Degraded operation and fault recovery control method after a position sensor failure

CN122600802APending Publication Date: 2026-08-18TOP GEAR POWERTRAIN TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610815989.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-06-08
Publication Date
2026-08-18

AI Technical Summary

Technical Problem

[0004]第一类是故障停机方式:当检测到位置传感器故障时,直接执行高级别故障停机,且故障状态不可自动恢复,需要人工复位

Benefits of technology

1.本发明提供了一种位置传感器故障后的降级运行与故障恢复控制方法,通过设置故障判定阈值与恢复一致性阈值构成迟滞带,使得故障判定与恢复判定之间形成非对称的判定门槛。这种非对称性从结构上避免了临界偏差状态下位置传感器信号稍有波动就反复触发故障判定和恢复判定的模式振荡,克服了现有技术中使用单一阈值或仅依赖信号状态判定所导致的临界振荡缺陷。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122600802A_ABST
    Figure CN122600802A_ABST
Patent Text Reader

Abstract

The application provides a degradation operation and fault recovery control method after a position sensor failure. It includes: maintaining a first position acquisition path based on position sensor feedback signals and a second position acquisition path based on motor electrical quantities; presetting a fault determination threshold greater than a recovery consistency threshold to form a hysteresis band; performing fault detection including double-path position cross-checking, switching to a degraded operation mode and applying derating when a fault occurs, and increasing a fault frequency counter by one; returning to a normal mode only when the fault detection continuously indicates normal and the double-path positions are consistent; when the counter reaches a threshold within a sliding statistical time window, prohibiting subsequent recovery and entering a permanent fault state, in which the degraded operation is maintained. The application solves the problems of high risk of false recovery and difficult suppression of mode oscillation in existing solutions through the cooperation of double-threshold asymmetric judgment, double-recovery confirmation and anti-oscillation upgrade, and realizes safe recovery and stable operation in the position sensor failure state.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of motor control technology, specifically to a method for degraded operation and fault recovery control after a position sensor failure. Background Technology

[0002] In the field-oriented control system of a permanent magnet synchronous motor, the motor controller relies on position sensors mounted on the motor shaft to obtain rotor position information in real time. Commonly used position sensors include rotary transformers, magnetic encoders, photoelectric encoders, and Hall effect sensors. During long-term operation, position sensors may experience momentary or permanent failures due to poor wiring harness contact, electromagnetic interference, mechanical vibration, or component aging.

[0003] In the existing technology, there are five typical ways to handle position sensor failures.

[0004] The first type is the fault shutdown method: when a position sensor fault is detected, a high-level fault shutdown is executed directly, and the fault state cannot be automatically recovered, requiring manual reset. The drawback of this method is that when the fault is caused by intermittent poor contact in the wiring harness or brief electromagnetic interference, it still causes the motor to stop directly, seriously affecting driving comfort; and when the sensor hardware permanently fails, the vehicle completely loses power and cannot actively limp to the repair location, increasing towing costs.

[0005] The second type is the dual-sensor redundancy method: two sets of position sensors and corresponding hardware decoding circuits are set on the same motor, and the system switches to the other set when one fails. This method adds an extra set of position sensors and hardware decoding circuits, significantly increasing hardware costs and complicating the structural layout, making it difficult to meet the constraints of automotive-grade motor controllers in terms of size and cost.

[0006] The third type involves retaining the hardware decoding circuit and adding software decoding as a backup path. This method switches to the software decoding path when the main decoding path fails, but it fails to fundamentally eliminate the dependence on the hardware decoding circuit, and the hardware cost is not effectively reduced.

