Emergency power-assisted steering cooperative control method and system for electric commercial vehicle
Patent Information
- Application Number
- CN202610652539.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2026-05-13
- Publication Date
- 2026-09-22
- Estimated Expiration
- 2046-05-13
AI Technical Summary
[0005]为了解决现有电动商用车应急助力转向方案在主助力电机至应急助力电机的切换过程中存在驾驶员手感跳变、识别滞后、应急电机响应滞后以及对整车协议依赖的问题,本申请提供一种电动商用车应急助力转向协同控制方法及系统
1、在主助力电机至应急助力电机的接管过程中,通过双电机助力扭矩按互补函数分配并保持总扭矩之和恒等于接管起始瞬时的主助力电机扭矩,使驾驶员通过方向盘感知到的总助力扭矩保持连续无阶跃,消除现有方案在切换瞬间的手感跳变。
Smart Images

Figure CN122402636B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of electric control, and in particular to a method and system for coordinated emergency power steering control of electric commercial vehicles. Background Technology
[0002] With the rapid development of new energy vehicles, electric power steering systems in electric commercial vehicles are now generally powered by the vehicle's high-voltage bus. The rated power of the main power steering motor can reach several kilowatts to tens of kilowatts to meet the steering force requirements of vehicles with heavy front axle loads, such as buses, heavy trucks, and mining trucks. However, the reliability of the high-voltage system faces several inherent risks: accidental disconnection of the high-voltage contactor, insulation faults causing the vehicle controller to trip, the power battery management system to actively cut off the high-voltage output, poor contact of the high-voltage wiring harness, and abnormal high-voltage interlock signals can all lead to a sudden power outage of the vehicle's high-voltage bus during vehicle operation. Once the high-voltage bus loses power, the main power steering motor loses its energy source and immediately loses its steering assist capability. In commercial vehicle driving conditions where power steering is highly dependent, the instantaneous loss of power steering forces the driver to bear all steering resistance alone, posing a serious risk of loss of control in scenarios such as large-angle steering, high-speed lane changes, and emergency obstacle avoidance.
[0003] To address this risk, existing industry solutions generally employ a dual-assistance channel architecture consisting of a main assist motor and an emergency assist motor. In the event of a main assist motor failure, the emergency assist motor takes over and provides assistance. However, during the switching process from the main assist motor to the emergency assist motor, existing solutions often use a simple hard switch method: the main assist motor is immediately de-energized upon failure, and the emergency assist motor jumps directly from zero torque to the target assist torque. This switching method has the following interconnected shortcomings: First, because the sum of the assist torque of the two motors undergoes a step change at the moment of switching, the total assist torque perceived by the driver through the steering wheel shows a significant jump, especially under hard steering conditions, which can easily induce driver misoperation. Second, passive failure detection generally uses the high-voltage bus voltage dropping below the lower operating limit as the trigger condition, and the detection time is already the moment the main assist motor fails, resulting in the takeover action always lagging behind the failure itself, creating a period of assist gap between the two. Third, at the moment of switching, the emergency assist motor is generally in a zero-excitation standby state, and there is an electrical delay of several milliseconds from the command to the actual torque output. Even if the controller issues the takeover command in time, the actual assistance is still delayed after the command. Fourth, existing solutions generally rely on fault messages issued by the vehicle battery management system or vehicle controller for failure detection, and the protocols of these messages vary from vehicle manufacturer to vehicle manufacturer, making the engineering implementation of the emergency power steering solution highly dependent on the protocol cooperation of the vehicle manufacturer, thus limiting its universality.
[0004] The four problems mentioned above are not independent of each other, but different aspects of the same core contradiction—the existing emergency power steering solution lacks a coordinated control mechanism that runs through the entire process of power failure warning, transition takeover, and emergency steady state. This causes problems such as recognition lag, motor response lag, sudden torque connection, and protocol dependence to overlap, which together amplify the magnitude and duration of the driver's hand feel changes. Summary of the Invention
[0005] To address the issues of driver feedback abrupt changes, recognition lag, emergency motor response lag, and dependence on vehicle protocols in existing emergency power steering solutions for electric commercial vehicles during the switching process from the main power steering motor to the emergency power steering motor, this application provides a collaborative control method and system for emergency power steering in electric commercial vehicles.
[0006] Firstly, this application provides a method for coordinated control of emergency power steering for electric commercial vehicles, which adopts the following technical solution: A coordinated control method for emergency power steering in electric commercial vehicles is applied to a dual-power steering system with a main power steering motor and a main controller, and an emergency power steering motor and an emergency controller. The main power steering motor and the emergency power steering motor are coaxially and parallelly coupled to the same steering input shaft. The main controller is connected to a high-voltage bus, and the emergency controller is connected to a low-voltage power supply. The method includes the following steps: S1. When the main controller detects the high-voltage bus power failure warning condition, the main controller wakes up the emergency controller from standby to current loop ready state through the inter-controller communication bus, and obtains the emergency assist motor in the standby state. In the standby state, the output torque of the emergency assist motor is zero. S2. During the takeover time window, the main controller causes the assist torque of the main assist motor to decrease according to a monotonically decreasing function, and the emergency controller causes the assist torque of the emergency assist motor to increase according to a complementary monotonically increasing function. The sum of the assist torque of the main assist motor and the assist torque of the emergency assist motor remains at a preset torque conservation constant at any time during the takeover time window. S3. After the takeover time window ends, the main controller will cut off the power to the main assist motor, and the emergency controller will enable the emergency assist motor to independently provide steering assistance, thereby obtaining emergency steady-state assist output.
[0007] By adopting the above technical solution, between the high-voltage bus power failure and the complete takeover of the emergency assist motor, the attenuation torque of the main assist motor and the rise torque of the emergency assist motor are distributed in real time according to a complementary function. The sum of the assist torques of the two motors remains the same as the output torque of the main assist motor at the moment of takeover in the entire takeover time window, so that the total assist torque perceived by the driver through the steering wheel remains continuous and stepless during the switching process. At the same time, in the preparation stage, the emergency controller is first awakened and put into the current loop ready state, so that the emergency assist motor is ready to output power at the beginning of the takeover stage, eliminating the electrical delay from cold start to output power, and eliminating the assist gap in coordination with the torque conservation takeover.
[0008] Optionally, the monotonically decreasing function and the monotonically increasing function are selected from the complementary function family. The complementary function family includes at least one of the following: complementary cosine function pairs, complementary sigmoid function pairs, complementary piecewise linear function pairs, and complementary third-order polynomial function pairs. Any pair of functions in the complementary function family satisfies the following at the beginning of the takeover time window: the monotonically decreasing function has a value of 1 and the monotonically increasing function has a value of 0. At the end of the takeover time window, the monotonically decreasing function has a value of 0 and the monotonically increasing function has a value of 1.
[0009] By adopting the above technical solutions, a variety of optional complementary function forms are provided to adapt to the torque attenuation slope requirements of different working conditions.
[0010] Optionally, the length of the takeover time window is constrained by the upper limit of the high-voltage bus voltage time margin. The upper limit of the high-voltage bus voltage time margin is determined in the following way: the main controller acquires the instantaneous voltage and voltage drop rate of the high-voltage bus in real time; the main controller extrapolates the failure time when the instantaneous voltage of the high-voltage bus drops below the minimum operating voltage of the main motor based on the instantaneous voltage, voltage drop rate, and preset minimum operating voltage of the main motor; the main controller takes the difference between the failure time and the start time of the takeover time window, deducts the preset safety margin, and uses it as the upper limit of the high-voltage bus voltage time margin.
[0011] By adopting the above technical solution, the end of the takeover time window is earlier than the moment when the main power motor fails, ensuring that the conservation constraints are physically feasible within the window.
[0012] Optionally, the voltage drop rate is obtained by performing least-squares fitting on the instantaneous voltage sampling sequence of the high-voltage bus within a preset time period. The preset time period is dynamically adjusted according to the current phase current amplitude of the main and auxiliary motors. The larger the current phase current amplitude, the longer the preset time period.
[0013] By adopting the above technical solution, the disturbance of the voltage drop rate estimation caused by the high current transient of the main and auxiliary motors is suppressed.
[0014] Optionally, after obtaining the emergency assist motor in the ready state in S1, before starting S2, the process further includes: applying a preset amplitude d-axis pre-excitation current to the emergency assist motor by the emergency controller, so that the emergency assist motor completes the magnetic field establishment under zero torque output conditions, and obtains an emergency assist motor that has completed pre-excitation; the main controller takes the product of the remaining response delay of the emergency assist motor after pre-excitation and the preset safety factor as the lower limit of the takeover time window, and the window length of the takeover time window is not less than the lower limit of the window.
[0015] By adopting the above technical solution, the electrical response delay of the emergency assist motor is reduced, and a lower limit of the window is set to prevent the actual torque from failing to keep up with the command during the takeover phase.
[0016] Optionally, the torque conservation constant is established as a consistent reference between the main controller and the emergency controller in the following way: at the beginning of the takeover time window, the main controller collects the current output torque of the main auxiliary motor as the torque conservation constant; the main controller broadcasts the torque conservation constant to the emergency controller once through the inter-controller communication bus. After the single broadcast, the monotonically decreasing function and the monotonically increasing function evolve independently by the main controller and the emergency controller according to their respective local clocks, without the need to repeatedly synchronize the torque conservation constant within the takeover time window.
[0017] By adopting the above technical solution, bilateral reference consistency is achieved through a single broadcast + independent clock evolution, reducing the dependence on communication bandwidth.
[0018] Optionally, the main auxiliary motor power-off execution in S3 includes sub-steps S31-S33. S31. At the end of the takeover time window, the emergency controller sends a takeover completion confirmation message to the main controller via the inter-controller communication bus. S32. Upon receiving the takeover completion confirmation message, the main controller executes the main auxiliary motor power-off. S33. If the takeover completion confirmation message does not arrive within the preset timeout window, the main controller forcibly executes the main auxiliary motor power-off according to the local clock and triggers fault code recording. The preset timeout window is a preset multiple of the takeover time window length.
[0019] By adopting the above technical solutions, a clear takeover completion boundary is established through two-way confirmation, and a timeout is used as a fallback to avoid two-way deadlock.
[0020] Optionally, in S2, the main controller acquires the sum of the assist torque of the main power assist motor and the assist torque of the emergency power assist motor in real time, and calculates the conservation deviation between the sum and the torque conservation constant. When the conservation deviation exceeds the preset conservation tolerance and the duration exceeds the preset tolerance duration threshold, the main controller abandons the torque conservation constraint, and the main controller and the emergency controller work together to perform a hard-switching fallback action. The hard-switching fallback action includes: the main controller immediately switching the assist torque of the main power assist motor to zero; the emergency controller causing the emergency power assist motor to directly output the preset minimum assist torque obtained by looking up a table based on vehicle speed and instantaneous steering torque; and the main controller triggering fault code recording and driver alarm signals through the inter-controller communication bus.
[0021] By adopting the above technical solutions, a safety net is provided for abnormal operating conditions where conservation constraints fail, ensuring that the driver can still receive basic assistance.
