Bypass control method and device and energy storage system

By employing a dual-processing unit collaborative control method in the energy storage system and using bypass commands with legality and consistency verification, the problem of unreliability in single-point control is solved, the reliability and accuracy of bypass control are improved, and the security of communication data is enhanced.

CN121508033APending Publication Date: 2026-02-10CONTEMPORARY AMPEREX FUTURE ENERGY RES INST (SHANGHAI) LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411071405.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-08-05
Publication Date
2026-02-10

AI Technical Summary

Technical Problem

In existing energy storage systems, the control function of the bypass switch suffers from single-point control unreliability, leading to unreliable control.

Method used

A dual-processing unit collaborative control method is adopted. The first processing unit generates a bypass command and verifies the legality and consistency of the bypass command of the second processing unit. After the verification is passed, the bypass switch is closed together to disconnect the energy storage submodule.

Benefits of technology

It improves the reliability and accuracy of bypass control, reduces erroneous execution caused by a single control link failure, and enhances the security of communication data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121508033A_ABST
    Figure CN121508033A_ABST
Patent Text Reader

Abstract

The invention discloses a bypass control method and device and an energy storage system. The bypass control method is applied to a first processing unit in at least two processing units of an energy storage sub-module. The method comprises the following steps: in response to a bypass event, generating a first bypass command of a first processing unit; performing verification processing on the obtained second bypass command; the second bypass command is generated by a second processing unit in the at least two processing units in response to the bypass event; and under the condition that the second bypass command passes the verification, closing the bypass switch based on the first bypass command so as to disconnect the energy storage sub-module.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of energy storage technology, and in particular to a bypass control method, device and energy storage system. Background Technology

[0002] With the advent of the smart grid era, energy storage technology has also developed rapidly, and its safety has received increasing attention. An energy storage system consists of multiple energy storage sub-modules, and the power module within these sub-modules undertakes crucial safety functions such as switching and bypassing. As a key component ensuring the normal operation of the energy storage system, the bypass switch control function within the power module must possess high reliability and safety.

[0003] In related technologies, to improve the reliability of the bypass switch's control function, redundant control circuits are added to the power module. These redundant control circuits or the main control circuit enable bypassing of the energy storage submodule. However, the problem with this approach is that both the redundant control circuit and the main control circuit are essentially single-link controls, resulting in unreliability due to single-point control limitations. Summary of the Invention

[0004] In view of this, embodiments of this application provide at least one bypass control method, apparatus, and energy storage system.

[0005] The technical solution of this application embodiment is implemented as follows:

[0006] In a first aspect, embodiments of this application provide a bypass control method, which is applied to a first processing unit among at least two processing units of an energy storage submodule; the method includes:

[0007] In response to a bypass event, a first bypass command is generated for the first processing unit;

[0008] The acquired second bypass command is verified; the second bypass command is generated by the second processing unit in response to the bypass event among at least two processing units.

[0009] If the second bypass command verification passes, the bypass switch is closed based on the first bypass command to disconnect the energy storage submodule.

[0010] In this embodiment, the first processing unit of the at least two processing units in the energy storage submodule can generate a first bypass command in response to a bypass event. Then, it verifies the second bypass command generated by the second processing unit in response to the bypass event. If the second bypass command passes verification, it closes the bypass switch based on the first bypass command to disconnect the energy storage submodule. This allows the first and second processing units to jointly perform bypass control, solving the problem of unreliable bypass control caused by a single control link in related technologies, thereby improving the reliability of bypass control.

[0011] In some embodiments, the second bypass command carries command verification information; the verification process for the acquired second bypass command includes: verifying the legality of the second bypass command based on the command verification information; verifying the consistency of the second bypass command based on the first bypass command; and, if the second bypass command passes verification, closing the bypass switch based on the first bypass command to disconnect the energy storage submodule, including: if the second bypass command is legal and consistent with the first bypass command, closing the bypass switch based on the first bypass command to disconnect the energy storage submodule.

[0012] In this embodiment, the legality of the second bypass command is verified based on command verification information; the consistency of the second bypass command is verified based on the first bypass command; if the second bypass command is legal and consistent with the first bypass command, the bypass switch is closed based on the first bypass command to disconnect the energy storage submodule. Thus, by verifying the legality of the second bypass command, the security of communication data between the first and second processing units can be improved. By verifying the consistency of the second bypass command, the first and second processing units can jointly execute the bypass action, thereby reducing the possibility of errors in bypass action execution due to the failure of a single processing unit when only one processing unit performs the bypass action, and thus improving the reliability and accuracy of bypass control.

[0013] In some embodiments, the command verification information includes at least one of the following: command sequence number information, command time information, type information, and checksum information; based on the command verification information, the legality verification of the second bypass command includes at least one of the following: based on the command sequence number information, the second bypass command is checked for orderliness; based on the command time information, the second bypass command is checked for timing; based on the type information, the second bypass command is checked for authenticity; based on the checksum information, the second bypass command is checked for integrity.

[0014] In this embodiment, the first processing unit can perform at least one of the following verification methods on the second bypass command: order verification, timing verification, authenticity verification, and integrity verification, using command verification information. This improves the security of communication data between the first and second processing units by verifying the second bypass command of the second processing unit.

[0015] In some embodiments, the method further includes: sending a first bypass command to a second processing unit; wherein the second processing unit is configured to perform verification processing on the first bypass command; and if the first bypass command passes verification, closing a bypass switch based on the second bypass command to disconnect the energy storage submodule.

[0016] In this embodiment, the first processing unit and the second processing unit can jointly perform bypass control, which solves the problem of unreliable bypass control caused by using a single control link in related technologies, thereby improving the reliability of bypass control.

[0017] In some embodiments, the energy storage submodule further includes a bypass switch and at least two drive units corresponding one-to-one with at least two processing units; closing the bypass switch based on a first bypass command to disconnect the energy storage submodule includes: closing the bypass switch based on a first bypass command through the drive unit corresponding to the first processing unit to disconnect the energy storage submodule.

