Motor controller and control method, vehicle
By adopting a single-channel redundant interlock architecture and redundant power supply design in the motor controller of new energy vehicles, hardware-level linkage and monitoring between power modules are realized, which improves the safety and reliability of the motor controller and meets the ASIL D level functional safety requirements.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- DEEPAL AUTOMOBILE TECH CO LTD
- Filing Date
- 2026-06-08
- Publication Date
- 2026-07-14
AI Technical Summary
In the existing safety design of new energy vehicle motor controllers, the safety mechanisms of each key functional module lack deep hardware-level coordination, resulting in increased fault response delay, insufficient hardware backup, difficulty in linkage when signal acquisition is abnormal, difficulty in dealing with complex faults, and inability to meet high-level functional safety requirements.
A single-channel redundant interlocking architecture is adopted. Through hardware-level linkage between the electrical safety monitoring module and the active short-circuit protection module, combined with redundant power supply design, the whole-link hardware safety collaborative protection is realized. This includes hardware-level linkage between the power supply module, control module, drive module, sampling module and safety monitoring module, forming a dual or multiple protection mechanism.
It significantly improves the overall safety and reliability of the motor controller, enables rapid response to faults, avoids protection lag, meets ASIL D level functional safety requirements, reduces the risk of system failure due to single point of failure, and extends the service life of the system.
Smart Images

Figure CN122379302A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of vehicle technology, specifically to a motor controller and control method, and a vehicle. Background Technology
[0002] In the field of functional safety technology for new energy vehicle motor controllers, existing safety design schemes generally suffer from modular silos, with a lack of deep hardware-level collaboration in the safety mechanisms of various key functional modules. Specifically, the safety monitoring functions of core modules such as power management units, main control units, power drive units, and signal acquisition units often adopt independent design patterns. The safety status detection, fault diagnosis, and protection execution of each module form separate technical loops, failing to build a unified safety protection network covering the entire hardware chain.
[0003] This discrete safety architecture has significant technical drawbacks: First, power supply anomalies cannot directly trigger the hardware-level rapid protection of the power drive module, such as voltage dips and current overloads; they must rely on the software processing of the main control unit, leading to increased fault response latency. Second, when a functional safety fault occurs in the main control chip, there is a lack of a hardware backup mechanism independent of the main control system, and the switching of safe states relies excessively on software logic. Third, anomalies in the signal acquisition module are difficult to achieve hard-wired linkage with the drive module; for example, sensor failure or signal drift results in a timing disconnect between fault diagnosis and protection execution. More seriously, when the system encounters multiple concurrent faults, such as power supply anomalies combined with signal acquisition failures, the discrete safety mechanisms often create protection blind spots due to a lack of coordination logic. Summary of the Invention
[0004] In view of the shortcomings of the prior art, the purpose of this application is to provide a motor controller and control method, and a vehicle, which can realize full-link hardware security collaborative protection and build a comprehensive security protection network on the integrated drive and control hardware platform through a single-channel redundant interlock architecture.
[0005] In a first aspect, embodiments of this application provide a motor controller, which includes a control module, a drive module, a sampling module, an electrical safety monitoring module, and an active short-circuit protection module. The drive module is used to drive the motor to run according to the control signal output by the control module; The sampling module is used to collect motor operating parameters and send the motor operating parameters to the control module and the electrical safety monitoring module; The electrical safety monitoring module is used to receive the motor operating parameters, make safety judgments based on preset thresholds, and when the motor operating parameters are detected to exceed the preset thresholds, output a hardware shutdown signal to the active short circuit protection module and output monitoring status information to the control module. The active short-circuit protection module is connected to the control module and the electrical safety monitoring module respectively, and is used to control the drive module to enter a short-circuit state when it receives a hardware shutdown signal from the control module or the electrical safety monitoring module.
[0006] In the above technical solution, the sampling module simultaneously sends operating parameters to both the control module and the electrical safety monitoring module, freeing the safety monitoring function from sole reliance on the control module. The independent safety judgment of the electrical safety monitoring module and the software control of the control module form a dual protection system. Under normal operating conditions, the control module leads the motor controller operation; under abnormal operating conditions, the electrical safety monitoring module can independently trigger protection actions. Simultaneously, the active short-circuit protection module uses OR logic to receive shutdown signals from two independent sources; either safety mechanism detecting a fault can trigger protection. This dual protection architecture not only covers single-point fault scenarios but also effectively addresses composite failure modes where different faults occur simultaneously in both the control module and the electrical safety monitoring module, significantly improving overall safety and reliability.
[0007] In one embodiment, the system further includes a power supply module configured to provide power to the control module, the drive module, the sampling module, the electrical safety monitoring module, and the active short-circuit protection module.
[0008] In the above technical solution, by setting up an independent power supply module to provide unified power supply for all functional modules inside the motor controller, it is possible to stably and continuously output working voltage and working current to each module, ensuring the normal and stable operation of signal processing modules such as control modules and sampling modules, as well as execution modules such as drive modules and protection modules.
[0009] In one embodiment, the power module is signal-connected to both the control module and the active short-circuit protection module. The power module is used to send a hardware shutdown signal to the active short-circuit protection module and a fault indication signal to the control module when a power fault is detected. When the control module receives the fault indication signal and confirms the power failure, it sends a hardware shutdown signal to the active short-circuit protection module. When the active short-circuit protection module receives a hardware shutdown signal from the power supply module or a hardware shutdown signal from the control module, it controls the drive module to enter a short-circuit state.
[0010] The above technical solution incorporates a layered power fault detection and linkage protection mechanism, enabling the power module to not only provide power supply but also possess independent fault monitoring and hardware protection triggering capabilities. The power module can monitor its own power supply status in real time. Once a power fault is detected, it can directly output a hardware shutdown signal to the active short-circuit protection module, rapidly triggering protection action via the hardware link, thus avoiding protection lag issues caused by software processing delays and main control failures. Simultaneously, the power module can report a fault indication signal to the control module. After fault verification and logical judgment, the control module outputs a secondary hardware shutdown signal at the software level. The active short-circuit protection module employs a dual-signal OR logic response, forming a dual protection link against power faults through the power module's hardware direct-drive protection and the control module's software verification protection.
[0011] In one embodiment, the power module includes a main power supply and a redundant power supply, wherein the redundant power supply provides power when the main power supply fails.
[0012] In the above technical solution, a dual-power supply architecture with primary and redundant power supplies is configured for the power module, achieving redundant backup design of the power supply link. Under normal operating conditions, the primary power supply provides stable power to all functional modules of the motor controller, ensuring the normal operation of the entire machine under normal working conditions. When the power module detects a fault such as power failure, abnormal voltage, or output failure of the primary power supply, it can automatically switch to the redundant power supply to seamlessly take over the power supply from the primary power supply. This effectively avoids the risks of power outage, system shutdown, and protection function failure caused by the failure of the primary power supply under a single power supply structure, and avoids safety hazards such as motor control failure and paralysis of fault protection links due to power interruption. At the same time, during the primary power supply fault switching process, the core safety function modules such as the control module, electrical safety monitoring module, and active short-circuit protection module are always guaranteed to remain powered and function properly, ensuring the continuous effectiveness of core functions such as fault monitoring, signal feedback, and short-circuit protection.
[0013] In one embodiment, the power module includes a watchdog monitoring unit, a voltage monitoring unit, a current monitoring unit, and a fault monitoring unit; The watchdog monitoring unit is used to monitor the watchdog enable signal status of the control module; The voltage monitoring unit is used to monitor the input voltage status of the control module; The current monitoring unit is used to monitor the input current status of the control module; The fault monitoring unit is used to monitor the safety fault status of the control module; When any one of the watchdog monitoring unit, voltage monitoring unit, current monitoring unit, and fault monitoring unit detects an abnormal state, the power module outputs a fault handling signal to the control module. The fault handling signal includes at least one of a reset signal, a diagnostic signal, or an interrupt signal.