[0022] Optionally, during the emergency steady-state power assist output phase, the emergency controller sets an upper limit on the output current of the emergency power assist motor according to vehicle speed segments. Under low vehicle speed and large steering angle conditions, the upper limit of the current is relaxed to prioritize the output of assist torque. Under high vehicle speed and small correction conditions, the upper limit of the current is tightened and the output filtering time constant is increased.
[0023] By adopting the above technical solutions, the different assistance requirements under the condition of limited low-voltage power supply can be matched.
[0024] Optionally, at the starting moment of entering the emergency steady-state power assist output, the emergency controller superimposes a torque pulsation with a preset amplitude and a preset duration on the basic power assist torque of the emergency power assist motor. The torque pulsation is transmitted to the steering wheel through the steering gear to form a tactile cues. The frequency of the torque pulsation avoids the frequency range that is sensitive to human fatigue and the mechanical resonance frequency range of the steering wheel.
[0025] By adopting the above technical solution, the system can proactively inform the driver that it has entered emergency mode through tactile prompts, guiding subsequent operations.
[0026] Optionally, the high-voltage bus power failure early warning condition is triggered by a dual-threshold hysteresis method. When the voltage drop rate exceeds the high threshold of the early warning, the main controller wakes up the emergency controller. When the voltage drop rate falls back to below the low threshold of the early warning, the emergency controller is allowed to re-enter the standby state. The high threshold of the early warning is greater than the low threshold of the early warning to form a hysteresis dead zone.
[0027] By adopting the above technical solution, repeated wake-ups caused by voltage drop rate jittering near the threshold are suppressed.
[0028] Optionally, the fault code record includes at least one of the following: the trigger cause code, the timestamp of the start time of the takeover time window, the difference between the expected arrival time and the actual arrival time of the takeover completion confirmation message, and the time of forced power-off of the local clock. The fault code is reported to the upper-level fault management system through the inter-controller communication bus.
[0029] By adopting the above technical solutions, a complete chain of evidence can be provided for retrospective analysis of failed takeovers.
[0030] Optionally, the preset safety margin value is not less than the product of the remaining response delay of the emergency assist motor after pre-excitation and the preset safety factor, so as to ensure that the end time of the takeover time window is earlier than the failure time.
[0031] By adopting the above technical solution, the upper and lower limit constraints of the window are made compatible at the numerical level.
[0032] Optionally, the specific function form selected from the complementary function family is related to the steering condition. Under hard steering or high vehicle speed conditions, a complementary S-shaped function pair with a smaller absolute value of the decay slope is selected, and under small steering angle or low vehicle speed conditions, a complementary piecewise linear function pair with a faster response is selected.
[0033] By adopting the above technical solution, the form of the complementary function is matched with the risk level of the working condition.
[0034] Optionally, the takeover time window length is constrained by both the upper limit of the high-voltage bus voltage time margin and the lower limit of the window. When the upper limit of the high-voltage bus voltage time margin is less than the lower limit of the window, the main controller triggers a hard switchover fallback action.
[0035] By adopting the above technical solution, a hard switching path is adopted in extreme working conditions where the upper and lower limits of the window cannot be satisfied at the same time.
[0036] Optionally, the inter-controller communication bus can be any one of the following: controller local area network bus, controller local area network flexible data bus, vehicle Ethernet or serial peripheral interface bus. The inter-controller communication bus is independent of the vehicle controller local area network bus. The identification of high-voltage bus power failure warning conditions depends only on the instantaneous voltage and voltage drop rate of the high-voltage bus collected by the main controller itself, without the need for vehicle battery management system or vehicle controller message support.
[0037] By adopting the above technical solutions, the engineering implementation of the emergency power steering solution does not depend on the cooperation of the whole vehicle protocol, thus improving its versatility.
[0038] Optionally, after the emergency controller is awakened and enters the current loop ready state, if the high-voltage bus recovers to the normal operating voltage within the preset backoff time and the voltage drop rate falls below the warning threshold, the emergency controller will re-enter the standby state, and the pre-excitation current of the emergency assist motor will drop to zero.
[0039] By adopting the above technical solution, a recovery path is provided after a power outage warning is misjudged, thus avoiding unnecessary power consumption.
[0040] Optionally, during the emergency steady-state assist output phase, the emergency controller monitors the winding temperature of the emergency assist motor and the temperature of the power components inside the controller in real time. When the temperature exceeds the first protection threshold, the upper limit of the output current of the emergency assist motor is reduced. When the temperature exceeds the second protection threshold, a hard switching fallback action is further triggered.
[0041] By adopting the above technical solution, thermal protection is provided for long-term emergency steady-state operation.
[0042] Optionally, the takeover completion confirmation message includes at least one of the following: the local clock timestamp of the emergency controller, the measured torque value of the emergency booster motor, and the measured phase current value of the emergency booster motor. After receiving the takeover completion confirmation message, the main controller compares the measured torque value with the torque conservation constant to verify the takeover effect.
[0043] By adopting the above technical solution, the takeover completion boundary is upgraded from "instruction issued" to "torque achieved", thereby improving the credibility of the boundary judgment.
[0044] Secondly, the emergency power steering cooperative control system for electric commercial vehicles provided in this application adopts the following technical solution: An emergency power steering cooperative control system for electric commercial vehicles includes: a main power steering motor and a main controller connected to the main power steering motor, the main controller being connected to a high-voltage bus; an emergency power steering motor and an emergency controller connected to the emergency power steering motor, the emergency controller being connected to a low-voltage power supply; a steering gear, the main power steering motor and the emergency power steering motor being coaxially and parallelly coupled to the same input shaft of the steering gear; an inter-controller communication bus, the inter-controller communication bus being connected between the main controller and the emergency controller, configured to transmit status messages and torque conservation constants between the main controller and the emergency controller; and a main controller, configured to: upon detecting a high-voltage bus power failure warning condition... The emergency controller is woken up via the inter-controller communication bus and enters the current loop ready state; during the takeover time window, the assist torque of the main assist motor decreases according to a monotonically decreasing function; after the takeover time window ends, the main assist motor is de-energized; the emergency controller is configured to: during the takeover time window, the assist torque of the emergency assist motor increases according to a complementary monotonically increasing function; after the takeover time window ends, the emergency assist motor independently provides steering assistance; the main controller and the emergency controller work together to ensure that the sum of the assist torques of the main assist motor and the emergency assist motor remains at a preset torque conservation constant at any time during the takeover time window.
[0045] By adopting the above technical solution, at the device level, the two controllers independently drive the corresponding motors and use the torque conservation constant as the coordination benchmark. Under the premise of unchanged hardware BOM, the sum of the assist torque of the two motors remains continuous during the switching process, realizing a purely software-deployable emergency assistance coordination.
[0046] Optionally, the main controller is also configured to: acquire the instantaneous voltage and voltage drop rate of the high-voltage bus in real time, extrapolate the instantaneous voltage, voltage drop rate and preset minimum operating voltage of the main motor to obtain the failure time when the instantaneous voltage of the high-voltage bus drops below the minimum operating voltage of the main motor, and take the difference between the failure time and the start time of the takeover time window, minus the preset safety margin, as the upper limit of the window length of the takeover time window.
[0047] By adopting the above technical solution, the device is equipped with the ability to adaptively determine the upper limit of the window based on local electrical quantities.
[0048] Optionally, the emergency controller is also configured to apply a preset amplitude d-axis pre-excitation current to the emergency booster motor before the start of the takeover time window, so that the emergency booster motor can establish a magnetic field under zero torque output conditions.
[0049] By adopting the above technical solution, the device is equipped with the ability to reduce the response delay of the emergency assist motor.
[0050] Optionally, the main controller is also configured to broadcast the torque conservation constant to the emergency controller once via the inter-controller communication bus at the start of the takeover time window. The emergency controller is also configured to send a takeover completion confirmation message to the main controller via the inter-controller communication bus at the end of the takeover time window. The main controller is also configured to forcibly de-energize the main auxiliary motor according to the local clock if the takeover completion confirmation message does not arrive within the preset timeout window.
[0051] By adopting the above technical solution, the device can achieve consistency of the two-sided references with low-bandwidth communication, and establish a clear takeover completion boundary with two-way confirmation and timeout fallback.
[0052] Optionally, the main controller is also configured to acquire the sum of the assist torque of the main power assist motor and the assist torque of the emergency power assist motor in real time and calculate the conservation deviation between the sum and the torque conservation constant. When the conservation deviation exceeds the preset conservation tolerance and the duration exceeds the preset tolerance duration threshold, the torque conservation constraint is abandoned and the main controller and the emergency controller work together to perform a hard switch fallback action. The hard switch fallback action includes switching the assist torque of the main power assist motor to zero and the emergency power assist motor directly outputting the preset minimum assist torque obtained by looking up a table based on the vehicle speed and instantaneous steering torque.
[0053] By adopting the above technical solutions, the device is equipped with a safety fallback capability in the event of conservation failure or abnormal operating conditions.
[0054] Optionally, the main controller and the emergency controller are also configured to select a monotonically decreasing function and a monotonically increasing function from a complementary function family, which includes at least one of complementary cosine function pairs, complementary sigmoid function pairs, complementary piecewise linear function pairs, and complementary third-order polynomial function pairs.
[0055] By adopting the above technical solution, the device can flexibly select the attenuation shape under different operating conditions.
[0056] In summary, this application includes at least one of the following beneficial technical effects: 1. During the takeover process from the main power assist motor to the emergency power assist motor, the dual motor assist torque is distributed according to a complementary function and the sum of the total torque is kept constant equal to the torque of the main power assist motor at the moment of takeover. This ensures that the total assist torque perceived by the driver through the steering wheel remains continuous without a step change, eliminating the sudden change in feel at the moment of switching in the existing solution.
[0057] 2. By waking up the emergency controller and applying d-axis pre-excitation in the preparatory stage, maintaining the conservation constraints in the takeover stage with a single broadcast and dual independent clock evolution, and calibrating the boundary with bidirectional confirmation and timeout after takeover completion, the takeover process can still be stably implemented under engineering constraints of limited communication bandwidth and limited electrical response.
[0058] 3. By extrapolating the failure time and adaptively determining the takeover time window length based on the instantaneous voltage and voltage drop rate of the high-voltage bus collected by the main controller itself, the predictive identification of the emergency power steering scheme does not depend on the vehicle battery management system or vehicle controller messages, significantly reducing the dependence of engineering implementation on vehicle protocol coordination. Attached Figure Description
[0059] Figure 1 This is a general flowchart of the emergency power steering collaborative control method for electric commercial vehicles provided in the embodiments of this application.
[0060] Figure 2 This is a schematic diagram of the extrapolation of the upper limit of the high-voltage bus voltage time margin provided in the embodiments of this application.
[0061] Figure 3 This is a timing diagram illustrating the torque distribution of the dual motors within the takeover time window provided in this application embodiment.
[0062] Figure 4 This is an interactive timing diagram of the establishment of the dual-controller torque reference and the confirmation of the takeover completion provided in the embodiments of this application.
