Method and device for protecting energy storage device, energy storage system and electric equipment

By generating and updating the transmission path and verification information of the initial task, the problem of poor communication reliability in the energy storage system is solved, ensuring the safe operation of the energy storage cells.

CN120855613BActive Publication Date: 2026-02-03ZHEJIANG JINKO ENERGY STORAGE CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511367736.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-23
Publication Date
2026-02-03
Estimated Expiration
2045-09-23

AI Technical Summary

Technical Problem

In existing technologies, the communication reliability between the system control unit, battery control unit, and energy storage converter is poor, which affects the safe operation of the energy storage cells.

Method used

By generating an initial task, including transmission path and verification information, and sending it to the energy storage converter, multi-level path updates and verifications are performed between the battery control units. Finally, data integrity and transmission path verification are performed at the system control unit, triggering a shutdown protection operation to ensure safety.

Benefits of technology

It improves the communication reliability between the system control unit, energy storage converter and battery control unit, ensuring the safe and stable operation of energy storage cells under complex operating conditions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120855613B_ABST
    Figure CN120855613B_ABST
Patent Text Reader

Abstract

The embodiment of the application relates to the field of energy storage systems, and provides a protection method and device of an energy storage device, an energy storage system and an electric equipment. Communication ring detection is established among a system control unit, an energy storage converter and a battery control unit. The system control unit generates an initial task containing check information and a transmission path and sends the initial task to the energy storage converter, the energy storage converter updates the transmission path and adds the check information to form an intermediate task, and then the battery control unit continues to update and add the check information to generate a final task and return the final task to the system control unit. The system control unit checks the data integrity and the transmission path correctness of the final task to determine whether the communication among the three is normal, and triggers a shutdown protection when the final task is not received or the check fails, so that communication abnormalities can be found in time, and the reliability of the energy storage system operation and the safety of the energy storage cells are improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of energy storage systems, and in particular to a protection method and device for an energy storage device, an energy storage system, and an electrical equipment. BACKGROUND

[0002] With the rapid development of the new energy industry, energy storage systems are increasingly widely used in power peak shaving, renewable energy consumption, power grid auxiliary services, and distributed energy management scenarios. Among them, the energy storage converter (also known as the energy storage inverter) is the core link of the energy storage system, and undertakes the important functions of bidirectional energy conversion, operation control, and protection. In the energy storage system, the system control unit, the battery control unit, and the energy storage converter need to communicate with each other through a communication link to transfer tasks, exchange operation parameters, and monitor states, so as to ensure that the energy storage cells can work in a safe and reliable condition.

[0003] In the prior art, there is a technical problem of poor communication reliability between the system control unit, the battery control unit, and the energy storage converter, which affects the safe operation of the energy storage cells. SUMMARY

[0004] The embodiments of the present application provide a protection method and device for an energy storage device, an energy storage system, and an electrical equipment, which at least help to solve the technical problem of poor communication reliability between the system control unit, the battery control unit, and the energy storage converter, which affects the safe operation of the energy storage cells.

[0005] To achieve the above object, according to one aspect of the present application, a protection method for an energy storage device is provided, comprising: generating an initial task, the initial task comprising a transmission path of the task and check information of a system control unit; sending the initial task to an energy storage converter; determining whether a final task sent by a battery control unit is received, the final task being obtained by the battery control unit updating the transmission path in an intermediate task and adding check information of the battery control unit to the intermediate task, the transmission path in the final task comprising fields that have been transmitted from the energy storage converter to the battery control unit, the intermediate task being obtained by the energy storage converter updating the transmission path in the initial task and adding check information of the energy storage converter to the initial task, the transmission path in the intermediate task comprising fields that have been transmitted from the system control unit to the energy storage converter; performing check processing on the final task in a case where the final task is received, the check processing comprising data integrity check and correctness check of the transmission path in the final task; triggering shutdown protection operation on the energy storage device in a case where the final task is not received or the final task fails the check.

[0006] Optionally, the transmission path in the initial task comprises a first path field transmitted from the system control unit to the energy storage converter and a second path field transmitted from the energy storage converter to the battery control unit, the updating of the transmission path in the initial task is implemented by the energy storage converter inserting a first preset identifier at a first predetermined position in the first path field, and the updating of the transmission path in the intermediate task is implemented by the battery control unit inserting a second preset identifier at a second predetermined position in the second path field.

[0007] Optionally, the transmission path in the initial task comprises a third field transmitted from the system control unit, the updating of the transmission path in the initial task is implemented by the energy storage converter adding the first path field transmitted from the system control unit to the energy storage converter after the third field, and the updating of the transmission path in the intermediate task is implemented by the battery control unit adding the second path field transmitted from the energy storage converter to the battery control unit after the first path field.

[0008] Optionally, the generating the initial task comprises: generating the transmission path, the unique transaction identifier, the first random check code and the first timestamp corresponding to the initial task to obtain a data packet; signing the data packet by using a private key of the system control unit to generate a first signature to obtain the initial task comprising the first signature and the data packet, wherein the check information of the initial task comprises the unique transaction identifier, the first random check code, the first timestamp and the first signature.

[0009] Optionally, the transmission path in the initial task is obtained by parsing the initial task in a case that the first signature is successfully verified by the energy storage converter using the public key of the system control unit; and the adding of the check information of the energy storage converter is implemented by signing the transmission path updated by the energy storage converter, the initial task, a second timestamp and a second random check code by using a private key of the energy storage converter to generate a second signature, and adding the second signature, the second timestamp and the second random check code to the initial task, wherein the second timestamp and the second random check code are generated by the energy storage converter when the initial task is received.

[0010] Optionally, the transmission path in the intermediate task is obtained by parsing the intermediate task in a case that the second signature is successfully verified by the battery control unit using the public key of the energy storage converter; and the adding of the check information of the battery control unit is implemented by signing the transmission path updated by the battery control unit, the intermediate task, a third timestamp and a third random check code by using a private key of the battery control unit to generate a third signature, and adding the third signature, the third timestamp and the third random check code to the intermediate task, wherein the third timestamp and the third random check code are generated by the battery control unit when the intermediate task is received.

[0011] Optionally, the field transmitted from the system control unit to the energy storage converter is a first field, the field transmitted from the energy storage converter to the battery control unit is a second field, the final task includes a first signature and a first timestamp of the system control unit, a second signature and a second timestamp of the energy storage converter, and a third signature and a third timestamp of the battery control unit, and the checking of the final task includes: performing the integrity check on the data in the final task by the first signature, the second signature, and the third signature; performing the correctness check on the transmission path in the final task according to the order of the transmission path in the final task, the order of generation of the second signature and update of the first field, and the order of generation of the third signature and update of the second field; and determining whether the system control unit meets the time delay requirement according to the time difference between the second timestamp and the first timestamp, determining whether the energy storage converter meets the time delay requirement according to the time difference between the third timestamp and the second timestamp, and determining whether the battery control unit meets the time delay requirement according to the time difference between the fourth time and the third timestamp.

[0012] Optionally, the method further includes: performing periodic communication detection with the energy storage converter and the battery control unit respectively through the life frame; triggering a shutdown protection operation of the energy storage device in the case that the communication detection is abnormal; and triggering the shutdown protection operation of the energy storage device in the case that a first feedback signal is received and the energy storage device is in normal operation, the first feedback signal being sent by the energy storage converter or the battery control unit in the case that the communication detection is determined to be abnormal in the process of performing periodic communication detection between the energy storage converter and the battery control unit through the life frame.

[0013] Optionally, the method further includes: in the case that a second feedback signal sent by the energy storage converter is received, synchronizing control parameters with the battery control unit, the second feedback signal being sent by the energy storage converter in the case that the energy storage converter receives a first adjustment instruction of a predetermined control parameter sent by the system control unit and a second adjustment instruction of the predetermined control parameter sent by the battery control unit within a predetermined time period, and executes a target adjustment instruction; the adjustment value of the first adjustment instruction is different from the adjustment value of the second adjustment instruction, and the target adjustment instruction is the instruction with the smaller adjustment value in the first adjustment instruction and the second adjustment instruction.

[0014] Optionally, the method further includes at least one of the following: when it is determined that an abnormality has occurred in the communication detection between the system control unit and the battery control unit, sending a command indicating that charge and discharge control is prohibited to the energy storage converter to prohibit the energy storage converter from performing charge and discharge control on the energy storage device; and triggering a shutdown protection operation on the energy storage device when an abnormality in the bus voltage is detected.

