A mobile energy system communication reliability redundancy design method and mobile energy system

By employing a redundant design with dual physical communication links, hardware anti-interference, and software filtering optimization in the mobile energy system, the communication reliability problem was solved, achieving stable communication and self-healing capabilities in complex environments, and ensuring the stable execution of the system's key functions.

CN122179327APending Publication Date: 2026-06-09SUZHOU YUNNENG MAGIC CUBE ENERGY TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
SUZHOU YUNNENG MAGIC CUBE ENERGY TECH CO LTD
Filing Date
2026-05-11
Publication Date
2026-06-09

AI Technical Summary

Technical Problem

Mobile energy systems have poor communication reliability in complex environments and are susceptible to electromagnetic interference and mechanical stress, which can lead to data packet loss and communication interruption, affecting the stability and security of automatic switching, seamless handover, and multi-unit parallel operation.

Method used

It adopts dual physical communication links, hardware anti-interference design (optical isolation, shielding and grounding, power purification) and software filtering and data verification optimization (moving average, median filtering, CRC check and retransmission, heartbeat packet mechanism), combined with intelligent diagnosis and fault self-healing design to ensure the redundancy and fault tolerance of the communication links.

Benefits of technology

It enhances the anti-interference and fault tolerance capabilities of communication, ensures the stable execution of automatic switching, seamless handover, and multi-machine parallel operation, reduces communication error rate and interruption rate, and improves the system's self-healing capability and ease of operation and maintenance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122179327A_ABST
    Figure CN122179327A_ABST
Patent Text Reader

Abstract

The present application belongs to the technical field of communication redundancy design during energy switching, and in particular to a mobile energy system communication reliability redundancy design method and a mobile energy system. The mobile energy system communication reliability redundancy design method improves the anti-interference ability and fault tolerance of communication from two aspects of hardware and software. In view of the problem of electromagnetic interference on site, multi-level hardware anti-interference measures are adopted to solve the problem of communication reliability. The built-in link automatic switching, degraded operation and local cache mechanism of the energy system enable the energy system to automatically recover or maintain basic operation when facing communication failure, avoiding system downtime caused by communication problems. The redundancy design is deeply integrated with business logic such as automatic switching, seamless switching and multi-machine parallel operation, and provides differentiated reliability protection for different scenarios. Through intelligent diagnosis, the quality of the communication link is monitored in real time, which facilitates the maintenance personnel to troubleshoot hidden dangers in advance and quickly locate problems.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of communication control technology for mobile energy systems, specifically relating to a communication reliability redundancy design method and mobile energy system, which is particularly suitable for communication anti-interference and fault self-healing in scenarios of seamless switching between charging / discharging compartments and energy vehicles during plugging and unplugging. Background Technology

[0002] Mobile energy vehicles include new energy vehicles and mobile energy storage vehicles. New energy vehicles are becoming increasingly common, while mobile energy storage vehicles have the advantage of flexible deployment and can be used in multiple fields such as emergency power supply, urban power supply, transportation energy, and industrial production.

[0003] Mobile energy vehicles mainly involve energy supply and replenishment operations. Energy supply is the release of energy, while replenishment is the reception of electrical energy. In different application scenarios of mobile energy vehicles (such as automatic switching, seamless switching, and multi-unit parallel connection), the various components of the energy system consisting of energy supply and replenishment need to conduct a large amount of real-time and reliable data interaction. For example, in an energy system consisting of a discharge compartment and an energy vehicle, during the energy exchange process, there is identification, status synchronization, and power command issuance between the EMS (Energy Management System) of the discharge compartment and the on-board EMS of the energy vehicle; in an energy system consisting of a main energy vehicle and a backup energy vehicle, there is parallel coordination and switching commands between the main and backup energy vehicles; and data transmission between energy-consuming sites and cloud dispatch centers is also included.