[0063] Figure 5 This is a schematic diagram of the overall architecture of the emergency power steering cooperative control system for electric commercial vehicles provided in this application embodiment. Detailed Implementation
[0064] The present application will be further described in detail below with reference to the accompanying drawings. It should be understood that the specific embodiments described herein are merely illustrative of the application and are not intended to limit the scope of the application.
[0065] This application provides a method for coordinated control of emergency power steering in electric commercial vehicles. It is applied to a dual-power steering system with a main power steering motor and a main controller, an emergency power steering motor and an emergency controller. The main power steering motor and the emergency power steering motor are coaxially and parallelly coupled to the same steering input shaft. The main controller is connected to a high-voltage bus, and the emergency controller is connected to a low-voltage power supply.
[0066] This method is designed for the emergency power assistance needs of electric commercial vehicles when they encounter a sudden power outage from the high-voltage bus during operation. In this scenario, the main power steering motor cannot continue to output power assistance due to the loss of power from the high-voltage bus, and the emergency power steering motor needs to take over the output of power assistance. At the same time, the sum of the power assistance torque of the two motors should be kept in a smooth transition during the switching process to avoid a step jump in the total power assistance torque perceived by the driver through the steering wheel.
[0067] The specific implementation forms of coaxial parallel coupling of the main power assist motor and the emergency power assist motor to the same steering gear input shaft include, but are not limited to: each motor being connected to the same worm gear via an independent reduction mechanism; the output shafts of the two motors being connected in parallel to the same gearbox and outputting to the steering gear; or each motor driving two adjacent pinions to mesh with the steering gear rack. The two motors are mechanically independent but functionally coordinated. The steering gear is a recirculating ball steering gear commonly used in commercial vehicles. The input shaft of the steering gear receives the sum of the assist torques from the two motors, which is amplified by the internal transmission mechanism of the steering gear and then drives the steering wheels to achieve steering.
[0068] The main power steering motor is driven by the main controller, which is connected to the high-voltage bus. In the typical electrical architecture of new energy electric commercial vehicles, the high-voltage bus is the output bus of the vehicle's power battery, and its voltage is typically in the range of DC 280V to DC 750V, with a typical value of DC 540V. The rated power of the main power steering motor is determined based on the vehicle model and front axle load, with a typical value of 9kW, which can cover the steering assistance needs of buses with a length of over 6 meters and trucks with a weight of over 4.5 tons. When the high-voltage bus is operating normally, the main power steering motor provides steering assistance, and the assist torque is adjusted in real time according to parameters such as driver's hand strength and vehicle speed.
[0069] The emergency power steering motor is driven by an emergency controller, which is connected to a low-voltage power supply. This low-voltage power supply is either a 24V onboard battery or a dedicated low-voltage battery pack, physically isolated from the high-voltage bus, ensuring independent power supply even when the high-voltage bus fails. The rated power of the emergency power steering motor is determined based on the emergency steering requirements, typically 3.2kW or 6.0kW, and it provides emergency steering assistance after the main power steering motor fails.
[0070] The main controller and the emergency controller are connected via an inter-controller communication bus. This inter-controller communication bus is an independent communication link within the electric power steering system. Typical implementations include CAN bus, CAN-FD bus, or serial peripheral interface bus. It is physically independent of the vehicle's CAN bus to avoid signal contention with other nodes in the vehicle and to prevent high-voltage side faults from propagating to the vehicle's communication network. The inter-controller communication bus is mainly used to transmit status messages, such as power failure warning messages, emergency controller readiness messages, torque conservation constant broadcast messages, takeover completion confirmation messages, and fault code reporting messages.
[0071] The core mechanism of this method is executed collaboratively by the main controller and the emergency controller. Without changing the hardware BOM, smooth transition of the assist torque between the two motors during switching can be achieved through software-level collaborative control. No new mechanical components, dedicated switchers, or additional hardware modules are required, allowing this method to be deployed on existing dual-assist steering hardware platforms in electric commercial vehicles via a pure software upgrade.
[0072] To facilitate a clear understanding of the subsequent technical solution description, the core terms involved in this method are explained as follows.
[0073] The high-voltage bus refers to the output bus of the vehicle's power battery, which provides power to the main and auxiliary motors and other high-voltage loads in electric commercial vehicles. The typical voltage range of the bus is DC 280V to DC 750V; this embodiment uses DC 540V as the reference voltage for subsequent scenario descriptions. High-voltage bus power failure refers to the state where the high-voltage bus cannot continue to supply power to the main and auxiliary motors due to reasons such as contactor malfunction, insulation fault tripping, active output cut-off by the power battery management system, or abnormal high-voltage interlock signal. The high-voltage bus power failure warning condition refers to the criteria identified by the main controller based on locally collected instantaneous voltage and voltage drop rate of the high-voltage bus, indicating that the high-voltage bus is about to lose power. The trigger time of this condition is earlier than the moment the bus voltage drops below the minimum operating voltage of the main motor, allowing sufficient time margin for the emergency auxiliary motor to be prepared for waking up.
[0074] The dual-assist steering system refers to a physical hardware platform consisting of a main power steering motor, a main controller, and a high-voltage bus channel; and an emergency power steering motor, an emergency controller, and a low-voltage power supply channel. The two motors are mechanically coupled to the same steering input shaft. This term refers to the hardware platform itself. In contrast, the electric commercial vehicle emergency power steering cooperative control system refers to the overall solution provided in this application, based on the core method and using the dual-assist steering system as the platform. At the system level, it encompasses hardware components, software configuration items, and their cooperative relationship. The two terms have different meanings in this specification; the former emphasizes physical structure, while the latter emphasizes the complete solution, and their distinction should be made based on the context.
[0075] Coaxial parallel coupling refers to a connection method in which two motors work together on the same steering gear input shaft at the mechanical level. Specifically, the two motors can be connected to the same worm gear through an independent reduction mechanism, or the output ends of the two motors can be connected in parallel to the same gearbox and output to the steering gear. The output torque of either motor can be transmitted to the steering gear input shaft.
[0076] The inter-controller communication bus refers to the independent communication link between the main controller and the emergency controller for exchanging status messages, torque conservation constants, and acknowledgment messages. It is independent of the vehicle's CAN bus at both the physical and protocol layers.
[0077] The standby state refers to the intermediate state of the emergency booster motor after the main controller detects the high-voltage bus power failure warning condition and before the start of the takeover time window. In this state, the emergency controller has been awakened by the main controller and the emergency booster motor has entered the current loop ready state, but the output torque of the emergency booster motor is still zero. The current loop ready state means that the current loop inside the emergency controller has completed parameter loading and zero-point calibration, and has the ability to issue and execute torque commands instantaneously.
[0078] The takeover time window refers to the time interval occupied by the main assist motor's assist torque decreasing from its rated value to zero and the emergency assist motor's assist torque increasing from zero to the takeover target value, denoted by the start time of takeover. Starting point, with the completion of the takeover. The endpoint is [the window's length]. The length of this window is denoted as [length]. The typical value is 20ms to 50ms, and in this embodiment it is... =30ms was used as the baseline window length for subsequent scenario descriptions.
[0079] The monotonically decreasing function and the monotonically increasing function refer to two time-normalized functions that describe the decrease in the assist torque of the main assist motor over time and the increase in the assist torque of the emergency assist motor over time, respectively denoted as . and The two functions are complementary, that is... This ensures that the sum of the assist torques of the two motors remains the same constant at any point within the takeover time window.
[0080] The torque conservation constraint refers to the constraint condition that the sum of the assist torque of the main assist motor and the assist torque of the emergency assist motor is always equal to the torque conservation constant within the takeover time window, which can be expressed as: in, To take over the instantaneous output torque of the main assist motor at the start of the takeover; To determine the target torque that the emergency assist motor should achieve upon completion of takeover, due to the normalization design of the complementary function, Values and Equal, so that the total assist torque perceived by the driver remains continuous before and after the switch; As a constant due to torque conservation, in this embodiment .
[0081] The torque conservation constant refers to the preset value that the sum of the assist torques of the two motors should maintain at any moment within the takeover time window, as required by the torque conservation constraint. In this embodiment, this constant is taken from the instantaneous output torque of the main assist motor at the moment of takeover initiation, typically ranging from several Newton-meters to tens of Newton-meters. In this embodiment, it is taken as... =10Nm was used as a baseline value for subsequent scenario descriptions.
[0082] The emergency steady-state power steering output refers to the phase in which the main power steering motor is de-energized and stops working after the emergency power steering takeover time window ends, and the emergency power steering motor independently assumes the responsibility of power steering. This phase continues until the high-voltage bus is restored or the vehicle is stopped for maintenance.
[0083] The hard-switching fallback action refers to a fallback action jointly executed by the main controller and the emergency controller when the torque conservation constraint is abandoned under abnormal operating conditions. This includes immediately cutting off power to the main power assist motor, directly outputting the preset minimum assist torque to the emergency power assist motor, recording fault codes, and issuing driver alarms. This action does not rely on the evolution of the complementary function and serves as a safety net when the conservation constraint fails.
[0084] The conservation deviation refers to the difference between the sum of the main assist motor's assist torque and the emergency assist motor's assist torque within the takeover time window and the torque conservation constant. It is used to monitor the execution effect of the torque conservation constraint in real time. When the deviation exceeds the preset tolerance and the duration exceeds the tolerance duration threshold, a hard switchover fallback action is triggered.
[0085] Reference Figure 1 The overall process of the method shown includes three main steps with sequential connections: S1 preparation stage, S2 takeover stage, and S3 emergency steady-state stage. The specific execution process of each step is described below.
[0086] S1. When the main controller detects a high-voltage bus power failure warning, it wakes up the emergency controller via the inter-controller communication bus, transitioning it from standby to the current loop ready state, thus obtaining the emergency assist motor in a ready state. In this ready state, the output torque of the emergency assist motor is zero. After obtaining the emergency assist motor in the ready state in S1, before starting S2, the process includes: the emergency controller applying a preset amplitude d-axis pre-excitation current to the emergency assist motor, enabling the emergency assist motor to establish a magnetic field under zero torque output conditions, thus obtaining a pre-excited emergency assist motor.
[0087] The criteria for determining the high-voltage busbar power outage warning condition are determined by the main controller based on the instantaneous voltage and voltage drop rate of the high-voltage busbar collected by itself. The high-voltage busbar power outage warning condition is determined to be valid when at least one of the following sub-conditions is met: First, the instantaneous voltage of the high-voltage bus is lower than the warning voltage threshold; Secondly, the voltage drop rate of the high-voltage bus exceeds the warning rate threshold.
[0088] The typical warning voltage threshold is 480V, which is the base voltage of 540V minus the preset warning voltage margin; the typical warning rate threshold is -2V / ms, which means that if the voltage drops by more than 2V within 1ms, it is considered that the voltage drop rate has exceeded the limit. The two sub-conditions complement each other, the former capturing slow leakage-type power failures and the latter capturing rapid drop-type power failures, so that the warning conditions cover different modes of high-voltage faults.
