A mobile energy storage device remote management and control method based on a multi-level security policy
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-05-11
- Publication Date
- 2026-08-11
AI Technical Summary
[0003]然而,现有远程管控机制普遍采用“硬锁机”式的直接断电策略,未充分评估负载端的实时工况;若设备正为电梯、医疗仪器或连续生产线等关键负荷供电,瞬间断电极易引发安全事故,系统安全冗余不足
1.安全性显著提升
Smart Images

Figure CN122553532A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of computer technology, and specifically to a method for remote control of mobile energy storage devices based on a multi-level security strategy. Background Technology
[0002] With the rapid development of new energy power systems, mobile energy storage devices are increasingly being used as key equipment for emergency power supply, peak shaving and frequency regulation, and off-grid operations. To ensure the safe operation of high-value assets and contract fulfillment, remote control technology has become a core industry requirement. Current mainstream solutions utilize a battery management system (BMS) and communication module to construct a two-way encrypted channel, combined with dynamic key authentication and heartbeat monitoring mechanisms, to achieve real-time monitoring of device operating status, geographical location, and authorized permissions. In abnormal situations, remote interlock commands can be triggered to cut off the power circuit and terminate power output.
[0003] However, existing remote control mechanisms generally employ a "hard-lock" direct power-off strategy, failing to adequately assess the real-time operating conditions of the load. If the equipment is supplying power to critical loads such as elevators, medical instruments, or continuous production lines, a sudden power outage can easily trigger safety accidents, resulting in insufficient system safety redundancy. Furthermore, existing solutions lack effective defenses against unauthorized physical disassembly. If the communication module is intentionally removed, causing a heartbeat interruption, the system often remains in its last operating state, lacking fault-oriented safety logic, thus rendering remote control functionality ineffective. In addition, current control logic often exhibits binary characteristics of "full power" or "zero power," failing to retain the basic power supply capacity of essential loads while stripping away the core usability of the equipment, making it difficult to achieve a dynamic balance between safety constraints and control effectiveness.
[0004] Therefore, there is an urgent need for a remote control method for mobile energy storage devices based on a multi-level safety strategy, which can systematically solve the fundamental contradiction between safety, reliability and control accuracy in existing technologies by means of graded response, smooth derating and zero-current switching mechanisms, while ensuring the safety of critical loads. Summary of the Invention
[0005] The purpose of this invention is to provide a remote control method for mobile energy storage devices based on a multi-level security strategy, which can effectively solve the problems mentioned in the background art.
[0006] To achieve the above objectives, the technical solution adopted by the present invention is as follows: A remote control method for mobile energy storage devices based on a multi-level security strategy includes the following specific steps: Step 1: Link encryption and heartbeat construction: The battery management system and the communication module establish a key interaction mechanism based on a dynamic asymmetric encryption algorithm, and initially generate a session key K1 through ECDH negotiation; thereafter, an encrypted heartbeat packet containing a time-varying factor and the association with the previous state is generated, forming an irreversible chain structure. Each time an encrypted heartbeat packet is generated, the security chip uses the ciphertext digest H of the previous cycle... n-1 Current timestamp T n And the device UID, through the key derivation function KDF(SHA-256, K1|H n-1 | T n Generate temporary encryption key K n Step 1: Encrypting the current heartbeat packet to achieve periodic dynamic evolution of the key; Step 2: Multi-dimensional real-time monitoring of operating conditions: Real-time monitoring of the location information, contract fulfillment status, and heartbeat integrity of the energy storage device, and synchronously collecting the DC-side output current and AC-side load feedback signal of the energy storage converter; Step 3: Graded safety response execution: Level 1: Limiting warning: If a geofence overstepping or overdue payment warning is triggered, a pop-up window and voice warning are triggered on the local human-machine interface to maintain the rated power output; Level 2: Limiting dynamic derating: If the warning timeout occurs, the battery management system issues a speed limiting command to the energy storage converter, and forcibly and smoothly reduces the output power to a lower level by adjusting the duty cycle of the converter's insulated gate bipolar transistor. A predetermined range of rated power is used to maintain basic life-sustaining loads and deprive the main operational capabilities; a three-level safety interlock: when the system receives a shutdown command or a heartbeat loss command, it enters a locked state; the battery management system continuously monitors the output current, and only when the output current is detected to be lower than the safe current threshold for a preset time, the battery management system controls the high-voltage contactor to disconnect the physical circuit, achieving zero-current switching; the safe current threshold is set according to the system's nominal voltage to ensure that the corresponding power does not exceed 1.2 times the maximum power consumption of the life-sustaining load; in mobile energy storage systems with a nominal voltage of 48V to 800V, this threshold is preferably 0.3A to 0.8A.