[0004] Due to the complex on-site application environment, mobile energy vehicles are prone to communication reliability issues during operation. In particular, the communication environment of mobile energy systems is often quite complex and harsh during actual operation, mainly facing the following types of problems: First, severe electromagnetic interference. Mobile energy systems contain a large number of power conversion modules, motor drive devices, etc., which generate strong electromagnetic radiation during operation, causing serious interference to communication signals, leading to data transmission errors, packet loss, or even link interruption. Especially at the moment of plugging / unplugging the charging / discharging compartment with the energy vehicle, a large instantaneous current and strong electromagnetic pulse are generated, which can easily impact the communication interface and communication link. Secondly, communication links are susceptible to physical environmental factors. Devices in mobile energy systems often need to move or frequently connect, such as the connection between an energy vehicle and a charging / discharging compartment. This can subject communication cables to mechanical stresses such as tension, bending, and vibration, leading to physical faults such as cable breakage and poor contact, thus affecting communication stability. Thirdly, real-time performance and reliability requirements are high in various scenarios. For example, in automatic switching scenarios, communication delays or failures may result in untimely switching of energy devices, causing power outages or equipment damage. In seamless switching scenarios, even brief communication interruptions can cause switching failures, affecting the continuity of energy supply. In multi-device parallel scenarios, precise power distribution command transmission between energy devices is required. Unreliable communication can lead to power distribution imbalances, affecting system operating efficiency and safety. Summary of the Invention

[0005] This invention aims to provide a communication reliability redundancy design method and a mobile energy system, so as to comprehensively improve the anti-interference capability and fault tolerance capability of the communication system from both hardware and software levels, thereby improving the communication reliability of the mobile energy system during operation.

[0006] In scenarios such as emergency power supply and urban power protection, mobile energy vehicles need to exchange key data such as identity recognition, status synchronization, and power commands with the charging / discharging compartment in real time via CAN bus. The research found the following specific technical problems in field applications: 1. Electromagnetic pulse interference during insertion and removal: When the energy vehicle is connected or disconnected from the charging / discharging compartment via a quick-connect connector, the engagement / disengagement of the high-power contactor will generate an electromagnetic pulse with a nanosecond rising edge. This pulse is coupled to the CAN bus through the communication interface, causing the CRC check bit in the data frame to flip. If the receiving end fails to verify the CRC check bit, the entire frame of data will be discarded.

[0007] 2. Command packet loss in seamless switching scenarios: During the switching process between the primary and backup power vehicles, power transfer needs to be completed within the following timeframes: contactor actuation time approximately 20ms, communication cycle approximately 10ms. If the CAN bus loses a packet once due to electromagnetic interference, the switching command will be delayed by one communication cycle (10ms), causing asynchronous contactor actuation, which may result in instantaneous overcurrent or power interruption.

[0008] 3. Limitations of existing solutions: Existing technologies mostly use a single CAN bus link, a single CRC check, or only add a retransmission mechanism, but do not solve the problem that retransmission will also fail due to interference during plugging and unplugging; they also lack a fast switching mechanism that links hardware and software.

[0009] In addition, in practical applications, mobile energy systems also have the following common problems: Severe Electromagnetic Interference: The mobile energy vehicle and discharge compartment contain high-power power electronic equipment (PCS, contactors, AC / DC modules, etc.). Their switching actions generate strong electromagnetic interference, affecting the integrity of communication signals and leading to data packet loss, bit errors, or even communication interruptions. Poor Connector Contact: The mobile energy vehicle and discharge compartment use quick-connect connectors. Frequent plugging and unplugging can cause oxidation and loosening of communication contacts, introducing contact noise or intermittent disconnections. Long-Distance Transmission Attenuation: Communication between energy consumption sites and charging sites, and between vehicles and the cloud, may involve long distances and diverse transmission media, making signals prone to attenuation and external interference. Lack of Systemic Redundancy Design: Existing solutions often use a single communication link and a single verification method. Once a communication anomaly occurs, the system cannot self-heal or degrade, potentially leading to serious consequences such as automatic switching failures and incorrect power allocation among multiple parallel units.

[0010] Therefore, in the operation of mobile energy systems, under various circumstances that affect communication, such as strong electromagnetic pulse interference during the plugging / unplugging of the charging / discharging compartment and the energy vehicle, how to avoid packet loss of communication data frames, and how to ensure the stable execution of core functions such as automatic switching, seamless switching, and multi-machine parallel operation are urgent problems to be solved.

