A battery safety protection method and system
By combining high-precision voltage monitoring and bypass freewheeling circuit, faulty batteries in the battery pack are detected and disconnected in real time, and a multi-dimensional matrix is constructed for dynamic balancing. This solves the problem of discontinuous power supply in traditional battery packs during faults, and improves fast response and safety redundancy.
Patent Information
- Application Number
- CN202511349660.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-22
- Publication Date
- 2026-02-27
- Estimated Expiration
- 2045-09-22
AI Technical Summary
Traditional battery packs are prone to problems such as open circuits in individual cells, voltage imbalance, and deterioration of internal resistance during long-term operation, which leads to a decline in overall performance and makes it impossible to guarantee the continuity of power supply in emergency situations such as AC power failure.
The high-precision voltage monitoring module detects open-circuit signals in individual cells, triggering the bypass freewheeling circuit to instantly and seamlessly disconnect the faulty cell, generating a bypass command and maintaining the power output of the battery pack. Based on the bypass command, real-time data acquisition is triggered to construct a multi-dimensional matrix of battery status with timestamps. Abnormal voltage cells are identified through cluster analysis, and dynamic balancing is performed through a bidirectional energy transfer circuit. When the battery safety risk index exceeds the threshold, the system automatically switches to the core capacity discharge mode and seamlessly switches to load power supply through a diode circuit.
It enables rapid response and enhanced safety redundancy of the battery pack in case of failure, ensuring stable power supply even during a failure, and improving the reliability and safety of the system.
Smart Images

Figure CN120855227B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application belongs to the technical field of storage batteries, in particular to a storage battery safety protection method and system. BACKGROUND
[0002] With the development of new energy technology, storage battery packs are increasingly widely used in energy storage systems, electric vehicles and other fields. However, in long-term operation, the battery pack is prone to problems such as single open circuit, voltage imbalance, internal resistance degradation, etc., which leads to overall performance decline and even thermal runaway risk. Traditional protection schemes mostly use passive balancing or time delay protection strategies, which are difficult to achieve rapid fault isolation and dynamic energy regulation, especially in emergency working conditions such as alternating current power loss, the system power continuity cannot be guaranteed. SUMMARY
[0003] The purpose of the present application is to provide a storage battery safety protection method and system to solve the problems in the prior art and improve the fault response speed and safety redundancy of the storage battery pack.
[0004] One embodiment of the present application provides a storage battery safety protection method, which comprises:
[0005] The high-precision voltage monitoring module detects the single battery open circuit signal, and when an open circuit fault is identified, a bypass freewheeling circuit is triggered to seamlessly remove the faulty battery, generates a bypass instruction and maintains the continuous output of the battery pack power;
[0006] Based on the bypass instruction, real-time data acquisition is triggered, and single voltage, internal resistance, temperature and charge-discharge current data are synchronously acquired, a multi-dimensional matrix of battery state with time stamp is constructed through an anti-reverse module and a blind insertion communication interface;
[0007] The multi-dimensional matrix of battery state is input into a clustering analysis engine to identify voltage abnormal single, a bidirectional energy transfer circuit is used to discharge high-voltage single and compensate charging to low-voltage single, and a dynamic balancing instruction set is output;
[0008] Based on the dynamic balancing instruction set and the multi-dimensional matrix of battery state, the single voltage, temperature change rate and internal resistance degradation trend are input into an SOS evaluation model, a safety parameter comprehensive evaluation value is calculated, and a battery safety risk index is generated;
[0009] When the battery safety risk index exceeds the threshold value, a discharge instruction is automatically sent to a remote core capacity system, a contactor is controlled to switch the storage battery pack to a core capacity discharge mode, and when the alternating current power is lost, it is seamlessly switched to load power supply through a diode loop, a core capacity completion signal is output and the protection state is reset.
[0010] Optionally, the open-circuit signal of the single battery is detected by the high-precision voltage monitoring module, when an open-circuit fault is identified, a bypass freewheeling circuit is triggered to instantaneously and seamlessly remove the faulty battery, a bypass instruction is generated and the battery pack power continues to be output, including:
[0011] The nanosecond-level response voltage sensor is used to collect the single battery terminal voltage in real time, the voltage instantaneous drop rate is detected by the sliding window difference algorithm, and the voltage abnormal fluctuation sequence is generated;
[0012] The voltage abnormal fluctuation sequence is input into the pre-trained fault classification model, when the drop rate of three consecutive sampling periods exceeds the threshold value, it is determined as an open-circuit fault, and a fault positioning signal is output;
[0013] According to the fault positioning signal, a bypass freewheeling circuit composed of silicon carbide MOSFET is triggered, a low-impedance path is turned on within 200ns, and the connection of the faulty battery is cut off, and a bypass instruction is generated;
[0014] The super capacitor group instantaneously injects compensation current to maintain the total output power fluctuation rate of the battery pack <2%, complete seamless switching and lock the bypass state.
[0015] Optionally, the real-time data acquisition is triggered based on the bypass instruction, the single voltage, internal resistance, temperature and charge and discharge current data are synchronously acquired, the battery state multi-dimensional matrix with timestamp is constructed through the anti-reverse module and the blind insertion communication interface, including:
[0016] According to the bypass instruction, a multi-channel synchronous acquisition circuit is started to synchronously capture the original data stream containing single voltage, internal resistance, temperature and Hall current data at a sampling rate of 10kHz;
[0017] The common-mode interference is eliminated by the magnetic isolation technology of the anti-reverse module, and the original data stream is converted into a CAN bus protocol frame with CRC check;
[0018] The elastic probe matrix of the blind insertion interface is used to establish physical connection, and the absolute time label with μs level precision is added to each frame of data by the timestamp chip;
[0019] The data stream with time label is reorganized into a three-dimensional tensor according to the battery ID, and an initial state matrix is generated;
[0020] The initial state matrix is subjected to moving average filtering and missing value interpolation, and a time-aligned battery state multi-dimensional matrix is output.
[0021] Optionally, the battery state multi-dimensional matrix is input into the clustering analysis engine to identify voltage abnormal single batteries, the high-voltage single batteries are discharged and the low-voltage single batteries are compensated by the bidirectional energy transfer circuit, and a dynamic equalization instruction set is output, including:
[0022] Based on the battery state multi-dimensional matrix, a voltage-internal resistance combined feature vector is extracted, and an OPTICS clustering algorithm is used to identify outlier single cells to generate a voltage abnormal single cell set;
[0023] The Euclidean distance between the abnormal single cell and the healthy cluster center is calculated, and the overcharged high voltage single cell and the undercharged low voltage single cell are divided according to the positive and negative values of the distance, and a classification label is output;
[0024] A bidirectional LLC resonant converter is controlled to build an energy transfer channel, and the energy of the high voltage single cell is transferred to the low voltage single cell through a high frequency isolation transformer according to the classification label;
[0025] The voltage convergence rate in the transfer process is monitored in real time, and a dynamic balancing instruction set is generated when the standard deviation falls within the standard deviation threshold.
[0026] Optionally, based on the dynamic balancing instruction set and the battery state multi-dimensional matrix, the single cell voltage, temperature change rate, and internal resistance deterioration trend are input into an SOS evaluation model to calculate a safety parameter comprehensive evaluation value and generate a battery safety risk index, including:
[0027] Based on the dynamic balancing instruction set, the single cell voltage time sequence, temperature change rate, and internal resistance deterioration slope after dynamic balancing are extracted to build a safety feature vector;
[0028] The safety feature vector is input into the SOS evaluation model to calculate a thermal runaway risk probability value;
[0029] The prior distribution of the risk probability value is corrected by Bayesian network fusion of historical failure data, and a safety parameter confidence score is output;
[0030] The confidence score weight is dynamically adjusted in combination with the battery cycle life curve to generate a battery safety risk index on a 0-100 scale;
[0031] When the index is greater than 85 for 5 consecutive minutes, a three-level alarm is triggered, and the current risk parameter snapshot is locked.
[0032] Optionally, when the battery safety risk index exceeds the threshold, a discharge instruction is automatically sent to a remote nuclear containment system, a contactor is controlled to switch the battery pack to a nuclear containment discharge mode, and when the AC power is lost, it is seamlessly switched to load power supply through a diode loop, a nuclear containment completion signal is output and the protection state is reset, including:
[0033] An encrypted discharge instruction is sent to the remote nuclear containment system through the Modbus-TCP protocol, accompanied by a battery safety risk index overrun proof and a battery topology diagram;
[0034] A magnetic latching contactor is controlled to switch the battery pack to a nuclear containment bus, and a bidirectional AC / DC converter is started to maintain load voltage stability;
[0035] Real-time monitoring of AC input phase, when detecting power loss, immediately turn on the Schottky diode freewheeling circuit, realize <100us seamless switching;
[0036] After the end of the core capacity, analyze the capacity attenuation report of BMS, if the capacity recovers to 95% or more of the nominal value, output the core capacity completion signal and reset the protection flag.
[0037] Yet another embodiment of the present application provides a battery safety protection system, the system comprises:
[0038] The trigger module is used for detecting the open circuit signal of the single battery through the high-precision voltage monitoring module, and when the open circuit fault is identified, the bypass freewheeling circuit is triggered to instantaneously and seamlessly remove the fault battery, a bypass instruction is generated and the battery pack power continuous output is maintained;
[0039] The acquisition module is used for triggering real-time data acquisition based on the bypass instruction, synchronously acquiring single voltage, internal resistance, temperature and charge-discharge current data, and constructing a battery state multi-dimensional matrix with time stamp through the anti-reverse module and blind insertion communication interface;
[0040] The identification module is used for inputting the battery state multi-dimensional matrix into a clustering analysis engine to identify voltage abnormal single batteries, discharging the high-voltage single batteries and charging the low-voltage single batteries through a bidirectional energy transfer circuit, and outputting a dynamic balancing instruction set;
[0041] The input module is used for inputting single voltage, temperature change rate, internal resistance deterioration trend into a SOS evaluation model based on the dynamic balancing instruction set and the battery state multi-dimensional matrix, calculating a safety parameter comprehensive evaluation value, and generating a battery safety risk index;
[0042] The output module is used for automatically sending a discharge instruction to a remote core capacity system when the battery safety risk index is over the threshold value, controlling a contactor to switch the battery pack to a core capacity discharge mode, and seamlessly switching to load power supply through a diode circuit when AC power is lost, outputting a core capacity completion signal and resetting the protection state.
[0043] Yet another embodiment of the present application provides a storage medium, the storage medium stores a computer program, wherein the computer program is set to execute the method described in any of the above.
[0044] Yet another embodiment of the present application provides an electronic device, comprising a memory and a processor, the memory stores a computer program, and the processor is set to run the computer program to execute the method described in any of the above.
[0045] Compared with the prior art, the battery safety protection method provided by the application detects the open-circuit signal of the single battery through a high-precision voltage monitoring module, generates a bypass instruction and maintains the continuous output of the battery pack power; based on the bypass instruction, real-time data acquisition is triggered, a battery state multi-dimensional matrix with a time stamp is constructed through an anti-reverse module and a blind insertion communication interface; the battery state multi-dimensional matrix is input into a clustering analysis engine to output a dynamic balancing instruction set; based on the dynamic balancing instruction set and the battery state multi-dimensional matrix, the single voltage, temperature change rate and internal resistance deterioration trend are input into an SOS evaluation model to generate a battery safety risk index; when the battery safety risk index exceeds the threshold value, the load power supply is seamlessly switched to the load power supply through a diode loop when the alternating current is lost, an output core capacity completion signal is output and the protection state is reset, so that the fault response speed and safety redundancy of the battery pack can be improved. BRIEF DESCRIPTION OF DRAWINGS
[0046] Figure 1 A hardware structure block diagram of a computer terminal of the battery safety protection method provided by the embodiment of the application is provided.