[0018] In this embodiment, the processing unit can close the bypass switch based on a first bypass command using its corresponding drive unit to disconnect the energy storage submodule. This allows the bypass switch to be closed via a relatively independent drive unit, reducing interference from other units when the drive unit performs the action of closing the bypass switch, thereby improving the reliability of bypass control.

[0019] In some embodiments, the bypass control method further includes: determining a first switching state of the bypass switch by a drive unit corresponding to the first processing unit; receiving a second switching state of the bypass switch sent by the second processing unit; the second switching state being acquired by the drive unit corresponding to the second processing unit; performing verification processing on the second switching state of the bypass switch; and sending the first switching state to the energy storage controller if the second switching state verification passes.

[0020] In this embodiment of the application, by verifying the second switch state of the bypass switch acquired by the drive unit corresponding to the second processing unit, the bypass result of the second processing unit can be verified, thereby improving the reliability of the bypass control.

[0021] Secondly, embodiments of this application provide a bypass control device, which includes at least two processing units; each pair of the at least two processing units is connected.

[0022] A first processing unit among at least two processing units is configured to generate a first bypass command in response to a bypass event; perform verification processing on the acquired second bypass command; the second bypass command is generated by the second processing unit among at least two processing units in response to the bypass event; if the second bypass command passes verification, close the bypass switch based on the first bypass command to bypass the energy storage submodule including the bypass control device.

[0023] In some embodiments, a first processing unit, a first driving unit, and a bypass switch form a first control link; a second processing unit, a second driving unit, and a bypass switch form a second control link; wherein, a battery module in an energy storage submodule is used to power the first control link; and a battery module in another energy storage submodule adjacent to the energy storage submodule is used to power the second control link.

[0024] In this embodiment, two different control links are established through different processing units and bypass switches, and these two different control links are powered by different battery modules. This creates two physically independent bypass control links, thereby improving the reliability of bypass control.

[0025] In some embodiments, the first processing unit and the second processing unit differ from each other in at least one of the following: the type of the processing unit, the operating system of the processing unit, and the compilation method of the code in the processing unit.

[0026] In this embodiment of the application, by setting two processing units in the bypass control device that differ in at least one of the following: the type of the processing unit, the operating system of the processing unit, and the compilation method of the code in the processing unit, the risk of common-mode failure of the two processing units can be reduced, thereby improving the reliability of the bypass control.

[0027] Thirdly, embodiments of this application provide an energy storage system, which includes multiple energy storage sub-modules, each of which includes the aforementioned bypass control device.

[0028] It should be understood that the above general description and the following detailed description are merely exemplary and explanatory, and are not intended to limit the technical solutions of this application. Attached Figure Description

[0029] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with this application and, together with the specification, serve to explain the technical solutions of this application.

[0030] Figure 1 A schematic diagram of the implementation process of a bypass control method provided in this application embodiment. Figure 1 ;

[0031] Figure 2 A schematic diagram of the implementation process of a bypass control method provided in this application embodiment. Figure 2 ;

[0032] Figure 3 A schematic diagram of the implementation process of a bypass control method provided in this application embodiment. Figure 3 ;

[0033] Figure 4 A schematic diagram of the implementation process of a bypass control method provided in this application embodiment. Figure 4 ;

[0034] Figure 5 A schematic diagram of the composition structure of an energy storage system provided in this application embodiment. Figure 1 ;

[0035] Figure 6 A schematic diagram of the composition structure of a bypass control device provided in this application embodiment. Figure 1 ;

[0036] Figure 7 A schematic diagram of the composition structure of a bypass control device provided in this application embodiment. Figure 2 ;

[0037] Figure 8 A schematic diagram of the composition structure of an energy storage system provided in this application embodiment. Figure 2 ;

[0038] Figure 9 A schematic diagram of the composition structure of an energy storage system provided in this application embodiment. Figure 3 . Detailed Implementation

[0039] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions of this application are further described in detail below with reference to the accompanying drawings and embodiments. The described embodiments should not be regarded as limitations on this application. All other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0040] In the following description, references are made to “some embodiments,” which describe a subset of all possible embodiments. However, it is understood that “some embodiments” may be the same subset or different subsets of all possible embodiments and may be combined with each other without conflict.

[0041] The terms “first / second / third” are used merely to distinguish similar objects and do not represent a specific ordering of objects. It is understood that “first / second / third” may be interchanged in a specific order or sequence where permitted, so that the embodiments of this application described herein can be implemented in an order other than that illustrated or described herein.

[0042] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application pertains. The terminology used herein is for descriptive purposes only and is not intended to limit the scope of this application.

[0043] Currently, with the advent of the smart grid era, energy storage technology has also developed rapidly, and its safety has received increasing attention. A DC direct-connected energy storage valve consists of multiple energy storage sub-modules and an energy storage valve control module. These sub-modules include a power module and a battery module. The power module, as a crucial component of the energy storage sub-modules, is responsible for safety control and status interaction with the energy storage valve control module, battery module, and other modules.

[0044] The power modules in the DC direct-connected energy storage valve are equipped with bypass switches. When a power module fails, closing the bypass switch will bypass the energy storage sub-modules of the failed power module, causing the energy storage sub-module to take off. This can reduce the risk of danger spreading to other energy storage sub-modules, thereby ensuring the safety of the energy storage system.

[0045] As a crucial component in ensuring the normal operation of an energy storage system, the bypass switch's control function must possess high reliability and safety. Ensuring the correctness of control commands and the reliability of control results are important reference indicators for guaranteeing its functional safety.

[0046] In related technologies, redundant control circuits are added to the power module. This allows the energy storage submodule to be disconnected even if the main control circuit in the power module fails. However, both the redundant control circuit and the main control circuit are essentially single-link control systems, which suffer from the unreliability of single-point control.

[0047] To address the aforementioned technical problems, this application provides a bypass control method, which can be applied to a first processing unit among at least two processing units of an energy storage submodule. The first processing unit can be any of the at least two processing units. In this application embodiment, the aforementioned energy storage submodule can be any energy storage submodule within an energy storage system. For example, the energy storage system can be a DC-connected energy storage valve.

