A control method for an external functional safety device of a motor controller

By using a dual MCU architecture with a second controller external to the motor controller, functional safety capabilities can be added to existing electric forklifts in a low-cost, non-intrusive manner. This solves the problems of high cost, difficult modification, and high failure rate in existing technologies, and achieves rapid response and full-scenario safety coverage.

CN122131570APending Publication Date: 2026-06-02ZHENGZHOU JIACHEN ELECTRIC CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
ZHENGZHOU JIACHEN ELECTRIC CO LTD
Filing Date
2026-02-13
Publication Date
2026-06-02

AI Technical Summary

Technical Problem

Upgrading the functional safety capabilities of existing electric forklifts using current technologies is costly, difficult to modify, and has a high failure rate, failing to meet the requirements of low cost, non-intrusive, comprehensive safety coverage, and rapid response.

Method used

By adding an independent second controller to the motor controller and connecting it in parallel with the original controller, a dual MCU redundancy architecture is used to perform signal cross-verification and hardware-level security response, generating security verification results and ensuring the security of the original controller.

Benefits of technology

It enables low-cost, non-intrusive addition of functional safety capabilities to existing equipment, reducing retrofit costs, avoiding resource waste, quickly responding to and covering safety risks across all scenarios, and avoiding single point of failure risks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122131570A_ABST
    Figure CN122131570A_ABST
Patent Text Reader

Abstract

This invention relates to a control method for an external functional safety device for a motor controller, specifically in the field of electric forklift technology. By adding a second controller connected in parallel with the original first controller, a non-intrusive design is employed, without altering the original vehicle controller's hardware and software logic. The second controller features a built-in dual-MCU redundant architecture, synchronously receiving vehicle safety signals with the first controller and independently generating safety control commands. It achieves dual safety decisions through internal cross-validation and external state verification. When a safety risk is detected, the second controller directly cuts off the power output of the first controller via an independent hardware link and triggers mechanical braking; otherwise, normal operation is permitted. This invention achieves low-cost, full-scenario safety coverage for functional safety enhancement, with fast response speed and no single point of failure risk. It is compatible with existing electric forklifts and upgrades of various non-functional safety motor controllers, demonstrating significant application value and promotion potential.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of electric drive forklift technology, and more specifically to a control method for an external functional safety device for a motor controller. Background Technology

[0002] With the increasingly widespread application of electric forklifts in warehousing, logistics, and manufacturing, their operational safety has become paramount. International and domestic standards have set clear requirements for the functional safety of forklifts, aiming to prevent personal injury and property damage caused by control system failures. Functional safety has become a prerequisite for forklifts, especially high-end models, to enter the mainstream market.

[0003] Conventional motor controllers are core control units in industrial automation equipment, new energy logistics vehicles, forklifts, electric sightseeing vehicles, and other electrified equipment. They primarily receive driver commands (such as acceleration, braking, and steering) and equipment status signals, precisely controlling the motor's voltage, current, and frequency to achieve functions such as motor start-up, stop, speed regulation, and torque control. These controllers are widely used in existing industrial vehicles, early new energy vehicles, and low-to-mid-range electric equipment. Their core components include a power module, a general-purpose microprocessor, signal acquisition circuits, protection circuits, and communication interfaces. While they possess basic motor drive control capabilities, they are not designed according to functional safety standards and lack systematic safety redundancy and fault tolerance mechanisms.

[0004] Therefore, this technological background has also given rise to a significant practical contradiction: on one hand, there are high safety standards demanded by regulations and the market; on the other hand, there is the low configuration of the vast number of ordinary forklifts on the market. The challenge is how to "patchise" these massive numbers of ordinary electric forklifts with minimal changes to their existing vehicle control systems, extremely low modification costs, and the simplest installation methods, enabling them to quickly obtain certified functional safety capabilities.

[0005] Under current technology, upgrading the functional safety of existing vehicles typically involves directly replacing the main controller with one that meets functional safety standards. This approach has two major drawbacks: First, it is costly, as functional safety controllers are expensive, and the replacement process involves disassembling the original controller and installing and debugging the new one, resulting in combined labor and material costs. Second, it wastes resources, as the replaced controller is often still functional and simply discarding it is not in line with economic and environmental principles.