[0007] The fourth category involves switching to a sensorless algorithm (hereinafter referred to as the sensorless algorithm) after a position sensor failure. Related technologies have proposed and implemented limp-out schemes for switching to the sensorless algorithm when the resolver (rotor transformer) fails. However, existing schemes of this type have the following main shortcomings: First, when switching to the sensorless algorithm, the internal observers of the sensorless algorithm (such as back EMF observers and stator flux linkage observers) are often in an unconverged initial state, requiring a certain amount of time to converge to the correct state. During this period, the position estimation error is relatively large, easily leading to current surges or torque pulsations at the moment of switching. Second, fault recovery determination relies solely on the state monitoring of the position sensor signal itself. In complex electromagnetic noise environments, when the sensor signal exhibits oscillations such as brief recovery followed by re-failure, simple recovery determination can easily trigger the motor to repeatedly switch between normal and degraded modes (i.e., mode oscillation), severely affecting system stability. Third, there is a lack of an automatic upgrade protection mechanism for mode oscillations; the system may continue to switch ineffectively between the two modes and cannot terminate when the sensor hardware continues to fail.

[0008] The fifth type involves using a signal selector to simultaneously maintain both sensored and sensorless control paths and switch between them. For example, a prior art limp controller for electric vehicles includes a sensorless speed and position estimator and a signal selector coupled to a resolver. This allows the use of the resolver signal when available, switching to sensorless signal control of the motor when the resolver fails, and, under certain conditions, initializing the sensorless system with the last known sensor position value before resuming sensored control. However, the recovery logic of these prior art technologies is based solely on the state detection of the position sensor signal and does not require consistency between the sensor output position and the sensorless estimated position. Therefore, there is a risk of false recovery when the signal recovers intermittently but the physical state is unstable. Furthermore, none of these prior art technologies propose cumulative count protection and fault escalation mechanisms for frequent mode switching, and cannot automatically terminate repeated mode oscillations in scenarios of continuous sensor failure.

[0009] In summary, existing solutions for handling position sensor failures have significant shortcomings and fail to meet the dual requirements of safe recovery and system stability. Summary of the Invention

[0010] To overcome the shortcomings of existing technologies, this invention proposes a method for degraded operation and fault recovery control after a position sensor failure, comprising: S1. In normal operating mode, maintain a first position acquisition path for obtaining the first rotor position θ1 and a second position acquisition path for obtaining the second rotor position θ2; The first position acquisition path obtains the first rotor position θ1 by soft decoding based on the feedback signal from the position sensor installed on the motor; the second position acquisition path obtains the second rotor position θ2 by estimating the electrical quantity of the motor using a sensorless algorithm; the first rotor position θ1 is used as the position input for the motor closed-loop control; S2. Preset fault determination threshold ε f and the recovery consistency threshold ε θ , and ε f >ε θ The ε f With the ε θ The difference constitutes the width (ε) f -ε θ The hysteresis band; S3. Periodically perform fault detection, the fault detection including a cross-validation term based on dual-path position consistency: when |θ1 - θ2| > ε f If the position sensor is found to be faulty, the system switches from the normal operation mode to the degraded operation mode, replaces the position input of the motor closed-loop control from the first rotor position θ1 to the second rotor position θ2, and applies a derating treatment to the motor. S4. Continue to perform fault detection and location consistency monitoring in the degraded operation mode; trigger fault self-recovery and switch back from the degraded operation mode to the normal operation mode if and only if the following two conditions are met simultaneously: The fault detection result is within a preset duration T. d Internal continuous indication is normal; |θ1-θ2|<ε θ ; S5. Set a fault count counter. Each time a switch occurs from the normal operation mode to the degraded operation mode, the fault count counter is incremented by one. The fault count counter is set within a preset statistical time window T. w Sliding update; when the fault count counter is in the statistical time window T w When the cumulative value reaches the preset threshold M, subsequent fault self-recovery is prohibited, and the system enters a permanent fault state. In the permanent fault state, the degraded operation mode is maintained, the second rotor position θ2 is used as the position input for the motor closed-loop control, and the derating process is maintained.

[0011] Furthermore, the consensus threshold ε θ The value range is from 3° to 10° electrical angle, and the fault determination threshold ε f The value range is from 10° to 30° electrical angle, and the hysteresis band width (ε) f -εθ The electrical angle shall not be less than 5°.

[0012] Furthermore, the duration T d Corresponding to N consecutive fault detection cycles, where N is an integer greater than or equal to 2; the statistical time window T w The value range is from 3 seconds to 600 seconds; the value range of the threshold M is from 2 to 5.

