Drive system and redundancy switching method
By introducing redundant first and second drive units into the drive unit system, and using the controller to monitor the status in real time and switch flexibly, the problem of incomplete fault diagnosis in the prior art is solved, and the automation and reliability of the system are improved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- CHINA TECHENERGY
- Filing Date
- 2026-02-13
- Publication Date
- 2026-06-02
Smart Images

Figure CN122131657A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of automation control technology, specifically to a drive device system and a redundancy switching method. Background Technology
[0002] The drive unit can make the motor, load and other equipment operate stably according to the instructions based on the control signal. In order to improve reliability, the drive unit system generally adopts a redundant design, that is, in addition to the main drive unit, a backup drive unit is also set up. When the main drive unit fails, the system switches to the backup drive unit to drive the equipment, thereby ensuring the stable operation of the equipment and avoiding equipment downtime.
[0003] However, existing technologies mainly rely on single parameters such as drive current, temperature, or vibration for fault diagnosis, lacking a comprehensive fault diagnosis standard. Furthermore, the switching principles between the primary and backup drive units are relatively fixed, resulting in low automation and low reliability of the system under complex operating conditions. Summary of the Invention
[0004] In view of this, this application provides a drive device system and a redundancy switching method, which can monitor the status of the drive device in real time to adjust the switching logic between the primary and backup drive devices, thereby improving the reliability of the system.
[0005] To solve the above problems, the technical solution provided in this application is as follows: In a first aspect of this application, a drive device system is provided, comprising: a first drive device and a second drive device that are redundant with each other; the first drive device is a host device in an operating state, and the second drive device is a standby device in a standby state. The first driving device includes a first communication module and a first controller, and the second driving device includes a second communication module and a second controller. The first controller is used to detect the status information of the first drive device, and the second controller is used to detect the status information of the second drive device. The status information includes normal status, alarm status and fault status. The alarm status is an abnormal status that does not affect the drive function, and the fault status is an abnormal status that affects the drive function. The first controller is also used to control the first communication module to send a host signal when the first drive device is in a normal state or an alarm state, and to control the first communication module to receive a standby signal from the second communication module; and to control the first communication module to send a standby signal when the first drive device is in a fault state. The second controller is also used to control the second communication module to receive the host signal from the first communication module and to control the second communication module to send the standby signal; when the second drive device is in normal or alarm state and the second communication module receives the standby signal from the first communication module, it controls the second communication module to send the host signal.
[0006] In one possible implementation, the first controller is further configured to control the first communication module to send a backup signal when the first drive device loses power or the first controller loses power.
[0007] In one possible implementation, before the first driving device is a host in a working state, the first controller is further configured to control the initialization of the first driving device and detect the status information of the first driving device. When the first driving device is in a normal state, the controller controls the first communication module to send a host signal to the second communication module. Before the second drive unit is in standby mode, the second controller is also used to control the initialization of the second drive unit and detect the status information of the second drive unit; when the second drive unit is in normal mode, it controls the second communication module to receive the host signal from the first communication module and the second communication module to send the standby signal to the first communication module.
[0008] In one possible implementation, the first controller is further configured to control the first drive device to re-enter the initialization state when the first drive device is not in a normal state; the second controller is further configured to control the second drive device to re-enter the initialization state when the second drive device is not in a normal state.
[0009] In one possible implementation, the master signal and the standby signal are pulse signals with different frequencies; The first controller is also used to confirm whether the pulse signal is a master signal or a standby signal by detecting the number of pulses of the pulse signal received by the first communication module within a time period. The second controller is also used to confirm whether the pulse signal is a master signal or a standby signal by detecting the number of pulses of the pulse signal received by the second communication module within a time period.
[0010] In one possible implementation, the first driving device further includes a first driving module, the first driving device being connected to a power supply through the input terminal of the first driving module; the output terminal of the first driving module is used to connect to a load. The second drive device also includes a second drive module, which is connected to a power source through the input terminal of the second drive module; the output terminal of the second drive module is used to connect to a load.
