A safe prevention and control system for energy storage power station based on distributed control

CN122533239APending Publication Date: 2026-08-07JIANGSU RIHUI ENERGY DEVELOPMENT CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
JIANGSU RIHUI ENERGY DEVELOPMENT CO LTD
Filing Date
2026-05-14
Publication Date
2026-08-07

AI Technical Summary

Technical Problem

[0003]现有技术在储能节点异常处理过程中,通常仅针对异常节点执行单一降载或隔离控制,缺少基于节点关联关系的协同接管与风险联动控制机制,难以根据各节点剩余承载能力动态分配功率接管任务

Benefits of technology

本发明通过对储能电站内的电池簇、电池舱、储能变流器支路、热管理单元及消防隔离单元进行分布式控制节点划分,并建立相邻节点关系、电气耦合关系、热耦合关系和控制权限关系,使储能电站内部各节点之间的运行关联关系得到统一描述。在此基础上,通过为各分布式控制节点配置节点安全合约,将节点功率安全边界、节点热负荷承受边界、节点风险转移边界、节点功率接管边界以及节点隔离补偿义务进行统一约束,实现了储能节点运行能力、风险承载能力与协同控制能力的规范化管理,从而能够在储能电站运行过程中对节点运行状态进行动态约束与实时管控,提高储能电站在复杂运行场景下的安全控制能力。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122533239A_ABST
    Figure CN122533239A_ABST
Patent Text Reader

Abstract

This invention discloses a safety control system for energy storage power stations based on distributed control, comprising: a node partitioning module for partitioning multiple distributed control nodes and establishing node associations; a contract configuration module for configuring node security contracts for each distributed control node; a data acquisition module for collecting operational status data of each distributed control node; a capacity calculation module for calculating the remaining safe capacity of each distributed control node; a risk identification module for identifying abnormal nodes and generating contract default risk signals; a takeover arbitration module for determining a set of candidate takeover nodes and executing takeover arbitration; and a safety verification module for performing full-site safety constraint verification on the negotiated control scheme and generating safety control commands. This invention utilizes distributed collaborative control and dynamic takeover arbitration methods to achieve coordinated prevention and control of abnormal risks in energy storage power stations, possessing advantages such as high security, strong collaboration, and high operational stability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of energy storage safety control, and in particular to a safety control system for energy storage power stations based on distributed control. Background Technology

[0002] As energy storage power stations continue to expand in scale, the operational coupling relationships between battery clusters, battery compartments, energy storage converters, and thermal management equipment within the energy storage system become increasingly complex. Under high-load operation, frequent charging and discharging, and localized fault propagation scenarios, energy storage power stations are prone to problems such as power fluctuations, thermal runaway propagation, and localized node anomalies. Existing energy storage safety control schemes typically employ a centralized control approach, performing unified scheduling and protection control of energy storage nodes, and combining operating parameters such as temperature, current, and state of charge for anomaly detection and safety protection.

[0003] Existing technologies for handling anomalies at energy storage nodes typically only implement single load reduction or isolation controls on the anomalous node, lacking a collaborative takeover and risk linkage control mechanism based on node relationships. This makes it difficult to dynamically allocate power takeover tasks according to the remaining carrying capacity of each node. Furthermore, existing technologies lack unified constraints and verification for heat spread risks, cooling resource occupancy, and risk-restricted areas, which can easily lead to the spread of anomalies to adjacent nodes, thereby affecting the overall operational stability and safety of the energy storage power station.

[0004] Therefore, how to provide a safety control system for energy storage power stations based on distributed control is a problem that urgently needs to be solved by those skilled in the art. Summary of the Invention

[0005] One objective of this invention is to propose a safety control system for energy storage power stations based on distributed control. This invention utilizes distributed collaborative control and dynamic takeover arbitration methods to achieve coordinated prevention and control of abnormal risks in energy storage power stations, and has the advantages of high security, strong collaboration and high operational stability.

[0006] A safety control system for an energy storage power station based on distributed control, according to an embodiment of the present invention, includes: The node partitioning module is used to partition multiple distributed control nodes according to the equipment structure and control responsibilities of the energy storage power station, and to establish the node association relationship between each distributed control node; The contract configuration module is used to configure node security contracts for each distributed control node based on the type, boundary parameters, and compensation obligations of the distributed control node. The data acquisition module is used to collect the operating status data of each distributed control node; The capacity calculation module is used to calculate the remaining security capacity of each distributed control node based on the running status data of each distributed control node and the corresponding node security contract. The risk identification module is used to identify the target distributed control node as an abnormal node and generate a contract default risk signal when the remaining security capacity of the target distributed control node does not meet the node security contract constraints. The takeover arbitration module is used to determine a set of candidate takeover nodes based on abnormal nodes as the source of takeover demand, contract default risk signals and node correlations, and to perform takeover arbitration based on the remaining security capacity of each node in the candidate takeover node set, thereby generating a negotiated prevention and control plan. The security verification module is used to perform site-wide security constraint verification on the negotiated prevention and control scheme, and generate security prevention and control instructions when the negotiated prevention and control scheme meets the site-wide security constraints.

[0007] Optionally, the energy storage power station equipment structure includes a battery cluster, a battery compartment, an energy storage converter branch, a thermal management unit, a fire isolation unit, and a station-level coordination and control unit. The control responsibilities include power regulation responsibilities, thermal management responsibilities, risk isolation responsibilities, power takeover responsibilities, and safety coordination responsibilities. The node association relationships include adjacent node relationships, electrical coupling relationships, thermal coupling relationships, and control authority relationships.

[0008] Optionally, the contract configuration module includes: The node type of the distributed control node is determined based on the equipment structure and control responsibilities of the energy storage power station corresponding to the distributed control node. Configure the corresponding node power safety boundary according to the node type of the distributed control node; Configure the corresponding node thermal load tolerance boundary based on the temperature limit, temperature rise rate limit, and cooling capacity limit of the distributed control node; Configure the corresponding node risk transfer boundary based on the adjacent node relationships, electrical coupling relationships, and thermal coupling relationships of the distributed control node; Configure the corresponding node power takeover boundary based on the rated power capacity, rated heat load capacity, rated cooling compensation capability, and control authority relationship of the distributed control node; Based on the power gap, heat load changes and risk limitation requirements of the distributed control node to the adjacent distributed control node under the preset abnormal isolation scenario, configure the corresponding node isolation compensation obligation; Configure corresponding node communication failure degradation obligations based on the communication link status, communication latency limits, and control permission relationships of the distributed control nodes; Write the node power safety boundary, node heat load tolerance boundary, node risk transfer boundary, node power takeover boundary, node isolation compensation obligation, and node communication anomaly degradation obligation into the node security contract of the corresponding distributed control node, and bind the node security contract to the node identifier of the distributed control node.

[0009] Optionally, the operating status data includes node current, node charging and discharging power, node temperature, node temperature rise rate, node state of charge, node health status, node internal resistance, node cooling response time, node communication delay, and node fire isolation status.

