Boot-up driving inverter safe starting control method, device, equipment and medium
By collecting and processing the inverter output filter inductor voltage, and determining the safe state before charging the bootstrap capacitor, the problem of inrush current and bridge arm shoot-through during inverter startup under unfavorable initial conditions is solved, thus achieving a safe and reliable startup process.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- SHENZHEN INTELLIWORK TECH CO LTD
- Filing Date
- 2026-01-09
- Publication Date
- 2026-07-21
AI Technical Summary
In the prior art, when an inverter starts up under unfavorable initial conditions, the contradiction between the hardware limitations of the bootstrap drive circuit and the possible negative residual voltage on the inverter output inductor causes the high-side switching transistor to enter the linear region due to insufficient drive voltage, generating a huge turn-on inrush current, which may cause bridge arm shoot-through, device overheating damage, and system failure.
By acquiring the real-time voltage signal of the inverter output filter inductor, performing analog-to-digital conversion and software calculation, reading the preset negative voltage threshold and performing hysteresis processing numerical comparison, if it is determined to be safe, a drive enable signal is generated to charge the bootstrap capacitor; otherwise, the PWM output and bootstrap drive circuit are blocked to ensure that the switching transistor is turned off, and the voltage is re-detected after a preset delay until it is safe.
Under unfavorable initial conditions, the inverter was able to start safely, avoiding inrush current and bridge arm shoot-through, ensuring reliable charging of the bootstrap capacitor, and improving the safety and reliability of the system.
Smart Images

Figure CN121485455B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of power electronics, and in particular to a method, apparatus, equipment, and medium for safe startup control of bootstrap inverters. Background Technology
[0002] In inverters employing half-bridge or full-bridge topologies, bootstrap drive circuits are commonly used for the high-side switches to reduce costs and simplify design. This circuit requires a critical prerequisite for proper operation: the lower switch in the bridge arm must be able to conduct effectively first to charge the bootstrap capacitor powering the high-side switches, forming a charging loop from ground to the bootstrap capacitor. This means the system must start from an initial electrical state that allows the lower switch to conduct reliably. However, in various practical scenarios such as UPS switching from AC to inverter mode, inverter restarting after fault protection, sudden load changes, or hot-swapping, uncontrollable negative residual voltage may exist on the inverter's output filter inductor due to load feedback energy or system transients. If the control algorithm ignores this state and directly sends a drive signal at the moment of startup, and the initial pulse happens to require the high-side transistor to be turned on, then the lower transistor cannot be effectively turned on due to the negative voltage, and the bootstrap capacitor will not be able to charge. The direct consequence is that the high-side switching transistor enters the linear region due to insufficient drive voltage, generating a huge turn-on inrush current, which is very likely to cause bridge arm shoot-through, device overheating and damage, or even system failure.
[0003] Conventional startup logic in existing technologies typically begins running a preset modulation algorithm upon power-on or upon receiving a startup command. This logic fails to adequately consider and resolve the fundamental contradiction between the hardware limitations of the bootstrap circuit and the diverse and unfavorable initial states of the system, resulting in significant safety hazards and reliability defects. Therefore, there is an urgent need for an intelligent control method that can proactively identify risks and ensure safe startup under any initial state. Summary of the Invention
[0004] The main objective of this invention is to provide a safe startup control method, device, equipment, and medium for a bootstrap inverter. This is achieved by modifying the control algorithm, without adding any power hardware, eliminating the risk of startup surges, and resolving the contradiction between the hardware limitations of the bootstrap drive circuit and the possible negative residual voltage on the inverter output inductor, thereby preventing the safety issues of surge current and bridge arm shoot-through during startup under unfavorable initial conditions.
[0005] To achieve the above objectives, the present invention provides a safe startup control method for a bootstrap inverter, comprising the following steps: In response to a startup event, before the output inverter bridge arm switch tubes are given an effective drive signal, a signal representing the real-time voltage of the inverter output filter inductor is acquired, and the detected voltage is obtained through analog-to-digital conversion and software calculation. The startup event includes at least one of the following: uninterruptible power supply mains-to-inverter switching, fault restart, system power-on initialization, and remote power-on signal. Read the preset negative voltage threshold, which is generated based on the inverter DC bus rated voltage, the inverter bridge arm switch safe operating area information and bootstrap capacitor charging demand information, and is a negative value with a fixed proportion to the DC bus rated voltage. The detected voltage is compared with a negative voltage threshold value with hysteresis processing. The hysteresis processing includes: when the state is unsafe, if the detected voltage is higher than the sum of the negative voltage threshold and a preset hysteresis voltage, it is determined to be safe; when the state is safe, if the detected voltage is not higher than the negative voltage threshold, it is determined to be unsafe. If it is determined to be safe, a drive enable signal is generated to release the blockade on the pulse width modulation (PWM) signal output and the bootstrap drive circuit, and the low-side switch is controlled to turn on for bootstrap capacitor charging. Then the modulation algorithm is started to control the inverter to work. If the system is deemed unsafe, a drive block signal is generated to block the PWM output and the bootstrap drive circuit, ensuring that all switching transistors are turned off. After a preset delay, the system returns to re-execute the detection, and the block is maintained throughout the process.
[0006] Furthermore, the detected voltage is obtained by converting the sampled signal through the analog-to-digital converter built into the inverter's controller, and then by digital processing such as software filtering and conversion by a preset proportional coefficient.
[0007] Furthermore, the sampling circuit of the sampling signal includes a voltage divider unit, a filtering unit, and an anti-interference unit; the preset proportional coefficient is associated with the signal amplification factor, voltage divider ratio, and gain error and offset of the analog-to-digital converter (ADC) of the sampling circuit, and the preset proportional coefficient conversion is achieved through a linear transformation formula.
[0008] Furthermore, the conversion mode of the analog-to-digital converter is configured as a single conversion mode or a continuous conversion mode, and the analog-to-digital conversion is triggered by software; a preset hardware blanking time is waited before sampling to eliminate residual resonance interference in the power circuit; during the sampling process, the PWM output and bootstrap drive circuit are kept in a blocked state to ensure that the inverter bridge arm switch is always turned off.
[0009] Furthermore, during the loop of returning to re-execute the detection, if the cumulative number of loop detections exceeds the preset maximum waiting number, or the cumulative time of drive blocking exceeds the preset maximum waiting time, the startup process is terminated, a fault signal that cannot be automatically reset is generated, and a fault log is recorded.
[0010] Furthermore, the hysteresis voltage is a fixed value of 1V to 10V, or 1% to 10% of the absolute value of the negative voltage threshold.