[0011] To achieve the above objectives, the present invention adopts the following technical solution: A method for designing communication reliability redundancy in a mobile energy system is provided. The mobile energy system includes a master energy device and slave energy devices, comprising: (1) Communication link physical redundancy design: a dual physical communication link is deployed between the communication nodes of the main energy device and the slave energy device, including a main link and a backup link. The main energy device and the slave energy device transmit control commands through the main link. When the main link fails, the main energy device and the slave energy device automatically switch to the backup link. (2) Hardware anti-interference design, including: (2.1) Opto-isolation design: High-speed optocouplers are used for isolation at the communication interfaces of the main energy device and the slave energy device; (2.2) Shielding and grounding design: The communication cable between the main energy device and the slave energy device is a twisted pair shielded cable, and the shielding layer of the twisted pair shielded cable is grounded at a single point; the communication module of the main energy device and the slave energy device is designed with metal shielding. (2.3) Power purification design: The communication modules of the main energy device and the slave energy device are configured with separate isolated power supplies, so that they are powered separately from the power module; (3) Software filtering and data verification optimization, including: (3.1) Moving average filtering: For the analog signal between the main energy device and the slave energy device, a moving average filtering algorithm is used to smooth out instantaneous spike interference; (3.2) Median filtering: For the switching signals between the main energy device and the slave energy device, a median filtering algorithm is used to filter out the glitches caused by contact jitter; (3.3) CRC check and retransmission mechanism: All communication data frames between the main energy device and the slave energy device are appended with a CRC check code, and the receiving end automatically requests retransmission when the check fails; (3.4) Heartbeat mechanism: The main energy device and the slave energy device periodically send heartbeat packets to each other. If no response is received for N consecutive heartbeat packets, the link is determined to be faulty and automatic switching is triggered.

[0012] Preferred options also include: (4) Intelligent diagnosis and fault self-healing design: The main energy device and the slave energy device are respectively equipped with a communication diagnosis module and an alarm module, which are used to monitor the status of each communication link in real time, specifically including: (4.1) Bit error rate statistics: Count the number of bit errors in the main link during the communication between the main energy device and the slave energy device. When the bit error rate exceeds the preset threshold, automatically reduce the communication rate or switch to the backup link. (4.2) Signal quality assessment: For analog communication between the main energy device and the slave energy device, monitor the signal amplitude fluctuation and assess the signal quality; (4.3) Degraded operation mode: When the communication link between the main energy device and the slave energy device fails completely, the main energy device and the slave energy device automatically enter the degraded operation mode and maintain basic power supply using locally preset default parameters until communication is restored.

[0013] Preferred options also include: (5) Deeply coupled design with core application scenarios: (5.1) Automatic switching scenario: The switching commands between the master energy device and the slave energy device are issued simultaneously through dual links to ensure that the switching can still be executed normally if any link fails; (5.2) Seamless switching scenario: The status signals of the main energy device and the slave energy device during the switching process are confirmed by both hardware DI signals and communication signals to avoid switching failure due to communication delay or packet loss; (5.3) Multi-machine parallel scenario: The power distribution command between the main energy device and the slave energy device is transmitted through the dual physical communication link, and the slave energy device has a built-in local cache mechanism, so that it can continue to run according to the last command when the communication is interrupted briefly, in order to avoid power sudden change.

[0014] Preferably, the alarm module issues an alarm when switching from the primary link to the backup link.

[0015] Preferably, the main link uses a CAN bus; the backup link uses an Ethernet bus.

[0016] Preferably, the main energy device is a charging / discharging compartment, the secondary energy device is an energy vehicle, and the communication nodes of the main energy device and the secondary energy device are the charging / discharging compartment EMS and the energy vehicle on-board EMS, respectively.

[0017] Preferably, the window length of the moving average filtering algorithm is 8-12 sampling points; the median filtering algorithm determines a valid state only after 2-5 consecutive consistent samplings.

[0018] Preferably, in the CRC check and retransmission mechanism, after the CRC check fails, the sending end retransmits the communication data frame 2-4 times; in the heartbeat mechanism, the heartbeat packet sending period is 1 second, and the N heartbeat packets are 3-6 heartbeat packets.

[0019] Preferably, in the bit error rate statistics, when the bit error rate exceeds 0.1%, an early warning is issued through the alarm module.

[0020] The present invention also provides a mobile energy system designed according to the mobile energy system communication reliability redundancy design method described in any of the preceding claims.

