ENERGY SUPPLY SYSTEM

The power supply system addresses the issue of undetected current detector failures by using a switch, fuse, and fault detector to switch to alternate paths, ensuring safe power supply and cost-effectiveness.

DE102020213929B4Active Publication Date: 2025-12-31DENSO CORP
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
DE102020213929
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Priority Date
2019-11-22
Filing Date
2020-11-05
Publication Date
2025-12-31
Estimated Expiration
2040-11-05

AI Technical Summary

Technical Problem

Existing power supply systems cannot determine whether a current detector is defective when it detects overcurrent, leading to potential continuous power supply to electrical loads despite the risk, and using high-performance detectors increases costs.

Method used

A power supply system with a switch, fuse, current detector, and fault detector that determines current detector defects by measuring elapsed time and fuse melting characteristics, allowing switching to alternate power paths without high-performance detectors.

Benefits of technology

The system effectively detects and responds to current detector failures, ensuring safe power supply without high-cost detectors, maintaining system integrity and reducing costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Energy supply system, featuring: - a switch (SW1 to SW4) that - is arranged in a power supply path from a DC power source (11, 12) to an electrical load (15), and - is configured to cause the power supply path to be in a conducting state or to interrupt the power supply path in accordance with an external command; - a fuse (17, 18) which - is located in the energy supply path, and - is configured to melt in accordance with a current flowing to the power supply path and a power supply time; - a current detector (24) which - is located in the switch (SW1 to SW4), and - is configured to detect the current flowing to the power supply path when the switch (SW1 to SW4) is turned on; - an overcurrent detector (30, S120) configured to determine whether a current value detected by the current detector (24) exceeds a predefined overcurrent detection value; and - a defect detector (30, S170 to S230, S300) configured to - to maintain an ON state of the switch (SW1 to SW4) when the overcurrent detector (30, S120) determines that the current value exceeds the overcurrent detection value, - then to measure an elapsed time, and - to determine that the current detector (24) is defective when the elapsed time exceeds a defect determination time, wherein the defect determination time is set in accordance with a melting characteristic of the fuse (17, 18) to a time required to melt the fuse (17, 18) when the current value exceeding the overcurrent determination value flows into the fuse (17, 18).
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The present disclosure relates to an energy source or energy supply system with an overcurrent protection function.

[0002] As described in publication JP 2018-164339 A, this type of power supply system is known to have a configuration in which multiple switches can switch a power supply path for an electrical load either to a power supply path from a lead-acid battery or a power supply path from a lithium-ion battery.

[0003] In this power supply system, a current detector is placed in each switch. A controller monitors the current supplied to the electrical load using the current detector in each switch and switches the power supply path accordingly. If the current detector detects an overcurrent, the controller switches off the switch where the overcurrent was detected, thus protecting the electrical load from the overcurrent.

[0004] Furthermore, a method for activating a first switch of an overcurrent fault detection circuit for normal system operation is known from publication EP 3 565 073 A1 in connection with a self-test with an overvoltage fault detection system. The method comprises activating the first switch for a predefined pulse time to supply an input voltage to a capacitor, where the predefined pulse time is less than an overcurrent fault time; deactivating the first switch for the predefined pulse time; determining whether the capacitor voltage is large enough to allow the first switch to be activated for more than the overcurrent fault time without generating an overcurrent fault condition; repeating the activation and deactivation if the capacitor voltage is not large enough; and activating the first switch for the duration of normal system operation.The publication EP 3 565 073 A1 thus discloses a method for monitoring the detected overcurrent for a predetermined period without tripping the circuit breakers. If the overcurrent subsides within the predetermined period, the circuit breaker is not switched off.