[0089] After the main controller detects the high-voltage bus power failure warning condition, it sends a wake-up message to the emergency controller via the inter-controller communication bus. Upon receiving the wake-up message, the emergency controller transitions from standby mode to current loop ready mode. The total time required from the main controller detecting the warning condition to the emergency controller entering the current loop ready mode consists of two parts: message transmission time and current loop initialization time. This time is typically between 1ms and 3ms, far shorter than the remaining time margin between the warning time and the voltage drop below the minimum operating voltage of the main motor. This allows the method to complete the preparation work for the emergency channel before the main and auxiliary motors fail.
[0090] After the emergency controller enters the current loop ready state, at the start of the takeover time window. Before arrival, the emergency controller applies a d-axis pre-excitation current to the emergency assist motor. The dq rotating coordinate system is the standard coordinate system in the field of permanent magnet synchronous motor control. This coordinate system rotates synchronously with the electrical position of the motor rotor, decomposing the stator three-phase current into two mutually orthogonal components: the d-axis component, along the direction of the rotor permanent magnet flux, primarily functions to establish or adjust the stator magnetic field; the q-axis component, orthogonal to the d-axis, interacts with the rotor permanent magnet magnetic field to generate electromagnetic torque, i.e., the q-axis torque. In this coordinate system, the d-axis current and q-axis current can be controlled independently, achieving decoupling between magnetic field establishment and torque output. D-axis pre-excitation involves applying a current of a certain amplitude to the d-axis while keeping the q-axis current zero, allowing the emergency assist motor to establish the stator magnetic field without generating q-axis torque. The typical amplitude of the pre-excitation current is 5% to 10% of the rated current of the emergency assist motor. In this state, although the emergency assist motor has established a magnetic field, the output torque remains zero, and the driver does not perceive any change in steering assist. The typical time for establishing d-axis pre-excitation is 1ms to 2ms. Combined with the time required for message transmission and current loop initialization, the total time for the entire S1 process is typically 2ms to 5ms, which can be completed before the high-voltage bus voltage drops below the minimum operating voltage of the main motor. After pre-excitation, the residual response delay between the zero torque command and the actual torque output of the emergency assist motor is reduced from the typical 3ms to 5ms to 0.5ms to 1ms. This time margin plays a crucial role in the S2 takeover phase, as detailed in the later description of the torque conservation constraint execution process.
[0091] In some embodiments, the high-voltage bus power outage early warning condition is triggered using a dual-threshold hysteresis method. Specifically, a high threshold for the early warning rate is set. and low threshold for early warning rate ,in The difference between the two forms a hysteresis dead zone. When the absolute value of the voltage drop rate exceeds... When the main controller wakes up the emergency controller to enter standby mode; when the absolute value of the voltage drop rate falls back to... The following conditions allow the emergency controller to re-enter standby mode. (Settings...) =2.0V / ms, =1.0V / ms. When the voltage drop rate increases from 1.5V / ms to 2.5V / ms, the main controller wakes up the emergency controller; if the voltage drop rate subsequently drops back to 1.2V / ms, since 1.2V / ms is still greater than 1.0V / ms, the emergency controller will be activated. The emergency controller remains in standby mode; when the voltage drop rate further decreases to 0.8V / ms, because 0.8V / ms is less than... The emergency controller then re-enters standby mode. The hysteresis deadband setting suppresses repeated wake-ups caused by voltage drop rate fluctuations near the threshold.
[0092] In some embodiments, the identification of high-voltage bus power failure warning conditions relies solely on the instantaneous voltage and voltage drop rate of the high-voltage bus collected by the main controller itself, without requiring fault messages issued by the vehicle battery management system or vehicle controller. This characteristic enables the warning identification capability of this method to be independent of the vehicle manufacturer's protocol cooperation; the main controller can complete the warning decision based solely on local electrical quantities, making the engineering implementation of this method universal across vehicle manufacturers. Extended implementations of this feature are described in detail later.
[0093] In some embodiments, after the emergency controller is awakened and enters the current loop ready state, if the high-voltage bus recovers to the normal operating voltage within a preset backoff time and the voltage drop rate falls below the warning rate threshold, the emergency controller re-enters the standby state, and the pre-excitation current of the emergency booster motor drops to zero. The preset backoff time is typically 100ms, which is long enough to accommodate occasional voltage transient disturbances, yet short enough to prevent the emergency controller from occupying low-voltage power for extended periods. This mechanism provides a recovery path for situations where the high-voltage bus power failure warning condition is erroneously triggered by transient disturbances, avoiding unnecessary energy consumption and cyclical component wake-ups.
[0094] The length of the takeover time window is constrained by the upper limit of the high-voltage bus voltage time margin. This upper limit is determined as follows: the main controller acquires the instantaneous voltage and voltage drop rate of the high-voltage bus in real time; based on the instantaneous voltage, voltage drop rate, and the preset minimum operating voltage of the main motor, the main controller extrapolates the failure moment when the instantaneous voltage of the high-voltage bus drops below the minimum operating voltage of the main motor; the main controller takes the difference between the failure moment and the start time of the takeover time window, deducts the preset safety margin, and uses this as the upper limit of the high-voltage bus voltage time margin. Simultaneously, the main controller takes the product of the remaining response delay of the emergency booster motor after pre-excitation and the preset safety factor as the lower limit of the takeover time window; the length of the takeover time window is not less than the lower limit.
[0095] Reference Figure 2 The voltage extrapolation diagram shown illustrates how the main controller continuously collects the instantaneous voltage of the high-voltage bus after the power failure warning. and voltage drop rate and with the preset minimum operating voltage of the main motor Using a reference threshold, assuming the voltage continues to decrease linearly at the current rate of decrease, the failure time can be extrapolated. : in, This is the starting point of the takeover time window; for The instantaneous voltage of the high-voltage busbar at any given moment; This is the absolute value of the voltage drop rate; This is the preset minimum operating voltage for the main motor. =480V, =2.0V / ms, =380V, substituting into the above formula, we get... =(480-380) / 2.0=50ms, meaning that under this operating condition, the bus voltage will drop below the minimum operating voltage of the main motor after 50ms from the start of the connection.
[0096] Since the voltage drop rate may accelerate further in actual operating conditions, and the extrapolation process itself has estimation bias, the main controller subtracts a safety margin from the extrapolated failure time, which serves as the upper limit of the takeover time window length. : in, This is a preset safety margin. Continuing with the above scenario, let's set... =5ms, then =50-5=45ms.
[0097] The physical meaning of the upper limit of the takeover time window length is: if this length is exceeded, the main and auxiliary motors will operate on a monotonically decreasing function. Before the voltage decayed to zero, a forced power outage occurred due to the bus voltage dropping below the minimum operating voltage, rendering the torque conservation constraint physically invalid. It is a necessary condition for the physical feasibility of the torque conservation constraint.
[0098] Lower limit of the takeover time window The residual response delay is determined by the emergency booster motor. As mentioned earlier, the typical residual response delay of the emergency booster motor after d-axis pre-excitation is on the order of 0.5ms to 1ms. The main controller takes the product of this residual response delay and a preset safety factor as the lower limit of the window. in, This refers to the residual response delay of the emergency booster motor after pre-excitation. Let a preset safety factor be used. =0.8ms, =8, substituting into the above formula, we get... =8×0.8=6.4ms.
[0099] The physical meaning of the lower limit of the takeover time window is: if Then the monotonically increasing function The command value's rate of increase exceeds the tracking capability of the emergency assist motor's actual torque response. The actual torque lags significantly behind the command value in the early part of the window, thus breaking the torque conservation constraint due to the actual response delay. It is a necessary condition for the feasibility of torque conservation constraint engineering.
[0100] Following the previous discussion on the baseline length of the takeover time window =30ms, this value simultaneously satisfies =45ms and =6.4ms, which is within the upper and lower limit compatibility range. The torque conservation constraint is both physically and engineering feasible within this window length.
[0101] In some embodiments, the takeover time window length is constrained by both the upper limit and lower limit of the high-voltage bus voltage time margin. When the upper limit of the high-voltage bus voltage time margin is less than the lower limit, the main controller triggers a hard switchover fallback action. That is, when... Extreme operating conditions, such as an ultra-rapid drop in the high-voltage busbar, Reaching the 30V / ms level, making If the calculation result is negative or extremely small, the torque conservation constraint does not have a feasible window length under this operating condition. The main controller directly abandons the conservation takeover and switches to a hard switch fallback action. The specific execution process will be described later.
[0102] In some embodiments, the preset safety margin is not less than the product of the residual response delay of the emergency assist motor after pre-excitation and the preset safety factor, i.e. This ensures that the upper and lower limits of the window are naturally compatible at the numerical level. This principle holds true for the vast majority of typical power outage conditions, allowing this method to guarantee the existence of a feasible solution for the takeover time window during the engineering parameter calibration stage.
[0103] S2. During the takeover time window, the main controller causes the assist torque of the main assist motor to decrease according to a monotonically decreasing function, and the emergency controller causes the assist torque of the emergency assist motor to increase according to a complementary monotonically increasing function. The sum of the assist torque of the main assist motor and the assist torque of the emergency assist motor remains at a preset torque conservation constant at any time during the takeover time window.
[0104] Reference Figure 3 The diagram shown illustrates the timing of torque distribution between the two motors within the takeover time window. The start time of the takeover time window is... The end time of the takeover window is .exist to Within the range, the assist torque of the main assist motor According to a monotonically decreasing function Attenuation, the assist torque of the emergency assist motor According to complementary monotonically increasing functions Rising, and and Satisfying the complementary relationship: The assist torques of the main assist motor and the emergency assist motor within the window are as follows: in, This is a constant torque, specifically the output torque of the main assist motor at the instant the tripping begins. The sum of the assist torques of the two motors is: That is, the sum of the assist torques of the two motors is always equal to the torque conservation constant at any moment within the takeover time window. This ensures that the total power assist torque perceived by the driver through the steering wheel remains continuous and stepless during the switching process.
[0105] The monotonically decreasing and monotonically increasing functions are selected from the complementary function family. The complementary function family includes at least one of the following: complementary cosine function pairs, complementary sigmoid function pairs, complementary piecewise linear function pairs, and complementary third-order polynomial function pairs. Any pair of functions in the complementary function family satisfies the following conditions at the beginning of the takeover time window: the monotonically decreasing function has a value of 1 and the monotonically increasing function has a value of 0. At the end of the takeover time window, the monotonically decreasing function has a value of 0 and the monotonically increasing function has a value of 1.
[0106] To standardize the description of the form of each complementary function pair, normalized time is introduced. The specific form of the complementary function pair in normalized time is as follows.
[0107] Complementary cosine function pairs: Complementary sigmoid function pairs, taking the cubic smooth step function as an example: Complementary piecewise linear function pairs: Complementary third-order polynomial function pairs, taking a fifth-order smooth step function as an example: All four sets of functions satisfy the endpoint conditions. , , , and at any time within the window The complementary relationships between the function pairs are as follows: The torque decay slope distributions of each pair of functions are different. Specifically, the complementary piecewise linear function pairs have a constant slope within the window and the most direct response; the complementary cosine function pairs have zero slopes at the beginning and end of the window and the smoothest transition; the complementary sigmoid function pairs and the complementary third-order polynomial function pairs have the largest slopes in the middle of the window and smaller slopes at the beginning and end, falling between the two.