[0015] According to another aspect of this application, a protection device for an energy storage device is provided, comprising: a generation module for generating an initial task, the initial task including a transmission path of the task and verification information of a system control unit; a sending module for sending the initial task to an energy storage converter; and a determining module for determining whether a final task sent by a battery control unit has been received, the final task being obtained by the battery control unit updating the transmission path in the intermediate task and adding the verification information of the battery control unit to the intermediate task when the battery control unit receives an intermediate task sent by the energy storage converter, wherein the transmission path in the final task includes data already transmitted from the energy storage converter to the battery control unit. The intermediate task is obtained by updating the transmission path in the initial task and adding the verification information of the energy storage converter to the initial task when the energy storage converter receives the initial task. The transmission path in the intermediate task includes fields that have been transmitted from the system control unit to the energy storage converter. The processing module is used to perform verification processing on the final task when the final task is received. The verification processing includes data integrity verification and the correctness verification of the transmission path in the final task. The triggering module is used to trigger a shutdown protection operation for the energy storage device when the final task is not received or the final task verification fails.

[0016] According to another aspect of this application, an energy storage system includes: an energy storage device; a system control unit for executing any of the protection methods for the energy storage device; an energy storage converter electrically connected to the energy storage device and electrically connected to the system control unit via Ethernet, wherein, upon receiving an initial task, the energy storage converter updates the transmission path in the initial task and adds the verification information of the energy storage converter to the initial task to obtain an intermediate task, wherein the transmission path in the intermediate task includes fields that have been transmitted from the system control unit to the energy storage converter; and a battery control unit communicatively connected to the energy storage converter via a CAN bus and electrically connected to the system control unit via Ethernet, wherein, upon receiving an intermediate task sent by the energy storage converter, the battery control unit updates the transmission path in the intermediate task and adds the verification information of the battery control unit to the intermediate task to obtain a final task, wherein the transmission path in the final task includes fields that have been transmitted from the energy storage converter to the battery control unit.

[0017] According to another aspect of this application, an electrical appliance is provided, including a protection device for the energy storage device.

[0018] The technical solution provided in this application has at least the following advantages:

[0019] The protection method for the energy storage device of this application establishes a communication loop detection between the system control unit, the energy storage converter, and the battery control unit. The system control unit generates an initial task including verification information and a transmission path and sends it to the energy storage converter. When communication between the three is normal, the initial task updates the transmission path and adds verification information to obtain an intermediate task via the energy storage converter. Then, the battery control unit updates the transmission path in the intermediate task and adds verification information to obtain the final task, which is then returned to the system control unit. The system control unit checks the data integrity and transmission path correctness in the final task to determine whether the loop communication is normal. In case of abnormality, the shutdown protection of the energy storage cell is triggered, ensuring the safety of the energy storage cell and effectively improving the communication reliability and operational safety between the three, ensuring the safe and stable operation of the energy storage cell under complex operating conditions. Attached Figure Description

[0020] One or more embodiments are illustrated by way of example with reference to the accompanying drawings. These illustrations do not constitute a limitation on the embodiments. Unless otherwise stated, the drawings in the accompanying drawings do not constitute a limitation on scale. In order to more clearly illustrate the technical solutions in the embodiments of this application or in the conventional art, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0021] Figure 1 A hardware structure block diagram of a mobile terminal for a protection method of an energy storage device provided in an embodiment of this application;

[0022] Figure 2 This is a schematic flowchart illustrating a protection method for an energy storage device provided in an embodiment of this application.

[0023] Figure 3 A flowchart illustrating a detailed method for task generation and verification provided in an embodiment of this application;

[0024] Figure 4 A flowchart illustrating another protection method for an energy storage device provided in an embodiment of this application;

[0025] Figure 5 This is a schematic diagram illustrating the communication process of a specific system control unit, battery control unit, and energy storage converter provided in an embodiment of this application.

[0026] Figure 6 This is a schematic diagram of a communication detection process between a system control unit, a battery control unit, and an energy storage converter provided in an embodiment of this application;

[0027] Figure 7 This is a structural block diagram of a protection device for an energy storage device provided in an embodiment of this application.

[0028] The above figures include the following reference numerals:

[0029] 102. Processor; 104. Memory; 106. Transmission device; 108. Input / output device. Detailed Implementation

[0030] As is known from the background art, existing technologies suffer from poor communication reliability between the system control unit, battery control unit, and energy storage converter, which affects the safe operation of energy storage cells. This application provides a protection method, device, energy storage system, and electrical equipment for an energy storage device. The protection method for the energy storage device of this application includes: generating an initial task, which includes the transmission path of the task and the verification information of the system control unit; sending the initial task to the energy storage converter; determining whether a final task sent by the battery control unit has been received, wherein the final task is obtained by the battery control unit updating the transmission path in the intermediate task and adding the verification information of the battery control unit to the intermediate task when it receives the intermediate task sent by the energy storage converter, and the transmission path in the final task includes fields that have been transmitted from the energy storage converter to the battery control unit; the intermediate task is obtained by the energy storage converter updating the transmission path in the initial task and adding the verification information of the energy storage converter to the initial task when it receives the initial task, and the transmission path in the intermediate task includes fields that have been transmitted from the system control unit to the energy storage converter; if the final task is received, performing verification processing on the final task, including data integrity verification and correctness verification of the transmission path in the final task; and triggering a shutdown protection operation for the energy storage device if the final task is not received or the final task verification fails.

[0031] In the description of the embodiments of this application, technical terms such as "first" and "second" are used only to distinguish different objects and should not be construed as indicating or implying relative importance or implicitly specifying the number, specific order, or primary and secondary relationship of the indicated technical features. In the description of the embodiments of this application, "multiple" means two or more, unless otherwise explicitly defined.

[0032] In this document, the term "embodiment" means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of this application. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.

[0033] In the description of the embodiments in this application, the term "and / or" is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent three cases: A exists, A and B exist simultaneously, and B exists. In addition, the character " / " in this document generally indicates that the related objects before and after it have an "or" relationship.

[0034] In the description of the embodiments of this application, the term "multiple" refers to two or more (including two), similarly, "multiple sets" refers to two or more (including two sets), and "multiple pieces" refers to two or more (including two pieces).

[0035] In the description of the embodiments of this application, the technical terms "center," "longitudinal," "lateral," "length," "width," "thickness," "upper," "lower," "front," "rear," "left," "right," "vertical," "horizontal," "top," "bottom," "inner," "outer," "clockwise," "counterclockwise," "axial," "radial," and "circumferential" indicate the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings. They are only for the convenience of describing the embodiments of this application and simplifying the description, and are not intended to indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, they should not be construed as limitations on the embodiments of this application.

[0036] In the description of the embodiments of this application, unless otherwise expressly specified and limited, the technical terms such as "installation," "connection," "joining," and "fixing" should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral part; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; they can refer to the internal communication of two components or the interaction between two components. For those skilled in the art, the specific meaning of the above terms in the embodiments of this application can be understood according to the specific circumstances.

[0037] In the accompanying drawings corresponding to the embodiments of this application, the thickness and area of ​​the layers are enlarged for better understanding and ease of description. When describing a component (such as a layer, film, region, or substrate) on or on the surface of another component, the component may be "directly" located on the surface of the other component, or there may be a third component between the two components. Conversely, when describing a component on the surface of another component, or when another component is formed or disposed on the surface of a component, it indicates that there is no third component between the two components. Furthermore, when describing a component as being "generally" formed on another component, it means that the component is not formed on the entire surface (or front surface) of the other component, nor is it formed on a portion of the edge of the entire surface.

[0038] In the description of the embodiments of this application, when a component "includes" another component, other components are not excluded unless otherwise stated, and other components may be further included. Furthermore, when a component such as a layer, film, region, or plate is referred to as being "on / located" on another component, it can be "directly on" the other component (i.e., located on the surface of the other component with no other components between them), or another component may be present therein. Moreover, when a component such as a layer, film, region, or plate is "directly located" on another component, or when a component such as a layer, film, region, or plate is located on the surface of another component, it indicates that no other components are located therein.

[0039] The terminology used in the description of the various embodiments herein is for the purpose of describing particular embodiments only and is not intended to be limiting. As used in the description of the various embodiments and the appended claims, the word "part" is also intended to include the plural form, unless the context clearly indicates otherwise. Components include layers, films, regions, or plates, etc.

[0040] The embodiments of this application will now be described in detail with reference to the accompanying drawings. However, those skilled in the art will understand that many technical details have been provided in the embodiments of this application to facilitate a better understanding of the application. However, the technical solutions claimed in this application can be implemented even without these technical details and various variations and modifications based on the following embodiments.

[0041] The methods and embodiments provided in this application can be executed on a mobile terminal, computer terminal, or similar computing device. Taking running on a mobile terminal as an example, Figure 1 This is a hardware structure block diagram of a mobile terminal for a protection method of an energy storage device according to an embodiment of the present invention. Figure 1 As shown, a mobile terminal may include one or more ( Figure 1 Only one is shown in the diagram. A processor 102 (which may include, but is not limited to, a microprocessor MCU or a programmable logic device FPGA, etc.) and a memory 104 for storing data are also shown. The mobile terminal may further include a transmission device 106 for communication functions and an input / output device 108. Those skilled in the art will understand that... Figure 1 The structure shown is for illustrative purposes only and does not limit the structure of the mobile terminal described above. For example, the mobile terminal may also include components that are more... Figure 1 The more or fewer components shown, or having the same Figure 1 The different configurations shown.