[0006] Existing technologies also employ software upgrades to optimize the MCU program of the original controller, adding software logic such as signal range verification and fault diagnosis. These attempts aim to compensate for security deficiencies through software algorithms, but they do not change the original hardware's single-path structure. The software upgrade depends on the performance of the original controller's MCU, and some older MCUs do not support complex security algorithms. The software logic still runs on a single MCU, posing a risk that MCU failure could lead to the failure of the security algorithm. Furthermore, the software response speed is slow and cannot meet the security response requirements in emergency situations. It is also impossible to verify the authenticity of the original signal received by the controller; if the signal is interfered with or tampered with, the software algorithm will still generate instructions based on the erroneous signal.

[0007] Therefore, existing modification methods all adopt an intrusive approach, which is costly, requires targeted solutions based on the current controller situation, cannot achieve comprehensive coverage, is difficult to modify, and has a high failure rate. Based on this, there is an urgent need to study a control method for external functional safety devices for motor controllers, which can add functional safety capabilities to existing non-functional safety controllers without replacing them, thereby completing the upgrade and modification of the existing market at low cost and high efficiency. Summary of the Invention

[0008] Therefore, the purpose of this invention is to provide a control method for external functional safety devices for motor controllers. This method addresses the problems of high cost, incomplete safety protection, and single-point-of-failure risks inherent in existing retrofit solutions, making it difficult to meet the practical application requirements of low cost, non-intrusiveness, comprehensive safety coverage, and rapid response. Therefore, developing a control method that requires no modification to the original controller hardware and software logic, can be directly externally installed, and possesses comprehensive safety verification and hardware-level safety response capabilities to supplement existing non-functional safety motor controllers with functional safety features has become a pressing technical problem in the industry.

[0009] To achieve the above objectives, the technical solution adopted by the present invention is: a control method for an external functional safety device for a motor controller. Add a second controller connected in parallel with the first controller; The first controller and the second controller generate a first control command and a second control command respectively based on the synchronous input signals; The second controller receives the first control command and cross-compares it with the second control command to generate a security verification result. Based on the security verification result, the second controller intervenes in the execution of the first control command.

[0010] Furthermore, the second controller includes a first processing unit and a second processing unit that independently process the input signal and obtain a first intermediate result and a second intermediate result respectively; the second control command is generated by cross-validating the first intermediate result and the second intermediate result between the first processing unit and the second processing unit.

[0011] Furthermore, the first processing unit and the second processing unit are two parallel and independent microcontrollers (MCUs). The two MCUs are connected through an internal interface and simultaneously connected to the communication port of the first controller through an independent external communication interface.

[0012] Furthermore, the two microcontrollers (MCUs) independently receive the pre-processed input signals, parse and logically judge the received signals, and compare whether the judgments of the two MCUs on the same signal or the same safety state are consistent. If they are inconsistent, it is determined that there is a system fault and a safety response is triggered. If they are consistent, a second control command is generated based on the judgment result.

[0013] Furthermore, within a preset time period, the two microcontrollers (MCUs) send their own operating status data through the communication interface. The operating status data includes the MCU's power supply voltage, program running counter, and signal processing progress information. If either MCU fails to receive the other's operating status data within the preset time, or if the operating status data contains abnormal information, it is determined that the corresponding MCU is faulty, and the second controller triggers a safety response, outputting an enable / disable signal.

[0014] Furthermore, the second controller receives the exact same vehicle input signals synchronously with the original first controller via a parallel wiring harness. These input signals include, for example, multiple safety switch signals, multiple safety analog signals, and position and speed signals.

[0015] Furthermore, based on the input signal, the second controller generates a second control command through its internal redundant safety logic processing, and obtains the status information output by the first controller through the vehicle communication bus. The status information includes the current power output enable status of the first controller, the target drive speed or torque, the operating mode, and the feedback of the processing results of the vehicle input signal.

[0016] Furthermore, when the security verification result indicates a security risk, the second controller outputs an enable / disable signal through its independent hardware output link to directly cut off the power output of the first controller; when the security verification result indicates no security risk, it outputs an enable / allow signal to allow the power output of the first controller.

