A ship direct-current integrated power system fault cooperative management method and system

Through real-time monitoring and arbitration rules of the energy management system, global fault collaborative management of the ship's DC integrated power system has been realized, which solves the problems of inaccurate fault assessment and delayed emergency response in the existing technology, and improves the system's operational reliability and safety.

CN122159163APending Publication Date: 2026-06-05SANDIANSHUI NEW ENERGY TECH (ANHUI) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
SANDIANSHUI NEW ENERGY TECH (ANHUI) CO LTD
Filing Date
2026-02-28
Publication Date
2026-06-05

AI Technical Summary

Technical Problem

In existing technologies, each subsystem of a ship's DC integrated power system handles faults independently, making it impossible to comprehensively assess the impact of faults by combining the system topology. This leads to an expansion of the fault scope, delays in emergency response, and scattered alarm information, making it difficult to adapt to the safe operation requirements of complex power systems.

Method used

The system uses an energy management system as the central hub to monitor fault information of each subsystem in real time. It also uses series, parallel, hybrid, and priority arbitration rules to accurately map the fault level of the entire ship, generate collaborative control commands, drive the subsystems to perform collaborative operations, and display the fault correlation through a human-machine interaction unit.

Benefits of technology

It achieves global linkage control across subsystems, avoids the escalation of local faults, improves the accuracy of fault handling and the reliability of system operation, shortens emergency response time, and enhances the intelligence level and navigation safety of the ship's DC integrated power system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122159163A_ABST
    Figure CN122159163A_ABST
Patent Text Reader

Abstract

The application discloses a kind of ship direct current comprehensive power system fault coordination management method and system.The method includes: multiple subsystems real-time monitoring own operating state, and when triggering fault, to energy management system, report fault information including self-determination local fault level;Energy management system is based on the electrical connection topological relationship between each subsystem and its function importance, by the arbitration rule received each local fault level is comprehensively analyzed, to determine the whole ship fault level;According to the whole ship fault level, generate coordination control instruction, and issue coordination control instruction to target subsystem, to drive target subsystem to execute the coordinated operation matched with the whole ship fault level, and send fault information, whole ship fault level and processing state information to man-machine interaction unit, by man-machine interaction unit, the correlation of multiple faults is integrated and displayed.The application realizes the global fault coordination management with energy management system as the center.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of ship power management technology, and more specifically, relates to a method and system for collaborative fault management of a ship DC integrated power system. Background Technology

[0002] With the rapid development of intelligent and electric ship technologies, the application of DC integrated power systems in the marine field is becoming increasingly widespread, significantly increasing the complexity of system integration. A typical marine DC integrated power system usually includes several core subsystems such as a battery management subsystem (e.g., a battery management system, BMS), a DC-DC converter subsystem (e.g., a DC-DC converter), a motor control subsystem (e.g., a motor inverter, MCU), a propulsion control subsystem (e.g., a propulsion control system, PCS), a daytime inverter subsystem (e.g., a daytime inverter), and a DC charging subsystem (e.g., a DC 24V charger). These subsystems are interconnected through complex electrical topologies. For example, the battery management subsystem forms a series power supply link with the DC-DC converter subsystem, propulsion control subsystem, and motor control subsystem, while the propulsion and power supply systems on both sides form parallel redundant branches, jointly ensuring the ship's power output and daily power supply.

[0003] Currently, each of the aforementioned core subsystems is independently configured with a fault monitoring unit, capable of monitoring only its own operating status (such as battery condition, power conversion parameters, motor control signals, and power supply voltage) from a single dimension. When a fault is triggered, each subsystem can only autonomously execute local protective actions based on a preset local fault level. For example, the battery management subsystem may disconnect the battery pack circuit, the DC-DC converter subsystem may shut down due to overvoltage, the motor control subsystem may interrupt power output, and the daytime inverter subsystem may stop supplying power due to overload. These actions are then distributed and alerted through their respective independent alarm components.

[0004] However, this decentralized and independent fault handling method has the following drawbacks: First, there is a lack of standardized cross-system collaborative communication mechanisms between subsystems, and a fault linkage logic based on the overall ship operational status has not been formed. The Energy Management System (EMS), as the core management hub of the ship, has not yet been involved in the overall management of faults, and cannot comprehensively assess the impact range and cumulative effects of dispersed faults by combining system topology relationships. For example, during a ship's voyage, if the motor control subsystem on one side triggers a power interruption fault, the battery management subsystem on the same side, without receiving a coordination command, continues to maintain high-voltage output, causing the power devices on the faulty side to continuously experience overcurrent surges, thus expanding the fault range.

[0005] Secondly, existing technologies do not fully consider the series / parallel topology relationships between subsystems in a DC integrated power system. On the one hand, when an upstream subsystem in a series link (such as the DC-DC converter subsystem) triggers a fault, existing technologies only allow that subsystem to perform protection actions independently, without considering the impact on the power supply to downstream subsystems (such as the daytime inverter subsystem), which may lead to abnormal power supply to critical loads. For example, if a single-sided DC-DC converter subsystem on a ship triggers a power limiting fault, the downstream daytime inverter subsystem may be unable to maintain its output voltage due to insufficient input power, causing fluctuations in the power supply voltage to critical loads such as navigation and communication. On the other hand, when multiple subsystems in a parallel redundant design (such as the propulsion subsystems on both sides or multiple parallel battery management subsystems) trigger minor faults simultaneously, due to the lack of global assessment, the system may misjudge it as a serious fault and cut off the high voltage across the entire ship, causing unnecessary shutdowns and reducing system availability.

[0006] Furthermore, each subsystem is equipped with an independent alarm unit, requiring operators to switch between multiple human-machine interfaces to view fault information. For example, if the battery management subsystem alarm (battery overheating), DC-DC converter subsystem alarm (output overvoltage), and propulsion control subsystem alarm (power limitation) occur simultaneously during ship navigation, operators cannot quickly obtain the causal relationship of "battery overheating → DC-DC output overvoltage → propulsion power limitation," nor can they know the scope of the fault's impact on the ship's overall power and power supply, as well as the current progress of the handling, leading to delays in emergency response.

[0007] In summary, existing fault handling methods suffer from fragmentation and are ill-suited to the safe operation requirements of complex DC integrated power systems. There is an urgent need for a solution that can achieve centralized and collaborative management of faults across the entire ship. Summary of the Invention

[0008] The purpose of this invention is to propose a collaborative fault management method and system for a ship's integrated DC power system, which solves the technical problems in the prior art where each subsystem of the ship's integrated DC power system handles faults independently, cannot comprehensively assess the impact of faults in conjunction with the system topology, and suffers from delayed emergency response due to scattered alarm information. The invention achieves global collaborative fault management with the energy management system as the central hub, realizes accurate mapping of fault levels and cross-subsystem collaborative control through arbitration rules based on topological relationships and functional importance, and improves fault perception efficiency and ship operational reliability through integrated display of the human-machine interaction unit.

[0009] To achieve the above objectives, in a first aspect, the present invention proposes a fault collaborative management method for a shipboard integrated DC power system, applicable to an integrated DC power system comprising an energy management system and multiple subsystems, including: Multiple subsystems monitor their own operating status in real time and, when a fault is triggered, report fault information, including the local fault level determined by the system itself, to the energy management system. The energy management system, based on the electrical connection topology and functional importance of each subsystem, performs a comprehensive analysis of the received local fault levels through preset arbitration rules to determine the overall ship fault level. The energy management system generates collaborative control commands based on the overall ship fault level and sends the collaborative control commands to the target subsystem to drive the target subsystem to perform collaborative operations that match the overall ship fault level. It also sends the fault information, overall ship fault level, and processing status information to the human-machine interaction unit, which integrates and displays the correlation between multiple faults.

[0010] Optionally, the preset arbitration rules include: Series rule: For multiple subsystems in a series electrical connection topology, the overall ship fault level is the highest local fault level in the series electrical connection topology, which is increased by a preset level; Parallel connection rule: For multiple subsystems in a parallel electrical connection topology, the overall ship fault level is the highest among all local fault levels in the parallel electrical connection topology; Hybrid rule: For multiple subsystems in a hybrid electrical connection topology, i.e. a complex topology that simultaneously contains series and parallel relationships, the overall ship fault level is first determined according to the series rule, and then the final overall ship fault level is determined according to the parallel rule. Priority rule: When multiple subsystems belong to different functional importance levels, the overall ship failure level is determined based on the local failure level corresponding to the subsystem with the highest functional importance.

