Power source control device and control program

The power supply control device addresses excessive backup power consumption by degrading communication functions and optimizing data transmission during backup operations, effectively reducing power usage in vehicles.

JP2025185768APending Publication Date: 2025-12-23DENSO TEN LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024094133
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-06-11
Publication Date
2025-12-23

AI Technical Summary

Technical Problem

Existing power supply control systems in vehicles consume excessive power during backup operations due to communication between loads and the backup power source via CAN, despite efforts to reduce backup power consumption.

Method used

A power supply control device that degrades its communication function during backup operations to minimize power consumption by reducing unnecessary data transmission and extending communication cycles.

Benefits of technology

Significantly reduces power consumption of the backup power source by minimizing communication power usage during backup operations without interfering with the functionality of the vehicle's loads.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025185768000001_ABST
    Figure 2025185768000001_ABST
Patent Text Reader

Abstract

To provide a power source control device and a control program in which power consumption in a backup power source can be further suppressed.SOLUTION: A power source control device according to an embodiment includes a controller. The controller performs communication with another control device, and performs backup control to supply power from a backup power source to a load when a failure in a main power source is detected. When performing the backup control, the controller degenerates a communication function.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The disclosed embodiments relate to a power supply control device and a control program. [Background technology]

[0002] A redundant power supply unit installed in a vehicle performs backup control using a backup power supply in the event of a failure of the main power supply. Because the capacity of the backup power supply is limited, it is desirable for the controller of the redundant power supply unit to reduce the consumption of the backup power supply when performing backup control.

[0003] For this reason, when the main power supply fails and backup control is performed using a backup power supply, there is prior art that reduces consumption of the backup power supply by stopping or limiting the operation of loads that are not necessary for the vehicle to run autonomously (see, for example, Patent Document 1). This allows the redundant power supply device to reduce consumption of the backup power supply during backup control. [Prior art documents] [Patent documents]

[0004] [Patent Document 1] Japanese Patent Publication No. 2022-130215 Summary of the Invention [Problem to be solved by the invention]

[0005] However, in the prior art, even during backup control, communication is performed between the load for automatic driving, including the automatic driving control device, via a controller area network (CAN), for example, and power from the backup power source is consumed by the communication. Therefore, there is room for improvement in the prior art as a technology for reducing consumption of the backup power source.

[0006] One aspect of the embodiment has been made in view of the above, and aims to provide a power supply control device and a control program that can further reduce the power consumption of a backup power supply. [Means for solving the problem]

[0007] According to one aspect of the embodiment, a power supply control device includes a controller. The controller communicates with other control devices and, upon detecting a failure of the main power supply, performs backup control to supply power to a load from a backup power supply. When performing the backup control, the controller degrades its communication function. [Effects of the Invention]

[0008] The power supply control device and control program according to the embodiment degrade communication functions when performing backup control to supply power from a backup power source to a load, thereby reducing the power consumption required for communication and thereby further reducing the power consumption of the backup power source. [Brief explanation of the drawings]

[0009] [Figure 1] FIG. 1 is an explanatory diagram illustrating an example of the configuration of a power supply control device according to an embodiment. [Figure 2] FIG. 2 is an explanatory diagram illustrating an example of the operation of the power supply control device according to the embodiment. [Figure 3] FIG. 3 is an explanatory diagram illustrating an example of the operation of the power supply control device according to the embodiment. [Figure 4] FIG. 4 is an explanatory diagram of a CAN communication circuit of the power supply control device and the upper control device according to the embodiment. [Figure 5] FIG. 5 is an explanatory diagram of CAN communication according to the embodiment. [Figure 6] FIG. 6 is an explanatory diagram of CAN communication according to the embodiment. [Figure 7] FIG. 7 is an explanatory diagram of CAN communication according to the embodiment. [Figure 8]FIG. 8 is a flowchart illustrating an example of processing executed by the controller according to the embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0010] Hereinafter, embodiments of a power supply control device and a control program will be described in detail with reference to the accompanying drawings. Note that the present invention is not limited to the embodiments described below. The following description will be given using an example of a power supply control device that is installed in a vehicle with an autonomous driving function and supplies power to a load, but the power supply control device according to the embodiment may also be installed in a vehicle that does not have an autonomous driving function.

