Multi-channel DC monitoring and protection system for photovoltaic and / or battery storage systems with system-specific normal state initialization, local anomaly detection, deterministic protection logic, channel-wise separation, lock / acknowledge logic and local event memory

The multi-channel DC monitoring and protection system addresses the challenge of distinguishing between normal and fault states in photovoltaic and battery storage systems by employing plant-specific modeling and hybrid logic for deterministic, local fault detection and shutdown, enhancing safety and reliability.

DE202026000983U1Active Publication Date: 2026-04-30SONNEN STARK GMBH +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
DE · DE
Patent Type
Utility models
Current Assignee / Owner
Filing Date
2026-03-05
Publication Date
2026-04-30

AI Technical Summary

Technical Problem

Existing DC arc detection systems in photovoltaic and battery storage systems struggle to robustly distinguish between normal state signatures and fault-related signatures, particularly series and parallel arcs, due to installation-specific differences and switching noise interference, necessitating a multi-channel protection architecture that operates locally and deterministically without internet dependency.

Method used

A multi-channel DC monitoring and protection system that combines plant-specific normal state modeling with a hybrid protection logic, channel-wise isolation, and local safety state machine, utilizing high-frequency and low-frequency electrical signatures, and cross-channel correlations to detect anomalies and enforce safe disconnection.

Benefits of technology

Enables robust, internet-independent protection against safety-relevant faults by accurately distinguishing between normal and fault states, ensuring deterministic and traceable shutdowns with local decision-making and event logging.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader

Abstract

Multi-channel DC monitoring and protection system for monitoring and protective shutdown of DC energy paths of a photovoltaic system and / or a battery storage system, including a) a plurality of channels, wherein each channel can be assigned a DC path to be monitored, b) a measuring and I / O unit for acquiring at least one electrical DC measurement per channel, c) an evaluation unit that is set up to generate features from channel-related measurement data and to derive at least one anomaly indicator by comparing current measurement data and / or features with channel-related reference data, d) a storage unit for storing configuration data and channel-related reference data, wherein the reference data includes a plant-specific normal state model and / or a baseline of good state, e) Channel-wise isolating devices for electrical isolation of the respective DC path, each isolating device having a switching status feedback, f) a safety state machine which, in the event of a fault-relevant event or in the event of a contradiction between the controlled and the reported switching state, sets a blocking state and prevents re-switching until acknowledged, the evaluation unit includes a hybrid protection logic with g) a deterministic protection pathway for evaluating limit and / or plausibility violations and h) an anomaly path for detecting plant-specific signature deviations.
Need to check novelty before this filing date? Find Prior Art

Description

Technical field

[0001] The invention relates to a device for electrical monitoring and protective shutdown of direct current energy paths, in particular in photovoltaic systems and battery storage systems.

[0002] The invention relates in particular to a multi-channel, locally operating protection system that detects plant-specific electrical signatures of normal operation and recognizes deviations from these as anomalies in order to trigger messages and / or protective shutdowns.

[0003] The invention is particularly suitable as a retrofittable protection node in DC-side plant areas, for example in the area of ​​string aggregations, DC distributions, storage systems or combined photovoltaic / battery storage systems. State of the art

[0004] Arc fault protection devices are known to be used in PV systems. These devices detect electrical DC arcs and, depending on their design, interrupt the power supply. The detection and, if necessary, interruption of DC arcs in PV circuits is described in standards and is subject to standardized testing and evaluation procedures.

[0005] In a technical context, arcing events in DC systems are typically classified as series arcs and parallel arcs. Parallel arcs can occur, in particular, between two conductors (conductor-conductor) or between a conductor and earth (conductor-earth) and are especially relevant to safety and fire safety due to additional fault current paths and potentially high energy release. In practice, standardized testing and evaluation procedures for DC arc detection often focus primarily on series arcing events. Furthermore, robustly distinguishing between normal state signatures, series arcs, and parallel arcs based solely on high-frequency signal components can be challenging. Therefore, there is a need for an evaluation method that combines high-frequency signature features with low-frequency current and / or voltage changes, as well as with differential / leakage indicators and, where applicable, cross-channel correlations.Furthermore, inverters with integrated arc fault function are known which interrupt the current flow in the event of detected arc faults and provide for automatic restart or manual reset depending on the frequency of events and / or time behavior.

