Hybrid-specific engine electronic oil pump failure handling method and apparatus

CN122589515APending Publication Date: 2026-08-18CHONGQING CHANGAN AUTOMOBILE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610963389.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-06-30
Publication Date
2026-08-18

AI Technical Summary

Technical Problem

[0004]本发明的目的之一在于提供混合动力专用发动机电子机油泵的故障处理方法,以解决现有技术中的电子机油泵的故障诊断与后处理逻辑需具备过于粗放,不能针对不同的故障执行不同的保护策略,在满足发动机安全保护的同时兼顾整车的驾驶体验的问题;目的之二在于提供一种混合动力专用发动机电子机油泵的故障处理装置;目的之三在于提供一种电子设备;其目的之四在于提供一种混合动力车辆;其目的之五在于提供一种计算机可读存储介质

Benefits of technology

[0102](1)本发明通过在通讯、温度、电源、堵转、预驱过流、位置速度等各故障均采用多条件复合判定且需连续多个周期或预设时长验证的累积判定策略,克服了单次参数异常即判定故障而无法区分瞬态干扰与真实故障的缺陷,避免了因瞬时波动被误判导致不必要的保护动作,显著提升了各类故障诊断的准确性与鲁棒性。;

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122589515A_ABST
    Figure CN122589515A_ABST
Patent Text Reader

Abstract

The present application relates to a kind of hybrid special-purpose engine electronic oil pump fault processing method and device, the method comprises: in the operation of electronic oil pump, obtain the multiple parameter monitoring data related to electronic oil pump;According to multiple parameter monitoring data and the preset fault judgment strategy, determine the fault of electronic oil pump occurs;According to the preset protection strategy of different fault of electronic oil pump, corresponding protection action and post-failure processing measures are executed to fault.The present application improves the accuracy of electronic oil pump fault diagnosis and driving safety by fault judgment strategy and differential protection strategy and post-failure processing measures.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of hybrid vehicle technology, and specifically to a fault handling method and apparatus for an electronic oil pump for a hybrid engine. Background Technology

[0002] With the rapid development of new energy vehicle technology, hybrid vehicles are widely used due to their advantages in balancing fuel economy and power performance. In hybrid engines, the electronic oil pump, as a core component of the lubrication system, directly affects the engine's reliability and lifespan. Driven by an electric motor, the electronic oil pump provides precise oil pressure and flow to the engine, ensuring good lubrication even under complex operating conditions. However, the electronic oil pump operates in a complex environment, needing to cope with various potential failure modes such as power fluctuations, motor stall, sensor failure, and communication interruptions. If the electronic oil pump malfunctions and is not addressed promptly, it may lead to insufficient engine lubrication, component wear, or even serious damage, threatening the safety of the entire vehicle.

[0003] In the existing technology, the fault diagnosis and post-processing logic for electronic oil pumps is too coarse and cannot implement different protection strategies for different faults, making it difficult to meet engine safety protection requirements while also taking into account the overall driving experience of the vehicle. Summary of the Invention

[0004] One objective of this invention is to provide a fault handling method for an electronic oil pump in a hybrid powertrain engine, thereby addressing the problem that the fault diagnosis and post-processing logic of existing electronic oil pumps is too coarse and cannot implement different protection strategies for different faults, thus failing to meet engine safety protection requirements while also considering the overall driving experience of the vehicle. A second objective is to provide a fault handling device for an electronic oil pump in a hybrid powertrain engine. A third objective is to provide an electronic device. A fourth objective is to provide a hybrid powertrain vehicle. A fifth objective is to provide a computer-readable storage medium.

[0005] To achieve the above objectives, the technical solution adopted by the present invention is as follows:

[0006] A troubleshooting method for an electronic oil pump in a hybrid powertrain engine includes:

[0007] During the operation of the electronic oil pump, acquire multi-parameter monitoring data related to the electronic oil pump;

[0008] Based on multi-parameter monitoring data and preset fault diagnosis strategies, the fault in the electronic oil pump is determined.

[0009] Based on the preset protection strategies for different faults of the electronic oil pump, corresponding protection actions and post-fault handling measures are executed for the faults.

[0010] Based on the aforementioned technical means, multi-parameter monitoring data during the operation of the electronic oil pump is acquired and combined with fault diagnosis strategies for fault identification. This overcomes the shortcomings of existing technologies that rely solely on a single parameter or use a crude diagnostic approach, leading to inaccurate fault type determination and the equivalent treatment of different faults. By matching corresponding protection strategies to different faults and executing differentiated protection actions and post-processing measures, the risks of over-protection during minor faults due to a one-size-fits-all protection strategy, resulting in a sharp drop in driving experience, or insufficient protection during serious faults, leading to engine lubrication failure and component damage, are avoided. By combining fault diagnosis accuracy with a graded protection strategy, the pertinence and timeliness of electronic oil pump fault handling are improved, achieving a balance in maintaining the overall vehicle driving experience to the greatest extent possible while ensuring engine lubrication safety.

[0011] Furthermore, the fault diagnosis strategy includes at least one of the following:

[0012] Power supply fault diagnosis strategy;

[0013] Temperature fault diagnosis strategy;

[0014] Communication failure detection strategy;

[0015] Motor fault diagnosis strategy;

[0016] The motor operation fault determination strategy includes at least one of the following: stall fault determination strategy, pre-drive or overcurrent fault determination strategy, position sensor fault determination strategy, motor reverse fault determination strategy, motor overspeed fault determination strategy, and excessive speed deviation fault determination strategy.

[0017] Based on the aforementioned technical means, by setting up a multi-dimensional fault judgment strategy covering power supply, temperature, communication, motor, and motor operation faults, and further subdividing motor operation faults into at least six sub-judgment strategies such as stall, pre-drive or overcurrent, position sensor fault, motor reverse rotation, motor overspeed, and excessive speed deviation, the shortcomings of existing technologies in fault diagnosis logic being singular, incomplete in coverage, and unable to accurately distinguish different fault modes are overcome. This avoids the risk of mismatch or missed judgment of protection strategies due to inaccurate identification of fault types. By refining the granularity of fault judgment to specific sub-types and corresponding them one-to-one with differentiated protection strategies, the comprehensiveness and accuracy of fault diagnosis are improved, ensuring engine lubrication safety while minimizing undue impact on the overall vehicle driving experience.

[0018] Furthermore, the fault is a stall fault; according to the preset protection strategy for different faults of the electronic oil pump, the corresponding protection actions and post-fault handling measures are executed, including:

[0019] The electronic oil pump is stopped, and its forward and reverse rotation is repeated once to determine if it is stuck.

[0020] If the electronic oil pump is determined to still have a stall fault, the stall fault is reported to the EMS, the output of the electronic oil pump is cut off, and after the first preset time, the electronic oil pump is controlled to perform a self-diagnosis process to determine whether the fault is cleared or upgraded to a permanent fault.

[0021] If the stall fault escalates into a permanent fault and the vehicle is not powered on or off again, report to EMS that the engine should not be started.

[0022] If the stall fault is cleared, the self-diagnostic process will exit.

[0023] Based on the aforementioned technical means, a secondary verification mechanism is implemented by stopping operation and reversing the engine once after detecting a stall. This overcomes the shortcomings of existing technologies that rely solely on a single monitoring to determine a stall and cannot distinguish between temporary and permanent stalls. After confirming that the stall still exists, the system first reports to the EMS and cuts off the output. Then, after a first preset time, a self-diagnosis is initiated to determine whether the fault has been cleared or upgraded to a permanent fault. This avoids the risks of overprotecting the engine by misjudging a temporary stall as a permanent fault, resulting in unnecessary engine start-stop, or underprotecting the engine by misjudging a permanent stall as a temporary fault, leading to insufficient lubrication and operation. Furthermore, through a closed-loop design that additionally reports and prohibits starting when there is a permanent fault and no power is restored, and automatically resumes normal operation after the fault is cleared, an effective balance is achieved between automatic recovery from temporary stalls and strict protection against permanent stalls. This minimizes the loss of driving experience caused by misjudgments while ensuring lubrication safety.

[0024] Furthermore, the self-diagnostic process of the electronic oil pump includes:

[0025] Perform a reverse test for a second preset duration at a first preset speed, and after stopping for a third preset duration, perform a forward test for a second preset duration at the first preset speed, and after stopping for a third preset duration, check whether the electronic oil pump triggers a shutdown fault again;

[0026] After the electronic oil pump triggered a shutdown fault again, an attempt was made to restart it;

[0027] If the number of startup failures exceeds the first preset number, the electronic oil pump self-diagnosis process will be entered again after the first preset time, and the number of failures will be accumulated once. When the number of failures reaches the second preset number, the stall fault will be upgraded to a permanent fault.

[0028] If the number of failed starts is less than the first preset number and the start attempt is successful, or if the electronic oil pump does not trigger the shutdown fault again, then the fault is cleared.

[0029] Based on the aforementioned technical means, a self-diagnostic process including reverse rotation test, forward rotation test, and multiple start attempts is established. The comparison of the number of failed starts with a preset number and the accumulation of faults reaching a threshold are used as the criteria for determining permanent faults. This overcomes the shortcomings of existing technologies that rely solely on a single test to determine whether a fault is cleared or permanent. By first performing alternating forward and reverse rotation to simulate actual working conditions and detect whether a shutdown is triggered again, and then performing multiple start attempts for each triggered shutdown, differentiating between successful and failed paths, this avoids situations where a single successful start results in the fault being cleared, overlooking intermittent jamming risks, or where a single failed start results in a permanent fault, directly escalating recoverable temporary stalls to a complete ban on starting. By introducing a fault accumulation mechanism, a permanent fault is only escalated after multiple self-diagnostic cycles have consistently identified the fault as stalled, improving the rigor and fault tolerance of the determination. This gives the self-diagnostic system both self-repair verification and fault escalation confirmation functions, ensuring that permanent stalls are strictly blocked while maximizing the opportunity for automatic recovery from temporary faults, thus balancing lubrication safety protection and overall vehicle availability.

[0030] Furthermore, the fault is either a pre-drive fault or an overcurrent fault; based on the preset protection strategies for different faults of the electronic oil pump, corresponding protection actions and post-fault handling measures are executed, including:

[0031] The controller hardware stops outputting;

[0032] Control the motor to stop rotating, and then control the motor to try rotating again at the currently requested speed;

[0033] If the number of times the motor fails to rotate reaches the third preset number, a pre-drive or overcurrent fault will be reported to the EMS, and after the fourth preset time, the electronic oil pump will be controlled to perform a self-diagnosis process to determine whether the fault is cleared or upgraded to a permanent fault.

[0034] If a pre-drive or overcurrent fault escalates to a permanent fault and the vehicle is not powered on or off again, report to EMS to stop the engine and prevent it from starting.

[0035] If the pre-drive or overcurrent fault is cleared, the self-diagnostic process will exit.

[0036] Based on the aforementioned technical means, a multi-level verification mechanism is established whereby, upon detecting a pre-drive or overcurrent fault, the controller hardware first stops output and controls the motor to re-attempt rotation at the currently requested speed. Furthermore, a fault is reported and self-diagnosis is initiated only when the number of failed attempts reaches the third preset number. This overcomes the shortcomings of existing technologies that directly execute shutdown protection without distinguishing between transient overcurrent and permanent pre-drive faults. By differentiating between fault clearing and escalation to permanent faults after self-diagnosis, the risk of transient current fluctuations being misjudged as permanent faults, leading to unnecessary engine shutdown, or the failure to promptly intercept genuine permanent pre-drive faults, resulting in motor winding burnout, is avoided. By combining re-attempt rotation with the accumulation of failure counts and introducing self-diagnosis closed-loop verification, the accuracy of fault diagnosis and the specificity of protection strategies are improved. This achieves a balance between automatic recovery from temporary overcurrents and strict isolation of permanent faults, ensuring lubrication safety while maximizing vehicle availability and driving continuity.

[0037] Furthermore, the self-diagnostic process of the electronic oil pump includes:

[0038] After the electronic oil pump is controlled to run at the second preset speed for a fifth preset time, it stops for a sixth preset time, and the system checks whether the electronic oil pump triggers a shutdown fault again during the operation.

[0039] After the electronic oil pump triggered a shutdown fault again, an attempt was made to restart it;

[0040] If the number of startup failures exceeds the fourth preset number, the electronic oil pump will re-enter the self-diagnosis process after the seventh preset time, and the number of failures will be accumulated once. When the number of failures reaches the fifth preset number, the pre-drive failure will be upgraded to a permanent failure.

[0041] If the number of failed startup attempts is less than the fourth preset number and the startup attempt is successful, or if the electronic oil pump does not trigger a shutdown fault again during operation, then the fault is confirmed to be cleared.

[0042] Based on the aforementioned technical means, by setting a self-diagnostic process that runs at a second preset speed and detects whether a shutdown fault is triggered again, combined with a permanent fault determination mechanism that accumulates the number of start-up failures and involves multiple self-diagnostic cycles, the shortcomings of existing technologies that determine whether a fault is cleared or permanent after a single self-diagnosis and cannot distinguish between transient overcurrent and permanent pre-drive faults are overcome. By first simulating the working condition at a specific speed for verification and then using whether the number of start-up failures exceeds a threshold as the determination criterion, the risk of transient overcurrent being mistakenly judged as a permanent fault and triggering excessive protection that prohibits starting is avoided, or the risk of a genuine permanent pre-drive fault being missed due to a single self-diagnosis not being triggered, leading to motor burnout, is avoided. The design that requires multiple self-diagnoses to be abnormal before being upgraded to a permanent fault through fault accumulation improves the rigor and fault tolerance of pre-drive or overcurrent fault determination. While strictly intercepting permanent faults, it provides the greatest possible opportunity for automatic recovery of temporary anomalies, taking into account both motor safety and the continuity of vehicle driving.

[0043] Furthermore, the fault is any one of the following: position sensor fault, motor reverse rotation fault, or motor overspeed fault; according to the preset protection strategy for different faults of the electronic oil pump, corresponding protection actions and post-fault handling measures are executed for the fault, including:

[0044] Control the electronic oil pump to stop running, and then control the electronic oil pump to attempt to restart it again according to the current request;

[0045] If the number of failed restart attempts reaches the sixth preset number, a fault is reported to EMS to stop the engine and prevent starting, and the fault count is accumulated once. When the number of faults reaches the seventh preset number, the pre-drive fault is determined to be upgraded to a permanent fault.

