Fault self-checking and safety control method and device for medical power supply and storage medium
The medical power supply control method, which employs multi-logic online fault self-checking and dynamic hardware reconfiguration, solves the problem of the one-size-fits-all approach in fault handling of traditional medical power supplies. It implements a fault urgency differentiation strategy, thereby improving the safety and availability of the system.
Patent Information
- Application Number
- CN202511982848.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-26
- Publication Date
- 2026-05-15
AI Technical Summary
Traditional medical power supplies take uniform protective actions when a fault is detected, which can lead to the interruption of medical equipment due to non-emergency faults. They also lack adaptive recovery capabilities. Existing backup power solutions are costly and have fault points in their switching logic.
Through multi-logic online fault self-checking, strategies are differentiated based on the urgency of the fault to make safety logic decisions, and flexible safety control is achieved through dynamic hardware reconfiguration, including changes in the electrical connection topology of reconfigurable power units.
It enables flexible and automatic implementation of different safety strategies in the event of a failure, balancing safety and availability, improving the system's adaptive recovery capability, and avoiding equipment interruption caused by non-emergency failures.
Smart Images

Figure CN122052248A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of medical power supply technology, and in particular relates to a method, device and storage medium for fault self-checking and safety control of medical power supply. Background Technology
[0002] Medical devices have extremely high requirements for the reliability and safety of their power supply. Traditional medical power supply safety protection mechanisms generally have limitations. When a fault is detected (such as overvoltage or overcurrent), a uniform protective action is usually taken, such as immediately cutting off the output to ensure safety. While this "one-size-fits-all" approach is simple and reliable, it has significant drawbacks. For some non-emergency faults that do not affect basic safety or are tolerable (such as single sensor drift or auxiliary circuit abnormalities), directly shutting down the device will interrupt the medical treatment process, leading to unnecessary clinical risks.
[0003] Furthermore, most existing power supplies use a fixed topology, meaning that the entire power supply fails once a critical power component is damaged, lacking the ability to maintain some functionality by adjusting its structure after a failure. Although backup power supply solutions exist, they are costly, bulky, and their switching logic may also have points of failure.
[0004] Therefore, there is an urgent need for a medical power supply control scheme that can assess the severity of a fault online and flexibly and automatically implement different safety strategies to achieve safe operation. Summary of the Invention
[0005] In view of this, embodiments of the present invention provide a method, device and storage medium for fault self-verification and safety control of medical power supply. Through online fault self-verification with multiple logics and by distinguishing at least two handling strategies according to the urgency of the fault, different safety strategies can be implemented flexibly and automatically. Furthermore, by dynamically reconfiguring the reconfigurable power unit in hardware, the fundamental problems of difficulty in balancing safety and availability and lack of adaptive recovery capability of the system are solved.
[0006] A first aspect of this invention provides a method for fault self-checking and safety control of a medical power supply, the method comprising: Perform online fault self-checking of the power supply system using multiple logic logics; Based on the self-verification results, a security logic decision is made, which distinguishes at least two different handling strategies according to the urgency of the fault. According to the aforementioned handling strategy, the reconfigurable power unit in the medical power supply is dynamically reconfigured in hardware to change its electrical connection topology and achieve a safe operating state corresponding to the handling strategy.
[0007] In one embodiment, the online fault self-checking of the power system using multiple logic logics includes: Based on the cyber-physical fusion model of the power system and the current control commands, the model estimates of key electrical quantities are calculated in real time. The estimated values of the cyber-physical fusion model are compared with the measurements from at least two independent physical channels; If the estimated value of the cyber-physical fusion model deviates from the measured value of all physical channels beyond the preset tolerance, it is diagnosed that there is a component fault in the modeled power circuit, and the first type of diagnosis result is output. If the estimated value of the cyber-physical fusion model deviates from the measurement value of a single physical channel by more than the preset tolerance, but is consistent with the measurement value of other physical channels, then the physical channel is diagnosed as a faulty channel, and a second type of diagnostic result is output.
[0008] In one embodiment, the online fault self-checking of the power system with multiple logic logics further includes: After a drive command is issued to the power switching device, the actual switching response waveform of the power switching device is acquired through a diagnostic circuit that is electrically isolated from its main drive circuit. The timing and morphological matching degree of the actual switch response waveform and the expected standard waveform generated based on the driving command and the cyber-physical fusion model are analyzed. If the matching degree is lower than the preset threshold, a functional fault is diagnosed in the power switch device or its corresponding drive circuit, and a third type of diagnostic result is output.
[0009] In one embodiment, the step of performing security logic decision based on the self-verification result includes: The self-verification results are mapped to a preset urgency level; Based on the preset urgency level, a security logic decision is made.
[0010] In one embodiment, the preset urgency levels include Level 1 emergency faults, Level 2 emergency faults, and Level 3 non-emergency faults; the security logic decision distinguishes at least two different handling strategies based on the urgency of the fault, including: For a Level 1 emergency fault, a microsecond-level Level 1 decision is triggered by independent hardware logic, which shuts down the main power or isolates the faulty branch. For a Level 2 emergency fault, a millisecond-level Level 2 decision is triggered by the safety processor, executing a combined strategy including output power derating, switching to standby control mode, and initiating the dynamic hardware reconfiguration. For Level 3 non-emergency faults, the Level 2 decision is triggered, local alarms and operation logs are recorded, and preventative maintenance prompts are issued.