[0010] Optionally, the load capacity calculation module includes: Based on node charging and discharging power, node current, node state of charge, node health status, and node power safety boundary, the power takeover capability of distributed control nodes is determined. Based on node temperature, node temperature rise rate, node internal resistance, node cooling response time, and node heat load bearing boundary, the heat load bearing capacity of the distributed control node is determined. The risk buffering capacity of distributed control nodes is determined by combining the node fire isolation status, node temperature rise rate, node internal resistance, node risk transfer boundary, and node association relationship. The cooling compensation capability of distributed control nodes is determined based on node cooling response time, node temperature, node temperature rise rate, node isolation compensation obligation, and node heat load tolerance boundary. The capability indicators corresponding to power takeover capability, heat load carrying capacity, risk buffering capability, and cooling compensation capability are normalized and then weighted and fused according to the bearing weight corresponding to the node type in the node security contract to obtain the remaining security bearing capacity of each distributed control node.

[0011] Optionally, the risk identification module includes: The remaining security capacity of each distributed control node is compared with various limiting conditions in the node security contract to identify the target distributed control node whose remaining security capacity does not meet the limiting conditions of the node security contract. Based on the contract fields in the target distributed control node that do not meet the node security contract constraints, determine the default contract entries corresponding to the target distributed control node. Based on the boundary difference corresponding to the default contract item and the node charging and discharging power of the target distributed control node, determine the power reduction requirement of the target distributed control node. Based on the node risk transfer boundary, node fire isolation status, node temperature rise rate, and node association relationship corresponding to the target distributed control node, determine the risk transfer limit of the target distributed control node; The isolation requirements of the target distributed control node are determined based on the node temperature, node temperature rise rate, node cooling response time, node fire isolation status, and node isolation compensation obligation. When the target distributed control node has defaulted contract entries, power reduction requirements, risk transfer restrictions, or isolation requirements, the target distributed control node will be identified as an abnormal node, and the node identifier of the target distributed control node will be identified as an abnormal node identifier. By writing the abnormal node identifier, default contract entry, power reduction requirement, risk transfer restriction, and isolation requirement into the same contract default risk signal, a contract default risk signal corresponding to the abnormal node is generated.

[0012] Optionally, the takeover arbitration module includes: Abnormal nodes are identified based on the abnormal node identifiers in the contract default risk signals. Based on the node association relationships corresponding to the abnormal nodes, distributed control nodes that have adjacent node relationships, electrical coupling relationships, thermal coupling relationships, or control authority relationships with the abnormal nodes are identified. The identified distributed control nodes are used as the initial takeover node set. Based on risk transfer restrictions, abnormal node isolation methods, and node power takeover boundaries, the initial takeover node set is screened for takeover eligibility to obtain a candidate takeover node set. Based on the remaining safe carrying capacity of each node in the candidate takeover node set, the takeover priority of each distributed control node in the candidate takeover node set is determined, and the distributed control nodes are sorted according to the takeover priority to generate the power takeover order corresponding to the candidate takeover nodes. Based on the power reduction requirements, the remaining safe carrying capacity of each node in the candidate takeover node set, and the node power takeover boundary, determine the power takeover ratio corresponding to each candidate takeover node. Based on the cooling compensation capability, cooling response time, temperature and temperature rise rate of each node in the candidate takeover node set, the cooling compensation priority of each candidate takeover node is determined. Based on risk transfer restrictions, isolation requirements, node fire isolation status, adjacent node relationships, and thermal coupling relationships, determine the risk isolation boundary between abnormal nodes and candidate takeover nodes; Based on the remaining security capacity of each node in the candidate takeover node set, the node power takeover boundary, the node risk transfer boundary, the node communication anomaly degradation obligation, and the control authority relationship, the scope of nodes prohibited from takeover is determined. The power takeover sequence, power takeover ratio, cooling compensation priority, risk isolation boundary, and prohibited takeover node range are written into the same negotiation and control scheme to generate the negotiation and control scheme corresponding to the abnormal node.

[0013] Optionally, the security verification module includes: The station-level coordination and control unit reads the negotiated prevention and control plan and identifies the abnormal nodes, candidate takeover nodes, thermal management units, fire isolation units, energy storage converter branches, and communication abnormal nodes that participate in the station-wide safety constraint verification. Based on the load reduction power of abnormal nodes, the power taken over by candidate takeover nodes according to the power takeover ratio, and the current total charging and discharging power of the energy storage power station, perform a total charging and discharging power balance constraint verification. Based on the takeover power, node current, node power takeover boundary and current carrying conditions of the energy storage converter branch corresponding to the candidate takeover node, perform DC bus current constraint and energy storage converter load rate constraint verification. Based on the changes in grid-connected power after load reduction at abnormal nodes, power takeover of candidate nodes, and power adjustment of energy storage converter branches, perform grid-connected power fluctuation constraint verification. Based on the cooling compensation priority, the node temperature of the candidate takeover node, the node temperature rise rate, the node cooling response time, and the cooling resource occupancy status of the thermal management unit, a cooling resource occupancy constraint check is performed. Based on the risk isolation boundary, the fire isolation status of the node, the fire control action range of the fire isolation unit, and the fire isolation area constraints, perform fire isolation area constraint verification; Based on the risk isolation boundary, the scope of nodes prohibited from takeover, risk transfer restrictions, and node risk transfer boundaries, perform risk restriction area constraint verification; When the constraints of the station's charging and discharging power balance, DC bus current, grid-connected power fluctuation, energy storage converter load rate, cooling resource occupancy, fire isolation area, and risk restriction area are all satisfied, the negotiated prevention and control scheme is deemed to satisfy the station's safety constraints. Based on the negotiated prevention and control scheme that meets the security constraints of the entire site, security prevention and control instructions are generated and sent to the corresponding distributed control nodes to execute security prevention and control actions.

[0014] The beneficial effects of this invention are: This invention divides the battery clusters, battery compartments, energy storage converter branches, thermal management units, and fire isolation units within an energy storage power station into distributed control nodes, and establishes relationships between adjacent nodes, electrical coupling relationships, thermal coupling relationships, and control authority relationships, thereby providing a unified description of the operational relationships between the nodes within the energy storage power station. Based on this, by configuring node safety contracts for each distributed control node, the invention uniformly constrains node power safety boundaries, node heat load bearing boundaries, node risk transfer boundaries, node power takeover boundaries, and node isolation compensation obligations. This achieves standardized management of the operational capabilities, risk-bearing capabilities, and collaborative control capabilities of energy storage nodes, enabling dynamic constraints and real-time control of node operating states during the operation of the energy storage power station, and improving the safety control capabilities of the energy storage power station in complex operating scenarios.