[0046] If the restart attempt is successful or the number of failures is less than the sixth preset number and normal operation is restored, then the fault is confirmed to be cleared.

[0047] Based on the aforementioned technical means, a multi-level verification mechanism is implemented. Upon detecting a position sensor malfunction, motor reversal, or overspeed fault, operation is stopped and a restart attempt is made upon the current request. A fault is only reported and the count accumulated after the sixth preset number of failed restarts, and only after the seventh preset number of failed restarts is it upgraded to a permanent fault. This overcomes the shortcomings of existing technologies that directly shut down the system for such faults, failing to distinguish between transient anomalies and permanent faults. By employing a differentiated processing path—determining fault clearance upon successful restart or failure before reaching a threshold, and then reporting in stages after reaching the threshold—the risk of transient anomalies such as sensor signal jitter being mistakenly identified as permanent faults, leading to unnecessary engine restart restrictions, or permanent faults such as motor reversal and overspeed not being promptly intercepted, resulting in oil pump damage or even engine cylinder scoring, is avoided. This closed-loop verification combining restart attempts and failure count accumulation improves the accuracy of fault diagnosis and the targeted nature of protection strategies, achieving a balance between automatic recovery from transient anomalies and strict isolation of permanent faults. This ensures lubrication safety while maximizing vehicle availability and driving continuity.

[0048] Furthermore, the fault is a communication failure; based on the preset protection strategies for different faults of the electronic oil pump, corresponding protection actions and post-fault handling measures are executed, including:

[0049] The electronic oil pump is controlled to run at the maximum permissible speed for a first preset number of message cycles, and then the machine is stopped after all message cycles are completed. The communication fault is then checked again to see if it has been eliminated and communication has been restored.

[0050] If the communication failure is cleared and communication is restored, the electronic oil pump will resume operation, and the engine will resume operation.

[0051] If the communication failure is not cleared or communication is not restored, the system will report to the EMS to control the engine to stop and prevent it from starting.

[0052] Based on the aforementioned technical means, by first controlling the electronic oil pump to run at the highest permissible speed for a first preset number of message cycles after a communication failure, and then detecting whether communication has been restored, the shortcomings of the prior art in which direct shutdown protection due to communication failure leads to engine lubrication interruption are overcome. The tiered processing of restoring oil pump and engine operation upon communication restoration, and reporting a prohibition on starting only if communication has not been restored, avoids the risk of the engine being unnecessarily prohibited from starting due to momentary communication interference being mistaken for a permanent fault, or the risk of engine lubrication loss due to the oil pump having stopped before communication is restored. By running at the highest speed to ensure that lubrication is not interrupted during communication interruption, the rationality of communication failure handling and engine operation safety are improved.

[0053] Furthermore, communication failures include any one of the following: CAN bus off failure, CRC check failure, RollingCnt failure, and node loss failure.

[0054] Communication failure detection strategies include:

[0055] After power-on, communication fault detection is initiated after the eighth preset time. If continuous recovery fails according to the preset recovery cycle, and the number of failures reaches the eighth preset number, a CAN bus off fault is determined.

[0056] If a CRC check error occurs in the received CAN bus communication data for a second preset number of consecutive message cycles, a CRC check failure is determined to have occurred.

[0057] If the received CAN bus communication data shows a RollingCnt value error for the third consecutive preset number of message cycles, then a RollingCnt fault is confirmed.

[0058] In hardware wake-up mode, if a message with a preset ID is not received for the fourth preset number of message cycles, a node loss fault is determined to have occurred.

[0059] Based on the aforementioned technical methods, by setting consecutive message cycles as the judgment threshold for four types of communication faults—CAN bus off, CRC check, RollingCnt, and node loss—and delaying the detection after power-on, the shortcomings of existing technologies that determine faults based on a single communication anomaly and cannot distinguish between transient interference and genuine faults are overcome. The cumulative judgment mechanism, which confirms faults only after multiple consecutive failures, avoids the risk of unnecessary engine start-up being unnecessarily prevented due to transient bus fluctuations, occasional CRC errors, or brief node timeouts being mistakenly judged as communication faults, or the risk of uncontrolled oil pump operation due to the failure to promptly identify genuine bus off or node loss. By using power-on delay detection to avoid the communication instability period during initialization, the accuracy and robustness of the judgment are improved, ensuring controllable operation of the oil pump while minimizing the impact of false alarms on the overall vehicle availability.

[0060] Furthermore, the temperature fault determination strategy includes:

[0061] If the temperature value collected by the temperature sensor is greater than the first preset temperature or less than the second preset temperature for a period of time that exceeds the ninth preset duration, then the temperature sensor is determined to be faulty.

[0062] If the temperature sensor is not malfunctioning, and the collected temperature value is greater than the third preset temperature for a duration exceeding the tenth preset duration, then an over-temperature frequency reduction fault is determined to have occurred.

[0063] If the collected temperature value exceeds the fourth preset temperature and the duration exceeds the eleventh preset duration, an over-temperature shutdown fault is determined to have occurred.

[0064] Among them, the first preset temperature is greater than the fourth preset temperature, the fourth preset temperature is greater than the third preset temperature, and the third preset temperature is greater than the second preset temperature.

[0065] Based on the aforementioned technical means, by setting the duration of sustained temperature exceedance as a sensor fault determination condition, and by implementing a dual protection strategy of over-temperature frequency reduction and over-temperature shutdown based on the actual temperature value after sensor failure, this overcomes the shortcomings of existing technologies that determine faults based solely on a single temperature exceedance and cannot distinguish between sensor failure and actual over-temperature. Through the progressive threshold formed by the first to fourth preset temperatures and the continuous determination mechanism of the ninth to eleventh preset durations, the risks of instantaneous temperature fluctuations being misjudged as sensor failures, leading to unnecessary frequency reduction or shutdown of the oil pump, or the inability to sense the actual temperature after sensor failure, resulting in motor over-temperature burnout, are avoided. The hierarchical protection design, which separates sensor fault and over-temperature fault determination and prioritizes frequency reduction over shutdown, improves the accuracy of temperature fault diagnosis and the hierarchy of protection strategies, ensuring motor thermal safety while maximizing vehicle availability.

[0066] Furthermore, based on the preset protection strategies for different faults of the electronic oil pump, corresponding protection actions and post-fault handling measures are executed for the faults, including:

[0067] After confirming a temperature sensor malfunction, the electronic oil pump speed is controlled to be limited to below the third preset speed, and the EMS is notified to limit the engine speed to below the fourth preset speed, which is less than the third preset speed.

[0068] After confirming the overheating and frequency reduction fault, the control electronic oil pump limits the maximum speed to below the third preset speed, and restores the motor speed after the collected temperature value drops to the fifth preset temperature value. The fifth preset temperature value is less than the third preset temperature value and greater than the second preset temperature value.

[0069] After confirming an overheating shutdown fault, the electronic oil pump is stopped, and the EMS is notified to stop the engine and prevent it from starting.

[0070] Based on the above technical means, a three-level differentiated protection strategy of temperature sensor failure, over-temperature frequency reduction, and over-temperature shutdown is adopted to overcome the shortcomings of the single and crude temperature fault protection strategy in the existing technology. By designing frequency reduction before shutdown and protection based on actual temperature after sensor failure, the risk of motor burnout due to sensor failure or unnecessary engine start-prevention caused by a one-size-fits-all shutdown when over-temperature occurs is avoided. The combination of speed limiting and automatic recovery mechanism when temperature reaches the target improves the accuracy of temperature fault handling.

[0071] Furthermore, the power supply fault diagnosis strategy includes:

[0072] If the power supply voltage of the electronic oil pump is greater than the first voltage threshold and the duration exceeds the twelfth preset duration, then a power supply overvoltage fault is determined.

[0073] If the power supply voltage of the electronic oil pump is less than the second voltage threshold and the duration exceeds the twelfth preset duration, then a power undervoltage fault is determined.

[0074] The second voltage threshold is less than the first voltage threshold.

[0075] Based on the aforementioned technical means, a strategy is adopted to determine overvoltage or undervoltage faults only when the supply voltage exceeds a first voltage threshold or falls below a second voltage threshold for a continuous period exceeding a twelfth preset duration. Furthermore, the second threshold is lower than the first threshold to define the normal voltage range. This overcomes the shortcomings of existing technologies that determine power supply faults based on a single voltage fluctuation, failing to distinguish between transient interference and genuine power supply anomalies. The cumulative judgment mechanism based on duration verification avoids the risk of transient overvoltage or undervoltage caused by voltage fluctuations or load changes during vehicle start-up and shutdown being mistakenly judged as power supply faults and triggering unnecessary shutdown protection, or of genuine power supply overvoltage or undervoltage being missed due to insufficient duration, leading to motor burnout. The dual-threshold tiered judgment of overvoltage and undervoltage improves the accuracy of power supply fault diagnosis and the specificity of protection strategies, ensuring motor power supply safety while minimizing the impact of false alarms on vehicle availability.

[0076] Furthermore, based on the preset protection strategies for different faults of the electronic oil pump, corresponding protection actions and post-fault handling measures are executed for the faults, including:

[0077] If a power overvoltage fault is detected, it is reported to the EMS and the motor is controlled to continue running according to the current request; after the power supply voltage of the electronic oil pump drops to the third voltage threshold and remains there for a thirteenth preset time, the power overvoltage fault is cleared, and the third voltage threshold is greater than the second voltage threshold and less than the first voltage threshold.

[0078] If a power supply undervoltage fault is detected, it is reported to the EMS and the motor is controlled to continue running according to the current request; after the power supply voltage of the electronic oil pump rises to the fourth voltage threshold and continues for the fourteenth preset time, the power supply overvoltage fault is cleared, and the fourth voltage threshold is greater than the second voltage threshold and less than the third voltage threshold.

[0079] Based on the aforementioned technical means, the strategy of maintaining operation after determining overvoltage or undervoltage faults and clearing the fault only when the voltage returns to the normal range and continuously meets the standard overcomes the shortcomings of existing technologies that shut down immediately upon power abnormality and cannot distinguish between instantaneous fluctuations and real faults. By reporting but not shutting down and setting graded clearing thresholds, the risk of unnecessary shutdown of the oil pump due to instantaneous voltage fluctuations or motor damage due to continuous power abnormalities not being intercepted is avoided. The closed-loop mechanism of maintaining operation during the fault and automatically restoring when the voltage meets the standard improves the accuracy of power fault handling.

[0080] Furthermore, the stall fault determination strategy includes:

[0081] If, during motor operation, the motor speed is lower than the preset minimum speed and the combined current of the motor is greater than the first current threshold for more than eight preset control cycles, then a stall fault is determined to have occurred.

[0082] Based on the aforementioned technical means, by setting a dual-condition cumulative judgment strategy where the motor speed is lower than the preset minimum speed and the combined current is greater than the first current threshold and continues for more than the eighth preset number of control cycles, the shortcomings of the existing technology, which judges stall based on a single low speed or instantaneous high current and cannot distinguish between normal high current during startup and true stall, are overcome. Through the cumulative judgment mechanism that simultaneously meets both conditions and requires verification over multiple consecutive control cycles, the risk of unnecessary shutdown protection caused by misjudging the motor as stall during startup or brief lag, or the risk of winding burnout due to failure to reach the required continuous judgment for true stall, is avoided. Through the composite judgment of dual constraints of speed and current, the accuracy of stall fault diagnosis and the pertinence of protection strategies are improved.

[0083] Further, the pre-drive or overcurrent fault determination strategy includes:

[0084] If the highest preset bit of the pre-drive status register is abnormal, or the chip voltage is higher than the fifth voltage threshold, or the chip voltage is lower than the sixth voltage threshold, the hardware output is turned off, and if the duration of the abnormality detected in the pre-drive status register exceeds the fifteenth preset duration, a pre-drive fault is determined to have occurred.

[0085] If the duration of the motor winding phase current being greater than the second current threshold exceeds the sixteenth preset duration, or if the hardware overcurrent comparator output is valid, or if there is an abnormality in the six MOSFET overcurrent detection bits of the pre-drive status register, then an overcurrent fault is confirmed to have occurred.

[0086] Based on the above technical means, a pre-drive fault is confirmed only when the pre-drive register is abnormal or the chip voltage exceeds the limit (i.e., hardware shutdown and continuous exceeding of the threshold). Overcurrent is determined by multiple conditions triggered by continuous current exceeding the limit, hardware comparator, or MOSFET detection bit. This overcomes the shortcomings of existing technologies that determine faults based on a single condition and cannot distinguish between transient abnormalities and real faults. Through a hierarchical mechanism that combines immediate hardware shutdown with delayed software confirmation, the risk of transient register abnormalities or current fluctuations being misjudged as permanent faults, leading to unnecessary shutdowns, or the risk of motor burnout due to failure to intercept real pre-drive damage or overcurrent in time is avoided. Multi-dimensional cross-verification improves the accuracy of fault diagnosis and the timeliness of protection response.

[0087] Furthermore, the position sensor fault determination strategy includes: if the position sensor signal collected for the ninth preset number of consecutive detections is outside the preset allowable range, and the number of failed restart attempts reaches the tenth preset number, then a position sensor fault is determined to have occurred.

[0088] The motor reversal fault determination strategy includes: if the motor's requested speed is greater than the fifth preset speed and the actual speed is less than the sixth preset speed, and the duration exceeds the seventeenth preset duration, then a motor reversal fault is determined to have occurred; wherein, the fifth preset speed is greater than the sixth preset speed, and the sixth preset speed is a negative value of the fifth preset speed;

[0089] The motor overspeed fault determination strategy includes: if the detected motor speed feedback value is greater than the seventh preset speed and the duration exceeds the eighteenth preset duration, then a motor overspeed fault is determined to have occurred.

[0090] The fault determination strategy for excessive speed deviation includes: if the difference between the motor speed command value and the speed feedback value is greater than the eighth preset speed and the duration exceeds the nineteenth preset duration, then an excessive speed deviation fault is determined to have occurred.