[0011] In a second aspect of this application, a redundancy switching method is provided. The method is applied to a drive device system, which includes: a first drive device and a second drive device that are redundant with each other; the first drive device is a host device in an active state, and the second drive device is a standby device in a standby state; the first drive device includes a first communication module and a first controller, and the second drive device includes a second communication module and a second controller. The method includes: Detect the status information of the first drive device and the second drive device; the status information includes normal status, alarm status and fault status, the alarm status is an abnormal status that does not affect the drive function, and the fault status is an abnormal status that affects the drive function. When the first drive unit is in a normal or alarm state, the first communication module is controlled to send a host signal and receive a standby signal from the second communication module; when the first drive unit is in a fault state, the first communication module is controlled to send a standby signal. The second communication module is controlled to receive host signals from the first communication module. When the second communication module receives host signals from the first communication module, the second communication module is controlled to send standby signals. When the second drive device is in normal or alarm state and the second communication module receives standby signals from the first communication module, the second communication module is controlled to send host signals.
[0012] One possible implementation further includes: controlling the first communication module to send a backup signal when the first drive device loses power or the first controller loses power.
[0013] One possible implementation includes controlling the first driving device to enter an initialization state and detecting the status information of the first driving device before the first driving device is in a working state. When the first driving device is in a normal state, the first communication module is controlled to send a host signal to the second communication module. Before the second drive device is in standby mode, the system also includes controlling the second drive device to enter the initialization state and detecting the status information of the second drive device. When the second drive device is in normal state, the system controls the second communication module to receive the host signal from the first communication module. When the second drive device is not in normal state, the system controls the second drive device to re-enter the initialization state.
[0014] In one possible implementation, the master signal and the standby signal are pulse signals with different frequencies; The method further includes: confirming that the pulse signal is a master signal or a backup signal by detecting the number of pulses of the pulse signal received by the first communication module within a time threshold; and confirming that the pulse signal is a master signal or a backup signal by detecting the number of pulses of the pulse signal received by the second communication module within a time threshold.
[0015] The drive system provided in this application includes a redundant first drive unit and a second drive unit; the first drive unit is the master unit, and the second drive unit is the standby unit; the first drive unit includes a first communication module and a first controller, and the second drive unit includes a second communication module and a second controller. The first controller can detect the status of the first drive unit, and the second controller can detect the status of the second drive unit, including normal status, alarm status, and fault status. The controllers are used to execute different master / standby switching logic according to the status of the drive units. This allows the drive system to switch between the master and standby units according to the drive status corresponding to the current operating condition, reducing the need for manual intervention when the drive system faces complex operating conditions, and achieving a high degree of automation. Moreover, the master / standby switching logic of this drive system can ensure that only one drive unit is in working condition, resulting in high reliability. Attached Figure Description
[0016] Figure 1 A driving device system provided in the embodiments of this application; Figure 2a This application provides a schematic diagram of the switching logic of a driving device. Figure 2b This is a schematic diagram of the switching logic of another driving device provided in an embodiment of this application; Figure 3 This application provides a schematic diagram of a primary / backup switchover in an initialization state. Figure 4 A power-on initialization flowchart of a driving device provided in an embodiment of this application; Figure 5 A schematic diagram of another driving device system provided in the embodiments of this application; Figure 6 A flowchart of a redundancy switching method provided in an embodiment of this application. Detailed Implementation
[0017] To make the above-mentioned objectives, features and advantages of this application more apparent and understandable, the embodiments of this application will be further described in detail below with reference to the accompanying drawings and specific implementation methods.
[0018] See Figure 1 The figure shows a driving device system provided in an embodiment of this application.
[0019] The drive system includes a first drive unit 100 and a second drive unit 200 that are redundant with each other. It should be understood that in the drive system, it is necessary to ensure that only one drive unit is in a working state at any given time; that is, when one drive unit is in a working state, the other drive unit is in a hot standby state. This embodiment of the application uses the first drive unit 100 as the main unit in a working state and the second drive unit 200 as a standby unit in a standby state as an example for illustration.
[0020] The first driving device 100 includes a first communication module 101 and a first controller 102, the first controller 102 being used to detect the status information of the first driving device 100. The second driving device 200 includes a second communication module 201 and a second controller 202; the second controller 202 being used to detect the status information of the second driving device 200.