[0047] Figure 2 A flowchart of the battery safety protection method provided by the embodiment of the application is provided.
[0048] Figure 3 A structure diagram of the battery safety protection system provided by the embodiment of the application is provided. DETAILED DESCRIPTION
[0049] The embodiments described below with reference to the drawings are exemplary and are only used to explain the application and cannot be explained as a limitation of the application.
[0050] The embodiment of the application first provides a battery safety protection method, which can be applied to electronic equipment such as a computer terminal, specifically, a general computer and the like.
[0051] The following will be described in detail by taking a computer terminal as an example. Figure 1 A hardware structure block diagram of a computer terminal of the battery safety protection method provided by the embodiment of the application is provided. As shown in the figure, Figure 1 The computer device includes a processor, a memory and a network interface connected through a system bus, wherein the memory can include a non-volatile storage medium and an internal memory.
[0052] The non-volatile storage medium can store an operating system and a computer program. The computer program includes program instructions, which, when executed, can make the processor execute any kind of battery safety protection method.
[0053] The processor is used to provide computing and control capabilities to support the operation of the entire computer device.
[0054] The internal memory provides an environment for the running of a computer program in a non-volatile storage medium, which, when executed by the processor, can enable the processor to perform any one of the battery safety protection methods.
[0055] The network interface is used for network communication, such as sending assigned tasks, etc. Those skilled in the art can understand that, Figure 1 The structure shown in the figure is only a block diagram of part of the structure related to the scheme of the present application, and does not constitute a limitation on the computer device to which the scheme of the present application is applied. The specific computer device can include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.
[0056] It should be understood that the processor can be a central processing unit (CPU), and the processor can also be other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), field programmable gate arrays (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc. Among them, the general-purpose processor can be a microprocessor or the processor can also be any conventional processor.
[0057] Referring to Figure 2 The embodiments of the present application provide a battery safety protection method, which can include the following steps:
[0058] S201, detecting the open circuit signal of the single battery through a high-precision voltage monitoring module, triggering a bypass freewheeling circuit to instantaneously and seamlessly remove the faulty battery when an open circuit fault is identified, generating a bypass instruction and maintaining the power output of the battery pack;
[0059] Specifically, a nanosecond-level response voltage sensor can be used to collect the terminal voltage of the single battery in real time, a sliding window difference algorithm can be used to detect the voltage instantaneous drop rate, and a voltage abnormal fluctuation sequence can be generated.
[0060] The system's voltage monitoring of each individual cell in the battery pack relies on the core component of the high-precision voltage monitoring module deployed on the positive and negative terminals of each cell - the nanosecond response voltage sensor. These sensors typically employ a differential amplifier chain designed based on special semiconductor materials such as gallium arsenide or high-speed silicon-based integrated circuits. Their core advantage lies in their extremely short signal response time, allowing them to capture even the slightest or drastic changes in battery voltage within extremely short time frames (e.g., nanoseconds, or one billionth of a second). The sensor integrates a low-noise, high-bandwidth preamplifier and a high-speed analog-to-digital converter (ADC) internally, with a sampling rate typically set at the megahertz (MHz) level, such as one million samples per second (1 MSPS, Mega Samples Per Second) or higher. Such high sampling speed ensures that even if the voltage suddenly changes due to extremely rapid physical changes within the battery (such as a connection break), it can still be accurately captured, without missing critical information or introducing significant measurement delays due to slow sampling speed. The sensor is connected to the battery terminals safely through a precise voltage dividing resistor network and optical or magnetic isolation devices, ensuring electrical isolation between the high-voltage battery system and the low-voltage measurement circuit, preventing common ground interference and safety hazards. The digitized voltage signal output by the sensor is transmitted in real time to the central processing unit (CPU) or dedicated fault detection logic circuit (such as FPGA, Field-Programmable Gate Array) through a high-speed, low-delay dedicated data bus (such as LVDS, Low-Voltage Differential Signaling).
[0061] The central processing unit or dedicated logic circuit receives the stream of high-speed sampled individual voltage data and immediately applies a sliding window differential algorithm for processing. The core idea of this algorithm is to dynamically and continuously analyze a small window of recent voltage data (i.e., a “window”) and calculate the voltage difference (i.e., “differential”) between adjacent sampling points or specific interval points within the window to reflect the instantaneous rate of voltage change. For example, the system sets a window containing the last twenty sampling points (assuming a sampling rate of 1 MSPS, the window time span is 20 microseconds). The algorithm calculates the difference between the last sampling point (V_now) and the second last sampling point (V_prev) (dV1 = V_now - V_prev), and possibly the difference between the second last and the third last point (dV2 = V_prev - V_prev_prev), etc. These instantaneous differential values (dV) directly reflect the amount of voltage change within a very short time interval, and by dividing by the sampling time interval (e.g., 1 microsecond), the instantaneous voltage drop rate (usually in units of volts per microsecond, V / μs) can be calculated. The algorithm continuously removes the oldest data point in the window and adds the newest data point as new sampling points arrive, and recalculates the latest differential value, thus achieving the “sliding” of the window and real-time update calculation of the voltage change rate. This sliding and calculation process is continuous, ensuring real-time monitoring of voltage dynamics.
[0062] The calculated sequence of voltage instantaneous drop rates is the key input for anomaly detection. The system maintains such a real-time drop rate data stream for each individual battery. When the voltage of a certain individual battery drops significantly at a certain sampling point, its corresponding drop rate calculation value will suddenly become a larger negative value (because the voltage is falling). The algorithm continuously monitors this drop rate value and compares it with a pre-set threshold value (Threshold). This threshold value is an empirical or theoretical value based on the battery type, the maximum expected voltage fluctuation under normal operating conditions, and the open-circuit fault characteristics to be detected (usually rapid and large voltage drop), for example, -1 volt per microsecond (-1 V / μs). Any drop rate below (i.e., more negative) this threshold value will be marked as a potential anomaly point. The algorithm outputs a sequence that records all the marked abnormal drop rate events, their timestamps and corresponding individual battery numbers, which is the voltage abnormal fluctuation sequence. This sequence not only contains the numerical value of the anomaly point, but also its context (time, individual ID), providing a raw data basis for subsequent fault classification. The entire cycle of acquisition, differential calculation, threshold comparison, and sequence generation is completed within microseconds to milliseconds, ensuring the rapidity of fault detection.
[0063] The voltage anomaly fluctuation sequence is input into a pre-trained fault classification model. When the drop rate of three consecutive sampling periods exceeds the threshold, it is determined to be an open circuit fault, and the fault positioning signal is output.
[0064] The generated voltage anomaly fluctuation sequence is immediately sent to a pre-trained fault classification model. This model is the "smart brain" of the system, responsible for distinguishing between real open circuit faults and other interference events that may cause temporary voltage fluctuations, such as instantaneous voltage drop caused by large load switching, measurement noise or local micro-short circuit inside the battery, etc. The model is usually trained based on machine learning algorithms (such as Support Vector Machine SVM, Random Forest or lightweight Neural Network). The training data comes from a large amount of historical battery operation data, laboratory simulated open circuit fault data and voltage waveform data under various normal and abnormal conditions. The key features learned by the model are the morphology, amplitude, duration, frequency of voltage drop events and possible accompanying features (such as changes in the current of the single cell, temperature changes, etc., although this step mainly relies on voltage sequence). The model is fully trained and verified before deployment to ensure high accuracy and low false alarm rate. The model is solidified in the system's embedded processor or special AI acceleration chip to achieve low-latency real-time inference.
[0065] After receiving the voltage anomaly fluctuation sequence, the fault classification model will analyze it. The model not only focuses on whether a single drop exceeds the threshold, but also on the continuity and morphology of the drop. This is the key to distinguishing between transient interference and persistent faults. The system has an important decision rule: only when the voltage drop rate of three consecutive sampling periods (i.e. three consecutive sampling points) exceeds the pre-set threshold, will the model finally determine it as an open circuit fault. This "three consecutive" requirement is a carefully designed filtering mechanism. Transient interference (such as a sampling point of sharp noise) usually only affects one sampling point, even if it causes the drop rate of that point to exceed the threshold, it will not meet the condition of three consecutive points, and thus be filtered out by the model. The voltage drop caused by a real open circuit fault (such as a broken connection or a blown fuse) is persistent, and almost certainly will detect a drop rate exceeding the threshold at multiple consecutive sampling points (far exceeding 3 points) after the fault occurs. The model analyzes the continuity of abnormal points in the sequence and checks whether the drop rate of three or more consecutive points is below the threshold. At the same time, the model may also evaluate the initial steepness of the drop (whether the slope is very negative), the voltage platform after the drop (whether it is stable at a lower voltage), etc. to further confirm whether it is an open circuit fault.
[0066] Once the fault classification model comprehensively determines that an open-circuit fault has occurred according to the rule of three consecutive sampling points exceeding the threshold value and other learned features, it will immediately generate a fault location signal. This signal is a clear digital instruction or message containing two core pieces of information: confirming an open-circuit fault and identifying the faulty cell. The signal precisely indicates which monobloc battery in the battery pack (through its unique battery identifier Battery ID) has been detected as faulty. The output of this signal is low-latency, usually within tens to hundreds of microseconds after the fault occurs (depending on the sampling rate and processing speed). The fault location signal is the basis for decision-making and the source of precise instructions for triggering subsequent protection actions (bypass freewheeling). It is quickly sent to the hardware control unit responsible for performing bypass operations through a high-speed internal communication bus (such as SPI, Serial Peripheral Interface) or parallel signal lines.
[0067] According to the fault location signal, a bypass freewheeling circuit composed of silicon carbide MOSFETs is triggered to turn on a low-impedance path within 200 ns, while cutting off the connection of the faulty battery, generating a bypass instruction;
[0068] Upon receiving the fault location signal, the system immediately activates a bypass freewheeling circuit composed of silicon carbide MOSFETs (Silicon Carbide Metal-Oxide-Semiconductor Field-Effect Transistor, SiC MOSFET) as the core component. Silicon carbide (SiC) is a wide-bandgap semiconductor material that has significant advantages over traditional silicon (Si) MOSFETs: extremely high switching speed (can complete conduction or turn-off in nanoseconds), extremely low on-state resistance (Rds_on), excellent high-temperature working ability, and higher breakdown voltage. These characteristics are crucial for achieving "instantaneous seamless" switching. The bypass circuit is usually designed to have a branch with a SiC MOSFET as the main switch in parallel across each monobloc battery. In normal state, this SiC MOSFET is in complete OFF state, presenting extremely high impedance (megaohm level), equivalent to an open circuit, without affecting the normal charging and discharging current path of the battery. The circuit design ensures that it can withstand the highest operating voltage of the battery pack and the maximum possible fault current.
