Power control unit
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-10-06
- Publication Date
- 2026-08-13
AI Technical Summary
【0008】 本発明によれば、比較器によって電力系統の失陥が検出された場合、ラッチ回路から瞬時にラッチ信号が出力されて特定スイッチが駆動するため、速やかにバックアップ状態に移行できる。また、ラッチ回路は、ラッチ信号を出力した後は、クリアされるまでラッチ信号を出力し続けてバックアップ状態を維持することから、バックアップ状態を確実に維持することができる。
Smart Images

Figure 0007905005000001 
Figure 0007905005000002 
Figure 0007905005000003
Abstract
Description
Technical Field
[0001] The present invention relates to a power control device.
Background Art
[0002] Conventionally, in a power control device that performs backup control using a backup power supply when the main power supply fails, a device that detects a power failure with a hardware circuit and immediately starts backup control is known (see, for example, Patent Document 1).
[0003] In the above prior art, when the hardware circuit detects a power failure, it outputs a fixed-width one-shot pulse to cut off the inter-system switch and enter the backup state, and notifies a microcomputer (hereinafter sometimes referred to as a "microcontroller"). When the microcontroller receives a notification of a power failure, it outputs a drive signal to maintain the cutoff state of the inter-system switch and maintains the backup state. The microcontroller executes a process of determining a grounded system while maintaining the backup state.
Prior Art Documents
Patent Documents
[0004]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0005] However, in the above prior art, the microcontroller takes over the maintenance of the backup state upon receiving a notification from the hardware circuit. Therefore, for example, if the notification from the hardware circuit to the microcontroller is delayed or fails due to some reason such as noise, the microcontroller cannot take over the maintenance of the backup state. As a result, if the microcontroller cannot take over the maintenance of the backup state before the pulse period of the one-shot pulse by the hardware circuit ends, the device returns from the backup state to the normal state.
[0006] The present invention has been made in view of the above, and aims to provide a power control device that can quickly switch to a backup state when a power failure is detected and can reliably maintain the backup state. [Means for solving the problem]
[0007] To solve the above problems and achieve the objective, the power control device in the present invention comprises a comparator, a latch circuit, and a microcomputer. The comparator compares the voltage of the power system supplied with power from the main power supply to a threshold value to detect a power system failure and outputs a detection signal. The latch circuit latches the detection signal and outputs a latch signal, which drives a specific switch that controls the power supply to the load. When the microcomputer receives the latch signal, it determines whether the comparator's detection of the power system failure is correct, and if it determines that the power system has not failed, it clears the latch circuit and stops the output of the latch signal. [Effects of the Invention]
[0008] According to the present invention, when a power system failure is detected by the comparator, a latch signal is instantly output from the latch circuit, driving a specific switch, thus enabling a rapid transition to the backup state. Furthermore, after outputting the latch signal, the latch circuit continues to output the latch signal until it is cleared, maintaining the backup state reliably. [Brief explanation of the drawing]
[0009] [Figure 1] Figure 1 is an explanatory diagram showing an example configuration of a control system according to the first embodiment. [Figure 2] Figure 2 is an explanatory diagram showing an example of operation of a power control device, etc., according to the first embodiment. [Figure 3] Figure 3 is an explanatory diagram showing an example of operation of a power control device, etc., according to the first embodiment. [Figure 4] Figure 4 is an explanatory diagram showing an example of operation of a power control device, etc., according to the first embodiment. [Figure 5] Figure 5 shows an example of the configuration of a defect detection device according to the first embodiment. [Figure 6A] Figure 6A is a time chart of the processes performed by the power control device and the like. [Figure 6B] Figure 6B is a time chart of the processes performed by the power control device and other components. [Figure 7] Figure 7 is a flowchart showing an example of a process performed by the controller of the power control device according to the first embodiment. [Figure 8] Figure 8 is an explanatory diagram showing an example configuration of the control system according to the second embodiment. [Figure 9] Figure 9 is an explanatory diagram showing an example of operation of the power control device according to the second embodiment. [Figure 10] Figure 10 is an explanatory diagram showing an example of operation of the power control device according to the second embodiment. [Figure 11] Figure 11 is an explanatory diagram showing an example of operation of the power control device according to the second embodiment. [Figure 12] Figure 12 is an explanatory diagram showing an example of operation of the power control device according to the second embodiment. [Figure 13] Figure 13 shows an example of the configuration of a loss detection device according to the second embodiment. [Figure 14A] Figure 14A is a time chart of the processes performed by the power control device, etc., according to the second embodiment. [Figure 14B] Figure 14B is a time chart of the processes performed by the power control device, etc., according to the second embodiment. [Figure 15] Figure 15 is a flowchart showing an example of a process performed by the controller of the power control device according to the second embodiment. [Modes for carrying out the invention]
[0010] Hereinafter, embodiments of the power control device will be described in detail with reference to the accompanying drawings. Note that the present invention is not limited to the embodiments described below. The power control device according to the embodiment is mounted on an electric vehicle, a hybrid vehicle, or an engine vehicle that runs by an internal combustion engine, which has an automatic driving function.
[0011] [1. First Embodiment] [1-1. Configuration of Control System] FIG. 1 is an explanatory diagram showing a configuration example of a control system 100 according to the first embodiment. As shown in FIG. 1, the control system 100 according to the embodiment includes a power control device 1, a main power supply 10, and an automatic driving control device 60. Further, the power control device 1 is electrically connected to a first load 101, a second load 102, and a third load 103.
[0012] The first load 101 is connected between the main power supply 10 and the power control device 1. The first load 101 includes, for example, a display, an air conditioner, an audio, a video, and various lights. Specifically, the first load 101 includes an electrical load (general load) that has nothing to do with the running of the vehicle itself.
[0013] [[ID=十六]]The second load 102 is connected between the main power supply 10 and the power control device 1 and is also connected to a backup switch 44 of the power control device 1 described later. The second load 102 includes, for example, an electric brake device, an electric accelerator device, etc. In other words, the second load 102 includes an electrical load required during the running of the vehicle. Specifically, it includes an electrical load (running load) required during normal driving including manual driving and during automatic driving. The second load 102 is directly supplied with power from the main power supply 10 via the line 80 and is also supplied with power from the backup power supply 20 via the backup switch 44. Note that the second load 102 is an example of a load.
[0014] The third load 103 is connected to the power control device 1. The third load 103 includes, for example, the steering device. In other words, the third load 103 includes the electrical load necessary for the vehicle to run, and more specifically, the electrical load (driving load) necessary during normal operation, including manual operation, and during automatic operation. The second load 102 and the third load 103 are loads to which power is supplied when evasive driving control is performed by automatic operation in the event of a power failure, as described later. Furthermore, although specific devices have been shown for the first to third loads 101 to 103 above, these are merely examples and not limiting.
[0015] The main power supply 10 includes a DC / DC converter (hereinafter referred to as "DC / DC11") and a lead-acid battery (hereinafter referred to as "PbB12"). The battery for the main power supply 10 may be any secondary battery other than the PbB12.
[0016] DC / DC11 is connected to a generator (not shown) and a high-voltage battery (not shown) with a higher voltage than PbB12, and steps down the voltages of the generator and the high-voltage battery to output to the main power system line 70. The generator is, for example, an alternator that generates electricity by converting the kinetic energy of a moving vehicle. The high-voltage battery is, for example, a vehicle drive battery installed in an electric vehicle or a hybrid vehicle.
[0017] When installed in an engine-powered vehicle, the main power supply 10 is replaced by an alternator (generator) instead of the DC / DC 11. The DC / DC 11 charges the PbB 12 and the backup power supply 20, which will be described later. The main power supply 10 also supplies power to multiple electrical loads installed in the vehicle, namely the first to third loads 101 to 103.
[0018] The automatic driving control device 60 is connected to the power control device 1. The automatic driving control device 60 is a device that controls the vehicle to drive automatically. The automatic driving control device 60 drives the vehicle by operating, for example, the second load 102 and the third load 103. In addition, if, for example, the main power system line 70 including the main power supply 10 fails, the automatic driving control device 60 can perform a fail-operation (FOP) control using the second load 102 and the third load 103. A fail-operation means, for example, driving the vehicle to a safe place and stopping it.
