Redundant Battery Management System Architecture

The redundant BMS architecture addresses system failures by using multiple battery units and controllers to ensure continued operation and reliability in vehicles, particularly for autonomous systems.

JP7722919B2Active Publication Date: 2025-08-13ZOOX INC
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2021507914
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2018-08-17
Filing Date
2019-08-16
Publication Date
2025-08-13
Estimated Expiration
2039-08-16

AI Technical Summary

Technical Problem

Conventional battery system architectures in vehicles can lead to system failure due to battery, battery controller, or communication link failures, rendering the vehicle inoperable, which is unsuitable for autonomous vehicles requiring robustness.

Method used

A redundant battery management system (BMS) architecture with multiple battery units and controllers that provide fault tolerance through redundant communication paths and controllers to manage and aggregate battery data, ensuring continued operation even in the event of component failures.

Benefits of technology

The redundant BMS architecture ensures fault-tolerant operation by maintaining system functionality even under failure conditions, enabling continued operation and enhanced reliability in vehicles.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007722919000001
    Figure 0007722919000001
  • Figure 0007722919000002
    Figure 0007722919000002
  • Figure 0007722919000003
    Figure 0007722919000003
Patent Text Reader

Abstract

A vehicle can include a battery architecture configured to power a motor, accessories, and other components of the vehicle. The architecture can include a controller coupled to multiple battery units. Each battery unit can include a battery and a battery management system. Further, each battery unit can be coupled to a controller and other battery units. Using redundant connections and redundant data transmitted between the controller, battery units, and other components, the architecture can detect a failure and continue operation while providing an indication of the failure.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a redundant battery management system architecture.

[0002] [CROSS-REFERENCE TO RELATED APPLICATIONS] This patent application claims priority to U.S. Utility Model Patent Application Serial No. 16 / 104,310, filed August 17, 2018. Application Serial No. 16 / 104,310 is incorporated herein by reference in its entirety. [Background technology]

[0003] Vehicles can use batteries to provide energy for vehicle operation. Operation can include powering one or more electric motors, sensors, accessories available to vehicle passengers, and / or other vehicle systems. To ensure reliable vehicle operation, some or all of these vehicle systems rely on a steady supply of battery power. However, during operation, performance degradation or failures can occur that severely limit or render the vehicle inoperable. For example, in some conventional battery system architectures, failure of the battery, the battery controller, or the coupling to the battery can cause the system or vehicle to become inoperable. [Brief explanation of the drawings]

[0004] The detailed description will be set forth with reference to the accompanying drawings, in which the leftmost digit(s) of a reference number identifies the figure in which the reference number first appears. The use of the same reference number in different drawings indicates similar or equivalent components or functionality.

[0005] [Figure 1] FIG. 1 illustrates an example architecture for a redundant battery management system (BMS) architecture. [Figure 2] FIG. 2 illustrates an example system for implementing a redundant BMS architecture and an example environment of a vehicle traveling to a charging station. [Figure 3] FIG. 3 is a schematic diagram of an exemplary vehicle including a body module, a pair of drive modules disposed on either end of the body module, and a battery unit disposed within or coupled to each drive module. [Figure 4A] FIG. 4A shows an example architecture of a redundant BMS architecture using a ring configuration. [Figure 4B] FIG. 4B illustrates an example architecture of a redundant BMS architecture using a mesh configuration. [Figure 5] FIG. 5 illustrates an exemplary process for receiving battery data and instructing the battery unit. [Figure 6] FIG. 6 shows an example process for generating battery data and transmitting the battery data. [Figure 7] FIG. 7 illustrates an example process for determining a fault condition. DETAILED DESCRIPTION OF THE INVENTION

[0006] This disclosure describes systems, methods, and apparatus for providing a vehicle with a redundant battery management system (BMS) architecture (e.g., a communication architecture). As discussed above, conventional battery system architectures can cause the vehicle to become inoperable under some fault conditions. For example, in conventional battery system architectures, failure of the battery, the battery controller, the communication link therebetween, or the coupling to the battery can cause failure of the entire system. Such architectures may be unsuitable for autonomous vehicles or other types of electrically powered devices or systems that require a certain degree of robustness.

[0007] This disclosure is generally directed to systems, methods, and apparatus for redundant BMS architectures, e.g., communication architectures. In some examples, a system providing a redundant BMS architecture can include one or more controllers used to issue commands to other components (e.g., adjusting a load connected to an output, such as setting torque of a motor controller, connecting or disconnecting a battery, etc.), communicate the status or parameters of one or more components (e.g., batteries), and determine if a fault condition has occurred in the system. The controllers can also be configured to provide an indication of the fault. In some examples, the controllers can calculate the capacity or limitations of the system (e.g., the maximum current or power provided by one or more batteries) based on data received from the other components.

[0008] The redundant BMS architecture of the present disclosure may also include a first battery unit and a second battery unit, although any number of units is contemplated. In some examples, each battery unit may include a battery and a BMS. The battery may store energy used by the redundant BMS architecture and / or the electrical loads. The BMS may monitor the status of the battery and / or battery unit, including, but not limited to, state of charge, voltage level, current consumption, power level, internal resistance, etc. Additionally, the BMS may be configured to transmit and receive battery data and receive operational commands.

[0009] In some examples, a redundant BMS architecture can be implemented such that the controller is electrically and / or communicatively coupled to the first battery unit and / or the second battery unit via a coupling. The coupling can enable the controller to communicate with the first battery unit and / or the second battery unit. In some examples, the controller can send operational commands to the first battery unit and / or the second battery unit. For example, such commands can include either an “on” or “off” symbol such that the BMS of the battery unit appropriately connects or disconnects the battery to a common line (which may be for charging or discharging through a load). In some examples, the controller can send other operational commands necessary for the operation of the vehicle or device. As some non-limiting examples, such commands can include drive commands (e.g., sending torque requests to a motor controller), brake commands, sleep commands, etc. In some examples, the controller can send battery data to the first battery unit and / or the second battery unit. The battery data can include current limit data, power limit data, voltage limit data, temperature data, connection data, battery condition, system condition, or battery status, although other information regarding battery parameters is contemplated. In some examples, the battery data may include impedance data (such as internal resistance) or other data related to the battery.