[0069] Upon receiving the fault location signal, a dedicated high-speed drive circuit (e.g. a GaN FET or high-speed IC based driver) will immediately apply a strong, fast-rising drive voltage (typically 15-20V) to the gate (Gate) of the bypass SiC MOSFET corresponding to the faulty cell. Thanks to the extremely fast charge mobility of the SiC MOSFET itself and the optimized design of the drive circuit, the MOSFET can switch from a fully off state to a fully on (ON) state in a very short time (targeting 200 nanoseconds, or 0.2 microseconds) after receiving the drive signal. When on, the on-resistance (Rds_on) of the SiC MOSFET is very low (possibly only a few milliohms), creating a low-impedance path across the faulty cell. This path provides a new, extremely low-resistance alternative path for the current that was originally flowing through the faulty cell.
[0070] At the same time or almost simultaneously (design ensures the on action takes precedence) that the bypass SiC MOSFET is triggered on and the low-impedance bypass path is established, the system will disconnect the faulty cell. This is not typically done by physically removing the connection, but by controlling the protection elements in series with the faulty cell. There are two common ways to do this: 1) if the battery pack design has a controllable fuse (e.g. an eFuse) for each cell, the fuse is triggered to open; 2) if the battery itself has a safety structure (e.g. a current interrupt device, CID), the dramatic voltage drop and current interruption can also trigger its action. The core goal is to ensure that once the bypass path is established, the impedance of the faulty cell on the main current path becomes extremely high (the fuse is blown or the CID action causes a physical disconnection), forcing the current to flow through the newly established, low-impedance bypass path. At this point, the faulty cell is effectively and physically removed from the string circuit (Instantaneous and Seamless Removal). After completing this series of actions (receiving the signal, driving the MOSFET on, triggering the fuse to open), the system will generate a bypass command. This command is a status signal that informs other parts of the system (such as data acquisition, equalization control, etc.) that the specific cell has been bypassed and the system is currently in a bypass operation state. The command will also be recorded for diagnosis and status monitoring.
[0071] By injecting a compensation current from the supercapacitor pack, the total output power fluctuation of the battery pack is maintained at less than 2%, completing seamless switching and locking the bypass state.
[0072] Although the bypass circuit can remove the faulty battery and provide a current path in a very short time (200 nanoseconds), the switching process itself is not absolutely zero time. In the very short time when the SiC MOSFET starts to conduct, and in the moment when the series fuse or CID acts, the main current path will experience a very short but theoretically existing transition period of current interruption or impedance change. This may cause a small, instantaneous "dip" in the total output voltage of the battery pack (i.e. the sum of all normal single cell voltages minus the voltage before the bypass of the faulty single cell). In order to eliminate this voltage dip and maintain the absolute continuity of the load supply (i.e. the core requirement of seamless switching), the system introduces a super capacitor bank as a transient energy compensation source. The super capacitor (also known as double-layer capacitor) has extremely high power density and extremely fast charging and discharging speed (milliseconds or even faster), although its energy density is much lower than that of the battery, but it is very suitable for providing short-time high-power pulse. This super capacitor bank is usually connected to the total output end (between the positive and negative electrodes) of the battery pack and is pre-charged to a voltage close to the normal operating voltage of the battery pack.
[0073] At the same time (or slightly earlier, based on fault prediction or in conjunction with the bypass trigger signal) when the fault is detected and the bypass action is triggered, the system will control another set of high-speed switches (which may also use SiC MOSFET) connected to the output end of the super capacitor bank. These switches are immediately turned on after receiving the command, causing the pre-charged super capacitor bank to be connected in parallel to the total output end of the battery pack. The energy stored in the super capacitor bank (its voltage is slightly higher than or equal to the current output voltage of the battery pack) will inject an instantaneous compensation current pulse through a very low impedance path (also composed of high-performance MOSFET and low ESL / ESR capacitor, bus) to the load. The injected current exactly fills the small gap that may occur in the main loop current in the switching moment, supports the total output voltage, and keeps it stable during the switching process. The timing, duration and current size of the injection are calculated and adjusted in real time by a precise control circuit.
[0074] The entire switching process has minimal impact on the load end, thanks to the transient energy injection from the supercapacitor and the fast action of the bypass circuit. The system monitors the total output voltage of the battery pack in real time and calculates the power fluctuation rate within a short time window before and after the fault occurs. The calculation is as follows: measure the maximum transient drop in output voltage (Delta V) at the moment of switching, divide it by the nominal output voltage (V_nominal), and multiply by 100% to get the voltage drop percentage. Since the load is usually constant (or the change is known), this voltage drop percentage is approximately equal to the power fluctuation rate. The goal of the system control is to ensure that this fluctuation rate is strictly less than 2% (<2%). With carefully designed supercapacitor capacity, voltage, connection impedance, and precise control timing, this goal is achieved. The load device hardly perceives any power interruption or voltage fluctuation, achieving true "seamless switching". Once the switching is complete and the voltage is stable (usually within a few microseconds), the system locks the bypass state. This means that the bypass circuit remains on, the faulty battery is removed, and the system records and maintains this state until the fault is repaired and the system is manually reset. At the same time, the injection switch of the supercapacitor is closed, and the supercapacitor pack may enter a charging state, preparing for the next possible compensation. At this point, the faulty battery is safely, quickly, and seamlessly removed, and the battery pack as a whole continues to provide stable and uninterrupted power output to the load.
[0075] This step detects the voltage change of the battery cell in real time through a high-precision voltage monitoring module, identifies the open-circuit fault using a fast response algorithm, and triggers the bypass freewheeling circuit within milliseconds to ensure that the faulty battery is isolated while the overall power output of the battery pack is not affected. The bypass freewheeling circuit uses a low-impedance design combined with transient compensation from the supercapacitor to achieve seamless switching. This technology solves the problem of slow response speed and power interruption caused by fault removal in traditional battery protection systems, ensuring stable power supply of the battery pack under fault conditions and improving system reliability and safety.
[0076] S202, based on the bypass instruction, trigger real-time data acquisition, synchronously acquire single cell voltage, internal resistance, temperature and charge-discharge current data, construct a multi-dimensional matrix of battery state with time stamp through anti-reverse module and blind insertion communication interface;
[0077] Specifically, a multi-channel synchronous acquisition circuit can be started according to the bypass instruction to synchronously capture raw data streams containing single cell voltage, internal resistance, temperature and Hall current data at a sampling rate of 10 kHz;
[0078] Hardware architecture of the multi-channel synchronous acquisition circuit:
[0079] When the system receives a bypass command (BC, a control signal triggered after the faulty battery is cut off), the central control unit (CCU) immediately activates the multi-channel synchronous acquisition circuit (MSAC) embedded in the system. The circuit is composed of a high-density signal conditioning module, a multiplexing switch array, and an analog-to-digital converter (ADC) group. Each battery monomer corresponds to an independent acquisition channel, and the number of channels matches the size of the battery pack (e.g., 48 channels for 48 batteries). The signal conditioning module uses a low-temperature drift instrumentation amplifier (e.g., INA128 model) to amplify the weak monomer voltage signal (range 0-5 volts V) to the optimal range of the ADC (e.g., 0-3.3 volts V), while suppressing common-mode noise. The implementation of a 10 kHz sampling rate (i.e., 10,000 data points collected per second) relies on the parallel working mode of high-speed ADC chips (e.g., ADS8588S model): all ADCs share the same external clock source (10 megahertz MHz crystal oscillator), and the clock signal phase alignment is achieved through a precision resistance network, ensuring that the sampling time deviation of all channels is less than 10 nanoseconds ns. A Hall current sensor (e.g., ACS712 model) is connected in series in the battery pack loop, and its output voltage signal (proportionality coefficient 66 millivolts per ampere mV / A) is directly connected to a dedicated ADC channel, realizing synchronous capture of charging and discharging current.
[0080] Synchronous acquisition process of four-dimensional parameters:
[0081] Monomer voltage acquisition: contact the battery electrode through gold-plated spring probes, and input the ADC after buffering through a voltage follower.
[0082] Internal resistance measurement: use the AC injection method, generate a 1 kilohertz kHz sinusoidal excitation signal by a digital signal processor (DSP), inject it into the positive and negative electrodes of the battery through an isolation transformer, synchronize the phase difference of the response voltage and current, and calculate the real-time internal resistance value (unit milliohm mΩ) through Ohm's law.
[0083] Temperature monitoring: a patch-type NTC thermistor (e.g., MF52AT model) is attached to the battery shell, and its resistance value change is converted into a voltage signal input to the ADC by a constant-current source circuit.
[0084] Hall current data: the Hall sensor output signal is sent to the ADC after being filtered by a second-order low-pass filter (cutoff frequency 15 kilohertz kHz) to eliminate high-frequency interference.
[0085] All parameters are strictly sliced according to the time window under the CCU scheduling: every 100 microseconds (i.e. 1 / 10,000 seconds) completes a full-channel scan to generate a raw data stream (RDS) containing battery ID, voltage value, internal resistance value, temperature value, and current value. The data format is a structured binary frame.
[0086] Anti-interference and real-time protection mechanism:
[0087] To cope with electromagnetic interference in the battery pack working environment, the acquisition circuit adopts a four-layer PCB design, including an independent power supply layer and a ground layer. Key signal wiring is implemented with ground processing, and ferrite beads (such as BLM18PG model) are added to suppress high-frequency noise. The sampling timing is controlled by a hardware timer interrupt, avoiding operating system scheduling delays. Acquisition data is transmitted to a dual-port static random access memory (SRAM) through direct memory access (DMA) technology, ensuring that all channel data storage is completed within 1 millisecond (ms), providing non-blocking pipeline support for subsequent processing.
[0088] Through the magnetic isolation technology of the anti-reverse module, common-mode interference is eliminated, and the raw data stream is converted into a CAN bus protocol frame with CRC check;
[0089] Core design of magnetic isolation technology:
[0090] The anti-reverse module (AIM) is located between the acquisition circuit and the communication interface, and the core component is a multi-channel magnetic isolation chip (such as ADI's ADuM5401 model). It integrates a high-frequency transformer inside, which uses electromagnetic induction principle to transmit signals: the electrical signal of the raw data stream is converted into a magnetic flux change at the sending end, coupled to the receiving end through a micro magnetic core, and then restored to an electrical signal. This design achieves an electrical isolation strength of 3000 volts (Vrms), completely blocking the common-mode interference (CMI, i.e. interference voltage acting on all signal lines at the same time) between the battery pack and the control system. The magnetic isolation chip has a built-in refresh circuit to transmit data at a rate of 100 megabits per second (Mbps), with a delay of less than 50 nanoseconds (ns), ensuring real-time performance.
[0091] Data protocol conversion and verification mechanism:
[0092] The anti-reverse module output end is connected to a protocol conversion microcontroller (such as NXP LPC11C24 model), whose firmware performs the following operations:
[0093] Data packaging: The raw data stream is grouped by battery ID, and each frame contains the voltage (16 bits), internal resistance (16 bits), temperature (12 bits), current (16 bits), and time reference mark (32 bits) of one battery section.
[0094] CRC check generation: The cyclic redundancy check (CRC) algorithm (polynomial standard: CRC-16-CCITT) is used to perform division on all bits of the data frame, generating a 2-byte check code that is appended to the end of the frame. This check code can detect all single-bit errors and 99.99% of multi-bit errors in transmission.
[0095] CAN frame packaging: According to the Controller Area Network (CAN) protocol 2.0B standard, an extended data frame is constructed: frame header (11-bit identifier + 1-bit SRR + 1-bit IDE + 18-bit extended identifier), control field (6 bits), data field (carrying the aforementioned packaged data, up to 64 bits), CRC field (15 bits), response field (2 bits), and frame tail (7 bits). The identifier code includes the battery pack number (8 bits), data type (4 bits), and priority (3 bits).