[0019] The power control device 1 is a device that controls the power supply to the second load 102 and the third load 103. The power control device 1 comprises a controller 3, a backup power supply 20, a failure detection device 30, first to third switches 41 to 43, a backup switch 44, and a DC / DC converter 45 (hereinafter referred to as "DC / DC 45").
[0020] The backup power supply 20 is a backup power supply for when the main power supply 10 is unable to supply power. The backup power supply 20 is equipped with a lithium-ion battery (hereinafter referred to as "LiB21"). However, the battery of the backup power supply 20 may be any secondary battery other than LiB21.
[0021] The failure detection device 30 detects failures of the main power supply 10. Examples of failures of the main power supply 10 include ground faults in the main power supply system line 70, which includes the main power supply 10. The failure detection device 30 is connected to the main power supply system line 70. For example, the failure detection device 30 detects a failure of the main power supply 10 when the voltage of the main power supply system line 70, which includes the main power supply 10, falls below a preset ground fault threshold. The detailed configuration of the failure detection device 30 will be described later with reference to Figure 5.
[0022] The first switch 41 is provided in the main power supply line 70. More specifically, the first switch 41 is provided in the main power supply line 70 between connection point 71 to which the first load 101 is connected and the third load 103. The first switch 41 is provided in the main power supply line 70 between connection point 72 to which the second load 102 is connected and the third load 103. The first switch 41 is provided in the main power supply line 70 between connection point 73 to which the failure detection device 30 is connected and the third load 103. In other words, the first switch 41 is provided in the power path between the main power supply 10 and the third load 103 and is a switch that can connect and disconnect (cut off) this power path. The first switch 41 is controlled by the controller 3. For example, the first switch 41 is turned on during normal operation, including manual operation, and turned off during automatic operation and in the event of a power failure.
[0023] DC / DC45 is connected in parallel with the first switch 41. DC / DC45 is configured to boost or buck the voltage output from the main power supply 10. The second switch 42 is connected in series with DC / DC45. The second switch 42 is controlled by the controller 3. For example, the second switch 42 is turned off during normal operation, including manual operation, and turned on during automatic operation and in the event of a power failure.
[0024] The third switch 43 is located between the backup power supply 20 and the second load 102. In other words, the third switch 43 is located in the power path between the backup power supply 20 and the second load 102, and is a switch that can connect and disconnect this power path. The third switch 43 is also connected to the connection point 74 between the DC / DC 45 and the second switch 42. The third switch 43 is controlled by the controller 3. For example, the third switch 43 functions as the system's main relay and is always on, including during normal operation, automatic operation, and power failure.
[0025] The backup switch 44 is located between the backup power supply 20 and the second load 102. In other words, the backup switch 44 is located in the power path between the backup power supply 20 and the second load 102, and is a switch that can connect and disconnect this power path. The backup switch 44 is also connected to the connection point 74 between the DC / DC 45 and the second switch 42, and to the connection point 75 between the DC / DC 45 and the third switch 43. The backup switch 44 is controlled by the controller 3 and the failure detection device 30. For example, the backup switch 44 is turned off during normal operation, including manual operation, and during automatic operation, and turned on in the event of a power failure. The on / off operation of the backup switch 44 by the controller 3 and the failure detection device 30 will be described in detail later. The backup switch 44 is also an example of a specific switch that controls the power supply to the second load 102, which is a load.
[0026] The power control device 1 includes a voltage sensor 51. The voltage sensor 51 is installed on the main power supply line 70. The voltage sensor 51 detects the voltage of the main power supply line 70, including the main power supply 10, and outputs the detection result to the controller 3.
[0027] Controller 3 includes a microcomputer (MCU) with a CPU (Central Processing Unit), ROM (Read Only Memory), RAM (Random Access Memory), and various circuits.
[0028] Controller 3 may be composed of hardware such as an ASIC (Application Specific Integrated Circuit) or FPGA (Field Programmable Gate Array), either partially or entirely. Furthermore, Controller 3 is an example of a microcontroller.
[0029] Controller 3 controls the operation of the first to third switches 41 to 43, the backup switch 44, and the failure detection device 30, etc., by having the CPU execute a program stored in ROM using RAM as a working area.
[0030] Furthermore, the controller 3 obtains information indicating the remaining charge of the backup power supply 20, which is acquired from the backup power supply 20 via the status monitoring line 23. The information indicating the remaining charge of the backup power supply 20 is, for example, the State of Charge (SOC) of the LiB 21.
[0031] LiB21 has maximum charge when its SOC is 100%. LiB21 has no charge when its SOC is 0%. Controller 3 monitors the SOC of LiB21 and, when the SOC falls below a specified value that serves as the criterion for starting charging, uses the power of the main power supply 10 to charge the backup power supply 20.
[0032] Controller 3 is installed in a vehicle with an autonomous driving function and performs fail-safe control (described later) that supplies power from the backup power supply 20 to the loads (for example, the second load 102 and the third load 103) in the event that the main power system line 70, including the main power supply 10, fails.
[0033] [1-2. Examples of operation of power control devices, etc.] Next, the operation of the power control device 1, etc., according to the first embodiment will be described with reference to Figures 2 to 4. Figures 2 to 4 are explanatory diagrams showing examples of operation of the power control device 1, etc., according to the first embodiment.
[0034] [1-2-1. Operation during normal operation] When the vehicle's ignition switch (IG) is turned ON, the controller 3 controls the first to third switches 41 to 43 and the backup switch 44 during normal operation, including manual operation, as shown in Figure 2.
[0035] Specifically, controller 3 turns on the first switch 41 and the third switch 43. Controller 3 also turns off the second switch 42 and the backup switch 44. This allows the power control device 1 to supply power from the main power supply 10 to the first load 101, the second load 102, and the third load 103. In addition, if the State of Charge (SOC) of the LiB 21 is below a specified value, controller 3 can charge the LiB 21 by boosting or bucking the power from the main power supply 10 using the DC / DC converter 45 and supplying it to the backup power supply 20.
[0036] [1-2-2. Operation during autonomous driving] During automatic operation, the controller 3 turns on the second switch 42 and the third switch 43, as shown in Figure 3. The controller 3 also turns off the first switch 41 and the backup switch 44. This allows the power control device 1 to supply power from the main power supply 10 to the first load 101 and the second load 102. The power control device 1 can also supply power from the main power supply 10 to the third load 103 while boosting the voltage using the DC / DC converter 45. Furthermore, if the State of Charge (SOC) of the LiB 21 is below a specified value, the controller 3 can charge the LiB 21 by supplying power from the main power supply 10 to the backup power supply 20 while boosting or bucking the voltage using the DC / DC converter 45.
[0037] [1-2-3. Actions to take when a position is lost] In the control system 100, the main power supply 10 may fail, such as due to a ground fault in the main power supply line 70 including the main power supply 10. When the main power supply 10 fails, the control system 100, including the controller 3, performs fail-safe control by supplying power from the backup power supply 20 to the load.
[0038] Specifically, as shown in Figure 4, when the main power supply 10 fails, the backup switch 44 is turned on by a signal (a latch signal described later) output from the failure detection device 30 that detected the failure. This latch signal is also output to the controller 3. Upon receiving the latch signal, the controller 3 turns on the second switch 42 and the third switch 43. The controller 3 then turns off the first switch 41. As a result, the second load 102 and the third load 103 are supplied with power from the backup power supply 20. In other words, the control system 100, including the controller 3, enters a backup state. It should be noted that the failure of the main power supply 10 detected here may be a transient voltage drop, so it can be said that the failure detection device 30 has tentatively determined that a failure has occurred in the main power supply 10.
[0039] Controller 3 notifies the automatic driving control device 60 that the main power supply 10 has failed and fail-safe control using the backup power supply 20 has been initiated. When the automatic driving control device 60 is notified that fail-safe control using the backup power supply 20 has been initiated, it initiates automatic escape operation control (FOP), for example, by driving the vehicle to a safe location and stopping it.
[0040] [1-3. Example of a Loss Detection Device Configuration] Next, with reference to Figure 5, an example of the configuration of the failure detection device 30 of the power control device 1 according to the first embodiment will be described. Figure 5 is a diagram showing an example of the configuration of the failure detection device 30 according to the first embodiment.