[0010] In some examples, the battery data may include aggregate battery data. In some examples, the aggregate battery data may represent, for example, an aggregate battery limit, the current that can be provided by the battery units in the power system. To generate and / or calculate the aggregate battery data, the BMS architecture may include redundant communication paths for data exchanged between various components of the vehicle. For example, in some examples, the second battery unit may send second battery data to the controller and the first battery unit, the controller may send second battery data to the first battery unit, and the first battery unit may send the first battery data to the controller. The first battery unit may use the second battery data to generate and / or calculate first aggregate battery data and send the first aggregate battery data to the controller. In some examples, the transmission of data may occur simultaneously and / or in different orders without affecting the operation of the system. In some examples, the second battery unit may use the first battery data to send second aggregate battery data to the controller. In some examples, the controller may receive the first aggregate battery data and / or the second aggregate battery data. In some examples, the controller compares the first aggregate battery data with the second aggregate battery data and can select the lower aggregate battery data, the higher aggregate battery data, or either aggregate battery data if the first aggregate battery data and the second aggregate battery data are substantially similar. In some examples, the controller can select the lower aggregate battery data and operate in a conservative configuration, for example, to prevent damage to system components. In other examples, the controller can select the higher aggregate battery data and operate in a high-performance configuration. Operation of vehicle components, such as the traction motor, can be controlled according to the aggregate battery data.

[0011] In some examples, the battery unit can transmit one or more states or statuses of the battery unit, the battery, the BMS, or the system to the controller. The states can be a sleep state, a standby state, a driving state, a charging state, or a shutdown fault state. In some examples, other states can be implemented as needed. The status can be an “okay” status (e.g., a normal operation status), a “do not start” status (e.g., a low-level fault that, in some examples, can indicate a single-point failure that does not affect performance or safety), an “end mission” status (e.g., a medium-level fault that, in some examples, can indicate a fault that may affect performance and / or safety operation persists above an operational threshold), or a “stop immediately” status (e.g., a high-level fault that, in some examples, can disable continued operation). In some examples, other states can be implemented as needed.

[0012] In some examples, the first battery unit can be coupled to the second battery unit. In such cases, the controller can be coupled to the first battery unit and the second battery unit, and each battery unit can be coupled to the other battery unit. In some examples, the first battery unit can transmit the first battery data to the second battery unit without transmitting the first battery data to the controller. In some examples, the first battery unit can transmit the first battery data to the second battery unit by transmitting it directly to the second battery unit and via the controller. In such cases, the second battery unit can receive the first battery data from the first battery unit and from the controller.

[0013] In some examples, a redundant BMS architecture can include a third battery unit or more. In such implementations, a controller can be coupled to each battery unit in the BMS architecture, such as in a hub-and-spoke topology. In other examples, a controller can be coupled to a subset of the available battery units. In some examples, a controller can be coupled to each battery unit, and each battery unit can be coupled to all other battery units, such as in a full-mesh topology. In other examples, a controller can be coupled to a subset of the available battery units, and some battery units can be coupled to some or all of the other available battery units. In some examples, all battery units and any one or more controllers can be connected as a ring, and relevant information (including aggregation) can be passed along the ring so that any one component (BMS or controller) can perform checks for failures, exceeded limits, or other issues. As discussed above, the controller can send operational commands and send and receive battery data. Additionally, the battery units can send and receive battery data.

[0014] The methods, apparatus, and systems discussed herein can be implemented in multiple ways. Example implementations are provided below with reference to the following drawings. While discussed in the context of autonomous vehicles, the methods, apparatus, and systems described herein can be applied to a variety of systems that use electrical power and are not limited to autonomous vehicles. In another example, the methods, apparatus, and systems can be utilized in an aviation or nautical context.

[0015] FIG. 1 illustrates an example architecture 100 for implementing a redundant BMS architecture. As illustrated, the architecture 100 includes an executive controller (EC) 102 (also referred to as a controller). In some examples, multiple controllers can be used. The EC 102 can be coupled to a first BMS 104 and a second BMS 106. Although not shown in FIG. 1, the first BMS 104 can be included in a battery unit together with the batteries or can be included independently of the battery unit. Similarly, the second BMS 106 can be separate from or located within the second battery unit. In some examples, the first BMS 104 and the second BMS 106 can be located within the same battery unit. While any number of BMS units can be used in some examples, generally, one BMS can be used to monitor and / or control a single battery unit. The EC 102 can be coupled to the first BMS 104 via a first coupling or a first drive controller area network (CAN) 108. The EC 102 can also be coupled to a second BMS 106 via a second coupling or second drive CAN 110. The redundant BMS architecture 100 can also implement a coupling or interpack CAN 112 that couples the first BMS 104 to the second BMS 106.

[0016] 1 , the first BMS 104 can be coupled to the EC 102 via the first drive CAN 108. Additionally, the second BMS 106 can be coupled to the EC 102 via the second drive CAN 110. In such a case, the first BMS 104 can transmit data 114 to the EC 102 via the first drive CAN 108. In some examples, the data 114 can include first battery data from the first BMS 104 to the EC 102. Additionally, using the second drive CAN 110, the second BMS 106 can transmit data 116 to the EC 102. The EC 102 can be configured to transmit the first battery data to the second BMS 106 and the second battery data to the first BMS 104.