[0011] In one embodiment, the preset tolerance is a dynamic tolerance, the value of which is adaptively adjusted based on the current operating point of the key electrical quantity, historical measurement noise statistics, and component aging coefficient.
[0012] In one embodiment, the step of confirming a component fault in the modeled power loop further includes: In the cyber-physical fusion model, the deviations of the key electrical quantities are simulated sequentially when a single component fails. The deviation between the actual measured value and the model estimate is compared with the matching degree of each simulation deviation; The hypothetical failed component corresponding to the simulation with the highest matching degree is determined to be the faulty component.
[0013] A second aspect of this application provides a fault self-checking and safety control device for a medical power supply, comprising: The verification module is used to perform online fault self-verification of multiple logics in the power supply system; The adjudication module is used to make security logic adjudications based on the self-verification results. The security logic adjudications distinguish at least two different handling strategies according to the urgency of the fault. The reconfiguration module is used to dynamically reconfigure the reconfigurable power units in the medical power supply according to the treatment strategy, so as to change their electrical connection topology and achieve a safe operating state corresponding to the treatment strategy.
[0014] In one embodiment, the verification module includes: The computing unit is used to calculate the model estimates of key electrical quantities in real time based on the cyber-physical fusion model of the power system and the current control commands. The comparison unit is used to compare the estimated value of the cyber-physical fusion model with the measurement value from at least two independent physical channels. The first diagnostic unit is used to diagnose a component fault in the modeled power circuit if the deviation between the estimated value of the cyber-physical fusion model and the measured value of all physical channels exceeds the preset tolerance, and outputs a first type of diagnostic result. The second diagnostic unit is used to diagnose a physical channel as a faulty channel if the estimated value of the cyber-physical fusion model deviates from the measurement value of a single physical channel by more than a preset tolerance, but is consistent with the measurement values of other physical channels, and outputs a second type of diagnostic result.
[0015] In one embodiment, the verification module further includes: The acquisition unit is used to acquire the actual switching response waveform of the power switching device through a diagnostic circuit that is electrically isolated from its main drive circuit after a drive command is issued to the power switching device; The analysis unit is used to perform timing and morphological matching analysis on the actual switch response waveform and the expected standard waveform generated based on the drive command and the cyber-physical fusion model. The third diagnostic unit is used to diagnose a functional fault in the power switch device or its corresponding drive circuit if the matching degree is lower than a preset threshold, and outputs a third type of diagnostic result.
[0016] The adjudication module includes: The mapping unit is used to map the self-verification result to a preset urgency level. The adjudication unit is used to make security logic decisions based on the preset urgency level.
[0017] In one embodiment, the preset urgency levels include Level 1 emergency faults, Level 2 emergency faults, and Level 3 non-emergency faults; the adjudication module is specifically used for: For a Level 1 emergency fault, a microsecond-level Level 1 decision is triggered by independent hardware logic, which shuts down the main power or isolates the faulty branch. For a Level 2 emergency fault, a millisecond-level Level 2 decision is triggered by the safety processor, executing a combined strategy including output power derating, switching to standby control mode, and initiating the dynamic hardware reconfiguration. For Level 3 non-emergency faults, the Level 2 decision is triggered, local alarms and operation logs are recorded, and preventative maintenance prompts are issued.
[0018] In one embodiment, the preset tolerance is a dynamic tolerance, the value of which is adaptively adjusted based on the current operating point of the key electrical quantity, historical measurement noise statistics, and component aging coefficient.
[0019] In one embodiment, the device further includes: The simulation module is used to sequentially simulate the deviation of the key electrical quantities when a single component fails in the cyber-physical fusion model. The matching module is used to calculate the degree of matching between the deviation of the actual measured value and the model estimate and each simulation deviation. The determination module is used to determine the hypothetical failed component corresponding to the simulation with the highest matching degree as the faulty component.
[0020] A third aspect of this application provides a fault self-checking and safety control device for a medical power supply, comprising: a processor, a memory, and a computer program stored in the memory and executable on the processor; the processor executes the computer program to implement the method described in the first aspect above.
[0021] A fourth aspect of this application provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the method described in the first aspect above.
[0022] The beneficial effects of the embodiments of this application are as follows: The embodiments of this application provide a method for fault self-checking and safety control of medical power supply, the method including: performing online fault self-checking of the power supply system with multiple logics; Based on the self-verification results, a safety logic decision is made, distinguishing at least two different handling strategies according to the urgency of the fault. According to the handling strategy, the reconfigurable power unit in the medical power supply undergoes dynamic hardware reconfiguration to change its electrical connection topology, achieving a safe operating state corresponding to the handling strategy. Through multi-logic online fault self-verification and the distinction between at least two handling strategies based on fault urgency, different safety strategies can be implemented flexibly and automatically. Furthermore, by dynamically reconfiguring the reconfigurable power unit, the fundamental problems of balancing safety and availability, and the lack of adaptive recovery capabilities in the system, are solved. Attached Figure Description
[0023] To more clearly illustrate the technical solutions in the embodiments of the present invention, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0024] Figure 1 A flowchart illustrating a method for fault self-checking and safety control of a medical power supply provided in an embodiment of this application; Figure 2 for Figure 1 A schematic diagram illustrating the specific implementation process of S110 in China; Figure 3 A schematic diagram of a medical power supply fault self-checking and safety control device provided in an embodiment of this application; Figure 4 This is a schematic diagram of a medical power supply fault self-checking and safety control device provided in an embodiment of this application. Detailed Implementation
[0025] The embodiments of the technical solution of this application will now be described in detail with reference to the accompanying drawings. These embodiments are only used to more clearly illustrate the technical solution of this application and are therefore merely examples, and should not be used to limit the scope of protection of this application.
