Redundant communication control system and method for power unit

By employing a redundant control architecture with multiple controller backups and independent communication expansion modules, combined with an analog reference benchmark verification mechanism, the problem of the lack of fault tolerance in the single control architecture of power electronic equipment control systems and the high cost and poor compatibility of existing redundancy schemes has been solved, thus achieving stable operation and economical adaptation of the equipment.

CN121596720BActive Publication Date: 2026-04-17DONGFANG ELECTRIC AUTOMATIC CONTROL ENG CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
DONGFANG ELECTRIC AUTOMATIC CONTROL ENG CO LTD
Filing Date
2026-01-29
Publication Date
2026-04-17

AI Technical Summary

Technical Problem

Existing power electronic equipment control systems suffer from a lack of fault tolerance due to their single control architecture. The switching strategy based on heartbeat signals cannot identify abnormal analog quantity sampling, leading to abnormal equipment operation. Furthermore, existing redundancy solutions are costly and have poor compatibility.

Method used

A redundant control architecture is constructed using multiple controller backups and independent communication expansion modules. Analog sampled data is used to assist in verifying the controller status, enabling seamless switching between primary and backup controllers. An analog reference benchmark verification mechanism is introduced, combining three core parameters—voltage, current, and temperature—to ensure system stability and compatibility.

Benefits of technology

It significantly improves system stability, avoids the risk of equipment downtime due to single controller failure, reduces hardware modification costs, and has good adaptability, allowing direct application in existing equipment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121596720B_ABST
    Figure CN121596720B_ABST
Patent Text Reader

Abstract

The application belongs to the technical field of power electronics, and discloses a redundant communication control system and method of a power unit, aiming at solving the problems of high single-point fault risk, difficult identification of sampling abnormalities and poor compatibility of the existing system. The system comprises a communication expansion module, a power circuit system and a plurality of controllers which are backup to each other, and the controllers have independent sampling, operation and input / output channels; the communication expansion module is the decision center, and determines the fault and the main ring controller in combination with the power circuit analog quantity and the controller heartbeat signal. The method defines the system state, initially determines the main and backup controllers after power-on by listening to the heartbeat, synchronously samples the analog quantity, calculates the reference reference value to check the sampling state of the controller, seamlessly switches the main and backup controllers in case of fault, and forms a closed-loop control. The application can avoid single-point fault, cover the sampling abnormal blind area, be compatible with the existing equipment, reduce the transformation cost, and ensure the stable operation of the photovoltaic inverter and other equipment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of power electronics technology, and particularly relates to a redundant communication control system and method for a power unit. Background Technology

[0002] As the global energy structure transitions towards low-carbon energy, the power share of power electronic new energy equipment (such as photovoltaic inverters and energy storage converters) in the power grid continues to increase. These devices are gradually shifting from the traditional "grid-following" operation mode to a "grid-supporting" mode, placing higher demands on their reliability, stability, and fault tolerance. In existing technologies, the control systems of power electronic equipment generally adopt a single control architecture, containing only one controller, sampling loop, and control loop. This architecture has significant drawbacks: when the sampling loop, control loop, or controller itself malfunctions, it can easily lead to abnormal equipment operation or even shutdown, causing direct losses to industrial production, grid stability, and residential life.

[0003] To improve system reliability, some products attempt to adopt a redundancy switching strategy based on the controller's heartbeat signal: when the main controller's heartbeat signal is abnormal, the system automatically switches to the hot standby controller. However, this strategy relies solely on the controller's own operating status (such as CPU operating status and communication link connectivity), completely neglecting to verify the correctness of analog quantity sampling (such as key parameters like voltage, current, and temperature). In practical applications, if the controller is operating normally but the sampling channel malfunctions (such as sensor failure or signal interference), this strategy cannot identify the distortion of the sampled data and will still use erroneous sampling information for control calculations, ultimately leading to equipment output overvoltage, overcurrent, or overtemperature faults, which may, in severe cases, cause equipment damage or safety accidents.

[0004] Furthermore, existing redundancy solutions generally suffer from high costs and poor compatibility. Traditional redundancy designs often require a complete overhaul of the controller and power system, resulting in significant hardware investment and potentially impacting the compatibility and versatility of the original system, making them difficult to promote and apply in existing equipment.

[0005] In summary, existing power electronic equipment control systems have significant shortcomings in reliability design: single control architectures lack effective fault tolerance, heartbeat signal-based switching strategies cannot cover scenarios with analog signal sampling anomalies, and existing redundancy solutions are costly and have poor adaptability. Therefore, there is an urgent need for a redundant control technology that balances reliability, cost, and compatibility to achieve comprehensive verification of controller status and sampling loops, and to enable seamless switching in case of faults, ensuring the stable operation of power electronic equipment. Summary of the Invention

[0006] The purpose of this invention is to address the shortcomings of the existing technology by proposing a redundant communication control system and method for power units. The system constructs a redundant control architecture by adding a communication expansion module and peripheral control circuits; the method introduces analog sampling data to assist in verifying the controller state, enabling hot-switching in case of main loop controller malfunction or sampling channel failure. This solution is compatible with existing systems, improves reliability, and reduces costs.

[0007] To achieve the above objectives, the present invention adopts the following technical solution:

[0008] A redundant communication control system for a power unit includes a communication expansion module, a power loop system, and a controller; the power loop system is configured according to the three phase correspondences. One power unit, This indicates the number of cascaded power units in a single phase of a power loop system.

[0009] The number of controllers Each controller serves as a backup for the others, and each individual controller has an independent analog signal sampling channel, control calculation module, and digital output channel. It is connected to the power loop system through the analog signal sampling channel and digital output channel, and has the functions of independently completing analog signal sampling, control parameter calculation, PWM control signal generation, and sending digital control commands to the power loop system in the main loop state.

[0010] The communication expansion module is bidirectionally connected to the power loop system and each controller, and is used to determine the system fault state based on the analog signals of the power loop system and the heartbeat signals of the controllers, and to determine the system fault state and, in the system non-fault state, to... The main loop controller is determined among the controllers, and under non-fault conditions of the system, the PWM control signal of the main loop controller is converted and sent to the power loop system to implement PWM control on each power unit in the power loop system.

[0011] Preferably, the communication expansion module includes a backplane, on which a core board, a power board, and an optical signal adapter board are mounted; the core board is controlled by an FPGA module with external SDRAM, and has reserved Ethernet optical and Ethernet electrical ports for high-speed communication with the controller; the number of optical signal adapter boards... All optical signal adapter boards are routed through the backplane and connected to the FPGA module via the onboard buffer I on the core board. Each individual optical signal adapter board is equipped with at least one optical transceiver with onboard buffer II for connecting to the power loop system. The power supply board is routed through the backplane and connected to the core board and each optical signal adapter board.

[0012] Preferably, the backplane is provided with terminal block units based on the inter-board wiring; the terminal block units include onboard connector JⅠ, onboard connector JⅡ, and onboard connector JⅢ. The number of onboard connector JⅠ... The core board is equipped with board-to-board connectors CNI that plug into each other, corresponding one-to-one with the onboard connectors JI. The board-to-board connectors CNI are connected to the FPGA module through corresponding onboard buffers I. The number of onboard connectors JI... Each optical signal adapter board is equipped with a board-to-board connector CNⅡ. On each individual optical signal adapter board, all optical transceivers are connected to the board-to-board connector CNⅡ through a corresponding onboard buffer Ⅱ. All optical signal adapter boards are connected to the onboard connector JⅡ through the board-to-board connector CNⅡ, and the same or different onboard connector JⅠ are connected through the corresponding onboard connector JⅡ. The power supply board is equipped with an isolated DC-DC converter and filter system. The input end of the isolated DC-DC converter and filter system is equipped with a power interface for connecting an external 24V power supply. The output end of the isolated DC-DC converter and filter system is equipped with a board-to-board connector CNⅢ for connecting to the onboard connector JⅢ, outputting 12V power to the power terminals of each onboard connector JⅠ and onboard connector JⅡ.

