Multiplex system control system and power conversion system including same
The multiplex control system addresses the inefficiency of manual error resolution in multi-system control systems by using dual control devices to automatically switch control circuits, swiftly resolving software errors and maintaining system reliability.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- TMEIC CORP
- Filing Date
- 2024-11-06
- Publication Date
- 2026-05-15
AI Technical Summary
Existing multi-system control systems require significant user effort and time to address abnormalities in control circuits, leading to impaired redundancy and reliability due to manual intervention.
A multiplex control system with dual control devices that automatically detect and respond to software errors by switching control circuits between operating and standby states, using electrical contacts and operation circuits to quickly resolve abnormalities without user intervention.
Automatically resolves software errors in control circuits, reducing user effort and quickly restoring system redundancy and reliability by minimizing downtime.
Smart Images

Figure JP2024039424_15052026_PF_FP_ABST
Abstract
Description
Multi-system control system and power conversion system including the same
[0001] The present disclosure relates to a multi-system control system and a power conversion system including the same.
[0002] Japanese Patent Application Laid-Open No. 2014-241679 (Patent Document 1) discloses a multi-system control system. This multi-system control system includes a plurality of control devices (control circuits) and is used, for example, to improve the reliability of a power system.
[0003] Japanese Patent Application Laid-Open No. 2014-241679
[0004] In the multi-system control system, each control circuit selectively takes either a state of controlling an object (operating state) or a state of waiting without controlling the object (standby state). For example, when the first control circuit detects an abnormality in itself while in the operating state, the first control circuit switches from the operating state to the standby state, and the second control circuit switches from the standby state to the operating state. When an abnormality occurs in the first control circuit, the user can go to the installation location of the first control circuit, check the abnormal state of the first control circuit, and take appropriate countermeasures (in one example, repair by replacing parts). However, going to the installation location of the first control circuit and taking countermeasures every time an abnormality occurs requires a lot of labor and time.
[0005] The present disclosure has been made to solve the above problems, and an object thereof is to quickly eliminate an abnormality while saving the labor of the user when an abnormality occurs in a control circuit of a multi-system control system.
[0006] The multiplex control system of this disclosure comprises a first control device and a second control device, each capable of controlling an object. The first control device includes an electrical contact, an operating circuit, and a first control circuit. The electrical contact is provided on a power line. The operating circuit operates the electrical contact. The first control circuit has a first memory for storing software and, when the electrical contact is in a closed state, receives power supplied through the power line and selectively takes either a first state or a second state. The first state is a state in which the object is controlled. The second state is a state in which the object is not controlled and the control device is in standby mode. The second control device includes a second control circuit that takes either the first state or the second state complementary to the first control circuit. When the first control circuit detects an abnormality in the first control circuit, it transmits abnormality information indicating the type of abnormality to the second control circuit. The abnormality information includes first information indicating that the abnormality is a software error. In response to receiving the first information from the first control circuit, the second control circuit performs open / close control, controlling the operating circuit to open and then close the electrical contact.
[0007] According to this disclosure, when an abnormality occurs in the control circuit of a multi-system control system, the abnormality can be resolved quickly while saving the user effort.
[0008] This is a diagram showing the configuration of a power conversion system to which the multiplex control system according to this embodiment is applied. This is a diagram showing the detailed configuration of the control system. This is a diagram explaining the process to be executed when a malfunction occurs in the control circuit. This is a flowchart illustrating the process executed by the control circuit in the embodiment. This is a diagram showing the configuration of a control system according to Modification 1. This is a flowchart illustrating the process executed by the control circuit in Modification 1. This is a diagram showing the configuration of a control system according to Modification 2.
[0009] Embodiments of this disclosure will be described in detail below with reference to the drawings. The same or corresponding parts in the drawings will be denoted by the same reference numerals and their descriptions will not be repeated. Each of the embodiments and its modifications may be combined with one another as appropriate.
[0010] Where it is stated in this disclosure that an element (the first element) is "connected" between another element (the second element) and yet another element (the third element), there may be a fourth element interposed between the first element and the second element, or between the first element and the third element, or the first element may be directly connected to the second or third element without a fourth element. Similarly, where it is stated that the first element is "connected" to the second element, there may be a fourth element interposed between the first element and the second element, or the first element may be directly connected to the second element without a fourth element.