[0006] Furthermore, DC combiner boxes and string monitoring systems are known, which record current and voltage values ​​of several strings and monitor the status information of other components.

[0007] It is also known from the technical field that switching noises and their spectral components, which depend on the installation, manufacturer and operating condition, can make it difficult to robustly distinguish between normal state signatures and fault-related signatures.

[0008] Finally, feedback from switching devices and their validation for monitoring the actual switching operation are known in industrial safety architectures.

[0009] Against this background, individual sub-functions such as arc detection, channel-by-channel measurement, shutdown, reset / lockout, and feedback monitoring are known in isolation. However, in practice, there remains a need for a robust, multi-channel protection architecture that considers installation-specific normal states while simultaneously handling safety-relevant faults deterministically; preferably, the protection functions should be executable locally and not dependent on an internet connection. The problem underlying the invention

[0010] The invention is based on the objective of providing a multi-channel DC monitoring and protection system that 1. Plant-specific differences taken into account during normal operation, 2. enables local detection and protective shutdown, whereby the protection functions are preferably executable independently of the internet, 3. Deterministically detects and handles hard, safety-relevant error states, 4. can assess complex or plant-specific deviations as anomalies, 5. electrically disconnects channel by channel and verifies switching operations, 6. enforces a lock state with defined acknowledgment, 7. provides a commissioning release logic with wiring / plausibility check and 8. Protection decisions and state transitions are optionally logged locally in a traceable manner. Description of the invention

[0011] The problem is solved by a system according to claim 1.

[0012] The core idea of ​​the invention is the combination of • a plant-specific determination and storage of a normal state model and / or a baseline of a good state per channel, • a hybrid protection logic with a deterministic protection path and an anomaly path, • channel-wise electrical isolation with switching status feedback, • a local safety state machine with lock / acknowledge logic as well as • optionally a local event log with time reference, The protection function should preferably be executable without an internet connection.

[0013] The evaluation unit generates features from channel-related measurement data and derives at least one anomaly indicator by comparing it with channel-related reference data. In parallel, deterministic protection criteria are evaluated, in particular limit value, plausibility, and condition violations.

[0014] This hybrid structure ensures that safety-relevant, deterministically detectable errors are not dependent on a learning or model-based method, while at the same time complex, installation-specific pattern deviations can be detected.

[0015] Preferably, the evaluation unit is further configured to detect arcing events based on high-frequency signature features and to classify a detected arcing event as a series or parallel arc using additional criteria. These additional criteria can include, in particular, a current- and / or voltage-related short-circuit or undervoltage index, a differential / leakage index from a comparison of an outgoing and a returning current, and a cross-channel correlation pattern of simultaneous changes in multiple channels. In the case of a classified parallel arc, a protective shutdown can be triggered such that a plurality of channels that could feed the arc are brought into a safe disconnection state.

[0016] The local safety state machine sets a lockout state in the event of fault-relevant events or a discrepancy between the controlled and reported switching states. In this lockout state, re-enabling is prevented until acknowledged.

[0017] Preferably, the system also includes a commissioning release test, periodic self-tests including active functional testing of at least one isolating device, a secondary safety response via a potential-free output, and drift detection for controlled updating of the normal state model. Beneficial effects

[0018] The invention enables a robust protection function even with installation- and manufacturer-dependent signature differences, especially with changing operating conditions and different system architectures.

[0019] The plant-specific normal state initialization and the hybrid design consisting of a deterministic protection path and anomaly path can improve the protection function against non-trivial signature deviations without shifting hard safety functions to non-deterministic methods.

[0020] The channel-wise verified separation with switching status feedback and blocking / acknowledgment logic increases the functional load capacity of the shutdown chain.

