Energy storage system hazard analysis method and system based on full-link fault sorting
By employing a comprehensive fault analysis approach, potential hazardous scenarios and control behaviors of lithium-ion battery energy storage systems are identified, and a safety control system is established. This addresses the safety blind spots caused by the difficulty in analyzing component interactions in existing technologies, enabling more comprehensive risk management and accident prevention.
Patent Information
- Application Number
- CN202510154181.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2024-11-14
- Filing Date
- 2025-02-11
- Publication Date
- 2025-10-28
AI Technical Summary
Existing lithium-ion battery energy storage systems have blind spots in safety risk analysis. FMEA and FTA methods are insufficient to fully analyze the potential hazards caused by the interaction between various components. Furthermore, existing monitoring and protection systems are prone to accidents when dealing with thermal runaway, conflicts in the exhaust system, and insufficient information for firefighters.
A comprehensive fault analysis approach is adopted to define the hazard scenarios of the energy storage system, establish a safety control system, analyze faults through battery modules, sensing modules, protection control modules, and execution modules, identify control behaviors that may cause hazards, and formulate corresponding hazard mitigation measures.
It can identify critical failure events and hazards caused by interactions, avoid potential safety hazards in complex systems, provide hazard mitigation methods for design, decision-making, and operation and maintenance, and reduce the likelihood of accidents.
Smart Images

Figure CN120851574A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of energy storage system technology, and in particular to a method and system for hazard analysis of energy storage systems based on comprehensive fault analysis. Background Technology
[0002] The global transition to zero-carbon energy has significantly driven the large-scale application of renewable energy. Due to the inherent volatility and intermittency of renewable energy, energy storage systems are needed for balancing and absorption. Lithium-ion battery energy storage systems, with their advantages of flexibility, speed, and long lifespan, have seen the fastest growth in installed capacity in the emerging energy storage field, gradually becoming a key component of new power systems. According to the latest statistics from the National Energy Administration, by the end of 2022, lithium-ion battery energy storage accounted for 94.5% of the total installed capacity.
[0003] Due to the complex operating and usage conditions of lithium-ion batteries, the causes of safety accidents are difficult to completely avoid, and extinguishing a fire is extremely difficult once it occurs. Currently, a more feasible solution is to use a Battery Management System (BMS) and Energy Management System (EMS) for monitoring, early warning, and protection. This involves sampling from battery modules, battery clusters, battery compartments, and the entire environment, such as smoke, sound, video, and ambient temperature, to monitor the safety status of lithium batteries in real time. Once a safety problem occurs or an early warning is issued, the reaction process can be promptly interrupted using fire extinguishing, heating, exhaust fans, air conditioning, inverter relays, etc.
[0004] Currently used Failure Mode and Effects Analysis (FMEA) or Fault Tree Analysis (FTA) methods tend to focus on how individual components of an energy storage system fail and analyze the potential accidents caused by these failures. However, lithium-ion battery energy storage systems are complex systems with unique hazard profiles. Monitoring, early warning, and protection solely through BMS and EMS are insufficient. Furthermore, FMEA and FTA methods pay less attention to the complex interrelationships between components that lead to unsafe conditions, resulting in blind spots in risk analysis. The main potential problems are as follows: 1. There is a potential contradiction between the exhaust system, fire prevention, and prevention of thermal runaway propagation. For example, if multiple batteries are in a state of thermal runaway, active fire suppression measures may prevent flammable gases from being consumed by the flames, leading to the generation of more flammable gases. Alternatively, in high ambient temperatures, if the exhaust system is used to prevent the spread of thermal runaway, the presence of open flames and flammable gases inside effectively supplies oxygen, accelerating and exacerbating the propagation of thermal runaway. If the speed of thermal runaway propagation exceeds the ventilation capacity of air conditioning and fans, it may lead to the accumulation of flammable gases. In April 2019, at the McMicken substation 2MW / 2MWh energy storage project of APS Company in Arizona, USA, dendrites in lithium batteries caused the cells to overheat and ignite. The fire spread between the cells, and the gas fire suppression system was unable to extinguish the fire, and the ventilation system could not remove the explosive gases outdoors. The explosive gases continued to accumulate, and when the first emergency responders opened the hatch, oxygen entered the compartment, causing a deflagration. The cause of this accident closely resembled the theoretical analysis.