[0013] A redundant communication control method for a power unit, which employs the aforementioned redundant communication control system to implement redundant communication control of the power unit, specifically includes the following steps:

[0014] S1 defines the initial state of the system. System fault status and the loop operation status of each controller ;in, Indicates the controller's index number, i.e. Indicates that the index number is The controller corresponds to the loop operating state. ;

[0015] S2, The control system powers on and enters the initial state. The communication expansion module listens for the heartbeat signals of all controllers within a set time period in order to... One main loop controller has been initially identified from among the controllers. and One hot standby controller, ,in This indicates the index number of the main loop controller, and ;

[0016] S3, the control system switches to the current main loop controller. Corresponding to the loop operation state Main loop controller Send a switching control command to the power loop system to bring the power loop system into its initial operating state;

[0017] S4, Main Loop Controller Through the communication expansion module, the power loop system and After each hot standby controller sends periodic parameters and a sampling start signal, the power loop system and the main loop controller... and Each hot standby controller synchronously performs analog counting and sampling of the power loop system according to the period parameters, and uploads the sampled data to the communication expansion module;

[0018] S5, main loop controller and Each hot standby controller calculates its own control parameters based on its analog signal counting and sampling results to generate PWM control signals.

[0019] S6, the communication expansion module obtains the analog reference value based on the sampled data uploaded by the power loop system, and combines the reference value with the main loop controller. and The system uses sampled data uploaded by each hot standby controller to determine if a fault has occurred in the control system; if so, the control system switches to a system fault state. If not, proceed to step S7;

[0020] S7, based on the abnormal status determination of the controller's analog signal sampling, to further clarify the number of hot standby controllers. and main loop controller And through the communication expansion module, the main loop controller The corresponding PWM control signal is converted and sent to the power loop system to complete one control cycle;

[0021] S8, determine if the number of hot standby controllers is sufficient. If not, the system is determined to be abnormal and a system maintenance prompt is given before returning to step S4; if yes, the system returns directly to step S4; thus forming a closed-loop control cycle.

[0022] Preferably, in step S2, a main loop controller is initially determined. and The method for a hot standby controller is as follows:

[0023] S21, the communication extension module determines whether it has received a heartbeat signal from at least one controller within a set time; if yes, proceed to step S22; if no, the control system switches from system to system fault state. ;

[0024] S22, the controller that first receives the heartbeat signal from the communication expansion module is designated as the initial main loop controller. ;

[0025] S23, for the main loop controller Other For each controller, the communication expansion module determines whether it receives its corresponding heartbeat signal within a set time. If not, the corresponding controller is determined to be abnormal, and the abnormal controller is prevented from participating in the subsequent control process. If yes, the corresponding controller is determined to be normal.

[0026] S24, Count the number of normal controllers and make the The normal controller is the initial hot standby controller.

[0027] Preferably, the analog quantities include voltage, current, and temperature. Therefore, in step S6, the method for determining whether the control system has malfunctioned is as follows:

[0028] S61, sequentially traverse the current main loop controllers. and Each hot standby controller, for each individual controller The voltage, current, and temperature sampling status are determined by comparing the sampled values ​​with a reference value. If any analog quantity sampling status is abnormal, the corresponding controller is flagged. abnormal; ;

[0029] S62, determine the current main loop controller Is it an abnormal controller? If yes, proceed to step S63; if no, directly determine that the control system has not malfunctioned.

[0030] S63, Determine the current state If all the hot standby controllers are faulty, then the system is determined to be faulty; otherwise, the control system is determined not to be faulty.

[0031] Preferably, in step S7, the number of hot standby controllers is determined again. and main loop controller The method is as follows: determine the current value based on the reference baseline. Are there any faulty controllers among the hot standby controllers? If so, determine the number of faulty controllers. And from the current Remove faulty controllers from each hot standby controller, and retain the following number of hot standby controllers: If not, retain the original. One hot standby controller. The current main loop controller is determined based on a reference baseline value. Is it an abnormal controller? If not, maintain the current main loop controller. Corresponding to the loop operation state Proceed directly to step S8; if so, proceed from the reserved... Of the hot standby controllers, the nearest primary loop controller will be reassigned. And switch to the corresponding loop operation state of the main loop controller. , To determine the nearest index number interval, the number of hot standby controllers is set. Then, proceed to step S8.

[0032] Preferably, in step S61, the method for determining the voltage sampling state is as follows:

[0033] definition This indicates the DC bus voltage of each power unit transmitted back by the power loop system. This indicates the modulation duty cycle of each power unit transmitted through the power loop system. This indicates the index number of each power unit in the power loop system. ;

[0034] Let the index number of the R-phase power unit in the power loop system be represented as , and The S-phase power unit index number is represented as follows: , and The T-phase power unit index number is represented as follows: , and ;

[0035] Calculate the equivalent output voltage of each phase of the power loop system. As a voltage reference value; where The corresponding three phases of the power circuit system; R-phase equivalent output voltage S-phase equivalent output voltage T-phase equivalent output voltage ;

[0036] Set the maximum permissible error threshold for the output phase voltage. , make the controller For power loop systems The output voltage sample value of the phase is expressed as If it exists Then determine the controller abnormal.

[0037] Preferably, in step S61, the method for determining the current sampling state is as follows:

[0038] definition This represents the DC bus current returned by each power unit in the power loop system. This indicates the index number of each power unit in the power loop system. ;

[0039] Let the index number of the R-phase power unit in the power loop system be represented as , and The S-phase power unit index number is represented as follows: , and The T-phase power unit index number is represented as follows: , and ;

[0040] Command the current main loop controller The total number of hot standby controllers is And sorted by index number from smallest to largest The controllers are sorted, and the sorting sequence number is represented as... , Among them, the first A controller for the power loop system The output current sampling value of the phase is expressed as ; This corresponds to the three phases of the power circuit system;

[0041] Power distribution loop system and The current sampling weights of each controller; where... The current sampling weights of each controller are all The current sampling weight of the power loop system is Then there is and ;

[0042] Calculate the reference value of instantaneous current in each phase of the power loop system. As a current reference; where, the instantaneous current reference value of phase R. S-phase instantaneous current reference value T-phase instantaneous current reference value ;

[0043] Set the maximum permissible error threshold for the output phase current. , make the controller For power loop systems The output current sampling value of the phase is expressed as If it exists Then determine the controller abnormal.

[0044] Preferably, in step S61, the method for determining the temperature sampling status is as follows:

[0045] make Indicating a power loop system The index number of each temperature sampling point Temperature sampling points The number of adjacent power units is Then use This indicates the power unit index number. ;

[0046] For each individual temperature sampling point Obtain their corresponding The internal temperature monitoring values ​​and temperature rise values ​​of each adjacent power unit, where the power unit The internal temperature monitoring value and temperature rise value are respectively expressed as: and Temperature rise Through power unit The output power-temperature rise curve is obtained;

[0047] For each individual temperature sampling point Calculate the equivalent temperature value As a temperature reference standard; among which ;

[0048] Set the maximum permissible error threshold for ambient temperature. , make the controller At temperature sampling points The temperature sample value at that location is expressed as If it exists Then determine the controller abnormal.

[0049] The beneficial effects of this invention are:

[0050] 1) Compared to traditional power electronic equipment control systems, which often employ a "single controller + single sampling / control loop" architecture, where a failure in any component leads to equipment shutdown, this technical solution constructs a highly redundant system through multi-controller backup combined with independent communication expansion modules: the number of controllers meets the requirements... Each controller has an independent analog signal sampling channel, control calculation module, and switch output channel, and can independently complete sampling, calculation, and control command generation, providing hot standby for each other; the communication expansion module serves as an independent decision-making center, uniformly managing the switching between primary and backup controllers without relying on any single controller, while the power unit is designed for three phases. This allows for cascading expansion, completely avoiding the risk of equipment downtime caused by single controller or single-loop failures, and significantly improving system stability.