[0011] In addition, although the following description will be given of a case where the vehicle in which the power supply control device is installed is an electric vehicle or a hybrid vehicle, the vehicle in which the power supply control device is installed may also be an engine vehicle that runs on an internal combustion engine.

[0012] ≪1. Configuration of power supply control device≫ 1 is an explanatory diagram showing an example of the configuration of a power supply control device 1 according to an embodiment. The power supply control device 1 according to the embodiment is connected to a main power supply 10, a DC / DC converter 11 (hereinafter referred to as "DCC 11"), a load 101, and a host control device 200.

[0013] The main power supply 10 is, for example, a lead battery. However, the main power supply 10 may be any secondary battery other than a lead battery. The main power supply 10 is a power supply that mainly supplies power to the load 101 and the like.

[0014] The DCC 11 is connected to a high-voltage battery 12. The high-voltage battery 12 is a vehicle drive battery that supplies power to a motor that drives the vehicle. The high-voltage battery 12 is, for example, a lithium-ion battery.

[0015] The DCC 11 steps down the voltage of the high-voltage battery 12 to charge the main power supply 10 and a backup power supply 20 (described later). The DCC 11 also steps down the voltage of the high-voltage battery 12 to supply power to a load 101 and the like.

[0016] When the DCC 11 is mounted on an engine vehicle, it is connected to an alternator that converts the vehicle's regenerative energy into electric power to generate electricity, and transforms and outputs the input voltage input from the generator.

[0017] The load 101 includes a driving load related to the vehicle's driving and a non-driving load unrelated to the vehicle's driving. The driving load is a device used for fail-safe control (hereinafter referred to as "FOP") that uses the power of the backup power supply 20 to drive the vehicle to an evacuation route when the main power supply 10 fails. Evacuation route means driving the vehicle to a safe location on the shoulder of the road. The driving load is also used when autonomous driving is performed.

[0018] The driving loads include devices related to automatic driving, steering, and braking of the vehicle, such as an electric steering device, an electric braking device, radar, sensors, and an on-board camera.

[0019] Non-driving loads are loads other than those related to driving. For example, non-driving loads include door lock devices, emergency call devices, information notification devices, A / V (audio / video) devices, air conditioners, power windows, and outlets inside and outside the vehicle.

[0020] The host control device 200 includes, in addition to the power supply control device 1, a plurality of ECUs (Electronic Control Units) that operate the loads 101 to control the vehicle. In the following, an example will be described in which the host control device 200 is an automatic driving control device.

[0021] In this case, the host controller 200 operates the traveling loads to control the automatic driving of the vehicle. Furthermore, if the power supply from the main power supply 10 becomes impossible, the host controller 200 operates the traveling loads using power from the backup power supply 20 to perform FOP. The host controller 200 operates by receiving power from the main power supply 10 and the backup power supply 20.

[0022] The power supply control device 1 is supplied with power from an externally provided main power supply 10. The power supply control device 1 can supply the power supplied from the externally provided main power supply 10 to a load 101 and a power source.

[0023] The power supply control device 1 includes a first system 110 and a second system 120. The first system 110 is a system capable of supplying power from the main power supply 10 to the load 101. The second system 120 is a system capable of supplying power from the backup power supply 20, which will be described later, to the load 101.

[0024] The first system 110 and the second system 120 are connected by an inter-system line 130. The inter-system line 130 is provided with an inter-system switch 42 that can connect and disconnect the first system 110 and the second system 120.

[0025] The power supply control device 1 includes a backup power supply 20, a battery switch 41, an inter-system switch 42, a first load switch 43, a second load switch 44, a first voltage sensor 51, a second voltage sensor 52, and a controller 3.

[0026] Backup power supply 20 is, for example, a lithium ion battery. Backup power supply 20 is a backup power supply in the event that main power supply 10 is unable to supply power. Note that backup power supply 20 may be any secondary battery other than a lithium ion battery.

[0027] The battery switch 41 is a switch that can connect and disconnect the backup power supply 20 and the second system 120. The inter-system switch 42 is provided on the inter-system line 130. The inter-system switch 42 is a switch that can connect and disconnect the first system 110 and the second system 120.

[0028] The first load switch 43 is a switch that can connect and disconnect the first system 110 and the load 101. The second load switch 44 is a switch that can connect and disconnect the second system 120 and the load 101.

