Safety monitoring and management system for mine explosion-proof lithium-ion battery trackless rubber-wheeled vehicles
By constructing a dynamic system resilience map, proactive risk exploration and cross-subsystem interactive testing of mine explosion-proof lithium-ion battery trackless rubber-wheeled vehicles were realized. This solved the problem of insufficient safety assessment of existing systems under complex underground working conditions, and provided gradient guidance and intrinsic safety linkage protection to ensure vehicle safety and availability.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- SHANDONG HONGLU HEAVY IND CO LTD
- Filing Date
- 2026-01-28
- Publication Date
- 2026-06-30
AI Technical Summary
Existing monitoring and management systems for explosion-proof batteries used in mining vehicles are unable to identify the risk of lithium plating and dynamic internal resistance fluctuations within the cells under complex underground working conditions. They lack collaborative safety assessments across subsystems, and traditional systems may cause vehicles to lose control when power is lost, lacking flexible retreat strategies.
By employing a proactive risk exploration and cross-subsystem interactive testing method based on operating condition identification, a dynamic system resilience map is constructed. Through comprehensive data acquisition, risk pattern definition, operating condition identification and exploration activation, cross-subsystem interactive testing, dynamic resilience map construction, and decision execution and guidance control, a forward-looking assessment of vehicle system-level risks and resilience adaptive safety control are achieved.
It enables proactive assessment of system-level risks and resilient adaptive safety control for the entire vehicle, and can detect potential risks during the incubation period, providing tiered guidance and intrinsically safe linkage protection to ensure the safety and availability of the vehicle under complex operating conditions.
Smart Images

Figure CN121572805B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of mining explosion-proof machinery and equipment technology, and in particular to a safety monitoring and management system for mining explosion-proof lithium-ion battery trackless rubber-wheeled vehicles. Background Technology
[0002] With the continuous advancement of safe production and intelligent construction in my country's mines, mining auxiliary transportation equipment is undergoing an upgrade from traditional fuel-powered systems to inherently safe, green, and low-carbon electric systems. In the high-gas, flammable, and explosive underground environment, high-performance electric inspection vehicles have become key equipment for improving inspection efficiency and achieving increased efficiency with reduced manpower.
[0003] Currently, some monitoring and protection solutions for explosion-proof battery vehicles used in mining have emerged in the industry. For example, the comprehensive protection system for explosion-proof battery locomotives disclosed in the prior art document CN117799498A uses a sensor network to monitor battery and environmental parameters, processes the data through deep learning algorithms, and dynamically adjusts protection parameters according to the battery status, thereby improving the safety and energy efficiency of the vehicle to a certain extent.
[0004] However, in complex downhole applications, existing monitoring and management systems still have the following shortcomings: Insufficient system monitoring depth, making it difficult to capture deep-seated electrochemical risks. Existing technologies primarily focus on threshold monitoring of apparent parameters such as battery voltage, current, and temperature, lacking analysis of deep failure mechanisms in large-capacity individual cells. Especially under high-intensity inspection conditions, they cannot effectively identify lithium plating risks and dynamic internal resistance fluctuations within the cells, making early warning difficult during the latency period of thermal runaway. Lack of a collaborative safety evaluation mechanism across subsystems. Existing systems often operate as independent "information silos," lacking interactive testing methods under specific risk scenarios. Overly simplistic failure protection strategies, leading to secondary risks. Traditional systems typically issue simple power-off shutdown commands when risks are detected, without considering the unique geographical environment of mine roadways. On steep slopes, direct power outages may cause vehicles to lose control and slide downhill; simultaneously, existing mechanical braking systems lack deep integration with electronic control systems, making it difficult to implement flexible avoidance strategies in the event of partial system failure. Therefore, a safety monitoring and management system that can realize cross-subsystem interactive inquiry, has dynamic resilience assessment capabilities, and can provide gradient guidance and intrinsic safety linkage protection has become a key technical problem that urgently needs to be solved in the field of explosion-proof electric equipment for mining. Summary of the Invention
[0005] To address the aforementioned issues, this invention provides a safety monitoring and management system for mine explosion-proof lithium-ion battery trackless rubber-wheeled vehicles. It employs an active risk exploration method based on operating condition identification and a cross-subsystem interactive testing method to construct a dynamic system resilience map, enabling proactive assessment of system-level risks and resilience-adaptive safety control for the entire vehicle.
[0006] To achieve the above objectives, this application adopts the following technical solution:
[0007] Firstly, a safety monitoring and management system for mine explosion-proof lithium-ion battery-powered trackless rubber-wheeled vehicles is provided, comprising: a comprehensive data acquisition module for acquiring basic vehicle operating status data and periodic self-inspection reports from subsystems, generating a comprehensive status dataset, wherein the subsystems include a power battery subsystem, a drive control subsystem, a hydraulic braking subsystem, and an environmental perception subsystem; a risk mode definition module for presetting several specific risk exploration modes, including: an electrochemical stability exploration mode for the risk of lithium plating in large-capacity cells, a brake fade risk exploration mode for long downhill conditions, and an explosion-proof safety linkage exploration mode for high-risk gases underground; and a working condition identification and exploration activation module. The system is configured to: identify the current operating mode of the vehicle based on the comprehensive status dataset, and dynamically activate the corresponding specific risk inquiry mode based on the identified operating mode; perform a cross-subsystem interaction test module to perform a light interaction test across subsystems under the activated specific risk inquiry mode, and obtain collaborative response data between subsystems; construct a dynamic resilience map based on the periodic self-inspection report and the collaborative response data, wherein the system resilience map is used to describe the safety boundary margin and collaborative working margin of each subsystem; and implement a decision execution and guidance control module to combine the system resilience map and real-time environmental data to implement resilience adaptation strategies and gradient guidance strategies.
[0008] Based on the above technical solution, the safety monitoring and management system for the mine explosion-proof lithium-ion battery trackless rubber-wheeled vehicle provided in this application adopts an active risk exploration and cross-subsystem interactive testing method based on working condition identification to construct a dynamic system resilience map, which can realize the forward-looking assessment of the system-level risks of the whole vehicle and the resilience adaptive safety control.
[0009] In conjunction with the first aspect mentioned above, in one possible implementation, the integrated data acquisition module includes: a basic data acquisition unit, used to acquire vehicle speed, motor operating mode, vehicle gradient, total current and total voltage of the vehicle power supply in real time, constituting basic operating status data; a self-test command interaction unit, used to issue self-test commands to each of the subsystems and receive battery health reports and braking status reports returned by each of the subsystems, constituting periodic self-test reports; and a dataset integration unit, used to integrate the basic operating status data, the battery health reports and the braking status reports to generate a comprehensive status dataset.
[0010] In conjunction with the first aspect above, in one possible implementation, the operating condition identification and inquiry activation module includes: a pattern matching unit, used to compare the comprehensive state dataset with a preset operating condition feature library to identify whether the vehicle is currently in a long downhill operating condition, a high-load uphill operating condition, or a stationary standby operating condition; an inquiry decision unit, used to match the corresponding inquiry priority according to the identified operating condition pattern and determine whether the activation conditions of the specific risk inquiry mode are met; and a logic triggering unit, used to send a synchronization command to the relevant subsystem when the activation conditions are met to activate the corresponding electrochemical stability inquiry mode, brake fade risk inquiry mode, or explosion-proof safety linkage inquiry mode.
[0011] In conjunction with the first aspect above, in one possible implementation, the cross-subsystem interactive testing module includes: a dynamic load triggering unit, used to instruct the drive control subsystem to generate a short-time pulse load and simultaneously collect the terminal voltage response data of the power battery subsystem to obtain the dynamic DC internal resistance characteristics of the cell when executing the electrochemical stability inquiry mode; a braking performance detection unit, used to apply a compensation torque through the drive control subsystem to detect the pressure build-up time and braking torque feedback data of the hydraulic braking subsystem under fully sealed oil chamber conditions when executing the braking fade risk inquiry mode; and a safety redundancy verification unit, used to simulate the intrinsically safe circuit fault signal of the environmental perception subsystem and test the response speed of the vehicle controller to the failure safety logic and the execution reliability of the automatic brake holding mechanism when executing the explosion-proof safety linkage inquiry mode.
