Network Security Protection System, Method and Related Equipment for Power Batteries
By separating control instructions management and execution in the power battery network, using independent security review modules to prevent malicious attacks, the frequent attack problems in the security protection of power battery networks are solved, and the balance between security and ease of use is achieved.
Patent Information
- Application Number
- CN202510120290.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-25
- Publication Date
- 2025-08-05
- Estimated Expiration
- 2045-01-25
AI Technical Summary
In the network security protection of power batteries, there are frequent network attacks and it is difficult to effectively defend against, resulting in potential safety accident risks. Especially high-integration and highly intelligent electric vehicles and energy storage stations are easily attacked, which may cause serious consequences such as out-of-control and fire.
By separating the management and control of control instructions, the independent first computing module is used to conduct security review of the scheduling control instructions, ensuring that they are not destructive in the current environment, and are independent of the complex computing functions of the second computing module, and the separation of management and execution is achieved.
It improves the security of the power battery network, prevents security accidents caused by malicious attacks, and ensures the stability of the last line of defense, while not affecting normal operation and maintenance and system logic, reducing the cost of modification.
Smart Images

Figure CN119583217B_ABST
Abstract
Description
Technical Field
[0001] The present invention is applicable to the field of battery safety technology, and particularly relates to a network security protection system, method and related equipment for power batteries. Background Art
[0002] With the increasingly prominent world energy and environmental problems, the battery energy density and manufacturing technology level have been continuously improved, and related industries such as power batteries and electric vehicles have rapidly emerged. At the same time, as the core equipment in new energy technology, the degree of intelligence in the management, storage and use of power batteries is also constantly increasing. However, while these technologies are developing rapidly, new network security problems have been introduced. For example, compared with fuel vehicles and battery systems, new energy facilities such as highly integrated and highly intelligent electric vehicles, battery management systems and energy storage stations are more vulnerable to cyberattacks. At the same time, for ordinary information systems, after being maliciously attacked by hackers, the main losses are the availability of data and information systems, or the leakage of privacy and secrets. However, for equipment equipped with power batteries, since it is connected to a high-voltage power system and related components such as controllers and management systems are attacked, it is very likely to cause situations such as vehicle out-of-control and battery fire and explosion, which endanger people's life safety, and the consequences are very serious.
[0003] Existing technical solutions simply combine common network information system security technologies and apply them to specific energy scenarios. They still inherit the boundary protection idea of traditional security technologies and prevent cyberattack behaviors by strictly demarcating boundaries and performing access control. However, facts have proved that despite the deployment of various security protection means and equipment, due to the existence and unpredictability of various security vulnerabilities, cyberattacks still occur frequently.
[0004] Therefore, there is an urgent need for a new network security protection system, method and related equipment for power batteries to solve the above problems. Summary of the Invention
[0005] The present invention provides a network security protection system, method and related equipment for power batteries, aiming to separate the management and control of control instructions, thereby improving the network security of power batteries.
[0006] In a first aspect, the present invention provides a network security protection system for power batteries. The network security protection system is used for data transmission between an energy storage device and a cloud platform. The network security protection system includes an acquisition control module, a first calculation module, a second calculation module and a communication module; wherein,
[0007] The acquisition control module is used for acquiring the index data information of the energy storage device and sending the index data information to the first calculation module; wherein, the index data information includes battery temperature, battery voltage, battery current, battery internal resistance and insulation resistance.
[0008] The first calculation module is configured to send the received metric data information to the second calculation module, and to receive the instructions fed back by the communication module and the instructions fed back by the second calculation module, and perform a security review on the instructions fed back by each module received according to the configuration parameters corresponding to the energy storage device; wherein, the first calculation module is implemented based on an independent chip or an independent core in a multi-core processor to run an independent review program;
[0009] The second calculation module is configured to encapsulate the received metric data information and send it to the communication module; wherein, the second calculation module is implemented based on a preset operating system;
[0010] The communication module is configured to send the encapsulated metric data information to the cloud platform.
[0011] Preferably, the communication module is further configured to receive a first scheduling control instruction sent by the cloud platform according to the encapsulated metric data information, and send the first scheduling control instruction to the second calculation module.