[0041] As shown in Figure 5, the failure detection device 30 includes a comparator 31, a latch circuit 32, and an OR logic circuit 33. The comparator 31 detects a failure of the main power supply 10 and outputs a detection signal. Specifically, the comparator 31 is a comparator that compares the voltage of the main power supply system line 70, which includes the main power supply 10 (voltage detected by the voltage sensor 51), with a ground fault threshold. When the voltage of the main power supply system line 70 falls below the ground fault threshold, the comparator 31 detects a power failure and outputs a detection signal to the latch circuit 32. In other words, the comparator 31 makes a preliminary determination of a power failure. In this way, the comparator 31 detects a power failure by comparing the voltage of the main power supply system line 70 (an example of a power system) to which the power of the main power supply 10 is supplied with a ground fault threshold (an example of a threshold) and outputs a detection signal.
[0042] The latch circuit 32 latches (holds) the detection signal input from the comparator 31 and outputs the latch signal to the OR logic circuit 33. The OR logic circuit 33 connects the backup switch 44 by outputting the latch signal from the latch circuit 32 as a connection signal to the backup switch 44. In other words, the latch circuit 32 drives (turns on) the backup switch 44 via the OR logic circuit 33 in response to the latch signal.
[0043] As described above, the failure detection device 30 according to this embodiment is composed of hardware circuits including a comparator 31 and a latch circuit 32. This allows the backup switch 44 to be driven (connected) early when a failure of the main power supply 10 is detected. In other words, in this embodiment, the system can quickly transition to the backup state when a failure of the main power supply 10 is detected.
[0044] Furthermore, the latch circuit 32 also outputs a latch signal to the controller 3. Upon receiving the latch signal, the controller 3 makes a final determination of the failure state of the main power supply 10. More specifically, the controller 3 makes a final determination of whether the failure of the main power supply 10 detected by the failure detection device 30 is a true failure or a false detection caused by a temporary voltage drop or the like. In other words, the controller 3 makes a final determination of whether the detection of power system failure by the comparator 31 is correct or not.
[0045] For example, the controller 3 determines, based on the output of the voltage sensor 51 (see Figure 1), whether the voltage of the main power supply line 70, including the main power supply 10, is below the ground fault threshold. In other words, the controller 3 determines whether the main power supply 10 has failed. If the voltage of the main power supply line 70 remains below the ground fault threshold for a specified period of time or longer, the controller 3 determines that the main power supply 10 has failed. If the controller 3 determines that the main power supply 10 has failed, it determines that the failure of the main power supply 10 detected by the failure detection device 30 is not a false detection; in other words, it determines that it is a true failure.
[0046] On the other hand, the controller 3 determines that the main power supply 10 has not failed if the voltage of the main power supply line 70 remains higher than the ground fault threshold for a specified period of time or longer. If the controller 3 determines that the main power supply 10 has not failed, it determines that the failure of the main power supply 10 detected by the failure detection device 30 is a false detection caused by a temporary voltage drop or the like. If the controller 3 determines that the main power supply 10 has not failed, it outputs a clear signal to the latch circuit 32, clearing the latch circuit 32 and stopping the output of the latch signal. As a result, the backup switch 44 returns to its original state, i.e., the tripped state.
[0047] In this embodiment, the latch circuit 32 connects the backup switch 44 via a latch signal. When the controller 3 (microcontroller) receives the latch signal, it determines whether the main power supply 10 has failed. If it determines that the main power supply 10 has not failed, it clears the latch circuit 32 and stops outputting the latch signal. This allows for a quick transition to the backup state when a failure of the main power supply 10 is detected, and ensures that the backup state is reliably maintained. In other words, when the main power supply 10 fails, the latch circuit 32 instantly outputs a latch signal, causing the backup switch 44 to conduct, thus enabling a quick transition to the backup state. Furthermore, after outputting the latch signal, the latch circuit 32 continues to output the latch signal until it is cleared by the controller 3, thus maintaining the backup state. Therefore, the backup state can be reliably maintained.
[0048] As mentioned above, the latch circuit 32 is cleared when it receives a clear signal from the controller 3. However, during this clearing process, the voltage of the main power supply line 70 may drop below the ground fault threshold again, causing the main power supply 10 to fail. In such a case, because the latch circuit 32 is in the process of clearing, it cannot receive the detection signal from the comparator 31 indicating the failure of the main power supply 10. Therefore, even though the main power supply 10 has failed, the latch circuit 32 cannot output a latch signal, and as a result, it may not be able to transition to the backup state where the backup switch 44 is connected.
[0049] Therefore, in the controller 3 according to this embodiment, upon receiving a latch signal, it outputs a backup drive signal to the OR logic circuit 33 that drives (conducts) the backup switch 44. The OR logic circuit 33 connects the backup switch 44 by outputting the backup drive signal from the controller 3 or the latch signal from the latch circuit 32 as a connection signal to the backup switch 44. Furthermore, after clearing the latch circuit 32, the controller 3 re-determines whether the main power supply 10 is normal or abnormal, and maintains or releases the output of the backup drive signal according to the determination result.
[0050] This makes it possible to maintain the backup state by connecting the backup switch 44, even if, for example, the voltage of the main power supply line 70 drops below the ground fault threshold again and the main power supply 10 is lost during the clearing process in the latch circuit 32.
[0051] The above process will now be explained in detail with reference to Figures 6A and 6B. Figures 6A and 6B are time charts of the processes performed by the power supply control device 1, etc. Figure 6A shows an example in which the main power supply 10 fails again during the clearing process in the latch circuit 32. Figure 6B shows an example in which the main power supply 10 does not fail again.
[0052] As shown in Figure 6A, when the voltage of the main power supply line 70 falls below the ground fault threshold (see time T1), the comparator 31 detects (i.e., makes a preliminary determination) the failure of the main power supply 10 and outputs a detection signal to the latch circuit 32. The latch circuit 32 latches the detection signal and outputs a latch signal, connecting the backup switch 44. The latch circuit 32 also outputs a latch signal to the controller 3.
[0053] When controller 3 receives a latch signal, it outputs a backup drive signal to drive the backup switch 44 (see time T2). As a result, the OR logic circuit 33 receives both the backup drive signal and the latch signal.
[0054] Furthermore, when controller 3 receives a latch signal, it performs a process (main determination) to determine the failure state of the main power supply 10. Specifically, controller 3 determines whether the failure of the main power supply 10 detected by the failure detection device 30 (comparator 31) is a false detection caused by a temporary voltage drop or the like. Here, controller 3 checks whether the voltage of the main power supply line 70 remains below the ground fault threshold for a determination time T or longer. Controller 3 also checks whether the voltage of the main power supply line 70 remains above the ground fault threshold for a determination time T or longer. In Figure 6A, the voltage of the main power supply line 70 is below the ground fault threshold from time T1 to time T3, but the time T3-T1 during which it is below the ground fault threshold is shorter than the determination time T. Therefore, controller 3 does not determine that the main power supply 10 has failed. On the other hand, the voltage of the main power supply line 70 exceeds the ground fault threshold for a determination time T or longer from time T3 onward. Therefore, the controller 3 determines that the voltage of the main power supply line 70 continues for a judgment time T or longer, and makes a final determination that the main power supply 10 has not failed. In other words, the controller 3 determines that the failure of the main power supply 10 detected by the failure detection device 30 (comparator 31) was a false detection caused by a temporary voltage drop, etc., and that the main power supply 10 is normal (see time T4).
[0055] If the controller 3 determines that the main power supply 10 is not failing and is functioning normally, it outputs a clear signal (Lo signal) to the latch circuit 32, clearing the latch circuit 32 and stopping the output of the latch signal (see time T5). Here, we assume that during the clearing process of the latch circuit 32, the voltage of the main power supply line 70 drops again below the ground fault threshold, causing the main power supply 10 to fail (see time T6). At this time, the comparator 31 outputs a voltage drop detection signal at time T6, but because the latch circuit 32 is in the process of clearing, it cannot detect the detection signal from the comparator 31 and cannot output a latch signal (Hi signal). However, since the controller 3 has been outputting a backup drive signal since time T2, the backup switch 44 remains connected.
[0056] After clearing the latch circuit 32, controller 3 executes the process of determining the failure state of the main power supply 10 again. In other words, controller 3 re-determines whether the main power supply 10 (power system) is normal or abnormal.
[0057] If the voltage of the main power supply line 70 remains below the ground fault threshold for a judgment time T or longer, the controller 3 determines that the main power supply 10 has failed again, that is, that the main power supply 10 is abnormal (see time T7). If the controller 3 determines that the main power supply 10 is abnormal, it performs backup processing to maintain the output of the backup drive signal, in other words, it maintains the connection of the backup switch 44.