[0029] The first voltage sensor 51 is provided in the first system 110. The first voltage sensor 51 detects the voltage of the first system 110 and outputs the detection result to the controller 3. The second voltage sensor 52 is provided in the second system 120. The second voltage sensor 52 detects the voltage of the second system 120 and outputs the detection result to the controller 3.

[0030] The controller 3 includes a microcomputer having a CPU (Central Processing Unit), ROM (Read Only Memory), RAM (Random Access Memory), etc., and various other circuits. The controller 3 may also be configured with hardware such as an ASIC (Application Specific Integrated Circuit) or an FPGA (Field Programmable Gate Array).

[0031] The controller 3 controls the operations of the battery switch 41, the inter-system switch 42, the first load switch 43, and the second load switch 44 by having the CPU execute a control program stored in the ROM using the RAM as a work area. The control program may be stored in a storage device from the outside via a communication line or the like.

[0032] Furthermore, the controller 3 periodically transmits and receives control information to and from the upper control device 200 and each load 101 at predetermined intervals (for example, every 100 ms) while the ignition switch of the vehicle is on.

[0033] The controller 3 communicates with the upper control device 200 and each load 101, for example, using a controller area network (CAN). Note that the controller 3 may be configured to communicate with the upper control device 200 and each load 101 using a communication standard other than CAN, such as Ethernet (registered trademark).

[0034] ≪2. Example of power supply control device operation≫ Next, an example of operation of the power supply control device 1 according to the embodiment will be described with reference to Figures 2 and 3. Figures 2 and 3 are explanatory diagrams showing an example of operation of the power supply control device 1 according to the embodiment.

[0035] 2, during normal operation when no power supply failure occurs, the controller 3 turns off the battery switch 41 and turns on the inter-system switch 42, the first load switch 43, and the second load switch 44. This allows power to be supplied from the main power supply 10 to the load 101.

[0036] Thereafter, the controller 3 monitors whether a ground fault has occurred in the first system 110 or the second system 120. Specifically, when a ground fault occurs in the first system 110 or the second system 120, a large current flows toward the ground fault point, causing the voltage of the first system 110 (hereinafter referred to as "first system voltage V1") and the voltage of the second system 120 (hereinafter referred to as "second system voltage V2") to fall below the ground fault threshold.

[0037] Therefore, when the detection result (first system voltage V1 and second system voltage V2) input from the first voltage sensor 51 or the second voltage sensor 52 becomes below the ground fault threshold, the controller 3 provisionally determines that a ground fault has occurred in the first system 110 or the second system 120.

[0038] When the controller 3 provisionally determines that a ground fault has occurred, it pre-shuts off the inter-system switch 42 and turns on the battery switch 41. This cuts off the connection between the first system 110 and the second system 120, and power is supplied to the first system 110 from the main power supply 10, and to the second system 120 from the backup power supply 20. Thereafter, the controller 3 makes a final determination as to whether a ground fault has occurred in the first system 110 or the second system 120.

[0039] At this time, if a ground fault occurs in the second system 120, the second system voltage V2 remains below the ground fault threshold even when the inter-system switch 42 is turned off. On the other hand, the first system voltage V1 returns to a normal value higher than the ground fault threshold when the inter-system switch 42 is turned off.

[0040] Furthermore, if a ground fault occurs in the first system 110, the first system voltage V1 remains below the ground fault threshold even if the inter-system switch 42 is turned off. On the other hand, the second system voltage V2 returns to a normal value higher than the ground fault threshold when the inter-system switch 42 is turned off.

[0041] Therefore, the controller 3 officially determines that a ground fault has occurred in the second system 120 when the second system voltage V2 remains equal to or lower than the ground fault threshold for a predetermined time period after the inter-system switch 42 is turned off. Also, the controller 3 officially determines that a ground fault has occurred in the first system 110 when the first system voltage V1 remains equal to or lower than the ground fault threshold for a predetermined time period after the inter-system switch 42 is turned off.

[0042] If the first system voltage V1 and the second system voltage V2 remain higher than the ground fault threshold for a predetermined time after the inter-system switch 42 is turned off, the controller 3 determines that this is a transient voltage drop due to an overload or the like and that no ground fault has occurred. In this case, the controller 3 turns the inter-system switch 42 back on and turns the battery switch 41 off again, returning the state of the power supply control device 1 to the normal state shown in FIG. 2.