[0091] Based on the above technical means, a multi-condition cumulative judgment strategy is adopted, which uses continuous over-limit superposition of position sensor restart failure, bidirectional speed constraint of motor reversal, and verification of overspeed and speed deviation for a continuous duration. This overcomes the shortcomings of judging faults based on a single abnormal signal and failing to distinguish between vibration, start-up transient and real faults. The multi-condition composite judgment avoids the risk of unnecessary engine start-up shutdown due to sensor vibration or startup phase misjudgment, or damage to the oil pump due to failure to identify real reverse overspeed. By judging the differentiated threshold and duration of each fault, the accuracy of position and speed fault diagnosis and the protection targeting are improved.

[0092] A fault handling device for an electronic oil pump for a hybrid powertrain engine includes:

[0093] The acquisition module is used to acquire multi-parameter monitoring data related to the electronic oil pump during operation.

[0094] The first processing module is used to determine the fault of the electronic oil pump based on multi-parameter monitoring data and preset fault determination strategies.

[0095] The second processing module is used to perform corresponding protection actions and post-fault handling measures for different faults of the preset electronic oil pump.

[0096] An electronic device includes: a memory, a processor, and an interface;

[0097] The memory stores the instructions that the computer executes;

[0098] The processor executes computer execution instructions stored in memory, causing the processor to perform any of the methods described above.

[0099] A hybrid vehicle includes: a hybrid engine equipped with an electronic oil pump and the aforementioned electronic equipment.

[0100] A computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the method as described above.

[0101] The beneficial effects of this invention are:

[0102] (1) This invention overcomes the shortcomings of previous methods that judged faults based on a single parameter anomaly without distinguishing between transient interference and real faults by employing a cumulative judgment strategy that uses multiple conditions for composite judgment and requires verification over multiple consecutive cycles or a preset time period for each fault, such as communication, temperature, power supply, stall, pre-drive overcurrent, and position speed. This avoids unnecessary protection actions caused by misjudgment due to transient fluctuations and significantly improves the accuracy and robustness of various fault diagnosis methods.

[0103] (2) This invention avoids unnecessary engine shutdown due to occasional abnormalities by implementing shutdown or prohibition of start-up through differentiated strategies such as automatic recovery of frequency reduction in temperature fault grade protection, continued operation during power failure instead of direct shutdown, and communication fault delay detection to avoid the initial unstable period. This invention maintains the continuity of vehicle operation and driving availability to the greatest extent while ensuring the safety of motor and oil pump.

[0104] (3) This invention uses hardware comparator and register abnormality in pre-drive overcurrent faults to directly trigger hardware shutdown as the first line of defense, and sets clear speed and current thresholds for fast response in stall and overspeed faults. This overcomes the defects of pure software judgment delay leading to power device damage, avoids irreversible damage such as MOSFET burnout or motor reverse cylinder scoring caused by judgment lag, and improves the real-time performance and reliability of power stage protection. Attached Figure Description

[0105] Figure 1 A flowchart illustrating a fault handling method for an electronic oil pump for a hybrid power engine provided in this application embodiment;

[0106] Figure 2 A schematic diagram illustrating the stall failure handling process provided in the embodiments of this application;

[0107] Figure 3 A schematic diagram illustrating the pre-drive or overcurrent fault handling process provided in the embodiments of this application;

[0108] Figure 4 A schematic diagram illustrating the communication failure handling process provided in an embodiment of this application;

[0109] Figure 5 A schematic diagram illustrating the processing flow of position sensor failure, reverse rotation failure, and overspeed failure provided in the embodiments of this application;

[0110] Figure 6 A simplified flowchart illustrating the fault diagnosis and post-processing logic of the electronic oil pump provided in this application embodiment;

[0111] Figure 7 A schematic diagram of the fault handling device for the electronic oil pump of a hybrid power engine provided in this application embodiment;

[0112] Figure 8 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application.

[0113] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation

[0114] The embodiments of the present invention will be described below with reference to the accompanying drawings and preferred embodiments. Those skilled in the art can easily understand other advantages and effects of the present invention from the content disclosed in this specification. The present invention can also be implemented or applied through other different specific embodiments, and various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present invention. It should be understood that the preferred embodiments are only for illustrating the present invention and not for limiting the scope of protection of the present invention.

[0115] It should be noted that the illustrations provided in the following embodiments are only schematic representations of the basic concept of the present invention. Therefore, the drawings only show the components related to the present invention and are not drawn according to the actual number, shape and size of the components in the actual implementation. In the actual implementation, the form, quantity and proportion of each component can be arbitrarily changed, and the layout of the components may also be more complex.

[0116] The terms "first," "second," "third," etc., used in the specification, claims, and accompanying drawings of this application are used to distinguish similar or related objects or entities, and do not necessarily imply a specific order or sequence, unless otherwise specified. It should be understood that such terms are interchangeable where appropriate.

[0117] The terms “comprising” and “having”, and any variations thereof, are intended to cover but not exclusively include, for example, a product or device that includes a series of components is not necessarily limited to all of the components that are clearly listed, but may include other components that are not clearly listed or that are inherent to such product or device.

[0118] The term "module" refers to any known or subsequently developed hardware, software, firmware, artificial intelligence, fuzzy logic, or combination of hardware and / or software code that is capable of performing the functions associated with that element.

[0119] First, let me explain the terms used in this application:

[0120] The Engine Management System (EMS) is the core electronic control unit of a vehicle's powertrain. It is responsible for collecting real-time data from various engine sensors (such as speed, temperature, pressure, and current) and executing strategies such as fuel injection, ignition timing, intake control, and fault diagnosis and protection based on this data. It also works in conjunction with systems such as the transmission and battery management system to ensure that the engine operates efficiently within a safe range and to perform protective actions such as frequency reduction and engine shutdown in case of abnormalities.

[0121] An electric oil pump (EOP) is a core component of an engine lubrication system driven by an electric motor. Unlike traditional oil pumps that are mechanically driven by the engine crankshaft, EOP uses an electronic control unit to adjust the speed and flow rate in real time according to engine operating conditions. It can actively build up oil pressure in scenarios where traditional oil pumps cannot supply enough oil, such as engine start-stop, low speed and low load. This ensures that all friction pairs of the engine receive sufficient lubrication and cooling under all operating conditions. It also has the advantages of supplying oil on demand and reducing parasitic losses to improve fuel economy. It is a key actuator for modern engine thermal management and energy-saving control.

[0122] This application pertains to the field of lubrication control for hybrid vehicle engines, specifically addressing the troubleshooting of electronic oil pump failures in hybrid-specific engines. Electronic oil pumps typically work in conjunction with engine management systems and related detection units to maintain stable lubrication pressure and flow under conditions of frequent engine start-stop cycles, variable loads, and high-temperature operation.

[0123] An electric oil pump, driven by an electric motor, provides precise oil pressure and flow to the engine, ensuring good lubrication even under complex operating conditions. However, the electric oil pump operates in a complex environment, needing to cope with various potential failure modes such as power fluctuations, motor stalling, sensor failure, and communication interruptions. If the electric oil pump malfunctions and is not addressed promptly, it can lead to insufficient engine lubrication, component wear, or even serious damage, threatening the safety of the entire vehicle.

[0124] In related technologies, the fault diagnosis and post-processing logic for electronic oil pumps is too crude, and cannot implement different protection strategies for different faults, making it difficult to meet engine safety protection requirements while also taking into account the overall driving experience of the vehicle.

[0125] Based on this, this application provides a fault handling method for an electronic oil pump of a hybrid power engine. By acquiring multi-parameter monitoring data related to the electronic oil pump during its operation and introducing a collaborative diagnostic mechanism for fault judgment strategies, this method overcomes the limitations of existing technologies that rely solely on single parameters or discrete signals for fault judgment. It effectively avoids false alarms and unexpected torque limiting or shutdown risks caused by instantaneous interference. Furthermore, by matching differentiated protection actions and post-processing logic to different fault types, it achieves graded responses from minor warnings to severe shutdowns, significantly improving the accuracy of electronic oil pump fault diagnosis, the reliability of engine lubrication protection, and the vehicle's drivability and driving safety under fault conditions.

[0126] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will now be described with reference to the accompanying drawings.

[0127] Please see Figure 1 , Figure 1 A flowchart illustrating a fault handling method for an electronic oil pump in a hybrid power engine, as provided in this application embodiment, is shown below. Figure 1 As shown, the fault handling method for the electric oil pump of this hybrid-specific engine includes at least steps S101 to S103, which are described in detail below:

[0128] Step S101: During the operation of the electronic oil pump, acquire multi-parameter monitoring data related to the electronic oil pump.

[0129] For example, the operating status of the electronic oil pump, as the monitored and processed object, directly corresponds to the basis for subsequent fault determination and protection control. Multi-parameter monitoring data serves as the input for fault determination, no longer limited to a single parameter but covering multiple types of operating information related to the electronic oil pump's operating status. Specifically, the data acquisition process can collect and organize different parameters according to a preset sampling period, and combine parameters within the same determination window into a set of multi-parameter monitoring data for subsequent decision-making strategies.

[0130] Optionally, when any parameter is abnormal or the sampling result is invalid, the corresponding abnormal state can be included in the multi-parameter monitoring data.

[0131] Step S102: Based on multi-parameter monitoring data and a preset fault judgment strategy, determine the fault that occurred in the electronic oil pump.

[0132] For example, the fault sent by the electronic oil pump can be determined based on the collected multi-parameter detection data and the pre-set fault determination strategy. The pre-set fault determination strategy is used to identify the type of fault occurring in the electronic oil pump based on the multi-parameter monitoring data. Its implementation does not involve simply judging each parameter independently and then concatenating them; instead, a set of judgment rules corresponding to fault identification is pre-established within the controller, and the collected data is analyzed according to preset conditions.

[0133] Optionally, in some feasible embodiments, fault determination may include processing methods such as threshold judgment, state integration, time window accumulation, state detection, and condition verification. Threshold judgment is used to identify whether a parameter has entered an abnormal range, state integration is used to count the number of consecutive occurrences or the cumulative duration of anomalies, time window accumulation is used to filter single spike disturbances, and state detection and condition verification are used to combine multi-parameter information to determine the fault state.

[0134] Step S103: Based on the preset protection strategies for different faults of the electronic oil pump, execute the corresponding protection actions and post-fault handling measures for the fault.

[0135] For example, based on the preset protection strategies corresponding to different fault types of the electronic oil pump, after determining the fault type and fault level, the corresponding protection actions and post-fault handling measures can be executed. The protection actions include, but are not limited to, one or more of the following: hardware shutdown output, speed frequency reduction limit, and forced shutdown command. The post-fault handling measures include, but are not limited to, reporting fault information to the engine management system to trigger engine torque limiting or shutdown, recording fault codes and storing fault snapshot data for subsequent diagnosis, and automatically attempting to resume operation after the fault is cleared or requiring manual confirmation before resuming operation.

[0136] Optionally, preset protection strategies for different faults of the electronic oil pump are used to perform differentiated control for the identified fault types. Protection actions are used to take safety control measures for the electronic oil pump or engine after a fault is detected. Post-fault handling measures are used to further determine whether the fault status is cleared and whether operation is restored after the protection actions are executed.

[0137] Specifically, after determining the fault result, corresponding control actions and post-processing measures are executed according to the protection strategy corresponding to the fault. Protection actions may include shutdown, speed limit, derated, maintain operation, alarm or other safety control methods. Fault post-processing measures may include fault state maintenance, fault clearing determination, operation recovery determination or fault information output, etc. In some feasible embodiments, fault post-processing may also include fault information encapsulation, fault level reporting and linkage control with the engine management system.

[0138] It should be understood that the above examples are for demonstration purposes only and are not limiting. Protection strategies, protection actions, and post-fault handling measures can be adapted to different fault types, as long as they can achieve the execution of corresponding protection actions and post-fault handling measures for the fault.

[0139] In the embodiments provided in this application, by matching and determining multi-parameter monitoring data with fault judgment strategies and implementing differentiated protection strategies, the shortcomings of single-parameter monitoring in not being able to fully identify complex faults are overcome, avoiding the risk of motor damage or engine lubrication failure due to fault misjudgment or omission, and improving the accuracy of electronic oil pump fault diagnosis and driving safety.

[0140] Based on the above embodiments, in one exemplary embodiment provided in this application, the fault determination strategy includes at least one of the following:

[0141] Power supply fault diagnosis strategy;

[0142] Temperature fault diagnosis strategy;

[0143] Communication failure detection strategy;

[0144] Motor fault diagnosis strategy;

[0145] The motor operation fault determination strategy includes at least one of the following: stall fault determination strategy, pre-drive or overcurrent fault determination strategy, position sensor fault determination strategy, motor reverse fault determination strategy, motor overspeed fault determination strategy, and excessive speed deviation fault determination strategy.

[0146] Specifically, during the operation of the electronic oil pump, multiple parameters such as power supply voltage, chip temperature, communication status, motor speed, motor current, position sensor signals, speed commands, and feedback values ​​can be acquired and monitored in parallel and synchronously. Parallel fault diagnosis strategies include at least one of the following:

[0147] The power supply fault detection strategy is used to monitor whether the power supply voltage exceeds the overvoltage or undervoltage threshold and to make an cumulative judgment based on the duration of the fault.

[0148] Temperature fault detection strategy is used to monitor whether the chip temperature exceeds the graded protection threshold and to perform frequency reduction or shutdown according to the temperature level;

[0149] The communication failure detection strategy is used to monitor whether the communication link with the engine management system (EMS) is interrupted or abnormal, and to delay detection during the initial unstable period to avoid false judgments.

[0150] Motor fault diagnosis strategy is used to monitor whether the motor windings are stalled, whether the pre-drive stage is overcurrent, and whether the position sensor signal is abnormal.

[0151] Motor operation fault determination strategy is used to monitor whether the actual operating status of the motor is abnormal.

[0152] The motor operation fault determination strategy includes at least one of the following:

[0153] The stall fault determination strategy is used to determine stall when the motor speed is lower than a preset threshold and the current is continuously higher than the stall current threshold and verified after a certain duration.

