A range extender fault processing method and vehicle

By introducing collaborative protection and degradation protection strategies for the vehicle controller, engine controller, and generator controller in the range extender system, the problem of lack of coordination among the controllers in the range extender system is solved, safe shutdown is achieved, and system safety and driving experience are improved.

CN122379519APending Publication Date: 2026-07-14CHERY NEW ENERGY AUTOMOBILE TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
CHERY NEW ENERGY AUTOMOBILE TECH CO LTD
Filing Date
2026-05-29
Publication Date
2026-07-14

AI Technical Summary

Technical Problem

The lack of coordination and linkage among controllers in existing range extender systems makes the engine prone to abnormal operation when the load suddenly fails, causing the engine to run away and threatening driving safety and experience.

Method used

A fault handling method for range extenders is designed. Through the coordinated protection strategy and degradation protection strategy among the vehicle controller, engine controller and generator controller, the system can be safely shut down to prevent the engine from running away when the communication status is normal or faulty.

Benefits of technology

It enables safe shutdown of the range extender system under various fault scenarios, improves the system's functional safety level and driving experience, and prevents dangerous situations such as engine runaway.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122379519A_ABST
    Figure CN122379519A_ABST
Patent Text Reader

Abstract

The application belongs to the technical field of range extenders, and discloses a range extender fault processing method and a vehicle.The method comprises the following steps: detecting the communication state between controllers in a range extender system; if the communication is normal, executing a corresponding first cooperative protection strategy according to the specific controller where the fault occurs; and if there is a fault in the communication link, executing a preset second degradation protection strategy according to the specific fault link.The vehicle controller, the engine controller and the generator controller are integrated into an organic whole, and the first cooperative protection strategy and the second degradation protection strategy are designed, so that for the two failure modes of component faults and communication faults, a preset cooperative and degradation processing flow covering all fault scenarios is provided, the safety hazard of engine runaway caused by independent protection of controllers and lack of system cooperation in the prior art is solved, and the safety, reliability and driving experience of the range extender system are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of range extender technology, and specifically relates to a range extender fault handling method and vehicle. Background Technology

[0002] As an energy component of new energy vehicle energy systems, a range extender is a power generation system consisting of an engine and an integrated generator, including a vehicle controller, an engine controller, a generator controller, and corresponding hardware. The three controllers work together to generate electricity.

[0003] Currently, each controller employs an independent fault diagnosis and protection strategy, meaning it takes corresponding protective measures when its own system fails. However, this "each doing its own thing" model has systemic flaws: due to the lack of coordination between controllers, the protective actions of a single system (such as a sudden generator unload) may cause related systems (such as the engine) to enter an abnormal operating state. This problem is particularly prominent during the start-up, shutdown, and operation of the range extender, easily causing the engine to "run away," producing a loud roar and potentially damaging hardware, seriously threatening driving safety and experience.

[0004] Therefore, those in the field urgently need to develop a systematic method for handling range extender faults. Summary of the Invention

[0005] To address the aforementioned problem of the lack of coordination mechanisms among controllers in existing range extender systems for handling faults, this invention provides a range extender fault handling method.

[0006] To achieve the above objectives, the present invention provides the following technical solution: This invention provides a fault handling method for a range extender, applicable to a range extender system including a vehicle controller, an engine controller, and a generator controller. The method includes: Detect the communication status between the vehicle controller, the engine controller, and the generator controller; If the communication status is normal, then the first collaborative protection strategy corresponding to the controller that has failed is executed; If the communication status indicates a communication failure, then the corresponding second degradation protection strategy is executed according to the communication link where the failure occurred. Both the first collaborative protection strategy and the second degradation protection strategy are used to control the range extender system to enter a safe shutdown state.

[0007] Further configuration: The execution of the first cooperative protection strategy corresponding to the faulty controller includes: If the engine controller malfunctions, the vehicle controller, after determining that the engine controlled by the engine controller has stopped outputting torque, controls the generator controller to shut down the generator.

[0008] Further configuration: The execution of the first cooperative protection strategy corresponding to the faulty controller includes: If the generator controller malfunctions, the vehicle controller requests the engine controller to limit the engine's torque output or immediately cut off the fuel supply.