[0042] The memory 104 can be used to store computer programs, such as application software programs and modules, like the computer program corresponding to the energy storage device protection method in this embodiment of the invention. The processor 102 executes various functional applications and data processing by running the computer program stored in the memory 104, thereby implementing the above-described method. The memory 104 may include high-speed random access memory and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include memory remotely located relative to the processor 102, and these remote memories can be connected to the mobile terminal via a network. Examples of the aforementioned networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof. The transmission device 106 is used to receive or send data via a network. Specific examples of the aforementioned networks may include wireless networks provided by the mobile terminal's communication provider. In one example, the transmission device 106 includes a network interface controller (NIC), which can be connected to other network devices via a base station to communicate with the Internet. In one example, the transmission device 106 may be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.

[0043] This embodiment provides a protection method for an energy storage device that operates on a mobile terminal, computer terminal, or similar computing device. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.

[0044] Figure 2 This is a flowchart of a protection method for an energy storage device according to an embodiment of this application. The protection method for the energy storage device of this application is applied to a system control unit. Figure 2 As shown, the method includes the following steps:

[0045] Step S201: Generate an initial task, which includes the task's transmission path and the system control unit's verification information;

[0046] Optionally, the system control unit generates an initial task periodically or under detection-triggered conditions. The transmission path field indicates the communication links that the task transmission needs to traverse, and the system control unit's verification information is used by other units in the subsequent path for verification, ensuring the uniqueness and integrity of the task. By setting verification information in the initial stage, it is possible to prevent forged or tampered tasks from entering the communication loop, thereby improving the security and controllability of communication from the source.

[0047] Step S202: Send the initial task to the energy storage converter;

[0048] Optionally, the system control unit transmits the generated initial task to the energy storage converter via Ethernet or other communication links. The energy storage converter, acting as a relay unit in the communication loop, is responsible for receiving the task and performing update operations. By sending the task from the system control unit to the energy storage converter, it is ensured that the task is completely transmitted in the communication loop, and communication reliability testing is performed starting from the core power conversion device, thus better reflecting the actual communication status between the system control unit, the energy storage converter, and the battery control unit.

[0049] Step S203: Determine whether the final task sent by the battery control unit has been received. The final task is obtained by the battery control unit updating the transmission path in the intermediate task and adding the verification information of the battery control unit to the intermediate task when it receives the intermediate task sent by the energy storage converter. The transmission path in the final task includes the fields that have been transmitted from the energy storage converter to the battery control unit. The intermediate task is obtained by the energy storage converter updating the transmission path in the initial task and adding the verification information of the energy storage converter to the initial task when it receives the initial task. The transmission path in the intermediate task includes the fields that have been transmitted from the system control unit to the energy storage converter.

[0050] Optionally, after receiving the initial task, the energy storage converter updates the path field and adds its own verification information to form an intermediate task, which is then transmitted to the battery control unit. Upon receiving the intermediate task, the battery control unit also performs the update and verification information addition to obtain the final task, which is then returned to the system control unit. This multi-level path update and verification method ensures that the task indeed passes sequentially through the energy storage converter and the battery control unit before returning to the system control unit, thus verifying the entire communication link process.

[0051] Step S204: Upon receiving the final task, perform verification processing on the final task. The verification processing includes data integrity verification and verification of the correctness of the transmission path in the final task.

[0052] Optionally, after receiving the final task, the system control unit performs integrity verification on the task data (such as CRC check, signature verification, etc.) and checks whether the transmission path in the final task is consistent with the expected path. Through integrity verification and path correctness verification, it can be ensured that the task data has not been tampered with during transmission and that the transmission logic of each node in the link is executed correctly, greatly improving the accuracy and reliability of communication detection.

[0053] Step S205: If the final task is not received or the final task verification fails, trigger the shutdown protection operation of the energy storage device.

[0054] Optionally, if the system control unit fails to receive the final task, or if errors are found in the data integrity or transmission path during the verification process, it is determined that the loop communication between the system control unit, the energy storage converter, and the battery control unit is abnormal, and the shutdown protection of the energy storage device is triggered to prevent the cells from continuing to charge and discharge.

[0055] Through the embodiments of this application, a communication loop detection is established between the system control unit, the energy storage converter, and the battery control unit. The system control unit generates an initial task including verification information and a transmission path and sends it to the energy storage converter. When the communication between the three is normal, the transmission path of the initial task is updated by the energy storage converter, and verification information is added to obtain an intermediate task. Then, the transmission path in the intermediate task is updated by the battery control unit, and verification information is added to obtain the final task, which is then returned to the system control unit. The system control unit determines whether the loop communication is normal by detecting the data integrity and transmission path correctness in the final task. In case of abnormality, the shutdown protection of the energy storage cell is triggered, ensuring the safety of the energy storage cell and effectively improving the communication reliability and operational safety between the three, ensuring the safe and stable operation of the energy storage cell under complex operating conditions.

[0056] In one optional embodiment, the transmission path in the initial task includes a first path field for transmission from the system control unit to the energy storage converter and a second path field for transmission from the energy storage converter to the battery control unit. The update of the transmission path in the initial task is achieved by the energy storage converter inserting a first preset identifier at a first predetermined position in the first path field. The update of the transmission path in the intermediate task is achieved by the battery control unit inserting a second preset identifier at a second predetermined position in the second path field.

[0057] Optionally, the transmission path in the initial task is subdivided into two fields: a first path field, which identifies the path information transmitted from the system control unit to the energy storage converter; and a second path field, which identifies the path information transmitted from the energy storage converter to the battery control unit. In other words, the initial task includes the complete transmission path from the system control unit to the battery control unit. Furthermore, this segmented setting of the path field facilitates clear differentiation and determination of whether each path segment is transmitted sequentially and on schedule during the task transmission process, facilitating segment-by-segment confirmation in subsequent verification stages.

[0058] After the initial task is transmitted to the energy storage converter, the energy storage converter inserts a first preset identifier at a first predetermined position in the first path field. This first preset identifier serves as the unique confirmation information for the completion of the transmission from the system transmission unit node to the energy storage converter node, proving that the task has been successfully transmitted and processed from the system control unit to the energy storage converter. This further ensures the traceability of the link transmission.

[0059] Subsequently, the updated intermediate task from the energy storage converter is sent to the battery control unit. Upon receiving this intermediate task, the battery control unit inserts a second preset identifier at a second predetermined position in the second path field. This serves as a confirmation that the task has successfully completed the transmission from the energy storage converter to the battery control unit. This second preset identifier is the sole confirmation information for the completion of the transmission from the energy storage converter node to the battery control unit node, proving that the task has successfully completed the transmission and processing from the energy storage converter to the battery control unit. This further ensures the traceability of the link transmission. When the system control unit receives the final task, it can accurately confirm whether the task has sequentially passed through the two key nodes, the energy storage converter and the battery control unit, by checking the identifiers inserted in the first and second path fields.

[0060] The above mechanism enables segmented updating and verification of the transmission path. Compared to traditional verification methods, this method not only verifies whether the task returns in a closed loop but also pinpoints the fault location of a specific link segment. For example, if the first preset identifier is missing in the final task, it can be determined that the link from the system control unit to the energy storage converter is abnormal; if the second preset identifier is missing, it can be determined that the link from the energy storage converter to the battery control unit is faulty. This segmented path updating and identifier insertion mechanism significantly improves the accuracy and traceability of fault detection, reduces the risk of communication failures to the safe operation of energy storage cells, and thus further enhances the overall operational reliability and safety of the energy storage device.

[0061] It should be noted that the first predetermined position can be any position in the first path field. Similarly, the second predetermined position can be any position in the second path field. Those skilled in the art can flexibly set the first and second predetermined positions. In one optional embodiment, the position of the first predetermined position in the first path field is the same as the position of the second predetermined position in the second path field; for example, both predetermined positions are located at the 5th position in the path field. Of course, the position of the first predetermined position in the first path field can also be different from the position of the second predetermined position in the second path field.

[0062] In some embodiments, the first preset identifier and the second preset identifier contain timestamp information, so that the system control unit can determine whether the insertion time of the first preset identifier is earlier than that of the second preset identifier based on the timestamp information, thereby further ensuring that the task is transmitted according to the expected path.

[0063] In some embodiments, the transmission path in the initial task further includes a third path field for transmission from the battery control unit to the system control unit. Upon receiving the final task, the method may further include inserting a third preset identifier at a third predetermined position in the third path field. This third preset identifier serves as unique confirmation information for the completion of transmission from the battery control unit node to the system control unit node.

[0064] As another optional implementation, the transmission path in the initial task includes: a third field that transmits from the system control unit; the update of the transmission path in the initial task is achieved by adding a first path field for transmission from the system control unit to the energy storage converter after the third field; and the update of the transmission path in the intermediate task is achieved by adding a second path field for transmission from the energy storage converter to the battery control unit after the first path field.