[0021] This application does not specifically limit the types of the first and second driving devices. One possible implementation is that the first and second driving devices can be safety-grade absorption ball driving devices. For ease of understanding, the following embodiments use safety-grade absorption ball driving devices as an example for illustration.
[0022] Specifically, the status information includes normal status, alarm status, and fault status, where alarm status is an abnormal status that does not affect the driving function of the drive device, and fault status is an abnormal status that affects the driving function of the drive device. In one possible implementation, the first controller 102 and the second controller 202 can detect the status information of the first drive device 100 and the second drive device 200 respectively according to the table below.
[0023]
[0024] In one possible implementation, the first controller 102 can also be used to take corresponding processing measures based on the detected status information of the first drive device 100. For example, when the first drive device 100 is in a fault state, the first controller 102 is also used to display the current fault state through a digital tube or the like, and illuminate the fault indicator light while extinguishing the ready indicator light and the working indicator light; when the first drive device 100 is in an alarm state, the first controller 102 is also used to display the current alarm state through a digital tube or the like, and keep the indicator lights unchanged. The second controller 202 can also be used to take corresponding processing measures based on the detected status information of the second drive device 200. The processing measures are similar to those of the first controller 102 and will not be described in detail here.
[0025] When both the first drive device 100 and the second drive device 200 are in normal operation, the first communication module 101 is used to send a host signal to the second communication module 201 and receive a standby signal from the second communication module 201; the second communication module 201 is used to send a standby signal to the first communication module 101 and receive a host signal from the first communication module 101. The first controller 102 is also used to control the first communication module 101 to send a host signal and to control the first communication module 101 to receive a standby signal from the second communication module 201 when the first drive device 100 is in a normal state or an alarm state; and to control the first communication module 101 to send a standby signal when the first drive device 100 is in a fault state.
[0026] The second controller 202 is also used to control the second communication module 201 to receive the host signal from the first communication module 101; when the second communication module 201 receives the host signal from the first communication module 101, control the second communication module 201 to send the standby signal; when the second drive device 200 is in a normal state or an alarm state, and the second communication module 201 receives the standby signal from the first communication module 101, control the second communication module 201 to send the host signal.
[0027] To enable those skilled in the art to better understand the control logic of the first and second controllers, the switching logic is further explained below with reference to the accompanying drawings.
[0028] See Figure 2a The figure is a schematic diagram of the switching logic of a driving device provided in an embodiment of this application.
[0029] Specifically, when the first drive device 100 is in normal or alarm state, it can still perform its drive function. The first drive device 100 acts as the master, and the first controller 102 controls the first communication module 101 to send master signals and receive standby signals from the second communication module 201. It should be understood that when the first drive device 100 is in a master / standby readback / disconnection alarm state, it is possible that while the first drive device 100 remains the master, the first communication module 101 may fail to successfully send master signals or receive standby signals from the second communication module 201.
[0030] When the first drive unit 100 is in a faulty state, it cannot continue to perform normal drive functions. The first controller 102 controls the first communication module 101 to send a standby signal, thereby actively controlling the first drive unit 100 to be downgraded from the primary drive unit to a new standby drive unit, that is, the first drive unit 100 is downgraded from the working state to the standby state. It should be understood that after the first drive unit 100 is downgraded to a standby drive unit, the first controller 102 is also used to control the first communication module 101 to receive the primary drive signal from the second communication module 201.
[0031] The second drive unit 200 is a standby unit. When the second communication module 201 receives a master signal from the first communication module 101, it indicates that the first drive unit 100 is the master unit at this time. In order to ensure that only one drive unit is working, the second drive unit 200 remains a standby unit at this time, that is, the second controller 202 is used to control the second communication module 201 to send the master signal.
[0032] Even when the second drive device 200 is in normal or alarm state, it can still perform the drive function. When the second communication module 201 receives the standby signal from the first communication module 101, the second controller 202 controls the second communication module 201 to send the host signal to the first communication module 101, thereby upgrading the second drive device 200 from standby to the new host, that is, upgrading the second drive device 200 from standby state to working state, and the second drive device 200 performs the drive function.