[0051] 2) Compared to existing redundant solutions that rely solely on controller heartbeat signals to determine status, which cannot identify scenarios where the heartbeat is normal but the sampling channel is faulty (e.g., sensor damage, signal interference), easily leading to erroneous control outputs, this technical solution innovatively introduces an analog reference benchmark verification mechanism. It uses three core analog quantities—voltage, current, and temperature—as verification dimensions: a reference benchmark value is calculated based on the power loop system's native data (e.g., power unit DC bus voltage, modulation duty cycle). The sampled values ​​of each controller are then compared to the benchmark value. If the deviation exceeds a set threshold, the controller is deemed abnormal. This mechanism covers key operating parameters of the power unit, completely resolving the blind spot of traditional solutions that rely solely on heartbeat signals, and enabling accurate fault location in the early stages.

[0052] 3) Compared to traditional redundancy solutions that require comprehensive modifications to the controller and power system, resulting in high hardware investment, poor compatibility, and difficulty in widespread adoption in existing equipment, this technical solution achieves high adaptability through a modular design of the communication expansion module: the communication expansion module adopts a structure of backplane, core board, optical signal adapter board, and power board. The core board reserves Ethernet optical and electrical ports to adapt to different controllers, and the number of optical signal adapter boards... It can be flexibly adjusted, with the power board providing independent 12V power supply and isolated from the original system; there is no need to modify the existing power circuit system and controller, and redundancy can be achieved simply by connecting through the communication expansion module, which greatly reduces the cost of hardware modification. It can be directly applied to existing equipment such as photovoltaic inverters and energy storage converters, and its adaptability and economy are significantly better than traditional solutions. Attached Figure Description

[0053] Figure 1 This is a schematic diagram of the redundant communication control system of this technical solution;

[0054] Figure 2 This is an example diagram of the backplane wiring structure for this technical solution;

[0055] Figure 3 This is a schematic diagram illustrating the structural principle of the core board in this technical solution.

[0056] Figure 4 This is a schematic diagram illustrating the structural principle of the optical signal adapter board in this technical solution;

[0057] Figure 5 This is a schematic diagram illustrating the structural principle of the power board in this technical solution.

[0058] Figure 6 This is a schematic diagram of the preferred flow of the redundant communication control method in this technical solution. Detailed Implementation

[0059] To make the purpose, technical solution and advantages of the invention clearer, the technical solution of the invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are some embodiments of the invention, but not all embodiments.

[0060] Therefore, the following detailed description of the invention provided in the accompanying drawings is not intended to limit the scope of the claimed invention, but merely to illustrate selected embodiments of the invention. All other embodiments obtained by those skilled in the art based on the embodiments of the invention without inventive effort are within the scope of protection of the invention.

[0061] Example 1

[0062] This embodiment discloses a redundant communication control system for a power unit, as a preferred embodiment of the present invention, such as... Figure 1 As shown, it includes a communication expansion module, a power loop system, and a controller; the power loop system is configured according to the three phases. One power unit, This indicates the number of cascaded power units in a single phase of a power loop system. When When, it indicates no cascading, and there is only one power unit in a single phase; when When there is a cascade, it means that there is only two power units in a single phase participating in the cascade, and so on.

[0063] Number of controllers Each controller serves as a backup for the others, and each individual controller has an independent analog signal sampling channel, control calculation module, and digital output channel. It is connected to the power loop system through the analog signal sampling channel and digital output channel, and has the functions of independently completing analog signal sampling, control parameter calculation, PWM control signal generation, and sending digital control commands to the power loop system in the main loop state.

[0064] The communication expansion module is bidirectionally connected to the power loop system and each controller, and is used to determine the system fault state based on the analog signals of the power loop system and the heartbeat signals of the controllers, and to determine the system fault state and, in the system non-fault state, to... The main loop controller is determined among the controllers, and under non-fault conditions of the system, the PWM control signal of the main loop controller is converted and sent to the power loop system to implement PWM control on each power unit in the power loop system.

[0065] The power loop system can be an existing circuit structure, including a sampling unit, a power unit, and a switch control unit. The sampling unit and the switch control unit are connected to the controller via electrical signals, and the power unit is connected to the communication expansion module via electrical signals or optical signals.

[0066] Example 2

[0067] This embodiment discloses a redundant communication control system for a power unit. As a preferred implementation of the present invention, based on embodiment 1, combined with... Figure 2 , Figure 3 , Figure 4 and Figure 5 As shown, the communication expansion module adopts a modular design, including a backplane, on which a core board, a power board, and an optical signal adapter board are arranged.

[0068] The core board's main controller is a high-performance FPGA module, which is externally connected to a 128Mbits SDRAM for temporary data storage. The core board reserves multiple Gigabit Ethernet ports for connecting to the controller, such as... Figure 3 The core board shown features four Gigabit Ethernet ports, including two Ethernet electrical ports and two Ethernet optical ports. Each Gigabit Ethernet port can connect to a controller, which then directly connects to the FPGA module via Gigabit Ethernet for high-speed real-time communication. The communication expansion module can be configured as a standalone device within a chassis. The Ethernet electrical ports are suitable for low-cost inter-board interconnection within the chassis and can be connected using an 8-core network cable; the Ethernet optical ports are suitable for long-distance data communication between control boxes, requiring the additional installation of an SFP optical module and corresponding fiber optic cable to achieve communication functionality.

[0069] The number of optical signal adapter boards All optical signal adapter boards are routed through the backplane and connected to the FPGA module via onboard buffer I on the core board. Each individual optical signal adapter board is equipped with at least one 10Mbps / 50Mbps optical transceiver configured with onboard buffer II for connecting to the power loop system. Figure 4 The optical signal adapter board shown is equipped with nine 10Mbps optical transceivers.

[0070] The power board is routed through the backplane and then connected to the core board and each optical signal adapter board.

[0071] Example 3

[0072] This embodiment discloses a redundant communication control system for a power unit. As a preferred embodiment of the present invention, based on embodiment 2, a terminal block unit is provided on the backplane based on the inter-board wiring. The terminal block unit includes onboard connector JⅠ, onboard connector JⅡ and onboard connector JⅢ. Onboard connector JⅠ, onboard connector JⅡ and onboard connector JⅢ can all adopt DIN41612 / 3*32PIN / 2.54MM pitch straight male connectors.

[0073] Number of onboard connectors JⅠ The core board is equipped with board-to-board connectors CNⅠ that are plugged into each other with the onboard connector JⅠ. The board-to-board connectors CNⅠ are connected to the FPGA module through corresponding onboard buffers I.

[0074] Number of onboard connectors JII Each optical signal adapter board is equipped with a board-to-board connector CNⅡ; on each individual optical signal adapter board, all optical transceivers are connected to the board-to-board connector CNⅡ through a one-to-one corresponding onboard buffer Ⅱ; all optical signal adapter boards are connected to the onboard connector JⅡ through the board-to-board connector CNⅡ, and the same or different onboard connector JⅠ are connected through the corresponding onboard connector JⅡ.

[0075] The power supply board is equipped with an isolated DC-DC converter and filtering system (such as...). Figure 5 As shown, it includes an EMI filter and an isolated DC / DC unit; the input end of the isolated DC-DC converter and filter system is equipped with a power interface, which connects to the front panel of the chassis for connecting to an external 24V power supply; the output end of the isolated DC-DC converter and filter system is equipped with a board-to-board connector CNⅢ (20PIM) for plugging into the onboard connector JⅢ, outputting 12V power to the power terminals of each onboard connector JⅠ and onboard connector JⅡ. The core board and each optical signal adapter board convert the 12V power supply a second time through their internal DC / DC modules before supplying it to their own circuits.

[0076] Example 4

[0077] This embodiment discloses a redundant communication control method for a power unit. As a preferred embodiment of the present invention, the redundant communication control system in Embodiments 1, 2, or 3 is used to implement redundant communication control of the power unit, such as... Figure 6 As shown, it includes the following steps:

[0078] S1 defines the initial state of the system. System fault status and the loop operation status of each controller ;in, Indicates the controller's index number, i.e. Indicates that the index number is The controller corresponds to the loop operating state. Its implementation principle is based on the state machine design logic of the correspondence between the state and behavior of a power electronic system—three types of states clearly define the core behavioral boundaries of different stages (…). For power-on standby, For emergency protection, (for normal control), and simultaneously through indexing With state The binding establishes a one-to-one mapping between physical controllers and logical control roles, preventing the disconnect between state and controller. This step aims to create a unified logical framework for the entire redundant control process, clarify the behavioral boundaries of the system at each stage, and simplify the decision-making complexity of subsequent master / standby switching by indexing the state, ensuring that the operating state of the target controller can be quickly located during switching.