[0012] In conjunction with the first aspect above, in one possible implementation, the dynamic resilience map construction module includes: a safety boundary quantification unit, used to calculate the state-of-charge margin of the power battery subsystem, the pressure stability margin of the hydraulic braking subsystem, and the intrinsically safe circuit insulation margin of the environmental perception subsystem based on the periodic self-inspection report, and determine the initial safety boundary of each subsystem; a synergy effect evaluation unit, used to analyze the performance fluctuation correlation between different subsystems under the specific risk inquiry mode based on the synergy response data, and extract the synergy working margin index; and a map mapping generation unit, used to perform multi-dimensional feature mapping between the initial safety boundary of each subsystem and the synergy working margin index to generate a dynamic resilience map describing the adaptability of the vehicle system to extreme complex operating conditions.
[0013] In conjunction with the first aspect above, in one possible implementation, the decision execution and guidance control module includes: a resilience adaptation strategy unit, used to assess the current health status of each subsystem based on the dynamic resilience map, dynamically adjust the maximum output power limit of the drive control subsystem and the pre-charge pressure of the hydraulic braking subsystem, and adapt to the current system resilience; a gradient guidance execution unit, used to execute a graded safety response based on the real-time environmental data and the system resilience map, and maintain an intrinsically safe low-power traction mode to guide the vehicle to evacuate from the danger zone when the environmental risk reaches a preset threshold and the system resilience meets the evacuation conditions; and a fail-safe interlock unit, used to immediately trigger a high-voltage power-off command and forcibly release the spring-energy-storage emergency brake when the braking pressure or battery thermal runaway index in the system resilience map exceeds the safety boundary, thereby achieving fail-safe automatic braking.
[0014] In conjunction with the first aspect described above, in one possible implementation, the system further includes: an integrated explosion-proof control enclosure, which integrates the vehicle controller, motor controller, and high-voltage power distribution unit of the drive control subsystem; an intrinsically safe associated isolation unit, disposed inside the integrated explosion-proof control enclosure, used to electrically isolate the intrinsically safe circuit of the environmental perception subsystem from the non-intrinsically safe circuit within the enclosure, and to limit the energy output to sensors outside the enclosure; and a communication bus management module, used to establish an explosion-proof and intrinsically safe communication link between the integrated explosion-proof control enclosure and the explosion-proof power supply box of the power battery subsystem, enabling real-time transmission of self-test commands and collaborative response data.
[0015] In conjunction with the first aspect above, in one possible implementation, the power battery subsystem includes: an explosion-proof power supply monitoring module, used to manage an explosion-proof power supply box composed of lithium iron phosphate cells connected in series, and integrating a thermal runaway early warning algorithm to perform anomaly judgment by monitoring the changing trends of cell voltage, temperature and internal resistance; and a quick-switch interface safety interlock module, located at the quick-switch interface of the explosion-proof power supply box, used to perform connection status monitoring and foolproof verification between the high-voltage power interface and the low-voltage communication interface.
[0016] In conjunction with the first aspect above, in one possible implementation, the system further includes: an energy efficiency closed-loop management module, used to dynamically adjust the motor output power and perform energy regenerative braking through the vehicle controller based on the real-time road load determined by the operating condition identification and inquiry activation module; and a thermal management closed-loop control module, used to dynamically adjust the cooling circulation flow of the integrated drive axle according to the temperature rise gradient inside the integrated explosion-proof control box.
[0017] Secondly, a safety monitoring and management method for mine explosion-proof lithium-ion battery-powered trackless rubber-wheeled vehicles is provided, including: acquiring basic operating status data of the vehicle and periodic self-inspection reports of subsystems to generate a comprehensive status dataset, wherein the subsystems include a power battery subsystem, a drive control subsystem, a hydraulic braking subsystem, and an environmental perception subsystem; and pre-setting several specific risk exploration modes, including: an electrochemical stability exploration mode for the risk of lithium plating in large-capacity cells, a brake fade risk exploration mode for long downhill conditions, and an explosion-proof safety linkage exploration mode for high-risk gases underground. The system employs a multi-stage risk assessment and assessment process. Based on the comprehensive status dataset, it identifies the current operating condition of the vehicle and dynamically activates the corresponding specific risk assessment mode. Under the activated specific risk assessment mode, it performs a light-scale interaction test across subsystems to obtain collaborative response data between subsystems. Based on the periodic self-inspection report and the collaborative response data, it constructs a dynamic system resilience map, which describes the safety boundary margin and collaborative working margin of each subsystem. Combining the system resilience map with real-time environmental data, it implements resilience adaptation strategies and gradient guidance strategies.
[0018] Compared with the prior art, the present invention has the following advantages:
[0019] This invention upgrades the safety management model from passive monitoring to proactive prevention. Instead of simply waiting for fault parameters to exceed limits, the system proactively initiates targeted risk probing based on the vehicle's real-time operating conditions. Through light interactive testing, it identifies potential risks within safety boundaries caused by component performance degradation or system coordination malfunctions, achieving forward-looking prediction and management of vehicle safety status.
[0020] This invention provides a system-level overall safety assessment method. By constructing a dynamic resilience map, it combines the independent safety boundary margins of each subsystem with the collaborative working margins obtained from cross-system interactive testing to form a macroscopic quantitative evaluation of the vehicle's ability to withstand complex operating conditions and sudden risks. This system-level perspective overcomes the limitations of traditional monitoring methods that only focus on the state of individual components, enabling a more accurate assessment of the overall safety level of the vehicle.
[0021] This invention achieves adaptive safety control based on the actual health status of the vehicle. The system dynamically adjusts key control parameters such as the vehicle's maximum output power and brake pre-charge pressure based on the current system resilience assessed by a dynamic resilience map, ensuring that the vehicle's operating intensity matches its actual load-bearing capacity. When encountering external environmental risks, it can also execute tiered guidance control strategies to maximize vehicle availability while ensuring safety, achieving intelligent and refined closed-loop safety management.
[0022] It should be understood that the descriptions of technical features, technical solutions, beneficial effects, or similar language in this application do not imply that all features and advantages can be achieved in any single embodiment. Rather, it is understood that the description of a feature or beneficial effect means that a specific technical feature, technical solution, or beneficial effect is included in at least one embodiment. Therefore, the descriptions of technical features, technical solutions, or beneficial effects in this specification do not necessarily refer to the same embodiment. Furthermore, the technical features, technical solutions, and beneficial effects described in this embodiment can be combined in any suitable manner. Those skilled in the art will understand that embodiments can be implemented without one or more specific technical features, technical solutions, or beneficial effects of a particular embodiment. In other embodiments, additional technical features and beneficial effects may be identified in specific embodiments that do not embody all embodiments. Attached Figure Description
[0023] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0024] Figure 1 A flowchart illustrating the safety monitoring and management method for a mine explosion-proof lithium-ion battery trackless rubber-wheeled vehicle provided in this application embodiment;
[0025] Figure 2 A structural architecture diagram of the safety monitoring and management system for a mine explosion-proof lithium-ion battery trackless rubber-wheeled vehicle provided in this application embodiment;
[0026] Figure 3 This is a schematic diagram of the decision response logic of the security monitoring and management system provided in the embodiments of this application;
[0027] Figure 4 This is a schematic diagram of the sensor signal conversion and transmission link provided in the embodiments of this application. Detailed Implementation
[0028] In the description of this application, unless otherwise stated, " / " means "or," for example, A / B can mean A or B. The "and / or" in this document is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, and B alone. Furthermore, "at least one" means one or more, and "multiple" means two or more. The terms "first," "second," etc., do not limit the quantity or order of execution, and "first," "second," etc., do not necessarily imply differences.
[0029] It should be noted that, in this application, the terms "exemplary" or "for example" are used to indicate that something is being described as an example, illustration, or illustration. Any embodiment or design described as "exemplary" or "for example" in this application should not be construed as being more preferred or advantageous than other embodiments or design solutions. Specifically, the use of terms such as "exemplary" or "for example" is intended to present the relevant concepts in a concrete manner.
[0030] The safety monitoring and management system for mine explosion-proof lithium-ion battery trackless rubber-wheeled vehicles provided in this application embodiment can be applied to, for example... Figure 1 The safety monitoring and management method for the mine explosion-proof lithium-ion battery trackless rubber-wheeled vehicle shown in the figure includes, for example... Figure 1 As shown, the method includes:
[0031] Acquire basic operating status data of the vehicle and periodic self-inspection reports of the subsystems to generate a comprehensive status dataset. The subsystems include a power battery subsystem, a drive control subsystem, a hydraulic braking subsystem, and an environmental perception subsystem.