[0011] Optionally, the functional importance hierarchy, from highest to lowest, includes: The propulsion system is structured at the level of motor control and propulsion control. The main power supply electronic system level corresponds to multiple battery management subsystems and multiple DC-DC conversion subsystems; The auxiliary power supply system level corresponds to the daily inverter subsystem and the DC charging subsystem.

[0012] Optionally, the energy management system generates coordinated control commands based on the overall ship fault level, including: Query the pre-stored collaborative instruction mapping table, in which different ship-wide fault levels are associated with standard instruction content issued to each of the subsystems; The standard instructions include one or more combinations of power limiting instructions, torque limiting instructions, high voltage cut-off instructions, high voltage maintenance instructions, and operating mode switching instructions.

[0013] Optionally, it also includes: The energy management system receives the execution results fed back by the target subsystem and verifies whether the execution results meet the preset requirements; If the verification fails, the energy management system executes a fault-tolerant processing procedure, which includes: repeatedly issuing the collaborative control command; if the number of repetitions exceeds a preset threshold and the target is still not met, the current ship-wide fault level is raised by one level, and a new collaborative control command matching the raised level is generated.

[0014] Optionally, the human-computer interaction unit integrates and displays the correlation between multiple faults, including: The system displays the causal relationships, impact scope, and processing progress among multiple faults. Based on the overall ship fault level, sound and light alarms are triggered according to the preset graded alarm mode. The causal relationship between the multiple faults is determined by the energy management system based on the electrical connection topology between the subsystems and fault parameters, and then sent to the human-machine interaction unit for display.

[0015] Optionally, the fault information is transmitted to the energy management system via a hybrid communication network; The energy management system communicates with the propulsion control subsystem, DC-DC converter subsystem, day-use inverter subsystem, and DC charging subsystem via Ethernet; the energy management system communicates with the battery management subsystem via a controller area network bus; and the propulsion control subsystem communicates with the motor control subsystem via a controller area network bus.

[0016] Optionally, the preset level is level one, and the upgraded ship-wide fault level does not exceed the predefined highest fault level.

[0017] Optionally, the fault information may also include subsystem identifier, fault parameters, and fault location.

[0018] Secondly, this invention proposes a fault collaborative management system for a ship's integrated DC power system, comprising: Multiple subsystems, each of which has a built-in fault monitoring module for real-time monitoring of its own operating status and reporting fault information including the local fault level determined by the system itself when a fault is triggered; The energy management system, which is communicatively connected to each of the subsystems, receives the fault information. Based on the electrical connection topology and functional importance of each subsystem, it performs a comprehensive analysis of the received local fault levels using preset arbitration rules to determine the overall ship fault level. It then generates a coordinated control command based on the overall ship fault level and sends the command to the target subsystem to drive it to perform a coordinated operation matching the overall ship fault level. Finally, it sends the fault information, the overall ship fault level, and the processing status information to the human-machine interface unit. The human-machine interaction unit is communicatively connected to the energy management system and is used to receive and display the fault information, the fault level of the entire ship and the processing status information, and to integrate and display the correlation between multiple faults.

[0019] The beneficial effects of this invention are as follows: By using the energy management system as the centralized control hub, it receives fault information reported by each subsystem in real time, including information on the local fault level determined autonomously. Based on the electrical connection topology and functional importance between subsystems, it uses preset series, parallel, mixed, and priority arbitration rules to comprehensively analyze the local fault level, accurately mapping the overall ship fault level that reflects the actual risk of the entire ship. This overcomes the technical defects of existing technologies where each subsystem handles faults independently and cannot comprehensively assess the impact of faults in conjunction with the system topology. By generating and issuing standardized collaborative control commands based on the overall ship fault level, it drives the target subsystem to perform collaborative operations such as power limiting and high-voltage cutoff, realizing global linkage control across subsystems. This avoids the expansion of the impact range of local faults due to a lack of coordination, improving the accuracy of fault handling and the reliability of system operation. By sending fault information, overall ship fault level, and processing status information to the human-machine interaction unit, which integrates and displays the causal relationship, impact range, and processing progress of multiple faults, it solves the problem of scattered alarm information and the inability to quickly obtain fault correlations. This significantly shortens the emergency response time of operators and effectively improves the intelligence level and navigation safety of the ship's DC integrated power system.

[0020] The system of the present invention has other features and advantages that will be apparent from or will be set forth in detail in the accompanying drawings and following detailed description, which together serve to explain the particular principles of the invention. Attached Figure Description

[0021] The above and other objects, features and advantages of the present invention will become more apparent from the accompanying drawings, in which like reference numerals generally denote like parts.

[0022] Figure 1 A flowchart illustrating the steps of a shipboard DC integrated power system fault collaborative management method according to Embodiment 1 of the present invention is shown.

[0023] Figure 2 A schematic diagram of a DC integrated power system including an energy management system and multiple subsystems according to Embodiment 1 of the present invention is shown.

[0024] Figure 3 A schematic diagram of the fault collaborative management system architecture according to Embodiment 1 of the present invention is shown.

[0025] Figure 4 A schematic diagram of the system communication network connection according to Embodiment 1 of the present invention is shown. Detailed Implementation

[0027] The invention will now be described in more detail with reference to the accompanying drawings. While preferred embodiments of the invention are shown in the drawings, it should be understood that the invention can be implemented in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided so that the invention will be thorough and complete, and will fully convey the scope of the invention to those skilled in the art.

[0028] Example 1

[0029] like Figure 1 As shown, this embodiment provides a fault collaborative management method for a ship's integrated DC power system, applicable to an integrated DC power system comprising an energy management system and multiple subsystems, such as... Figure 2 As shown, it includes: S1. Multiple subsystems monitor their own operating status in real time and report fault information, including the local fault level determined by the system itself, to the energy management system when a fault is triggered. Specifically, multiple subsystems monitor their own operating status in real time and, upon triggering a fault, report fault information, including the locally determined fault level, to the energy management system. These subsystems include the 1#-n# Battery Management Subsystem (BMS), the 1#-n# DC-DC Conversion Subsystem (DC-DC converter), the Motor Control Subsystem (left and right MCUs), the Propulsion Control Subsystem (left and right PCS), the Day-use Inverter Subsystem (left and right day-use inverters), and the DC Charging Subsystem (24V DC charger). Each subsystem's built-in fault monitoring module continuously collects its operating parameters, including but not limited to voltage, current, temperature, insulation resistance, power, torque, control signals, and communication status. Each subsystem has a preset local fault level definition that matches its functional characteristics. Each local fault level is associated with a corresponding basic action and specific fault scenario examples, as shown in Tables 1-6. When any subsystem detects that its operating parameters exceed the preset normal threshold range or an abnormal state occurs, it determines that a fault has been triggered and autonomously determines the local fault level based on the preset fault level definition. Subsequently, the subsystem will report fault information, including subsystem identifier, autonomously determined local fault level, fault parameters, and fault location, to the energy management system in real time via Ethernet or controller area network bus, providing a data foundation for subsequent ship-wide fault level arbitration and collaborative control.

[0030] Table 1. Local Fault Level Definition Table for Battery Management Subsystem

[0031] Table 2. Local Fault Level Definition Table for Propulsion Control Subsystem

[0032] Table 3. Local Fault Level Definition Table for Motor Control Subsystem

[0033] Table 4. Local Fault Level Definition Table for DC-DC Conversion Subsystem

[0034] Table 5. Local Fault Level Definition Table for Daily Inverter Subsystem

[0035] Table 6. Definition of Local Fault Levels in DC Charging Subsystem

[0036] In this step, the fault information also includes the subsystem identifier, fault parameters, and fault location.

