Safety protection methods and electronic equipment for energy storage battery management systems
By acquiring monitoring data and encrypted configuration data of the energy storage battery management system, and formulating differentiated security protection strategies, the security protection problem of the energy storage battery management system under advanced persistent threats was solved, achieving precise and dynamic security protection upgrades, and improving the system's response accuracy and anti-attack capabilities.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- HEFEI GUOXUAN HIGH TECH POWER ENERGY
- Filing Date
- 2026-05-26
- Publication Date
- 2026-06-26
Smart Images

Figure CN122293435A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of energy storage system safety management technology, and more specifically, to a safety protection method and electronic device for an energy storage battery management system. Background Technology
[0002] Currently, while battery management systems (BMS) are the core control units ensuring the safe operation of energy storage power stations, and generally integrate fault diagnosis modules, these modules operate in isolated, islanded architectures, lacking a collaborative mechanism based on a global security situation. Especially when facing low-frequency, multi-point collaborative advanced persistent threats (APTs), BMS struggles to achieve closed-loop control from "single-point detection" to "state awareness" and then to "strategy linkage." As a result, security protection lacks precision and initiative, failing to meet the requirements for dynamic state management and adaptive response of the BMS. Furthermore, it increases the risk of misjudgments and omissions due to information silos in actual operation, making it difficult to achieve precise, in-depth, and real-time security protection for the BMS. In summary, the isolated and static response of the security function modules in related technologies' BMS leads to a lack of dynamic linkage in protection strategies, hindering the achievement of precise security protection for energy storage batteries.
[0003] There is currently no effective solution to the above problems. Summary of the Invention
[0004] This application provides a safety protection processing method and electronic device for an energy storage battery management system, which at least solves the technical problem in the related art where the safety function modules of the energy storage battery management system are isolated and have static responses, resulting in a lack of dynamic linkage in the protection strategy and an inability to achieve accurate safety protection for the energy storage battery.
[0005] According to one aspect of the embodiments of this application, a security protection method for an energy storage battery management system is provided, comprising: acquiring monitoring data of the energy storage battery management system and data encryption and permission configuration data, wherein the monitoring data includes at least hardware self-test data, communication link status data, data integrity data, and network connection behavior data of the energy storage battery management system; determining the security status of the energy storage battery management system based on the monitoring data and the data encryption and permission configuration data; and determining a security protection strategy for the energy storage battery management system according to the security status, wherein the security protection strategy is at least used to indicate the data acquisition strategy of the monitoring data, the data encryption strategy of the specified data, and the access control strategy of the energy storage battery management system.
[0006] Optionally, based on monitoring data and data encryption and permission configuration data, the safety status of the energy storage battery management system is determined, including: detecting whether there is any abnormal behavior in the energy storage battery management system based on monitoring data and data encryption and permission configuration data; determining the safety status as normal if no abnormal behavior is detected; determining the safety status as early warning if abnormal behavior is detected and the abnormality level of the abnormal behavior is level one; and determining the safety status as emergency if abnormal behavior is detected and the abnormality level of the abnormal behavior is level two.
[0007] In the above approach, this mechanism achieves accurate determination of the security status through a dual criterion of "existence of abnormal behavior—abnormality level." This avoids misjudgments or omissions caused by the accidental triggering of a single indicator, ensuring that the status classification is strictly aligned with the actual level of security threat. This provides a reliable and traceable decision-making basis for the differentiated execution of subsequent protection strategies, significantly improving the system's response accuracy and stability in complex attack environments. Optionally, based on monitoring data and data encryption and permission configuration data, the system detects whether the energy storage battery management system exhibits abnormal behavior. This includes: determining that no abnormal behavior exists if both the monitoring data and the data encryption and permission configuration data are within the corresponding preset security range; and determining that abnormal behavior exists if either the monitoring data or the data encryption and permission configuration data is outside the corresponding preset security range.
[0008] By employing the above methods, a balance can be achieved between high sensitivity and low false alarm rate in abnormal behavior identification, laying a reliable and quantifiable input foundation for accurate classification of subsequent security status, and effectively enhancing the system's ability to detect covert and progressive attacks on energy storage BMS in its early stages.
[0009] Optionally, the method further includes: determining the anomaly level as Level 1 when the abnormal behavior is a communication or access anomaly between the energy storage battery management system and the interactive terminal; and determining the anomaly level as Level 2 when the abnormal behavior is a network attack or data tampering behavior targeting the energy storage battery management system.
[0010] By introducing a classification mechanism through the above methods and using a two-dimensional mapping of "behavior type - impact level", the system can accurately distinguish between "probing disturbances" and "destructive attacks". This avoids the system frequently entering high protection mode due to false alarms, which would affect normal operation. It also prevents the system from missing critical defense windows due to underestimation of the level. This provides a clear, operable, and auditable basis for the decisive execution of subsequent differentiated protection strategies, and significantly improves the resilience and intelligent response of the energy storage BMS in complex network environments.
[0011] Optionally, if communication link status data indicates a communication link anomaly within a first consecutive number of sampling periods, or if the frequency of cyclic redundancy check (CRC) failures in predetermined key communication frames in data integrity data reaches a preset maximum allowable failure frequency, or if network connection behavior data shows communication latency jitter, abnormal retransmission rate increases by a predetermined amount, or frequent connection requests from unauthorized protocol ports, the abnormal behavior is determined to be a communication anomaly. Here, "frequent" refers to a consecutive occurrence reaching a predetermined number, or a cumulative occurrence within a predetermined time period reaching a predetermined number. If data encryption and permission configuration data detects that an unauthorized IP address has initiated more than a specified number of failed access attempts to non-core service ports within a preset time window, or if network connection behavior data shows high-frequency unauthorized port scanning, unauthorized reuse of session tokens, or non-compliant credentials carried in authentication requests, or if hardware self-test data shows authentication module access anomalies, security boot verification failures, or abnormal access to the key storage area, the abnormal behavior is determined to be an access anomaly. Here, high-frequency unauthorized port scanning is used to indicate... If the scanning frequency of unauthorized ports exceeds a predetermined frequency; if a network attack pattern matching a preset attack signature database is identified in network connection behavior data, or if the hash value or digital signature verification of preset key control instructions fails in data integrity data, or if communication link status data indicates that the encrypted channel is abnormally interrupted or downgraded, the abnormal behavior is determined to be a network attack behavior. The network attack pattern includes at least one of the following: session interception behavior of a middleman attack, abnormal re-encryption of communication data packets, or sequence number jump; if a preset key system parameter stored in non-volatile memory is found to be inconsistent with the backup area mirror data or trusted hash value in data integrity data, and no physical damage to the memory is reported in the hardware self-test data, or if non-compliant authorized parameter update records are detected based on data encryption and permission configuration data, or if an abnormal write instruction source is found in network connection behavior data, the abnormal behavior is determined to be a data tampering behavior.
[0012] By introducing a judgment mechanism through the above methods and combining structured and quantifiable rules, "anomalies" are subdivided into four types of events with clear attack attributes and security levels. This achieves a leap from "phenomenon identification" to "attack attribution," which not only significantly improves the accuracy of anomaly judgment and the ability to resist false alarms, but also provides a solid and traceable event semantic foundation for subsequent security status classification and protection strategy matching, providing key support for building a proactive and accurate security protection system.
[0013] Optionally, based on monitoring data and data encryption and permission configuration data, detect whether the energy storage battery management system exhibits abnormal behavior, including: determining the existence of abnormal behavior when monitoring data or data encryption and permission configuration data are detected to be outside the corresponding preset security range; and determining the following scores when both monitoring data and data encryption and permission configuration data are within the corresponding preset security range: hardware self-test anomaly score corresponding to hardware self-test data, communication link status anomaly score corresponding to communication link status data, data integrity anomaly score corresponding to data integrity data, network connection behavior anomaly score corresponding to network connection behavior data, and data encryption parameter anomaly score corresponding to data encryption and permission configuration data. Anomaly scoring for access control permissions is performed; the weight values for hardware self-test anomaly scores, communication link status anomaly scores, data integrity anomaly scores, network connection behavior anomaly scores, data encryption parameter anomaly scores, and access control permission anomaly scores are determined; based on these scores and their respective weight values, a weighted summation is performed to obtain a comprehensive anomaly score; if the comprehensive anomaly score is less than a preset scoring threshold, it is determined that no abnormal behavior exists; if the comprehensive anomaly score is greater than or equal to the preset scoring threshold, it is determined that abnormal behavior exists.
[0014] By employing the above methods, the limitations of threshold-triggered modes can be overcome, enabling a shift from "event-driven" to "situation-driven" approaches. This significantly enhances the early identification capabilities of advanced persistent threats such as APT attacks, incremental penetration, and hidden backdoors. Furthermore, through an interpretable scoring structure and a configurable weighting system, it provides quantifiable and traceable decision-making basis for adaptive optimization of security strategies and audit tracing, thereby greatly improving the resilience and intelligent defense level of energy storage BMS in complex adversarial environments.
[0015] Optionally, if the preset scoring thresholds include a first scoring threshold and a second scoring threshold, and the first scoring threshold is less than the second scoring threshold, the method further includes: if the comprehensive abnormal score is greater than or equal to the first scoring threshold and less than the second scoring threshold, determining the abnormality level as the first level; and if the comprehensive abnormal score is greater than or equal to the second scoring threshold, determining the abnormality level as the second level.
[0016] Through the above methods, this dual-threshold grading mechanism breaks through the crude "all or nothing" judgment mode of a single threshold. By introducing a risk gradient range, it achieves a security response based on multi-level modulation. This avoids over-protection that could affect system availability due to low-intensity fluctuations, while ensuring timely intervention before the threat accumulation threshold is reached, enabling precise implementation and dynamic adaptation of security protection strategies. It not only significantly improves the early identification and graded handling capabilities of progressive attacks, but also provides quantifiable, traceable, and auditable decision support for the automated execution of subsequent coordinated protection strategies and the accurate generation of compliance audit reports.
[0017] Optionally, after determining the safety status of the energy storage battery management system based on monitoring data and data encryption and permission configuration data, the method further includes: if the safety status is determined to be normal, continuously detecting the first continuous period of anomaly level of the first level; if the first continuous period reaches a preset first continuous detection period, switching the safety status from normal to warning status.
[0018] By employing the above methods, false alarms caused by non-malicious factors such as electromagnetic interference, network congestion, and instantaneous load fluctuations can be effectively filtered out, significantly reducing the system's false trigger rate. At the same time, through continuous confirmation logic, early trend detection of potential attack behaviors can be achieved. If attackers adopt low-intensity, long-term penetration strategies (such as slow probing and tentative configuration tampering), their behavior will be identified by the system as a systemic risk rather than an isolated event due to its continuous existence. This enables steady-state response, anti-jitter, and prevention of false triggers during security state switching.
[0019] Optionally, after determining the safety status of the energy storage battery management system based on monitoring data and data encryption and permission configuration data, the method further includes: if the safety status is determined to be a warning status or an emergency status, continuously detecting the monitoring data and data encryption and permission configuration data within the corresponding preset safety range for a second continuous period; if the second continuous period reaches a preset second continuous detection period, switching the safety status from the warning status or emergency status to the normal status.