[0007] Preferably, in the dynamic derating stage of the secondary limit in step 3, the energy storage converter enters the survival mode. By adjusting the current limit of its internal control loop, the energy storage device can only drive low-power loads such as emergency lighting and controllers. For power loads such as elevators, cranes, or high-power precision machine tools, since their starting current far exceeds the maximum power supply capacity after the secondary limit, the energy storage converter automatically triggers soft current limiting protection, causing heavy equipment to fail to start. Thus, the equipment's usability is substantially locked without cutting off the power supply.
[0008] Preferably, in step 3, the three-level limit safety interlocking stage introduces a working condition monitoring window. When the cloud sends a shutdown command, the battery management system does not immediately disconnect the high-voltage contactor, but first forces the load to stop through the second-level speed limit. Only when the load actively stops running and the output current drops below the safe current threshold, the battery management system captures this physical characteristic and performs the disconnection action to ensure that the contactor is safely shut down without the risk of arcing and when the load is in a non-operating state.
[0009] Preferably, in step 1, the communication module has a built-in security chip that calculates a hash random number at fixed time intervals and sends it to the battery management system through an encrypted channel. The battery management system and the communication module form a logical parasitic relationship. Once the communication module is physically removed or the signal line is cut, the battery management system will automatically determine that the device has been stolen or maliciously tampered with based on the fault-oriented security principle because it cannot receive the correct key feedback within a preset time. It will also prohibit regular local manual reset and can only be unlocked through preset security authentication credentials or physical access tools.
[0010] Preferably, the safe current threshold is set within a preset range, and the preset time is also set within a specific time period. In a preferred embodiment, the safe current threshold and the preset time adopt a parameter combination that has been verified by actual testing to take into account both the continuous operation of the life support load and the identification of the load's complete shutdown state. The safe current threshold is set according to the system's nominal voltage to ensure that the corresponding power does not exceed 1.2 times the maximum power consumption of the life support load. In a mobile energy storage system with a nominal voltage of 48V to 800V, this threshold is preferably 0.3A to 0.8A, with a typical value of 0.5A.
[0011] Preferably, the data fusion mechanism for real-time monitoring of multi-dimensional working conditions in step 2 includes: comparing location information with the electronic geofence database in real time, periodically synchronizing and verifying contract performance status with the cloud billing system, verifying the consistency of heartbeat integrity with the encrypted sequence within a preset time window, and cross-verifying the DC-side output current with the AC-side load feedback signal to eliminate misjudgments caused by a single sensor failure.
[0012] Preferably, the triggering conditions for the first-level restriction warning in step 3 also include abnormal device operating parameters, invalid authorized identity, or communication link quality deterioration to below a preset threshold; the pop-up content of the local human-machine interface includes the type of abnormality, the time of occurrence, and suggested operation guidance, and the voice warning adopts a multi-language configurable broadcast mode, with a broadcast frequency of once per preset period until the warning is lifted.
[0013] Preferably, the dynamic asymmetric encryption algorithm adopts an elliptic curve cryptography system, the key length meets the security strength requirements, the time step period of the encrypted heartbeat packet is within a preset time range, and each heartbeat packet contains a timestamp, a unique device identifier, and a ciphertext digest of the previous period, forming an irreversible chain encryption structure.
