Method for operating a drive system, control device, drive system
The method ensures the validity of control instructions for drive systems by verifying message sequences in gate driver circuits, preventing erroneous safe operating states and maintaining safety integrity in the event of malfunctions.
Patent Information
- Application Number
- PCT/EP2024/083411
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-04
- Filing Date
- 2024-11-25
- Publication Date
- 2025-06-12
AI Technical Summary
Existing drive systems with electric machines and power electronics lack a reliable mechanism to ensure the validity of control instructions for safe operating states, particularly in the event of malfunctions, which can lead to erroneous instructions and safety risks.
A method where a computing unit sends a predetermined sequence of messages to gate driver circuits, which verify the sequence, number, and content of the messages. Only if the verification is successful is the control instruction stored and executed; otherwise, a substitute control instruction is used, ensuring a safe operating state is maintained.
This method provides a robust safeguard against malfunctions by ensuring the validity of control instructions, preventing erroneous safe operating states, and maintaining the safety integrity of precalculated safe operating states.
Smart Images

Figure EP2024083411_12062025_PF_FP_ABST
Abstract
Description
[0001] Description
[0002] title
[0003] Method for operating a drive system, control device, drive system
[0004] The invention relates to a method for operating a drive system, wherein the drive system comprises an electric machine, power electronics associated with the machine and a control device, wherein the control device comprises a computing unit and a plurality of gate driver circuits, wherein a control instruction is determined by means of the computing unit as a function of an actual speed of the machine, and wherein the control instruction contains at least one item of information about a predetermined safe operating state in the power electronics.
[0005] Furthermore, the invention relates to a control device specially designed to carry out such a method, as well as to a drive system with such a control device.
[0006] State of the art
[0007] Methods of the type mentioned above are known from the prior art. For example, the applicant's published patent application DE 10 2021 208 168 A1 discloses a method for operating such an electric drive system, wherein the drive system comprises an electric machine electrically connected to an electrical energy storage device via power electronics, and a control device for controlling the power electronics. The control device comprises a computing unit and a plurality of gate driver circuits. The computing unit determines a control instruction as a function of a current actual speed of the machine and stores it in the gate driver circuits. The drive system is monitored for faults, and the gate driver circuits, upon detection of a fault, set the safe operating state according to the stored control instruction.
[0008] Disclosure of the invention
[0009] The method according to the invention with the features of claim 1 is characterized in that a predetermined number of predetermined messages are sent by the computing unit to the gate driver circuits in a predetermined sequence, that a complete run in terms of sequence, number, and content of the messages is verified by the gate driver circuits, and that only if the verification is successful is the control instruction stored and / or executed in the gate driver circuits, and otherwise a predetermined substitute control instruction is stored and / or executed. This creates an advantageous safeguarding mechanism for a possible switch to the safe operating state if a malfunction of the drive system occurs. The invention is based on the finding that the control instruction must be correspondingly valid in order to reliably prevent an erroneous instruction regarding the safe operating state.The information in the control instruction is initially merely shadow information, which is only accessed in the event of a fault when the safe operating state is requested. The power electronics to be put into the safe operating state are designed to control the electrical machine, in particular a permanent magnet synchronous machine (PSM). The actual speed of the machine is determined in particular by means of the computing unit. The computing unit is preferably designed as a microcontroller. The gate driver circuits are preferably each designed as ASICs (application-specific integrated circuits). The computing unit preferably stores the control instruction in the gate driver circuits. In particular, the gate driver circuits each have a data memory for storing the control instruction.Preferably, the gate driver circuits each have a data memory for storing the control instruction, wherein in particular the computing unit is communicatively connected to the data memories by unidirectional communication devices. Preferably, the communication devices each have a data bus, in particular a UART bus. The power electronics preferably have a number of half-bridges corresponding to the number of phases of the electrical machine, wherein each half-bridge has at least one high-side switch and at least one low-side switch. Particularly preferably, the electrical machine has three phases, so that the power electronics then comprises three half-bridges and is thus designed as a B6 bridge. Preferably, the number of gate driver