[0011] Figure 1 is a diagram showing the configuration of a power conversion system to which a multiplex control system according to this embodiment is applied. Referring to Figure 1, the power conversion system 1 is applied, for example, to a static VAR compensator (SVC) or a high voltage direct current (HVCD) transmission system. The power conversion system 1 comprises a power conversion device 10 and a control system 20.
[0012] The power converter 10 is connected between power lines 32 and 34. Power lines 32 and 34 are, for example, power transmission cables in a power grid. The power converter 10 converts (for example, steps down) the voltage of power line 32 and supplies power of the converted voltage to power line 34. The power converter 10 includes a switching element 105. The switching element 105 is incorporated into the main conversion circuit (not shown) of the power converter 10.
[0013] The control system 20 is a multiplex control system and includes a plurality of control devices. Each control device is configured to control the power converter 10 (specifically, the switching element 105) as its controlled object via a control signal CS.
[0014] Figure 2 is a diagram showing the detailed configuration of the control system 20. Referring to Figure 2, the control system 20 includes power lines 201A, 201B, control devices (control panels) 202A, 202B, and a display device 205.
[0015] Power line 201A is connected to power supply PS and transmits power from power supply PS to control device 202A. Control device 202A includes power lines 206A, 207A, 209A, circuit breaker 210A, switch 215A, operating circuit 220A, and control circuit 230A.
[0016] Circuit breaker 210A is connected between power lines 201A and 206A and includes an electrical contact 212A. Power line 206A is connected between circuit breaker 210A and switch 215A. Electrical contact 212A is a mechanical contact located upstream of switch 215A on the power line PLA. The open and closed states of circuit breaker 210A correspond to the open and closed states of electrical contact 212A, respectively.
[0017] The power line PLA is a power supply path from the power supply PS to the control circuit 230A, and is specifically formed by power lines 201A, 206A, 209A, and circuit breakers 210A and switches 215A. If circuit breaker 210A is closed and an overcurrent is flowing through power lines 201A and 206A, circuit breaker 210A will automatically open. This will interrupt the overcurrent. In the following description, unless otherwise specified, circuit breaker 210A will be assumed to be in the closed state.
[0018] Switch 215A is connected between power lines 206A and 209A and includes an electrical contact 217A. The electrical contact 217A is a mechanical contact provided on the power line PLA. The open and closed states of switch 215A correspond to the open and closed states of electrical contact 217A, respectively. Electrical contact 212A and electrical contact 212B (described later) each form an example of an "electrical contact" of this disclosure.
[0019] The control circuit 220A is connected to power line 206A through power line 207A. The control circuit 220A operates by receiving power supplied from the power supply PS through power lines 201A, 206A, and 207A when the circuit breaker 210A is closed. The control circuit 220A is configured to operate (specifically, open or close) the electrical contact 217A. The control circuit 220A includes a capacitor (not shown).
[0020] When the circuit breaker 210A and the switch 215A are closed, the control circuit 230A receives operating power supplied from the power supply PS through the power line PLA and selectively enters either an operating state or a standby state. The operating state is a state in which the power converter 10 (Figure 1) is controlled via the control signal CS. The standby state is a state in which the control circuit remains on standby for backup purposes without controlling the power converter 10.
[0021] The control circuit 230A includes a memory unit 235A, a detection unit 240A, a communication unit 245A, and a control unit 247A. Each of the detection unit 240A, the communication unit 245A, and the control unit 247A is a dedicated processing circuit, such as an ASIC (Application Specific Integrated Circuit) or an FPGA (Field Programmable Gate Array).
[0022] The memory unit 235A is a volatile memory that stores the software SWA. The detection unit 240A detects an abnormality in the control circuit 230A and generates an abnormality signal SGA. The abnormality signal SGA includes information indicating the type of abnormality in the control circuit 230A. Specifically, this information indicates whether the abnormality in the control circuit 230A is a software SWA error (hereinafter also simply referred to as a "software error") or an abnormality other than the said error (for example, a hardware failure of the control circuit 230A). In the following description, a software error is assumed to be a data corruption in the software SWA. The communication unit 245A communicates with the control device 202B.