[0096] Anti-interference enhancement measures:
[0097] The CAN bus physical layer uses twisted pair transmission, and the differential signal (CAN_H and CAN_L voltage difference represents the logic state) suppresses common-mode noise. Terminal resistors of 120 ohms are installed at both ends of the bus to match the impedance and reduce signal reflection. The anti-reverse module additionally integrates a transient voltage suppression diode (such as the SMAJ5.0A model), which can absorb up to 600 watts of surge energy and prevent damage to devices caused by electrostatic discharge (ESD) or lightning strikes. After this processing, the raw data stream is converted into a CAN Protocol Frame with CRC (CPF-CRC) that has strong anti-interference ability, and is transmitted to the communication interface through an isolation barrier.
[0098] The flexible probe matrix of the blind plug interface is used to establish physical connection, and the timestamp chip is used to add absolute time labels with μs-level precision to each frame of data.
[0099] Mechanical and electrical design of blind plug interface:
[0100] The blind plug interface (Blind-Mate Connector, BMC) adopts a floating centering structure and is composed of two parts:
[0101] Socket end: fixed on the Battery Management System (BMS) case, contains spring-loaded gold-plated copper alloy probes (0.8 mm in diameter), probe stroke 1.5 mm, rated contact resistance less than 20 mΩ.
[0102] Plug end: integrated into the battery module plug-in unit, corresponding position is a copper foil pad (0.2 mm thick), surface plated with nickel gold to prevent oxidation.
[0103] When the plug approaches the socket, the conical guide groove automatically corrects the position deviation of ±2 mm, and the probe is compressed and maintains a contact force of 1 N after being pressed. The Elastic Probe Matrix (EPM) is arranged in an 8x6 grid, with 32 pins for data transmission and 16 pins for redundancy backup to ensure that communication can still be maintained even if any 3 pins fail.
[0104] High-precision timestamp generation and binding:
[0105] The time reference is provided by a timestamp chip (such as Maxim DS3231M model) driven by a Temperature-Compensated Crystal Oscillator (TCXO, accuracy ±0.5 parts per million ppm). The chip has a built-in Real-Time Clock (RTC) and leap year compensation algorithm, calibrated through the International Atomic Time (TAI) synchronization protocol (such as PTPv2), with an annual time drift of less than 2 minutes. When the CAN frame arrives at the BMS main control board through the blind plug interface:
[0106] The timestamp chip triggers an interrupt at the falling edge of the Start-of-Frame (SOF).
[0107] A 32-bit counter captures the current absolute time (format: 28 bits for seconds + 20 bits for microseconds, overflow period 136 years).
[0108] The time tag is bound to the extended identifier of the corresponding CAN frame, written to the reserved bits (the lower 4 bits of 6 bits for timestamp index) in the frame control field.
[0109] This process is delayed to stabilize within 1.2 microseconds (μs), achieving the addition of Absolute Time Tag (ATT) with μs-level precision (i.e., one-millionth of a second precision).
[0110] Fault tolerance and synchronization mechanism:
[0111] The probe surface of the blind-mate interface is coated with conductive lubricant (e.g., NYE 758G model) to inhibit fretting corrosion. The plug-in and pull-out life test is more than 10,000 times. The time-stamping system sets a redundant channel: the main and standby TCXOs compare the outputs through a phase detection circuit (e.g., AD9901 model), and automatically switch the clock source when the deviation exceeds 200 nanoseconds (ns). All BMS nodes periodically broadcast time synchronization messages (period 1 second (s)) through the CAN bus, and the main node corrects the clock of the slave nodes to ensure that the time deviation of the entire system is less than 10 microseconds (μs).
[0112] The time-labeled data stream is reorganized into a three-dimensional tensor according to the battery ID to generate an initial state matrix; the initial state matrix is subjected to moving average filtering and missing value interpolation to output a time-aligned battery state multi-dimensional matrix.
[0113] Three-dimensional tensor reorganization and matrix generation:
[0114] After the time-labeled CAN frame is parsed by the CAN controller (e.g., MCP2515 model), the data is sent to the reorganization engine (implemented based on Field-Programmable Gate Array (FPGA)). The reorganization rules are as follows:
[0115] First dimension (row): battery monomer ID (number 1 to N, N is the total number of batteries);
[0116] Second dimension (column): parameter type (voltage, internal resistance, temperature, current, a total of 4 columns);
[0117] Third dimension (layer): time sequence (arranged in ascending order according to the time label, with a layer interval of 100 microseconds (μs)).
[0118] For example, the three-dimensional tensor generated by a 48-battery pack in 1 second has a size of 48x4x10,000. The initial state matrix (ISM) is the memory storage form of this tensor, and a row-first storage strategy is adopted: each row stores the four-parameter values of a single battery at consecutive time points, and the total data volume = 48x4x10,000x2 bytes = 3.84 megabytes (MB) (assuming 16 bits per parameter).
[0119] Moving average filtering denoising processing:
[0120] For high-frequency noise (such as voltage measurement white noise) in the initial state matrix, a moving average filter (MAF) algorithm is used:
[0121] The time window width is set to 100 sampling points (corresponding to a 10-millisecond (ms) duration).
[0122] For each parameter of each battery, the time series is calculated independently: New filter value = Old filter value × 0.99 + New sample value × 0.01.
[0123] Boundary processing: the beginning of the data is filled with backward padding method to complete the window.
[0124] This first-order Infinite Impulse Response (IIR) filter is implemented in parallel in FPGA, and the filtering operation of 48 battery nodes takes less than 5 microseconds (μs). After processing, the peak-to-peak noise of the voltage signal is reduced from the original 50 millivolts (mV) to less than 5 mV.
[0125] Missing value interpolation and time alignment:
[0126] Missing values (MV) caused by communication packet loss or sampling failure are processed in two steps:
[0127] Neighboring interpolation: when the consecutive missing points are no more than 3, the missing value is filled by linear interpolation of the previous and next valid data (e.g., Value_t = (Value_{t-1} + Value_{t+1}) / 2).
[0128] Model prediction: when the consecutive missing points exceed 3, an Autoregressive Integrated Moving Average (ARIMA) model (order p=2, d=1, q=1) is started to predict the missing values based on the previous 1000 points of historical data.
[0129] Time alignment (TA) is achieved through resampling: based on a 100-microsecond (μs) reference interval, the filtered data cube is subjected to three times of spline interpolation to eliminate residual time deviations between channels. The final output Battery State Multidimensional Matrix (BSMM) meets the following standards: data integrity rate ≥ 99.99%; time synchronization error ≤ 1 μs; noise suppression ratio ≥ 40 decibels (dB).
[0130] This matrix serves as the standardized input for subsequent clustering analysis and safety evaluation, and is stored in Non-Volatile Memory (NAND Flash) and uploaded to the cloud database for backup.
[0131] After the bypass instruction is triggered, the system immediately starts multi-channel synchronous data acquisition, accurately measures the voltage, internal resistance, temperature and current of the single battery, and suppresses interference signals through the anti-reverse module to ensure data accuracy. The blind insertion interface provides reliable connection, and the timestamp chip adds accurate time label to the data, finally forming a structured battery state matrix. This step realizes comprehensive monitoring of the battery state and standardization of the data, providing high-precision data basis for subsequent fault analysis and balancing control, and avoiding misjudgment caused by different data or interference.
[0132] S203, input the battery state multi-dimensional matrix into the clustering analysis engine to identify voltage abnormal single bodies, discharge the high-voltage single bodies and compensate the low-voltage single bodies through the bidirectional energy transfer circuit, and output a dynamic balancing instruction set;
[0133] Specifically, a voltage-internal resistance joint feature vector can be extracted based on the battery state multi-dimensional matrix, an outlying single body is identified through an OPTICS clustering algorithm, and a voltage abnormal single body set is generated;
[0134] The Battery State Multidimensional Matrix is a standardized data structure containing all the parameters of each monobloc cell at a specific time slice, such as voltage, internal resistance, temperature, etc. The system first extracts the Voltage-Internal Resistance Joint Feature Vector from this matrix. Each monobloc cell's feature vector is composed of two core dimensions: the real-time collected terminal voltage value (unit: Volt V) and the dynamic internal resistance value measured by the AC injection method (unit: milli-Ohm mΩ). For example, the feature vector of a certain monobloc cell at timestamp T1 can be represented as (3.25V, 15.8mΩ). The extraction process is completed by a dedicated hardware accelerator, which generates the feature vector set at a rate of over 1000 monobloc cells per second. These vectors are input into the Clustering Analysis Engine, which uses the OPTICS clustering algorithm (Ordering Points To Identify the Clustering Structure). The OPTICS algorithm does not require a pre-set number of clusters and is particularly suitable for the natural grouping characteristics of monobloc cell states in a battery pack. The algorithm first calculates the Core Distance of each monobloc cell feature vector to its k-nearest neighbors (for example, k = 5), then calculates the Reachability Distance, and finally generates a Reachability Plot of all monobloc cells sorted by density reachability. The system automatically identifies outlier cells located in sparse areas by analyzing the "valley" and "peak" patterns in the reachability plot. For example, if the reachability distance of a certain monobloc cell is significantly higher than twice the standard deviation of the mean of adjacent monobloc cells, it is determined to be an outlier.
[0135] The outlier detection of the OPTICS algorithm has dynamic adaptability. The system presets the Reachability Distance Threshold (RDT) as 1.8 times the peak value of the historical health cell reachability distance. When the battery pack ages or the ambient temperature changes, the algorithm dynamically updates the RDT reference value through a sliding window (such as the last 24 hours of data) to avoid false positives. For example, in a low-temperature environment, the internal resistance of the healthy cell generally rises, and at this time the RDT will automatically increase to 2.1 times the historical average. The clustering engine performs secondary verification on the outlier cell: check whether the cell is continuously marked as an outlier in three consecutive time slices (100 milliseconds apart). If verified, it is added to the voltage anomaly cell set. At the same time, the engine records the anomaly type preliminary flag: if the cell voltage is higher than the cluster center value and the internal resistance is normal, it is marked as "suspected overcharge"; if the voltage is lower than the cluster center value and the internal resistance is high, it is marked as "suspected undercharge". The set is transmitted to the balancing control unit through a data packet with a check code to ensure data integrity.
[0136] To improve the robustness of clustering, the system introduces a multi-dimensional weight adaptive mechanism. The initial voltage dimension weight is set to 0.7, and the internal resistance dimension weight is 0.3. When the ambient temperature is detected to be above 40 degrees Celsius, the influence of internal resistance on battery state increases, and the system automatically increases the internal resistance weight to 0.5. At the same time, if a cell is frequently marked as abnormal in historical data (such as more than 10 times in 1 hour), its reachability distance calculation in the new round of clustering will be penalized by a factor of 1.2, reducing the false positive rate. The feature vector of all outlier cells and the cluster center coordinates of the healthy cluster they belong to are stored in the anomaly database for subsequent risk modeling. For example, the healthy cluster center may be located at (3.30V, 12.5mΩ), and the coordinates of a certain abnormal cell are (3.15V, 18.3mΩ), and the degree of deviation will be quantitatively recorded.