[0014] In the above technical solution, by setting up a watchdog monitoring unit, a voltage monitoring unit, a current monitoring unit, and a fault monitoring unit, comprehensive and three-dimensional real-time monitoring of the control module's operating status is achieved. Specifically, the watchdog monitoring unit can effectively identify software anomalies such as program crashes, freezes, and logic freezes in the control module; the voltage and current monitoring units can accurately capture electrical anomalies such as overvoltage, undervoltage, overcurrent, and current shortage in the control module's power supply input; and the fault monitoring unit can track the control module's safety fault status in real time, covering multiple fault scenarios including software malfunctions, electrical parameter anomalies, and safety logic anomalies.
[0015] By employing multiple monitoring units or a logic anomaly detection mechanism, once an anomaly is identified in any monitoring dimension, the power module can output differentiated fault handling signals such as reset signals, diagnostic signals, or interrupt signals, achieving fault stratification and precise handling. Compared to single fault monitoring methods, this multi-dimensional monitoring architecture can predict and promptly detect latent faults and transient anomalies in the control module, completing pre-processing before the fault spreads and causes motor runaway, protection malfunction, or system failure.
[0016] In one embodiment, the active short-circuit protection module includes a first NOT gate, a second NOT gate, a third NOT gate, a first OR gate, an AND gate, a second OR gate, a transistor, and a first resistor; The input of the first NOT gate receives a safety fault signal from the control module, the input of the second NOT gate receives an overcurrent and overvoltage interrupt signal from the electrical safety monitoring module, and the input of the third NOT gate receives an enable control signal from the control module. The first input terminal and the second input terminal of the first OR gate are respectively connected to the output terminals of the first NOT gate, the second NOT gate and the third NOT gate; The first input terminal of the AND gate is connected to the output terminal of the third NOT gate, and the second input terminal receives the status control signal from the control module. The first input terminal and the second input terminal of the second OR gate are respectively connected to the output terminal of the first OR gate and the output terminal of the AND gate; The base of the transistor is connected to the output of the second OR gate, the collector of the transistor is connected to the power supply through the first resistor, and a hardware shutdown enable signal is output. The emitter of the transistor is grounded. The hardware shutdown state signal is led out from the output of the second OR gate.
[0017] In the above technical solution, the active short-circuit protection module achieves multiple safety protection mechanisms through the ingenious design of hardware logic circuits, and has significant technical advantages.
[0018] First, by integrating safety fault signals from the control module and overcurrent and overvoltage interruption signals from the electrical safety monitoring module, a multi-dimensional safety monitoring system is constructed to ensure timely response when any safety threat occurs, thus significantly improving the safety and reliability of the system.
[0019] Secondly, the protection function is implemented using pure hardware logic circuits, which avoids the delay and fault risk that may be caused by software control. The response speed is faster and the protection action is more timely and accurate. Especially in high-speed motor systems, this hardware-level fast protection can effectively prevent the fault from escalating.
[0020] Furthermore, by introducing a logical combination of enable control signals and status control signals, flexible configuration of protection functions is achieved. Protection can be forcibly triggered in emergency situations, or the protection function can be temporarily disabled in normal maintenance mode, thus improving the operability and adaptability of the system.
[0021] In addition, the dual output design of hardware shutdown enable signal and hardware shutdown status signal not only realizes direct control of power switching transistors, but also provides real-time feedback of protection status, which facilitates system status monitoring and fault diagnosis.
[0022] Finally, the circuit structure of the transistor output stage combined with the first resistor ensures the stability of the output signal and the driving capability. It can reliably drive the subsequent power switching transistors into an active short-circuit state, so that when serious faults such as overcurrent and overvoltage occur in the motor drive system, the motor windings are quickly short-circuited, the regenerative energy is consumed, the bus voltage is prevented from soaring, the power devices and the motor body are protected from damage, and the service life of the entire drive system is extended.
[0023] In one embodiment, the system further includes a fourth NOT gate, the input of which receives a safety status signal from the power module, and the output of which is connected to the third input of the first OR gate.
[0024] In the above technical solution, by adding a fourth NOT gate to receive the safety status signal from the power module and connecting its output to the third input of the first OR gate, the safety and reliability of the active short-circuit protection system are significantly improved. Specifically, a real-time monitoring and rapid response mechanism for the power status is realized. When the power module malfunctions, the fourth NOT gate can immediately detect the change in the safety status signal and trigger a protection action through the logic operation of the first OR gate, thereby activating active short-circuit protection at the first moment of power abnormality and preventing damage to the motor controller caused by power instability.
[0025] At the same time, the power supply safety status is incorporated into the overall protection system, forming a triple protection mechanism with the original overcurrent and overvoltage interruption signals and safety fault signals. This greatly reduces the risk of system failure caused by a single fault point and improves the system's fault tolerance and safety level.
[0026] In addition, this purely hardware-based power status monitoring method avoids the delay of software processing, ensuring that a protection response can be completed within microseconds when a power failure occurs, effectively protecting the safety of personnel and equipment.
[0027] In one embodiment, the electrical safety monitoring module includes a first voltage divider circuit, a second voltage divider circuit, a first comparator, a second comparator, and a third OR gate; The first voltage divider circuit is connected between the power supply and ground, and outputs a first reference voltage to the inverting input of the first comparator. The non-inverting input of the first comparator receives the three-phase current detection signal. When the voltage value of the three-phase current detection signal is greater than the first reference voltage, the first comparator outputs an overcurrent interrupt signal. The second voltage divider circuit is connected between the power supply and ground, and outputs a second reference voltage to the inverting input of the second comparator. The non-inverting input of the second comparator receives the bus voltage detection signal. When the voltage value of the bus voltage detection signal is greater than the second reference voltage, the second comparator outputs an overvoltage interrupt signal. The two inputs of the third OR gate are respectively connected to the outputs of the first comparator and the second comparator, and the output of the third OR gate outputs an overcurrent and overvoltage interrupt signal to the active short-circuit protection module.
[0028] In the above technical solution, a pure hardware analog circuit architecture is adopted. The first voltage divider circuit and the second voltage divider circuit generate accurate first reference voltage and second reference voltage respectively. The first comparator and the second comparator are used to make threshold judgment, avoiding the inherent delay of software processing. Fault detection and output protection signal can be completed in microseconds.
[0029] Secondly, the modular design integrates overcurrent protection and overvoltage protection functions into one unit. The first comparator is dedicated to monitoring the three-phase current detection signal to ensure that overcurrent protection is triggered in a timely manner under abnormal conditions such as motor stall or short circuit. The second comparator focuses on bus voltage monitoring and quickly starts overvoltage protection when regenerative braking or grid fluctuations cause abnormal rise in bus voltage. By setting up a dual protection mechanism, the safety margin of the system is greatly improved.
[0030] Furthermore, by logically merging the two protection signals through a third OR gate, the signal transmission path is simplified, and the number of external connection cables is reduced. This not only improves the system's anti-interference capability but also reduces the overall circuit complexity and cost.
[0031] Furthermore, the overcurrent and overvoltage interrupt signals output by the electrical safety monitoring module can directly drive the subsequent active short-circuit protection circuit, forming a complete hardware protection link. Even if the software control system fails or the response is delayed, it can still independently complete the key protection functions. This hardware redundancy design significantly enhances the functional safety and reliability of the system, effectively prevents equipment damage or even safety accidents caused by electrical faults, extends the service life of the motor drive system, and reduces maintenance costs.
[0032] In one embodiment, the control module includes a redundantly arranged first analog-to-digital converter (ADC) and a second ADC. The sampling module synchronously inputs the collected motor operating parameters to the first and second ADCs for analog-to-digital conversion. The outputs of the first and second ADCs are mutually verified. The drive chip is used to drive the motor to run according to the control signal output by the control module.