[0023] The control unit 247A is configured to control the communication unit 245A. The control unit 247A controls the communication unit 245A to transmit status information SIA to the control device 202B. The status information SIA indicates the status of the control circuit 230A. Specifically, the status information SIA indicates whether the control circuit 230A is in operation or standby mode.
[0024] If an abnormal signal SGA is generated, the control unit 247A controls the communication unit 245A to also transmit abnormal information AIA to the control circuit 230B. Abnormal information AIA is generated based on the abnormal signal SGA and indicates the type of abnormality in the control circuit 230A. Specifically, abnormal information AIA is either software error information IA1 or non-software error information IA2. Software error information IA1 indicates that the abnormality in the control circuit 230A is a software error. Non-software error information IA2 indicates that the abnormality in the control circuit 230A is different from a software error.
[0025] Control device 202B has the same configuration as control device 202A. Specifically, control device 202B includes power lines 206B, 207B, 209B, circuit breaker 210B, switch 215B, operating circuit 220B, and control circuit 230B.
[0026] Circuit breaker 210B is connected between power lines 201B and 206B and includes electrical contact 212B. Switch 215B is connected between power lines 206B and 209B and includes electrical contact 217B. Circuit breaker 210B and switch 215B are located on the power line PLB. The power line PLB is the power supply path from the power supply PS to the control circuit 230B. The operating circuit 220B is configured to operate the electrical contact 217B.
[0027] The control circuit 230B receives operating power supplied from the power supply PS through the power line PLB and, in conjunction with the control circuit 230A, takes either an operating state or a standby state. For example, when the control circuit 230A is in the operating state, the control circuit 230B is in the standby state. On the other hand, when the control circuit 230A is in the standby state, the control circuit 230B is in the operating state.
[0028] The control circuit 230B includes a memory unit 235B, a detection unit 240B, a communication unit 245B, and a control unit 247B. Each of the detection unit 240B, the communication unit 245B, and the control unit 247B is a dedicated processing circuit such as an ASIC or FPGA.
[0029] The memory unit 235B is a volatile memory that stores the software SWB. The detection unit 240B detects an abnormality in the control circuit 230B and generates an abnormality signal SGB. The abnormality signal SGB indicates the type of abnormality in the control circuit 230B. Specifically, the abnormality signal SGB indicates whether the abnormality in the control circuit 230B is a software SWB error or an abnormality other than that error. The communication unit 245B communicates with the control device 202A.
[0030] The control unit 247B controls the communication unit 245B to transmit status information SIB to the control device 202A. The status information SIB indicates the state of the control circuit 230B. Specifically, the status information SIB indicates whether the control circuit 230B is in the aforementioned operating state or standby state.
[0031] The control unit 247B controls the communication unit 245B to also transmit abnormal information AIB to the control device 202A if an abnormal signal SGB is generated. The abnormal information AIB is generated based on the abnormal signal SGB and includes information indicating the type of abnormality in the control circuit 230B. Specifically, the abnormal information AIB is either software error information IB1 or non-software error information IB2. Software error information IB1 indicates that the abnormality in the control circuit 230B is a software SWB error. Non-software error information IA2 indicates that the abnormality in the control circuit 230A is different from a software SWB error.
[0032] The control unit 247B can also control the communication unit 245B to transmit an open command SA1 or a close command SA2 to the operation circuit 220A. The open command SA1 is a signal that commands the operation circuit 220A to open the switch 215A. The close command SA2 is a signal that commands the operation circuit 220A to close the switch 215A.
[0033] The control circuits 230A and 230B monitor each other by exchanging abnormal information AIA and AIB and status information SIA and SIB between them.
[0034] The display device 205 functions as a notification device that informs the user of various information (for example, an abnormality in the control circuit 230A or 230B). The display device 205 is controlled by either the control circuit 230A or 230B.