[0005] 2. When a thermal runaway battery is detected, shutting down the energy storage system from the grid may eliminate some hazards but could introduce others. Disconnecting the battery from the grid after thermal runaway could trap battery energy within the runaway battery, potentially leading to further thermal runaway. Furthermore, disconnecting the grid will cause the system's sensors to use backup power; once this backup power is depleted, technicians and firefighters will be unable to monitor the system's internal state. In July 2021, at Tesla's Megapack Victoria VBB project in Australia, the monitoring system required a 24-hour connection. Manually shutting it down left the energy storage system offline, causing a short circuit due to coolant leakage from the liquid cooling unit. This lack of monitoring failed to detect the fire in time, resulting in a blaze. The cause of this accident closely resembled the theoretical analysis.
[0006] 3. When firefighters arrive at the scene of a fire at an energy storage system, they will first assess the hazards. If the system is not open to firefighters regarding its current status or if firefighters have insufficient access, resulting in a lack of specific visual displays for them, firefighters may not be able to identify potential hazards when observing the energy storage system from the outside. When firefighters decide to open the system for inspection, there may be dangers such as fire, overvoltage, electrical sparks, smoke, or oxygen deficiency. When firefighters have doubts about the status of the power station system, in order to ensure safety, the process of consulting with equipment suppliers, maintenance personnel, and installers will consume additional time, leading to greater equipment damage. The cause of the Beijing Dahongmen accident was similar to this.
[0007] 4. Since the primary function of an EMS (Energy Storage Management System) is as a local monitoring device or cloud management platform, if software developers lack sufficient knowledge of energy storage safety management, they may configure it according to the functional safety principles of traditional software, only considering information security limitations. This lack of sufficient safety definition for complex systems can lead to information interruptions, ineffective and untimely fault control, or misoperation, potentially escalating into accidents. For example, setting excessively low or high SOC limits for some battery BMSs can easily lead to overcharging and over-discharging, damaging the internal structural materials of the battery, causing irreversible capacity decay, and even generating lithium dendrites that cause internal short circuits.
[0008] Currently, Failure Mode and Effects Analysis (FMEA) is a commonly used analytical method in risk management, focusing on the composition of the protection system, its own failure modes, failure probabilities, and risk mitigation measures. However, energy storage systems are highly interactive and complex systems, and there are many unknown factors in the intrinsic safety of batteries. A high degree of integration is needed between the Battery Management System (BMS), Power Converter System (PCS), Energy Management System (EMS), and fire protection system to jointly achieve protection functions. Therefore, FMEA cannot comprehensively analyze the failure modes between components, nor can it protect against many situations where failure cannot be detected. Summary of the Invention
[0009] The technical problem to be solved by the present invention is to overcome the shortcomings of the prior art and provide a method and system for hazard analysis of energy storage systems based on fault analysis of the entire process.
[0010] To solve the above technical problems, the technical solution of the present invention is as follows: A hazard analysis method for energy storage systems based on comprehensive fault analysis includes: Define the hazardous scenarios for energy storage systems; Establish a safety control system for the energy storage system; Taking the safety control loop of the entire energy storage system as the object, the fault analysis of the safety control system is carried out to identify the control behaviors of the safety control system that have potential hazards; Identify the energy storage system hazard scenarios corresponding to the potentially hazardous control behaviors of the safety control system.