[0137] Calculate the Euclidean distance between the abnormal cell and the healthy cluster center, divide the overcharged high-voltage cell and the undercharged low-voltage cell according to the distance positive and negative value, and output the classification label;
[0138] For each cell in the voltage anomaly cell set, the system calculates the Euclidean distance between it and the corresponding healthy cluster center. The distance formula is simplified to a two-dimensional space calculation: if the cell feature vector is (Vx, Rx) and the healthy cluster center is (Vc, Rc), then the Euclidean distance ED = √[(Vx - Vc) 2 + (Rx - Rc) 2]The calculation result is mixed with units of millivolts (mV) and milliohms (mΩ) and needs to be normalized. For example, the ED value of a single cell is 125 (normalized unit), and the system presets the distance partition threshold (DPT) as 80 units: if ED ≥ DPT, it is confirmed as an effective abnormal single cell; if ED < DPT, it is considered as a slight deviation and only recorded without performing balancing.
[0139] The key classification basis is the positive and negative of the voltage sub-distance (VSD). VSD = Vx - Vc (unit: millivolts mV). If VSD > +20mV (preset high voltage threshold), it is marked as an overcharged high-voltage cell; if VSD < -20mV (preset low voltage threshold), it is marked as an undercharged low-voltage cell. For example, the VSD of a certain single cell is +35mV, and the classification label is "H"; another single cell has a VSD of -28mV, and the label is "L". The system hysteresis processes the boundary value: when VSD is in the range of -15mV to +15mV, it is not classified, and the next clustering result is confirmed. All classification results are packaged as classification label data packets, including cell ID, label type (H / L), Euclidean distance value, and timestamp.
[0140] The classification process introduces a historical state tracing mechanism. If a certain single cell is classified as "H" for three consecutive times, but this time it is "L", the system will trigger a diagnosis process: check if the voltage acquisition channel is abnormal or the internal resistance is suddenly changed. At the same time, the "H" type single cell is additionally calculated for voltage deviation contribution rate (VDCR), the formula is: VDCR = |VSD| / Σ|VSD_all|. If the VDCR of a certain single cell is > 30%, it indicates that it is the main source of voltage imbalance and needs to be prioritized in subsequent balancing. The classification label and VDCR value are output to the energy transfer control unit to provide priority basis for balancing strategy.
[0141] The control bidirectional LLC resonant converter constructs the energy transfer channel, and the energy of high-voltage single cells is transferred to low-voltage single cells through high-frequency isolation transformer according to the classification label;
[0142] According to the classification label, the system activates the bidirectional energy transfer circuit. The core of the circuit is a modular unit composed of bidirectional LLC resonant converters. Each converter corresponds to a group of "H-L" single cell pairs (for example, one high-voltage single cell transfers energy to one low-voltage single cell). The converter adopts a half-bridge architecture, including two silicon carbide MOSFET switches (with a switching frequency of 100 kHz), resonant inductance (Lr=22μH), resonant capacitance (Cr=68nF), and excitation inductance (Lm=110μH). When the control signal drives the high-voltage side switch, energy flows from the "H" single cell to the resonant cavity; conversely, when the low-voltage side switch is driven, energy flows from the resonant cavity to the "L" single cell. A high-frequency isolation transformer (High-Frequency Isolation Transformer, with a ratio of 1:1) achieves electrical isolation, and the magnetic core uses ferrite material, with a working magnetic flux density controlled below 0.3T to prevent saturation.
[0143] The energy transfer process adopts adaptive phase-shift control. The system monitors the voltage difference ΔV (unit: volts V) between the paired single cells in real time. According to the size of ΔV, the phase-shift angle (PSA) of the LLC converter is dynamically adjusted:
[0144] If ΔV > 0.5V, set PSA=180 degrees to achieve maximum power transmission (for example, 300W);
[0145] If 0.1V < ΔV ≤ 0.5V, set PSA = 120 × (ΔV / 0.5) degrees, and the power is linearly adjusted with ΔV;
[0146] If ΔV ≤ 0.1V, suspend the transfer to avoid energy backflow.
[0147] At the same time, the zero voltage switching (ZVS) technology ensures that the switch is turned on at the voltage zero point, reducing the loss to below 3%. For example, when the "H" single cell (3.38V) transfers energy to the "L" single cell (3.15V), ΔV=0.23V, the system automatically sets PSA=55 degrees, and the transmission power is about 140W.
[0148] To cope with the demand of multiple parallel transfer, the system adopts Time-Division Multiple Access Scheduling. The 1-second balancing period is divided into 20 time slots (50 ms per time slot), and the time slots are preferentially allocated to the "H-L" pairs with high VDCR values. In each time slot, the LLC converter performs a complete energy transfer cycle: the first 5 ms soft start to establish resonance, 40 ms full power transmission, and the last 5 ms soft shutdown. The transfer process is monitored by a Hall current sensor in real time to monitor the actual transfer capacity (unit: milliampere-hour mAh), and compared with the theoretical value. If the deviation exceeds 5%, automatically adjust the PSA value of the next time slot to compensate. All operations are controlled by FPGA (Field Programmable Gate Array) hard real-time, ensuring timing accuracy to 1 microsecond level.
[0149] The voltage convergence rate during the transfer process is monitored in real time, and a dynamic balancing instruction set is generated when the standard deviation falls within the standard deviation threshold.
[0150] During the balancing process, the system samples the voltage values of all participating transfer monomers at a frequency of 100 Hz, calculates the voltage standard deviation (Voltage Standard Deviation, VSD) of the entire battery group. The initial VSD is denoted as σ0 (for example, σ0=35mV). The voltage convergence rate (Convergence Rate, CR) is calculated every 10 seconds, and the formula is: CR = (σ t - σ t+10 ) / 10, unit: millivolt per second (mV / s). At the same time, the convergence rate threshold (Convergence Rate Threshold, CRT=2mV / s) is preset: if CR < CRT for three consecutive times, it is determined that the convergence is too slow, and the LLC converter power level is automatically increased by 10%.
[0151] The system dynamically sets the standard deviation threshold (Standard Deviation Threshold, SDT). SDT = max(baseline threshold, temperature compensation term):
[0152] The baseline threshold is fixed at 8mV (set according to the battery pack consistency specification);
[0153] Temperature compensation term = 0.2 × |T_avg - 25| (T_avg is the average temperature of the battery pack, unit: ℃).
[0154] For example, when T_avg = 40℃, SDT = max(8, 0.2x15) = 8mV; when T_avg = 0℃, SDT = max(8, 0.2x25) = 10mV. Real-time monitoring of the current VSD value, when VSD ≤ SDT and the duration exceeds 30 seconds, the balance is determined to be up to standard.
[0155] The generated dynamic equalization instruction set includes three types of instructions:
[0156] Termination Command: Stop all LLC converter work, disconnect the energy transfer channel;
[0157] Status Logging Command: Record the equalization duration, total transferred energy, and final VSD value;
[0158] Parameter Update Command: Adjust the outlier threshold of the OPTICS algorithm according to the equalization effect (for example, if multiple monomers need to be balanced, reduce the RDT by 5% next time).
[0159] The instruction set is issued to each execution unit through a secure encryption channel and is accompanied by a digital signature verification. At the same time, the system enters the equalization monitoring mode: if VSD exceeds 1.2 times of SDT within 1 hour, a new round of fast equalization is automatically triggered without clustering analysis and directly reusing the last classification label.
[0160] The clustering analysis engine intelligently classifies battery state data, identifies voltage abnormal monomers, and uses a bidirectional energy transfer circuit to transfer energy between batteries, making high-voltage monomers discharge and low-voltage monomers charge, achieving dynamic equalization. The equalization process monitors the voltage convergence in real time to ensure the equalization effect. This technology effectively solves the capacity degradation problem of battery packs caused by monomer differences, prolongs the battery life, improves energy utilization, and avoids overcharging or overdischarging risks.
[0161] S204, based on the dynamic equalization instruction set and the battery state multi-dimensional matrix, inputting the monomer voltage, temperature change rate, and internal resistance deterioration trend into the SOS evaluation model, calculating the safety parameter comprehensive evaluation value, and generating the battery safety risk index;
[0162] Specifically, based on the dynamic equalization instruction set, the monomer voltage time sequence, temperature change rate, and internal resistance deterioration slope after dynamic equalization can be extracted to construct a safety feature vector;
[0163] When the dynamic balancing instruction set takes effect, the system immediately starts the security feature extraction engine. The engine first parses the list of battery cell numbers that have performed balancing operations included in the instruction set (such as Batt_ID: 5, 12, 23), and locks the latest data blocks of these cells in the battery state multi-dimensional matrix. For the cell voltage time series (CVTS), the engine extracts the voltage raw data stream within the last 60 seconds with a sampling rate of 10 milliseconds (i.e., 100 points per second) from the matrix. For example, for cell number 5, 6000 voltage values (unit: millivolts) from timestamp T-60s to T0 (current time) are extracted, the voltage change amount (ΔV) of adjacent sampling points is calculated by first-order difference, and the voltage fluctuation standard deviation (VF_STD) is calculated with a 1-second window to generate a key indicator reflecting voltage stability.
[0164] The extraction of temperature change rate (TCR) requires the combination of multi-source data:
[0165] Real-time temperature value: Read the temperature of the NTC thermistor deployed on the surface of each cell from the battery state multi-dimensional matrix (unit: Celsius), with a sampling rate of 10Hz.
[0166] Historical temperature trend: Backtrack the temperature data of the cell for the past 5 minutes, and calculate the temperature rise slope per minute (unit: ℃ / min) by linear fitting.
[0167] Transient change detection: Calculate the absolute value of the difference between the current temperature and the data 1 second and 10 seconds ago (|ΔT|), and if |ΔT| exceeds 0.5℃ / s for 3 consecutive times, it is marked as an "abnormal temperature rise event". Finally, integrate into three sub-features: average temperature rise rate (Avg_TCR), maximum temperature rise rate (Max_TCR), and abnormal temperature rise count (Abnormal_TCR_Count).
[0168] The construction of internal resistance degradation slope (IRDS) depends on long-term tracking:
[0169] Baseline internal resistance: Retrieve the direct current internal resistance value (unit: milliohms) of the cell under the last full charge state (SOC=100%) as the baseline point (Baseline_R).
[0170] Current internal resistance: Based on the real-time internal resistance measurement value (obtained by 1kHz AC injection method) in the battery state multi-dimensional matrix, recorded as Current_R.
[0171] Degradation Calculation: Calculate the deviation rate of current internal resistance from baseline internal resistance (R_Deviation = (Current_R- Baseline_R) / Baseline_R × 100%).
[0172] Trend Analysis: Combine the historical internal resistance data of the past 30 days, and fit the daily average internal resistance change curve by least squares method, output the degradation slope (unit: % per day). The final generated security feature vector (Security Feature Vector, SFV) contains 12-dimensional data, for example:
[0173] [VF_STD=3.2mV, Avg_TCR=0.08℃ / min, Max_TCR=0.35℃ / min, Abnormal_TCR_Count=1, R_Deviation=12.7%, IRDS=0.15% / day].
[0174] Input the security feature vector into the SOS evaluation model to calculate the thermal runaway risk probability value;
[0175] The SOS evaluation model (State Of Safety Assessment Model) adopts a three-layer hybrid architecture:
[0176] Input layer: Receive the security feature vector (SFV), while dynamically injecting four auxiliary parameters:
[0177] SOC (State of Charge): Read the real-time charge and discharge electric quantity integral value from the coulomb counting chip (precision ±1%).