[0011] Furthermore, the modulation algorithm is a pulse width modulation algorithm commonly used in inverter drives; the inverter startup process adopts a soft-start method that gradually increases the output voltage.
[0012] The present invention also provides a bootstrap inverter safety start control device, comprising: A voltage detection module is used to respond to a startup event and acquire a detection voltage characterizing the output filter inductor voltage of the inverter before the switching transistor of the control inverter arm is turned on. The voltage detection module includes a differential operational amplifier, a voltage divider resistor network and an analog-to-digital converter integrated with a microcontroller. The sampling point is set at the connection node between the output filter inductor and the midpoint of the inverter arm. The logic judgment module is used to compare the detected voltage with a preset negative voltage threshold. The drive control module is used to operate based on the comparison result: when the detected voltage is greater than the negative voltage threshold, it outputs a drive enable signal to allow the drive signal to be output; when the detected voltage is less than or equal to the negative voltage threshold, it outputs a drive block signal to disable the drive signal output. The state management module is connected to the logic judgment module and the drive control module respectively. It is configured to cause the control device to enter a waiting state when the drive control module outputs a drive block signal, and after a preset delay, trigger the voltage detection module to re-detect.
[0013] The present invention also provides a computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the bootstrap drive inverter safe startup control method described in any of the above claims.
[0014] Furthermore, the computer-readable storage medium includes non-volatile memory. Attached Figure Description
[0015] Figure 1 This is a flowchart of a bootstrap inverter safe startup control method according to an embodiment of the present invention; Figure 2 This is a structural block diagram of a bootstrap inverter safety start control device according to an embodiment of the present invention; Figure 3 This is a main power circuit diagram of a bootstrap inverter safe start control method in one embodiment of the present invention; Figure 4 This is a gate drive circuit diagram of a bootstrap inverter safe startup control method according to an embodiment of the present invention; Figure 5This is a voltage detection circuit diagram of a bootstrap inverter safe start control method in one embodiment of the present invention; The realization of the objective, functional features and advantages of the present invention will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation
[0016] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the invention.
[0017] Reference Figure 1 This is a flowchart illustrating a safe startup control method for a bootstrap inverter proposed in this invention, comprising the following steps: S1, in response to the start event, before the output inverter bridge arm switch tube effective drive signal is given, a signal characterizing the real-time voltage of the inverter output filter inductor is collected, and the detection voltage is obtained by analog-to-digital conversion and software calculation. The start event includes at least one of the following: uninterruptible power supply mains-to-inverter switching, fault restart, system power-on initialization and remote power-on signal. S2, Read the preset negative voltage threshold. The negative voltage threshold is generated based on the inverter DC bus rated voltage, the inverter bridge arm switch tube safe operating area information and the bootstrap capacitor charging requirement information, and is a negative value with a fixed ratio to the DC bus rated voltage. S3, compare the detected voltage with the negative voltage threshold value with hysteresis processing. The hysteresis processing includes: when in an unsafe state, if the detected voltage is higher than the sum of the negative voltage threshold and the preset hysteresis voltage, it is determined to be safe; when in a safe state, if the detected voltage is not higher than the negative voltage threshold, it is determined to be unsafe. S4. If it is determined to be safe, a drive enable signal is generated to release the blockade on the pulse width modulation (PWM) signal output and the bootstrap drive circuit, and the low-side switch is controlled to turn on for bootstrap capacitor charging. Then, the modulation algorithm is started to control the inverter to work. S5 If it is determined to be unsafe, a drive block signal is generated to block the PWM output and the bootstrap drive circuit, ensuring that all switching transistors are turned off. After waiting for a preset delay, the test is re-executed, and the block is maintained during this process.
[0018] As described in step S1 above, when the system receives a start event signal from the host computer, mode switching logic, or fault recovery unit, the main controller first performs a state perception operation. Before sending the first valid PWM drive signal to any of the high-side and low-side switches of the inverter bridge arm, it actively samples through its analog-to-digital converter (ADC) channel. After software conversion of the sampled signal, it obtains a detection voltage that can directly or indirectly characterize the voltage state across the output filter inductor, ensuring that any control action is based on a priori judgment of the current critical electrical state of the system.
[0019] As described in step S2 above, the main controller reads the negative voltage safety threshold V_Set that is pre-stored in the non-volatile memory. This threshold V_Set is a negative value that has been theoretically calculated and experimentally verified. It is proportional to the rated voltage of the inverter DC bus. Its setting is based on the rated voltage of the DC bus, the safe operating area information of the inverter bridge arm switch, and the charging requirements of the bootstrap capacitor, ensuring that the bootstrap capacitor Cboot can be effectively charged through the low-side switch at the critical inductor voltage condition.
[0020] As described in step S3 above, the main controller compares the real-time detection voltage obtained in step S1 with the negative voltage threshold V_Set read in step S2 with a value of hysteresis processing, and outputs the judgment result. The hysteresis processing logic is as follows: when the system is in an unsafe state, the detection voltage must be higher than the sum of V_Set and the preset hysteresis voltage to be determined as safe; when the system is in a safe state, the detection voltage is not higher than V_Set to be determined as unsafe. This step determines whether the current initial state of the system is within the safe operating area where the bootstrap drive circuit can work normally.
[0021] As described in step S4 above, if the comparison result of step S3 is safe, the controller will then generate a global drive enable signal. This signal will unlock the output stage of the PWM generator and the bootstrap drive circuit. First, it will control the low-side switch of the inverter bridge arm to turn on to build a bootstrap capacitor charging circuit. After the pre-charging is completed, the preset modulation algorithm will be started to generate drive pulses and output them normally to the drive chip. The inverter bridge arm switch will be controlled to turn on alternately, so that the inverter enters the soft start and normal operation process.
[0022] As described in step S5 above, if the comparison result of step S3 is unsafe, the controller immediately generates and maintains a drive blocking signal, forcing all PWM outputs to be in an invalid state, ensuring that all power switches are turned off, eliminating the risk of bridge arm shoot-through and inrush current. Then, a configurable delay timer is started. After a preset short delay of tens of microseconds, the program flow automatically returns to step S1 to re-detect and judge the voltage. This closed-loop cycle of detection-blocking-waiting-re-detection continues until the residual negative voltage of the inductor naturally decays to above the safety threshold. Only then is the system allowed to exit the loop through path S4, completing the safe start-up and building a robust risk avoidance mechanism.