[0011] As a preferred embodiment of the energy storage system hazard analysis method based on full-process fault analysis described in this invention, the defined hazard scenarios of the energy storage system include: The battery being in an abnormal operating state is defined as the first hazard scenario; Battery exhaust concentration exceeding the safety threshold is defined as the second hazard scenario; The exposure of operators to fire or explosion scenarios is defined as a third hazard scenario; The fourth hazard scenario is defined as the exposure of the human body to dangerous voltages, electric arcs, or electric sparks. Exposure of the human body to toxic fumes or dangerous firefighting activities is defined as the fifth hazard scenario; The sixth hazard scenario is defined as the cessation of external operations or the need for multiple maintenance.
[0012] As a preferred embodiment of the hazard analysis method for energy storage systems based on full-process fault analysis described in this invention, the safety control system includes: a battery module, a battery management module, a sensing module, a protection control module, and an execution module. The battery module includes a battery array in an energy storage system; The battery management module is used to collect the operating data of the battery module and transmit it to the protection control module; The sensing module is used to collect the operating data of the energy storage system and the environmental parameters, and transmit them to the protection and control module. The protection and control module is used to make system decisions based on the operating data of the battery module, the operating data of the energy storage system, and the environmental parameters, so that the battery module is in normal operating condition; the execution module is used to execute the system decisions made by the protection and control module.
[0013] As a preferred embodiment of the hazard analysis method for energy storage systems based on full-process fault analysis described in this invention, the sensing module includes a smoke sensor, a sound sensor, a vision sensor, and an ambient temperature sensor; the protection and control module includes an energy management system; and the execution module includes an energy storage converter, an emergency switch, a fire-fighting component, and a temperature regulation component.
[0014] As a preferred embodiment of the energy storage system hazard analysis method based on full-process fault analysis described in this invention, the step of analyzing the safety control loops of the entire energy storage system to identify potentially hazardous control behaviors of the safety control system includes: Scenarios where energy storage system hazards occur due to lack of provided, unset, unresponsive, or absent control behavior are classified as potentially hazardous control behavior A; scenarios where energy storage system hazards occur due to provided incorrect control behavior are classified as potentially hazardous control behavior B; scenarios where energy storage system hazards occur due to premature or delayed provision of control behavior are classified as potentially hazardous control behavior C; scenarios where energy storage system hazards occur due to excessively short or long provision of control behavior are classified as potentially hazardous control behavior D. Based on the above analysis method, the control behavior of each component in the safety control system is analyzed to identify all control behaviors with potential hazards.
[0015] As a preferred embodiment of the energy storage system hazard analysis method based on full-process fault analysis described in this invention, the energy storage system hazard scenarios corresponding to the potential hazard control behaviors of the safety control system include: Based on each potentially hazardous control behavior of each component in the safety control system, the corresponding energy storage system hazard scenario is determined.
[0016] The present invention also provides a hazard analysis system for energy storage systems based on full-process fault analysis, including: a definition module for defining hazard scenarios of energy storage systems; Establish a module to build a safety control system for the energy storage system; The identification module is used to analyze the safety control system for all aspects of the energy storage system and identify the control behaviors of the safety control system that have potential hazards. The determination module is used to determine the energy storage system hazard scenario corresponding to the potentially hazardous control behavior of the safety control system.
[0017] The present invention also discloses a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the program, it implements the method described in any of the above-mentioned energy storage system hazard analysis methods based on full-process fault analysis.
[0018] The present invention also discloses a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the method described in any of the above-mentioned energy storage system hazard analysis methods based on full-process fault analysis.
[0019] The beneficial effects of this invention are: (1) Compared with FMEA and FTA, which can only analyze the impact of the failure of the protection system itself, the above method can not only identify key failure events, but also analyze the harmful events that may be caused by unsafe fault protection decisions when failure events occur from the perspective of component interaction.
[0020] (2) The present invention classifies each component into safety functions and sorts out the entire process based on the interaction relationship, which can avoid the potential safety hazards that still exist in complex systems and alleviate the possibility of accidents caused by decision-making errors from a mechanism perspective.