[0048] Figure 1 A schematic diagram of the implementation process of a bypass control method provided in this application embodiment. Figure 1 ,like Figure 1 As shown, this bypass control method can be implemented through steps S101 to S103:

[0049] Step S101: In response to the bypass event, generate a first bypass command for the first processing unit.

[0050] Here, a bypass event is an event triggered by a failure in the energy storage submodule. In other words, when an energy storage submodule fails, to reduce the likelihood of the failure spreading to other energy storage submodules in the energy storage system, a bypass event needs to be generated. This allows the processing unit in the energy storage submodule to respond to the bypass event and execute the bypass control method provided in this embodiment, thereby bypassing the failed energy storage submodule. The entity generating the bypass event can be a power module including a first processing unit within the energy storage submodule, or it can be a higher-level module of the energy storage submodule. For example, the higher-level module of the energy storage submodule can be the energy storage controller of the energy storage system. In the case of a DC-connected energy storage valve in the energy storage system, this energy storage controller can be an energy storage valve controller.

[0051] In some embodiments, when the entity generating the bypass event is the energy storage controller of the energy storage system, step S101 may include: generating a first bypass command for the first processing unit in response to a bypass request sent by the energy storage controller to the first processing unit.

[0052] Here, when the energy storage controller determines that multiple energy storage submodules in the energy storage system are abnormal, it can send a bypass request to the first processing unit in the abnormal energy storage submodule to bypass the energy storage submodule.

[0053] Step S102: Verify the acquired second bypass command; the second bypass command is generated by the second processing unit among at least two processing units in response to the bypass event.

[0054] In step S103, if the second bypass command verification passes, the bypass switch is closed based on the first bypass command to disconnect the energy storage submodule.

[0055] In this embodiment, the second processing unit in the energy storage submodule also responds to the bypass event, generates a second bypass command for the second processing unit, and sends the second bypass command to the first processing unit. The second processing unit can be any processing unit in the energy storage submodule other than the first processing unit. The second bypass command has the same function: to close the bypass switch to disconnect the energy storage submodule.

[0056] It is understandable that the redundant control circuit and main control circuit in related technologies are essentially single-link control. That is, when the main control circuit is normal, the bypass action is achieved through the main control circuit; when the main control circuit malfunctions, the bypass action is achieved through the redundant control circuit. In other words, the redundant control circuit and main control circuit in related technologies do not interact when performing bypass actions; they are both single-point control. This reduces the reliability of bypass control. Therefore, in this application, when it is necessary to disconnect the energy storage submodule, both the first processing unit and the second processing unit in the energy storage submodule will generate corresponding bypass commands. To improve the reliability of bypass control, different processing units will mutually verify each other's bypass commands. If the other party's bypass command verification passes, the bypass switch will be closed based on its own generated bypass command to disconnect the energy storage submodule.

[0057] In this embodiment, the verification process performed on the acquired second bypass command may include at least one of the following: validity verification and consistency verification. It is understood that validity verification determines whether the second bypass command is valid, while consistency verification determines whether the second bypass command generated by the second processing unit is consistent with the first bypass command generated by the first processing unit. Since both the second and first processing units generate bypass commands in response to the same bypass event, their bypass commands should be consistent. Wherein, when the verification process includes both validity verification and consistency verification, consistency verification can be performed if the validity verification of the second bypass command passes.

[0058] In some embodiments, after the first processing unit generates the first bypass command, the first bypass command can be sent to the second processing unit. The second processing unit can perform the above-mentioned verification process on the first bypass command, and if the first bypass command passes the verification, it can close the bypass switch based on the second bypass command to disconnect the energy storage submodule.

[0059] In this embodiment, the first processing unit of the at least two processing units in the energy storage submodule can generate a first bypass command in response to a bypass event. Then, it verifies the second bypass command generated by the second processing unit in response to the bypass event. If the second bypass command passes verification, it closes the bypass switch based on the first bypass command to disconnect the energy storage submodule. This allows the first and second processing units to jointly perform bypass control, solving the problem of unreliable bypass control caused by a single control link in related technologies, thereby improving the reliability of bypass control.

[0060] In some embodiments, the second bypass command carries command verification information, such as... Figure 2As shown, step S102 can be implemented through steps S201 and S202, and correspondingly, step S103 can be implemented through step S203:

[0061] Step S201: Based on the command verification information, perform a validity check on the second bypass command.

[0062] Here, the command verification information is used to characterize the attribute information of the second bypass command. This command verification information may include at least one of the following: command sequence number information, command time information, type information, and checksum information.

[0063] In some embodiments, when the command verification information includes command sequence number information, the above step S201 can be implemented by step S2011:

[0064] Step S2011: Based on the command sequence number information, perform an order verification on the second bypass command.

[0065] It is understandable that when the processing unit generates different bypass commands, it will simultaneously generate command sequence number information corresponding to the bypass command. This command sequence number information is generated according to the time when the bypass command is generated. For example, if the processing unit generates bypass command 1 at time 1 and bypass command 2 at time 2, and if time 2 is later than time 1, then the command sequence number information of bypass command 1 can be 1, and the command sequence number information of bypass command 2 can be 2.

[0066] In this embodiment, the first processing unit stores the historical bypass commands of the second processing unit and the corresponding historical command sequence number information. Based on the historical command sequence number information and the current command sequence number information, the second bypass command can be checked for orderliness. If the current command sequence number is the preceding sequence number of the largest command sequence number in the historical command sequence number information, the second bypass command orderliness check passes. For example, if the largest command sequence number in the historical command sequence number information of the second processing unit is 4, and the command sequence number information of the second bypass command is 5, then the second bypass command orderliness check passes.

[0067] In some embodiments, when the command verification information includes command time information, the above step S201 can be implemented by step S2012:

[0068] Step S2012: Based on the command time information, perform timing verification on the second bypass command.