[0033] It should be understood that after the second drive unit 200 becomes the master unit, the second controller 202 is also used to control the second communication module 201 to receive the standby signal from the first communication module 101. When the second drive unit 200 is in the master / standby readback / disconnection alarm state, there may be a situation where the second drive unit 200 is the master unit, but the second communication module 201 cannot successfully send the master signal or cannot successfully receive the standby signal from the first communication module 101.
[0034] To enable those skilled in the art to further understand the switching logic of the drive device provided in this application, the switching logic is further explained below in the form of a state machine with reference to the accompanying drawings.
[0035] See Figure 2b This figure is a schematic diagram of the switching logic of another driving device provided in an embodiment of this application.
[0036] Figure 2bIn this context, S0_INT indicates that the driver is in the initialization state, S1_STBY indicates that the driver is in the standby state, and S2_ACT indicates that the driver is in the master state. When the driver is in the standby state, it sends a standby signal; when the driver is in the master state, it sends a master signal.
[0037] Initially, the drive device is in the S0_INT state. When the drive device in the S0_INT state satisfies condition D1, the drive device changes from the S0_INT state to the S2_ACT state. When the drive device in the S0_INT state does not satisfy condition D1, the drive device changes from the S0_INT state to the S1_STBY state. When the drive device in the S2_ACT state satisfies condition D2, the drive device changes from the S2_ACT state to the S1_STBY state. When the drive device in the S1_STBY state satisfies condition D3, the drive device changes from the S1_STBY state to the S2_ACT state.
[0038] Among them, condition D1 includes: when the drive device is ready for the first time, it receives the standby signal of the peer drive device, or does not receive the master signal or standby signal of the peer drive device; condition D2 includes: the drive device detects its own fault, or the drive device receives the master signal of the peer drive device; condition D3 includes: the drive device receives the standby signal of the peer drive device, and the drive device itself is not faulty.
[0039] It should be understood that Figure 2b The switching logic of the drive unit shown applies to both the first drive unit and the second drive unit. When Figure 2b When the driving device shown is the first driving device, then its opposite driving device is the second driving device; when Figure 2b When the driving device shown is the second driving device, then its opposite driving device is the first driving device.
[0040] This application does not specifically limit the types of the first and second controllers, and they can be flexibly selected according to the actual application scenario. The first and second controllers can be field-programmable gate arrays (FPGAs), microcontroller units (MCUs), application-specific integrated circuits (ASICs), digital signal processors (DSPs), or control units with data processing and logic control capabilities such as complex programmable logic devices (CPLDs). For example, in this application embodiment, the first controller can be a first FPGA, and the second controller can be a second FPGA.
[0041] The drive system provided in this application includes a redundant first drive system and a second drive system. The first drive system is the primary drive system, and the second drive system is the backup drive system. The first drive system includes a first communication module and a first controller, and the second drive system includes a second communication module and a second controller. The first controller can detect the status of the first drive system, and the second controller can detect the status of the second drive system, including normal status, alarm status, and fault status. The controllers are used to execute different primary / backup switching logic based on the status of the drive system. This allows the drive system to switch between the primary and backup drive systems according to the current drive status, reducing the need for manual intervention when the drive system faces complex operating conditions, and achieving a high degree of automation. Moreover, the primary / backup switching logic of this drive system ensures that only one drive system is in operation at any given time, resulting in high reliability.
[0042] In one possible implementation, the first controller is further configured to control the first communication module to send a backup signal when the first drive device loses power or the first controller loses power.
[0043] See also Figure 1When the first drive device 100 or the first controller 102 loses power, the first controller 102 can temporarily supply power using its internal power supply. The first controller 102 is used to control the first communication module 101 to send a standby signal to the second communication module 201. When the second communication module 201 receives the standby signal from the first communication module 101, if the second drive device 200 is in a normal state or an alarm state, that is, the second drive device 200 can perform the drive function, then the second controller 202 is used to control the second communication module 201 to send a master signal to the first communication module 101, thereby upgrading the second drive device 200 from a standby device to a new master device, that is, upgrading the second drive device 200 from a standby state to a working state, and the second drive device 200 performs the drive function.