[0021] (3) Based on the hazard analysis conclusions, the present invention can prepare hazard mitigation methods for each hazard scenario in terms of design, decision control and operation and maintenance, and can provide correct decision suggestions when unexpected hazard scenarios occur. Attached Figure Description
[0022] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the following description of the embodiments will be briefly introduced. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0023] Figure 1 A flowchart illustrating the hazard analysis method for energy storage systems based on comprehensive fault analysis provided by this invention; Figure 2 This is a schematic diagram of the safety control system for an energy storage system. Figure 3 A schematic diagram of the energy storage system hazard analysis system based on full-process fault analysis provided by the present invention; Figure 4 A schematic diagram of the computer device provided by the present invention. Detailed Implementation
[0024] To make the content of this invention easier to understand, the invention will be further described in detail below with reference to specific embodiments and accompanying drawings.
[0025] Figure 1 A flowchart illustrating the hazard analysis method for energy storage systems based on comprehensive fault analysis provided in this application embodiment is shown. The method includes the following steps: Step S101: Define the hazard scenarios of the energy storage system.
[0026] Specifically, to prevent fires and explosions in lithium-ion battery systems, it is necessary to define the hazardous scenarios of energy storage systems and the potential damage caused by different hazardous scenarios.
[0027] In this embodiment, there are six hazardous scenarios for the energy storage system: The battery being in an abnormal operating state is defined as the first hazard scenario, or H1.
[0028] Battery exhaust concentration exceeding the safety threshold is defined as the second hazard scenario, namely H2.
[0029] The exposure of operators to fire or explosion scenarios is defined as the third hazard scenario, or H3.
[0030] Exposure of the human body to dangerous voltages, electric arcs, or electric sparks is defined as the fourth hazard scenario, or H4.
[0031] Exposure of humans to toxic fumes or dangerous firefighting activities is defined as the fifth hazard scenario, or H5.
[0032] The sixth hazard scenario, or H6, is defined as the energy storage system being shut down or requiring multiple maintenance operations.
[0033] It should be noted that the above six hazardous scenarios are not ranked in terms of the degree of harm.
[0034] The potential damages from different hazardous scenarios are as follows: L1, battery thermal runaway propagation: After a battery experiences thermal runaway, nearby batteries may also experience thermal runaway.
[0035] L2. Combustible gas explosion: When a lithium-ion battery is in a state of thermal runaway, it will release combustible gases. In enclosed or confined areas, without a venting system, these gas explosions can cause property damage.
[0036] L3. Personnel casualties: If personnel are exposed to hazardous scenarios such as fire, explosion, overvoltage, electric arc, electric spark, toxic gas, or oxygen deficiency caused by energy storage accidents, they may be injured or killed.
[0037] L4. The energy storage system fails to work or operate, causing the energy storage function to stop and resulting in economic losses, including the cost of replacement that cannot be restored afterward.
[0038] The relationship between the hazardous scenarios and potential damages of the aforementioned energy storage systems is shown in Table 1. Table 1 Step S102: Establish a safety control system for the energy storage system.
[0040] Specifically, a safety control system for the energy storage system is established, and each component is categorized into battery modules, sensing modules, protection and control modules, and execution modules, according to the control system. (See [link to relevant documentation]). Figure 2 .
[0041] Among them, the battery module is a battery array in a single energy storage system. Depending on the size, it can be composed of one or more battery modules, battery clusters, or even battery compartments. The battery management module is used to collect the operating data of the battery module and transmit it to the protection and control module.
[0042] The sensing module is used to collect operating data and environmental parameters of the energy storage system, and provides data to the protection and control module through communication protocols such as CAN and Modbus. The sensing module includes various sensors such as smoke sensors, gas sensors, sound sensors, vision sensors, video camera sensors, ambient temperature sensors, as well as temperature sensors, current sensors, pressure sensors, etc., deployed in the battery pack and feeding back information to the battery management system (BMS).