[0020] By enforcing the requirement that "continuous compliance with all-dimensional data (monitoring, encryption, and permissions)" is the sole basis for state rollback, a closed-loop security governance model can be achieved, moving from "passive response" to "active confirmation," significantly improving the reliability and security of the recovery process. This approach prevents both excessive defense leading to long-term system degradation and potential security risks caused by hasty resets, thus building a dynamic self-healing capability for energy storage BMS that combines security and availability.
[0021] Optionally, based on the safety status, a safety protection strategy for the energy storage battery management system is determined, including: When the safety status is normal, the safety protection strategy is determined as follows: monitoring data is collected at a preset base frequency, specified data is encrypted using a first encryption algorithm, and access permissions for multiple access objects to the energy storage battery management system are set according to preset regular access permissions; When the safety status is in an early warning state, the safety protection strategy is determined as follows: monitoring data is collected at a specified frequency, specified data is encrypted using a second encryption algorithm, and access permissions for specified access objects among the multiple access objects are frozen, where the specified frequency is greater than the preset base frequency, and the encryption level of the second encryption algorithm is greater than the encryption level of the first encryption algorithm; When the safety status is in an emergency state, the safety protection strategy is determined as follows: abnormal physical ports in the specified physical ports are controlled to disconnect, abnormal logical links in the specified logical links are controlled to disconnect, specified data is encrypted using a third encryption algorithm, and access permissions for other access objects among the multiple access objects, except for the target access object, are frozen, where the specified physical port is the physical port associated with monitoring data collection, the specified logical link is the logical link associated with monitoring data collection, the encryption level of the third encryption algorithm is higher than the encryption level of the second encryption algorithm, and the target access object is the access object with the highest access permission among the multiple access objects.
[0022] Through the above methods, this strategy system is based on the design concept of "defense levels advancing with the escalation of threats". It can avoid excessive consumption of resources under low risk, and can decisively take extreme measures such as disconnecting the network, cutting off access, strong encryption, and hard isolation under high risk, thus achieving the optimal balance between security and availability.
[0023] According to another aspect of the embodiments of this application, a non-volatile storage medium is also provided, which stores multiple instructions, any one of which is adapted to be loaded by a processor for a security protection processing method of an energy storage battery management system.
[0024] According to another aspect of the embodiments of this application, an electronic device is also provided, including one or more processors and a memory, wherein the memory is used to store one or more programs, wherein when the one or more programs are executed by one or more processors, the one or more processors cause the one or more processors to implement any one of the safety protection processing methods of an energy storage battery management system.
[0025] According to another aspect of the embodiments of this application, a computer program product is also provided, including a computer program, wherein when the computer program is executed by a processor, it implements the steps of any one of the security protection processing methods of an energy storage battery management system.
[0026] In this embodiment, by acquiring monitoring data and data encryption and permission configuration data of the energy storage battery management system, wherein the monitoring data includes at least hardware self-test data, communication link status data, data integrity data, and network connection behavior data of the energy storage battery management system; based on the monitoring data and data encryption and permission configuration data, the security status of the energy storage battery management system is determined; and according to the security status, a security protection strategy for the energy storage battery management system is determined, wherein the security protection strategy is used to indicate the data acquisition strategy of the monitoring data, the data encryption strategy of the specified data, and the access control strategy of the energy storage battery management system. This achieves the goal of dynamically identifying the security status level and intelligently matching differentiated protection strategies covering multiple dimensions based on multi-dimensional monitoring data and data encryption and permission configuration data, thereby realizing the technical effect of intelligently upgrading the security protection of the energy storage battery management system from passive response to active collaboration and hierarchical precise prevention and control. This solves the technical problem in related technologies where the security function modules of the energy storage battery management system are isolated and have static responses, resulting in a lack of dynamic linkage in the protection strategy and the inability to achieve precise security protection for the energy storage battery. Attached Figure Description
[0027] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:
[0028] Figure 1 This is a flowchart of a safety protection method for an energy storage battery management system according to an embodiment of this application;
[0029] Figure 2 This is a flowchart of an optional safety protection method for an energy storage battery management system according to an embodiment of this application;
[0030] Figure 3 This is a schematic diagram of an optional security protection process for an energy storage battery management system according to an embodiment of this application;
[0031] Figure 4 This is a schematic diagram of a safety protection device for an energy storage battery management system according to an embodiment of this application;
[0032] Figure 5 This is a schematic diagram of an electronic device according to an embodiment of this application. Detailed Implementation
[0033] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort should fall within the scope of protection of the present application.
[0034] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0035] First, to facilitate understanding of the embodiments of this application, some terms or nouns involved in this application will be explained below:
[0036] The IEC 62443-3-3 standard is a core component of the information security series of standards for Industrial Automation and Control Systems (IACS) issued by the International Electrotechnical Commission (IEC).
[0037] AES-128 is an Advanced Encryption Standard (AES) symmetric encryption algorithm that uses a 128-bit key to efficiently encrypt non-core data under normal security conditions, ensuring the confidentiality of communication and storage.
[0038] AES-256 is an Advanced Encryption Standard (AES) symmetric encryption algorithm that uses a 256-bit key. It is used to implement high-strength encryption on sensitive data such as battery status parameters (e.g., State of Charge (SOC) and State of Health (SOH)) in early warning or emergency security situations to resist advanced persistent attacks and meet high security compliance requirements.
[0039] SM4: A symmetric encryption algorithm that uses a 128-bit key and has a security strength comparable to AES-128.
[0040] According to an embodiment of this application, a method embodiment for security protection processing of an energy storage battery management system is provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.
[0041] Figure 1 This is a flowchart of a safety protection method for an energy storage battery management system according to an embodiment of this application, such as... Figure 1 As shown, the method includes the following steps:
[0042] Step S102: Obtain monitoring data and data encryption and permission configuration data of the energy storage battery management system. The monitoring data includes at least the hardware self-test data, communication link status data, data integrity data, and network connection behavior data of the energy storage battery management system.
[0043] In this step, a multi-source data acquisition module deployed on the main control unit acquires real-time monitoring data during the operation of the Battery Management System (BMS). Hardware self-test data indicates the operational integrity and root of trust status of key hardware modules within the BMS, and may include, but is not limited to, one or more of the following: secure boot verification results, main control chip firmware hash value comparison results, encryption coprocessor health status, and abnormal access counts to the key storage area. Communication link status data indicates the stability and reliability of communication channels within the BMS and with external systems (such as Power Conversion System (PCS) and Energy Management System (EMS)), and may include, but is not limited to, one or more of the following: Controller Area Network (CAN) bus communication packet loss rate, Ethernet communication latency fluctuation value, heartbeat message timeout count, communication link retransmission count, and port connection interruption events. Data integrity data indicates whether key control parameters and transmission data have been tampered with or damaged during storage or transmission, and may include, but is not limited to, cyclic redundancy check of battery cell voltage / temperature sampling data. One or more of the following are considered: CRC failure count, backup area consistency comparison results of protection threshold parameters, digital signature verification status of firmware upgrade packages, and integrity verification anomaly flags of communication messages; Network connection behavior data is used to indicate abnormal response patterns of the energy storage BMS to external network access requests, and may include, but is not limited to, one or more of the following: frequency of unauthorized IP address access attempts to the WEB management interface, number of non-compliant protocol port scans, Secure Shell (SSH) / File Transfer Protocol (FTP) login failure records, and unexpected activation events of remote debugging interfaces; Data encryption and permission configuration data is used to indicate the current security protection configuration and permission changes adopted by the energy storage BMS, and may include, but is not limited to, one or more of the following: currently enabled data encryption algorithm type (e.g., AES-128 / AES-256), key rotation cycle, transport layer protocol encryption status (e.g., whether Transport Layer Security (TLS) is enabled), permission levels of each user role (e.g., administrator / maintenance personnel / visitor), and permission change logs (e.g., username, time, and operation items of the most recent permission modification). By using this data encryption and permission configuration data, abnormal data encryption or permission configuration situations corresponding to the energy storage battery management system can be identified, including but not limited to the number of times the encryption algorithm has been downgraded, the key length has been shortened, the encryption protocol has been disabled, the number of times the privilege has been elevated, and high-privilege roles have been assigned to unauthorized users (i.e., unauthorized port scanning behavior).The two types of data mentioned above (i.e., real-time monitoring data and data encryption and permission configuration data) serve as the input basis for the safety situation awareness of the energy storage battery management system. They are used uniformly for subsequent safety status assessment to ensure that the status judgment is based on comprehensive, true and traceable energy storage BMS operation and safety configuration information, and to avoid misjudgment or omission due to one-sided information.
[0044] In one optional embodiment, the safety status of the energy storage battery management system is determined based on monitoring data and data encryption and permission configuration data, including: detecting whether there is abnormal behavior in the energy storage battery management system based on monitoring data and data encryption and permission configuration data; determining the safety status as normal if no abnormal behavior is detected; determining the safety status as early warning if abnormal behavior is detected and the abnormality level of the abnormal behavior is the first level; and determining the safety status as emergency if abnormal behavior is detected and the abnormality level of the abnormal behavior is the second level.
[0045] In this embodiment, a unified abnormal behavior detection engine is constructed by integrating multi-source information such as hardware self-test results, communication link fluctuations, data integrity verification failures, abnormal network access behavior, encryption strength downgrades, and permission configuration changes. This engine can, but is not limited to, classify and grade various abnormal events according to a preset rule base. The first-level abnormality refers to a mild abnormality that only affects non-core functions and does not endanger the execution of control instructions or the authenticity of data (such as tentative access to non-critical ports or occasional delays in historical data communication). The second-level abnormality refers to a severe abnormality that may directly damage battery protection logic, tamper with key parameters, or break the system trust chain (such as non-compliant modification of core protection thresholds, hardware trust root verification failures, or repeated tampering of key communication frames). When no events marked as abnormal by the rule base are detected, the current energy storage BMS is determined to be in a normal state. When a Level 1 abnormality is detected without being accompanied by a Level 2 abnormality, it is determined that it does not pose a substantial threat to core functions such as battery charge and discharge control, SOC estimation, and equalization management, so the safety status is set to a warning state. Once any Level 2 abnormality is detected, regardless of whether a Level 1 abnormality exists, it is considered to pose a direct threat to the safety foundation of the energy storage BMS, and the state is immediately determined to be an emergency state.
[0046] In the above approach, the mechanism achieves accurate determination of safety status through the dual criteria of "existence of abnormal behavior and abnormality level". This can avoid misjudgment or omission caused by the mis-triggering of a single indicator, ensure that the safety status classification of energy storage BMS is strictly aligned with the actual level of safety threat, provide a reliable and traceable decision-making basis for the differentiated execution of subsequent security protection strategies, and significantly improve the system's response accuracy and stability in complex attack environments.
[0047] In one optional embodiment, based on monitoring data and data encryption and permission configuration data, the system detects whether there is abnormal behavior in the energy storage battery management system, including: if the monitoring data and data encryption and permission configuration data are both within the corresponding preset security range, it determines that there is no abnormal behavior; if the monitoring data or data encryption and permission configuration data are not within the corresponding preset security range, it determines that there is abnormal behavior.