[0012] Preferably, the second calculation module is further configured to generate a second scheduling control instruction according to the metric data information, and send the second scheduling control instruction and the received first scheduling control instruction to the first calculation module.
[0013] Preferably, the first calculation module is further configured to perform a security review on the first scheduling control instruction and the second scheduling control instruction according to the configuration parameters corresponding to the energy storage device, and determine whether there are security problems with the first scheduling control instruction and the second scheduling control instruction; if so, abort the execution of the first scheduling control instruction and / or the second scheduling control instruction; if not, send the first scheduling control instruction and the second scheduling control instruction to the acquisition control module.
[0014] Preferably, the configuration parameters include the number of batteries in the energy storage device and the battery performance parameters.
[0015] Preferably, the acquisition control module is further configured to send the received first scheduling control instruction and the second scheduling control instruction to the energy storage device.
[0016] In a second aspect, the present invention further provides a network security protection method for a power battery. The network security protection method is based on the network security protection system for a power battery according to any one of the above embodiments. The network security protection method includes the following steps:
[0017] S201. Obtain the index data information of the energy storage device through the acquisition control module; wherein, the index data information includes the battery temperature information, voltage information, and battery capacity information in the energy storage device;
[0018] S202. Generate a second scheduling control instruction according to the index data information through the second calculation module, and encapsulate the index data information to obtain encapsulated index data information;
[0019] S203. The communication module sends the encapsulated index data information to the cloud platform, and the cloud platform generates a first scheduling control instruction according to the encapsulated index data information;
[0020] S204. Perform security verification on the first scheduling control instruction and the second scheduling control instruction according to the configuration parameters corresponding to the energy storage device through the first calculation module, and determine whether there are security problems with the first scheduling control instruction and the second scheduling control instruction; if so, abort the first scheduling control instruction and / or the second scheduling control instruction; if not, send the first scheduling control instruction and the second scheduling control instruction to the energy storage device through the acquisition control module to perform corresponding operations.
[0021] Preferably, the configuration parameters include the number of batteries and battery performance parameters in the energy storage device.
[0022] In a third aspect, the present invention further provides a computer device, including: a memory, a processor, and a network security protection program for power batteries stored on the memory and executable on the processor. When the processor executes the network security protection program for power batteries, the steps in the network security protection method for power batteries as described in any one of the above embodiments are implemented.
[0023] In a fourth aspect, the present invention further provides a computer-readable storage medium, on which a network security protection program for power batteries is stored. When the network security protection program for power batteries is executed by a processor, the steps in the network security protection method for power batteries as described in any one of the above embodiments are implemented.
[0024] Compared with the prior art, the present invention conducts a security review of the scheduling control command through the first calculation module, and can reject malicious accusation commands when the cloud platform is controlled by an attacker to produce a destructive attack effect: even if the attacker has penetrated into the power battery safety system, due to the implementation of management and control separation of the first calculation module and the second calculation module, the first calculation unit module operates independently, and the attacker cannot influence it, thus ensuring the stability of the last line of defense. At the same time, the first calculation module only checks whether the control operation produces destruction in the current environment, does not perform other operations, and does not interfere with normal management and control. During normal operation and maintenance, the first calculation module is completely transparent to administrators and users, does not affect the business logic of the entire system, and has less impact on the original structure while improving security. It can largely resist intentional damage implemented by internal system personnel through the network side. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] The present invention will be described in detail below with reference to the drawings. Through the detailed description in combination with the following drawings, the above or other aspects of the present invention will become clearer and easier to understand. In the drawings:
[0026] Figure 1 is a schematic structural diagram of a network security protection system for a power battery provided by an embodiment of the present invention;
[0027] Figure 2 is a flowchart of a network security protection method for a power battery provided by an embodiment of the present invention;
[0028] Figure 3 is a schematic structural diagram of a computer device provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0029] In order to make the purpose, technical solutions and advantages of the present invention clearer and more understandable, the present invention will be further described in detail below with reference to the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.