[0023] In one embodiment, in response to a startup event, before outputting an effective drive signal for the inverter bridge arm switch, a signal characterizing the real-time voltage of the inverter output filter inductor is acquired, and the detected voltage is obtained through analog-to-digital conversion and software calculation. The startup event includes at least one of the following steps: S1, including: uninterruptible power supply mains-to-inverter switching, fault restart, system power-on initialization, and remote power-on signal. S11, detect and confirm the occurrence of a startup event, the startup event including a mode switching instruction from the system state machine, a restart instruction after fault recovery, or an externally input power-on signal; S12, in response to the startup event, configure the controller's analog-to-digital converter (ADC) related registers, set the ADC channel used for voltage sampling to single or continuous conversion mode, and enable interruption for that channel; S13, The signal connected to the sampling circuit is subjected to at least one analog-to-digital conversion through the ADC channel to obtain the original digital code value representing the analog voltage; S14, the original digital code value is subjected to software filtering processing, and converted into an actual voltage physical quantity according to a preset scaling factor to obtain the detection voltage.
[0024] In practical implementation, when the system's main controller MCU detects a valid start event signal through its general-purpose input / output ports, communication interfaces, or internal state machine flags, this event triggers a high-priority software interrupt or task. This start event specifically originates from: a "mains bypass to inverter" instruction issued by the system state machine, a "restart" instruction after the fault protection logic is released, or an initialization completion flag after hardware power-on reset. After responding to this event, the controller executes a safety status detection process.
[0025] Figure 4 The pai8233C-WR driver chip in the middle and Figure 3 The connection relationship is as follows: the pai8233C-WR driver chip is a dual-channel driver architecture, and its first channel SH_G output terminal is connected to... Figure 3 The gate of Q1, i.e. Figure 3 The FH_G pin drives the high-side main power transistor Q2 via Q1, and the output of the second channel SL_G is connected to... Figure 3 The gate of Q3, i.e. Figure 3 The “FL_G” pin drives the low-side main power transistor Q4 via Q3. Figure 3 Q2 and Q4 are the main power transistors of the inverter bridge arm. Both of them have integrated parasitic freewheeling diodes D: the freewheeling diode of Q2 is connected in reverse parallel between its drain (connected to BUS+) and source, and the freewheeling diode of Q4 is connected in reverse parallel between its drain and source (connected to BUS-). This is used to provide a discharge path for the freewheeling current of the output filter inductor L6 when Q2 and Q4 are turned off, so as to avoid the generation of voltage spikes across the main power transistors due to sudden current changes. Figure 3 TP61 and TP62 are voltage sampling test points for the output filter inductor L6. TP61 is connected to pin 3 of L6, and TP62 is connected to pin 2 of L6. Both serve as the input terminals of the voltage sampling circuit. Together with C102 (4.7nF 400V), C111 (4.7nF 400V), R341 (200K), R342 (200K), and R343 (200K), they form a voltage divider filter circuit to collect the real-time voltage signal across L6. TP3 is deployed at the input node of operational amplifier U38A, TP4 is deployed at the connection node between the drain of Q2 and BUS+, TP7 is deployed at the gate of Q1 (FH_G), TP10 is deployed at the source of Q1, and TP13 is deployed at the gate of Q3 (FL_G). These test points are used to collect the voltage signal of the corresponding node during debugging to verify the accuracy of the sampling circuit and the driving state of the switching transistor. Figure 3 The core circuit of the medium voltage sampling link is as follows: the voltage signal at both ends of L6 is input to the IP and pins of the U15 voltage sampling chip via TP61. The VCC pin of U15 is connected to a 3.3V power supply. Its peripheral components R317 (10R) and C80 (1NF) are used to suppress interference. The output signal of U15 is input to the IN1 and pins of the operational amplifier U38A (AD8552M / TR) via R315 (10K) and C83 (1NF). U38A converts the differential signal into a single-ended signal, outputs it to the IL-INV node via R74, and then filters it via C288 (1NF) before inputting it to the ADC sampling channel of the controller to realize the amplification and adaptation of the voltage signal. The software layer of the controller sets an internal "global security pre-check in progress" flag and calls the hardware abstraction layer function to perform targeted configuration of the analog-to-digital converter (ADC) module: specifically, the controller enables the clock of the ADC module and simultaneously... Figure 4 Setting the DISABLE enable pin of the pai8233C-WR driver chip to low forces the SH_G and SL_G outputs to be invalid, ensuring... Figure 3Q1, Q3, Q2, and Q4 are all kept off to avoid the risk of accidental conduction during the pre-detection process. Then, an ADC channel corresponding to the voltage sampling link is configured, which receives the IL-INV single-ended voltage signal processed by U38A. The controller sets the ADC sampling period and resolution and configures it as a software-triggered single-conversion sequence. To eliminate residual resonance interference after the switching transistors in the power loop are turned off, the program waits for a 2-microsecond hardware blanking time to ensure the voltage signal is stable at the sampling moment. The controller initiates a precise analog-to-digital conversion by writing a command to the ADC's trigger register, converting the analog voltage signal of the IL-INV node (i.e., the processed signal representing the voltage across L6). After the ADC conversion is complete, the controller is notified via an interrupt signal or status flag. The controller then reads the original digitized code value (an integer ranging from 0 to 4095) from the ADC data register in the corresponding interrupt service routine or polling detection process. Finally, the raw digital code values are processed by software to convert them into usable voltage physical quantities: a moving average filter or median filter is applied to suppress random noise in the ADC sampling, followed by calling calibration parameters pre-stored in non-volatile memory, which are associated with... Figure 3 The resistance ratio of the voltage divider circuit, the amplification factor of U38A, and the gain error / offset of the ADC are converted into a characteristic value using the linear transformation formula: Actual Voltage = (Filtered Digital Code Value × ADC Reference Voltage / Maximum Code Value - Offset) × Calibration Coefficient. Figure 3 The detection voltage V across the output filter inductor L6 is controlled within a window of less than 100 microseconds from event response to obtaining a reliable detection voltage V. Throughout this process, the time is strictly controlled by... Figure 4 The driver chip's DISABLE pin is continuously locked to the PWM output, ensuring Figure 3 All driving transistors and main power transistors are always in the off state. The detection voltage V obtained is used as a key state variable and stored in a designated memory location as the sole data input for the safety judgment in the subsequent step S2.
