trigger reason, action timing and energy evidence into a traceable data set, providing direct evidence for safety audit, device setting and on-site maintenance; the record path is mainly hardware and supplemented by software, with power failure retention and abnormal self-healing ability, suitable for engineering application in intrinsically safe power supply systems in coal mine explosive gas environment.
[0192] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system or a computer program product. Therefore, the present application can adopt a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects.
[0193] The above is only an embodiment of the present application and is not intended to limit the present application. Those skilled in the art can make various modifications and changes to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principles of the present application shall be included in the scope of the claims of the present application.
Claims
1. An intrinsic safety power supply control method for an explosion-proof robot, characterized by, The method comprises the following steps: In the non-intrinsic domain, the battery power is electrically isolated and outputted as discrete energy packets after being limited by cycle-by-cycle hardware current limiting and single packet energy, and energy packet record data is generated; In the intrinsic domain, output shaping is performed by limited energy storage, and time window energy barrier values are calculated according to the energy packet record data, and a hardware shutdown instruction is generated when the barrier is crossed; According to the task power demand and the energy barrier value, token-based energy scheduling is performed, energy packet rate instructions are generated and sent to the non-intrinsic domain; A double-chain safety path of active shutdown chain and passive energy limiting chain is established, and fast disconnection and clamping are implemented in response to the hardware shutdown instruction or the hardware abnormality detection signal, and event record data is formed.
2. The method of claim 1, wherein, The electrical isolation in the non-intrinsic domain is achieved by an isolation transformer, the cycle-by-cycle hardware current limiting is achieved by a current sampling resistor and a comparator to control the on-time of the main switch, and the energy packet record data includes serial number, time stamp and single packet energy estimation.
3. The method of claim 1, wherein, The limited energy storage in the intrinsic domain includes super capacitor and series inductor, and the output shaping includes reverse current blocking and soft start pre-charging of ideal diode controller, and peak shifting is achieved by switched capacitor circuit.
4. The method of claim 1, wherein, During the output shaping process, correlation calculation is performed on the energy packet arrival sequence and pseudo-random sequence to verify the consistency of the cross-domain link, and a hardware shutdown instruction is generated when the correlation coefficient is below a threshold.
5. The method of claim 1, wherein, The time window energy barrier value includes the instantaneous window energy barrier value and the thermal window energy barrier value, the instantaneous window energy barrier value is calculated based on the energy packet record data in the recent time window and the limited energy storage voltage, and the thermal window energy barrier value is calculated based on the energy packet record data in the long time window.
6. The method of claim 1, wherein, The amplitude and phase response of the preset test frequency point are calculated to obtain the equivalent resistance, equivalent inductance and equivalent capacitance, and the equivalent parameters and arc characteristic parameters are taken as the input of the token-based energy scheduling.
7. The method of claim 1, wherein, The token-based energy scheduling limits the energy packet rate instruction and the number of energy packets in the instantaneous window according to the instantaneous window energy barrier value and the thermal window energy barrier value respectively.
8. The method of claim 1, wherein, Before generating the energy packet rate instruction, the time window energy barrier value of the next time window is extrapolated according to the historical energy packet record data and the current energy allocation plan, and when the extrapolation result approaches the threshold, the energy packet rate instruction is reduced and the energy allocation of the low-priority subsystem is stopped.
9. The method of claim 1, wherein, The active shutdown chain includes power switch gate shutdown and silicon controlled short circuit clamping, the passive energy limiting chain includes transient voltage suppressor, positive temperature coefficient thermistor, saturable inductor and fuse, and the sequence of shutdown, clamping and fusing is executed in order.
10. The method of claim 1, wherein, The event record data includes trigger source, hardware shutdown time, silicon controlled silicon conductive time, fuse melting time, time window energy barrier value snapshot and energy packet record data segment, which is used for fault review and recovery process.