Loader safety control method with energy recovery and controlled descent function

CN122186190BActive Publication Date: 2026-09-04XIPAIGE (NANTONG) ELECTROHYDRAULIC CONTROL TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202610590618.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2026-04-30
Publication Date
2026-09-04
Estimated Expiration
2046-04-30

AI Technical Summary

Technical Problem

[0004]然而,这种以效率优先的控制策略在系统发生故障时,由于背压阀开度较大,系统无法提供足够的背压来限制工作装置的下落速度,可能导致其失控加速下砸,造成设备损坏甚至人身安全事故,现提出具备能量回收与受控降落功能的装载机安全控制方法,以改善现有存在的问题

Benefits of technology

(1)通过状态监测与智能故障诊断模块,对系统运行状态进行实时、分级评估,形成正常、预警、紧急安全三级综合故障等级,基于此等级,多模式决策与执行模块能够自动、无缝地切换至对应的工作模式,解决了传统系统中效率与安全相互矛盾的问题,使本系统实现能量高效利用与安全风险前置防控。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122186190B_ABST
    Figure CN122186190B_ABST
Patent Text Reader

Abstract

The application is suitable for the technical field of loader safety control, and provides a loader safety control method with energy recovery and controlled landing functions, comprising the following steps: S1, state monitoring and intelligent fault diagnosis, S2, multi-mode decision and execution: S21, if the comprehensive fault level is normal, enter the high-efficiency energy recovery mode, S22, if the comprehensive fault level is the early warning level, execute the reduced operation and issue an alarm prompt, S23, if the comprehensive fault level is the emergency safety level, enter the emergency safety controlled landing mode. Through the state monitoring and intelligent fault diagnosis module, the system running state is evaluated in real time and in stages to form a three-level comprehensive fault level of normal, early warning and emergency safety. Based on the level, the multi-mode decision and execution module can automatically and seamlessly switch to the corresponding working mode, solves the problem of mutual contradiction between efficiency and safety in the traditional system, and realizes efficient energy utilization and safety risk pre-control.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of loader safety control technology, and more specifically, to a loader safety control method with energy recovery and controlled landing functions. Background Technology

[0002] With the acceleration of electrification in construction machinery, electric loaders have attracted much attention due to their zero emissions, low noise, and energy-saving potential. Energy recovery technology is key to improving the range of electric loaders. Its core lies in harnessing the potential energy of the working device during descent, using a hydraulic system to drive a hydraulic pump, which in turn drives a motor to generate electricity, feeding the energy back into the battery.

[0003] In existing electric loader energy recovery systems, the descent speed and energy recovery are usually controlled by adjusting the opening of the electro-proportional back pressure valve on the return oil line. To maximize recovery efficiency, the back pressure valve should ideally be kept at a large opening to reduce throttling losses and allow the oil to drive the hydraulic pump as much as possible.

[0004] However, this efficiency-first control strategy can lead to equipment damage or even personal injury when the system malfunctions. For example, when the back pressure valve is too open, the system cannot provide enough back pressure to limit the falling speed of the working device. This could result in the device accelerating uncontrollably and crashing down, causing damage to the equipment or even personal injury. To address this issue, a loader safety control method with energy recovery and controlled descent functions is proposed. Summary of the Invention

[0005] In view of the shortcomings of the existing technology, the purpose of this invention is to provide a loader safety control method with energy recovery and controlled landing functions.

[0006] To achieve the above objectives, the present invention provides the following technical solution: A loader safety control method with energy recovery and controlled landing functions, which operates on a dual-channel heterogeneous redundant safety architecture, includes the following steps: The monitoring is executed cyclically in the security status monitoring bus channel with a fixed monitoring cycle. S1. The safety control system performs status monitoring and intelligent fault diagnosis. S11. Real-time acquisition of operating signals corresponding to the hydraulic system pressure, motor drive system voltage, integrated safety valve group valve status, and controller communication status of the electric loader's working mechanism; the acquisition action is independent of the sampling timing of the main working controller to ensure that the monitoring channel can still independently acquire field data when the main controller fails.

[0007] S12. For each operating signal, according to the degree of impact of its corresponding fault on system safety and operational stability, configure the corresponding fault judgment priority and fault confirmation duration threshold respectively; the fault confirmation duration threshold constitutes a timing redundancy verification mechanism to filter out signal glitches caused by electromagnetic interference or instantaneous vibration.

[0008] S13. When any collected operating signal value continuously exceeds its preset normal range threshold and the cumulative duration exceeds its corresponding fault confirmation duration threshold, the abnormal state is marked as a valid fault event; if the cumulative duration does not exceed the threshold, it is not marked for the time being, and the current set of valid fault events remains unchanged.

[0009] S14. At the end of each regulatory cycle, based on the fault determination priority corresponding to all currently marked valid fault events, the comprehensive fault level corresponding to the current regulatory cycle is re-determined according to preset rules; the comprehensive fault level is updated in real time with the dynamic changes of the set of valid fault events.

[0010] S2, the safety control system performs multi-mode decision-making and execution; S21. If the overall fault level is normal, then enter the high-efficiency energy recovery mode; at this time, the second channel remains silent and does not interfere with the main control logic of the first channel.

[0011] S22. If the overall fault level is a warning level, then perform a derated operation and issue an alarm.

[0012] S23. If the overall fault level is an emergency safety level, the mechanical arbitration mechanism is activated, and the emergency safety controlled landing mode is entered; the final execution of the mechanical arbitration mechanism does not depend on the continuous presence of electrical control signals.

[0013] The fixed monitoring cycle of the safety status monitoring bus channel is 5ms to 20ms; the mechanical arbitration channel completes the mode switching response within the next monitoring cycle after receiving the change in the comprehensive fault level; when the comprehensive fault level is upgraded from the normal level to the warning level or downgraded from the warning level to the normal level, the multi-mode control module completes the corresponding adjustment of the opening degree of the electro-proportional back pressure valve or the motor power limit within no more than two monitoring cycles.

[0014] The present invention is further configured such that the fault determination priority in step S12 is divided into: emergency safety priority, early warning priority, and normal priority.

[0015] The comprehensive fault level in step S14 includes normal level, early warning level, and emergency safety level.

[0016] The comprehensive fault level determination rules are as follows: Rule a: If there is a valid fault event with a fault determination priority of emergency safety priority, then the overall fault level is directly determined to be emergency safety level.