[0048] In this embodiment, a preset multi-dimensional security baseline library can be used to set acceptable dynamic threshold ranges for two types of data: hardware self-test results, communication link stability, data integrity verification results, network connection behavior patterns, and data encryption algorithm strength, key management strategy, and user permission configuration. When all monitoring data falls within its corresponding security baseline range, and the data encryption strategy meets mandatory compliance requirements and the permission configuration has not undergone unauthorized changes, the current operating environment is determined to be in a trusted state, confirming that there is no abnormal behavior. Conversely, if any item in any type of data (whether monitoring data or encryption / permission configuration data) exceeds the preset threshold, such as a CAN communication packet loss rate exceeding the tolerance limit, a hash value of a key parameter being inconsistent with the backup image, or a non-administrator being incorrectly granted firmware upgrade permissions, an abnormal behavior judgment is triggered. This detection mechanism abandons the one-sidedness of single-dimensional judgment, ensuring that even if an attacker attempts to evade detection through low-intensity, single-point penetration (such as only tampering with permission configuration or only creating communication jitter), they still cannot bypass the dual verification of "data integrity" and "security configuration compliance" in this embodiment.
[0049] By employing the above methods, a balance can be achieved between high sensitivity and low false alarm rate in anomaly behavior identification, laying a reliable and quantifiable input foundation for accurate classification of subsequent security status, and effectively enhancing the stealth of the energy storage BMS and the ability to detect progressive attacks early.
[0050] In an optional embodiment, the method further includes: determining the anomaly level as a first level when the abnormal behavior is a communication anomaly or access anomaly between the energy storage battery management system and the interactive terminal; and determining the anomaly level as a second level when the abnormal behavior is a network attack or data tampering behavior targeting the energy storage battery management system.
[0051] In this embodiment, a clear level judgment logic is established based on the nature, scope of impact, and potential threat level of abnormal behavior to core functions: When abnormal behavior manifests as communication delay exceeding limits between BMS and PCS, EMS, or remote monitoring platform, loss of heartbeat messages, frequent connection attempts on non-critical ports, or low-privilege users attempting to access unauthorized interfaces, although it reflects the risk of the energy storage BMS's peripheral protection being probed or misconfigured, it does not directly damage core control functions such as battery voltage / temperature acquisition, charge / discharge control command issuance, and SOC / SOH calculation. Therefore, it is uniformly classified as a first-level anomaly as an early warning signal of potential risks. When behavior with attack characteristics is detected, such as man-in-the-middle attacks matching intrusion detection signatures, malicious tampering of key data frames (such as protection thresholds and equalization control parameters), hardware trust root verification failure, or inconsistency between firmware hash values and the secure storage area mirror, it indicates that the attack has penetrated into the energy storage BMS kernel level and may directly cause physical safety accidents such as overcharging, over-discharging, and thermal runaway. Such behavior is judged as a second-level anomaly, representing a substantial infringement on the foundation of system security.
[0052] By introducing a classification mechanism through the above methods and using a two-dimensional mapping of "behavior type - impact level", the system can accurately distinguish between "probing disturbances" and "destructive attacks". This avoids the energy storage BMS from frequently entering high protection mode due to false alarms, which would affect normal operation. It also prevents the loss of critical defense windows due to underestimation of the level. This provides a clear, operable, and auditable basis for the decisive execution of subsequent differentiated protection strategies, and significantly improves the resilience and intelligent response of the energy storage BMS in complex network environments.
[0053] Optionally, a three-level safety status classification model can be constructed for energy storage BMS application scenarios. This model clearly divides safety status into normal, warning, and emergency states, and for each level, precisely defines its status judgment conditions, trigger thresholds, and priority order of protection responses. The normal state can be set as follows: No safety anomalies are detected, and all functional modules of the energy storage BMS are operating normally. Real-time monitoring data from the fault diagnosis module are all within the preset safety baseline range, and data encryption and access control data (i.e., data encryption and access control functions) are operating stably according to standard configurations. The warning state can be set as follows: At least one minor safety anomaly indicator is detected, such as instantaneous delay in non-critical data transmission or probing access to non-core ports. This type of anomaly has not yet substantially affected the integrity and real-time performance of the core control functions of the energy storage BMS (such as battery voltage / temperature acquisition and charge / discharge control command issuance), but it indicates a potential safety risk. The fault diagnosis module reports a "minor anomaly" level (i.e., Level 1). The emergency state is set as follows: A severe security event is detected, such as a confirmed middle-party attack, non-compliant (or abnormal) tampering (or alteration) of core data (e.g., SOC / SOH thresholds, protection parameters), non-compliant replacement of critical hardware (e.g., main control chip, storage units), or failure of root of trust verification. Such events have directly threatened the core functions of the energy storage BMS or are highly likely to trigger energy storage BMS-level security incidents (e.g., overcharging, over-discharging, thermal runaway). The fault diagnosis module reports a "Severe Anomaly" level (i.e., Level 2).
[0054] In one optional embodiment, when communication link status data indicates a communication link anomaly (e.g., packet loss rate exceeding a preset packet loss rate threshold) within a first consecutive number of sampling periods, or when the CRC failure frequency of predetermined key communication frames in data integrity data reaches a preset maximum allowable failure frequency, or when network connection behavior data shows communication latency jitter, abnormal retransmission rate increases by a predetermined amount, or frequent connection requests from unauthorized protocol ports, the abnormal behavior is determined to be a communication anomaly. Here, "frequent" refers to a consecutive occurrence reaching a predetermined number, or a cumulative occurrence within a predetermined duration reaching a predetermined number. When data encryption and permission configuration data detects that an unauthorized IP address has initiated more than a specified number of failed access attempts to a non-core service port within a preset time window, or when network connection behavior data shows high-frequency unauthorized port scanning, unauthorized reuse of session tokens, or non-compliant credentials carried in authentication requests, or when hardware self-test data shows authentication module access anomalies, security startup verification failures, or abnormal access to the key storage area, the abnormal behavior is determined to be an access anomaly. Here, "high-frequency" refers to... Unauthorized port scanning behavior is used to indicate that the scanning frequency of unauthorized ports is greater than a predetermined frequency; when a network attack pattern matching the preset attack feature library is identified in the network connection behavior data, or when the hash value or digital signature verification of preset key control instructions (such as charge / discharge limits, equalization enable signals, etc.) in the data integrity data fails, or when the communication link status data indicates that the encrypted channel is abnormally interrupted or degraded, the abnormal behavior is determined to be a network attack behavior, wherein the network attack pattern includes at least one of the following: session interception behavior of a middleman attack, abnormal re-encryption of communication data packets, or sequence number jump; when the preset key system parameters (which may include, but are not limited to, battery cell overvoltage / undervoltage thresholds, SOH calibration factors, protection action delay) stored in the non-volatile memory are detected to be inconsistent with the backup area mirror data or trusted hash value in the data integrity data, and no physical damage to the memory is reported in the hardware self-test data, or when non-compliant authorized parameter update records are detected based on the data encryption and permission configuration data, or when there is an abnormal write instruction source in the network connection behavior data, the abnormal behavior is determined to be a data tampering behavior.
[0055] In this embodiment, a multi-dimensional, fine-grained abnormal behavior identification mechanism is used to accurately classify and determine communication anomalies, access anomalies, network attack behaviors, and data tampering behaviors. When communication link status data continuously exceeds the first sampling period and experiences packet loss, latency exceeding limits, or heartbeat interruption, or when the CRC check failure frequency of key control frames (such as charging / discharging commands, equalization enable signals) reaches a preset tolerance threshold, or when network connection behavior exhibits non-protocol-standard latency jitter, abnormally high retransmission rates, or high-frequency triggering of connection requests from unauthorized ports within a short period (e.g., 5 consecutive times or ≥8 times cumulatively within 10 seconds), it is determined to be a communication anomaly. This type of anomaly reflects impaired underlying link stability, which may originate from electromagnetic interference, physical link degradation, or mild probing behavior, but has not yet reached the control logic level. When data encryption and permission configuration data detect that an unauthorized IP initiates multiple failed accesses (e.g., ≥3 times) to non-core service ports of the energy storage BMS within a preset time window, or when network behavior exhibits high-frequency port scanning (…), it is considered a communication anomaly. Access anomalies are identified when the following occur: scanning frequency > 10 times / minute, session token reuse, authentication requests carrying non-standard credentials (such as expired certificates or illegal keys), abnormal calls to the authentication module in the hardware self-test report, security boot verification failure, or unexpected reading / writing of the key storage area. These behaviors indicate that attackers are attempting to gain system access through identity forgery, privilege escalation, or configuration penetration, representing typical admission layer attacks. If network connection behavior data matches predefined attack patterns in the attack signature database, such as detected sequence number changes in communication data packets, repeated encryption, session key renegotiation by a man-in-the-middle, or forced downgrading of the communication channel to an insecure protocol, these are considered network attack behaviors. These behaviors demonstrate a clear attack intent, aiming to steal or manipulate communication content. When data integrity verification reveals that data is stored in flash memory... If critical system parameters (such as overcharge / over-discharge voltage thresholds and SOC estimation model coefficients) in the memory (Flash) or electrically erasable programmable read-only memory (EEPROM) differ from the backup image or trusted hash value, and hardware self-test rules out the possibility of physical memory damage, or if the permission configuration log records parameter update operations without compliant authorized signatures, or if abnormal write commands from untrusted sources appear in network behavior, then it is considered data tampering. Such anomalies directly threaten the core control logic of the energy storage BMS and are very likely to cause physical safety events such as battery thermal runaway.
[0056] By introducing a judgment mechanism through the above methods and combining structured and quantifiable rules, abnormal behavior is subdivided into four types of events with clear attack attributes and security levels. This achieves a leap from "phenomenon identification" to "attack attribution," which not only significantly improves the accuracy of anomaly judgment and the ability to resist false alarms, but also provides a solid and traceable event semantic foundation for subsequent security status classification and protection strategy matching, providing key support for building a proactive and accurate security protection system.
[0057] In one optional embodiment, based on monitoring data and data encryption and permission configuration data, the system detects whether the energy storage battery management system exhibits abnormal behavior. This includes: determining the existence of abnormal behavior when monitoring data or data encryption and permission configuration data are detected to be outside the corresponding preset security range; and determining the following scores when both monitoring data and data encryption and permission configuration data are within the corresponding preset security range: hardware self-test anomaly score corresponding to hardware self-test data, communication link status anomaly score corresponding to communication link status data, data integrity anomaly score corresponding to data integrity data, network connection behavior anomaly score corresponding to network connection behavior data, and data encryption parameter anomaly score corresponding to data encryption and permission configuration data. The system performs a routine score and an access control permission anomaly score; it determines the weight values for each of the following anomaly scores: hardware self-test anomaly score, communication link status anomaly score, data integrity anomaly score, network connection behavior anomaly score, data encryption parameter anomaly score, and access control permission anomaly score; based on these scores and their respective weight values, a weighted summation is performed to obtain a comprehensive anomaly score; if the comprehensive anomaly score is less than a preset score threshold, it is determined that there is no abnormal behavior; if the comprehensive anomaly score is greater than or equal to the preset score threshold, it is determined that there is abnormal behavior.