[0069] Here, the command timing information can be the timestamp when the second processing unit generates the second bypass command. If the command timing information is within a preset time range, the timing verification of the second bypass command passes.

[0070] Understandably, when a bypass event is generated, it indicates that the current energy storage submodule has failed. In this case, the submodule needs to be disconnected as soon as possible to reduce the risk of the failure spreading to other submodules in the energy storage system. Therefore, the timestamp when the second processing unit generates the second bypass command needs to be within a preset time range. This preset time range characterizes the response time to the bypass event.

[0071] In some embodiments, when the command verification information includes type information, the above step S201 can be implemented by step S2013:

[0072] Step S2013: Based on the type information, verify the authenticity of the second bypass command.

[0073] It is understandable that the processing unit can generate different types of messages, and the bypass command is a type of message. Therefore, it is necessary to determine whether the type information carried by the second bypass command is the same as the type of the second bypass command itself.

[0074] In this embodiment of the application, if the type information carried by the second bypass command is different from the type of the second bypass command itself, the authenticity verification of the second bypass command is determined to fail; if the type information carried by the second bypass command is the same as the type of the second bypass command itself, the authenticity verification of the second bypass command is determined to pass.

[0075] For example, the messages that the processing unit can generate may include heartbeat messages, configuration messages and control messages. The type information of the heartbeat message is type information 1, the type information of the configuration message is type information 2, and the type information of the control message is type information 3. If the type information carried by the second bypass command is not type information 3, the authenticity verification of the second bypass command will fail.

[0076] In some embodiments, when the command verification information includes verification code information, the above step S201 can be implemented by step S2014:

[0077] Step S2014: Perform integrity verification on the second bypass command based on the check code information.

[0078] In this embodiment, the checksum information is obtained by the second processing unit processing the second bypass command using a preset integrity check algorithm. The first processing unit can process the second bypass command using the same integrity check algorithm, and compare the processed checksum information with the checksum information carried by the second bypass command to determine the integrity check result of the second bypass command. For example, the preset integrity check algorithm may include, but is not limited to, Cyclic Redundancy Check (CRC) and MD5 Message-Digest Algorithm.

[0079] In some embodiments, if any of the checks performed on the second bypass command—orderliness check, timing check, authenticity check, and integrity check—fail, the first processing unit may control the energy storage submodule to be in a safe state.

[0080] In some embodiments, after the first processing unit sends a first bypass command to the second processing unit, the second processing unit may also perform at least one of the following verification methods on the first bypass command: order verification, timing verification, authenticity verification, and integrity verification.

[0081] In this embodiment, the first processing unit can perform at least one of the following verification methods on the second bypass command: order verification, timing verification, authenticity verification, and integrity verification, using command verification information. This improves the security of communication data between the first and second processing units by verifying the second bypass command of the second processing unit.

[0082] Step S202: Based on the first bypass command, perform a consistency check on the second bypass command.

[0083] In this embodiment of the application, the first processing unit may perform a consistency check on the second bypass command if it determines that the second bypass command is valid.

[0084] In this embodiment of the application, if the first bypass command and the second bypass command are consistent, it is determined that the consistency check of the second bypass command has passed; if the first bypass command and the second bypass command are inconsistent, it is determined that the consistency check of the second bypass command has failed.

[0085] It is understandable that both the first and second bypass commands are generated in response to bypass events, so they should be consistent. If the first and second bypass commands are inconsistent, it indicates that either the first or second processing unit is in an abnormal state. In this case, the first processing unit can control the energy storage submodule to a safe state.

[0086] In some embodiments, after generating the second bypass command, the second processing unit may encode the second bypass command and then send the encoded second bypass command to the first processing unit. The first processing unit may decode the encoded second bypass command to obtain the second bypass command and then perform a consistency check on the second bypass command. Similarly, the first processing unit may also encode the first bypass command and then send the encoded first bypass command to the second processing unit. The second processing unit may decode the encoded first bypass command to obtain the first bypass command and finally perform a consistency check on the first bypass command.

[0087] In some embodiments, when the encoding process is an XOR operation, the second processing unit may XOR each bit of the second bypass command using the first key, and then send the XOR-processed second bypass command to the first processing unit. Upon receiving the XOR-processed second bypass command, the first processing unit may XOR each bit of the XOR-processed second bypass command using the first key to obtain the second bypass command. Similarly, the first processing unit may XOR each bit of the first bypass command using the second key, and then send the XOR-processed first bypass command to the second processing unit. Upon receiving the XOR-processed first bypass command, the second processing unit may XOR each bit of the XOR-processed first bypass command using the second key to obtain the first bypass command. The first key and the second key are different. For example, the first key may be 0xA5A5A5A5, and the second key may be 0x5A5A5A5A.

[0088] In step S203, if the second bypass command is valid and consistent with the first bypass command, the bypass switch is closed based on the first bypass command to disconnect the energy storage submodule.

[0089] In this embodiment of the application, when the second bypass command is valid, it means that the validity check of the second bypass command has passed. When the second bypass command is consistent with the first bypass command, it means that the consistency check of the second bypass command has passed. At this time, the first processing unit can close the bypass switch through the first bypass command to disconnect the energy storage submodule.

[0090] In this embodiment, the legality of the second bypass command is verified based on command verification information; the consistency of the second bypass command is verified based on the first bypass command; if the second bypass command is legal and consistent with the first bypass command, the bypass switch is closed based on the first bypass command to disconnect the energy storage submodule. Thus, by verifying the legality of the second bypass command, the security of communication data between the first and second processing units can be improved. By verifying the consistency of the second bypass command, the first and second processing units can jointly execute the bypass action, thereby reducing the possibility of errors in bypass action execution due to the failure of a single processing unit when only one processing unit performs the bypass action, and thus improving the reliability and accuracy of bypass control.

[0091] In some embodiments, the energy storage submodule further includes a bypass switch and at least two drive units corresponding one-to-one with at least two processing units; such as Figure 3 As shown, step S103 above can also be achieved through step S301:

[0092] In step S301, if the second bypass command verification passes, the bypass switch is closed based on the first bypass command by the drive unit corresponding to the first processing unit to disconnect the energy storage submodule.