[0079] S2, The control system powers on and enters the initial state. The communication expansion module listens for the heartbeat signals (heartbeat pulses or heartbeat data frames) of all controllers within a set time period to enable... One main loop controller has been initially identified from among the controllers. and One hot standby controller, ;in This indicates the index number of the main loop controller, and The implementation principle relies on the decision-making center positioning of the communication expansion module—avoiding multiple controllers vying for the master loop role through a single coordinating unit. Simultaneously, a heartbeat signal serves as a survival indicator for the controller hardware to start normally, with a set time (e.g., 30 seconds) to balance avoiding misjudgments and startup delays. The initial master loop is selected based on the principle of the first heartbeat arrival (this principle is fair and efficient because the controller hardware specifications are consistent). The purpose of this step is to quickly establish the initial redundant architecture of the system, avoiding a long-term control vacuum state without a master loop after power-on, and simultaneously conducting preliminary troubleshooting for all controller failures, ensuring that subsequent control processes have available master and backup nodes for support.

[0080] S3, the control system switches to the current main loop controller. Corresponding to the loop operation state Main loop controller The takeover control sends switching control commands to the power loop system to bring it into its initial operating state. Specifically, the communication expansion module sends commands to the main loop controller. The master loop controller sends an in-loop request frame. Upon receiving a loop-in-the-loop request frame, control is taken over. Its implementation principle is based on the core control authority logic of the main loop controller—the main loop has the function of independently sending switching commands (unlike hot standby which only performs calculations and does not output). Switching commands (such as starting the cooling fan or activating the pre-charge circuit) are prerequisites for the power unit to transition from standby to operation. Simultaneously, state switching is bound to command issuance, ensuring that state changes correspond to hardware responses and preventing disordered power loop operation due to mere state switching. This step serves to initiate the basic functions of the power loop, clearing hardware obstacles for subsequent analog sampling and PWM control. It also marks the transition of the system from the initial standby phase to the normal control phase, representing a critical turning point in the redundant control process.

[0081] S4, Main Loop Controller Through the communication expansion module, the power loop system and After each hot standby controller sends a synchronization frame (period parameters and sampling start signal), the power loop system and the main loop controller... and Each hot standby controller synchronously performs analog quantity counting and sampling of the power loop system according to periodic parameters and uploads the sampled data to the communication expansion module. Its implementation principle is based on the requirement of data consistency—analog quantities such as voltage and current change dynamically in real time, and asynchronous sampling will cause data deviations at each node, leading to inconsistencies in control parameter calculations. Therefore, a unified signal triggers and forced synchronous sampling with periodic parameters ensures consistent data timestamps. Simultaneously, relying on the data hub positioning of the communication expansion module, all sampled data is aggregated to avoid data loss in the event of a main loop failure and to provide data support for subsequent benchmark verification. The purpose of this step is to provide a consistent data source for subsequent control parameter calculations, avoiding the problem of data asynchrony leading to control deviations, and simultaneously achieving centralized management of sampled data, laying the data foundation for fault diagnosis and main / standby switchover.

[0082] S5, main loop controller and Each hot-standby controller independently calculates control parameters based on its analog signal counting and sampling results to generate PWM control signals. The underlying principle is redundant logic based on independent controller computation—each controller has an independent control computation module. Hot-standby computation is independent rather than copying the main loop results, avoiding switching delays caused by recalculation in the event of a main loop failure, ensuring seamless PWM signal output during switching. Simultaneously, the PWM signal directly determines the switching timing of the power unit's IGBTs, serving as the instruction for power conversion; therefore, both main and standby controllers must generate the signal to achieve computational redundancy. This step shortens the subsequent main / standby switching delay, avoids power unit output fluctuations due to recalculation during switching, and mitigates the single-point-of-failure risk of main-loop computation alone, ensuring a always available PWM signal to support power control.

[0083] S6, the communication expansion module obtains the analog reference value based on the sampled data uploaded by the power loop system, and combines the reference value with the main loop controller. and The system uses sampled data uploaded by each hot standby controller to determine if a fault has occurred in the control system; if so, the control system switches to a system fault state. If not, proceed to step S7. The implementation principle is objective benchmark verification logic—the reference benchmark value is calculated from the power loop's native data, completely avoiding the impact of controller sampling channel failures. Anomalies are accurately identified by comparing the controller's sampled value with the benchmark value. Simultaneously, full-coverage verification of voltage, current, and temperature is employed, as these three are respectively related to output safety, load safety, and thermal safety; any anomaly may trigger a power unit failure. This step addresses the blind spot of traditional redundancy schemes that rely solely on heartbeat signals, accurately identifying controllers with normal heartbeats but abnormal sampling. Furthermore, by using the judgment condition of a main loop anomaly and the lack of effective hot standby, the boundary between fault and non-fault conditions is accurately defined, avoiding unnecessary fault triggering and ensuring continuous system operation.

[0084] S7, based on the abnormal status determination of the controller's analog signal sampling, to further clarify the number of hot standby controllers. and main loop controller And through the communication expansion module, the main loop controller The corresponding PWM control signal is converted and sent to the power loop system to complete one control cycle. Its implementation principle is a reliability logic of secondary confirmation—eliminating abnormal hot standby nodes marked in step S6; if the main loop is abnormal, a new main loop is selected from the nearest valid hot standby node to ensure that both the main and standby nodes meet the requirements of normal sampling and executable control; simultaneously, relying on the signal conversion function of the communication expansion module (such as an optical signal adapter board), it adapts to the interface differences between the main loop and the power unit (such as converting electrical signals to optical signals) to ensure accurate PWM command delivery. The purpose of this step is to ensure the effectiveness of the main and standby nodes, avoid invalid hot standby nodes participating in control, and complete the closed loop of sampling → calculation → control, enabling the power unit to output as expected, marking the complete execution of one control cycle.

[0085] S8, determine if the number of hot standby controllers is sufficient. If not, the system is determined to be abnormal, and system maintenance is prompted before returning to step S4; if yes, it directly returns to step S4; thus forming a closed-loop control cycle. Determining a control system abnormality and prompting system maintenance means that when only one main loop controller is participating in the control system, and the number of hot standby controllers is zero, the control system is determined to be capable of executing ordinary control without redundancy, posing a risk of failure. In this case, to ensure system reliability, timely system maintenance is necessary. Its implementation principle is based on redundancy bottom-line logic— It is the core of the redundancy architecture. Without effective hot standby, the system loses its backup capability. Once the main loop fails, it will inevitably be interrupted. Therefore, it is necessary to prompt maintenance but continue to operate (to avoid unnecessary downtime). At the same time, based on the periodic real-time control requirements of power electronics, the closed loop ensures that the control commands are updated in real time with the system status, rather than being a fixed output. The role of this step is to continuously monitor the redundancy health of the system, promptly detect the risk of redundancy loss and prompt intervention, and at the same time, to achieve real-time dynamic control through the closed loop to ensure that the power unit adapts to changes in operating conditions and maintains stable operation.

[0086] Example 5

[0087] This embodiment discloses a redundant communication control method for a power unit. As a preferred embodiment of the present invention, based on embodiment 4, in step S2, a main loop controller is initially determined. and The method for a hot standby controller is as follows:

[0088] S21, the communication extension module determines whether it has received a heartbeat signal from at least one controller within a set time; if yes, proceed to step S22; if no, the control system switches from system to system fault state. The heartbeat signal is a survival certificate sent by the controller to the communication expansion module, reflecting whether the controller hardware has started normally. If no heartbeat is received within a set time, it means that all controllers have not started normally, the system has no available control nodes, and subsequent power unit control cannot be executed. The communication expansion module is the core decision-making unit for redundancy control and must first confirm whether there is a controller available—this is a prerequisite for system startup. If even the survival of at least one controller cannot be guaranteed, subsequent main loop / hot standby selection and control command issuance are impossible, and the system must directly enter a fault state (such as triggering an alarm or cutting off the power loop input) to avoid the risks caused by system idle waiting.