[0108] Building upon the baseline scenario established earlier, let's assume... =10Nm, =30ms, taking complementary cosine function pairs as an example, in =0.5 (i.e.) The point time in the window (ms) Substituting into =0.5, =0.5, main assist motor torque =5Nm, torque of emergency assist motor =5Nm, the sum of the assist torque of the two motors =10Nm, equal to Combined with endpoint conditions, i.e., the starting time. =10+0=10Nm, endpoint time =0+10=10Nm, which shows that the total torque at the three typical moments is strictly equal to the torque conservation constant, verifying that the torque conservation constraint holds at each moment within the window.
[0109] In some embodiments, the specific function form selected from the complementary function family is associated with the steering condition. Specifically, under hard steering or high vehicle speed conditions, complementary S-shaped function pairs or complementary third-order polynomial function pairs with smaller absolute values of decay slopes are selected to make the torque change smoothly near the start and end of the window, reducing the boundary impact felt by the driver; under small steering angles or low vehicle speed conditions, complementary piecewise linear function pairs with faster response are selected to make the takeover phase complete more linearly and quickly. The condition identification is based on real-time data from the vehicle speed sensor and steering wheel torque sensor. The main controller and emergency controller collaboratively select the same pair of complementary functions based on the same condition identification results to avoid the breakdown of conservation constraints caused by inconsistent selection of functions on both sides.
[0110] The physical meaning of the torque conservation constraint is that the total assist torque perceived by the driver through the steering wheel remains a constant during the switching process from the main power steering motor to the emergency power steering motor, i.e., the output torque of the main power steering motor at the moment of takeover. At any moment during the switching process, the resultant force perceived by the driver's hands is equal to the assistance provided by the main power steering motor before the switching occurs, so that there is no abrupt change at the moment of switching, and the steering feel remains continuous.
[0111] The enforcement of the torque conservation constraint relies on a consistent benchmark for the torque conservation constant between the main controller and the emergency controller. If the two controllers use different values for the torque conservation constant, then... The complementary relationship will degenerate into When the sum of the torques of the two motors assists, it will deviate from the conservation constant, and the conservation constraint will immediately become mathematically invalid.
[0112] To address the issue of consistent references between the two sides, a consistent reference for the torque conservation constant is established between the main controller and the emergency controller in the following manner: At the beginning of the takeover time window, the main controller collects the current output torque of the main auxiliary motor as the torque conservation constant; the main controller broadcasts the torque conservation constant to the emergency controller once via the inter-controller communication bus. After the single broadcast, the monotonically decreasing function and the monotonically increasing function evolve independently by the main controller and the emergency controller according to their respective local clocks, without the need for repeated synchronization of the torque conservation constant within the takeover time window.
[0113] Reference Figure 4 The timing diagram shown illustrates the interaction between the establishment of the dual-controller torque reference and the confirmation of takeover completion. The specific execution process of this mechanism is as follows. At any given moment, the main controller samples the current output torque of the main boost motor from the current loop. Assign this value to the torque conservation constant. ,Right now Building upon the aforementioned benchmark scenario, The current output torque of the main assist motor is 10 Nm, therefore =10Nm. The main controller then sends a torque conservation constant broadcast message via the inter-controller communication bus. The message content includes... The value, Local clock timestamp, takeover time window length The numerical value, and the function family identifier field, which is used to inform the emergency controller of the complementary function pair to be used in this takeover.
[0114] After receiving the broadcast message, the emergency controller will broadcast the received message. , , The three values are cached in local registers and evolve independently according to their respective local clocks. Specifically, the emergency controller calculates the current normalized time using the local clock in each control cycle (typically 100μs). And substitute it into the selected complementary function family. Calculate the torque command of the emergency booster motor The main controller also evolves independently based on the local clock. , and according to The torque of the drive motor decreases. During the entire takeover time window, neither controller needs to be adjusted. For any synchronous communication, the communication load is reduced from continuous broadcasting to single-frame messages.
[0115] A comparison of the communication load magnitudes clearly illustrates the engineering value of this mechanism. If synchronization is achieved by broadcasting once per control cycle... ,exist Under conditions of 30ms and a control cycle of 100μs, the number of broadcast frames in a single takeover process is 30 / 0.1 = 300 frames. Even if each frame only occupies a few dozen bytes, in engineering scenarios where the bandwidth of the inter-controller communication bus is limited, such high-frequency broadcasts will compete for bandwidth with status messages, fault code messages, etc., which may cause message delays or loss. This mechanism reduces the number of broadcast frames in a single takeover to 1 frame, making the communication load independent of the window length. Even if the window length is extended to the order of 100ms, the communication load is still 1 frame.
[0116] The feasibility of dual-side independent clock evolution hinges on the controllability of local clock drift within a window length. Assuming the nominal frequency of the local clocks for both the main controller and the emergency controller is 100MHz, and the frequency stability of a typical quartz crystal oscillator is ±50ppm, then within a 30ms window length, the maximum cumulative difference in clock drift between the two sides is 30ms × 50ppm × 2 = 3μs, which accounts for 0.01% of the window length and is far smaller than that of the complementary function. The torque distribution accuracy requirement can be stably met by the conservation constraint under independent evolution on both sides.
[0117] In some embodiments, the main controller and the emergency controller exchange clock synchronization messages via an inter-controller communication bus during the system startup phase, ensuring that the local clocks on both sides are aligned immediately after system startup. This alignment mechanism can be implemented based on a precise time protocol, SAE J1939 time synchronization messages, or a custom bidirectional timestamp exchange protocol, further compressing the drift of the local clocks on both sides within the window length.
[0118] The determination of the takeover time window length and the judgment of the high-voltage bus power outage warning conditions both depend on the voltage drop rate. A reliable estimate. If the instantaneous difference method is used directly to obtain... That is, take the voltage difference between two adjacent sampling points and divide it by the sampling period. The estimation results will be affected by the superposition of multiple interference sources, specifically including: the high torque transient of the main auxiliary motor causing pulsed bus current, generating a transient voltage drop of several volts across the bus equivalent impedance; the charging and discharging pulsations of the bus filter capacitor superimposed on the DC voltage, introducing ripple in the range of hundreds of hertz to kilohertz; and the potential introduction of millisecond-level voltage spikes due to bus contactor jitter. These interference sources cause the output value of the instantaneous differential method to deviate from the true rate of decrease, potentially leading to incorrect triggering of warning conditions or significant deviation of the extrapolated failure time from reality.
[0119] To suppress the above interference, the voltage drop rate is obtained by performing least squares fitting on the instantaneous voltage sampling sequence of the high-voltage bus within a preset time period. The preset time period is dynamically adjusted according to the current phase current amplitude of the main and auxiliary motors. The larger the current phase current amplitude, the longer the preset time period.
[0120] The specific implementation process of least squares fitting is as follows: the main controller uses the sampling period... The instantaneous voltage of the high-voltage bus is continuously sampled to obtain a voltage sampling sequence within a preset time period. Linear least-squares fitting is then performed on this sampling sequence, and the slope of the fitted line is used as an estimate of the voltage drop rate. The advantage of least-squares fitting compared to the instantaneous difference method is that the fitting process simultaneously uses information from all sampling points within the window, has an averaging effect on single-point noise, and makes the estimation result more robust against random disturbances. Simultaneously, the fitting slope reflects the overall voltage change trend within the window, which can filter out the influence of high-frequency ripple and transient spikes on the slope estimation.
[0121] Preset duration The dynamic adjustment logic is based on the current phase current amplitude of the main and auxiliary motors. The decision is made based on the current phase current amplitude. A larger current amplitude results in a greater torque ripple amplitude superimposed on the bus voltage, requiring a longer window to average out the impact of the ripple on the slope estimation. Conversely, when the current phase current amplitude is smaller, the bus voltage is relatively clean, allowing for a shorter window to improve the response speed to actual power outages. The specific mapping relationship can be expressed piecewise, for example, when... <30A =10ms, when 30A≤ <60A =15ms, when ≥60A =20ms. Let the sampling period be... =1ms, under typical operating conditions where the phase current amplitude of the main and auxiliary motors is 50A. It falls within the second segment, corresponding to =15ms, number of sampling points N within the window= =15.
[0122] Reference Figure 2The voltage sampling points within the window are scattered near the fitted straight line, and the slope of the fitted straight line is the estimated voltage drop rate. Substituting this estimated value into the aforementioned extrapolation formula for the failure time yields the failure time under the current operating condition. The voltage drop rate estimation in this section also serves the warning condition decision mentioned above. That is, the warning rate threshold of -2V / ms is the decision threshold for the slope value of the least squares fitted output, so that the warning decision and the determination of the takeover time window length share the same set of disturbance rejection estimation results.
[0123] S3. After the takeover time window ends, the main controller de-energizes the main assist motor, and the emergency controller enables the emergency assist motor to independently provide steering assistance, thus obtaining emergency steady-state assist output. S3 includes sub-steps S31-S33.
[0124] S31. At the end of the takeover time window, the emergency controller sends a takeover completion confirmation message to the main controller via the inter-controller communication bus.
[0125] S32. After receiving the takeover completion confirmation message, the main controller will cut off the power to the main auxiliary motor.
[0126] S33. If the takeover completion confirmation message does not arrive within the preset timeout window, the main controller will force the main auxiliary motor to be powered off according to the local clock and trigger fault code recording. The preset timeout window is a preset multiple of the takeover time window length.
[0127] Establishing a clear takeover completion boundary is crucial for the stable completion of torque conservation constraints. Because the main controller and emergency controller do not synchronously communicate torque commands during the window period under the dual-side independent evolution mechanism, the main controller cannot determine whether the emergency controller has truly evolved to the correct state based solely on its own status. =1. If the main controller only operates according to its own local clock... The main power assist motor was constantly shut off, but the emergency controller failed to promptly drive the emergency power assist motor to its normal torque output. Then in The total assist torque will collapse at any given moment, and the torque conservation constraint will be violated at the end of the window. The two-way confirmation mechanism of S31-S33 is used to establish a clear boundary for the completion of the takeover.
[0128] Reference Figure 4 The execution process of sub-step S31 is as follows: The emergency controller reaches the local clock... At that time, and the measured torque value of the emergency assist motor has stabilized and approached... At this time, a takeover completion confirmation message is sent to the main controller via the inter-controller communication bus. The message content includes at least the local clock information of the emergency controller. Timestamp and confirmation status code.
[0129] The execution process of sub-step S32 is as follows: After receiving the takeover completion confirmation message, the main controller immediately sends a command to the inverter of the main auxiliary motor to stop the pulse width modulation (PWM) output, causing the main auxiliary motor to enter a safe power-off state. At the moment of power-off, the rotor of the main auxiliary motor is passively rotated due to the reverse force of the steering gear. The back electromotive force of the rotor may still generate a voltage of several volts on the stator winding of the main auxiliary motor, but since the inverter has stopped the PWM output, this back electromotive force will not drive the stator current, and the main auxiliary motor will no longer output torque to the steering gear.