[0017] The first battery data and / or the second battery data can include data such as limit data. In some examples, the battery unit, battery, or BMS can have operating limits or maximum limits. The operating limits can indicate limits that would not normally be exceeded while operating under normal conditions. The maximum limits can indicate a maximum value before damage or failure occurs. Types of limits can include current limits, power limits, voltage limits, operating limits, etc.

[0018] The first battery data and / or the second battery data may also include connection data. In some examples, via a communication protocol, the first BMS 104 and / or the second BMS 106 may detect data loss and / or corruption. The first BMS 104 and / or the second BMS 106 may transmit this information as connection data to the EC 102 or other BMS units and / or components.

[0019] The first battery data and / or the second battery data may also include a state and / or a status. The state may be a system state, a battery state, a BMS state, and / or a battery unit state. The state may include a sleep state (e.g., the battery is not supplying power and the vehicle is inactive), a standby state (e.g., the battery is ready to supply power and awaiting further instructions), a driving state (e.g., the battery is supplying power and / or actively responding to steering commands), a charging state (e.g., the battery is receiving power), and / or a shutdown fault state (e.g., the battery has shut down due to a fault, such as awaiting assistance, attention, and / or maintenance). In some examples, other states may be implemented. Additionally, the status may be a battery status, a BMS status, and / or a battery unit status. As described above, the status may include an “okay” status, a “do not start” status, an “end mission” status, and / or a “stop immediately” status. In some examples, other states may be implemented.

[0020] The first battery data and / or the second battery data may also include impedance data. The impedance data may be real-time impedance data measured or determined by the first BMS 104 and the second BMS 106, respectively. In some examples, the impedance data may be static data based on an initial configuration of the battery, BMS, or battery unit (e.g., by using a lookup table, based on temperature, state of charge, current draw, or other).

[0021] In some examples, the first BMS 104 can be configured to determine first aggregate battery data and transmit the first aggregate battery data to the EC 102. Further, in some examples, the second BMS 106 can be configured to determine second aggregate battery data and transmit the second aggregate battery data to the EC 102. The first aggregate battery data and / or the second aggregate battery data can include any combination of data or a calculation of data including any of the above battery data. In some examples, the first aggregate battery data can include a first aggregate current limit (e.g., a first aggregate limit). In some examples, the second aggregate battery data can include a second aggregate current limit (e.g., a second aggregate limit). Such a current limit can indicate, for example, a limit on the current that can be supplied by the combined battery sources. In some examples, the first aggregate current limit can include a sum of the first current limit and the second current limit. In some examples, the first aggregate current limit may include a table lookup based on a characterization of the battery and using any one or more of temperature, voltage, state of charge, or current limit as lookup values into the table. In some examples, the first aggregate current limit may include a dynamic current limit based on impedance data or current data determined by the first BMS 104 and / or the second BMS 106. In some examples, such a dynamic limit may be based on a feedback loop that includes, for example, observed characteristics of the first battery. In some examples, the observed characteristics may include impedance, slew rate, and / or overshoot of the first battery. Such an aggregate limit may similarly be calculated by the second BMS 106.

[0022] The first BMS 104 can also be configured to transmit data 118 to the second BMS 106 using the Interpack CAN 112. Additionally, the second BMS 106 can be configured to transmit data 118 to the first BMS 104 using the Interpack CAN 112. The data can include data similar to the data 114 and data 116 transmitted by the first BMS 104 and second BMS 106, respectively.

[0023] In some examples, the redundant BMS architecture 100 can provide a degree of fault tolerance. As an example, the Interpack CAN 112 can be disconnected, resulting in the first BMS 104 being unable to send data directly to the second BMS 106 using the Interpack CAN 112. However, the data 118 sent along the Interpack CAN 112 is substantially similar to the data 114 sent along the first drive CAN 108. As shown in FIG. 1, a portion of the data 114 is then sent to the second BMS 106 via the second drive CAN 110. Thus, all components (the first and second BMSs 104, 106, and the EC 102) all have the same data as they would if the Interpack CAN 112 had not been disconnected. Thus, in this illustration, the redundant BMS architecture 100 can continue normal operation. However, the aggregation limit calculated by the first BMS 104 will be lower than the actual aggregation because the first BMS 104 is no longer able to receive data 118 from the second BMS 106. For example, because of this difference, the EC 102 could determine a fault condition in this illustration, where the Interpack CAN 112 is disconnected, and in some instances generate an indication of the fault condition.

[0024] As another example, either the first drive CAN 108 or the second drive CAN 110 can be disconnected (or otherwise damaged), resulting in the second BMS 106 being unable to send data directly to the EC 102 using the second drive CAN 110. However, the data 118 sent along the Interpack CAN 112 is substantially similar to the data 116 sent along the second drive CAN 110. Thus, in this illustration, the redundant BMS architecture 100 can continue normal operation. As noted above, a difference in the aggregate limits received by the EC 102 from the first and second BMSs 104, 106 can indicate such a failure, and the EC 102 can respond accordingly.

[0025] 2 illustrates an example system 200 for implementing a redundant BMS architecture and an example environment of a vehicle 202 traveling to a charging station. Vehicle 202 may be a vehicle of any configuration, such as, for example, a sedan, a van, a sport utility vehicle, a crossover vehicle, a truck, a bus, an agricultural vehicle, and a construction vehicle. Vehicle 202 may be powered by one or more electric motors, one or more internal combustion engines, any combination thereof (e.g., a hybrid powertrain), and / or any other suitable power source. For purposes of illustration, vehicle 202 is an at least partially powered vehicle having two battery units configured to power vehicle 202.

[0026] The vehicle 202 may have a first battery unit 204 that may include a first battery 206 and a first battery management system (BMS) 208. In some examples, the first battery unit 204 may be communicatively coupled to a second battery unit 210. The second battery unit 210 may include a second battery 212 and a second BMS 214.