[0014] Preferably, the predetermined ratio range of the rated power is a critical effective range determined through extensive simulation and field testing; when it is below the lower limit of this range, the basic power consumption of the communication module, controller and positioning unit cannot be maintained, resulting in the loss of remote monitoring function; when it is above the upper limit of this range, it can still drive some small and medium-sized operating equipment, but cannot effectively deprive the core use value of the equipment.
[0015] Preferably, the drive circuit of the high-voltage contactor integrates a micro-current steady-state detection unit, which monitors the main circuit current waveform in real time before performing the disconnection action. The tripping command is only issued when the instantaneous current value is lower than the safe current threshold for several consecutive cycles, further ensuring the reliability of zero-current switching.
[0016] Compared with the prior art, the present invention has the following beneficial effects: 1. Significantly improved security The three-level restriction safety interlocking mechanism completely avoids the risk of secondary accidents caused by forced power cut-off when the critical load is energized in the traditional "hard lock" mode; the condition-aware interlocking logic ensures that the high-voltage contactor only performs the tripping operation after the output current approaches zero and remains stable, realizing true zero-current switching and greatly reducing the probability of arc damage and equipment damage.
[0017] 2. Enhanced precision and binding force of control. The non-binary hierarchical response strategy breaks the binary limitation of existing technologies that use "full power" or "zero power"; the two-level dynamic derating precisely limits the output power to a predetermined ratio range, which not only ensures the life-sustaining power supply for emergency lighting, communication and control systems, but also prevents heavy power equipment from operating due to insufficient starting current, thus achieving a dynamic balance between asset management effectiveness and basic functional availability.
[0018] 3. Enhanced resistance to physical attacks The hardware-level encrypted anti-tamper self-locking mechanism automatically triggers a three-level interlock within a preset time after the communication module is illegally removed, based on the logical parasitic relationship between the BMS and the communication module, without relying on external network signals. This inherent fault-oriented safety design effectively solves the security vulnerability of existing systems that maintain the last running state due to the loss of heartbeat, and significantly improves the asset protection level in offline scenarios.
[0019] 4. Improved system reliability and robustness Multi-dimensional real-time monitoring integrates four data sources: location, contract, heartbeat, and electrical parameters. Through a cross-validation mechanism, it effectively suppresses false triggering caused by a single sensor failure. Dynamic asymmetric encrypted heartbeat packets combined with a chained timestamp structure ensure the integrity of the communication link and the ability to resist replay attacks, providing a solid foundation for the reliable execution of remote control commands. Attached Figure Description
[0020] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only for this invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0021] Figure 1 This is a schematic diagram of the overall technical solution architecture of a remote control method for mobile energy storage devices based on a multi-level security strategy proposed in this invention. Figure 2 This is a schematic diagram of the core principle framework of the three-level restriction security response mechanism in this invention; Figure 3 This is a logical flowchart of the multi-dimensional real-time monitoring of working conditions and dynamic encrypted heartbeat collaborative verification in this invention. Detailed Implementation
[0022] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to specific embodiments.