[0037] Specifically, the fault information reported by the subsystems includes not only the local fault level but also the subsystem identifier, fault parameters, and fault location. The subsystem identifier uniquely identifies the source of the fault, including the subsystem type identifier (e.g., BMS, DC-DC, MCU) and instance number (e.g., 1#BMS, left MCU), facilitating the energy management system's accurate identification of the specific subsystem where the fault occurred. Fault parameters are key operational data that triggered the fault, including specific values ​​exceeding limits and their trends, such as battery temperature 68℃, voltage deviation 0.2V, insulation resistance 500MΩ, and output power 50kW. These parameters provide quantitative basis for the energy management system to conduct fault impact assessments and arbitration decisions. The fault location indicates the specific location where the fault occurred, such as the battery pack module number, power module location, or circuit board unit, facilitating rapid fault location and repair by subsequent maintenance personnel. By reporting this complete information, the energy management system can comprehensively grasp the details of each fault, providing sufficient data support for subsequent ship-wide fault level arbitration based on topology and functional importance, generation of collaborative control commands, and integrated display of the human-machine interface unit.

[0038] S2. The energy management system, based on the electrical connection topology and functional importance between subsystems, performs a comprehensive analysis of the received local fault levels through preset arbitration rules to determine the overall ship fault level. Specifically, after the energy management system collects the local fault levels and fault information reported by each subsystem, it enters the core arbitration stage of the overall ship fault level assessment. This step is not a simple summary or numerical comparison of the fault levels of each subsystem, but a comprehensive analysis process that deeply integrates the physical architecture characteristics and functional safety logic of the ship's DC integrated power system. The energy management system has a pre-stored electrical connection topology diagram of the entire system, such as... Figure 2As shown, the series relationships between the subsystems are clearly defined, such as the unidirectional energy transmission link formed by the battery management subsystem, DC-DC conversion subsystem, propulsion control subsystem, and motor control subsystem, as well as the parallel relationships, such as the redundant backup structure formed by the left and right propulsion systems and multiple battery management subsystems. Simultaneously, the system also has a pre-defined hierarchical system based on functional safety importance, dividing the subsystems into propulsion system level, main power supply system level, and auxiliary power supply system level. Based on this, the energy management system initiates a preset four-dimensional arbitration rule for level mapping: First, a series rule is applied, where for multiple faults in the same series link, the highest local fault level in the link is raised by a preset level to reflect the superposition and amplification effect of the fault along the energy flow; then, a parallel rule is applied, where for multiple faults in a parallel redundant topology, the highest value of the local fault level among all parallel branches is taken as the level of the parallel region, ensuring that the value of the redundancy design is realized; when the system has both series and parallel relationships, a hybrid rule is initiated, first calculating the superposition level of each series branch according to the series rule, and then taking the highest value among the superposition levels of all branches according to the parallel rule as the final ship-wide fault level; finally, when the fault involves subsystems at different functional importance levels, a priority rule is initiated, using the local fault level corresponding to the highest-level subsystem as the benchmark for the final comprehensive determination of the ship-wide fault level. Through the sequential application and comprehensive consideration of the above rules, the energy management system ultimately outputs a ship fault level that can truly reflect the impact of the current fault on the ship's power, power supply and safe operation. This level is usually uniformly divided into six levels, which are connected with the local fault level system of each subsystem, laying a scientific basis for the subsequent generation of accurate collaborative control commands.

[0039] In this step, the preset arbitration rules include: Series rule: For multiple subsystems in a series electrical connection topology, the overall ship fault level is the highest local fault level in the series electrical connection topology, which is increased by a preset level; Parallel rule: For multiple subsystems in a parallel electrical connection topology, the overall ship fault level is the highest among all local fault levels in the parallel electrical connection topology; Hybrid rule: For multiple subsystems in a hybrid electrical connection topology, i.e., a complex topology that simultaneously contains series and parallel relationships, the overall ship fault level is initially determined according to the series rule, and then the final overall ship fault level is determined according to the parallel rule. Priority rule: When multiple subsystems belong to different functional importance levels, the overall ship failure level is determined based on the local failure level of the subsystem with the highest functional importance.

[0040] Specifically, in determining the overall ship fault level, the energy management system does not simply aggregate or take the maximum value of the local fault levels reported by each subsystem. Instead, it conducts a comprehensive analysis based on a set of pre-defined multi-dimensional arbitration rules. These rules deeply integrate the system's physical topology and functional safety logic, ensuring that the arbitration results accurately reflect the actual impact of the fault on the ship's operation. Specifically, these rules include the following four core rules: Series connection rules apply to multiple subsystems within the same electrical series topology. In a DC integrated power system, a typical series link is "battery management subsystem → DC-DC converter subsystem → propulsion control subsystem → motor control subsystem." Its characteristic is unidirectional energy flow; a fault in any link directly affects the energy supply to downstream equipment. When multiple subsystems in the same series link simultaneously trigger faults, their overall impact on the system is not a simple sum of individual faults, but rather a cumulative amplification effect. Therefore, series connection rules stipulate that the overall ship fault level corresponding to the series branch should be based on the highest local fault level in that branch, increased by a preset level (usually level one). For example, when the battery management subsystem reports a level four fault, and its downstream DC-DC converter subsystem simultaneously reports a level two fault, the overall ship fault level is determined to be level five, reflecting the cumulative damage risk of series faults to the energy transmission link.

[0041] Parallel topology rules apply to multiple subsystems within a parallel electrical connection topology. In marine electrical systems, parallel topology is widely used for redundancy design, such as two independent propulsion systems on the port and starboard sides, or multiple parallel battery management subsystems. Parallel branches serve as backups for each other; a fault in a single branch typically does not lead to a complete loss of system function, and non-faulty branches can continue to bear the load. Therefore, parallel topology rules stipulate that for multiple faults in a parallel topology, the overall ship fault level is the highest value among the local fault levels of all parallel branches, without aggregation. For example, when the port propulsion system reports a level 3 fault and the starboard propulsion system reports a level 4 fault, the overall ship fault level is determined to be level 4. This rule ensures that the value of redundancy design is fully realized, avoiding the erroneous increase in the overall ship risk level due to the normal operation of non-faulty sides.

[0042] Hybrid rules are used to handle complex topology scenarios that simultaneously involve series and parallel relationships. Actual ship electrical systems often have a hybrid structure interwoven with series and parallel connections. For example, the port and starboard propulsion systems may each have series links internally, while the two systems form parallel redundancy between each other. For such hybrid topologies, hybrid rules specify a step-by-step processing logic: First, the superposition level within each series branch is calculated according to the series rules; then, each series branch is treated as a parallel relationship, and the highest value among all branch superposition levels is taken as the final ship-wide fault level according to the parallel rules. For example, if the port propulsion link (battery → DC-DC → PCS → MCU) has a superposition level of four after calculation using the series rules, and the port propulsion link has a superposition level of five, then the ship-wide fault level is five. This rule ensures that the hybrid topology considers both the superposition effect within links and the redundancy relationship between branches, achieving a globally optimal risk assessment.

[0043] Prioritization rules apply when multiple faults belong to different functional importance levels. In a ship's integrated DC power system, the impact of each subsystem on navigation safety varies significantly. Therefore, the system pre-classifies subsystems into three levels: propulsion system (highest), main power supply system (medium), and auxiliary power supply system (lower). When a fault involves subsystems at different levels, the priority rules stipulate that the overall ship fault level is determined based on the local fault level of the subsystem with the highest functional importance. For example, if the auxiliary-level DC charging subsystem reports a level four fault, while the propulsion-level motor control subsystem only reports a level three fault, the overall ship fault level is determined by the propulsion-level level three. This rule ensures that limited control resources prioritize core functions, avoiding excessive restrictions on critical system operation due to faults in secondary systems.

[0044] The four rules mentioned above work together in a hierarchical and progressive manner to form a complete ship-wide fault level arbitration logic. In practical applications, the energy management system, based on the received fault information, first identifies the subsystem to which each fault belongs, its location in the topology, and its functional level. Then, it sequentially applies series rules, parallel rules, mixed rules, and priority rules for comprehensive evaluation, ultimately outputting a ship-wide fault level that accurately reflects the impact of the current fault on the overall ship's operational safety, providing a scientific basis for the generation of subsequent coordinated control commands.