[0065] Optionally, the transmission path in the initial task contains only the third field, which identifies that the task begins transmission from the system control unit.

[0066] Once the initial task arrives at the energy storage converter, the converter adds a first path field after the third field to indicate that the task has been transmitted from the system control unit to the energy storage converter. This operation updates the transmission path at the energy storage converter and clarifies the converter's role as a node in the task transmission, thus facilitating the system control unit's ability to trace and verify the task path in subsequent verification stages.

[0067] Subsequently, the updated intermediate task from the energy storage converter is sent to the battery control unit. Upon receiving the intermediate task, the battery control unit adds a second path field after the first path field to identify that the task has been transmitted from the energy storage converter to the battery control unit. Through this path accumulation method, the final task can fully represent the entire transmission path from the system control unit, sequentially passing through the energy storage converter and the battery control unit. When the system control unit receives the final task, it can accurately confirm whether the task has been transmitted in a complete closed loop by checking the order and completeness of each path field, and can also locate anomalies in specific link segments.

[0068] The above embodiments form a complete and traceable record of the task path through cumulative path updates, enabling the system control unit to accurately verify the communication status of each link segment. Compared with traditional verification methods, this method can clearly identify the task transmission path and the processing status of each node, improving the accuracy of communication link anomaly identification. At the same time, this mechanism can quickly trigger the shutdown protection operation of the energy storage device when the link is abnormal, significantly enhancing the operational safety of the energy storage cells and the overall reliability of the system.

[0069] Figure 3 This is a flowchart illustrating a detailed method for task generation and verification according to an embodiment of this application. For example... Figure 3 As shown, the initial task is generated, including:

[0070] Step S301: Generate the transmission path, unique transaction identifier, first random checksum, and first timestamp corresponding to the initial task to obtain the data packet;

[0071] Optionally, when generating the initial task, the system control unit first defines the task transmission path. Simultaneously, it generates a unique transaction identifier to distinguish each verified task and avoid task confusion; a random verification code to enhance task tamper resistance; and a first timestamp to record the task generation time, supporting latency monitoring and task validity verification. All this information combines to form a complete data packet, ensuring the task's uniqueness, traceability, and tamper resistance, providing a fundamental guarantee for subsequent task integrity verification and ring communication verification.

[0072] Step S302: Sign the data packet using the private key of the system control unit to generate a first signature, so as to obtain an initial task including the first signature and the data packet. The verification information of the initial task includes a unique transaction identifier, a first random check code, a first timestamp, and a first signature.

[0073] Optionally, the system control unit uses its own private key to digitally sign the entire data packet, ensuring that the task is not tampered with during transmission. This also allows the receiver to verify the task's origin, achieving task source authentication and data integrity verification, preventing unauthorized task injection or data tampering, and further enhancing communication security. The initial task, after signing, contains complete verification information, serving as the basis for subsequent updates, verifications, and generation of intermediate and final tasks by the energy storage converter and battery control unit. This provides a reliable basis for downstream nodes to verify the integrity and legitimacy of tasks, ensuring the secure updating and correct transmission of tasks at each node in the ring communication.

[0074] The above embodiments of this application introduce a transmission path, a unique transaction identifier, a random checksum, a timestamp, and a system control unit signature into the initial task, enabling the task to have identity authentication, data integrity assurance, and anti-tampering functions. This provides a safe and reliable foundation for the ring communication between the energy storage converter and the battery control unit, thereby significantly improving the communication security and stability of the energy storage system and ensuring the safe operation of the energy storage cells under abnormal conditions.

[0075] In other exemplary schemes, the transmission path in the initial task is obtained by parsing the initial task after the energy storage converter successfully verifies the first signature using the public key of the system control unit. The addition of the energy storage converter's verification information is achieved by the energy storage converter signing the updated transmission path, initial task, second timestamp, and second random verification code using its private key, generating a second signature, and then adding the second signature, second timestamp, and second random verification code to the initial task. The second timestamp and second random verification code are generated by the energy storage converter when it receives the initial task. This ensures the reliability of the task source received by the energy storage converter, prevents malicious task injection or data tampering, and improves the security and trustworthiness of the ring communication task.

[0076] Optionally, upon receiving the initial task, the energy storage converter first verifies the signature in the initial task using the public key of the system control unit. This ensures that the initial task indeed originates from a legitimate system control unit, preventing unauthorized nodes or attackers from forging tasks and injecting them into the system. Simultaneously, public key verification guarantees that the task content has not been tampered with during transmission, thus verifying data integrity and source credibility. This not only enhances the security of the communication link but also prevents downstream nodes (such as the energy storage converter and battery control unit) from continuing to execute operations based on erroneous or malicious tasks, reducing security risks during the operation of the energy storage system. After successful verification, the energy storage converter parses the initial task, updates the transmission path, and generates a new timestamp and random checksum to represent its processing time and uniqueness. Subsequently, it uses its own private key to sign the data containing the updated transmission path and original task information, generating a second signature. This signature, along with the newly generated timestamp and random checksum, is added to the task to form an intermediate task. This achieves identity authentication and integrity protection for the task by the energy storage converter, enabling subsequent battery control units to verify the legitimacy of the energy storage converter and the integrity of the task, ensuring the security and reliability of each node in the ring communication link.

[0077] The above embodiments, by adding the energy storage converter's signature on the transmission path, task content, timestamp, and random checksum in the initial task, not only verify the legitimacy of the initial task but also perform security updates and verifications on the task, forming an intermediate task and providing a reliable foundation for further processing by the battery control unit. This mechanism ensures the authentication and data integrity of each node in the ring communication link, significantly improving the communication security and anomaly protection capabilities of the energy storage system, thereby guaranteeing the safe operation of the energy storage cells.

[0078] As an example implementation, the transmission path in the intermediate task is obtained by parsing the intermediate task when the battery control unit successfully verifies the second signature using the public key of the energy storage converter.

[0079] Optionally, the battery control unit first verifies the second signature in the intermediate task using the public key of the energy storage converter to confirm that the task was indeed generated by the energy storage converter and that its content has not been tampered with. After successful verification, the intermediate task is parsed, and the transmission path information is extracted for subsequent processing. This ensures that the intermediate task received by the battery control unit is from a reliable source, prevents the intermediate task from being maliciously tampered with or forged, and thus improves the security of the ring communication link.

[0080] The addition of verification information to the battery control unit is achieved by the battery control unit using its private key to sign the updated transmission path, intermediate task, third timestamp, and third random verification code, generating a third signature, and then adding the third signature, third timestamp, and third random verification code to the intermediate task. The third timestamp and third random verification code are generated by the battery control unit when it receives the intermediate task.

[0081] Optionally, after parsing the intermediate task, the battery control unit generates a new timestamp and random checksum to represent its processing time and uniqueness. It then uses its own private key to sign the updated transmission path, intermediate task content, and the newly generated timestamp and random checksum, generating a third signature. This signature and the newly generated data are added to the intermediate task, forming the final task returned to the system control unit. This achieves task authentication and integrity protection by the battery control unit, enabling the system control unit to verify the legitimacy and integrity of the final task and ensuring the trustworthiness of each node in the ring communication link.

[0082] The above embodiments verify, parse, and sign intermediate tasks through the battery control unit, constructing a complete ring communication loop from the system control unit to the energy storage converter and then to the battery control unit, ensuring the identity and data integrity of each node. This mechanism realizes multi-layer verification and secure updates of the ring communication link, improving the reliability and tamper resistance of task transmission, thereby effectively ensuring the safe operation of the cells in the energy storage system and timely response to communication anomalies.

[0083] As an example implementation, Figure 4 This is a flowchart of another protection method for an energy storage device according to an embodiment of this application. The field transmitted from the system control unit to the energy storage converter is the first field, and the field transmitted from the energy storage converter to the battery control unit is the second field. The final task includes the first signature and first timestamp of the system control unit, the second signature and second timestamp of the energy storage converter, and the third signature and third timestamp of the battery control unit, as shown below. Figure 4 As shown, the final task verification process includes the following steps:

[0084] Step S401: Verify the integrity of the data in the final task using the first signature, the second signature, and the third signature;

[0085] Optionally, after receiving the final task, the system control unit uses the public keys of each node to verify the signature, ensuring that the task content has not been tampered with during transmission, including the path field, timestamp, and random checksum. This ensures the tamper-proof nature of data during transmission across the three nodes, improving the security and reliability of the communication link.

[0086] Step S402: Verify the correctness of the transmission path in the final task according to the order of the transmission path in the final task, the order of the generation of the second signature and the update of the first field, and the order of the generation of the third signature and the update of the second field.

[0087] Optionally, the system control unit verifies the order of the path fields in the task and the order in which each node's signature is generated. This ensures that the energy storage converter and battery control unit follow the correct order when updating the path fields, i.e., the first field is updated before the second signature is generated, and the second field is updated before the third signature is generated. This ensures that the task processing order and path update logic of each node are correct, preventing data order disorder or nodes not updating the task path as agreed, and improving the logical consistency of the ring communication link.