[0021] The local executability of the protection function, as well as optional local storage of protection decisions, events and state transitions, enables internet-independent protection and traceable event analysis. Detailed description of embodiments: 1. System structure and channel structure

[0022] The system has multiple channels. Each channel can be assigned a DC path to be monitored.

[0023] A channel can, in particular, monitor a photovoltaic string. In another embodiment, two or more channels are used as a functional channel group for a battery storage system. The allocation is not restrictive; what matters is the multi-channel monitoring and protection architecture.

[0024] Preferably, domain profiles can be stored and activated for each channel or channel pair, defining operation as a PV string channel or as a BESS channel group and specifying parameters for event evaluation, switching states and blocking / acknowledgment conditions. 2. Measurement and I / O unit, measured quantities and feature formation

[0025] The measurement and I / O unit includes at least one DC measurement path per channel for measuring voltage and / or current.

[0026] Additionally, a sensor connection via a dedicated sensor bus can be provided, in particular a 1-Wire bus for connecting at least one temperature sensor, for example for recording an inverter and / or battery storage temperature.

[0027] Furthermore, the system can have a fieldbus or communication interface for integrating external detectors and states, in particular a Modbus interface for communication via Modbus RTU and / or Modbus TCP with external devices (e.g. smoke detectors, cabinet states, other status signals).

[0028] Additionally, each channel preferably includes an RF acquisition front end that captures high-frequency signal components of the respective DC path. Time-domain characteristics, frequency-domain characteristics, envelope characteristics, energy distributions, and / or other derived quantities can be generated from the measurement data.

[0029] In one embodiment, a comparative measurement is provided in which an outgoing and a returning current of the same DC path or functionally related DC paths are detected and compared to form a difference / leakage indicator. 3. Initialization of a plant-specific normal state

[0030] Upon commissioning or after authorized re-initialization, the system performs an initialization phase. During this phase, measurement data is acquired and used to determine a channel-specific normal state model and / or a baseline of good condition.

[0031] To avoid distortion, plausibility and / or exclusion criteria can be used to prevent unstable states, switching operations, obviously implausible measured values ​​or other disturbances from being included in the normal state model.

[0032] The normal state model can be stored in a non-volatile memory unit. 4. Hybrid protection logic

[0033] The evaluation unit includes a hybrid protection logic with at least two functionally distinguishable protection paths: • a deterministic protection path that evaluates limit, plausibility, and state violations, and • an anomaly path that detects plant-specific or complex pattern deviations.

[0034] The deterministic protection path can be used in particular for overcurrent, polarity errors, wiring errors, feedback contradiction of a disconnect device and / or differential / leakage indications.

[0035] The anomaly path can be used in particular for the detection of signature anomalies and / or arc events.

[0036] In a preferred embodiment, the event evaluation includes at least event classes from the group: overcurrent, serial arc, parallel arc, ground fault or leakage indications and anomaly.

[0037] In one embodiment, the event class of an arc flash event is not derived solely from high-frequency signal components. Rather, the evaluation unit can additionally evaluate at least one of the following indicators to distinguish between series and parallel arc flashes: (i) current and / or voltage-related changes in the low-frequency range, in particular a short-circuit or undervoltage indicator, (ii) a difference / leakage indicator from a comparison of an outgoing and a returning current of the same DC path or functionally related DC paths, and / or (iii) a cross-channel correlation pattern of simultaneous changes in a plurality of channels. In the case of an arc flash classified as parallel, the protective shutdown can be performed across channels to bring all supplying energy paths into a safe disconnect state.A protection decision can be triggered by each protection path individually or by a combination of both protection paths. 5. Anomaly detection and algorithmic openness

[0038] During operation, the evaluation unit compares current measurement data and / or characteristics derived from it with the stored normal state model or the baseline.

[0039] Anomaly detection is not limited to a single method. It can be rule-based, statistical, model-based, machine learning-based, or a combination thereof.