[0045] In this step, the functional importance hierarchy, from highest to lowest, includes: The propulsion system is structured at the level of motor control and propulsion control. The main power supply electronic system level corresponds to multiple battery management subsystems and multiple DC-DC conversion subsystems; The auxiliary power supply system level corresponds to the daily inverter subsystem and the DC charging subsystem.

[0046] Specifically, in the ship-wide failure level arbitration rules, the functional importance hierarchy is the foundation for implementing the priority rule. Its purpose is to determine the overall ship failure level based on the subsystem with the most critical impact on the ship's operational safety when multiple subsystems belonging to different levels fail simultaneously, ensuring that limited control resources prioritize core functions. Specifically, based on the functional positioning of each subsystem within the ship's integrated DC power system and its impact on navigation safety, they are divided into the following three levels from highest to lowest: The propulsion system level is given the highest functional importance. This level corresponds to the motor control subsystem and the propulsion control subsystem, both directly responsible for the ship's power output and navigation control. The propulsion control subsystem, as the management core of the propulsion system, is responsible for receiving navigation commands and coordinating the operation of the motor control unit; the motor control subsystem directly drives the motors and is the final execution unit for ship navigation. Any failure affecting the propulsion system level will directly jeopardize the ship's navigation capability. Therefore, in the event of multiple concurrent failures, the overall ship failure level should be determined based on the failure level of this level.

[0047] The main power supply system ranks second. This level corresponds to multiple battery management subsystems and multiple DC-DC conversion subsystems. The battery management subsystem is responsible for monitoring and managing the operating status of the battery pack, ensuring the safety and availability of the energy storage system; the DC-DC conversion subsystem converts the high-voltage DC power output from the battery pack into a voltage level suitable for downstream equipment, providing a stable power supply for the entire ship. The main power supply system is the energy source for the propulsion system and auxiliary power supply system. Although its failure does not directly cause the ship to lose navigation, it will indirectly affect downstream equipment through power limiting or output cutoff; therefore, its importance is second only to the propulsion system.

[0048] The auxiliary power supply system ranks third in the hierarchy. This hierarchy corresponds to the daily inverter subsystem and the DC charging subsystem. The daily inverter subsystem converts the DC bus voltage to AC power to supply daily loads such as ship lighting, navigation, and communication; the DC charging subsystem is responsible for providing power to the 24V DC control system and instrumentation equipment. Failures in the auxiliary power supply system primarily affect crew comfort and the operation of auxiliary equipment. In emergencies, non-essential loads can be disconnected to ensure priority operation of the propulsion and main power supply systems; therefore, its functional importance is relatively low.

[0049] By classifying the functional importance levels as described above, the energy management system can accurately identify which subsystem's fault level should be used as the benchmark for ship-wide arbitration when multiple faults occur concurrently and involve different levels, ensuring that the fault response strategy matches the system's safety requirements.

[0050] In this step, the preset level is Level 1, and the upgraded ship-wide fault level does not exceed the predefined highest fault level.

[0051] Specifically, in the ship-wide fault level arbitration rules, the preset level value and the constraint of the level upper limit are key technical elements to ensure that the arbitration result can sensitively reflect the superposition effect of series faults without exceeding the system safety boundary. Specifically, the preset level is set to level one, based on a quantitative analysis of the impact of fault propagation in series links: In a DC integrated power system, multiple subsystems on the same series link (such as the battery management subsystem, DC-DC converter subsystem, propulsion control subsystem, etc.) have a unidirectional dependence on energy flow. When multiple subsystems on the link fail simultaneously, their impact on downstream equipment and the overall ship operation is not simply additive, but rather exhibits a superimposed amplification effect. Raising the highest local fault level by one level can more accurately characterize the actual risk level after this superposition. At the same time, it is clearly stipulated that the upgraded ship-wide fault level must not exceed the system's predefined highest fault level (usually level six). This aims to maintain the inviolability of the safety boundary; the highest level corresponds to catastrophic faults (such as immediate disconnection of the entire ship's high voltage). Any value exceeding this level has no engineering significance and may disrupt the integrity of the coordinated command mapping table, leading to control logic chaos. It should be emphasized that the above-mentioned "preset level is level one" and "maximum fault level is level six" are preferred embodiments of the present invention. In practical applications, the preset level and the maximum level can be flexibly calibrated and adjusted by configuring software according to different ship types, safety level requirements or system architectures, so that the technical solution can be adapted to various specifications of DC integrated power systems, further enhancing its universality and engineering applicability.

[0052] S3. The energy management system generates collaborative control commands based on the overall ship fault level and sends the collaborative control commands to the target subsystem to drive the target subsystem to perform collaborative operations that match the overall ship fault level. It also sends fault information, overall ship fault level and processing status information to the human-machine interaction unit, which integrates and displays the correlation between multiple faults.

[0053] Specifically, after the energy management system determines the overall ship fault level through arbitration rules, the system immediately enters the stage of generating and issuing collaborative control commands, and simultaneously initiates a unified alarm and information integration process. The fault collaborative management system architecture is as follows: Figure 3As shown. First, the energy management system uses the overall ship fault level as an index to query the internally stored collaborative instruction mapping table. This table predefines the standard instruction content to be issued to various types of subsystems for each overall ship fault level. Depending on the overall ship fault level, the instruction content may include one or more combinations of power limiting instructions, torque limiting instructions, high voltage cut-off instructions, high voltage maintenance instructions, and operating mode switching instructions. These instructions together constitute a collaborative control instruction set matching that level. For example, when the overall ship fault level is level four, the collaborative instruction set may include: issuing a high voltage cut-off instruction to the faulty side battery management subsystem and a high voltage maintenance instruction to the non-faulty side battery management subsystem; issuing a pipe shut-off instruction to the faulty side propulsion control subsystem and motor control subsystem, while simultaneously issuing a torque compensation instruction to the non-faulty side propulsion control subsystem and motor control subsystem; issuing an output cut-off instruction to the faulty side DC-DC converter subsystem and daytime inverter subsystem, and issuing a power limiting instruction to the non-faulty side similar subsystems; issuing a power limiting instruction to the DC charging subsystem, etc.

[0054] After generating coordinated control commands, the energy management system distributes these commands to each target subsystem in real time via a hybrid communication network. Upon receiving the commands, each target subsystem immediately parses and executes the corresponding coordinated operations, such as adjusting output power, limiting torque, cutting off high voltage, or switching operating modes, and feeds back the execution results to the energy management system. Simultaneously, the energy management system packages the received raw fault information, the ship-wide fault level determined through arbitration, and the current processing status information (such as commands issued and command execution progress), and sends it to the human-machine interface unit via the communication network.

[0055] Upon receiving the aforementioned information, the human-machine interface (HMI) unit initiates an integrated display of the relationships between multiple faults. Specifically, based on the causal relationships provided by the energy management system (identified by the energy management system according to topological relationships and fault parameters), the HMI unit displays the inherent connections between multiple faults in a causal chain format on the interface, such as "battery overheating → DC-DC output overvoltage → propulsion power limitation." It also dynamically marks the location and impact range of each fault on the system topology diagram, and displays the processing progress of each fault using progress bars or status labels. Furthermore, the HMI unit triggers preset graded audible and visual alarms based on the overall ship fault level. For example, in the case of a level four fault, a flashing yellow indicator light illuminates and a continuous buzzer sounds, while emergency suggestions are displayed prominently on the screen. Through this integrated display, operators can quickly obtain a comprehensive overview of the faults, understand the causal relationships between faults, and grasp the processing progress without switching between multiple HMI interfaces, thereby significantly improving emergency response efficiency and ship operational safety.

[0056] In this step, the energy management system generates coordinated control commands based on the overall ship fault level, including: Query the pre-stored collaborative instruction mapping table. The collaborative instruction mapping table is associated with different ship-wide fault levels and contains standard instruction content issued to each subsystem. The standard instructions include one or more combinations of power limiting instructions, torque limiting instructions, high voltage cut-off instructions, high voltage maintenance instructions, and operating mode switching instructions.