[0093] In this embodiment of the application, when the driving unit includes a driving chip, the first processing unit can send a first bypass command to the driving chip of the driving unit corresponding to the first processing unit, and the driving chip can close the bypass switch in response to the first bypass command.

[0094] In some embodiments, when the driving unit does not contain a driving chip, the first bypass command generated by the first processing unit is an electrical signal. In this case, the first processing unit can transmit the electrical signal to the driving unit, and the driving unit closes the bypass switch in response to the first bypass command.

[0095] In some embodiments, if the first bypass command verification passes, the bypass switch is closed based on the second bypass command by the drive unit corresponding to the second processing unit to disconnect the energy storage submodule.

[0096] In this embodiment, the processing unit can close the bypass switch based on a first bypass command using its corresponding drive unit to disconnect the energy storage submodule. This allows the bypass switch to be closed via a relatively independent drive unit, reducing interference from other units when the drive unit performs the action of closing the bypass switch, thereby improving the reliability of bypass control.

[0097] In some embodiments, such as Figure 4As shown, the above method can also be implemented through steps S401 to S404:

[0098] Step S401: Determine the first switching state of the bypass switch through the drive unit corresponding to the first processing unit.

[0099] In this embodiment of the application, steps S401 to S404 can be performed after step S301 above, that is, to verify the bypass result of the first bypass command in order to determine whether the energy storage submodule has been successfully disconnected.

[0100] In some embodiments, steps S401 to S404 may be performed before step S101 described above. In this case, steps S401 to S404 are performed to determine the current switching state of the bypass switch.

[0101] In this embodiment of the application, when the driving unit includes a data acquisition chip, the first processing unit can send a data acquisition command to the data acquisition chip in the driving unit corresponding to the first processing unit. Then, the data acquisition chip responds to the data acquisition command, acquires the first switching state of the bypass switch, and sends the first switching state to the first processing unit.

[0102] In some embodiments, where the driving unit does not include a data acquisition chip, the first processing unit can transmit a data acquisition electrical signal to the driving unit, and then the driving unit can transmit the first switching state to the first processing unit after acquiring the first switching state of the bypass unit.

[0103] In some embodiments, the second processing unit may also determine the second switching state of the bypass switch through a driving unit corresponding to the second processing unit. The method by which the second processing unit determines the second switching state through the driving unit may be the same as the method by which the first processing unit determines the first switching state through the driving unit.

[0104] Step S402: Receive the second switch state of the bypass switch sent by the second processing unit; the second switch state is acquired by the drive unit corresponding to the second processing unit.

[0105] In this embodiment of the application, the timing at which the driving unit corresponding to the second processing unit collects the second switching state of the bypass switch is the same as the timing at which the driving unit corresponding to the first processing unit collects the first switching state of the bypass switch.

[0106] It is understood that the second switch state sent by the second processing unit in this embodiment of the application is to verify whether the first switch state is correct. Therefore, the first switch state and the second switch state need to be the switch states of the bypass switch at the same time.

[0107] Step S403: Verify the second switch status of the bypass switch.

[0108] In this embodiment, the second switch state carries state verification information. The first processing unit can perform legality verification on the second bypass command based on the state verification information; and perform consistency verification on the second switch state based on the first switch state. The legality verification includes at least one of the following: order verification, timing verification, authenticity verification, and integrity verification. In this embodiment, the steps of the first processing unit performing legality verification and consistency verification on the second switch state can be referred to the steps of the first processing unit verifying the second bypass command in the above embodiments.

[0109] In some embodiments, the second processing unit may encode the second switch state and then send the encoded second switch state to the first processing unit; the first processing unit may decode the encoded second switch state to obtain the second switch state. Similarly, the first processing unit may encode the first switch state and then send the encoded first switch state to the second processing unit; the second processing unit may decode the encoded first switch state to obtain the first switch state. The encoding and decoding of the switch state can be found in the steps described above regarding the encoding and decoding of bypass commands.

[0110] Step S404: If the second switch status verification passes, send the first switch status to the energy storage controller.

[0111] In this embodiment of the application, when the second switch state verification passes, it indicates that the first switch state is correct, and at this time the first switch state can be sent to the energy storage controller.

[0112] In this embodiment, if steps S401 to S404 are performed after step S301, when the second switch state verification passes and the first switch state indicates that the bypass switch is closed, the bypass result of the first bypass command is successful, meaning the energy storage submodule is disconnected. At this time, the first processing unit can send the first switch state to the energy storage controller to report the successful bypass result of the energy storage submodule. When the second switch state verification passes and the first switch state indicates that the bypass switch is open, the bypass result of the first bypass command is unsuccessful, meaning the energy storage submodule is not bypassed. At this time, the first processing unit can send the first switch state to the energy storage controller to report the failed bypass result of the energy storage submodule. The energy storage controller can then send a bypass request to both the first and second processing units to control them to bypass the energy storage submodule again.

[0113] In this embodiment of the application, by verifying the second switch state of the bypass switch acquired by the drive unit corresponding to the second processing unit, the bypass result of the second processing unit can be verified, thereby improving the reliability of the bypass control.

[0114] In some embodiments, after determining the first switching state of the bypass switch, the first processing unit can send the first switching state of the bypass switch to the second processing unit. The second processing unit can perform verification processing on the first switching state of the bypass switch; if the first switching state verification passes, it sends a second switching state to the energy storage controller. The step of the second processing unit verifying the first switching state can be referred to the step of the first processing unit verifying the second bypass command in the above embodiments.

[0115] In this embodiment of the application, by verifying the first switch state of the bypass switch acquired by the drive unit corresponding to the first processing unit, the bypass result of the first processing unit can be verified, thereby improving the reliability of the bypass control.