[0026] In one embodiment, step S2, which reads a preset negative voltage threshold, the negative voltage threshold being generated based on the inverter DC bus rated voltage, inverter bridge arm switch safe operating area information, and bootstrap capacitor charging demand information, and being a negative value with a fixed proportion to the DC bus rated voltage, includes: S21, Read the preset negative voltage threshold V_Set from the non-volatile memory; S22, after performing anti-interference filtering on the detection voltage V, the numerical comparison function is called to compare the filtered detection voltage V with the negative voltage threshold V_Set with hysteresis processing. The logic of hysteresis processing is as follows: when the system is currently in an unsafe state, the detection voltage V must be greater than the sum of the negative voltage threshold V_Set and the preset hysteresis voltage to be determined as a safe state; when the system is currently in a safe state, it is determined as unsafe if V ≤ V_Set. S23. Based on the comparison operation result with hysteresis processing, generate and output a binary logic flag bit, where the first logic state represents V>V_Set and the second logic state represents V≤V_Set.
[0027] In the specific implementation process, in the independent voltage detection circuit, that is... Figure 3 The circuit consisting of U15, U38A, and a voltage divider filter network completes... Figure 1 After precise quantization of the detection voltage V characterizing the output filter inductor L6, Figure 5 The current detection module synchronously acquires the input current signal, and the logic judgment module then initiates its core comparison and judgment process. First, the controller accesses a specific parameter sector of the non-volatile memory via the internal bus to read the pre-stored negative voltage safety threshold V_Set. The threshold setting is based on the latest... Figure 3 , Figure 4 The characteristics of the hardware shown include: Figure 3 The rated DC bus voltage V_bus of BUS+ / BUS- is... Figure 3 The safe operating area characteristics of the high-side main power transistor Q2 and the low-side main power transistor Q4. Figure 3 The inductance and parasitic resistance parameters of the output filter inductor L6. Figure 4 The driving capability parameters of the gate drive circuit of the pai8233C-WR and the charging requirements of the bootstrap capacitor C134 are analyzed. The threshold calculation formula is defined as V_Set=-k×V_Bus, where the proportional coefficient K is verified by triple verification: Analysis Figure 4 The reliable operating conditions of the bootstrap drive circuit under negative voltage ensure that the bootstrap capacitor C134 can form an effective charging circuit when the low-side main power transistor is turned on: DC drive power supply → bootstrap diode D19 → bootstrap capacitor C134 → low-side main power transistor Q4 → BUS-; the simulation system operates under worst-case startup scenarios such as UPS mode switching and fault restart. Figure 3 The voltage transient response of the output filter inductor L6 is analyzed; the optimal value is determined through experimental verification. This is significant because it ensures that when the detected voltage V > V_Set, Figure 3 The low-side main power transistor Q4 of the intermediate inverter bridge arm can be Figure 4The pai8233C-WR driver chip, amplified by Q3, is reliably driven to conduct, thereby pre-charging the bootstrap capacitor C134 and preventing the high-side main power transistor Q2 from entering the linear region due to undervoltage of the bootstrap capacitor, which could cause inrush current. In a preferred embodiment, V_Set is programmed to be a fixed ratio to V_bus, for example, V_Set = -0.1 × V_bus. If V_bus = 400V, then V_Set = -40V. This allows the safety criterion to adapt to inverter systems of different power levels. After reading the threshold V_Set parameter, the controller loads it into a designated variable in the core register or random access memory (RAM) for real-time numerical comparison. Subsequently, the controller calls its arithmetic logic unit to perform the core comparison operation, directly subtracting the value of the detected voltage, which has been converted to the actual voltage value from step S1, from the V_Set value read from the RAM. This comparison operation is performed at the hardware level by the integer or floating-point comparison unit of the main controller or digital signal processor, and its result is directly reflected in the zero flag (ZF), negative flag (NF), and other flags in the processor's status register. To ensure the stability and anti-interference capabilities of the judgment, and to avoid... Figure 3 Voltage detection circuit Figure 5 The residual sampling noise from the power circuit EMI introduced by the current detection module (after suppression by the common-mode inductor SQ1918 / 10A) can be mitigated by the software performing moving average filtering or median filtering on 3-5 consecutively acquired detection voltage values before performing this critical comparison. This process suppresses potential sampling noise and occasional interference. Furthermore, based on the state of this hardware flag, the program generates a software logic flag for control flow decisions: if the comparison result is V>V_Set, i.e. Figure 3If the residual voltage of the output filter inductor L6 is within the safe range and meets the bootstrap capacitor charging condition, the "safety state flag" defined in RAM is set to '1' (Boolean true). If the result is V≤V_Set, the flag is cleared to '0' (Boolean false). The state of this logic flag directly determines whether the program flow jumps to S3 safe start execution or S4 risk avoidance loop. To further enhance the system's anti-disturbance capability and stability near the threshold boundary and prevent frequent oscillations of the flag between safe and unsafe states due to small voltage fluctuations, this embodiment introduces a hysteresis voltage ΔV (e.g., 5V) in the comparison logic. Specifically, two comparison conditions with slight offsets are set in the software logic. When the system is currently in an unsafe state with the flag set to '0' and attempts to enter a safe state, the judgment condition is more stringent, requiring V>V_Set+ΔV. When the system is currently in a safe state with the flag set to '1' and determines whether to switch to an unsafe state, the original condition V≤V_Set is used. The comparison logic with hysteresis effectively creates a buffer region at the safety threshold boundary, significantly improving the system's decision robustness near critical states and preventing control oscillations caused by noise. The execution cycle of the entire S2 step is strictly controlled to the microsecond level of <20μs, achieving precise control over the system's performance. Figure 3 Rapid, accurate, and stable determination of the initial safety state of the power circuit.
[0028] In one embodiment, the detected voltage is compared with a negative voltage threshold value with hysteresis processing. The hysteresis processing includes step S3: when the detected voltage is higher than the sum of the negative voltage threshold and a preset hysteresis voltage in an unsafe state, it is determined to be safe; when the detected voltage is not higher than the negative voltage threshold in a safe state, it is determined to be unsafe. This step includes: S31, read the detection voltage V, the preset negative voltage threshold V_Set and the hysteresis voltage ΔV obtained in step S1, and read the current safety status flag of the system; S32, if the current state is unsafe, then execute the first comparison logic: determine whether V is greater than V_Set plus ΔV. If so, update the state flag to safe; otherwise, keep it unsafe. S33, if the current state is safe, then execute the second comparison logic: determine whether V is not greater than V_Set. If so, update the state flag to unsafe; otherwise, keep it safe. S34 stores the updated security status flag to a specified address in RAM as the basis for subsequent driver control decisions.