[0013] Furthermore, in addition to the cross-validation item, the fault detection also includes at least one of the following detection items: Amplitude detection: Calculate the energy envelope of the position sensor feedback signal, and determine it as an amplitude abnormality when it exceeds the preset upper limit of amplitude or falls below the preset lower limit of amplitude; Jump detection: Calculate the change in the position sensor feedback signal between adjacent sampling periods. When it exceeds the theoretical upper limit of the change corresponding to the current motor speed, it is determined to be an abnormal jump. Open circuit / short circuit detection: Detect whether the differential voltage of the feedback signal from the position sensor remains constant or zero within a preset time window; if so, it is determined to be an open circuit or short circuit abnormality. When any one of the at least one detections is determined to be abnormal, a logical OR is taken with the determination result of the cross-validation item to confirm that the position sensor is faulty.

[0014] Furthermore, the permanent fault state is a fault state that cannot be automatically recovered; after entering the permanent fault state, the motor controller maintains the torque output of the motor under the constraint of the derating process, and no longer executes the fault self-recovery determination in step S4, until it can re-enter the normal operation mode after being reset by an external command.

[0015] Furthermore, the fault count counter is updated in a sliding manner specifically by accumulating only the fault counts within the most recent statistical time window T. w The number of times the operation switches from the normal operating mode to the degraded operating mode occurs within the specified time period exceeds the specified T. w The duration of historical transitions is no longer counted.

[0016] Furthermore, during the process of switching back from the degraded operation mode to the normal operation mode, the position input θ used in the motor closed-loop control... use We obtain the weighted average by the following formula: θ use (t) = α(t)·θ2+(1-α(t))·θ1 The weight α(t) is within the preset transition time window T. transThe value decreases linearly from 1 to 0; simultaneously, the maximum allowable torque limit of the motor corresponding to the derating process increases linearly from the derating value to the normal value.

[0017] Furthermore, the derating process employs a differentiated derating strategy based on motor speed partitioning: Set a first speed threshold ω1 and a second speed threshold ω2, where ω1 > ω2; When the motor speed is greater than ω1, the maximum allowable torque of the motor is limited to a first proportion k1 of the normal value; When the motor speed is greater than or equal to ω2 and less than or equal to ω1, the second ratio k2 is limited to the normal value; When the motor speed is less than ω2, the third ratio k3 is limited to the normal value; Where k1>k2>k3≥0.

[0018] Furthermore, the motor controller is an electric vehicle drive motor controller; in the event of a permanent fault, the electric vehicle maintains its driving capability with a torque output subject to derating constraints.

[0019] Furthermore, the position sensor is a rotary transformer; the motor controller includes a main chip, which has a built-in digital Sigma-Delta analog-to-digital converter (DSADC); the first position acquisition path outputs an excitation signal to the rotary transformer through the main chip, and acquires the sinusoidal signals Sin+ / Sin- and cosine signals Cos+ / Cos- fed back by the rotary transformer in real time through the DSADC, and then uses a soft decoding algorithm to parse and obtain the first rotor position θ1; the electrical quantities include DC bus voltage and stator three-phase current.

[0020] Compared with the prior art, the beneficial effects of the present invention are: 1. This invention provides a method for degraded operation and fault recovery control after a position sensor failure. By setting a fault determination threshold and a recovery consistency threshold to form a hysteresis band, an asymmetric determination threshold is created between fault determination and recovery determination. This asymmetry structurally avoids the pattern oscillation where slight fluctuations in the position sensor signal under critical deviation conditions repeatedly trigger fault determination and recovery determination, overcoming the critical oscillation defects caused by using a single threshold or relying solely on signal state determination in existing technologies.

[0021] 2. This invention provides a method for degraded operation and fault recovery control after a position sensor failure, introducing |θ1 - θ2| < ε θAs a necessary condition, position consistency is incorporated into the fault recovery determination. This means that switching back to normal mode is only allowed when the position sensor signal is not only continuously normal at the signal level, but also when its decoded position result is consistent with the estimation result of the sensorless algorithm. This dual confirmation of "signal state" and "semantic consistency" solves the risk of erroneous recovery caused by triggering a switchback solely based on signal state recovery in existing technologies.