[0017] Furthermore, the enable / disable signal or enable signal is applied to the power output enable pin of the first controller, or to the control terminal of the main contactor that controls the main power supply circuit of the first controller.

[0018] Furthermore, while outputting the enable / disable signal, the second controller also outputs a brake control signal to trigger the vehicle's mechanical braking device.

[0019] The beneficial effects of the above technical solution are as follows: This invention uses a non-intrusive redundant safety supplementation method to modify the equipment. That is, without changing the hardware structure, software logic and wiring harness interface of the original first controller (non-functional safety motor controller) of the existing equipment, an external independent second controller (functional safety controller) is used to collect data in parallel and synchronously, generate safety verification results using dual-channel independent decision verification, and upgrade the original equipment through forced intervention, thereby adding functional safety capabilities to existing electric forklifts and other equipment at low cost.

[0020] This invention achieves the transformation in a low-cost, non-invasive manner, lowering the upgrade threshold. It does not require replacing the first controller; the transformation is achieved simply by connecting an external second controller in parallel. The transformation cost is far lower than replacing the functional safety main controller, avoiding the waste of the original controller resources. The transformation process does not require modification of the original vehicle wiring or program, the installation and debugging cycle is short, and it does not affect the normal operation of the equipment.

[0021] This invention effectively solves the risk of failure of the second controller by adopting a dual MCU redundancy architecture. It solves external risks such as failure of the first controller, signal abnormality, and communication failure by using internal and external dual verification, thus achieving full-scenario coverage of self-safety and external safety.

[0022] Safety intervention is executed directly by hardware circuits without relying on any software processes, resulting in a short response time far below industry safety standard limits. Even if the first controller experiences serious malfunctions such as software crashes or program crashes, the second controller can still forcibly cut off power and apply the brakes, ensuring that the safety functions do not fail.

[0023] This invention adopts standardized parallel interfaces and communication protocol adaptation at the physical level, eliminating the need for customized development for different models of first controllers. It can cover the upgrade needs of most existing non-functional safety motor controllers, and is especially suitable for on-site operation scenarios without network coverage.

[0024] Therefore, this invention addresses the functional safety upgrade needs of existing non-functional safety motor controllers, overcoming the limitations of existing solutions such as replacing the main controller and software upgrades. It proposes a technical path of external dual-MCU redundant safety controllers and non-intrusive parallel modification, tailored to practical needs. With extremely low modification costs and without altering the original vehicle power control architecture, it adds functional safety capabilities to existing equipment, providing full-scenario safety coverage, hardware-level rapid response, and eliminating single-point-of-failure risks, effectively resolving the contradiction between regulatory requirements and the low configuration of existing equipment. The application scenarios of this invention are not limited to electric forklifts but can be extended to various existing equipment using non-functional safety motor controllers, such as warehousing and logistics equipment, industrial automation vehicles, and low-to-mid-range new energy logistics vehicles, possessing strong practical application value and market promotion potential. Its non-intrusive redundancy supplementation design also provides a referable technical solution for the functional safety upgrade of other industrial equipment. Attached Figure Description

[0025] Figure 1 This is a system implementation block diagram of the present invention; Figure 2 This is a data processing logic block diagram of the present invention; Figure 3 This is a block diagram illustrating the implementation logic of the second controller. Figure 4 This is a flowchart illustrating the process after a risk assessment is triggered. Figure 5 This is a wiring diagram of the second controller of the present invention; Figure 6 This is an internal block diagram of the second controller safety device of the present invention. Detailed Implementation

[0026] The present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments: Example

[0027] This embodiment aims to provide a control method for an external functional safety device for the motor controller. It is primarily used to retrofit existing equipment in a low-cost, highly reliable, and non-intrusive manner, enabling a large number of existing electric forklifts that currently lack functional safety features to meet current regulatory and customer requirements for functional safety. The purpose of this invention is to overcome the drawbacks of existing upgrade solutions, such as high cost and significant waste, by providing a control method for an external functional safety device. Its objective is to add an independent, dedicated safety controller with redundancy verification capabilities, which monitors the overall vehicle safety status in parallel without modifying the original vehicle controller. Upon detecting a hazard, it can directly and reliably cut off power via hardware circuitry, thereby enabling ordinary electric forklifts to quickly and reliably obtain functional safety certification.