[0027] In some examples, vehicle 202 can have a vehicle computing system 216. Vehicle computing system 216 can be communicatively coupled to first battery unit 204 and / or second battery unit 210 according to the discussion provided in FIG.

[0028] Vehicle 202 also includes an executive controller 218 that may include a processor 220 and a memory 222 communicatively coupled to processor 220. In some examples, executive controller 218 or components within executive controller 218 may be implemented within vehicle computing system 216. In other examples, vehicle computing system 216 may be implemented within executive controller 218. In some examples, components within executive controller 218 may be implemented within first battery management system 208 and / or second battery management system 214.

[0029] In the depicted example, memory 222 of executive controller 218 stores operation command component 224, limit comparison component 226, fault detection component 228, system controller 230, battery condition component 232, battery status component 234, and limit aggregation component 236. Although discussed in the context of memory 222, executive controller 218 may include a processor and memory that may implement one or more of components 224, 226, 228, 230, 232, 234, and 236. In some examples, the executive controller may comprise processor 220 and memory 222.

[0030] The operational command component 224 can be configured to generate commands to be transmitted by the executive controller 218. The commands can be, in some examples, a shutdown command, a drive command, a charge command, or a sleep command. The executive controller 218 can be communicatively coupled to the first battery unit 204 and / or the second battery unit 210 and can transmit commands to the first battery unit 204 and / or the second battery unit 210.

[0031] The limit comparison component 226 can compare limits received at the executive controller 218. As discussed above, the first battery management system 208 can transmit first battery data to the executive controller 218, and the second battery management system 214 can transmit second battery data to the executive controller 218. The first battery data and second battery data can each include operational data, such as temperature data, and / or first limit data and / or second limit data, such as current limit data, power limit data, and / or voltage limit data. In at least some examples, such limit data includes aggregate limits calculated by each of the first and second BMSs 208, 214 based on the limits of their own batteries, as well as limits received from other BMSs. In other examples, such aggregations can be determined by the executive controller 218 based on data of the first and second batteries 206, 212 transmitted by the BMSs 208, 214. The limit comparison component 226 can compare the values of the first limit data (e.g., first aggregated data) and the second limit data (e.g., second aggregated data) to determine which has a higher or lower value. In at least some examples, the executive controller 218 can choose the lower value to provide conservative operating limits, ensuring that the battery is not over-currented or that the system can generally provide the required power. The vehicle 202 can be an autonomous vehicle, and in some examples, the vehicle 202 can use the limit data to determine the trajectory of the vehicle 202 and / or adjust the driving characteristics / behavior of the vehicle 202.

[0032] The fault detection component 228 can determine a fault in the system based at least in part on the battery data received from the respective BMS. In some examples, the fault detection component 228 can detect a fault using battery data such as real-time current data. As an example, if the first battery management system 208 transmits battery data including real-time current data that exceeds a normal operating threshold, the fault detection component 228 can determine that a fault has occurred, identify the type of fault as an over-current fault, and / or generate an indication of the fault. In some examples, the fault detection component 228 can detect a fault using battery data such as limit data. As an example, if the first battery management system 208 transmits battery data including a current limit at a value below a normal operating threshold, the fault detection component 228 can determine that a fault has occurred, identify the type of fault as a current limit fault, and / or generate an indication of the fault. Additionally, for illustrative purposes, the fault detection component 228 can use a battery status, such as a shutdown fault status, in the battery data. The fault detection component 228 can then determine that a fault has occurred, identify the type of fault as a shutdown fault condition associated with the particular battery, and / or generate an indication of the fault.

[0033] System controller 230 can be configured to control steering, propulsion, braking, safety, emitter, communication, and other systems of vehicle 202. System controller 230 can communicate with and / or control corresponding systems, such as drive modules and / or other components of vehicle 202, such as executive controller 218. In some examples, executive controller 218 can program and assign system controllers 230 to operate in conjunction with one another.

[0034] The battery status component 232 can monitor and / or update the status of the first battery unit 204 and / or the second battery unit 210. In some examples, the first battery unit 204 can receive commands from the executive controller 218 in the first battery management system 208. Based on the current state of the first battery unit 204, the command received by the executive controller 218, and / or the current state (e.g., temperature, charge level, etc.), the battery status component 232 can update the status of the first battery unit 204. For purposes of illustration, if the current state of the first battery unit 204 is a driving state and the executive controller 218 sends a charge command to the first battery unit 204, which is received at the first battery management system 208, the battery status component 232 can change the current state of the first battery unit 204 from a driving state to a charging state.

[0035] The battery status component 234 can monitor and / or update the status of the first battery 206 and / or the second battery 212. In some examples, the first battery 206 can indicate a normal status, and the battery status component 234 can broadcast an "okay" status via the first battery management system 208. In some examples, the first battery management system 208 can broadcast a "do not start" status, an "end mission" status, and / or a "stop immediately" status. The different statuses can inform other components, such as the executive controller 218, of the operational status of the batteries, thus enabling the executive controller 218 to adjust drive operation based on the status of one or more batteries.

[0036] The limited aggregation component 236 can provide different methods for generating and / or calculating the aggregated data. In some examples, the limited aggregation component 236 can be implemented in the first battery unit 204 and / or the second battery unit 210. Additionally, the limited aggregation component 236 can be implemented in the vehicle computing system 216. Depending on the implementation, the limited aggregation component 236 can be implemented in all or some of the executive controller 218, the first battery unit 204, the second battery unit 210, the vehicle computing system 216, and / or the additional battery units. In some examples, the limited aggregation component 236 can include an open-loop component 238 and / or a closed-loop component 240, where the open-loop component 238 includes a summing component 242 and / or a look-up table component 244. In some cases, the aggregated data can be based on the first battery data and the second battery data. In some examples, the first battery data may include a first current limit associated with the first battery 206, and the second battery data may include a second current limit associated with the second battery 212.