[0088] Step S403: Based on the time difference between the second timestamp and the first timestamp, determine whether the system control unit meets the time delay requirement; based on the time difference between the third timestamp and the second timestamp, determine whether the energy storage converter meets the time delay requirement; and based on the time difference between the fourth timestamp and the third timestamp, determine whether the battery control unit meets the time delay requirement.

[0089] Optionally, the system control unit calculates the difference between the second timestamp and the first timestamp to determine the processing delay of the energy storage converter, calculates the difference between the third timestamp and the second timestamp to determine the processing delay of the battery control unit, and calculates the difference between the final return time and the third timestamp to determine whether the final task return delay meets the system requirements. This enables real-time monitoring of the processing delays of the three nodes, ensuring timely communication and task processing responses, preventing excessive delays from causing safety risks to the energy storage cells, and improving system responsiveness and safety.

[0090] As an exemplary implementation, the method of this application further includes:

[0091] Periodic communication and detection are performed with the energy storage converter and the battery control unit through life frames;

[0092] Optionally, the system control unit periodically (e.g., once per second) sends life frame signals to the energy storage converter and battery control unit, with the two slave nodes responding within a specified time. The life frame contains key parameters and a timestamp, used to monitor the communication link's connectivity and the node's normal operation. Through periodic communication checks, the communication status between the three components can be monitored in real time, ensuring link reliability and identifying potential communication anomalies early.

[0093] In the event of an anomaly in communication detection, a shutdown protection operation for the energy storage device is triggered;

[0094] Optionally, if the system control unit does not receive a life frame response within a specified time, or if the response data is abnormal, a communication link fault is determined, and the energy storage device shutdown protection is immediately triggered, including closing dry contacts and prohibiting cell charging and discharging. This timely isolation of potential faults prevents overcharging, over-discharging, or other safety accidents of the energy storage cells due to communication abnormalities, thereby improving system operational safety.

[0095] Upon receiving the first feedback signal and with the energy storage device operating normally, a shutdown protection operation for the energy storage device is triggered. The first feedback signal is issued by the energy storage converter or the battery control unit when an abnormality is detected during the periodic communication detection between the energy storage converter and the battery control unit via life frames.

[0096] Optionally, when the energy storage converter or battery control unit detects an anomaly in the lifeframe communication between the two, it sends a feedback signal to the system control unit. Upon receiving this feedback signal, the system control unit will trigger a shutdown protection operation even if its own operating status is normal, thus forming a cross-node linkage protection mechanism. This ensures that even if the main control node does not detect an anomaly when the communication link is abnormal, it can still initiate shutdown protection through the feedback signal, achieving multi-node collaborative protection and improving the timeliness and comprehensiveness of fault handling.

[0097] In the above embodiments, a periodic communication detection mechanism is established between the system control unit, energy storage converter, and battery control unit through life frames. The system can monitor the communication status of each node in real time. Once a communication anomaly is detected, the shutdown protection operation of the energy storage device is immediately triggered. At the same time, the feedback signal sent by the energy storage converter to the battery control unit can further ensure cross-node linkage protection under abnormal conditions, enabling the energy storage cells to operate safely under the collaborative protection of multiple nodes, and significantly improving the reliability and safety of the energy storage system.

[0098] In practical applications, life frame detection is performed between each pair of the system control unit, energy storage converter, and battery control unit.

[0099] As an exemplary implementation, the method of this application further includes:

[0100] Upon receiving the second feedback signal from the energy storage converter, the control parameters are synchronized with the battery control unit. The second feedback signal is issued when the energy storage converter receives the first adjustment command for the predetermined control parameters from the system control unit and the second adjustment command for the predetermined control parameters from the battery control unit within a predetermined time period, and executes the target adjustment command. The adjustment value of the first adjustment command is different from the adjustment value of the second adjustment command, and the target adjustment command is the command with the smaller adjustment value between the first adjustment command and the second adjustment command.

[0101] Optionally, if the energy storage converter receives control parameter adjustment commands from the system control unit and the battery control unit within a predetermined time period, and the control parameters of the two adjustment commands are inconsistent, a second feedback signal will be generated. This signal is used to notify the system control unit and the battery control unit to synchronize the control parameters. After receiving the second feedback signal, the system control unit and the battery control unit will perform consistency processing on the control parameters. If the values ​​of the adjustment commands sent by the system control unit and the battery control unit differ, the energy storage converter will select the command with the smaller value as the target adjustment command for execution, thereby ensuring that the battery cells will not pose a safety risk due to excessively high control parameters.

[0102] The method described in this application establishes a multi-node collaborative mechanism among the energy storage converter, system control unit, and battery control unit to achieve real-time synchronization and conflict resolution of control parameters. Even when adjustment commands issued by different nodes differ, the method can select a safer target command to avoid overcharging or over-discharging of the cells, thus ensuring the safe operation and stability of the energy storage system. Simultaneously, this method improves the overall reliability of system control, reduces the potential risk of failure caused by command conflicts, and enhances the safety protection capability of the energy storage device under complex operating conditions.

[0103] As an exemplary implementation, the method of this application further includes at least one of the following steps:

[0104] If an anomaly is detected in the communication between the system control unit and the battery control unit, a command indicating that charge and discharge control is prohibited is sent to the energy storage converter to prevent the energy storage converter from controlling the charge and discharge of the energy storage device.

[0105] Optionally, when the system control unit detects an anomaly or interruption in the communication link with the battery control unit through the communication detection mechanism, the system control unit generates a control command indicating that charging and discharging are prohibited, and sends the command to the energy storage converter. Upon receiving the command, the energy storage converter immediately stops charging and discharging operations on the energy storage device, ensuring that the battery cells are not affected by abnormal control commands. This measure can quickly cut off charging and discharging operations when the communication link is abnormal, effectively preventing overcharging, over-discharging, or other safety hazards caused by abnormal control commands, and improving the operational safety of the energy storage system.

[0106] If an abnormal bus voltage is detected, a shutdown protection operation for the energy storage device is triggered.

[0107] Optionally, a bus voltage monitoring unit is installed in the energy storage system. When the bus voltage is detected to be higher or lower than a preset threshold, the abnormal signal will trigger the system control unit or energy storage converter to perform a shutdown protection operation, immediately interrupting the charging and discharging function of the energy storage device. This timely response to abnormal bus voltage prevents voltage fluctuations from damaging the energy storage cells or system equipment, ensuring the safe operation of the energy storage device and cells under abnormal voltage conditions.

[0108] According to some other exemplary embodiments of this application, triggering a shutdown protection operation for an energy storage device includes at least one of the following:

[0109] When the system control unit and the energy storage converter are communicating normally, a shutdown command is sent to the energy storage converter, so that the energy storage converter responds to the shutdown command and controls the energy storage device to shut down.

[0110] In the event of communication failure between the system control unit and the energy storage converter, but normal communication between the system control unit and the battery control unit, and normal communication between the battery control unit and the energy storage converter, a shutdown command is sent to the battery control unit, causing the battery control unit to forward the shutdown command to the energy storage converter, and the energy storage converter responds to the shutdown command to control the energy storage device to shut down.

[0111] A heartbeat signal is periodically sent to the energy storage converter, and the energy storage converter continues to control the operation of the energy storage device upon receiving the heartbeat signal.

[0112] If the final task is not received or the final task verification fails, the heartbeat signal will be stopped, so that if the energy storage converter does not receive the heartbeat signal within a predetermined time, the energy storage device will be automatically shut down.

[0113] Specifically, the life frame signal is transmitted using a cyclic accumulation method.

[0114] To enable those skilled in the art to better understand the technical solutions of this application, the communication process of the system control unit, battery control unit, and energy storage converter in the above embodiments of this application will be described in detail below with reference to specific examples.

[0115] This embodiment relates to a specific communication flow diagram of a system control unit, a battery control unit, and an energy storage converter, as shown below. Figure 5 As shown, the system control unit, battery control unit, and energy storage converter periodically exchange life frame signals. For example, the application software module inside the system control unit generates a life frame signal once per second to prove that it is in a healthy operating state. This life frame signal is transmitted through the power distribution system module, which sends life frame signals to the battery control unit and the energy storage converter respectively. The power distribution system module is responsible for receiving instructions from the application software module and reliably transmitting the life frame signal. The battery control unit sends life frame signals to the system control unit and the energy storage converter respectively, and the energy storage converter sends life frame signals to the system control unit and the battery control unit respectively. The life frame signal is transmitted in a cyclic accumulation manner to realize the communication status detection between the control units. When any control unit detects that the life frame signal of the other end has not accumulated as expected, it determines that the communication is abnormal and outputs a shutdown trigger signal through the emergency stop signal output port of the energy storage converter, so that the energy storage converter immediately performs the cell shutdown protection operation, thereby ensuring that the energy storage system can quickly enter the safety protection state in the event of communication abnormality.