[0089] S22, the controller that first receives the heartbeat signal from the communication expansion module is designated as the initial main loop controller. In this system, N ≥ 2 controllers have identical hardware specifications (each controller serves as a backup for the others, possessing independent sampling, computation, and output functions). Differences in the heartbeat signal transmission timing stem only from minor delays in the communication link (such as differences in cable length and interface contact resistance), with no fundamental priority distinction. Adopting a first-come, first-served principle eliminates the need for complex priority algorithms (such as sorting based on hardware number or performance parameters), significantly simplifying the computational logic of the communication expansion module and shortening the master loop determination time—crucial for power electronic equipment to prevent control vacuums caused by excessively long master loop selection times during startup. The master loop controller must take priority in taking over system control (e.g., sending initial switching commands to the power circuit to put the power unit into standby mode). If the master loop determination is delayed, the power circuit may remain in a state of uncontrolled disorder for an extended period, posing a risk of malfunction. The first-come, first-served principle quickly identifies the first surviving controller as the master loop, ensuring control commands are issued as early as possible.

[0090] S23, for the main loop controller Other Each controller has a communication extension module that checks whether it receives its corresponding heartbeat signal within a set time. If not, the controller is deemed abnormal and excluded from subsequent control processes. If it does receive the heartbeat signal, the controller is deemed normal. The core function of the hot standby controller is to seamlessly take over in case of a main loop failure; therefore, it must have the same survival capability as the main loop (normal hardware and uninterrupted communication). Failure to verify each controller individually may result in abnormal controllers that have lost heartbeats being included in the hot standby pool, leading to a switch to an invalid hot standby in case of a subsequent main loop failure, causing system interruption. The hot standby verification setting time is consistent with step S21 to ensure that the survival judgment criteria for all controllers are unified—avoiding some controllers being misjudged as abnormal (e.g., short-time threshold missed detection of slow-start controllers) or abnormal controllers being misjudged as normal (e.g., long-time threshold tolerance fault controllers) due to different time thresholds. Abnormal controllers do not participate in subsequent processes, essentially severing the connection between invalid nodes and the control link—if abnormal controllers remain in the system, they may send incorrect signals to interfere with the main loop control or occupy communication bandwidth, affecting the data transmission of valid controllers.

[0091] S24, Count the number of normal controllers and make the One normal controller serves as the initial hot standby controller. Number of hot standby controllers. It is the core indicator of system redundancy capability. This indicates no redundancy. (Indicates fault tolerance capability), statistics The redundancy level at system startup can be clearly determined—subsequent steps (such as step S8) can be used to determine this. This data is needed to determine whether maintenance is required, therefore quantification must be completed in the initial stage. After statistics, the specific scope of the initial hot standby controller is clarified, so that the communication expansion module can accurately call hot standby resources, avoid confusion between effective hot standby and abnormal controllers, and simplify the decision-making process for subsequent redundancy switching.

[0092] Example 6

[0093] This embodiment discloses a redundant communication control method for a power unit. As a preferred embodiment of the present invention, based on embodiment 4 or 5, where the analog quantities include voltage, current, and temperature, the method for determining whether the control system has a fault in step S6 is as follows:

[0094] S61, sequentially traverse the current main loop controllers. and Each hot standby controller, for each individual controller The voltage, current, and temperature sampling status are determined by comparing the sampled values ​​with a reference value. If any analog quantity sampling status is abnormal, the corresponding controller is flagged. abnormal; Voltage, current, and temperature are the three core parameters for the operation of a power unit. Voltage determines the output amplitude of the power unit, current reflects the load matching status, and temperature relates to the thermal safety of components. These three directly determine the effectiveness of the control strategy (such as PWM signal generation and over-protection triggering). If any parameter sampling is abnormal, the control parameters calculated by the controller (such as duty cycle and protection threshold) will inevitably be distorted. Even if the controller CPU is operating normally, it will lead to power unit failure (such as overvoltage burnout or overcurrent tripping). Therefore, full-coverage verification of these three types of parameters is necessary. The use of a veto system, rather than multi-parameter fault tolerance, is essentially based on the safety priority principle of power electronic equipment: for example, abnormal temperature sampling may cause over-temperature protection failure, and even if voltage / current sampling is normal, components may still be damaged due to overheating; abnormal current sampling may cause uncontrolled output current, triggering grid impact. Therefore, if a single analog quantity sampling is abnormal, the controller must be deemed invalid to prevent it from participating in control or switching. The reference values ​​for the three types of analog quantities all come from the native data of the power loop system, completely independent of the controller's own sampling channel. This completely avoids interference from controller sampling deviations or faults, ensuring the objectivity of anomaly marking.

[0095] S62, determine the current main loop controller Is it an abnormal controller? If yes, proceed to step S63; otherwise, directly determine that the control system is not faulty. In a redundant architecture, the main loop controller is the only core that executes real-time control commands (such as sending switching commands to the power loop and generating PWM control signals), and its state directly determines the stability of the current system operation. If the main loop controller samples normally (is not marked as abnormal), it means that the calculation basis of the current control command (voltage, current, and temperature data) is reliable. Even if all hot standby controllers are abnormal, it only indicates that the control system is in normal control without redundancy, and the system can be judged as abnormal rather than faulty.

[0096] S63, Determine the current state If all hot standby controllers are faulty, the system is considered faulty; otherwise, the control system is considered normal. When the main loop controller is faulty (marked as invalid), the system's continued operation depends entirely on the availability of the hot standby controllers. If at least one valid hot standby controller (not marked as faulty) exists, it can be upgraded to the main loop via the nearest switch in step S7 to maintain system control. If all hot standby controllers are faulty, the system will lose its backup control nodes, unable to maintain current control or switch over, and can only be considered a system fault to avoid power unit runaway due to lack of controller takeover. Using main loop fault + full hot standby fault as the sole triggering condition for system fault, rather than determining fault solely based on main loop fault, is essentially maximizing the fault tolerance of the redundant architecture. For example, if the main loop is faulty but one hot standby controller is normal, the system can recover control through switching, which is not an unrecoverable fault. Only when all control nodes (main loop + hot standby) are invalid is it a true system fault, requiring the system to enter a fault state (such as shutdown protection or alarm prompts).

[0097] Example 7

[0098] This embodiment discloses a redundant communication control method for a power unit. As a preferred embodiment of the present invention, based on embodiment 6, in step S7, the number of hot standby controllers is determined again. and main loop controller The method is as follows:

[0099] Determine the current value based on the reference baseline. Are there any faulty controllers among the hot standby controllers? If so, determine the number of faulty controllers. And from the current Remove faulty controllers from each hot standby controller, and retain the following number of hot standby controllers: If not, retain the original. There is one hot standby controller. The reference benchmark value is an objective standard calculated based on the native data of the power loop system in step S6, and is not affected by the controller's sampling deviation. By comparing the sampled value of the hot standby controller with the reference benchmark value, the sampling channel fault of the hot standby controller (such as sensor damage or signal interference) can be accurately identified. The core function of the hot standby controller is to seamlessly switch over in the event of a main loop fault. If the hot standby itself has sampling abnormalities, the switching will lead to incorrect calculation of control parameters (such as generating incorrect PWM signals), which may cause system failure. Therefore, abnormal hot standby controllers need to be eliminated in advance to ensure that the remaining hot standby controllers all meet the conditions of normal sampling and can take over control at any time.