[0026] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application pertains; the terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the application; the terms “comprising” and “having”, and any variations thereof, in the specification, claims, and foregoing description of the drawings are intended to cover non-exclusive inclusion.
[0027] In the description of the embodiments of this application, technical terms such as "first" and "second" are used only to distinguish different objects and should not be construed as indicating or implying relative importance or implicitly specifying the number, specific order, or primary and secondary relationship of the indicated technical features. In the description of the embodiments of this application, "multiple" means two or more, unless otherwise explicitly defined.
[0028] In this document, the term "embodiment" means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of this application. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.
[0029] In the description of the embodiments in this application, the term "and / or" is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, and B existing alone. Additionally, the character " / " in this document generally indicates that the preceding and following related objects have an "or" relationship.
[0030] In the description of the embodiments of this application, the term "multiple frames" refers to two or more (including two).
[0031] In the description of the embodiments of this application, the technical terms "center," "longitudinal," "lateral," "length," "width," "thickness," "upper," "lower," "front," "rear," "left," "right," "vertical," "horizontal," "top," "bottom," "inner," "outer," "clockwise," "counterclockwise," "axial," "radial," and "circumferential" indicate the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings. They are only for the convenience of describing the embodiments of this application and simplifying the description, and are not intended to indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, they should not be construed as limitations on the embodiments of this application.
[0032] Please see Figure 1 , Figure 1This is a flowchart illustrating a method for self-checking and safety control of a medical power supply fault according to an embodiment of this application. This method is implemented by a device for self-checking and safety control of a medical power supply fault. This device includes, but is not limited to, a terminal or a server.
[0033] Depend on Figure 1 As can be seen, the fault self-checking and safety control method for a medical power supply provided in this application includes the following steps S110 to S130. Details are as follows: S110: Performs online fault self-checking for multiple logics in the power supply system.
[0034] This step aims to diagnose the health status of the power system in real time and in parallel from multiple logical levels without interrupting power supply, and to output structured diagnostic conclusions.
[0035] For example, please refer to Figure 2 , Figure 2 for Figure 1 A schematic diagram illustrating the specific implementation process of S110. (By...) Figure 2 It can be seen that S110 includes S1101 to S1104. Details are as follows: S1101: Based on the cyber-physical fusion model of the power system and the current control commands, calculate the model estimates of key electrical quantities in real time.
[0036] The cyber-physical system model for a power supply system is a high-order parameterized mathematical model established during the power supply system design phase, based on the specific topology of the reconfigurable power unit (such as Buck, Boost, LLC, etc.) and grounded in Kirchhoff's laws, switching device characteristics, parasitic parameters, etc. This model is implemented and operated in a digital controller (such as a DSP or FPGA) in the form of discretized state equations or transfer functions. To ensure timely diagnostics, the model's computational complexity and time consumption are optimized to ensure that all state updates and output calculations can be completed within one control cycle (e.g., 10μs).
[0037] In each control cycle, the model receives current control commands from the main controller (such as PWM duty cycle D, phase shift angle φ, and switching frequency fsw) and system inputs from sensors (such as input voltage Vin). The model's internal states (such as inductor current and capacitor voltage) are iteratively updated based on the previous cycle's state and the current input, ultimately calculating in real-time model estimates of key electrical quantities used for fault diagnosis. These key electrical quantities include, but are not limited to, output voltage and current, peak current of power switching devices, and topology-related critical node voltages. These estimates are theoretically expected values calculated based on currently known accurate model parameters and control commands. Their core function is to serve as a diagnostic benchmark, used to detect whether the actual system behavior significantly deviates from expectations.
[0038] S1102: Compare the cyber-physical fusion model estimates with measurements from at least two independent physical channels.
[0039] To achieve reliable cross-validation, two or more physically independent measurement channels are set up for the same critical electrical quantity (e.g., output voltage). For example, channel A may be measured using a high-precision differential operational amplifier; channel B may be measured using an isolated voltage sensor. The power supply, sampling, and analog-to-digital conversion (ADC) circuits of the two channels are physically and electrically isolated. The core design purpose is to ensure that a local hardware failure in one channel will not affect the other, thus laying the foundation for accurately distinguishing between power loop faults and sensor channel faults.