[0021] Compared with existing technologies, the beneficial effects of this invention are as follows: This mobile energy system communication reliability redundancy design method comprehensively improves the anti-interference and fault tolerance capabilities of communication from both hardware and software levels, ensuring the stable execution of core functions such as automatic switching, seamless handover, and multi-machine parallel operation. For on-site electromagnetic interference issues, multi-layered hardware anti-interference measures are adopted to solve communication reliability problems. The energy system's built-in automatic link switching, degraded operation, and local caching mechanisms enable the energy system to automatically recover or maintain basic operation when facing communication failures, avoiding system downtime due to communication problems. The redundancy design is deeply integrated with business logic such as automatic switching, seamless handover, and multi-machine parallel operation, providing differentiated reliability guarantees for different scenarios. Through intelligent diagnostics, the quality of communication links is monitored in real time, facilitating maintenance personnel to proactively identify potential problems and quickly locate issues. Attached Figure Description

[0022] The accompanying drawings are provided to further illustrate the invention and form part of the specification. They are used in conjunction with embodiments of the invention to explain the invention and do not constitute a limitation thereof. In the drawings: Figure 1 This is a diagram of the communication hardware redundancy architecture in one embodiment of the mobile energy system communication reliability redundancy design method of the present invention.

[0023] Figure 2 This is a flowchart of software filtering and data verification in one embodiment of the mobile energy system communication reliability redundancy design method of the present invention.

[0024] Figure 3 This is a circuit diagram corresponding to the double confirmation of the DI signal in one embodiment of the mobile energy system communication reliability redundancy design method of the present invention.

[0025] Figure 4 This is a flowchart illustrating communication fault diagnosis and self-healing in one embodiment of the mobile energy system communication reliability redundancy design method of the present invention. Detailed Implementation

[0026] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0027] In one embodiment, a communication reliability redundancy design method for a mobile energy system is provided. In this method, the mobile energy system includes a master energy device and slave energy devices. The master energy device is typically an energy device that outputs energy or acts as a master in communication, while the slave energy device is typically an energy device that receives energy or acts as a slave in communication. Figure 1-4 As shown, the communication reliability redundancy design method of this mobile energy system includes the following aspects: (1) Communication link physical redundancy design: deploy dual physical communication links between the communication nodes of the main energy device and the slave energy device, including the main link and the backup link. The main energy device and the slave energy device transmit control commands through the main link. When the main link fails, the main energy device and the slave energy device automatically switch to the backup link.

[0028] In this embodiment, the main energy device is a charging / discharging compartment, and the secondary energy device is a mobile energy vehicle. The charging / discharging compartment is used to charge the mobile energy vehicle, which can be a new energy vehicle. This usage scenario involves charging the mobile energy vehicle through the charging / discharging compartment. The communication nodes for the main and secondary energy devices are the charging / discharging compartment EMS and the energy vehicle's onboard EMS, respectively. The charging / discharging compartment EMS manages the electrical energy of the charging / discharging compartment, and the energy vehicle's onboard EMS manages the electrical energy of the energy vehicle.

[0029] The main link here uses a CAN bus for transmitting control commands with high real-time requirements; the backup link uses Ethernet for status data backup and emergency control in case of main link failure.

[0030] (2) Hardware anti-interference design, including: (2.1) Opto-isolation design: High-speed optocouplers are used to isolate the communication interface between the main energy device and the slave energy device, and the communication circuit between the main energy device and the slave energy device is electrically isolated from the power circuit and control circuit to block the transmission path of interference signals; (2.2) Shielding and grounding design: The communication cable between the main energy device and the slave energy device is a twisted pair shielded cable, and the shielding layer of the twisted pair shielded cable is grounded at a single point to prevent ground loop interference; the communication module of the main energy device and the slave energy device is designed with metal shielding to block electromagnetic radiation interference. (2.3) Power purification design: The communication modules of the main energy equipment and the slave energy equipment are equipped with separate isolated power supplies, so that they are powered separately from the power modules to avoid power ripple interference to the operation of the communication modules; Specifically, such as Figure 1As shown, regarding the hardware aspects above, for the communication interface design, a dual-channel communication interface is designed between the discharge chamber EMS and the energy vehicle's onboard EMS: one is a CAN bus (main link), and the other is an Ethernet (backup link). All interface circuits use high-speed optocoupler isolation, with an isolation voltage of no less than 2500Vrms. For the cable selection and wiring of the main and backup links, twisted-pair shielded cables are used. The shielding layer is grounded at a single point on the discharge chamber side. Communication cables and power cables are laid separately to avoid parallel laying, with a spacing of no less than 200mm. For the power supply design, a separate DC-DC isolated power supply is configured for the communication module. The input comes from the 24V control power supply, and the output is 5V / 3.3V for the communication chip, isolated from the MCU (EMS's main control unit). This communication module is the dedicated communication component for both the discharge chamber EMS and the energy vehicle's onboard EMS. For the electromagnetic shielding design, the charging / discharging chamber's EMS is installed in a metal shielding box, which is connected to the cabinet ground via a grounding wire.