[0044] The drive device system provided in this application embodiment is further configured to control the first communication module to send a backup signal when the first drive device loses power or the first controller loses power, so that when the first drive device loses power, the second drive device can also be upgraded from a backup to a new host, ensuring that there is still a drive device in the system that is in working condition, and thus ensuring high reliability.
[0045] In one possible implementation, when the states of the first drive device and the second drive device do not meet the above switching logic, for example, when both the first drive device and the second drive device are in a fault state, the controller in the drive device system provided in the above embodiments cannot execute the master / standby switching logic in the above embodiments. At this time, manual intervention can be introduced into the drive device system to ensure the reliable operation of the drive device system.
[0046] In one possible implementation, before the first drive device is a host in a working state, the first controller is further configured to control the initialization of the first drive device and detect the status information of the first drive device. When the first drive device is in a normal state, the controller controls the first communication module to send a host signal to the second communication module. Before the second drive device is a standby device in a standby state, the second controller is further configured to control the initialization of the second drive device and detect the status information of the second drive device. When the second drive device is in a normal state, the controller controls the second communication module to receive the host signal from the first communication module and controls the second communication module to send a standby device signal to the first communication module.
[0047] See Figure 3 This figure is a schematic diagram of a master / slave switching in an initialization state provided in an embodiment of this application.
[0048] Specifically, after the first drive device is powered on or reset, the first controller controls the initialization of the first drive device and detects the current status information of the first drive device. When the first drive device is in a normal state, it indicates that the first drive device is ready, and the first controller is used to control the first communication module to send host signals to the second communication module.
[0049] After the second drive unit is powered on or reset, the second controller controls the initialization of the second drive unit and detects the current status information of the second drive unit. When the second drive unit is in a normal state, it indicates that the second drive unit is ready. The second controller is used to control the second communication module to receive the host signal from the first communication module. When the second communication module receives the host signal from the first communication module, the second controller confirms that the second drive unit is a standby unit, and the second controller is used to control the second communication module to send a standby unit signal.
[0050] In one possible implementation, before the first controller detects the current status information of the first drive device, the first controller is further configured to determine whether the first drive device has entered maintenance mode. If the first drive device is currently in maintenance mode, the first controller is configured to update the operating parameters of the first drive device. Similarly, before the second controller detects the current status information of the second drive device, the second controller is further configured to determine whether the second drive device has entered maintenance mode; this will not be elaborated further here.
[0051] In one possible implementation, the first controller is further configured to control the first drive device to re-enter the initialization state when the first drive device is not in a normal state; the second controller is further configured to control the second drive device to re-enter the initialization state when the second drive device is not in a normal state.
[0052] Specifically, the first controller controls the initialization of the first drive device, including initializing its own clock. If the clock is successfully reset, the initialization is successful. If the initialization fails, the first controller also controls the first drive device to re-initialize. The second controller controls the initialization of the second drive device, including initializing its own clock. If the clock is successfully reset, the initialization is successful. If the initialization fails, the second controller also controls the second drive device to re-initialize.
[0053] Based on the control logic of the first controller and the second controller provided in the above embodiments, this application provides a primary / backup allocation logic during the power-on initialization of the drive device.
[0054] See Figure 4 The figure is a power-on initialization flowchart of a drive device provided in an embodiment of this application.
[0055] Figure 4The power-on initialization process of the drive device shown includes the following steps: S401: Controller is powered on or reset.
[0056] S402: Controller internal clock initialization.
[0057] S403: The controller determines whether the internal clock reset initialization was successful. If yes, execute S404; otherwise, execute S402.
[0058] S404: The controller determines whether the drive unit has entered maintenance mode. If yes, execute S405; otherwise, execute S406.
[0059] S405: The controller updates the operating parameters of the drive unit.
[0060] S406: The controller checks whether the drive device is in a normal state. If yes, execute S407; otherwise, execute S408.
[0061] S407: Control the detection communication module to see if it receives a host signal. If yes, execute S409; if no, execute S410.
[0062] S408: Drive unit not ready, drive unit is standby.