[0058] In this embodiment, instead of relying solely on a single dimension of "whether the limit is exceeded" for binary judgment, a multi-dimensional quantitative scoring mechanism is introduced after initially confirming that all raw data has not exceeded the hard security baseline. This mechanism provides a refined assessment of potential, low-intensity, or concealed anomalies. Six types of anomalies—hardware self-test anomalies, communication link disturbances, occasional data verification failures, slight deviations in network behavior, non-compliant changes to encryption policies, and lax permission configurations—are each assigned an independent score. Different weights are assigned based on their criticality in the energy storage BMS security architecture. For example, hardware root trust verification failures may have the highest weight, while occasional communication link jitter may have the lowest weight, reflecting their varying contributions to energy storage BMS security. By weighted summing of the six scores, a continuous and quantifiable comprehensive anomaly score is generated, thus aggregating previously discrete and fragmented anomaly signals into a unified security posture indicator. When the score is below the threshold, the current energy storage BMS is determined to be in an "implicitly trusted" state, and no abnormal alarm is triggered to avoid system malfunctions caused by minor disturbances. When the score reaches or exceeds the preset threshold, even if no single hard limit is exceeded, "cumulative abnormal behavior" is determined to exist, indicating that an attack may be gradually eroding the system's security boundary through low-intensity, multi-point penetration.
[0059] By employing the above methods, the limitations of threshold-triggered modes can be overcome, enabling a shift from "event-driven" to "situation-driven" approaches. This significantly enhances the early identification capabilities of advanced persistent threats such as abnormal attacks, gradual penetration, and hidden backdoors. Furthermore, through an interpretable scoring structure and a configurable weighting system, it provides quantifiable and traceable decision-making basis for adaptive optimization of security strategies and audit tracing, thereby greatly improving the resilience and intelligent defense level of energy storage BMS in complex adversarial environments.
[0060] It should be noted that this embodiment employs a two-level anomaly detection mechanism: the first level is a static threshold screening based on a preset security range, used to quickly eliminate obviously normal states and reduce the system's computational load; the second level is a dynamic comprehensive assessment based on a weighted anomaly scoring model, used to identify advanced persistent threats (APTs) composed of multiple low-intensity anomalies that cannot be identified by a single threshold. These two levels are not substitutes for each other, but rather synergistic—the second-level model is activated only when the first level detects multiple edge anomalies for refined risk assessment, thereby significantly improving the detection rate of covert attacks while ensuring real-time performance.
[0061] Optionally, but not limited to, a comprehensive anomaly score can be obtained by weighted summation of the following factors: hardware self-test anomaly score, communication link status anomaly score, data integrity anomaly score, network connection behavior anomaly score, data encryption parameter anomaly score, and access control permission anomaly score, along with their respective weight values: ;in, This is a comprehensive anomaly score, expressed as a dimensionless score value. The hardware self-test anomaly score can be determined based on, but is not limited to, the number of security boot verification failures and the number of abnormal accesses to the key storage area (cumulative summation, weighted summation, or weighted average), and normalized to the [0,1] interval using an exponential decay function. Scoring for communication link status anomalies can be based, but is not limited to, on the continuous packet loss rate p according to the formula. Calculation, where This is the sensitivity coefficient for the communication link. Scoring for data integrity anomalies can be based, but is not limited to, on the frequency f of keyframe CRC failures, according to the formula. Calculation, where Set the maximum allowed failure frequency (can be set to 5). Network connectivity anomaly scoring can be based, but is not limited to, on the frequency of unauthorized port scans (r) and the number of session token reuses (t), as follows: The calculation is performed, where the preset maximum scanning frequency is (which can be set to 10 times / minute). Set the maximum number of reuses (can be set to 3 times). Scoring for abnormal data encryption parameters can be based on, but is not limited to, information on downgraded encryption algorithms, shortened key lengths, and disabled encryption protocols, as follows: ,in, This indicates encryption algorithm downgrade information, used to indicate whether an encryption algorithm downgrade has occurred. If a downgrade has occurred (e.g., from AES-256 to AES-128), it is 1; otherwise, it is 0. The key length shortening information indicates whether a key length shortening has occurred. If a key length shortening has occurred (e.g., the key length is adjusted from 256 bits to 128 bits or less), the value is 1; otherwise, it is 0. The encryption protocol disabled information indicates whether security protocols such as TLS / DTLS are disabled or downgraded to unencrypted transmission. If so, the value is 1; otherwise, it is 0. The value range is [0,1]. The scoring of access control permission anomalies can be determined based on, but is not limited to, privilege escalation information, the assignment of high-privilege roles to unauthorized users, bypassing of two-factor authentication, and the granting of remote configuration permissions. The corresponding formula is expressed as follows: ,in, This indicates privilege escalation information, used to indicate whether privilege escalation has occurred. If it has (e.g., an operations and maintenance role gains administrator privileges), the value is 1; otherwise, it is 0. This indicates the situation where a high-privilege role is assigned to an unauthorized user. It is used to indicate whether the unauthorized account logs into a higher-privilege account. If yes (e.g., if the unauthorized IP address successfully logs into the administrator account), the value is 1; otherwise, it is 0. This indicates whether two-factor authentication has been bypassed. It indicates whether two-factor authentication is disabled or skipped. If yes, it is 1; otherwise, it is 0. This indicates whether remote configuration permissions are enabled. It indicates whether remote configuration permissions are enabled. If they are enabled (e.g., remote firmware upgrade or parameter modification permissions are enabled and the enabling IP is not in the IP authorization list), the value is 1; otherwise, it is 0. The value range is [0,1]. Each weight coefficient satisfies... You can set, but are not limited to, settings , , , , , .
[0062] It should be noted that this embodiment provides an optional implementation method for obtaining a comprehensive anomaly score based on individual scores from hardware self-test anomaly scoring, communication link status anomaly scoring, data integrity anomaly scoring, network connection behavior anomaly scoring, data encryption parameter anomaly scoring, and access control permission anomaly scoring, as well as through row-weighted summation. In practical applications, the corresponding thresholds and scoring logic can be dynamically determined according to the specific monitoring scenario and the selection of indicators for various data types in hardware self-test data, communication link status data, data integrity data, and network connection behavior data, which will not be elaborated here.
[0063] In an optional embodiment, where the preset scoring thresholds include a first scoring threshold and a second scoring threshold, and the first scoring threshold is less than the second scoring threshold, the method further includes: determining the abnormality level as a first level when the comprehensive abnormal score is greater than or equal to the first scoring threshold and less than the second scoring threshold; and determining the abnormality level as a second level when the comprehensive abnormal score is greater than or equal to the second scoring threshold.
[0064] In this embodiment, by setting two-level scoring thresholds, the continuous "comprehensive anomaly score" is transformed into two-level anomaly levels with clear security semantics, thereby achieving a precise transformation from "risk level quantification" to "response level mapping". When the comprehensive anomaly score reaches the first scoring threshold (e.g., 0.5) but does not exceed the second scoring threshold (e.g., 0.7), it indicates that although the energy storage BMS has not suffered a direct destructive attack, it has accumulated multi-dimensional, moderate-intensity anomalies, such as continuous slight jitter in the communication link, non-critical lenient permission configuration, and failure to trigger hard blocking when the encryption algorithm is downgraded. These behaviors have not yet endangered the core control functions, but constitute potential, evolving security threats, and are therefore classified as Level 1 anomalies, triggering early warning response mechanisms (e.g., increasing monitoring frequency and improving the encryption strength of sensitive data). When the comprehensive anomaly score exceeds the second scoring threshold, it means that the energy storage BMS has accumulated to a high-risk level and is very likely to face organized, multi-vector coordinated attacks, such as multiple critical modules experiencing anomalies simultaneously, permission bypass and data verification failures coexisting, and encryption channel anomalies superimposed with network scanning behavior. At this time, it is determined that the attack has posed a substantial threat to the security foundation of the energy storage BMS, and is immediately upgraded to Level 2 anomalies, initiating the highest level of protection response (e.g., freezing non-administrator privileges, forcing high-strength encryption across the entire link, and initiating emergency shutdown plans).
[0065] Through the above methods, this dual-threshold grading mechanism breaks through the crude "all or nothing" judgment mode of a single threshold. By introducing a risk gradient range, it achieves a security response based on multi-level modulation. This not only avoids over-protection due to low-intensity fluctuations affecting the availability of the energy storage BMS, but also ensures timely intervention before the threat accumulation threshold, achieving precise implementation and dynamic adaptation of security protection strategies. It not only significantly improves the early identification and graded handling capabilities of progressive attacks, but also provides quantifiable, traceable, and auditable decision support for the automated execution of subsequent coordinated protection strategies and the accurate generation of compliance audit reports.
[0066] Step S104: Based on monitoring data and data encryption and permission configuration data, determine the safety status of the energy storage battery management system.
[0067] In this step, based on the comprehensive analysis of the aforementioned monitoring data and encryption / permission configuration data, it is determined whether there are any abnormal behaviors in the current operating environment, and accordingly, the security status of the BMS is dynamically classified into three categories: normal status, warning status, or emergency status. For example, in the security status classification step, a normal status is defined as no security anomalies in the system; a warning status is defined as the detection of minor security anomalies that do not affect the core control functions of the BMS; and an emergency status is defined as the detection of a serious security event that may endanger the core functions of the BMS or cause a safety accident in the energy storage system. By comparing and aggregating risks from multiple dimensions of information such as hardware self-test results, communication link anomalies, data integrity verification failures, network behavior anomalies, encryption algorithm downgrades, and permission configuration changes, and based on a preset logical rule base, the nature, duration, and combination patterns of each anomaly are comprehensively evaluated to eliminate occasional fluctuations or false alarms, and finally, the current security status level is confirmed and locked. This process does not rely on a single event trigger but is based on the overall security characterization of the energy storage BMS, ensuring that the status determination is sufficient and stable, and providing a reliable basis for the accurate deployment of subsequent differentiated protection strategies.
[0068] In an optional embodiment, after determining the safety status of the energy storage battery management system based on monitoring data and data encryption and permission configuration data, the method further includes: if the safety status is determined to be normal, continuously detecting the first continuous period of anomaly level of the first level; and if the first continuous period reaches a preset first continuous detection period, switching the safety status from normal to warning status.
[0069] In this embodiment, a state switch is not triggered by a single occurrence of a Level 1 anomaly. Instead, a time-accumulated confirmation mechanism is introduced to ensure that the state change is based on persistent risks rather than instantaneous disturbances. When the energy storage battery management system is in a normal state, if multiple Level 1 anomalies (such as communication or access anomalies) are detected during subsequent continuous monitoring, these anomaly events will be continuously counted and accumulated within a time window. Only when the Level 1 anomaly is stably identified and does not disappear within a preset first continuous detection cycle (such as 10 consecutive sampling cycles or 5 minutes) is it determined that the anomaly has formed a stable trend, rather than being an occasional interference or noise false alarm. At this time, the safety state is smoothly switched from the normal state to the warning state, and lightweight protection measures such as enhanced monitoring and restricted access are activated. In other words, when the safety state is determined to be normal, a first continuous period of continuous detection is performed to detect whether there is a communication or access anomaly between the energy storage battery management system and the interactive terminal; when the first continuous period reaches the preset first continuous detection cycle, the safety state is switched from the normal state to the warning state.
