Protecting a Three-Phase Inverter Against IGBT Failure

Tom Garrett9 min read
Other ManufacturerTechnical ReferenceVFD / Drives
Licensed PE Working through this on a live machine? A Maine-licensed engineer can take it from here — included with IMD hardware, by the hour for everything else. Book an engineer

An inverter power stage fails when device current, junction temperature, or terminal voltage crosses its limit before the protection path removes gate drive. The number that matters is not only the motor current reported by the controller; it is the instantaneous switch current, the commutation-loop overvoltage, and the time between fault inception and controlled turn-off.

Protection fixes that fail

Several familiar measures protect the installation without protecting the semiconductor junction. A feeder fuse or branch breaker clears sustained faults and isolates failed equipment, but it normally cannot interrupt a switch-level short circuit before an IGBT is damaged. Apply the feeder and branch protection required by the installation rules, then treat gate-driver protection as a separate design function.

Attempted fix Why it fails Required correction
Higher breakdown-voltage device Voltage rating does not suppress the L × di/dt overshoot produced by DC-link and commutation-loop inductance. Shorten and widen the commutation path, place local DC-link capacitance at the bridge, and measure overshoot at the device terminals.
Fuse or circuit breaker alone Branch protection operates on a different energy and time scale from semiconductor short-circuit protection. Use hardware current or collector/drain-voltage detection that directly controls the gate driver.
Software current limit The processor, sampling path, and PWM update can be slower than a destructive shoot-through event. Make the fast trip independent of the space-vector control program; let software record and coordinate the shutdown afterward.
Deadtime chosen from PWM logic alone One switch can still conduct while its complementary switch turns on. Base deadtime on actual device turn-off, driver propagation, mismatch, and worst-case operating conditions.
Any antiparallel or body diode Reverse-recovery behavior can create excessive current and overvoltage during commutation. Select a diode or integrated switch-diode combination rated for inverter commutation.
Reduced gate drive followed by automatic retry A fixed sequence is not portable across devices, bus voltages, loads, or fault impedances. Use the switch and driver manufacturers’ short-circuit operating data and a controlled fault-latch policy.

A suggested sequence of approximately half gate drive, a 5 µs observation interval, then either full drive or about 10 µs off before retry is not a universal protection law. Gate voltage changes short-circuit current, conduction loss, and switching behavior simultaneously. Repeatedly energizing a hard short can accumulate energy until the die, diode, or package fails.

Current, heat, and timing limits

Shoot-through occurs when the upper and lower devices in one bridge leg conduct together. A phase-to-phase or phase-to-DC-bus fault produces the same basic result: current rises through a low-impedance loop limited mainly by source impedance, DC-link inductance, device conduction characteristics, and wiring. This is heat, not logic. The protection system must detect the abnormal state, reject switching transients, and remove drive before the device exhausts its short-circuit capability.

Normal losses also set the thermal boundary. Approximate conduction loss from the applicable datasheet characteristic and calculate switching loss from measured or tabulated turn-on and turn-off energy:

Pswitch = fsw × (Eon + Eoff)

Add diode conduction and recovery losses, then evaluate the complete junction-to-coolant or junction-to-ambient thermal path. Use transient thermal impedance for pulses; a steady-state thermal resistance calculation does not describe a brief high-energy fault.

Quantity Design limit Where to read or measure it
Peak device current Below the device’s permitted operating boundary Switch datasheet and a properly rated current probe
Junction temperature Below the stated maximum under normal and fault transients Datasheet, thermal model, module temperature sensor, and loss calculation
Turn-off interval Shorter than the device-specific fault-withstand interval Switch short-circuit data and driver timing measurements
Deadtime Longer than worst-case complementary-device overlap Device turn-off data plus driver propagation and measured gate waveforms
Terminal overvoltage Below the applicable collector-emitter or drain-source rating with design margin Differential probe directly across the power terminals
Reverse-recovery stress Within the diode and switch operating limits Diode data and double-pulse measurement

Independent hardware protection architecture

Protect each bridge leg through the gate-driver layer. For an IGBT, a common method monitors collector-emitter voltage after turn-on. A high collector voltage while the gate is commanded on indicates that the device has not entered its expected low-voltage conduction state, which can result from overcurrent or a short circuit. MOSFET implementations apply the corresponding drain-source measurement or use a fast current-sensing path.

The evidence identifies turn-off within 10 µs as a common protection approach, not a transferable setting. The acceptable interval comes from the selected switch’s short-circuit data across bus voltage, gate voltage, and junction temperature. Detection blanking must outlast legitimate turn-on transients without masking a real fault.

Once a fault is detected, the driver should perform a controlled turn-off. Excessively fast gate discharge can create destructive L × di/dt overvoltage; slow turn-off adds fault energy. Driver undervoltage lockout, complementary-output interlocking, fault latching, isolated fault reporting, and a defined discharge path for the gate all belong in the hardware chain. Software should inhibit every PWM output after the hardware trip and require an intentional reset policy.

Integrated power modules can combine IGBTs, antiparallel diodes, drivers, short-circuit protection, current sensing, and temperature sensing. Such a module reduces interface risk, but its layout, supply decoupling, thermal design, and fault behavior still require validation against the module documentation.

Switch and freewheel-diode selection

An IGBT chip does not inherently provide the same body-diode structure as a power MOSFET, but many inverter-grade IGBT modules and some discrete packages integrate a matched antiparallel diode. Inspect the complete device or module datasheet before adding an external diode. A second diode selected without considering recovery charge, stray inductance, and commutation direction can increase stress rather than reduce it.