[0058] This allows the backup switch 44 to be connected and the backup state to be maintained even if, for example, the voltage of the main power supply line 70 drops below the ground fault threshold again and the main power supply 10 is lost during the clearing process in the latch circuit 32.
[0059] Next, we will explain with reference to Figure 6B the case where, after clearing the latch circuit 32, the voltage of the main power supply line 70 does not fall below the ground fault threshold again, that is, the case where the main power supply 10 returns to a normal state from a temporary voltage drop.
[0060] As shown in Figure 6B, at time T5, the controller 3 clears the latch circuit 32 and then performs the process of determining the failure state of the main power supply 10 again. The controller 3 determines that the main power supply 10 is normal if the voltage of the main power supply line 70 is continuously higher than the ground fault threshold for a determination time T or longer (see time T7). If the controller 3 determines that the main power supply 10 is normal, it cancels the output of the backup drive signal, in other words, it shuts off the backup switch 44 (see time T8). Accordingly, the controller 3 returns from the backup state to the normal state and performs normal processing.
[0061] As a result, in this embodiment, even if the failure of the main power supply 10 detected by the failure detection device 30 is a false detection caused by a temporary voltage drop or the like, the system can quickly return from the backup state to the normal processing state.
[0062] In the first embodiment, the controller 3 immediately output a backup drive signal upon receiving a latch signal, but it is not limited to this. Specifically, the controller 3 only needs to output a backup drive signal between receiving the latch signal and outputting the clear signal.
[0063] [1-4. Processes executed by the power control unit's controller] Next, with reference to Figure 7, the processes executed by the controller 3 of the power control device 1 according to the first embodiment will be described. Figure 7 is a flowchart showing an example of the processes executed by the controller 3 of the power control device 1 according to the first embodiment. The processes shown in Figure 7 are executed repeatedly at predetermined intervals, but are not limited to this.
[0064] As shown in Figure 7, the controller 3 determines whether or not it has received a latch signal from the latch circuit 32 (step S101). Specifically, when the voltage of the main power supply line 70 falls below the ground fault threshold, a detection signal is output from the comparator 31 of the failure detection device 30, and the controller 3 determines whether or not it has received a latch signal from the latch circuit 32 that latches this detection signal. In other words, the controller 3 determines whether or not a provisional determination of power failure has been made by the failure detection device 30. Since this latch signal is also output to the backup switch 44 via the OR logic circuit 33, the backup switch 44 is in a connected (conductive) state.
[0065] If controller 3 determines that it has not received a latch signal from latch circuit 32 (step S101, No), it skips the subsequent processing. On the other hand, if controller 3 determines that it has received a latch signal from latch circuit 32 (step S101, Yes), it outputs a backup drive signal to conduct to the backup switch 44 (step S102).
[0066] Next, the controller 3 executes the main determination process to determine the failure status of the main power supply 10 (step S103). Specifically, the controller 3 determines whether or not the main power supply 10 has failed. Specifically, the controller 3 determines whether or not the voltage of the main power supply system line 70 is between the ground fault threshold and the determination time T, that is, whether or not the main power supply 10 has failed. The controller 3 also determines whether or not the voltage of the main power supply system line 70 is higher than the ground fault threshold and the determination time T, that is, whether or not the main power supply 10 is in a normal state and has not failed.
[0067] Next, the controller 3 determines whether the result of step S103 was a failure of the main power supply 10 (step S104). If the controller 3 determines that the main power supply 10 has failed (step S104, Yes), it repeats the process of step S104. As a result, when the controller 3 determines that the main power supply 10 has failed, it continues to output the backup drive signal output in step S102 until the main power supply 10 returns to normal (until the voltage of the main power supply line 70 is higher than the ground fault threshold). In this case, the backup switch 44 is kept connected by both the latch signal output from the latch circuit 32 and the backup drive signal output from the controller 3, and fail-safe control is performed.
[0068] On the other hand, if the controller 3 determines that the main power supply 10 has not failed (step S104, No), it outputs a clear signal to the latch circuit 32 (step S105). In other words, the controller 3 clears the latch circuit 32 and stops outputting the latch signal.
[0069] Next, the controller 3 determines again whether the main power supply 10 has failed (step S106). In other words, the controller 3 determines again whether the main power supply 10 is normal or abnormal. Specifically, the controller 3 determines whether the voltage of the main power supply line 70 is between the ground fault threshold and the determination time T, and whether the voltage of the main power supply line 70 is higher than the ground fault threshold and the determination time T.
[0070] Next, the controller 3 determines whether the result of step S106 was a failure of the main power supply 10 (step S107). If the controller 3 determines that the main power supply 10 is not failed (step S107, No), that is, if the main power supply 10 is functioning normally, it cancels the output of the backup drive signal (step S108). As a result, the output of both the latch signal and the backup drive signal is stopped, and the backup switch 44 returns to its normal state (off state).
[0071] On the other hand, if the controller 3 determines that the main power supply 10 has failed (step S107, Yes), that is, if the main power supply 10 is abnormal, it continues to output the backup drive signal (step S109). As a result, the latch signal output is stopped, but because the controller 3 continues to output the backup drive signal, the backup switch 44 maintains its connected state and fail-safe control continues.
[0072] As described above, the power control device 1 according to the first embodiment includes a comparator 31, a latch circuit 32, and a controller 3 (an example of a microcontroller). The comparator 31 compares the voltage of the main power system line 70 (an example of a power system) to which the power of the main power supply 10 is supplied with a ground fault threshold (an example of a threshold) to detect a failure in the main power system line 70 and outputs a detection signal. The latch circuit 32 latches the detection signal and outputs a latch signal, which drives a backup switch 44 (an example of a specific switch) that controls the power supply to the second load 102 (an example of a load). When the controller 3 receives the latch signal, it determines whether the detection of the failure of the main power system line 70 by the comparator 31 is correct or not, and if it determines that the main power system line 70 has not failed, it clears the latch circuit 32 and stops outputting the latch signal. This allows for a quick transition to the backup state when a power failure is detected, and ensures that the backup state is reliably maintained.
[0073] More specifically, the power control device 1 according to the first embodiment includes a backup switch 44, a comparator 31, a latch circuit 32, and a controller 3 (an example of a microcontroller). The backup switch 44 connects and disconnects the power path between the second load 102 (an example of a load) to which the main power supply 10 is supplied and the backup power supply 20. The comparator 31 compares the voltage of the main power supply system line 70 (an example of a power system) to which the main power supply 10 is supplied with a ground fault threshold (an example of a threshold) to detect a failure in the main power supply system line 70 and outputs a detection signal. The latch circuit 32 latches the detection signal and outputs a latch signal, and connects the backup switch 44 based on the latch signal. When the controller 3 receives the latch signal, it determines whether the detection of the failure of the main power supply system line 70 by the comparator 31 is correct or not, and if it determines that the main power supply system line 70 has not failed, it clears the latch circuit 32 and stops outputting the latch signal. This allows for a quick transition to the backup state when a power supply failure is detected, and ensures that the backup state is reliably maintained.
[0074] [2. Second Embodiment] [2-1. Control System Configuration] Next, the control system 100, including the power control device 1a according to the second embodiment, will be described with reference to Figure 8. Figure 8 is an explanatory diagram showing an example configuration of the control system 100 according to the second embodiment. In the following description, components common to the first embodiment will be denoted by the same reference numerals and their descriptions will be omitted.
[0075] The power control device 1a according to the second embodiment includes a controller 3, a backup power supply 20, a failure detection device 30, a first system line 110, a second system line 120, an inter-system line 130, an inter-system switch 151, a battery switch 152, and first to fifth switches 201 to 205.
[0076] The first power supply line 110 is a power supply line that supplies power from the main power supply 10 to multiple electrical loads. More specifically, the first power supply line 110 is the line that supplies power from the main power supply 10 to the first load 101, the second load 102, and the third load 103. In other words, the power supply system for the main power supply 10 includes the main power supply 10 and the first power supply line 110.