[0070] By employing the above methods, false alarms caused by non-malicious factors such as electromagnetic interference, network congestion, and instantaneous load fluctuations can be effectively filtered out, significantly reducing the system's false trigger rate. At the same time, through continuous confirmation logic, early trend detection of potential attack behaviors can be achieved. If attackers adopt low-intensity, long-term penetration strategies (such as slow probing and tentative configuration tampering), their behavior will be identified by the system as a systemic risk rather than an isolated event due to its continuous existence. This enables steady-state response, anti-jitter, and prevention of false triggers during security state switching.
[0071] In an optional embodiment, after determining the safety status of the energy storage battery management system based on monitoring data and data encryption and permission configuration data, the method further includes: if the safety status is determined to be a warning status or an emergency status, continuously detecting the monitoring data and data encryption and permission configuration data within the corresponding preset safety range for a second continuous period; if the second continuous period reaches a preset second continuous detection period, switching the safety status from the warning status or emergency status to the normal status.
[0072] In this embodiment, after the energy storage battery management system enters a warning or emergency state, it does not immediately return to normal operation simply because a single event has been mitigated. Instead, a safety recovery confirmation mechanism is introduced. This requires that after the abnormal event is eliminated, the energy storage BMS must continuously and stably operate in a baseline state without any abnormalities for a preset second consecutive detection cycle (e.g., 20 consecutive sampling cycles or 10 minutes) before a state rollback operation can be performed. This design ensures that the energy storage BMS not only "appears to be normal," but also verifies over time that the threat has been completely eliminated, the risk has not rebounded, and there are no residual anomalies in the configuration. This avoids misjudgments of "false recovery" caused by transient phenomena such as brief network recovery, temporary communication continuity, or cached data reset. Especially in an emergency state, after implementing high-intervention measures such as strong isolation, permission freezing, and encryption hardening, if the system switches back to normal without sufficient stability verification, it may fall back into risk due to incomplete removal of attack payloads or failure to restore trusted configurations.
[0073] By mandating continuous compliance with all data dimensions (monitoring, encryption, permissions) as the sole basis for state rollback, a closed-loop security governance model can be achieved, moving from "passive response" to "active confirmation," significantly improving the reliability and security of the recovery process. This approach prevents long-term degradation of the energy storage BMS's security status due to excessive defense and eliminates potential security risks caused by hasty resets, thus building a dynamic self-healing capability for the energy storage BMS that combines security and availability.
[0074] Optionally, the first continuous detection cycle can be set to 3 consecutive sampling cycles, each sampling cycle being 100 ms; the second continuous detection cycle can be set to 10 consecutive sampling cycles; and the third continuous detection cycle can be set to 2 consecutive sampling cycles. When the safety status is in the warning state, if the third continuous cycle of communication abnormality or access abnormality lasts for more than 200 ms and is not handled, the automatic switch from the safety status to the emergency status will be triggered. When the safety status is in the emergency status, if the monitoring data, data encryption, and permission configuration data are all restored to the preset safety range within 10 consecutive sampling cycles, and the energy storage BMS self-test passes all hardware trust root verifications, the system can only switch back to the normal status after manual confirmation.
[0075] Optional, but not limited to, protection strategies under normal conditions include: collecting monitoring data in real time at a preset baseline frequency and performing full-function monitoring; protecting routine data (such as real-time collected monitoring data) with standard-strength encryption algorithms (such as using the first encryption algorithm AES-128); and implementing routine, role-based access control policies according to preset routine access permissions. Protection strategies under alert conditions include: increasing the monitoring frequency of monitoring data to twice or more than the preset baseline frequency (e.g., 50ms / time), and focusing on tracking and performing deep packet inspection on specific links that generate abnormal signals (such as specific communication ports or data segments); automatically increasing the encryption strength of all data marked as sensitive (such as battery status parameters and protection settings) to a high level (e.g., using the second encryption algorithm AES-256); automatically restricting operation permissions, temporarily freezing all access permissions for low-privilege roles (such as visitors), and restricting the permissions of maintenance personnel to modify core parameters. Issuing prompt alerts through the human-machine interface or alarm devices to remind maintenance personnel to intervene and investigate. The following protection strategies may be implemented in an emergency, but are not limited to: immediately locking and isolating the detected abnormal physical ports or logical links, and continuously capturing data snapshots and operational logs before and after the attack at the highest sampling rate as evidence for subsequent analysis; forcibly enabling the highest level of encryption algorithms (such as the third encryption algorithm, AES-256 and SM4 hybrid encryption mode) to protect all outgoing and stored data, and blocking all unverified abnormal data write requests, while simultaneously backing up critical system states and core data to an independent secure storage area; freezing all user operation permissions except those with the highest access privileges (such as the highest administrator privileges), allowing only administrators to execute preset emergency procedures; triggering the highest level of audible and visual alarms, and sending emergency shutdown commands to the energy management system and energy storage converter of the energy storage system, actively cutting off the main battery charging and discharging circuit, and, if necessary, linking the fire protection system to enter standby mode. Simultaneously, initiating preset emergency response procedures and notifying relevant personnel.
[0076] Step S106: Based on the safety status, determine the safety protection strategy of the energy storage battery management system. The safety protection strategy is used to indicate at least the data acquisition strategy for monitoring data, the data encryption strategy for specified data, and the access control strategy for the energy storage battery management system.
[0077] In this step, based on the determined safety status of the energy storage BMS, a preset safety protection strategy mapping table is automatically matched, and corresponding operation instructions are dynamically generated and issued. The safety protection strategy at least indicates: the data acquisition strategy for monitoring data (at least indicating the data acquisition frequency), the data encryption strategy for specified data (at least indicating the data encryption algorithm used), and the access control strategy for the energy storage battery management system. For example, when the safety status is normal, the baseline monitoring frequency is maintained, a default-strength encryption algorithm is used for non-sensitive data, and standard role access control policies are implemented. When the safety status escalates to a warning status, the acquisition frequency of critical monitoring data is automatically increased, high-strength encryption is forcibly enabled for core parameters such as battery SOC, SOH, and protection thresholds, and non-administrator users' write permissions to the parameter configuration interface are restricted. When the safety status enters an emergency status, unnecessary data acquisition is suspended, only high-frequency recording of critical safety logs is retained, the highest-strength encryption algorithm is forcibly enabled for all externally transmitted and stored data, and the operation permissions of all users except the highest-level administrator are frozen, prohibiting high-risk operations such as remote configuration and firmware upgrades. The determination and implementation of the above protection strategies are entirely driven by the current security status, realizing the coordinated response of the three major security dimensions of monitoring, encryption and access control, and ensuring that the protection capabilities of the energy storage battery management system match the level of security risks.
[0078] In one optional embodiment, the security protection strategy of the energy storage battery management system is determined according to the security status, including: when the security status is normal, the security protection strategy is determined as follows: collecting monitoring data at a preset reference frequency, encrypting specified data using a first encryption algorithm, and setting access permissions for multiple access objects to the energy storage battery management system according to preset regular access permissions; when the security status is in an early warning state, the security protection strategy is determined as follows: collecting monitoring data at a specified frequency, encrypting specified data using a second encryption algorithm, and freezing the access permissions of a specified access object among the multiple access objects, wherein the specified frequency is greater than the preset reference frequency, and the encryption level of the second encryption algorithm is greater than the encryption level of the first encryption algorithm; when the security status is in an emergency state, the security protection strategy is determined as follows: controlling the disconnection of abnormal physical ports in the specified physical ports, controlling the disconnection of abnormal logical links in the specified logical links, encrypting specified data using a third encryption algorithm, and freezing the access permissions of other access objects among the multiple access objects except for the target access object, wherein the specified physical port is the physical port associated with the monitoring data collection, the specified logical link is the logical link associated with the monitoring data collection, the encryption level of the third encryption algorithm is higher than the encryption level of the second encryption algorithm, and the target access object is the access object with the highest access permission among the multiple access objects.
[0079] In this embodiment, the designated access object is an access object with an access permission level lower than a predetermined level. A logical link represents a virtual data channel defined by a communication protocol used to transmit monitoring data, control commands, or encrypted communication information within the energy storage battery management system or during interactions with external systems. By constructing a dynamic response framework with a one-to-one mapping of "state-policy," a fundamental shift in security protection from "static configuration" to "situation-driven" is achieved. Under normal conditions, efficient operation is maintained with minimal disturbance. Standard sampling frequency and basic encryption strength (such as AES-128) are used to ensure the security of routine communication, and access control follows the principle of minimum necessity to ensure that operational efficiency and system availability are not affected. Once an alert state is entered, lightweight enhancement measures are initiated—the monitoring frequency is doubled to improve anomaly detection sensitivity, the encryption strength of sensitive data (such as SOC, SOH, and protection thresholds) is upgraded to AES-256, and high-risk operation permissions of unnecessary roles (such as visitors and ordinary maintenance personnel) are frozen, forming a three-tiered defense of "enhanced perception, strengthened encryption, and restricted access." The gradient effectively curbs potential infiltration and probing attacks, preventing threat escalation. When the state escalates to an emergency, it enters the highest level of defense mode, not only increasing the encryption strength to the strongest level (such as the national cryptographic standard SM4 based on hardware security modules or customized anti-quantum encryption), but also immediately cutting off physical ports (such as abnormal Ethernet ports) and logical links (such as hijacked CAN bus channels) identified as attack sources, achieving physical isolation of the attack surface. At the same time, it freezes all access permissions except for the highest-level administrator (requiring two-factor authentication + physical key), ensuring that the system is controlled only by trusted entities, and, if necessary, linking PCS to perform emergency shutdown.
[0080] Through the above methods, this strategy system is based on the design concept of "defense levels advancing with the escalation of threats". It can avoid excessive consumption of resources under low risk, and can decisively take extreme measures such as disconnecting the network, cutting off access, strong encryption, and hard isolation under high risk, thus achieving the optimal balance between security and availability.
[0081] Optionally, the preset base frequency is 100ms / time, the specified frequency is 50ms / time, the first encryption algorithm is AES-128, the second encryption algorithm is AES-256, and the third encryption algorithm is a hybrid encryption mode of AES-256 and SM4; when the safety state is a warning state, the specified data includes the real-time SOC, SOH, single cell voltage threshold and equalization control command of the battery pack; when the safety state is an emergency state, the specified data further includes the main control chip firmware hash value, security boot verification signature and communication key rotation record.
[0082] As an optional embodiment, when the safety status is an emergency state, the safety protection strategy also includes: controlling the triggering of audible and visual alarms, sending emergency shutdown commands to the energy management system (EMS) and energy storage converter (PCS) corresponding to the energy storage battery management system, and controlling the disconnection of the main charging and discharging circuit of the energy storage battery.
[0083] In this embodiment, upon entering an emergency state, the energy storage battery management system not only implements permission freezing and communication isolation at the software level, but also proactively triggers a physical layer security closed-loop response. By linking with local audible and visual alarm devices, it immediately issues clear visual and audible warnings to on-site maintenance personnel, ensuring immediate human intervention. Simultaneously, through a secure and reliable control channel, it sends an emergency shutdown command encrypted with a digital signature to the upper-level energy management system and the lower-level energy storage converter, forcibly halting all charging and discharging operations and driving hardware relays or solid-state switches to disconnect the battery system's main circuit, achieving ultimate protection from "logical isolation" to "physical power cutoff." This mechanism completely eliminates the risk sources of chain-reaction physical safety accidents such as overcharging, over-discharging, and thermal propagation that may result from data tampering, command injection, or malicious control, fundamentally preventing the transmission of cybersecurity incidents to battery safety. By directly binding network layer threats to battery safety, this design significantly enhances the survivability of the energy storage battery management system against advanced persistent threats (APTs) or organized attacks.