[0178] SOH (State of Health): Calculate based on the capacity attenuation model (current maximum capacity / initial nominal capacity × 100%).
[0179] R and ΔR: Real-time internal resistance value (R) and its recent 1-minute change (ΔR).
[0180] T and ΔT: Real-time temperature value (T) and its recent 10-second change (ΔT).
[0181] For example, the input data set is: SOC=85%, SOH=78%, R=25.3mΩ, ΔR=+0.4mΩ, T=41.2℃, ΔT=+1.8℃.
[0182] Model core calculation process:
[0183] Feature Fusion: Merge SFV and auxiliary parameters into an 18-dimensional input tensor with weights, where temperature-related features account for 40% of the weight.
[0184] Risk Probability Calculation:
[0185] Using a Random Forest Classifier to predict risk levels: input the input tensor into 200 decision trees, each tree independently judges based on feature thresholds (such as "if T>45℃ and ΔT>2℃ / min, then vote high risk"), and finally generate an initial risk probability (range 0-1) by majority voting.
[0186] LSTM Time Series Analysis: For voltage time series data (CVTS), use Long Short-Term Memory to detect hidden voltage drop patterns (such as a drop of more than 50mV within 0.5 seconds may indicate a micro-short circuit).
[0187] Probability Fusion: Weighted average of Random Forest output probability (P_RF) and LSTM anomaly score (0-1) to get Thermal Runaway Risk Probability (TRRP). For example: TRRP = 0.7×P_RF +0.3×LSTM_Score.
[0188] Quantitative output of Safety Status (SOS):
[0189] Hierarchical Mapping: Convert TRRP to SOS level (0-5 levels):
[0190] Level 0 (TRRP<0.05): Safe;
[0191] Level 3 (0.05≤TRRP<0.3): Warning;
[0192] Level 5 (TRRP≥0.3): High risk.
[0193] Dynamic Compensation: If the monomer is in a high SOC (>90%) and high temperature (>40℃) environment, TRRP is automatically multiplied by a factor of 1.2 (strengthening the weight of the risk of overheating). Final output example: TRRP of monomer 12 = 0.28 → SOS level = 4 (high risk).
[0194] Through Bayesian network fusion of historical failure data, correct the prior distribution of risk probability value, and output safety parameter confidence score;
[0195] Build Bayesian Correction Network (BCN):
[0196] Historical Database: Access the past 2 years of battery pack failure cases database, each record contains: failure type (e.g. thermal runaway, overcharge), SFV data 5 minutes before failure, environmental parameters (humidity, altitude).
[0197] Prior Probability Calculation: For the current cell characteristics (e.g. Avg_TCR=0.15℃ / min in SFV), retrieve the actual failure rate under similar characteristics in the historical database. For example: under the condition of "Avg_TCR>0.1℃ / min and SOH<80%", the historical failure rate (Prior Probability) is 18.3%.
[0198] Probability Correction Process:
[0199] Likelihood Estimation: Calculate the matching degree (Likelihood) of the current TRRP with historical failure cases. For example:
[0200] Current TRRP=0.28 (output by SOS model);
[0201] In historical cases, when TRRP is in the interval of 0.25-0.3, the actual proportion of thermal runaway is 73% (Likelihood=0.73).
[0202] Bayesian Inference:
[0203] Apply Bayesian formula: Posterior Probability = (Likelihood × Prior Probability) / Normalization Factor. Fuse the prior probability of 18.3% with the likelihood of 73% to output the corrected risk probability (Posterior Probability). For example: the corrected probability rises to 32.5%.
[0204] Confidence Score Generation:
[0205] Confidence Factor: Calculate according to data integrity and timeliness:
[0206] If the resistance data is missing for more than 2 sampling times, the confidence factor (Confidence Factor, CF) is reduced to 0.7;
[0207] If the temperature data is the current real-time value (<1 second delay), CF is increased to 1.0.
[0208] Score Output: Multiply the corrected probability (32.5%) by the confidence factor (e.g. 0.9) to generate the Security Confidence Score (SCS), ranging from 0 to 100 points. For example: SCS = 32.5% × 100 ×0.9 = 29.25 points.
[0209] Adjust the confidence score weight dynamically combined with the battery cycle life curve to generate a battery safety risk index on a 0-100 scale;
[0210] Cycle life curve integration:
[0211] Lifetime model retrieval: Read the cycle life degradation curve of the monomer battery from the BMS (Battery Management System), which is established through accelerated aging experiments. The horizontal axis is the cycle count, and the vertical axis is the capacity retention. For example: the capacity retention is 82% at 500 cycles.
[0212] Lifetime stage division:
[0213] Define three key stages:
[0214] Adolescence (cycle <300 times): high risk tolerance, confidence weight (Life Weight, LW) set to 0.8;
[0215] Middle age (300-600 times): LW=1.0;
[0216] Decline (>600 times): LW=1.2 (amplify risk weight).
[0217] Dynamic weight adjustment strategy:
[0218] Real-time cycle number acquisition: Through BMS cumulative charge and discharge Ah-throughput, the current cycle number (Current_Cycle) is converted. For example: the monomer has experienced 428 equivalent cycles.
[0219] Weight calculation:
[0220] If Current_Cycle=428 times (middle age), the basic weight LW=1.0;
[0221] If the capacity retention rate is less than 80%, add a weight coefficient of 0.2;
[0222] Final weight (Final_Weight) = LW×(1 + additional coefficient) = 1.0×1.2=1.2.
[0223] Battery safety risk index generation:
[0224] Index calculation: Multiply the safety parameter confidence score (SCS) by the final weight (Final_Weight), and then map it to a 0-100 scale:
[0225] Risk Index (RI) = min(100, SCS × Final_Weight × 100); for example: SCS = 29.25 points × Final_Weight = 1.2 → 35.1 → rounded to 35 points.
[0226] Threshold linkage: when RI > 85, automatically trigger level 3 alarm (the highest level), and store the current snapshot of all parameters to the fault analysis black box.
[0227] Trigger level 3 alarm when the index is > 85 for 5 consecutive minutes, and lock the current risk parameter snapshot.
[0228] Continuous monitoring and timing mechanism:
[0229] Index buffer: create a ring buffer, store the risk index (RI) of all monomers every 2 seconds.
[0230] Threshold timer: start a timer for each monomer independently:
[0231] If the current RI > 85, the timer increments (+2 seconds);
[0232] If RI ≤ 85, the timer is reset to zero;
[0233] When the timer accumulates to 300 seconds (5 minutes), it is determined to be a sustained threshold value.
[0234] Three-level alarm triggering process:
[0235] Alarm grading execution:
[0236] Level 1 alarm (RI > 60): local BMS audible and visual alarm;
[0237] Level 2 alarm (RI > 75): send SMS to maintenance personnel;
[0238] Level 3 alarm (RI > 85 for 5 consecutive minutes): automatically trigger contactor disconnection + pre-start the fire fighting system.
[0239] Parameter snapshot locking:
[0240] Freeze all data (including SFV, TRRP, SCS, RI original value) 10 minutes before the current time;
[0241] Store environmental parameters (environmental temperature, humidity, vibration intensity);
[0242] Generate encrypted data packet (including timestamp, battery topology positioning code).
[0243] Safety Linkage Response:
[0244] Electrical Isolation: Control the Latching Contactor to cut off the branch where the battery is located within 20ms.
[0245] Fire Preparation: Start the coolant pump of the adjacent battery, and the nozzle is aimed at the high-risk battery.
[0246] Data Security: Synchronize the risk parameter snapshot to the cloud platform and write it to the local FRAM anti-erase memory (to ensure that power failure does not result in loss). After all actions are completed, the system enters the protection lockdown mode and requires manual authorization to reset.
[0247] SOS (State Of Safety) evaluation model analyzes the balanced battery state data, including voltage, temperature change and internal resistance degradation trend, combines historical failure data, calculates the battery safety risk probability, dynamically adjusts the weight, and finally generates a quantitative safety risk index. This step realizes the intelligent evaluation of the battery safety state, provides early warning of potential thermal runaway risk, provides decision basis for proactive protection strategy, and avoids serious safety accidents.
[0248] S205, when the battery safety risk index exceeds the threshold, automatically send a discharge command to the remote nuclear containment system, control the contactor to switch the battery pack to the nuclear containment discharge mode, and when the AC power is lost, it is seamlessly switched to the load power supply through the diode loop, outputs the nuclear containment completion signal and resets the protection state.
[0249] Specifically, an encrypted discharge command can be sent to the remote nuclear containment system through the Modbus-TCP protocol, accompanied by a battery safety risk index overrun proof and a battery topology diagram;
[0250] Encrypted command generation and transmission mechanism:
[0251] When the battery safety risk index (range 0-100) exceeds the preset threshold of 85 for 5 consecutive minutes, the system automatically triggers a level 3 alarm and locks the current risk parameter snapshot. The central controller establishes a communication link with the remote nuclear containment system through the Modbus-TCP protocol (an industrial communication protocol based on TCP / IP network). First, the controller packages the discharge command, over-limit proof (including timestamp, risk index curve, abnormal monomer number), and battery topology graph (describing the parallel and series structure of the battery pack, monomer position) into a data frame, encrypts it using the AES-256 encryption algorithm (Advanced Encryption Standard, key length 256 bits), and ensures the safety of the transmission. For example, the encrypted instruction frame contains: instruction type code "DISCHG_CMD", risk index time series "88, 89, 87, 90, 91", topology graph encoding "3P48S" (indicating 3 parallel 48 series). The data frame is transmitted to the remote nuclear containment system through the Ethernet physical layer, with a transmission delay controlled within 50 milliseconds.
[0252] Generation logic of over-limit proof:
[0253] The battery safety risk index over-limit proof consists of three parts:
[0254] Static parameters: record the total voltage of the battery pack at the time of triggering (e.g. 384V), average temperature (e.g. 35℃), and average internal resistance (e.g. 20mΩ).
[0255] Dynamic parameters: extract the characteristics of abnormal monomers in the locked snapshot, such as the voltage fluctuation amplitude of monomer B23 ±0.5V / min, temperature change rate +2℃ / s.
[0256] Historical comparison: associate the historical database of the SOS evaluation model, and mark the deviation of this risk index compared to the previous 10 cycles (e.g. more than 30% of the historical average).
[0257] All data is packaged in JSON structured format (a lightweight data exchange format) and accompanied by a digital signature to prevent tampering.
[0258] Dynamic mapping of battery topology graph:
[0259] The battery topology graph is generated based on the real-time collected multi-dimensional matrix of battery status. The system abstracts each monomer as a node and the connection relationship as an edge through graph theory algorithm, and constructs a topology network graph. For example, a 48-string battery pack is mapped to a chain structure with 48 nodes in series, each node is labeled with physical location (e.g. rack 1-slot 3) and electrical parameters (initial internal resistance 18mΩ). When an open circuit fault bypass occurs, the topology graph automatically updates the bypass path (e.g. B15 is short-circuited by silicon carbide MOSFET), ensuring the accurate positioning of the nuclear containment system for the discharge object.
[0260] The magnetic latching contactor switches the battery pack to the nuclear capacity bus, while the bidirectional AC / DC converter is started to maintain the load voltage stable.