[0040] This keeps the protection architecture open for different plant configurations and later developments, without replacing the safety-relevant deterministic protection path. 6. Channel-by-channel isolation devices and switching status feedback

[0041] Each channel is assigned a disconnecting device. In one embodiment, at least one disconnecting device is designed as a two-pole disconnecting device that separates a positive path and a negative path of the assigned DC path.

[0042] Preferably, the disconnect devices are configured as two-pole disconnect devices on a channel-by-channel basis. In a further embodiment, the disconnection can be switched to single-pole operation, in particular by means of a jumper or comparable hardware configuration.

[0043] In BESS monitoring, a channel pair can be operated in such a way that two channels each separate unipolarly, resulting in a total two-pole separation of the functionally related energy path.

[0044] Each disconnecting device has a switching status feedback, in particular via a signaling contact.

[0045] In a preferred embodiment, at least one separation device is designed to be fail-safe, in particular such that it transitions into a safe separation state when a control energy is lost.

[0046] Preferably, at least one isolating device is designed for a DC voltage up to 1500 VDC and a current up to 100 A; the specific design depends on the application and the channel. 7. Safety state machine, locking logic and acknowledgment

[0047] The evaluation unit includes a local safety state machine. If a fault-relevant event is detected or a deviation between the controlled and the reported switching state is identified, the affected channel is put into a blocked state.

[0048] In a preferred embodiment, an emergency stop input (SF-ESTOP) is provided, which is implemented via an external safety relay and causes a stop category 0 (immediate power cut-off). When the emergency stop is triggered, the system initiates a protective shutdown and sets a locked state until authorized acknowledgment is received.

[0049] When locked, the device cannot be switched on again. It will preferably only be released after manual and / or authorized confirmation.

[0050] The blocking logic can be designed in such a way that automatic reactivation after a fault-relevant event is prevented. 8. Commissioning and release testing

[0051] In a preferred embodiment, the system performs a commissioning release check before enabling a channel. This check includes at least a polarity check, a wiring check, and / or a plausibility check.

[0052] If a negative test result is detected, the safety status machine sets a lock state and prevents release until acknowledgment and / or another successful test. 9. Self-test and active functional testing of the protective chain

[0053] In a preferred embodiment, the system performs periodic self-tests that check at least parts of the protection chain, in particular the disconnect control and switching status feedback.

[0054] Preferably, the self-test includes an active functional test of at least one disconnecting device, in which a test control must cause an expected change of state and this is validated on the basis of the switching state feedback.

[0055] If the expected change in state does not occur or the feedback is implausible, an error state is logged and a secondary safety response can be triggered. 10. Secondary safety response

[0056] In one embodiment, the system includes at least one potential-free output for outputting a message and / or shutdown request to an external safety or shutdown chain.

[0057] Such a potential-free output can be used in particular if there is a diagnosed fault in a primary disconnect device or a faulty protection chain. 11. Local data storage and event traceability

[0058] In one embodiment, the system includes a local data storage for storing protection decisions, events, and time-referenced state transitions. The data storage can be configured as a ring buffer.

[0059] Preferably, the local data storage is designed as a ring buffer and set up to buffer measured values ​​and events for at least one month.

[0060] The data storage device stores, in particular, state transitions of the safety state machine and protection logic, as well as event data records with timestamps and channel assignments; optionally, raw signal sections and / or feature vectors can be stored that are temporally assigned to a shutdown event or self-test result.

[0061] This creates a locally available, temporally traceable event sequence that enables a technical analysis of protection decisions and state transitions. 12. Offline operation and optional synchronization

[0062] The protection functions, in particular deterministic protection paths, anomaly path, safety state machine and protection shutdown, are executable locally and do not depend on an internet connection.

[0063] If a communication connection is available, an optional transfer or synchronization of locally stored data can take place without the local protection function being dependent on this.

[0064] Such a communication connection can be established in particular via mobile network, LAN and / or WLAN; local or remote visualization (e.g. web UI) as well as alarm / fault notification, for example via messaging service or voice call, can be implemented via the same communication channels.