[0040] In practical implementation, during each control cycle, it is necessary to ensure that the model estimate, the measurement value of channel A, and the measurement value of channel B are strictly synchronized in time, all reflecting the system state at the same sampling moment. Subsequently, the synchronously acquired model estimate (denoted as M) is compared with the measurement values of channel A (denoted as A) and channel B (denoted as B) respectively, and the absolute deviation ΔA = |M - A| and ΔB = |M - B| (or the relative deviation is used) are calculated, thereby generating a set of consistency analysis data for subsequent fault diagnosis.
[0041] S1103: If the deviation between the estimated value of the cyber-physical fusion model and the measured value of all physical channels exceeds the preset tolerance, it is diagnosed that there is a component fault in the modeled power circuit, and the first type of diagnosis result is output.
[0042] Specifically, the absolute values (ΔA, ΔB, ...) of the deviations between the model estimates and the measurements of each physical channel are calculated. If the deviations of the measurements of all independent channels from the model estimates exceed a preset dynamic tolerance band, it indicates that the theoretical model has systematically deviated from all actual observation channels. Therefore, it can be inferred that the root cause of the problem is not a specific "observation tool" (sensor channel), but rather the "observed object" itself, i.e., a component failure in the modeled main power circuit.
[0043] Furthermore, the preset tolerance is a dynamic tolerance, whose value is adaptively adjusted according to the system's operating status. For example, the dynamic tolerance Tdynamic can be calculated based on the base tolerance Tbase, the current load rate Iload / Imax, the measurement noise statistics σnoise, and the component aging factor AgeFactor (e.g., Tdynamic = Tbase). (1 + k1 Iload / Imax) + k2 σnoise + k3 AgeFactor) is used to ensure the accuracy and robustness of diagnosis under different operating conditions. k1, k2, and k3 are adjustable coefficients.
[0044] Once a power circuit fault is diagnosed, component-level localization can be further performed. In the cyber-physical fusion model, typical faults (such as open circuit, short circuit, parameter drift) are simulated sequentially for individual key components (such as switches, inductors, and capacitors). The theoretical deviation vector (including amplitude and frequency characteristics) between the model output and the best estimate of the actual system state (such as the median of the measurements of each channel) under each "hypothetical fault" is calculated.
[0045] Subsequently, the actual monitored system deviation vectors are matched with the aforementioned theoretical deviation vector libraries. The matching degree can be calculated by determining the cosine similarity between vectors or by analyzing the energy distribution of the main frequency bands. The component corresponding to the theoretical fault scenario with the highest matching degree is identified as the most likely faulty component. For example, if the matching degree shows a simulation pattern of "increased output capacitor ESR" that closely matches the actual deviation, the fault source can be accurately located.
[0046] S1104: If the estimated value of the cyber-physical fusion model deviates from the measurement value of a single physical channel by more than the preset tolerance, but is consistent with the measurement value of other physical channels, then the physical channel is diagnosed as a faulty channel, and the second type of diagnostic result is output.
[0047] For example, within the same control cycle, the model estimate M, the channel A measurement A, and the channel B measurement B are acquired, and the deviations ΔA = |M - A| and ΔB = |M - B| are calculated. The dynamic tolerance threshold is set to T.
[0048] A specific physical channel fault is diagnosed if and only if all of the following conditions are met: ΔA>T (model is inconsistent with channel A); ΔB≤T (model is consistent with channel B); |A - B|>k T (The measurements of channel A and channel B are significantly different, where k is a coefficient greater than 1, for example, k=2) This set of conditions constitutes a rigorous logical criterion: the cyber-physical model, in conjunction with one or more physical channels (channel B), confirms the true state of the system, while the observations from another physical channel (channel A) are isolated outliers. This strongly suggests that the inconsistency does not originate from the observed system itself, but from the observation tools. Therefore, it can be diagnosed that channel A (including its sensors, signal conditioning circuits, analog-to-digital converters, etc.) is faulty, while the main power circuit is functioning normally. A second type of diagnostic result is output, which should at least include: a faulty channel identifier (e.g., "output voltage sampling channel A"), fault characteristics (e.g., "reading drift", "fixed deviation", "no signal output"), and a confidence level indication.
[0049] Furthermore, online fault self-checking of the power system with multiple logic components can also perform functional-level diagnostics on the core execution unit, the power switching device, to detect whether it correctly executes switching actions according to instructions. Specifically, this includes: after issuing a drive command to the power switching device, acquiring the actual switching response waveform of the power switching device through a diagnostic circuit electrically isolated from its main drive circuit; performing timing and morphological matching degree analysis between the actual switching response waveform and the expected standard waveform generated based on the drive command and the cyber-physical fusion model; if the matching degree is lower than a preset threshold, a functional fault is diagnosed in the power switching device or its corresponding drive circuit, and a third type of diagnostic result is output.
[0050] Each power switching device (such as a MOSFET or IGBT) to be diagnosed is configured with a dedicated diagnostic circuit independent of its main drive circuit. Taking a MOSFET as an example, a typical implementation involves connecting a milliohm-level precision sampling resistor in series with the source of the device. The differential voltage signal across this resistor is amplified by a high-speed, high common-mode rejection ratio differential amplifier powered by an independent isolated power supply and employing magnetic or optocoupler isolation technology. The amplified analog signal is then fed to a high-sampling-rate ADC channel on the main controller or a dedicated diagnostic chip. The sampling clock of this ADC channel is synchronized with the PWM drive signal to accurately capture switching transients. The power, ground, and signal paths of the entire diagnostic circuit are electrically isolated from the main power drive link, ensuring the independence and safety of the diagnostics.