[0063] S409: The controller sends a standby signal, indicating that the drive unit is a standby unit.
[0064] S410: The controller sends a host signal, and the drive device is the host.
[0065] In the drive device system provided in this application embodiment, the driver that initializes and sends the host signal first becomes the host. This drive device system can clearly define the host and standby allocation after the drive device is ready for the first time, reducing the situation where there are two hosts or two standbys in the system due to host contention.
[0066] This application does not specifically limit the types of master signals and standby signals; master signals and standby signals can be different signals that can be distinguished by the controller. For example, master signals and standby signals can be status signals with different codes, pulse signals with the same frequency but different duty cycles, or pulse signals with different frequencies. The following explanation uses pulse signals of different frequencies as an example.
[0067] For example, in this embodiment, the master signal is a pulse signal with a frequency of 1 kHz and a duty cycle of 50%, and the standby signal is a pulse signal with a frequency of 500 Hz and a duty cycle of 50%. To improve fault tolerance, pulse signals with frequencies between 800 Hz and 1200 Hz can be considered as master signals, and pulse signals with frequencies between 300 Hz and 700 Hz can be considered as standby signals.
[0068] In one possible implementation, the first controller is further configured to confirm that the pulse signal is a master signal or a backup signal by detecting the number of pulses of the pulse signal received by the first communication module within a time period; the second controller is further configured to confirm that the pulse signal is a master signal or a backup signal by detecting the number of pulses of the pulse signal received by the second communication module within a time period.
[0069] This application does not specifically limit the value of the time threshold; for example, the time period can be 10ms. The first controller detects the number of pulses of the received pulse signal within 10ms. For example, the number of pulses can be detected by detecting the number of falling edges of the pulse signal. If the first controller detects 8 to 12 falling edges of the pulse signal within 10ms, it can determine that the received pulse signal is a master signal; if the first controller detects 3 to 7 falling edges of the pulse signal within 10ms, it can determine that the received pulse signal is a master signal. When the pulse signal has neither 8 to 12 falling edges nor 3 to 7 falling edges, it is considered that the first communication module has not received a master signal or backup signal from the second communication module. The detection method of the second controller is similar to that of the first controller and will not be described again here.
[0070] In one possible implementation, to improve reliability, the first controller can be used to confirm whether a pulse signal is a master signal or a standby signal by counting the number of pulses received within multiple consecutive time periods. This application does not specifically limit the number of time periods; for example, the first controller can detect the pulse signal within three consecutive 10ms time periods.
[0071] The drive device system provided in this application embodiment has a controller that detects the number of falling edges of the pulse signal within a time period and confirms the received pulse signal by combining the pulse signal frequency range. This can effectively reduce the probability of signal detection failure caused by signal attenuation on the communication cable when the distance between the first drive device and the second drive device is far, thereby improving the accuracy and reliability of the drive device system status judgment.
[0072] This application does not specifically limit the types of the first and second communication modules, nor does it specifically limit the communication method between the first and second communication modules. In one possible implementation, in this embodiment, the first and second communication modules may include digital input and output interfaces, communicating via a DB25 line used by the driver device to interact with the distributed control system. The digital input and output interfaces can be implemented using optocoupler isolation and relay outputs, and the node type can be a passive dry contact, powered by the driver device receiving the signal, thereby ensuring the reliability and anti-interference capability of signal transmission. For example, the signal can be acquired through a HARTING DB25 connector and digitally filtered by an FPGA to effectively eliminate signal noise. Since no dedicated communication cables are required, the driver system provided in this embodiment can save hardware costs, reduce wiring complexity, and improve system integration.
[0073] In one possible implementation, the first driving device further includes a first driving module, and the second driving device further includes a second driving module.
[0074] See Figure 5 This figure is a schematic diagram of another driving device system provided in an embodiment of this application.
[0075] Figure 5 and Figure 1 The difference is that the first drive device 100 also includes a first drive module 103, and the first drive device 100 is connected to a power supply through the input terminal of the first drive module 103; the output terminal of the first drive module 103 is used to connect to a load.
[0076] The second drive device 200 also includes a second drive module 203, which is connected to a power source via its input terminal; the output terminal of the second drive module 203 is used to connect to a load. For example, the load can be a motor.