[0033] In the above technical solution, a dual analog-to-digital converter (ADC) redundancy verification architecture is added to achieve dual redundancy processing for the analog-to-digital conversion process of motor operating parameters. The analog operating parameters output by the sampling module are synchronously sent to two independent first and second ADCs to complete the conversion calculation in parallel. By comparing and verifying the conversion results of the two channels, single-point anomalies in the ADC conversion process can be identified in real time, including single-channel converter failure, conversion accuracy deviation, data distortion, and sampling point loss. Compared with the traditional single ADC solution, this solution can effectively avoid problems such as distorted motor operating parameter acquisition, control logic misjudgment, and false triggering of safety protection caused by ADC conversion anomalies, thus making up for the reliability shortcomings of a single sampling and conversion link.
[0034] In one embodiment, the first analog-to-digital converter is powered by a first independent power supply, and the second analog-to-digital converter is powered by a second independent power supply; The power supply circuits of the first independent power supply and the second independent power supply are isolated from each other.
[0035] In the above technical solution, by configuring a first independent power supply and a second independent power supply for the first analog-to-digital converter and the second analog-to-digital converter respectively, and by physically isolating the two power supply circuits from each other, problems such as common-source interference, power supply crosstalk, synchronization voltage drop, and power supply fault coupling that occur in the traditional shared power supply architecture can be completely avoided. When one power supply circuit experiences abnormal faults such as voltage fluctuations, electrical interference, or short-circuit failure, it will not affect the other independent power supply circuit, ensuring that the two analog-to-digital conversion links do not interfere with each other and operate independently and reliably.
[0036] Secondly, embodiments of this application provide a control method for a motor controller, comprising: The control module outputs control signals to drive the drive module and control the motor to run. The motor operating parameters are collected by the sampling module and transmitted to the control module and the electrical safety monitoring module respectively. The electrical safety monitoring module receives the motor's operating parameters and makes a safety judgment based on preset thresholds. When the motor operating parameters are detected to exceed the preset threshold, the electrical safety monitoring module outputs a hardware shutdown signal to the active short circuit protection module and outputs monitoring status information to the control module. When the active short-circuit protection module receives a hardware shutdown signal output by either the control module or the electrical safety monitoring module, it controls the drive module to enter a short-circuit state.
[0037] The above technical solution constructs a hierarchical control and safety protection logic that integrates hardware and software, achieving closed-loop operation of precise motor control and proactive fault protection. A dual-channel synchronous transmission mechanism for sampling parameters is adopted, synchronously distributing motor operating parameters to both the control module and the electrical safety monitoring module. This enables shared monitoring and independent judgment of operating data, eliminating the single dependence of the safety monitoring function on the main control software. Under normal operating conditions, the control module outputs control signals, which drive the motor to operate stably, ensuring the motor efficiently and accurately completes various operating commands. When motor operating parameters are abnormal or exceed preset safety thresholds, the electrical safety monitoring module can independently perform hardware-level safety judgments, quickly outputting hardware shutdown signals without relying on the control module's logic operations. Simultaneously, it provides feedback on monitoring status information, enabling rapid fault detection and accurate reporting.
[0038] In one embodiment, it further includes: The power supply module provides power to the control module, drive module, sampling module, electrical safety monitoring module, and active short-circuit protection module. When the power module detects a power failure, it outputs a hardware shutdown signal to the active short-circuit protection module and a fault indication signal to the control module. After receiving the fault indication signal and confirming the power failure, the control module outputs a hardware shutdown signal to the active short-circuit protection module. When the active short-circuit protection module receives a hardware shutdown signal output by the power module or control module, it controls the drive module to enter a short-circuit state.
[0039] In the above technical solution, a power supply module provides unified power to all functional modules of the entire machine, ensuring the basic working conditions of each control, sampling, monitoring, and protection unit, and ensuring the continuous effectiveness of system control and protection functions. Simultaneously, a dual-path protection trigger mechanism is set up for power failure scenarios. The power supply module can directly output a hardware shutdown signal when it detects a power anomaly, achieving ultra-fast fallback protection without software delay through a direct hardware link, unaffected by the operating status of the control module; alternatively, it can report a fault indication signal to the control module, which, after fault confirmation and logical verification, outputs a secondary software-level shutdown protection command.
[0040] In one embodiment, it further includes: The watchdog enable signal status of the control module is monitored by the watchdog monitoring unit in the power module. The input voltage status of the control module is monitored by the voltage monitoring unit; The input current status of the control module is monitored by the current monitoring unit; The safety fault status of the control module is monitored through the fault monitoring unit; When any monitoring unit detects an abnormal state, the power module outputs a fault handling signal to the control module. The fault handling signal includes at least one of a reset signal, a diagnostic signal, or an interrupt signal.
[0041] In one embodiment, it further includes: The sampling module synchronously inputs the collected motor operating parameters to the first analog-to-digital converter and the second analog-to-digital converter. The motor operating parameters are converted from analog to digital using the first analog-to-digital converter and the second analog-to-digital converter. The conversion results of the first analog-to-digital converter and the second analog-to-digital converter are mutually verified; The first analog-to-digital converter is powered by a first independent power supply, the second analog-to-digital converter is powered by a second independent power supply, and the power supply circuits of the first independent power supply and the second independent power supply are isolated from each other.
[0042] Thirdly, this application provides a vehicle including an electric drive system, the electric drive system including the aforementioned motor controller. Attached Figure Description
[0043] To more clearly illustrate the technical solutions in the embodiments of this application or the background art, the accompanying drawings used in the embodiments of this application will be described below.
[0044] Figure 1 This is a schematic diagram of one embodiment of the motor controller disclosed in this application; Figure 2This is a schematic diagram of another embodiment of the motor controller disclosed in this application; Figure 3 This is a schematic diagram of another embodiment of the motor controller disclosed in this application; Figure 4 This is a schematic diagram of another embodiment of the motor controller disclosed in this application; Figure 5 This is a circuit diagram of the active short-circuit protection module disclosed in an embodiment of this application; Figure 6 This is a circuit diagram of the electrical safety monitoring module disclosed in an embodiment of this application; Figure 7 This is a schematic flowchart of the control method of the motor controller disclosed in the embodiments of this application; Figure 8 This is a schematic diagram of the protection mechanism for main power supply failure disclosed in an embodiment of this application; Figure 9 This is a schematic diagram of the protection mechanism for control module failure disclosed in an embodiment of this application; Figure 10 This is a schematic diagram of the protection mechanism for motor operating parameters exceeding limits as disclosed in an embodiment of this application.
[0045] Explanation of reference numerals in the attached figures: 1-Control module, 11-First analog-to-digital converter, 12-First analog-to-digital converter 2-Driver module, 21-Driver chip, 22-Power module 3-Sampling module, 31-Eddy current acquisition unit, 32-Motor temperature acquisition unit, 33-Bus voltage acquisition unit, 34-Three-phase voltage acquisition unit. 4-Electrical safety monitoring module, 41-First voltage divider circuit, 411-Second resistor, 412-Third resistor, 42-Second voltage divider circuit, 421-Fourth resistor, 422-Fifth resistor, 43-First comparator, 44-Second comparator, 45-Third OR gate, 5-Active short-circuit protection module, 51-First NOT gate, 52-Second NOT gate, 53-Third NOT gate, 54-Fourth NOT gate, 55-First OR gate, 56-AND gate, 57-Second OR gate, 58-Transistor, 59-First resistor; 6-Power supply module, 61-Main power supply, 62-Redundant power supply. Detailed Implementation
[0046] In the field of functional safety technology for motor controllers in new energy vehicles, existing safety design schemes generally suffer from the phenomenon of "modular silos," with a lack of deep hardware-level collaboration in the safety mechanisms of various key functional modules. Specifically, the safety monitoring functions of core modules such as power management units, main control units, power drive units, and signal acquisition units often adopt independent design patterns. The safety status detection, fault diagnosis, and protection execution of each module form separate technical loops, failing to build a unified safety protection network covering the entire hardware link.