[0077] The second system line 120 is a power supply line that supplies power from the backup power supply 20 to multiple electrical loads. More specifically, the second system line 120 is the line that supplies power from the backup power supply 20 to the second load 102 and the third load 103. In other words, the power supply system for the backup power supply 20 includes the backup power supply 20 and the second system line 120. The inter-system line 130 is a connection line that electrically connects the first system line 110 and the second system line 120. The first load 101, the second load 102, and the third load 103 are examples of the first load. The second load 102 and the third load 103 are examples of the second load.
[0078] The failure detection device 30 according to the second embodiment detects failures in the power supply system. Examples of power supply system failures include ground faults in the first system line 110 including the main power supply 10, and ground faults in the second system line 120 including the backup power supply 20. Therefore, the failure detection device 30 detects failures in either the main power supply 10 or the backup power supply 20. The detailed configuration of the failure detection device 30 will be described later with reference to Figure 13.
[0079] The inter-system switch 151 is a switch that can connect and disconnect (break) the first system line 110 and the second system line 120. The inter-system switch 151 is controlled by the controller 3 and the failure detection device 30. For example, the inter-system switch 151 is turned on during normal operation, including manual operation, and during automatic operation, and turned off in the event of a power failure. The on / off operation of the inter-system switch 151 by the controller 3 and the failure detection device 30 will be described in detail later.
[0080] The inter-system switch 151 may also be a DC / DC switch. In this case, the DC / DC switch connects the first system line 110 and the second system line 120 when it operates. The DC / DC switch disconnects the connection between the first system line 110 and the second system line 120 when it stops operating. The battery switch 152 is a switch that can connect and disconnect (disconnect) the backup power supply 20 and the second system line 120.
[0081] The first switch 201 is a switch that can connect and disconnect the first line 110 and the first load 101. The second switch 202 is a switch that can connect and disconnect the first line 110 and the second load 102. The third switch 203 is a switch that can connect and disconnect the first line 110 and the third load 103.
[0082] The fourth switch 204 is a switch that can connect and disconnect the second line 120 and the second load 102. The fifth switch 205 is a switch that can connect and disconnect the second line 120 and the third load 103.
[0083] Furthermore, the power control device 1a includes a first voltage sensor 51 and a second voltage sensor 52. The first voltage sensor 51 is provided on the first line 110. The first voltage sensor 51 detects the voltage of the first line 110 and outputs the detection result to the controller 3. The second voltage sensor 52 is provided on the second line 120. The second voltage sensor 52 detects the voltage of the second line 120 and outputs the detection result to the controller 3.
[0084] Controller 3 controls the operation of the inter-system switch 151, the battery switch 152, the first to fifth switches 201 to 205, and the failure detection device 30, etc., by having the CPU execute a program stored in ROM using RAM as a working area.
[0085] Controller 3 is installed in vehicles with autonomous driving capabilities and performs fail-safe control by supplying power from the backup power supply 20 to the load in the event of a failure of the main power supply 10. Furthermore, Controller 3 also performs fail-safe control by supplying power from the main power supply 10 to the load in the event of a failure of the backup power supply 20.
[0086] [2-2. Examples of Power Control Device Operation] Next, the operation of the power control device 1a according to the second embodiment will be described with reference to Figures 9 to 12. Figures 9 to 12 are explanatory diagrams showing an example of the operation of the power control device 1a according to the second embodiment.
[0087] [2-2-1. Operation during normal operation] When the vehicle's ignition switch is turned on and the power supply systems for the main power supply 10 and backup power supply 20 are not lost, during normal stationary operation, manual operation, or automatic operation, the controller 3 controls the inter-system switch 151, the battery switch 152, and the first to fifth switches 201 to 205, as shown in Figure 9.
[0088] Specifically, controller 3 turns on the inter-system switch 151. Controller 3 turns off the battery switch 152. Controller 3 turns on the first to fifth switches 201 to 205. As a result, the power control device 1a can supply power from the main power supply 10 to the first load 101, the second load 102, and the third load 103 while suppressing the normal discharge of the LiB 21.
[0089] [2-2-2. Operation in the event of a power supply system failure] In the control system 100 according to the second embodiment, the power supply system may fail due to a ground fault in the first system line 110 including the main power supply 10, or a ground fault in the second system line 120 including the backup power supply 20.
[0090] In the power control device 1a, if a ground fault occurs in the first system line 110 or the second system line 120 during normal operation, the voltages of the first system line 110 and the second system line 120 will become lower than normal voltages.
[0091] Therefore, the failure detection device 30 detects that a failure has occurred in the power supply system when the voltage of the first system line 110, including the main power supply 10, falls below a preset ground fault threshold. However, since it is not possible to determine whether the detected failure in the power supply system is a failure of the main power supply 10 or a failure of the backup power supply 20, it can be said that the failure detection device 30 is making a provisional determination that a failure has occurred in the power supply system. Alternatively, the failure detection device 30 may also detect that a failure has occurred in the power supply system when, for example, the voltage of the second system line 120 falls below a ground fault threshold.
[0092] As shown in Figure 10, when a power failure occurs in the power supply system, the inter-system switch 151 is turned off by a signal (a latch signal described later) output from the failure detection device 30 that detects the failure. This latch signal is also output to the controller 3. Upon receiving the latch signal, the controller 3 turns on the battery switch 152 and outputs a backup drive signal that turns off the inter-system switch 151.
[0093] This disconnects the connection between the first line 110 and the second line 120. Then, if the first line 110 is not ground faulted, the power control device 1a can supply power using the main power supply 10. Also, if the second line 120 is not ground faulted, the power control device 1a can supply power using the backup power supply 20.
[0094] After the failure detection device 30 detects a failure, the controller 3 monitors the first system voltage V1 and the second system voltage V2. The first system voltage V1 is the voltage of the first system line 110 detected by the first voltage sensor 51. The second system voltage V2 is the voltage of the second system line 120 detected by the second voltage sensor 52.
[0095] After the failure detection device 30 detects a failure (after a preliminary determination), the controller 3 makes a final determination that there is a ground fault in the second system line 120 if the second system voltage V2 remains below the ground fault threshold for a determination time T or longer, and the first system voltage V1 recovers to exceed the ground fault threshold for a determination time T or longer.
[0096] In this case, the controller 3 performs fail-safe control to supply power from the main power supply 10 to the loads. Specifically, as shown in Figure 11, the controller 3 turns off the battery switch 152 while keeping the inter-system switch 151 off. The controller 3 also turns off the fourth switch 204 and the fifth switch 205. Then, the controller 3 supplies power from the main power supply 10 to each load 101 to 103 via the first system line 110.
[0097] If the controller 3 determines that the backup power supply 20 has failed, such as when the second system line 120 experiences a ground fault, it notifies the automatic operation control device 60 that the backup power supply 20 has failed and that fail-safe control by the main power supply 10 has been initiated.
[0098] When the automatic driving control device 60 receives notification from the power control device 1a that fail-safe control by the main power supply 10 has started, it starts automatic escape operation control (FOP), for example, by driving the vehicle to a safe location and stopping it.
[0099] Furthermore, after the failure detection device 30 detects a failure (after a preliminary determination), the controller 3 makes a final determination that there is a ground fault in the first system line 110 if the first system voltage V1 remains below the ground fault threshold for a determination time T or longer, and the second system voltage V2 recovers to exceed the ground fault threshold for a determination time T or longer.
[0100] In this case, the controller 3 performs fail-safe control to supply power from the backup power supply 20 to the load. Specifically, as shown in Figure 12, the controller 3 keeps the inter-system switch 151 off and the battery switch 152 on, turns off the first to third switches 201 to 203, and supplies power from the backup power supply 20 to the second load 102 and the third load 103 via the second system line 120.
[0101] If controller 3 determines that the main power supply 10 has failed due to a ground fault in the first system line 110 or the like, it notifies the automatic operation control device 60 that the main power supply 10 has failed and that fail-safe control by the backup power supply 20 has been initiated.
[0102] When the automatic driving control device 60 receives notification from the power control device 1a that fail-safe control using the backup power supply 20 has been initiated, it starts automatic escape operation control (FOP), for example, by driving the vehicle to a safe location and stopping it.
[0103] [2-3. Example of a Loss Detection Device Configuration] Next, with reference to Figure 13, an example of the configuration of the failure detection device 30 of the power control device 1a according to the second embodiment will be described. Figure 13 is a diagram showing an example of the configuration of the failure detection device 30 according to the second embodiment.