[0022] 3. This invention provides a method for degraded operation and fault recovery control after a position sensor failure. It employs an anti-oscillation mechanism combining a fault count counter and a sliding statistical time window to track the number of fault switching events within a certain time window in real time. When the number of switching events within the window reaches a threshold, subsequent recovery is automatically prohibited, and the system is locked in a permanent fault state of degraded operation. This terminates the infinite oscillation between the two operating modes in scenarios of continuous sensor failure, avoids the risk of frequent torque surges damaging the motor or powertrain, and retains the continuous torque output capability based on a positionless algorithm, allowing the vehicle to still limp to the repair location. This overcomes the shortcomings of existing technologies that directly shut down the vehicle, causing it to lose power, and compensates for the lack of such an automatic upgrade protection mechanism in existing technologies.

[0023] 4. This invention provides a method for degraded operation and fault recovery control after a position sensor failure. The dual-threshold recovery and anti-oscillation mechanism of this application is organically combined with the dual-path parallel operation architecture: the second position acquisition path is continuously maintained in the normal operation mode, and θ2 required for cross-verification is provided synchronously during the degraded operation, so that the position consistency recovery condition can be achieved with low overhead without introducing additional hardware or independent detection modules. Attached Figure Description

[0024] To more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the drawings used in the description of the specific embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0025] Figure 1 This is a schematic diagram illustrating the connection relationship between the motor controller and its external components provided in an embodiment of this application.

[0026] Figure 2 This is a flowchart illustrating the dual-threshold recovery and anti-oscillation control method for position sensor failure states provided in an embodiment of this application.

[0027] Figure 3 This is a schematic diagram illustrating the principle of dual-threshold hysteresis band provided in an embodiment of this application.

[0028] Figure 4 This is a schematic diagram of the operation mode switching provided in the embodiments of this application.

[0029] Figure 5 A schematic diagram of the anti-oscillation mechanism provided in the embodiments of this application. Detailed Implementation

[0030] The technical solution of the present invention will be more clearly and completely explained below with reference to the accompanying drawings and through the description of preferred embodiments of the present invention.

[0031] As one specific embodiment, such as Figure 1 As shown, the motor controller 11 provided in this embodiment includes a main chip 12 and a power drive stage 13; The main chip 12 has a built-in digital Sigma-Delta analog-to-digital converter module (DSADC module), and is equipped with an output port for outputting excitation signals to the position sensor 21, an input port for receiving feedback signals from the position sensor 21, a sampling circuit for acquiring the three-phase current at the motor 22, and a sampling circuit for acquiring the DC bus voltage. The power drive stage 13 outputs three-phase drive current to the motor 22 under the control of the main chip 12.

[0032] The position sensor 21 is mounted on the rotor shaft of the motor 22 and is mechanically coupled to the motor 22. In this embodiment, the position sensor 21 is a resolver. The motor controller 11 does not contain any external hardware decoding circuit. The decoding of the resolver feedback signal is completely completed by the software decoding algorithm running in the main chip 12, thereby reducing hardware costs and simplifying the system structure.

[0033] In an alternative implementation, the position sensor 21 can also be a magnetic encoder, photoelectric encoder or Hall sensor, and the main chip 12 can also be a processor without a DSADC module. In this case, differential signal acquisition can be achieved by ordinary ADC sampling combined with software Sinc filtering.