[0047] While existing solutions attempt to improve safety through multi-level shutdown path design, their safety coverage remains limited. Typical solutions focus only on shutdown path optimization under specific fault scenarios, failing to build a hardware-level collaborative protection system encompassing the power supply, main control, driver, and sampling stages. At the hardware implementation level, there is a lack of deep signal linkage mechanisms between the power management unit and the main control unit and power drive unit, such as hardware-level interaction of critical safety signals like watchdog enable signals, reset signals, and emergency shutdown signals. Furthermore, multi-dimensional hardware redundancy technologies, such as dual ADC redundant acquisition and independent overvoltage and overcurrent monitoring, are not fully integrated. These technical limitations result in insufficient safety protection capabilities for complex fault scenarios, making it difficult to meet the stringent requirements of ASIL D functional safety level for single-point fault coverage and potential fault coverage. This has become a major technical bottleneck in achieving high-level functional safety under the integrated drive and control architecture.
[0048] To address the aforementioned technical issues, this application discloses a motor controller and control method, as well as a vehicle, which can achieve end-to-end hardware security collaborative protection and construct a comprehensive security protection network on the integrated drive and control hardware platform through a single-channel redundant interlock architecture.
[0049] The embodiments of this application are described below with reference to the accompanying drawings.
[0050] In one embodiment, see Figure 1 As shown in the figure, this application discloses a motor controller, which includes a control module 1, a drive module 2, a sampling module 3, an electrical safety monitoring module 4, and an active short-circuit protection module 5. The drive module 2 drives the motor to run according to the control signal output by the control module 1. The sampling module 3 collects motor operating parameters and sends these parameters to the control module 1 and the electrical safety monitoring module 4. The electrical safety monitoring module 4 receives the motor operating parameters, performs a safety judgment based on a preset threshold, and outputs a hardware shutdown signal to the active short-circuit protection module 5 when the detected motor operating parameters exceed the preset threshold, while simultaneously outputting monitoring status information to the control module 1. The active short-circuit protection module 5 is connected to both the control module 1 and the electrical safety monitoring module 4, and controls the drive module 2 to enter a short-circuit state when it receives a hardware shutdown signal from either the control module 1 or the electrical safety monitoring module 4.
[0051] In this embodiment, the motor controller adopts an integrated drive and control hardware architecture, achieving full-module safety coordination through a hardware-level signal linkage mechanism. The sampling module 3 simultaneously sends operating parameters to both the control module 1 and the electrical safety monitoring module 4, freeing the safety monitoring function from its sole dependence on the control module.
[0052] The independent safety judgment of the electrical safety monitoring module 4 and the software control of the control module 1 form a dual protection system. Under normal operating conditions, the control module 1 leads the operation of the motor controller, while under abnormal operating conditions, the electrical safety monitoring module 4 can independently trigger protection actions. Simultaneously, the active short-circuit protection module 5 uses OR logic to receive shutdown signals from two independent sources; either safety mechanism can trigger protection upon detecting a fault. This dual protection architecture not only covers single-point fault scenarios but also effectively addresses composite failure modes where different faults occur simultaneously in both the control module 1 and the electrical safety monitoring module 4, significantly improving overall safety and reliability.
[0053] In one alternative implementation, see Figure 2 As shown in the figure, a motor controller disclosed in this application embodiment also includes a power supply module 6, which is configured to provide power to the control module 1, the drive module 2, the sampling module 3, the electrical safety monitoring module 4, and the active short circuit protection module 5.
[0054] In this embodiment, the power supply module 6 is integrated into the motor controller 6 to provide unified power to the relevant functional modules. It can stably and continuously output working voltage and working current to each module, ensuring the normal and stable operation of signal processing modules such as control module 1 and sampling module 3, as well as execution modules such as drive module 2 and active short circuit protection module 5.
[0055] In one optional embodiment, the power module 6 is signal-connected to both the control module 1 and the active short-circuit protection module 5. When a power failure is detected, the power module 6 sends a hardware shutdown signal to the active short-circuit protection module 5 and a fault indication signal to the control module 1. When the control module 1 receives the fault indication signal and confirms the power failure, it sends a hardware shutdown signal to the active short-circuit protection module 5. When the active short-circuit protection module 5 receives the hardware shutdown signal from either the power module 6 or the control module 1, it controls the drive module 2 to enter a short-circuit state.
[0056] Power module 6 can monitor its own power supply status in real time. Once a power supply fault is detected, it can directly output a hardware shutdown signal to the active short-circuit protection module 5, quickly triggering protection action through the hardware link, avoiding protection lag issues caused by software processing delays and main control failures. Simultaneously, power module 6 can report a fault indication signal to control module 1. After fault verification and logic determination, control module 1 outputs a secondary hardware shutdown signal at the software level. The active short-circuit protection module 5 uses a dual-signal OR logic response, forming a dual protection link against power supply faults through the hardware direct-drive protection of power module 6 and the software verification protection of the control module.
[0057] Control module 1, drive module 2, sampling module 3, electrical safety monitoring module 4, active short-circuit protection module 5, and power supply module 6 are interconnected via hard-wired safety signals, forming a single-channel redundant interlocking network. The safety signals of each module mutually constrain and verify each other. Active short-circuit protection module 5 is triple-triggered by control module 1, electrical safety monitoring module 4, and power supply module 6, completely eliminating the risk of single-point failure. Multiple ASIL D-level chips jointly monitor and achieve system-level end-to-end safety protection, stably meeting ASIL D-level functional safety requirements under a single MCU architecture.
[0058] In one optional implementation, the power module 6 includes a main power supply 61 and a redundant power supply 62. When the main power supply 61 fails, the redundant power supply 62 provides power. By configuring the power module 6 with a dual-power supply architecture of main and redundant power supplies, a redundant backup design for the power supply link is achieved. Under normal operating conditions, the main power supply 61 provides stable power to the various functional modules of the motor controller, ensuring the normal operation of the entire machine under normal working conditions. When the power module 6 detects a fault such as power failure, abnormal voltage, or output failure of the main power supply, it can automatically switch to the redundant power supply 62 to provide power, seamlessly taking over the power supply from the main power supply 61. This configuration effectively avoids the risks of power outage, system shutdown, and protection function failure caused by the failure of the main power supply under a single power supply structure, and avoids safety hazards such as motor control failure and paralysis of the fault protection link due to power interruption. At the same time, during the main power supply fault switching process, the core safety function modules such as the control module 1, electrical safety monitoring module 4, and active short-circuit protection module 5 are always kept powered on and do not fail, ensuring the continuous effectiveness of core functions such as fault monitoring, signal feedback, and short-circuit protection.
[0059] In one optional embodiment, the power module 6 includes a watchdog monitoring unit, a voltage monitoring unit, a current monitoring unit, and a fault monitoring unit; The watchdog monitoring unit is used to monitor the watchdog enable signal status of the control module; The voltage monitoring unit is used to monitor the input voltage status of the control module; The current monitoring unit is used to monitor the input current status of the control module; The fault monitoring unit is used to monitor the safety fault status of the control module; When any one of the watchdog monitoring unit, voltage monitoring unit, current monitoring unit, and fault monitoring unit detects an abnormal state, the power module 6 outputs a fault handling signal to the control module 1. The fault handling signal includes at least one of a reset signal, a diagnostic signal, or an interrupt signal.
[0060] In this embodiment, by setting up a watchdog monitoring unit, a voltage monitoring unit, a current monitoring unit, and a fault monitoring unit, comprehensive and three-dimensional real-time monitoring of the operating status of the control module 1 is achieved. The watchdog monitoring unit can effectively identify software anomalies such as program crashes, freezes, and logic freezes in the control module 1. The voltage and current monitoring units can accurately capture electrical anomalies such as overvoltage, undervoltage, overcurrent, and current shortage in the power supply input of the control module 1. The fault monitoring unit can track the safety fault status of the control module 1 in real time, covering multiple fault scenarios such as software malfunctions, electrical parameter anomalies, and safety logic anomalies.
[0061] By employing multiple monitoring units or a logic anomaly detection mechanism, once an anomaly is identified in any monitoring dimension, the power module 6 can output differentiated fault handling signals such as reset signals, diagnostic signals, or interrupt signals, achieving fault stratification and precise handling. Compared to single fault monitoring methods, this multi-dimensional monitoring architecture can predict and promptly perceive latent faults and transient anomalies in the control module, completing pre-processing before the fault spreads and causes motor runaway, protection malfunction, or system failure.