[0032] Several specific risk exploration modes are preset, including: an electrochemical stability exploration mode for the risk of lithium plating in large-capacity cells, a braking fade risk exploration mode for long downhill conditions, and an explosion-proof safety linkage exploration mode for high-risk gases in the well.
[0033] The vehicle's current operating condition is identified based on the comprehensive status dataset, and the corresponding special risk inquiry mode is dynamically activated based on the identified operating condition.
[0034] Under the activated special risk exploration mode, perform light interaction tests across subsystems to obtain collaborative response data between subsystems;
[0035] Based on the periodic self-inspection reports and the collaborative response data, a dynamic system resilience map is constructed, wherein the system resilience map is used to describe the safety boundary margin and collaborative working margin of each subsystem.
[0036] Based on the system resilience map and real-time environmental data, a resilience adaptation strategy and a gradient guidance strategy are implemented.
[0037] like Figure 2 As shown in the embodiment of this application, a safety monitoring and management system for a mine explosion-proof lithium-ion battery trackless rubber-wheeled vehicle is provided, including:
[0038] The integrated data acquisition module is used to acquire basic operating status data of the vehicle and periodic self-inspection reports of the subsystems, and generate an integrated status dataset. The subsystems include a power battery subsystem, a drive control subsystem, a hydraulic braking subsystem, and an environmental perception subsystem.
[0039] The risk mode definition module is used to preset several special risk inquiry modes, including: an electrochemical stability inquiry mode for the risk of lithium plating in large-capacity cells, a braking fade risk inquiry mode for long downhill conditions, and an explosion-proof safety linkage inquiry mode for high-risk gases in the well.
[0040] The working condition identification and inquiry activation module is used to identify the current working condition mode of the vehicle based on the comprehensive status dataset, and dynamically activate the corresponding special risk inquiry mode based on the identified working condition mode.
[0041] The cross-subsystem interaction testing module is used to perform light interaction tests across subsystems under the activated special risk exploration mode to obtain collaborative response data between subsystems.
[0042] The dynamic resilience map construction module is used to construct a dynamic system resilience map based on the periodic self-inspection report and the collaborative response data, wherein the system resilience map is used to describe the safety boundary margin and collaborative working margin of each subsystem;
[0043] The decision execution and guidance control module is used to combine the system resilience map and real-time environmental data to implement resilience adaptation strategies and gradient guidance strategies.
[0044] It should be noted that the system constructs a closed-loop active safety management framework from data perception to decision control. Through a comprehensive data acquisition module, it fully acquires the vehicle's own operating status and the health self-check information of each core subsystem, forming a unified multi-dimensional status dataset. The system does not passively wait for faults to occur, but rather actively triggers preset specific risk probing modes based on real-time operating conditions using the condition identification and inquiry activation module. In these specific modes, the system applies mild, controlled disturbances to key systems such as power and braking through a cross-subsystem interaction testing module to probe their coordinated response capabilities. The system integrates static self-check data with dynamic coordinated response data, and through a dynamic resilience map construction module, generates a system resilience map that quantitatively describes the vehicle's safety boundaries and coordination margins. Based on this map and real-time environmental information, the decision execution and guidance control module ultimately implements an adaptive control strategy.
[0045] In one possible implementation of the embodiments of this application, combined with Figure 2 The integrated data acquisition module includes:
[0046] The basic data acquisition unit is used to acquire vehicle speed, motor operating mode, vehicle gradient, and total current and voltage of the on-board power supply in real time, forming basic operating status data.
[0047] The self-test command interaction unit is used to issue self-test commands to each of the subsystems and receive battery health reports and braking status reports returned by each of the subsystems, forming a periodic self-test report.
[0048] The dataset integration unit is used to integrate the basic operating status data, the battery health report, and the braking status report to generate a comprehensive status dataset.
[0049] In some implementations, the integrated data acquisition module provides a unified, synchronous, and comprehensive data foundation for subsequent operating condition identification and risk assessment. Through the collaborative work of the basic data acquisition unit, self-test command interaction unit, and dataset integration unit, the discrete, multi-frequency state information of the vehicle is integrated into a structured comprehensive state dataset. The task of the basic data acquisition unit is to capture the vehicle's dynamic operating information at high frequency. Through the vehicle controller local area network bus, i.e., the CAN bus, it continuously listens to and parses key message data at a sampling frequency of 10 to 50 Hz, thereby acquiring the core variables constituting the basic operating state data. These include the real-time vehicle speed calculated by the wheel speed sensors, the motor operating mode (e.g., traction mode or energy feedback mode) fed back by the motor controller, the vehicle gradient reported by the inertial measurement unit, and the total current and total voltage of the vehicle power supply, which are core indicators of the vehicle load, reported by the battery management system (BMS). The self-test command interaction unit actively manages the health status reporting of each subsystem at a lower frequency. This unit sends standardized self-test commands to the battery management system of the power battery subsystem and the electronic control unit of the hydraulic braking subsystem via a preset period, such as every 30 to 60 seconds, through a CAN bus or a dedicated communication link. Upon triggering the command, each subsystem executes its internal diagnostic procedures and encapsulates the diagnostic results into a report. The battery health report includes the key estimated state of health (SOH) value, a comprehensive indicator of the battery's remaining lifespan, as well as the difference between the highest and lowest single-cell voltages and the difference between the highest and lowest temperatures within the battery pack. These parameters directly reflect the battery's internal consistency. The braking status report includes real-time readings from the brake fluid pressure sensor, the status of the brake pad wear sensor, and the system readiness flag. The dataset integration unit is responsible for fusing the data from these two sources and frequencies to generate the final comprehensive status dataset. However, timestamp alignment is crucial. This unit uses the high-frequency data stream from the basic data acquisition unit as its main timeline. When it receives a frame of basic operating status data, it searches for and appends the content of the most recently received periodic self-test report. In this way, low-frequency updated health status data is broadcast to each frame of high-frequency dynamic data, forming a complete snapshot of the vehicle's state over time. This comprehensive state dataset can be represented as a vector. The calculation formula is:
[0050] ;
[0051] in, For timestamps, For vehicle speed, This is the motor operating mode code. For vehicle slope, This represents the total current of the vehicle's power supply. The total voltage is derived from basic operating status data. SOH represents the battery's state of health. This represents the maximum voltage difference between individual cells within the battery pack. For the maximum single-unit temperature difference, For the master cylinder pressure of the braking system, The brake pad wear status data are derived from the latest periodic self-inspection reports. This integrated comprehensive status dataset will serve as a unique, standardized data source, inputting into the condition identification and inquiry activation module.
[0052] For example, the basic data acquisition unit uses a CAN bus to... The sampling frequency captures vehicle dynamic information in real time, at a certain sampling moment. At that time, the real-time vehicle speed is obtained by parsing the bus messages. Motor in traction mode code Current driving slope Total output current of vehicle power supply and real-time total voltage Meanwhile, the self-test command interaction unit retrieved the most recent health briefing from each subsystem, such as periodic sampling points. At that time, the power battery subsystem reported its battery health status (SOH) as follows: Maximum single-cell voltage difference Maximum single-unit temperature difference The hydraulic braking subsystem provides feedback on the master cylinder pressure. And the shoe wear status indicator This indicates normal operation; ultimately, the dataset integration unit executes timestamp alignment logic to associate the infrequently updated self-check parameters with... At the high-frequency sampling points, a comprehensive state vector for that moment is generated by inputting specific numerical values. .
[0053] In one possible implementation, combining Figure 2 The working condition identification and inquiry activation module includes:
[0054] The pattern matching unit is used to compare the comprehensive state dataset with a preset working condition feature library to identify whether the vehicle is currently in a long downhill working condition, a high-load uphill working condition, or a stationary standby working condition.
[0055] The inquiry decision unit is used to match the corresponding inquiry priority according to the identified working condition mode and determine whether the activation conditions of the special risk inquiry mode are met.
[0056] The logic triggering unit is used to send a synchronization command to the relevant subsystem when the activation condition is met, thereby activating the corresponding electrochemical stability probing mode, braking fade risk probing mode, or explosion-proof safety linkage probing mode.