[0130] Sub-step S33 is a timeout fallback branch. The preset timeout window is set to twice the length of the takeover time window, meaning the timeout threshold is 2 × 30 = 60 ms. From... After 60ms, that is If the main controller does not receive a takeover completion confirmation message within the next 30ms, it will forcibly de-energize the main auxiliary motor according to its local clock. The timeout window is set to... The rationale for doubling the capacity is that it provides the emergency controller with at least a full window of margin to handle short-term processing delays within the emergency controller, while also preventing the main and auxiliary motors from being energized for extended periods, thus consuming the bus capacitor energy and accelerating the process of the bus voltage dropping below the minimum operating voltage.
[0131] After a forced power failure, the main controller synchronously triggers fault code recording. In some embodiments, the fault code record includes at least one of the following: trigger cause code, timestamp of the start time of the takeover time window, difference between the expected and actual arrival time of the takeover completion confirmation message, and the forced power failure time of the local clock. The fault code is reported to the upper-level fault management system via the inter-controller communication bus. This fault code is used to trace the root cause of the takeover failure afterward. For example, if the "confirmation message timeout" fault code appears multiple times, it may indicate an intermittent fault in the inter-controller communication bus or an anomaly in the emergency controller firmware; if the "excessive deviation between the emergency booster motor torque value and the torque conservation constant" fault code appears multiple times, it may indicate degradation of the emergency booster motor body or torque sensor.
[0132] After the takeover window ends and the main power steering motor is de-energized, the system enters the emergency steady-state power steering output phase. During this phase, the emergency power steering motor independently provides steering assistance, with the assist torque adjusted in real-time based on the driver's hand strength and vehicle speed, similar to the assist strategy of the main power steering motor during normal operation. However, because the typical upper limit of the low-voltage power supply is 6.0kW, lower than the power of the main power steering motor under high-voltage bus power (typically 9kW), the output capacity of the emergency power steering motor is somewhat limited. The emergency steady-state power steering output phase continues until the high-voltage bus is restored or the vehicle is stopped for maintenance. During this period, the driver can still operate the steering system normally to perform operations such as pulling over or leaving dangerous road sections.
[0133] During the emergency steady-state assist output phase, this method supports several extended embodiments to address the differences in operating conditions, driver perception needs, and thermal management needs during long-term operation under emergency steady-state conditions.
[0134] In some embodiments, during the emergency steady-state power assist output phase, the emergency controller sets upper limits on the output current of the emergency power assist motor according to vehicle speed segments. Specifically, the vehicle speed is divided into three segments: low speed, medium speed, and high speed, with each segment corresponding to a different upper limit on current and output filtering time constant. When the vehicle speed is below 20 km / h, the typical operating conditions for the emergency power assist motor are stationary turning or low-speed large-angle turning, with high steering resistance torque and high driver assistance torque. In this case, the emergency controller relaxes the current limit to prioritize the output capability of the assist torque, allowing the driver to smoothly complete large-angle operations within the power limit of the low-voltage power supply. When the vehicle speed is between 20 km / h and 60 km / h, the typical operating conditions for the emergency power assist motor are lane changing or obstacle avoidance, with moderate steering resistance torque. The emergency controller uses a moderate current limit to balance the assist capability and power consumption. When the vehicle speed is above 60 km / h, the typical operating conditions for the emergency power assist motor are small-angle corrections at high speeds, with low steering resistance torque. However, the driver is sensitive to the finesse of the steering feel. The emergency controller tightens the current limit and increases the output filter time constant to keep the output of the emergency power assist motor smooth under small corrections, avoiding instability caused by excessive assistance at high speeds.
[0135] In some embodiments, at the starting moment of entering the emergency steady-state power assist output, the emergency controller superimposes a torque pulsation with a preset amplitude and a preset duration onto the base assist torque of the emergency power assist motor. This torque pulsation is transmitted to the steering wheel via the steering system, creating a tactile feedback. The frequency of the torque pulsation avoids the frequency range sensitive to human fatigue and the mechanical resonance frequency range of the steering wheel. Typical pulsation parameters are: amplitude 0.3 Nm, frequency 8 Hz, and duration 200 ms, meaning that eight small torque oscillations with an amplitude of 0.3 Nm are generated on the steering wheel within 200 ms. This frequency avoids the frequency range sensitive to human fatigue (typically 4 Hz to 6 Hz) and the mechanical resonance frequency range of the steering wheel (typically above 12 Hz), and will not cause driver discomfort or amplify steering wheel resonance. This torque pulsation, as a tactile feedback, actively informs the driver that the system has entered emergency mode, guiding the driver to use more cautious steering operations and to pull over or leave the dangerous area as soon as possible.
[0136] In some embodiments, during the emergency steady-state power assist output phase, the emergency controller monitors the winding temperature of the emergency assist motor and the temperature of the power components within the controller in real time. When the temperature exceeds a first protection threshold, the upper limit of the output current of the emergency assist motor is reduced. When the temperature exceeds a second protection threshold, a hard-switching fallback action is further triggered. The typical value for the first protection threshold is 95°C, and the typical value for the second protection threshold is 130°C. In situations where the vehicle remains stationary in an emergency steady-state state for an extended period, such as when the driver fails to pull over in time and continues to drive slowly in congested areas, the emergency assist motor may experience a rapid temperature rise due to the limited power density of the low-voltage power supply. Setting up two levels of temperature protection can prevent the emergency assist motor from overheating and being damaged. When the temperature rise reaches the first threshold, the upper limit of the current is actively reduced to slow the rate of temperature rise. When the temperature rise reaches the second threshold, a hard-switching fallback action is directly initiated, outputting a fixed minimum torque by looking up a table and stopping the regular closed-loop assist, thus protecting the electrical components of the emergency assist motor and the emergency controller.
[0137] During the S2 takeover phase, the torque conservation constraint holds stably under most typical operating conditions. However, it may fail under abnormal conditions such as emergency assist motor malfunction, torque sensor drift, dual-controller communication interruption, or severe energy prediction inaccuracies. The conservation deviation monitoring and hard-switching fallback mechanism introduced in this method is an anomaly fallback mechanism spanning the entire takeover phase and the emergency steady-state phase, ensuring that the driver still receives basic assistance when the conservation constraint fails.
[0138] In S2, the main controller acquires the sum of the assist torque of the main assist motor and the assist torque of the emergency assist motor in real time, and calculates the conservation deviation between this sum and the torque conservation constant. Let the measured assist torque of the main assist motor be... The measured assist torque of the emergency assist motor is Conservation bias for: in, and The current is sampled from its respective current loop by the main controller and the emergency controller, and the emergency controller transmits the data via the inter-controller communication bus. The data is periodically reported to the main controller, enabling the main controller to obtain a real-time estimate of the sum of the assist torques of the two motors.
[0139] Main controller continuously monitors When the torque conservation deviation exceeds the preset conservation tolerance and its duration exceeds the preset tolerance duration threshold, the main controller abandons the torque conservation constraint, and the main controller and emergency controller work together to execute a hard switchover fallback action. The preset conservation tolerance and tolerance duration threshold are determined based on the following principle: the conservation tolerance must be greater than the torque sensor measurement noise under normal conditions but less than the torque jump level that the driver can clearly perceive; the tolerance duration threshold is used to filter instantaneous spike interference to avoid accidental deviations at a single sampling point triggering the fallback. In a baseline scenario with a tolerance of 10 Nm, the typical value for the conservation tolerance is 1 Nm. 10%, with a typical tolerance duration threshold of 5ms. For example, if exist When the deviation reaches 1.2 Nm at a given time (1.2 Nm > 1 Nm), the main controller starts timing; if this deviation continues to exceed 1 Nm within the following 5 ms, that is, at... If the millisecond deviation still exceeds the threshold, the main controller will immediately trigger a hard switch as a fallback.
[0140] The hard-switch fallback action includes three concurrent sub-actions: the main controller immediately switches the assist torque of the main power assist motor to zero; the emergency controller enables the emergency power assist motor to directly output the preset minimum assist torque obtained by looking up a table based on vehicle speed and instantaneous steering torque; and the main controller triggers fault code recording and driver alarm signals through the inter-controller communication bus.
[0141] The process of switching the assist torque of the main assist motor to zero is as follows: the main controller immediately sends a command to the inverter of the main assist motor to stop the PWM output, and the main assist motor enters a safe power-off state. This process no longer follows a monotonically decreasing function. Instead of following the gradual change pattern, the torque of the main assist motor is directly reduced to zero.
[0142] The process of the emergency booster motor directly outputting the preset minimum boost torque is as follows: the emergency controller queries the pre-stored two-dimensional lookup table, based on the current vehicle speed. and instantaneous steering torque As input, obtain the corresponding emergency backup torque output. ,in This refers to the instantaneous torque applied to the steering wheel by the driver. The design principle of the lookup table is to output a higher minimum torque under low-speed, large-angle conditions, and a lower minimum torque under high-speed, straight-line, small-correction conditions. For example... =5km / h =8Nm =9Nm. The lookup table covers a vehicle speed range of 0km / h to 100km / h and a steering torque range of 0Nm to 12Nm, clamping at boundary values outside these ranges. This lookup table ensures that even if conservation constraints fail, the driver still receives basic assistance matching the current operating conditions, keeping the vehicle basically controllable.
[0143] The fault code recording and driver alarm signal triggering share the same reporting channel as the timeout fallback fault code logic described above. In a hard handover fallback scenario, the fault code content includes the trigger cause code, which specifically includes different sub-causes such as excessive conservation deviation or incompatibility between upper and lower limits, as well as the trigger time. , Peak values and other information. The driver warning signal is achieved by illuminating the emergency turn indicator light on the vehicle's instrument panel and sounding a short buzzer, indicating to the driver that the system has entered hard-switch fallback mode and that the driver needs to pull over and check as soon as possible.
[0144] In some embodiments, if the aforementioned upper limit of the high-voltage bus voltage time margin is less than the lower limit of the window, i.e. The main controller can directly trigger the hard switchover fallback action in this section without entering the takeover phase. This branch addresses the extreme condition of an ultra-rapid drop in the high-voltage busbar, ensuring that the extrapolated failure time is within a certain range. If the length is too short, the torque conservation constraint does not have a feasible window length under this condition, and the conservation take-off cannot be physically established. Directly switching to hard switching as a fallback is the only feasible safe path.
[0145] This application also provides an emergency power steering cooperative control system for electric commercial vehicles, comprising: a main power steering motor and a main controller connected to the main power steering motor, the main controller being connected to a high-voltage bus; an emergency power steering motor and an emergency controller connected to the emergency power steering motor, the emergency controller being connected to a low-voltage power supply; a steering gear, the main power steering motor and the emergency power steering motor being coaxially and parallelly coupled to the same input shaft of the steering gear; and an inter-controller communication bus, the inter-controller communication bus being connected between the main controller and the emergency controller, configured to transmit status messages and torque conservation constants between the main controller and the emergency controller.