[0031] (3) Software filtering and data verification optimization, including: (3.1) Moving average filtering: For analog signals between the main energy device and the slave energy device, the moving average filtering algorithm is used to smooth out instantaneous spike interference to ensure data stability; (3.2) Median filtering: For the switching signals between the main energy device and the slave energy device, the median filtering algorithm is used to filter out the glitches caused by contact jitter in order to avoid false triggering; (3.3) CRC check and retransmission mechanism: All communication data frames between the master energy device and the slave energy device are appended with CRC check codes. When the receiving end fails the check, it will automatically request retransmission to ensure data integrity. (3.4) Heartbeat mechanism: The primary energy device and the secondary energy device periodically send heartbeat packets to each other to monitor the health status of the link. If no response is received for N consecutive heartbeat packets, the link is determined to be faulty and automatic switching is triggered.

[0032] Specifically, such as Figure 2 As shown, in the software layer design above, regarding data filtering, for analog signals such as voltage and current, a moving average filtering algorithm is used with a window length of 10 sampling points; for DI switch signals, a median filtering algorithm is used, and a valid state is determined only if three consecutive samples are consistent. Regarding the communication protocol design, the communication frame structure includes a frame header, data length, data field, CRC16 checksum, and frame trailer. The CRC is calculated and appended at the sending end. The receiving end parses the data only after the checksum passes. If the checksum fails, the receiving end does not return an ACK, and the sending end automatically retransmits after a timeout, up to a maximum of three retransmissions. Here, the sending end's CRC checksum calculation refers to the sender performing a calculation on the original data before sending the data to generate a fixed-length checksum; ACK is the acknowledgment character.

[0033] Regarding heart rate monitoring, such as Figure 4 As shown, the two communicating parties send heartbeat packets to each other every second. If there is no response to the heartbeat after 5 consecutive heartbeats, the link is considered to be faulty. The energy system consisting of the main energy device and the slave energy device automatically switches to the backup link and records the fault log.

[0034] (4) Intelligent diagnosis and fault self-healing design: The main energy device and the slave energy device are equipped with built-in communication diagnosis module and alarm module, respectively, for real-time monitoring of the status of each communication link, specifically including: (4.1) Bit error rate statistics: Count the number of bit errors in the main link during the communication between the main energy device and the slave energy device. When the bit error rate exceeds the preset threshold, the communication rate will be automatically reduced or the connection will be switched to the backup link. (4.2) Signal quality assessment: For analog communication between the main energy device and the slave energy device, monitor the signal amplitude fluctuation, assess the signal quality, and trigger the alarm module when the quality is poor; (4.3) Degraded operation mode: When the communication link between the main energy device and the slave energy device fails completely, the main energy device and the slave energy device automatically enter the degraded operation mode and maintain basic power supply using the local preset default parameters until communication is restored.

[0035] Here, the main and secondary energy devices monitor real-time metrics such as bit error rate, communication latency, and number of outages on the main link. These metrics are then visualized via a local HMI (Human-Machine Interface) or cloud-based system. When the bit error rate exceeds 0.1%, an alert is issued prompting maintenance personnel to check cable connections and sources of interference. In the event of a complete communication failure, the system automatically switches to the backup link and records relevant data at the time of the failure for post-incident analysis. Additionally, the alarm module triggers an alarm when switching from the main link to the backup link to alert maintenance personnel.

[0036] (5) Deeply coupled design with core application scenarios: (5.1) Automatic switching scenario: The switching commands between the master energy device and the slave energy device are issued simultaneously through dual links to ensure that the switching can still be executed normally if any link fails; (5.2) Seamless switching scenario: The status signals of the main energy device and the slave energy device during the switching process are confirmed by both hardware DI signals and communication signals to avoid switching failure due to communication delay or packet loss; (5.3) Multi-machine parallel scenario: Power distribution instructions between the master energy device and the slave energy device are transmitted through dual physical communication links, and the slave energy device has a built-in "local cache" mechanism, which can continue to run according to the last instruction when communication is interrupted briefly, so as to avoid power sudden change.