[0005] Furthermore, German patent application DE 10 2011 121 604 A1 discloses a method for protecting an electrical or electronic system, in particular a high-voltage battery system in an electric or hybrid vehicle, against electrical overcurrent and / or short circuits in connection with a short-circuit and overcurrent protection device. This method includes at least a measuring device for measuring the operating current flowing through the system, a circuit breaker for interrupting the current, and a control unit for tripping the circuit breaker.The control unit compares an actual value of the current increase in the operating current, determined by the measuring instrument and / or the control unit itself, with a first setpoint. This first setpoint, representing the maximum permissible current increase in the operating current, is dynamically set by the control unit according to the system design and / or current demand. The control unit then trips the circuit breaker to interrupt the operating current if the actual value of the current increase exceeds the first setpoint. As can be seen from German patent application DE 10 2011 121 604 A1, the measured overcurrent value is checked for plausibility. If the current sensor does not measure plausible overcurrent values, this indicates a defect in the current sensor.

[0006] Furthermore, from US patent 2019 / 0252908A1, a power supply control device and a battery unit are known in which a power supply control device is applied to a power supply system that includes an opening and closing unit having a plurality of switches connected in series on an excitation path through which excitation is carried out from a voltage source, and a plurality of diodes connected in parallel to the plurality of switches, wherein the plurality of diodes includes diodes arranged in opposite directions to each other.The power supply control device comprises a detection unit that determines that an abnormal condition has occurred, in which current flows to one of the multiple diodes in a state where the multiple switches are off, and a control unit that switches the switch connected in parallel to the diode through which the current flows to an on state when the abnormal condition is determined to have occurred. Thus, US Publication 2019 / 0252908A1 shows that, for a power supply system, each current path of the deployed switches has a current detector.

[0007] As a result of a detailed investigation by the inventor, a problem has arisen in that the power supply system described above cannot determine whether the cause is a defect or failure of the current detector when the current detector has detected the overcurrent.

[0008] This means that if an overcurrent actually flows, it is necessary to protect the electrical load by interrupting the power supply path. However, if the current detector is defective, it may be possible to continue supplying power to the electrical load by switching the power supply path to bypass the path containing the current detector. The power supply system described above, however, cannot perform such a switching of the power supply path.

[0009] In order to enable the power supply system described above to determine the defect in the current detector and to switch the power supply path, it may be necessary to use a high-performance current detector that is capable of outputting a detection threshold whose current value is extremely higher than that of the overcurrent to be detected.

[0010] In this way, if the current value obtained from the current detector is below the detection limit, it can be determined that the current detector is defective, and the power supply path can be switched. However, since it is necessary to use the high-power current detector in this case, there is a problem in that the costs for the power supply system increase.

[0011] The invention is based on the objective of implementing a fail-safe function in a power supply system with an overcurrent protection function in the event of a defect in a current detector, different from the fail-safe function in the event of an overcurrent occurring, without using a high-performance current detector.

[0012] This problem is solved by an energy supply system with the features of claim 1. Advantageous embodiments of the invention are the subject of the attached dependent claims.

[0013] According to one aspect of the present disclosure, a power supply system thus comprises a switch arranged in a power supply path of a direct current to an electrical load, a fuse, a current detector arranged in the switch, an overcurrent detector and a fault detector.

[0014] The switch causes the power supply path to be in a conductive state, or it interrupts the power supply path in accordance with an external command. The fuse blows according to the current flowing to the power supply path and the duration of the power supply, thus interrupting the power supply path.

[0015] The current detector measures the current flowing to the power supply path when the switch is turned on. The overcurrent detector determines whether a current value detected by the current detector exceeds a predefined overcurrent threshold.

[0016] The fault detector maintains an ON state of the switch when the overcurrent detector determines that the current value exceeds the overcurrent determination value, subsequently measures an elapsed time and determines that the current detector is faulty if the elapsed time exceeds a fault determination time, the fault determination time being set in accordance with a fuse melting characteristic to a time required for the fuse to melt when the current value exceeding the overcurrent determination value flows into the fuse.