[0015] This invention collects operational status data from distributed control nodes, calculates the remaining safety capacity of each distributed control node based on node security contracts, and uses this remaining safety capacity to identify abnormal nodes and arbitrate takeover of candidate nodes. This achieves dynamic power takeover control based on the real-time operational capabilities of nodes. Compared to existing technologies that only perform single load reduction or isolation control, this invention prioritizes candidate takeover nodes and allocates power takeover ratios based on their power takeover capabilities, thermal load capacity, risk buffering capacity, and cooling compensation capabilities. This reduces the impact of local node anomalies on the overall operation of the energy storage power station, prevents further expansion of risks caused by local node overload or heat diffusion, and improves the continuous operation capability and power regulation stability of the energy storage power station under abnormal scenarios.

[0016] This invention also performs a full-site safety constraint verification of the negotiated prevention and control scheme, uniformly constraining and controlling the station's charging and discharging power balance, DC bus current, grid-connected power fluctuations, energy storage converter load rate, cooling resource occupancy, and risk-restricted areas. Combined with risk isolation boundaries and prohibited access node ranges, it generates safety prevention and control commands, achieving coordinated control between power regulation, risk isolation, localized cooling enhancement, and fire isolation linkage within the energy storage power station. Through these methods, the spread of risks from abnormal nodes to adjacent nodes can be effectively limited, reducing the probability of thermal runaway chain reactions in the energy storage power station and improving the overall operational safety, fault handling efficiency, and multi-node collaborative prevention and control capabilities of the energy storage power station. Attached Figure Description

[0017] The accompanying drawings are provided to further illustrate the invention and form part of the specification. They are used in conjunction with embodiments of the invention to explain the invention and do not constitute a limitation thereof. In the drawings: Figure 1 This is a schematic diagram of the structure of a distributed control-based safety control system for energy storage power stations proposed in this invention. Figure 2 This is a flowchart illustrating the calculation of the remaining safety carrying capacity of a distributed control-based energy storage power station safety control system proposed in this invention. Figure 3 This is a flowchart illustrating the generation process of a negotiation-based security control scheme for a distributed control-based energy storage power station security control system proposed in this invention. Detailed Implementation

[0018] The present invention will now be described in further detail with reference to the accompanying drawings. These drawings are simplified schematic diagrams, illustrating only the basic structure of the invention, and therefore only show the components relevant to the invention.

[0019] refer to Figures 1-3A safety control system for energy storage power stations based on distributed control, comprising: The node partitioning module is used to partition multiple distributed control nodes according to the equipment structure and control responsibilities of the energy storage power station, and to establish the node association relationship between each distributed control node; The contract configuration module is used to configure node security contracts for each distributed control node based on the type, boundary parameters, and compensation obligations of the distributed control node. The data acquisition module is used to collect the operating status data of each distributed control node; The capacity calculation module is used to calculate the remaining security capacity of each distributed control node based on the running status data of each distributed control node and the corresponding node security contract. The risk identification module is used to identify the target distributed control node as an abnormal node and generate a contract default risk signal when the remaining security capacity of the target distributed control node does not meet the node security contract constraints. The takeover arbitration module is used to determine a set of candidate takeover nodes based on abnormal nodes as the source of takeover demand, contract default risk signals and node correlations, and to perform takeover arbitration based on the remaining security capacity of each node in the candidate takeover node set, thereby generating a negotiated prevention and control plan. The security verification module is used to perform site-wide security constraint verification on the negotiated prevention and control scheme, and generate security prevention and control instructions when the negotiated prevention and control scheme meets the site-wide security constraints.

[0020] In this embodiment, the energy storage power station equipment structure includes a battery cluster, a battery compartment, an energy storage converter branch, a thermal management unit, a fire isolation unit, and a station-level coordination and control unit. The control responsibilities include power regulation responsibilities, thermal management responsibilities, risk isolation responsibilities, power takeover responsibilities, and safety coordination responsibilities. The node relationships include adjacent node relationships, electrical coupling relationships, thermal coupling relationships, and control authority relationships. Adjacent node relationship refers to the association between distributed control nodes in an energy storage power station based on equipment layout location, connection distance or physical adjacency status. It is used to characterize the range of nodes that may be directly affected when an abnormal node experiences power fluctuations, heat diffusion or isolation actions. When the equipment distance between two distributed control nodes is less than a preset distance threshold, is in the same battery compartment or shares the same thermal management channel, an adjacent node relationship is established between the corresponding distributed control nodes. Electrical coupling refers to the electrical influence relationship between distributed control nodes through DC buses, AC buses, current loops, or power transmission paths. It is used to characterize the degree of influence of the charging and discharging power changes, current fluctuations, or fault isolation actions of one distributed control node on the electrical operating status of other distributed control nodes. When multiple distributed control nodes are connected to the same DC bus, the same AC bus, or the same energy storage converter branch, electrical coupling relationships are established between the corresponding distributed control nodes. Thermal coupling relationship refers to the heat influence relationship between distributed control nodes through heat conduction, heat radiation, air flow or cooling channels. It is used to characterize the degree of influence of heat change generated by one distributed control node on the temperature distribution, temperature rise rate and cooling load of other distributed control nodes. When multiple distributed control nodes share the same heat dissipation channel, the same cooling circuit or the same air flow area, thermal coupling relationship is established between the corresponding distributed control nodes. Control permission relationships refer to the control authorization scope, control priority, and control coordination relationships between distributed control nodes. They are used to characterize whether a distributed control node has the authority to perform power regulation, isolation control, cooling enhancement, takeover arbitration, or communication degradation control on other distributed control nodes. When a distributed control node has the control capability to send power regulation commands, isolation control commands, cooling enhancement commands, or communication degradation commands to another distributed control node, a control permission relationship is established between the corresponding distributed control nodes.