[0037] The summing component 242 can calculate the aggregate data by using additivity. As an example, the summing component 242 can sum the value of the first current limit and the value of the second current limit to generate an aggregate current limit. For example, if the first current limit associated with the first battery 206 is 50 A and the second current limit associated with the second battery 212 is 60 A, the summing component 242 can generate an aggregate limit of 110 A. In some examples, the summing component 242 can calculate the aggregate current limit using a weighted sum. For example, the first battery 206 may have a weighted sum of 0. 8The first battery 212 may have a first current limit associated with a weighted 100A of 0, and the second battery 212 may have a second current limit associated with a weighted 200A of 0.30, so the summing component 242 may generate an aggregate current limit of ((100A*0.80)+(200A*0.30))=140A.

[0038] The lookup table component 244, in some examples, can use a database with entries in which the first current limit and the second current limit serve as a key or reference to another value that can be used as the aggregate current limit. For example, if the first current limit associated with the first battery 206 is 50 A and the second current limit associated with the second battery is 60 A, the lookup table component 244 can search a table that indicates the aggregate limit is 100 A (or any value, depending on the implementation). In some examples, the table can be associated with the battery and provided, for example, as a configuration file. In other examples, the table can be derived, for example, by performing characterization of the battery. In other examples, the table can be derived by collecting data during operation of the battery.

[0039] The closed-loop component 240 can use real-time data for one or more batteries, such as, but not limited to, internal impedance data. In some examples, the closed-loop component 240 can use a first impedance associated with the first battery unit 204 and a second impedance associated with the second battery unit 210 to calculate an aggregate current limit using the first impedance, the second impedance, the first current limit, and the second current limit. In at least some examples, such a current limit can be calculated according to, for example, a shunt law model.

[0040] 2, vehicle 202 can be configured to use a charging system 246 for charging first battery 206 and / or second battery 212 coupled to vehicle 202. Charging system 246 can include a charging coupler 248 for coupling to a corresponding receptacle in the lower body of vehicle 202. Charging coupler 248 can have a housing 250 including electrical contacts 252 and 254. Charging coupler can include a cable 256 coupled to a power source 258. Additional details of charging system 246 are described in U.S. Patent Application Serial No. 15 / 837,862, which is incorporated herein by reference.

[0041] 2, charging system 246 may also include anchor 260 associated with a surface on which charging coupler 248 is disposed and configured to selectively hold charging coupler 248 in place. In some examples, charging coupler 248 may be intended to be either portable or fixed in place on a surface, and anchor 260 may be configured to selectively secure charging coupler 248 in a fixed position or allow for repositioning using known fastening assemblies, such as fasteners, clamps, etc.

[0042] Vehicle 202 can be driven to a position on charging coupler 248 such that electrical contacts 252 and 254 of charging coupler 248 are aligned with contacts mounted on the bottom of vehicle 202. Vehicle 202 can be an autonomous vehicle, and charging system 246 can include one or more markers that can be used by vehicle 202 to drive to a substantially aligned position to receive electricity from charging system 246. In at least some examples, autonomous vehicles can be manually controlled on such charging platforms. Details of such manual control of autonomous vehicles are described in U.S. Patent Application Serial No. 15 / 833,695, which is incorporated herein by reference.

[0043] In some examples, vehicle 202 may be an unmanned vehicle, such as an autonomous vehicle configured to operate in accordance with a Level 5 classification issued by the U.S. National Highway Traffic Safety Administration, which describes a vehicle capable of performing all safety-critical functions for an entire journey without the expectation that a driver (or passenger) is in control of the vehicle at all times. In such examples, vehicle 202 may be configured to control all functions from the start to the completion of a journey, including all parking functions, and may not include a driver and / or controls for driving vehicle 202, such as a steering wheel, accelerator pedal, and / or brake pedal. This is merely an example, and the systems and methods described herein may be incorporated into any land, air, or water vehicle, including vehicles that require manual control at all times by a driver, to those that are partially or fully autonomously controlled.

[0044] Although vehicle 202 has four wheels, the systems and methods described herein may be incorporated into vehicles having fewer or more wheels, tires, and / or tracks. Vehicle 202 may have four-wheel steering and may operate with generally equal performance characteristics in all directions, such that when traveling in a first direction 264, first end 262 of vehicle 202 is the front end of vehicle 202, and when traveling in an opposite second direction 266, first end 262 is the rear end of vehicle 202, as shown in FIG. 2 . Similarly, when traveling in second direction 266, second end 268 of vehicle 202 is the front end of vehicle 202, and consequently, when traveling in the opposite first direction 264, second end 268 is the rear end of vehicle 202. These example features may provide improved maneuverability in small spaces or crowded environments, such as parking lots and city streets.

[0045] Vehicle 202 may traverse through an environment relying at least in part on sensor data indicative of objects in the environment to determine a trajectory of vehicle 202. In some examples, as vehicle 202 traverses through an environment, one or more sensors 270 capture data associated with detected objects (e.g., vehicles, pedestrians, buildings, barriers, etc.). Sensors 270 may include image capture devices, LIDAR sensors, SONAR sensors, RADAR sensors, microphones, etc. Data captured by sensors 270 may be used, for example, as input to determine a trajectory of vehicle 202.

[0046] Figure 3 is a schematic diagram of a vehicle 300 including a body module (or body unit) 302, a first drive module (or first drive unit) 304 disposed on either end of the body module 302, and a second drive module (or second drive unit) 306. Figure 3 shows the vehicle 300 in an unassembled state 308 and an assembled state 310. In the unassembled state 308, the body module 302 may be supported by supports that are internal to or incorporated into the vehicle 300, or that are incorporated into a service center or the like.