[0017] In the power supply system of the present disclosure, configured according to the above description, if the overcurrent actually flows to the power supply path, the fuse melts after a predetermined power supply time has elapsed, according to the fuse's melting characteristic. The power supply path to the electrical load is interrupted.

[0018] Therefore, according to the power supply system of the present disclosure, the electrical load can be protected from overcurrent by the fuse melting. In a case where the overcurrent determiner determines that the current value detected by the current detector exceeds the overcurrent determination value, the fault determiner determines that the current detector is faulty if the elapsed time of the condition exceeds the fault determination time.

[0019] Therefore, according to the power supply system of the present disclosure, the defect of the current detector can be detected without using the high-performance current detector, which is capable of determining the defect based on the detected current value (detection threshold). Consequently, according to the power supply system of the present disclosure, a power supply system can be implemented that is capable of performing the fault or defect determination of the current detector at low cost.

[0020] As in the aforementioned publication JP 2018-164339 A, the power supply system of the present disclosure is applied to the power supply system that switches the power supply path to the electrical load via several switches and can thereby achieve more effects.

[0021] This means that in the power supply system with multiple power supply paths to the electrical load, the switch containing the faulty current detector is switched off, and a switch located in a different power supply path is switched on. This allows the power supply to the electrical load to continue.

[0022] The functions, features, and advantages of this disclosure are more clearly evident from the following detailed description with reference to the accompanying drawings. The drawings show: Fig. 1 a circuit diagram to illustrate an entire configuration of a power supply system according to a first embodiment; Fig. 2. A flowchart illustrating a defect detection process of a current detector; Fig. 3. An explanatory diagram to illustrate a relationship between a melting characteristic, an overcurrent determination value, and a defect determination time; Fig. 4. An explanatory illustration to demonstrate a change of state after an overcurrent measurement of switch SW3; and Fig. 5 A flowchart illustrating the defect determination process according to a second embodiment.

[0023] Embodiments of the present disclosure are described below with reference to the drawings. (First embodiment)(configuration)

[0024] In a vehicle that uses an internal combustion engine as a power source, an energy supply system of the present embodiment is an in-vehicle energy supply system that provides electrical energy to various instruments of the vehicle.

[0025] As in Fig. As shown in Figure 1, the energy source or energy supply system of the present embodiment is a dual energy supply system comprising a lead-acid battery 11 and a lithium-ion battery 12 as energy sources. Electrical energy can be supplied from either battery (storage battery) 11 or 12 to a starter 13, various electrical loads 14 and 15, or a rotating electric machine 16. Each battery 11 or 12 can be charged by the rotating electric machine 16.

[0026] Therefore, the lead-acid battery 11 and the lithium-ion battery 12 are connected in parallel to the rotating electric machine 16 and in parallel to the electrical loads 14 and 15. A fuse 17 is placed in a power supply path from the lead-acid battery 11 to each component described above. A fuse 18 is placed in a power supply path from the lithium-ion battery 12 to each component described above.

[0027] When the overcurrent determined by the melting characteristics of fuses 17 and 18 flows in the power supply path in which fuses 17 and 18 are located, each fuse 17 and 18 melts and interrupts the power supply path. Accordingly, the electrical loads 14 and 15 are protected from overcurrent by the melting of fuses 17 and 18.

[0028] The lithium-ion battery 12 is housed in a casing and designed as a battery unit 20 integrated with a substrate. The battery unit 20 has output terminals P1, P2, and P3. Output terminal P1 is connected to the lead-acid battery 11, the starter 13, and the electrical load 14. Output terminal P2 is connected to the rotating electric machine 16. Output terminal P3 is connected to the electrical load 15.