[0043] When the controller 3 determines that a ground fault has occurred in the first system 110, it switches off the first load switch 43 from the pre-shutdown state in which the inter-system switch 42 is shut off, as shown in Fig. 3. This causes power to be supplied to the load 101 from the backup power supply 20 via the second system 120. This allows the upper control device 200 or the driver to operate the load 101 using power from the backup power supply 20 and drive the vehicle to evacuate.

[0044] When the controller 3 determines that a ground fault has occurred in the second system 120, it switches from a pre-shutdown state in which the inter-system switch 42 is shut off to a battery switch 41 and a second load switch 44. This causes power to be supplied to the load 101 from the main power supply 10 via the first system 110. This allows the upper control device 200 or the driver to operate the load 101 using power from the main power supply 10 to cause the vehicle to evacuate.

[0045] In this way, when a ground fault occurs in the first system 110, the controller 3 performs FOP using the backup power supply 20. However, since the power of the backup power supply 20 is limited, it is desirable to reduce the consumption of the backup power supply 20.

[0046] However, since the controller 3 needs to communicate with the load 101 (travel load) as well as the higher-level control device 200 via the CAN even during FOP, it is necessary to suppress the power consumption of the backup power supply 20 due to communication.

[0047] Therefore, the controller 3 according to the embodiment degrades the communication function when detecting a failure in the main power supply 10 and causing the backup power supply 20 to supply power to the load 101 to perform FOP.

[0048] This allows the power supply control device 1 to reduce power consumption due to communication during FOP, thereby further reducing power consumption of the backup power supply 20. A specific example of CAN communication performed by the controller 3 of the power supply control device 1 will now be described.

[0049] 3. CAN Communication According to the Embodiment Fig. 4 is an explanatory diagram of the CAN communication circuits of the power supply control device 1 and the upper control device 200 according to the embodiment. Figs. 5 to 7 are explanatory diagrams of CAN communication according to the embodiment.

[0050] 4, the controller 3 of the power supply control device 1 includes a microcomputer (hereinafter referred to as "microcomputer 31") and a CAN transceiver 32. On the other hand, the upper control device 200 includes a controller 201. The controller 201 of the upper control device 200 includes a microcomputer 202 and a CAN receiver 203.

[0051] The CAN transceiver 32 and the CAN receiver 203 are connected to each other so as to be able to communicate information via two communication lines, a CAN High line 61 and a CANLow line 62. The CAN High line 61 and the CANLow line 62 are connected at their ends on the power supply control device 1 side and on the upper control device 200 side via a power supply side resistor 63 and an upper side resistor 64, respectively.

[0052] The power supply side resistor 63 and the upper side resistor 64 are called termination resistors, and are resistors provided to suppress reflection of signals transmitted and received between the power supply control device 1 and the upper control device 200.

[0053] As shown in FIG. 5, the microcomputer 31 of the power supply control device 1 transmits data generated by changing the voltage states of the CANHigh line 61 and the CANLow line 62 to the microcomputer 202 of the upper level control device 200.

[0054] For example, the microcomputer 31 of the power supply control device 1 generates 1-bit data "0" by setting the voltage of the CANHigh line 61 to 3.75V (dominant state) and the voltage of the CANLow line 62 to 1.25V (dominant state).

[0055] Furthermore, the microcomputer 31 of the power supply control device 1 generates 1-bit data "1" by setting the voltage of the CANHigh line 61 to 2.5V (recessive state) and the voltage of the CANLow line 62 to 2.5V (recessive state).

[0056] The microcomputer 31 of the power supply control device 1 transmits the generated data signal to the upper control device 200 via the CAN High line 61 and the CANLow line 62 by the CAN transceiver 32 .

[0057] When the voltage difference between the CAN High line 61 and the CANLow line 62 received by the CAN receiver 203 is 2.5V, the microcomputer 202 of the upper control device 200 determines that data "0" has been received.

[0058] When the voltage difference between the CAN High line 61 and the CANLow line 62 received by the CAN receiver 203 is 0V, the microcomputer 202 of the upper control device 200 determines that data "1" has been received.

[0059] The controller 3 of the power supply control device 1 transmits a signal containing 4 bits of data per frame at a predetermined cycle (for example, 100 ms cycle) to the controller 201 of the upper control device 200. Fig. 5 shows a signal containing 4 bits of data "0, 1, 0, 1" sent from the power supply control device 1 to the upper control device 200.