[0017] Rule b: If there are no valid fault events with emergency safety priority, but there are valid fault events with fault determination priority of warning priority, then the overall fault level is determined to be warning level.

[0018] Rule c: If there are no valid fault events, the condition is determined to be at the normal level.

[0019] The present invention is further configured such that the high-efficiency energy recovery mode in step S21 includes the following steps: The electro-proportional back pressure valve connected to the hydraulic actuator oil port of the electric loader's working mechanism is in the first opening state. In this opening state, the hydraulic oil discharged by the hydraulic actuator can preferentially flow through the hydraulic pump coaxially connected to the motor, driving it to run as a hydraulic motor, thereby driving the motor to generate electricity and realize energy recovery.

[0020] The first opening is the preset optimal opening for energy recovery, and the size of the first opening is such that the throttling resistance of the electro-proportional back pressure valve is minimized.

[0021] The present invention is further configured such that the emergency safe controlled landing mode in step S23 includes the following steps: S231, Dynamic Buffer Sub-step: The pilot relief valve, which is connected in parallel with the pilot control oil circuit of the electro-proportional back pressure valve, is opened. The electro-proportional back pressure valve is connected in series in the oil circuit of the hydraulic actuator of the electric loader working mechanism. After the pilot relief valve is opened, it provides a pressure relief channel for the oil circuit on the inlet side of the hydraulic actuator, so that the inlet pressure of the hydraulic actuator is reduced gradually. The purpose of this sub-step is to create a low-energy, low-flow-rate safety window for the subsequent intervention of the mechanical limit structure, so as to suppress the hydraulic impact when the valve core hits the mechanical limit.

[0022] S232, Stable and Controlled Reduction Sub-step: When the inlet pressure of the hydraulic actuator is detected to drop to the preset buffer completion pressure, the electrical drive circuit of the electro-proportional back pressure valve is cut off. The valve core of the electro-proportional back pressure valve moves in the closing direction under the action of the return spring until it abuts against the preset mechanical limit structure. The mechanical limit structure is a fixed hard limit component calculated according to the safety speed model and machined in one go before leaving the factory. Its limit position limits the valve core to retain a fixed throttling opening. This opening is determined by the mechanical geometry and is completely decoupled from the electrical signal, communication status, and controller operating status. Thus, the load of the electric loader is reduced at a limited safe speed.

[0023] The present invention is further configured such that, in step S232, the safe speed is determined based on the effective working area of ​​the rodless chamber of the hydraulic actuator, the throttling area of ​​the electro-proportional back pressure valve, the pressure difference between the inlet of the rodless chamber of the hydraulic actuator and the oil tank, and the hydraulic oil density.

[0024] Among them, the safe speed is positively correlated with the throttling area, and is adapted to the square root of the hydraulic oil density and pressure difference. Moreover, the safe opening degree limited by the mechanical limiting structure is inversely matched with the preset safe speed threshold.

[0025] The safe speed threshold is set based on the loader's rated load, operating conditions, and impact safety requirements.

[0026] The present invention is further configured such that, in the high-efficiency energy recovery mode, the generator torque command of the hydraulic pump drive motor is determined collaboratively based on the pressure difference between the rod-side and rodless-side chambers of the hydraulic actuator, the effective working area of ​​the two chambers, the operating speed of the hydraulic actuator, and the overall conversion efficiency of the system.

[0027] The overall system conversion efficiency is the comprehensive efficiency that includes the conversion of hydraulic oil hydraulic energy into hydraulic pump mechanical energy and the conversion of hydraulic pump mechanical energy into motor electrical energy. The torque command is set to maximize the recovery of electrical power and is adapted to the first opening degree of the electro-proportional back pressure valve.

[0028] The present invention is further configured such that: the fault confirmation duration threshold is dynamically set according to the type of operating signal; for signals reflecting instantaneous fatal faults, the corresponding duration threshold is set to a first short time threshold; for signals reflecting faults requiring continuous confirmation, the corresponding duration threshold is set to a second long time threshold, and the second long time threshold is greater than the first short time threshold.

[0029] The present invention is further configured such that the hardware cooperation relationship of the dual-channel heterogeneous redundant safety architecture is as follows: the hardware corresponding to the safety status monitoring bus channel includes the sensing unit and the hierarchical diagnostic module in the control unit; the hardware corresponding to the mechanical arbitration channel includes the normally closed electro-proportional back pressure valve, the pilot relief valve, and the mechanical limiting structure built into the electro-proportional back pressure valve in the integrated safety valve group; the specific cooperation relationship is as follows: The oil port of the hydraulic actuator is connected to the pump motor unit.

[0030] The hydraulic actuator unit includes a hydraulic cylinder, and the pump motor unit includes a hydraulic pump driven by a four-quadrant motor.

[0031] An integrated safety valve assembly is installed in the hydraulic actuator's oil circuit.

[0032] The integrated safety valve assembly includes a normally closed electro-proportional back pressure valve and a pilot-operated relief valve.

[0033] The normally closed electro-proportional back pressure valve is equipped with a mechanical limiting structure, which is used to limit the minimum throttling opening to form a safe opening. The pilot relief valve is connected in parallel in the pilot control oil circuit of the electro-proportional back pressure valve.

[0034] The sensing unit collects operating signals such as hydraulic system pressure, motor drive system voltage, integrated safety valve group valve status, and controller communication status and transmits them to the control unit. The sensing unit includes a pressure sensor installed in the hydraulic actuator, a voltage sensor installed in the motor drive circuit, a valve status sensor installed in the integrated safety valve group, and a signal detector installed in the controller communication interface.

[0035] The control unit is electrically connected to the driver of the four-quadrant motor, the electro-proportional back pressure valve, and the pilot relief valve to output control commands to each actuator.

[0036] The present invention is further configured such that the control unit includes a hierarchical diagnostic module and a multi-mode control module.

[0037] The hierarchical diagnostic module is configured to implement status monitoring and intelligent fault diagnosis steps, specifically: receiving multiple operating signals collected by the sensing unit, including hydraulic system pressure status signal, motor drive system voltage status signal, integrated safety valve group valve status signal, and controller communication status signal; determining valid fault events according to preset fault judgment priority and fault confirmation duration threshold; determining the comprehensive fault level based on the type and priority of the valid fault events; and outputting the comprehensive fault level to the multi-mode control module.