[0035] If a malfunction occurs in control circuit 230A or 230B, the user can go to the location where the malfunctioning control circuit is installed, check the malfunctioning state of the control circuit, and implement appropriate countermeasures. These countermeasures may include, for example, repair by replacing parts. However, going to the location of the control circuit and implementing countermeasures every time a malfunction occurs requires considerable effort and time. Furthermore, since the control circuit cannot operate normally until the malfunction is resolved, the redundancy (concurrency) of the control system 20 may be impaired for an extended period. This is undesirable from the standpoint of the reliability of the control system 20.
[0036] Therefore, the control system 20 according to this embodiment has a configuration to address the above-mentioned problems. This will be explained below.
[0037] Figure 3 illustrates the process executed when an abnormality occurs in the control circuit 230A. In this example, the abnormality in the control circuit 230A is assumed to be a software error.
[0038] Referring to Figure 3, the control circuit 230B receives software error information IA1 as abnormal information AIA from the control device 202A. In response to receiving the software error information IA1, the control circuit 230B performs opening and closing control of the switch 215A. This opening and closing control corresponds to controlling the operation circuit 220A to open the switch 215A (specifically, the electrical contact 217A) and then close it. Specifically, this opening and closing control corresponds to the process of transmitting an opening command SA1 to the operation circuit 220A via the communication unit 245B, and then transmitting a closing command SA2 to the operation circuit 220A after a predetermined time has elapsed. The predetermined time is determined in advance by experimentation, for example, as the time from the transmission of the opening command SA1 to the completion of the discharge of the capacitor in the operation circuit 220A.
[0039] The miniaturization of various IC components on the circuit board of control circuit 230A makes it prone to software errors such as data corruption. Such software errors can lead to malfunctions in control circuit 230A, but these can be resolved by turning the control circuit 230A's power off and on (shutting it down and restarting it).
[0040] According to the above switching control, the switch 215A is automatically opened and closed upon detection of a software error. This temporarily interrupts and then re-establishes the electrical connection between the control circuit 230A and the power supply PS, temporarily stopping and then resuming the supply of operating power from the power line PLA to the control circuit 230A. As a result, the control circuit 230A is automatically powered off (shut down and then restarted). Therefore, if the malfunction of the control circuit 230A is a software error, this error can be automatically resolved. Thus, the user does not need to go to the installation site each time a malfunction occurs in the control circuit 230A to check the malfunction status and take corrective action. As a result, the user's effort can be saved.
[0041] Furthermore, since the aforementioned predetermined time is generally very short, the time required for switching control is also very short. Therefore, with switching control, the control circuit 230A is powered on and off in a very short time. As a result, software errors are resolved more quickly compared to the example where a user goes to the location where the control circuit 230A is installed and manually opens and closes the circuit breaker 210A, etc., to power on and off the control circuit 230A. Therefore, the redundancy of the control system 20 can be restored quickly, and the reliability of the control system 20 can be improved.
[0042] When control circuit 230B receives non-software error information IA2 from control circuit 230A, control circuit 230B controls the display device 205 to notify the user of the abnormality in control circuit 230A. For example, control circuit 230B controls the display device 205 to notify the user that a hardware failure has occurred and that repairs such as parts replacement are necessary.
[0043] By adopting such a configuration, the user is motivated to take appropriate countermeasures at the installation location of the control circuit 230A. As a result, hardware failures and the like of the control circuit 230A can be eliminated by component replacement or the like. When the abnormality is a software error, the control circuit 230B executes the above-described opening / closing control without notifying the fact. Thereby, a situation where the number of notifications increases unnecessarily is avoided.
[0044] The opening / closing control may be executed in either the first case or the second case described below.
[0045] In the first case, immediately before the software error, the control circuit 230A is in the operating state and the control circuit 230B is in the standby state. When the abnormal signal SGA indicates a software error, the control circuit 230A switches from the operating state to the standby state. Then, the control circuit 230A includes information indicating the state change in the state information SIA and transmits the state information SIA together with the abnormal information AIA to the control circuit 230B.