[0030] Embodiment 1
[0031] An embodiment of the present invention provides a network security protection system 100 for a power battery. Please refer to Figure 1 , Figure 1 which is a schematic structural diagram of the network security protection system 100 for a power battery provided by an embodiment of the present invention. The network security protection system is used for data transmission between an energy storage device and a cloud platform. The network security protection system includes a collection control module 101, a first calculation module 102, a second calculation module 103, and a communication module 104; wherein,
[0032] The acquisition control module 101 is used to collect the index data information of the energy storage device and send the index data information to the first calculation module 102; wherein, the index data information includes battery parameters information such as battery temperature, battery voltage, battery current, battery internal resistance, and insulation resistance that need to be collected. Specifically, the acquisition control module 101 receives the index data information through a preset network protocol, and the preset network protocol can be correspondingly set according to the actual situation, such as the MQTT (Message Queuing Telemetry Transport) protocol, the AMQP (Advanced Message Queuing Protocol) protocol, the STOMP (Simple Text Oriented Messaging Protocol) protocol, etc. It should be noted that the above protocols are only examples, and other types of protocols are also feasible.
[0033] The first calculation module 102 is used to send the received index data information to the second calculation module 103, and is also used to receive the instructions feedback by the communication module 104 and the instructions feedback by the second calculation module 103, and conduct a security review on the instructions feedback by each module received according to the configuration parameters corresponding to the energy storage device. Among them, the first calculation module 102 is implemented based on an independent chip or an independent core in a multi-core processor to run an independent review program, and its related functions are directly implemented within chips such as FPGA, and the attack surface is very small. And the first calculation module 102 only performs security review operations to judge whether the feedback instructions and the configuration parameters corresponding to the energy storage device are destructive in the current environment, without performing other operations, and will not interfere with normal management and control. During normal operation and maintenance in daily use, the first calculation module 102 is completely transparent to administrators and users, does not affect the operation logic of the entire power battery network security protection system, and makes fewer changes to the original structure while improving security.
[0034] Specifically, the first computing module 102 is a HEM-P2P50 chip, which stores configuration parameters of various energy storage devices and can run review control algorithms to perform security verification on the received scheduling control instructions. Among them, the review control algorithms can be SOX algorithm, MPPT (Maximum Power Point Tracking) algorithm, battery balancing algorithm, etc. Other types of control algorithms are also feasible and can be correspondingly set according to the situation of the energy storage devices. Taking the SOX algorithm as an example, SOX is a set of algorithms used to describe the estimation of battery state and can be applied to electric vehicles, energy storage systems, and portable devices. It provides comprehensive monitoring and evaluation of the battery state, helps to optimize the battery usage efficiency and extend the battery life, and includes various algorithms such as SOC algorithm (State of Charge, percentage of remaining power), SOH algorithm (State of Health, battery health), SOP algorithm (State of Power, allowable charge and discharge current value of lithium battery), and SOE algorithm (State of Energy, remaining energy). These algorithms together constitute a comprehensive evaluation of the battery state.
[0035] The second computing module 103 is used to encapsulate the received metric data information and send it to the communication module 104. Specifically, the second computing module 103 is responsible for running application software that implements various functions such as network communication, task scheduling, and security management, processes the received data, and generates scheduling control instructions. Among them, the second computing module 103 is a Xinchi D9340 chip, which deploys a Linux operating system or ARM, and the operating system is reinstalled with an energy management system software to provide edge computing capabilities, so that the second scheduling control instruction can be calculated according to the metric data information of the energy storage device. Among them, the second computing module 103 is implemented based on a preset operating system, and the preset operating system can be ARM and Linux, which can implement application software with various functions such as network communication, task scheduling, and security management, and has a larger attack surface while being rich in functions.
[0036] The communication module 104 is used to send the encapsulated metric data information to the cloud platform. Specifically, the communication module 104 can send the metric data information to a centralized management system such as a centralized control center or a cloud platform through communication interfaces such as Bluetooth, wifi, Ethernet, 4G / 5G, or RS485.
[0037] In the embodiment of the present invention, the communication module 104 is further used to receive the first scheduling control instruction sent by the cloud platform according to the encapsulated metric data information and send the first scheduling control instruction to the second computing module 103.
[0038] In an embodiment of the present invention, the second computing module 103 is further configured to generate a second scheduling control instruction according to the index data information, and send the second scheduling control instruction and the received first scheduling control instruction to the first computing module 102.