[0062] For example, the main power supply 61 uses an ASIL D-grade automotive-grade PMIC (Power Management Integrated Circuit) chip, with the vehicle's KL_30 constant power input and multiple independent power outputs to power different modules of the motor controller.
[0063] The redundant power supply 62 uses an independent automotive-grade DC-DC chip. Its input is also a constant power supply from KL_30, and its output provides redundant power to different modules of the motor controller. It forms a competing power supply architecture with the PMIC main power supply. The two power supplies are physically isolated and there is no risk of common cause failure.
[0064] The voltage of the main power supply 61 is monitored in real time. When the voltage of the main power supply 61 is lower than the rated threshold, such as 9V for a 12V system, a seamless switch to the redundant power supply 62 is completed within ≤10us to ensure uninterrupted power supply.
[0065] KL_30 is a power attribute in automotive electrical systems, representing constant power. In the field of automotive electronics, automotive-grade DC-DC chips specifically refer to DC-DC converters that conform to automotive electronic standards, featuring high reliability, high temperature resistance, and vibration resistance, and are specifically designed for use in automotive environments.
[0066] In one alternative implementation, see Figure 5 As shown, the active short-circuit protection module 5 includes a first NOT gate 51, a second NOT gate 52, a third NOT gate 53, a first OR gate 55, an AND gate 56, a second OR gate 57, a transistor 58, and a first resistor 59.
[0067] The input of the first NOT gate 51 receives the safety fault signal ERRB from the control module 1, the input of the second NOT gate 52 receives the overcurrent and overvoltage interrupt signal INTB3 from the electrical safety monitoring module 4, and the input of the third NOT gate 52 receives the enable control signal FSENB from the control module 1.
[0068] The first input terminal and the second input terminal of the first OR gate 55 are respectively connected to the output terminals of the first NOT gate 51, the second NOT gate 52 and the third NOT gate 53.
[0069] The first input terminal of the AND gate 56 is connected to the output terminal of the third NOT gate 53, and the second input terminal receives the STATEL status control signal from the control module 1.
[0070] The first input terminal and the second input terminal of the second OR gate 57 are respectively connected to the output terminal of the first OR gate 55 and the output terminal of the AND gate 56.
[0071] The base of the transistor 58 is connected to the output of the second OR gate 57, and the collector of the transistor 58 is connected to the power module 6 through the first resistor 59. At the same time, it outputs a hardware shutdown enable signal FSENB-1, and the emitter of the transistor 58 is grounded. The hardware shutdown state signal FSS_LS is led out from the output of the second OR gate 57.
[0072] Further, see Figure 5 As shown, the active short-circuit protection module 5 also includes a fourth NOT gate 54. The input terminal of the fourth NOT gate 54 receives the safety status signal SSPB from the power supply module 6, and the output terminal of the fourth NOT gate 54 is connected to the third input terminal of the first OR gate 55.
[0073] Among them, the safety status signal SSPB from power module 6, the safety fault signal ERRB from control module 1, the overcurrent and overvoltage interrupt signal INTB3 from electrical safety monitoring module 4, and the enable control signal FSENB from control module 1 are active low signals, while the status control signal STATEL from control module 1 is active high signals. In the output signals, the hardware shutdown enable signal FSENB-1 is active low, and the hardware shutdown status signal FSS_LS is active high signals. A active high signal indicates that when the signal is at a logic high level, the function or state it represents is activated or valid; when the signal is at a logic low level, the function or state is disabled or invalid. Conversely, an active low signal indicates that when the signal is at a logic low level, the function or state it represents is activated or valid; when the signal is at a logic high level, the function or state is disabled or invalid.
[0074] See Figure 5 As shown, node A is located in the PMIC fault detection branch and is directly connected to the output of the fourth NOT gate 54. When SSPB is low (fault valid), node A outputs a high level, indicating that the PMIC power supply fault state has been captured.
[0075] Node B is located in the MCU fault detection branch and is directly connected to the output of the first NOT gate 51. When ERRB is low (fault valid), node B outputs a high level, indicating that the fault state of the control module has been identified.
[0076] Node C is located in the electrical safety monitoring branch and is directly connected to the output of the second NOT gate 52. When INTB3 is low (fault valid), node C outputs a high level, indicating that the electrical safety fault state has been detected.
[0077] Node D is located in the MCU active control logic branch and is directly connected to the output of the third NOT gate 53. When FSENB is low (enabled), node D outputs a high level, indicating that the MCU's active control request has been accepted by the system.
[0078] Node E is located in the fault priority determination circuit and is connected to the output of the first OR gate 55. When any fault detection node (A, B, or C) is high, node E outputs a high level, indicating that a hardware fault exists and needs to be handled first.
[0079] Node F is located in the control validity verification circuit and is connected to the output of AND gate 56. Node F outputs a high level when the MCU's active control request is valid and there is no hardware fault, indicating that the software control can be executed safely.
[0080] Node G: Located in the final protection decision circuit, it connects the output of the second OR gate 57 between nodes E and F. When a hardware fault occurs (node E is high) or a valid software control request is made (node F is high), node G outputs a high level, driving the final protection actuator.
[0081] The circuit signal logic states of the active short-circuit protection module under different fault scenarios are as follows.
[0082] When the motor controller is in normal operation, all input signals are invalid: the safety status signal SSPB of power module 6 is high, the safety fault signal ERRB of control module 1 is high, the overcurrent and overvoltage interrupt signal INTB3 of electrical safety monitoring module 4 is high, the enable control signal FSENB of control module 1 is high, and the status control signal STATEL is low. At this time, internal logic nodes A, B, C, D, E, F, and G are all kept at low levels, the hardware shutdown enable signal FSENB-1 is high (invalid), and the hardware shutdown status signal FSS_LS is low (invalid). The motor controller maintains normal operation mode.
[0083] When only power module 6 fails, the SSPB signal becomes active low, while the other input signals remain inactive. At this time, logic node A is set high, nodes E and G are set high, and nodes B, C, D, and F remain low. The output signal FSENB-1 becomes active low, and FSS_LS becomes active high. The motor controller immediately enters active protection mode, cutting off power output to prevent the fault from escalating.
[0084] When only control module 1 fails, the ERRB signal becomes low, while the other input signals remain inactive. At this time, logic node B is set high, nodes E and G are set high, and nodes A, C, D, and F remain low. The output signals also trigger FSENB-1 to go low and FSS_LS to go high, causing the motor controller to enter active protection mode, demonstrating the independence and reliability of the hardware protection mechanism.
[0085] When only overcurrent or overvoltage faults occur, the INTB3 signal becomes active low, while the other input signals remain inactive. At this time, logic node C is set high, nodes E and G are set high, and nodes A, B, D, and F remain low. The motor controller outputs a protection signal, entering active protection mode to ensure electrical safety.
[0086] Under fault-free conditions requiring active control from module 1, the FSENB signal becomes active low, the STATEL signal becomes active high, and other fault signals remain inactive. At this time, logic nodes D, F, and G are set high, node E is set low, and nodes A, B, and C remain low. Output signals FSENB-1 are low and FSS_LS are high, and the motor controller responds to the MCU's active control command by entering protection mode.
[0087] In scenarios with multiple concurrent faults, such as when a power module 6 fault and a control module 1 active control occur simultaneously, SSPB is low, FSENB is low, and STATEL is high. At this time, logic nodes A, D, E, F, and G are all set to high, and the motor controller can still correctly output protection signals. When a control module 1 fault causes a loss of control capability, ERRB is low and STATEL is low, and the motor controller automatically enters protection mode, independent of the MCU's control capabilities. When an overcurrent or overvoltage fault occurs simultaneously with a control module 1 active control, INTB3 is low, FSENB is low, and STATEL is high, and the motor controller prioritizes responding to safety fault signals.