[0009] Further configuration: The execution of the first cooperative protection strategy corresponding to the faulty controller includes: If the vehicle controller malfunctions, the engine controller and the generator controller will monitor the engine speed and generator speed respectively, and each will enter a preset protection control process when the speed is abnormal.

[0010] Further configuration: The step of executing the corresponding second degradation protection strategy based on the failed communication link includes: If the communication link between the vehicle controller and the engine controller fails, the engine controller, the vehicle controller, and the generator controller are controlled to execute a processing procedure corresponding to the failure type of the communication link. If the communication link between the vehicle controller and the generator controller fails, the vehicle controller, the engine controller, and the generator controller will execute a processing procedure corresponding to the fault type of the communication link.

[0011] Further configuration: The processing flow corresponding to the fault type of the communication link is determined based on whether each of the vehicle controller, the engine controller, and the generator controller can normally receive messages from the other two.

[0012] Further configuration: The detection of the communication status between the vehicle controller, the engine controller, and the generator controller includes: If a controller does not receive a periodic message from the target controller within a preset time, it is determined that there is a communication failure with the target controller.

[0013] Further configuration: Determining that the engine controlled by the engine controller has stopped outputting torque includes: The vehicle controller detects a flag indicating that the torque output from the engine controller is zero, and / or detects that the engine speed has dropped below the idle speed threshold.

[0014] Further configuration: When the range extender system has no communication failure and the engine needs to be stopped, the method further includes: If the energy recovered from the vehicle battery is insufficient, the vehicle controller requests the engine controller to cut off the fuel supply and the generator to output negative torque to assist in shutdown, while also requesting the vehicle heater to start to consume the excess recovered power.

[0015] The present invention also provides a vehicle including a range extender fault handling system, the system being configured to perform the range extender fault handling method as described above.

[0016] Compared with the prior art, the present invention has the following advantages: This invention integrates the vehicle controller, engine controller, and generator controller into a cohesive whole, and designs a first collaborative protection strategy and a second degradation protection strategy. It provides a pre-defined collaborative and degradation processing flow covering all failure scenarios for two major failure modes: component failure and communication failure. This breaks the protection mode of each controller acting independently in the prior art, fundamentally solves the core safety hazard of engine runaway, and greatly improves the functional safety level of the system and the driving experience.

[0017] Other features and advantages of the invention will be set forth in the description which follows, and will be apparent in part from the description, or may be learned by practicing the invention. The objects and other advantages of the invention may be realized and obtained by means of the structures pointed out in the description, claims and drawings. Attached Figure Description

[0018] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0019] Figure 1 A flowchart illustrating the range extender fault handling method of the present invention is shown; Figure 2 A flowchart illustrating the execution of the first collaborative protection strategy in the processing method of the present invention is shown; Figure 3 A flowchart illustrating the execution of the second degradation protection strategy in the processing method of the present invention is shown; Figure 4 A flowchart illustrating the additional shutdown control in the processing method of the present invention is shown; Figure 5 A schematic diagram of the fault handling system for the range extender of the present invention is shown. Detailed Implementation

[0020] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0021] Currently, during the start-up, shutdown, and operation of the range extender, when the engine is outputting power (positive torque), if its load (i.e., the generator) suddenly fails, is removed, or loses control, the engine is very likely to "run away." That is, there is a sudden and severe imbalance between the engine output torque and the load torque, and the engine speed rises sharply and abnormally in a very short time, entering an uncontrolled overspeed state. This is accompanied by a loud roar and may cause hardware damage, seriously threatening driving safety and experience.

[0022] To address the aforementioned problems, those skilled in the art have developed a method and system for handling range extender faults. The embodiments of the present invention will be further described below with reference to the accompanying drawings.

[0023] This invention provides a method for handling range extender faults, applicable to a range extender system including a vehicle controller, an engine controller, and a generator controller.

[0024] like Figure 1 As shown, the troubleshooting method for this range extender includes the following steps: S1: Detect the communication status between the vehicle controller, the engine controller, and the generator controller; S2: Branching based on detection results: If the communication status is normal, then the first collaborative protection strategy corresponding to the controller that has failed is executed, that is, step S3 is executed; If the communication status indicates a communication failure, then according to the communication link where the failure occurred, the corresponding second degradation protection strategy is executed, that is, step S4 is executed. Both the first collaborative protection strategy and the second degradation protection strategy are used to control the range extender system to enter a safe shutdown state.