[0051] In the cyber-physical fusion model, a behavioral sub-model incorporating the dynamic switching characteristics of each power switching device is established. Key parameters include: on-resistance (Rds(on)), gate charge characteristics (Qg, particularly Miller plateau charge Qgd), parasitic capacitances (Ciss, Coss, Crss), and body diode reverse recovery characteristics. During each switching cycle, based on the current drive command (PWM signal), load current (estimated by the model or measured by adjacent channels), and device junction temperature (estimated by a temperature sensor), the expected standard waveform is generated in real-time using one of the following methods: First, the expected switching time parameters (e.g., Td(on), Tr, Td(off), Tf) under the current operating condition are obtained through multidimensional interpolation from a pre-stored feature parameter mapping table based on device data and experimental calibration. Then, the current or voltage waveform is reconstructed using standard functions (e.g., exponential rise / fall). Finally, a normalized standard switching waveform template is invoked and its amplitude and time axis are scaled according to the current operating voltage and current. Using the logic edge (e.g., rising edge) of the drive instruction as the time reference point, the acquired actual switching waveform is precisely aligned in the time domain with the generated expected standard waveform. From the aligned waveform, a set of quantifiable key feature values are automatically extracted, including but not limited to: timing features such as turn-on delay time, voltage drop / current rise time, Miller plateau duration, turn-off delay time, and current drop time; and morphological features such as overshoot and oscillation amplitude during turn-on / turn-off, Miller plateau voltage level, and amplitude and duration of turn-off tail current.
[0052] Calculate the deviation between the actual waveform eigenvalues and the expected standard eigenvalues. Perform a comprehensive score on the deviations of multiple features (i=1...N), for example, using weighted root mean square error or weighted absolute error. The formula is: Match Score = 100 - Σ(wi) |Factuali-Fexpectedi| / Fexpectedi); where wi is the weight coefficient of each feature, and the sum is 1.
[0053] If the matching score is lower than the preset fault threshold (e.g., below 70 points), then a functional fault is diagnosed in the power switch device or its drive circuit.
[0054] Based on the specific characteristic exhibiting a significant deviation, the fault type can be further inferred. For example: a significant increase in turn-on delay suggests insufficient drive capability of the drive circuit or abnormal gate resistance. A missing Miller plateau or an abnormally shortened plateau suggests insufficient gate drive voltage or damage to the device gate. Violent turn-off oscillations suggest excessive parasitic inductance in the circuit or failure of the snubber circuit. An abnormally increased on-state voltage drop suggests device aging (increased Rds(on)) or poor connection. The third type of diagnostic result is output, a structured diagnostic object containing: faulty device identification (e.g., "Q1 on the bridge arm"), fault mode (e.g., "abnormal turn-on delay"), quantified deviation data (e.g., "delay time exceeds the limit by 80%)", and a recommended fault severity level (e.g., "medium degradation"). This result directly provides accurate input for subsequent safety logic decisions.
[0055] S120: Based on the self-verification results, perform a safety logic decision, which distinguishes at least two different handling strategies according to the urgency of the fault.
[0056] Based on the self-verification results and according to preset rules, the faults are mapped to different urgency levels, thereby triggering the most suitable handling strategy.
[0057] Specifically, based on the self-verification results, security logic decisions are made, including: mapping the self-verification results to a preset urgency level; and making security logic decisions based on the preset urgency level.
[0058] The preset urgency levels include Level 1 emergency faults, Level 2 emergency faults, and Level 3 non-emergency faults. The safety logic decision distinguishes at least two different handling strategies based on the urgency of the fault, including: for Level 1 emergency faults, triggering a microsecond-level Level 1 decision implemented by independent hardware logic to shut down the main power or isolate the faulty branch; for Level 2 emergency faults, triggering a millisecond-level Level 2 decision implemented by the safety processor to execute a combination of strategies including output power derating, switching to standby control mode, and initiating dynamic hardware reconfiguration; for Level 3 non-emergency faults, triggering a Level 2 decision to execute local alarm and operation log recording, and providing preventative maintenance prompts.
[0059] For example, a Level 1 emergency fault is a fatal behavior fault mapped from the third type of diagnostic results, such as "short circuit" or "switching tube shoot-through", as well as a fault located in the first type of diagnostic results that will cause the output to lose control directly, such as "severe short circuit of output filter capacitor".
[0060] Level 2 emergency faults are those identified in the first type of diagnostic results that cause performance degradation but do not immediately lead to loss of control, such as "inductance value drift of 20%"; and the complete failure of critical sensors (such as the main output voltage channel) in the second type of diagnostic results.
[0061] Level 3 non-emergency faults are those mapped from the second type of diagnostic results, such as non-critical sensors (e.g., phase current sampling) with out-of-tolerance accuracy, or slight parameter drift in the first type of diagnostic results.