[0116] See Figure 6 This embodiment provides a schematic diagram of the communication detection process between a system control unit, a battery control unit, and an energy storage converter. The following description uses the example of the system control unit sending a life frame signal to the battery control unit / energy storage converter. The confirmation process performed between any other two at the logic control layer (i.e., the upper logic interaction layer used to exchange control commands and status information) is the same as the principle of this example.

[0117] Step S1: The system control unit generates a life frame according to a preset period (e.g., every 1 second) and sends the life frame to the battery control unit / energy storage converter, and then proceeds to step S2;

[0118] Step S2: The battery control unit / energy storage converter determines whether a life frame has been received. If a life frame has been received, return to step S1 to continue execution; if the battery control unit determines that no life frame has been received within a preset time period (e.g., 5 seconds), proceed to step S3; if the energy storage converter determines that no life frame has been received within a preset time period (e.g., 5 seconds), proceed to step S41.

[0119] Step S41: The battery control unit sends a command to the energy storage converter to close the dry contact, causing the energy storage converter to close the dry contact.

[0120] Step S42: The dry contact of the energy storage converter is directly shut off;

[0121] Step S5: The battery cell stops charging and discharging, and the process ends.

[0122] In terms of communication architecture, the system control unit establishes communication connections with the energy storage converter and battery control unit through a switch, forming two independent communication links. Simultaneously, the energy storage converter and battery control unit directly exchange data via a CAN bus. All three periodically send heartbeat signals at the communication layer to detect link abnormalities. In the event of a failure in any link, the energy storage converter will be triggered to perform a cell shutdown protection operation to avoid potential system risks.

[0123] The above process is further illustrated by taking the example of the energy storage converter sending a heartbeat signal to the battery control unit. The communication detection process between any other two is the same in principle as this example.

[0124] The energy storage converter sends a heartbeat signal to the battery control unit at a preset cycle (e.g., every 1 second);

[0125] The battery control unit determines whether a heartbeat signal has been received within a specified time (e.g., 5 seconds). If a heartbeat signal is received, the battery control unit sends an acknowledgment signal to the energy storage inverter and the energy storage inverter sends a heartbeat signal back to the battery control unit at a preset cycle (e.g., every 1 second) to continue execution; if no heartbeat signal is received within the specified time, the battery control unit determines that a communication abnormality has occurred.

[0126] The energy storage converter further determines whether it has received an acknowledgment signal from the battery control unit. If no acknowledgment signal is received, the energy storage converter directly closes the dry contacts, prohibiting the charging and discharging of the battery cells; if an acknowledgment signal is received, the energy storage converter returns to the battery control unit and sends a heartbeat signal at a preset cycle (e.g., every 1 second) to continue execution.

[0127] Through the dual mechanism of logic control layer life frame detection and communication layer heartbeat detection, this embodiment can quickly trigger the shutdown protection operation of the energy storage converter when communication is abnormal, ensuring that the battery cells do not charge or discharge under abnormal conditions, thereby significantly improving the safety and stability of the energy storage system.

[0128] This embodiment provides a schematic diagram of a protection mechanism for an energy storage device. Its core lies in the communication and collaboration among the System Control Unit (SCU), Battery Control Unit (BCU), and Power Conversion System (PCS) to achieve cell safety protection and standardized testing procedures. Specifically, it includes the following:

[0129] The protection mechanisms of the energy storage converter include diagnostic and fault handling mechanisms. The diagnostic mechanisms include: total voltage over-detection, system control unit power limiting, and emergency stop dry contact input from the battery control unit. The fault handling mechanisms include: controlling the battery cells to enter constant voltage (CV) charging mode after detecting that the total voltage exceeds a threshold; limiting current based on the State of Power (SOP) sent by the Controller Area Network (CAN) bus; and controlling the battery cells to shut down upon receiving the emergency stop dry contact.

[0130] The system control unit's protection mechanisms include diagnostic and fault handling mechanisms. The diagnostic mechanisms include: process monitoring, detection of communication loss with the battery control unit, and detection of abnormal bus total voltage. The fault handling mechanisms include: limiting charging and discharging power; sending a command to the energy storage converter to disable charging and discharging; and sending a shutdown command to the energy storage converter.

[0131] The protection mechanisms of the battery control unit include diagnostic and fault handling mechanisms. The diagnostic mechanism includes: communication loss with the system control unit, system control unit lifeframe diagnosis, and diagnosis of abnormal individual cell voltages within the battery cluster. The fault handling mechanism includes: forwarding charge / discharge prohibition commands to the energy storage converter via the system control unit; issuing emergency stop dry contacts to the energy storage converter; and actively disconnecting the circuit breaker if the emergency stop of the energy storage converter fails.

[0132] The testing process specifications include diagnostic and fault handling mechanisms. The diagnostic mechanism includes: the software version release process, on-site personnel monitoring mechanisms, and the rationality of testing steps. The fault handling mechanism includes: not performing testing if the version number is incorrect; and immediate shutdown upon detection of abnormal startup by on-site personnel.

[0133] Furthermore, to enhance the robustness of protection, when the energy storage converter receives the same control parameter (e.g., charge / discharge power command) from both the system control unit and the battery control unit, if the parameter values ​​are inconsistent within a predetermined validity period, the energy storage converter selects the safe value as the execution basis. Specifically, when there are differences in power commands, the energy storage converter will prioritize executing the power command with the smaller value to avoid overcharging or over-discharging of the cells due to command deviations, thereby significantly improving the operational safety and reliability of the energy storage device.

[0134] This application also provides a protection device for an energy storage device. It should be noted that the protection device for the energy storage device in this application can be used to execute the protection method for the energy storage device provided in this application. This device is used to implement the above embodiments and preferred embodiments; details already described will not be repeated. As used below, the term "module" can refer to a combination of software and / or hardware that implements a predetermined function. Although the device described in the following embodiments is preferably implemented in software, hardware implementation, or a combination of software and hardware, is also possible and contemplated.

[0135] The protection device for the energy storage device provided in the embodiments of this application will be described below.

[0136] Figure 7 This is a schematic diagram of the structure of the protection device of the energy storage device according to an embodiment of this application. Figure 7 As shown, the device includes:

[0137] The generation module 10 is used to generate an initial task, which includes the transmission path of the task and the verification information of the system control unit.

[0138] The sending module 20 is used to send the initial task to the energy storage converter;

[0139] The determination module 30 is used to determine whether the final task sent by the battery control unit has been received. The final task is obtained by the battery control unit updating the transmission path in the intermediate task and adding the verification information of the battery control unit to the intermediate task when it receives the intermediate task sent by the energy storage converter. The transmission path in the final task includes the fields that have been transmitted from the energy storage converter to the battery control unit. The intermediate task is obtained by the energy storage converter updating the transmission path in the initial task and adding the verification information of the energy storage converter to the initial task when it receives the initial task. The transmission path in the intermediate task includes the fields that have been transmitted from the system control unit to the energy storage converter.

[0140] The processing module 40 is used to perform verification processing on the final task upon receiving it. The verification processing includes data integrity verification and the correctness verification of the transmission path in the final task.

[0141] Trigger module 50 is used to trigger a shutdown protection operation on the energy storage device if the final task is not received or the final task verification fails.

[0142] Through the protection device of the aforementioned energy storage device, a communication loop detection is established between the system control unit, the energy storage converter, and the battery control unit. The system control unit generates an initial task including verification information and transmission path, and sends it to the energy storage converter. When the communication between the three is normal, the initial task updates the transmission path and adds verification information to obtain an intermediate task via the energy storage converter. Then, the battery control unit updates the transmission path in the intermediate task and adds verification information to obtain the final task, which is then returned to the system control unit. The system control unit determines whether the loop communication is normal by detecting the data integrity and transmission path correctness in the final task. In case of abnormality, the shutdown protection of the energy storage cell is triggered, ensuring the safety of the energy storage cell and effectively improving the communication reliability and operational safety between the three, ensuring the safe and stable operation of the energy storage cell under complex operating conditions.

[0143] In some embodiments of the protection device for the energy storage device described above, the transmission path in the initial task includes: a first path field for transmission from the system control unit to the energy storage converter and a second path field for transmission from the energy storage converter to the battery control unit. The update of the transmission path in the initial task is achieved by the energy storage converter inserting a first preset identifier at a first predetermined position in the first path field, and the update of the transmission path in the intermediate task is achieved by the battery control unit inserting a second preset identifier at a second predetermined position in the second path field.

[0144] According to the protection device of the energy storage device described above, the transmission path in the initial task also includes: a third field that transmits from the system control unit. The update of the transmission path in the initial task is achieved by adding a first path field for transmission from the system control unit to the energy storage converter after the third field. The update of the transmission path in the intermediate task is achieved by adding a second path field for transmission from the energy storage converter to the battery control unit after the first path field.

[0145] As an example implementation, the generation module includes a data packet generation submodule and a signature generation submodule.