[0025] In this embodiment, the vehicle controller, the engine controller, and the generator controller interact through periodic message exchanges. That is, each controller exchanges data frames containing key status information (such as speed, torque, and fault codes) at a preset frequency (such as 10ms, 20ms, and 100ms). The communication status refers to the health status of the communication link between any two controllers that need to communicate. Only when all communication links are normal is the system in a "normal communication status".

[0026] Under normal conditions, the vehicle controller, acting as a coordination center, needs to maintain normal communication with the other two controllers. That is, the vehicle controller can receive periodic messages sent by the engine controller and the generator controller, and at the same time, the periodic messages or control commands sent by the vehicle controller to the engine controller and the generator controller can also be successfully received and responded to. Specifically, the vehicle controller can continuously and stably receive periodic messages sent by the engine controller, which contain engine status information such as speed, output torque, and fault codes. At the same time, the control commands (such as torque requests and fuel cut-off commands) sent by the vehicle controller to the engine controller can also be successfully received and responded to by the engine controller. If the vehicle controller does not detect message loss or timeout from the engine controller within a preset time, the communication link between the vehicle controller and the engine controller is in normal condition, and the communication fault flag between the vehicle controller and the engine controller remains unset. Specifically, the vehicle controller can continuously and stably receive periodic messages from the generator controller, which contain generator status information such as speed, output torque, fault level, and operating mode. At the same time, the control commands (such as target speed, torque, and shutdown commands) sent by the vehicle controller to the generator controller can also be successfully received and responded to by the generator controller. If the vehicle controller does not detect message loss or timeout from the generator controller within a preset time, the communication link between the vehicle controller and the generator controller is in a normal state, and the communication fault flag between the vehicle controller and the generator controller remains unset.

[0027] like Figure 2 As shown, the execution of step S3 specifically includes: The execution of the first cooperative protection strategy corresponding to the faulty controller includes: S3-1: If the engine controller malfunctions, the vehicle controller will control the generator controller to shut down the generator after determining that the engine controlled by the engine controller has stopped outputting torque. S3-2: If the generator controller malfunctions, the vehicle controller is controlled to request the engine controller to limit the engine torque output or immediately cut off the fuel supply. S3-3: If the vehicle controller malfunctions, the engine controller and the generator controller will monitor the engine speed and generator speed respectively, and each will enter a preset protection control process when the speed is abnormal.

[0028] In this embodiment, the prerequisite for executing step S3 is that the communication links between any two controllers that need to communicate, namely the vehicle controller, engine controller, and generator controller, are in a normal state. At this time, the vehicle controller, engine controller, and generator controller can exchange status or messages normally and promptly. Under this premise, if any controller fails, the other controllers can quickly detect it and trigger the corresponding collaborative protection strategy, specifically manifested as follows: When the engine controller malfunctions, step S3-1 is executed. Specifically, if the engine controller enters a fault protection state due to an internal problem (such as sensor failure), it sets its "fault status flag" via a CAN message and reports it to the vehicle controller. After receiving the fault message from the engine controller, the vehicle controller determines that "engine controller malfunctions." At this time, the vehicle controller does not immediately shut down the generator, but waits until it is confirmed that the engine has stopped outputting torque before sending a command to the generator controller to shut down the generator, causing the generator to enter OFF mode or stop outputting torque. After determining that the engine controller has malfunctioned, the vehicle controller waits to confirm that the engine has stopped outputting torque before shutting down the generator. The purpose of this is to prevent runaway caused by suddenly unloading the load when the engine is still outputting power. When the generator controller malfunctions, step S3-2 is executed. Specifically, when the generator controller detects a malfunction, such as limited power generation or generator speed exceeding a preset threshold, it internally determines the fault level and immediately sets its "fault status flag" via a CAN message, along with the fault level, and reports it to the vehicle controller. Upon receiving the fault message from the generator controller, the vehicle controller determines that "generator controller malfunction" has occurred. For example, when the generator controller detects that its speed exceeds the first threshold, the fault level is medium. In this case, the vehicle controller requests the engine controller to limit the output torque. When the generator controller detects that its speed exceeds the second threshold, the fault level is the highest. In this case, the vehicle controller immediately sends a "fuel cut-off" request command to the engine controller without waiting for any conditions. This is because a generator controller malfunction means that the generator's load has become uncontrollable or is about to become uncontrollable, and its power source must be cut off immediately. At the same time, this is also to prevent the engine from running away due to the imbalance between power output and load when the generator load suddenly disappears or decreases sharply. When the vehicle controller malfunctions, step S3-3 is executed. Specifically, the vehicle controller self-diagnoses its internal functional failure (such as a critical memory check error). Although its control decision-making ability may be impaired, its underlying communication processing program can still run. The vehicle controller immediately sets its "fault status flag" via CAN message and actively sends it to the engine controller and generator controller. After receiving the message containing the "fault status flag" from the vehicle controller, the engine controller and generator controller no longer rely on the communication timeout logic, but directly determine "vehicle controller failure" based on the message content. At this time, the engine controller and generator controller no longer wait for any subsequent coordination instructions from the vehicle controller, but immediately and autonomously enter the preset independent protection mode based on local information. In this mode, the engine controller initiates independent engine overspeed monitoring, continuously detecting engine speed. Once the engine speed exceeds the locally stored fault threshold (meaning that when the vehicle controller malfunctions, the engine controller automatically adopts a lower preset speed threshold to ensure safety), the engine controller immediately executes fuel cut-off protection to cut off the power source and prevent the engine from running away. In this mode, the generator controller initiates independent generator overspeed monitoring, continuously detecting the generator speed. Once the generator speed exceeds the locally stored speed protection threshold, the generator controller immediately executes a stop-output waiting protection action to prevent the generator itself from becoming an unstable factor.