[0034] In normal operation mode, the main chip 12 of the motor controller 11 simultaneously maintains the first position acquisition path and the second position acquisition path. The first position acquisition path obtains the first rotor position θ1 based on the feedback signal from the position sensor 21 through a soft decoding algorithm: the main chip 12 outputs an excitation signal with a typical frequency of 10 kHz to the position sensor 21 through its output port. The position sensor 21 modulates the rotor position onto the feedback signals Sin+ / Sin- and Cos+ / Cos-. The main chip 12 acquires the feedback signal in real time through the DSADC module, and then obtains θ1 by the soft decoding algorithm. The soft decoding algorithm uses a combination of arctangent function and Type II phase-locked loop to output smooth and continuous angle and angular velocity signals. The second position acquisition path estimates the second rotor position θ2 based on the stator three-phase current and DC bus voltage of the motor 22 through a sensorless algorithm. In this embodiment, a composite sensorless algorithm segmented by speed is used: in the low-speed zone (motor speed is below the switching speed threshold ω)... s The high-frequency signal injection method is used in the medium-to-high speed range (motor speed not less than ω). s Using a sliding mode observer based on back electromotive force, the two algorithms are compared at ω. s Within the nearby transition range, a weighted fusion or hysteresis-based smooth transition is used to balance low-speed observability with medium-to-high-speed estimation accuracy. In alternative implementations, sliding mode observers, Luneburger observers, or extended Kalman filter observers can also be used individually across the entire speed range. In normal operation mode, the main chip 12 uses θ1 as the position input for the FOC closed-loop control of the motor 22, while θ2 continuously operates but does not directly participate in the control, serving as a redundant backup estimator.

[0035] like Figure 2 As shown, the main chip 12 uses a preset fault detection cycle T chk (Synchronized with the PWM carrier cycle, executed once per PWM cycle, with a typical PWM cycle of approximately 100 µs and a corresponding switching frequency of approximately 10 kHz) Periodically performs fault detection.

[0036] This embodiment presets a fault determination threshold ε f and the recovery consistency threshold ε θ , and ε f >ε θ ,like Figure 3 As shown, ε f With ε θ The difference constitutes the width (ε) f -ε θ The hysteresis band of ε. In this embodiment, ε θ The typical value is 5° electrical angle, ε f The typical value is 15° electrical angle, and the hysteresis band width is 10° electrical angle; in an alternative embodiment, εθ The value can be taken in the range of 3° to 10° electrical angle, ε f The value can be selected within the range of 10° to 30° electrical angle, and the hysteresis band width is not less than 5° electrical angle. This asymmetric dual-threshold design makes the fault determination trigger threshold higher than the recovery determination trigger threshold, structurally avoiding the mode oscillation phenomenon of the system repeatedly entering and exiting the degraded operation mode when the dual-path position deviation fluctuates near the critical value.

[0037] Fault detection includes a cross-validation term based on dual-path position consistency: when the angular deviation between the first rotor position θ1 and the second rotor position θ2 satisfies |θ1 - θ2| > ε f When the position sensor malfunctions, the system switches from normal operation mode to degraded operation mode. This cross-validation item fully utilizes the θ2 signal provided by the continuously maintained second position acquisition path during normal operation, enabling the identification of fault modes that are difficult to detect by other detection methods, such as slow drift of the resolver signal and temperature drift bias, with low additional overhead. In addition to the above cross-validation item, fault detection may also include one or more of the following: amplitude detection (calculating the energy envelope of Sin²+Cos², and determining that the amplitude is abnormal when it exceeds a preset upper limit or falls below a preset lower limit; in this embodiment, the upper limit is 1.2 times the rated energy envelope, and the lower limit is 0.5 times); jump detection (calculating the change in the resolver feedback signal between adjacent sampling periods, and determining that the jump is abnormal when it exceeds the theoretical change limit corresponding to the current motor speed); open circuit / short circuit detection (detecting whether the differential voltage between Sin+ and Sin- or Cos+ and Cos- falls within a preset time window T). disc The value of T remains constant or zero in this embodiment. disc (Typical value is 5 ms). If any of the above detection items is determined to be abnormal, the position sensor is confirmed to be faulty.