[0154] The pre-drive or overcurrent fault determination strategy is used to monitor whether the pre-drive stage current exceeds the overcurrent threshold through a hardware comparator or register and trigger hardware shutdown or software current limiting.

[0155] The position sensor fault determination strategy is used to confirm the fault by double verification of the number of times the position sensor signal continuously exceeds the allowable range and the number of restart failures.

[0156] The motor reverse fault detection strategy is used to determine reverse when the speed command value is positive but the actual speed is negative and the duration reaches a threshold.

[0157] The motor overspeed fault determination strategy is used to determine overspeed after the motor speed exceeds the preset overspeed threshold and is verified for a continuous period of time.

[0158] The fault determination strategy for excessive speed deviation is used to determine speed loss of control after the deviation between the speed command value and the speed feedback value exceeds a preset threshold and is verified for a continuous period of time.

[0159] In the embodiments provided in this application, by executing multiple fault judgment strategies such as power supply, temperature, communication, motor and motor operation in parallel and setting multi-condition composite judgment and duration verification for each strategy, the defects of insufficient single fault monitoring dimension leading to missed fault judgment under complex working conditions are overcome. This avoids unnecessary protection actions triggered by transient interference or single parameter abnormality being misjudged as real faults, and improves the comprehensiveness, accuracy and reliability of fault diagnosis and protection response of electronic oil pump under all working conditions.

[0160] Based on the above embodiments, in one exemplary embodiment provided in this application, the above-mentioned fault is a stall fault; the specific execution process of performing corresponding protection actions and post-fault handling measures for different faults of the electronic oil pump according to the preset protection strategy for different faults may further include steps S201 to S204, which are described in detail below:

[0161] Step S201: Control the electronic oil pump to stop running, and control the electronic oil pump to reverse once to reconfirm whether it is stuck;

[0162] Step S202: If the electronic oil pump is determined to still have a stall fault, the stall fault is reported to the EMS, the output of the electronic oil pump is cut off, and after a first preset time, the electronic oil pump is controlled to perform a self-diagnosis process to determine whether the fault is cleared or upgraded to a permanent fault.

[0163] Step S203: If the stall fault is upgraded to a permanent fault and the vehicle is not powered on or off again, report to EMS to prohibit engine starting.

[0164] Step S204: If the stall fault is cleared, exit the self-diagnosis process.

[0165] For example, after determining that the electronic oil pump has a stall fault, the electronic oil pump is controlled to stop running, and the electronic oil pump is controlled to perform a reciprocating action of forward and reverse rotation to verify the stall judgment result. The current response and speed feedback during the forward and reverse rotation process are used to distinguish between instantaneous mechanical jamming and continuous stalling.

[0166] If the electronic oil pump still has a stall fault after forward and reverse rotation verification, a stall fault code is sent to the engine management system (MES), and the drive output of the electronic oil pump is cut off to disable the motor. At the same time, a delay waiting period of a first preset time is entered. The first preset time is set to be in the range of several hundred milliseconds to several seconds, which is used to wait for the temperature rise of the motor windings to drop, the elastic rebound of the mechanical structure, or the dissipation of external transient interference before entering the self-diagnosis process.

[0167] During the self-diagnosis process, motor current and speed data can be re-acquired to determine whether the stall fault has been cleared or upgraded to a permanent fault. If the stall fault is upgraded to a permanent fault and the vehicle has not undergone a power-on and power-off reset operation, an engine start prohibition command is reported to the engine management system to prevent the engine from starting in a lubrication-deficient state. If the stall fault is cleared during the self-diagnosis process, the self-diagnosis process is exited and the normal operation monitoring of the electronic oil pump is restored.

[0168] In the embodiments provided in this application, a graded verification mechanism that combines forward and reverse rotation verification with delayed self-diagnosis after stopping operation overcomes the problem of misjudgment caused by the difficulty in distinguishing between instantaneous mechanical jamming and continuous stalling. It avoids the risk of starting the engine under lubrication deficiency due to unnecessary permanent fault lock-up triggered by instantaneous interference or due to missed stalling. By reporting a prohibition command to the engine management system, it achieves active interception of engine starting under fault conditions, improving the accuracy of electronic oil pump stall fault diagnosis and the reliability of engine starting safety protection.

[0169] Based on the above embodiments, in one exemplary embodiment provided in this application, the self-diagnosis process of the electronic oil pump may further include steps S301 to S304, which are described in detail below:

[0170] Step S301: Perform a reverse test for a second preset duration at a first preset speed, and after stopping for a third preset duration, perform a forward test for a second preset duration at the first preset speed, and after stopping for a third preset duration, check whether the electronic oil pump triggers a shutdown fault again.

[0171] Step S302: Attempt to start the engine after the electronic oil pump triggers a shutdown fault again;

[0172] Step S303: If the number of startup failures is greater than the first preset number, the electronic oil pump self-diagnosis process will be entered again after the first preset time, and the number of failures will be accumulated once. When the number of failures reaches the second preset number, the stall fault will be upgraded to a permanent fault.

[0173] Step S304: If the number of startup failures is less than the first preset number and the startup attempt is successful, or if the electronic oil pump does not trigger the shutdown fault again, then the fault is cleared.

[0174] As described in the above embodiments, the electronic oil pump performs a reciprocating motion of forward and reverse rotation to perform a second verification of the stall judgment result. If the stall fault is still reported after the forward and reverse rotation verification, the electronic oil pump is controlled to enter the self-diagnosis process.

[0175] Specifically, the self-diagnostic process includes performing a reverse rotation test at a first preset speed for a second preset duration, and then stopping operation for a third preset duration after the reverse rotation test to allow the motor winding current to decay and the mechanical structure stress to be released. Subsequently, a forward rotation test is performed at the first preset speed for a second preset duration, and then stopping operation again for a third preset duration after the forward rotation test. After that, it is checked whether a shutdown fault is triggered again to determine whether the stall condition persists.

[0176] If a shutdown fault is triggered again, the motor will be started. If the number of consecutive start failures exceeds the first preset number, the self-diagnosis process will be entered again after the first preset time and the number of faults will be incremented by one. When the number of faults reaches the second preset number, the stall fault will be upgraded to a permanent fault. If the number of start failures is less than the first preset number and the start attempt is successful, or if no shutdown fault is triggered again during the reverse and forward rotation tests, the stall fault will be cleared and the self-diagnosis process will be exited.

[0177] Optional, please refer to Figure 2 , Figure 2 This is a schematic diagram of the stall fault handling process provided in the embodiments of this application, such as... Figure 2 As shown, the self-diagnostic process of the electronic oil pump may include: reversing the speed at a first preset speed (e.g., 200 rpm) for a second preset time (e.g., 500 ms), stopping for a third preset time (e.g., 50 ms), then reversing the speed at the first preset speed (e.g., 200 rpm) for a second preset time (e.g., 500 ms), and stopping for a third preset time (e.g., 50 ms). After that, it is checked whether the electronic oil pump triggers the shutdown fault again. If both forward and reverse rotations can be completed smoothly, that is, the shutdown fault is no longer triggered, then it is determined that the fault has disappeared, the fault code is cleared, and the oil pump returns to normal.

[0178] If a stall is triggered again during self-diagnosis, the system will wait for a first preset time (e.g., 1 second) before retrying. After a first preset number of consecutive failures (e.g., 3 times), the cumulative fault count will be incremented by 1, and the system will wait 1 minute before attempting self-diagnosis again. If the system operates normally for 1 minute without any faults, the cumulative count will be cleared. When the cumulative fault count reaches a second preset number (e.g., 20 times), it will be upgraded to a permanent fault, which can only be cleared by powering on or waking from sleep mode.

[0179] Regardless of the level of stall fault, once triggered, the engine control system (EMS) must immediately stop the engine and prevent it from starting until the electronic fuel pump fault is cleared.

[0180] In the embodiments provided in this application, a graded self-diagnostic mechanism combining forward and reverse rotation tests with multiple start attempts overcomes the defect that a single forward and reverse rotation review cannot completely distinguish between momentary jamming and continuous stalling. It avoids the fault being mistakenly judged as a permanent fault due to residual mechanical stress or transient interference, thus incorrectly preventing the engine from starting. By accumulating the number of faults and determining the escalation of permanent faults, the accuracy of stall fault diagnosis and the robustness of the self-diagnostic process are improved.

[0181] Based on the above embodiments, in one exemplary embodiment provided in this application, the fault is a pre-drive or overcurrent fault; the specific execution process of performing corresponding protection actions and post-fault handling measures according to the preset protection strategy for different faults of the electronic oil pump may further include steps S401 to S405, which are described in detail below:

[0182] Step S401: The controller hardware stops outputting;

[0183] Step S402: Control the motor to stop rotating, and then control the motor to try rotating again at the currently requested speed;

[0184] Step S403: If the number of times the motor fails to rotate reaches the third preset number, a pre-drive or overcurrent fault is reported to the EMS, and after the fourth preset time, the electronic oil pump is controlled to perform a self-diagnosis process to determine whether the fault is cleared or upgraded to a permanent fault.

[0185] Step S404: If the pre-drive or overcurrent fault is upgraded to a permanent fault and the vehicle is not powered on or off again, report to EMS to stop the engine and prevent it from starting.

[0186] In step S405, if the pre-drive or overcurrent fault is cleared, the self-diagnostic process is exited.

[0187] For example, when it is determined that the electronic oil pump malfunctions due to a pre-drive fault or an overcurrent fault, the controller hardware circuit directly shuts off the pre-drive stage power output to achieve rapid hardware-level protection. Subsequently, the control motor stops rotating and attempts to rotate again at the currently requested speed to verify the overcurrent status. If the number of failed motor rotation attempts reaches a third preset number, a pre-drive fault code is reported to the engine management system. After a fourth preset time, the electronic oil pump is controlled to enter a self-diagnostic process to determine whether the fault is cleared or escalated to a permanent fault. The fourth preset time is used to wait for the junction temperature of the pre-drive stage power devices to drop and the residual charge of the bus capacitor to be released.

[0188] Among them, controlling the motor to stop rotating means controlling the motor that drives the electronic oil pump to stop rotating. In other words, when a pre-drive fault or overcurrent fault is detected, the motor that drives the electronic oil pump will be stopped immediately to protect the power devices and windings.

[0189] In addition, if a pre-drive fault or overcurrent fault escalates into a permanent fault and the vehicle has not undergone a power-on and power-off reset operation, an instruction to stop engine operation and prevent engine starting will be reported to the engine management system. If the pre-drive or overcurrent fault is cleared during the electronic oil pump self-diagnosis process, the self-diagnosis process will be exited and the normal operation monitoring of the electronic oil pump will be restored.

[0190] Optionally, in some feasible embodiments, upon determining that the electronic oil pump has a pre-drive or overcurrent fault, the controller hardware immediately stops outputting and controls the motor to stop. Then, it attempts to rotate again at the currently requested speed. If the number of failed motor attempts reaches a third preset number (e.g., 3 times), a pre-drive or overcurrent fault is reported to the engine control system (MES). Subsequently, after a fourth preset duration (e.g., 1 second), the electronic oil pump is controlled to perform a self-diagnostic process to determine whether the fault is cleared or escalated into a permanent fault. If the pre-drive or overcurrent fault escalates into a permanent fault, and the vehicle has not been powered on or off again, a report can be sent to the engine management system (EMS) to stop the engine and prevent starting. If the pre-drive or overcurrent fault is cleared during the electronic oil pump self-diagnostic process, the electronic oil pump is controlled to exit the self-diagnostic process.

[0191] In the embodiments provided in this application, a hierarchical protection mechanism combining hardware shutdown and multiple retry verification is used to overcome the problem of difficulty in distinguishing between overcurrent or pre-drive transient faults and permanent drive failures. This avoids the mistaken prohibition of engine starting due to reporting a permanent fault after a single failed attempt. By combining the pre-drive register and current speed feedback in the self-diagnosis process, the accuracy of pre-drive or overcurrent fault diagnosis and the reliability of engine operation safety protection are improved.

[0192] Based on the above embodiments, in one exemplary embodiment provided in this application, the self-diagnosis process of the electronic oil pump corresponding to the above-mentioned pre-drive or overcurrent fault includes at least steps S501 to S504, which are described in detail below:

[0193] Step S501: After controlling the electronic oil pump to run at the second preset speed for a fifth preset time, stop for a sixth preset time, and check whether the electronic oil pump triggers a shutdown fault again during the operation.

[0194] Step S502: Attempt to start the engine after the electronic oil pump triggers a shutdown fault again;

[0195] Step S503: If the number of startup failures is greater than the fourth preset number, the electronic oil pump self-diagnosis process will be entered again after the seventh preset time, and the number of failures will be accumulated once. When the number of failures reaches the fifth preset number, the pre-drive failure will be upgraded to a permanent failure.

[0196] Step S504: If the number of startup failures is less than the fourth preset number and the startup attempt is successful, or if the electronic oil pump does not trigger the shutdown fault again during operation, then the fault is determined to be cleared.

[0197] For example, the self-diagnostic process of the electronic oil pump corresponding to the pre-drive or overcurrent fault is as follows: the motor is run at the second preset speed for the fifth preset time to fully enter the steady-state operating range. After the operation ends, it stops for the sixth preset time to wait for the junction temperature of the pre-drive stage power device to drop and the residual charge of the bus capacitor to be released. Then, it checks whether the shutdown fault is triggered again during the operation to determine whether the overcurrent or pre-drive state continues. If the shutdown fault is triggered again during the operation, the motor is started. If the number of consecutive start failures is greater than the fourth preset number, the self-diagnostic process is entered again after the seventh preset time and the number of faults is incremented by one. When the number of faults reaches the fifth preset number, the pre-drive fault is determined to be upgraded to a permanent fault. If the number of start failures is less than the fourth preset number and the start attempt is successful, or if the shutdown fault is not triggered again during the operation, the fault is determined to be cleared and the self-diagnostic process is exited.