A MOSFET body diode can carry reverse current, but conduction is not the only criterion. For rated breakdown voltages above 200 V, ordinary intrinsic body diodes may have reverse-recovery behavior unsuitable for hard-switched inverter service. Select a device specifically characterized for the intended commutation duty or use an appropriate external path based on measured switching behavior.

Breakdown voltage must cover the DC-link voltage plus transient overshoot and design margin. A severely inductive DC-link can defeat a seemingly generous voltage rating; even a 3300 V device can be destroyed on a 100 V DC link when layout inductance produces uncontrolled terminal overshoot. Device rating and low-inductance construction solve different parts of the problem.

Low-inductance DC-link construction

The commutation loop includes the local positive-bus path, the conducting switch pair, the antiparallel diode path, the negative-bus return, and the local DC-link capacitor. Every added conductor length contributes inductance. During rapid current interruption, that inductance produces:

Vovershoot = Lstray × di/dt

Place the high-frequency DC-link capacitor close to the bridge terminals, minimize loop area, and use tightly coupled outgoing and return conductors. Separate the power-current path from gate-driver references. Connect the driver’s switching reference at the intended device terminal so load current does not modulate the apparent gate voltage.

Snubbers or clamps can absorb residual energy after the physical loop has been reduced. Size them from measured overshoot, ringing frequency, switching energy, and repetition rate rather than treating them as a substitute for layout. Line reactors and EMI filters may address supply harmonics, conducted emissions, or line transients, but they are application-dependent and do not replace local semiconductor protection.

Protection implementation procedure

  1. Define the electrical envelope. Record DC-link maximum voltage, motor current range, switching frequency, expected regeneration, cooling conditions, and credible faults such as leg shoot-through, phase-to-phase short, phase-to-bus short, and loss of gate-drive supply.
  2. Select the switch-diode combination. Check voltage, current, switching energy, reverse-recovery behavior, thermal impedance, and short-circuit operating information. For an integrated module, identify which protection and sensing functions are internal.
  3. Set the commutation geometry. Place local film or other suitable high-frequency capacitance at the bridge, minimize bus loop area, and establish separate power and gate-reference paths.
  4. Build hardware interlocking. Prevent simultaneous upper and lower gate commands independently of the space-vector modulation code. Set deadtime from worst-case measured turn-off and propagation behavior, not only nominal logic timing.
  5. Add the fast trip. Implement collector/drain-voltage or fast current detection, transient blanking, controlled turn-off, and a latched fault output. Derive all timing from the selected switch and driver documentation.
  6. Add thermal supervision. Monitor the available module, heatsink, or coolant temperature and correlate it with a junction-temperature model. Thermal protection handles overload and cooling faults; it is too slow for shoot-through.
  7. Define restart behavior. Block PWM after a fast trip, discharge or inhibit all gates, and diagnose the power stage before reset. Permit automatic retry only when the fault class, energy per attempt, and manufacturer operating data make it safe.
  8. Coordinate installation protection. Select feeder and branch protection for the conductors, rectifier, DC link, and applicable installation rules. Review NEC 430 and NEMA ICS 7/7.1 where they apply; verify the actual edition and jurisdiction rather than treating them as semiconductor short-circuit specifications.

Measured verification

Begin with a current-limited DC source or another controlled-energy test arrangement appropriate to the design. Verify gate polarity, isolation, driver supply levels, interlock, and deadtime before connecting the intended motor and full DC-link energy. Do not energize a full-energy bridge when complementary-device overlap remains unmeasured.

Measure upper and lower gate-emitter or gate-source waveforms together with phase current and device terminal voltage. Use probes and isolation methods rated for the common-mode voltage and transient environment. Probe directly at the power terminals; a measurement across remote bus conductors omits the local inductive overshoot that threatens the die.

Observed symptom Likely mechanism Verification
Both gates overlap Insufficient deadtime, propagation mismatch, or Miller-induced turn-on Capture both gate voltages at the device terminals under worst-case current
High turn-off voltage spike Commutation-loop inductance or overly fast fault turn-off Measure terminal voltage and current slew rate; compare normal and fault turn-off
Trip only at switching edges Protection blanking or sensing layout problem Correlate the trip input with collector/drain voltage and gate command
Temperature rises at acceptable motor current Switching, diode-recovery, conduction, or cooling loss underestimated Compare measured case temperature and electrical loss with the thermal model
Device fails during restart Persistent hard short or accumulated retry energy Latch the first trip and inspect the bridge, load, and gate signals before re-energizing

Complete normal switching tests before controlled fault tests. Fault testing needs bounded DC-link energy, remote operation, suitable containment, and instrumentation that survives the prospective transient. Compare detection time, turn-off waveform, peak current, voltage overshoot, and temperature response with the selected component limits.

Frequently asked questions

Can I protect an IGBT inverter with fuses alone?

No. Fuses and breakers protect conductors and isolate sustained faults, while the gate driver must interrupt switch-level short-circuit current within the device-specific withstand interval.

Does a higher IGBT voltage rating fix DC-link spikes?

No. Reduce commutation-loop inductance and measure collector-emitter overshoot at the device terminals; the spike follows V = L × di/dt.

Can I use the MOSFET body diode as the freewheel diode?

Only when its reverse-recovery and thermal data support the inverter’s voltage, current, and switching conditions. Above 200 V breakdown rating, an ordinary intrinsic diode may be unsuitable for hard-switched inverter commutation.

When should I stop testing and contact official support?

Stop when protection timing cannot be placed inside the switch’s documented fault capability, terminal overshoot remains above the design limit, or the datasheets omit the required short-circuit and diode data. Escalate to the official support channels of the power-device, module, and gate-driver manufacturers with measured gate, current, and terminal-voltage waveforms.

Back to blog