[0043] A battery management system (BMS) typically consists of three levels: the battery module management unit (BMU), the battery cluster management unit (BCMU), and the battery array management unit (BAU), with the number of each corresponding to the number of battery modules, battery clusters, and battery compartments.
[0044] The protection and control module is responsible for maintaining battery safety. It provides system decisions based on the battery module's operating data, such as charging, discharging, heating, cooling, and ventilation, to ensure the battery module is in normal operating condition. It also responds to faults and provides alarms, as well as providing safety-related information to external operators and firefighters. The main components of the protection and control module include the energy management system (EMS).
[0045] For an energy storage power station consisting of multiple battery compartments, the Energy Management System (EMS) includes local monitoring devices, a coordinating controller, and a cloud service platform.
[0046] The execution module executes system decisions made by the protection control module. The main components of the execution module include an energy storage converter, an emergency switch, an independent fire suppression system, and a temperature regulation system. The temperature regulation system includes a heating, ventilation, and cooling (HVAC) system or a liquid cooling system. Heating or cooling is performed via the liquid cooling system or HVAC based on instructions from the protection control module, or the battery is heated using graphene thermally conductive sheets as disclosed in patent 2023207755045. The independent fire suppression system performs independent fire suppression and feeds back the status to the battery management system (BMS) and the energy management system (EMS).
[0047] It should be noted that, based on the different roles and functions, the external information of the Energy Management System (EMS) is divided into three categories: investors and installers, management users and maintenance providers, and firefighters. Different roles have different access permissions. This function has been disclosed in patent CN116054312B.
[0048] Step S103: Taking the safety control loop of the entire energy storage system as the object, conduct fault analysis on the safety control system and identify the control behaviors of the safety control system that have potential hazards.
[0049] Specifically, firstly, the potential problem control behaviors of each component are divided into the following four types for analysis: Potentially hazardous control behavior A: Scenarios where the energy storage system is hazardous due to the lack of provided, defined, unresponsive, or absent control behavior. B: Scenario where erroneous control behavior leads to hazards in the energy storage system; C: Control behaviors with potential hazards: Scenarios where the timing of control behaviors is too early or too late, leading to hazards in the energy storage system. Control behaviors with potential hazards (D): Control behaviors that are provided for too short or too long, resulting in a hazard scenario for the energy storage system.
[0050] Subsequently, all relevant controls of each component in the safety control system were analyzed according to these four types. The analysis results are shown in Table 2, where A, B, C, and D refer to control behaviors A, B, C, and D with potential hazards in S103. Table 2 Step S104: Determine the energy storage system hazard scenario corresponding to the potentially hazardous control behavior of the safety control system.
[0051] Specifically, determine the energy storage system hazard scenarios corresponding to each potentially hazardous control behavior of each component in the safety control system, and establish a hazard analysis list of different types of faults in the entire process, as shown in Table 3. In Table 3, A, B, C, and D refer to potentially hazardous control behaviors A, B, C, and D in S103. Table 3 Based on the hazard analysis conclusions in Table 3, hazard mitigation methods for each hazard scenario can be developed in terms of design, decision-making and control, and operation and maintenance. Details are as follows: Scenario 1: If a battery is in a state of thermal runaway, venting, and without open flame, and active fire extinguishing measures are taken due to the detection of smoke, it is possible that the combustible gas cannot be consumed by the flame, resulting in the generation of more combustible gas. This could cause the concentration of combustible gas to exceed the safety limit (H2), leading to a combustible gas explosion (L2). (Table 3, No. 10, Event 10.4 [Smoke and Venting], Type B [Problem Due to Provision], Possible Problems H1\H2\H5).
[0052] Similarly, if a battery is in a state of thermal runaway, venting, or open flame, and the ventilation system is mistakenly used to prevent the spread of thermal runaway because the smoke sensor fails to detect the open flame, this is equivalent to supplying oxygen to accelerate and exacerbate the propagation of thermal runaway, given the actual presence of open flame and flammable gas. If the speed of thermal runaway propagation exceeds the ventilation capacity of the air conditioner and fan, it may further lead to the accumulation of flammable gas. (Table 3, No. 10, Event 10.4 [Smoke and Ventilation], Type A [Problem Due to Lack of Information], Possible Problems H1\H2\H5).