circuits corresponds to the number of switches in the power electronics.If the power electronics is designed as a B6 bridge, for example, the control device accordingly has six gate driver circuits, each of the gate driver circuits being assigned to a different one of the switches of the power electronics. Preferably, the computing unit is designed to continuously determine updated control instructions and store them in the gate driver circuits. If an updated control instruction is stored in the gate driver circuits, a control instruction already stored in the gate driver circuits is preferably replaced by the updated control instruction.If serious malfunctions occur in the drive system, in particular in the power electronics, for example, in a microcontroller, a monitoring device ("watchdog"), a voltage monitor, a gate driver, and / or a power semiconductor of a B6 bridge, the safe operating state specified in the stored control instruction is preferably set in the power electronics by executing the control instruction. The shadow information is therefore now used to adjust the power electronics. Typically, an active short circuit (ACS) is set as the safe operating state in the event of such malfunctions. An active short circuit is generated, in particular, by closing all semiconductor switches of the power electronics on one side, i.e., high-side or low-side, while simultaneously opening all semiconductor switches on the opposite side. This approach can be implemented regardless of the number of phases.For example, the active short circuit is set by closing all low-side switches. Such an active short circuit reliably prevents any unwanted feedback of electrical energy from the electrical machine into a connected electrical supply network, such as a motor vehicle's HV electrical system, and thus any unwanted current flow into an electrical energy storage device, such as an HV battery, as well as overvoltage, for example when HV battery contactors are open. Energy is fed back into the machine when a rectified induced voltage of the machine is higher than a current DC voltage. The induced voltage depends on the rotor excitation of a rotor of the machine (in the PSM this is constant) and the rotor speed.If the induced voltage of the machine is lower than the voltage of the energy storage device, for example, lower than the voltage of the HV battery, and the maximum permissible DC voltage is exceeded, a so-called freewheel (FW, "freewheel") is preferably set as an alternative safe operating state, for example for simple faults or predetermined operating states, such as a speed-free charging process. Freewheeling is achieved in particular by opening all semiconductor switches. If a serious fault occurs, for example, the active short circuit is selected as the fail-safe state without an independent decision-making authority regarding the operating state. A further development of such a fail-safe state, which is always the same, represents a speed-dependent safe operating state, which is known, for example, from the prior art mentioned above.In this speed-dependent safe operating state underlying the present invention, the computing unit, for example a processor, precalculates a necessary safe operating state as a control instruction for a predetermined period of time, at least taking into account the actual speed of the machine, in particular also taking into account a maximum possible acceleration, for example of the motor vehicle in which the drive system is installed, and / or an electrical voltage of an energy storage device, for example battery voltage. This necessary safe operating state can be freewheeling or an active short circuit and is stored cyclically in a safety logic independent of the computing unit, in this case in the gate driver circuits. In particular, the safety logic is present multiple times, for example in each of the gate driver circuits.If a serious error occurs, the freewheeling or active short circuit in the power electronics is set, as described above, depending on the currently valid stored safe operating state. The method according to the invention advantageously ensures that the correspondingly predicted safe operating state has the same safety integrity as the fail-safe state. The messages and their verification are thus designed to ensure the secure transmission of information about the operating state to be set in the event of a fault from the processing unit to the gate driver circuits, without random individual errors leading to an erroneous safe operating state.Likewise, manipulation of the data by a program instruction assigned to the computing unit, in particular processor software, which carries out communication between the computing unit and the gate driver circuits, is reliably prevented because successful verification would no longer be possible if the sequence, number, and / or content of the messages were changed. The invention has the advantage that the content and time-based security of the information is transmitted unidirectionally and cyclically from the computing unit to the independent safety logic, while the transmission is still protected against manipulation and random errors. This also means, in particular, that regardless of the state of an individual safety logic, the same information regarding the safe operating state is transmitted to all safety logic.This singular calculation of the information advantageously requires fewer resources in the software than, for example, a complex question-answer watchdog mechanism per security logic.