[0028] This embodiment, based on the actual retrofitting scenario of existing electric forklifts, provides a detailed description of a control method for an external functional safety device on the motor controller. Its core is to achieve equipment modification by adding a second controller connected in parallel with the original first controller without altering the original first controller. Specifically, in this embodiment, the first controller is the original vehicle's non-functional safety controller, and the second controller is a functional safety controller. Figure 1 As shown, without affecting the original vehicle's non-functional safety controller, an additional independent functional safety controller is added to upgrade the electric forklift, supplementing its functional safety capabilities, thereby completing the upgrade and transformation of the existing market at low cost and high efficiency.

[0029] When processing data, such as Figure 3-4 As shown in the figure, in this embodiment, the first controller and the second controller generate the first control command and the second control command respectively based on the synchronous input signals. During the operation of the forklift, all safety-related input signals are synchronously transmitted to the first controller and the second controller through parallel wiring harnesses to ensure that the two obtain completely consistent control basis. The two controllers execute the processing logic independently based on the same input signals and generate the corresponding control commands without interfering with each other.

[0030] The first controller fully adheres to the original vehicle's fixed control logic, with no modifications to its hardware structure, internal control program, or wiring harness interface. The first controller receives multiple core input signals, outputs three-phase AC power to drive the traction motor, and periodically outputs status information via the vehicle communication bus.

[0031] The second controller receives the exact same vehicle input signals synchronously with the original first controller via a parallel wiring harness. These input signals include multiple safety switch signals, multiple safety analog signals, and position and speed signals. This external controller also passively monitors the output status of the original controller via the CAN bus. This design decouples the safety monitoring system from the original vehicle control system both physically and logically, avoiding complex software modifications and achieving non-intrusive integration.

[0032] like Figure 1As shown, the second controller, based on the input signal, generates a second control command through its internal redundant safety logic processing, and obtains the status information output by the first controller via the vehicle communication bus. This status information includes the first controller's current power output enable status, target drive speed or torque, operating mode, and feedback on the processing results of the vehicle input signal. The second controller independently analyzes the signal based on its built-in functional safety logic (meeting the corresponding functional safety standard level requirements), determines that the current state meets the permissible driving safety conditions (driver seated, no emergency stop triggered, no signal abnormalities), and generates the second control command.

[0033] like Figure 3-4 As shown, the second controller receives the first control command and cross-compares it with the second control command to generate a safety verification result. In specific implementation, after receiving the actual status information of the first controller through the communication bus, the second controller starts the cross-verification process to ensure that the control behavior of the first controller complies with safety rules: During verification, by comparing the actual output status of the first controller (power output enable status, target speed, duty cycle) with the expected safety status of the second control command (power output enable is effective, target speed does not exceed the safety speed limit threshold, duty cycle is within a reasonable range), if the two statuses are completely consistent, the output has no safety risk; otherwise, the output has a safety risk.

[0034] Based on the safety verification results, the second controller intervenes in the execution of the first control command. When a decision result indicating no safety risk is output, the second controller outputs a high-level enable signal to the power output enable pin of the first controller through a hardware intervention link. The first controller maintains its original power output, and the motor runs stably at the target speed. Throughout the process, the original vehicle processing logic of the first controller is not interfered with in any way. The second controller only plays a safety monitoring role to ensure that it operates within the safety boundaries.

[0035] When the safety verification result indicates a safety risk, the second controller outputs an enable / disable signal via its independent hardware output link to directly cut off the power output of the first controller; when the safety verification result indicates no safety risk, it outputs an enable / allow signal to enable the power output of the first controller. The enable / disable or enable signal is applied to the power output enable pin of the first controller, or to the control terminal of the main contactor controlling the main power supply circuit of the first controller. Simultaneously with outputting the enable / disable signal, the second controller also outputs a brake control signal to trigger the vehicle's mechanical braking device.