[0057] In some implementations, the condition identification and inquiry activation module transforms the original comprehensive state dataset into explicit risk inquiry actions, achieving an upgrade from passive data monitoring to proactive safety diagnosis. This is accomplished through the sequential collaboration of the pattern matching unit, inquiry decision unit, and logic triggering unit. The function of the pattern matching unit is to parse the input comprehensive state dataset in real time and compare it with a preset condition feature library to identify the vehicle's current critical operating state. The condition feature library is a set of conditional judgment logic embedded in the vehicle controller. For example, the rule for identifying long downhill conditions is: when the comprehensive state dataset contains a value representing the vehicle's slope... The value remains below -5 degrees Celsius, while the vehicle speed... Maintain a speed of 5 kilometers per hour or more, and this state shall be maintained for a period of time. If the preset 30-second threshold is exceeded, the vehicle is determined to be in a long downhill driving condition. Similarly, the rule for identifying a stationary standby condition is: when the vehicle speed... Approaching zero, and the total current of the vehicle power supply If the absolute value of the brake fade risk is less than the static consumption threshold of 2 amperes, and this state lasts for more than 5 minutes, the vehicle is determined to have entered a static standby condition. The inquiry decision unit executes the risk inquiry decision logic based on the identification results of the pattern matching unit. This unit sets independent inquiry priorities and activation conditions for each specific risk inquiry mode. For example, when a long downhill condition is identified, the inquiry priority of the brake fade risk inquiry mode is set to the highest, and the decision unit calculates an activation score A_brake to determine whether to execute the inquiry. This score is determined by the following formula:
[0058] ;
[0059] in, It is a Boolean variable, which is 1 when the condition is a long downhill slope, and 0 otherwise. It is the time interval since the last execution of this query. It is a reference time period, such as 72 hours, used to normalize time. It is based on the brake pad wear sensor data in the braking status report. The quantitatively derived health index of the braking system ranges from 0 to 1. , , These are preset weighting coefficients, summing to 1, reflecting the importance of triggering conditions, time periods, and system health status in decision-making. When the calculated activation score... When the preset activation threshold is exceeded, for example, 0.75, the query decision unit determines that the activation conditions for the brake fade risk query mode are met. Similarly, when the vehicle is in a stationary standby condition and the battery state of charge (SOC) is high, a decision calculation for the electrochemical stability query mode will be triggered. Once the query decision unit determines that the activation conditions are met, the logic trigger unit immediately generates and broadcasts a synchronization command. This command is a CAN message with a specific identifier, used to synchronously send commands to relevant subsystems, such as the drive control subsystem and the hydraulic braking subsystem, thereby accurately activating the corresponding specific risk query mode. For example, to activate the brake fade risk query mode, the logic trigger unit will simultaneously send a synchronization command with ID 0x1F0 to both the vehicle controller and the brake controller, ensuring that the two subsystems enter the test state in a coordinated manner, which is a prerequisite for realizing cross-subsystem interactive testing.
[0060] For example, in the process of identifying long downhill conditions and triggering the brake fade risk inquiry mode, the pattern matching unit analyzes the comprehensive state dataset in real time. When the vehicle gradient is detected... consistently below Threshold, vehicle speed higher than The threshold and the duration of this state reaches When the vehicle is determined to be in a long downhill condition, the decision-making unit performs decision calculations based on the result of this condition, setting weight coefficients as follows: and the operating condition Boolean variable Set to 1 if the time interval since the last query is... Reference period And the current braking system health indicators Substituting into the activation score formula, the result is... Since the calculated activation score of 0.78 exceeds the preset activation threshold of 0.75, the activation condition is determined to be met. The logic triggering unit then generates and broadcasts a synchronization command CAN message with the identifier 0x1F0 to the vehicle controller and the brake controller, thereby officially starting the brake fade risk probing mode.
[0061] In one possible implementation, combining Figure 2 The cross-subsystem interaction testing module includes:
[0062] The dynamic load triggering unit is used to instruct the drive control subsystem to generate a short-time pulse load when executing the electrochemical stability probing mode, and simultaneously collect the terminal voltage response data of the power battery subsystem to obtain the dynamic DC internal resistance characteristics of the cell.
[0063] The braking performance detection unit is used to detect the pressure build-up time and braking torque feedback data of the hydraulic braking subsystem under the fully sealed oil chamber condition by applying a compensation torque through the drive control subsystem when executing the brake fade risk inquiry mode.
[0064] The safety redundancy verification unit is used to simulate the intrinsically safe circuit fault signal of the environmental perception subsystem when executing the explosion-proof safety linkage interlocking mode, and to test the response speed of the vehicle controller to the failure safety logic and the execution reliability of the automatic braking.
[0065] In some implementations, the cross-subsystem interactive testing module quantifies and evaluates the collaborative response capabilities and performance boundaries of different subsystems under specific risk scenarios by actively applying controlled disturbances, providing crucial measured data for constructing a dynamic resilience profile. This is achieved collaboratively by a dynamic load triggering unit, a braking performance detection unit, and a safety redundancy verification unit. After the electrochemical stability probing mode is activated, the dynamic load triggering unit begins operation, non-invasively acquiring the dynamic DC internal resistance characteristics of the battery cell. This unit sends commands to the drive control subsystem via the vehicle controller, controlling the motor to generate a pulse discharge load with a duration of 100 to 500 milliseconds and a current amplitude of approximately 50 to 100 amperes. At the instant the pulse is applied, the terminal voltage response data fed back by the power battery subsystem is simultaneously acquired at a sampling rate of no less than 100 Hz. Dynamic DC internal resistance... It is calculated using the following formula:
[0066] ;
[0067] in, To apply the battery terminal voltage one moment before the pulse is applied, The terminal voltage is the voltage at the moment the pulse ends. Both of these values are collected with high precision by the battery management system of the power battery subsystem. The average current value during the pulse period is fed back by the motor controller of the drive control subsystem. This internal resistance value is a key indicator for assessing the risk of lithium plating in large-capacity battery cells. When the vehicle enters a long downhill driving condition and triggers the brake fade risk probing mode, the brake performance detection unit is activated. In order to detect the ultimate performance of the braking system without affecting driving safety, this unit performs a precise coordinated test. First, a command is issued to the hydraulic braking subsystem to apply a light braking force with a target pressure value in the range of 1 to 2 MPa, simulating the fully sealed oil chamber condition. At the same time, a command is issued to the drive control subsystem to generate a compensating torque that is equal in magnitude and opposite in direction to the braking torque. In this way, the braking system is subjected to a real load with almost no deceleration. During this period, the unit records the pressure build-up time required from the issuance of the command to the brake oil pressure reaching the target value, and collects the compensating torque data output by the drive control subsystem to maintain constant speed as braking torque feedback data, thereby evaluating the response speed and efficiency of the braking system. In the explosion-proof safety linkage interrogation mode, typically executed during vehicle startup self-test or specific maintenance modes, the safety redundancy verification unit is responsible for verifying the vehicle's final safety barrier. This unit sends a simulated message to the vehicle controller via the internal bus. This message simulates the signal characteristics of a short-circuit or open-circuit fault in the intrinsically safe circuit of the environmental perception subsystem. Intrinsically safe circuits are designed to limit circuit energy, ensuring they cannot generate sparks or heat sufficient to ignite explosive gases in the mine under any fault condition. After the test starts, a timer inside the unit begins timing and monitors the vehicle controller's response. The total time from the issuance of the simulated fault signal to the vehicle controller completing the fail-safe logic judgment, issuing a high-voltage power-off command, and finally confirming the spring-loaded emergency brake's mechanical engagement is achieved. This time directly reflects the response speed and execution reliability of the vehicle's fail-safe logic.
[0068] For example, when the electrochemical stability probing mode is activated, the dynamic load triggering unit commands the control subsystem to generate an amplitude of The pulse discharge current is obtained, and the battery terminal voltage at the moment before the pulse is synchronously acquired. and the terminal voltage at the moment the pulse ends Substitute into the formula The dynamic DC internal resistance of the battery cell was calculated. This serves as a quantitative characteristic for assessing the lithium plating risk of large-capacity battery cells; when the brake fade risk probing mode is activated, the brake performance detection unit instructs the hydraulic brake subsystem to apply... The target pressure simulates the fully sealed oil chamber condition, and the drive control subsystem generates a compensating torque in the opposite direction to counteract the braking effect. The measured pressure settling time is... Furthermore, the feedback torque data is stable, used to evaluate the response speed and efficiency of the braking system; in the explosion-proof safety linkage interrogation mode, the safety redundancy verification unit simulates sending a signal characteristic message representing an intrinsically safe circuit fault, and the timer accurately records the total time from the issuance of the simulated signal to the vehicle controller completing the fail-safe logic judgment, executing high-voltage power cut-off, and confirming the mechanical brake of the spring-energy-storage emergency brake being in place. This test time verified the vehicle's safety response speed and logic execution reliability under extreme fault conditions.