[0023] In the aforementioned remote control method for mobile energy storage devices based on multi-level security strategies, step 1, link encryption and heartbeat construction, specifically includes the following operational procedures: The battery management system and the communication module first establish an initial handshake connection through the physical layer. This connection uses a high-speed serial interface such as SPI or UART to ensure low-latency data interaction. The communication module is powered by the battery management system through a dedicated power line, and an anti-tamper detection circuit is provided between the two. When the communication module is removed or the signal / power line is cut, the anti-tamper detection circuit outputs a low-level signal to the BMS. The BMS immediately determines that it has been physically tampered with and forces a jump to the level 3 restriction security lockout mode within 100ms, without waiting for the heartbeat timeout. Subsequently, the security chip built into the communication module initiates the key negotiation protocol. This security chip is a dedicated security element conforming to the Chinese national cryptographic standard SM2 or the international ECC standard, and it contains a non-derivative private key seed. The battery management system generates a temporary public key and sends it to the security chip. The security chip uses its private key to sign the temporary public key and returns an initial authentication packet containing a timestamp T0, a device unique identifier UID, and a signature value S0. After the battery management system verifies the signature validity, both parties generate a shared session key K1 based on the elliptic curve Diffie-Hellman (ECDH) key exchange mechanism. This key is 256 bits long and meets the NIST SP800-131A security strength requirements. After this, the system enters the heartbeat maintenance phase. The security chip performs a hash random number generation operation at a fixed period of T=1000ms, and each calculation is based on the ciphertext digest H of the previous period. n-1 Current timestamp T n And the device UID, using the SHA-256 algorithm to generate a new hash value H n The hash value is then encrypted using the session key K1 using AES-256-GCM to form an encrypted heartbeat packet; the heartbeat packet structure includes the field: timestamp T. n (4 bytes), Device UID (16 bytes), Ciphertext H n (32 bytes), Message Authentication Code (MAC) (16 bytes); After receiving the heartbeat packet, the battery management system first verifies the integrity of the MAC, and then decrypts it to obtain the H... n and with the locally cached H n-1 A chain comparison is performed. If a valid heartbeat packet is not received within a 1500ms window for three consecutive times, the communication link is determined to be abnormal. In particular, once the communication module is physically removed or the signal line is cut, the security chip stops sending heartbeat packets. If the battery management system cannot receive the correct key feedback within the 1500ms timeout threshold, the fault-oriented security logic is immediately triggered, and regular local manual reset is prohibited. The lockout can only be released through preset security authentication credentials or physical access tools.
[0024] In the above method, step 2, multi-dimensional real-time monitoring of operating conditions, is specifically executed as follows: The system synchronously collects four types of heterogeneous data sources, including location information, contract performance status, heartbeat integrity, and electrical parameters; the location information is acquired by a dual-frequency GNSS receiver integrated in the communication module, with a positioning accuracy better than 2 meters (CEP50), a sampling frequency of 1Hz, and the original latitude and longitude coordinates are converted to the WGS-84 coordinate system and then compared in real time with the electronic geofence database pre-stored in the non-volatile memory of the battery management system. The geofence is stored in GeoJSON format and supports polygon, circular, and composite area definitions. The comparison algorithm uses the ray cross method to determine whether the device has crossed the boundary; the contract performance status establishes an HTTPS secure channel with the cloud billing system through the communication module, and periodically synchronizes the account balance, lease term, and authorization status every 30 seconds. The synchronized data is transmitted via TLS. 1.3 Encrypted transmission: If the balance is detected to be below a preset threshold (e.g., 50 yuan) or the authorization validity period has expired, it is marked as an overdue payment warning state; The heartbeat integrity monitoring module continuously parses the encrypted heartbeat packets generated in step 1 to verify their timestamp continuity, sequence number increment, and MAC consistency. If replay attack characteristics (e.g., timestamp rollback) or sequence interruption are found, the heartbeat is marked as abnormal; The electrical parameter acquisition unit monitors the DC side output current of the energy storage converter in real time through a high-precision Hall current sensor. The sensor has a range of ±1000A, an accuracy class of 0.5%, and a sampling frequency of 10kHz. It also acquires load feedback signals, including three-phase voltage, via an AC-side voltage / current transformer. Three-phase current and power factor cosφ; the multi-dimensional data fusion engine cross-validates the above four types of data: when location out-of-bounds and overdue payment occur simultaneously, the warning priority is increased; when the heartbeat is abnormal but the electrical parameters show that the device is still running under high load, network jitter misjudgment is ruled out; when Calculate power on the AC side When the deviation exceeds 5%, the sensor self-diagnosis program is triggered, and the system switches to the redundant sensor channel. All monitoring data is cached in the circular buffer of the battery management system in the form of structured logs with a buffer depth of 10 minutes, and supports resume transmission after network interruption.