[0104] As shown in Figure 13, the failure detection device 30 includes a comparator 31, a latch circuit 32, and an OR logic circuit 33. The comparator 31 detects the failure of the main power supply 10 or the backup power supply 20 and outputs a detection signal. Specifically, the comparator 31 is a comparator that compares the voltage of the first system line 110, which includes the main power supply 10 (first system voltage V1), with a ground fault threshold. When the voltage of the first system line 110 falls below the ground fault threshold, the comparator 31 detects the failure of the main power supply 10 or the backup power supply 20 (i.e., the failure of the power supply system) and outputs a detection signal to the latch circuit 32. In other words, the comparator 31 makes a preliminary determination of power supply failure.
[0105] In the above example, the comparator 31 compares the voltage of the first system line 110 with the ground fault threshold, but it is not limited to this. That is, the comparator 31 may compare the voltage of the second system line 120 (second system voltage V2) with the ground fault threshold, and if the voltage of the second system line 120 falls below the ground fault threshold, it may detect that a power failure has occurred in the power supply system. In this way, the comparator 31 detects a power failure by comparing the voltage of the power system, including the first system line 110 and the second system line 120, with the ground fault threshold (an example of a threshold) and outputs a detection signal.
[0106] The latch circuit 32 latches (holds) the detection signal input from the comparator 31 and outputs the latch signal to the OR logic circuit 33. The OR logic circuit 33 outputs the latch signal from the latch circuit 32 as a cutoff signal to the inter-system switch 151, thereby cutting off the inter-system switch 151. In other words, the latch circuit 32 drives (turns off) the inter-system switch 151 via the OR logic circuit 33 using the latch signal.
[0107] Thus, the failure detection device 30 according to the second embodiment is composed of a hard circuit including a comparator 31 and a latch circuit 32. As a result, in the second embodiment, when a failure of the main power supply 10 or the backup power supply 20 is detected, the inter-system switch 151 can be driven (shut off) early. In other words, in the second embodiment, when a failure of the power supply system is detected, it is possible to quickly switch to the backup state.
[0108] Furthermore, the latch circuit 32 also outputs a latch signal to the controller 3. Upon receiving the latch signal, the controller 3 makes a final determination of the failure status of the main power supply 10 and the backup power supply 20. Specifically, the controller 3 makes a final determination of whether the failure of the main power supply 10 or the backup power supply 20 detected by the failure detection device 30 is a true failure or a false detection caused by a temporary voltage drop or the like. In other words, the controller 3 makes a final determination of whether the detection of power system failure by the comparator 31 is correct or not.
[0109] For example, the controller 3 determines, based on the output of the first voltage sensor 51 (see Figure 8), whether the first system voltage V1 has remained below the ground fault threshold for a judgment time T or longer. In other words, the controller 3 determines whether the power supply system, including the main power supply 10, has failed. The controller 3 also determines, based on the output of the second voltage sensor 52 (see Figure 8), whether the second system voltage V2 has remained below the ground fault threshold for a judgment time T or longer. In other words, the controller 3 determines whether the power supply system, including the backup power supply 20, has failed.
[0110] If the controller 3 determines that the power supply system has failed because at least one of the first system voltage V1 and the second system voltage V2 has remained below the ground fault threshold for a judgment time T or longer, the controller 3 determines that the failure of the power supply system detected by the failure detection device 30 is not a false detection, in other words, it determines that it is a true failure.
[0111] On the other hand, if both the first system voltage V1 and the second system voltage V2 remain above the ground fault threshold for a judgment time T or longer, the controller 3 determines that the main power supply 10 and the backup power supply 20 have not failed. If the controller 3 determines that there has been no failure, it determines that the power supply system failure detected by the failure detection device 30 is a false detection caused by a temporary voltage drop or the like. If the controller 3 determines that the power supply system, including the main power supply 10 and the backup power supply 20, has not failed, it outputs a clear signal to the latch circuit 32, clearing the latch circuit 32 and stopping the output of the latch signal.
[0112] As described above, in the second embodiment, the latch circuit 32 shuts off the inter-system switch 151 with a latch signal. When the controller 3 (microcontroller) receives the latch signal, it determines the failure state of the power supply system, including the main power supply 10 and the backup power supply 20. If it determines that the power supply system has not failed, it clears the latch circuit 32 and stops outputting the latch signal. This allows for a swift transition to the backup state when a failure of the power supply system, including the main power supply 10 and the backup power supply 20, is detected, and ensures that the backup state is reliably maintained. In other words, if the main power supply 10 fails, the latch circuit 32 instantly outputs a latch signal, shutting off the inter-system switch 151, thus allowing for a swift transition to the backup state. Furthermore, after outputting the latch signal, the latch circuit 32 continues to output the latch signal until it is cleared by the controller 3, thus maintaining the backup state. Therefore, the backup state can be reliably maintained.
[0113] As mentioned above, the latch circuit 32 is cleared when it receives a clear signal from the controller 3. However, during this clearing process, the first system voltage V1 (or second system voltage V2) may drop below the ground fault threshold again, causing the power supply system to fail. In such a case, because the latch circuit 32 is in the process of clearing, it cannot receive the detection signal from the comparator 31 indicating the failure of the power supply system. Therefore, even though the power supply system has failed, the latch circuit 32 may not be able to output a latch signal, and as a result, it may not be able to transition to the backup state in which the inter-system switch 151 is shut off.
[0114] Therefore, in the controller 3 according to the second embodiment, upon receiving a latch signal, it outputs a backup drive signal to the OR logic circuit 33 to drive (shut off) the inter-system switch 151. The OR logic circuit 33 shuts off the inter-system switch 151 by outputting the backup drive signal from the controller 3, or the latch signal from the latch circuit 32, as a shut-off signal to the inter-system switch 151. Furthermore, after clearing the latch circuit 32, the controller 3 re-determines whether the main power supply 10 and the backup power supply 20 (power system) are normal or abnormal, and maintains or releases the output of the backup drive signal according to the determination result.
[0115] As a result, even if the voltage of the first system voltage V1 (or the second system voltage V2) drops below the ground fault threshold again and the power supply system fails during the clearing process in the latch circuit 32, it becomes possible to shut off the inter-system switch 151 and continue the backup state.
[0116] Here, the above process will be explained in detail with reference to Figures 14A and 14B. Figures 14A and 14B are time charts of the processes performed by the power control device 1a, etc., according to the second embodiment. Figure 14A shows an example in which the power supply system (in this case, the main power supply 10) fails again during the clearing process in the latch circuit 32. Figure 14B shows an example in which the main power supply 10 does not fail again.
[0117] As shown in Figure 14A, for example, when the first system voltage V1, which is the voltage of the first system line 110, falls below the ground fault threshold (see time T11), the comparator 31 detects the failure of the main power supply 10 or the backup power supply 20 and outputs a detection signal to the latch circuit 32 (provisional determination). The latch circuit 32 latches the detection signal and outputs a latch signal, and shuts off the inter-system switch 151. The latch circuit 32 also outputs a latch signal to the controller 3.
[0118] When controller 3 receives a latch signal, it outputs a backup drive signal that shuts off the inter-system switch 151 (see time T12). As a result, the OR logic circuit 33 receives both the backup drive signal and the latch signal.
[0119] Furthermore, when controller 3 receives a latch signal, it monitors the first system voltage V1 and the second system voltage V2 and performs a final determination to determine the failure status of the main power supply 10 and the backup power supply 20 (see time T11). Specifically, controller 3 makes a final determination that there is a ground fault in the first system line 110, including the main power supply 10, if the first system voltage V1 is below the ground fault threshold for at least the determination time T, and the second system voltage V2 recovers to exceed the ground fault threshold for at least the determination time T. Also, controller 3 makes a final determination that there is a ground fault in the second system line 120, including the backup power supply 20, if the second system voltage V2 is below the ground fault threshold for at least the determination time T, and the first system voltage V1 recovers to exceed the ground fault threshold for at least the determination time T. Furthermore, if both the first system voltage V1 and the second system voltage V2 recover to the point where they exceed the ground fault threshold for a judgment time T or longer, the controller 3 determines that both the first system line 110 and the second system line 120 are normal, that is, the power supply system failure detected by the failure detection device 30 is a false detection caused by a temporary voltage drop or the like.