[0069] In one possible implementation, combining Figure 2 The dynamic toughness map construction module includes:
[0070] The safety boundary quantification unit is used to calculate the state of charge margin of the power battery subsystem, the pressure stability margin of the hydraulic braking subsystem, and the intrinsically safe circuit insulation margin of the environmental sensing subsystem based on the periodic self-inspection report, and to determine the initial safety boundary of each subsystem.
[0071] The synergy effect assessment unit is used to analyze the performance fluctuation correlation between different subsystems under the special risk exploration mode based on the synergy response data, and extract the synergy work margin index.
[0072] The map mapping generation unit is used to perform multi-dimensional feature mapping between the initial safety boundaries of each subsystem and the cooperative working margin index to generate a dynamic resilience map describing the adaptability of the whole vehicle system to extreme complex working conditions.
[0073] In some implementations, the dynamic resilience map construction module integrates discrete health status indicators and dynamic collaborative response data of each subsystem into a quantitative model that can macroscopically characterize the vehicle system's ability to withstand risks. This is achieved through a processing flow involving a safety boundary quantification unit, a collaborative effect evaluation unit, and a map mapping generation unit. The safety boundary quantification unit is responsible for establishing independent health baselines for each subsystem, i.e., initial safety boundaries. Using periodic self-inspection reports as input data, it normalizes key parameters and calculates the safety boundary margin for each subsystem. For example, the state of charge margin of the power battery subsystem does not refer to SOC, but rather to the difference between its state of health (SOH) and the scrap threshold. Its safety boundary margin... It can be represented as:
[0074] ;
[0075] in, This is an estimate of the current battery health status. It is the end-of-life threshold. This is the initial value for the new battery. Similarly, the pressure stability margin of the hydraulic braking subsystem. The intrinsic safety margin of the environmental sensing subsystem is determined by evaluating its oil pressure fluctuation amplitude and pressure holding capacity under static conditions. These margin values are derived from the ratio of the insulation resistance value measured during self-test to the lower limit of the safety standard. Together, these factors form the foundation of system resilience. The synergy assessment unit quantifies the degree of interaction between subsystems under specific stress scenarios, thereby extracting a synergy margin index. The data for this unit originates from synergy response data acquired by the cross-subsystem interaction test module. For example, the dynamic DC internal resistance acquired during the execution of the electrochemical stability probing mode. It is itself an indicator of collaborative work margin. When A significant increase indicates a deterioration in the battery's voltage stability under high-current surges, which directly affects the power output capability of the drive control subsystem. Another indicator is the pressure settling time obtained in the brake fade risk inquiry mode. The longer this time, the slower the braking response and the lower the coordination margin between the drive and braking subsystems. These indicators The data is normalized to characterize the coupling performance between subsystems. The graph mapping generation unit fuses the two types of data to generate the final dynamic resilience graph. Here, "graph" refers to a multi-dimensional state vector or a comprehensive scalar exponent. It is not a visual chart, but rather a multi-dimensional feature mapping process that can be achieved through weighted summation.
[0076] ;
[0077] in, This refers to the dynamic resilience index of the entire vehicle system. It represents the safety boundary margin of each subsystem. It is based on and Normalized collaborative work margin index. The weighting coefficients representing each indicator are calibrated according to the importance of different subsystems and synergistic effects. and It refers to the overall weight of the two main categories of indicators. This is dynamically updated. The index accurately describes the overall adaptability and safety margin of the vehicle system to extremely complex operating conditions at any given moment.
[0078] For example, the safety boundary quantification unit establishes an independent health baseline for each subsystem, if the current estimated health status of the power battery is... End-of-life threshold initial value Then substitute into the formula The safety boundary margin of the power battery subsystem is obtained, and similarly, the braking pressure stability margin is determined by combining the measured parameters. Intrinsically safe circuit insulation margin The synergy evaluation unit obtains a normalized synergy margin index based on the interactive test results, and sets it according to the dynamic DC internal resistance. Electrochemical stability index of the mapping Time to build up pressure Mapped braking response index Finally, the map mapping generation unit sets the weighting coefficients. , and sub-item weights , , and , Substitute into the mapping formula The dynamic resilience index, which reflects the overall risk resistance capability of the vehicle system, was calculated. This quantitative index accurately describes the overall adaptability and safety margin of the vehicle system to extremely complex operating conditions at the current moment.
[0079] In one possible implementation, combining Figure 2 The decision execution and guidance control module includes:
[0080] The resilience adaptation strategy unit is used to assess the current health status of each subsystem based on the dynamic resilience map, dynamically adjust the maximum output power limit of the drive control subsystem and the pre-charge pressure of the hydraulic braking subsystem, and adapt to the current system resilience.
[0081] The gradient guidance execution unit is used to execute a graded safety response based on the real-time environmental data and the system resilience map. When the environmental risk reaches a preset threshold and the system resilience meets the evacuation conditions, it maintains an intrinsically safe low-power traction mode to guide the vehicle to evacuate from the danger zone.
[0082] The fail-safe interlocking unit is used to immediately trigger a high-voltage power-off command and forcibly release the spring-energy-storage emergency brake when the braking pressure or battery thermal runaway index in the system toughness profile exceeds the safety boundary, thereby achieving fail-safe automatic braking.
[0083] In some implementations, the decision execution and guidance control module transforms the abstract safety state represented by the dynamic resilience map into specific vehicle control strategies and emergency response measures, achieving closed-loop control from risk perception to proactive intervention. This is accomplished collaboratively by the resilience adaptation strategy unit, the gradient guidance execution unit, and the fail-safe interlock unit. The resilience adaptation strategy unit makes preventative adjustments to the vehicle's routine operating parameters based on the evaluation results of the dynamic resilience map. This unit continuously monitors the vehicle system resilience index output by the dynamic resilience map construction module. .when If the power output falls below a preset health threshold (e.g., 0.8) due to component aging or performance degradation, the unit will automatically lower the maximum output power limit of the drive control subsystem. Maximum output power The regulation logic can be expressed as:
[0084] ;
[0085] ;
[0086] in, It is the rated power of the motor. It is a casual The changing adjustment function, when When it decreases, The value of also decreases linearly or stepwise, thereby limiting the vehicle's acceleration and load capacity to mitigate system wear. The threshold for health status. This is the minimum operating threshold; This serves as the minimum power coefficient reference for the linear control section. This is the fixed power coefficient for the intrinsically safe low-power traction mode. Simultaneously, if the dynamic toughness profile indicates a decrease in the cooperative working margin of the hydraulic braking subsystem, it will instruct the braking system to increase the pre-charge pressure from the standard 0.2 MPa to 0.3 MPa to shorten the braking response time and compensate for the performance degradation. The gradient-guided execution unit handles more urgent risks caused by the external environment. This unit integrates real-time environmental data, such as gas concentration obtained from the environmental sensing subsystem. .when If the level 1 alarm threshold is exceeded, for example, the volume concentration reaches 0.5%, and the overall vehicle system resilience index is also affected. If the pressure remains above the preset minimum operating threshold, such as 0.4, the system is deemed to meet the evacuation conditions. At this point, the unit immediately activates the intrinsically safe low-power traction mode. In this mode, the vehicle controller forcibly limits the output power of the drive system to within 10% to 20% of the rated power, while simultaneously shutting down all unnecessary auxiliary electrical equipment. This ensures the vehicle's electrical system operates in an intrinsically safe state with minimal energy consumption, guiding the vehicle to evacuate the danger zone safely and slowly. The fail-safe interlock unit constitutes the system's last line of defense, used to deal with impending or ongoing catastrophic failures. This unit sets an inviolable safety red line. It monitors key raw data in the dynamic resilience profile in real time, such as braking system pressure or the highest temperature of individual battery cells. Once the braking pressure is detected to be below the minimum safe pressure threshold, or the power battery subsystem reports an uncontrollable thermal runaway warning signal, this unit bypasses all conventional control logic and immediately executes the highest-priority safety interlock command. This command, via independent hardware circuitry or the highest-priority CAN message in the controller area network, directly triggers the main contactor in the high-voltage power distribution unit to disconnect, cutting off the vehicle's high-voltage power supply. Simultaneously, a de-energization signal is sent to the solenoid valve of the spring-operated emergency brake. Upon de-energization of the solenoid valve, the mechanical force of the spring is immediately released, locking the wheels and achieving the most reliable fail-safe automatic braking, ensuring the vehicle stops before complete loss of control. For example... Figure 3 As shown, the integrated explosion-proof control box serves as the core decision-making unit, receiving real-time battery status information from the explosion-proof power supply monitoring module, gas sensor monitoring data, and braking pressure signals from the intrinsically safe pressure sensor. When specific parameters trigger preset thresholds, such as a gas concentration reaching 0.5% or braking pressure falling below the safety limit, the internal logic unit of the control box executes a gradient guidance strategy or a fail-safe interlock command. The specific logic is as follows: Figure 3 As shown, gradient guidance is implemented through audible and visual alarms or power limiting; when the red line is triggered, fail-safe interlocks, such as mechanical brakes, are implemented through power-off protection and emergency braking. The physical conditioning and conversion process of the sensor signals is described in reference [reference needed]. Figure 4 The demonstration showcased the signal transmission link between the integrated explosion-proof control enclosure and the external intrinsically safe sensor. Braking pressure data acquired by the mining intrinsically safe pressure sensor is transmitted via signal lines to the internal CAN mining intrinsically safe display screen for real-time display. Furthermore, the integrated I / O and CAN conversion boards convert the physical signals into digital messages recognizable by the vehicle control unit (VCU), thereby achieving precise sensing and digital monitoring of the hydraulic braking subsystem pressure.