[0146] Reference Figure 5The overall architecture of the emergency power steering cooperative control system for electric commercial vehicles is shown. This system comprises two parts: hardware components and software configuration items. The hardware components include the main power steering motor, main controller, emergency power steering motor, emergency controller, steering gear, and communication bus between controllers. The software configuration items include functions such as high-voltage bus monitoring, torque decay drive, torque conservation constant broadcasting, conservation deviation monitoring, and hard switching triggering within the main controller; and functions such as current loop readiness, d-axis pre-excitation, torque increase drive, takeover completion confirmation message transmission, and emergency steady-state assist within the emergency controller. The operating mode of this system is specified by this method, as detailed in the description of the method steps above.
[0147] The coaxial parallel coupling of the main power assist motor and the emergency power assist motor can be implemented in the following ways at the hardware level, including but not limited to: The first way is that each motor is connected to the same worm gear in the steering gear via an independent reduction mechanism, jointly driving the worm gear to rotate; the second way is that the output shafts of the two motors are connected in parallel to the same gearbox, and the output end of the gearbox is connected to the input shaft of the steering gear; the third way is that each motor drives two adjacent pinions, and the two pinions mesh together with the rack in the steering gear, with the torque superimposed through the rack. These three methods mechanically achieve parallel torque output from the two motors, and even if one motor fails, the output torque of the other motor can still act on the steering gear through a common transmission chain.
[0148] The main controller and emergency controller are physically independent packages, located in different positions in the vehicle's front compartment, and connected via independent low-voltage wiring harnesses and an inter-controller communication bus. The main controller contains an inverter, current loop, voltage sampling circuit, message transceiver module, and fault management module; the emergency controller contains an independent inverter, current loop, d-axis pre-excitation circuit, message transceiver module, and emergency steady-state control module. The two controllers are hardware-independent, ensuring that a failure in one controller does not affect the normal operation of the other.
[0149] The inter-controller communication bus is an independent communication link within the electric power steering system. The signal cables of this bus are physically independent of the vehicle's CAN bus, using independent twisted-pair wires. The grounding point and power reference point are also independently designed, ensuring that a failure in either communication bus—such as a wire harness open circuit or shielding failure—will not affect the normal operation of the other communication bus. The inter-controller communication bus primarily carries the following message types: wake-up messages from the main controller to the emergency controller, torque conservation constant broadcast messages, and status query messages; ready status messages from the emergency controller to the main controller, emergency power steering motor measured torque reporting messages, and takeover completion confirmation messages; as well as bidirectional fault code reporting messages and heartbeat maintenance messages.
[0150] The main controller is configured to: wake up the emergency controller and enter the current loop ready state via the inter-controller communication bus when a high-voltage bus power failure warning condition is detected; drive the main auxiliary motor to decrease the auxiliary torque according to a monotonically decreasing function within the takeover time window; and execute the power cut-off of the main auxiliary motor after the takeover time window ends.
[0151] The main controller is also configured to: acquire the instantaneous voltage and voltage drop rate of the high-voltage bus in real time, extrapolate the instantaneous voltage, voltage drop rate and preset minimum operating voltage of the main motor to obtain the failure time when the instantaneous voltage of the high-voltage bus drops below the minimum operating voltage of the main motor, and take the difference between the failure time and the start time of the takeover time window, minus the preset safety margin, as the upper limit of the window length of the takeover time window.
[0152] The main controller is internally divided into several modules, each with a specific function that corresponds to a step in this method. The voltage sampling module is responsible for continuously sampling the instantaneous voltage of the high-voltage bus, and the sampled output is sent to... Estimation module; The estimation module calculates the voltage drop rate using the least squares fitting method described earlier; the early warning decision module identifies high-voltage bus power failure early warning conditions based on instantaneous voltage and voltage drop rate using the twin condition criterion described earlier; the extrapolation calculation module calculates the upper limit of the window length using the failure time extrapolation formula described earlier; and the torque decay drive module uses the monotonically decreasing function described earlier. The torque of the main and auxiliary motors decreases; the broadcast message sending module sends the torque conservation constant to the emergency controller according to the single broadcast mechanism described above; the power-off execution module executes the power-off of the main and auxiliary motors according to the two-way confirmation mechanism and timeout fallback mechanism described above. All modules run concurrently within the main controller, exchanging data through shared memory or message queues.
[0153] In some embodiments, the main controller is further configured to acquire the sum of the assist torque of the main assist motor and the assist torque of the emergency assist motor in real time, calculate the conservation deviation between this sum and the torque conservation constant, and abandon the torque conservation constraint and trigger a hard-switching fallback action when the conservation deviation exceeds a preset conservation tolerance and the duration exceeds a preset tolerance duration threshold. This configuration item corresponds to the method steps of conservation deviation monitoring and hard-switching fallback action described above, and is implemented jointly by the conservation deviation monitoring module and the hard-switching triggering module inside the main controller. The conservation deviation monitoring module periodically calculates... Compared with the constant tolerance, the hard switching trigger module immediately sends a power-off command to the main auxiliary motor inverter when the deviation exceeds the threshold and the duration exceeds the threshold, and notifies the emergency controller to switch to emergency steady-state lookup table output through the inter-controller communication bus.
[0154] In some embodiments, the main controller is further configured to broadcast a torque conservation constant to the emergency controller via the inter-controller communication bus at the start of the takeover time window, and to forcibly de-energize the main auxiliary motor according to the local clock if the takeover completion confirmation message does not arrive within a preset timeout window. This configuration item corresponds to the method steps of the single-broadcast torque conservation constant mechanism and the timeout fallback mechanism described above, and is implemented jointly by the broadcast message sending module and the timeout monitoring module within the main controller.
[0155] The emergency controller is configured to: increase the assist torque of the emergency assist motor according to a complementary monotonically increasing function during the takeover time window; and allow the emergency assist motor to independently provide steering assistance after the takeover time window ends. The main controller and the emergency controller work together to ensure that the sum of the assist torques of the main assist motor and the emergency assist motor remains at a preset torque conservation constant at any time during the takeover time window.
[0156] The emergency controller is internally divided into several modules, each with a specific function corresponding to the steps in this method. The message receiving module receives wake-up messages and torque conservation constant broadcast messages from the main controller; the current loop ready module switches the current loop from standby to ready state upon receiving the wake-up message; the torque increase drive module operates according to the monotonically increasing function described earlier. The emergency power steering motor torque increases; the takeover completion confirmation message sending module sends a confirmation message to the main controller at the end of the takeover time window; the emergency steady-state control module takes over the normal closed-loop control of the power steering after the main power steering motor is powered off.
[0157] The coordinated operation of the main controller and the emergency controller does not rely on real-time handshakes during the takeover window, but rather on the aforementioned... The system employs a "single-time broadcast + independent clock evolution on both sides" mechanism. This mechanism allows each controller to evolve independently within a window period according to its local clock and a selected complementary function. However, because both sides use the same torque conservation constant reference and the same pair of complementary functions, and the local clock drift is controllable within the window length, the torque conservation constraint is mathematically rigorous. This collaborative approach is fundamentally different from the traditional "master-slave real-time synchronization" mechanism, which requires both sides to synchronize torque commands in every control cycle, with the communication load proportional to the window length. In contrast, the communication load of this mechanism is independent of the window length, enabling the system to operate stably even in engineering scenarios where the bandwidth of the inter-controller communication bus is limited.
[0158] In some embodiments, the emergency controller is further configured to apply a preset amplitude d-axis pre-excitation current to the emergency booster motor before the start of the takeover time window, enabling the emergency booster motor to establish a magnetic field under zero torque output conditions. This configuration corresponds to the pre-excitation method steps described above and is implemented internally by the d-axis pre-excitation circuit within the emergency controller. The amplitude of the pre-excitation current is configured by a parameter table, typically ranging from 5% to 10% of the rated current of the emergency booster motor.
[0159] In some embodiments, the main controller and the emergency controller are further configured to select a monotonically decreasing function and a monotonically increasing function from a complementary function family, which includes at least one of complementary cosine function pairs, complementary sigmoid function pairs, complementary piecewise linear function pairs, and complementary third-order polynomial function pairs. The specific selection of the complementary function pair is determined by the main controller based on the operating condition identification result at the start of takeover and is communicated to the emergency controller via the function family identifier field in the torque conservation constant broadcast message, enabling both controllers to use the same pair of complementary functions to evolve their respective torque commands during the window period.
[0160] The inter-controller communication bus serves as the key engineering carrier of this method and system. Its implementation form and protocol layer independence are important characteristics of this application. The implementation extension of this bus will be further described below.
[0161] The inter-controller communication bus can be any of the following: Controller Area Network (CAN) bus, CAN flexible data bus, vehicle Ethernet, or serial peripheral interface bus. A typical CAN bus has a speed of 500 kbps or 1 Mbps, suitable for emergency steering scenarios with short message lengths and few nodes. A typical CAN flexible data bus has a speed of 2 Mbps to 5 Mbps, reaching up to 8 Mbps in the data segment, suitable for extended message scenarios requiring higher throughput. A typical vehicle Ethernet bus has a speed of 100 Mbps or 1 Gbps, suitable for future integration with higher-level vehicle control systems. A typical serial peripheral interface bus has a speed of 1 Mbps to 10 Mbps, suitable for compact layouts where the main controller and emergency controller are physically close, such as within the same controller box. All types of buses can carry the core communication content required by this method, such as status messages, torque conservation constant broadcast messages, and takeover completion confirmation messages.
[0162] The inter-controller communication bus is independent of the vehicle controller LAN bus at both the physical and protocol layers. Physical layer independence is reflected in the fact that this bus uses independent wiring harnesses and connectors, and does not share any signal lines, power lines, or ground lines with the vehicle's CAN bus. This ensures that a failure in one communication bus does not affect the normal operation of the other. Simultaneously, this bus is connected to the independent power domain of the electric power steering system within the vehicle's electrical architecture, independent of the power supply status of the vehicle's communication gateway. This allows the bus to continue operating independently even when the vehicle's communication gateway is powered off or fails. Protocol layer independence is reflected in the fact that the message ID, message format, handshake protocol, heartbeat mechanism, and fault diagnosis protocol of this bus are all defined internally by the electric power steering system, requiring no protocol adaptation by the vehicle manufacturer.
[0163] The identification of high-voltage bus power failure warning conditions relies solely on the instantaneous voltage and voltage drop rate of the high-voltage bus collected by the main controller itself, without requiring support from the vehicle's battery management system or vehicle controller messages. This characteristic allows the system's warning identification capability to be entirely completed within the electric power steering system, independent of fault warning messages provided by the OEM. In terms of engineering implementation, this feature offers the following value: the system can be sold as a universal emergency power steering product to multiple OEMs. When deployed on different models from different OEMs, there is no need for customized development for each OEM's warning protocol, significantly reducing engineering integration costs and adaptation time.
[0164] In some embodiments, in scenarios where a high-voltage fault warning message for the battery management system is provided on a certain vehicle controller LAN, the main controller can selectively use this message as an auxiliary warning source in the decision-making process, supplementing rather than replacing the local warning. Specifically, the main controller still uses the local instantaneous voltage and voltage drop rate as the primary warning source, but simultaneously listens for battery management system warning messages on the vehicle's CAN bus. If the message is triggered before the local warning conditions, the main controller wakes up the emergency controller a certain amount of time in advance, allowing for more preparation time. This embodiment enables the system to have stronger warning capabilities when the vehicle provides the BMS protocol, but even if the vehicle does not provide the protocol, the system can still operate independently based on the local warning source, and its versatility remains unaffected.