[0053] The correct decision in the above situation is to first extinguish the fire when thermal runaway, venting, and open flame are correctly detected, so that the battery status becomes number 9 in Table 3. Then, use the ventilation system and cooling system. When the ventilation system is activated, evacuate the unprotected people at the ventilation openings to change the battery status to number 8 in Table 3. Combine this with reducing the SOC to reduce the thermal runaway energy, so as to smoothly enter the normal state.
[0054] Scenario 2: When the EMS detects thermal runaway, exhaust, or smoke, directly disconnecting the energy storage system from the grid may eliminate some hazards but could introduce others. After disconnecting the grid, the system's sensors will use backup power. When the backup power is depleted, the BMS and all sensors powered from the grid may face data loss.
[0055] When maintenance personnel and firefighters arrive at the scene of a fire at an energy storage system, they first assess the hazards. If the system is not open to firefighters regarding its current status or if their access is insufficient, resulting in a lack of specific visual displays, firefighters may not be able to identify potential hazards when inspecting the energy storage system. When firefighters decide to open the system for inspection, there may be hazards present, such as fire, overvoltage, electric sparks, smoke, or oxygen deficiency. If firefighters have doubts about the status of the power station system, the process of consulting with equipment suppliers, maintenance personnel, and installers to ensure safety will consume additional time, leading to greater equipment damage. This makes it difficult for maintenance personnel and firefighters to know the current status of the system, potentially exposing them to dangerous voltages, arcs, or electric sparks, resulting in personal injury or death (H3 / H4 / H5). Data loss also makes recovery from the incident difficult (H6). A similar scenario occurred in Tesla's VBB project in Victoria, Australia (Table 3, No. 1, Event 1.5 [Energy Storage System Shutdown and Off-Grid], BC Type [Problem Occurred Due to Occurrence or Occurrence Too Quickly], Possible Problems H3\H4\H5).
[0056] Meanwhile, when a battery experiences thermal runaway, if the EMS disconnects the battery from the grid, it may leave battery energy trapped in the thermally runaway battery, with the continuous current causing it to become the energy that causes the thermal runaway.
[0057] The correct decision in the above situation should be to ensure that, even after the system is disconnected, the Energy Management System (EMS) can still guarantee that critical parameters can be measured accurately and promptly, providing this information to maintenance personnel and firefighters to meet safety requirements for data accuracy and acquisition delay. According to general specifications, voltage measurements should be within 2% of full scale, current measurements should be accurate to within 5% of full scale, temperature measurements should be accurate to within 2°C, the time difference between automated measurement and system controller startup should not exceed 10 seconds, and ground fault detection circuits should be tested starting during the post-accident commissioning period. These should be checked regularly through on-site calibration and verification.
[0058] Therefore, compared to FMEA and FTA, which can only analyze the impact of the protection system's own failure, the above methods can not only identify critical failure events but also analyze the potential hazards caused by unsafe fault protection decisions at the time of failure events from the perspective of component interactions. Furthermore, classifying each component by safety function and analyzing the entire process based on interaction relationships can prevent potential safety hazards from remaining in complex systems, thus mitigating the possibility of accidents caused by decision-making errors from a mechanistic perspective.
[0059] Figure 3This is a schematic diagram of a hazard analysis system for energy storage systems based on comprehensive fault analysis, provided as an embodiment of this application. The system includes a definition module 201, an establishment module 202, an identification module 203, and a determination module 204.
[0060] Specifically, the definition module 201 is used to define the hazardous scenarios of the energy storage system.
[0061] Module 202 is used to establish a safety control system for the energy storage system.
[0062] The identification module 203 is used to analyze the safety control system for all aspects of the energy storage system and identify the control behaviors of the safety control system that have potential hazards.