[0021] In this embodiment, the contract configuration module includes: Based on the energy storage power station equipment structure and control responsibilities corresponding to the distributed control nodes, the node types of the distributed control nodes are determined. The node types include battery cluster nodes, battery compartment nodes, energy storage converter branch nodes, thermal management nodes, fire isolation nodes, and station-level coordination control nodes. Based on the node type of the distributed control node, configure the corresponding node power safety boundary. The node power safety boundary includes the upper limit of allowed charging power, the upper limit of allowed discharging power, the upper limit of allowed power change rate, and the upper limit of allowed short-term power takeover. Based on the temperature limit, temperature rise rate limit, and cooling capacity limit of the distributed control node, configure the corresponding node heat load tolerance boundary. The node heat load tolerance boundary includes the upper limit of the allowed node temperature, the upper limit of the allowed node temperature rise rate, the upper limit of the allowed cooling response time, and the upper limit of the allowed heat load duration. Based on the adjacent node relationships, electrical coupling relationships, and thermal coupling relationships of the distributed control node, the corresponding node risk transfer boundary is configured. The node risk transfer boundary includes the range of nodes that are allowed to transfer risk, the range of nodes that are prohibited from transferring risk, the upper limit of the allowed risk transfer intensity, and the upper limit of the allowed risk duration. Based on the rated power capacity, rated heat load capacity, rated cooling compensation capability, and control authority relationship of the distributed control nodes, configure the corresponding node power takeover boundary. The node power takeover boundary includes the range of nodes that can be taken over, the range of nodes that cannot be taken over, the upper limit of the allowed takeover power, and the upper limit of the allowed takeover duration. Based on the power gap, heat load changes, and risk limitation requirements generated by distributed control nodes to adjacent distributed control nodes under preset abnormal isolation scenarios, corresponding node isolation compensation obligations are configured. Node isolation compensation obligations include power compensation obligations, cooling compensation obligations, risk isolation coordination obligations, and fire isolation coordination obligations. Among them, the power compensation obligation includes the allowed power takeover range, the upper limit of the allowed power takeover duration, and the upper limit of the allowed power change rate; the cooling compensation obligation includes the allowed cooling compensation range, the upper limit of the allowed cooling compensation duration, and the allowed cooling resource occupation range; the risk isolation coordination obligation includes the allowed risk blocking range, the allowed isolation duration range, and the allowed operational adjustment range; the fire isolation coordination obligation includes the allowed fire isolation range, the upper limit of the allowed fire linkage duration, and the allowed fire control action range. Based on the communication link status, communication delay limits, and control authority relationships of the distributed control nodes, configure corresponding node communication anomaly degradation obligations. Node communication anomaly degradation obligations include communication delay over-limit degradation control, communication interruption autonomous control, station-level coordination and control unit takeover control, and security control command delay execution limit. The node power safety boundary, node heat load tolerance boundary, node risk transfer boundary, node power takeover boundary, node isolation compensation obligation, and node communication anomaly degradation obligation are written into the node security contract of the corresponding distributed control node. The node security contract is bound to the node identifier of the distributed control node. The node security contract is stored in the form of a contract field table, including the node identifier field, node type field, node power safety boundary field, node heat load tolerance boundary field, node risk transfer boundary field, node power takeover boundary field, node isolation compensation obligation field, node communication anomaly degradation obligation field, and contract version field.

[0022] In this embodiment, the operating status data includes node current, node charging and discharging power, node temperature, node temperature rise rate, node state of charge, node health status, node internal resistance, node cooling response time, node communication delay, and node fire isolation status.

[0023] In this embodiment, the load capacity calculation module includes: Based on node charging and discharging power, node current, node state of charge, node health status, and node power safety boundary, the power takeover capability of distributed control nodes is determined. Specifically, the following steps are taken: First, extract the allowable charging power limit, allowable discharging power limit, allowable power change rate limit, and allowable short-term power takeover limit from the node power safety boundary. Second, determine the node's static power margin based on the difference between the node's charging / discharging power and the allowable charging power limit and allowable discharging power limit. Third, determine the node's power regulation margin based on the difference between the node's charging / discharging power change amplitude and the allowable power change rate limit within adjacent acquisition cycles. Fourth, determine the node's current carrying margin based on the allowable current carrying conditions corresponding to the node's current and the node power safety boundary. Fifth, correct the node's static power margin, node power regulation margin, node current carrying margin, and allowable short-term power takeover limit based on the node's state of charge and node health status to obtain the short-term power takeover margin. Finally, determine the minimum value among the node's static power margin, node power regulation margin, node current carrying margin, and short-term power takeover margin as the distributed control node's power takeover capability. Based on node temperature, node temperature rise rate, node internal resistance, node cooling response time, and node heat load bearing boundary, the heat load bearing capacity of the distributed control node is determined. Specifically, the following steps are taken: First, extract the upper limit of allowable node temperature, the upper limit of allowable node temperature rise rate, the upper limit of allowable cooling response time, and the upper limit of allowable heat load duration from the node heat load bearing boundary. Second, determine the node temperature margin based on the difference between the node temperature and the upper limit of allowable node temperature. Third, determine the node temperature rise margin based on the difference between the node temperature rise rate and the upper limit of allowable node temperature rise rate. Fourth, determine the node cooling response margin based on the difference between the node cooling response time and the upper limit of allowable cooling response time. Fifth, correct the node temperature margin, node temperature rise margin, node cooling response margin, and upper limit of allowable heat load duration based on the node internal resistance to obtain the heat load duration margin. Finally, determine the minimum value among the node temperature margin, node temperature rise margin, node cooling response margin, and heat load duration margin as the heat load bearing capacity of the distributed control node. The risk buffering capacity of distributed control nodes is determined by combining the node fire isolation status, node temperature rise rate, node internal resistance, node risk transfer boundary, and node association relationship. Specifically, the process involves: extracting the permitted risk transfer node range, prohibited risk transfer node range, permitted risk transfer intensity upper limit, and permitted risk duration upper limit from the node risk transfer boundary; determining the set of adjacent distributed control nodes corresponding to the distributed control node based on node association relationships; determining the risk isolation state corresponding to the distributed control node based on the node's fire isolation state; determining the node's thermal risk diffusion trend based on the node's temperature rise rate; determining the node's continuous heating trend based on the node's internal resistance; and constraining the permitted risk transfer node range, permitted risk transfer intensity upper limit, and permitted risk duration upper limit based on the set of adjacent distributed control nodes, risk isolation state, node thermal risk diffusion trend, and node continuous heating trend. Finally, determining the risk buffering capacity of the distributed control node based on the constrained permitted risk transfer node range, permitted risk transfer intensity upper limit, and permitted risk duration upper limit. The cooling compensation capability of distributed control nodes is determined based on node cooling response time, node temperature, node temperature rise rate, node isolation compensation obligation, and node heat load tolerance boundary. Specifically, the process involves: extracting cooling compensation obligations from node isolation compensation obligations; extracting the allowable cooling compensation range, the upper limit of the allowable cooling compensation duration, and the allowable cooling resource occupation range from the cooling compensation obligations; determining the node cooling response capability based on the node cooling response time; determining the node heat load growth trend based on the node temperature and the node temperature rise rate; determining the node cooling compensation constraint conditions based on the allowable node temperature upper limit, the allowable node temperature rise rate upper limit, and the allowable heat load duration upper limit in the node heat load bearing boundary; constraining the allowable cooling compensation range, the upper limit of the allowable cooling compensation duration, and the allowable cooling resource occupation range based on the node cooling response capability, the node heat load growth trend, and the node cooling compensation constraint conditions; and determining the cooling compensation capability of the distributed control node based on the constrained allowable cooling compensation range, the upper limit of the allowable cooling compensation duration, and the allowable cooling resource occupation range. The capability indicators corresponding to power takeover capability, heat load carrying capacity, risk buffering capability, and cooling compensation capability are normalized and then weighted and fused according to the bearing weight corresponding to the node type in the node security contract to obtain the remaining security bearing capacity of each distributed control node.