[0057] Specifically, after the energy management system determines the overall ship fault level through arbitration rules, the system immediately enters the stage of generating coordinated control commands. This process is not an isolated response to a single fault, but rather based on a standardized mapping relationship between the overall ship fault level and the control requirements of each subsystem, achieved by querying a pre-stored coordinated command mapping table. The coordinated command mapping table is a core decision database pre-stored in the energy management system, which establishes the correspondence between different overall ship fault levels and the standard command content issued to each type of subsystem, as shown in Table 7. The construction of this mapping table is based on an in-depth analysis of the operating characteristics of the ship's DC integrated power system, combined with the functional characteristics of each subsystem, fault response requirements, and overall ship safety operation requirements, ensuring that each overall ship fault level has a matching set of standardized coordinated commands.

[0058] Once the overall ship fault level is determined, the energy management system immediately uses that level as an index to query the collaborative instruction mapping table and quickly retrieve the standard instructions corresponding to that level. These instructions are not isolated commands for a single subsystem, but rather a set of collaborative instructions covering multiple related subsystems, ensuring that all subsystems on the ship perform unified collaborative operations under the same overall ship fault level. For example, when the overall ship fault level is level three, the collaborative instruction mapping table might include: issuing power limiting instructions to all battery management subsystems, limiting discharge power to 50% of the rated value; issuing power limiting instructions to all DC-DC conversion subsystems, limiting output power to 50% of the rated value; issuing torque limiting instructions to all propulsion control subsystems and motor control subsystems, limiting output torque to 50% of the rated value; issuing power limiting instructions to all daytime inverter subsystems, limiting inverter power to 50% of the rated value; issuing power limiting instructions to the DC charging subsystem, limiting output power to 50% of the rated value; and simultaneously issuing corresponding alarm display instructions to the human-machine interface unit. This standardized instruction set design ensures that regardless of which subsystem the fault occurs in, as long as the overall ship fault level is the same, all subsystems will perform unified coordinated operations, simplifying the control logic and improving the predictability and reliability of the system.

[0059] The standard commands defined in the collaborative command mapping table include various types, which can be combined and applied according to actual fault scenarios. Power limiting commands are used to limit the output power of a subsystem to a certain percentage of its rated value. They are suitable for scenarios requiring reduced system load and prevention of fault escalation, such as those received by the battery management subsystem, DC-DC converter subsystem, and daytime inverter subsystem. Torque limiting commands are specifically used for the propulsion control subsystem and motor control subsystem, controlling the ship's propulsion power by limiting output torque. They are suitable for fault scenarios requiring reduced speed and power load. High-voltage cutoff commands are used to cut off the high-voltage output of the battery management subsystem or the high-voltage power supply of the DC-DC converter subsystem. They are suitable for severe fault scenarios requiring isolation of the faulty side and prevention of fault propagation. Depending on the fault level, the high-voltage on the faulty side or the high-voltage power supply to the entire ship can be cut off. High-voltage maintenance commands correspond to the high-voltage cutoff commands and are used to ensure that non-faulty subsystems continue to maintain high-voltage power supply, ensuring the continuous operation of critical loads. This reflects the precision and differentiated processing capabilities of collaborative control. Operating mode switching commands are used to switch a subsystem to a specific operating mode, such as switching the daily inverter subsystem to emergency power supply mode or the propulsion control subsystem to power limiting mode, to adapt to the operating requirements under different fault scenarios.

[0060] In practical applications, the aforementioned commands are often not used in isolation, but rather in combination based on the specific requirements of the ship's overall fault level. For example, in a Level 4 ship fault (a relatively severe fault) scenario, the coordinated commands might include: issuing a high-voltage cut-off command to the faulty battery management subsystem while simultaneously issuing a high-voltage maintenance command to the non-faulty battery management subsystem; issuing a high-voltage cut-off command (or shut-off command) to the faulty propulsion control subsystem and motor control subsystem while simultaneously issuing a torque limiting command (allowing 100% of the rated output torque as compensation) to the non-faulty propulsion control subsystem and motor control subsystem; issuing a high-voltage cut-off command to the faulty DC-DC converter subsystem and daytime inverter subsystem while simultaneously issuing a power limiting command (allowing 80% of the rated output power) to the non-faulty DC-DC converter subsystem and daytime inverter subsystem; and issuing a power limiting command to the DC charging subsystem (limiting the output power to 30% of the rated value). This multi-command combination issuance mechanism based on the overall ship fault level ensures the global coordination and accuracy of fault response, effectively avoiding the defects of traditional fault handling methods such as each acting independently, over-responding or under-responding.

[0061] Table 7. Mapping Table of Ship Fault Levels and Coordination Commands

[0062] In this step, the human-computer interaction unit integrates and displays the relationships between multiple faults, including: The system displays the causal relationships, impact scope, and processing progress among multiple faults. Based on the overall ship failure level, sound and light alarms are triggered according to the preset graded alarm modes. Among them, the causal relationship between multiple faults is determined by the energy management system based on the electrical connection topology between each subsystem and the fault parameters, and then sent to the human-machine interaction unit for display.

[0063] Specifically, after the human-machine interface unit receives fault information, the overall ship fault level, and the handling status information sent by the energy management system, it immediately initiates a process to integrate and display the relationships between multiple faults. The core of this process is to transform scattered fault data into intuitive and visual information, enabling operators to quickly grasp the full picture of the fault and make accurate decisions.

[0064] First, the human-machine interface unit (HMI) displays the causal relationships of faults identified by the energy management system in the form of a causal chain on the interface. For example, when a battery over-temperature fault reported by the battery management subsystem, an output overvoltage fault reported by the DC-DC converter subsystem, and a power limitation fault reported by the propulsion control subsystem occur simultaneously, the HMI will generate a causal chain diagram on the interface showing "Battery over-temperature → DC-DC output overvoltage → Propulsion power limitation" based on the causal relationship data provided by the energy management system. Each fault node is labeled with specific fault parameters (e.g., temperature 68℃, voltage 415V, current power 50kW) and its location (e.g., module 3 of battery pack #1, left DC-DC converter, left PCS). This visual presentation of causal relationships allows operators to clearly understand the propagation path and internal connections of faults at a glance, avoiding the tedious process of switching between multiple HMI interfaces.

[0065] Secondly, the human-machine interface unit dynamically marks the impact range of a fault on the system topology diagram. The system topology diagram, pre-stored in the human-machine interface unit, fully displays the electrical connections between each subsystem. Upon receiving fault information, the human-machine interface unit automatically highlights the status of each subsystem on the topology diagram with different colors: faulty subsystems are displayed in flashing red, subsystems affected by the fault but not yet faulty are highlighted in yellow, and normally operating subsystems are displayed in solid green. Simultaneously, red arrows indicate the direction of fault propagation along the series link. For example, when the left-side DC-DC converter subsystem fails, its icon on the topology diagram flashes red, while its upstream battery management subsystem and downstream left propulsion control subsystem and left daytime inverter subsystem are all displayed in yellow, clearly showing the operator the potential scope of the fault and providing an intuitive basis for subsequent emergency decision-making.

[0066] Secondly, the human-machine interface unit dynamically tracks and displays the processing progress of each fault subsystem. After the coordinated control command is issued, each target subsystem will report the command execution status to the energy management system in real time, and the energy management system will forward this status information to the human-machine interface unit. Based on this, the human-machine interface unit displays the processing progress of each fault subsystem on the interface in the form of a progress bar, percentage, or status label. For example, for the battery management subsystem that needs to perform high-voltage cutoff, it can display "High-voltage cutoff: Completed (100%)"; for the DC-DC converter subsystem that is performing power limiting, it can display "Power limited to 80%: Executing (60%)"; for the propulsion control subsystem that has not yet started execution, it can display "Power limited to 50%: Pending execution (0%)". At the same time, the human-machine interface unit will also display the overall progress of the current fault handling on the interface according to the overall processing situation, so that the operator can grasp the whole picture of fault handling in real time.