[0063] The determination module 204 is used to determine the energy storage system hazard scenario corresponding to the control behavior of the safety control system that has potential hazards.
[0064] See Figure 4 This embodiment also provides a computer device, the components of which may include, but are not limited to: one or more processors or processing units, system memory, and buses connecting different system components (including system memory and processing units).
[0065] A bus refers to one or more of several bus architectures, including a memory bus or memory controller, a peripheral bus, a graphics acceleration port, a processor, or a local bus using any of the various bus architectures. Examples of these architectures include, but are not limited to, the Industry Standard Architecture (ISA) bus, the Micro Channel Architecture (MAC) bus, the Enhanced ISA bus, the Video Electronics Standards Association (VESA) local bus, and the Peripheral Component Interconnect (PCI) bus.
[0066] Computer systems / servers typically include a variety of computer system-readable media. These media can be any available media that can be accessed by the computer system / server, including volatile and non-volatile media, and removable and non-removable media.
[0067] System memory may include computer system readable media in the form of volatile memory, such as random access memory (RAM) and / or cache memory. The computer device may further include other removable / non-removable, volatile / non-volatile computer system storage media. By way of example only, the storage system may be used to read and write non-removable, non-volatile magnetic media. Disk drives for reading and writing to removable non-volatile disks (e.g., "floppy disks") and optical disc drives for reading and writing to removable non-volatile optical discs (e.g., CD-ROMs, DVD-ROMs, or other optical media) may be provided. In these cases, each drive may be connected to a bus via one or more data media interfaces. The memory may include at least one program product having a set (e.g., at least one) of program modules configured to perform the functions of the embodiments of the present invention.
[0068] A program / utility having a set (at least one) of program modules can be stored, for example, in memory. Such program modules include—but are not limited to—an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include an implementation of a network environment. The program modules typically perform the functions and / or methods described in the embodiments of this invention.
[0069] Computer devices can also communicate with one or more external devices (such as keyboards, pointing devices, monitors, etc.). This communication can be done through input / output (I / O) interfaces. Furthermore, computer devices can communicate with one or more networks (such as local area networks (LANs), wide area networks (WANs), and / or public networks, such as the Internet) via network adapters.
[0070] The processing unit executes the functions and / or methods described in the embodiments of the present invention by running programs stored in the system memory.
[0071] The aforementioned computer program can be stored in a computer storage medium, that is, the computer storage medium is encoded with a computer program, which, when executed by one or more computers, causes one or more computers to perform the method flow and / or device operation shown in the above embodiments of the present invention.
[0072] With the development of time and technology, the meaning of "medium" has become increasingly broad. The dissemination of computer programs is no longer limited to tangible media; they can also be downloaded directly from the network. Any combination of one or more computer-readable media can be used. A computer-readable medium can be a computer-readable signal medium or a computer-readable storage medium. Computer-readable storage media can be, for example,—but not limited to—electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatuses, or devices, or any combination thereof. More specific examples of computer-readable storage media (a non-exhaustive list) include: electrical connections having one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this document, a computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.
[0073] Computer-readable signal media may include data signals propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals may take various forms, including—but not limited to—electromagnetic signals, optical signals, or any suitable combination thereof. Computer-readable signal media may also be any computer-readable medium other than computer-readable storage media, capable of transmitting, propagating, or transmitting programs for use by or in connection with an instruction execution system, apparatus, or device.
[0074] The program code contained on a computer-readable medium may be transmitted using any suitable medium, including—but not limited to—wireless, wire, optical fiber, RF, etc., or any suitable combination thereof.
[0075] Computer program code for performing the operations of this invention can be written in one or more programming languages or a combination thereof. Programming languages include object-oriented programming languages—such as Java, Smalltalk, and C++—as well as conventional procedural programming languages—such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0076] In addition to the above embodiments, the present invention may have other implementation methods; all technical solutions formed by equivalent substitution or equivalent transformation fall within the protection scope claimed by the present invention.