[0261] Switching control of the magnetic latching contactor:
[0262] After receiving the discharge command, the magnetic latching contactor (using permanent magnets to keep the contact state, coil pulse driving) sends a 12V / 100ms pulse current to its driving coil, causing the contact to switch from the "load supply point" to the "nuclear capacity bus segment". The contact resistance of the contactor is less than 0.5mΩ, and the switching action time is ≤20ms. To prevent arcing, the switching timing is strictly matched with the current zero point (achieved through an AC phase detection circuit). For example, the opening operation is performed when the AC phase is 0° or 180°, and the nuclear capacity bus is closed at 90° or 270°, decoupling the battery pack from the load and connecting it to the nuclear capacity discharge loop.
[0263] Voltage stabilization strategy of the bidirectional AC / DC converter:
[0264] The bidirectional AC / DC converter (which can achieve AC / DC and DC / AC bidirectional energy conversion) is started at the moment of contactor switching. Its control unit samples the load end voltage (such as 220V AC) in real time, and if it detects that the voltage has dropped by more than ±5%, it immediately triggers the compensation mode:
[0265] When the load voltage drops, the converter draws energy from the DC bus (such as a supercapacitor pack) and outputs a compensation current through a full-bridge IGBT inverter circuit (an inverter topology composed of insulated gate bipolar transistors) to maintain voltage stability.
[0266] When the voltage rises, switch to the rectification mode to absorb excess energy. The dynamic response time is <10ms, and the output voltage fluctuation rate is controlled within ±2%.
[0267] Energy management of the nuclear capacity bus:
[0268] After the battery pack is connected to the nuclear capacity bus, the discharge current is released through an adjustable electronic load (precision 0.1A) at a constant current, and the current value is set according to the nuclear capacity plan (such as 0.2C rate discharge). The bus voltage is stabilized in the safety range (such as ±10% of the rated voltage) through a Buck-Boost circuit (buck-boost topology). The discharge energy is recovered to the energy storage cabinet or the grid, with an efficiency >92%.
[0269] Real-time monitoring of AC input phase, immediately turn on the Schottky diode freewheeling circuit when power loss is detected, achieving <100μs seamless switching;
[0270] AC phase monitoring mechanism:
[0271] The system tracks the phase and frequency of the AC input voltage in real time through a phase-locked loop (PLL). The sampling circuit collects the grid voltage waveform (e.g., 220V / 50Hz) at a rate of 100kHz, and extracts the phase angle θ (accuracy ±0.5°) through a zero comparator (output square wave signal) and digital filter. When no change in θ is detected for 5 consecutive cycles or the amplitude is less than 15% of the rated value, it is determined that the AC power is lost (e.g., grid failure).
[0272] Triggering of the Schottky diode freewheeling circuit:
[0273] The loss of power signal triggers the gate drive chip (e.g., IR2110) to send a conduction signal to the Schottky diode array (forward voltage drop 0.3V, reverse recovery time <10ns). The diode set is connected in parallel across the contactor contacts, forming a low-impedance freewheeling path (resistance <1mΩ). For example, within 5μs after detecting power loss, the drive chip outputs a 15V high level to the diode cathode, causing it to conduct instantaneously, and the battery pack current is freewheeled to the load, avoiding load power failure.
[0274] Performance guarantee for seamless switching:
[0275] The freewheeling circuit design uses a multi-stage parallel topology (e.g., 8 diodes in parallel to share current), supporting instantaneous current of 1000A. The switching process is verified by high-speed oscilloscope measurement: the delay from power loss detection to load voltage recovery is ≤80μs, and the voltage drop amplitude is <5%. The system records switching event logs (including timestamp, phase angle, and freewheeling current peak), which are used for fault backtracking.
[0276] After the end of the capacity test, analyze the capacity attenuation report of the BMS. If the capacity recovers to 95% or more of the nominal value, output the capacity test completion signal and reset the protection flag.
[0277] Generation logic of the capacity attenuation report:
[0278] The BMS (Battery Management System) records the single cell voltage, current, and temperature data during the entire capacity test discharge, and calculates the actual capacity by integrating the current over time (Ah integration method) and open circuit voltage method (OCV-SOC curve calibration). After the capacity test is completed (discharged to the cutoff voltage such as 1.8V per cell), a report is generated, including:
[0279] Total capacity attenuation rate: (difference between nominal capacity and actual discharge capacity) / nominal capacity × 100%.
[0280] Single cell consistency analysis: standard deviation σ (e.g., σ <0.5% is considered to be good consistency).
[0281] The report is transmitted to the host through the CAN bus, and the format is SAE J1939 standard frame (vehicle network communication standard).
[0282] Capacity recovery determination and signal output:
[0283] The host analyzes the actual capacity value in the report (such as a nominal 200Ah battery discharging 192Ah), calculates the recovery rate (192 / 200=96%). If the recovery rate ≥95%, then:
[0284] Send a capacity recovery completion signal (digital signal "1" + green indicator light) to the HMI (human-machine interface).
[0285] Broadcast the completion event through RS485 (including the capacity recovery value, abnormal single cell repair status, and capacity recovery time).
[0286] If the recovery rate <95%, trigger the capacity degradation alarm and mark the single cell that needs to be replaced.
[0287] Protection state reset process:
[0288] The completion signal triggers the following reset operations:
[0289] Clear fault latch: reset open-circuit bypass command (SiC MOSFET off), three-level alarm flag.
[0290] Restore the equalization function: re-enable the dynamic equalization strategy of the bidirectional LLC resonant converter.
[0291] Reset the SOS model: the safety risk index is reset to zero, and the historical snapshot is stored in the database for reference.
[0292] The system automatically switches the magnetic latching contactor back to the load supply position and generates a capacity recovery report for archiving.
[0293] When the safety risk index exceeds the limit, the system automatically starts the capacity recovery discharge mode, switches the battery pack to the capacity recovery bus through the contactor, and uses a diode loop to ensure uninterrupted load power supply when AC power is lost. After the capacity recovery is completed, the system returns to the initial state and outputs a completion signal. This technology realizes safe capacity recovery maintenance of the battery pack, avoids manual intervention delays, and ensures load power supply continuity in abnormal situations, improving system availability and safety.
[0294] It can be seen that the open circuit signal of the single battery is detected by the high-precision voltage monitoring module, a bypass instruction is generated and the battery pack power is maintained for continuous output; real-time data acquisition is triggered based on the bypass instruction, a multi-dimensional matrix of battery state with a time stamp is constructed through the anti-reverse module and the blind insertion communication interface; the multi-dimensional matrix of battery state is input into the clustering analysis engine, and a dynamic balancing instruction set is output; based on the dynamic balancing instruction set and the multi-dimensional matrix of battery state, the single voltage, temperature change rate and internal resistance deterioration trend are input into the SOS evaluation model, and a battery safety risk index is generated; when the battery safety risk index exceeds the threshold value, the load power is seamlessly switched to the diode loop during AC power failure, the nuclear capacity completion signal is output and the protection state is reset, so that the fault response speed and safety redundancy of the battery pack can be improved.
[0295] Another embodiment of the application provides a battery safety protection system, see Figure 3 , the system can include:
[0296] The trigger module 301 is used for detecting the open circuit signal of the single battery through the high-precision voltage monitoring module, generating a bypass instruction and maintaining the battery pack power for continuous output when the open circuit fault is identified, and triggering the bypass freewheeling circuit to instantaneously and seamlessly remove the fault battery.
[0297] The acquisition module 302 is used for triggering real-time data acquisition based on the bypass instruction, synchronously acquiring single voltage, internal resistance, temperature and charge-discharge current data, and constructing a multi-dimensional matrix of battery state with a time stamp through the anti-reverse module and the blind insertion communication interface.
[0298] The identification module 303 is used for inputting the multi-dimensional matrix of battery state into the clustering analysis engine, identifying the voltage abnormal single battery, discharging the high-voltage single battery and charging the low-voltage single battery through the bidirectional energy transfer circuit, and outputting a dynamic balancing instruction set.
[0299] The input module 304 is used for inputting the single voltage, temperature change rate and internal resistance deterioration trend into the SOS evaluation model based on the dynamic balancing instruction set and the multi-dimensional matrix of battery state, calculating a safety parameter comprehensive evaluation value, and generating a battery safety risk index.
[0300] The output module 305 is used for automatically sending a discharge instruction to a remote nuclear capacity system when the battery safety risk index exceeds the threshold value, controlling the contactor to switch the battery pack to a nuclear capacity discharge mode, and seamlessly switching to the load power through the diode loop during AC power failure, outputting a nuclear capacity completion signal and resetting the protection state.
[0301] The embodiment of the application further provides a storage medium, and the storage medium stores a computer program, wherein the computer program is set to execute the steps in any one of the method embodiments when running.
[0302] Specifically, in the embodiment, the storage medium can be configured to store a computer program for executing the following steps:
[0303] S201, detecting an open circuit signal of a single battery through a high-precision voltage monitoring module, triggering a bypass freewheeling circuit to instantaneously and seamlessly remove a faulty battery when an open circuit fault is identified, generating a bypass instruction and maintaining a power continuous output of a battery pack;
[0304] S202, triggering real-time data acquisition based on the bypass instruction, synchronously acquiring single battery voltage, internal resistance, temperature and charge-discharge current data, constructing a battery state multi-dimensional matrix with a time stamp through an anti-reverse module and a blind insertion communication interface;
[0305] S203, inputting the battery state multi-dimensional matrix into a clustering analysis engine to identify voltage abnormal single batteries, discharging high-voltage single batteries and charging low-voltage single batteries through a bidirectional energy transfer circuit, and outputting a dynamic balancing instruction set;
[0306] S204, based on the dynamic balancing instruction set and the battery state multi-dimensional matrix, inputting single battery voltage, temperature change rate and internal resistance deterioration trend into an SOS evaluation model, calculating a safety parameter comprehensive evaluation value, and generating a battery safety risk index;
[0307] S205, when the battery safety risk index is greater than a threshold value, automatically sending a discharge instruction to a remote nuclear capacity system, controlling a contactor to switch a storage battery pack to a nuclear capacity discharge mode, and seamlessly switching to load power supply through a diode loop when alternating current power is lost, outputting a nuclear capacity completion signal and resetting a protection state.
[0308] The embodiment of the application further provides an electronic device including a memory and a processor, the memory storing a computer program, and the processor being configured to run the computer program to execute the steps in any of the method embodiments.
[0309] Specifically, the electronic device can further include a transmission device and an input-output device, wherein the transmission device is connected to the processor, and the input-output device is connected to the processor.
[0310] Specifically, in the embodiment, the processor can be configured to execute the following steps through the computer program:
[0311] S201, detecting an open circuit signal of a single battery through a high-precision voltage monitoring module, triggering a bypass freewheeling circuit to instantaneously and seamlessly remove a faulty battery when an open circuit fault is identified, generating a bypass instruction and maintaining a power continuous output of a battery pack;
[0312] S202, triggering real-time data acquisition based on the bypass instruction, synchronously acquiring single cell voltage, internal resistance, temperature and charge-discharge current data, and constructing a battery state multi-dimensional matrix with time stamp through the anti-reverse module and blind insertion communication interface;
[0313] S203, inputting the battery state multi-dimensional matrix into a clustering analysis engine to identify voltage abnormal single cells, discharging high-voltage single cells and charging low-voltage single cells through a bidirectional energy transfer circuit, and outputting a dynamic balancing instruction set;
[0314] S204, inputting single cell voltage, temperature change rate and internal resistance deterioration trend into a SOS evaluation model based on the dynamic balancing instruction set and the battery state multi-dimensional matrix, calculating a safety parameter comprehensive evaluation value, and generating a battery safety risk index;
[0315] S205, when the battery safety risk index is over the threshold value, automatically sending a discharge instruction to a remote nuclear containment system, controlling a contactor to switch the battery pack to a nuclear containment discharge mode, and seamlessly switching to load power supply through a diode loop when alternating current power is lost, outputting a nuclear containment completion signal and resetting the protection state.