[0046] In response to the reception of the state information SIA, the control circuit 230B switches from the standby state to the operating state and, in response to the reception of the abnormal information AIA, executes the opening / closing control. If the control circuit 230A is powered on after the opening / closing control and the abnormal signal SGA indicating a software error is no longer generated, the control circuit 230A determines that the software error has been resolved. The control circuit 230A notifies the control circuit 230B of the result of this determination.
[0047] In response to the notification from the control circuit 230B, the control circuit 230B switches from the operating state to the standby state. In this case, the control circuit 230B includes information indicating the state change in the state information SIB and transmits the state information SIB to the control circuit 230A. In response to the reception of the state information SIB, the control circuit 230A switches from the standby state to the operating state.
[0048] In the second case, immediately before the software error, the control circuit 230A is in the standby state and the control circuit 230B is in the operating state. When the abnormal signal SGA indicates a software error, the control circuit 230A transmits the abnormal information AIA to the control circuit 230B while continuing the standby state. In this case, the control circuit 230B executes the opening / closing control while continuing the operating state.
[0049] As described above, in both the first case and the second case, after the detection of the software error, the control circuit 230A is in the standby state and the control circuit 230B is in the operating state as long as the software error is not resolved.
[0050] Hereinafter, another advantage of the embodiment will be described. As described above, the operation circuit 220A opens and closes the switch 215A instead of the circuit breaker 210A. Then, at the time of a software error, the control circuit 230B executes the opening / closing control of the switch 215A.
[0051] According to such opening / closing control, the electrical connection between the power lines 201A and 206A is maintained even after the switch 215A is opened. As a result, the operation circuit 220A can continue to operate while receiving power supply from the power source PS through the power lines 201A, 206A, and 207A.
[0052] Suppose that the circuit breaker 210A can be operated using the operation circuit 220A, and the circuit breaker 210A is opened using the operation circuit 220A at the time of a software error. In this case, the power supply from the power source PS to the control circuit 230A stops, the control circuit 230A is powered off, and the operation circuit 220A may also become inoperable. As a result, the circuit breaker 210A cannot be automatically closed in accordance with the closing command SA2 using the operation circuit 220A. Therefore, the user has to manually close the circuit breaker 210A to power on the control circuit 230A and resolve the software error.
[0053] On the other hand, in this embodiment, even after the switch 215A is opened, the power supply to the operating circuit 220A is maintained while the circuit breaker 210A functions. Therefore, the switch 215A can be automatically closed according to the closing command SA2 from the control circuit 230B. Consequently, the user does not need to manually operate the circuit breaker 210A as described above.
[0054] Figure 4 is a flowchart illustrating the processes executed by control circuits 230A and 230B in the embodiment. This flowchart starts when an abnormality signal SGA is generated due to an abnormality detection by control circuit 230A. Hereinafter, steps will be abbreviated as "S".
[0055] Referring to Figure 4, the control circuit 230A determines whether the abnormality is a software error according to the abnormality signal SGA (S105). If the abnormality is a software error (YES in S105), the control circuit 230A transmits software error information IA1 as abnormality information AIA to the control circuit 230B (S110). If the abnormality is not a software error, for example, a hardware failure (NO in S105), the control circuit 230A transmits non-software error information IA2 as abnormality information AIA to the control circuit 230B (S115). Subsequently, the control circuit 230A controls the display device 205 to notify the user of an abnormality in the control circuit 230A itself (for example, a hardware failure) (S117). After S117, the process ends.
[0056] The control circuit 230B determines whether or not it has received abnormal information AIA (S220). If the control circuit 230B has not yet received abnormal information AIA (NO in S220), the process returns. If the control circuit 230B has received abnormal information AIA (YES in S220), the control circuit 230B determines whether or not abnormal information AIA is software error information IA1 (S225).
[0057] If the abnormal information AIA is software error information IA1 (YES in S225), the control circuit 230B performs opening and closing control of the switch 215A (S229). Specifically, the control circuit 230B sends an open command SA1 to the operation circuit 220A (S230), and after a predetermined time, sends a close command SA2 to the operation circuit 220A (S235). As a result, the control circuit 230A is powered off (S136) and then powered on (S137). On the other hand, if the abnormal information AIA is non-software error information IA2 (NO in S225), the control circuit 230A controls the display device 205 to notify the user of an abnormality in the control circuit 230A itself (S240). After S235 and S240, the process ends.