[0198] Specifically, please refer to Figure 3 , Figure 3 This is a schematic diagram of the pre-drive or overcurrent fault handling process provided in the embodiments of this application, such as... Figure 3 As shown, after determining that the motor has a pre-drive or overcurrent fault, the electronic oil pump's self-diagnostic program is executed after a 1-second delay. The electronic pump-based self-diagnostic program includes: the oil pump running at a second preset speed (e.g., 500 rpm) for a fifth preset time (e.g., 500 ms), then stopping for a sixth preset time (e.g., 50 ms). It also checks whether the electronic oil pump triggers a shutdown fault again during operation. If the electronic oil pump does not trigger a shutdown fault again during operation, the fault is immediately cleared, and the electronic oil pump resumes normal operation.

[0199] If the electronic oil pump of the running device reports a shutdown fault again, it will attempt to start again. If the number of failed starts exceeds the fourth preset number (e.g., 3 times), the self-diagnosis process will exit, and the self-diagnosis logic will be executed again after 1 minute. The fault accumulation count will be incremented by 1. If there are no faults during 1 minute of normal operation, the fault accumulation count will be cleared. If the number of failed starts is less than the fourth preset number (e.g., 3 times) and the startup attempt is successful without triggering a shutdown fault again, the fault is cleared.

[0200] If the number of accumulated faults is greater than or equal to the fifth preset number (e.g., 20 times), it will be upgraded to a permanent fault and reported to the engine control system, so that the engine control system (EMS) will immediately stop the engine and prevent it from starting upon receiving the fault.

[0201] In the embodiments provided in this application, the hierarchical self-diagnosis mechanism, which combines steady-state operation at a second preset speed with multiple start-up retry, overcomes the problem of difficulty in distinguishing between pre-drive or overcurrent transient faults and permanent drive failures. It avoids the mistaken prohibition of engine start due to reporting a permanent fault after a single start failure. By accumulating the number of faults and real-time monitoring during speed operation, the accuracy of pre-drive or overcurrent fault diagnosis and the reliability of engine safety protection are improved.

[0202] Based on the above embodiments, in one exemplary embodiment provided in this application, the aforementioned fault is any one of a position sensor fault, a motor reverse fault, or a motor overspeed fault; the specific implementation process of executing corresponding protection actions and post-fault handling measures for different faults of the electronic oil pump according to the preset protection strategy for different faults may further include steps S601 to S603, which are described in detail below:

[0203] Step S601: Control the electronic oil pump to stop running, and control the electronic oil pump to try to restart it again according to the current request;

[0204] Step S602: If the number of failed restart attempts reaches the sixth preset number, a fault is reported to the EMS to stop the engine and prevent starting, and the fault count is accumulated once. When the number of faults reaches the seventh preset number, the pre-drive fault is upgraded to a permanent fault.

[0205] Step S603: If the restart attempt is successful or the number of failures is less than the sixth preset number and normal operation is restored, then the fault is cleared.

[0206] For example, when the fault is any of the following: position sensor fault, motor reverse fault, or motor overspeed fault, a stop control command can be output first to stop the electronic oil pump from rotating, and then a start control quantity can be reissued according to the current request. The start control quantity may include the target speed, direction command and enable signal.

[0207] If the system still fails to return to normal operation after restarting, the number of failed restarts will be incremented. When the number of failed restarts reaches the sixth preset number, a fault code will be sent to the engine management system (MES). The engine management system (EMS) will then perform a vehicle protection action to stop the engine and prevent it from starting, while incrementing the fault count corresponding to that fault type.

[0208] When the cumulative number of faults reaches the seventh preset number, the pre-drive fault will be marked as a permanent fault and kept in a state where recovery is prohibited. If the electronic oil pump returns to its allowable operating range during the restart process, the current fault mark will be cleared and the subsequent fault escalation judgment will be exited.

[0209] Optionally, taking a position sensor as an example, a fault is triggered when the position sensor signal is detected as being outside the allowable range for 5 consecutive times (within 50ms). The motor immediately stops and attempts to restart 3 times. Only if all 3 restarts fail is a fault reported. After each trigger, the fault is automatically cleared after a 1-second delay to attempt recovery, and the fault accumulation count is incremented by 1. If the machine operates normally within 1 minute, the accumulation count is reset to zero. When the accumulation count reaches 20 times, the fault is upgraded to a permanent fault, requiring a power cycle to recover.

[0210] In the embodiments provided in this application, a graded protection mechanism that combines multiple restart attempts with the accumulation of fault counts overcomes the problem that it is difficult to distinguish between non-permanent anomalies such as position sensor signal jitter or transient motor overspeed and reverse rotation and real drive failures. It avoids the mistaken prohibition of engine starting due to reporting a permanent fault because of a single anomaly. The accuracy of fault diagnosis and system fault tolerance are improved by judging the fault count threshold and confirming the resumption of operation.

[0211] Based on the above embodiments, in one exemplary embodiment provided in this application, the aforementioned fault is a communication fault; the specific implementation process of performing corresponding protection actions and post-fault handling measures for different faults of the electronic oil pump according to the preset protection strategy may further include steps S701 to S703, which are described in detail below:

[0212] Step S701: Control the electronic oil pump to run at the maximum permissible speed for a first preset number of message cycles, and stop the machine after executing all message cycles, and check again whether the communication fault has been eliminated and communication has been restored.

[0213] Step S702: If the communication failure is cleared and communication is restored, control the electronic oil pump to resume operation and control the engine to resume operation.

[0214] In step S703, if the communication failure is not cleared or communication is not restored, a report is sent to the EMS to control the engine to stop and prevent it from starting.

[0215] For example, when the fault of the electronic oil pump is determined to be a communication fault, the electronic oil pump is controlled to run at the maximum allowable speed and continue for a first preset number of message cycles, so that the motor maintains full load operation under the condition of no communication command to verify the integrity of the drive link. After all message cycles are executed, the motor is controlled to stop, and then it is checked whether the communication fault has been eliminated and whether the communication link has returned to normal.

[0216] If the communication fault is detected and the communication is restored, the electronic oil pump is controlled to resume operation and the engine is controlled to resume operation synchronously. If the communication fault is not eliminated or the communication link is not restored after all message cycles are completed, the communication fault is reported to the engine control system to control the engine to stop running and prevent the engine from starting.

[0217] Optionally, in some feasible embodiments, after a communication failure is detected, the motor stops after running at the maximum permissible speed for a first preset number (e.g., 40 message cycles). If the Busoff event disappears and CAN communication is normal, the motor resumes normal operation. If the engine control system (EMS) does not receive a message from the electronic fuel pump, the engine must be stopped immediately and restarting must be prohibited.

[0218] In the embodiments provided in this application, the communication link integrity verification mechanism with a preset message cycle at full load and maximum permissible speed overcomes the problem of difficulty in distinguishing between transient communication interruptions and permanent link failures, avoids the mistaken prohibition of engine starting due to reporting a permanent fault due to a single communication jitter, and improves the accuracy of communication fault diagnosis and the reliability of engine safety protection through post-run re-inspection and hierarchical reporting strategies.

[0219] Based on the above embodiments, in one exemplary embodiment provided in this application, the communication failure includes any one of the following: Controller Area Network (CAN) bus off failure, CRC check failure, RollingCnt failure, and node loss failure; furthermore, the communication failure determination strategy includes:

[0220] After power-on, communication fault detection is initiated after the eighth preset time. If continuous recovery fails according to the preset recovery cycle, and the number of failures reaches the eighth preset number, a CAN bus off fault is determined.

[0221] It should be noted that a CAN bus off fault refers to a state in which the communication of the CAN communication bus of the electronic oil pump is completely interrupted due to reasons such as physical link disconnection, bus controller hibernation, or complete node disconnection. The fault determination strategy for a CAN bus off fault can be as follows: after power-on, the detection of communication faults is started after an eighth preset time (e.g., 3s), and the failure is continuously recovered according to a preset recovery cycle. The preset recovery cycle includes: a fast recovery cycle of 50ms and a slow recovery cycle of 1s. If the number of consecutive failures within the preset recovery cycle reaches the eighth preset number (e.g., 30 times), then the electronic oil pump is determined to have a CAN bus off fault.

[0222] If a CRC check error occurs in the received CAN bus communication data for a second preset number of consecutive message cycles, a CRC check failure is determined to have occurred.

[0223] It should be noted that a CRC check failure refers to an error occurring in the data received by the electronic oil pump during CAN bus communication after multiple consecutive message cycles following CRC cyclic redundancy check. This indicates that the data frame content transmitted on the bus has been corrupted at the bit level or has been distorted due to electromagnetic interference. The fault determination strategy for CRC check failures can be as follows: if a CRC check failure occurs in the received CAN communication data for a second preset number of message cycles (e.g., 20), then it is determined that a CRC check failure has occurred in the electronic oil pump.

[0224] If the received CAN bus communication data shows a RollingCnt value error for the third consecutive preset number of message cycles, then a RollingCnt fault is confirmed.

[0225] It should be noted that a RollingCnt fault refers to a communication failure in CAN bus communication where the receiving end continuously detects discontinuous, repetitive, or out-of-order rolling counters embedded in the messages. In other words, the received count values ​​are inconsistent with the expected values, and this failure is confirmed after exceeding a preset number of frames or a preset duration. This indicates problems such as message loss, repeated reception, or incorrect transmission order on the bus. The fault determination strategy for RollingCnt faults can be as follows: when the received CAN bus communication data shows consecutively incorrect RollingCnt values ​​for the third preset number (e.g., 20 message cycles), a RollingCnt fault is determined to have occurred in the electronic oil pump.

[0226] In hardware wake-up mode, if a message with a preset ID is not received for the fourth preset number of message cycles, a node loss fault is determined to have occurred.

[0227] It should be noted that node loss fault refers to a fault state in which a key node (such as an upper-level control node like EMS) in the CAN bus communication of the electronic oil pump fails to send any valid message after a preset timeout window, causing the electronic oil pump to be unable to receive communication data from that node. This results in the node being permanently offline or disconnected from the bus. The fault determination strategy for node loss faults can be as follows: In hard-wired wake-up mode, if no message with a preset ID (e.g., ID=0x27A) is received for the fourth consecutive preset number of message cycles (e.g., 20), then a node loss fault is determined to have occurred in the electronic oil pump.

[0228] Optional, please refer to Figure 4 , Figure 4 This is a schematic diagram of the communication failure handling process provided in the embodiments of this application, such as... Figure 4As shown, after determining that the electronic oil pump has experienced a communication failure, including any of the following: CAN bus off failure, CRC check failure, RollingCnt failure, or node loss failure, the motor driving the electronic oil pump will run at the maximum permissible speed for 40 message cycles before shutting down. The system will then determine if the fault has disappeared and communication has returned to normal. If yes, the motor driving the electronic oil pump will resume normal operation. If no, the system will remain shut down and continue monitoring. If the engine control system (EMS) does not receive any feedback messages from the electronic oil pump, the engine must be stopped immediately and restarting prohibited.

[0229] In the embodiments provided in this application, the problem of difficulty in distinguishing between transient interference and permanent link failure of CAN bus is overcome by combining power-on delay detection and continuous failure counting for CAN bus off determination, and by using CRC verification based on continuous message cycle counting, RollingCnt and node loss fault classification determination strategies. This avoids the mistaken judgment of fault due to a single abnormal message and the incorrect prohibition of engine starting. The accuracy of communication fault diagnosis and the reliability of engine safety protection are improved by multi-dimensional fault classification and graded threshold determination.

[0230] Based on the above embodiments, in one exemplary embodiment provided in this application, the temperature fault determination strategy of the electronic oil pump may specifically include the following steps S801 to S803, which are described in detail below:

[0231] Step S801: If the temperature value collected by the temperature sensor is greater than the first preset temperature or less than the second preset temperature for a period of time that exceeds the ninth preset duration, then the temperature sensor is determined to be faulty.

[0232] Step S802: If the temperature sensor is not malfunctioning, and the collected temperature value is greater than the third preset temperature and the duration exceeds the tenth preset duration, then an over-temperature frequency reduction fault is determined to have occurred.

[0233] Step S803: If the collected temperature value exceeds the fourth preset temperature and the duration exceeds the eleventh preset duration, then an over-temperature shutdown fault is determined to have occurred.

[0234] Among them, the first preset temperature is greater than the fourth preset temperature, the fourth preset temperature is greater than the third preset temperature, and the third preset temperature is greater than the second preset temperature.

[0235] For example, a temperature fault detection strategy for an electronic oil pump may include: if the temperature value collected by the temperature sensor is greater than a first preset temperature (e.g., 175°C) or lower than a second preset temperature (e.g., -55°C) for a duration that lasts longer than a ninth preset duration (e.g., 500ms), or if the temperature difference between two consecutive adjacent measurements is greater than 10°C (within 500ms), it is determined that the sensor is faulty, and thus the electronic oil pump has a temperature sensor fault.

[0236] If the temperature sensor malfunctions and the collected temperature value is greater than the third preset temperature (e.g., calibrated to 145°C) and the duration exceeds the tenth preset duration (e.g., 2 seconds), it can be determined that the electronic oil pump has a temperature-induced frequency reduction fault.

[0237] If the temperature value collected by the temperature sensor exceeds the fourth preset temperature (e.g., calibrated to 155℃) and the duration exceeds the eleventh preset duration (e.g., 2 seconds), it can be determined that the electronic oil pump has an over-temperature shutdown fault.

[0238] The first preset temperature is greater than the fourth preset temperature, and the fourth preset temperature is greater than the third preset temperature.

[0239] In the embodiments provided in this application, a layered temperature protection mechanism that combines gradient temperature thresholds with duration determination overcomes the problem of difficulty in distinguishing between transient temperature fluctuations and actual sensor failures or overheating conditions. This avoids unnecessary engine shutdowns caused by triggering shutdowns due to a single temperature exceeding the limit. The three-level progressive protection of sensor failure, overheating frequency reduction, and overheating shutdown improves the accuracy of temperature fault diagnosis and the rationality of engine operation safety protection.

[0240] Based on the above embodiments, in one exemplary embodiment provided in this application, the specific implementation process of performing corresponding protection actions and post-fault handling measures for different faults of the electronic oil pump according to the preset protection strategy may include the following steps, which are described in detail below:

[0241] After confirming a temperature sensor malfunction, the control system limits the speed of the electronic oil pump to below the third preset speed and reports to the EMS to limit the engine speed to below the fourth preset speed, which is less than the third preset speed.