[0047] During installation, in some examples, the first drive module 304 and the second drive module 306 can be installed by moving them longitudinally of the vehicle 300 toward the body module 302, as indicated by arrows 312 and 314. Once the drive modules 304 and 306 are installed in the body module 302, the first battery unit 316 included in the first drive module 304 and the second battery unit 318 included in the second drive module 306 can be electrically coupled via a bus or a controller area network (CAN). In some examples, the first drive module 304 and the second drive module 306 can be installed by moving them vertically (not limited to the horizontal coupling shown in FIG. 3 ) toward the body module 302. Furthermore, in some examples, the first drive module 304 and the second drive module 306 can be substantially similar such that they can be interchanged within the body module 302 and continue normal operation. In some examples, the first drive module 304 and the second drive module 306 can be substantially different while having substantially similar interfaces. In such cases, the first drive module 304 and the second drive module 306 may provide different functionality or limitations, but may still be interchangeably coupled to the body module 302 .

[0048] FIG. 4A illustrates an example architecture for a redundant BMS architecture using a ring configuration or topology 400. In some examples, one or more executive controllers 402 can be coupled to a first battery management system 404 and a last or nth battery management system 404. While depicted between the BMSs for illustrative purposes, any one or more executive controllers 402 can be interspersed between the BMSs. In such cases, the executive controller 402 may not be directly coupled to the second battery management system 406. Furthermore, this configuration 400 allows for continued operation in the event of certain failure scenarios. In some examples, the system can continue operation even if any connection between adjacent components is damaged and / or severed. While this provides the system with continuity of operation, multiple types of failure conditions can degrade performance. In such a configuration, each BMS can receive limit data and / or physical parameters from the other BMSs and calculate one or more aggregate limits that it passes to one or more ECs 402. In turn, any one or more executive controllers 402 can receive aggregate limits from multiple sources and, at least in some examples, relay the individual BMS data to the remaining BMSs along the ring. This diagram shows an example configuration, and other configurations are contemplated. In some examples, the executive controller 402 may be connected to additional battery management systems, and not all battery management systems may be coupled to the ring.

[0049] FIG. 4B illustrates an example architecture for a redundant BMS architecture using a mesh configuration 408. In some examples, an executive controller 410 can be coupled to a first battery management system 412, a second battery management system 414, a third battery management system 416, and a last or nth battery management system 418. In such cases, the executive controller 410 can be coupled to all battery management systems, with each battery management system being coupled to two other battery management systems. In some examples, the system can continue operation under fault conditions, such as damage or disconnection of N-1 connections to the executive controller 410. For illustrative purposes, if the nth battery management system 418 is the fourth battery management system, the system can continue operation even if three of the four connections to the executive controller 410 are damaged and / or disconnected. Furthermore, the configuration 408 can continue operation even with multiple damage or disconnection of connections between the battery management systems. In such examples, each BMS can relay limit and / or parameter data to at least one or more other BMSs and the executive controller 410. Each BMS may in turn calculate an aggregation limit that is in turn sent to the executive controller 410. This diagram shows an example configuration, and other configurations are contemplated. In some examples, the executive controller 410 may not be connected to all battery management systems, but rather to only a subset of the available battery management systems. In some examples, the configuration may implement a full-mesh topology in which the executive controller 410 is coupled to every battery management system, and every battery management system is coupled to every other battery management system.

[0050] 5 through 7 illustrate example processes according to embodiments of the present disclosure. These processes are illustrated as logical flow graphs, with each operation representing a sequence of operations that may be implemented in hardware, software, or a combination thereof. In the software context, the operations represent computer-executable instructions stored on one or more computer-readable storage media that, when executed on one or more processors, perform the recited operations. Generally, computer-executable instructions include routines, programs, objects, components, data structures, etc. that perform particular functions or implement particular abstract data types. The order in which the operations are described is not intended to be construed as a limitation, and any number of the described operations may be implemented in a process in any order and / or in parallel or combination.

[0051] FIG. 5 shows an example process 500 for receiving battery data and instructing battery units. In operation 502, process 500 may include receiving, at an executive controller (EC), first battery data and first aggregate battery data from a first battery unit. As discussed above, the EC may be coupled to the first battery unit. In some examples, the first battery data may include current limit data, power limit data, voltage limit data, temperature data, connection data, system state, battery state, battery status, and / or impedance data. In some examples, the aggregate battery data may include any combination of data or calculation of data, including any of the battery data described herein. In operation 504, process 500 may include receiving, at the EC, second battery data and second aggregate battery data from a second battery unit. Similarly, as discussed above, the EC may be coupled to the second battery unit. Although shown operating in parallel (e.g., substantially simultaneously within technical limits), operations 502 and 504 may occur sequentially, with either operation 502 or 504 occurring before the other.

[0052] In operation 506, process 500 may include generating, at the EC, a comparison between the first aggregated battery data and the second aggregated battery data. The comparison may indicate whether the value of the first aggregated battery data is greater than the second aggregated battery data, or vice versa.

[0053] In operation 508, process 500 may include selecting operational battery data based on the comparison. In some examples, operation 508 selects lower aggregate battery data (e.g., also referred to as aggregate battery limits) as the operational battery data (e.g., also referred to as operating limits). In some examples, operation 508 selects higher aggregate battery data as the operational battery data. For purposes of illustration, under normal operation, the system may use a conservative setting and select lower aggregate battery data as the operational battery data. If the aggregate battery data includes a current limit, using a conservative setting and selecting a lower aggregate current limit may reduce the probability of drawing excessive current from the battery, which in turn may reduce the probability of damaging the battery unit, the battery, and / or the battery management system. Further, for purposes of illustration, under critical conditions, the system may require increased power and may select higher aggregate battery data as the operational battery data. The higher aggregate battery data may represent optimistic available power, allowing the system to anticipate stresses that may be placed on system components due to environmental or other critical conditions.