[0039] In an embodiment of the present invention, the first computing module 102 is further configured to perform a security review on the first scheduling control instruction and the second scheduling control instruction according to the configuration parameters corresponding to the energy storage device, and determine whether there are security issues with the first scheduling control instruction and the second scheduling control instruction; if so, abort the execution of the first scheduling control instruction and / or the second scheduling control instruction; if not, send the first scheduling control instruction and the second scheduling control instruction to the acquisition control module 101.
[0040] Specifically, since the second computing module 103 can perform complex calculations to generate precise control commands, its attack surface is relatively large. The first computing module 102 is only responsible for performing a security review on the first scheduling control instruction and the second scheduling control instruction. The algorithm is relatively simple and does not depend on the operation of the operating system and other application software, so its attack surface is small and it is difficult to be subjected to network attacks. The network security protection system of the present invention can be implemented in the form of an energy storage station gateway, and can also be implemented in ways such as a Battery Management System (BMS) and a charging pile controller. By implementing the idea of separating management and execution through the first computing module 102 and the second computing module 103, the power battery network system is protected, so that even if the energy storage device, the charging pile or the vehicle networking system has been hacked, it is still possible to largely prevent the power battery network system from being maliciously attacked and causing dangerous situations such as fire and explosion. Even if a hacker controls internal staff through means such as social engineering and allows the internal staff to damage the power battery network system, the present invention can resist such attacks to a certain extent and achieve a balance between security and usability.
[0041] The safety issue refers to the problem that the first scheduling control instruction and the second scheduling control instruction may cause failures of the energy storage device or trigger safety accidents. Exemplarily, the first computing module 102 analyzes the first scheduling control instruction according to the configuration information corresponding to the energy storage device through the SOX algorithm, and determines that "the compliance parameter in the instruction is 0xx3 - 0xx9". However, if the parameter in the received first scheduling control instruction is 0xxA, it is determined that the first scheduling control instruction is a high-risk instruction, and the forwarding of this instruction is refused and the system administrator is warned that the system may be under attack. If the parameter in the first scheduling control instruction is 0xx4, it is determined as a normal regulation instruction, and this instruction is sent to the acquisition control module 101 to send to the energy storage device. It should be noted that both the first scheduling control instruction and the second scheduling control instruction may have safety issues. If the parameters in both scheduling control instructions are non-compliant, both are aborted. If the parameter in one scheduling control instruction is non-compliant while the parameter in the other scheduling control instruction is compliant, the scheduling control instruction with non-compliant parameter is aborted, and the other scheduling control instruction is sent.
[0042] In an embodiment of the present invention, the configuration parameters include the number of batteries and battery performance parameters in the energy storage device.
[0043] In an embodiment of the present invention, the acquisition control module 101 is further configured to send the received first scheduling control instruction and the second scheduling control instruction to the energy storage device.
[0044] Compared with the prior art, the present invention conducts a safety review of the scheduling control command through the first computing module, and can reject malicious accusation commands when the cloud platform is controlled by an attacker to produce a destructive attack effect: Even if the attacker has penetrated into the power battery safety system, due to the implementation of management and control separation of the first computing module and the second computing module, the first computing unit module operates independently, and the attacker cannot influence it, thus ensuring the stability of the last line of defense. At the same time, the first computing module only checks whether the control operation is destructive in the current environment, does not perform other operations, and does not interfere with normal management and control. During normal operation and maintenance, the first computing module is completely transparent to administrators and users, does not affect the business logic of the entire system, and has less impact on the original structure while improving security. It can largely resist intentional damage implemented by internal system personnel through the network side.
[0045] Embodiment 2
[0046] Please refer to Figure 2, the present invention also provides a network security protection method for a power battery. The network security protection method is based on the network security protection system 100 of the power battery as described in any one of the above embodiments. The network security protection method includes the following steps:
[0047] S201. Obtain the index data information of the energy storage device through the acquisition control module 101; wherein, the index data information includes the battery temperature information, voltage information, and battery capacity information in the energy storage device;
[0048] S202. Generate a second scheduling control instruction according to the index data information through the second calculation module 103, and encapsulate the index data information to obtain the encapsulated index data information.