[0036] In the specific implementation of this embodiment, if there is a safety risk in the output, the second controller will output a low-level enable / disable signal to the power output enable pin of the first controller through the hardware intervention link within a preset response time, directly forcibly shutting down the power output module of the first controller; at the same time, the second controller will output a braking control signal to trigger the vehicle's mechanical braking, ensuring that the motor completely stops running within the time required by the safety standard, and the total response time is far lower than the industry safety standard limit.

[0037] Therefore, the modification scheme provided in this embodiment has a significantly lower total cost than replacing the original functional safety controller, avoiding the waste of resources of the original controller and greatly reducing the safety upgrade cost of existing equipment. The modification is carried out in a non-intrusive manner, without altering the hardware structure of the first controller, the original vehicle processing logic, or the original wiring harness. The modification cycle is short and does not affect the normal operation of the equipment. In terms of data processing, through the processing logic of same-source signal acquisition, independent operation of the original vehicle logic of the first controller, independent decision-making of the safety logic of the second controller, dual instruction cross-verification, and hardware forced intervention, the original functions of the first controller are preserved, while covering core safety risks such as failure of the first controller, signal abnormality, and communication failure. This enables existing forklifts to meet the current functional safety certification requirements, with fast safety response speed and high reliability. In addition, the second controller itself has redundant verification capabilities, avoiding safety protection failure caused by single point of failure. Therefore, this embodiment effectively resolves the cost-reliability contradiction in upgrading the functional safety of existing electric forklifts through a non-intrusive modification method using an external independent safety controller, demonstrating strong practical application value. With extremely low modification costs and without altering the original vehicle's power control architecture, it adds functional safety capabilities to existing equipment, including full-scenario safety coverage, hardware-level rapid response, and no single point of failure risk, effectively resolving the conflict between regulatory market requirements and the low configuration of existing equipment. Example

[0038] Based on Embodiment 1, in order to solve the safety problem, the functional safety device adopts a dual MCU redundancy architecture. Two independent microcontrollers (i.e., the first processing unit MCU1 and the second processing unit MCU2) are integrated inside the second controller. The power supply circuit, signal acquisition channel and execution output link of the two are completely physically isolated to avoid the failure of the second controller due to a single point of failure.

[0039] In this embodiment, as shown... Figure 2 , 5As shown in Figure 6, the source data is simultaneously sent to both the non-functional safety controller and the functional safety equipment, enabling parallel signal uploading. The specific source data includes multiple safety switch signals from the vehicle (such as emergency stop buttons and seat switches), multiple safety analog signals (such as accelerator pedal position and steering angle), and position / speed sensor signals. In terms of data preprocessing, within the functional safety controller, these signals enter the conditioning circuits of MCU1 and MCU2 respectively, undergoing filtering, level conversion, and other preprocessing to form digital signals recognizable by the MCUs.

[0040] The second controller includes a first processing unit and a second processing unit that independently process the input signal and obtain a first intermediate result and a second intermediate result respectively; the second control command is generated by cross-validating the first intermediate result and the second intermediate result between the first processing unit and the second processing unit.

[0041] In implementation, the first processing unit and the second processing unit are two independent microcontrollers (MCUs). On the one hand, MCU1 and MCU2 achieve data interaction through internal CAN communication or a dedicated communication interface. On the other hand, they are connected to the communication port of the first controller through an independent external communication bus interface, which is only used to listen to the status information output by the first controller and does not interfere with its original communication logic.

[0042] This embodiment uses shielded branch wiring harnesses to synchronously connect various core safety signals of the forklift (multi-channel safety switch signals, multi-channel safety analog signals, and position / speed sensor signals) to the signal input terminal of the first controller and the signal acquisition terminal of the second controller. This ensures that both receive completely identical and synchronized original signals, avoiding verification deviations caused by signal asynchrony. The two microcontrollers (MCUs) independently receive the pre-processed input signals, parse and logically judge the received signals, and compare whether the judgments of the two MCUs on the same signal or the same safety state are consistent. If they are inconsistent, it is determined that there is a system fault and a safety response is triggered. If they are consistent, a second control command is generated based on the judgment result.