[0058] As described above, according to this embodiment, the control circuit 230B controls the opening and closing of the switch 215A in response to receiving software error information IA1 from the control circuit 230A. This allows for the early resolution of abnormalities in the event of a software error, while saving the user effort.
[0059] Referring again to Figure 2, when an error is detected in the software SWA of control circuit 230A, control circuit 230B uses the operation circuit 220A to control the opening and closing of switch 215A. Alternatively, when an error is detected in the software SWB of control circuit 230B, control circuit 230A may use the operation circuit 220B to control the opening and closing of switch 215B. This opening and closing control corresponds to the process of transmitting an open command SB1 to the operation circuit 220B via the communication unit 245A, and then transmitting a close command SB2 to the operation circuit 220B after a predetermined time has elapsed. The open command SB1 is a signal that commands the operation circuit 220B to open switch 215B. The close command SB2 is a signal that commands the operation circuit 220B to close switch 215B. According to the above opening and closing control by control circuit 230A, when an error is detected in the software SWB of control circuit 230B, this error can be resolved automatically and quickly.
[0060] [Modification 1] Referring again to Figure 3, when the control circuit 230B receives software error information IA1 from the control circuit 230A, it may determine whether or not to perform switching control of switch 215A according to the number of switching control operations of switch 215A that have already been performed in the most recent period. The most recent period refers to the period from a predetermined time before the current time to the current time. In one example, the predetermined time is 5 minutes.
[0061] For example, if the above occurs many times, it is possible that the software error was not resolved by a single switching operation of the switch 215A, and that the switching operation was unintentionally repeated many times afterward. Repeated switching operations in this manner can lead to wear of the electrical contacts 217A of the switch 215A.
[0062] Therefore, in Modification 1, the control circuit 230B no longer performs (prohibits) the opening and closing control of the switch 215A if the number of occurrences is large, and performs the opening and closing control only if the number of occurrences is small. This prevents the opening and closing control from being unintentionally repeated. As a result, the electrical contacts 217A of the switch 215A can be adequately protected from wear. The configuration of the control system according to Modification 1 will be described in detail below.
[0063] Figure 5 is a diagram showing the configuration of a control system according to Modification 1. Referring to Figure 5, the control system 50 differs from the control system 20 of the embodiment (Figure 2) in that the memory units 235A and 235B further store count information 236A and 236B, respectively. In other respects, unless otherwise specified, the control system 50 is basically the same as the control system 20. Therefore, a detailed explanation will not be repeated.
[0064] The count information 236A indicates the number of times the control circuit 230A has performed the opening and closing control of the switch 215B within the most recent period. The count information 236B indicates the number of times the control circuit 230B has performed the opening and closing control of the switch 215A within the most recent period.
[0065] In this example, a software error is detected in the control circuit 230A. As a result, similar to the embodiment, the control circuit 230A is in standby mode and the control circuit 230B is in operation mode.
[0066] In response to receiving software error information IA1 from control circuit 230A, control circuit 230B reads the number of times the opening / closing control has been executed within the most recent period from memory unit 235B according to count information 236B. Control circuit 230B determines whether the read count is less than a threshold. The threshold is, for example, a positive integer of 2 or more, and is predetermined as appropriate.
[0067] If the number of reads is less than the threshold, the control circuit 230B uses the operating circuit 220A to control the opening and closing of the switch 215A. If the software error is resolved after this control, the control circuit 230B may switch from the operating state to the standby state and the control circuit 230A may switch from the standby state to the operating state. Alternatively, the control circuit 230A may remain in the standby state and the control circuit 230B may remain in the operating state. On the other hand, if the number of reads has already reached the threshold, the control circuit 230B continues in the operating state without controlling the opening and closing of the switch 215A. This prevents the opening and closing control of the switch 215A from being unintentionally repeated. As a result, the power conversion system 1 can continue to control the power converter 10 while appropriately protecting the electrical contacts 217A of the switch 215A from wear.