[0100] Determine the current main loop controller based on the reference baseline value. Is it an abnormal controller? If not, maintain the current main loop controller. Corresponding to the loop operation state Proceed directly to step S8; if so, proceed from the reserved... Of the hot standby controllers, the nearest primary loop controller will be reassigned. And switch to the corresponding loop operation state of the main loop controller. By the main loop controller Takeover and control To determine the nearest index number interval, the number of hot standby controllers is set. Next, proceed to step S8. The main loop controller is the core of the current control commands (such as sending switching signals and generating PWM signals), and its state directly determines the stability of the system operation. Therefore, the main loop sampling state needs to be re-verified using a reference value. If the main loop sampling is abnormal (such as voltage sampling deviation exceeding the limit), even if its heartbeat signal is normal, it will output incorrect control commands and must be replaced immediately. The design of the main loop is re-determined based on hardware and communication efficiency considerations: controllers with similar index numbers are usually closer in physical layout (such as backplane slot position) and / or communication link (such as the trace distance with the communication expansion module), resulting in faster data synchronization and lower latency during switching, which can minimize control interruption time (within milliseconds) and meet the requirements of seamless control of power electronic equipment. The new main loop controller is selected from the effective hot standby pool, which means that the original hot standby quantity is reduced by 1. This update is to provide an accurate basis for the hot standby quantity verification in the subsequent step S8, avoiding the situation where there are still hot standby but no usable resources.

[0101] Example 8

[0102] This embodiment discloses a redundant communication control method for a power unit. As a preferred embodiment of the present invention, based on embodiment 6 or 7, the method for determining the voltage sampling state in step S61 is as follows:

[0103] Consider a power loop system (such as AC / AC, DC / AC) with three phase output voltages. In a given phase, the bus voltage and duty cycle of a power unit at a given moment can be used to calculate the output voltage of that single power unit at that moment. By calculating the output voltages of all power units in that phase at that moment and summing them, the equivalent output phase voltage can be obtained.

[0104] Based on this, the definition is... This indicates the DC bus voltage of each power unit transmitted back by the power loop system. This indicates the modulation duty cycle of each power unit transmitted through the power loop system. This indicates the index number of each power unit in the power loop system. Power units (such as IGBT cascaded units) are the core actuators of the power circuit, and their DC bus voltage... The voltage is directly acquired by the power unit's built-in voltage sensor (such as a voltage divider resistor or a voltage Hall effect sensor), reflecting the true voltage state on the power supply side of the power unit; the duty cycle is modulated. This is a core parameter for the power unit to execute PWM control, directly determining the effective value of the unit's output voltage, and is uploaded in real time by the power loop system. The power loop system is clearly configured as a three-phase system. Design, and each phase contains There are [number] power units, therefore the total number of power units is [number]. .pass Assigning a unique index to all power units essentially establishes a mapping between discrete unit data and the three-phase topology, preventing data from becoming disconnected from physical units.

[0105] Let the index number of the R-phase power unit in the power loop system be represented as , and The S-phase power unit index number is represented as follows: , and The T-phase power unit index number is represented as follows: , and The power circuits of power electronic devices (such as photovoltaic inverters and energy storage converters) generally adopt a three-phase AC topology. Furthermore, power units of the same phase achieve voltage / power superposition through series / parallel connection. Therefore, according to Each power unit is grouped into an index, which accurately matches the physical structure of the three phases, ensuring that power unit data for the same phase are classified together. In a three-phase AC system, , , The voltage of each phase needs to be controlled independently. Therefore, the power unit indexes of different phases are clearly separated to avoid cross-phase data interference and ensure that the voltage references of each phase are calculated independently in the future.

[0106] Calculate the equivalent output voltage of each phase of the power loop system. As a voltage reference value; where The corresponding three phases of the power circuit system; R-phase equivalent output voltage S-phase equivalent output voltage T-phase equivalent output voltage When the power unit uses PWM (Pulse Width Modulation) control, its instantaneous output voltage is the DC bus voltage. With modulation duty cycle The product of the products. For power units in the same phase, their output voltages are superimposed on the topology, therefore the product of the output voltages of all power units in that phase is... Summing these values ​​yields the equivalent total output voltage for that phase. This equivalent voltage is based on the native data of the power unit. , The calculation does not go through the controller sampling stage, thus avoiding deviations caused by controller sampling channel failures (such as sensor damage or signal interference), and therefore possesses the attributes of a system-level objective benchmark.

[0107] Set the maximum permissible error threshold for the output phase voltage. , make the controller For power loop systems The output voltage sample value of the phase is expressed as If it exists Then determine the controller An anomaly. Minor deviations between the controller's sampled values ​​and the voltage reference value are normal (e.g., due to sensor accuracy errors or signal transmission line losses). Therefore, the setting... This is considered a reasonable error range. This threshold needs to be pre-calibrated based on hardware parameters (such as sensor accuracy level) to ensure that neither genuine faults are missed nor misjudgments are made due to normal deviations. When the absolute value of the deviation exceeds... If the voltage sampling channel of the controller is faulty (such as a damaged sensor causing a low sampling value, or signal line interference causing excessive fluctuations in the sampling value), it indicates an abnormal error. In this case, the controller's sampling should be determined to be abnormal.

[0108] Example 9

[0109] This embodiment discloses a redundant communication control method for a power unit. As a preferred embodiment of the present invention, based on embodiments 6, 7, or 8, the method for determining the current sampling state in step S61 is as follows:

[0110] In a power circuit system, the power units are connected in series, and theoretically, the output current of each power unit is equal to the output phase current.

[0111] Based on this, the definition is... This represents the DC bus current returned by each power unit in the power loop system. This indicates the index number of each power unit in the power loop system. In a power circuit system, each power unit (such as an IGBT module) is equipped with an independent current sensor (such as a Hall sensor) to monitor the current value of its own DC bus in real time. This value directly reflects the operating current state of the power unit and is the basic raw data for system current monitoring. The power circuit system is defined as a three-phase system. set up Each power unit, through Binding the current data of all power units to a unique index essentially establishes a mapping between discrete unit data and a unified management system, preventing data confusion. This standardizes and indexes the dispersed power unit current data, ensuring accurate location of a specific power unit at a particular phase and avoiding cross-phase data contamination; the power unit's feedback... It is system native data independent of the controller, which can be used to correct controller sampling bias and avoid misjudgments caused by relying solely on the controller.

[0112] Let the index number of the R-phase power unit in the power loop system be represented as , and The S-phase power unit index number is represented as follows: , and The T-phase power unit index number is represented as follows: , and The power circuits of power electronic devices (such as inverters and converters) generally adopt a three-phase topology. And the power unit of each phase is unified as Therefore, according to Each power unit is indexed as a group, accurately corresponding to the physical structure of the three phases. When cascaded power units in the same phase are operating, their DC bus currents theoretically remain consistent (due to the characteristics of series / parallel topology). Therefore, power unit indices in the same phase are grouped together, and subsequent averaging can offset the current measurement errors of individual units. In this way, the range of power units corresponding to each phase is clearly defined, providing accurate data boundaries for subsequent calculation of the current reference value for each phase, ensuring that the three-phase current verification is performed independently. Averaging the current of power units in the same phase reduces the amount of data and reduces the impact of a single power unit failure on the overall current reference value, improving the stability of the current reference value.

[0113] Command the current main loop controller The total number of hot standby controllers is And sorted by index number from smallest to largest The controllers are sorted, and the sorting sequence number is represented as... , Among them, the first A controller for the power loop system The output current sampling value of the phase is expressed as ; This corresponds to the three phases of the power circuit system. The ordering of the controllers is to avoid calculation chaos caused by disordered data from multiple controllers; each controller needs to independently collect the three-phase current. Therefore, the controller sample value is compared with the sorting number. and phase Dual binding forms a three-dimensional data structure of controller-phase-sampled value, ensuring precise traceability of each sampled value. This ordered sorting and naming rule ensures that sampled data from all controllers are equally included in subsequent weight allocation and benchmark calculations, avoiding verification vulnerabilities caused by disordered data; clearly defining each... The corresponding controller sample values ​​are used to facilitate subsequent application of uniform weights. Calculate the sum to simplify the fusion algorithm.