[0242] For example, after determining that the electronic oil pump has a temperature sensor malfunction, the speed of the electronic oil pump can be controlled to be limited to a third preset speed (e.g., 3500 rpm) and reported to the engine control system (EMS) to limit it to a fourth preset speed (e.g., 1500 rpm), wherein the fourth preset speed is less than the third preset speed.

[0243] After confirming the overheating and frequency reduction fault, the control electronic oil pump limits the maximum speed to below the third preset speed. After the collected temperature value drops to the fifth preset temperature value, the motor speed is restored. The fifth preset temperature value is less than the third preset temperature value and greater than the second preset temperature value.

[0244] Once an overheating and frequency reduction fault is confirmed in the electronic oil pump, the maximum speed of the electronic oil pump can be limited to below the third preset speed (e.g., 3500 rpm). After the collected temperature value drops to the fifth preset temperature value (e.g., calibrated to 135°C), the motor speed is restored. Simultaneously, the engine control system (EMS) must limit the engine speed to a preset value (e.g., calibrated to 3000 rpm) to reduce the thermal load. The fifth preset temperature value is lower than the third preset temperature value and higher than the second preset temperature value.

[0245] After confirming an overheating shutdown fault, the electronic oil pump is stopped, and the EMS is notified to stop the engine and prevent it from starting.

[0246] Once an overheating shutdown fault is confirmed in the electronic oil pump, the pump can be stopped, and the engine control system (EMS) can be notified to stop and restart the engine. Furthermore, in some feasible embodiments, if the temperature drops below a preset temperature threshold (e.g., calibrated to 145°C), the operation of both the electronic oil pump and the engine can be resumed.

[0247] In the embodiments provided in this application, a three-level progressive protection mechanism is used to overcome the problem of difficulty in distinguishing between sensor failure and actual over-temperature conditions. This mechanism includes speed limiting when the temperature sensor fails, frequency reduction when over-temperature occurs, and prohibition of starting when over-temperature occurs. It avoids unnecessary engine shutdown caused by sensor failure or slight over-temperature triggering the shutdown. The rationality of temperature fault graded protection and the continuity of engine operation are improved by the coordinated speed limiting and automatic temperature recovery strategy of the pump end and engine end.

[0248] Based on the above embodiments, in one exemplary embodiment provided in this application, the power failure determination strategy may specifically include the following steps, which are described in detail below:

[0249] If the power supply voltage of the electronic oil pump is greater than the first voltage threshold and the duration exceeds the twelfth preset duration, then a power supply overvoltage fault is determined.

[0250] If the power supply of the electronic oil pump is detected to be greater than the first voltage threshold (e.g., calibrated to 16.5V) and the duration reaches the twelfth preset duration (e.g., 2 seconds), it is determined that the electronic oil pump has an overvoltage fault.

[0251] If the power supply voltage of the electronic oil pump is less than the second voltage threshold and the duration exceeds the twelfth preset duration, then a power undervoltage fault is determined.

[0252] The second voltage threshold is less than the first voltage threshold.

[0253] If the power supply voltage of the electronic oil pump is detected to be less than the second voltage threshold (e.g., calibrated to 8.0V) and the duration exceeds the twelfth preset duration (e.g., 2 seconds), it is determined that the electronic oil pump has a power undervoltage fault.

[0254] Furthermore, the second voltage threshold is less than the first voltage threshold.

[0255] In the embodiments provided in this application, the power supply fault determination mechanism that combines dual voltage thresholds and duration overcomes the problem of difficulty in distinguishing between transient power supply fluctuations and actual overvoltage or undervoltage faults. It avoids incorrectly restricting pump operation or prohibiting engine starting due to misjudgment of faults caused by a single voltage exceeding the limit. The accuracy of power supply fault diagnosis and the reliability of engine electrical safety protection are improved by using upper and lower threshold grading determination.

[0256] Based on the above embodiments, in one exemplary embodiment provided in this application, the specific implementation process of performing corresponding protection actions and post-fault handling measures for different faults of the electronic oil pump according to the preset protection strategy may further include the following steps, which are described in detail below:

[0257] If a power overvoltage fault is detected, it is reported to the EMS and the motor is controlled to continue running according to the current request; after the power supply voltage of the electronic oil pump drops to the third voltage threshold and remains there for a thirteenth preset time, the power overvoltage fault is cleared, and the third voltage threshold is greater than the second voltage threshold and less than the first voltage threshold.

[0258] For example, when an overvoltage fault is detected in the electric oil pump, a fault code is reported to the engine management system (EMS) via the CAN bus. However, to ensure basic lubrication, the motor continues to operate normally at the currently requested speed. If the supply voltage of the electric oil pump drops to a third voltage threshold (e.g., calibrated to 16.0V) and remains there for a thirteenth preset duration (e.g., 500ms), the overvoltage fault in the electric oil pump can be cleared, and normal monitoring can be restored. The third voltage threshold is greater than the second voltage threshold but less than the first voltage threshold.

[0259] If a power supply undervoltage fault is detected, it is reported to the EMS and the motor is controlled to continue running according to the current request; after the power supply voltage of the electronic oil pump rises to the fourth voltage threshold and continues for the fourteenth preset time, the power supply overvoltage fault is cleared, and the fourth voltage threshold is greater than the second voltage threshold and less than the third voltage threshold.

[0260] For example, after determining that the electronic oil pump has a power undervoltage fault, the system reports to the engine control system (EMS) and controls the motor to continue running as requested. After the power supply voltage of the electronic oil pump rises to the fourth voltage threshold (e.g., calibrated to 8.5V) and remains there for a fourteenth preset duration (e.g., 500ms), the system determines that the power overvoltage fault of the electronic oil pump has been cleared. The fourth voltage threshold is greater than the second voltage threshold and less than the third voltage threshold.

[0261] Based on this, it is ensured that there will be no false alarms or frequent start-stops during short-term power fluctuations, while the vehicle controller can be alerted in the event of continuous power abnormalities.

[0262] In the embodiments provided in this application, the protection mechanism of maintaining operation when the power supply is abnormal and using a hysteresis threshold recovery overcomes the problem of difficulty in distinguishing between transient power supply fluctuations and actual overvoltage or undervoltage faults, avoids unnecessary engine shutdowns caused by voltage transient exceeding the limit, and improves the accuracy of power supply fault diagnosis and the continuity of engine operation through graded threshold judgment and automatic recovery strategy.

[0263] Based on the above embodiments, in one exemplary embodiment provided in this application, the stall fault determination strategy may specifically include the following, which are detailed below:

[0264] If, during motor operation, the motor speed is lower than the preset minimum speed and the combined current of the motor is greater than the first current threshold for more than eight preset control cycles, then a stall fault is determined to have occurred.

[0265] Specifically, during motor operation, if the motor speed is lower than the preset minimum speed (e.g., 20 rpm) and the duration of the motor's combined current being greater than the first current threshold (e.g., calibrated to 60A) exceeds the eighth preset number of control cycles (e.g., 20 times), then the electronic oil pump is determined to have a stall fault. The motor combined current can be obtained by combining the bus current and the phase point current.

[0266] For further information, please refer to [link / reference]. Figure 2 Upon confirming a stall fault in the electronic oil pump, the motor driving the pump is immediately stopped and rotated forward and reversed once. If a stall fault still exists, it is reported to the engine control system (EMS), and the motor output is immediately cut off. Subsequently, after a first preset time, the electronic oil pump enters its self-diagnostic process. The self-diagnostic process of the electronic oil pump is described in the embodiments corresponding to steps S301 to S304 above, and will not be repeated here.

[0267] In the embodiments provided in this application, the stall determination mechanism, which combines the dual parameters of speed and synthetic current and counts the continuous cycle, overcomes the problem of difficulty in distinguishing between the transient low speed and high current of the motor during start-stop and the actual stall condition. It avoids the mistaken judgment of stall due to a single start-stop current surge, which would lead to the incorrect prohibition of engine start. The accuracy of stall fault diagnosis and the reliability of engine safety protection are improved by dual-condition threshold verification and control cycle accumulation determination.

[0268] Based on the above embodiments, in one exemplary embodiment provided in this application, the above-mentioned pre-drive or overcurrent fault determination strategy may further include the following steps, which are described in detail below:

[0269] If the highest preset bit of the pre-drive status register becomes abnormal, or if the chip voltage is higher than the fifth voltage threshold, or if the chip voltage is lower than the sixth voltage threshold, the hardware output will be shut down. If the duration of the detected abnormality in the pre-drive status register exceeds the fifteenth preset duration, a pre-drive fault is determined to have occurred.

[0270] Specifically, if an abnormality is detected in the highest preset bit (e.g., 8 bits) of the pre-drive status register, or if the chip voltage is higher than the fifth voltage threshold (e.g., calibrated to 18V) or lower than the sixth voltage threshold (e.g., calibrated to 7.5V), the hardware immediately shuts off the output. If the duration of the abnormality in the pre-drive status register exceeds the fifteenth preset duration (100ms), it is determined that the electronic oil pump has a pre-drive failure.

[0271] If the duration of the motor winding phase current being greater than the second current threshold exceeds the sixteenth preset duration, or if the hardware overcurrent comparator output is valid, or if there is an abnormality in the six MOSFET overcurrent detection bits of the pre-drive status register, then an overcurrent fault is confirmed to have occurred.

[0272] Specifically, if the motor winding phase point current is detected to be greater than the second current threshold (e.g., 190A) and the duration exceeds the sixteenth preset duration (e.g., 875us), or if an abnormality is detected in the six MOSFET overcurrent monitoring bits of the pre-drive status register, then an overcurrent fault is determined to have occurred in the electronic oil pump.

[0273] After determining that the electronic oil pump has a pre-drive fault or an overcurrent fault, the self-diagnosis process of the electronic oil pump can be executed after a fourth preset time (e.g., 1 second). The self-diagnosis process of the electronic oil pump is as described in the embodiments corresponding to steps S501 to S504 above, and will not be repeated in this embodiment.

[0274] In the embodiments provided in this application, a multi-dimensional overcurrent fault determination mechanism combining hardware output immediate shutdown and register continuous abnormality is used to overcome the problems of difficulty in distinguishing between pre-drive transient abnormalities and permanent failures, as well as current spikes and real overcurrents. This avoids the mistaken prohibition of engine starting due to misjudgment of faults caused by a single register jump or current spike. The accuracy of pre-drive and overcurrent fault diagnosis and the reliability of engine safety protection are improved through drive-level hardware protection and multiple software verifications.

[0275] Based on the above embodiments, in an exemplary embodiment provided in this application, the specific implementation process of the above-mentioned position sensor fault determination strategy, motor reverse fault determination strategy, motor overspeed fault determination strategy, and speed deviation excessive fault determination strategy may further include the following steps, which are described in detail below:

[0276] The position sensor fault determination strategy includes: if the position sensor signal collected for the ninth preset number of consecutive times is outside the preset allowable range, and the number of failed restart attempts reaches the tenth preset number, then a position sensor fault is determined to have occurred.

[0277] Specifically, regarding the position sensor fault determination strategy, if the position sensor signal is detected to be outside the preset allowable range for the ninth preset number of consecutive (e.g., within 50ms) consecutively (e.g., within 50ms), and the motor immediately stops and attempts to restart for the tenth preset number of times (e.g., 3 times) and all restarts fail, then it is determined that the electronic oil pump has a position sensor fault.

[0278] The motor reversal fault determination strategy includes: if the motor's requested speed is greater than the fifth preset speed and the actual speed of the motor is less than the sixth preset speed, and the duration exceeds the seventeenth preset duration, then a motor reversal fault is determined to have occurred; wherein, the fifth preset speed is greater than the sixth preset speed, and the sixth preset speed is the negative value of the fifth preset speed.

[0279] Specifically, the strategy for determining motor reversal faults includes: if the requested motor speed is greater than the fifth preset speed (e.g., 50 rpm) and the actual motor speed is less than the sixth preset speed (-50 rpm), or the requested motor speed is less than the sixth preset speed (-50 rpm) and the actual motor speed is greater than the fifth preset speed (e.g., 50 rpm), and the duration exceeds the seventeenth preset duration (e.g., 500 ms), then the electronic oil pump is determined to have a motor reversal fault. Here, the fifth preset speed is greater than the sixth preset speed, and the sixth preset speed is a negative value of the fifth preset speed.

[0280] The motor overspeed fault determination strategy includes: if the detected motor speed feedback value is greater than the seventh preset speed and the duration exceeds the eighteenth preset duration, then a motor overspeed fault is determined to have occurred.

[0281] Specifically, the strategy for determining motor speed faults may include: if the motor speed is detected to be greater than the seventh preset speed (e.g., 6000 rpm) and the duration exceeds the eighteenth preset duration (e.g., 50 ms), then the electronic oil pump is determined to have a motor overspeed fault.

[0282] The fault determination strategy for excessive speed deviation includes: if the difference between the motor speed command value and the speed feedback value is greater than the eighth preset speed and the duration exceeds the nineteenth preset duration, then an excessive speed deviation fault is determined to have occurred.

[0283] Specifically, the fault determination strategy for speed deviation may also include: if the difference between the motor speed command value and the speed feedback value is greater than the eighth preset speed (e.g., 500 rpm) and the overspeed time exceeds the nineteenth preset duration (e.g., 5s), then it is determined that the electronic oil pump has a fault of excessive speed deviation.

[0284] Furthermore, after determining that the electronic oil pump has a fault of excessive speed deviation, the above-mentioned protection strategies for different faults of the electronic oil pump, which are preset, can be used to perform corresponding protection actions and post-fault handling measures for the fault, such as: maintaining the current maximum speed / torque output of the motor, and restoring normal operation when the difference between the speed command and the feedback speed is less than 500 rpm; limiting the engine speed to 1500 rpm by the engine control system (EMS).