[0038] like Figure 4As shown, when a position sensor malfunction is confirmed, the main chip 12 switches from normal operation mode to degraded operation mode: the position input of the motor closed-loop control is replaced from θ1 to θ2; derating is applied to the motor; and a fault alarm is reported to the vehicle controller. In this embodiment, the peak motor speed is 12000 rpm. The derating process adopts a differentiated strategy based on motor speed partitioning, specifically: a first speed threshold ω1 = 8000 rpm (approximately 70% of the peak speed) and a second speed threshold ω2 = 8500 rpm are preset; when the motor speed is not greater than ω1, the maximum allowable torque of the motor is limited to 90% of the normal value; when the motor speed is between ω1 and ω2, the maximum allowable torque limit decreases linearly from 90% of the normal value to 0 as the speed increases; when the motor speed is not less than ω2, the maximum allowable torque limit is 0, that is, the motor speed in the degraded operation mode is constrained to approximately 8500 rpm through a zero torque upper limit. Within rpm, speed limiting protection is implemented in degraded operation mode; in the low and medium speed ranges, due to the use of a composite positionless algorithm of high-frequency injection and sliding mode observer, the position estimation observability is good, and only a 10% torque margin derating is applied; in the high speed range, the position estimation error has a greater impact on control safety, so a linear transition is adopted and it is eventually limited to zero torque, while avoiding the impact of a step change in torque limit on the powertrain; the above derating ratios satisfy k1>k2≥0, and in this embodiment, k1=90% and k2=0; in alternative embodiments, other continuous functions with speed as the independent variable can also be used instead of piecewise linear functions.

[0039] In degraded operation mode, the main chip continuously operates at a detection cycle T. chk Perform fault detection and continuously monitor |θ1-θ2|. Fault self-recovery is triggered, switching back from degraded operation mode to normal operation mode, only if both of the following conditions are met simultaneously: First, the fault detection result is within a preset duration T. d The continuous indication is normal, meaning that no abnormalities are detected in any of the fault detections within N consecutive detection cycles. In this embodiment, N typically takes the value of 50 to 100 PWM cycles, corresponding to a duration T. d Approximately 5 to 10 ms; second, |θ1-θ2|<ε θ This means that the angular deviation between the first rotor position and the second rotor position is less than the recovery consistency threshold. The first condition confirms the resolver feedback signal has returned to normal from the signal stability dimension, and the second condition confirms that the resolver decoding result has converged with the sensorless algorithm estimation result from the position semantic consistency dimension. Together, these two conditions constitute a dual guarantee at both the "signal level" and the "semantic level," resolving the risk of erroneous recovery caused by allowing a switchback solely based on signal state recovery in existing technologies. Because ε θ <ε f To restore the required positional deviation condition (|θ1-θ2|<ε) θThe positional deviation condition required to trigger the fault (|θ1-θ2|>ε) f The design is even more stringent, and this hysteresis band further prevents erroneous oscillations during the recovery process.

[0040] like Figure 5 As shown, based on the fault self-recovery mechanism, this embodiment further introduces an anti-oscillation mechanism. The main chip sets a fault count counter (Count). f The initial value is 0. Each time a switch occurs from normal operating mode to degraded operating mode, the count... f Add one. Count f Updated in a sliding manner, meaning only the most recent statistical time window T is accumulated. w The number of handovers occurring within the time limit exceeds T. w The duration of historical switching is no longer included in this embodiment. w The typical value is 10 seconds; under a long statistical window configuration, T w Alternatively, a time window of 300 seconds (5 minutes) or longer can be used, for example, a statistical time window of 300 seconds and a threshold M of 3. When Count f In T w When the cumulative value within the time window reaches a preset threshold M (in this embodiment, M is typically 3 times, i.e., triggered when the switch from normal operation mode to degraded operation mode occurs for the 3rd time within the statistical time window), the main chip immediately prohibits subsequent fault self-recovery and enters a permanent fault state: the motor controller maintains the degraded operation mode, continues to use the second rotor position θ2 estimated without a position algorithm as the position input and maintains the derating process, and no longer performs fault self-recovery judgment until it is reset by an external command before it can re-enter the normal operation mode. Through the anti-oscillation mechanism, the system retains automatic recovery capability in the event of intermittent sensor failure; when the sensor fails continuously and causes frequent switching, it promptly terminates mode oscillation and locks in degraded operation, which avoids torque mutation caused by repeated mode switching and retains the vehicle's limp driving capability.