[0029] Each of the electrical loads 14 and 15 has a different requirement for the voltage of an electrical power supply provided by each of the accumulators 11 and 12. Of the electrical loads, electrical load 15 is a load requiring a constant voltage, which must be stable so that the voltage of the electrical power supply is constant or at least fluctuates within a predetermined range. In contrast, electrical load 14 is a general electrical load, different from the load requiring a constant voltage. It can also be said that electrical load 15 is a load that does not tolerate a power source failure, while electrical load 14 is a load that tolerates a power source failure, compared to electrical load 15.

[0030] Specific examples of electrical load 15, i.e., loads requiring constant voltage, include navigation devices, audio devices, measuring devices, or various ECUs, such as an internal combustion engine ECU. In this case, voltage fluctuations in the electrical supply are suppressed, thereby preventing unnecessary resets or similar issues in each of the devices described above. Stable operation is thus achieved.

[0031] Specific examples of electrical load 14 include a seat heater, a defroster heater for a rear window, a headlight, a windshield wiper, an air conditioning blower, or the like.

[0032] The rotating electric machine 16 is a generator that includes a three-phase motor and a motor controller for drive control of the motor, has a motor function and is configured as an electromechanical ISG (integrated starter generator).

[0033] The rotating electric machine 16 has a power generation function for producing electrical energy (regeneration energy) based on the rotation of an internal combustion engine output shaft or a vehicle axle, and a drive function for applying a rotational force to the internal combustion engine output shaft. During an idle stop, the drive function of the rotating electric machine 16 applies a rotational force to the internal combustion engine when the engine, which was automatically stopped, restarts. The rotating electric machine 16 delivers the generated electrical energy to each of the batteries 11 and 12 or the electrical loads 14 and 15.

[0034] The battery unit 20 further comprises, as an electrical path within the unit, a first electrical path L1, which connects the output terminal P1 and the lithium-ion battery 12. The output terminal P2 is connected to a node N1 as a midpoint of the first electrical path L1.

[0035] In this case, the first electrical path L1 is a path that electrically connects the lead-acid battery 11 and the lithium-ion battery 12. The junction N1 on the first electrical path L1 is connected to the rotating electric machine 16. In the first electrical path L1, a first switch SW1 is located closer to the lead-acid battery 11 than junction N1. A second switch SW2 is located closer to the lithium-ion battery 12 than junction N1.

[0036] In battery unit 20, a second electrical path L2 is arranged parallel to the first electrical path L1. A node N2, as a midpoint of the second electrical path L2, is connected to the output terminal P3.

[0037] One end of the second electrical path L2 is connected to a junction point N3 between the output terminal P1 and the first switch SW1 in the first electrical path L1. The other end is connected to a junction point N4 between the second switch SW2 and the lithium-ion battery 12 in the first electrical path L1.

[0038] In the second electrical path L2, a third switch SW3 is located closer to the lithium-ion battery 12 than junction N2. A fourth switch SW4 is located closer to the lead-acid battery 11 than junction N2.

[0039] Accordingly, the second electrical path L2 is a path that electrically connects each of the accumulators 11 and 12 to the electrical load 15. As shown in an enlarged section in Fig. As shown in Figure 1, each of the switches SW1 to SW4 contains a semiconductor switching element, such as a MOSFET, and is, in other words, a normally open switch.

[0040] In particular, each of the switches SW1 to SW4 contains switching sections 21 and 22 connected in parallel. The two ends of each of the switching sections 21 and 22 are connected to the first electrical path L1 or the second electrical path L2. Thus, each of the switches SW1 to SW4 is located on the corresponding electrical path L1 or L2.

[0041] Circuit section 21 contains circuit elements Q1 and Q2 connected in series. The orientations of the parasitic diodes of circuit elements Q1 and Q2 are opposite to each other. Circuit section 22 contains circuit elements Q3 and Q4 connected in series. Similarly, the orientations of the parasitic diodes of circuit elements Q3 and Q4 are opposite to each other.

[0042] In each of the switching sections 21 and 22 there is a current detector 24. The current detector 24 detects a current flowing through the first electrical path L1 or the second electrical path L2, in which each of the switches SW1 to SW4 is located, when the switching sections 21 and 22 are switched on (on state).