[0116] In some embodiments, such as Figure 5 As shown, the energy storage system includes an energy storage valve controller 501 and multiple energy storage sub-modules (not shown in the figure). Each energy storage sub-module includes a power module controller 502, a bypass switch driver board 503, and a bypass switch 504. The power module controller 502 includes a first processing unit 5021 and a second processing unit 5022. The bypass switch driver board 503 includes a first drive-sampling module 5031 (equivalent to the drive unit in the above embodiment) and a second drive-sampling module 5032 (equivalent to the drive unit in the above embodiment). The energy storage valve controller 501 is connected to the first processing unit 5021 and the second processing unit 5022, respectively, and the first processing unit 5021 and the second processing unit 5022 are interconnected. The first processing unit 5021 is connected to the first drive-sampling module 5031, and the second processing unit 5022 is connected to the second drive-sampling module 5032. The bypass switch 504 is connected to the first drive-sampling module 5031 and the second drive-sampling module 5032, respectively.

[0117] based on Figure 5 This application also provides a bypass control method, which is implemented through the following steps:

[0118] In step S501, the first processing unit 5021 and the second processing unit 5022 respectively receive bypass requests sent by the energy storage valve controller 501.

[0119] In step S502, the first processing unit 5021 performs security encoding on the bypass request control command and adds verification information, and sends it to the second processing unit 5022; the second processing unit 5022 performs security encoding on the bypass request control command and adds verification information, and sends it to the first processing unit 5021.

[0120] In this embodiment, the first processing unit 5021 and the second processing unit 5022 perform the same security encoding and verification information addition processing on the bypass request control command. The implementation of step S502 is explained below using the first processing unit 5021 performing security encoding and adding verification information on the bypass request control command as an example:

[0121] In step S5021, the first processing unit 5021 encodes the bypass request control command.

[0122] For example, the first processing unit 5021 can perform an XOR operation on the bypass request control command and 0xA5A5A5A5. The second processing unit 5022 can perform an XOR operation on the bypass request control command and 0x5A5A5A5A.

[0123] In step S5022, the first processing unit 5021 adds verification information to the coded bypass request control command.

[0124] For example, the verification information can be added using at least one of the CRC algorithm and the MD5 algorithm.

[0125] In step S503, the first processing unit 5021 performs a security verification on the bypass request control command sent by the second processing unit 5022; the second processing unit 5022 performs a security verification on the bypass request control command sent by the first processing unit 5021.

[0126] In this embodiment, if the security verification of the bypass request control command fails, the energy storage submodule is controlled to be in a safe state.

[0127] In this embodiment, the first processing unit 5021 and the second processing unit 5022 perform security verification on the bypass request control command in the same way. The implementation of step S503 is explained below using the first processing unit 5021 performing security verification on the bypass request control command as an example:

[0128] In step S5031, the first processing unit 5021 determines the orderliness of the bypass request control command and prohibits the use of duplicate messages.

[0129] In step S5032, the first processing unit 5021 determines the timing of the bypass request control command and prohibits the use of expired messages.

[0130] In step S5033, the first processing unit 5021 determines the authenticity of the bypass request control command and prohibits the use of unauthorized messages.

[0131] In step S5034, the first processing unit 5021 determines the integrity of the bypass request control command based on the verification information and prohibits the use of corrupted messages.

[0132] In step S504, if the bypass request control command sent by the second processing unit 5022 passes the security verification, the first processing unit 5021 decodes the bypass control command and performs a consistency verification; if the bypass request control command sent by the first processing unit 5021 passes the security verification, the second processing unit 5022 decodes the bypass control command and performs a consistency verification.

[0133] In this embodiment, the first processing unit 5021 and the second processing unit 5022 decode the bypass request control command and perform consistency verification in the same way. The implementation of step S504 is explained below using the first processing unit 5021 decoding the bypass request control command and performing consistency verification as an example:

[0134] In step S5041, the first processing unit 5021 decodes the bypass request control command.

[0135] Here, the first processing unit 5021 can use 0xA5A5A5A5 to perform XOR processing on the bypass request control command.

[0136] Step S5042: Determine whether the bypass request control command sent by the second processing unit 5022 is consistent with the bypass request control command of the first processing unit 5021 itself.

[0137] In step S505, if the consistency verification of the bypass request control command sent by the second processing unit 5022 passes, the first processing unit 5021 sends its own bypass request control command to the first drive and acquisition module 5031; if the consistency verification of the bypass request control command sent by the first processing unit 5021 passes, the second processing unit 5022 sends its own bypass request control command to the second drive and acquisition module 5032.

[0138] In step S506, the first drive acquisition module 5031 and the second drive acquisition module 5032 respond to the bypass request control command and control the bypass switch 504 to close.

[0139] In step S507, the first processing unit 5021 acquires the switching status of the bypass switch 504 through the first drive acquisition module 5031; the second processing unit 5022 acquires the switching status of the bypass switch 504 through the second drive acquisition module 5032.

[0140] In step S508, the first processing unit 5021 performs security encoding on the switch status of the bypass switch 504 collected by the first drive acquisition module 5031 and adds verification information, and sends it to the second processing unit 5022; the second processing unit 5022 performs security encoding on the switch status of the bypass switch 504 collected by the second drive acquisition module 5032 and adds verification information, and sends it to the first processing unit 5021.

[0141] In this embodiment of the application, the method by which the first processing unit 5021 and the second processing unit 5022 perform security encoding on the switch state and add verification information can be found in steps S5021 and S5022.

[0142] In step S509, the first processing unit 5021 performs a safety verification on the switching status of the bypass switch 504 collected by the second drive acquisition module 5032; the second processing unit 5022 performs a safety verification on the switching status of the bypass switch 504 collected by the first drive acquisition module 5031.

[0143] In this embodiment of the application, the method by which the first processing unit 5021 and the second processing unit 5022 perform security verification on the switch state can be found in steps S5031 to S5034.

[0144] In this embodiment, if the safety verification of the switch state fails, the energy storage submodule is controlled to enter a safe state.