[0024] In this embodiment, the risk identification module includes: The remaining security capacity of each distributed control node is compared with various limiting conditions in the node security contract to identify the target distributed control node whose remaining security capacity does not meet the limiting conditions of the node security contract. Based on the contract fields in the target distributed control node that do not meet the node security contract constraints, determine the default contract entries corresponding to the target distributed control node. The default contract entries include node power security boundary default entries, node heat load bearing boundary default entries, node risk transfer boundary default entries, node power takeover boundary default entries, node isolation compensation obligation default entries, and node communication abnormal degradation obligation default entries. Based on the boundary difference corresponding to the default contract item and the node charging and discharging power of the target distributed control node, the power reduction requirement of the target distributed control node is determined. The power reduction requirement is used to characterize the amount of power that the target distributed control node needs to reduce from its current charging and discharging power to meet the node power safety boundary. Based on the node risk transfer boundary, node fire isolation status, node temperature rise rate, and node association relationship corresponding to the target distributed control node, the risk transfer restrictions of the target distributed control node are determined. The risk transfer restrictions include the range of nodes where risk transfer is prohibited, the upper limit of the allowed risk transfer intensity, and the upper limit of the allowed risk duration. Based on the node temperature, node temperature rise rate, node cooling response time, node fire isolation status, and node isolation compensation obligation of the target distributed control node, the isolation requirements of the target distributed control node are determined. The isolation requirements include the isolation method for abnormal nodes, the isolation duration range, the fire isolation linkage requirements, and the compensation requirements for adjacent distributed control nodes. The isolation method for abnormal nodes is determined based on the node temperature, node temperature rise rate, and node fire isolation status of the target distributed control node. When the node temperature or node temperature rise rate exceeds the isolation trigger condition in the node security contract, the target distributed control node is determined to adopt one of the following isolation methods: load reduction isolation, electrical isolation, thermal isolation, or fire isolation. The isolation duration range is determined based on the node cooling response time, node temperature drop status, and node isolation compensation obligation of the target distributed control node. When the node cooling response time is extended or the node temperature does not drop to within the node's heat load tolerance boundary, the isolation duration range is extended. The node temperature drop status refers to the decrease in node temperature after isolation control relative to the node temperature before isolation control, which is determined based on the difference in node temperature changes within adjacent acquisition cycles before and after isolation control. Fire isolation linkage requirements are determined based on the fire isolation status, temperature, and temperature rise rate of the target distributed control node. When the fire isolation status of the node is not activated, and the node temperature or temperature rise rate meets the fire isolation triggering conditions, a fire isolation linkage requirement is generated. The compensation requirements of adjacent distributed control nodes are determined based on the power reduction requirements of the target distributed control node, the isolation method of abnormal nodes, and the node association relationship. After the target distributed control node performs load reduction or isolation, the power compensation, cooling compensation, risk isolation coordination or fire isolation coordination requirements that the adjacent distributed control nodes need to undertake are determined based on the power takeover boundary of the adjacent distributed control nodes, the node isolation compensation obligation, and the node association relationship. When the target distributed control node has defaulted contract entries, power reduction requirements, risk transfer restrictions, or isolation requirements, the target distributed control node will be identified as an abnormal node, and the node identifier of the target distributed control node will be identified as an abnormal node identifier. By writing the abnormal node identifier, default contract entry, power reduction requirement, risk transfer restriction, and isolation requirement into the same contract default risk signal, a contract default risk signal corresponding to the abnormal node is generated.

[0025] In this embodiment, the arbitration module is taken over, including: Abnormal nodes are identified based on the abnormal node identifiers in the contract default risk signals. Based on the node association relationships corresponding to the abnormal nodes, distributed control nodes that have adjacent node relationships, electrical coupling relationships, thermal coupling relationships, or control authority relationships with the abnormal nodes are identified. The identified distributed control nodes are used as the initial takeover node set. Based on risk transfer restrictions, abnormal node isolation methods, and node power takeover boundaries, the initial takeover node set is screened for takeover eligibility to obtain a candidate takeover node set. The takeover eligibility screening includes: eliminating distributed control nodes that are not allowed to receive risk transfers from abnormal nodes based on the prohibited risk transfer node range in the risk transfer restrictions; eliminating distributed control nodes that are not allowed to participate in power takeover based on the risk isolation requirements corresponding to the abnormal node isolation methods; eliminating distributed control nodes that cannot meet power reduction requirements based on the allowed takeover power limit and allowed takeover duration limit in the node power takeover boundaries; eliminating distributed control nodes that do not have the corresponding power adjustment authority or isolation coordination authority based on control permission relationships; and eliminating distributed control nodes that trigger communication interruption autonomous control or communication delay exceeding limit degradation control based on node communication anomaly degradation obligations. The remaining distributed control nodes after screening are determined as the candidate takeover node set. Based on the remaining safe carrying capacity of each node in the candidate takeover node set, the takeover priority of each distributed control node in the candidate takeover node set is determined, and the distributed control nodes are sorted according to the takeover priority to generate the power takeover order corresponding to the candidate takeover nodes. The determination of takeover priority includes: eliminating distributed control nodes whose power takeover capacity is lower than the minimum takeover requirement corresponding to the power reduction demand; initially sorting the remaining distributed control nodes according to their power takeover capacity from largest to smallest; when the power takeover capacity is the same or the difference is less than a preset difference threshold, sorting them again according to their heat load carrying capacity from largest to smallest; when the heat load carrying capacity is the same or the difference is less than a preset difference threshold, sorting them a third time according to their risk buffer capacity from largest to smallest; when the risk buffer capacity is the same or the difference is less than a preset difference threshold, sorting them a fourth time according to their cooling compensation capacity from largest to smallest, and determining the sorting results as the takeover priority of each distributed control node. Based on the power reduction requirements, the remaining safe carrying capacity of each node in the candidate takeover node set, and the node power takeover boundary, the power takeover ratio corresponding to each candidate takeover node is determined. The power takeover ratio refers to the proportion of power allocation undertaken by the candidate takeover node in the power reduction requirements corresponding to the abnormal node. The power takeover ratio is determined according to the proportion of the remaining safe carrying capacity of the candidate takeover node to the total remaining safe carrying capacity of the candidate takeover node set, and is constrained by the upper limit of the allowed takeover power and the upper limit of the allowed takeover duration in the node power takeover boundary. Based on the cooling compensation capability, cooling response time, temperature, and temperature rise rate of each node in the candidate takeover node set, the cooling compensation priority for each candidate takeover node is determined. Specifically: candidate takeover nodes whose node temperature exceeds the upper limit of the allowable node temperature or whose temperature rise rate exceeds the upper limit of the allowable node temperature rise rate are removed; the remaining candidate takeover nodes are initially sorted according to their cooling compensation capability from largest to smallest; when the cooling compensation capabilities are the same or the difference is less than a preset difference threshold, they are sorted a second time according to their cooling response time from shortest to longest; when the cooling response times are the same or the difference is less than a preset difference threshold, they are sorted a third time according to their temperature from lowest to highest; when the temperatures are the same or the difference is less than a preset difference threshold, they are sorted a fourth time according to their temperature rise rate from lowest to highest. The sorting results are then used to determine the cooling compensation priority for each candidate takeover node. Based on risk transfer restrictions, isolation requirements, node fire isolation status, adjacent node relationships, and thermal coupling relationships, determine the risk isolation boundary between abnormal nodes and candidate takeover nodes; The risk isolation boundary refers to the isolation range used to limit the spread of risks from abnormal nodes to candidate takeover nodes. The determination of the risk isolation boundary includes: determining prohibited risk transfer nodes based on the range of prohibited risk transfer nodes; determining the isolation area based on the isolation method of abnormal nodes; determining fire-fighting linkage nodes based on the fire isolation status of nodes; determining heat diffusion associated nodes based on thermal coupling relationships; and eliminating nodes or areas whose risk transfer intensity exceeds the upper limit of the allowed risk transfer intensity or whose risk duration exceeds the upper limit of the allowed risk duration based on the upper limit of the allowed risk transfer intensity and the upper limit of the allowed risk duration. The risk isolation boundary between abnormal nodes and candidate takeover nodes is formed based on the prohibited risk transfer nodes, isolation areas, fire-fighting linkage nodes, and heat diffusion associated nodes that remain after elimination. Based on the remaining security capacity of each node in the candidate takeover node set, the node power takeover boundary, the node risk transfer boundary, the node communication anomaly degradation obligation, and the control authority relationship, the scope of nodes prohibited from takeover is determined. The scope of nodes prohibited from takeover refers to the range of distributed control nodes that are prohibited from undertaking power reduction requirements of abnormal nodes in takeover arbitration. The scope of nodes prohibited from takeover includes distributed control nodes whose remaining security capacity does not meet the takeover requirements, distributed control nodes whose node power takeover boundary does not meet the power takeover ratio requirements, distributed control nodes whose node risk transfer boundary does not allow receiving risk transfer from abnormal nodes, distributed control nodes whose communication communication abnormality degradation obligation triggers communication interruption autonomous control, and distributed control nodes that do not have the corresponding control authority relationship. The power takeover sequence, power takeover ratio, cooling compensation priority, risk isolation boundary, and prohibited takeover node range are written into the same negotiation and control scheme to generate the negotiation and control scheme corresponding to the abnormal node.