[0120] In Figure 14A, the first system voltage V1 is below the ground fault threshold from time T11 to time T14, but the time T14–T11 during which it is below the ground fault threshold is shorter than the determination time T. Therefore, the controller 3 does not determine that the first system line 110 is ground faulted. On the other hand, the first system voltage V1 exceeds the ground fault threshold for more than the determination time T from time T14 onward. Therefore, the controller 3 makes the final determination that the first system line 110 is normal.
[0121] Furthermore, in Figure 14A, the second system voltage V2 is below the ground fault threshold from time T11 to time T13, but the time T13–T11 during which it is below the ground fault threshold is shorter than the determination time T. Therefore, the controller 3 does not determine that the second system line 120 is ground faulted. On the other hand, the second system voltage V2 exceeds the ground fault threshold for more than the determination time T from time T13 onward. Therefore, the controller 3 makes the determination that the second system line 120 is normal.
[0122] Therefore, in the final determination performed after time T11, controller 3 determines that both the first system line 110 and the second system line 120 are normal (time T15).
[0123] If controller 3 determines that both the main power supply 10 and the backup power supply 20 are functioning normally and have not failed, it outputs a clear signal to the latch circuit 32, clearing the latch circuit 32 and stopping the output of the latch signal (see time T16). Here, it is assumed that during the clearing process of the latch circuit 32, the first system voltage V1 drops again below the ground fault threshold, causing the main power supply 10 to fail (see time T17).
[0124] After clearing the latch circuit 32, controller 3 performs the process of determining the failure status of the main power supply 10 and the backup power supply 20 again. In other words, controller 3 re-determines whether the main power supply 10 and the backup power supply 20 are normal or abnormal.
[0125] Controller 3 determines that the backup power supply 20 is normal if the second system voltage V2 exceeds the ground fault threshold for a judgment time T or longer. Also, if the first system voltage V1 is below the ground fault threshold for a judgment time T or longer, Controller 3 determines that the main power supply 10 has failed again, that is, that the backup power supply 20 is normal and the main power supply 10 is abnormal (see time T18). If Controller 3 determines that the main power supply 10 is abnormal, it performs backup processing to maintain the output of the backup drive signal, in other words, it maintains the tripping of the inter-system switch 151.
[0126] Although not shown in the diagram, the controller 3 determines that the backup power supply 20 has failed, that is, that the backup power supply 20 is abnormal, if the first system voltage V1 exceeds the ground fault threshold for a judgment time T or longer, and the second system voltage V2 is below the ground fault threshold for a judgment time T or longer. If the controller 3 determines that the backup power supply 20 is abnormal, it maintains the output of the backup drive signal, in other words, it maintains the tripping of the inter-system switch 151.
[0127] As a result, even if the first system voltage V1 (or second system voltage V2) drops below the ground fault threshold again and the power supply system fails during the clearing process in the latch circuit 32, for example, the inter-system switch 151 can be shut off and the backup state can be maintained.
[0128] Next, we will explain the case where, after clearing the latch circuit 32, the first system voltage V1 does not fall below the ground fault threshold again, that is, the main power supply 10 returns to a normal state from a temporary voltage drop, with reference to Figure 14B.
[0129] As shown in Figure 14B, at time T16, the controller 3 clears the latch circuit 32 and then performs the process of determining the failure status of the main power supply 10 and the backup power supply 20 again. If both the first system voltage V1 and the second system voltage V2 are higher than the ground fault threshold for a determination time T or longer, the controller 3 determines that both the power supply system including the main power supply 10 and the power supply system including the backup power supply 20 are normal (see time T18). If the controller 3 determines that both power supply systems are normal, it cancels the output of the backup drive signal, in other words, it connects the inter-system switch 151 (see time T19). The controller 3 also shuts off the battery switch 152. Accordingly, the controller 3 returns from the backup state to the normal state and performs normal processing.
[0130] In the above example, the latch signal output from the failure detection device 30 and the backup drive signal output from the controller 3 are shown as signals to drive the inter-system switch 151, but this is not the only example. For example, the failure detection device 30 may output the latch signal and / or backup drive signal to the battery switch 152 via the OR logic circuit 33, as shown by the dashed line in Figure 13. That is, the battery switch 152 conducts in response to the latch signal and the backup drive signal. More specifically, the OR logic circuit 33 conducts (connects) the battery switch 152 by outputting the latch signal from the latch circuit 32 or the backup drive signal from the controller 3 as a connection signal to the battery switch 152.
[0131] In this way, the battery switch 152 conducts in response to the latch signal and the backup drive signal, so that when a failure of the main power supply 10 or the backup power supply 20 is detected, for example, the battery switch 152 can be driven (conducted) early. In other words, when a failure of the power supply system is detected, the system can quickly switch to the backup state.
[0132] In the second embodiment, the controller 3 immediately outputs a backup drive signal upon receiving a latch signal, but is not limited to this. Specifically, the controller 3 only needs to output a backup drive signal between receiving the latch signal and outputting the clear signal.
[0133] [2-4. Processes executed by the power control unit's controller] Next, with reference to Figure 15, the processes executed by the controller 3 of the power control device 1a according to the second embodiment will be described. Figure 15 is a flowchart showing an example of the processes executed by the controller 3 of the power control device 1a according to the second embodiment. The processes shown in Figure 15 are executed repeatedly at predetermined intervals, but are not limited to this.
[0134] As shown in Figure 15, the controller 3 determines whether or not it has received a latch signal from the latch circuit 32 (step S201). Specifically, when the voltage of the first system voltage V1 (or the second system voltage V2) falls below the ground fault threshold, a detection signal is output from the comparator 31 of the failure detection device 30, and the controller 3 determines whether or not it has received a latch signal from the latch circuit 32 that latches this detection signal. In other words, the controller 3 determines whether or not a provisional determination of power failure has been made by the failure detection device 30. Since this latch signal is also output to the inter-system switch 151 via the OR logic circuit 33, the inter-system switch 151 is in an interrupted state.
[0135] If controller 3 determines that it has not received a latch signal from latch circuit 32 (step S201, No), it skips the subsequent processing. On the other hand, if controller 3 determines that it has received a latch signal from latch circuit 32 (step S201, Yes), it outputs a backup drive signal to shut off the backup switch and also opens the battery switch 152 (step S202).
[0136] Next, the controller 3 monitors the first system voltage V1 and the second system voltage V2 and performs a final determination process to determine whether the failure detected by the failure detection device 30 is a ground fault in the first system line 110, a ground fault in the second system line 120, or that both system lines are normal (step S203). Specifically, the controller 3 makes a final determination that there is a ground fault in the second system line 120 if the second system voltage V2 is below the ground fault threshold for a determination time T or longer, and the first system voltage V1 recovers to exceed the ground fault threshold for a determination time T or longer. The controller 3 also makes a final determination that there is a ground fault in the first system line 110 if the first system voltage V1 is below the ground fault threshold for a determination time T or longer, and the second system voltage V2 recovers to exceed the ground fault threshold for a determination time T or longer. Furthermore, the controller 3 makes a final determination that both system lines are normal if both the first system voltage V1 and the second system voltage V2 recover to exceed the ground fault threshold for a determination time T or longer.
[0137] Next, the controller 3 determines whether the result of step S203 was a failure of the main power supply 10 or the backup power supply 20 (step S204).
[0138] If the controller 3 determines that the main power supply 10 or the backup power supply 20 has failed (step S204, Yes), it repeats the process in step S204. As a result, when the controller 3 determines that the main power supply 10 or the backup power supply 20 has failed, it continues to output the backup drive signal output in step S202. In this case, both the latch signal output from the latch circuit 32 and the backup drive signal output from the controller 3 keep the inter-system switch 151 in the off state, and fail-safe control is performed.
[0139] On the other hand, if the controller 3 determines that the main power supply 10 and the backup power supply 20 have not failed (step S204, No), it outputs a clear signal to the latch circuit 32 (step S205). In other words, the controller 3 clears the latch circuit 32 and stops outputting the latch signal.
[0140] Next, the controller 3 determines again whether the main power supply 10 and the backup power supply 20 have failed (step S206). In other words, the controller 3 determines again whether the main power supply 10 and the backup power supply 20 are normal or abnormal.
[0141] Next, the controller 3 determines whether the result of step S206 was a failure of at least one of the main power supply 10 and the backup power supply 20 (step S207). If the controller 3 determines that neither the main power supply 10 nor the backup power supply 20 has failed (step S207, No), that is, if the main power supply 10 and the backup power supply 20 are normal, it cancels the output of the backup drive signal and shuts off the battery switch 152 (step S208). As a result, the output of both the latch signal and the backup drive signal is stopped, and the inter-system switch 151 returns to its normal state (conductive state). The battery switch 152 also returns to its normal state (shut-off state).