[0038] The multi-mode control module is configured to implement multi-mode decision-making and execution steps, specifically: receiving the comprehensive fault level output by the graded diagnosis module, generating and sending corresponding control commands to the driver, electro-proportional back pressure valve and pilot relief valve of the pump motor unit to execute the corresponding operating mode.

[0039] The present invention is further configured such that: the electro-proportional back pressure valve in the integrated safety valve assembly is a spring-reset normally closed proportional throttle valve, and the electro-proportional back pressure valve is equipped with a mechanical limiting structure for limiting the minimum throttle opening of the valve core.

[0040] The mechanical limiting structure is configured such that when the system determines the comprehensive fault level to be an emergency safety level, the electro-proportional back pressure valve is de-energized, and the valve core is reset to the closing direction under the action of the spring force. When the valve core is reset to the limit position of the mechanical limiting structure, the reset stops. At this time, the valve core still retains a fixed throttling opening, which corresponds to the safe opening designed based on the controlled descent speed model.

[0041] In summary, this application includes at least one of the following beneficial technical effects: (1) Through the status monitoring and intelligent fault diagnosis module, the system operation status is evaluated in real time and in a hierarchical manner, forming a three-level comprehensive fault level of normal, early warning and emergency safety. Based on this level, the multi-mode decision and execution module can automatically and seamlessly switch to the corresponding working mode, which solves the problem of the contradiction between efficiency and safety in traditional systems, and enables the system to achieve efficient energy utilization and proactive prevention and control of safety risks.

[0042] (2) By configuring fault judgment priority based on the degree of impact and dynamic fault confirmation time threshold, the system can distinguish between instantaneous fatal faults and potential faults that require continuous confirmation, reducing the possibility of false alarms and missed alarms. For faults with warning level, the system adopts derated operation instead of direct shutdown, and is supplemented by audible and visual alarms. This not only gives operators time to check and deal with the faults, but also maximizes the continuity of equipment operation, reduces unplanned downtime, and improves overall operational efficiency and system availability.

[0043] (3) In the emergency safety controlled landing mode, the pilot relief valve is first opened to dynamically relieve pressure and buffer the hydraulic actuator inlet pressure, effectively avoiding hydraulic shock. Then, the control electro-proportional back pressure valve is de-energized, and its built-in mechanical limit structure resets it and stabilizes it at the predetermined safe opening. Based on the above design, even in the worst case of complete failure of the electronic control system, the working device can still descend smoothly to the ground at a preset, limited safe speed through the fixed throttle orifice until it touches the ground, reducing the risk of arm crush. Attached Figure Description

[0044] Figure 1 This is a flowchart of the loader safety control method with energy recovery and controlled landing functions in this invention.

[0045] Figure 2 This is a flowchart of the safety control system in this invention.

[0046] Figure 3 This is a schematic diagram of the hardware connection of the safety control system in this invention.

[0047] Figure 4 This is a flowchart illustrating the dynamic change logic of the comprehensive fault level in this invention. Detailed Implementation

[0048] It should be noted that, unless otherwise specified, the embodiments and features described in this application can be combined with each other. The present invention will now be described in detail with reference to the accompanying drawings and embodiments.

[0049] It should be noted that, unless otherwise specified, all technical and scientific terms used in this application have the same meaning as commonly understood by one of ordinary skill in the art to which this application pertains.

[0050] Please see Figures 1-3 The present invention provides the following technical solutions: Example 1, see Figure 1 A loader safety control method with energy recovery and controlled landing functions, which operates on a dual-channel heterogeneous redundant safety architecture.

[0051] The architecture consists of two heterogeneous redundant channels: a security status monitoring bus channel (first channel) and a mechanical arbitration channel (second channel).

[0052] The safety status monitoring bus channel operates continuously in a fixed monitoring cycle (10ms in this embodiment). Within each monitoring cycle, the channel sequentially executes four sub-steps: signal acquisition, validity verification, timing redundancy verification, and fault level arbitration. Independent of the loader's regular operation control logic, this channel dynamically and continuously monitors the system's health status and outputs a real-time updated comprehensive fault level signal. The hardware foundation of this channel includes a sensing unit and a hierarchical diagnostic module in the control unit.

[0053] The mechanical arbitration channel receives the latest comprehensive fault level output by the safety status monitoring bus channel at the end of each monitoring cycle and completes the corresponding mode switching operation in the next monitoring cycle. This channel includes a multi-mode control module and an integrated safety valve assembly, responsible for translating the arbitration results of the monitoring channel into specific execution actions.

[0054] The dynamic update mechanism for the overall fault level: Unlike the one-time conclusion of conventional fault diagnosis, the overall fault level in this embodiment is a dynamic variable that evolves in real time with the system's operating status. When an abnormality occurs in a certain operating signal, the monitoring channel does not immediately change the overall fault level, but instead starts a timer to accumulate the duration of the abnormality. Only when the accumulated duration reaches the fault confirmation duration threshold corresponding to that signal type is the abnormality officially marked as a "valid fault event," and the overall fault level is recalculated at the end of the current monitoring cycle. The timing redundancy verification mechanism effectively filters out false triggers caused by instantaneous sensor jitter, electromagnetic interference, or sudden load changes.

[0055] The safety control method specifically includes the following steps: Execute in the first channel (security status monitoring bus channel): S1. The safety control system performs status monitoring and intelligent fault diagnosis.

[0056] First, the safety control system collects key operating signals such as hydraulic system pressure, motor drive system voltage, and controller communication status in real time, and configures fault judgment priorities and corresponding fault confirmation time thresholds based on the degree of impact, thereby realizing the perception and hierarchical diagnosis of the system status.

[0057] When an abnormal signal continues to exceed its threshold, it is marked as a valid fault event, and the normal level, warning level, or emergency safety level of the system is determined comprehensively based on the rule of highest emergency safety priority.

[0058] Based on the above monitoring and diagnostic methods, the specific implementation steps are as follows: S11. Real-time acquisition of operating signals corresponding to the hydraulic system pressure, motor drive system voltage, integrated safety valve group valve status, and controller communication status of the electric loader's working mechanism; this acquisition action is independent of the sampling timing of the main working controller to ensure that the monitoring channel can still independently acquire field data when the main controller fails.