[0316] The above embodiments according to the drawings illustrate the structure, features and effects of the present application. The above description is only a preferred embodiment of the present application, but the present application is not limited by the drawings. Any change or modification within the scope of the present application, or equivalent embodiments within the scope of the present application, shall be within the scope of the present application.
Claims
1. A method for protecting the safety of a storage battery, characterized in that, The method includes: The high-precision voltage monitoring module detects the open circuit signal of a single battery cell. When an open circuit fault is detected, the bypass freewheeling circuit is triggered to instantly and seamlessly disconnect the faulty battery, generate a bypass command, and maintain the continuous power output of the battery pack. Real-time data acquisition is triggered based on the bypass command, and the individual cell voltage, internal resistance, temperature and charge / discharge current data are acquired synchronously. A multi-dimensional matrix of battery status with timestamps is constructed through the anti-reverse module and the blind insertion communication interface. The battery state multidimensional matrix is input into the clustering analysis engine to identify cells with abnormal voltage. A bidirectional energy transfer circuit discharges high-voltage cells and compensates for low-voltage cells, outputting a dynamic balancing instruction set. Specifically, a voltage-internal resistance joint feature vector is extracted based on the battery state multidimensional matrix, and outlier cells are identified using the OPTICS clustering algorithm, generating a set of cells with abnormal voltage. The Euclidean distance between the abnormal cells and the healthy cluster centers is calculated, and overcharged high-voltage cells and undercharged low-voltage cells are classified according to the positive or negative value of the voltage quantum distance, outputting classification labels. If the Euclidean distance is greater than or equal to a preset distance threshold, the abnormal cell is confirmed as a valid abnormal cell; if the Euclidean distance is less than the preset distance threshold, it is only recorded without performing balancing. If the cell feature vector is (Vx, Rx) and the healthy cluster center is (Vc, Rc), then the voltage quantum distance VSD = Vx. –Vc, Vx are the voltage values of the xth cell, Rx is the internal resistance value of the xth cell, Vc is the voltage value of the cluster center c, and Rc is the internal resistance value of the cluster center c; control the bidirectional LLC resonant converter to construct an energy transfer channel, and transfer the energy of the high-voltage cell to the low-voltage cell through the high-frequency isolation transformer according to the classification label; monitor the voltage convergence rate during the transfer process in real time, and generate a dynamic equalization instruction set when the standard deviation drops to within the standard deviation threshold; Based on the dynamic equalization instruction set and the battery state multidimensional matrix, the cell voltage, temperature change rate and internal resistance degradation trend are input into the SOS evaluation model to calculate the comprehensive evaluation value of safety parameters and generate the battery safety risk index. When the battery safety risk index exceeds the threshold, a discharge command is automatically sent to the remote capacity control system to control the contactor to switch the battery pack to capacity discharge mode. In the event of AC power failure, the system seamlessly switches to load power supply through a diode circuit, outputs a capacity completion signal, and resets the protection state.
2. The method according to claim 1, characterized in that, The high-precision voltage monitoring module detects open-circuit signals in individual batteries. When an open-circuit fault is detected, the bypass freewheeling circuit is triggered to instantly and seamlessly disconnect the faulty battery, generate a bypass command, and maintain continuous power output of the battery pack. This includes: A nanosecond-level response voltage sensor is used to collect the terminal voltage of a single battery cell in real time. The instantaneous voltage drop rate is detected by a sliding window differential algorithm, and a voltage anomaly fluctuation sequence is generated. The abnormal voltage fluctuation sequence is input into the pre-trained fault classification model. When the drop rate exceeds the threshold for three consecutive sampling periods, it is determined to be an open circuit fault, and the fault location signal is output. The bypass freewheeling circuit composed of silicon carbide MOSFETs is triggered by the fault location signal, which conducts the low impedance path within 200ns and disconnects the faulty battery connection at the same time, generating a bypass command. By injecting compensation current instantaneously through the supercapacitor bank, the total output power fluctuation rate of the battery pack is maintained at <2%, achieving seamless switching and locking the bypass state.
3. The method according to claim 2, characterized in that, The process involves triggering real-time data acquisition based on the bypass command, simultaneously acquiring cell voltage, internal resistance, temperature, and charge / discharge current data. A timestamped multi-dimensional battery state matrix is constructed using the anti-reverse module and blind-insertion communication interface, including: The multi-channel synchronous acquisition circuit is activated according to the bypass command to synchronously capture the raw data stream containing individual cell voltage, internal resistance, temperature and Hall current data at a sampling rate of 10kHz. The magnetic isolation technology of the anti-reverse module eliminates common-mode interference and converts the original data stream into a CAN bus protocol frame with CRC check. A physical connection is established using a flexible probe matrix of a blind-plug interface, and an absolute time stamp with μs precision is added to each frame of data using a timestamp chip. Reassemble the time-stamped data stream into a three-dimensional tensor according to the battery ID to generate the initial state matrix; The initial state matrix is subjected to moving average filtering and missing value interpolation to output a time-aligned multidimensional matrix of battery states.
4. The method according to claim 3, characterized in that, Based on the dynamic balancing instruction set and the battery state multidimensional matrix, the individual cell voltage, temperature change rate, and internal resistance degradation trend are input into the SOS assessment model to calculate a comprehensive safety parameter assessment value and generate a battery safety risk index, including: Based on the dynamic equalization instruction set, the individual cell voltage timing, temperature change rate and internal resistance degradation slope after dynamic equalization are extracted to construct a safety feature vector. Input the safety feature vector into the SOS assessment model to calculate the probability value of thermal runaway risk. By fusing historical fault data through Bayesian networks, the prior distribution of risk probability values is corrected, and a confidence score for safety parameters is output. By dynamically adjusting the confidence score weights based on the battery cycle life curve, a battery safety risk index with a scale of 0-100 is generated. When the index is greater than 85 for 5 consecutive minutes, a level 3 alarm is triggered, and the current risk parameter snapshot is locked.
5. The method according to claim 4, characterized in that, When the battery safety risk index exceeds the threshold, a discharge command is automatically sent to the remote capacity approval system, controlling the contactor to switch the battery pack to capacity approval discharge mode. In the event of AC power failure, a diode circuit seamlessly switches to load power supply, outputs a capacity approval completion signal, and resets the protection state, including: The encrypted discharge command is sent to the remote capacity system via Modbus-TCP protocol, along with proof of exceeding the battery safety risk index and a battery topology diagram. The magnetic latching contactor is controlled to switch the battery pack to the core capacity bus, and at the same time the bidirectional AC / DC converter is started to maintain the load voltage stability. Real-time monitoring of AC input phase; when power failure is detected, the Schottky diode freewheeling circuit is immediately activated to achieve seamless switching of <100μs. After the capacity reduction is completed, the capacity decay report of the BMS is analyzed. If the capacity recovers to more than 95% of the nominal value, a capacity reduction completion signal is output and the protection flag is reset.
6. A battery safety protection system, characterized in that, The system includes: The trigger module is used to detect the open circuit signal of a single battery cell through the high-precision voltage monitoring module. When an open circuit fault is detected, the bypass freewheeling circuit is triggered to instantly and seamlessly disconnect the faulty battery, generate a bypass command, and maintain the continuous power output of the battery pack. The acquisition module is used to trigger real-time data acquisition based on the bypass command, and synchronously acquire data on cell voltage, internal resistance, temperature and charge / discharge current. It constructs a multi-dimensional matrix of battery status with timestamps through the anti-reverse module and the blind insertion communication interface. The identification module is used to input the battery state multidimensional matrix into the clustering analysis engine, identify cells with abnormal voltage, discharge high-voltage cells and compensate for low-voltage cells through a bidirectional energy transfer circuit, and output a dynamic balancing instruction set. Specifically, it extracts a voltage-internal resistance joint feature vector based on the battery state multidimensional matrix, identifies outliers using the OPTICS clustering algorithm, and generates a set of cells with abnormal voltage. It calculates the Euclidean distance between the abnormal cells and the healthy cluster centers, and classifies overcharged high-voltage cells and undercharged low-voltage cells based on the positive or negative value of the voltage quantum distance, outputting classification labels. If the Euclidean distance is greater than or equal to a preset distance threshold, the abnormal cell is confirmed as a valid abnormal cell; if the Euclidean distance is less than the preset distance threshold, it is only recorded and balancing is not performed. If the cell feature vector is (Vx, Rx) and the healthy cluster center is (Vc, Rc), then the voltage quantum distance VSD = Vx – Vc and Vx are the voltage values of the xth cell, Rx is the internal resistance value of the xth cell, Vc is the voltage value of the cluster center c, and Rc is the internal resistance value of the cluster center c; control the bidirectional LLC resonant converter to construct an energy transfer channel, and transfer the energy of the high-voltage cell to the low-voltage cell through the high-frequency isolation transformer according to the classification label; monitor the voltage convergence rate during the transfer process in real time, and generate a dynamic equalization instruction set when the standard deviation drops to within the standard deviation threshold; The input module is used to input the cell voltage, temperature change rate, and internal resistance degradation trend into the SOS evaluation model based on the dynamic equalization instruction set and the battery state multidimensional matrix, calculate the comprehensive evaluation value of safety parameters, and generate the battery safety risk index. The output module is used to automatically send a discharge command to the remote capacity-controlled system when the battery safety risk index exceeds the threshold, control the contactor to switch the battery pack to the capacity-controlled discharge mode, and seamlessly switch to load power supply through the diode circuit when AC power fails, output the capacity-controlled completion signal and reset the protection state.
7. The system according to claim 6, characterized in that, The triggering module is specifically used for: A nanosecond-level response voltage sensor is used to collect the terminal voltage of a single battery cell in real time. The instantaneous voltage drop rate is detected by a sliding window differential algorithm, and a voltage anomaly fluctuation sequence is generated. The abnormal voltage fluctuation sequence is input into the pre-trained fault classification model. When the drop rate exceeds the threshold for three consecutive sampling periods, it is determined to be an open circuit fault, and the fault location signal is output. The bypass freewheeling circuit composed of silicon carbide MOSFETs is triggered by the fault location signal, which conducts the low impedance path within 200ns and disconnects the faulty battery connection at the same time, generating a bypass command. By injecting compensation current instantaneously through the supercapacitor bank, the total output power fluctuation rate of the battery pack is maintained at <2%, achieving seamless switching and locking the bypass state.
8. A storage medium, characterized in that, The storage medium stores a computer program, wherein the computer program is configured to execute the method of any one of claims 1-5 when it is run.
9. An electronic device comprising a memory and a processor, characterized in that, The memory stores a computer program, and the processor is configured to run the computer program to perform the method of any one of claims 1-5.
Citation Information
Patent Citations
Full intercommunication magnetic circuit network battery automatic balance compensation system and control method thereof
CN109120028A
Storage battery pack fault management system
CN115275386A
Storage battery abnormity early warning system based on intelligent battery gateway
CN120352780A
And auxiliary power supply device is used for improving availability of storage battery pack
CN211830332U