[0043] Each of the switches SW1 to SW4 contains the two switching sections 21 and 22, which are connected in parallel, so that if one of the switching sections is defective, the other of the switching sections can function as switches SW1 to SW4.

[0044] Since each of the switching sections 21 and 22 contains a pair of semiconductor switching elements in which the directions of the parasitic diodes are opposite to each other, the current flow through the parasitic diode is completely interrupted when each of the semiconductor switching elements is switched off (off state). Accordingly, an unintended current flow in each of the electrical paths L1 and L2 can be avoided.

[0045] Instead of a MOSFET, an IGBT, a bipolar transistor, or a similar semiconductor switching element can be used. In this case, if an IGBT or a bipolar transistor is used, a diode replacing the parasitic diode can be connected in parallel to each of the semiconductor switching elements.

[0046] In the first electrical path L1, the first switch SW1 is connected in parallel to a bypass path L3, which contains a resistor 26 for current limiting. This means that even when the first switch SW1 is off (off state), the lead-acid battery 11 and the rotating electric machine 16 are electrically connected.

[0047] Accordingly, even when the vehicle's power source switch (ignition switch) is off, a dark current flows through the rotating electric machine 16, and the electrical energy required to start the rotating electric machine 16 is accumulated. The rotating electric machine 16 can be driven immediately after the power source switch (ignition switch) is turned on.

[0048] The fourth switch, SW4, contains a bypass path L4, which includes a series circuit consisting of a normally open bypass relay 28 and a fuse 29. The bypass path L4 comprises two series circuits of the bypass relay 28 and the fuse 29.

[0049] This means that when all switches SW1 to SW4 are switched off (off state), the electrical energy from the lead-acid battery 11 can be supplied to the electrical load 15 by switching on the bypass relays 28 in the two systems described above.

[0050] The battery unit 20 further comprises a controller 30, which controls the opening and closing of each of the switches SW1 to SW4 and the bypass relays 28 of the two systems. The controller 30 contains a microcomputer with a CPU, ROM, RAM, non-volatile memory, an input / output interface, or the like. The non-volatile memory is used to store a defect determination result from the current detector 24 or the like. The defect determination result is obtained using the defect determination process described below.

[0051] The controller 30 is connected to an ECU 50 located outside the battery unit 20. The controller 30 and the ECU 50 are connected via a vehicle communication network, enabling them to communicate with each other and share various data stored in the controller 30 and the ECU 50.

[0052] The controller 30 controls the opening and closing of each of the switches SW1 to SW4 and the bypass relay 28 on the basis of a memory state of each of the accumulators 11 and 12 or a command signal from the ECU 50, which is a higher-level control device.

[0053] For example, the controller 30 causes the energy supply path from the lead-acid battery 11 or the lithium-ion battery 12 to the electrical load 15 to assume a conductive state by selectively switching on the fourth switch SW4 and the third switch SW3, and supplies the electrical load 15 with energy.

[0054] Incidentally, in a case where electrical energy is supplied to the electrical load 15 in this manner, the electrical load 15 may fail if an overcurrent exceeding the permissible range flows from the lead-acid battery 11 or the lithium-ion battery 12 to the electrical load 15. Therefore, fuses 17 and 18 are used whose melting characteristics are designed to cause them to melt in the event of an overcurrent flowing through the electrical load 15.

[0055] On the other hand, when the fourth switch SW4 or the third switch SW3 is turned on, the controller 30 monitors the current flowing through each of the switches SW4 and SW3 using the current detector 24, which is located in each of the switches SW4 and SW3.

[0056] If the current value exceeds the overcurrent determination value, the switch SW4 or the switch SW3 is switched off in the on state and the energy supply to the electrical load 15 is interrupted.