[0059] S12. For each operating signal, configure the corresponding fault judgment priority and fault confirmation duration threshold according to the degree of impact of its corresponding fault on system safety and operational stability. The fault confirmation duration threshold constitutes a timing redundancy verification mechanism to filter out signal glitches caused by electromagnetic interference or instantaneous vibration.

[0060] The fault determination priority is divided into: emergency safety priority, early warning priority, and normal priority.

[0061] The fault judgment priority of controller communication interruption is set to emergency safety priority. This fault will cause the control signal to fail completely and the working mechanism to lose control directly. It is an instantaneous fatal fault.

[0062] If the pilot relief valve fails to open or close as instructed, or if the spool of the electro-proportional back pressure valve becomes stuck, and the system is configured for emergency safety priority, such malfunctions can directly cause the emergency landing mode to fail, leading to a risk of loss of control.

[0063] Setting the hydraulic system pressure to be consistently high, close to the rated value, as the warning priority indicates that the system load is consistently too high. Although it has not exceeded the limit immediately, long-term operation may damage the life of components. Continuous confirmation is required to avoid misjudgment.

[0064] If the opening deviation of the electro-proportional back pressure valve exceeds the allowable range, it is configured as a warning priority. Since this type of fault affects energy recovery efficiency or derating operational stability, the operator needs to be notified to perform maintenance.

[0065] S13. When any collected operating signal value continuously exceeds its preset normal range threshold and the duration exceeds its corresponding fault confirmation duration threshold, it is marked as an abnormal state, and the abnormal state is recorded as a valid fault event.

[0066] The fault confirmation duration threshold is dynamically set based on the type of operating signal. For signals reflecting instantaneous fatal faults, the corresponding duration threshold is set to the first short time threshold. For signals reflecting faults requiring continuous confirmation, the corresponding duration threshold is set to the second long time threshold, and the second long time threshold is greater than the first short time threshold.

[0067] S14. Based on the fault judgment priority corresponding to all current valid fault events, comprehensively determine the overall fault level of the current system according to preset rules; the overall fault level serves as the arbitration result signal output from the first channel to the second channel.

[0068] The comprehensive fault level includes normal level, early warning level, and emergency safety level.

[0069] The comprehensive fault level determination rules are as follows: Rule a: If there is a valid fault event with a fault determination priority of emergency safety priority, then the overall fault level is directly determined to be emergency safety level.

[0070] Rule b: If there are no valid fault events with emergency safety priority, but there are valid fault events with fault determination priority of warning priority, then the overall fault level is determined to be warning level.

[0071] Rule c: If there are no valid fault events, the condition is determined to be at the normal level.

[0072] like Figure 4 The diagram shows the dynamic change logic of the comprehensive fault level within one cycle. To further clarify the dynamic monitoring logic of the safety status monitoring bus channel, the following describes the complete timing process of the comprehensive fault level changing from the normal level to the warning level, combined with specific operating parameters.

[0073] Assuming the current time is T0, the system is in normal operation, the hydraulic system pressure is 18MPa (normal range 0~20MPa), the motor temperature is 65℃ (normal range ≤80℃), and all communication statuses are normal. At this time, the safety status monitoring bus channel shows: All operating signals acquired by the signal acquisition submodule are within the normal range; The validity verification submodule did not detect any anomalies; There are no abnormal timers to be confirmed in the timing redundancy verification submodule; The fault level arbitration submodule scans the current set of valid fault events and finds it to be empty, then outputs the overall fault level as normal.

[0074] At time T1, the loader began heavy-load lifting operations, and the hydraulic system pressure rose to 22MPa, exceeding the upper limit of the normal range.

[0075] at this time: The signal acquisition submodule detected an abnormal pressure signal; The validity verification submodule marks this anomaly as the status word "pressure too high"; The timing redundancy verification submodule starts a timer to accumulate the duration of the anomaly; Since this signal type is configured as an early warning priority, the corresponding fault confirmation duration threshold is the second longest time threshold (5s). Therefore, at the end of the current monitoring cycle, the timer's accumulated duration (<5s) has not reached the threshold, so the anomaly is not marked as a valid fault event, and the set of valid fault events remains empty. The overall fault level output by the fault level arbitration submodule remains at the normal level.

[0076] Throughout the monitoring cycles T1+1s, T1+2s, and up to T1+4.99s, the pressure signal remained consistently high, and the accumulated timer duration continued to increase. However, because the 5s threshold was not yet reached, the set of valid fault events remained empty, and the overall fault level remained at the normal level. During this period, the mechanical arbitration channel continued to operate in high-efficiency energy recovery mode, and system operation was unaffected.

[0077] Within the monitoring period at time T1+5s, the timing redundancy verification submodule detected that the cumulative duration of the abnormally high pressure had reached the 5s threshold.

[0078] At the end of the regulatory period: The exception has been officially marked as a valid fault event and added to the current set of valid fault events; The fault level arbitration submodule rescans the set of valid fault events and finds that there is a valid fault event with warning priority, but no valid fault event with emergency safety priority. According to the preset rule b, the overall fault level is re-determined as a warning level.

[0079] At the start of T1+5s+10ms (i.e., the next monitoring cycle), the mechanical arbitration channel receives the updated comprehensive fault level, and the multi-mode control module immediately performs the following actions: Limit the maximum output power of the motor to 70% of its rated value; An audible and visual alarm is issued via the instrument panel, prompting the operator that "the hydraulic system pressure remains too high; please reduce the load." Adjust the target opening of the electro-proportional back pressure valve from the first opening (90%) where energy recovery is optimal to the intermediate opening (60%) that is suitable for derating.

[0080] If the operator subsequently reduces the load, and the hydraulic system pressure returns to the normal range (e.g., 18 MPa), then: The abnormal high pressure condition has disappeared; Clear the timer in the timing redundancy verification submodule; The corresponding valid fault event is cleared after the recovery confirmation time (e.g., 3 seconds) is met; The set of valid fault events has become empty again; The fault level arbitration submodule will downgrade the overall fault level back to the normal level in the next regulatory cycle. The mechanical arbitration channel then exited the reduced-rate operation and resumed the high-efficiency energy recovery mode.