[0029] In the specific implementation process Figure 3 An independent voltage detection circuit, consisting of U15, U38A, and a high-resistance precision voltage divider filter network, completes the quantization of the detected voltage V. Figure 5A current detection module consisting of a medium current detection chip U16 and a common-mode inductor SQ1918 / 10A synchronously acquires the input current signal. After software filtering and linear conversion in step S1, the controller initiates the hysteresis-based numerical comparison process in step S3. This process effectively suppresses hysteresis through precise state-based judgment logic. Figure 3 The small fluctuations in the detection voltage caused by electromagnetic interference (EMI) in the power circuit ensure the robustness of subsequent drive control decisions. Figure 4 The reliable operation of the pai8233C-WR gate driver chip and the effective pre-charging of the bootstrap capacitor C134 provide a basis for preliminary judgment. The voltage sampling signal of the output filter inductor L6 is directly taken from... Figure 3 The differential measurement points TP61 and TP62 at both ends of L6 directly characterize the residual energy state of the inductor; when the inductor generates a negative voltage due to load feedback, the signal is transmitted through... Figure 3 The voltage detection circuit, after common-mode rejection implemented by U15 and peripheral differential circuits, is input to differential operational amplifier U38A for signal conditioning. Figure 5 The sampling signal of the current detection module is taken from Figure 3 The input power circuit is used to acquire the input current signal. This signal is then processed by the common-mode inductor SQ1918 / 10A to suppress common-mode interference before being input to the current detection chip U16. U16 converts the current signal into a single-ended voltage signal that matches the controller's ADC. Meanwhile, the voltage signal from the output filter inductor L6 is processed by... Figure 3 The differential operational amplifier U38A in the independent voltage detection circuit eliminates common-mode interference and performs single-ended conversion before being converted into a digital signal by an ADC. This dual anti-interference processing ensures the accuracy of subsequent numerical comparison and determination. The controller quickly loads all parameters required for comparison and determination via its internal data bus: first, it reads the detection voltage V generated in step S1 from a specified address in RAM; this voltage characterizes… Figure 3 The real-time residual voltage of the output filter inductor L6 has been eliminated by moving average / median filtering. Figure 3 The residual sampling noise introduced by the power loop EMI through the voltage detection circuit is then synchronously accessed to the dedicated parameter sector of the non-volatile memory to read the preset negative voltage threshold V_Set and hysteresis voltage ΔV, where V_Set is based on... Figure 3 The rated DC bus voltage V_bus of BUS+ / BUS-, the safe operating area characteristics of the inverter bridge arm switches, and Figure 4The charging demand of the bootstrap capacitor C134 is generated according to the formula V_Set=-k×V_bus. For example, when V_bus=400V, V_Set=-40V. ΔV is preset to the optimal anti-interference value of 5V. The value is determined by system simulation (UPS mode switching, worst-case fault restart) and physical experiment. It has good noise suppression and response speed balance characteristics. The initial default value of the current safety status flag of the system is unsafe, corresponding to logic 0. It is read from the dedicated status flag area of RAM. After all parameters are loaded, the core comparison and judgment stage is entered. If the current safety status flag read is unsafe (logic 0), the controller calls the internal arithmetic logic unit (ALU) to first perform the sum operation of V_Set and ΔV. For example, when V_Set = -40V and ΔV = 5V, the result is -35V. This operation is completed by the hardware ALU in one step without software iteration loss. Then, the detected voltage V obtained in step S1 is compared with the sum value using a hardware-level integer / floating-point comparison. This comparison operation is directly executed by the hardware comparison unit of the main controller without software intervention. The result is fed back to the dedicated flag bit of the processor status register in real time: when V > -35V, the negative flag bit NF of the status register is set to 0 and the zero flag bit ZF is set to 0, and the safety status flag in RAM is immediately updated to safe (logic 1); when V ≤ -35V, NF is set to 1 or ZF is set to 1, and the safety status flag remains unsafe (logic 0). This ensures the strictness of the judgment for the transition from an unsafe state to a safe state and avoids the false triggering of the safe state due to small voltage fluctuations. If the current safety status flag is safe (logic 1), the controller directly compares the detected voltage V with the negative voltage threshold V_Set (e.g., -40V) through the hardware comparison unit, without adding ΔV. The comparison result is still fed back in real time through the status register flag: when V≤-40V, NF is set to 1 or ZF is set to 1, and the safety status flag is updated to unsafe (logic 0); when V>-40V, NF is set to 0 and ZF is set to 0, and the safety status flag remains safe (logic 1). This dual threshold difference design forms a hysteresis buffer region with a width of ΔV, which ensures the timeliness of the transition from safe to unsafe state and avoids frequent state switching in critical states. The updated safety status flag (logic 0 or logic 1) is written to a designated locked address in RAM. The address is configured with a write protection attribute of "only writable in step S3" to prevent low-priority tasks or interrupts from accidentally modifying the flag status. The controller synchronously sends a flag update completion signal to the interrupt controller, triggering a ready interrupt for subsequent drive control processes, ensuring that the latest safety judgment result can be obtained in real time for step S4 safe start or step S5 risk avoidance. The execution cycle of the entire S3 step is strictly controlled within 5μs. Relying on hardware-based computing and comparison units, it achieves rapid determination without software redundancy, accurately matching the real-time requirements of the inverter startup process, and providing reliable state support for subsequent bootstrap capacitor charging and bridge arm switch driving.
[0030] In one embodiment, if safety is deemed assured, a drive enable signal is generated to release the blockade on the pulse width modulation (PWM) signal output and the bootstrap drive circuit, and the low-side switch is controlled to turn on for bootstrap capacitor charging. Step S4, which then initiates the modulation algorithm to control the inverter's operation, includes: S41 generates a global drive enable signal to unlock the software / hardware PWM output. S42, configures the PWM module to force the low-side switch to be turned on and the high-side switch to be turned off, thus constructing a bootstrap capacitor charging circuit; S43 initializes the PWM time base / compare register, completing the configuration of parameters such as switching frequency and dead time; S44, start the PWM counter and perform bootstrap capacitor pre-charge; S45 executes the soft-start strategy, releases the PWM forced function, and starts the modulation algorithm to control the inverter to work normally.