[0057] However, if the current value detected by current detector 24 exceeds the overcurrent limit, the overcurrent flows to the power supply path containing switches SW1 to SW4. Fuses 17 and 18 blow. However, if current detector 24 is defective or fails, fuses 17 and 18 will not blow.

[0058] This means that if the current detector 24 is defective, the current value "gets stuck" at a detection limit. Therefore, the controller 30 determines, based on the current value, that an overcurrent has flowed, and the fail-safe function against the overcurrent switches on the fourth switch SW4 or the third switch SW3.

[0059] However, if the current detector 24 is defective and the overcurrent is incorrectly detected, the switch is switched to the on-state, which forms the power supply path to the electrical load 15. This allows the power supply to the electrical load 15 to continue.

[0060] Controller 30 similarly monitors the current in the first switch SW1 and the second switch SW2. Therefore, if an overcurrent is incorrectly detected, controller 30 switches off either the first switch SW1 or the second switch SW2.

[0061] In the present embodiment, the controller 30 carries out the in Fig. The defect determination process shown for each of the switches SW1 to SW4 is shown in section 2. (Processes)

[0062] As in Fig. As shown in Figure 2, in the defect detection process, a current value Isw is first recorded in step S110 by the current detector 24 of a switch SW (hereinafter referred to as target switch SW), which is a target for fault or defect detection among the switches SW1 to SW4. The current flows through the power supply path in which the target switch SW is located.

[0063] In the following step S120, the recorded current value Isw is compared with a determination value (overcurrent determination value) Iref for overcurrent determination, and it is determined whether the current value Isw is above the overcurrent determination value Iref.

[0064] If the current value Isw is less than or equal to the overcurrent determination value Iref, the overcurrent does not flow through the power supply path of the target switch SW. Therefore, the process proceeds to step S130. In the processes S170 to S230, described below, it is determined whether the overcurrent flow has been confirmed.

[0065] If step S130 determines that the overcurrent has not been confirmed, step S140 determines that the overcurrent is not confirmed. The process then proceeds to step S150. In step S150, it is determined that each of the switches SW1 to SW4 can be switched normally based on the command from ECU 50, whereupon the fault determination process ends.

[0066] If step S130 confirms the overcurrent, the process proceeds to step S160. In step S160, it is determined that the overcurrent will blow fuses 17 and 18 and that the current value Isw is less than or equal to the overcurrent determination value Iref. The target switch SW is then switched off.

[0067] In step S160, for example, it is determined that the off state of the target switch SW lasts until the next energy source switch (ignition switch) is turned on. The fault detection process ends.

[0068] If, in step S120, it is determined that the current value Isw is above the overcurrent detection value Iref, the process proceeds to step S170. A timer T counts up to measure a time during which Isw > Iref. The process then proceeds to step S180.

[0069] In step S180, it is determined whether a timer value incremented in step S170 exceeds a predefined defect detection time (Tref). If the timer value is less than or equal to the defect detection time (Tref), the process proceeds to step S190. If the timer value exceeds the defect detection time (Tref), the process proceeds to step S210.

[0070] The defect determination time Tref is determined in accordance with the in Fig. The fuse characteristics of fuses 17 and 18 are set as shown in Figure 3. This means that fuses 17 and 18 melt according to the current flow and the duration of the power supply. If the current is high, the time until the fuse melts is short. If the current is low, the time until the fuse melts is long. When the overcurrent flows through fuses 17 and 18 and the time determined based on the melting characteristics has elapsed, the fuses 17 and 18 melt or blow. The current value detected by the current detector 24 decreases.

[0071] In contrast, fuses 17 and 18 do not melt if the current detector 24 is defective and the current value Isw remains at or "stuck" at the detection limit. Therefore, the current value detected by the current detector 24 does not decrease.

[0072] Consequently, the fault detection time Tref is set in accordance with the melting characteristics of fuses 17 and 18 to a time required for the melting of fuses 17 and 18 when the overcurrent, which is greater than or equal to the detection limit, flows to fuses 17 and 18.