[0088] Under extreme conditions, when power module 6, control module 1, and overcurrent / overvoltage faults occur simultaneously and the MCU attempts active control, all fault signals (SSPB, ERRB, INTB3) are active low, FSENB is low, and STATEL is high. At this time, all logic nodes A, B, C, D, E, F, and G are set high, output signals FSENB-1 are low, and FSS_LS is high. The motor controller reliably enters protection mode, verifying the robustness of the hardware protection mechanism under multiple fault conditions.
[0089] In one alternative implementation, see Figure 6 As shown, the electrical safety monitoring module 4 includes a first voltage divider circuit 41, a second voltage divider circuit 42, a first comparator 43, a second comparator 44, and a third OR gate 45.
[0090] The first voltage divider circuit 41 is connected between the power module 6 and ground, and outputs the first reference voltage to the inverting input of the first comparator 43. The non-inverting input of the first comparator 43 receives the three-phase current detection signal. When the voltage value of the three-phase current detection signal is greater than the first reference voltage, the first comparator 43 outputs an overcurrent interrupt signal.
[0091] The second voltage divider circuit 42 is connected between the power module 6 and ground, and outputs the second reference voltage to the inverting input of the second comparator 44. The non-inverting input of the second comparator 44 receives the bus voltage detection signal. When the voltage value of the bus voltage detection signal is greater than the second reference voltage, the second comparator 44 outputs an overvoltage interrupt signal. The two input terminals of the third OR gate 45 are respectively connected to the output terminals of the first comparator 43 and the second comparator 44, and the output terminal of the third OR gate 45 outputs an overcurrent and overvoltage interrupt signal to the active short circuit protection module 5.
[0092] Specifically, the first voltage divider circuit 41 includes a second resistor 411 and a third resistor 412, wherein one end of the second resistor 411 is connected to the output terminal of the power module 6, and the other end is connected to one end of the third resistor 412, and the other end of the third resistor 412 is grounded; through the series voltage divider effect of the second resistor 411 and the third resistor 412, a stable first reference voltage is generated at the connection node of the two.
[0093] The second voltage divider circuit 42 includes a fourth resistor 421 and a fifth resistor 422. One end of the fourth resistor 421 is connected to the output terminal of the power module 6, and the other end is connected to one end of the fifth resistor 422. The other end of the fifth resistor 422 is grounded. Through the series voltage divider effect of the fourth resistor 421 and the fifth resistor 422, a stable second reference voltage is generated at the connection node of the two.
[0094] It should be noted that by precisely configuring the resistance ratios of the second resistor 411, the third resistor 412, the fourth resistor 421, and the fifth resistor 422, the first reference voltage and the second reference voltage that meet the system requirements can be obtained respectively, providing an accurate reference level for the subsequent comparator circuit or analog-to-digital conversion module.
[0095] In one alternative implementation, see Figure 3 As shown, the control module 1 includes a redundantly arranged first analog-to-digital converter 11 and second analog-to-digital converter 12. The sampling module 3 synchronously inputs the collected motor operating parameters to the first analog-to-digital converter 11 and the second analog-to-digital converter 12 for analog-to-digital conversion. The output results of the first analog-to-digital converter 11 and the second analog-to-digital converter 12 are mutually verified. The drive chip is used to drive the motor to run according to the control signal output by the control module.
[0096] Because the analog operating parameters output by sampling module 3 are synchronously fed into two independent first analog-to-digital converters 11 and second analog-to-digital converters 12 to complete the conversion operation in parallel, single-point anomalies in the analog-to-digital conversion process can be identified in real time by comparing and verifying the conversion results of the two channels. These anomalies include single-channel converter failure, conversion accuracy deviation, data distortion, and sampling point loss. Compared with traditional single analog-to-digital conversion schemes, this approach effectively avoids problems such as distorted motor operating parameter acquisition, misjudgment of control logic, and false triggering of safety protection caused by analog-to-digital conversion anomalies, thus compensating for the reliability shortcomings of a single sampling and conversion link.
[0097] In one optional embodiment, the first analog-to-digital converter 11 is powered by a first independent power supply, and the second analog-to-digital converter 12 is powered by a second independent power supply; the power supply circuits of the first independent power supply and the second independent power supply are isolated from each other. It should be noted that the first independent power supply and the second independent power supply are two isolated power supply circuits led out from the power module 6.
[0098] By configuring a first independent power supply for the first analog-to-digital converter 11 and a second independent power supply for the second analog-to-digital converter 12, and physically isolating the two power supply circuits from each other, problems such as common-source interference, power supply crosstalk, synchronization voltage drop, and power supply fault coupling that occur in traditional shared-power-supply architectures can be completely avoided. When one power supply circuit experiences abnormal faults such as voltage fluctuations, electrical interference, or short-circuit failures, it will not affect the other independent power supply circuit, ensuring that the two analog-to-digital conversion links do not interfere with each other and operate independently and reliably.
[0099] In one embodiment, this application provides a control method for a motor controller, see [link to relevant documentation]. Figure 7 As shown, it includes: The control module 1 outputs a control signal to drive the drive module 2 to control the motor operation; The motor operating parameters are collected by the sampling module 3 and transmitted to the control module 1 and the electrical safety monitoring module 4 respectively. The electrical safety monitoring module 4 receives motor operating parameters and makes safety judgments based on preset thresholds. When the motor operating parameters are detected to exceed the preset threshold, the electrical safety monitoring module 4 outputs a hardware shutdown signal to the active short circuit protection module 5, and at the same time outputs monitoring status information to the control module 1. When the active short-circuit protection module 5 receives a hardware shutdown signal from either the control module 1 or the electrical safety monitoring module 4, the control drive module 2 enters a short-circuit state.
[0100] After receiving the monitoring status information output by the electrical safety monitoring module 4, the control module 1 executes the following verification and judgment process: Based on the raw data transmitted by sampling module 3, the abnormal parameters are cross-validated; and the authenticity of the abnormality is determined by combining the current operating status of the motor and historical data.
[0101] If the verification confirms that the motor operating parameters do indeed exceed the preset threshold, a second hardware shutdown signal is output to the active short-circuit protection module 5 to ensure that the drive module 2 remains in the short-circuit protection state. If the verification confirms that the motor operating parameters do not exceed the preset threshold, i.e., a false alarm, a reset signal is sent to the electrical safety monitoring module 4 and the active short circuit protection module 5 respectively, so that the drive module 2 is removed from the short circuit protection state and resumes normal operation.
[0102] In this embodiment, a hierarchical control and safety protection logic with hardware and software collaboration is constructed to achieve closed-loop operation of precise motor control and proactive fault protection. A dual-channel synchronous transmission mechanism for sampling parameters is adopted to synchronously distribute motor operating parameters to control module 1 and electrical safety monitoring module 4, enabling shared monitoring and independent judgment of operating data, eliminating the single dependence of the safety monitoring function on the main control software. Under normal operating conditions, control module 1 outputs control signals, which drive drive module 2 to drive the motor to operate stably, ensuring the motor efficiently and accurately completes various operating commands. When motor operating parameters are abnormal or exceed preset safety thresholds, electrical safety monitoring module 4 can independently complete hardware-level safety judgments, quickly outputting hardware shutdown signals without relying on the logic operations of control module 1, while simultaneously feeding back monitoring status information, achieving rapid fault detection and accurate reporting.
[0103] In an optional embodiment, the control method of the motor controller provided in this application further includes: providing power to the control module 1, drive module 2, sampling module 3, electrical safety monitoring module 4, and active short-circuit protection module 5 through the power module 6. The power module 6 includes a main power supply 61 and a redundant power supply 62. The main power supply 61 uses a PMIC chip, and the redundant power supply 62 uses an independent automotive-grade DC-DC chip. Both power supplies have their input terminals connected to a KL_30 constant power supply.
[0104] When power module 6 detects a power fault, it outputs a hardware shutdown signal to active short-circuit protection module 5 and a fault indication signal to control module 1. Specifically, when power module 6 detects a power fault, see [link to relevant documentation]. Figure 4 As shown, if the main power supply 61 experiences abnormal PMIC input voltage, output voltage drop, or over-temperature protection, the dual-path protection mechanism will be activated simultaneously. First protection path: The PMIC chip in the power module 6 directly outputs a hardware shutdown signal to the active short circuit protection module 5. After receiving the SSPB signal, the active short circuit protection module 5 immediately outputs a hardware shutdown status signal and a hardware shutdown enable signal to the driver chip 21. The driver chip 21 controls the power module 22 to enter the active short circuit protection mode and short-circuit the three-phase windings of the motor.