[0026] In this embodiment, the security verification module includes: The station-level coordination and control unit reads the power takeover sequence, power takeover ratio, cooling compensation priority, risk isolation boundary and prohibited takeover node range in the negotiated prevention and control plan, and determines the abnormal nodes, candidate takeover nodes, thermal management units, fire isolation units, energy storage converter branches and communication abnormal nodes that participate in the station-wide safety constraint verification. Based on the power reduction of abnormal nodes, the power taken over by candidate takeover nodes according to the power takeover ratio, and the current total charging and discharging power of the energy storage power station, a total charging and discharging power balance constraint verification is performed. The total charging and discharging power balance constraint refers to the constraint conditions used to limit the deviation range between the power withdrawal of abnormal nodes and the power access of candidate takeover nodes during the power reduction, isolation, and power takeover of abnormal nodes and candidate takeover nodes. When the difference between the total power withdrawal of abnormal nodes and the total power access of candidate takeover nodes exceeds the preset power balance threshold, it is determined that the negotiated prevention and control scheme does not meet the total charging and discharging power balance constraint. Based on the takeover power, node current, node power takeover boundary and current carrying conditions of the energy storage converter branch corresponding to the candidate takeover node, perform DC bus current constraint and energy storage converter load rate constraint verification. DC bus current constraint refers to the constraint condition used to limit the range of DC bus current change after abnormal nodes perform load reduction and isolation, and after candidate takeover nodes perform power takeover. When the predicted DC bus current after the candidate takeover node performs power takeover exceeds the upper limit of the allowable DC bus current, it is determined that the negotiated control scheme does not meet the DC bus current constraint. Energy storage converter load rate constraint refers to the constraint condition used to limit the range of load rate change of energy storage converter branches during power adjustment. When the predicted load rate after the energy storage converter branch performs power adjustment exceeds the upper limit of the allowable load rate of the energy storage converter branch, it is determined that the negotiated control scheme does not meet the energy storage converter load rate constraint. Based on the changes in grid-connected power after load reduction at abnormal nodes, power takeover at candidate nodes, and power adjustment of energy storage converter branches, a grid-connected power fluctuation constraint verification is performed. The grid-connected power fluctuation constraint refers to the constraint conditions used to limit the range of grid-connected power changes of the energy storage power station after load reduction at abnormal nodes, power takeover at candidate nodes, and power adjustment of energy storage converter branches. When the grid-connected power fluctuation amplitude after the implementation of the negotiated control scheme exceeds the preset grid-connected power fluctuation threshold, it is determined that the negotiated control scheme does not meet the grid-connected power fluctuation constraint. Based on the cooling compensation priority, the node temperature of the candidate takeover node, the node temperature rise rate, the node cooling response time, and the cooling resource occupancy status of the thermal management unit, a cooling resource occupancy constraint check is performed. The cooling resource occupancy constraint refers to the constraint condition used to limit the range of cooling resources occupied by the thermal management unit during the execution of local cooling enhancement. When the cooling compensation demand corresponding to the candidate takeover node exceeds the available cooling resources of the thermal management unit, it is determined that the negotiated prevention and control scheme does not meet the cooling resource occupancy constraint. Based on the risk isolation boundary, the fire isolation status of the node, the fire control action range of the fire isolation unit, and the fire isolation area constraints, a fire isolation area constraint verification is performed. The fire isolation area constraint refers to the constraint conditions used to limit the range of the fire isolation area when the fire isolation unit performs fire isolation linkage. When the fire isolation area corresponding to the risk isolation boundary exceeds the range of the fire isolation unit's allowed control area, it is determined that the negotiated prevention and control plan does not meet the fire isolation area constraints. Based on the risk isolation boundary, the scope of prohibited takeover nodes, risk transfer restrictions, and node risk transfer boundaries, a risk restriction area constraint verification is performed. The risk restriction area constraint refers to the constraint conditions used to limit the spread of abnormal node risks. When the risk of an abnormal node exceeds the restriction area corresponding to the risk isolation boundary, or when a distributed control node within the scope of prohibited takeover nodes participates in power takeover, it is determined that the negotiated prevention and control scheme does not meet the risk restriction area constraint. When the constraints of the station's charging and discharging power balance, DC bus current, grid-connected power fluctuation, energy storage converter load rate, cooling resource occupancy, fire isolation area, and risk restriction area are all satisfied, the negotiated prevention and control scheme is deemed to satisfy the station's safety constraints. Based on the negotiated prevention and control scheme that meets the overall site safety constraints, safety prevention and control commands are generated and sent to the corresponding distributed control nodes to execute safety prevention and control actions. The safety prevention and control commands include load reduction or isolation commands for abnormal nodes, power takeover commands for candidate takeover nodes, local cooling enhancement commands for thermal management units, fire isolation linkage commands for fire isolation units, power adjustment commands for energy storage converter branches, and degradation control commands for communication abnormal nodes.