[0087] For example, when the system monitors the vehicle system resilience index in real time At that time, because it fell into The risk warning range is automatically calculated using the linear adjustment segment formula: by substituting the numerical values... If the rated power of the motor is known According to the power regulation formula Substitute the values into the calculation to obtain the current maximum output power limit. Calculation results show that by sensing the decrease in resilience, the power output was actively reduced. This effectively reduces the risk of lithium plating in batteries under high-current discharge while ensuring basic inspection operations are carried out.
[0088] In one possible implementation, combining Figure 2 The system also includes:
[0089] An integrated explosion-proof control enclosure houses the vehicle controller, motor controller, and high-voltage power distribution unit of the drive control subsystem.
[0090] The intrinsically safe associated isolation unit is located inside the integrated explosion-proof control box and is used to electrically isolate the intrinsically safe circuit of the environmental sensing subsystem from the non-intrinsically safe circuit inside the box, and to limit the energy output to the external sensors of the box.
[0091] The communication bus management module is used to establish an explosion-proof and intrinsically safe communication link between the integrated explosion-proof control box and the explosion-proof power supply box of the power battery subsystem, so as to realize the real-time transmission of self-test commands and collaborative response data.
[0092] In some implementations, a specific hardware architecture provides a physically safe and reliable operating platform that meets mining explosion-proof standards for the software algorithms and control logic of the entire monitoring and management system. This platform, through the synergistic effect of an integrated explosion-proof control enclosure, intrinsically safe isolation units, and a communication bus management module, fundamentally prevents the electrical system from becoming an ignition source for the underground explosive environment. The integrated explosion-proof control enclosure serves as a physical safety barrier, cast from high-strength metal materials. The shell's mating surfaces are designed with precise explosion-proof gaps, such as 0.1 to 0.3 mm, ensuring that even if an electrical component inside the enclosure malfunctions and generates an electrical spark that ignites any possible gas mixture inside, the resulting explosion pressure and flame will not propagate to the hazardous environment outside the enclosure. This enclosure highly integrates the system's core computing and execution units, including the main vehicle controller as the decision-making center, the motor controller responsible for drive torque control, and the high-voltage power distribution unit managing the distribution of high-voltage DC power. The intrinsically safe isolation unit, located inside the integrated explosion-proof control enclosure, is a crucial safety interface connecting the high-energy circuits inside the enclosure with the low-energy sensors outside. Intrinsically safe circuits, also known as intrinsically safe circuits, are designed to limit voltage and current within the circuit so that the energy generated under normal operation or any fault condition is lower than the minimum ignition energy required to ignite a specific hazardous gas. This isolation unit is typically implemented in engineering using certified safety barriers. It provides complete electrical isolation between intrinsically safe circuits from external sensors such as the environmental sensing subsystem and non-intrinsically safe circuits such as the vehicle controller within the enclosure. This isolation is usually achieved through opto-isolation or magnetic isolation, and incorporates voltage and current limiting elements to ensure that the peak voltage output to external sensors does not exceed 24 volts and the short-circuit current is less than 100 mA, thus guaranteeing the safety of the underground sensor network from the source. The communication bus management module is responsible for establishing a stable and explosion-proof-compliant digital communication link between two relatively far-away critical explosion-proof devices: the integrated explosion-proof control enclosure and the explosion-proof power supply box of the power battery subsystem. This link employs an explosion-proof and intrinsically safe design. The physical cable itself may be protected by armor or explosion-proof sheathing, while the CAN bus signals transmitted on it are processed by an intrinsically safe associated isolation unit to ensure that their signal energy meets intrinsically safe requirements. This module ensures that critical safety information, including self-test commands and collaborative response data, can be transmitted in real time and without errors at a rate of 500 kilobits per second between two independent explosion-proof cavities, providing reliable communication support for the closed-loop control of the entire safety monitoring and management system.
[0093] For example, integrated explosion-proof control enclosures, through their sophisticated design The explosion-proof gap acts as a physical barrier, protecting the integrated vehicle controller, motor controller, and high-voltage power distribution unit for safe operation in high methane concentration environments. When the vehicle controller needs to retrieve methane concentration data from the environmental sensing subsystem, the intrinsically safe isolation unit uses its integrated safety barrier to electrically isolate non-intrinsically safe circuits and performs voltage and current limiting protection, for example, when abnormal voltage fluctuations occur at the input terminal. At this time, the safety barrier strictly limits the peak voltage output to the external sensor through an internal Zener diode and a current-limiting resistor. The short-circuit current is limited below. This ensures that the energy of the sensor circuit under any fault condition downhole is far below the minimum ignition energy of the gas, approximately Meanwhile, the communication bus management module establishes a communication connection between the explosion-proof control box and the explosion-proof power supply box at a speed of [missing information]. The explosion-proof and intrinsically safe CAN communication link, calculated by substituting physical parameters, if the length of a single frame self-test command message is... Then its transmission delay is only This extremely low-latency intrinsically safe data interaction ensures that critical safety information, including subsystem collaborative response data, can flow in real time between various independent explosion-proof cavities.
[0094] In one possible implementation, combining Figure 2 The power battery subsystem includes:
[0095] The explosion-proof power supply monitoring module is used to manage the explosion-proof power supply box composed of lithium iron phosphate battery cells connected in series, and integrates a thermal runaway early warning algorithm to perform anomaly judgment by monitoring the changes in battery cell voltage, temperature and internal resistance.
[0096] The quick-switch interface safety interlock module is installed at the quick-switch interface of the explosion-proof power supply box and is used to perform connection status monitoring and foolproof verification between the high-voltage power interface and the low-voltage communication interface.
[0097] In some implementations, the power battery subsystem provides comprehensive, high-precision safety management of the vehicle's core energy unit, the explosion-proof power supply box, from its internal electrochemical state to its external physical interfaces, ensuring its operational reliability and inherent safety in the harsh underground environment. This subsystem's functions are jointly implemented by the explosion-proof power supply monitoring module and the quick-swap interface safety interlock module. The explosion-proof power supply monitoring module is the battery management system integrated inside the explosion-proof power supply box. Its primary task is to manage battery stacks consisting of dozens to hundreds of high-capacity lithium iron phosphate cells connected in series. The module's built-in thermal runaway early warning algorithm is not based on a simple temperature threshold alarm, but rather employs a multivariate trend prediction model. This model continuously monitors and calculates the time gradient, or rate of change, of key safety indicators at intervals of 500 milliseconds to 1 second. A comprehensive thermal runaway risk index is also included. Calculated dynamically using the following formula:
[0098] ;
[0099] in, This represents the fastest rate of temperature rise of a single battery cell currently monitored, measured in degrees Celsius per second. This represents the maximum rate of voltage drop of a single cell. This represents the growth rate of the cell's dynamic DC internal resistance. These values are obtained by performing differential calculations on high-frequency acquired cell voltage, temperature, and internal resistance data. These are pre-defined safety thresholds, such as a temperature rise rate threshold that might be set at 0.2 degrees Celsius per second. These are the weighting coefficients for each indicator. When the calculated... When the preset alarm threshold of 1 is exceeded, the module immediately determines that there is an early risk of thermal runaway and reports the highest level fault alarm to the vehicle controller. The quick-swap interface safety interlock module provides hardware-level safety protection for the physical replacement operation of the battery. In terms of physical structure, this module includes position detection sensors for the high-voltage power interface and the low-voltage communication interface. Its core safety logic lies in the mandatory verification of the connection sequence. Through a set of logic gate circuits or microcontrollers, it is ensured that only after the connection status of the low-voltage communication interface is confirmed to be reliably connected will an allow signal be generated, authorizing the explosion-proof power monitoring module to close its internal high-voltage relay, thereby connecting the high-voltage power interface. Conversely, during the disconnection operation, once an intention or action to disconnect the low-voltage communication interface is detected, the allow signal will be immediately revoked, forcing the battery management system to first disconnect the high-voltage main circuit, ensuring that the high-voltage power interface can achieve zero-voltage insertion and removal under no current load. This is the specific implementation of its foolproof verification function, fundamentally eliminating the risk of arcing due to misoperation.