[0145] In step S510, if the safety verification of the switch status of the bypass switch 504 collected by the second drive acquisition module 5032 passes, the first processing unit 5021 decodes the switch status of the bypass switch 504 collected by the second drive acquisition module 5032 and performs a consistency verification; if the safety verification of the switch status of the bypass switch 504 collected by the first drive acquisition module 5031 passes, the second processing unit 5022 decodes the switch status of the bypass switch 504 collected by the first drive acquisition module 5031 and performs a consistency verification.

[0146] In this embodiment of the application, the method by which the first processing unit 5021 and the second processing unit 5022 decode the switch state can be referred to step S5041.

[0147] In this embodiment of the application, the consistency verification of the switch state refers to: the first processing unit 5021 determining whether the switch state of the bypass switch 504 collected by the second drive acquisition module 5032 is consistent with the switch state of the bypass switch 504 collected by the first drive acquisition module 5031; and the second processing unit 5022 determining whether the switch state of the bypass switch 504 collected by the first drive acquisition module 5031 is consistent with the switch state of the bypass switch 504 collected by the second drive acquisition module 5032.

[0148] In this embodiment, if the switching state of the bypass switch 504 collected by the second drive-collection module 5032 is inconsistent with the switching state of the bypass switch 504 collected by the first drive-collection module 5031, the energy storage submodule is controlled to enter a safe state.

[0149] In step S511, if the switching state of the bypass switch 504 collected by the second drive sampling module 5032 is consistent with the switching state of the bypass switch 504 collected by the first drive sampling module 5031, the first processing unit 5021 sends the switching state of the bypass switch 504 collected by the first drive sampling module 5031 to the energy storage valve controller 501; if the switching state of the bypass switch 504 collected by the first drive sampling module 5031 is consistent with the switching state of the bypass switch 504 collected by the second drive sampling module 5032, the second processing unit 5022 sends the switching state of the bypass switch 504 collected by the second drive sampling module 5032 to the energy storage valve controller 501.

[0150] In some embodiments, this application also provides a bypass control device, such as... Figure 6 As shown, the bypass control device 600 includes at least two processing units; the at least two processing units include a first processing unit 5021 and a second processing unit 5022; the first processing unit 5021 and the second processing unit 5022 are connected; wherein,

[0151] The first processing unit 5021 is used to generate a first bypass command in response to a bypass event; to perform verification processing on the acquired second bypass command; the second bypass command is generated by the second processing unit 5022 in response to the bypass event; if the second bypass command passes the verification, the bypass switch is closed based on the first bypass command to disconnect the energy storage submodule including the bypass control device 600.

[0152] The second processing unit 5022 is used to generate a second bypass command in response to a bypass event; to perform verification processing on the acquired first bypass command; and, if the first bypass command passes verification, to close the bypass switch based on the second bypass command to disconnect the energy storage submodule including the bypass control device 600.

[0153] In some embodiments, such as Figure 7 As shown, the bypass control device 600 further includes a first drive unit 701 corresponding to the first processing unit 5021 and a second drive unit 702 corresponding to the second processing unit 5022; the first processing unit 5021 is connected to the first drive unit 701, and the first drive unit 5021 is connected to the bypass switch 504; the second processing unit 5022 is connected to the second drive unit 702, and the second drive unit 5022 is connected to the bypass switch 504; wherein,

[0154] The first processing unit 5021 is used to close the bypass switch 504 based on the first bypass command through the first driving unit 701 to disconnect the energy storage submodule when the second bypass command verification is passed.

[0155] The second processing unit 5022 is used to close the bypass switch 504 based on the second bypass command through the second driving unit 702 to disconnect the energy storage submodule if the first bypass command verification is successful.

[0156] In some embodiments, the first drive unit 701 is used to acquire the first switching state of the bypass switch 504;

[0157] The second drive unit 702 is used to collect the second switch state of the bypass switch 504;

[0158] The first processing unit 5021 is used to receive the second switching state of the bypass switch 504 sent by the second processing unit 5022; to perform verification processing on the second switching state of the bypass switch 504; and to send the first switching state to the energy storage controller if the verification of the second switching state passes.

[0159] The second processing unit 5022 is used to receive the first switching state of the bypass switch 504 sent by the first processing unit 5021; to perform verification processing on the first switching state of the bypass switch 504; and to send the second switching state to the energy storage controller if the verification of the first switching state passes.

[0160] In some embodiments, the first processing unit 5021, the first driving unit 701, and the bypass switch 504 form a first control link; the second processing unit 5022, the second driving unit 702, and the bypass switch 504 form a second control link; wherein...

[0161] The battery module in the energy storage submodule is used to power the first control link;

[0162] The battery modules in other energy storage submodules adjacent to the energy storage submodule are used to power the second control link.

[0163] In this embodiment, two different control links are established through different processing units and bypass switches, and these two different control links are powered by different battery modules. This creates two physically independent bypass control links, thereby improving the reliability of bypass control.

[0164] In some embodiments, the first processing unit 5021 and the second processing unit 5022 differ from each other in at least one of the following: the type of the processing unit, the operating system of the processing unit, and the compilation method of the code in the processing unit.

[0165] In this embodiment of the application, by setting two processing units in the bypass control device that differ in at least one of the following: the type of the processing unit, the operating system of the processing unit, and the compilation method of the code in the processing unit, the risk of common-mode failure of the two processing units can be reduced, thereby improving the reliability of the bypass control.

[0166] In some embodiments, this application also provides an energy storage system, such as Figure 8 As shown, the energy storage system includes an energy storage valve control module 801 and multiple energy storage sub-modules 802. Each energy storage sub-module 802 includes a bypass control device 600 provided in the above embodiment. The bypass control device 600 can bypass the corresponding energy storage sub-module 802.

[0167] In some embodiments, such as Figure 9 As shown, the energy storage valve control module 801 includes an energy storage valve controller 501. Each energy storage sub-module 802 includes a power module 803 and a battery module 804. The power module 803 includes a power module controller 502 and a bypass switch 504. The power module controller 502 includes the aforementioned bypass control device 600.

[0168] In this embodiment, the energy storage valve controller 501 can send a bypass request to the bypass control device 600. Based on the bypass control method provided in the above embodiment, the bypass control device 600 can control the bypass switch 504 to close, thereby realizing the bypass of the corresponding energy storage submodule 802.