[0029] It should be noted that, under normal communication conditions between controllers, when the vehicle controller detects a fault in itself, it will immediately generate a fault message. This message has the highest priority when a controller fails and will be immediately sent to the engine controller and generator controller to ensure that the engine controller and generator controller receive it in a timely manner. That is, the engine controller and generator controller do not need to rely on communication timeout logic and can enter the independent protection mode within milliseconds of receiving the fault message from the vehicle controller.

[0030] like Figure 4 As shown, when the range extender system has no communication failure and the engine needs to be shut down, the method further includes: If the energy recovered from the vehicle battery is insufficient, the vehicle controller requests the engine controller to cut off the fuel supply and the generator to output negative torque to assist in stopping the engine, while also requesting the vehicle heater to start to consume the excess recovered power. Specifically, when the engine shutdown command is issued, the generator outputs negative torque to drag the engine to decelerate quickly. This process generates a large amount of electrical energy that is fed back to the high-voltage battery. However, if the battery is already fully charged at this time (insufficient recovery capacity), this excess energy, if not handled in time, can lead to battery overcharging and even cause high-voltage safety risks in the system. In this embodiment, under the premise of normal system communication, when executing the planned "engine shutdown" process or the "engine shutdown" process triggered by controller failure, an additional energy recovery channel, namely the vehicle heater, is activated to safely consume the excess power generated by the generator that cannot be absorbed by the battery, in order to ensure that the shutdown process is both fast and safe.

[0031] like Figure 3 As shown, the S4 step specifically includes: The step of executing a corresponding second degradation protection strategy based on the faulty communication link includes: S4-1: If the communication link between the vehicle controller and the engine controller fails, the engine controller, the vehicle controller, and the generator controller are controlled to execute the processing flow corresponding to the failure type of the communication link. S4-2: If the communication link between the vehicle controller and the generator controller fails, the vehicle controller, the engine controller, and the generator controller are controlled to execute the processing flow corresponding to the fault type of the communication link.

[0032] In this embodiment, the prerequisite for executing step S4 is that if each controller does not receive a periodic message from the target controller within a preset time, it is determined that there is a communication failure with the target controller, that is, at least one communication link between the vehicle controller, engine controller and generator controller is faulty; and when a controller fails to successfully receive any valid periodic message from another controller (target controller) with which it has a fixed communication relationship within a preset, continuous time window, the controller determines that there is a communication failure with the target controller and sets the corresponding internal communication failure flag. At this time, the system degrades to an emergency protection mode based on residual connections and local information to ensure a safe shutdown in the end.