[0114] To achieve better decision-making performance, the power distribution loop system and The current sampling weights of each controller; where... The current sampling weights of each controller are all The current sampling weight of the power loop system is Then there is and The controller is the core component that directly participates in control calculations. Its current sampling values ​​need to reflect load demand in real time and are more closely related to control strategies (such as PWM generation), therefore it is given higher weight. This ensures the core role of controller sampling. If relying solely on controller sampling, the system cannot identify faults when all controller sampling channels simultaneously experience deviations; therefore, incorporating the power loop system... Weights can correct collective biases in controllers through system-level data, avoiding the risk of relying on a single entity. This is to keep the fused current reference value within a reasonable physical range (consistent with the order of magnitude of the actual current value), avoiding distortion of the current reference value due to weighting. In this way, the real-time performance of the controller sampling and its control correlation are emphasized, while system data provides a fallback check, improving the reference value's anti-interference capability and reliability; a clear... and Ensure that multi-source data can be merged at a fixed ratio to avoid instability of the baseline value caused by human adjustment.

[0115] Calculate the reference value of instantaneous current in each phase of the power loop system. As a current reference; where, the instantaneous current reference value of phase R. S-phase instantaneous current reference value T-phase instantaneous current reference value Therefore, the current reference value integrates real-time sampling from multiple controllers and system-level power unit data, making it closer to the true current value than data from a single controller or a single power unit. This provides a reliable reference standard for subsequent judgment of controller sampling anomalies. The reference value is calculated using a clear formula, avoiding subjective judgment and ensuring a unified sampling verification standard for different controllers.

[0116] Set the maximum permissible error threshold for the output phase current. , make the controller For power loop systems The output current sampling value of the phase is expressed as If it exists Then determine the controller An anomaly. In power electronic systems, sampled values ​​are inevitably subject to slight deviations due to factors such as sensor accuracy and signal transmission interference. This is a reasonable upper limit of error set based on hardware characteristics (such as sensor accuracy level) to avoid misjudging faults due to normal deviations. When the controller... The sampled value and the current reference value The absolute value of the difference exceeds If the sampling channel of the controller is faulty (e.g., damaged sensor, loose signal line, excessive signal interference), it indicates that the sampled value deviates significantly from the true value. This allows for direct identification of a specific phase sampling anomaly in a controller, rather than a general assessment of system current anomaly, providing specific fault information for redundancy switching. Timely identification of controllers with sampling anomalies prevents erroneous sampled data from being used in control calculations, ensuring system control accuracy and safety.

[0117] Example 10

[0118] This embodiment discloses a redundant communication control method for a power unit. As a preferred embodiment of the present invention, based on embodiments 6, 7, 8, or 9, the method for determining the temperature sampling status in step S61 is as follows:

[0119] make Indicating a power loop system The index number of each temperature sampling point Temperature sampling points The number of adjacent power units is Then use This indicates the power unit index number. In a power circuit system, temperature sampling points are not randomly placed, but rather based on the physical arrangement of power units (such as the mounting positions of core heat-generating components like IGBT modules and capacitors), preferentially placed in areas where the thermal impact of multiple power units overlaps. For example, if two power units share a single heatsink, a temperature sampling point is placed in the middle of the heatsink. ,at this time This corresponds to two power units. By adopting... and The indexed management establishes a one-to-many mapping relationship, essentially binding discrete temperature sampling data with specific power unit heat sources, preventing the sampling data from becoming disconnected from physical location. In case of subsequent temperature anomalies, [the system can be used to address these issues]. and It can quickly pinpoint which sampling area or which power units have a temperature problem, rather than just knowing that the system temperature is abnormal.

[0120] Because each power unit has an independent temperature sampling point, i.e., a built-in temperature sensor (such as an NTC thermistor or thermocouple), it directly monitors its own core temperature. During the power conversion process of the power loop system, the power unit will heat up due to device heating, and its temperature rise has a certain linear relationship with the system's operating power. Therefore, for each individual temperature sampling point... Obtain their corresponding The internal temperature monitoring values ​​and temperature rise values ​​of each adjacent power unit, where the power unit The internal temperature monitoring value and temperature rise value are respectively expressed as: and .

[0121] Temperature rise Through power unit The output power-temperature rise curve is obtained as follows: The heat generation of the power unit originates from the conduction losses and switching losses of power devices (such as IGBTs and diodes), and the total power loss is... With output power Switching frequency Positive correlation, combined with the thermal resistance of the power unit The expression for thermal resistance and temperature rise is: . and This is the loss coefficient; The ratio of on-state loss to power, The proportionality coefficient between switching losses and power × frequency is determined by device characteristics and circuit topology. If the switching frequency during system operation... Keep it constant, , , and Combined into a comprehensive coefficient At this point, the temperature rise and power have a linear relationship: ; It is only related to the inherent characteristics of the power unit and the fixed switching frequency. Under normal voltage and current sampling conditions, the output power of the power unit can be calculated. This results in a temperature rise. Different measurements were taken beforehand through experiments. , Below Plot the output power-temperature rise curve; during actual operation, only the real-time temperature rise of the power unit needs to be obtained. (Calculated from voltage / current sampling data), which can then be found from the curve. .

[0122] For each individual temperature sampling point Calculate the equivalent temperature value As a temperature reference standard; among which Among them, the same temperature sampling point corresponding Each power unit, - All reflect the temperature sampling point The ambient temperature (because the temperature rise from losses in each unit is removed). Averaging these values ​​offsets random errors in individual power unit sensors (such as sensor drift and signal interference), resulting in a more stable temperature reference value. Power units around the same sampling point are in similar thermal environments, and their ambient temperatures are theoretically consistent; therefore, the average temperature calculated from multi-unit data is... It can accurately reflect the actual temperature of the area, rather than the localized abnormal temperature of a single unit.

[0123] Set the maximum permissible error threshold for ambient temperature. , make the controller At temperature sampling points The temperature sample value at that location is expressed as If it exists Then determine the controller An anomaly. Minor deviations between the controller's temperature sampling values ​​and the temperature reference are normal (e.g., temperature drift in the sampling circuit, signal transmission delay). Therefore, the settings... This is considered a reasonable error range; if the deviation exceeds this threshold, it indicates a fault in the sampling channel (such as sensor damage or signal interference), rather than a normal error. By verifying each sampling point and each controller individually, the system can accurately pinpoint which sampling channel of which controller is malfunctioning, rather than simply assuming the entire controller is faulty.

Claims

1. A redundant communication control method for a power unit, characterized in that: A redundant communication control system is used to implement redundant communication control of power units; the redundant communication control system comprises a communication expansion module, a power loop system and a controller; in the power loop system, three phases are correspondingly provided with power units, indicates the number of power unit cascaded structures of a single phase in the power loop system; The number of controllers Each controller serves as a backup for the others, and each individual controller has an independent analog signal sampling channel, control calculation module, and digital output channel. It is connected to the power loop system through the analog signal sampling channel and digital output channel, and has the functions of independently completing analog signal sampling, control parameter calculation, PWM control signal generation, and sending digital control commands to the power loop system in the main loop state. The communication expansion module is bidirectionally connected to the power loop system and each controller, and is used to determine the system fault state based on the analog signals of the power loop system and the heartbeat signals of the controllers, and to determine the system fault state and, in the system non-fault state, to... The main loop controller is determined among the controllers, and under non-fault conditions of the system, the PWM control signal of the main loop controller is converted and sent to the power loop system to implement PWM control on each power unit in the power loop system; The redundant communication control includes the following steps: S1 defines the initial state of the system. System fault status and the loop operation status of each controller ;in, Indicates the controller's index number, i.e. Indicates that the index number is The controller corresponds to the loop operating state. ; S2, The control system is powered on and enters the initial state. The communication expansion module listens for the heartbeat signals of all controllers within a set time period in order to... One main loop controller has been initially identified from among the controllers. and One hot standby controller, ;in This indicates the index number of the main loop controller, and ; S3, the control system switches to the current main loop controller. Corresponding to the loop operation state Main loop controller Send a switching control command to the power loop system to bring the power loop system into its initial operating state; S4, Main Loop Controller Through the communication expansion module, the power loop system and After each hot standby controller sends periodic parameters and a sampling start signal, the power loop system and the main loop controller... and Each hot standby controller synchronously performs analog counting and sampling of the power loop system according to the period parameters, and uploads the sampled data to the communication expansion module; S5, main loop controller and Each hot standby controller calculates its own control parameters based on its analog signal counting and sampling results to generate PWM control signals. S6, the communication expansion module obtains the analog reference value based on the sampled data uploaded by the power loop system, and combines the reference value with the main loop controller. and The system uses sampled data uploaded by each hot standby controller to determine if a fault has occurred in the control system; if so, the control system switches to a system fault state. If not, proceed to step S7; S7, based on the abnormal status determination of the controller's analog signal sampling, to further clarify the number of hot standby controllers. and main loop controller And through the communication expansion module, the main loop controller The corresponding PWM control signal is converted and sent to the power loop system to complete one control cycle; S8, determine if the number of hot standby controllers is sufficient. If not, the system is determined to be abnormal and a system maintenance prompt is given before returning to step S4; if yes, the system returns directly to step S4; thus forming a closed-loop control cycle.