[0049] S203. The communication module 104 sends the encapsulated index data information to the cloud platform, and the cloud platform generates a first scheduling control instruction according to the encapsulated index data information.
[0050] S204. Perform security verification on the first scheduling control instruction and the second scheduling control instruction according to the configuration parameters corresponding to the energy storage device through the first calculation module 102, and determine whether there are security problems with the first scheduling control instruction and the second scheduling control instruction; if so, abort the first scheduling control instruction and / or the second scheduling control instruction; if not, send the first scheduling control instruction and the second scheduling control instruction to the energy storage device through the acquisition control module 101 to perform corresponding operations.
[0051] In the embodiment of the present invention, the configuration parameters include the number of batteries in the energy storage device and the battery performance parameters.
[0052] Specifically, the first calculation module 102 is a HEM-P2P50 chip, which stores configuration parameters of various energy storage devices and can run review control algorithms to perform security verification on the received scheduling control instructions. Among them, the review control algorithm can be one of the SOX algorithm, MPPT (Maximum Power Point Tracking) algorithm, battery balancing algorithm, etc. Other types of control algorithms are also feasible and can be set correspondingly according to the situation of the energy storage device. Taking the SOX algorithm as an example, SOX is a set of algorithms used to describe the estimation of battery state and can be applied to electric vehicles, energy storage systems, and portable devices. It provides comprehensive monitoring and evaluation of the battery state, helps to optimize the battery usage efficiency and extend the battery life, and includes various algorithms such as the SOC algorithm (State of Charge, percentage of remaining charge), SOH algorithm (State of Health, battery health), SOP algorithm (State of Power, allowable charge and discharge current value of lithium battery), and SOE algorithm (State of Energy, remaining energy). These algorithms together constitute a comprehensive evaluation of the battery state.
[0053] The second calculation module 103 is used to encapsulate the received metric data information and send it to the communication module 104. Specifically, the second calculation module 103 is responsible for running application software that implements various functions such as network communication, task scheduling, and security management, processing the received data, and generating scheduling control instructions. Among them, the second calculation module 103 is a Xinchi D9340 chip, which deploys a Linux operating system or ARM, and the operating system is reinstalled with energy management system software to provide edge computing capabilities, so that the second scheduling control instruction can be calculated according to the metric data information of the energy storage device.
[0054] Since the second computing module 103 can perform complex calculations to generate precise control commands, its attack surface is relatively large. The first computing module 102 is only responsible for performing security reviews on the first scheduling control instruction and the second scheduling control instruction. The algorithm is relatively simple and does not depend on the operation of the operating system and other application software, so its attack surface is small and it is difficult to be subject to network attacks. The network security protection system of the present invention can be implemented in the form of an energy storage station gateway, or can also be implemented in ways such as a Battery Management System (BMS), a charging pile controller, etc. By implementing the idea of separating management and execution through the first computing module 102 and the second computing module 103, the power battery network system is protected, so that even if the energy storage device, the charging pile or the vehicle networking system has been hacked, it can still largely prevent the power battery network system from being maliciously attacked and causing dangerous situations such as fire and explosion. Even if a hacker controls internal staff through means such as social engineering and makes the internal staff damage the power battery network system, the present invention can resist such attacks to a certain extent and achieve a balance between security and usability.
[0055] The security problem refers to the problem that the first scheduling control instruction and the second scheduling control instruction may cause energy storage device failures or trigger safety accidents. Exemplarily, the first computing module 102 analyzes the first scheduling control instruction according to the configuration information corresponding to the energy storage device through the SOX algorithm, and judges that "the compliance parameter in the instruction is 0xx3 - 0xx9", but the parameter in the received first scheduling control instruction is 0xxA, then it is judged that the first scheduling control instruction is a high-risk instruction, and the instruction is refused to be forwarded and a warning is sent to the system administrator that the system may be attacked; if the parameter in the first scheduling control instruction is 0xx4, it is determined as a normal regulation instruction, and the instruction is sent to the acquisition control module 101 to send to the energy storage device. It should be noted that both the first scheduling control instruction and the second scheduling control instruction may have security problems. If the parameters in both scheduling control instructions are non-compliant, both are aborted. If the parameter in one scheduling control instruction is non-compliant and the parameter in the other scheduling control instruction is compliant, the scheduling control instruction with non-compliant parameters is aborted, and the other scheduling control instruction is sent.