[0054] In operation 510, process 500 may include transmitting first battery data from the EC to the second battery unit, and in operation 512, transmitting second battery data from the EC to the first battery unit. This may include receiving data from the second battery unit to the first battery unit and receiving data from the second battery unit to the first battery unit. Like operations 502 and 504, while shown occurring in parallel, operations 510 and 512 may occur sequentially, with one operation occurring before the other, or vice versa. Furthermore, operations 502, 504, 510, and 512 may represent an ongoing process occurring with any frequency. Thus, in some examples, battery data and aggregate battery data may be transmitted continuously between the first and second battery units, while the EC may generate comparisons and essentially independently select operational battery data as it receives the battery data.

[0055] In operation 514, the process 500 may include controlling an electrical load based on the operational battery data. As discussed above, the system may, in some examples, provide power to a drive module for the autonomous vehicle to travel.

[0056] 6 illustrates a process 600 for transmitting aggregate battery data from a battery management system, for example, to an executive controller and / or another battery management system. In operation 602, process 600 may include generating first battery data at a first battery management system (BMS). In this process, the first battery management system may reference the first BMS 104, as described with respect to FIG. 1. In operation 602, the first battery data may include current limit data, power limit data, voltage limit data, temperature data, connection data, state, status, and / or impedance data, as discussed above. The first BMS may also be configured to monitor and / or measure the battery and / or battery unit to generate the battery data.

[0057] In operation 604, process 600 may include transmitting the first battery data from the first BMS to an executive controller (EC) and / or a second BMS. As described with respect to FIG. 1, the EC may refer to the EC 102, and the second BMS may refer to the second BMS 106. Further, as shown in FIG. 1, the first BMS may be coupled to the executive controller and / or the second BMS. The coupling may enable the first BMS to transmit the first battery data to either the executive controller or the second BMS.

[0058] In operation 606, process 600 may include receiving, at the first BMS, the second battery data from the second BMS. As discussed in FIG. 1, the first BMS may receive the second battery data via a coupling between the first BMS and the second BMS. In some examples, the first BMS may receive the second battery data from an EC.

[0059] In operation 608, the process 600 may include generating, at the first BMS, aggregate battery data. The aggregate battery data may include any combination of data or calculation of data, including any of the battery data described above. In some examples, the first battery data may include a first current limit, and the second battery data may include a second current limit. When generating the aggregate battery data, the first BMS may use the first current limit and the second current limit to generate the aggregate battery data as an aggregate current limit. In some examples, the first aggregate current limit may include a sum of the first current limit and the second current limit. In some examples, the first aggregate current limit may include a table entry that uses the first current limit and the second current limit as a lookup key. In some examples, the first aggregate current limit may include a dynamic current limit based on observed characteristics of the first and / or second batteries, such as, but not limited to, impedance, slew rate, or overshoot.

[0060] In operation 610, process 600 may include transmitting aggregate battery data from the first BMS to the EC and / or the second BMS. In some examples, the aggregate battery data may be an aggregate current limit. The first BMS may then transmit the aggregate battery data to the EC and / or to the second BMS using a combination. In some examples, the system may have additional controllers and / or battery management systems. In such cases, the first BMS may be configured to transmit the aggregate battery data to a subset of components in the architecture. In some examples, the first BMS may be configured to broadcast the battery data to all components in the architecture.

[0061] 7 shows an example process for determining a fault condition. In operation 702, process 700 may include receiving battery data (e.g., limits, status, temperature, etc.) at an EC. The battery data may refer, for example, to the battery data described with respect to FIG. 1.

[0062] In operation 704, process 700 may perform a check to determine whether the battery data meets or exceeds a threshold. In some examples, the battery data may include aggregate current data, as described above. A minimum current may be required to perform a required operation in the system. In some examples, the aggregate current data may meet or exceed the required minimum current amount. In such a case, process 700 may return to operation 702. If the aggregate current data does not meet or exceed the required minimum current amount, process 700 may proceed to operation 706.

[0063] In operation 706, process 700 may include generating an indication of a fault at the EC. In some examples, the fault may be available current less than the amount of current required for a particular driving operation. In some examples, the fault may be available current less than the recommended current (e.g., if the recommended current includes a built-in safety factor that exceeds the amount of current required). Faults may also include indications of damaged or disconnected connections and other battery data above or below required or recommended operational thresholds.

[0064] In operation 708, process 700 may include controlling an electric load, for example, but not limited to, an electric motor, based at least in part on the battery data. In some examples, after detecting a fault and generating an indication of the fault, the system may continue basic operations, for example, providing available power to an electric motor. In some examples, operation 708 may allow the system to operate as a fully functional system, but with an indication of the fault, which may be a warning or an indication of a possible future error.

[0065] [Example of invention content] A: A system comprising: a first battery unit including a first battery and a first battery management system (BMS); a second battery unit including a second battery and a second BMS; and a controller communicatively coupled to the first BMS and the second BMS, the controller configured to perform operations including: receiving first battery data and first aggregated limit data from the first BMS; receiving second battery data and second aggregated limit data from the second BMS; determining operating limits based at least in part on the first aggregated limit data and the second aggregated limit data; determining a torque value of an electric motor based at least in part on the operating limits; and controlling the electric motor based at least in part on the torque value.

[0066] B: The system of paragraph A, wherein the first BMS is communicatively coupled to the second BMS, and the operation further includes transmitting the first battery data from the first BMS to the second BMS and transmitting the second battery data from the second BMS to the first BMS, wherein the first aggregated limit data is determined by the first BMS and based at least in part on the first battery data and the second battery data, and the second aggregated limit data is determined by the second BMS and based at least in part on the first battery data and the second battery data.