[0025] In the above method, step 3, the hierarchical security response execution, is specifically divided into three levels of operational logic: During the Level 1 restriction warning phase, when the multi-dimensional operating condition monitoring module detects either a geofence breach or an overdue payment warning, the battery management system immediately activates the local human-machine interface (HMI), displaying a full-screen warning window on the 7-inch TFT-LCD screen. The window content includes the anomaly type (e.g., "geofence breach" or "insufficient account balance"), the occurrence time (accurate to the second), and suggested operation instructions (e.g., "Please contact the operation center to renew" or "Return to the authorized operating area"). Simultaneously, the voice synthesis module initiates multi-language broadcasting, supporting three preset languages: Chinese, English, and Spanish. The broadcast content is consistent with the pop-up window, and the broadcast frequency is once every 30 seconds until the warning status is lifted. During this phase, the energy storage converter maintains its rated power output, all loads are powered normally, and the system only provides visual and auditory warnings without interfering with the power output capability.
[0026] The Level 2 dynamic derating phase is automatically triggered after the Level 1 warning continuously exceeds the preset timeout threshold (default 10 minutes). The battery management system sends a speed-limiting command to the energy storage converter. This command is transmitted via the CAN 2.0B bus at a baud rate of 100kbps and includes the target power percentage parameter. Upon receiving the command, the energy storage converter's digital signal processor (DSP) adjusts the pulse width modulation (PWM) duty cycle of the IGBT drive circuit to reduce the output power. The derating is forced to a smooth rate of 5% to 15% of the rated power; this derating process is achieved using an exponential decay curve with a time constant τ = 5 seconds to avoid voltage sags caused by power step changes; in sustainment mode, the current limit of the internal control loop of the energy storage converter is reset to [value missing]. ,in The rated output current is sufficient to drive low-power sustainment loads such as emergency lighting (typical power consumption 50W), the battery management system itself (20W), communication modules (10W), and positioning units (5W), with a total power consumption of approximately 85W. However, for power loads such as elevators (starting current ≥300A), cranes (starting current ≥500A), or high-power precision machine tools (starting current ≥200A), their starting current requirements far exceed the maximum power supply capacity after the secondary derating (corresponding to a current of approximately 15A). The soft current limiting protection mechanism of the energy storage converter is automatically triggered, resulting in the output voltage dropping below the undervoltage threshold, causing heavy equipment to fail to complete the starting process, thus substantially locking in the equipment's usability without cutting off the power supply. Actual test data shows that when a mobile energy storage device with a rated power of 100kW enters the secondary derating stage, the output power stabilizes between 5kW and 15kW, the sustainment load maintenance rate is 100%, while the starting success rate of loads above 5kW drops to 0%. The predetermined ratio range is based on the total power consumption of the equipment's sustainment load. With rated power Calculation determined, satisfying ,in For the maximum power consumption of the sustaining load, This is the minimum startup power consumption for the core operating load; for typical mobile energy storage devices, this predetermined percentage range is dynamically set based on the ratio of life-sustaining load power consumption to rated power, preferably 5% to 15%.
[0027] The Level 3 safety interlock phase is initiated upon receiving a shutdown command from the cloud or triggering fault-guided safety logic due to heartbeat loss. The battery management system first enters a locked-out state, but instead of immediately disconnecting the high-voltage contactor, it performs a Level 2 speed limiting operation, reducing the output power to 5%–15%, forcing all operating loads to stop. Subsequently, the system opens a condition monitoring window to continuously monitor the DC-side output current. Only when detected Physical disconnection is only performed after the current is below the safe current threshold I0 and I0≈0 for a preset time t. In the preferred embodiment, I0 is set to 0.5A and t is set to 200ms. This parameter combination has been verified by extensive field tests: 0.5A is sufficient to cover the minimum operating current of the life-sustaining load (the standby current of the communication module is about 0.3A), while 200ms can effectively filter out transient load fluctuations (such as brief current spikes caused by relay release). The current monitoring uses a sliding window averaging algorithm with a window width of 100 sampling points (corresponding to 10ms). When 20 consecutive windows (i.e., 200ms) are reached, the current is measured. When the average value of the current is below 0.5A, the load is determined to be completely shut down. At this time, the battery management system sends a trip command to the high-voltage contactor drive circuit. The drive circuit integrates a micro-current steady-state detection unit to sample the main circuit current waveform in real time. Only when the instantaneous current value is below 0.5A for three consecutive sampling observation windows (60ms) will the contactor coil be finally triggered to disconnect, ensuring physical isolation is completed in a true zero-current state and achieving arc-free switching. After the contactor is disconnected, the system enters a locked state, prohibiting any local or remote reset operation until maintenance personnel manually unlock it using a physical key switch.