[0165] As a key carrier of the takeover completion boundary, the extended implementation of the takeover completion confirmation message further enhances the credibility of the takeover effect.
[0166] In some embodiments, the takeover completion confirmation message includes at least one of the following: the local clock timestamp of the emergency controller, the measured torque value of the emergency booster motor, and the measured phase current value of the emergency booster motor. After receiving the takeover completion confirmation message, the main controller compares the measured torque value with the torque conservation constant to verify the takeover effect.
[0167] Specifically, in addition to the aforementioned basic fields of timestamp and acknowledgment status code, the extended takeover completion confirmation message also includes the following fields: (The emergency controller...) Real-time measured torque value of emergency assist motor Emergency assist motor in Measured phase current value at time After receiving the message, the main controller will... With torque conservation constant Compare and calculate torque deviation If the deviation is less than the preset verification threshold, the takeover is confirmed as successful; otherwise, it is considered a soft failure and a fault code or hard switchover is triggered as a fallback. A typical preset verification threshold value is... 5%. Undertake In a baseline scenario with a torque of 10 Nm, the verification threshold is 0.5 Nm. Assuming the measured torque of the emergency assist motor at the moment of takeover completion is 9.7 Nm, the torque deviation |9.7 - 10| = 0.3 Nm. Since 0.3 Nm < 0.5 Nm, the main controller considers the takeover successful and executes the power-off of the main assist motor.
[0168] The engineering significance of introducing this extended field lies in upgrading the takeover completion boundary semantics from merely determining that a command has been issued to simultaneously determining that torque has been achieved. The former only guarantees that the emergency controller has completed its task. While the evolution of emergency assist motors has been observed, their actual torque output is affected by factors such as electrical delays, mechanical transmission backlash, and torque sensor errors, potentially causing deviations from the commanded value. The latter method directly verifies on the main controller side whether the measured torque of the emergency assist motor is truly close to the commanded value. This significantly improves the reliability of the criteria for determining the takeover completion boundary. In this extended embodiment, even if the emergency assist motor itself has an abnormality that causes the measured torque to fail to track the command, the main controller can promptly detect it through the verification mechanism and switch to a fallback mode, avoiding the delayed failure of discovering that the emergency assist motor has failed to take over properly only after the main assist motor has been de-energized.
[0169] The measured phase current value field is used for post-event traceability; that is, in the fault code record of a failed takeover, the measured phase current value can reflect the emergency assist motor's status. The operating status at any time, combined with the measured torque value, can diagnose the source of the fault. Specifically, a low current may indicate an abnormal current loop, while a high current but low torque may indicate demagnetization of the permanent magnet or loss of rotor synchronism.
[0170] The above embodiments are only some embodiments of this application, and not all embodiments. Equivalent substitutions, modifications, and improvements made by those skilled in the art without departing from the concept of this application are all within the scope of protection of this application. The accompanying drawings in this application are merely illustrative. In actual implementation, the specific shape, size ratio, connection method of each component, and the specific execution details of each step in the flowchart can be appropriately adjusted. As long as the core mechanism of its technical solution is substantially the same as the torque conservation constraint, bilateral independent evolution mechanism, bidirectional confirmation and timeout fallback mechanism, and local early warning identification mechanism described in this application, they should all be considered to fall within the scope of protection of this application.
[0171] The above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application, and should all be included within the protection scope of this application.
Claims
1. A method for coordinated control of emergency power steering in electric commercial vehicles, applied to a dual-power steering system with a main power steering motor and a main controller, and an emergency power steering motor and an emergency controller, wherein the main power steering motor and the emergency power steering motor are coaxially and parallelly coupled to the same steering input shaft, the main controller is connected to a high-voltage bus, and the emergency controller is connected to a low-voltage power supply, characterized in that... Includes the following steps: S1. When the main controller detects the high-voltage bus power failure warning condition, the main controller wakes up the emergency controller from standby to current loop ready state through the inter-controller communication bus, and obtains the emergency assist motor in the preparation state. The output torque of the emergency assist motor in the preparation state is zero. S2. During the takeover time window, the main controller causes the assist torque of the main assist motor to decrease according to a monotonically decreasing function, and the emergency controller causes the assist torque of the emergency assist motor to increase according to a complementary monotonically increasing function. The sum of the assist torque of the main assist motor and the assist torque of the emergency assist motor remains at a preset torque conservation constant at any time during the takeover time window, thereby obtaining a dual-motor cooperative output that satisfies the torque conservation constraint. S3. After the takeover time window ends, the main controller will de-energize the main assist motor, and the emergency controller will enable the emergency assist motor to independently provide steering assistance, thereby obtaining an emergency steady-state assist output; The length of the takeover time window is constrained by the upper limit of the high-voltage bus voltage time margin, which is determined in the following way: The main controller acquires the instantaneous voltage and voltage drop rate of the high-voltage bus in real time. The main controller extrapolates the moment when the instantaneous voltage of the high-voltage bus drops below the minimum operating voltage of the main motor based on the instantaneous voltage, the voltage drop rate, and the preset minimum operating voltage of the main motor. The main controller takes the difference between the failure time and the start time of the takeover time window, deducts a preset safety margin, and uses this difference as the upper limit of the high-voltage bus voltage time margin.
2. The emergency power steering coordinated control method for electric commercial vehicles according to claim 1, characterized in that, The monotonically decreasing function and the monotonically increasing function are selected from a family of complementary functions. The family of complementary functions includes at least one of complementary cosine function pairs, complementary sigmoid function pairs, complementary piecewise linear function pairs, and complementary third-order polynomial function pairs. Any pair of functions in the family of complementary functions satisfies the following conditions at the beginning of the takeover time window: the monotonically decreasing function has a value of 1 and the monotonically increasing function has a value of 0. At the end of the takeover time window, the monotonically decreasing function has a value of 0 and the monotonically increasing function has a value of 1.
3. The emergency power steering coordinated control method for electric commercial vehicles according to claim 1, characterized in that, The voltage drop rate is obtained by performing least-squares fitting on the instantaneous voltage sampling sequence of the high-voltage bus within a preset time period. The preset time period is dynamically adjusted according to the current phase current amplitude of the main auxiliary motor. The larger the current phase current amplitude, the longer the preset time period.
4. The emergency power steering coordinated control method for electric commercial vehicles according to claim 1, characterized in that, After the emergency booster motor is in a ready state in step S1, and before step S2 begins, the following is also included: The emergency controller applies a preset amplitude d-axis pre-excitation current to the emergency assist motor, so that the emergency assist motor completes the magnetic field establishment under zero torque output conditions, thus obtaining an emergency assist motor with pre-excitation completed. The main controller takes the product of the remaining response delay of the emergency assist motor after pre-excitation and the preset safety factor as the lower limit of the takeover time window, and the window length of the takeover time window is not less than the lower limit of the window.
5. The emergency power steering coordinated control method for electric commercial vehicles according to claim 1, characterized in that, The torque conservation constant is used to establish a consistent reference between the main controller and the emergency controller in the following manner: At the start of the takeover time window, the main controller collects the current output torque of the main assist motor as the torque conservation constant. The main controller broadcasts the torque conservation constant to the emergency controller once via the inter-controller communication bus. After the single broadcast, the monotonically decreasing function and the monotonically increasing function evolve independently by the main controller and the emergency controller according to their respective local clocks, without the need to repeatedly synchronize the torque conservation constant within the takeover time window.
6. The emergency power steering coordinated control method for electric commercial vehicles according to claim 5, characterized in that, The step of cutting off the power to the main auxiliary motor in S3 includes the following sub-steps: S31. At the end of the takeover time window, the emergency controller sends a takeover completion confirmation message to the main controller through the inter-controller communication bus; S32. After receiving the takeover completion confirmation message, the main controller executes the power-off of the main auxiliary motor; S33. If the takeover completion confirmation message does not arrive within the preset timeout window, the main controller shall force the main auxiliary motor to be powered off according to the local clock and trigger fault code recording. The preset timeout window is a preset multiple of the length of the takeover time window.
7. The emergency power steering coordinated control method for electric commercial vehicles according to claim 1, characterized in that, In step S2, the main controller acquires the sum of the assist torque of the main assist motor and the assist torque of the emergency assist motor in real time, and calculates the conservation deviation between the sum and the torque conservation constant. When the conservation deviation exceeds a preset conservation tolerance and its duration exceeds a preset tolerance duration threshold, the main controller abandons the torque conservation constraint, and the main controller and the emergency controller jointly execute a hard switchover fallback action. The hard switchover fallback action includes: The main controller immediately switches the assist torque of the main assist motor to zero; The emergency controller enables the emergency power assist motor to directly output a preset minimum assist torque obtained by looking up a table based on vehicle speed and instantaneous steering torque; The main controller triggers fault code recording and driver alarm signals via the inter-controller communication bus.
8. A collaborative control system for emergency power steering in electric commercial vehicles, characterized in that, The method for emergency power steering coordination control of electric commercial vehicles as described in any one of claims 1-7 includes: The main auxiliary motor and the main controller connected to the main auxiliary motor are connected to the high-voltage bus. An emergency booster motor and an emergency controller connected to the emergency booster motor, with the emergency controller connected to a low-voltage power supply; The steering gear has a main power assist motor and an emergency power assist motor coaxially and parallelly coupled to the same input shaft of the steering gear. An inter-controller communication bus is connected between the main controller and the emergency controller and is configured to transmit status messages and torque conservation constants between the main controller and the emergency controller. The main controller is configured to: wake up the emergency controller and enter the current loop ready state via the inter-controller communication bus when a high-voltage bus power failure warning condition is detected; drive the main auxiliary motor to decrease the auxiliary torque according to a monotonically decreasing function within the takeover time window; and execute the power cut-off of the main auxiliary motor after the takeover time window ends. The emergency controller is configured to: drive the assist torque of the emergency assist motor to increase according to a complementary monotonically increasing function during the takeover time window; and allow the emergency assist motor to independently provide steering assistance after the takeover time window ends. The main controller and the emergency controller work together to ensure that the sum of the assist torques of the main assist motor and the emergency assist motor remains at a preset torque conservation constant at any time within the takeover time window.
9. The emergency power steering cooperative control system for electric commercial vehicles according to claim 8, characterized in that, The main controller is further configured to: acquire the instantaneous voltage and voltage drop rate of the high-voltage bus in real time; extrapolate the instantaneous voltage, the voltage drop rate and the preset minimum operating voltage of the main motor to obtain the failure time when the instantaneous voltage of the high-voltage bus drops below the minimum operating voltage of the main motor; and take the difference between the failure time and the start time of the takeover time window, minus a preset safety margin, as the upper limit of the window length of the takeover time window.
Citation Information
Patent Citations
Redundancy circuit of electric power steering system
CN113329931A
Redundant steer-by-wire system fault-tolerant control method based on dynamic torque distribution
CN120039306A