[0081] The aforementioned dynamic monitoring mechanism ensures that brief signal anomalies will not trigger unnecessary throttling or shutdown; at the same time, for persistent abnormal trends, the system can respond promptly after confirmation to prevent further deterioration of the fault, and solve the problems of fixed threshold fault diagnosis through situation-based response logic.

[0082] Executed in the second channel (mechanical arbitration channel): S2, the safety control system performs multi-mode decision-making and execution.

[0083] Based on the fault level setting in step S1, the safety control system automatically makes a decision and seamlessly switches to the corresponding mode. The matching relationship between the fault level and the decision content is as follows: If the level is normal, it will enter the high-efficiency energy recovery mode.

[0084] In the high-efficiency energy recovery mode, the safety control system controls the electro-proportional back pressure valve to the optimal opening degree, so that the oil discharged by the hydraulic actuator preferentially drives the hydraulic pump coaxial with the motor, which in turn drives the motor to generate electricity, thus achieving efficient energy recovery.

[0085] If the warning level is reached, the operation will be reduced.

[0086] In practical work, the motor power or operating speed can be limited, and an audible and visual alarm can be issued to prompt the operator to check, thus ensuring basic operating capabilities while preventing the malfunction from escalating.

[0087] If the emergency safety level is reached, immediately switch to emergency safe controlled landing mode.

[0088] The emergency safe controlled landing mode is further divided into two sub-steps: Step 1: First, open the parallel pilot relief valve to provide a pressure relief channel for the hydraulic actuator inlet pressure, achieve dynamic buffering, and gradually reduce the pressure.

[0089] Step 2: Once the pressure drops to the safety threshold, switch the electro-proportional back pressure valve to the safe opening degree limited by the mechanical structure, so that the working device descends steadily at a preset, limited safe speed until it touches the ground.

[0090] In actual operation, the specific steps for the above matching relationship are as follows: S21. If the overall fault level is normal, then enter the high-efficiency energy recovery mode; at this time, the second channel remains silent and does not interfere with the main control logic of the first channel.

[0091] The high-efficiency energy recovery mode includes the following steps: The electro-proportional back pressure valve connected to the hydraulic actuator oil port of the electric loader's working mechanism is in the first opening state. In this opening state, the hydraulic oil discharged by the hydraulic actuator can preferentially flow through the hydraulic pump coaxially connected to the motor, driving it to run as a hydraulic motor, thereby driving the motor to generate electricity and realize energy recovery.

[0092] The first opening is the preset optimal opening for energy recovery, and the size of the first opening is such that the throttling resistance of the electro-proportional back pressure valve is minimized.

[0093] In the high-efficiency energy recovery mode, the generator torque command of the hydraulic pump drive motor is determined collaboratively based on the pressure difference between the rod-side and rodless sides of the hydraulic actuator, the effective working area of ​​the two sides, the operating speed of the hydraulic actuator, and the overall conversion efficiency of the system.

[0094] The overall system conversion efficiency is the comprehensive efficiency that includes the conversion of hydraulic oil hydraulic energy into hydraulic pump mechanical energy and the conversion of hydraulic pump mechanical energy into motor electrical energy. The torque command is set to maximize the recovery of electrical power and is adapted to the first opening degree of the electro-proportional back pressure valve.

[0095] The energy recovery power model is as follows:

[0096] in, This indicates the predicted recovered electrical power, and represents the rod chamber pressure of the hydraulic actuator. This indicates the pressure in the rodless chamber of the hydraulic actuator. This indicates the effective working area of ​​the rod chamber in a hydraulic actuator. η represents the effective working area of ​​the rodless chamber of the hydraulic actuator, v represents the operating speed of the hydraulic actuator, and η represents the total conversion efficiency of the system.

[0097] S22. If the overall fault level is a warning level, then perform a derated operation and issue an alarm.

[0098] S23. If the overall fault level is an emergency safety level, the mechanical arbitration mechanism is activated, and the emergency safety controlled landing mode is entered. The final execution of the mechanical arbitration mechanism does not depend on the continuous presence of electrical control signals.

[0099] S231, Dynamic Buffer Sub-step: The pilot relief valve, which is connected in parallel with the pilot control oil circuit of the electro-proportional back pressure valve, is opened. The electro-proportional back pressure valve is connected in series in the oil circuit of the hydraulic actuator of the electric loader working mechanism. After the pilot relief valve is opened, it provides a pressure relief channel for the oil circuit on the inlet side of the hydraulic actuator, so that the inlet pressure of the hydraulic actuator is reduced gradually. The purpose of this sub-step is to create a low-energy, low-flow-rate safety window for the subsequent intervention of the mechanical limit structure, so as to suppress the hydraulic impact when the valve core hits the mechanical limit.

[0100] S232, Stable and Controlled Landing Sub-Step: When the inlet pressure of the hydraulic actuator is detected to drop to the preset buffer completion pressure, the electrical drive circuit of the electro-proportional back pressure valve is cut off. The valve core of the electro-proportional back pressure valve moves in the closing direction under the action of the return spring until it abuts against the preset mechanical limit structure.

[0101] The mechanical limit structure is a fixed limit component that is calculated and machined in one go according to the safe speed model before leaving the factory. Its limit position limits the valve core to retain a fixed throttling opening. This opening is determined by the mechanical geometry and is decoupled from any electrical signals, communication status, or controller operating status; thereby enabling the load of the electric loader to drop at a limited safe speed.

[0102] The safe speed is determined collaboratively based on the effective working area of ​​the rodless chamber of the hydraulic actuator, the throttling area of ​​the electro-proportional back pressure valve, the pressure difference between the inlet of the rodless chamber of the hydraulic actuator and the oil tank, and the hydraulic oil density.

[0103] Among them, the safe speed is positively correlated with the throttling area, and is adapted to the square root of the hydraulic oil density and pressure difference. Moreover, the safe opening degree limited by the mechanical limiting structure is inversely matched with the preset safe speed threshold.

[0104] The safe speed threshold is set based on the loader's rated load, operating conditions, and impact safety requirements.

[0105] The safe speed is determined by the following controlled landing speed model:

[0106]

[0107] Where Q represents the flow rate through the safety opening. This indicates the effective working area of ​​the rodless chamber of the hydraulic actuator. This indicates the flow coefficient at the throttling orifice of the electro-proportional back pressure valve. This represents the throttling area corresponding to the safe opening degree. Indicates the inlet pressure of the hydraulic actuator. ρ represents the pressure in the oil tank, and ρ represents the density of the hydraulic oil.