[0142] On the other hand, if the controller 3 determines that the main power supply 10 or the backup power supply 20 has failed (step S207, Yes), that is, if the main power supply 10 or the backup power supply 20 is abnormal, it continues to output the backup drive signal (step S209).
[0143] As described above, the power control device 1a according to the second embodiment includes an inter-system switch 151, a comparator 31, a latch circuit 32, and a controller 3 (an example of a microcontroller). The inter-system switch 151 connects and disconnects a first system (first system line 110) that supplies power from the main power supply 10 to a first load, and a second system (second system line 120) that supplies power from the backup power supply 20 to a second load. The comparator 31 compares the voltage of the power systems, including the first and second systems, with a threshold to detect power system failure and outputs a detection signal. The latch circuit 32 latches the detection signal and outputs a latch signal, which disconnects the inter-system switch 151. When the controller 3 receives the latch signal, it determines whether the detection of power system failure by the comparator 31 is correct, and if it determines that the power system has not failed, it clears the latch circuit 32 and stops the output of the latch signal. This allows for a rapid transition to a backup state in the event of a power failure, and ensures that the backup state is reliably maintained.
[0144] [3. Addendum] As an addendum, the features of the present invention are as follows. (1) A comparator that compares the voltage of the power system supplied with power from the main power supply to a threshold value to detect a power system failure and outputs a detection signal, A latch circuit that latches the detection signal and outputs a latch signal, and drives a specific switch that controls the power supply to the load using the latch signal, Upon receiving the latch signal, the microcomputer determines whether the comparator's detection of power system failure is correct, and if it determines that the power system has not failed, it clears the latch circuit and stops the output of the latch signal. A power control device equipped with the following features. (2) The aforementioned microcomputer is Upon receiving the latch signal, the system outputs a backup drive signal to drive the specific switch, determines whether the comparator's detection of power system failure is correct, and if it determines that the power system has not failed, clears the latch circuit, then re-determines whether the power system is normal or abnormal, maintains the output of the backup drive signal if it determines that the power system is abnormal, and cancels the output of the backup drive signal if it determines that the power system is normal. (1) The power control device described above. (3) A backup switch connects and disconnects the power path between the load supplied with power from the main power supply and the backup power supply, A comparator that compares the voltage of the power system supplied with power from the main power supply to a threshold value to detect a power system failure and outputs a detection signal, A latch circuit that latches the detection signal and outputs a latch signal, and connects the backup switch based on the latch signal, Upon receiving the latch signal, the microcomputer determines whether the comparator's detection of power system failure is correct, and if it determines that the power system has not failed, it clears the latch circuit and stops the output of the latch signal. A power control device equipped with the following features. (4) The aforementioned microcomputer is Upon receiving the latch signal, the system outputs a backup drive signal to activate the backup switch, determines whether the comparator's detection of power system failure is correct, and if it determines that the power system has not failed, clears the latch circuit, then re-determines whether the power system is normal or abnormal, maintains the output of the backup drive signal if it determines that the power system is abnormal, and cancels the output of the backup drive signal if it determines that the power system is normal. (3) The power supply control device described above. (5) A system switch connects and disconnects a first system that supplies power from the main power supply to a first load and a second system that supplies power from the backup power supply to a second load, A comparator that compares the voltage of the power system including the first system and the second system with a threshold to detect a power system failure and outputs a detection signal, A latch circuit that latches the detection signal and outputs a latch signal, and uses the latch signal to shut off the inter-system switch, Upon receiving the latch signal, the microcomputer determines whether the comparator's detection of power system failure is correct, and if it determines that the power system has not failed, it clears the latch circuit and stops the output of the latch signal. A power control device equipped with the following features. (6) The aforementioned microcomputer is Upon receiving the latch signal, the system outputs a backup drive signal to shut off the inter-system switch, determines whether the comparator's detection of power system failure is correct, and if it is determined that the power system has not failed, clears the latch circuit, then re-determines whether the power system is normal or abnormal, maintains the output of the backup drive signal if it is determined that the power system is abnormal, and cancels the output of the backup drive signal if it is determined that the power system is normal. (5) The power supply control device described above. (7) Battery switch for connecting the backup power supply to the second system Furthermore, The aforementioned battery switch is Conducts in accordance with the latch signal and the backup drive signal, (6) The power supply control device described above.
[0145] Further effects and modifications can be readily derived by those skilled in the art. Therefore, broader aspects of the present invention are not limited to the specific details and representative embodiments expressed and described above. Accordingly, various modifications are possible without departing from the spirit or scope of the overall concept of the invention as defined by the appended claims and their equivalents. [Explanation of Symbols]
[0146] 1,1a Power supply control device 3 Controllers 10 Main power 20 Backup power supply 30. Loss detection device 31 Comparator 32 Latch Circuits 44 Backup Switches 151 Inter-system switch 152 Battery Switch
Claims
1. A comparator that compares the voltage of the power system supplied with power from the main power supply to a threshold value to detect a power system failure and outputs a detection signal, A latch circuit that latches the detection signal and outputs a latch signal, and drives a specific switch that controls the power supply to the load using the latch signal, Upon receiving the latch signal, the microcomputer determines whether the comparator's detection of power system failure is correct, and if it determines that the power system has not failed, it clears the latch circuit and stops the output of the latch signal. A power control device equipped with the following features.
2. The aforementioned microcomputer is Upon receiving the latch signal, the system outputs a backup drive signal to drive the specific switch, determines whether the comparator's detection of power system failure is correct, and if it determines that the power system has not failed, clears the latch circuit, then re-determines whether the power system is normal or abnormal, maintains the output of the backup drive signal if it determines that the power system is abnormal, and cancels the output of the backup drive signal if it determines that the power system is normal. The power control device according to claim 1.
3. A backup switch connects and disconnects the power path between the load supplied with power from the main power supply and the backup power supply, A comparator that compares the voltage of the power system supplied with power from the main power supply to a threshold value to detect a power system failure and outputs a detection signal, A latch circuit that latches the detection signal and outputs a latch signal, and connects the backup switch based on the latch signal, Upon receiving the latch signal, the microcomputer determines whether the comparator's detection of power system failure is correct, and if it determines that the power system has not failed, it clears the latch circuit and stops the output of the latch signal. A power control device equipped with the following features.
4. The aforementioned microcomputer is Upon receiving the latch signal, the system outputs a backup drive signal to activate the backup switch, determines whether the comparator's detection of power system failure is correct, and if it determines that the power system has not failed, clears the latch circuit, then re-determines whether the power system is normal or abnormal, maintains the output of the backup drive signal if it determines that the power system is abnormal, and cancels the output of the backup drive signal if it determines that the power system is normal. The power control device according to claim 3.
5. A system switch connects and disconnects a first system that supplies power from the main power supply to a first load and a second system that supplies power from the backup power supply to a second load, A comparator that compares the voltage of the power system including the first system and the second system with a threshold to detect a power system failure and outputs a detection signal, A latch circuit that latches the detection signal and outputs a latch signal, and uses the latch signal to shut off the inter-system switch, Upon receiving the latch signal, the microcomputer determines whether the comparator's detection of power system failure is correct, and if it determines that the power system has not failed, it clears the latch circuit and stops the output of the latch signal. A power control device equipped with the following features.
6. The aforementioned microcomputer is Upon receiving the latch signal, the system outputs a backup drive signal to shut off the inter-system switch, determines whether the comparator's detection of power system failure is correct, and if it is determined that the power system has not failed, clears the latch circuit, then re-determines whether the power system is normal or abnormal, maintains the output of the backup drive signal if it is determined that the power system is abnormal, and cancels the output of the backup drive signal if it is determined that the power system is normal. The power control device according to claim 5.
7. Battery switch for connecting the backup power supply to the second system Furthermore, The aforementioned battery switch is Conducts in accordance with the latch signal and the backup drive signal, The power control device according to claim 6.
Citation Information
Patent Citations
Load driving circuit and method of detecting its abnormality
JP2007135251A
Power supply control unit and power supply control method
JP2022063249A
Power supply control unit
JP2023041482A
Power supply control unit
JP2023043533A