[0105] The second protection path: The PMIC chip in power module 6 outputs a fault indication signal (interrupt signal INTB1) to control module 1, i.e., the MCU. After receiving the INTB1 signal, control module 1 combines the reset signal and diagnostic signal to make a comprehensive judgment to confirm the authenticity of the power fault. If it is confirmed to be a real power fault, control module 1 outputs an enable control signal and a status control signal to active short-circuit protection module 5. After receiving the control signal, active short-circuit protection module 5 outputs a hardware shutdown status signal and a hardware shutdown enable signal to driver chip 21. Driver chip 21 controls power module 22 to maintain active short-circuit protection mode. When control module 1 confirms that it is not a real power fault, such as instantaneous voltage fluctuations or electromagnetic interference: it sends a reset command to the PMIC chip to clear the fault flag bit in the diagnostic register; it sends a reset signal to active short-circuit protection module 5 to ensure that the ASC circuit remains in normal working state; the system returns to normal operating mode, and at the same time increases the monitoring frequency of this signal to prevent faults from being missed.
[0106] In the event of a main power supply failure (61), the redundant power supply (62) seamlessly takes over the power supply, ensuring that critical safety modules such as control module 1, electrical safety monitoring module 4, and active short-circuit protection module 5 continuously receive stable power, and that the system's safety functions remain unaffected. Specifically, upon detecting a main power supply failure, the redundant power supply (62) automatically increases its output current capability to maintain the normal operating voltage of the critical system modules; control module 1 continues to perform fault diagnosis, status recording, and safety decision-making functions under the power supply of the redundant power supply (62); and electrical safety monitoring module 4 and active short-circuit protection module 5 maintain their hardware-level safety monitoring and protection capabilities under the power supply of the redundant power supply.
[0107] In this embodiment, a dual-path protection triggering mechanism is set up for power failure scenarios. When the power module 6 detects a power abnormality, it can directly output a hardware shutdown signal and achieve ultra-fast fallback protection without software delay by relying on the hardware direct connection link, which is not restricted by the operating status of the control module 1. Alternatively, it can report a fault indication signal to the control module 1, and after the control module 1 completes the fault confirmation and logic identification, it outputs a second software-level shutdown protection command.
[0108] For example, participate Figure 8 As shown, when the main power supply PMIC fails, three parallel operations are performed: 1) Switch to redundant power supply to ensure that critical control circuits continue to work.
[0109] 2) Output a hardware shutdown signal to the active short-circuit protection module 5 to prepare for subsequent protection actions; that is, the PMIC sends a safety status signal SSPB to the active short-circuit protection module 5, and the active short-circuit protection module 5 outputs a hardware shutdown status signal FSS_LS and a hardware shutdown enable signal FSENB-1 to the driver chip 21 of the driver module 2. The driver chip 21 controls the power module 22 to enter the active protection mode.
[0110] 3) Output a fault indication signal to control module 1 to notify control module 1 of the abnormal main power supply status. That is, PMIC sends an interrupt signal INTB1 to control module 1. Control module 1 combines the reset signal and diagnostic signal to determine whether PMIC is faulty. If PMIC is confirmed to be faulty, control module 1 sends an enable control signal FSENB and a status control signal STATEL to active short circuit protection module 5. Active short circuit protection module 5 outputs a hardware shutdown status signal FSS_LS and a hardware shutdown enable signal FSENB-1 to the driver chip 21 of driver module 2. Driver chip 21 controls power module 22 to enter active protection mode.
[0111] In one optional implementation, the control method for the motor controller provided in this application further includes: The watchdog enable signal status of the control module is monitored by the watchdog monitoring unit in power module 6. The input voltage status of the control module is monitored by the voltage monitoring unit; The input current status of the control module is monitored by the current monitoring unit; The safety fault status of the control module is monitored through the fault monitoring unit; When any monitoring unit detects an abnormal state, the power module outputs a fault handling signal to the control module. The fault handling signal includes at least one of a reset signal, a diagnostic signal, or an interrupt signal.
[0112] For example, see Figure 9 As shown, when control module 1 malfunctions, the following workflow will be followed to ensure equipment safety and maintain critical functions: The power supply module 6 continuously provides a stable power supply to the control module 1, drive module 2, sampling module 3, electrical safety monitoring module 4, and active short-circuit protection module 5. During normal operation, the operating status of the control module 1 is monitored in real time, including its operating sequence, data interaction, and internal self-test signals.
[0113] When a potential fault is detected in control module 1, such as through abnormal internal self-test signals, communication timeouts, or missing expected responses, the fault handling mechanism is immediately activated. At this time, two parallel operations are performed: 1) Output a hardware shutdown signal to the active short circuit protection module 5. The active short circuit protection module 5 outputs a hardware shutdown status signal FSS_LS and a hardware shutdown enable signal FSENB-1 to the driver chip 21 of the driver module 2. The driver chip 21 controls the power module 22 to enter the active protection mode.
[0114] 2) Output a fault indication signal to power module 6 for secondary confirmation and judgment. Combine the watchdog enable signal and voltage monitoring signal to further verify the actual fault state of control module 1, preventing malfunctions caused by momentary interference or temporary abnormalities. If the secondary judgment confirms that control module 1 is not faulty (i.e., the judgment result is "No"), clear the fault flag and restore normal monitoring state. If the control module is indeed faulty (i.e., the judgment result is "Yes"), maintain drive module 2 in a short-circuit state, cut off the power output path, prevent the fault from escalating, and protect the power devices.
[0115] For example, see Figure 10 As shown, in response to situations where motor operating parameters exceed limits, the following workflow should be followed to ensure equipment safety and maintain critical functions: The power supply module 6 continuously provides a stable power supply to the control module 1, drive module 2, sampling module 3, electrical safety monitoring module 4, and active short-circuit protection module 5. During normal operation, the motor operating parameters, including but not limited to current and temperature, are monitored in real time and compared with preset safety thresholds.
[0116] When the motor operating parameters are detected to exceed the preset threshold, the protection mechanism is immediately activated. At this time, the system performs two key operations: 1) Output a hardware shutdown signal to the active short circuit protection module 5. The active short circuit protection module 5 outputs a hardware shutdown status signal FSS_LS and a hardware shutdown enable signal FSENB-1 to the driver chip 21 of the driver module 2. The driver chip 21 controls the power module 22 to enter the active protection mode.
[0117] 2) An interrupt signal is output to control module 1, which performs a secondary confirmation and judgment to reassess whether the motor operating parameters actually exceed the preset threshold, preventing malfunctions caused by momentary interference or measurement noise. If the secondary judgment confirms that the motor parameters have returned to normal (i.e., the judgment result is "No"), the fault flag is cleared and normal monitoring is restored. If the motor parameters are still confirmed to be out of range (i.e., the judgment result is "Yes"), drive module 2 is kept in a short-circuit state to cut off the power output path, prevent motor overload damage, and protect the power devices.
[0118] In one optional implementation, the control method for the motor controller provided in this application further includes: The sampling module 3 synchronously inputs the collected motor operating parameters to the first analog-to-digital converter 11 and the second analog-to-digital converter 12. The motor operating parameters are converted from analog to digital by the first analog-to-digital converter 11 and the second analog-to-digital converter 12. The conversion results of the first analog-to-digital converter 11 and the second analog-to-digital converter 12 are mutually verified; The first analog-to-digital converter 11 is powered by a first independent power supply, and the second analog-to-digital converter 12 is powered by a second independent power supply. The power supply circuits of the first independent power supply and the second independent power supply are isolated from each other.
[0119] In one embodiment, this application discloses a vehicle including an electric drive system, the electric drive system including a motor controller of any of the above embodiments.