[0062] The tiered decision-making process includes the following steps: When the mapping result is "Level 1 Emergency Fault," the signal is directly sent to a Level 1 decision-making unit composed of pure hardware logic circuits (such as a CPLD or dedicated ASIC). This unit is completely independent of the digital processor running the main control software. Within a few microseconds of receiving the signal, it directly pulls down the "enable" pins of all drive signals and triggers hardware latch-up to achieve the fastest and most reliable power shutdown. When the mapping result is "Level 2 Emergency Fault" or "Level 3 Non-Emergency Fault," the signal is sent to Level 2 decision-making software running on a safety coprocessor (such as a lockstep MCU). This software queries a more complex "policy matrix" based on factors such as the fault type, whether the device is currently in "operation" or "standby" mode, and whether the load is a life support device. For a Level 2 Emergency Fault, the possible decision is: "Immediately initiate dynamic hardware reconfiguration, isolate the faulty module, derated the system by 30% and continue operating, and issue an audible and visual alarm." For a Level 3 Non-Emergency Fault, the possible decision is: "Pop up maintenance prompts on the main control interface, record the fault log, but do not change the current operating status."
[0063] S130: According to the handling strategy, the reconfigurable power unit in the medical power supply is dynamically reconfigured in hardware to change its electrical connection topology and achieve a safe operating state corresponding to the handling strategy.
[0064] By responding to the core execution steps of the "Level 2 Emergency Fault" handling strategy, a "seamless" or "minimally disruptive" power supply switch is achieved, maximizing system functionality while isolating the fault. For example, taking the isolation of a faulty power submodule as an example, assume the Level 2 adjudication unit issues a reconfiguration command. Based on the fault location information, the reconfiguration manager selects a target topology from the pre-stored "topology configuration library" (e.g., reconfiguring from "four-phase parallel" to "three-phase parallel"). Simultaneously, it calculates the target current values that the remaining three healthy submodules need to handle in the new three-phase parallel mode.
[0065] Without interrupting the existing four-phase parallel output, the reconfiguration manager subtly adjusts the control reference values of the three healthy submodules via the control bus, allowing their output currents to be slowly and precisely adjusted to the target values. Simultaneously, it controls the faulty submodule to be isolated to reduce its current to zero. This process is achieved through a high-bandwidth current loop, minimizing voltage disturbance to the overall output. When the outputs of the three healthy submodules are detected to have stabilized at the target values and the faulty submodule current is zero, the reconfiguration manager sends a command via fiber optic to a SiC MOSFET-based solid-state switch matrix. This matrix performs two actions simultaneously within one switching cycle (e.g., 10μs): a) disconnecting the series switch connecting the faulty submodule; b) connecting the backplane connection switch required to form the new three-phase parallel topology. At the instant the hardware switch is complete, the main controller seamlessly switches the power conversion control algorithm parameters (such as current loop PI parameters and current sharing coefficients) from the "four-phase parallel parameter set" to the "three-phase parallel parameter set." Due to effective pre-synchronization, the loop enters a stable state immediately upon switching, resulting in a smooth transition of output voltage and current, with the load equipment experiencing virtually no power interruption or disturbance.
[0066] As can be seen from the above analysis, the embodiments of this application provide a method for fault self-verification and safety control of medical power supply, the method including: performing online fault self-verification of the power supply system with multiple logics; Based on the self-verification results, a safety logic decision is made, distinguishing at least two different handling strategies according to the urgency of the fault. According to the handling strategy, the reconfigurable power unit in the medical power supply undergoes dynamic hardware reconfiguration to change its electrical connection topology, achieving a safe operating state corresponding to the handling strategy. Through multi-logic online fault self-verification and the distinction between at least two handling strategies based on fault urgency, different safety strategies can be implemented flexibly and automatically. Furthermore, by dynamically reconfiguring the reconfigurable power unit, the fundamental problems of balancing safety and availability, and the lack of adaptive recovery capabilities in the system, are solved.
[0067] Please see Figure 3 , Figure 3 This is a schematic diagram of a medical power supply fault self-checking and safety control device provided in an embodiment of this application. The medical power supply fault self-checking and safety control device includes modules or units used to perform... Figure 1 or Figure 2 The steps in the corresponding embodiments. Please refer to the details. Figure 1 or Figure 2 The relevant descriptions in the corresponding embodiments are shown below. For ease of explanation, only the parts relevant to this embodiment are shown. See also... Figure 3 The medical power supply fault self-checking and safety control device 300 includes: Verification module 310 is used to perform online fault self-verification of the power supply system with multiple logic logics; The adjudication module 320 is used to make a security logic adjudication based on the self-verification result, wherein the security logic adjudication distinguishes at least two different handling strategies according to the urgency of the fault. The reconfiguration module 330 is used to dynamically reconfigure the reconfigurable power unit in the medical power supply according to the treatment strategy, so as to change its electrical connection topology and realize a safe operating state corresponding to the treatment strategy.