[0010] According to a preferred development of the invention, it is provided that the substitute control instruction specifies an active short circuit as the safe operating state and / or the control instruction specifies a freewheeling state in the power electronics as the safe operating state. If the control instruction can be verified, the freewheeling state is specified as shadow information. If it cannot be verified, the active short circuit is specified as fail-safe state, as described above. This advantageously ensures that the freewheeling state is only specified as shadow information if its validity is assured, and otherwise, as a precaution, the active short circuit forms the shadow information.Particularly preferably, the drive system is monitored for malfunctions, and if a malfunction is detected, the gate driver circuits are used to set the safe operating state according to the respectively stored control instruction or substitute control instruction. This provides the advantage that the currently valid shadow information is used to set the safe operating state in the event of a fault.
[0011] According to a preferred embodiment of the invention, the content of at least one of the messages is verified using a checksum. This advantageously ensures that any manipulation and / or faulty transmission of the corresponding message can be reliably detected.
[0012] Particularly preferably, it is provided that at least a predetermined first number of predetermined first at least partially matching, in particular identical, messages and a predetermined second number of predetermined second at least partially matching, in particular identical, messages are sent to the gate driver circuits in a predetermined order. The second messages therefore have a content that differs from the first messages. The use of at least two different messages results in the advantage that the robustness of the method is further improved. In particular, the first number is the same as, greater than, or smaller than the second number. Preferably, in a generalized or alternative formulation, a plurality of corresponding messages is provided as a corresponding message block.For example, n message blocks are provided, where n is a natural number, and where each of the message blocks has a predetermined number of predetermined, at least partially matching, in particular identical, messages.
[0013] In particular, within a run of message blocks, all messages have different content. Alternatively, at least one of the messages is repeatedly present within a run, in particular separated in its repetition by at least one message block with a message that differs in content. In particular, at least two of the numbers, in particular all of the numbers, are identical or different. According to a preferred development of the invention, it is provided that the first messages comprise a predetermined first binary bit pattern and the second messages comprise a predetermined second binary bit pattern that differs from the first bit pattern. The use of two different binary bit patterns creates a particularly advantageous and simple possibility for distinguishing the messages. For example, 4-bit patterns are provided in each case, so that each of the messages has 4 bits.In particular, fewer than ten repetitions are intended. For example, each bit pattern is transmitted five times. The information about the safe operating state is secured by transmitting a first bit pattern for a defined minimum number of transmissions. After the minimum number of transmissions of the first bit pattern, this is varied for a further defined minimum number of transmissions as a second bit pattern. If the first and second bit patterns are transmitted validly, both in terms of the number and the pattern itself, the safe operating state is stored as shadow information according to the control instruction. For example, the shadow information is reconfigured, as described above, from a fail-safe operating state, i.e., active short circuit, to an alternative safe operating state, i.e., freewheeling.If message blocks are provided as described above, a maximum of n different bit patterns are provided accordingly, whereby if the message content is repeated in different message blocks, fewer than n different bit patterns are provided. The bit patterns advantageously prevent unwanted incorrect transmission of the safe operating state in the event of random disruptions or errors. Preferably, the entire message content, in addition to the bit pattern, is checked with a checksum, for example an 8-bit CRC. The minimum number of bit pattern repetitions rules out accidental manipulation of the shadow information by the communication software. The number of bit pattern repetitions advantageously ensures debouncing of unintentionally correctly transmitted bit patterns in the fast calculation grid of the communication software.
[0014] Particularly preferably, it is provided that if the corresponding
[0015] control instruction is saved, a timer is started, and when the timer expires, the substitute control instruction is saved. Preferably, the start value of the timer is selected depending on a specified forecast interval for the information. Appropriate use of the timer has the advantage that the information on the safe operating state is only valid for a limited time, for example, for the forecast interval, and that without cyclical updating of the safe operating state, the control instruction is discarded and the substitute control instruction is automatically selected, for example with the active short circuit as the fail-safe operating state. In this respect, the timer serves in particular to limit the time for reconfiguration of the shadow information on the safe operating state to the forecast interval.If communication fails, the timer ensures that, after the precalculation interval has expired, the information contained in the substitute control instruction is used as shadow information. The timer is particularly preferably implemented in the safety logic in the gate driver circuits.
[0016] According to a preferred development of the invention, the timer is reset upon successful verification of a run. This advantageously ensures that a successful verification is only valid for a limited period and must be continuously renewed, which further improves the robustness of the method. The timer is therefore reset and restarted with each correctly completed run as described above. If the described transmission sequence of the run is not carried out correctly in terms of order, number, and content within the maximum time of the timer, the reconfiguration of the safe operating state is canceled, and the information contained in the substitute control instruction is valid.