[0033] Specifically, this manifests as follows: 1. When a communication link between the vehicle controller and the engine controller fails, step S4-1 is executed. Specifically, the type of communication link failure is determined based on whether each of the vehicle controller and the engine controller can normally receive messages from the other. Then, a corresponding processing procedure is performed according to the type of communication link failure. That is, the specific processing method varies depending on whether the communication link failure between the vehicle controller and the engine controller is unidirectional or bidirectional. When the communication link between the vehicle controller and the engine controller experiences a bidirectional communication interruption fault, step S4-1-1 is executed. Specifically, both the vehicle controller and the engine controller set the communication fault flag because they did not receive a message from each other within a preset time (message reception timeout or loss), indicating a bidirectional communication interruption fault between them. At this time, the system degradation protection logic is triggered. The engine controller immediately and autonomously cuts off the fuel supply according to its preset degradation protection logic. Simultaneously, the generator controller continuously monitors its own output torque according to its preset degradation protection logic. When it detects that its own output torque is >0 (indicating that it is performing a power generation task), it autonomously stops outputting and removes the load. This disconnects the engine power source and removes the generator load, allowing the system to quickly enter a safe state through parallel protection actions, avoiding a possible speed spike caused by a delay in one party's action. When the communication link between the vehicle controller and the engine controller experiences a one-way communication interruption fault, there are two scenarios: In the first scenario, the vehicle controller can receive messages sent by the engine controller, but cannot send messages to the engine controller (the engine controller cannot receive messages sent by the vehicle controller); In the second scenario, the vehicle controller cannot receive messages sent by the engine controller, but can send messages to the engine controller (the engine controller can receive messages sent by the vehicle controller). In the first scenario, step S4-1-2 is executed. Specifically, the vehicle controller can receive the status messages from the engine controller, but the engine controller cannot receive the command messages from the vehicle controller and sets the "communication failure with vehicle controller" flag. At this time, the system degradation protection logic is triggered, and the engine controller immediately and autonomously cuts off the fuel supply. Simultaneously, the generator controller continuously monitors its own output torque. When it detects that its own output torque is >0 (indicating that it is performing a power generation task), it autonomously stops output and removes the load. In this case, the system degradation protection logic is consistent with the protection logic for a bidirectional communication interruption fault. This disconnects the engine power source, removes the generator load, and allows the system to quickly enter a safe state through parallel protection actions, avoiding a possible speed spike caused by a delay in one action. In the second scenario, step S4-1-3 is executed. Specifically, the engine controller can receive command messages from the vehicle controller normally, but the vehicle controller cannot receive status messages from the engine controller and sets the "communication failure with engine controller" flag. At this time, the system degradation protection logic is triggered, the engine controller immediately stops fuel injection, and the vehicle controller, having lost direct status feedback from the engine, instead monitors the status of the still-communicating generator controller. When it detects that the real-time output torque of the generator is greater than 0, it determines that the generator is still working and then controls the generator controller to shut down the generator. In this way, when the vehicle controller cannot know the exact status of the engine, it can monitor the status of the still-controllable generator load and safely unload it after confirming the existence of the load, preventing sudden load changes and ensuring a safe shutdown.