[0068] In one embodiment, the verification module 310 includes: The computing unit is used to calculate the model estimates of key electrical quantities in real time based on the cyber-physical fusion model of the power system and the current control commands. The comparison unit is used to compare the estimated value of the cyber-physical fusion model with the measurement value from at least two independent physical channels. The first diagnostic unit is used to diagnose a component fault in the modeled power circuit if the deviation between the estimated value of the cyber-physical fusion model and the measured value of all physical channels exceeds the preset tolerance, and outputs a first type of diagnostic result. The second diagnostic unit is used to diagnose a physical channel as a faulty channel if the estimated value of the cyber-physical fusion model deviates from the measurement value of a single physical channel by more than a preset tolerance, but is consistent with the measurement values of other physical channels, and outputs a second type of diagnostic result.
[0069] In one embodiment, the verification module 310 further includes: The acquisition unit is used to acquire the actual switching response waveform of the power switching device through a diagnostic circuit that is electrically isolated from its main drive circuit after a drive command is issued to the power switching device; The analysis unit is used to perform timing and morphological matching analysis on the actual switch response waveform and the expected standard waveform generated based on the drive command and the cyber-physical fusion model. The third diagnostic unit is used to diagnose a functional fault in the power switch device or its corresponding drive circuit if the matching degree is lower than a preset threshold, and outputs a third type of diagnostic result.
[0070] The adjudication module 320 includes: The mapping unit is used to map the self-verification result to a preset urgency level. The adjudication unit is used to make security logic decisions based on the preset urgency level.
[0071] In one embodiment, the preset urgency levels include Level 1 emergency faults, Level 2 emergency faults, and Level 3 non-emergency faults; the adjudication module is specifically used for: For a Level 1 emergency fault, a microsecond-level Level 1 decision is triggered by independent hardware logic, which shuts down the main power or isolates the faulty branch. For a Level 2 emergency fault, a millisecond-level Level 2 decision is triggered by the safety processor, executing a combined strategy including output power derating, switching to standby control mode, and initiating the dynamic hardware reconfiguration. For Level 3 non-emergency faults, the Level 2 decision is triggered, local alarms and operation logs are recorded, and preventative maintenance prompts are issued.
[0072] In one embodiment, the preset tolerance is a dynamic tolerance, the value of which is adaptively adjusted based on the current operating point of the key electrical quantity, historical measurement noise statistics, and component aging coefficient.
[0073] In one embodiment, the device 300 further includes: The simulation module is used to sequentially simulate the deviation of the key electrical quantities when a single component fails in the cyber-physical fusion model. The matching module is used to calculate the degree of matching between the deviation of the actual measured value and the model estimate and each simulation deviation. The determination module is used to determine the hypothetical failed component corresponding to the simulation with the highest matching degree as the faulty component.
[0074] Please see Figure 4 , Figure 4 This is a schematic diagram of a medical power supply fault self-checking and safety control device provided in one embodiment of this application. Figure 4 It is understood that the medical power supply fault self-checking and safety control device 400 includes: a processor 410, a memory 420, and a computer program 430 stored in the memory 420 and executable on the processor 410; when the processor 410 executes the computer program 430, it implements the steps in the above-mentioned embodiments of the medical power supply fault self-checking and safety control methods, for example... Figure 1 The steps S110 to S130 are shown. Alternatively, when the processor 410 executes the computer program 430, it implements the functions of each module / unit in the above-described device embodiments, for example... Figure 3 The functions of modules 310 to 330 are shown.
[0075] For example, computer program 430 may be divided into one or more modules / units, one or more of which are stored in memory 420 and executed by processor 410 to complete this application. One or more modules / units may be a series of computer program instruction segments capable of performing specific functions, which describe the execution process of computer program 430 in a medical power supply fault self-checking and safety control device. For example, computer program 430 may be divided into a verification module, a decision module, and a reconfiguration module.
[0076] The fault self-checking and safety control device for medical power supplies provided in this embodiment may include, but is not limited to, processors and memory. Those skilled in the art will understand that... Figure 4 This is merely an example of a fault self-checking and safety control device for medical power supplies and does not constitute a limitation on such devices. It may include more or fewer components than shown in the figure, or combine certain components, or different components. For example, a fault self-checking and safety control device for medical power supplies may also include input / output devices, network access devices, buses, etc.
[0077] The processor 410 may be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor.
[0078] The memory 420 can be an internal storage unit of the medical power supply fault self-checking and safety control device, such as a hard drive or memory. The memory 420 can also be an external storage device, such as a plug-in hard drive, Smart Media Card (SMC), Secure Digital (SD) card, or Flash Card. Furthermore, the medical power supply fault self-checking and safety control device can include both internal and external storage units. The memory 420 is used to store computer programs and other programs and data required by the medical power supply fault self-checking and safety control device. The memory 420 can also be used to temporarily store data that has been output or will be output.
[0079] It should be noted that the information interaction and execution process between the above-mentioned devices / units are based on the same concept as the method embodiments of this application. For details on their specific functions and technical effects, please refer to the method embodiments section, and they will not be repeated here.
[0080] This application also provides a network device, which includes: at least one processor, a memory, and a computer program stored in the memory and executable on the at least one processor, wherein the processor executes the computer program to implement the steps in any of the above method embodiments.
[0081] This application also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps described in the various method embodiments above.
[0082] This application provides a computer program product that, when run on a mobile terminal, enables the mobile terminal to implement the steps described in the above-described method embodiments.