[0017] Particularly preferably, when a first of the messages is recognized by the gate driver circuits as the start of a new run, a counter is started which is incremented for each subsequent message of the same run until the counter reaches a predetermined maximum value for the last message of the run. Such a counter has the advantage that a position within the run, and thus a progress of the verification, is always reliably recognized. According to a preferred development of the invention, when the counter reaches its maximum value, the run is verified as successful and the counter is reset. This advantageously ensures that a fully verified run is always reliably recognized as such.
[0018] Particularly preferably, if further first messages beyond the first number are detected within a single run, the counter is assigned its previous value until the second message is detected. This provides the advantage that verification progress is maintained until the run is continued.
[0019] According to a preferred embodiment of the invention, the counter is reset if a message with false content and / or if another of the second messages exceeding the second number is detected within a single run. This advantageously ensures that unsuccessful and completed verifications are each recognizable.
[0020] Particularly preferably, a message with incorrect content is detected if, before the first number of first messages is reached, a message with content that differs from the first message is detected, and / or before the second number of second messages is reached, a message with content that differs from the second message is detected. This results in the advantage that the verification of a run is reliably terminated if an error occurs. This always ensures that a corresponding error within a run—be it due to manipulation or a communication error—will abort the verification, and an erroneous run is detected as such.
[0021] The control device for a drive system with the features of claim 14 has at least one computing unit and a plurality of gate driver circuits. It is characterized in that the control device is specifically designed to carry out the method according to the invention. This results in the advantages already mentioned. The drive system with the features of claim 15 has at least one electric machine and power electronics associated with the machine. It is characterized by the control device according to the invention. This also results in the advantages already mentioned. In particular, the drive system is designed as a drive system of a motor vehicle.
[0022] Further preferred features and combinations of features emerge from the above description and from the claims. The invention is explained in more detail below with reference to the drawings.
[0023] Figure 1 a drive system,
[0024] Figure 2 Components of the drive system,
[0025] Figure 3 shows a method for operating the drive system, and
[0026] Figure 4 Message flows between components of the
[0027] drive system during the process.
[0028] Figure 1 shows a drive system 1 in a simplified representation. The drive system 1 is designed in particular as a drive system 1 of a motor vehicle (not shown in detail). The drive system 1 has an electric machine 2. The electric machine 2 has a rotatably mounted rotor 3, on which several permanent magnets 4 are arranged in a rotationally fixed manner. The electric machine 2 also has a motor winding 5 with, in this case, three phases II, V, and W. The motor winding 5 is arranged distributed around the rotor 3 in such a way that the rotor 3 can be rotated by suitable current supply to the phases II, V, and W.
[0029] The drive system 1 also has an electrical energy storage device 6. The motor winding 5 is electrically connected to the energy storage device 6 via power electronics 7 of the drive system 1. The power electronics 7 is thus assigned to the electric machine 2 and, in this case, has a number of half-bridges corresponding to the number of phases U, V, and W, each of which has at least one low-side switch and at least one high-side switch. Accordingly, the power electronics in this case has three half-bridges.
[0030] The drive system 1 also has a control device 8. The control device 8 is designed to control or switch the switches of the power electronics 7. The specific structure of the control device 8 and its connection to the power electronics 7 is explained in more detail below with reference to Figure 2.
[0031] Figure 2 shows the control device 8 and the power electronics 7 in detail. A half-bridge 9 of the power electronics 7 is shown. The half-bridge 9 has two semiconductor switches 10, 11, namely a high-side switch 10 (HS) and a low-side switch 11 (LS). The remaining two half-bridges correspond to the design of the half-bridge 9.
[0032] The control device 8 has a computing unit 12. The computing unit 12 is embodied in this case as a microcontroller having at least one processor. The control device 8 also has a number of gate driver circuits corresponding to the number of switches in the power electronics 7, with each of the switches being assigned a different gate driver circuit. The gate driver circuits are each embodied in this case as an ASIC.