[0028] To verify the technical effect of this invention, the following specific application example is constructed: A mobile energy storage device with a rated power of 200kW is deployed in a container yard of a port to provide auxiliary power for quay cranes; the device is configured with a geofence of a circular area with a radius of 500 meters, and the contract is valid until 24:00 on the same day; at 23:30 on the same day, the device moves out of the geofence boundary due to work scheduling, triggering a level one warning, and the HMI pop-up window prompts "geofence exceeded", with voice broadcast once every 30 seconds; by 23:45, the warning timeout, and the system automatically enters level two derating, with the output power smoothly reduced from 200kW to 12kW. (6%); At this time, the quay crane attempted to start, but its starting current requirement reached 600A (corresponding to a power of about 120kW), far exceeding the 12kW power supply capacity. The converter triggered soft current limiting, and the output voltage dropped to 320V (below the nominal value of 380V). The crane control system reported "power abnormality" and stopped starting. After the operator contacted the operation center to renew the contract, the geofence was reauthorized, the warning was lifted, and the system resumed full power output. At 00:10 the next day, the cloud issued a shutdown command due to the contract expiration. The BMS first reduced the power to 10kW, and the quay crane automatically stopped because it could not maintain operation. The voltage gradually decreased from 80A to 0.4A over 250ms; confirmed by BMS. After the current is less than 0.5A and lasts for more than 200ms, the high-voltage contactor is driven to disconnect. When the contactor drive circuit detects that the current is less than 0.5A for three consecutive cycles, it performs the tripping operation to achieve zero-current switching. Throughout the process, the emergency lighting and communication modules continue to work to ensure on-site safety and remote monitoring capabilities.
[0029] Another application scenario is a hospital emergency power supply system: a 100kW mobile energy storage device provides backup power for the operating room UPS; when the device is illegally towed out of the hospital area (geofence crossing) and not dealt with in time, it enters level two derating (7kW) after 10 minutes; at this time, the UPS switches to battery mode due to insufficient input power, but critical equipment such as operating room lighting and monitors are still maintained by the UPS battery, and no power outage occurs; if level three interlocking is further triggered, the system waits for the UPS load to be completely transferred to the internal battery ( The contactor is disconnected only after the voltage drops to 0.3A and remains there for 300ms to ensure patient safety.
[0030] Example 2 In another embodiment, the dynamic asymmetric encryption algorithm adopts the SM2 elliptic curve cryptosystem, with a key length of 256 bits and a time step T of 800ms for the encrypted heartbeat packet. Each heartbeat packet contains a timestamp (Unix millisecond time), a unique device identifier (128-bit UUID), and a ciphertext digest of the previous period, forming an irreversible chain encryption structure. The chain verification mechanism ensures that even if a single heartbeat packet is intercepted, the keys before and after cannot be deduced, significantly enhancing the resistance to replay attacks.
[0031] The data fusion mechanism for the multi-dimensional real-time monitoring of operating conditions has been further optimized: the comparison of location information with geofences adopts an improved R-tree spatial indexing algorithm, improving query efficiency by 3 times; digital signature verification is added to the contract status synchronization to prevent man-in-the-middle tampering; and a Kalman filter is introduced for cross-verification of electrical parameters. State estimation is performed with AC power to effectively suppress sensor noise; when a single sensor fails, the system automatically switches to model-based virtual sensor output to maintain monitoring continuity.
[0032] During the secondary limit dynamic derating stage, the IGBT duty cycle adjustment strategy adopts adaptive control: the target power percentage is automatically fine-tuned according to the load type; for purely resistive loads (such as heaters), the target is set to 5%; for motor loads, the target is set to 12%; this strategy is implemented through a load characteristic identification module, which analyzes the AC side current harmonic content and power factor change rate to classify the load type in real time.