[0077] Based on the drive device system provided in the above embodiments, this application also provides a redundancy switching method. The redundancy switching method provided in this application is applied to the drive device system provided in this application. The drive device system includes: a first drive device and a second drive device that are redundant with each other; the first drive device is a host device in a working state, and the second drive device is a standby device in a standby state; the first drive device includes a first communication module and a first controller, and the second drive device includes a second communication module and a second controller.
[0078] See Figure 6 The figure is a flowchart of a redundancy switching method provided in an embodiment of this application.
[0079] The method includes: S601: Detect the status information of the first drive device; the status information includes normal status, alarm status and fault status, the alarm status is an abnormal status that does not affect the drive function, and the fault status is an abnormal status that affects the drive function; when the first drive device is in normal status or alarm status, control the first communication module to send the host signal, and when the first drive device is in fault status, control the first communication module to send the standby signal.
[0080] For example, the first controller detects the status information of the first drive device; the status information includes normal status, alarm status and fault status, the alarm status is an abnormal status that does not affect the drive function, and the fault status is an abnormal status that affects the drive function; when the first drive device is in normal status or alarm status, the controller controls the first communication module to send a host signal, and when the first drive device is in fault status, the controller controls the first communication module to send a standby signal.
[0081] S602: Detect the status information of the second drive device, and control the second communication module to send a standby signal when the second drive device is in a normal state; when the second drive device is in a normal state or an alarm state and the second communication module receives a standby signal from the first communication module, control the second communication module to send a master signal.
[0082] For example, the second controller detects the status information of the second drive device, and controls the second communication module to send a standby signal when the second drive device is in a normal state; when the second drive device is in a normal state or an alarm state and the second communication module receives a standby signal from the first communication module, it controls the second communication module to send a master signal.
[0083] In the above methods, S601 and S602 are not executed in any particular order.
[0084] The redundancy switching method provided in this application enables the drive system to switch between the primary and backup drives based on the current drive status, reducing the need for manual intervention when the drive system faces complex operating conditions and achieving a high degree of automation. Furthermore, this redundancy switching method ensures that only one drive unit is in operation at any given time, resulting in high reliability.
[0085] In one possible implementation, the method further includes: controlling the first communication module to send a backup signal when the first drive device loses power or the first controller loses power.
[0086] In one possible implementation, before the first driving device is a host in a working state, the method further includes controlling the first driving device to enter an initialization state and detecting the status information of the first driving device. When the first driving device is in a normal state, the method controls the first communication module to send a host signal to the second communication module. Before the second drive device is in standby mode, the system also includes controlling the second drive device to enter the initialization state and detecting the status information of the second drive device. When the second drive device is in normal state, the system controls the second communication module to receive the host signal from the first communication module. When the second drive device is not in normal state, the system controls the second drive device to re-enter the initialization state.
[0087] In one possible implementation, the master signal and the standby signal are pulse signals with different frequencies; The method further includes: confirming that the pulse signal is a master signal or a backup signal by detecting the number of pulses of the pulse signal received by the first communication module within a time threshold; and confirming that the pulse signal is a master signal or a backup signal by detecting the number of pulses of the pulse signal received by the second communication module within a time threshold.
[0088] It should be noted that the various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. The same or similar parts between the various embodiments can be referred to each other.
[0089] The above description of the disclosed embodiments enables those skilled in the art to make or use this application. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of this application. Therefore, this application is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A drive device system, characterized in that, include: A first drive unit and a second drive unit are redundant with each other; the first drive unit is the main unit in working state, and the second drive unit is the standby unit in standby state. The first driving device includes a first communication module and a first controller, and the second driving device includes a second communication module and a second controller; The first controller is used to detect the status information of the first drive device, and the second controller is used to detect the status information of the second drive device; the status information includes normal status, alarm status and fault status, the alarm status is an abnormal status that does not affect the drive function, and the fault status is an abnormal status that affects the drive function; The first controller is further configured to control the first communication module to send a host signal and receive a standby signal from the second communication module when the first drive device is in the normal state or the alarm state; and to control the first communication module to send a standby signal when the first drive device is in the fault state. The second controller is also configured to control the second communication module to receive the host signal from the first communication module and to control the second communication module to send the standby signal; when the second drive device is in the normal state or alarm state and the second communication module receives the standby signal from the first communication module, the controller controls the second communication module to send the host signal.