[0031] In the specific implementation process, when the core computing unit of the controller reads the state variable of the specified lock address in RAM and confirms that the security flag bit updated in step S3 is valid (logic 1), that is... Figure 3 When the detection voltage V of the output filter inductor L6 exceeds the negative voltage threshold V_Set, the bootstrap driver circuit's safe startup condition is met. Subsequently, hardware register configuration and driver link unlocking operations are initiated. The core purpose is to ensure, from the underlying hardware and software level, that... Figure 3 Power circuit, Figure 4 The bootstrap drive circuit's operational sequence is absolutely safe, with no risk of unauthorized conduction. The controller first clears its internally maintained "global drive lockout" software flag. This flag is set before the safety pre-check in step S1 and during the subsequent loop detection phase in step S4, preventing the PWM interrupt service routine from updating modulation parameters or drive control registers at the program logic level, thus blocking the generation of invalid PWM signals from the software level. Subsequently, a high-level signal is output through the general purpose input / output (GPIO) pin to release the lockout. Figure 4 The hardware blocking of the pai8233C-WR gate driver chip means that even if the PWM module outputs a valid pulse, if the pai8233C-WR's DISABLE enable pin is low, the drive signal will still be blocked by the chip's internal hardware logic and cannot be output to the gate of the switching transistor. Only when the DISABLE pin is set to high can the driver chip be fully enabled, and the PWM pulse can then be amplified by the chip's internal circuitry and output to the gate of the inverter bridge arm switching transistor. A preset configuration value is written to the PWM module's operation limit register to... Figure 3In the inverter bridge arm, all high-side main power transistors Q1 and Q2, and their corresponding PWM channels, are forcibly locked to an invalid low level to ensure that Q2 and Q4 are completely off. Only the PWM channel corresponding to Q3 is forcibly output to a valid high level to ensure that the low-side main power transistor Q3 is reliably turned on, while Q4 and its corresponding drive link remain synchronously off, preventing unrelated circuits from interfering with bootstrap charging. After configuration, the output enable bit of the PWM module's main control register is set, and the level lock of the hardware output pin is released, allowing the aforementioned forced level signal to be output through the controller's GPIO-PB0 / GPIO-PB1 pins to... Figure 4 The PWMH-INV / PWML-INVS input ports of the pai8233C-WR driver chip are used. At this time, the high-side output terminal SH_G of the pai8233C-WR outputs a low level, and the low-side output terminal SL_G outputs a high level. After amplification by the driver transistor, this precisely controls the high-side main power transistor Q2 to turn off and the low-side main power transistor Q3 to turn on, ensuring that the low-side main power transistor is preferentially and reliably turned on. Figure 4 The charging of bootstrap capacitor C134 creates the necessary circuit conditions. When Figure 3 Low-side main power transistor Q3 via Figure 4 After the high-level drive output of the driver chip SL_G is turned on, it is connected with... Figure 4 The bootstrap circuit forms a closed-loop charging circuit, specifically through the following path: Figure 4 Driver chip power supply terminal (12V) → Bootstrap diode D19 → Bootstrap capacitor C134 → Figure 3 Bridge arm midpoint → Figure 3 The low-side main power transistor Q3 is turned on → BUS → Figure 4 The driver chip's ground terminal forms a complete and non-redundant charging path. The effective conduction of this path depends on the reliable conduction of Q3, and the conduction state of Q3 is determined by... Figure 4 The high level at the output of the driver chip SL_G is maintained continuously, and the circuit linkage between the two ensures that the bootstrap capacitor C134 can quickly establish a stable voltage. Subsequently, the controller continues to initialize the time base unit and comparator unit of the PWM module, and all parameter configurations are matched. Figure 3 The hardware characteristics and specific configuration of the power circuit are as follows: ① Set the period register to determine the PWM switching frequency as 20kHz, and the frequency adaptation... Figure 3 The inductance of the output filter inductor L6 and the capacitance of the output filter capacitor are adjusted to avoid the inherent resonant frequency of the power circuit, preventing voltage and current spikes caused by resonance; ② A dead-time register is configured, setting a dead time of 5~10μs, which is used for compensation. Figure 3The switching delay characteristics of Q2 and Q3 in the same bridge arm prevent bridge arm shoot-through caused by timing deviation between them, avoiding the risk of direct short circuit from BUS+ to BUS- and burnout; ③ Initialize the comparator register: The comparator register CMPA, which controls the turn-on time of the high-side main power transistor Q2, is initialized to a value greater than that of the period register to ensure that there is no high-side transistor turn-on event in the first PWM cycle, ensuring charging safety; the comparator register CMPB, which controls the turn-on time of the low-side main power transistor Q3, is initialized to a non-zero positive number much smaller than the period value to ensure that the low-side transistor is triggered to turn on immediately after the PWM counter starts, without charging delay. When the controller finally sets the count enable bit of the PWM time base control register, the PWM counter starts to increment. The first output valid pulse maintains the safe state of "low-side main power transistor Q3 on, high-side main power transistor Q2 off", which is for Figure 4 The bootstrap capacitor C134 provides an enhanced charging circuit: Figure 3 DC bus BUS+→ Figure 4 Bootstrap diode D19 → Figure 4 Bootstrap capacitor C134 → Figure 3 Bridge arm midpoint → Figure 3 The low-side main power transistor Q3 is turned on. Figure 3 DC bus BUS-. Because the low-side transistor is continuously and reliably on, the bootstrap capacitor C134 can charge to a stable drive voltage of 12~13V within microseconds, which meets the requirements. Figure 4 The driver chip's requirement for the drive voltage of Q2 lays a solid hardware foundation for the normal turn-on of the subsequent high-side transistor. To avoid Figure 3 The output filter inductor L6 and output filter capacitor experience inrush currents due to voltage surges, damaging power devices. In the subsequent 3-5 PWM cycles, the controller executes a segmented soft-start strategy: keeping Q2 off throughout, and gradually increasing the value of the comparator register CMPB cycle by cycle to linearly increase the duty cycle of the low-side transistor, creating a gentle soft-start ramp for the output voltage, gradually releasing the residual energy of L6 and establishing a stable output voltage. Once the output voltage reaches more than 90% of its rated value and remains stable, the value of the comparator register CMPA is adjusted to the normal SPWM / SVPWM modulation range. Simultaneously, a configuration command is written to the PWM module to release the "software forced" function of the PWM channel, unlocking the level lock of the high and low-side transistors. Afterward, the controller generates a symmetrical drive pulse sequence according to a preset SPWM / SVPWM modulation algorithm. This pulse sequence is then processed... Figure 4 After amplification, the pai8233C-WR driver chip drives... Figure 3 The main power transistors Q1, Q2, Q3, and Q4 are turned on alternately according to a predetermined timing sequence, allowing the inverter to smoothly leave the pre-charge state and enter the normal inverter operation state, achieving seamless switching from mains bypass to inverter output or safe restart after a fault.