[0108] The irreversible execution mechanism for emergency security levels is as follows: When the safety status monitoring bus channel detects a valid fault event with an emergency safety priority within any monitoring cycle, the overall fault level is immediately determined to be an emergency safety level, and the mechanical arbitration channel is activated accordingly.

[0109] Unlike normal and warning levels, the execution process of the emergency safe controlled landing mode is irreversible. Specifically: Once the mechanical arbitration channel begins executing S231 (dynamic buffer sub-step), the system will not abort the landing process or attempt to switch back to energy recovery mode, even if the fault signal that subsequently led to the emergency decision is unexpectedly restored (e.g., unexpected restoration after a communication interruption).

[0110] When the control unit activates the mechanical arbitration mechanism, it records an irreversible fault code. This fault code will permanently prevent the system from entering the high-efficiency energy recovery mode until it is manually repaired.

[0111] With the above settings in place, once the system has been determined to be at its highest risk level, the safest course of action is to allow the working device to complete a controlled descent definitively, rather than attempting to return to a normal operating state where there may be unknown risks.

[0112] Physical safeguards against irreversibility: Since the electro-proportional back pressure valve has been de-energized in sub-step S232, the valve core resets to the mechanical limit structure under spring force. Thereafter, the throttling area of ​​the return oil passage is determined by the physical dimensions of the mechanical limit structure. Even if the control unit attempts to re-energize and control the electro-proportional back pressure valve, it must first complete the reset action and undergo manual confirmation, thus physically eliminating the risk of accidental restoration of electronic control during an emergency landing.

[0113] The above operation method is executed by a dedicated safety control system, which integrates a hydraulic actuator, a pump motor unit, an integrated safety valve assembly, a sensing unit, and a control unit.

[0114] The safety control system in this embodiment improves the speed, reliability, and security of fault detection, level judgment, and mode execution.

[0115] See Figure 2 and Figure 3 The core control logic of the safety control system corresponds to the following hardware coordination relationship: This hardware coordination relationship enables status monitoring, fault diagnosis, and multi-mode control execution. Specifically, the hydraulic actuator's oil port is connected to the pump motor unit.

[0116] The hydraulic actuator unit includes a hydraulic cylinder, and the hydraulic actuator is the hydraulic cylinder. The pump motor unit includes a hydraulic pump driven by a four-quadrant motor.

[0117] An integrated safety valve assembly is installed in the hydraulic actuator's oil circuit.

[0118] The integrated safety valve assembly includes a normally closed electro-proportional back pressure valve and a pilot-operated relief valve.

[0119] Among them, the normally closed electro-proportional back pressure valve is equipped with a mechanical limiting structure, which is used to limit the minimum throttling opening to form a safe opening. The pilot relief valve is connected in parallel in the pilot control oil circuit of the electro-proportional back pressure valve.

[0120] The sensing unit collects operating signals such as hydraulic system pressure, motor drive system voltage, integrated safety valve group valve status, and controller communication status and transmits them to the control unit. The sensing unit includes a pressure sensor installed in the hydraulic actuator, a voltage sensor installed in the motor drive circuit, a valve status sensor installed in the integrated safety valve group, and a signal detector installed in the controller communication interface.

[0121] The control unit is electrically connected to the driver of the four-quadrant motor, the electro-proportional back pressure valve, and the pilot relief valve to output control commands to each actuator.

[0122] The control unit includes a hierarchical diagnostic module and a multi-mode control module.

[0123] The hierarchical diagnostic module is configured to implement status monitoring and intelligent fault diagnosis steps for the safety status supervision bus channel. Specifically, it receives multiple operating signals collected by the sensing unit, including hydraulic system pressure status signals, motor drive system voltage status signals, integrated safety valve group valve status signals, and controller communication status signals. Based on the preset fault judgment priority and fault confirmation duration threshold, it determines the valid fault events, then determines the comprehensive fault level based on the valid fault event type and priority, and outputs the comprehensive fault level to the multi-mode control module. The sampling timing of this module is physically isolated from the sampling timing of the main operation controller, and it can still operate independently when the main controller communication is interrupted.

[0124] It should be noted that the graded diagnostic module receives real-time signals from the valve status sensor. If it detects that the pilot relief valve fails to open as instructed in emergency mode, or that the electro-proportional back pressure valve fails to reset to the mechanical limit opening, it is immediately marked as an emergency safety priority valid fault event. If an opening deviation is detected, it is combined with pressure and voltage signals for comprehensive judgment to avoid misjudgment by a single sensor.

[0125] The multi-mode control module is configured to implement multi-mode decision-making and execution steps of the mechanical arbitration channel. Specifically, it receives the comprehensive fault level output by the graded diagnosis module, generates and sends corresponding control commands to the pump motor unit's driver, electro-proportional back pressure valve, and pilot relief valve to execute the corresponding operating mode. When the comprehensive fault level is the emergency safety level, the multi-mode control module executes the mechanical arbitration sequence, specifically: first, it opens the pilot relief valve for dynamic buffering; after the pressure drops to the buffer completion pressure, it actively cuts off the electrical drive circuit of the electro-proportional back pressure valve, causing the valve core to return to the mechanical limit structure by spring force.

[0126] The electro-proportional back pressure valve in the integrated safety valve assembly is a spring-return normally closed proportional throttle valve, which is equipped with a mechanical limiting structure for limiting the minimum throttle opening of the valve core.

[0127] The mechanical limit structure is set so that when the system determines the comprehensive fault level to be the emergency safety level, the electro-proportional back pressure valve is de-energized, and the valve core is reset to the closing direction under the action of the spring force. When the valve core is reset to the limit position of the mechanical limit structure, the reset stops. At this time, the valve core still retains a fixed throttling opening, which corresponds to the safe opening designed based on the controlled descent speed model.

[0128] The existence of this mechanical limiting structure enables the system to establish a purely physical safety throttling channel decoupled from the electrical signal even in the event of a complete failure of the electrical control link. The mechanical limiting structure forms the physical basis of the second channel (mechanical arbitration channel) in the dual-channel heterogeneous redundancy safety architecture—its execution does not depend on electromagnetic force, position sensor feedback, or communication bus status, but is determined solely by the elastic potential energy of the spring and solid-state geometric limiting.