[0285] Optional, please refer to Figure 5 , Figure 5 This is a schematic diagram illustrating the processing flow for position sensor faults, reversal faults, and overspeed faults provided in the embodiments of this application, as shown below. Figure 5 As shown, position sensor faults, motor reverse rotation faults, and overspeed faults all employ a cumulative counting mechanism. Taking the position sensor as an example, a fault is triggered when the position sensor signal is detected as being outside the allowable range five consecutive times (within 50ms). The motor immediately stops and attempts to restart three times; only if all three restarts fail is a fault reported. After each trigger, the fault is automatically cleared after a 1-second delay to attempt recovery, and the fault cumulative count is incremented by 1. If normal operation resumes within one minute, the cumulative count is reset to zero. When the cumulative count reaches 20, the fault is upgraded to a permanent fault, requiring a power-off to recover.

[0286] In the embodiments provided in this application, the problem of difficulty in distinguishing between sensor signal jitter, transient motor reversal, overspeed or speed deviation and real faults is overcome by using a multi-dimensional threshold duration determination mechanism that combines the determination of continuous over-limit and restart failure of position sensor and motor reversal, motor reversal, overspeed or speed deviation. This avoids the mistaken judgment of fault due to a single abnormal signal or instantaneous speed deviation, which would lead to the incorrect prohibition of engine starting. The accuracy of fault diagnosis of abnormal motor operation and the reliability of engine safety protection are improved by combining multiple conditions and using graded threshold determination.

[0287] In summary, please refer to Figure 6 , Figure 6 A simplified flowchart illustrating the electronic oil pump fault diagnosis and post-processing logic provided in this application embodiment is shown below. Figure 6 As shown, after the system is powered on and initialized, the electronic oil pump is monitored in parallel, including at least four branch fault monitoring, specifically: branch A: power supply fault monitoring, branch B: temperature fault detection, branch C: communication fault detection, and branch D: motor operation fault monitoring, that is, motor operation fault monitoring that drives the electronic oil pump. Then, it is determined whether the motor is running. If the engine is running, further parallel monitoring of operational faults is performed. These operational faults include stall faults, pre-drive faults, overcurrent faults, position sensor faults, reverse rotation faults, overspeed faults, and excessive speed deviation faults. The system checks if any faults are triggered. If so, the corresponding fault protection action is executed, and it is determined whether self-diagnosis mode is enabled. If so, the corresponding electronic oil pump self-diagnosis process is executed. If not, it is determined whether the fault has been resolved. If the fault is resolved during the electronic oil pump self-diagnosis process, the corresponding fault flag is cleared. If the fault has not been resolved, it is determined whether to report to the Engine Management System (EMS). If reporting to the EMS is required, the corresponding fault code is sent to cause the EMS to perform engine torque limiting or shutdown. If reporting to the EMS is not required, the protection state is maintained, and continuous monitoring continues. The specific implementation process is as described in the above embodiments and will not be repeated here.

[0288] Figure 7 This is a schematic diagram of the fault handling device for the electronic oil pump of a hybrid power engine provided in the embodiments of this application, as shown below. Figure 7 As shown, the fault handling device 70 for the electric oil pump of the hybrid power engine provided in this embodiment includes: an acquisition module 710, used to acquire multi-parameter monitoring data related to the electric oil pump during the operation of the electric oil pump; a first processing module 720, used to determine the fault of the electric oil pump according to the multi-parameter monitoring data and a preset fault determination strategy; and a second processing module 730, used to perform corresponding protection actions and post-fault handling measures for the fault according to the preset protection strategies for different faults of the electric oil pump.

[0289] In one feasible embodiment, the fault determination strategy includes at least one of the following:

[0290] Power supply fault diagnosis strategy;

[0291] Temperature fault diagnosis strategy;

[0292] Communication failure detection strategy;

[0293] Motor fault diagnosis strategy;

[0294] The motor operation fault determination strategy includes at least one of the following: stall fault determination strategy, pre-drive or overcurrent fault determination strategy, position sensor fault determination strategy, motor reverse fault determination strategy, motor overspeed fault determination strategy, and excessive speed deviation fault determination strategy.

[0295] In one possible embodiment, the second processing module 730 described above is further configured to:

[0296] The electronic oil pump is stopped, and its forward and reverse rotation is repeated once to determine if it is stuck.

[0297] If the electronic oil pump is determined to still have a stall fault, the stall fault is reported to the EMS, the output of the electronic oil pump is cut off, and after the first preset time, the electronic oil pump is controlled to perform a self-diagnosis process to determine whether the fault is cleared or upgraded to a permanent fault.

[0298] If the stall fault escalates into a permanent fault and the vehicle is not powered on or off again, report to EMS that the engine should not be started.

[0299] If the stall fault is cleared, the self-diagnostic process will exit.

[0300] In one possible embodiment, the self-diagnostic process of the above-mentioned electronic oil pump includes:

[0301] Perform a reverse test for a second preset duration at a first preset speed, and after stopping for a third preset duration, perform a forward test for a second preset duration at the first preset speed, and after stopping for a third preset duration, check whether the electronic oil pump triggers a shutdown fault again;

[0302] After the electronic oil pump triggered a shutdown fault again, an attempt was made to restart it;

[0303] If the number of startup failures exceeds the first preset number, the electronic oil pump self-diagnosis process will be entered again after the first preset time, and the number of failures will be accumulated once. When the number of failures reaches the second preset number, the stall fault will be upgraded to a permanent fault.

[0304] If the number of failed starts is less than the first preset number and the start attempt is successful, or if the electronic oil pump does not trigger the shutdown fault again, then the fault is cleared.

[0305] In one possible embodiment, the second processing module 730 described above is further configured to:

[0306] The fault is either a pre-drive fault or an overcurrent fault; based on the preset protection strategy for different faults of the electronic oil pump, corresponding protection actions and post-fault handling measures are executed, including:

[0307] The controller hardware stops outputting;

[0308] Control the motor to stop rotating, and then control the motor to try rotating again at the currently requested speed;

[0309] If the number of times the motor fails to rotate reaches the third preset number, a pre-drive or overcurrent fault will be reported to the EMS, and after the fourth preset time, the electronic oil pump will be controlled to perform a self-diagnosis process to determine whether the fault is cleared or upgraded to a permanent fault.

[0310] If a pre-drive or overcurrent fault escalates to a permanent fault and the vehicle is not powered on or off again, report to EMS to stop the engine and prevent it from starting.

[0311] If the pre-drive or overcurrent fault is cleared, the self-diagnostic process will exit.

[0312] In one possible embodiment, the self-diagnostic process of the above-mentioned electronic oil pump includes:

[0313] After the electronic oil pump is controlled to run at the second preset speed for a fifth preset time, it stops for a sixth preset time, and the system checks whether the electronic oil pump triggers a shutdown fault again during the operation.

[0314] After the electronic oil pump triggered a shutdown fault again, an attempt was made to restart it;

[0315] If the number of startup failures exceeds the fourth preset number, the electronic oil pump will re-enter the self-diagnosis process after the seventh preset time, and the number of failures will be accumulated once. When the number of failures reaches the fifth preset number, the pre-drive failure will be upgraded to a permanent failure.

[0316] If the number of failed startup attempts is less than the fourth preset number and the startup attempt is successful, or if the electronic oil pump does not trigger a shutdown fault again during operation, then the fault is confirmed to be cleared.

[0317] In one possible embodiment, the aforementioned fault is any one of a position sensor fault, a motor reverse rotation fault, or a motor overspeed fault. The second processing module 730 is further configured to...

[0318] Control the electronic oil pump to stop running, and then control the electronic oil pump to attempt to restart it again according to the current request;

[0319] If the number of failed restart attempts reaches the sixth preset number, a fault is reported to EMS to stop the engine and prevent starting, and the fault count is accumulated once. When the number of faults reaches the seventh preset number, the pre-drive fault is determined to be upgraded to a permanent fault.

[0320] If the restart attempt is successful or the number of failures is less than the sixth preset number and normal operation is restored, then the fault is confirmed to be cleared.

[0321] In one possible embodiment, the aforementioned fault is a communication fault; the second processing module 730 is further configured to,

[0322] The electronic oil pump is controlled to run at the maximum permissible speed for a first preset number of message cycles, and then the machine is stopped after all message cycles are completed. The communication fault is then checked again to see if it has been eliminated and communication has been restored.

[0323] If the communication failure is cleared and communication is restored, the electronic oil pump will resume operation, and the engine will resume operation.

[0324] If the communication failure is not cleared or communication is not restored, the system will report to the EMS to control the engine to stop and prevent it from starting.

[0325] In one possible embodiment, the communication failure includes any one of the following: CAN bus off failure, CRC check failure, RollingCnt failure, and node loss failure.

[0326] Communication failure detection strategies include:

[0327] After power-on, communication fault detection is initiated after the eighth preset time. If continuous recovery fails according to the preset recovery cycle, and the number of failures reaches the eighth preset number, a CAN bus off fault is determined.

[0328] If a CRC check error occurs in the received CAN bus communication data for a second preset number of consecutive message cycles, a CRC check failure is determined to have occurred.

[0329] If the received CAN bus communication data shows a RollingCnt value error for the third consecutive preset number of message cycles, then a RollingCnt fault is confirmed.

[0330] In hardware wake-up mode, if a message with a preset ID is not received for the fourth preset number of message cycles, a node loss fault is determined to have occurred.

[0331] In one possible embodiment, the temperature fault determination strategy includes:

[0332] If the temperature value collected by the temperature sensor is greater than the first preset temperature or less than the second preset temperature for a period of time that exceeds the ninth preset duration, then the temperature sensor is determined to be faulty.

[0333] If the temperature sensor is not malfunctioning, and the collected temperature value is greater than the third preset temperature for a duration exceeding the tenth preset duration, then an over-temperature frequency reduction fault is determined to have occurred.

[0334] If the collected temperature value exceeds the fourth preset temperature and the duration exceeds the eleventh preset duration, an over-temperature shutdown fault is determined to have occurred.

[0335] Among them, the first preset temperature is greater than the fourth preset temperature, the fourth preset temperature is greater than the third preset temperature, and the third preset temperature is greater than the second preset temperature.

[0336] In one possible embodiment, the second processing module 730 described above is further configured to:

[0337] After confirming a temperature sensor malfunction, the electronic oil pump speed is controlled to be limited to below the third preset speed, and the EMS is notified to limit the engine speed to below the fourth preset speed, which is less than the third preset speed.

[0338] After confirming the overheating and frequency reduction fault, the control electronic oil pump limits the maximum speed to below the third preset speed, and restores the motor speed after the collected temperature value drops to the fifth preset temperature value. The fifth preset temperature value is less than the third preset temperature value and greater than the second preset temperature value.

[0339] After confirming an overheating shutdown fault, the electronic oil pump is stopped, and the EMS is notified to stop the engine and prevent it from starting.

[0340] In one possible embodiment, the power failure determination strategy includes:

[0341] If the power supply voltage of the electronic oil pump is greater than the first voltage threshold and the duration exceeds the twelfth preset duration, then a power supply overvoltage fault is determined.

[0342] If the power supply voltage of the electronic oil pump is less than the second voltage threshold and the duration exceeds the twelfth preset duration, then a power undervoltage fault is determined.

[0343] The second voltage threshold is less than the first voltage threshold.

[0344] In one possible embodiment, the second processing module 730 described above is further configured to:

[0345] If a power overvoltage fault is detected, it is reported to the EMS and the motor is controlled to continue running according to the current request; after the power supply voltage of the electronic oil pump drops to the third voltage threshold and remains there for a thirteenth preset time, the power overvoltage fault is cleared, and the third voltage threshold is greater than the second voltage threshold and less than the first voltage threshold.

[0346] If a power supply undervoltage fault is detected, it is reported to the EMS and the motor is controlled to continue running according to the current request; after the power supply voltage of the electronic oil pump rises to the fourth voltage threshold and continues for the fourteenth preset time, the power supply overvoltage fault is cleared, and the fourth voltage threshold is greater than the second voltage threshold and less than the third voltage threshold.

[0347] In one possible embodiment, the stall failure determination strategy includes:

[0348] If, during motor operation, the motor speed is lower than the preset minimum speed and the combined current of the motor is greater than the first current threshold for more than eight preset control cycles, then a stall fault is determined to have occurred.

[0349] In one possible embodiment, the pre-drive or overcurrent fault determination strategy includes:

[0350] If the highest preset bit of the pre-drive status register is abnormal, or the chip voltage is higher than the fifth voltage threshold, or the chip voltage is lower than the sixth voltage threshold, the hardware output is turned off, and if the duration of the abnormality detected in the pre-drive status register exceeds the fifteenth preset duration, a pre-drive fault is determined to have occurred.

[0351] If the duration of the motor winding phase current being greater than the second current threshold exceeds the sixteenth preset duration, or if the hardware overcurrent comparator output is valid, or if there is an abnormality in the six MOSFET overcurrent detection bits of the pre-drive status register, then an overcurrent fault is confirmed to have occurred.

[0352] In one possible embodiment, the position sensor fault determination strategy includes: if the position sensor signal collected for the ninth preset number of consecutive times is outside the preset allowable range, and the number of failed restart attempts reaches the tenth preset number, then a position sensor fault is determined to have occurred.

[0353] The motor reversal fault determination strategy includes: if the motor's requested speed is greater than the fifth preset speed and the actual speed is less than the sixth preset speed, and the duration exceeds the seventeenth preset duration, then a motor reversal fault is determined to have occurred; wherein, the fifth preset speed is greater than the sixth preset speed, and the sixth preset speed is a negative value of the fifth preset speed;

[0354] The motor overspeed fault determination strategy includes: if the detected motor speed feedback value is greater than the seventh preset speed and the duration exceeds the eighteenth preset duration, then a motor overspeed fault is determined to have occurred.

[0355] The fault determination strategy for excessive speed deviation includes: if the difference between the motor speed command value and the speed feedback value is greater than the eighth preset speed and the duration exceeds the nineteenth preset duration, then an excessive speed deviation fault is determined to have occurred.

[0356] The fault handling device for the electronic oil pump of the hybrid power engine provided in this embodiment can execute the method provided in the above method embodiment. Its implementation principle and technical effect are similar, and will not be described in detail here.

[0357] Figure 8 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Figure 8 As shown, the electronic device 80 provided in this embodiment includes at least one processor 810 and a memory 820. Optionally, the electronic device 80 further includes a communication component 830. The processor 810, memory 820, and communication component 830 are connected via a bus 840.