[0084] Through the above steps S102 to S106, the goal of dynamically identifying security status levels and intelligently matching differentiated protection strategies covering multiple dimensions can be achieved by using multi-dimensional monitoring data and data encryption and permission configuration data. This achieves the technical effect of intelligently upgrading security protection from passive response to active collaboration and hierarchical precise prevention and control. It also solves the technical problem in related technologies where the safety function modules of the energy storage battery management system are isolated and have static responses, resulting in a lack of dynamic linkage in protection strategies and an inability to achieve precise safety protection for energy storage batteries.
[0085] Currently, energy storage power stations, as a key component supporting new power systems, are undergoing large-scale, high-density deployment. The energy storage battery management system (BMS) of an energy storage power station, as the core control and decision-making unit of the energy storage system, is responsible for battery status monitoring, safety protection, energy management, and communication interaction. Its functional safety and information security levels directly determine the operational reliability and safety of the entire energy storage power station.
[0086] The IEC 62443 series of standards is an authoritative standard system issued by the International Electrotechnical Commission (IEC) for information security in industrial automation and control systems, and has become a universal guideline for information security construction of control systems in the industrial field. Among them, the IEC 62443-3-3 standard, "Industrial communication networks—Network and system security—Part 3-3: System security requirements and security levels," clearly stipulates core requirements for control systems, including security status management, security incident response, data flow protection, and audit traceability. For energy storage BMS products targeting the energy storage system market, especially the high-end market, achieving IEC 62443 compliance is a necessary condition for enhancing the core competitiveness of the product. However, current mainstream energy storage BMS generally suffers from the following defects in security control design: First, isolated module functions. Security function modules such as fault diagnosis, data encryption, and access control usually operate independently, lacking effective coordination mechanisms, forming "security islands." This makes it impossible to dynamically adjust based on the overall security situation. Second, static security response. When faced with security incidents such as network scanning, penetration attacks, or internal data tampering, systems often only execute preset, single protective actions (such as simply logging or triggering a single alarm), lacking the ability to adapt differentiated protection strategies based on the severity of the incident. This "one-size-fits-all" response model manifests as delayed response and insufficient targeted protection when facing advanced persistent threats or graded security incidents. Third, auditing and tracing capabilities are weak. Related technologies record fragmented and inconsistent information after security incidents, making it difficult to generate standardized compliance audit reports that cover incident details, handling processes, results, and accountability according to IEC 62443-3-3 requirements. This leads to difficulties in post-incident analysis, unclear responsibility identification, and failure to meet the mandatory traceability requirements of regulatory agencies at all levels. These problems not only hinder energy storage BMS products from passing IEC 62443 standard certification but also increase the risk of chain physical safety accidents such as battery thermal runaway and equipment damage caused by cybersecurity incidents in actual operation. Therefore, developing a safety management method for energy storage BMS that can deeply integrate the IEC62443-3-3 system status management concept, realize hierarchical quantification of safety status, cross-module linkage protection, and have the ability to generate standardized audit reports has become a key technical problem that urgently needs to be solved in this field.
[0087] Based on the above embodiments and optional embodiments, this application proposes an optional implementation method. The security protection processing method for energy storage BMS provided in this embodiment can be understood as a security status linkage control method for energy storage BMS that conforms to the IEC62443 standard. This method addresses the problems of poor module coordination, rigid protection strategies, and insufficient audit traceability in related technologies by constructing a security status hierarchical model, establishing a multi-module linkage mechanism, implementing differentiated protection strategies, and automatically generating compliance audit reports. This improves the ability of energy storage BMS to cope with complex cybersecurity threats, ensures its compliance with the IEC62443-3-3 standard, and enhances the overall operational security and reliability of the energy storage system. Figure 2 This is a flowchart of an optional safety protection method for an energy storage battery management system according to an embodiment of this application. Figure 3 This is a schematic diagram of an optional safety protection process for an energy storage battery management system according to an embodiment of this application. The method can be applied to, for example... Figure 3 In the system interaction scenario shown, such as Figure 2 As shown, the method includes:
[0088] Step S1: Definition of Safety Status Classification. Based on the framework requirements for energy storage system status management in the IEC 62443-3-3 standard, a three-level safety status classification model for energy storage BMS application scenarios is constructed. Safety status is clearly divided into normal status, early warning status, and emergency status. For each level, the status determination conditions, trigger thresholds, and priority order of protection responses are precisely defined. Details are as follows:
[0089] The normal operating condition is defined as follows: no safety anomalies were detected, and all functional modules of the energy storage BMS are operating normally. Real-time monitoring data from the fault diagnosis module are all within the preset safety baseline range, and data encryption and access control configuration data (i.e., data encryption and access control functions) are operating stably according to standard configurations.
[0090] The warning status is determined as follows: at least one minor safety anomaly indicator has been detected, such as momentary delays in non-critical data transmission or probing access to non-core ports. This type of anomaly has not yet substantially affected the integrity and real-time performance of core BMS control functions (such as battery voltage / temperature acquisition and charge / discharge control command issuance), but it indicates a potential safety risk. The fault diagnosis module reports it as a "minor anomaly" (i.e., Level 1).
[0091] An emergency state is defined as follows: a severe security event has been detected, such as a confirmed middle-party attack, non-compliant (or anomalous) tampering (or alteration) of core data (e.g., SOC / SOH thresholds, protection parameters), non-compliant replacement of critical hardware (e.g., main control chip, storage units), or failed root of trust verification. Such events pose a direct threat to the core functions of the energy storage BMS or are highly likely to trigger a system-wide safety incident (e.g., overcharging, over-discharging, thermal runaway). The fault diagnosis module reports a "Severe Anomaly" level (i.e., Level 2).
[0092] Step S2: Multi-module linkage configuration and communication establishment. Construct a star-shaped linkage architecture with the safety status management core module as the hub, integrating the fault diagnosis module, data encryption module, and access control module. Through a preset industrial control communication protocol (preferably the Module Communication Protocol (MCP) or other bus protocols supporting high real-time performance and high reliability), establish bidirectional, redundant communication links between each module and the core module, and clearly define the collaborative working modes and linkage response logic of each sub-module under different safety states. The specific configuration is as follows:
[0093] The fault diagnosis module is configured as a multi-dimensional anomaly monitoring engine, collecting and analyzing hardware self-test data, communication link status, data flow integrity (i.e., data integrity data), and network connection behavior data within the BMS in real time. It employs a combination of rule-based and anomaly behavior analysis-based detection algorithms to extract and fuse features from the collected information, identifying security event types and determining their severity level (minor / serious). The judgment results and relevant feature data are then reported to the core security status management module in real time at a set frequency (e.g., 100ms / time).
[0094] Data encryption module: Configured as a flexible encryption unit that supports switching between multiple encryption algorithms. It integrates at least two encryption algorithms of different strengths (e.g., AES-128 and AES-256) and can receive instructions from the security status management core module to dynamically apply encryption strategies of appropriate strength to the data stream in transmission and the statically stored sensitive data fields according to the current security status level.
[0095] Access Control Module: Configured as a role-based dynamic access control unit. It divides user permissions into multiple levels (e.g., administrators, operations personnel, auditors, visitors) and maintains an operation permission list for each level under different security states. This module receives status instructions from the security status control core module and dynamically activates or freezes specific operation permissions for specific roles, enabling real-time control of high-risk operations such as critical configuration modifications, firmware upgrades, and data exports.
[0096] Step S3: Real-time detection and dynamic state switching of security events. The core module for security state management, acting as the central hub of the linkage mechanism, continuously receives and parses security event reports from the fault diagnosis module. This module internally maintains a state machine, and based on the judgment conditions defined in step S1, automatically executes the state switching logic as follows:
[0097] Normal state → Warning state: When a "minor abnormality" signal is received from the fault diagnosis module, and the signal is confirmed to be valid within a preset continuous detection cycle (e.g., the preset first continuous detection cycle, 3 times in a row), the state switch is triggered.
[0098] Warning / Normal State → Emergency State: Once a "serious anomaly" signal is received from the fault diagnosis module, or an attack characteristic that matches the definition of an emergency state (such as a specific type of network attack signature) is identified, the state switch is immediately triggered, regardless of the current state.
[0099] Warning / Emergency State → Normal State: After a safety incident is effectively handled, the fault diagnosis module reports "no abnormality" within a preset continuous detection cycle (e.g., a preset second continuous detection cycle, 10 consecutive times), and after the core functions of the energy storage BMS are confirmed to be correct through self-check, it automatically or after confirmation by the administrator switches back to the normal state.
[0100] Step S4: Coordinated Execution of Differentiated Protection Strategies. Based on the currently effective security status level, the core security status management module issues unified status commands to all linked modules, triggering each module to collaboratively execute the differentiated protection strategy strictly corresponding to that level:
[0101] The protection strategy under normal conditions is as follows: Fault diagnosis module: collects monitoring data in real time at a preset base frequency and performs full-function monitoring; Data encryption module: protects regular data (such as real-time collected monitoring data) with standard strength encryption algorithms (such as the first encryption algorithm AES-128); Access control module: executes regular, role-based access control policies according to preset regular access permissions.
[0102] The protection strategy under early warning status is as follows: Fault diagnosis module: Increase the monitoring frequency of monitoring data to twice or higher than the preset baseline frequency (e.g., 50ms / time), and focus on tracking and deep packet inspection of specific links generating abnormal signals (e.g., specific communication ports or data segments); Data encryption module: Automatically increase the encryption strength to a high level (e.g., using the second encryption algorithm AES-256) for all data marked as sensitive (e.g., battery status parameters, protection settings); Access control module: Automatically restrict operation permissions, temporarily freeze all access permissions for low-privilege roles (e.g., visitors), and restrict the permissions of maintenance personnel to modify core parameters. Issue prompt warnings through the human-machine interface or alarm devices to remind maintenance personnel to intervene and investigate.
[0103] The emergency protection strategy is as follows: Fault Diagnosis Module: Immediately lock and isolate the detected abnormal physical ports or logical links, and continuously capture data snapshots and operational logs before and after the attack at the highest sampling rate as evidence for subsequent analysis; Data Encryption Module: Force the use of the highest level encryption algorithm (such as the third-level encryption algorithm AES-256) to protect all outgoing and stored data, and block all unverified abnormal data write requests. Simultaneously, back up critical system states and core data to an independent secure storage area; Access Control Module: Freeze all user operation permissions except those with the highest access privileges (such as the highest administrator privileges), allowing only administrators to execute preset emergency procedures; System-Level Linkage Response: Trigger the highest level audible and visual alarms, send emergency shutdown commands to the energy management system and energy storage converter of the energy storage system, actively disconnect the battery charging and discharging main circuit, and, if necessary, link the fire protection system to enter standby mode. Simultaneously, activate the preset emergency response process and notify relevant personnel.
