AC Battery Safety Control With Hardware State-Machine Bypass

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Electric vehicles with AC batteries face challenges in safely transitioning the traction system to a safe state in case of faults, such as cable breaks, due to the need for precise control of contactors and battery modules to ensure functional safety and compliance with hazard and risk analyses.

Innovation Solution

A safety concept utilizing a central controller with a hardware-programmable processor unit and a state machine that rapidly switches battery modules to a 'bypass' state via a high-speed bus and fault loop, allowing contactors to assume safety positions, ensuring immediate fault detection and safe operating state maintenance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If conventional controllers with software-based control are used for contactor switching, then the system is easier to program and modify, but the switching speed is insufficient to achieve immediate safe state transition upon fault detection

Engineering Contradiction:
Improveswitching speedVSAvoidcontrol system complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The patent replaces software-based control with hardware-based control using a state machine implemented in hardware (e.g., FPGA or ASIC). This substitution enables deterministic, high-speed response to faults by eliminating software execution delays, achieving immediate contactor switching to safe states while maintaining controlled complexity through dedicated hardware logic design.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If the system transitions to a safe state immediately upon fault detection, then safety requirements are met, but the loss of power to the traction machine occurs abruptly

Engineering Contradiction:
Improvefunctional safetyVSAvoidpower interruption time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements a state machine that pre-defines safe operating states and transition paths. Upon fault detection, the system immediately transitions to pre-planned safe states by activating bypass contactors that maintain power flow through alternative paths, ensuring both immediate safety response and continuous power supply to prevent abrupt interruptions.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If multiple contactors are controlled with precise timing requirements, then the system achieves coordinated safe state transition, but the control program becomes increasingly complex and difficult to verify

Engineering Contradiction:
Improvecoordinated controlVSAvoidcontrol program complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces complex software timing control with hardware-based state machine logic that inherently enforces correct sequencing through its state transition structure. The hardware implementation provides deterministic timing and coordination of multiple contactors without requiring complex software timing algorithms, making the system both reliable and verifiable through hardware design review.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The state machine automatically manages the coordination of multiple contactors through its internal logic, self-regulating the timing and sequencing of switching operations without requiring external control intervention. This self-managing approach simplifies the overall control system while ensuring reliable coordinated transition to safe states.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11777436B2Method and system for a safety concept for an AC battery
Publication Date: 2023.10.03 DR ING H C F PORSCHE AG
  • US11777436B2 patent drawing
  • US11777436B2 patent drawing
  • US11777436B2 patent drawing

AI summary

A method for a safety concept for an AC battery, in which the AC battery includes a central controller, a plurality of battery modules which respectively have a power board with a plurality of switching states, a plurality of contactors, a plurality of current sensors, a fault loop and a high-speed bus and is connected to a traction machine. The central controller has a hardware-programmable processor unit with at least one microprocessor core on which a control program is configured to control the battery modules, the plurality of contactors and the fault loop. A state machine is implemented by the control program. The battery modules are connected, starting from the central controller, via the high-speed bus and the fault loop. If an abort fault occurs, the AC battery is changed to a safe operating state. The safe state is achieved at least by emergency disconnection of the central controller.