[0034] 2. When a communication link between the vehicle controller and the generator controller fails, step S4-2 is executed. Specifically, the type of communication link failure is determined based on whether each of the vehicle controller and the generator controller can normally receive messages from the other. Then, a corresponding processing procedure is performed according to the type of communication link failure. That is, the specific processing method varies depending on whether the communication link failure between the vehicle controller and the generator controller is unidirectional or bidirectional. When the communication link between the vehicle controller and the generator controller experiences a bidirectional communication interruption fault, step S4-2-1 is executed. Specifically, both the vehicle controller and the generator controller set the communication fault flag because they did not receive a message from each other within a preset time (message reception timeout or loss). This indicates a bidirectional communication interruption fault between the vehicle controller and the generator controller. At this time, the system degradation protection logic is triggered. The vehicle controller diagnoses the abnormal communication with the generator controller and immediately controls the engine controller, which can still communicate, to cut off the fuel supply, thus cutting off power at the source. At the same time, the generator controller continuously monitors its own output torque according to its preset degradation protection logic. When it detects that its own output torque is >0 (indicating that it is performing a power generation task), it autonomously stops output and removes the load. When the communication link between the vehicle controller and the generator controller experiences a one-way communication interruption fault, there are two scenarios, A and B: In scenario A, the vehicle controller can receive messages sent by the generator controller, but cannot send messages to the generator controller (the generator controller cannot receive messages sent by the vehicle controller); In scenario B, the vehicle controller cannot receive messages sent by the generator controller, but can send messages to the generator controller (the generator controller can receive messages sent by the vehicle controller). In case A, step S4-2-2 is executed. Specifically, the vehicle controller can receive the status messages from the generator controller normally, but the generator controller cannot receive the command messages from the vehicle controller. The generator controller diagnoses the communication abnormality with the vehicle controller and reports the communication abnormality to the vehicle controller, and sets the "communication fault with vehicle controller" flag. At this time, the system degradation protection logic is triggered. The generator controller continues to maintain the current control state. Since the vehicle controller cannot directly control the generator, it controls the engine controller to perform fuel cut-off. The generator controller continuously monitors its own output torque according to its preset degradation protection logic. When it detects that its own output torque is >0 (indicating that it is performing a power generation task), it autonomously stops output and removes the load. In scenario B, step S4-2-3 is executed. Specifically, the generator controller can receive command messages from the vehicle controller normally, but the vehicle controller cannot receive status messages from the generator controller and sets the "communication failure with generator controller" flag. The vehicle controller cannot receive direct status feedback from the generator, but can still send commands to the generator controller. At this time, the system degradation protection logic is triggered, and the vehicle controller then controls the engine controller, which it can still communicate with, to cut off the fuel supply. After confirming that the engine has stopped outputting torque, it sends a shutdown command to the engine controller, causing the generator to stop. In this way, when the vehicle controller cannot know the exact status of the generator, it can cut off the fuel supply and disconnect the power source by controlling the still controllable engine operating status, and wait a reasonable time after stopping before stopping the load, thus minimizing the risk of runaway and ensuring a safe shutdown.

[0035] Further, determining that the engine controlled by the engine controller has stopped outputting torque includes: the vehicle controller detecting a flag indicating that the torque output is zero from the engine controller, and / or detecting that the engine speed has dropped below the idle speed threshold; In this embodiment, both steps S3-1 and S4-2-3 mention that the vehicle controller first confirms that the engine has stopped outputting torque before sending a command to the generator controller to shut down the generator. The method for determining that the engine controlled by the engine controller has stopped outputting torque is specifically as follows: Method 1: Direct status flag judgment, that is, the vehicle controller continuously receives periodic status messages from the engine controller. The message contains a specific "torque output flag". When the engine is outputting torque normally, this flag is "1" and when the engine performs fuel cut-off and stops fuel injection and stops outputting torque, this flag is "0". When the vehicle controller detects that this flag bit changes from "1" to "0" in a message from the engine controller, it indicates that the engine controller has issued a clear statement to stop torque output. It should be noted that, in order to prevent interference and misjudgment, the vehicle controller can also be set to require this "0" state to remain for one or several message cycles (such as two consecutive frames of messages with the flag bit both being 0) before making a final judgment.

[0036] Method 2: Indirect speed inference. After the engine stops outputting torque, its speed will drop rapidly from the operating speed under the action of generator load and its own mechanical resistance. When the engine speed is detected to drop far below the normal operating range, close to or below the idle speed, it can be indirectly inferred that the engine has no effective power output. It should be noted that this method requires a preset idle speed threshold below the engine's physical idle speed within the vehicle controller (e.g., if the engine's physical idle speed is 800 rpm, the idle speed threshold can be set to 500 rpm). When the vehicle controller continuously receives engine speed status information from the engine controller messages and detects that the engine speed has continuously decreased from a high point to below the preset idle speed threshold, it can determine that the engine has stopped outputting torque. Similarly, to prevent misjudgments caused by speed fluctuations, the speed can also be required to remain below the idle speed threshold for a short period of time to ensure that the vehicle controller can accurately and reliably determine the engine's true state, providing a solid and safe decision-making basis for subsequent generator shutdown control.

[0037] The present invention also provides a range extender fault handling system.

[0038] like Figure 5 As shown, the range extender fault handling system includes a vehicle controller, an engine controller, and a generator controller; The vehicle controller, the engine controller, and the generator controller are configured to collaboratively execute the range extender fault handling method described above.