[0065] Additionally or alternatively, a local status indicator, in particular via status LEDs, may be provided to indicate operating status, locking status and / or communication status. 13. Drift detection and controlled update

[0066] The evaluation unit can perform drift detection to identify long-term changes from the normal state.

[0067] An update of the normal state model preferably only takes place under predefined release conditions in order to prevent faulty or unstable states from being incorporated into the normal state model. 14. Installation-dependent parameterization with safety limits

[0068] In a preferred embodiment, the system processes installation parameters, in particular conductor cross-section, conductor length, duct type and / or component data.

[0069] From these parameters, permissible ranges for protection thresholds can be determined. User inputs are preferably limited to these permissible ranges to avoid safety-critical parameterization errors. Example of implementation

[0070] An embodiment of the invention is described below.

[0071] The exemplary embodiment serves for illustration purposes and does not limit the scope of protection of the invention.

[0072] In one embodiment, the system has several channels, some of which monitor photovoltaic strings and another part of which is assigned as a channel group to a battery storage energy path.

[0073] During commissioning, an initialization phase is carried out, during which channel-related DC and, if applicable, RF data are recorded and processed into channel-related reference data using plausibility and exclusion criteria.

[0074] During operation, the evaluation unit continuously generates features and compares them with the stored normal state model. In parallel, the deterministic protection path monitors limit violations, plausibility checks, and state violations, in particular overcurrent, polarity errors, wiring errors, feedback contradictions, and / or indications of discrepancies / leakage.

[0075] In the event of a fault-relevant event, the system triggers a channel-by-channel protective shutdown, validates the switching state via the switching state feedback, sets a blocking state and logs the protection decision, event and state transition in the local data storage.

[0076] If a self-test detects a missing or implausible change in the state of a disconnecting device, an external safety or shutdown chain can also be controlled via a potential-free output.

[0077] Re-release preferably only occurs after acknowledgment and successful commissioning release testing.