[0033] The safety current threshold I0 and preset time t of the three-level interlock adopt a dynamic adjustment mechanism: in low temperature environment (<0℃), I0 is increased to 0.8A to compensate for sensor drift; in high altitude area (>3000m), t is extended to 300ms to cope with the extended arc maintenance time caused by thin air; the parameter adjustment is based on the environmental sensor array, including temperature, air pressure and humidity probes.
[0034] Example 3 In another implementation, the hardware-level encrypted anti-tamper self-locking mechanism is enhanced to a two-way logical parasitic mechanism: not only does the BMS monitor the heartbeat of the communication module, but the communication module also monitors the operating status of the BMS in reverse; the BMS sends a status heartbeat to the security chip every 500ms, and if the security chip does not receive it twice in a row, it will actively cut off its own power supply and erase the key; this two-way monitoring ensures that the removal of any component will trigger a three-level lockout.
[0035] The high-voltage contactor drive circuit integrates dual redundant current detection channels: the main channel uses a Hall sensor, and the backup channel uses a shunt + isolation amplifier; the data from the two channels are processed independently, and only when both are confirmed... Only when I0 and it lasts for t, the opening command output is allowed; this design meets the requirements of IEC 61508 SIL2 functional safety level.
[0036] Multi-dimensional working condition monitoring adds abnormal equipment operation parameters as the triggering condition for the first-level warning: including the battery cell voltage difference > 50 mV, insulation resistance < 1 MΩ, PCS radiator temperature > 85 °C, etc.; the HMI pop-up window content is dynamically generated, including specific abnormal parameter values and historical trend charts; voice warning supports customizing the broadcast content and is synthesized in real time through the TTS engine.
[0037] The above shows and describes the basic principles, main features and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited by the above embodiments, and the above embodiments and descriptions in the specification are only preferred embodiments of the present invention. Without departing from the spirit and scope of the present invention, the present invention will have various changes and improvements, and these changes and improvements all fall within the scope of the present invention claimed. The scope of the present invention claimed is defined by the appended claims and their equivalents.
Claims
1. A method for remote control of mobile energy storage devices based on a multi-level security strategy, characterized in that, Includes the following steps: Step 1: Link Encryption and Heartbeat Construction: The battery management system and the communication module establish a key exchange mechanism based on a dynamic asymmetric encryption algorithm to generate an encrypted heartbeat packet containing a time-varying factor and the association with the previous state, forming an irreversible chain structure. Step 2: Real-time monitoring of multi-dimensional operating conditions: Real-time monitoring of the location information, contract fulfillment status, and heartbeat integrity of the energy storage equipment, and synchronously collecting the DC-side output current and AC-side load feedback signal of the energy storage converter; Step 3: Execution of graded security response: Level 1 Limitation Warning: If a geofence overtravel or overdue payment warning is triggered, a pop-up window and voice alert will be triggered on the local human-machine interface to maintain rated power output; Level 2 dynamic derating limit: If the warning timeout is exceeded, the battery management system issues a speed limit command to the energy storage converter, and forces the output power to be smoothly reduced to a predetermined proportion range of rated power by adjusting the duty cycle of the converter's insulated gate bipolar transistor, so as to maintain basic life-sustaining load and deprive the main operating capability. Three-level safety interlock: When the system receives a shutdown command or a heartbeat loss command, it enters a locked state; the battery management system continuously monitors the output current, and only when the output current is detected to be lower than the safe current threshold for a preset time, the battery management system controls the high-voltage contactor to disconnect the physical circuit, achieving zero-current switching; the safe current threshold is set according to the system's nominal voltage to ensure that the corresponding power does not exceed 1.2 times the maximum power consumption of the sustaining load; in mobile energy storage systems with a nominal voltage of 48V to 800V, this threshold is preferably 0.3A to 0.8A.