2. The redundant communication control method for a power unit as described in claim 1, characterized in that: The communication expansion module of the redundant communication control system includes a backplane, on which a core board, a power board, and an optical signal adapter board are mounted. The core board is controlled by an external SDRAM-based FPGA module and has reserved Ethernet optical and Ethernet electrical ports for high-speed communication with the controller. The number of optical signal adapter boards... All optical signal adapter boards are routed through the backplane and connected to the FPGA module via the onboard buffer I on the core board. Each individual optical signal adapter board is equipped with at least one optical transceiver with onboard buffer II for connecting to the power loop system. The power supply board is routed through the backplane and connected to the core board and each optical signal adapter board.

3. The redundant communication control method for a power unit as described in claim 2, characterized in that: On the backplane of the communication expansion module of the redundant communication control system, there are terminal block units based on the inter-board wiring; the terminal block units include onboard connector JⅠ, onboard connector JⅡ and onboard connector JⅢ; The number of onboard connectors JⅠ The core board is provided with board-to-board connectors CNⅠ that are plugged into each other with the onboard connector JⅠ. The board-to-board connectors CNⅠ are connected to the FPGA module through corresponding onboard buffers I. The number of onboard connectors JII Each optical signal adapter board is equipped with a board-to-board connector CNⅡ; on each individual optical signal adapter board, all optical transceivers are connected to the board-to-board connector CNⅡ through a one-to-one corresponding onboard buffer Ⅱ; all optical signal adapter boards are connected to the onboard connector JⅡ through the board-to-board connector CNⅡ, and the same or different onboard connector JⅠ are connected through the corresponding onboard connector JⅡ. The power board is equipped with an isolated DC-DC converter and filtering system; The input end of the isolated DC-DC converter and filter system is equipped with a power interface for connecting an external 24V power supply; the output end of the isolated DC-DC converter and filter system is equipped with a board-to-board connector CNⅢ for plugging into the onboard connector JⅢ, and outputs 12V power to the power terminals of each onboard connector JⅠ and onboard connector JⅡ.

4. The redundant communication control method for a power unit as described in claim 1, characterized in that, In step S2, a main loop controller is initially determined. and The method for a hot standby controller is as follows: S21, the communication extension module determines whether it has received a heartbeat signal from at least one controller within a set time; if yes, proceed to step S22; if no, the control system switches from system to system fault state. ; S22, the controller that first receives the heartbeat signal from the communication expansion module is designated as the initial main loop controller. ; S23, for the main loop controller Other For each controller, the communication expansion module determines whether it receives its corresponding heartbeat signal within a set time. If not, the corresponding controller is determined to be abnormal, and the abnormal controller is prevented from participating in the subsequent control process. If it is, the corresponding controller is determined to be normal. S24, Count the number of normal controllers and make the The normal controller is the initial hot standby controller.

5. The redundant communication control method for a power unit as described in claim 1, characterized in that, The analog quantities include voltage, current, and temperature. Therefore, in step S6, the method for determining whether the control system has malfunctioned is as follows: S61, sequentially traverse the current main loop controllers. and Each hot standby controller, for each individual controller The voltage, current, and temperature sampling status are determined by comparing the sampled values ​​with a reference value. If any analog quantity sampling status is abnormal, the corresponding controller is flagged. abnormal; ; S62, determine the current main loop controller Is it an abnormal controller? If yes, proceed to step S63; if no, directly determine that the control system has not malfunctioned. S63, Determine the current state If all the hot standby controllers are faulty, then the system is determined to be faulty; otherwise, the control system is determined not to be faulty.

6. The redundant communication control method for a power unit as described in claim 5, characterized in that, In step S7, the number of hot standby controllers is determined again. and main loop controller The method is as follows: Determine the current based on the reference baseline value. Are there any faulty controllers among the hot standby controllers? If so, determine the number of faulty controllers. And from the current Remove faulty controllers from each hot standby controller, and retain the following number of hot standby controllers: If not, retain the original. One hot standby controller; Determine the current main loop controller based on the reference baseline value. Is it an abnormal controller? If not, maintain the current main loop controller. Corresponding to the loop operation state Proceed directly to step S8; if so, proceed from the reserved... Of the hot standby controllers, the nearest primary loop controller will be reassigned. And switch to the corresponding loop operation state of the main loop controller. , To determine the nearest index number interval, the number of hot standby controllers is set. Then, proceed to step S8.

7. The redundant communication control method for a power unit as described in claim 5, characterized in that, In step S61, the method for determining the voltage sampling state is as follows: definition This indicates the DC bus voltage of each power unit transmitted back by the power loop system. This indicates the modulation duty cycle of each power unit transmitted through the power loop system. This indicates the index number of each power unit in the power loop system. ; Let the index number of the R-phase power unit in the power loop system be represented as , and The S-phase power unit index number is represented as follows: , and ; The T-phase power unit index number is represented as follows: , and ; Calculate the equivalent output voltage of each phase of the power loop system. As a voltage reference value; where The corresponding three phases of the power circuit system; R-phase equivalent output voltage S-phase equivalent output voltage T-phase equivalent output voltage ; Set the maximum permissible error threshold for the output phase voltage. , make the controller For power loop systems The output voltage sample value of the phase is expressed as If it exists Then determine the controller abnormal.

8. The redundant communication control method for a power unit as described in claim 5, characterized in that, In step S61, the method for determining the current sampling state is as follows: definition This represents the DC bus current returned by each power unit in the power loop system. This indicates the index number of each power unit in the power loop system. ; Let the index number of the R-phase power unit in the power loop system be represented as , and The S-phase power unit index number is represented as follows: , and The T-phase power unit index number is represented as follows: , and ; Command the current main loop controller The total number of hot standby controllers is And sorted by index number from smallest to largest. The controllers are sorted, and the sorting sequence number is represented as... , Among them, the first A controller for the power loop system The output current sampling value of the phase is expressed as ; This corresponds to the three phases of the power circuit system; Power distribution loop system and The current sampling weights of each controller; where... The current sampling weights of each controller are all The current sampling weight of the power loop system is Then there is and ; Calculate the reference value of instantaneous current in each phase of the power loop system. As a current reference; where, the instantaneous current reference value of phase R. S-phase instantaneous current reference value T-phase instantaneous current reference value ; Set the maximum permissible error threshold for the output phase current. , make the controller For power loop systems The output current sampling value of the phase is expressed as If it exists Then determine the controller abnormal.

9. The redundant communication control method for a power unit as described in claim 5, characterized in that, In step S61, the method for determining the temperature sampling status is as follows: make Indicating a power loop system The index number of each temperature sampling point Temperature sampling points The number of adjacent power units is Then use This indicates the power unit index number. ; For each individual temperature sampling point Obtain their corresponding The internal temperature monitoring values ​​and temperature rise values ​​of each adjacent power unit, where the power unit The internal temperature monitoring value and temperature rise value are respectively expressed as: and Temperature rise Through power unit The output power-temperature rise curve is obtained; For each individual temperature sampling point Calculate the equivalent temperature value As a temperature reference standard; among which ; Set the maximum permissible error threshold for ambient temperature , make the controller At temperature sampling points The temperature sample value at that location is expressed as If it exists Then determine the controller abnormal.

Citation Information

Patent Citations

  • Implementation method of dual-computer hot standby system based on FPGA (Field Programmable Gate Array) fault detection

    CN114610551A

  • Power control device and switching method of power control unit

    CN115589015A