[0032] In one embodiment, if an unsafe condition is determined, a drive block signal is generated to block the PWM output and the bootstrap drive circuit, ensuring that all switching transistors are turned off. After a preset delay, the detection is re-executed, and step S5, which maintains the block during this process, includes: S51, risk response and mandatory hardware blocking; S52, waiting for loop management and timer triggering; S53, interrupt response and re-detection trigger; S54, Active State Resampling and Security Reassessment; S55, timeout monitoring and ultimate fault protection.
[0033] In the specific implementation process, when the controller's logic judgment module determines that the detected voltage V ≤ the negative voltage threshold V_Set, the system immediately enters a risk avoidance loop of "hardware forced blocking - timed waiting - active re-detection" to block the energy flow of the power circuit and eliminate risks such as bridge arm shoot-through and inrush current. The drive control module executes a deterministic hardware operation sequence to ensure absolute safety: by writing preset safety configuration values to the PWM module's action limit register and output enable register, Figure 3 Simultaneously, all PWM channels corresponding to Q1, Q2, Q4, and Q3 of the inverter bridge arm are forcibly locked to an invalid low level; and the count enable bit of the PWM time base control register is cleared at the same time, stopping the PWM counter from running, ensuring that no valid drive pulses are output from the source of the PWM signal generation. Figure 4 The blocking logic of the pai8233C-WR driver chip and Figure 3 The switching transistors provide dual hardware protection: the controller outputs a low level through a general-purpose input / output (GPIO) pin, disabling the DISABLE enable pin of the driver chip. At this time, the chip's internal hardware logic forcibly pulls the outputs of SH_G and SL_G low, preventing the drive signal from being transmitted even if the PWM module has an abnormal output. Figure 3 The gate of the switching transistor; combined with the source blocking of the PWM channel, forms a dual hardware protection of "PWM signal generation blocking + driver chip output blocking". The logic directly acts on... Figure 3 The gates of Q1, Q2, Q3, and Q4 are ensured to have no drive current, completely cutting off the power path from the DC bus BUS+ to the output, thus avoiding the risk of bridge arm shoot-through or false conduction. Finally, the controller sets the "global drive lockout" software flag, prohibiting the PWM interrupt service routine from updating modulation parameters or drive control registers, forming a triple safety guarantee of "software logic lockout + hardware chip lockout + PWM source lockout," ensuring safety from both hardware and software levels. Figure 3All power switches are in a defined off state. After the state management module is activated, it first starts the controller's general-purpose timer GPTM, configures it for automatic reload mode, and sets the timing period to a preset delay of 40μs. This delay must be significantly shorter than... Figure 3 The discharge time constant of the output filter inductor L6 (time constant τ=L / R, where L is the inductance of L6 (4mH) and R is the parasitic resistance of the inductor + the equivalent load resistance (10Ω), calculated to be τ=400μs). After the timer starts counting, the controller main program can enter a low-power sleep mode (reducing system power consumption) or switch to executing low-priority tasks such as system status monitoring and communication heartbeat maintenance until the timer counts down and triggers an interrupt. After the timer counts down, a high-priority interrupt service routine is triggered. This routine only performs a lightweight operation of "setting the 're-detection request' software flag in RAM" and then exits the interrupt—avoiding the interrupt from occupying processor resources for a long time and ensuring system real-time performance. After the controller main program detects the "re-detection request" flag through the polling mechanism, it immediately pauses low-priority tasks or exits sleep mode and triggers the subsequent voltage state resampling process. After the controller responds to the "re-detection request", it immediately calls... Figure 3 The independent voltage detection circuit, composed of U15, U38A, and a high-resistance precision voltage divider filter network, performs a complete state resampling: First, the ADC module is re-enabled, and analog-to-digital conversion is performed on the sampling channel of the voltage detection circuit (corresponding to the TP61 / TP62 test points at both ends of L6); then, the raw ADC code value is subjected to moving average filtering to suppress residual noise introduced by EMI in the power loop; finally, combined with the pre-stored calibration parameters (related to the voltage divider ratio of the voltage detection circuit, the operational amplifier gain of U38A, and the gain error / offset of the ADC), it is converted into the latest detection voltage V_new (characterizing...). Figure 3The real-time residual voltage of the output filter inductor L6 is used. V_new is sent back to the logic judgment module and compared with the negative voltage threshold V_Set with hysteresis: if V_new>V_Set, the loop in step S5 is exited and the process jumps to step S3 to re-execute the safety judgment; if V_new≤V_Set, the "block-wait-re-check" process in S51~S54 is repeated. To deal with extreme scenarios where the negative voltage of L6 cannot decay naturally due to load faults (such as continuous energy feedback), the state management module maintains a "wait timeout counter" to build the ultimate safety boundary: before entering the drive block state each time, the timeout counter is automatically incremented by 1; if the counter value exceeds the preset maximum number of waits (corresponding to a maximum wait time of 20ms), it is judged as a "startup abnormal fault". At this time, the system will perform irreversible safety protection actions: generate a fault alarm signal that cannot be automatically reset, and record the fault code (such as "L6 residual negative voltage timeout without decay"), the system state snapshot at the time of occurrence (including V_new, motherboard, and motherboard), and the system state snapshot at the time of occurrence (including V_new, motherboard, and motherboard). The system records line voltage, timer values, etc., to non-volatile memory; forces the system to completely exit the startup process and enter hardware protection state—by controlling the conduction of the bus discharge circuit to discharge the residual charge of the DC bus capacitor; at the same time, it reports a "safe startup failure" fault to the host computer through onboard indicator lights (such as a red LED that is always on) or communication interface (such as RS485), locks the system state (prohibits the generation of any drive signals), and requires external intervention such as hardware reset and fault diagnosis to release the protection, preventing the system from being in a high-frequency "block-retest" cycle for a long time, and avoiding damage to the controller or drive chip due to continuous high-frequency operation.