[0027] Example 1: To verify the feasibility of this invention in practice, it was applied to a large-scale new energy storage power station in East China. This power station is equipped with multiple battery compartments, energy storage converter branches, thermal management units, and fire isolation units. During continuous charging and discharging in the high temperatures of summer, some battery clusters are prone to rapid temperature rise, concentrated local heat loads, and power takeover imbalances. Traditional centralized control methods typically require unified scheduling by the station-level control system after an anomaly is detected, which can easily lead to response delays, expanded risk spread, and sudden increases in load on adjacent equipment, making it difficult to promptly isolate local risks and dynamically take over the power supply.

[0028] During operation, the system first divides the battery compartment, energy storage converter branch, and thermal management unit into multiple distributed control nodes according to equipment structure and control responsibilities, and establishes electrical coupling, thermal coupling, and control authority relationships. During operation, each distributed control node continuously collects operational status data such as node temperature, node temperature rise rate, node charging and discharging power, node communication latency, and node fire isolation status, and calculates the remaining safety capacity in real time based on node safety contracts. When the remaining safety capacity of a battery compartment decreases due to continuous high-load operation, the risk identification module quickly identifies the corresponding default contract item and generates a contract default risk signal that includes power reduction requirements, risk transfer restrictions, and isolation requirements.

[0029] The takeover arbitration module automatically filters candidate takeover nodes based on the node relationships around the abnormal node, and generates a negotiated prevention and control plan by combining the remaining safe carrying capacity, cooling compensation capacity, and node power takeover boundary of each node. The station-level coordination and control unit further performs joint verification of grid-connected power fluctuation constraints, fire isolation zone constraints, and cooling resource occupation constraints. After meeting the station-wide safety constraints, it issues safety prevention and control commands, enabling adjacent energy storage converter branches to gradually take on part of the power load of the abnormal node, while coordinating the thermal management unit to prioritize cooling of high-temperature areas.

[0030] During actual operation, the invention completed the identification and takeover arbitration of abnormal nodes during continuous high-temperature operation, effectively limiting the range of abnormal heat diffusion. No chain overload phenomenon occurred in the energy storage converter branch. Even under communication abnormalities, it was still able to maintain local collaborative control capabilities, verifying that the invention can improve the distributed safety control and risk isolation capabilities of energy storage power stations in complex operating environments.

[0031] Table 1. Performance Comparison of the Invention and Traditional Centralized Control Methods

[0032] As can be clearly seen from Table 1, the method of the present invention is superior to the traditional method in many indicators.

[0033] The anomaly identification latency of this invention is reduced from 428ms to 351ms, a reduction of 77ms. This is because this invention continuously judges the status of each distributed control node through node security contracts and remaining security capacity, enabling abnormal nodes to be identified in advance on the local side, reducing the time required for unified judgment at the station level in traditional centralized control methods.

[0034] The fault takeover scheduling time was reduced from 963ms to 804ms, a reduction of 159ms. This is because the present invention pre-establishes node association relationships, and upon the occurrence of a contract default risk signal, it can directly filter the set of candidate takeover nodes and complete the takeover allocation based on the remaining safe carrying capacity and node power takeover boundary.

[0035] The peak node temperature rise decreased from 57.8℃ to 52.9℃, a reduction of 4.9℃. This is because the present invention considers cooling compensation capacity, node temperature rise rate, and thermal coupling relationship simultaneously during the connection process, enabling the thermal management unit to preferentially act on nodes with higher temperature rises.

[0036] The grid-connected power fluctuation rate decreased from 6.4% to 5.2%, a reduction of 1.2%. This is because the present invention performs full-site charging and discharging power balance constraint and grid-connected power fluctuation constraint verification before generating safety control commands, avoiding large power fluctuations caused by abnormal node load reduction and candidate takeover node takeover.

[0037] The number of nodes affected by the fault was reduced from 5 to 3, a reduction of 2. This is because the present invention limits the impact of abnormal nodes on adjacent nodes, electrically coupled nodes, and thermally coupled nodes by using risk isolation boundaries and prohibited takeover node ranges.

[0038] The power takeover success rate increased from 91.7% to 95.4%, an improvement of 3.7%. This is because the present invention does not simply designate a backup node to take over, but rather performs takeover arbitration by combining the remaining safety capacity, node power takeover boundaries, and control authority relationships.

[0039] The control retention rate under communication anomalies increased from 88.5% to 93.1%, an improvement of 4.6%. This is because the node security contract is configured with a node communication anomaly degradation obligation, which enables local control to be maintained even when the communication link is abnormal. The overall site security constraint satisfaction rate increased from 92.6% to 96.2%, an improvement of 3.6%, indicating that the present invention can improve the overall safety and stability of the energy storage power station.

[0040] The above are merely preferred embodiments of the present invention, but the scope of protection of the present invention is not limited thereto. Any equivalent substitutions or modifications made by those skilled in the art within the scope of the technology disclosed in the present invention, based on the technical solution and inventive concept of the present invention, should be covered within the scope of protection of the present invention.

Claims

1. A safety control system for an energy storage power station based on distributed control, characterized in that, include: The node partitioning module is used to partition multiple distributed control nodes according to the equipment structure and control responsibilities of the energy storage power station, and to establish the node association relationship between each distributed control node; The contract configuration module is used to configure node security contracts for each distributed control node based on the type, boundary parameters, and compensation obligations of the distributed control node. The data acquisition module is used to collect the operating status data of each distributed control node; The capacity calculation module is used to calculate the remaining security capacity of each distributed control node based on the running status data of each distributed control node and the corresponding node security contract. The risk identification module is used to identify the target distributed control node as an abnormal node and generate a contract default risk signal when the remaining security capacity of the target distributed control node does not meet the node security contract constraints. The takeover arbitration module is used to determine a set of candidate takeover nodes based on abnormal nodes as the source of takeover demand, contract default risk signals and node correlations, and to perform takeover arbitration based on the remaining security capacity of each node in the candidate takeover node set, thereby generating a negotiated prevention and control plan. The security verification module is used to perform site-wide security constraint verification on the negotiated prevention and control scheme, and generate security prevention and control instructions when the negotiated prevention and control scheme meets the site-wide security constraints.

2. The energy storage power station safety control system based on distributed control according to claim 1, characterized in that, The energy storage power station equipment structure includes battery clusters, battery compartments, energy storage converter branches, thermal management units, fire isolation units, and station-level coordination and control units. The control responsibilities include power regulation responsibilities, thermal management responsibilities, risk isolation responsibilities, power takeover responsibilities, and safety coordination responsibilities. The node relationships include adjacent node relationships, electrical coupling relationships, thermal coupling relationships, and control authority relationships.