[0056] The network security protection method for the power battery can implement the steps in the power battery network security protection system 100 in the above embodiments and can achieve the same technical effects. Refer to the description in the above embodiments, and details are not described herein again.
[0057] Embodiment 3
[0058] The embodiment of the present invention also provides a computer device. Please refer to Figure 3 ,Figure 3 It is a schematic structural diagram of a computer device provided by an embodiment of the present invention. The computer device 300 includes: a memory 302, a processor 301, and a network security protection program for a power battery stored on the memory 302 and operable on the processor 301.
[0059] The processor 301 calls the network security protection program for the power battery stored in the memory 302 and executes the steps in the network security protection method for the power battery provided by the embodiment of the present invention. Please refer to Figure 2 Specifically, it includes the following steps:
[0060] A network security protection method for a power battery. The network security protection method is based on the network security protection system for a power battery as described in any one of the above embodiments. The network security protection method includes the following steps:
[0061] S201. Obtain the index data information of the energy storage device through the acquisition control module 101; wherein, the index data information includes the battery temperature information, voltage information, and battery capacity information in the energy storage device;
[0062] S202. Generate a second scheduling control instruction according to the index data information through the second calculation module 103, and encapsulate the index data information to obtain encapsulated index data information;
[0063] S203. The communication module 104 sends the encapsulated index data information to the cloud platform, and the cloud platform generates a first scheduling control instruction according to the encapsulated index data information;
[0064] S204. Perform security verification on the first scheduling control instruction and the second scheduling control instruction according to the configuration parameters corresponding to the energy storage device through the first calculation module 102 to determine whether there are security problems with the first scheduling control instruction and the second scheduling control instruction; if so, abort the first scheduling control instruction and / or the second scheduling control instruction; if not, send the first scheduling control instruction and the second scheduling control instruction to the energy storage device through the acquisition control module 101 to execute corresponding operations.
[0065] The computer device 300 provided by the embodiment of the present invention can implement the steps in the network security protection method for the power battery in the above embodiment and can achieve the same technical effects. Refer to the description in the above embodiment, and details are not described herein again.
[0066] Embodiment 4
[0067] An embodiment of the present invention further provides a computer-readable storage medium, on which a network security protection program for a power battery is stored. When the network security protection program for the power battery is executed by a processor, it implements each process and step in the network security protection method for the power battery provided by the embodiment of the present invention, and can achieve the same technical effects. To avoid repetition, it will not be elaborated here.
[0068] Those of ordinary skill in the art can understand that all or part of the processes of implementing the methods in the above embodiments can be completed by instructing relevant hardware through a computer program. The program can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above methods. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only memory (ROM), or a random access memory (RAM), etc.
[0069] Embodiment Five
[0070] An embodiment of the present invention further provides an implementation scheme when the data processing algorithm has low requirements for computing power, with lower costs. Specifically, when the computing power meets the requirements, the first computing module 102 and the second computing module 103 are implemented using different computing cores in a multi-core processor. For example, the review control algorithm of the first computing module 102 (i.e., an independent review program running on an independent core in a multi-core processor) can be implemented using 1 core in the Xinchi D9340 chip in a bare system to perform security verification on the received scheduling control instructions.
[0071] The second computing module 103 can use 0 core in the Xinchi D9340 chip, which runs the Linux operating system and installs an energy management system software to provide edge computing capabilities. Thus, it can calculate the second scheduling control instruction based on the index data information of the energy storage device, and send the first scheduling instruction and the second scheduling control instruction to the first computing module 102 through inter-core communication.
[0072] It should be noted that in this article, the terms "include", "comprise" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "including a..." does not exclude the existence of additional identical elements in the process, method, article or device including that element.
[0073] Through the description of the above embodiments, those skilled in the art can clearly understand that the above-described example methods can be implemented by means of software plus a necessary general hardware platform. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation. Based on such an understanding, the technical solution of the present invention, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions for causing a terminal (which can be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in various embodiments of the present invention.