[0067] While integrating and displaying the fault correlations, the human-machine interface unit also activates audible and visual alarms according to the ship-wide fault levels issued by the energy management system and the preset graded alarm modes. The alarm modes correspond one-to-one with the ship-wide fault levels: for a Level 1 fault, the green indicator light is constantly on and there is no buzzer, and the interface displays "Minor fault, does not affect operation"; for a Level 2 fault, the green indicator light flashes and there is no buzzer, and the interface displays "Minor fault, power limited operation"; for a Level 3 fault, the yellow indicator light is constantly on and there is an intermittent buzzer (2 seconds / time), and the interface displays "General fault, power limited operation, it is recommended to conduct maintenance after berthing"; for a Level 4 fault, the yellow indicator light flashes and there is a continuous buzzer, and the interface displays "Severe fault, the faulty side has been disconnected, the non-faulty side is operating under compensation, it is recommended to conduct maintenance nearby"; for a Level 5 fault, the red indicator light is constantly on and there is a continuous buzzer, and the interface displays "Severe fault, the entire ship's power has been limited, immediately proceed to a safe water area for maintenance"; for a Level 6 fault, the red indicator light flashes and there is a continuous high-decibel alarm, and the interface displays "Catastrophic fault, the entire ship's high voltage has been disconnected, immediately activate the emergency procedure". This tiered audio-visual alarm mechanism allows operators to perceive the severity of the current fault through hearing and sight, even without looking at the screen, and thus take timely countermeasures of the appropriate level.

[0068] It is important to note that the most crucial causal relationships in the above-described content were not analyzed and identified by the human-machine interface unit (HMI), but rather determined by the energy management system based on a comprehensive assessment of the electrical connection topology between subsystems and fault parameters. During the arbitration of the overall ship fault level, the energy management system has thoroughly analyzed the positional relationships of each fault within the topology (e.g., whether they are on the same series link) and the correlation between fault parameters (e.g., whether abnormal upstream fault parameters lead to downstream faults), thereby identifying the causal chains between faults. This identification result, along with the fault information, is sent to the HMI, which is responsible for presenting it to the operators in an intuitive manner. This division of labor—"energy management system identification, HMI display"—fully leverages the global data processing capabilities of the energy management system as the control center while ensuring the HMI's focus on a user-friendly information presentation design. Both functions work in tandem, achieving efficient integration and display of multiple fault relationships.

[0069] In this embodiment, it also includes: The energy management system receives the execution results from the target subsystem and verifies whether the execution results meet the preset requirements. If the verification fails, the energy management system executes a fault-tolerant process, which includes: repeatedly issuing collaborative control commands. If the number of repetitions exceeds a preset threshold and the target is still not met, the current ship-wide fault level is raised by one level, and a new collaborative control command matching the raised level is generated.

[0070] Specifically, after the energy management system issues coordinated control commands to each target subsystem, the system immediately enters the stage of verifying and handling the execution results. This step is a key closed-loop mechanism to ensure that the coordinated control commands are effectively executed and to avoid failure in fault handling due to execution failure.

[0071] Upon receiving the coordinated control command, each target subsystem immediately executes the corresponding coordinated operation and, during or after execution, feeds back the execution results to the energy management system via the communication network. Feedback information typically includes: subsystem identifier, command execution status (e.g., "Completed," "Executing," "Execution Failed"), current operating parameters (e.g., actual output power after executing the power limiting command, actual voltage value after executing the high-voltage cutoff command), and a description of any abnormalities. For example, after receiving a power limiting command of "allowed inverter power 50kW," the left daytime inverter subsystem adjusts its output power to 48kW and feeds back to the energy management system: "The left daytime inverter subsystem has executed the power limiting command, current output power 48kW, output voltage 380V, execution status: completed." This real-time feedback mechanism provides the energy management system with raw data to verify the execution results.

[0072] Upon receiving feedback, the energy management system immediately initiates an execution result verification procedure. Verification criteria typically include two aspects: first, response time verification, which checks whether the subsystem responds and provides feedback within a preset time threshold after the instruction is issued; this threshold is usually set to 100ms. Second, execution parameter deviation verification, which checks whether the actual operating parameters of the subsystem after execution are within a preset deviation range, typically set to ±5% of the instruction value. The energy management system compares the actual execution parameters in the feedback information with the instruction requirements and calculates the time delay from instruction issuance to receiving feedback. Verification is considered successful only if the response time is ≤100ms and the actual execution parameter deviation is ≤±5%; otherwise, verification fails.

[0073] When the verification result fails, the energy management system automatically initiates a fault-tolerant processing procedure. The design philosophy of this procedure is to ensure the effective execution of collaborative control commands to the greatest extent possible through multiple attempts and dynamic adjustments, avoiding interruption of fault handling due to a single execution failure.

[0074] The first step in the fault-tolerant processing procedure is to repeatedly issue the coordinated control command. The energy management system records the current number of issuances and reissues the same coordinated control command to the same target subsystem. This retry mechanism aims to eliminate execution failures caused by occasional factors such as momentary communication interference or brief periods of subsystem busy. After each retry, the system receives feedback and performs verification, forming a "issue-feedback-verification" loop.

[0075] If the execution result still fails to meet the target after the number of repeated issuances exceeds a preset threshold (usually set to 3), the system determines that the current fault cannot be effectively handled by the original level of collaborative instructions. At this point, the fault tolerance process enters the second step—shipwide fault level escalation. The energy management system automatically escalates the current shipwide fault level by one level (e.g., from level four to level five) and returns to the collaborative control instruction generation stage. It then re-queries the collaborative instruction mapping table according to the new level, generates collaborative control instructions matching the new level, and reissues them to the relevant target subsystems. The logic behind the level escalation is that when instructions at the original level cannot be executed, it indicates that the severity or scope of the fault may exceed the original assessment, requiring higher-level collaborative control measures to ensure system safety.

[0076] Through the above fault-tolerant processing flow, the present invention achieves the following technical effects: First, by using the repeated delivery mechanism, occasional failures in the communication or execution process are effectively eliminated, improving the reliability of instruction execution; Second, by using the level promotion mechanism, dynamic adaptive adjustment of fault response is achieved, avoiding the stagnation or failure of fault handling due to execution failure; Third, the entire fault-tolerant process is completed automatically by the energy management system without manual intervention, significantly improving the robustness and security of the system under complex fault scenarios.

[0077] It should be noted that the response time threshold (100ms), deviation range (±5%), and retry threshold (3 times) in the above verification standard are all preferred embodiments of the present invention. In practical applications, they can be flexibly calibrated and adjusted according to different ship types, different subsystem characteristics, and different safety level requirements to adapt to diverse engineering needs.

[0078] In this embodiment, fault information is transmitted to the energy management system via a hybrid communication network; The energy management system communicates with the propulsion control subsystem, DC-DC converter subsystem, day-use inverter subsystem, and DC charging subsystem via Ethernet; the energy management system communicates with the battery management subsystem via a controller area network bus; and the propulsion control subsystem communicates with the motor control subsystem via a controller area network bus.

[0079] Specifically, in this embodiment, fault information is transmitted to the energy management system through a carefully designed hybrid communication network to ensure the real-time, reliable, and efficient nature of data interaction. This hybrid communication network, tailored to the communication needs and control characteristics of different subsystems, employs a dual-network architecture combining Ethernet and Controller Area Network (CLAN) bus, enabling differentiated connections and optimized configurations for all subsystems on the ship.

[0080] like Figure 4As shown, the energy management system establishes communication connections with the propulsion control subsystem, DC-DC converter subsystem, household inverter subsystem, and DC charging subsystem via Ethernet. Ethernet, as a high-speed communication network, boasts a communication rate of up to 100Mbps and a transmission latency controlled within 50ms, meeting the high-volume, real-time data exchange requirements between these subsystems and the energy management system. The propulsion control subsystem needs to upload the propulsion system's operating status and fault information in real time and receive coordinated control commands such as torque and power limits from the energy management system; the DC-DC converter subsystem needs to continuously report output voltage, current, and fault parameters, while receiving power limit or disconnection commands; the household inverter subsystem needs to upload the load power supply status and receive inverter power limit commands; and the DC charging subsystem needs to upload the 24V power supply status and receive power limit or disconnection commands. This high-frequency, high-volume data interaction between these subsystems and the energy management system is efficiently achieved thanks to the high bandwidth and low latency characteristics of Ethernet.