[0060] When the voltage on the CANHigh line 61 is in a dominant state and the voltage on the CANLow line 62 is in a dominant state, a potential difference is created between the CANHigh line 61 and the CANLow line 62 .

[0061] For this reason, in the dominant state, current flows from the CANHigh line 61 to the CANL line 62 via the power supply side resistor 63 and the upper side resistor 64, causing power loss due to the power supply side resistor 63 and the upper side resistor 64 (see FIG. 4). If the controller 3 of the power supply control device 1 performs the same CAN communication during FOP as during normal times, the CAN communication will consume power from the backup power supply 20.

[0062] Therefore, under normal circumstances when no power failure has occurred, the power supply control device 1 transmits the first and second frames of data sequentially to the upper control device 200 at a predetermined cycle (for example, every 100 ms) as shown in Fig. 6. On the other hand, during FOP using the power of the backup power supply 20, the power supply control device 1 degrades the communication function.

[0063] The first frame includes a first abnormality flag, a second abnormality flag, and a third abnormality flag. The first abnormality flag includes a battery overcharge flag, a battery overdischarge flag, and a high temperature abnormality flag for the backup power supply 20.

[0064] The battery overcharge flag of the backup power supply 20 is "0" if the battery of the backup power supply 20 is not in an overcharged state, and is "1" if the battery is in an overcharged state. The battery overdischarge flag of the backup power supply 20 is "0" if the battery of the backup power supply 20 is not in an overdischarged state, and is "1" if the battery is in an overdischarged state. The high temperature abnormality flag of the backup power supply 20 is "0" if the backup power supply 20 is not in an abnormally high temperature state, and is "1" if the backup power supply 20 is in an abnormally high temperature state.

[0065] The second abnormality flag includes, for example, a primary system low voltage flag, which is set to "0" when no ground fault has occurred in the first system 110, and is set to "1" when a ground fault has occurred in the first system 110.

[0066] The third abnormality flag includes, for example, a secondary system low voltage flag. The secondary system low voltage flag is set to "0" when no ground fault has occurred in the second system 120, and is set to "1" when a ground fault has occurred in the second system 120. The above-mentioned first to third abnormality flags are merely examples, and the contents thereof are not limited to the above-mentioned specific examples, but these first to third abnormality flags are data required for FOP.

[0067] The second frame also includes a backup possible state, a charge request to the upper control device 200, software identification information, etc. The backup possible state is "0" when the remaining capacity of the backup power source 20 is sufficient to complete the FOP, and is "1" when the remaining capacity is not sufficient to complete the FOP.

[0068] If the main power supply 10 fails, the upper control device 200 must immediately execute (continue) FOP regardless of the remaining power of the backup power supply 20. For this reason, the backup available state is not necessarily data required for FOP.

[0069] The charge request to the upper control device 200 becomes "0" when the remaining power of the backup power supply 20 is greater than the charge threshold and there is no need to charge the backup power supply 20. The charge request to the upper control device 200 becomes "1" when the remaining power of the backup power supply 20 falls below the charge threshold and there is a need to charge the backup power supply 20.

[0070] When the charge request to the host controller 200 becomes "1", the host controller 200 turns on the battery switch 41 and activates the DCC 11, and charges the backup power supply 20 with the power of the high-voltage battery 12 that has been stepped down by the DCC 11. Note that when the remaining charge of the main power supply 10 is sufficient, the host controller 200 can also turn on the battery switch 41 and charge the backup power supply 20 with the power of the main power supply 10.

[0071] As described above, when the main power supply 10 fails, the upper control device 200 must immediately execute (continue) FOP regardless of the remaining power of the backup power supply 20. For this reason, the charge request to the upper control device 200 is not necessarily data required for FOP.

[0072] The software identification information is information that indicates the version of the power control program used by the controller 3 of the power control device 1. The upper control device 200 periodically communicates with the software distribution center, and when new software is distributed, it compares the version of the latest software with the version included in the software identification information.

[0073] If the version included in the software identification information is not the latest version, the upper control device 200 updates (reprograms) the power control program used by the controller 3 of the power control device 1 to the latest version. Such software identification information does not directly affect FOP. Therefore, software identification information is not necessarily required data for FOP.