[0100] For example, the explosion-proof power supply monitoring module performs thermal runaway early warning monitoring on a battery stack composed of high-capacity lithium iron phosphate cells connected in series, with preset weighting coefficients as follows: , , And the safety threshold for each indicator is set as follows: Within a certain monitoring period, the highest temperature rise rate of a single battery cell is obtained through high-frequency data acquisition and differential calculation. Maximum single-cell voltage drop rate Dynamic DC internal resistance growth rate Substitute into the formula The thermal runaway risk index was calculated. Since the calculation result did not exceed the alarm threshold 1, it was determined that the current situation was within the safe fluctuation range, and the thermal runaway warning was not triggered for the time being. At the same time, when the power supply box replacement operation was performed, the quick-change interface safety interlock module monitored the interface status in real time through the position detection sensor. When it was confirmed that the low-voltage communication interface was fully connected, the logic circuit generated an authorization signal to authorize the explosion-proof power supply monitoring module to close the high-voltage relay to connect the high-voltage power interface. During the disconnection operation, once the low-voltage interface was detected to have displaced, the authorization signal was immediately forcibly revoked to disconnect the high-voltage main circuit first, ensuring that the high-voltage power interface could achieve zero-voltage insertion and removal under no-current load. Thus, through the deep coupling of electrochemical multivariate trend prediction and physical interface hard interlock, the risk of thermal runaway and the hidden danger of electric arc during power replacement were eliminated.
[0101] In one possible implementation, combining Figure 2 The system also includes:
[0102] The energy efficiency closed-loop management module is used to dynamically adjust the motor output power and perform energy regenerative braking through the vehicle controller based on the real-time road load determined by the working condition identification and inquiry activation module.
[0103] The thermal management closed-loop control module is used to dynamically adjust the cooling circulation flow rate of the integrated drive axle based on the temperature rise gradient inside the integrated explosion-proof control box.
[0104] In some implementations, closed-loop control of energy efficiency and thermal management, while ensuring the vehicle's explosion-proof safety, improves the vehicle's operating economy and the service life of key components through refined closed-loop regulation of energy and heat flow. This is achieved through two independent control loops: an energy efficiency closed-loop management module and a thermal management closed-loop control module. The energy efficiency closed-loop management module aims to dynamically optimize the vehicle's energy usage strategy based on real-time changes in external load. This module uses the real-time road condition load determination output by the operating condition identification and query activation module as its core input. For example, when the system identifies that the vehicle is in a high-load uphill condition, the vehicle controller will adjust the motor's torque distribution strategy based on a preset motor efficiency graph, ensuring it operates in its highest efficiency range, rather than simply responding to the driver's accelerator pedal commands. When the system detects that the vehicle is entering a long downhill condition, the module automatically activates the regenerative braking function. At this point, the vehicle controller calculates the target regenerative braking torque. The magnitude of this torque depends not only on the gradient and vehicle speed but also on the dynamic constraints of the current state of charge (SOC) and the maximum allowable charging current reported by the battery subsystem. This ensures that energy recovery is maximized while avoiding overcharging damage to the battery. The thermal management closed-loop control module focuses on maintaining the temperature stability of core powertrain components. Its controlled objects are high-power electronic devices such as the motor controller and vehicle controller within the integrated explosion-proof control enclosure, as well as the tightly integrated drive motor. The core input to this module is not the absolute temperature value, but rather the temperature rise gradient, i.e., the rate of temperature change, calculated through high-frequency sampling and time-difference calculation of data from multiple temperature sensors within the enclosure. This gradient-based feedforward control logic enables predictive thermal management. When the temperature rise gradient exceeds a warning threshold, such as 0.5 degrees Celsius per second, even if the current temperature is far below the alarm limit, the module will immediately increase the speed of the integrated drive axle cooling system's water pump via a pulse-width modulation signal, thereby increasing the cooling circulation flow rate. Its control logic can be expressed as a piecewise function, dynamically adjusting the cooling circulation flow rate based on the temperature rise gradient and the current temperature. This ensures that the temperature of the core components is always kept within the optimal operating range of 40 to 75 degrees Celsius, thereby effectively preventing performance degradation or hardware damage caused by heat buildup.
[0105] For example, the energy efficiency closed-loop management module can detect when a vehicle enters a slope. During long downhill driving conditions, the state of charge reported by the power battery subsystem should be considered. and maximum allowable charging current The system calculates and activates the target regenerative braking torque, ensuring that the battery charging current remains within a safe threshold while recovering gravitational potential energy. Simultaneously, the thermal management closed-loop control module monitors the temperature rise gradient of the power devices within the integrated explosion-proof control enclosure in real time. If the measured temperature rises from [a certain value] within a sampling period... Rise to The temperature gradient was calculated. Because the value exceeded Upon reaching the warning threshold, the system immediately instructs the cooling water pump speed to decrease from the rated speed via a pulse width modulation signal. Upgraded to This increases the cooling circulation flow rate. From the initial Dynamically increase to This allows for predictive thermal management to control the temperature of core components within a specific range. to The optimal range effectively prevents the performance degradation of electrical components caused by heat accumulation in the enclosed explosion-proof space.
[0106] It should be noted that the electrical connections between the various units described above do not necessarily represent direct or indirect connections. Any indirect connection method can be applied to the embodiments of the present invention as long as it achieves the purpose of the present invention. The above descriptions are merely exemplary embodiments of the present invention and should not be construed as limiting the scope of the present invention.
[0107] All equivalent changes and modifications made in accordance with the teachings of this invention are still within the scope of this invention. Those skilled in the art will readily conceive of other embodiments of this invention upon considering the specification and the disclosure of practical truth. This application is intended to cover any variations, uses, or adaptations of this invention that follow the general principles of this invention and include common knowledge or conventional techniques in the art not described herein.
Claims
1. A safety monitoring and management system for mine explosion-proof lithium-ion battery-powered trackless rubber-wheeled vehicles, characterized in that, The system includes: The integrated data acquisition module is used to acquire basic operating status data of the vehicle and periodic self-inspection reports of the subsystems, and generate an integrated status dataset. The subsystems include a power battery subsystem, a drive control subsystem, a hydraulic braking subsystem, and an environmental perception subsystem. The risk mode definition module is used to preset several special risk inquiry modes, including: an electrochemical stability inquiry mode for the risk of lithium plating in large-capacity cells, a braking fade risk inquiry mode for long downhill conditions, and an explosion-proof safety linkage inquiry mode for high-risk gases in the well. The working condition identification and inquiry activation module is used to identify the current working condition mode of the vehicle based on the comprehensive status dataset, and dynamically activate the corresponding special risk inquiry mode based on the identified working condition mode. The cross-subsystem interaction testing module is used to perform light interaction tests across subsystems under the activated special risk exploration mode to obtain collaborative response data between subsystems. The dynamic resilience map construction module is used to construct a dynamic system resilience map based on the periodic self-inspection report and the collaborative response data, wherein the system resilience map is used to describe the safety boundary margin and collaborative working margin of each subsystem; The decision execution and guidance control module is used to combine the system resilience map and real-time environmental data to implement resilience adaptation strategies and gradient guidance strategies. The dynamic resilience mapping construction module includes: The safety boundary quantification unit is used to calculate the state of charge margin of the power battery subsystem, the pressure stability margin of the hydraulic braking subsystem, and the intrinsically safe circuit insulation margin of the environmental sensing subsystem based on the periodic self-inspection report, and to determine the initial safety boundary of each subsystem. The synergy effect assessment unit is used to analyze the performance fluctuation correlation between different subsystems under the special risk exploration mode based on the synergy response data, and extract the synergy work margin index. The map mapping generation unit is used to perform multi-dimensional feature mapping between the initial safety boundaries of each subsystem and the cooperative working margin index to generate a dynamic resilience map describing the adaptability of the whole vehicle system to extreme complex working conditions. The decision execution and guidance control module includes: The resilience adaptation strategy unit is used to assess the current health status of each subsystem based on the dynamic resilience map, dynamically adjust the maximum output power limit of the drive control subsystem and the pre-charge pressure of the hydraulic braking subsystem, and adapt to the current system resilience. The gradient guidance execution unit is used to execute a graded safety response based on the real-time environmental data and the system resilience map. When the environmental risk reaches a preset threshold and the system resilience meets the evacuation conditions, it maintains an intrinsically safe low-power traction mode to guide the vehicle to evacuate from the danger zone. The fail-safe interlocking unit is used to immediately trigger a high-voltage power-off command and forcibly release the spring-energy-storage emergency brake when the braking pressure or battery thermal runaway index in the system toughness profile exceeds the safety boundary, thereby achieving fail-safe automatic braking.