[0081] Meanwhile, the energy management system communicates with multiple battery management subsystems via a Controller Area Network (CAN) bus. The CAN bus uses a 250kbps baud rate and boasts extremely high fault tolerance (over 99.9%), making it particularly suitable for scenarios like the battery management system where communication reliability is extremely critical and data transmission volume is relatively small. The battery management subsystems need to upload key parameters such as battery pack voltage, current, temperature, and insulation resistance, as well as fault information, in real time. While these data require high real-time performance, the amount of data transmitted at a time is relatively small, and the reliability and anti-interference capabilities of the CAN bus ensure stable transmission even in complex electromagnetic environments. Multiple battery management subsystems connect to the energy management system via the CAN bus in a multi-node manner, forming an efficient distributed data acquisition network.

[0082] Furthermore, the propulsion control subsystem and the motor control subsystem communicate via a controller area network (CAN) bus. This design is based on the following considerations: the propulsion control subsystem, as the management core of the propulsion system, is responsible for receiving driving commands and coordinating the operation of the motor control subsystem; the motor control subsystem, as the execution unit that directly drives the motor, needs to receive control signals such as torque and speed commands from the propulsion control subsystem in real time. The communication between the two has extremely high real-time requirements and a clear periodicity, and they are usually located in close physical locations. Using a CAN bus connection can meet the real-time control requirements while reducing system complexity and cost. The propulsion control subsystem sends motor control commands to the motor control subsystem via the CAN bus, while simultaneously receiving motor operating status and fault information uploaded by the motor control subsystem. This information is then integrated and reported to the energy management system via Ethernet.

[0083] The advantages of the aforementioned hybrid communication network architecture lie in the fact that Ethernet and CAN bus each perform their respective functions and complement each other. Ethernet undertakes the high-speed data exchange between the energy management system and the main power conversion and control subsystems, ensuring the real-time issuance of coordinated control commands and the rapid reporting of fault information. CAN bus, on the other hand, is responsible for reliable communication between the battery management subsystem and the propulsion control subsystem and the motor control subsystem, fully leveraging its strong anti-interference capabilities and stable communication in harsh industrial environments. This hierarchical and categorized communication network design not only ensures the real-time and reliable transmission of fault information across the entire system but also avoids the bandwidth bottlenecks or reliability risks that a single communication network might bring, providing a solid communication foundation for the energy management system to achieve global collaborative fault management.

[0084] In one specific embodiment, the workflow of this method is as follows: 1. System initialization: After the ship starts, each subsystem (BMS, DCDC, MCU, PCS, etc.) completes self-test. The #1 BMS detects that the battery pack insulation resistance is 800MΩ (normal) and the left DCDC converter detects that the output voltage is 400V (rated value). It establishes a connection with EMS through the communication layer. The data interaction channel delay test is 30ms to ensure smooth operation. 2. Fault Level Reporting: Each subsystem monitors its own operating parameters in real time and reports key information upon triggering a fault. For example: If BMS #1 detects that the cell temperature rises from 55℃ to 68℃ within 10 seconds, it is determined to be a Level 4 fault and reports to EMS: "Subsystem Identifier: BMS #1; Fault Level: Level 4; Fault Parameters: Cell temperature 68℃, current available power 200kW; Fault Location: Module 3 of Battery Pack #1"; If the right MCU detects that the power module temperature reaches 95℃, it is determined to be a Level 4 fault and, after being summarized by the right PCS, reports to EMS: "Subsystem Identifier: Right PCS (associated with right MCU); Fault Level: Level 4; Fault Parameters: MCU power module temperature 95℃, torque output 0N" m; Fault location: Right MCU power module; 3. Shipwide Fault Level Arbitration: After receiving fault information from one or more subsystems, the EMS maps the overall shipwide fault level based on the three-dimensional principle of "core subsystem priority, series fault superposition, and parallel fault selection based on the most severe fault" (the overall shipwide fault level is uniformly set to six levels): Core subsystem priority order: propulsion system (MCU+PCS) > power supply system (BMS+DCDC) > auxiliary power supply system (daily inverter + DC24V charger). Series fault superposition rule: When multiple subsystems in a series topology fail, the overall ship fault level after superposition is equal to the fault level of the highest subsystem in the series branch plus 1, and the superposition level does not exceed level six (if the highest level is level six, the superposition level is still level six). The rule for parallel faults is to take the most severe fault: When multiple subsystems in a parallel topology fail, the overall fault level of the ship is equal to the highest fault level of all subsystems in the parallel branch, and they are not cumulative. Mixed faults (including series and parallel faults) handling rules: First, calculate the superposition level of each series branch according to the series rule, and then take the highest level after superposition of all branches according to the parallel rule as the fault level of the whole ship.

[0085] Arbitration example: Example 1 (Series Fault Superposition): BMS #1 reports a Level 4 fault (battery overheating), and the left DC-DC reports a Level 2 fault (output overvoltage). The two are in a series topology of "battery-BMS-DCDC-daily inverter". The highest subsystem fault level is Level 4. After superposition, the overall ship fault level = 4 + 1 = Level 5. Example 2 (Series Fault Overlap - Level 6 Limitation): BMS #2 reports a Level 6 fault (cell short circuit), and the right DC-DC reports a Level 3 fault (power output prohibited). The highest level of the series branch is Level 6, and the overall fault level of the ship remains Level 6 after overlapping. Example 3 (Series Fault Overlap - Same Level Overlap): The left DC-DC converter reports a Level 4 fault (high voltage cut-off), the left daytime inverter reports a Level 4 fault (high voltage cut-off), the highest level of the series branch is Level 4, after overlap, the overall ship fault level = 4 + 1 = Level 5; Example 4 (parallel faults are classified as the most severe): The left PCS reports a level 3 fault (no power output), and the right PCS reports a level 4 fault (high voltage cutoff). The two are in a parallel propulsion topology, and the overall fault level of the ship is equal to the highest level (level 4). Example 5 (Mixed Fault): Series branch 1 (3#BMS Level 3 + Right DCCDC Level 2) superposition level = 3 + 1 = Level 4; Series branch 2 (Left PCS Level 3 + Left MCU Level 4) superposition level = 4 + 1 = Level 5; The two branches are connected in parallel, and the overall ship fault level = the highest superposition level (Level 5). Example 6 (Core Subsystem Priority): The DC24V charger reports a Level 4 fault (power depletion), and the left MCU reports a Level 3 fault (zero torque). The propulsion system (left MCU) has higher priority than the 24V power supply system (DC24V charger). The overall ship fault level is based on the fault level of the left MCU, which is mapped to Level 3. 4. Cooperative instruction generation and issuance: Based on the overall ship fault level (level 6), combined with the system topology characteristics and the scope of fault impact, EMS issues standardized cooperative processing instructions to each subsystem. The same overall ship fault level corresponds to a unified instruction system. In multiple fault scenarios, instructions are executed according to the overall ship level without additional adjustments. At the same time, information is sent to HMI (the power reduction allowance in the table can be specifically marked according to the actual application scenario).

[0086] Example of instruction issuance: Example 1 (Parallel Fault - Shipwide Level 4): The left PCS reports a Level 3 fault (no power output), and the right PCS reports a Level 4 fault (high voltage cutoff). The overall shipwide fault level is Level 4. The EMS issues the following Level 4 instructions: The fault-side (right PCS) BMS cuts off high voltage, while the left BMS maintains power supply; the right PCS cuts off power output, and the left PCS is allowed to discharge power equal to 100% of its rated power (compensated); the right MCU shuts down, and the left MCU is allowed to output torque equal to 100% of its rated torque; the right DC-DC converter cuts off output, and the left DC-DC converter is allowed to output power equal to 80% of its rated power; the right daytime inverter cuts off output, and the left daytime inverter is allowed to invert power equal to 80% of its rated power; the DC24V charger's power output is limited to 30% of its rated power; the HMI yellow indicator light flashes and a continuous buzzer sounds.