[0074] Therefore, during FOP using the power of the backup power supply 20, the power supply control device 1 transmits the first frame of data, which is data necessary for FOP, to the upper level control device 200, as shown in FIG.

[0075] The power supply control device 1 then degrades the communication function by stopping transmission of the second frame of data, which is not necessarily required for the FOP, to the upper control device 200. This allows the power supply control device 1 to reduce the power consumption of the backup power supply 20 without interfering with the FOP.

[0076] The above-described method of degrading the communication function is an example, and various modifications and combinations are possible. The controller 3 of the power supply control device 1 may be configured to degrade the communication function by making the communication cycle with the upper control device 200 longer than normal during FOP.

[0077] For example, the controller 3 may be configured to communicate with the upper control device 200 at a 100 ms interval during normal operation, but at a 200 ms interval during FOP. In this case, the controller 3 may transmit the first and second frames of data, or may transmit only the first frame of data and stop transmitting the second frame of data. The former is more preferable, because it reduces the amount of data and lengthens the communication interval, thereby further reducing the power consumption of the backup power source 20.

[0078] As a result, the power supply control device 1 can reduce the power consumption of the backup power supply 20 by reducing the power consumption required for transmitting data compared to when the data transmission cycle is not lengthened.

[0079] Furthermore, when the backup power supply 20 fails and power is supplied from the main power supply 10 to the load 101 to perform FOP, even if the remaining charge of the main power supply 10 decreases, the main power supply 10 can be charged by power supplied from the high-voltage battery 12 via the DCC 11.

[0080] Therefore, the controller 3 of the power supply control device 1 does not degrade the communication function when it detects a failure in the backup power supply 20 and performs FOP to supply power from the main power supply 10 to the load 101. In other words, the controller 3 transmits the first and second frame data to the upper control device 200 at a predetermined cycle even during FOP. This allows the power supply control device 1 to reduce the power consumption of the backup power supply 20 without interfering with FOP.

[0081] 1 to 3, the controller 3 and the load 101 are connected by a communication line capable of communicating information. Therefore, when performing FOP to supply power from the backup power supply 20 to the load 101, the controller 3 may be configured to request the load 101, which is operated by the backup power supply 20, to degrade its communication function.

[0082] In this case, the controller 3 transmits a request to the load 101 (including other ECUs) to transmit only the data necessary for the FOP and to prohibit the transmission of data not necessary for the FOP. This allows the power supply control device 1 to reduce the power consumption of the backup power supply 20 for the entire vehicle.

[0083] ≪4. Processes executed by the controller≫ Next, a process executed by the controller 3 according to the embodiment will be described with reference to Fig. 8. Fig. 8 is a flowchart showing an example of a process executed by the controller 3 according to the embodiment. The controller 3 repeats the process shown in Fig. 8 from when the ignition switch of the vehicle is turned on until it is turned off.

[0084] When the ignition switch is turned on, the controller 3 turns off (hereinafter may be referred to as "off") the battery switch 41. Then, the controller 3 turns on (hereinafter may be referred to as "on") the inter-system switch 42, the first load switch 43, and the second load switch 44, and then starts the processing shown in FIG.

[0085] 8, the controller 3 first determines whether or not a power failure has occurred (step S101). The power failure here is, for example, a ground fault in the first system 110 or the second system 120. If the controller 3 determines that a power failure has not occurred (step S101, No), the controller 3 ends the process.

[0086] Furthermore, when the controller 3 determines that a power supply failure has occurred (step S101, Yes), it turns off (pre-shutdown) the inter-system switch 42 and turns on the battery switch 41 (step S102). Next, the controller 3 makes a final determination of the system in which the ground fault has occurred (step S103). That is, the controller 3 makes a final determination of whether the system in which the ground fault has occurred is the first system 110 or the second system 120, or whether a ground fault has actually occurred.

[0087] When the controller 3 determines that the first system 110 has failed (step S104, Yes), it performs FOP to supply power from the backup power supply 20 to the load 101 (step S105). Next, the controller 3 degenerates the communication function and communicates with the upper control device 200 (step S106).

[0088] At this time, the controller 3 transmits data necessary for the FOP to the upper control device 200 and stops the transmission of unnecessary data to the FOP, thereby degrading the communication function. The controller 3 may also degrade the communication function by making the communication cycle with the upper control device 200 longer than normal.