[0037] In the automatic switching scenario, when the standby vehicle is put into operation and the main vehicle is taken out to switch to the new energy vehicle, the switching command (standby vehicle put into operation, main vehicle taken out) is issued simultaneously through two links. The EMS executes the command as soon as it receives a valid command from either link and then feeds back the execution result through the two links.

[0038] like Figure 3 As shown, for the dual confirmation circuit of DI signal, the contactor output contact is connected to the DI output port through a 10kΩ pull-up, and the DI output port is connected to the DI pin of the MCU in both EMS through an isolator. The DI signal is a hard-wired feedback method. For seamless switching scenarios, the contactor energizing state used for power supply is confirmed by both hardware DI signal and communication signal. After receiving the communication feedback, both EMS read the DI signal and compare it. Only when the two match is the switching successful.

[0039] In multi-machine parallel scenarios, the power commands issued by the master (main energy device) to the slave (slave energy device) are transmitted through redundant links. The slave locally caches the three most recent valid commands. When communication is interrupted for more than 2 seconds, the slave continues to operate according to the most recent command and issues an alarm to wait for communication to be restored or manual intervention.

[0040] Based on the above embodiments, it can be seen that the mobile energy system communication reliability redundancy design method forms a complete technical chain from interference suppression → signal purification → data repair → diagnostic self-healing → fault switching through a multi-layered progressive design of "physical redundant links + hardware isolation + software filtering + fault diagnosis + scenario coupling judgment". The logical progression of this design method is as follows: physical isolation (blocking conduction) → shielding grounding (blocking radiation) → independent power supply (avoiding ripple) → moving average / median filtering (eliminating residual noise) → CRC check (error detection) → retransmission (error correction) → heartbeat monitoring (fault detection) → link switching (fault recovery) → DI double confirmation (ultimate guarantee).

[0041] This mobile energy system communication reliability redundancy design method addresses communication issues such as "CAN bus packet loss caused by electromagnetic pulses during insertion and removal." Through a multi-layered progressive design, it achieves the following technical effects: improved electromagnetic pulse suppression capability: isolation voltage ≥2500Vrms, communication bit error rate reduced from 0.5% to below 0.01%; improved seamless switching success rate: DI dual confirmation mechanism reduces switching failure rate by more than 90%; shortened fault recovery time: link switching time ≤50ms, local buffer support operation time ≥2 seconds.

[0042] In another embodiment, a mobile energy system is provided. This mobile energy system is designed according to the communication reliability redundancy design method of the mobile energy system in the previous embodiment. The main advantages of this mobile energy system are: 1. Significantly improved communication reliability: Through multiple means such as physical link redundancy, hardware anti-interference, and software filtering optimization, the communication error rate can be reduced to below 0.01%, and the communication interruption rate can be reduced by more than 90%, effectively ensuring the stable execution of core functions such as automatic switching and seamless handover. 2. Strong self-healing capability of the energy system: The built-in automatic link switching, degradation operation, and local caching mechanism enable the energy system to automatically recover or maintain basic operation when facing communication failures, avoiding system downtime caused by communication problems. 3. Deep coupling with core functions: Redundancy design is not an "additional item," but is deeply integrated with business logic such as automatic switching, seamless handover, and multi-machine parallel connection, providing differentiated reliability guarantees for different scenarios, ensuring that key commands can be sent, received, and executed accurately. 4. Improved maintenance convenience: Through intelligent diagnosis, the quality of communication links is monitored in real time, and a visualized health status assessment and fault warning are provided, making it easier for maintenance personnel to identify potential problems in advance and quickly locate issues.

[0043] It should be noted that, in this document, terms such as “comprising,” “including,” or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus.

[0044] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.