[0043] In practice, the preprocessed digital signal is received independently by MCU1 and MCU2. MCU1 and MCU2, according to their respective program logic, parse and logically judge the received signal (e.g., determining whether the emergency stop switch is pressed or whether the pedal signal is within a reasonable range). MCU1 and MCU2 exchange their judgment results and key data in real time via internal CAN communication or a dedicated communication interface. The two MCUs perform cross-validation: comparing whether their judgments on the same signal or the same safety state (e.g., whether the vehicle should be allowed to drive) are consistent. If they are inconsistent, a system fault is immediately determined (i.e., the safety controller itself fails), triggering a safety response.

[0044] Within a preset time period, the two microcontrollers (MCUs) send their own operating status data through a communication interface. This data includes the MCU's power supply voltage, program counter, and signal processing progress information. If either MCU fails to receive the other's operating status data within the preset time, or if the operating status data contains abnormal information, it is determined that the corresponding MCU is faulty. The second controller then triggers a safety response, outputting an enable / disable signal. In this embodiment, MCU1 and MCU2 independently acquire and process the same input signals, which are then processed by conditioning circuits and cross-validated via CAN communication. This not only detects faults in external signal links (such as position / speed signal failure or analog signal abnormalities) but also identifies internal random hardware faults by comparing the calculation results of the two MCUs. Furthermore, the self-judgment result is cross-validated again with the status of the original controller (non-functional safety controller) obtained from the CAN bus, thereby achieving a comprehensive and highly reliable diagnosis of the vehicle's safety status.

[0045] When the system determines a dangerous state, the external safety device, independent of the original controller's (non-functional safety controller) software response, can directly control the power output enable pin or main contactor connected to the original controller (non-functional safety controller) through its hardware output. By setting or disconnecting this pin and the main contactor, the power drive section of the original controller can be forced to fail directly at the hardware level, thereby cutting off the motor power. Simultaneously, the electromagnetic brake is controlled in conjunction with the system, achieving dual safety protection of power failure and braking. This hardware-level response mechanism is fast and highly reliable, ensuring that the safety functions remain effective even if the original controller experiences serious faults such as software crashes.

[0046] The non-functional safety controller transmits its internally calculated vehicle status (such as current enable status, target speed, etc.) via the CAN bus. The functional safety device (controlled by MCU1 or MCU2) listens to this status data via the CAN bus. It then performs a secondary cross-verification between the monitored original controller status and its own independently determined safety status based on the original signals. For example, if the functional safety controller determines a dangerous state (such as an emergency stop triggered), but the original controller still outputs a drive enable status, it is determined that the original controller has failed or is experiencing a communication anomaly, thus achieving external cross-verification with the main controller's status.

[0047] Internal and external verification results generate the final safety status decision. If all verifications pass, MCU1 and MCU2 output valid power output enable 1 and enable 2 signals, respectively. These two signals, through subsequent integrated circuitry, work together to enable the power output of the non-functional safety controller. Simultaneously, an electromagnetic brake enable signal is output, releasing the brake and allowing the motor to run. If any verification fails, MCU1 and / or MCU2 will retract its enable signal. If any enable signal is invalid, the integrated circuitry will disable the original controller. Simultaneously, the electromagnetic brake enable signal is retracted, the electromagnetic brake actuates, and the motor is forced to stop. This response is executed directly by the hardware circuitry, without relying on any software process, ensuring the highest response speed and reliability.

[0048] The power output enable signals from MCU1 and MCU2 are input to a synthesis circuit, which is essentially an AND logic gate. It requires both enable signals to be valid simultaneously in order to output a valid total enable signal.

[0049] In this embodiment, the external safety controller acts as the master controller, the original controller is downgraded to an actuator, and the external functional safety controller is upgraded to the system's master control unit. All safety-related signals (emergency stop, handbrake, etc.) are directly connected to this new master controller. After making a safety decision, the external safety controller sends speed or torque commands to the original non-functional safety controller (whose function is now downgraded to a simple motor driver) via the CAN bus. The original controller is only responsible for executing commands and no longer makes safety decisions. Simultaneously, in this embodiment, the external safety controller serves as a data monitoring and verification unit, handling fault connections without driving the motor.