[0083] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the methods of the above embodiments of this application can be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when executed by a processor, it can implement the steps of the various method embodiments described above. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or certain intermediate forms. The computer-readable medium can include at least: any entity or device capable of carrying computer program code to a photographing device / terminal device, a recording medium, a computer memory, a read-only memory (ROM), a random access memory (RAM), an electrical carrier signal, a telecommunication signal, and a software distribution medium. Examples include USB flash drives, portable hard drives, magnetic disks, or optical disks. In some jurisdictions, according to legislation and patent practice, computer-readable media cannot be electrical carrier signals or telecommunication signals.
[0084] In the above embodiments, the descriptions of each embodiment have different focuses. For parts that are not described in detail or recorded in a certain embodiment, please refer to the relevant descriptions of other embodiments.
[0085] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0086] In the embodiments provided in this application, it should be understood that the disclosed apparatus / network devices and methods can be implemented in other ways. For example, the apparatus / network device embodiments described above are merely illustrative. For instance, the division of modules or units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between devices or units may be electrical, mechanical, or other forms.
[0087] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0088] The above-described embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application, and should all be included within the protection scope of this application.
Claims
1. A method for self-verification and safety control of faults in a medical power supply, characterized in that, The method includes: Perform online fault self-checking of the power supply system using multiple logic logics; Based on the self-verification results, a security logic decision is made, which distinguishes at least two different handling strategies according to the urgency of the fault. According to the aforementioned handling strategy, the reconfigurable power unit in the medical power supply is dynamically reconfigured in hardware to change its electrical connection topology and achieve a safe operating state corresponding to the handling strategy.
2. The method according to claim 1, characterized in that, The online fault self-checking of the power system using multiple logic logics includes: Based on the cyber-physical fusion model of the power system and the current control commands, the model estimates of key electrical quantities are calculated in real time. The estimated values of the cyber-physical fusion model are compared with the measurements from at least two independent physical channels; If the estimated value of the cyber-physical fusion model deviates from the measured value of all physical channels beyond the preset tolerance, it is diagnosed that there is a component fault in the modeled power circuit, and the first type of diagnosis result is output. If the estimated value of the cyber-physical fusion model deviates from the measurement value of a single physical channel by more than the preset tolerance, but is consistent with the measurement value of other physical channels, then the physical channel is diagnosed as a faulty channel, and a second type of diagnostic result is output.
3. The method according to claim 2, characterized in that, The online fault self-checking of the power system with multiple logic logics also includes: After a drive command is issued to the power switching device, the actual switching response waveform of the power switching device is acquired through a diagnostic circuit that is electrically isolated from its main drive circuit. The timing and morphological matching degree of the actual switch response waveform and the expected standard waveform generated based on the driving command and the cyber-physical fusion model are analyzed. If the matching degree is lower than the preset threshold, a functional fault is diagnosed in the power switch device or its corresponding drive circuit, and a third type of diagnostic result is output.
4. The method according to claim 3, characterized in that, The security logic decision based on the self-verification result includes: The self-verification results are mapped to a preset urgency level; Based on the preset urgency level, a security logic decision is made.
5. The method according to claim 4, characterized in that, The preset urgency levels include Level 1 emergency faults, Level 2 emergency faults, and Level 3 non-emergency faults. The security logic decision distinguishes at least two different handling strategies based on the urgency of the fault, including: For a Level 1 emergency fault, a microsecond-level Level 1 decision is triggered by independent hardware logic, which shuts down the main power or isolates the faulty branch. For a Level 2 emergency fault, a millisecond-level Level 2 decision is triggered by the safety processor, executing a combined strategy including output power derating, switching to standby control mode, and initiating the dynamic hardware reconfiguration. For Level 3 non-emergency faults, the Level 2 decision is triggered, local alarms and operation logs are recorded, and preventative maintenance prompts are issued.
6. The method according to claim 2, characterized in that, The preset tolerance is a dynamic tolerance, and its value is adaptively adjusted based on the current operating point of the key electrical quantity, historical measurement noise statistics, and component aging coefficient.
7. The method according to claim 2, characterized in that, The process of diagnosing a component fault in the modeled power circuit also includes: In the cyber-physical fusion model, the deviations of the key electrical quantities are simulated sequentially when a single component fails. The deviation between the actual measured value and the model estimate is compared with the matching degree of each simulation deviation; The hypothetical failed component corresponding to the simulation with the highest matching degree is determined to be the faulty component.
8. A fault self-checking and safety control device for a medical power supply, characterized in that, include: The testing module is used to perform online fault self-checking of the power supply system using multiple logic logics. The adjudication module is used to make security logic adjudications based on the self-verification results. The security logic adjudications distinguish at least two different handling strategies according to the urgency of the fault. The reconfiguration module is used to dynamically reconfigure the reconfigurable power units in the medical power supply according to the treatment strategy, so as to change their electrical connection topology and achieve a safe operating state corresponding to the treatment strategy.
9. A fault self-checking and safety control device for a medical power supply, characterized in that, include: Processor, memory, and computer programs stored in said memory and executable on said processor; When the processor executes the computer program, it implements the method as described in any one of claims 1 to 7.
10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by a processor, it implements the method as described in any one of claims 1 to 7.