[0068] Figure 6 is a flowchart illustrating the process executed by the control circuit 230B in Modification 1. Referring to Figure 6, this flowchart is started when abnormal information AIA is determined to be software error information IA1 (YES in S225 of Figure 4). Immediately after the start of this flowchart, the control circuit 230A is in standby mode and the control circuit 230B is in operation mode.
[0069] The control circuit 230B reads the number of times the opening / closing control was executed within the most recent period from the memory unit 235B (S226). The control circuit 230B determines whether the read count is less than a threshold (S227).
[0070] If the number of reads is less than the threshold (YES in S227), the control circuit 230B performs opening and closing control of the switch 215A (S226 in Figure 4). On the other hand, if the number of reads has already reached the threshold (NO in S227), the control circuit 230B continues the operating state without performing opening and closing control of the switch 215A (S228). The control circuit 230B may further control the display device 205 to notify the user of a malfunction in the control circuit 230A. After S228, the process ends.
[0071] As described above, according to this modified example 1, if the switching control of switch 215A has already been repeated many times in the most recent period, the control circuit 230B will no longer perform the switching control of switch 215A after receiving the software error information IA1, and will continue the operating state. This prevents the switching control of switch 215A from being unintentionally repeated. As a result, the power conversion system 1 can continue to control the power converter 10 while adequately protecting the electrical contacts 217A of switch 215A from wear.
[0072] Referring again to Figure 5, control circuit 230A may perform the same processing as control circuit 230B. Specifically, in response to receiving software error information IB1 from control circuit 230B, control circuit 230A may determine, according to count information 236A, whether the number of times control circuit 230A has controlled the switch 215B in the most recent period is below a threshold. If the number of times control circuit control has controlled the switch 215B in the most recent period has reached the threshold, control circuit 230A will no longer control the switch 215B. This prevents the switch 215B from being controlled repeatedly and unintentionally. As a result, the electrical contacts 217B of the switch 215B can be adequately protected from wear.
[0073] [Modification 2] In the embodiment and its modification 1, the control circuits 230A and 230B are powered on and off by the automatic opening and closing of the switches 215A and 215B.
[0074] In contrast, in Modification 2, the control circuits 230A and 230B are powered on and off by the automatic opening and closing of the circuit breakers 210A and 210B. As will be explained below, in Modification 2, the circuit breakers 210A and 210B can be automatically closed even after they have been opened.
[0075] Figure 7 shows the configuration of a control system according to Modification 2. Referring to Figure 7, the control system 60 differs from the control system 20 of the embodiment (Figure 2) in that it includes power lines 207AA, 207BB and control devices 202AA, 202BB instead of power lines 207A, 207B and control devices 202A, 202B. In other respects, unless otherwise specified, the control system 60 is basically the same as the control system 20. Therefore, a detailed explanation will not be repeated.
[0076] Power lines 207AA and 207BB are connected to power lines 201A and 201B, respectively. Power lines 207AA and 207BB may also be connected to power lines (not shown) that are connected separately from power lines 201A and 201B to the power supply PS.
[0077] Control device 202AA differs from control device 202A in that it includes power line 206AA and operating circuit 220AA instead of power lines 206A, 207A, 209A and switch 215A and operating circuit 220A. Control device 202BB differs from control device 202B in that it includes power line 206BB and operating circuit 220BB instead of power lines 206B, 207B, 209B and switch 215B and operating circuit 220B.
[0078] Power line 206AA is connected between circuit breaker 210A and control circuit 230A. Power line PLAA is formed by power lines 201A, 206AA and circuit breaker 210A. Operating circuit 220AA is connected to power line 201A through power line 207AA and operates the electrical contact 212A of circuit breaker 210A.
[0079] Power line 206BB is connected between circuit breaker 210B and control circuit 230B. Power line PLBB is formed by power lines 201B, 206BB and circuit breaker 210B. Operating circuit 220BB is connected to power line 201B through power line 207BB and operates the electrical contact 212B of circuit breaker 210B.