[0104] Step S5: Automated generation of compliance audit reports. Throughout the entire lifecycle of security state transitions and security incident handling, all critical activities are recorded immutably through the log recording and auditing unit built into the core security state management module. Recorded content includes, but is not limited to: precise timestamps, security incident types and details, state transition trajectories, configuration changes and actions of each linked module, detailed execution of protection strategies, incident handling procedures and results, and identification of personnel involved in the handling.
[0105] Based on the structured requirements for audit logs in the IEC 62443-3-3 standard, the above-mentioned record information is automatically aggregated to generate a standardized compliance audit report. This report supports querying by multiple dimensions such as time range and event type, and can be exported to a specified common format (such as PDF). It is also stored in encrypted form locally or remotely for a long period of no less than 3 years to meet regulatory compliance and internal audit requirements.
[0106] This embodiment's method can achieve at least one of the following effects: 1) Deep compliance with the IEC 62443 standard: The system architecture and operational logic of this embodiment's method deeply align with the core requirements of the IEC 62443-3-3 standard, especially in the three key areas of system state management, security response mechanisms, and audit traceability, providing a complete engineering implementation path and helping to ensure the operational safety of energy storage BMS products. 2) Building a closed-loop proactive defense system: By establishing a security state hierarchical model and a multi-module linkage mechanism, previously isolated security function modules are coupled into an organic whole, achieving a fundamental shift from passive, static single-point defense to proactive, dynamic, and collaborative defense. This embodiment's method can adjust the protection level in real time according to the severity of the threat, minimizing the impact on the normal operation efficiency of the system while ensuring security. 3) Improving the accuracy and timeliness of responding to advanced security threats: Through multi-dimensional anomaly detection by the fault diagnosis module and real-time state machine judgment of the core module, different levels of security events, from minor probing to severe attacks, can be quickly and accurately identified. Differentiated protection strategies ensure effective containment of potential threats during early warning states and immediate implementation of the most stringent isolation and blocking measures during emergencies, minimizing security risks. 4) Enhanced traceability and auditing capabilities for security incidents: Automated, standardized compliance audit reports fully record the entire lifecycle of security incidents, resolving issues such as scattered, incomplete, and non-standardized formats in energy storage BMS security logs. This provides solid and reliable data support for post-incident review, root cause analysis, liability determination, and compliance checks by regulatory agencies. 5) Enhanced system engineering practicality and scalability: The method in this embodiment does not rely on a specific hardware platform. Its modular and configurable design allows for flexible deployment in energy storage BMS products of different sizes and architectures, exhibiting good adaptability and scalability, and fully meeting the stringent safety management requirements of the complex and ever-changing operating environment of energy storage power plants.
[0107] Based on the above embodiments and optional embodiments, this application proposes another optional implementation method for the safety protection processing of an energy storage battery management system. In this embodiment, the BMS adopts a master-slave architecture, and the master control unit has communication interfaces with the PCS, EMS, and remote monitoring platform. The method includes:
[0108] Step S01: The specific implementation of the safety status classification definition is as follows: Based on the actual operating characteristics and threat model of the energy storage power station, the safety status is divided into three levels, and the following quantitative or semi-quantitative judgment conditions are defined:
[0109] Normal operation is determined as follows: the communication cycle between the BMS master control unit and each slave control unit, PCS, and EMS is within 100ms ± 10ms, and the packet loss rate is less than 0.1%. The fault diagnosis module reports no abnormalities in hardware self-tests, data verification, and communication frame count verification. The data encryption module performs AES-128 encryption on CAN bus and Ethernet communication data, and the access control module only allows authorized users who have passed two-factor authentication (username / password and dynamic token) to operate.
[0110] The warning status is determined as follows: Condition 1 (Communication Anomaly): For three consecutive sampling cycles, a communication delay exceeding 500ms is detected between the energy storage BMS and EMS for non-real-time data (such as historical statistics), but communication with the PCS for real-time control commands is normal. Condition 2 (Access Anomaly): Within one minute, more than five failed attempts are detected from the same IP address to read non-core configuration files from the BMS's WEB service port. If either of the above conditions is met, and the fault diagnosis module, after comprehensive evaluation, deems it not to affect the BMS's core control functions over the battery pack (such as single-cell voltage / temperature acquisition, SOC / SOH calculation, and protection judgment), then the warning status is deemed to be valid.
[0111] Emergency state criteria are set as follows: Condition 1 (Network Attack): The intrusion detection signature database matches a clear middle-party attack, specifically manifested as consecutive failures of cyclic redundancy checks on key data frames communicating with the PCS (such as charging / discharging current / voltage limits), and inconsistencies are found in the content comparison. Condition 2 (Data Tampering): When comparing key battery protection parameters (such as single-cell overcharge / over-discharge voltage thresholds) in the memory with the image in the backup area, inconsistencies are found, and the hardware root of trust security boot verification report shows an abnormal hash value in the main control chip firmware.
[0112] Step S02: The specific implementation of the multi-module linkage configuration is as follows: The BMS main control unit runs a real-time operating system, wherein:
[0113] The security status management core module runs as a high-priority task, receiving reports from other modules through a message queue.
[0114] The fault diagnosis module, as an independent task, integrates the Unified Diagnostic Services (UDS) diagnostic protocol stack with a custom abnormal behavior detection algorithm. It not only monitors communication but also verifies the data integrity of Random Access Memory (RAM) / Flash Memory (Flash) through sampling.
[0115] The data encryption module is encapsulated in the communication interface driver layer, and the key length (128 bits or 256 bits) of the AES algorithm can be dynamically switched during operation via system calls.
[0116] The access control module is used to maintain an access control matrix stored in a protected flash memory area, which contains the mapping between "role-operation-status".
[0117] Inter-module communication uses the lightweight MCP protocol based on the publish / subscribe model to ensure the real-time and reliable transmission of information.
[0118] Step S03: The specific implementation of security event detection and state switching is as follows:
[0119] When the warning state condition 1 in step S01 occurs, the fault diagnosis module generates an event report containing "Warning Event: Communication Delay" and sends it to the core module. The counter inside the core module increments the count of consecutively received similar event reports. When the count reaches a preset threshold (e.g., 3 times), the state machine switches from the normal state to the warning state.
[0120] If the fault diagnosis module detects a network behavior pattern that matches the middle-party attack signature database, it immediately generates a "Critical Event: Network Attack" report with the highest priority. Upon receiving this report, the core module unconditionally switches its state machine to an emergency state and triggers a non-maskable interrupt to initiate the emergency response process.
[0121] Step S04: The specific implementation of the differentiated protection strategy is as follows:
[0122] In alert mode, the following protection strategies are implemented: Fault diagnosis module: The monitoring frequency is adjusted from 100ms / time to 50ms / time, and a high-precision timing monitor for the EMS communication link is activated. Data encryption module: After identifying specific CAN bus identifiers (CAN IDs) such as "SOC", "SOH", and "balanced state" in the data stream, the AES-256 encryption function is called to repackage and resend the data. AES-256 encryption is also used when storing newly generated historical data. Access control module: The access control matrix is updated; all operation permissions for the "guest" role are disabled, and the "write" permission for the "maintenance personnel" role to the parameter configuration page is prohibited. A yellow alarm banner pops up on the local human-machine interface (HMI), and an intermittent beeping sound is emitted.
[0123] In an emergency, the following protection strategies are implemented: Fault Diagnosis Module: Immediately close the Transmission Control Protocol (TCP) / User Datagram Protocol (UDP) ports associated with the source of the anomaly, and store the last 1000 packets received before the port closure in the isolation zone. Data Encryption Module: Force all communication links (including CAN and Ethernet) to use AES-256 encryption and send an encrypted "Emergency Shutdown" command to the PCS. Access Control Module: Deny any access attempts except by on-site operators holding the physical key and entering the highest-level administrator password. System Response: The system triggers the highest-level audible and visual alarm, and simultaneously sends a "Serious security incident, system has been shut down urgently" alarm message to the EMS and remote maintenance platform. The internal state of the energy storage BMS is recorded in a non-volatile "Security Event Log".
[0124] Step S05: The specific implementation of generating the compliance audit report is as follows: All log information generated in steps S03 and S04, including timestamps accurate to milliseconds, event IDs, source modules, event content, execution actions, operator information, etc., are written in real time to a circularly stored secure log buffer and periodically synchronized to a dedicated secure storage chip (such as an encrypted EEPROM with a serial peripheral interface (SPI)).
[0125] The audit unit provides a web-based console interface. After logging in, administrators can select filtering conditions such as time range and event level, and click the "Generate Audit Report" button. The backend service will call a structured template conforming to the audit log recording recommendations in Annex A of IEC 62443-3-3, populate relevant data, and generate a PDF report containing an event overview, detailed timeline, action chain, and information on responsible parties. The hash value of this report file is recorded to prevent tampering. The report is retained locally for at least 5 years.
[0126] Through the specific implementation steps described above, this embodiment successfully realizes the construction of a dynamic, intelligent, and IEC62443-3-3 compliant in-depth security defense system within the energy storage BMS.
[0127] This embodiment also provides a safety protection device for an energy storage battery management system. This device is used to implement the above embodiments and preferred embodiments, and details already described will not be repeated. As used below, the terms "module" and "device" can refer to a combination of software and / or hardware that performs a predetermined function. Although the device described in the following embodiments is preferably implemented in software, hardware implementation, or a combination of software and hardware, is also possible and contemplated.
[0128] According to an embodiment of this application, an apparatus embodiment for implementing the above-described safety protection method for an energy storage battery management system is also provided. Figure 4 This is a schematic diagram of the structure of a safety protection device for an energy storage battery management system according to an embodiment of this application, as shown below. Figure 4 As shown, the safety protection processing device of the above-mentioned energy storage battery management system includes: a multi-dimensional data acquisition module 400, a safety status determination module 402, and a safety protection strategy determination module 404, wherein:
[0129] The multi-dimensional data acquisition module 400 is used to acquire monitoring data of the energy storage battery management system, as well as data encryption and permission configuration data. The monitoring data includes at least the hardware self-test data, communication link status data, data integrity data, and network connection behavior data of the energy storage battery management system.
[0130] The safety status determination module 402 is connected to the multi-dimensional data acquisition module 400 and is used to determine the safety status of the energy storage battery management system based on monitoring data, as well as data encryption and permission configuration data.
[0131] The safety protection strategy determination module 404 is connected to the safety status determination module 402 and is used to determine the safety protection strategy of the energy storage battery management system according to the safety status. The safety protection strategy is used to indicate at least the data acquisition strategy of monitoring data, the data encryption strategy of specified data, and the access control strategy of the energy storage battery management system.
[0132] It should be noted that the above modules can be implemented by software or hardware. For example, for the latter, it can be implemented in the following ways: the above modules can be located in the same processor; or the above modules can be located in different processors in any combination.
[0133] It should be noted that the multi-dimensional data acquisition module 400, the security status determination module 402, and the security protection strategy determination module 404 correspond to steps S102 to S106 in the embodiments. The instances and application scenarios implemented by the above modules and their corresponding steps are the same, but they are not limited to the content disclosed in the above embodiments. It should be noted that the above modules, as part of the device, can run in a computer terminal.