[0050] A streamlined safety monitoring module is retained on the vehicle side (responsible for collecting key signals and executing emergency stops), while complex tasks such as signal analysis, historical fault diagnosis, and algorithm learning are performed on a cloud server. The vehicle-side module maintains a connection with the cloud via wireless communication (such as 4G / 5G) and receives safety policies or fault models from the cloud.

[0051] This embodiment does not use two independent MCUs, but instead uses a high-security MCU that integrates two or more physical cores and can run in lockstep mode. In this mode, the two cores execute the same code and compare the results in real time. If a discrepancy occurs, an error is reported.

[0052] The embodiments of the present invention described above do not constitute a limitation on the scope of protection of the present invention. The basic concept of the present invention lies in the optimization of the system architecture. It does not replace the original non-functional safety controller, but adds an independent functional safety controller in parallel. These two controllers are connected through shared (parallel) input signals and CAN communication, forming a heterogeneous architecture in which the main control system and the safety monitoring system coexist. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention should be included within the scope of protection of the claims of the present invention.

Claims

1. A control method for an external functional safety device for a motor controller, characterized in that: Add a second controller connected in parallel with the first controller; The first controller and the second controller generate a first control command and a second control command respectively based on the synchronous input signals; The second controller receives the first control command and cross-compares it with the second control command to generate a security verification result. Based on the security verification result, the second controller intervenes in the execution of the first control command.

2. The control method for an external functional safety device for a motor controller according to claim 1, characterized in that: The second controller includes a first processing unit and a second processing unit that independently process the input signal and obtain a first intermediate result and a second intermediate result respectively; the second control command is generated by cross-validating the first intermediate result and the second intermediate result between the first processing unit and the second processing unit.

3. The control method for an external functional safety device for a motor controller according to claim 2, characterized in that: The first processing unit and the second processing unit are two parallel and independent microcontrollers (MCUs). The two MCUs are connected through an internal interface and simultaneously connected to the communication port of the first controller through an independent external communication interface.

4. The control method for an external functional safety device for a motor controller according to claim 3, characterized in that: The two microcontrollers (MCUs) independently receive the pre-processed input signals, parse and logically judge the received signals, and compare whether the judgments of the two MCUs on the same signal or the same safety state are consistent. If they are inconsistent, it is determined that the system is faulty and a safety response is triggered. If they are consistent, a second control command is generated based on the judgment result.

5. The control method for an external functional safety device for a motor controller according to claim 4, characterized in that: Within a preset time period, the two microcontrollers (MCUs) send their own operating status data through the communication interface. The operating status data includes the MCU's power supply voltage, program running counter, and signal processing progress information. If either MCU fails to receive the other's operating status data within the preset time, or if the operating status data contains abnormal information, it is determined that the corresponding MCU is faulty, and the second controller triggers a safety response and outputs an enable / disable signal.

6. The control method for an external functional safety device for a motor controller according to claim 1, characterized in that: The second controller receives identical vehicle input signals synchronously with the original first controller via a parallel wiring harness. These input signals include, for example, multiple safety switch signals, multiple safety analog signals, and position and speed signals.

7. The control method for an external functional safety device for a motor controller according to claim 1, characterized in that: Based on the input signal, the second controller generates a second control command through its internal redundant safety logic processing, and obtains the status information output by the first controller through the vehicle communication bus. The status information includes the current power output enable status of the first controller, the target drive speed or torque, the operating mode, and the feedback of the processing results of the vehicle input signal.

8. The control method for an external functional safety device for a motor controller according to any one of claims 1-7, characterized in that: When the security verification result indicates that there is a security risk, the second controller outputs an enable / disable signal through its independent hardware output link to directly cut off the power output of the first controller; when the security verification result indicates that there is no security risk, it outputs an enable / allow signal to allow the power output of the first controller.

9. The control method for an external functional safety device for a motor controller according to claim 7, characterized in that: The enable / disable signal or enable signal is applied to the power output enable pin of the first controller, or to the control terminal of the main contactor that controls the main power supply circuit of the first controller.

10. The control method for an external functional safety device for a motor controller according to claim 8, characterized in that: While outputting the enable / disable signal, the second controller also outputs a brake control signal to trigger the vehicle's mechanical braking device.