2. The safety monitoring and management system for mine explosion-proof lithium-ion battery trackless rubber-wheeled vehicles according to claim 1, characterized in that, The integrated data acquisition module includes: The basic data acquisition unit is used to acquire vehicle speed, motor operating mode, vehicle gradient, and total current and voltage of the on-board power supply in real time, forming basic operating status data. The self-test command interaction unit is used to issue self-test commands to each of the subsystems and receive battery health reports and braking status reports returned by each of the subsystems, forming a periodic self-test report. The dataset integration unit is used to integrate the basic operating status data, the battery health report, and the braking status report to generate a comprehensive status dataset.
3. The safety monitoring and management system for the mine explosion-proof lithium-ion battery trackless rubber-wheeled vehicle according to claim 1, characterized in that, The operating condition identification and inquiry activation module includes: The pattern matching unit is used to compare the comprehensive state dataset with a preset working condition feature library to identify whether the vehicle is currently in a long downhill working condition, a high-load uphill working condition, or a stationary standby working condition. The inquiry decision unit is used to match the corresponding inquiry priority according to the identified working condition mode and determine whether the activation conditions of the special risk inquiry mode are met. The logic triggering unit is used to send a synchronization command to the relevant subsystem when the activation condition is met, thereby activating the corresponding electrochemical stability probing mode, braking fade risk probing mode, or explosion-proof safety linkage probing mode.
4. The safety monitoring and management system for mine explosion-proof lithium-ion battery trackless rubber-wheeled vehicles according to claim 1, characterized in that, The cross-subsystem interaction testing module includes: The dynamic load triggering unit is used to instruct the drive control subsystem to generate a short-time pulse load when executing the electrochemical stability probing mode, and simultaneously collect the terminal voltage response data of the power battery subsystem to obtain the dynamic DC internal resistance characteristics of the cell. The braking performance detection unit is used to detect the pressure build-up time and braking torque feedback data of the hydraulic braking subsystem under the fully sealed oil chamber condition by applying a compensation torque through the drive control subsystem when executing the brake fade risk inquiry mode. The safety redundancy verification unit is used to simulate the intrinsically safe circuit fault signal of the environmental perception subsystem when executing the explosion-proof safety linkage interlocking mode, and to test the response speed of the vehicle controller to the failure safety logic and the execution reliability of the automatic braking.
5. The safety monitoring and management system for mine explosion-proof lithium-ion battery trackless rubber-wheeled vehicles according to claim 1, characterized in that, The system also includes: An integrated explosion-proof control enclosure houses the vehicle controller, motor controller, and high-voltage power distribution unit of the drive control subsystem. The intrinsically safe associated isolation unit is located inside the integrated explosion-proof control box and is used to electrically isolate the intrinsically safe circuit of the environmental sensing subsystem from the non-intrinsically safe circuit inside the box, and to limit the energy output to the external sensors of the box. The communication bus management module is used to establish an explosion-proof and intrinsically safe communication link between the integrated explosion-proof control box and the explosion-proof power supply box of the power battery subsystem, so as to realize the real-time transmission of self-test commands and collaborative response data.
6. The safety monitoring and management system for the mine explosion-proof lithium-ion battery trackless rubber-wheeled vehicle according to claim 1, characterized in that, The power battery subsystem includes: The explosion-proof power supply monitoring module is used to manage the explosion-proof power supply box composed of lithium iron phosphate battery cells connected in series, and integrates a thermal runaway early warning algorithm to perform anomaly judgment by monitoring the changes in battery cell voltage, temperature and internal resistance. The quick-switch interface safety interlock module is installed at the quick-switch interface of the explosion-proof power supply box and is used to perform connection status monitoring and foolproof verification between the high-voltage power interface and the low-voltage communication interface.
7. The safety monitoring and management system for mine explosion-proof lithium-ion battery trackless rubber-wheeled vehicles according to claim 5, characterized in that, The system also includes: The energy efficiency closed-loop management module is used to dynamically adjust the motor output power and perform energy regenerative braking through the vehicle controller based on the real-time road load determined by the working condition identification and inquiry activation module. The thermal management closed-loop control module is used to dynamically adjust the cooling circulation flow rate of the integrated drive axle based on the temperature rise gradient inside the integrated explosion-proof control box.
8. A safety monitoring and management method for trackless rubber-wheeled vehicles equipped with explosion-proof lithium-ion batteries used in mining, characterized in that... The method is used in the safety monitoring and management system of a mine explosion-proof lithium-ion battery trackless rubber-wheeled vehicle as described in any one of claims 1-7, and the method includes: Acquire basic operating status data of the vehicle and periodic self-inspection reports of the subsystems to generate a comprehensive status dataset. The subsystems include a power battery subsystem, a drive control subsystem, a hydraulic braking subsystem, and an environmental perception subsystem. Several specific risk exploration modes are preset, including: an electrochemical stability exploration mode for the risk of lithium plating in large-capacity cells, a braking fade risk exploration mode for long downhill conditions, and an explosion-proof safety linkage exploration mode for high-risk gases in the well. The vehicle's current operating condition is identified based on the comprehensive status dataset, and the corresponding special risk inquiry mode is dynamically activated based on the identified operating condition. Under the activated special risk exploration mode, perform light interaction tests across subsystems to obtain collaborative response data between subsystems; Based on the periodic self-inspection reports and the collaborative response data, a dynamic system resilience map is constructed, wherein the system resilience map is used to describe the safety boundary margin and collaborative working margin of each subsystem. Based on the system resilience map and real-time environmental data, a resilience adaptation strategy and a gradient guidance strategy are implemented. The dynamic resilience mapping construction module includes: The safety boundary quantification unit is used to calculate the state of charge margin of the power battery subsystem, the pressure stability margin of the hydraulic braking subsystem, and the intrinsically safe circuit insulation margin of the environmental sensing subsystem based on the periodic self-inspection report, and to determine the initial safety boundary of each subsystem. The synergy effect assessment unit is used to analyze the performance fluctuation correlation between different subsystems under the special risk exploration mode based on the synergy response data, and extract the synergy work margin index. The map mapping generation unit is used to perform multi-dimensional feature mapping between the initial safety boundaries of each subsystem and the cooperative working margin index to generate a dynamic resilience map describing the adaptability of the whole vehicle system to extreme complex working conditions. The decision execution and guidance control module includes: The resilience adaptation strategy unit is used to assess the current health status of each subsystem based on the dynamic resilience map, dynamically adjust the maximum output power limit of the drive control subsystem and the pre-charge pressure of the hydraulic braking subsystem, and adapt to the current system resilience. The gradient guidance execution unit is used to execute a graded safety response based on the real-time environmental data and the system resilience map. When the environmental risk reaches a preset threshold and the system resilience meets the evacuation conditions, it maintains an intrinsically safe low-power traction mode to guide the vehicle to evacuate from the danger zone. The fail-safe interlocking unit is used to immediately trigger a high-voltage power-off command and forcibly release the spring-energy-storage emergency brake when the braking pressure or battery thermal runaway index in the system toughness profile exceeds the safety boundary, thereby achieving fail-safe automatic braking.
Citation Information
Patent Citations
Comprehensive protection system for explosion-proof storage battery electric locomotive
CN117799498A
Explosion-proof electrical control system and method for mining underground explosion-proof electric vehicle
CN118928253A