[0039] In this embodiment, the vehicle controller serves as the coordination and decision-making center of the processing system. During operation, the vehicle controller continuously receives and monitors engine status messages from the engine controller and generator status messages from the generator controller. It determines whether the communication status is normal based on preset logic, identifies whether the faulty component is the engine controller, the generator controller, or itself, and executes corresponding protection strategies based on the diagnostic results. It can issue a "fuel cut-off" command to the engine controller or a "stop" or "zero torque output" command to the generator controller. In this embodiment, the engine controller serves as the control and safety execution unit for the engine power source. During operation, the engine controller controls the engine's fuel injection and ignition upon request from the vehicle controller to achieve engine torque output. It can also independently monitor the engine's own status, such as overspeed, and autonomously execute "fuel cut-off" protection when the local fault threshold is exceeded. The engine controller can also report the engine's operating status (such as torque, speed, and shutdown completion flag) to the vehicle controller and receive and execute control commands from the vehicle controller. In this embodiment, the generator controller serves as the control and status feedback unit for the generator load. During operation, the generator controller controls the generator's operating state upon request from the vehicle controller, such as operating in "idle generation torque mode" or "high-speed generation speed mode" to output generating torque, or switching the operating mode to "OFF mode". The generator controller can also monitor its own operating status and communication status. When it detects that its own torque output is greater than zero (indicating that it is outputting power), it can enter a shutdown process. It can also report the generator's real-time status (such as torque, speed, and fault level) to the vehicle controller and receive and execute control commands from the vehicle controller. When communication is abnormal, the generator controller can also take protective actions based on local detection (such as its own torque).

[0040] In the range extender fault handling system, the vehicle controller, engine controller, and generator controller form a collaborative control network via a CAN bus to coordinate the operation of each actuator (vehicle heater, engine, generator) during different stages such as start-up, power generation, and shutdown. Among them, the vehicle controller is responsible for overall monitoring, decision-making, and coordination; the engine controller acts as a control switch to control the start and stop of power; and the generator controller acts as a control switch to control the connection and disconnection of the load. Under both normal and fault conditions, the vehicle controller, engine controller, and generator controller work together through information interaction and preset logic to achieve an orderly and safe shutdown.

[0041] The following example demonstrates the operating status of each controller and actuator in the range extender fault handling system when communication is normal: During the engine start-up phase, the generator controller operates in start-up mode, outputting positive torque to drive the engine to rotate. The engine controller is initially in standby mode. After the engine is driven to the target speed, the engine controller controls the engine to inject fuel and ignite and output positive torque synchronously. During this phase, there is a risk of the engine running away due to bidirectional acceleration. The vehicle controller monitors the speed reported by the engine controller and generator controller in real time and is ready to intervene if any speed is abnormal. During the continuous power generation phase, the generator controller operates in power generation mode, outputting negative torque to convert the engine's mechanical energy into electrical energy and charge the battery. The engine controller outputs positive torque to drive the engine and continuously and independently monitors the engine speed. At the same time, the generator controller also continuously monitors its own faults and reports the fault level. The vehicle controller receives torque or speed information from the engine controller and power generation capacity or fault level information from the generator controller. When the generator power is limited, the vehicle controller will dynamically request the engine controller to reduce the output torque according to its reported power generation capacity to protect the power balance. When the generator speed exceeds the first threshold, the vehicle controller requests the engine controller to limit the torque. When the generator speed exceeds the second threshold or a serious fault occurs, the vehicle controller requests the engine controller to immediately cut off the fuel supply and control the generator to shut down. During the shutdown phase, the vehicle controller determines whether the battery recovery capacity is sufficient. If it is sufficient, the shutdown process continues. If it is insufficient, the vehicle controller requests the vehicle heater to start to consume excess power.

[0042] The range extender fault handling system in this embodiment, through the coordinated work of three controllers, can not only detect risks faster and more accurately, but also execute the most appropriate coordinated protection actions according to different risks, thus preventing the specific safety hazard of engine runaway and bringing about an improvement in safety and reliability.

[0043] The present invention also provides a vehicle including the range extender fault handling system described above; The vehicle integrates a range extender fault handling system with systematic coordination and fault tolerance capabilities. This enables the vehicle to ensure that the range extender can shut down in an orderly and safe manner under any operating condition (including controller component failure or inter-controller communication failure), fundamentally preventing dangerous situations such as engine runaway.