[0041] To avoid impacting the motor control system during the transition from degraded operation mode back to normal operation mode due to abrupt changes in position input, this embodiment employs the following smooth transition process. Within a preset transition time window T... trans (Typically, the position input θ used in the motor closed-loop control is within 20 to 50 ms) use We obtain the weighted average by the following formula: θ use (t)=α(t)·θ2+(1-α(t))·θ1 Where the weight α(t) is in T transThe torque decreases linearly from 1 to 0; simultaneously, the maximum permissible torque limit of the motor increases linearly from the derating value to the normal value, avoiding the impact on the powertrain caused by a step increase in the torque limit. In an alternative implementation, the change curve of α(t) can also adopt a non-linear curve such as a cosine curve or an S-curve to obtain a smoother transition effect.

[0042] In a preferred embodiment, the sensorless algorithm in the second position acquisition path can use θ1 as a reference input during normal operation to periodically calibrate its internal observer state variables (such as back electromotive force observation value and stator flux linkage observation value), so that the sensorless algorithm is already in a convergent state when the degradation switch occurs, which helps to further improve the stability of the switch moment.

[0043] In alternative implementations for different sensor types, when the position sensor is a magnetic encoder or photoelectric encoder, the soft decoding of the first position acquisition path is changed to reading and verifying encoder data through a digital interface (such as SSI, BiSS-C, or SPI); when the position sensor is a Hall sensor, a position interpolation algorithm based on the commutation interval is used. In alternative implementations for different sensorless algorithms, the sensorless algorithm for the second position acquisition path can be replaced by a Luneburger observer, an extended Kalman filter observer, or a model reference adaptive observer; when using a high-frequency signal injection method in the low-speed region, the usable range of the degraded operation mode in the low-speed region can be further expanded, in conjunction with the speed partition derating strategy. The core logic of the dual-threshold recovery and anti-oscillation control method of this application does not change due to the different position sensor types or sensorless algorithm types.

[0044] The above-described specific embodiments are merely preferred embodiments of the present invention and are not intended to limit the scope of protection of the present invention. Various modifications, substitutions, and improvements made by those skilled in the art to the technical solutions of the present invention based on the provided textual description and drawings, without departing from the design concept and spirit of the present invention, should all fall within the scope of protection of the present invention. The scope of protection of the present invention is determined by the claims.

Claims

1. A method for degraded operation and fault recovery control after a position sensor failure, characterized in that, include: S1. In normal operating mode, maintain a first position acquisition path for obtaining the first rotor position θ1 and a second position acquisition path for obtaining the second rotor position θ2; The first position acquisition path obtains the first rotor position θ1 by software decoding based on the feedback signal from the position sensor installed on the motor; The second position acquisition path estimates the second rotor position θ2 based on the electrical quantities of the motor using a sensorless algorithm; The first rotor position θ1 is used as the position input for the motor closed-loop control; S2. Preset fault determination threshold ε f and the recovery consistency threshold ε θ , and ε f >ε θ The ε f With the ε θ The difference constitutes the width (ε) f -ε θ The hysteresis band; S3. Perform fault detection periodically; when |θ1-θ2|>ε f If other abnormalities are detected, the position sensor is determined to be faulty; in case of a fault, the system switches from normal operation mode to degraded operation mode, the position input is replaced by θ2 instead of θ1, and derating is applied to the motor. S4. Continuously perform fault detection and location consistency monitoring in degraded operation mode; if and only if T d The internal fault detection continuously indicates normal operation, and |θ1-θ2|<ε θ At this time, switch back to normal operating mode; S5. Set a fault count counter. Each time a switch occurs from the normal operation mode to the degraded operation mode, the fault count counter is incremented by one. The fault count counter is set within a preset statistical time window T. w Slide to update; When the fault count counter is in the statistical time window T w When the cumulative value reaches the preset threshold M, subsequent fault self-recovery is prohibited, and the system enters a permanent fault state. Under the permanent fault condition, the degraded operation mode is maintained, the second rotor position θ2 is continued as the position input for the motor closed-loop control, and the derating process is maintained.