[0146] The data packet generation submodule is used to generate the transmission path, unique transaction identifier, first random checksum, and first timestamp corresponding to the initial task, so as to obtain the data packet;

[0147] The signature generation submodule is used to sign the data packet using the private key of the system control unit to generate a first signature, so as to obtain an initial task including the first signature and the data packet. The verification information of the initial task includes a unique transaction identifier, a first random check code, a first timestamp, and the first signature.

[0148] In some embodiments of the protection device of the energy storage device described above, the transmission path in the initial task is obtained by parsing the initial task when the energy storage converter successfully verifies the first signature using the public key of the system control unit.

[0149] The addition of verification information to the energy storage converter is achieved by the energy storage converter using its private key to sign the updated transmission path, initial task, second timestamp, and second random verification code, generating a second signature, and adding the second signature, second timestamp, and second random verification code to the initial task. The second timestamp and second random verification code are generated by the energy storage converter when it receives the initial task.

[0150] In some embodiments of the protection device of the energy storage device described above, the transmission path in the intermediate task is obtained by parsing the intermediate task when the battery control unit successfully verifies the second signature using the public key of the energy storage converter.

[0151] The addition of verification information to the battery control unit is achieved by the battery control unit using its private key to sign the updated transmission path, intermediate task, third timestamp, and third random verification code, generating a third signature, and then adding the third signature, third timestamp, and third random verification code to the intermediate task. The third timestamp and third random verification code are generated by the battery control unit when it receives the intermediate task.

[0152] As an example implementation, the field that has been transmitted from the system control unit to the energy storage converter is the first field, and the field that has been transmitted from the energy storage converter to the battery control unit is the second field. The final task includes the first signature and first timestamp of the system control unit, the second signature and second timestamp of the energy storage converter, and the third signature and third timestamp of the battery control unit. The processing module includes: an integrity verification submodule, a correctness verification submodule, and a delay determination submodule.

[0153] The integrity verification submodule is used to verify the integrity of the data in the final task using the first signature, the second signature, and the third signature.

[0154] The correctness verification submodule is used to verify the correctness of the transmission path in the final task based on the order of the transmission path in the final task, the order of the generation of the second signature and the update of the first field, and the order of the generation of the third signature and the update of the second field.

[0155] The delay determination submodule is used to determine whether the system control unit meets the delay requirement based on the time difference between the second time stamp and the first time stamp, to determine whether the energy storage converter meets the delay requirement based on the time difference between the third time stamp and the second time stamp, and to determine whether the battery control unit meets the delay requirement based on the time difference between the fourth time stamp and the third time stamp.

[0156] As an exemplary implementation, the apparatus of this application further includes: a detection module, a first protection module, and a second protection module.

[0157] The detection module is used to periodically communicate and detect the energy storage converter and the battery control unit through life frames.

[0158] The first protection module is used to trigger a shutdown protection operation for the energy storage device in the event of an abnormality in communication detection.

[0159] The second protection module is used to trigger a shutdown protection operation for the energy storage device when the first feedback signal is received and the energy storage device is operating normally. The first feedback signal is issued by the energy storage converter or the battery control unit when an abnormality is detected during the periodic communication detection between the energy storage converter and the battery control unit through life frames.

[0160] As an exemplary implementation, the apparatus of this application further includes a synchronization module.

[0161] The synchronization module is used to synchronize control parameters with the battery control unit upon receiving a second feedback signal from the energy storage converter. The second feedback signal is issued when the energy storage converter receives a first adjustment command for predetermined control parameters from the system control unit and a second adjustment command for predetermined control parameters from the battery control unit within a predetermined time period, and executes the target adjustment command. The adjustment value of the first adjustment command is different from the adjustment value of the second adjustment command, and the target adjustment command is the command with the smaller adjustment value between the first and second adjustment commands.

[0162] As an exemplary implementation, the apparatus of this application further includes: an exception sending module and a third protection module.

[0163] The anomaly sending module is used to send a command indicating that charging and discharging control is prohibited to the energy storage converter when an anomaly is detected in the communication between the system control unit and the battery control unit, so as to prohibit the energy storage converter from controlling the charging and discharging of the energy storage device.

[0164] The third protection module is used to trigger a shutdown protection operation for the energy storage device when an abnormal bus voltage is detected.

[0165] The protection device of the aforementioned energy storage device includes a processor and a memory. The generation module, transmission module, determination module, processing module, and triggering module are all stored as program units in the memory, and the processor executes the program units stored in the memory to achieve the corresponding functions. All of the above modules are located in the same processor; or, the above modules are located in different processors in any combination.

[0166] The processor contains a kernel, which retrieves the corresponding program units from memory. One or more kernels can be configured. By adjusting the kernel parameters, the problem in existing technologies—where the high coupling of different types of parameters in photovoltaic power generation system inverters makes it impossible to accurately obtain all the parameters of the inverter, thus hindering the stable operation of the photovoltaic power generation system—can be addressed.

[0167] The memory may include non-permanent memory in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM, and the memory includes at least one memory chip.

[0168] This invention provides an energy storage system, comprising:

[0169] Energy storage devices;

[0170] The system control unit is used to execute any of the above-mentioned protection methods for the energy storage device;

[0171] The energy storage converter is electrically connected to the energy storage device and electrically connected to the system control unit via Ethernet. Upon receiving the initial task, the energy storage converter updates the transmission path in the initial task and adds the verification information of the energy storage converter to the initial task to obtain the intermediate task. The transmission path in the intermediate task includes the field that has been transmitted from the system control unit to the energy storage converter.

[0172] The battery control unit communicates with the energy storage converter via a CAN bus and is electrically connected to the system control unit via an Ethernet. When the battery control unit receives an intermediate task sent by the energy storage converter, it updates the transmission path in the intermediate task and adds the verification information of the battery control unit to the intermediate task to obtain the final task. The transmission path in the final task includes the fields that have been transmitted from the energy storage converter to the battery control unit.

[0173] The aforementioned energy storage system includes an energy storage device, a system control unit, an energy storage converter, and a battery control unit that are interconnected in pairs. By implementing a protection method for the energy storage device, a communication loop detection is established between the system control unit, the energy storage converter, and the battery control unit. The system control unit generates an initial task including verification information and a transmission path and sends it to the energy storage converter. Under normal communication conditions, the initial task is updated by the energy storage converter, which adds verification information to obtain an intermediate task. The battery control unit then updates the transmission path in the intermediate task and adds verification information to obtain the final task, which is then returned to the system control unit. The system control unit checks the data integrity and transmission path correctness in the final task to determine whether the loop communication is normal. In case of an anomaly, the system control unit triggers the shutdown protection of the energy storage cell, ensuring the safety of the energy storage device and effectively improving the communication reliability and operational safety among the three components. This ensures the safe and stable operation of the energy storage system under complex operating conditions.

[0174] Optionally, the protection methods for the energy storage device include:

[0175] Step S201: Generate an initial task, which includes the task's transmission path and the system control unit's verification information;

[0176] Step S202: Send the initial task to the energy storage converter;

[0177] Step S203: Determine whether the final task sent by the battery control unit has been received. The final task is obtained by the battery control unit updating the transmission path in the intermediate task and adding the verification information of the battery control unit to the intermediate task when it receives the intermediate task sent by the energy storage converter. The transmission path in the final task includes the fields that have been transmitted from the energy storage converter to the battery control unit. The intermediate task is obtained by the energy storage converter updating the transmission path in the initial task and adding the verification information of the energy storage converter to the initial task when it receives the initial task. The transmission path in the intermediate task includes the fields that have been transmitted from the system control unit to the energy storage converter.

[0178] Step S204: Upon receiving the final task, perform verification processing on the final task. The verification processing includes data integrity verification and verification of the correctness of the transmission path in the final task.

[0179] Step S205: If the final task is not received or the final task verification fails, trigger the shutdown protection operation of the energy storage device.

[0180] This invention provides an electrical device, including a protection device for an energy storage device.

[0181] The aforementioned electrical equipment includes a protection device for the aforementioned energy storage device. This protection device establishes a communication loop detection between the system control unit, the energy storage converter, and the battery control unit. The system control unit generates an initial task including verification information and a transmission path, and sends it to the energy storage converter. When communication between the three is normal, the initial task updates the transmission path and adds verification information to obtain an intermediate task via the energy storage converter. Then, the battery control unit updates the transmission path in the intermediate task and adds verification information to obtain the final task, which is then returned to the system control unit. The system control unit determines whether the loop communication is normal by detecting the data integrity and transmission path correctness in the final task. In case of abnormality, it triggers the shutdown protection of the energy storage cell, ensuring the safety of the energy storage device, effectively improving the communication reliability and operational safety between the three, and ensuring the safe and stable operation of the energy storage system under complex operating conditions.