Claims
1. A hazard analysis method for energy storage systems based on comprehensive fault analysis, characterized in that: include: Define the hazardous scenarios for energy storage systems; Establish a safety control system for the energy storage system; Taking the safety control loop of the entire energy storage system as the object, the fault analysis of the safety control system is carried out to identify the control behaviors of the safety control system that have potential hazards; Identify the energy storage system hazard scenarios corresponding to the potentially hazardous control behaviors of the safety control system.
2. The hazard analysis method for energy storage systems based on full-process fault analysis according to claim 1, characterized in that: The defined hazardous scenarios for energy storage systems include: The battery being in an abnormal operating state is defined as the first hazard scenario; Battery exhaust concentration exceeding the safety threshold is defined as the second hazard scenario; The exposure of operators to fire or explosion scenarios is defined as a third hazard scenario; The fourth hazard scenario is defined as the exposure of the human body to dangerous voltages, electric arcs, or electric sparks. Exposure of the human body to toxic fumes or dangerous firefighting activities is defined as the fifth hazard scenario; The sixth hazard scenario is defined as the cessation of external operations or the need for multiple maintenance.
3. The hazard analysis method for energy storage systems based on full-process fault analysis according to claim 1, characterized in that: The safety control system includes: a battery module, a battery management module, a sensing module, a protection control module, and an execution module; The battery module includes a battery array in an energy storage system; The battery management module is used to collect the operating data of the battery module and transmit it to the protection control module; The sensing module is used to collect the operating data of the energy storage system and the environmental parameters, and transmit them to the protection and control module. The protection and control module is used to provide system decisions based on the operating data of the battery module, the operating data of the energy storage system, and the environmental parameters, so that the battery module is in normal operating condition. The execution module is used to execute the system decisions made by the protection control module.
4. The hazard analysis method for energy storage systems based on full-process fault analysis according to claim 3, characterized in that: The sensing module includes a smoke sensor, a sound sensor, a vision sensor, and an ambient temperature sensor; the protection and control module includes an energy management system; and the execution module includes an energy storage converter, an emergency switch, a fire-fighting component, and a temperature regulation component.
5. The hazard analysis method for energy storage systems based on full-process fault analysis according to claim 4, characterized in that: The method of analyzing the safety control loops of the entire energy storage system and identifying potentially hazardous control behaviors of the safety control system includes: Scenarios where energy storage system hazards occur due to lack of provided, unset, unresponsive, or absent control behavior are classified as potentially hazardous control behavior A; scenarios where energy storage system hazards occur due to provided incorrect control behavior are classified as potentially hazardous control behavior B; scenarios where energy storage system hazards occur due to premature or delayed provision of control behavior are classified as potentially hazardous control behavior C; scenarios where energy storage system hazards occur due to excessively short or long provision of control behavior are classified as potentially hazardous control behavior D. Based on the above analysis method, the control behavior of each component in the safety control system is analyzed to identify all control behaviors with potential hazards.
6. The hazard analysis method for energy storage systems based on full-process fault analysis according to claim 5, characterized in that: The energy storage system hazard scenarios corresponding to the potentially hazardous control behaviors of the safety control system include: Based on each potentially hazardous control behavior of each component in the safety control system, the corresponding energy storage system hazard scenario is determined.
7. A hazard analysis system for energy storage systems based on comprehensive fault analysis, characterized in that: include: The definition module is used to define the hazardous scenarios of the energy storage system; Establish a module to build a safety control system for the energy storage system; The identification module is used to analyze the safety control system for all aspects of the energy storage system and identify the control behaviors of the safety control system that have potential hazards. The determination module is used to determine the energy storage system hazard scenario corresponding to the potentially hazardous control behavior of the safety control system.
8. A computer device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the program, it implements the method as described in any one of claims 1 to 6.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by the processor, it implements the method as described in any one of claims 1 to 6.