[0120] It should be noted that the vehicle can be, but is not limited to, a pure electric vehicle (PEV / BEV), a hybrid electric vehicle (HEV), a range-extended electric vehicle (REEV), a plug-in hybrid electric vehicle (PHEV), or a new energy vehicle.
[0121] The above embodiments are merely preferred embodiments provided to fully illustrate the present invention, and the scope of protection of the present invention is not limited thereto. Equivalent substitutions or modifications made by those skilled in the art based on the present invention are all within the scope of protection of the present invention.
Claims
1. A motor controller, characterized in that: It includes a control module, a drive module, a sampling module, an electrical safety monitoring module, and an active short-circuit protection module. The drive module is used to drive the motor to run according to the control signal output by the control module; The sampling module is used to collect motor operating parameters and send the motor operating parameters to the control module and the electrical safety monitoring module; The electrical safety monitoring module is used to receive the motor operating parameters, make safety judgments based on preset thresholds, and when the motor operating parameters are detected to exceed the preset thresholds, output a hardware shutdown signal to the active short circuit protection module and output monitoring status information to the control module. The active short-circuit protection module is connected to the control module and the electrical safety monitoring module respectively, and is used to control the drive module to enter a short-circuit state when it receives a hardware shutdown signal from the control module or the electrical safety monitoring module.
2. The motor controller according to claim 1, characterized in that: It also includes a power supply module configured to provide power to the control module, the drive module, the sampling module, the electrical safety monitoring module, and the active short-circuit protection module.
3. The motor controller according to claim 2, characterized in that: The power module is connected to the control module and the active short-circuit protection module respectively. When a power failure is detected, the power module is used to send a hardware shutdown signal to the active short-circuit protection module and a fault indication signal to the control module. When the control module receives the fault indication signal and confirms the power failure, it sends a hardware shutdown signal to the active short-circuit protection module. When the active short-circuit protection module receives a hardware shutdown signal from the power supply module or a hardware shutdown signal from the control module, it controls the drive module to enter a short-circuit state.
4. The motor controller according to claim 2, characterized in that: The power module includes a main power supply and a redundant power supply. When the main power supply fails, the redundant power supply provides power.
5. The motor controller according to claim 2, characterized in that: The power module includes a watchdog monitoring unit, a voltage monitoring unit, a current monitoring unit, and a fault monitoring unit; The watchdog monitoring unit is used to monitor the watchdog enable signal status of the control module; The voltage monitoring unit is used to monitor the input voltage status of the control module; The current monitoring unit is used to monitor the input current status of the control module; The fault monitoring unit is used to monitor the safety fault status of the control module; When any one of the watchdog monitoring unit, voltage monitoring unit, current monitoring unit, and fault monitoring unit detects an abnormal state, the power module outputs a fault handling signal to the control module. The fault handling signal includes at least one of a reset signal, a diagnostic signal, or an interrupt signal.
6. The motor controller according to claim 1, characterized in that: The active short-circuit protection module includes a first NOT gate, a second NOT gate, a third NOT gate, a first OR gate, an AND gate, a second OR gate, a transistor, and a first resistor; The input of the first NOT gate receives a safety fault signal from the control module, the input of the second NOT gate receives an overcurrent and overvoltage interrupt signal from the electrical safety monitoring module, and the input of the third NOT gate receives an enable control signal from the control module. The first input terminal and the second input terminal of the first OR gate are respectively connected to the output terminals of the first NOT gate, the second NOT gate and the third NOT gate; The first input terminal of the AND gate is connected to the output terminal of the third NOT gate, and the second input terminal receives the status control signal from the control module. The first input terminal and the second input terminal of the second OR gate are respectively connected to the output terminal of the first OR gate and the output terminal of the AND gate; The base of the transistor is connected to the output of the second OR gate, the collector of the transistor is connected to the power module through the first resistor, and a hardware shutdown enable signal is output. The emitter of the transistor is grounded. The hardware shutdown state signal is led out from the output of the second OR gate.
7. The motor controller according to claim 6, characterized in that: The active short-circuit protection module also includes a fourth NOT gate, the input of which receives a safety status signal from the power supply module, and the output of which is connected to the third input of the first OR gate.
8. The motor controller according to claim 1, characterized in that: The electrical safety monitoring module includes a first voltage divider circuit, a second voltage divider circuit, a first comparator, a second comparator, and a third OR gate; The first voltage divider circuit is connected between the power module and ground, and outputs the first reference voltage to the inverting input of the first comparator. The non-inverting input of the first comparator receives the three-phase current detection signal. When the voltage value of the three-phase current detection signal is greater than the first reference voltage, the first comparator outputs an overcurrent interrupt signal. The second voltage divider circuit is connected between the power module and ground, and outputs the second reference voltage to the inverting input of the second comparator. The non-inverting input of the second comparator receives the bus voltage detection signal. When the voltage value of the bus voltage detection signal is greater than the second reference voltage, the second comparator outputs an overvoltage interrupt signal. The two inputs of the third OR gate are respectively connected to the outputs of the first comparator and the second comparator, and the output of the third OR gate outputs an overcurrent and overvoltage interrupt signal to the active short-circuit protection module.
9. The motor controller according to claim 1, characterized in that: The control module includes a redundantly arranged first analog-to-digital converter (ADC) and second ADC. The sampling module synchronously inputs the collected motor operating parameters to the first and second ADCs for analog-to-digital conversion. The output results of the first and second ADCs are mutually verified.
10. The motor controller according to claim 9, characterized in that: The first analog-to-digital converter is powered by a first independent power supply, and the second analog-to-digital converter is powered by a second independent power supply; The power supply circuits of the first independent power supply and the second independent power supply are isolated from each other.
11. A control method for a motor controller, characterized in that, include: The control module outputs control signals to drive the drive module and control the motor to run. The motor operating parameters are collected by the sampling module and transmitted to the control module and the electrical safety monitoring module respectively. The electrical safety monitoring module receives the motor's operating parameters and makes a safety judgment based on preset thresholds. When the motor operating parameters are detected to exceed the preset threshold, the electrical safety monitoring module outputs a hardware shutdown signal to the active short circuit protection module and outputs monitoring status information to the control module. When the active short-circuit protection module receives a hardware shutdown signal output by either the control module or the electrical safety monitoring module, it controls the drive module to enter a short-circuit state.
12. The control method of the motor controller according to claim 11, characterized in that, Also includes: The power supply module provides power to the control module, drive module, sampling module, electrical safety monitoring module, and active short-circuit protection module. When the power module detects a power failure, it outputs a hardware shutdown signal to the active short-circuit protection module and a fault indication signal to the control module. After receiving the fault indication signal and confirming the power failure, the control module outputs a hardware shutdown signal to the active short-circuit protection module. When the active short-circuit protection module receives a hardware shutdown signal output by the power module or control module, it controls the drive module to enter a short-circuit state.
13. The control method of the motor controller according to claim 11, characterized in that, Also includes: The watchdog enable signal status of the control module is monitored by the watchdog monitoring unit in the power module. The input voltage status of the control module is monitored by the voltage monitoring unit; The input current status of the control module is monitored by the current monitoring unit; The safety fault status of the control module is monitored through the fault monitoring unit; When any monitoring unit detects an abnormal state, the power module outputs a fault handling signal to the control module. The fault handling signal includes at least one of a reset signal, a diagnostic signal, or an interrupt signal.
14. The control method according to claim 11, characterized in that, Also includes: The sampling module synchronously inputs the collected motor operating parameters to the first analog-to-digital converter and the second analog-to-digital converter. The motor operating parameters are converted from analog to digital using the first analog-to-digital converter and the second analog-to-digital converter. The conversion results of the first analog-to-digital converter and the second analog-to-digital converter are mutually verified; The first analog-to-digital converter is powered by a first independent power supply, the second analog-to-digital converter is powered by a second independent power supply, and the power supply circuits of the first independent power supply and the second independent power supply are isolated from each other.
15. A vehicle comprising an electric drive system, characterized in that: The electric drive system includes a motor controller as described in any one of claims 1 to 10.