[0358] In the specific implementation process, at least one processor 810 executes computer execution instructions stored in memory 820, causing at least one processor 810 to execute the above-mentioned fault handling method for the electric oil pump of the hybrid power engine.

[0359] The specific implementation process of processor 810 can be found in the above method embodiments, and its implementation principle and technical effect are similar. It will not be repeated here.

[0360] In the above embodiments, it should be understood that the processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), etc. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in this invention can be directly implemented by a hardware processor, or implemented by a combination of hardware and software modules within the processor.

[0361] The memory may include random access memory (RAM) and may also include non-volatile memory (NVM), such as at least one disk storage device.

[0362] The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized as address buses, data buses, control buses, etc. For ease of illustration, the buses shown in the accompanying drawings are not limited to a single bus or a single type of bus.

[0363] This application also provides a hybrid vehicle, including: a hybrid engine equipped with an electronic oil pump and the aforementioned electronic equipment.

[0364] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the above-described fault handling method for the electronic oil pump of a hybrid power engine.

[0365] This application also provides a computer-readable storage medium storing computer-executable instructions. When a processor executes the computer-executable instructions, it implements the above-described fault handling method for the electronic oil pump of a hybrid power engine.

[0366] The aforementioned readable storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. The readable storage medium can be any available medium accessible to a general-purpose or special-purpose computer.

[0367] An exemplary readable storage medium is coupled to a processor, enabling the processor to read information from and write information to the readable storage medium. Of course, the readable storage medium can also be a component of the processor. The processor and the readable storage medium can reside in an application-specific integrated circuit (ASIC). Alternatively, the processor and the readable storage medium can exist as discrete components in the device.

[0368] The division of units is merely a logical functional division; in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be indirect coupling or communication connection through some interfaces, devices, or units, and may be electrical, mechanical, or other forms.

[0369] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0370] In addition, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0371] If a function is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0372] Those skilled in the art will understand that all or part of the steps of the above-described method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When executed, the program performs the steps of the above-described method embodiments; and the aforementioned storage medium includes various media capable of storing program code, such as ROM, RAM, magnetic disks, or optical disks.

[0373] Finally, it should be noted that other embodiments of the invention will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This invention is intended to cover any variations, uses, or adaptations of the invention that follow the general principles of the invention and include common knowledge or customary techniques in the art not disclosed herein, and is not limited to the precise structures described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope.

Claims

1. A troubleshooting method for an electronic oil pump in a hybrid powertrain engine, characterized in that, include: During the operation of the electronic oil pump, multi-parameter monitoring data related to the electronic oil pump are acquired; Based on the multi-parameter monitoring data and the preset fault judgment strategy, the fault of the electronic oil pump is determined; Based on the preset protection strategies for different faults of the electronic oil pump, corresponding protection actions and post-fault handling measures are executed for the faults.

2. The method according to claim 1, characterized in that, The fault diagnosis strategy includes at least one of the following: Power supply fault diagnosis strategy; Temperature fault diagnosis strategy; Communication failure detection strategy; Motor fault diagnosis strategy; The motor operation fault determination strategy includes at least one of the following: stall fault determination strategy, pre-drive or overcurrent fault determination strategy, position sensor fault determination strategy, motor reverse fault determination strategy, motor overspeed fault determination strategy, and excessive speed deviation fault determination strategy.

3. The method according to claim 1 or 2, characterized in that, The fault is a stall fault; The method of implementing corresponding protection actions and post-fault handling measures for different faults of the electronic oil pump according to the preset protection strategy includes: The electronic oil pump is controlled to stop running, and then the electronic oil pump is controlled to rotate in both directions once to determine whether it is stuck. If the electronic oil pump is determined to still have a stall fault, the stall fault is reported to the EMS, the output of the electronic oil pump is cut off, and after a first preset time, the electronic oil pump is controlled to perform a self-diagnosis process to determine whether the fault is cleared or upgraded to a permanent fault. If the stall fault escalates into a permanent fault and the vehicle is not powered on or off again, a report is sent to the EMS prohibiting engine starting. If the stall fault is cleared, the self-diagnostic process will exit.

4. The method according to claim 3, characterized in that, The self-diagnostic process of the electronic oil pump includes: The reverse rotation test is performed at a first preset speed for a second preset duration, and after stopping for a third preset duration, the forward rotation test is performed at the first preset speed for a second preset duration, and after stopping for the third preset duration, it is detected whether the electronic oil pump triggers a shutdown fault again. An attempt was made to restart the electronic oil pump after it triggered a shutdown fault again. If the number of startup failures exceeds the first preset number, the electronic oil pump self-diagnosis process will be entered again after the first preset time, and the number of failures will be accumulated once. When the number of failures reaches the second preset number, the stall fault will be upgraded to a permanent fault. If the number of failed startup attempts is less than the first preset number and the startup attempt is successful, or if the electronic oil pump does not trigger a shutdown fault again, then the fault is determined to be cleared.

5. The method according to claim 1 or 2, characterized in that, The fault is either a pre-drive or overcurrent fault; the protection strategy for different faults of the preset electronic oil pump, which executes corresponding protection actions and post-fault handling measures for the fault, includes: The controller hardware stops outputting; Control the motor to stop rotating, and then control the motor to attempt to rotate again at the currently requested speed; If the number of times the motor fails to rotate reaches the third preset number, a pre-drive or overcurrent fault is reported to the EMS, and after the fourth preset time, the electronic oil pump is controlled to perform a self-diagnosis process to determine whether the fault is cleared or upgraded to a permanent fault. If the pre-drive or overcurrent fault escalates to a permanent fault and the vehicle is not powered on or off again, report to EMS to stop the engine and prevent it from starting. If the pre-drive or overcurrent fault is cleared, the self-diagnostic process exits.

6. The method according to claim 5, characterized in that, The self-diagnostic process of the electronic oil pump includes: After the electronic oil pump is controlled to run at the second preset speed for a fifth preset time, it stops for a sixth preset time, and the system checks whether the electronic oil pump triggers a shutdown fault again during the operation. An attempt was made to restart the electronic oil pump after it triggered a shutdown fault again. If the number of startup failures exceeds the fourth preset number, the electronic oil pump will re-enter the self-diagnosis process after the seventh preset time, and the number of failures will be accumulated once. When the number of failures reaches the fifth preset number, the pre-drive failure will be upgraded to a permanent failure. If the number of failed startup attempts is less than the fourth preset number and the startup attempt is successful, or if the electronic oil pump does not trigger a shutdown fault again during operation, then the fault is determined to be cleared.

7. The method according to claim 1 or 2, characterized in that, The fault is any one of a position sensor fault, a motor reverse rotation fault, or a motor overspeed fault; the step of executing corresponding protection actions and post-fault handling measures for the fault according to the preset protection strategy for different faults of the electronic oil pump includes: The electronic oil pump is controlled to stop running, and then the electronic oil pump is controlled to attempt to restart again according to the current request; If the number of failed restart attempts reaches the sixth preset number, a fault is reported to the EMS to stop the engine and prevent starting, and the fault count is accumulated once. When the number of faults reaches the seventh preset number, the pre-drive fault is determined to be upgraded to a permanent fault. If the restart attempt is successful or the number of failures is less than the sixth preset number and normal operation is restored, then the fault is determined to be cleared.

8. The method according to claim 2, characterized in that, The fault is a communication fault; the step of executing corresponding protection actions and post-fault handling measures for the fault according to the preset protection strategy for different faults of the electronic oil pump includes: The electronic oil pump is controlled to run at the maximum permissible speed for a first preset number of message cycles, and then stopped after all message cycles have been executed. The system then checks again to see if the communication fault has been eliminated and communication has been restored. If the communication failure is cleared and communication is restored, the electronic oil pump is controlled to resume operation, and the engine is controlled to resume operation. If the communication failure is not cleared or communication is not restored, a report will be sent to the EMS to control the engine to stop and prevent it from starting.

9. The method according to claim 8, characterized in that, The communication failures include any one of the following: CAN bus off failure, CRC check failure, RollingCnt failure, and node loss failure. The communication failure determination strategy includes: After power-on, communication fault detection is initiated after the eighth preset time. If continuous recovery fails according to the preset recovery cycle, and the number of failures reaches the eighth preset number, a CAN bus off fault is determined. If a CRC check error occurs in the received CAN bus communication data for a second preset number of consecutive message cycles, a CRC check failure is determined to have occurred. If the received CAN bus communication data shows a RollingCnt value error for the third consecutive preset number of message cycles, then a RollingCnt fault is confirmed. In hardware wake-up mode, if a message with a preset ID is not received for the fourth preset number of message cycles, a node loss fault is determined to have occurred.

10. The method according to claim 2, characterized in that, The temperature fault determination strategy includes: If the temperature value collected by the temperature sensor is greater than the first preset temperature or less than the second preset temperature for a period of time that exceeds the ninth preset duration, then the temperature sensor is determined to be faulty. If the temperature sensor is not malfunctioning, and the collected temperature value is greater than the third preset temperature for a duration exceeding the tenth preset duration, then an over-temperature frequency reduction fault is determined to have occurred. If the collected temperature value exceeds the fourth preset temperature and the duration exceeds the eleventh preset duration, an over-temperature shutdown fault is determined to have occurred. Among them, the first preset temperature is greater than the fourth preset temperature, the fourth preset temperature is greater than the third preset temperature, and the third preset temperature is greater than the second preset temperature.

11. The method according to claim 10, characterized in that, The method of implementing corresponding protection actions and post-fault handling measures for different faults of the electronic oil pump according to the preset protection strategy includes: After determining that the temperature sensor is faulty, the speed of the electronic oil pump is controlled to be limited to below a third preset speed, and the EMS is reported to limit the engine speed to below a fourth preset speed, which is less than the third preset speed; After confirming the overheating and frequency reduction fault, the control electronic oil pump limits the maximum speed to below the third preset speed, and restores the motor speed after the collected temperature value drops to the fifth preset temperature value. The fifth preset temperature value is less than the third preset temperature value and greater than the second preset temperature value. After confirming an overheating shutdown fault, the electronic oil pump is stopped, and the EMS is notified to stop the engine and prevent it from starting.

12. The method according to claim 2, characterized in that, The power supply fault determination strategy includes: If the power supply voltage of the electronic oil pump is greater than the first voltage threshold and the duration exceeds the twelfth preset duration, then a power supply overvoltage fault is determined. If the power supply voltage of the electronic oil pump is less than the second voltage threshold and the duration exceeds the twelfth preset duration, then a power undervoltage fault is determined. The second voltage threshold is less than the first voltage threshold.

13. The method according to claim 12, characterized in that, The method of implementing corresponding protection actions and post-fault handling measures for different faults of the electronic oil pump according to the preset protection strategy includes: If a power overvoltage fault is detected, it is reported to the EMS and the motor is controlled to continue running according to the current request; and after the power supply voltage of the electronic oil pump drops to the third voltage threshold and remains there for a thirteenth preset time, the power overvoltage fault is cleared, wherein the third voltage threshold is greater than the second voltage threshold and less than the first voltage threshold. If a power supply undervoltage fault is detected, it is reported to the EMS and the motor is controlled to continue running according to the current request; and after the power supply voltage of the electronic oil pump rises to the fourth voltage threshold and continues for the fourteenth preset time, it is determined that the power supply overvoltage fault is cleared, wherein the fourth voltage threshold is greater than the second voltage threshold and less than the third voltage threshold.

14. The method according to claim 2, characterized in that, The stall fault determination strategy includes: If, during motor operation, the motor speed is lower than the preset minimum speed and the combined current of the motor is greater than the first current threshold for more than eight preset control cycles, then a stall fault is determined to have occurred.

15. The method according to claim 2, characterized in that, The pre-drive or overcurrent fault determination strategy includes: If the highest preset bit of the pre-drive status register is abnormal, or the chip voltage is higher than the fifth voltage threshold, or the chip voltage is lower than the sixth voltage threshold, the hardware output is turned off, and if the duration of the abnormality detected in the pre-drive status register exceeds the fifteenth preset duration, a pre-drive fault is determined to have occurred. If the duration of the motor winding phase current being greater than the second current threshold exceeds the sixteenth preset duration, or if the hardware overcurrent comparator output is valid, or if there is an abnormality in the six MOSFET overcurrent detection bits of the pre-drive status register, then an overcurrent fault is confirmed to have occurred.

16. The method according to claim 2, characterized in that, The position sensor fault determination strategy includes: if the position sensor signal collected for the ninth preset number of consecutive times is outside the preset allowable range, and the number of failed restart attempts reaches the tenth preset number, then a position sensor fault is determined to have occurred. The motor reversal fault determination strategy includes: if the motor's requested speed is greater than the fifth preset speed and the actual speed of the motor is less than the sixth preset speed, and the duration exceeds the seventeenth preset duration, then a motor reversal fault is determined to have occurred; wherein, the fifth preset speed is greater than the sixth preset speed, and the sixth preset speed is a negative value of the fifth preset speed; The motor overspeed fault determination strategy includes: if the detected motor speed feedback value is greater than the seventh preset speed and the duration exceeds the eighteenth preset duration, then it is determined that a motor overspeed fault has occurred. The fault determination strategy for excessive speed deviation includes: if the difference between the motor speed command value and the speed feedback value is greater than the eighth preset speed and the duration exceeds the nineteenth preset duration, then it is determined that an excessive speed deviation fault has occurred.

17. A fault handling device for an electronic oil pump for a hybrid power engine, characterized in that, include: The acquisition module is used to acquire multi-parameter monitoring data related to the electronic oil pump during operation. The first processing module is used to determine the fault of the electronic oil pump based on the multi-parameter monitoring data and the preset fault determination strategy. The second processing module is used to perform corresponding protection actions and post-fault handling measures for different faults of the preset electronic oil pump.

18. An electronic device, characterized in that, include: Memory, processor, and interface; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory, causing the processor to perform the method as described in any one of claims 1 to 16.

19. A hybrid vehicle, characterized in that, include: A hybrid engine equipped with an electronic oil pump and the electronic device as described in claim 18.

20. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the method as described in any one of claims 1 to 16.