[0169] It should be understood that the phrase "one embodiment" or "an embodiment" throughout the specification means that a specific feature, structure, or characteristic related to the embodiment is included in at least one embodiment of this application. Therefore, "in one embodiment" or "in an embodiment" appearing throughout the specification does not necessarily refer to the same embodiment. Furthermore, these specific features, structures, or characteristics can be combined in any suitable manner in one or more embodiments. It should be understood that in the various embodiments of this application, the sequence numbers of the above steps / processes do not imply a sequential order of execution; the execution order of each step / process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application. The sequence numbers of the above embodiments of this application are merely descriptive and do not represent the superiority or inferiority of the embodiments.

[0170] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.

[0171] The above description is merely an embodiment of this application, but the scope of protection of this application is not limited thereto. Any changes or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application.

Claims

1. A bypass control method, characterized in that, The bypass control method is applied to the first processing unit of at least two processing units in the energy storage submodule; the method includes: In response to a bypass event, a first bypass command is generated for the first processing unit; The acquired second bypass command is verified; the second bypass command is generated by the second processing unit among the at least two processing units in response to the bypass event. If the second bypass command verification passes, the bypass switch is closed based on the first bypass command to disconnect the energy storage submodule.

2. The bypass control method according to claim 1, characterized in that, The second bypass command carries command verification information; The verification process for the acquired second bypass command includes: Based on the command verification information, the second bypass command is validated for legality. Based on the first bypass command, the second bypass command is subjected to consistency verification; If the second bypass command verification passes, bypassing the energy storage submodule based on the first bypass command includes: If the second bypass command is valid and is consistent with the first bypass command, the energy storage submodule is bypassed based on the first bypass command.

3. The bypass control method according to claim 2, characterized in that, The command verification information includes at least one of the following: command sequence number information, command time information, type information, and verification code information; The legality verification of the second bypass command based on the command verification information includes at least one of the following: Based on the command sequence number information, the second bypass command is checked for orderliness. Based on the command time information, the timing of the second bypass command is verified. Based on the type information, the authenticity of the second bypass command is verified. Based on the verification code information, the integrity of the second bypass command is verified.

4. The bypass control method according to any one of claims 1 to 3, characterized in that, The method further includes: Send the first bypass command to the second processing unit; The second processing unit is used to verify the first bypass command; if the first bypass command passes the verification, it closes the bypass switch based on the second bypass command to disconnect the energy storage submodule.

5. The bypass control method according to any one of claims 1 to 3, characterized in that, The energy storage submodule also includes a bypass switch and at least two drive units that correspond one-to-one with the at least two processing units; The step of closing the bypass switch based on the first bypass command to disconnect the energy storage submodule includes: The bypass switch is closed by the drive unit corresponding to the first processing unit based on the first bypass command to disconnect the energy storage submodule.

6. The bypass control method according to claim 5, characterized in that, The bypass control method further includes: The first switching state of the bypass switch is determined by the driving unit corresponding to the first processing unit; The second switch state of the bypass switch is received from the second processing unit; the second switch state is acquired by the drive unit corresponding to the second processing unit. The second switch state of the bypass switch is verified. If the second switch status verification passes, the first switch status is sent to the energy storage controller.

7. The bypass control method according to claim 6, characterized in that, The bypass control method further includes: Send the first switching state of the bypass switch to the second processing unit; The second processing unit is used to verify the first switching state of the bypass switch; if the first switching state verification passes, it sends the second switching state to the energy storage controller.

8. A bypass control device, characterized in that, The bypass control device includes at least two processing units; every two processing units are connected. The first processing unit of the at least two processing units is configured to generate a first bypass command for the first processing unit in response to a bypass event. The obtained second bypass command is verified. The second bypass command is generated by the second of the at least two processing units in response to the bypass event; If the second bypass command verification passes, the bypass switch is closed based on the first bypass command to disconnect the energy storage submodule including the bypass control device.

9. The bypass control device according to claim 8, characterized in that, The bypass control device further includes a first drive unit corresponding to the first processing unit and a second drive unit corresponding to the second processing unit; the first processing unit is connected to the first drive unit, and the first drive unit is connected to the bypass switch; the second processing unit is connected to the second drive unit, and the second drive unit is connected to the bypass switch; wherein... The first processing unit is configured to, upon successful verification of the second bypass command, close the bypass switch via the first driving unit based on the first bypass command to disconnect the energy storage submodule. The second processing unit is configured to, if the first bypass command verification passes, close the bypass switch based on the second bypass command via the second driving unit to disconnect the energy storage submodule.

10. The bypass control device according to claim 9, characterized in that, The first driving unit is used to collect the first switching state of the bypass switch; The second drive unit is used to acquire the second switching state of the bypass switch; The first processing unit is configured to receive the second switching state of the bypass switch sent by the second processing unit; The second switch state of the bypass switch is verified. If the verification of the second switch state passes, the first switch state is sent to the energy storage controller; The second processing unit is configured to receive the first switching state of the bypass switch sent by the first processing unit; perform verification processing on the first switching state of the bypass switch; and send the second switching state to the energy storage controller if the verification of the first switching state passes.

11. The bypass control device according to claim 9 or 10, characterized in that, The first processing unit, the first driving unit, and the bypass switch form a first control link; the second processing unit, the second driving unit, and the bypass switch form a second control link; wherein... The battery module in the energy storage submodule is used to supply power to the first control link; The battery modules in other energy storage submodules adjacent to the energy storage submodule are used to power the second control link.

12. The bypass control device according to any one of claims 8 to 11, characterized in that, The first processing unit and the second processing unit differ from each other in at least one of the following: the type of the processing unit, the operating system of the processing unit, and the compilation method of the code in the processing unit.

13. An energy storage system, characterized in that, The energy storage system includes multiple energy storage sub-modules, and each energy storage sub-module includes a bypass control device as described in any one of claims 8 to 12.