2. The drive device system according to claim 1, characterized in that, The first controller is further configured to control the first communication module to send a backup signal when the first drive device loses power or the first controller loses power.
3. The drive device system according to claim 2, characterized in that, Before the first driving device is a host in a working state, the first controller is also used to control the initialization of the first driving device and detect the status information of the first driving device. When the first driving device is in the normal state, the controller controls the first communication module to send the host signal to the second communication module. Before the second drive device is in standby mode, the second controller is further configured to: control the initialization of the second drive device and detect the status information of the second drive device; when the second drive device is in the normal state, control the second communication module to receive the host signal from the first communication module, and the second communication module sends the standby signal to the first communication module.
4. The drive device system according to claim 3, characterized in that, The first controller is further configured to control the first drive device to re-enter the initialization state when the first drive device is not in the normal state; the second controller is further configured to control the second drive device to re-enter the initialization state when the second drive device is not in the normal state.
5. The drive device system according to any one of claims 1 to 4, characterized in that, The host signal and the standby signal are pulse signals with different frequencies; The first controller is further configured to confirm that the pulse signal is the host signal or the backup signal by detecting the number of pulses of the pulse signal received by the first communication module within a time period; The second controller is further configured to confirm that the pulse signal is the host signal or the backup signal by detecting the number of pulses of the pulse signal received by the second communication module within a time period.
6. The drive device system according to any one of claims 1 to 4, characterized in that, The first driving device further includes a first driving module, and the first driving device is connected to a power supply through the input terminal of the first driving module; the output terminal of the first driving module is used to connect to a load. The second drive device further includes a second drive module, which is connected to a power source through the input terminal of the second drive module; the output terminal of the second drive module is used to connect to a load.
7. A redundancy switching method, characterized in that, The method is applied to a drive device system, which includes: a first drive device and a second drive device that are redundant with each other; the first drive device is a host device in a working state, and the second drive device is a standby device in a standby state; the first drive device includes a first communication module and a first controller, and the second drive device includes a second communication module and a second controller. The method includes: The status information of the first drive device and the second drive device is detected; the status information includes normal status, alarm status and fault status, the alarm status is an abnormal status that does not affect the drive function, and the fault status is an abnormal status that affects the drive function. When the first drive device is in the normal state or the alarm state, the first communication module is controlled to send a host signal and receive a standby signal from the second communication module; when the first drive device is in the fault state, the first communication module is controlled to send a standby signal. The system controls the second communication module to receive a host signal from the first communication module. When the second communication module receives the host signal from the first communication module, the system controls the second communication module to send a standby signal. When the second drive device is in the normal state or alarm state and the second communication module receives the standby signal from the first communication module, the system controls the second communication module to send the host signal.
8. The method according to claim 7, characterized in that, Also includes: When the first drive device loses power or the first controller loses power, the first communication module is controlled to send a backup signal.
9. The method according to claim 8, characterized in that, Before the first driving device is a host in the working state, the system further includes controlling the first driving device to enter the initialization state and detecting the status information of the first driving device. When the first driving device is in the normal state, the system controls the first communication module to send the host signal to the second communication module. Before the second drive device is a standby device in standby state, the system further includes controlling the second drive device to enter an initialization state and detecting the status information of the second drive device. When the second drive device is in the normal state, the system controls the second communication module to receive the host signal from the first communication module. When the second drive device is not in the normal state, control the second drive device to re-enter the initialization state.
10. The method according to any one of claims 7 to 9, characterized in that, The host signal and the standby signal are pulse signals with different frequencies; The method further includes: confirming that the pulse signal is the host signal or the backup signal by detecting the number of pulses of the pulse signal received by the first communication module within a time threshold; and confirming that the pulse signal is the host signal or the backup signal by detecting the number of pulses of the pulse signal received by the second communication module within a time threshold.