[0129] Through the status monitoring and intelligent fault diagnosis module, the system's operating status is assessed in real time and at different levels, forming a three-tiered comprehensive fault level: normal, early warning, and emergency safety. Based on this level, the multi-mode decision-making and execution module can automatically and seamlessly switch to the corresponding operating mode: under normal conditions, it enters a high-efficiency energy recovery mode, maximizing energy recovery by optimizing the back pressure valve opening; under early warning conditions, it executes derating operation to ensure basic operational capabilities while preventing the fault from escalating; and under emergency conditions, it immediately switches to an emergency safety controlled landing mode. This solves the problem of the contradiction between efficiency and safety in traditional systems, enabling the system to both increase efficiency and reduce costs while preventing problems before they occur, achieving a balance and seamless switching between high efficiency and safety.

[0130] In this embodiment, the sensing unit adopts a targeted deployment and full-link signal coverage design, specifically including: pressure sensors installed in the inlet oil circuit of the rodless chamber of the boom cylinder and the main return oil circuit of the hydraulic actuator to collect the working pressure and return oil pressure status signals of the hydraulic system in real time, providing data support for energy recovery power calculation and pressure over-limit fault diagnosis.

[0131] The voltage sensor, installed in the power supply box of the four-quadrant motor near the voltage transformer, directly collects the three-phase AC input voltage status signal of the motor drive circuit, ensuring rapid detection of emergency faults such as voltage drops.

[0132] Valve status sensors fall into two categories: one is a displacement sensor installed on the stem of a pilot relief valve, used to collect the valve core position signal, such as the open or closed state and the degree of opening, and to provide real-time feedback on whether the valve body has completed the opening and closing action according to the control command; the other is a displacement sensor installed on the stem of an electro-proportional back pressure valve, used to collect the valve core opening signal, to provide feedback on whether it is at the preset first opening, second opening, or target adjustment opening, and to monitor whether the valve core is stuck or whether the reset is in place.

[0133] Signal detectors installed at the bus communication interface between the main controller and the hydraulic valve slave controller, as well as at the communication interface between the control unit and the sensing unit, monitor the connection and delay status of the communication link in real time, supporting the hierarchical diagnosis of communication-related faults.

[0134] The deployment locations of the aforementioned sensors are all aligned with the core functional requirements, ensuring the accuracy and timeliness of the acquired signals. All operational signals are transmitted to the control unit in real time, providing reliable data input for system-level fault handling and multi-mode safety control.

[0135] This control method is applicable to various core operating conditions of electric loaders, including boom lowering, bucket lifting or lowering, boom lateral movement with load, and combined action conditions.

[0136] Obviously, the embodiments described above are merely some, not all, embodiments of the present invention. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without inventive effort should fall within the scope of protection of the present invention.

Claims

1. A loader safety control method with energy recovery and controlled landing functions, the method being based on a dual-channel heterogeneous redundant safety architecture including a safety status monitoring bus channel and a mechanical arbitration channel, characterized in that: Including the following steps: The monitoring is executed cyclically in the security status monitoring bus channel with a fixed monitoring cycle. S1. The safety control system performs status monitoring and intelligent fault diagnosis. S11. Real-time acquisition of operating signals including hydraulic system pressure, motor drive system voltage, integrated safety valve group status, and controller communication status corresponding to the electric loader's working mechanism; S12. For each operating signal, configure the corresponding fault judgment priority and fault confirmation duration threshold according to the degree of impact of its corresponding fault on system safety and operational stability. S13. During each monitoring cycle, if any collected operating signal value continuously exceeds its preset normal range threshold and the cumulative duration exceeds its corresponding fault confirmation duration threshold, the abnormal state is marked as a valid fault event; if the cumulative duration does not exceed the threshold, it is not marked and the current set of valid fault events remains unchanged. S14. At the end of each regulatory cycle, based on the fault determination priority corresponding to all currently marked valid fault events, the comprehensive fault level corresponding to the current regulatory cycle is re-determined according to preset rules. The overall fault level is updated in real time as the set of valid fault events changes dynamically. Executed in the mechanical arbitration channel: S2, the safety control system performs multi-mode decision-making and execution; S21. If the overall fault level is normal, then enter the high-efficiency energy recovery mode. S22. If the overall fault level is a warning level, then perform a derated operation and issue an alarm. S23. If the overall fault level is the emergency safety level, then activate the mechanical arbitration mechanism and enter the emergency safety controlled landing mode. Once the emergency safe controlled landing mode is entered, the execution process of this mode is irreversible until the working device completes the controlled landing.

2. The loader safety control method with energy recovery and controlled landing functions according to claim 1, characterized in that: In step S12, the fault determination priority is divided into: emergency safety priority, early warning priority, and normal priority; The comprehensive fault level in step S14 includes normal level, early warning level, and emergency safety level; The comprehensive fault level determination rules are as follows: Rule a: If there is a valid fault event with a fault determination priority of emergency safety priority, then the overall fault level shall be directly determined as emergency safety level. Rule b: If there are no valid fault events with emergency safety priority, but there are valid fault events with fault judgment priority of warning priority, then the overall fault level is judged as warning level. Rule c: If there are no valid fault events, the condition is determined to be at the normal level.

3. The loader safety control method with energy recovery and controlled landing functions according to claim 1, characterized in that: The high-efficiency energy recovery mode in step S21 includes the following steps: The electro-proportional back pressure valve connected to the hydraulic actuator oil port of the electric loader working mechanism is in the first opening state. In this opening state, the hydraulic oil discharged by the hydraulic actuator can flow first through the hydraulic pump coaxially connected to the motor, drive it to run as a hydraulic motor, and then drive the motor to generate electricity to realize energy recovery. The first opening is the preset optimal opening for energy recovery, and the size of the first opening is such that the throttling resistance of the electro-proportional back pressure valve is minimized.