Claims

[1] Multi-channel DC monitoring and protection system for monitoring and protective shutdown of DC energy paths of a photovoltaic system and / or a battery storage system, comprising a) a plurality of channels, wherein each channel can be assigned a DC path to be monitored, b) a measuring and I / O unit for acquiring at least one electrical DC measurement per channel, c) an evaluation unit that is set up to generate features from channel-related measurement data and to derive at least one anomaly indicator by comparing current measurement data and / or features with channel-related reference data, d) a storage unit for storing configuration data and channel-related reference data, wherein the reference data includes a plant-specific normal state model and / or a baseline of good state, e) Channel-wise isolating devices for electrical isolation of the respective DC path, each isolating device having a switching status feedback, f) a safety state machine which, in the event of a fault-relevant event or in the event of a contradiction between the controlled and the reported switching state, sets a blocking state and prevents re-switching until acknowledged, the evaluation unit includes a hybrid protection logic with g) a deterministic protection pathway for evaluating limit and / or plausibility violations and h) an anomaly path for detecting plant-specific signature deviations. [2] System according to claim 1, wherein the evaluation unit is configured to generate the channel-related reference data from time-recorded measurement data of the connected system during an initialization phase and to store it in the storage unit, wherein plausibility and / or exclusion criteria are applied during the initialization phase in order not to include measurement data from unstable states or switching operations in the normal state model. [3] System according to one of the preceding claims, wherein the deterministic protection path handles at least one fault from the group: overcurrent, polarity fault, wiring fault, feedback contradiction of a disconnecting device, differential / leakage indication, in particular formed from a comparison of an outgoing and a returning current of the same DC path or functionally related DC paths, wherein the evaluation unit distinguishes event classes at least from the group: overcurrent, series arc, parallel arc, ground fault / leakage indications and anomaly and triggers a protective shutdown in the case of at least one event class. [4] System according to one of the preceding claims, wherein the measuring and I / O unit has an RF acquisition frontend per channel for acquiring high-frequency signal components of the DC path and the evaluation unit generates frequency- and / or time-domain-related features, in particular envelope and / or energy distribution features. [5] System according to one of the preceding claims, wherein two or more channels can be operated as a functional channel group for a battery storage energy path, wherein a two-pole separation of an energy path is realized either by a two-pole separation device or by a channel set configurable as a channel pair, which in total causes a separation of a positive path and a negative path of the functionally related energy path. [6] System according to one of the preceding claims, wherein at least one isolating device is designed to be fail-safe such that it transitions to a safe isolating state when a control energy is lost, wherein at least one isolating device is designed for a DC voltage up to 1500 VDC and a current up to 100 A, and wherein at least one isolating device is switchable between two-pole operation and single-pole operation by means of a hardware configuration, in particular a jumper. [7] System according to one of the preceding claims, wherein in the locked state automatic restart after a fault-relevant event is prevented and release only occurs after manual and / or authorized acknowledgment, and wherein the evaluation unit performs a commissioning release test which includes at least a polarity test, wiring test and / or plausibility test before releasing a channel, and sets the locked state in the event of a negative test result. [8] System according to one of the preceding claims, wherein the system performs periodic self-tests that check at least parts of the protection chain including disconnect control and switching state feedback, wherein the self-test comprises an active functional test of at least one disconnect device in which a test control must cause an expected change of state and this is validated on the basis of the switching state feedback, and wherein if the expected change of state does not occur and / or if the feedback is implausible, an error state is logged and a secondary safety reaction is triggered. [9] System according to one of the preceding claims, wherein the evaluation unit performs drift detection to detect long-term changes in the normal state and allows an update of the normal state model only under specified release conditions. [10] System according to one of the preceding claims, wherein the evaluation unit determines permissible ranges for protection thresholds from installation parameters and limits user inputs to these permissible ranges. [11] System according to one of the preceding claims, further comprising at least one device selected from the group: a potential-free output for outputting a message and / or shutdown request to an external safety or shutdown chain, a dedicated sensor bus, in particular a 1-Wire bus, for connecting at least one temperature sensor, a Modbus interface for communication via Modbus RTU and / or Modbus TCP with external devices, a communication interface, in particular mobile communication and / or LAN / WLAN, for providing an operating / visualization interface and / or for transmitting alarm and fault messages as well as for synchronizing locally stored data when a connection is available, a local status indicator, in particular status LEDs, for indicating operating state, locked state and / or communication state, and / or an emergency stop input (SF-ESTOP) which is implemented via an external safety relay and effects a stop category 0,where, when the emergency stop is activated, a protective shutdown is triggered and a locking state is set. [12] System according to one of the preceding claims, wherein the storage unit contains activatable domain profiles for PV string operation and BESS operation for each channel or channel pair, which define parameters for event evaluation, switching states, blocking / acknowledgment conditions and / or interface assignments. [13] System according to one of the preceding claims, further comprising a local data storage device for storing protection decisions, events and state transitions with time reference, wherein the local data storage device is designed as a ring buffer and is set up to buffer measured values ​​and events for at least one month, wherein event data records comprise timestamps, channel assignment and state transitions of the safety state machine, and wherein the data storage device additionally stores at least one raw signal segment and / or one feature vector which is temporally assigned to a shutdown event or a self-test result. [14] System according to one of the preceding claims, wherein the storage unit is designed as a non-volatile storage unit and / or the system is capable of detecting and triggering a protective shutdown without an internet connection. [15] System according to any of the preceding claims, wherein the evaluation unit is set up, i) to detect arc flash events at least by means of a high-frequency-based arc flash signature criterion and ii) to classify a detected arc flash event as a serial arc flash or a parallel arc flash by evaluating at least one of the following criteria in addition to the arc flash signature criterion: ii1) a current and / or voltage-related short-circuit or undervoltage indicator of the DC path, ii2) a difference / leakage indicator formed by comparing an outgoing and a returning current of the same DC path or functionally related DC paths, ii3) a cross-channel correlation pattern of simultaneous changes in a plurality of channels. [16] System according to claim 15, wherein in the case of a classified parallel arc, a protective shutdown is triggered such that a plurality of channels that can feed the arc are brought into the safe disconnect state.