[0033] In Figure 2, only two of the gate driver circuits are shown, namely a first gate driver circuit 13 assigned to the high-side switch 10 and a second gate driver circuit 14 assigned to the low-side switch 11. In addition to the gate driver circuits 13, 14, further gate driver circuits are present which are assigned to the switches of the half-bridges of the power electronics 7 (not shown in Figure 2).
[0034] Each of the gate driver circuits 13, 14 has a safety logic unit 15, 16, wherein a first safety logic unit 15 is assigned to the first gate driver circuit 13 and a second safety logic unit 16 is assigned to the second gate driver circuit 14. The computing unit 12 is connected by a unidirectional or bidirectional communication connection to each of the gate driver circuits 13, 14, in particular to each of the
[0035] Safety logic units 15, 16, connected via communication technology.
[0036] Each of the gate driver circuits 13, 14 has a data memory 17, 18 assigned to the respective safety logic unit 15, 16, in particular integrated into the respective safety logic unit 15, 16. A first data memory 17 is assigned to the first safety logic unit 15, and a second data memory 18 is assigned to the second safety logic unit 16. The data memories 17, 18 are configured here to retain a control instruction containing information about a safe operating state of the drive system 1 in the event of a fault.
[0037] The control device 8 has a watchdog unit 19. Watchdog units are known from the prior art and are used, for example, to trigger a reset of the microcontroller in the event of a program crash, as well as to activate a shutdown path upon detection of a malfunction, in this case of the drive system 1, so that the provided control instruction is executed and the drive system 1 is placed in a safe operating state. For this purpose, the watchdog unit 19 is communicatively connected to both the processing unit 12 and each of the gate driver circuits 13, 14, in particular to each of the safety logic units 15, 16, via a communication connection.
[0038] An advantageous method for operating the drive system 1 is described below with reference to Figure 3. Figure 3 shows the method using a flowchart. In particular, the method ensures that a control instruction for the power electronics 7 is verified by the control device 8 and stored in the data memories 17, 18 only if it is successfully verified.
[0039] It is assumed that the electric machine 2 is, at least initially, in operation. The motor winding 5 is thus energized in such a way that the rotor 3 rotates to generate a torque. For this purpose, PWM signals are transmitted, in particular by means of the computing unit 12, to the corresponding gates via a corresponding communication interface.
[0040] Driver circuits 13, 14 are sent to control the semiconductor switches 10, 11.
[0041] In a step S1, the method begins with the computing unit 12 continuously determining a current actual speed of the rotor 3 of the electric machine 2, for example, as a function of a sensor signal from a rotation angle sensor or rotor position sensor assigned to the rotor 3. A control instruction is then determined as a function of the determined actual speed. The control instruction contains at least one piece of information about a predefined safe operating state in the power electronics 7. Preferably, the control instruction contains information about whether an active short circuit or freewheeling should be set in the power electronics 7 as the safe operating state in the event of a fault in the drive system 1.
[0042] In a step S2, which is performed following step S1 and / or at least partially in parallel thereto, the computing unit 12 sends the control instruction just determined as well as a predetermined number of predetermined messages in a predetermined sequence to all gate driver circuits 13, 14 of all phases of the electric machine 2. In particular, a corresponding communication interface, in particular UART, is used for this purpose.
[0043] Preferably, at least a predetermined first number of predetermined first, at least partially matching, in particular identical, messages and a predetermined second number of predetermined second, at least partially matching, in particular identical, messages are sent in a predetermined order to the gate driver circuits 13, 14. For example, the first messages comprise a predetermined first binary bit pattern, and the second messages comprise a predetermined second binary bit pattern that differs from the first bit pattern.
[0044] Figure 4 shows a concrete embodiment in the form of a corresponding message flow between the computing unit 12 and the corresponding gate driver circuits 13, 14 with the safety logic units 15, 16 and the data memories 17, 18. The first bit pattern is the 4-bit sequence 0101, and the second bit pattern is the 4-bit sequence 1010. The bit patterns are accordingly part of a longer message, which is only shown in part or indicated by ellipsis. The corresponding messages are numbered – merely for exemplary assignment – beginning with Data0. A correct run in this case, also merely as an example, consists of a total of 10 messages, namely five messages containing the first bit pattern and then five messages containing the second bit pattern. As already described above, this is scalable as required.However, it has been found that it makes sense to use at least two different bit patterns. The number of them is identical in this case (five), but this is not mandatory.