2. The remote control method for mobile energy storage devices based on multi-level security strategies according to claim 1, characterized in that, In step 3, during the dynamic derating stage of the secondary limit, the energy storage converter enters a survival mode. By adjusting the current limit of its internal control loop, the energy storage device can only drive emergency lighting, controllers, and communication modules. For power loads whose starting current demand exceeds the maximum power supply capacity after the secondary limit, the energy storage converter automatically triggers soft current limiting protection, causing such loads to fail to start.
3. The remote control method for mobile energy storage devices based on multi-level security strategies according to claim 2, characterized in that, In step 3, the three-level limit safety interlocking stage introduces a working condition monitoring window. When the cloud sends a shutdown command, the battery management system first performs a two-level limit dynamic derating operation to force the load to stop. Only when the load stops running and the output current drops below the safe current threshold for a preset time, does the battery management system control the high-voltage contactor to disconnect the physical circuit.
4. The remote control method for mobile energy storage devices based on multi-level security strategies according to claim 1, characterized in that, In step 1, the communication module has a built-in security chip that calculates a hash random number at fixed time intervals and sends it to the battery management system through an encrypted channel. The battery management system and the communication module form a logical parasitic relationship. Once the communication module is physically removed or the signal line is cut, the battery management system will automatically determine that the device has been stolen or maliciously tampered with if it cannot receive the correct key feedback within a preset time, and will be forced to jump to the three-level restricted security lockout mode.
5. The remote control method for mobile energy storage devices based on multi-level security strategies according to claim 1, characterized in that, The data fusion mechanism for real-time monitoring of multi-dimensional operating conditions in step 2 includes: comparing location information with the electronic geofence database in real time, periodically synchronizing and verifying contract performance status with the cloud billing system, verifying the consistency of heartbeat integrity with the encrypted sequence within a preset time window, and cross-verifying the DC-side output current with the AC-side load feedback signal to eliminate misjudgments caused by a single sensor failure.
6. The remote control method for mobile energy storage devices based on a multi-level security strategy according to claim 1, characterized in that, The triggering conditions for the Level 1 restriction warning in step 3 also include abnormal device operating parameters, invalid authorized identity, or communication link quality deterioration to below a preset threshold; the pop-up content of the local human-machine interface includes the type of abnormality, the time of occurrence, and suggested operation guidance; the voice warning adopts a multi-language configurable broadcast mode, and the broadcast frequency is once per preset period until the warning is lifted.
7. The remote control method for mobile energy storage devices based on multi-level security strategies according to claim 1, characterized in that, The dynamic asymmetric encryption algorithm adopts an elliptic curve cryptography system. The time step period of the encrypted heartbeat packet is within a preset time range. Each heartbeat packet contains a timestamp, a unique device identifier, and a ciphertext digest of the previous period, forming an irreversible chain encryption structure.
8. The remote control method for mobile energy storage devices based on multi-level security strategies according to claim 1, characterized in that, The predetermined ratio range is dynamically set based on the ratio of the power consumption of the life support load to the rated power, preferably 5% to 15%. This range is determined by simulation and actual measurement. When the range is lower than the lower limit, the basic power consumption of the communication module, controller and positioning unit cannot be maintained. When the range is higher than the upper limit, it can still drive some small and medium-sized operating equipment.
9. The remote control method for mobile energy storage devices based on multi-level security strategies according to claim 1, characterized in that, The drive circuit of the high-voltage contactor integrates a micro-current steady-state detection unit, which monitors the main circuit current waveform in real time before performing the disconnection action. The tripping command is only issued when the instantaneous current value is lower than the safe current threshold for several consecutive cycles, ensuring the reliability of zero-current switching.
10. The remote control method for mobile energy storage devices based on a multi-level security strategy according to claim 1, characterized in that, The safe current threshold is set to 0.5 amperes, and the preset time is 200 milliseconds. This parameter combination has been verified by field tests and can cover the minimum operating current of the life-sustaining load and effectively filter out transient load fluctuations, ensuring accurate identification of the load in a completely stopped state.