[0080] Control circuit 230B performs opening and closing control of circuit breaker 210A in response to receiving software error information IA1 from control circuit 230A. This opening and closing control corresponds to controlling the operating circuit 220AA to open and then close circuit breaker 210A (specifically, electrical contact 212A). Specifically, this opening and closing control corresponds to the process of sending an opening command SAA1 to the operating circuit 220AA and, after a predetermined time has elapsed, sending a closing command SAA2 to the operating circuit 220AA. The opening command SAA1 is a signal that commands the operating circuit 220AA to open circuit breaker 210A. The closing command SAA2 is a signal that commands the operating circuit 220AA to close circuit breaker 210A.
[0081] In Modification 2, power supply from the power source PS to the control circuit 220AA continues through power lines 201A and 207AA even after the circuit breaker 210A has opened. As a result, the control circuit 220AA can automatically close the circuit breaker 210A in accordance with the closing command SAA2 from the control circuit 230B. Therefore, as with the embodiment and its Modification 1, software errors can be automatically resolved.
[0082] Similarly, control circuit 230A may control operating circuit 220BB to open and then close circuit breaker 210B in response to receiving software error information IB1 from control circuit 230B.
[0083] In the modified example 2, each of the electrical contacts 212A and 212B of the circuit breakers 210A and 210B forms an example of an "electrical contact" of the present disclosure.
[0084] [Other Modifications] In the embodiment and its modifications 1 and 2, the object controlled by the control system 20 as a multiplex control system is the power converter 10 (specifically, the switching element 105). However, such an object is not limited to the power converter 10. That is, the multiplex control system according to the embodiment and its modifications can be applied to systems other than the power converter 1.
[0085] The embodiments disclosed herein should be considered in all respects to be illustrative and not restrictive. The scope of the invention is indicated by the claims rather than by the foregoing description, and all modifications within the meaning and scope of equivalents of the claims are intended.
[0086] 1 Power conversion system, 10 Power conversion device, 20, 50, 60 Control system, 230A, 230B Control circuit, 202A, 202AA, 202B, 202BB Control device, 205 Display device, 210A, 210B Circuit breaker, 212A, 212B, 217A, 217B Electrical contact, 215A, 215B Switch, 220A, 220AA, 220B, 220BB Operating circuit.
Claims
1. A multiplex control system comprising a first control device and a second control device, each capable of controlling an object, wherein the first control device includes an electrical contact provided on a power line, an operating circuit for operating the electrical contact, and a first control circuit having a first memory for storing software, and selectively taking either a first state or a second state upon receiving power supplied through the power line when the electrical contact is in a closed state, the first state being a state in which the object is controlled, and the second state being a state in which the object is not controlled but in standby mode, the second control device includes a second control circuit that takes either the first state or the second state complementary to the first control circuit, the first control circuit transmits abnormality information indicating the type of abnormality to the second control circuit when it detects an abnormality in the first control circuit, the abnormality information includes first information indicating that the abnormality is a software error, and the second control circuit performs opening / closing control to control the operating circuit to open and then close the electrical contact in response to receiving the first information from the first control circuit.
2. The multiplex control system according to claim 1, wherein the first control device further includes a circuit breaker provided upstream of the electrical contact on the power line, and a power line connected between the circuit breaker and the electrical contact, and the operating circuit is connected to the power line and operates by receiving power supplied through the power line when the circuit breaker is closed.
3. After detecting the error, the first control device is in the second state and the second control device is in the first state, the second control device includes a second memory that stores the number of times the opening / closing control has been executed within a period from a predetermined time before the current time to the current time, and in response to receiving the first information, the second control device reads the number of times the opening / closing control has been executed from the second memory, executes the opening / closing control if the read count is less than a threshold, and continues in the first state without executing the opening / closing control if the read count reaches the threshold, the multiplex control system according to claim 1.
4. The multiplex control system according to claim 1, further comprising a notification device for notifying of an abnormality in the first control circuit, wherein the abnormality information includes second information indicating that the abnormality is different from the error, and the notification device notifies of the abnormality in the first control circuit in response to the second control circuit receiving the second information from the first control circuit.
5. A power conversion system comprising a power conversion device as the object and a multiplex control system according to any one of claims 1 to 4.