[0045] In a subsequent step S3, a complete run of the messages is verified by the gate driver circuits 13, 14 in terms of order, number, and content to detect any malfunction or tampering with the communication and thus an incorrect control instruction. In particular, the content of at least one of the messages is verified using a checksum, for example, a CRC.
[0046] In a subsequent step S4, the control instruction is stored in the gate driver circuits 13, 14 only if the verification is successful, and otherwise a predefined substitute control instruction is stored. The aforementioned steps are performed continuously, in particular, so that continuously updated control instructions are determined and stored in the data memories 17, 18. Preferably, the substitute control instruction specifies an active short circuit as the safe operating state and / or the control instruction specifies a freewheeling state in the power electronics 7 as the safe operating state.
[0047] Preferably, when the corresponding control instruction is stored, a timer is started, and when the timer expires, the replacement control instruction is stored. In particular, the timer is reset upon successful verification of a run. When a first of the messages is recognized by the gate driver circuits 13, 14 as the start of a new run, a counter is preferably started, which is incremented for each subsequent message of the same run until the counter reaches a predetermined maximum value for the last message of the run. When the counter reaches its maximum value, the run is in particular verified as successful and the counter is reset. If further of the first messages beyond the first number are recognized within a run, the counter is preferably assigned its previous value until the second message is recognized.If a message with incorrect content and / or within a run another of the second messages beyond the second number is detected, the counter is preferably reset.
[0048] If, before the first number of first messages is reached, a message is detected that differs in content from the first message, at least with respect to the matching message part, for example, the bit pattern described above, and / or if, before the second number of second messages is reached, a message is detected that differs in content from the second message, at least with respect to the matching message part, for example, the corresponding bit pattern, a message with incorrect content is preferably detected. The verification of the run has thus failed.
[0049] A concrete example for the verification and storage of the control instruction, as well as the described behavior of the counter and timer, is also shown in Figure 4. For example, DataO initially transmits a bit pattern 0000 that does not match a run. This is therefore an incorrect message, so the counter is reset, i.e., SZ_COUNT=0. Because no successfully verified run has yet been detected, the substitute control instruction "active short circuit" is stored in the data memories as shadow information, SZ_CONF=AKS.
[0050] Messages are transmitted from Data1 to Data5, each with the correct first bit pattern, so the counter is iterated until SZ_COUNT=5. The first half of the run is thus successfully verified. Messages are transmitted from Data6 to Data10, each with the correct second bit pattern, so the counter is iterated until SZ_COUNT=10. Both bit patterns have now been transmitted correctly with regard to minimum number, pattern, and order, so the timer reaches its maximum value, and the run is completely verified. The timer is now reset, as can be seen in the corresponding trace t.
[0051] In addition, instead of the substitute control instruction, the determined control instruction, in this case "freewheel," is stored as SZ_CONF=FW in the data memories 17, 18. As long as the timer is active and is below a specified time value, in particular depending on a specified forecast interval, the correspondingly determined control instruction is configured with the corresponding shadow information.
[0052] This is the case between Data10 and Data20. To preserve the shadow information, the correct transmission of both bit pattern sequences must be repeated. Otherwise, if the defined time value of the timer is exceeded, the replacement control instruction is reconfigured as shadow information, in this example, for Data21 with SZ_CONF=AKS.
[0053] Examples of incorrect transmissions of a bit pattern can be seen in Data0, Data13, and Data14. The order of the bit patterns is no longer correct, and the bit pattern counter (see SZ_COUNT) is reset. If the first bit pattern is sent more than the minimum number of times, the bit pattern counter (see SZ_COUNT) remains at the last value and waits for the second bit pattern (see Data20 and Data21).