[0044] Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for handling range extender faults, applied to a range extender system including a vehicle controller, an engine controller, and a generator controller, characterized in that, The method includes: Detect the communication status between the vehicle controller, the engine controller, and the generator controller; If the communication status is normal, then the first collaborative protection strategy corresponding to the controller that has failed is executed; If the communication status indicates a communication failure, then the corresponding second degradation protection strategy is executed according to the communication link where the failure occurred. Both the first collaborative protection strategy and the second degradation protection strategy are used to control the range extender system to enter a safe shutdown state.

2. The method for handling range extender faults according to claim 1, characterized in that, The execution of the first cooperative protection strategy corresponding to the faulty controller includes: If the engine controller malfunctions, the vehicle controller, after determining that the engine controlled by the engine controller has stopped outputting torque, controls the generator controller to shut down the generator.

3. The method for handling range extender faults according to claim 1, characterized in that, The execution of the first cooperative protection strategy corresponding to the faulty controller includes: If the generator controller malfunctions, the vehicle controller requests the engine controller to limit the engine's torque output or immediately cut off the fuel supply.

4. The method for handling range extender faults according to claim 1, characterized in that, The execution of the first cooperative protection strategy corresponding to the faulty controller includes: If the vehicle controller malfunctions, the engine controller and the generator controller will monitor the engine speed and generator speed respectively, and each will enter a preset protection control process when the speed is abnormal.

5. A method for handling range extender faults according to claim 1, characterized in that, The step of executing a corresponding second degradation protection strategy based on the faulty communication link includes: If the communication link between the vehicle controller and the engine controller fails, the engine controller, the vehicle controller, and the generator controller will execute a processing procedure corresponding to the failure type of the communication link, based on the failure type of the communication link: If the two-way communication is interrupted, the engine controller will automatically cut off the fuel supply and control the generator controller to stop outputting when it detects that the generator's own output torque is greater than zero. If the vehicle controller can receive but cannot send messages to the engine controller, the engine controller will autonomously cut off the fuel supply and control the generator controller to stop outputting when it detects that the generator's own output torque is greater than zero. If the vehicle controller cannot receive messages but can send messages to the engine controller, then the engine controller is controlled to stop fuel injection, and the vehicle controller is controlled to control the generator controller to shut down the generator when it detects that the generator output torque is greater than zero.

6. A method for handling range extender faults according to claim 1, characterized in that, The step of executing the corresponding second degradation protection strategy based on the faulty communication link further includes: If the communication link between the vehicle controller and the generator controller fails, the engine controller, the vehicle controller, and the generator controller will execute the processing flow corresponding to the failure type of the communication link, based on the failure type of the communication link: If the two-way communication is interrupted, the vehicle controller requests the engine controller to cut off the fuel supply, and the generator controller stops outputting when it detects that the generator's own output torque is greater than zero. If the vehicle controller can receive but cannot send messages to the generator controller, the generator controller will maintain output and report the fault when it diagnoses an abnormal communication with the vehicle controller. After receiving the fault, the vehicle controller will request the engine controller to cut off the fuel supply. The generator controller will stop output when it detects that its own output torque is greater than zero. If the vehicle controller cannot receive messages but can send messages to the generator controller, the vehicle controller requests the engine controller to cut off the fuel supply. After confirming the engine shutdown torque output, the vehicle controller then controls the generator controller to shut down the generator.

7. A method for handling range extender faults according to claim 1, characterized in that, The detection of the communication status between the vehicle controller, the engine controller, and the generator controller includes: If a controller does not receive a periodic message from the target controller within a preset time, it is determined that there is a communication failure with the target controller.

8. A method for handling range extender faults according to claim 2, characterized in that, The step of determining that the engine controlled by the engine controller has stopped outputting torque includes: The vehicle controller detects a flag indicating that the torque output from the engine controller is zero, and / or detects that the engine speed has dropped below the idle speed threshold.

9. A method for handling range extender faults according to claim 1, characterized in that, When the range extender system has no communication failure and the engine needs to be shut down, the method further includes: If the energy recovered from the vehicle battery is insufficient, the vehicle controller requests the engine controller to cut off the fuel supply and the generator to output negative torque to assist in shutdown, while also requesting the vehicle heater to start to consume the excess recovered power.

10. A vehicle, characterized in that, The invention includes a range extender fault handling system configured to perform the range extender fault handling method as described in any one of claims 1-9.