[0073] Subsequently, in step S190, since it is determined in step S120 that the current value Isw exceeds the overcurrent determination value Iref, it is determined that the overcurrent has flowed into the power supply path of the target switch SW, and the overcurrent is confirmed.

[0074] In the following step S200, since there is a possibility that the current detector 24 is defective, the target switch SW is set to be held in its current state. The defect detection process ends. In contrast, in step S210, since the timer value T exceeds the defect detection time Tref and the current value Isw is above the overcurrent detection value Iref, it is determined that the current detector 24 is defective or has failed. The defect of the current detector 24 is confirmed.

[0075] In the subsequent step S220, the result determined in step S190, that the overcurrent is confirmed, is changed to a result indicating that the overcurrent is not confirmed. The process then proceeds to step S230, and the switch is turned on. Once the switch is turned on, and after another switch is turned on to provide electrical power in the power supply path that differs from that of the target switch SW, the target switch SW is turned off.

[0076] This means, for example, as in Fig. Figure 4 shows that in "state 1" the third switch SW3 is switched on and electrical energy from the lithium-ion battery 12 is supplied to the electrical load 15. Subsequently, when the defect of the current detector 24 of the third switch SW3 is detected, the state transitions to "state 2".

[0077] In "state 2", the fourth switch SW4 is switched on and the third switch SW3 is switched off sequentially. This does not stop the power supply to the electrical load 15, but rather switches the power supply path to the electrical load 15.

[0078] If the current value Isw becomes less than or equal to the overcurrent determination value Iref, until the overcurrent is determined on the basis of the current value detected by the current detector 24 of the third switch SW3 and the defect determination time Tref has elapsed, the “state 1” transitions to a “state 3”.

[0079] In "state 3", since fuse 18 melts due to the overcurrent, the third switch SW3 is switched off and the fourth switch SW4 is switched on. The electrical energy is supplied from the lead-acid battery 11 to the electrical load 15. (Effects)

[0080] As described above, the current detector 24 is located in each of the switches SW1 to SW4 in this configuration. If the current value Isw detected by the current detector 24 exceeds the predetermined overcurrent detection value Iref, the target switch SW is held in the open state. The controller 30 waits until the fuse 17 or fuse 18 has blown due to the overcurrent.

[0081] Timer T measures the waiting time. If the time of timer T exceeds the fault detection time Tref, the overcurrent does not flow to the target switch SW. It is determined that the current detector 24 of the target switch SW is faulty, and the power supply path is switched to another power supply path.

[0082] Accordingly, the power supply system of the present embodiment detects the failure or defect of the current detector 24, which is placed in each of the switches SW1 to SW4, on the basis of the determination time (timer T) of the overcurrent, determined from the current value detected by the current detector 24, and can implement the corresponding fail-safe function.

[0083] Since it is not necessary to use the high-performance current detector, whose current detection limit is sufficiently greater than the overcurrent, for the current detector 24 in order to determine the defect of the current detector 24, the power supply system can be implemented cost-effectively.

[0084] In the present embodiment, in the defect determination process performed by the controller 30, the process in step S120 can correspond to an overcurrent determiner of the present disclosure, and the processes in steps S170 to S230 can correspond to a defect determiner of the present disclosure. (Second embodiment)

[0085] In the first embodiment, the defect determination time Tref, which is used to perform the defect determination of the current detector 24, is set to a fixed value in accordance with the melting characteristics of the fuses 17 and 18.

[0086] In contrast, in the present embodiment, as in a flowchart of Fig. 5 shown, in step S300, before determining the elapsed time in step S180, the defect detection time Tref is set in accordance with the current value Isw detected by the current detector 24 and the melting characteristics of the fuses 17 and 18.