[0087] Example 2 (Mixed Fault - Shipwide Level 5): Series branch 1 (3# BMS Level 3 + Right DC-DC Level 2) has a superimposed Level 4 fault, and series branch 2 (Left PCS Level 3 + Left MCU Level 4) has a superimposed Level 5 fault, making the overall shipwide fault level Level 5. The EMS issues the following Level 5 instructions: The faulty branch (3# BMS branch, Left PCS branch) BMS is controlled to disconnect high voltage, while other BMS maintain power supply; all PCS are allowed to discharge power = 50% of rated power; all MCUs are allowed to output torque = 50% of rated power; the faulty branch DC-DC (Right DC-DC, Left DC-DC) output is cut off, while other DC-DC output power is allowed = 50% of rated power; the faulty branch's daytime inverter output is cut off, while other inverters are allowed to output power = 50% of rated power; the DC24V charger is prohibited from power output, triggering emergency power supply; the HMI red indicator light remains on and a continuous buzzer sounds.

[0088] 5. Command Execution and Feedback: After receiving the command issued by the EMS, each subsystem executes the corresponding action and feeds back the "action completion status + current operating parameters" to the EMS. For example, after receiving the command "allowed inverter power: 50kW", the left daytime inverter adjusts the output power to 48kW (within the limit) and feeds back to the EMS "the left daytime inverter has executed the power limiting command, the current output power is 48kW, and the voltage is 380V".

[0089] 6. Execution Result Verification: The EMS verifies the execution results of each subsystem in real time. The verification standard is "command response delay ≤ 100ms, execution parameter deviation ≤ 5%". If the expected effect is not achieved (e.g., no feedback is received 100ms after the command is issued, or the execution parameter deviation exceeds 5%), the command is reissued. If the standard is still not met after three repetitions, the overall ship fault level is upgraded by one level, and the command is issued according to the new level. For example, after the EMS issues a level four command "cut off high voltage" to BMS #1, it detects that battery pack #1 still has high voltage output (feedback error). After reissuing the command twice, if the high voltage is still not cut off, the overall ship fault level is upgraded from level four to level five, and the command is executed according to level five.

[0090] 7. Fault Resolution: After the subsystem fault is repaired, the system reports "Fault Clearance + Current Normal Operating Parameters" to the EMS. Upon receiving the driver's warning instruction, the EMS terminates the alarm, and all subsystems resume normal operation, thus ending the process.

[0091] Example 2

[0092] This embodiment provides a collaborative fault management system for a ship's integrated DC power system, including: Multiple subsystems, each with a built-in fault monitoring module, are used to monitor their own operating status in real time and report fault information including the local fault level determined by the system when a fault is triggered. The energy management system communicates with each subsystem to receive fault information. Based on the electrical connection topology and functional importance between the subsystems, it performs a comprehensive analysis of the received local fault levels through preset arbitration rules to determine the overall ship fault level. Based on the overall ship fault level, it generates collaborative control commands and sends them to the target subsystems to drive them to perform collaborative operations that match the overall ship fault level. It also sends fault information, overall ship fault level, and processing status information to the human-machine interface unit. The human-machine interface unit communicates with the energy management system to receive and display fault information, ship-wide fault levels and handling status information, and integrate and display the correlation between multiple faults.

[0093] The various embodiments of the present invention have been described above. These descriptions are exemplary and not exhaustive, nor are they limited to the disclosed embodiments. Many modifications and variations will be apparent to those skilled in the art without departing from the scope and spirit of the described embodiments.

Claims

1. A fault collaborative management method for a shipboard integrated DC power system, applied to an integrated DC power system comprising an energy management system and multiple subsystems, characterized in that, include: Multiple subsystems monitor their own operating status in real time and, when a fault is triggered, report fault information, including the local fault level determined by the system itself, to the energy management system. The energy management system, based on the electrical connection topology and functional importance of each subsystem, performs a comprehensive analysis of the received local fault levels through preset arbitration rules to determine the overall ship fault level. The energy management system generates collaborative control commands based on the overall ship fault level and sends the collaborative control commands to the target subsystem to drive the target subsystem to perform collaborative operations that match the overall ship fault level. It also sends the fault information, overall ship fault level, and processing status information to the human-machine interaction unit, which integrates and displays the correlation between multiple faults.

2. The method for collaborative fault management of a ship's integrated DC power system according to claim 1, characterized in that, The preset arbitration rules include: Series rule: For multiple subsystems in a series electrical connection topology, the overall ship fault level is the highest local fault level in the series electrical connection topology, which is increased by a preset level; Parallel connection rule: For multiple subsystems in a parallel electrical connection topology, the overall ship fault level is the highest among all local fault levels in the parallel electrical connection topology; Hybrid rule: For multiple subsystems in a hybrid electrical connection topology, i.e. a complex topology that simultaneously contains series and parallel relationships, the overall ship fault level is first determined according to the series rule, and then the final overall ship fault level is determined according to the parallel rule. Priority rule: When multiple subsystems belong to different functional importance levels, the overall ship failure level is determined based on the local failure level corresponding to the subsystem with the highest functional importance.

3. The method for collaborative fault management of a ship's integrated DC power system according to claim 2, characterized in that, The hierarchy of functional importance, from highest to lowest, includes: The propulsion system is structured at the level of motor control and propulsion control. The main power supply electronic system level corresponds to multiple battery management subsystems and multiple DC-DC conversion subsystems; The auxiliary power supply system level corresponds to the daily inverter subsystem and the DC charging subsystem.

4. The method for collaborative fault management of a ship's integrated DC power system according to claim 1, characterized in that, The energy management system generates coordinated control commands based on the overall ship fault level, including: Query the pre-stored collaborative instruction mapping table, in which different ship-wide fault levels are associated with standard instruction content issued to each of the subsystems; The standard instructions include one or more combinations of power limiting instructions, torque limiting instructions, high voltage cut-off instructions, high voltage maintenance instructions, and operating mode switching instructions.

5. The method for collaborative fault management of a ship's integrated DC power system according to claim 1, characterized in that, Also includes: The energy management system receives the execution results fed back by the target subsystem and verifies whether the execution results meet the preset requirements; If the verification fails, the energy management system executes a fault-tolerant processing procedure, which includes: repeatedly issuing the collaborative control command; if the number of repetitions exceeds a preset threshold and the target is still not met, the current ship-wide fault level is raised by one level, and a new collaborative control command matching the raised level is generated.

6. The method for collaborative fault management of a ship's integrated DC power system according to claim 1, characterized in that, The human-computer interaction unit integrates and displays the correlation between multiple faults, including: The system displays the causal relationships, impact scope, and processing progress among multiple faults. Based on the overall ship fault level, sound and light alarms are triggered according to the preset graded alarm mode. The causal relationship between the multiple faults is determined by the energy management system based on the electrical connection topology between the subsystems and fault parameters, and then sent to the human-machine interaction unit for display.

7. The method for collaborative fault management of a ship's integrated DC power system according to claim 3, characterized in that, The fault information is transmitted to the energy management system via a hybrid communication network; The energy management system communicates with the propulsion control subsystem, DC-DC converter subsystem, day-use inverter subsystem, and DC charging subsystem via Ethernet; the energy management system communicates with the battery management subsystem via a controller area network bus; and the propulsion control subsystem communicates with the motor control subsystem via a controller area network bus.

8. The method for collaborative fault management of a ship's integrated DC power system according to claim 2, characterized in that, The preset level is Level 1, and the upgraded ship-wide fault level does not exceed the predefined highest fault level.

9. The method for collaborative fault management of a ship's integrated DC power system according to claim 1, characterized in that, The fault information also includes subsystem identifier, fault parameters, and fault location.

10. A collaborative fault management system for a ship's integrated DC power system, characterized in that, include: Multiple subsystems, each of which has a built-in fault monitoring module for real-time monitoring of its own operating status and reporting fault information including the local fault level determined by the system itself when a fault is triggered; An energy management system, which is communicatively connected to each of the subsystems, is used to receive the fault information. Based on the electrical connection topology and functional importance between the subsystems, it performs a comprehensive analysis of the received local fault levels through preset arbitration rules to determine the overall ship fault level. Based on the overall ship fault level, a collaborative control command is generated and sent to the target subsystem to drive the target subsystem to perform a collaborative operation that matches the overall ship fault level, and to send the fault information, overall ship fault level and processing status information to the human-machine interaction unit. The human-machine interaction unit is communicatively connected to the energy management system and is used to receive and display the fault information, the fault level of the entire ship and the processing status information, and to integrate and display the correlation between multiple faults.