[0074] The embodiments of the present invention have been described above in conjunction with the accompanying drawings. What is disclosed is only the preferred embodiments of the present invention. However, the present invention is not limited to the above specific embodiments. The above specific embodiments are merely illustrative and not restrictive. Under the inspiration of the present invention, those of ordinary skill in the art can also make many equivalent changes in form without departing from the spirit and scope protected by the claims of the present invention, and all of them belong to the protection scope of the present invention.
Claims
1. A power battery network security protection system, characterized in that: The network security protection system is used for data transmission between the energy storage device and the cloud platform, and the network security protection system includes an acquisition control module, a first calculation module, a second calculation module and a communication module; wherein, The acquisition control module is used to collect index data information of the energy storage device and send the index data information to the first calculation module; wherein the index data information includes battery temperature, battery voltage, battery current, battery internal resistance and insulation resistance; The first computing module is configured to send the received indicator data information to the second computing module, receive instructions fed back by the communication module and instructions fed back by the second computing module, and perform a security review on the instructions fed back by each module according to the configuration parameters corresponding to the energy storage device; wherein the first computing module is implemented based on an independent review program running on an independent chip or an independent core in a multi-core processor; The second calculation module is used to encapsulate the received indicator data information and send it to the communication module; wherein the second calculation module is implemented based on a preset operating system; The communication module is used to send the packaged indicator data information to the cloud platform; The communication module is further configured to receive a first scheduling control instruction sent by the cloud platform according to the encapsulated indicator data information, and send the first scheduling control instruction to the second computing module; The second calculation module is further configured to generate a second scheduling control instruction according to the indicator data information, and send the second scheduling control instruction and the received first scheduling control instruction to the first calculation module; The first calculation module is also used to perform a security review of the first scheduling control instruction and the second scheduling control instruction based on the configuration parameters corresponding to the energy storage device, and determine whether there are security issues with the first scheduling control instruction and the second scheduling control instruction; if so, terminate the execution of the first scheduling control instruction and / or the second scheduling control instruction; if not, send the first scheduling control instruction and the second scheduling control instruction to the acquisition control module.
2. The power battery network security protection system according to claim 1, characterized in that: The configuration parameters include the number of batteries in the energy storage device and battery performance parameters.
3. The power battery network security protection system according to claim 1, characterized in that: The acquisition control module is further configured to send the received first scheduling control instruction and the second scheduling control instruction to the energy storage device.
4. A network security protection method for a power battery, the network security protection method being based on the network security protection system for a power battery according to any one of claims 1 to 3, characterized in that: The network security protection method comprises the following steps: S201. Acquire index data information of an energy storage device through the acquisition control module; wherein the index data information includes battery temperature information, voltage information, and battery capacity information in the energy storage device; S202: Generate a second scheduling control instruction according to the indicator data information by the second calculation module, and encapsulate the indicator data information to obtain encapsulated indicator data information; S203, the communication module sends the packaging index data information to the cloud platform, and the cloud platform generates a first scheduling control instruction according to the packaging index data information; S204. Perform a safety check on the first scheduling control instruction and the second scheduling control instruction according to the configuration parameters corresponding to the energy storage device through the first calculation module to determine whether there are safety issues with the first scheduling control instruction and the second scheduling control instruction; if so, terminate the first scheduling control instruction and / or the second scheduling control instruction; if not, send the first scheduling control instruction and the second scheduling control instruction to the energy storage device through the acquisition control module to perform corresponding operations.
5. The power battery network security protection method according to claim 4, characterized in that: The configuration parameters include the number of batteries in the energy storage device and battery performance parameters.
6. A computer device, characterized in that: include: A memory, a processor, and a network security protection program for a power battery stored in the memory and executable on the processor. When the processor executes the network security protection program for the power battery, the steps in the network security protection method for a power battery as described in any one of claims 4 to 5 are implemented.
7. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a network security protection program for a power battery. When the network security protection program for a power battery is executed by a processor, the steps in the network security protection method for a power battery as described in any one of claims 4-5 are implemented.
Citation Information
Patent Citations
Battery monitoring and management system and method thereof
CN117096983A
V2G charging and discharging system, control method and equipment thereof and medium
CN117485193A
Intelligent regulation and control method and system for micro-grid energy storage equipment
CN119010117A