[0089] Next, the controller 3 requests the loads 101 operating on the backup power supply 20 to degrade their communication functions (step S107). At this time, the controller 3 degrades the communication functions by continuing to send and receive necessary data to the FOP and stopping the sending and receiving of unnecessary data to the FOP. The controller 3 may also degrade the communication functions by making the communication cycle of each load 101 longer than normal.

[0090] Thereafter, the controller 3 determines whether the FOP has ended (step S108). At this time, the controller 3 determines that the FOP has ended, for example, when it receives information indicating that the FOP has ended from the upper control device 200.

[0091] In addition, when the upper control device 200 detects that the vehicle has stopped on a safe shoulder of the road based on images from an onboard camera or information obtained from a GPS (Global Positioning System), it sends information indicating that the FOP has ended to the controller 3.

[0092] If the controller 3 determines that the FOP has not ended (step S108, No), it repeats the determination in step S108 until the FOP ends. If the controller 3 determines that the FOP has ended (step S108, Yes), it ends the process.

[0093] Furthermore, if the controller 3 determines that the first system 110 is not faulty (step S104, No), it determines whether the second system 120 is faulty (step S109). If the second system 120 is faulty (step S109, Yes), the controller 3 turns off the battery switch 41 (step S110) and performs FOP, which supplies power from the main power supply 10 to the load 101 (step S111).

[0094] Thereafter, the controller 3 continues communication with the upper control device 200 without degrading the communication function (step S112), and ends the process. If the second system 120 has not failed (step S109, No), that is, if a ground fault has not occurred, the controller 3 turns on the inter-system switch 42 and turns off the battery switch 41 (step S113), returning to the normal state (see FIG. 2), and ends the process.

[0095] In the above embodiment, the case where the power supply control device 1 includes the system switch 42 has been described, but the power supply control device 1 may be configured not to include the system switch 42. In this case, the backup power supply 20 is provided outside the power supply control device 1. The power supply control device 1 is also provided with a battery switch that can connect and disconnect the main power supply 10 and the first system 110.

[0096] When a ground fault occurs, the controller 3 controls all the switches to turn off only one switch from a state in which all the switches are on. Then, when the first system voltage V1 or the second system voltage V2 recovers to a normal voltage after turning off a switch, the controller 3 identifies the location where that switch is installed as the ground fault location, and performs FOP by maintaining the switch at the ground fault location in the off state.

[0097] Further advantages and modifications will readily occur to those skilled in the art. Therefore, the invention in its broader aspects is not limited to the specific details and representative embodiments shown and described above. Accordingly, various modifications may be made without departing from the spirit or scope of the general inventive concept as defined by the appended claims and their equivalents. [Explanation of symbols]

[0098] 1 Power supply control device 3 Controller 10 Main power supply 12 High-voltage battery 20 Backup power supply 31 Microcomputer 41 Battery switch 42 Intersystem switch 43 First load switch 44 Second load switch 51 First voltage sensor 52 Second voltage sensor 63 Power supply side resistance 64 Upper Resistor 101 Load 110 1st system 120 2nd system 130 Intersystem Line 200 Upper control device 201 Controller 202 Microcomputer 32 CAN transceivers 203 CAN receiver 61 CAN High Line 62 CANLow Line 11 DCC

Claims

1. a controller that communicates with other control devices and performs backup control to supply power from a backup power source to a load when a failure of the main power source is detected; The controller When the backup control is performed, the communication function is degraded. Power control device.

2. The controller transmits data necessary for the backup control and stops transmitting data unnecessary for the backup control, thereby degrading the communication function. The power supply control device according to claim 1 .

3. The controller degrades the communication function by making the communication cycle longer than normal. The power supply control device according to claim 1 .

4. The controller does not degrade the communication function when detecting a failure of the backup power supply and performing backup control to supply power from the main power supply to the load. The power supply control device according to claim 1 .

5. When performing backup control to supply power from a backup power supply to a load, the controller requests the load operating on the backup power supply to degrade its communication function. The power supply control device according to claim 1 .

6. A controller that communicates with other control devices and performs backup control to supply power to a load from a backup power source when a failure of the main power source is detected. A procedure for degrading communication functions when performing the backup control. A control program that executes the above.

Citation Information

Patent Citations

  • Power control unit

    JP2022130215A