2. The method for degraded operation and fault recovery control after a position sensor failure according to claim 1, characterized in that, The consensus threshold ε θ The value range is from 3° to 10° electrical angle, and the fault determination threshold ε f The value range is from 10° to 30° electrical angle, and the hysteresis band width (ε) f -ε θ Not less than 5° electrical angle; The duration T d Corresponding to N consecutive fault detection cycles, where N is an integer greater than or equal to 2; the statistical time window T w The value range is from 3 seconds to 600 seconds; the value range of the threshold M is from 2 to 5.

3. The method for degraded operation and fault recovery control after a position sensor failure according to claim 1, characterized in that, In addition to cross-validation items, the fault detection also includes at least one of the following detection items: Amplitude detection: Calculate the energy envelope of the position sensor feedback signal, and determine it as an amplitude abnormality when it exceeds the preset upper limit of amplitude or falls below the preset lower limit of amplitude; Jump detection: Calculate the change in the position sensor feedback signal between adjacent sampling periods. When it exceeds the theoretical upper limit of the change corresponding to the current motor speed, it is determined to be an abnormal jump. Open circuit / short circuit detection: Detect whether the differential voltage of the feedback signal from the position sensor remains constant or zero within a preset time window; if so, it is determined to be an open circuit or short circuit abnormality. If any one of the at least one tests is determined to be abnormal, a logical OR is taken with the determination result of the cross-validation item to confirm that the position sensor is faulty.

4. The method for degraded operation and fault recovery control after a position sensor failure according to claim 1, characterized in that, The permanent fault state is a fault state that cannot be automatically recovered. After entering the permanent fault state, the motor controller maintains the torque output of the motor under the constraint of derating and no longer executes the fault self-recovery determination in step S4. It can only re-enter the normal operation mode after being reset by an external command.

5. The method for degraded operation and fault recovery control after a position sensor failure according to claim 1, characterized in that, The fault count counter is updated in a sliding manner as follows: The fault count counter only accumulates the most recent statistical time window T. w The number of times the operation switches from the normal operating mode to the degraded operating mode occurs within the specified time period exceeds the specified T. w The duration of historical transitions is no longer counted.

6. The method for degraded operation and fault recovery control after a position sensor failure according to claim 1, characterized in that, During the process of switching back from the degraded operation mode to the normal operation mode, the position input θ used by the motor closed-loop control use We obtain the weighted average by the following formula: i use (t) =α(t)·θ2+(1-α(t))·θ1 The weight α(t) is within the preset transition time window T. trans The value decreases linearly from 1 to 0; simultaneously, the maximum allowable torque limit of the motor corresponding to the derating process increases linearly from the derating value to the normal value.

7. The method for degraded operation and fault recovery control after a position sensor failure according to claim 1, characterized in that, The derating process employs a differentiated derating strategy based on motor speed partitioning: Set a first speed threshold ω1 and a second speed threshold ω2, where ω1 > ω2; When the motor speed is greater than ω1, the maximum allowable torque of the motor is limited to a first proportion k1 of the normal value; When the motor speed is greater than or equal to ω2 and less than or equal to ω1, the second ratio k2 is limited to the normal value; When the motor speed is less than ω2, the third ratio k3 is limited to the normal value; Where k1>k2>k3≥0.

8. The method for degraded operation and fault recovery control after a position sensor failure according to claim 1, characterized in that, The motor controller is an electric vehicle drive motor controller; in the event of a permanent fault, the electric vehicle maintains its driving capability with a torque output constrained by the derating process.

9. The method for degraded operation and fault recovery control after a position sensor failure according to claim 1, characterized in that, The position sensor is a rotary transformer; The motor controller includes a main chip, which has a built-in digital analog-to-digital converter (DSADC). The first position acquisition path outputs an excitation signal to the rotary transformer through the main chip, and collects the sine and cosine signals fed back by the rotary transformer in real time through the DSADC, and then obtains the first rotor position θ1 by a soft decoding algorithm; The electrical quantities include DC bus voltage and stator three-phase current.