4. The loader safety control method with energy recovery and controlled landing functions according to claim 1, characterized in that: The mechanical arbitration mechanism activated in step S23 includes the following steps: S231, Dynamic Buffer Sub-step: The pilot relief valve, which is connected in parallel with the pilot control oil circuit of the electro-proportional back pressure valve, is opened. The electro-proportional back pressure valve is connected in series in the oil circuit of the hydraulic actuator of the electric loader working mechanism. After the pilot relief valve is opened, it provides a pressure relief channel for the oil circuit on the inlet side of the hydraulic actuator, so that the inlet pressure of the hydraulic actuator is reduced gradually. S232, Stable and Controlled Landing Sub-step: When the inlet pressure of the hydraulic actuator is detected to drop to the preset buffer completion pressure, the electrical drive circuit of the electro-proportional back pressure valve is cut off, and the valve core of the electro-proportional back pressure valve is reset to the closing direction under the action of the reset spring until it abuts against the preset mechanical limit structure. The mechanical limiting structure restricts the maximum closing stroke of the valve core, allowing the return oil from the hydraulic actuator to flow out through a safe opening defined by the mechanical limiting structure. This safe opening is determined by the mechanical geometry and is decoupled from the electrical control signal, thereby allowing the load of the electric loader to decrease at a limited safe speed.

5. The loader safety control method with energy recovery and controlled landing functions according to claim 4, characterized in that: In step S232, the safe speed is determined based on the effective working area of ​​the rodless chamber of the hydraulic actuator, the throttling area of ​​the electro-proportional back pressure valve, the pressure difference between the inlet of the rodless chamber of the hydraulic actuator and the oil tank, and the hydraulic oil density. Among them, the safe speed is positively correlated with the throttling area, and is adapted to the square root of the hydraulic oil density and pressure difference. Moreover, the safe opening degree limited by the mechanical limiting structure is inversely matched with the preset safe speed threshold. The safe speed threshold is set based on the loader's rated load, operating conditions, and impact safety requirements.

6. The loader safety control method with energy recovery and controlled landing functions according to claim 3, characterized in that: In the high-efficiency energy recovery mode, the generator torque command of the hydraulic pump drive motor is determined collaboratively based on the pressure difference between the rod-side and rodless sides of the hydraulic actuator, the effective working area of ​​the two sides, the operating speed of the hydraulic actuator, and the overall conversion efficiency of the system. The overall system conversion efficiency is the comprehensive efficiency that includes the conversion of hydraulic oil hydraulic energy into hydraulic pump mechanical energy and the conversion of hydraulic pump mechanical energy into motor electrical energy. The torque command is set to maximize the recovery of electrical power and is adapted to the first opening degree of the electro-proportional back pressure valve.

7. The loader safety control method with energy recovery and controlled landing functions according to claim 1, characterized in that: The fault confirmation duration threshold is dynamically set according to the type of operating signal. For signals that reflect instantaneous fatal faults, the corresponding duration threshold is set to the first short time threshold; for signals that reflect faults that require continuous confirmation, the corresponding duration threshold is set to the second long time threshold, and the second long time threshold is greater than the first short time threshold.

8. The loader safety control method with energy recovery and controlled landing functions according to claim 1, characterized in that: The hardware coordination relationship of the dual-channel heterogeneous redundancy security architecture is as follows: The hardware corresponding to the security status monitoring bus channel includes a sensor unit and a hierarchical diagnostic module in the control unit. The hardware corresponding to the mechanical arbitration channel includes a normally closed electro-proportional back pressure valve, a pilot relief valve, and a mechanical limiting structure built into the electro-proportional back pressure valve in the integrated safety valve group. The specific cooperation relationship is as follows: The oil port of the hydraulic actuator is connected to the pump motor unit; The hydraulic actuator includes a hydraulic cylinder, and the pump motor unit includes a hydraulic pump driven by a four-quadrant motor. An integrated safety valve assembly is installed in the hydraulic actuator's oil circuit; The integrated safety valve assembly includes a normally closed electro-proportional back pressure valve and a pilot-operated relief valve. The normally closed electro-proportional back pressure valve is provided with a mechanical limiting structure, which is used to limit the minimum throttling opening to form a safe opening. The pilot relief valve is connected in parallel in the pilot control oil circuit of the electro-proportional back pressure valve. The sensing unit collects operating signals such as hydraulic system pressure, motor drive system voltage, integrated safety valve group valve status, and controller communication status and transmits them to the control unit. The sensing unit includes a pressure sensor installed in the hydraulic actuator, a voltage sensor installed in the motor drive circuit, a valve status sensor installed in the integrated safety valve group, and a signal detector installed in the controller communication interface. The control unit is electrically connected to the driver of the four-quadrant motor, the electro-proportional back pressure valve, and the pilot relief valve to output control commands to each actuator.

9. The loader safety control method with energy recovery and controlled landing functions according to claim 8, characterized in that: The control unit includes a hierarchical diagnostic module and a multi-mode control module; The hierarchical diagnosis module is configured to implement status monitoring and intelligent fault diagnosis steps, specifically: receiving multiple operating signals collected by the sensing unit, including hydraulic system pressure status signal, motor drive system voltage status signal, integrated safety valve group valve status signal and controller communication status signal; determining valid fault events according to preset fault judgment priority and fault confirmation duration threshold; determining the comprehensive fault level based on the type and priority of the valid fault events; and outputting the comprehensive fault level to the multi-mode control module. The multi-mode control module is configured to implement multi-mode decision-making and execution steps, specifically: receiving the comprehensive fault level output by the graded diagnosis module, generating and sending corresponding control commands to the driver, electro-proportional back pressure valve and pilot relief valve of the pump motor unit to execute the corresponding operating mode.

10. The loader safety control method with energy recovery and controlled landing functions according to claim 8, characterized in that: The electro-proportional back pressure valve in the integrated safety valve assembly is a spring-return normally closed proportional throttle valve, and the electro-proportional back pressure valve is equipped with a mechanical limiting structure for limiting the minimum throttle opening of the valve core. The mechanical limiting structure is configured such that when the system determines the comprehensive fault level to be an emergency safety level, the electro-proportional back pressure valve is de-energized, and the valve core is reset to the closing direction under the action of the spring force. When the valve core is reset to the limit position of the mechanical limiting structure, the reset stops. At this time, the valve core still retains a fixed throttling opening, which corresponds to the safe opening designed based on the controlled descent speed model.

Citation Information

Patent Citations

  • Lifting mechanism

    CA3164508A1

  • Electric loader intelligent fault diagnosis method based on multi-motor cooperation characteristic

    CN121388465A