[0054] If the second bit pattern is sent more often than the minimum number, the timer and the bit pattern counter are reset after the minimum number has been reached (see Data 10). The bit pattern counter then recognizes further repetitions of the second bit pattern as an incorrect bit pattern (see Data 11). From Data 15 onwards, a new run is recognized, whereby the first half of the run is successfully verified up to Data 20. Finally, preferably, as is known, for example, from the prior art mentioned above, the drive system 1 is monitored for a malfunction. As long as no malfunction is detected, the control of the machine 2 described above is continued using the PWM signals. If a malfunction is detected, the gate
[0055] Driver circuits 13, 14 set the safe operating state according to the respective stored control instruction or substitute control instruction, and the PWM signals are ignored accordingly. For example, the shutdown path described above is activated by the watchdog unit 19. This provides the safety logic units 15, 16 with the appropriate information regarding the detection of the malfunction, whereupon the respective stored control instruction or substitute control instruction is executed, and the corresponding safe operating state is set. This safe operating state preferably remains permanently active until it is actively canceled.
Claims
Claims 1 . Method for operating a drive system (1), - wherein the drive system (1) comprises an electric machine (2), power electronics (7) associated with the machine (2) and a control device (8), - wherein the control device (8) comprises a computing unit (12) and a plurality of gate driver circuits (13, 14), - wherein a control instruction is determined by means of the computing unit (12) as a function of an actual speed of the machine (2), and - wherein the control instruction contains at least one item of information about a predetermined safe operating state in the power electronics (7), characterized in that a predetermined number of predetermined messages is sent by the computing unit (12) to the gate driver circuits (13, 14) in a predetermined sequence, that a complete run in terms of sequence, number and content of the messages is verified by the gate driver circuits (13, 14), and that only if the verification is successful is the control instruction and otherwise a predetermined replacement control instruction stored and / or executed in the gate driver circuits (13, 14).
2. Method according to claim 1, characterized in that an active short circuit is specified as a safe operating state by the substitute control instruction and / or a freewheel in the power electronics (7) is specified as a safe operating state by the control instruction.
3. Method according to one of the preceding claims, characterized in that the drive system (1) is monitored for a malfunction, and that, if a malfunction is detected, by means of the gate Driver circuits (13,14) set the safe operating state according to the respectively stored control instruction or substitute control instruction.
4. Method according to one of the preceding claims, characterized in that the content of at least one of the messages is verified by means of a checksum.
5. Method according to one of the preceding claims, characterized in that at least a predetermined first number of predetermined first at least partially matching, in particular identical, messages and a predetermined second number of predetermined second at least partially matching, in particular identical, messages are sent to the gate driver circuits (13, 14) in a predetermined order.
6. The method according to claim 5, characterized in that the first messages comprise a predetermined first binary bit pattern and the second messages comprise a predetermined second binary bit pattern that differs from the first bit pattern.
7. Method according to one of the preceding claims, characterized in that when the corresponding control instruction is stored, a timer is started, and that when the timer expires, the replacement control instruction is stored.
8. Method according to claim 7, characterized in that the timer is reset upon successful verification of a run.
9. Method according to one of the preceding claims, characterized in that, when a first of the messages is recognized by the gate driver circuits (13, 14) as the beginning of a new run, a counter is started which is incremented for each subsequent message of the same run until the counter reaches a predetermined maximum value for the last message of the run.
10. The method according to claim 9, characterized in that when the counter reaches its maximum value, the run is verified as successful and the counter is reset.
11. Method according to one of claims 9 and 10, characterized in that if further of the first messages beyond the first number are recognized within a run, the counter is assigned its previous value until the second message is recognized.
12. Method according to one of claims 9 to 11, characterized in that the counter is reset when a message with incorrect content and / or a further one of the second messages beyond the second number is detected within one pass.
13. Method according to one of the preceding claims, characterized in that a message with incorrect content is recognized if, before the first number of first messages is reached, a message with content that differs from the first message is recognized, and / or before the second number of second messages is reached, a message with content that differs from the second message is recognized.
14. Control device (8) for a drive system (1), with a computing unit (12) and with a plurality of gate driver circuits (13, 14), characterized in that the control device (8) is specially designed to carry out the method according to one of the preceding claims.
15. Drive system (1), in particular for a motor vehicle, with an electric machine (2) and with power electronics (7) associated with the machine (2), characterized by a control device (8) according to claim 14.
Citation Information
Patent Citations
Control device for a drive system, drive system, method
DE102021208168A1
Updating control parameters of a gate driver during operation
US20220182004A1