Claims

1. A communication reliability redundancy design method for a mobile energy system, the mobile energy system comprising a master energy device and slave energy devices, characterized in that, include: (1) Communication link physical redundancy design: a dual physical communication link is deployed between the communication nodes of the main energy device and the slave energy device, including a main link and a backup link. The main energy device and the slave energy device transmit control commands through the main link. When the main link fails, the main energy device and the slave energy device automatically switch to the backup link. (2) Hardware anti-interference design, including: (2.1) Opto-isolation design: High-speed optocouplers are used for isolation at the communication interfaces of the main energy device and the slave energy device; (2.2) Shielding and grounding design: The communication cable between the main energy device and the slave energy device is a twisted pair shielded cable, and the shielding layer of the twisted pair shielded cable is grounded at a single point; the communication module of the main energy device and the slave energy device is designed with metal shielding. (2.3) Power purification design: The communication modules of the main energy device and the slave energy device are configured with separate isolated power supplies, so that they are powered separately from the power module; (3) Software filtering and data verification optimization, including: (3.1) Moving average filtering: For the analog signal between the main energy device and the slave energy device, a moving average filtering algorithm is used to smooth out instantaneous spike interference; (3.2) Median filtering: For the switching signals between the main energy device and the slave energy device, a median filtering algorithm is used to filter out the glitches caused by contact jitter; (3.3) CRC check and retransmission mechanism: All communication data frames between the main energy device and the slave energy device are appended with a CRC check code, and the receiving end automatically requests retransmission when the check fails; (3.4) Heartbeat mechanism: The main energy device and the slave energy device periodically send heartbeat packets to each other. If no response is received for N consecutive heartbeat packets, the link is determined to be faulty and automatic switching is triggered.

2. The mobile energy system communication reliability redundancy design method according to claim 1, characterized in that, Also includes: (4) Intelligent diagnosis and fault self-healing design: The main energy device and the slave energy device are respectively equipped with a communication diagnosis module and an alarm module, which are used to monitor the status of each communication link in real time, specifically including: (4.1) Bit error rate statistics: Count the number of bit errors in the main link during the communication between the main energy device and the slave energy device. When the bit error rate exceeds the preset threshold, automatically reduce the communication rate or switch to the backup link. (4.2) Signal quality assessment: For analog communication between the main energy device and the slave energy device, monitor the signal amplitude fluctuation and assess the signal quality; (4.3) Degraded operation mode: When the communication link between the main energy device and the slave energy device fails completely, the main energy device and the slave energy device automatically enter the degraded operation mode and maintain basic power supply using locally preset default parameters until communication is restored.

3. The mobile energy system communication reliability redundancy design method according to claim 2, characterized in that, Also includes: (5) Deeply coupled design with core application scenarios: (5.1) Automatic switching scenario: The switching commands between the master energy device and the slave energy device are issued simultaneously through dual links to ensure that the switching can still be executed normally if any link fails; (5.2) Seamless switching scenario: The status signals of the main energy device and the slave energy device during the switching process are confirmed by both hardware DI signals and communication signals to avoid switching failure due to communication delay or packet loss; (5.3) Multi-machine parallel scenario: The power distribution command between the main energy device and the slave energy device is transmitted through the dual physical communication link, and the slave energy device has a built-in local cache mechanism, so that it can continue to run according to the last command when the communication is interrupted briefly, in order to avoid power sudden change.

4. The mobile energy system communication reliability redundancy design method according to claim 2, characterized in that: When switching from the primary link to the backup link, the alarm module issues an alarm.

5. The mobile energy system communication reliability redundancy design method according to claim 1, characterized in that: The primary link uses a CAN bus; the backup link uses an Ethernet bus.

6. The mobile energy system communication reliability redundancy design method according to claim 1, characterized in that: The main energy device is a charging / discharging compartment, and the secondary energy device is an energy vehicle. The communication nodes of the main energy device and the secondary energy device are the charging / discharging compartment EMS and the energy vehicle on-board EMS, respectively.

7. The mobile energy system communication reliability redundancy design method according to claim 1, characterized in that: The window length of the moving average filtering algorithm is 8-12 sampling points; the median filtering algorithm is considered valid only after 2-5 consecutive consistent samples.

8. The mobile energy system communication reliability redundancy design method according to claim 1, characterized in that: In the CRC check and retransmission mechanism, after the CRC check fails, the sending end retransmits the communication data frame 2-4 times; in the heartbeat mechanism, the heartbeat packet sending period is 1 second, and the N heartbeat packets are 3-6 heartbeat packets.

9. The mobile energy system communication reliability redundancy design method according to claim 2, characterized in that: In the bit error rate statistics, when the bit error rate exceeds 0.1%, an early warning is issued through the alarm module.

10. A mobile energy system, characterized in that: The mobile energy system is a mobile energy system designed according to the communication reliability redundancy design method of the mobile energy system according to any one of claims 1-9.