3. The energy storage power station safety control system based on distributed control according to claim 1, characterized in that, The contract configuration module includes: The node type of the distributed control node is determined based on the equipment structure and control responsibilities of the energy storage power station corresponding to the distributed control node. Configure the corresponding node power safety boundary according to the node type of the distributed control node; Configure the corresponding node thermal load tolerance boundary based on the temperature limit, temperature rise rate limit, and cooling capacity limit of the distributed control node; Configure the corresponding node risk transfer boundary based on the adjacent node relationships, electrical coupling relationships, and thermal coupling relationships of the distributed control node; Configure the corresponding node power takeover boundary based on the rated power capacity, rated heat load capacity, rated cooling compensation capability, and control authority relationship of the distributed control node; Based on the power gap, heat load changes and risk limitation requirements of the distributed control node to the adjacent distributed control node under the preset abnormal isolation scenario, configure the corresponding node isolation compensation obligation; Configure corresponding node communication failure degradation obligations based on the communication link status, communication latency limits, and control permission relationships of the distributed control nodes; Write the node power safety boundary, node heat load tolerance boundary, node risk transfer boundary, node power takeover boundary, node isolation compensation obligation, and node communication anomaly degradation obligation into the node security contract of the corresponding distributed control node, and bind the node security contract to the node identifier of the distributed control node.

4. The energy storage power station safety control system based on distributed control according to claim 1, characterized in that, The operational status data includes node current, node charging and discharging power, node temperature, node temperature rise rate, node state of charge, node health status, node internal resistance, node cooling response time, node communication delay, and node fire isolation status.

5. A safety control system for an energy storage power station based on distributed control according to claim 1, characterized in that, The load capacity calculation module includes: Based on node charging and discharging power, node current, node state of charge, node health status, and node power safety boundary, the power takeover capability of distributed control nodes is determined. Based on node temperature, node temperature rise rate, node internal resistance, node cooling response time, and node heat load bearing boundary, the heat load bearing capacity of the distributed control node is determined. The risk buffering capacity of distributed control nodes is determined by combining the node fire isolation status, node temperature rise rate, node internal resistance, node risk transfer boundary, and node association relationship. The cooling compensation capability of distributed control nodes is determined based on node cooling response time, node temperature, node temperature rise rate, node isolation compensation obligation, and node heat load tolerance boundary. The capability indicators corresponding to power takeover capability, heat load carrying capacity, risk buffering capability, and cooling compensation capability are normalized and then weighted and fused according to the bearing weight corresponding to the node type in the node security contract to obtain the remaining security bearing capacity of each distributed control node.

6. The energy storage power station safety control system based on distributed control according to claim 1, characterized in that, The risk identification module includes: The remaining security capacity of each distributed control node is compared with various constraints in the node security contract to identify the target distributed control node whose remaining security capacity does not meet the constraints of the node security contract. Based on the contract fields in the target distributed control node that do not meet the node security contract constraints, determine the default contract entries corresponding to the target distributed control node. Based on the boundary difference corresponding to the default contract item and the node charging and discharging power of the target distributed control node, determine the power reduction requirement of the target distributed control node. Based on the node risk transfer boundary, node fire isolation status, node temperature rise rate, and node association relationship corresponding to the target distributed control node, determine the risk transfer limit of the target distributed control node; The isolation requirements of the target distributed control node are determined based on the node temperature, node temperature rise rate, node cooling response time, node fire isolation status, and node isolation compensation obligation. When the target distributed control node has default contract entries, power reduction requirements, risk transfer restrictions, or isolation requirements, the target distributed control node will be identified as an abnormal node, and the node identifier of the target distributed control node will be identified as an abnormal node identifier. By writing the abnormal node identifier, default contract entry, power reduction requirement, risk transfer restriction, and isolation requirement into the same contract default risk signal, a contract default risk signal corresponding to the abnormal node is generated.

7. A safety control system for an energy storage power station based on distributed control according to claim 1, characterized in that, The arbitration takeover module includes: Abnormal nodes are identified based on the abnormal node identifiers in the contract default risk signals. Based on the node association relationships corresponding to the abnormal nodes, distributed control nodes that have adjacent node relationships, electrical coupling relationships, thermal coupling relationships, or control authority relationships with the abnormal nodes are identified. The identified distributed control nodes are used as the initial takeover node set. Based on risk transfer restrictions, abnormal node isolation methods, and node power takeover boundaries, the initial takeover node set is screened for takeover eligibility to obtain a candidate takeover node set. Based on the remaining safe carrying capacity of each node in the candidate takeover node set, the takeover priority of each distributed control node in the candidate takeover node set is determined, and the distributed control nodes are sorted according to the takeover priority to generate the power takeover order corresponding to the candidate takeover nodes. Based on the power reduction requirements, the remaining safe carrying capacity of each node in the candidate takeover node set, and the node power takeover boundary, determine the power takeover ratio corresponding to each candidate takeover node. Based on the cooling compensation capability, cooling response time, temperature and temperature rise rate of each node in the candidate takeover node set, the cooling compensation priority of each candidate takeover node is determined. Based on risk transfer restrictions, isolation requirements, node fire isolation status, adjacent node relationships, and thermal coupling relationships, determine the risk isolation boundary between abnormal nodes and candidate takeover nodes; Based on the remaining security capacity of each node in the candidate takeover node set, the node power takeover boundary, the node risk transfer boundary, the node communication anomaly degradation obligation, and the control authority relationship, the scope of nodes prohibited from takeover is determined. The power takeover sequence, power takeover ratio, cooling compensation priority, risk isolation boundary, and prohibited takeover node range are written into the same negotiation and control scheme to generate the negotiation and control scheme corresponding to the abnormal node.

8. A safety control system for an energy storage power station based on distributed control according to claim 1, characterized in that, The security verification module includes: The station-level coordination and control unit reads the negotiated prevention and control plan and identifies the abnormal nodes, candidate takeover nodes, thermal management units, fire isolation units, energy storage converter branches, and communication abnormal nodes that participate in the station-wide safety constraint verification. Based on the load reduction power of abnormal nodes, the power taken over by candidate takeover nodes according to the power takeover ratio, and the current total charging and discharging power of the energy storage power station, perform a total charging and discharging power balance constraint verification. Based on the takeover power, node current, node power takeover boundary and current carrying conditions of the energy storage converter branch corresponding to the candidate takeover node, perform DC bus current constraint and energy storage converter load rate constraint verification. Based on the changes in grid-connected power after load reduction at abnormal nodes, power takeover of candidate nodes, and power adjustment of energy storage converter branches, perform grid-connected power fluctuation constraint verification. Based on the cooling compensation priority, the node temperature of the candidate takeover node, the node temperature rise rate, the node cooling response time, and the cooling resource occupancy status of the thermal management unit, a cooling resource occupancy constraint check is performed. Based on the risk isolation boundary, the fire isolation status of the node, the fire control action range of the fire isolation unit, and the fire isolation area constraints, perform fire isolation area constraint verification; Based on the risk isolation boundary, the scope of nodes prohibited from takeover, risk transfer restrictions, and node risk transfer boundaries, perform risk restriction area constraint verification; When the constraints of the station's charging and discharging power balance, DC bus current, grid-connected power fluctuation, energy storage converter load rate, cooling resource occupancy, fire isolation area, and risk restriction area are all satisfied, the negotiated prevention and control scheme is deemed to satisfy the station's safety constraints. Based on the negotiated prevention and control scheme that meets the security constraints of the entire site, security prevention and control instructions are generated and sent to the corresponding distributed control nodes to execute security prevention and control actions.