[0182] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0183] As can be seen from the above description, the embodiments of this application achieve the following technical effects:

[0184] The protection method for the energy storage device described in this application establishes a communication loop detection between the system control unit, the energy storage converter, and the battery control unit. The system control unit generates an initial task containing verification information and a transmission path and sends it to the energy storage converter. The energy storage converter updates the transmission path and adds verification information to form an intermediate task. The battery control unit then continues to update and add verification information to generate a final task, which is returned to the system control unit. The system control unit verifies the data integrity and transmission path correctness of the final task to determine if the communication between the three parties is normal. If the final task is not received or verification fails, a shutdown protection mechanism is triggered, thereby promptly detecting communication anomalies and improving the reliability of the energy storage system and the safety of the energy storage cells.

[0185] Those skilled in the art will understand that the above embodiments are specific examples of implementing this application, and in practical applications, various changes in form and detail can be made without departing from the spirit and scope of this application. Any person skilled in the art can make various alterations and modifications without departing from the spirit and scope of this application; therefore, the scope of protection of this application should be determined by the scope defined in the claims.

Claims

1. A protection method for an energy storage device, characterized in that, include: Generate an initial task, which includes the task's transmission path and the system control unit's verification information; Send the initial task to the energy storage converter; Determine whether a final task sent by the battery control unit has been received. The final task is obtained by the battery control unit updating the transmission path in the intermediate task and adding the verification information of the battery control unit to the intermediate task when it receives the intermediate task sent by the energy storage converter. The transmission path in the final task includes fields that have been transmitted from the energy storage converter to the battery control unit. The intermediate task is obtained by the energy storage converter updating the transmission path in the initial task and adding the verification information of the energy storage converter to the initial task when it receives the initial task. The transmission path in the intermediate task includes fields that have been transmitted from the system control unit to the energy storage converter. Upon receiving the final task, a verification process is performed on the final task, which includes data integrity verification and verification of the correctness of the transmission path in the final task. If the final task is not received or the final task verification fails, a shutdown protection operation is triggered on the energy storage device.

2. The protection method for the energy storage device according to claim 1, characterized in that, The transmission path in the initial task includes a first path field for transmission from the system control unit to the energy storage converter and a second path field for transmission from the energy storage converter to the battery control unit. The transmission path in the initial task is updated by the energy storage converter inserting a first preset identifier at a first predetermined position in the first path field. The transmission path in the intermediate task is updated by the battery control unit inserting a second preset identifier at a second predetermined position in the second path field.

3. The protection method for the energy storage device according to claim 1, characterized in that, The transmission path in the initial task includes a third field that starts from the system control unit. The update of the transmission path in the initial task is achieved by the energy storage converter adding a first path field for transmission from the system control unit to the energy storage converter after the third field. The update of the transmission path in the intermediate task is achieved by the battery control unit adding a second path field for transmission from the energy storage converter to the battery control unit after the first path field.

4. The protection method for the energy storage device according to claim 1, characterized in that, Generate the initial task, including: Generate the transmission path, unique transaction identifier, first random checksum, and first timestamp corresponding to the initial task to obtain the data packet; The data packet is signed using the private key of the system control unit to generate a first signature, thereby obtaining the initial task including the first signature and the data packet. The verification information of the initial task includes the unique transaction identifier, the first random checksum, the first timestamp, and the first signature.

5. The protection method for the energy storage device according to claim 4, characterized in that, The transmission path in the initial task is obtained by parsing the initial task when the energy storage converter successfully verifies the first signature using the public key of the system control unit. The addition of the verification information of the energy storage converter is achieved by the energy storage converter using its private key to sign the updated transmission path, the initial task, the second timestamp, and the second random verification code, generating a second signature, and adding the second signature, the second timestamp, and the second random verification code to the initial task. The second timestamp and the second random verification code are generated by the energy storage converter when it receives the initial task.

6. The protection method for the energy storage device according to claim 5, characterized in that, The transmission path in the intermediate task is obtained by parsing the intermediate task when the battery control unit successfully verifies the second signature using the public key of the energy storage converter. The addition of the verification information of the battery control unit is achieved by the battery control unit using its private key to sign the updated transmission path, the intermediate task, the third timestamp, and the third random verification code, generating a third signature, and adding the third signature, the third timestamp, and the third random verification code to the intermediate task. The third timestamp and the third random verification code are generated by the battery control unit when it receives the intermediate task.

7. The protection method for the energy storage device according to claim 1, characterized in that, The field that has been transmitted from the system control unit to the energy storage converter is the first field, and the field that has been transmitted from the energy storage converter to the battery control unit is the second field. The final task includes the first signature and first timestamp of the system control unit, the second signature and second timestamp of the energy storage converter, and the third signature and third timestamp of the battery control unit. The final task is verified, including: The integrity verification is performed on the data in the final task using the first signature, the second signature, and the third signature. The correctness of the transmission path in the final task is verified according to the order of the transmission path in the final task, the order of generation of the second signature and update of the first field, and the order of generation of the third signature and update of the second field. Based on the time difference between the second timestamp and the first timestamp, it is determined whether the system control unit meets the time delay requirement; based on the time difference between the third timestamp and the second timestamp, it is determined whether the energy storage converter meets the time delay requirement; and based on the time difference between the fourth time point and the third timestamp, it is determined whether the battery control unit meets the time delay requirement.

8. The protection method for the energy storage device according to claim 1, characterized in that, The protection method for the energy storage device also includes: Periodic communication checks are performed with the energy storage converter and the battery control unit via life frames; In the event of an anomaly in the communication detection, a shutdown protection operation for the energy storage device is triggered; Upon receiving the first feedback signal and with the energy storage device operating normally, a shutdown protection operation for the energy storage device is triggered. The first feedback signal is issued by the energy storage converter or the battery control unit when an abnormality is detected during the periodic communication detection between the energy storage converter and the battery control unit via the life frame.

9. The protection method for the energy storage device according to claim 1, characterized in that, The protection method for the energy storage device also includes: Upon receiving the second feedback signal from the energy storage converter, the energy storage converter synchronizes control parameters with the battery control unit. The second feedback signal is issued when the energy storage converter receives a first adjustment instruction for predetermined control parameters from the system control unit and a second adjustment instruction for predetermined control parameters from the battery control unit within a predetermined time period, and executes a target adjustment instruction. The adjustment value of the first adjustment instruction is different from the adjustment value of the second adjustment instruction, and the target adjustment instruction is the instruction with the smaller adjustment value between the first adjustment instruction and the second adjustment instruction.

10. The protection method for the energy storage device according to claim 1, characterized in that, The protection method for the energy storage device also includes at least one of the following: If an abnormality is detected in the communication detection between the system control unit and the battery control unit, a command indicating that charge and discharge control is prohibited is sent to the energy storage converter to prevent the energy storage converter from performing charge and discharge control on the energy storage device. If an abnormal bus voltage is detected, a shutdown protection operation is triggered on the energy storage device.

11. A protection device for an energy storage device, characterized in that, include: A generation module is used to generate an initial task, which includes the transmission path of the task and the verification information of the system control unit. The sending module is used to send the initial task to the energy storage converter; A determination module is used to determine whether a final task sent by the battery control unit has been received. The final task is obtained by the battery control unit updating the transmission path in the intermediate task and adding the verification information of the battery control unit to the intermediate task when it receives an intermediate task sent by the energy storage converter. The transmission path in the final task includes fields that have been transmitted from the energy storage converter to the battery control unit. The intermediate task is obtained by the energy storage converter updating the transmission path in the initial task and adding the verification information of the energy storage converter to the initial task when it receives the initial task. The transmission path in the intermediate task includes fields that have been transmitted from the system control unit to the energy storage converter. The processing module is used to perform verification processing on the final task upon receiving the final task. The verification processing includes data integrity verification and the correctness verification of the transmission path in the final task. The triggering module is used to trigger a shutdown protection operation on the energy storage device if the final task is not received or the final task verification fails.

12. An energy storage system, characterized in that, include: Energy storage devices; A system control unit is used to execute the protection method for the energy storage device according to any one of claims 1 to 10; An energy storage converter is electrically connected to the energy storage device and electrically connected to the system control unit via Ethernet. When the energy storage converter receives an initial task, it updates the transmission path in the initial task and adds the verification information of the energy storage converter to the initial task to obtain an intermediate task. The transmission path in the intermediate task includes fields that have been transmitted from the system control unit to the energy storage converter. The battery control unit is communicatively connected to the energy storage converter via a CAN bus and electrically connected to the system control unit via an Ethernet. When the battery control unit receives an intermediate task sent by the energy storage converter, it updates the transmission path in the intermediate task and adds the verification information of the battery control unit to the intermediate task to obtain the final task. The transmission path in the final task includes fields that have been transmitted from the energy storage converter to the battery control unit.

13. An electrical appliance, characterized in that, include: The protection device for the energy storage device as described in claim 11.

Citation Information

Patent Citations

  • Link communication method capable of responding to faults rapidly on basis of chained converter

    CN104092572A

  • High-reliability energy storage power station communication architecture and method thereof

    CN111641261A