[0087] In this way, the time required for fuses 17 and 18 to melt can be adjusted to the fault detection time Tref in accordance with the current value Isw, which is detected when the current detector 24 is normal, and the fuse characteristics of fuses 17 and 18.

[0088] Consequently, according to the present embodiment, it is possible to perform the defect determination of the current detector 24 more accurately. The in Fig. The flowchart shown in step 5 is modified by adding step S300 to the diagram in Fig. The flowchart shown in step 2 is obtained. Since the processes other than the process in step S300 are the same as those in Fig.The flowchart shown in section 2 is not discussed in detail below. [Other embodiments]

[0089] Although the embodiments of the present disclosure have been described above, the present disclosure is not limited to the embodiments described above, and various modifications are possible to realize the present disclosure.

[0090] In the embodiments described above, for example, the in-vehicle power supply system is described which is able to switch the power supply path from the two accumulators 11 and 12 to the electrical load 15 using the four switches SW1 to SW4.

[0091] However, the power supply system of the present disclosure is applicable in the same way as the embodiment described above, as long as it is a power supply or energy source system that delivers the electrical energy to the electrical load via the switch having the current detector. That is to say, even in a power supply system with a switch, if the current detector detects that an overcurrent is flowing to the electrical load, it can be determined whether the cause lies in a failure or defect of the current detector.

[0092] In this case, if the determination result is output to an external device, the external device can perform various fail-safe operations in the event of an overcurrent and a failure of the current detector.

[0093] In the embodiments described above, the controller 30 contains the computer. However, the controller 30 can contain one or more dedicated hardware logic circuits or a combination of the computer and the logic circuit. The defect detection process executed by the controller 30 can be stored as a computer-executed program on a computer-readable, non-volatile, tangible storage medium. Some or all of the functions of the defect detection process can be implemented by one or more hardware components.

Claims

[1] Energy supply system comprising: - a switch (SW1 to SW4) that - is arranged in a power supply path from a DC power source (11, 12) to an electrical load (15), and - is configured to cause the power supply path to be in a conducting state or to interrupt the power supply path in accordance with an external command; - a fuse (17, 18) which - is located in the energy supply path, and - is configured to melt in accordance with a current flowing to the power supply path and a power supply time; - a current detector (24) - is located in the switch (SW1 to SW4), and - is configured to detect the current flowing to the power supply path when the switch (SW1 to SW4) is turned on; - an overcurrent detector (30, S120) configured to determine whether a current value detected by the current detector (24) exceeds a predefined overcurrent detection value; and - a defect detector (30, S170 to S230, S300) configured to - to maintain an ON state of the switch (SW1 to SW4) when the overcurrent detector (30, S120) determines that the current value exceeds the overcurrent detection value, - then to measure an elapsed time, and - to determine that the current detector (24) is defective when the elapsed time exceeds a defect determination time, wherein the defect determination time is set in accordance with a melting characteristic of the fuse (17, 18) to a time required to melt the fuse (17, 18) when the current value exceeding the overcurrent determination value flows into the fuse (17, 18). [2] Power supply system according to claim 1, wherein the fault determiner (30, S170 to S230, S300) is configured to cancel an overcurrent determination result by the overcurrent determiner (30, S120) when it is determined that the current detector (24) is faulty. [3] Power supply system according to claim 1 or 2, wherein the fault identifier (30, S170 to S230, S300) is configured to turn off the switch (SW1 to SW4) and switch the power supply path to the electrical load (15) from the power supply path in which the current detector (24) is arranged to another power supply path when it is determined that the current detector (24) is faulty.

Citation Information

Patent Citations

  • Method for protecting electrical or electronic system i.e. high volt battery system, from short circuit, involves triggering circuit breaker to interrupt operating current, if actual value of current gradient exceeds reference value

    DE102011121604A1

  • Self-test of over-current fault detection

    EP3565073A1

  • JP002018164339A

  • Power supply control apparatus and battery unit

    US20190252908A1