[0134] It should be noted that the optional or preferred implementation methods of this embodiment can be found in the relevant descriptions in the embodiments, and will not be repeated here.
[0135] The aforementioned safety protection processing device of the energy storage battery management system may also include a processor and a memory. The aforementioned multi-dimensional data acquisition module 400, safety status determination module 402, and safety protection strategy determination module 404 are all stored in the memory as program modules, and the processor executes the aforementioned program modules stored in the memory to realize the corresponding functions.
[0136] The processor contains a core that retrieves the corresponding program modules from memory. One or more cores may be configured. Memory may include non-persistent memory in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory includes at least one memory chip.
[0137] According to an embodiment of this application, an embodiment of a non-volatile storage medium is also provided. Optionally, in this embodiment, the non-volatile storage medium includes a stored program, wherein, when the program is running, it controls the device containing the non-volatile storage medium to execute any of the aforementioned security protection processing methods of the energy storage battery management system.
[0138] Optionally, in this embodiment, the non-volatile storage medium may be located in any computer terminal in a group of computer terminals in a computer network, or in any mobile terminal in a group of mobile terminals, and the non-volatile storage medium includes stored programs.
[0139] Optionally, a program that controls the device containing the non-volatile storage medium to execute any of the above-mentioned safety protection processing steps of the energy storage battery management system during program execution.
[0140] According to an embodiment of this application, an embodiment of a processor is also provided. Optionally, in this embodiment, the processor is used to run a program, wherein the program executes any of the above-described safety protection processing methods for an energy storage battery management system.
[0141] According to an embodiment of this application, an embodiment of a computer program product is also provided, which, when executed on a data processing device, is suitable for executing a program that initializes the safety protection processing method steps of an energy storage battery management system having any of the above-described steps.
[0142] like Figure 5As shown, this application provides an electronic device 10, which includes a processor, a memory, and a program stored in the memory and executable on the processor. When the processor executes the program, it implements the safety protection processing method steps of any of the above-described energy storage battery management systems.
[0143] The order of the embodiments described above is merely for illustrative purposes and does not represent the superiority or inferiority of the embodiments.
[0144] In the above embodiments of this application, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.
[0145] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of modules described above can be a logical functional division, and in actual implementation, there may be other division methods. For example, multiple modules or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces, or indirect coupling or communication connection between modules, and may be electrical or other forms.
[0146] The modules described above as separate components may or may not be physically separate. Similarly, the components shown as modules may or may not be physical modules; they may be located in one place or distributed across multiple modules. Some or all of the modules can be selected to achieve the purpose of this embodiment, depending on actual needs.
[0147] Furthermore, the functional modules in the various embodiments of this application can be integrated into one processing module, or each module can exist physically separately, or two or more modules can be integrated into one module. The integrated modules described above can be implemented in hardware or as software functional modules.
[0148] If the aforementioned integrated modules are implemented as software functional modules and sold or used as independent products, they can be stored in a computer-readable non-volatile storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a non-volatile storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned non-volatile storage medium includes various media capable of storing program code, such as USB flash drives, read-only memory (ROM), random access memory (RAM), portable hard drives, magnetic disks, or optical disks.
[0149] The above are merely preferred embodiments of this application. It should be noted that those skilled in the art can make various improvements and modifications without departing from the principles of this application, and these improvements and modifications should also be considered within the scope of protection of this application.
Claims
1. A safety protection method for an energy storage battery management system, characterized in that, include: Acquire monitoring data from the energy storage battery management system, as well as data encryption and permission configuration data. The monitoring data includes at least the hardware self-test data, communication link status data, data integrity data, and network connection behavior data of the energy storage battery management system. Based on the monitoring data and the data encryption and permission configuration data, the safety status of the energy storage battery management system is determined. Based on the security status, a security protection strategy for the energy storage battery management system is determined, wherein the security protection strategy is at least used to indicate the data acquisition strategy for the monitoring data, the data encryption strategy for the specified data, and the access control strategy for the energy storage battery management system.
2. The method of claim 1, wherein, The process of determining the security status of the energy storage battery management system based on the monitoring data and the data encryption and permission configuration data includes: Based on the monitoring data and the data encryption and permission configuration data, detect whether the energy storage battery management system has any abnormal behavior; If no abnormal behavior is detected, the security status is determined to be a normal status; If the abnormal behavior is detected and the abnormality level of the abnormal behavior is the first level, the security status is determined to be a warning status. If the abnormal behavior is detected and the abnormality level of the abnormal behavior is level two, the security status is determined to be an emergency status.
3. The method according to claim 2, characterized in that, The method of detecting whether the energy storage battery management system exhibits abnormal behavior based on the monitoring data and the data encryption and permission configuration data includes: If the monitoring data and the data encryption and permission configuration data are both within the corresponding preset security range, it is determined that there is no abnormal behavior. If the monitoring data or the data encryption and permission configuration data are not within the corresponding preset security range, it is determined that the abnormal behavior exists.
4. The method of claim 2, wherein, The method further includes: If the abnormal behavior is a communication or access abnormality between the energy storage battery management system and the interactive terminal, the abnormality level is determined to be the first level. If the abnormal behavior is a network attack or data tampering behavior targeting the energy storage battery management system, the abnormality level is determined to be the second level.
5. The method according to claim 4, characterized in that, If the communication link status data indicates that a communication link anomaly occurs in a first consecutive number of sampling periods, or if the CRC failure frequency of a predetermined key communication frame in the data integrity data reaches a preset maximum allowable failure frequency, or if the network connection behavior data shows communication latency jitter that does not conform to a predetermined protocol specification, an increase in abnormal retransmission rate by a predetermined amount, or frequent connection requests from unauthorized protocol ports, then the abnormal behavior is determined to be the communication anomaly. Here, "frequent occurrence" refers to the number of consecutive occurrences reaching a predetermined number, or the cumulative number of occurrences within a predetermined time period reaching the predetermined number. If, based on the data encryption and permission configuration data, it is detected that an unauthorized IP address has made more than a specified number of failed access attempts to a non-core service port within a preset time window, or if the network connection behavior data shows high-frequency unauthorized port scanning behavior, unauthorized reuse of session tokens, or non-compliant credentials carried in the authentication request, or if the hardware self-test data shows abnormal access to the authentication module, failure of security startup verification, or abnormal access behavior to the key storage area, the abnormal behavior is determined to be the access abnormality. The high-frequency unauthorized port scanning behavior is used to indicate that the scanning frequency of the unauthorized port is greater than a predetermined frequency. If a network attack pattern matching a preset attack feature library is identified in the network connection behavior data, or if the hash value or digital signature verification of a preset key control instruction in the data integrity data fails, or if the communication link status data indicates that the encrypted channel is abnormally interrupted or downgraded, the abnormal behavior is determined to be the network attack behavior. The network attack pattern includes at least one of the following: session interception behavior of a middleman attack, abnormal re-encryption of communication data packets, or sequence number jump. If the preset key system parameters stored in the non-volatile memory are found to be inconsistent with the backup area mirror data or trusted hash value in the data integrity data, and the hardware self-test data does not report physical damage to the memory, or if the data encryption and permission configuration data detects the existence of non-compliant authorized parameter update records, or if the network connection behavior data contains an abnormal write instruction source, the abnormal behavior is determined to be the data tampering behavior.
6. The method according to claim 2, characterized in that, The method of detecting whether the energy storage battery management system exhibits abnormal behavior based on the monitoring data and the data encryption and permission configuration data includes: If the monitoring data or the data encryption and permission configuration data are not within the corresponding preset security range, it is determined that the abnormal behavior exists; If the monitoring data and the data encryption and permission configuration data are both within the corresponding preset security range, determine the hardware self-test anomaly score corresponding to the hardware self-test data, the communication link status anomaly score corresponding to the communication link status data, the data integrity anomaly score corresponding to the data integrity data, the network connection behavior anomaly score corresponding to the network connection behavior data, and the data encryption parameter anomaly score and access control permission anomaly score corresponding to the data encryption and permission configuration data. Determine the weight values corresponding to the hardware self-test anomaly score, the communication link status anomaly score, the data integrity anomaly score, the network connection behavior anomaly score, the data encryption parameter anomaly score, and the access control permission anomaly score. Based on the hardware self-test anomaly score, the communication link status anomaly score, the data integrity anomaly score, the network connection behavior anomaly score, the data encryption parameter anomaly score, and the access control permission anomaly score, and their respective weight values, a weighted summation operation is performed to obtain a comprehensive anomaly score. If the overall anomaly score is less than a preset score threshold, it is determined that the abnormal behavior does not exist. If the overall anomaly score is greater than or equal to the preset score threshold, the abnormal behavior is determined to exist.
7. The method of claim 6, wherein, If the preset scoring threshold includes a first scoring threshold and a second scoring threshold, and the first scoring threshold is less than the second scoring threshold, the method further includes: If the overall anomaly score is greater than or equal to the first score threshold and less than the second score threshold, the anomaly level is determined to be the first level. If the overall anomaly score is greater than or equal to the second score threshold, the anomaly level is determined to be the second level.
8. The method of claim 2, wherein, After determining the security status of the energy storage battery management system based on the monitoring data and the data encryption and permission configuration data, the method further includes: When the safe state is determined to be the normal state, the anomaly level is continuously detected for a first duration period of the first level. When the first duration reaches the preset first continuous detection period, the safety state is switched from the normal state to the warning state.
9. The method according to claim 2, characterized in that, After determining the security status of the energy storage battery management system based on the monitoring data and the data encryption and permission configuration data, the method further includes: When the security status is determined to be the warning status or the emergency status, the monitoring data is continuously detected, and the data encryption and permission configuration data are both within the corresponding preset security range for a second continuous period. When the second continuous period reaches the preset second continuous detection period, the safety status is switched from the warning status or the emergency status to the normal status.
10. The method according to claim 2, characterized in that, The step of determining the safety protection strategy of the energy storage battery management system based on the safety status includes: When the security state is the normal state, the security protection strategy is determined as follows: the monitoring data is collected according to a preset reference frequency, the specified data is encrypted using a first encryption algorithm, and multiple access objects are set with their respective access permissions to the energy storage battery management system according to preset conventional access permissions. When the security status is the warning status, the security protection strategy is determined as follows: collect the monitoring data at a specified frequency, encrypt the specified data using a second encryption algorithm, freeze the access permissions of a specified access object among the multiple access objects, the specified frequency is greater than the preset base frequency, and the encryption level of the second encryption algorithm is greater than the encryption level of the first encryption algorithm; When the security status is the emergency status, the security protection strategy is determined as follows: control the disconnection of abnormal physical ports in the specified physical ports, control the disconnection of abnormal logical links in the specified logical links, encrypt the specified data using a third encryption algorithm, and freeze the access permissions of other access objects among the multiple access objects except for the target access object. The specified physical port is a physical port associated with the monitoring data collection, the specified logical link is a logical link associated with the monitoring data collection, the encryption level of the third encryption algorithm is higher than the encryption level of the second encryption algorithm, and the target access object is the access object with the highest access permission among the multiple access objects.
11. An electronic device, characterized in that, The device includes one or more processors and a memory, the memory being used to store one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors cause the one or more processors to implement the safety protection processing method of the energy storage battery management system according to any one of claims 1 to 10.