[0034] Reference Figure 2 The above is a schematic block diagram of a bootstrap inverter safety start control device according to an embodiment of the present invention, comprising: A voltage detection module is used to respond to a startup event and acquire a detection voltage characterizing the output filter inductor voltage of the inverter before the switching transistor of the control inverter arm is turned on. The voltage detection module includes a differential operational amplifier, a voltage divider resistor network and an analog-to-digital converter integrated with a microcontroller. The sampling point is set at the connection node between the output filter inductor and the midpoint of the inverter arm. The logic judgment module is used to compare the detected voltage with a preset negative voltage threshold. The drive control module is used to operate based on the comparison result: when the detected voltage is greater than the negative voltage threshold, it outputs a drive enable signal to allow the drive signal to be output; when the detected voltage is less than or equal to the negative voltage threshold, it outputs a drive block signal to disable the drive signal output. The state management module is connected to the logic judgment module and the drive control module respectively. It is configured to cause the control device to enter a waiting state when the drive control module outputs a drive block signal, and after a preset delay, trigger the voltage detection module to re-detect.
[0035] In summary, this invention addresses the critical safety issue of inrush current and bridge arm shoot-through during startup of inverters employing bootstrap drive circuits under unfavorable initial conditions by introducing a safety pre-detection method. Upon responding to any startup event but before issuing the first drive pulse, the method proactively detects a signal characterizing the output filter inductor voltage and compares it to a negative voltage safety threshold adaptively set based on the DC bus voltage. Only when the detected voltage exceeds this safety threshold is the drive lock released, allowing the system to start safely; otherwise, the system enters a "detect-lock-wait" loop until the residual negative voltage in the inductor naturally decays to a safe level. This transforms a hardware constraint into a software-manageable state judgment problem, achieving hardware-level reliability improvements through pure algorithmic enhancements.
[0036] An embodiment of the present invention also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the above-described method. It is understood that the computer-readable storage medium in this embodiment can be a volatile readable storage medium or a non-volatile readable storage medium.
[0037] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments of the above methods. Any references to memory, storage, databases, or other media used in the present invention and embodiments can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), dual-rate SDRAM (SSRSDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM, etc.
[0038] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, apparatus, article, or method that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, apparatus, article, or method. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, apparatus, article, or method that includes that element.
[0039] The above description is only a preferred embodiment of the present invention and does not limit the patent scope of the present invention. Any equivalent structural or procedural transformations made based on the content of the present invention specification and drawings, or direct or indirect applications in other related technical fields, are similarly included within the patent protection scope of the present invention.
Claims
1. A method for safe startup control of a bootstrap inverter, characterized in that, Includes the following steps: In response to a startup event, before the output inverter bridge arm switch tubes are given an effective drive signal, a signal representing the real-time voltage of the inverter output filter inductor is acquired, and the detected voltage is obtained through analog-to-digital conversion and software calculation. The startup event includes at least one of the following: uninterruptible power supply mains-to-inverter switching, fault restart, system power-on initialization, and remote power-on signal. Read the preset negative voltage threshold, which is generated based on the inverter DC bus rated voltage, the inverter bridge arm switch safe operating area information and bootstrap capacitor charging demand information, and is a negative value with a fixed proportion to the DC bus rated voltage. The detected voltage is compared with a negative voltage threshold value after hysteresis processing. The hysteresis processing includes: when the state is unsafe, if the detected voltage is higher than the sum of the negative voltage threshold and a preset hysteresis voltage, it is determined to be safe; when the state is safe, if the detected voltage is not higher than the negative voltage threshold, it is determined to be unsafe. If it is determined to be safe, a drive enable signal is generated to release the blockade on the pulse width modulation (PWM) signal output and the bootstrap drive circuit, and the low-side switch is controlled to turn on for bootstrap capacitor charging. Then the modulation algorithm is started to control the inverter to work. If it is determined to be unsafe, a drive block signal is generated to block the PWM output and the bootstrap drive circuit, ensuring that all switching transistors are turned off. After a preset delay, the detection is re-executed, and the block is maintained during this process. The detection voltage is obtained by converting the sampled signal through the analog-to-digital converter built into the inverter controller, and then by digital processing after software filtering and conversion by a preset proportional coefficient. The analog-to-digital converter is configured to either a single conversion mode or a continuous conversion mode, and the conversion is initiated by software trigger. Before sampling, a preset hardware blanking time is waited to eliminate residual resonance interference in the power circuit. During the sampling process, the PWM output and bootstrap drive circuit are kept locked to ensure that the inverter bridge arm switching transistors are always turned off.
2. The bootstrap inverter safe start control method according to claim 1, characterized in that, The sampling circuit of the sampling signal includes a voltage divider unit, a filter unit, and an anti-interference unit; the preset proportional coefficient is associated with the signal amplification factor, voltage divider ratio, and gain error and offset of the analog-to-digital converter (ADC) of the sampling circuit, and the preset proportional coefficient is converted through a linear transformation formula.
3. The bootstrap inverter safe start control method according to claim 1, characterized in that, During the loop of returning to re-execute the detection, if the cumulative number of loop detections exceeds the preset maximum waiting number, or the cumulative time of drive blocking exceeds the preset maximum waiting time, the startup process is terminated, a fault signal that cannot be automatically reset is generated, and a fault log is recorded.
4. The bootstrap inverter safe start control method according to claim 1, characterized in that, The hysteresis voltage is a fixed value of 1V to 10V, or 1% to 10% of the absolute value of the negative voltage threshold.
5. The bootstrap inverter safe start control method according to claim 1, characterized in that, The modulation algorithm is a pulse width modulation algorithm commonly used in inverter drivers; the inverter startup process adopts a soft-start method that gradually increases the output voltage.
6. A bootstrap inverter safety start control device, characterized in that, The bootstrap inverter safe start control method according to any one of claims 1-5, wherein the bootstrap inverter safe start control device comprises: A voltage detection module is used to respond to a startup event and acquire a detection voltage characterizing the output filter inductor voltage of the inverter before the switching transistor of the control inverter arm is turned on. The voltage detection module includes a differential operational amplifier, a voltage divider resistor network and an analog-to-digital converter integrated with a microcontroller. The sampling point is set at the connection node between the output filter inductor and the midpoint of the inverter arm. The logic judgment module is used to compare the detected voltage with a preset negative voltage threshold. The drive control module is used to operate based on the comparison result: when the detected voltage is greater than the negative voltage threshold, it outputs a drive enable signal to allow the drive signal to be output; when the detected voltage is less than or equal to the negative voltage threshold, it outputs a drive block signal to disable the drive signal output. The state management module is connected to the logic judgment module and the drive control module respectively. It is configured to cause the control device to enter a waiting state when the drive control module outputs a drive block signal, and after a preset delay, trigger the voltage detection module to re-detect.
7. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the bootstrap drive inverter safe startup control method as described in any one of claims 1 to 5.
8. The computer-readable storage medium according to claim 7, characterized in that, The storage medium includes non-volatile memory.