[0067] C: The system described in paragraph A or paragraph B, wherein determining the operating limit includes comparing the first aggregate limit data with the second aggregate limit data as a comparison, and selecting an aggregate lower limit as the operating limit based at least in part on the comparison.

[0068] D: The system described in any of paragraphs A to C, wherein the first battery data includes a first current limit or a first power limit associated with the first battery, and the second battery data includes a second current limit or a second power limit associated with the second battery.

[0069] E: The system described in paragraph D, wherein the first aggregated limit data or the second aggregated limit data includes at least one of a combination of the first current limit and the second current limit, a lookup table entry based at least in part on the first current limit and the second current limit, or a dynamic limit based on observed characteristics of the first battery or the second battery, the observed characteristics including at least one of impedance, slew rate, or overshoot.

[0070] F: The system described in any of paragraphs A to E, wherein the operation further includes the steps of determining that an observed operating condition is within a range associated with the operating limits, the observed operating condition including at least one of power usage, current usage, or voltage usage, and determining that a fault condition has occurred, the fault condition indicating that at least one of the first battery unit or the second battery unit is malfunctioning.

[0071] G: A method comprising the steps of receiving first battery data and first aggregated limit data from a first battery unit, receiving second battery data and second aggregated limit data from a second battery unit, determining an operating limit based at least in part on the first aggregated limit data and the second aggregated limit data, determining a load value based at least in part on the operating limit, and controlling an electric device based at least in part on the load value.

[0072] H: The method of paragraph G, further comprising the steps of: determining that the electric device is a motor and that the operating limit does not meet or exceed a threshold; determining that a fault condition has occurred; and controlling the motor to execute a safe stopping trajectory for the vehicle.

[0073] I: The method of paragraph H, wherein the vehicle comprises an autonomous vehicle.

[0074] J: The method of any of paragraphs G to I, further comprising determining an aggregation lower limit based at least in part on the first aggregation limit data and the second aggregation limit data, and selecting the aggregation lower limit.

[0075] K: The method of any of paragraphs G to J, further comprising the steps of determining that the first aggregated restriction data does not meet or exceed a restriction threshold, and determining that the first battery unit is malfunctioning.

[0076] L: The method of any of paragraphs G to K, further comprising the step of transmitting a portion of the first battery data to the second battery unit.

[0077] M: The method described in any of paragraphs G to L, wherein the first battery data includes at least one of current limit data, power limit data, voltage limit data, temperature data, connection data, battery operating status, system operating status, or battery status.

[0078] N: A non-transitory computer-readable medium storing instructions executable by a processor, the instructions, when executed, causing the processor to perform operations including: receiving, at a controller, first battery data from a first battery unit; receiving, at the controller, second battery data from a second battery unit; determining operating limits based at least in part on the first battery data and the second battery data; determining a load value for an electrical component based at least in part on the operating limits; and controlling the electrical component based at least in part on the load value.

[0079] O: The non-transitory computer-readable medium of paragraph N, wherein the instructions, when executed, cause the processor to further perform operations including receiving, at the controller, first aggregate limit data from the first battery unit and second aggregate limit data from the second battery unit; determining an aggregate battery underlimit based at least in part on the first aggregate limit data and the second aggregate limit data; and selecting the aggregate battery underlimit.

[0080] P: The non-transitory computer-readable medium of paragraph O, wherein the first aggregate limit includes at least one of: a combination of the first aggregate limit data and the second aggregate limit data; a lookup table entry based at least in part on the first aggregate limit data and the second aggregate limit data; or a dynamic limit based at least in part on observed characteristics of the first battery unit or the second battery unit, the observed characteristics including at least one of impedance, slew rate, or overshoot.

[0081] Q: The non-transitory computer-readable medium of any of paragraphs N to P, wherein the instructions, when executed, further cause the processor to perform operations including generating an aggregate battery limit based at least in part on the first battery data and the second battery data.

[0082] R: The non-transitory computer-readable medium of any of paragraphs N to Q, wherein the instructions, when executed, cause the processor to further perform operations including receiving, at the controller, first aggregate limit data from the first battery unit and second aggregate limit data from the second battery unit; determining that a difference between the first aggregate limit data and the second aggregate limit data meets or exceeds a difference threshold; and determining a failure of a first coupling between the first battery unit and the controller or a second coupling between the second battery unit and the controller.

[0083] S: The non-transitory computer-readable medium of any of paragraphs N to R, wherein the instructions, when executed, further cause the processor to perform operations including: determining, based at least in part on the first battery data or the second battery data, that a fault condition has occurred, the fault condition including at least one of a current fault, a power fault, a voltage fault, or a temperature fault.

[0084] T: A non-transitory computer-readable medium described in any of paragraphs N to S, wherein the instructions, when executed, cause the processor to further perform operations including: transmitting a portion of the first battery data to the second battery unit; and transmitting a portion of the second battery data to the first battery unit.

[0085] Although the above example subject matter is described with respect to one particular implementation, it should be understood in the context of this document that the example subject matter may also be implemented via methods, devices, systems and / or computer-readable media, and / or other implementations.

[0086] [Conclusion] One or more examples of the technology described herein have been described; however, various modifications, additions, permutations, and equivalents thereof fall within the scope of the technology described herein.

[0087] In the illustrative description, reference is made to the accompanying drawings, which form a part hereof, and which show, by way of illustration, specific examples of the claimed subject matter. It is understood that other examples may be used and modifications, such as structural changes, or substitutions may be made. Such examples, modifications, or substitutions do not necessarily depart from the intended scope of the claimed subject matter. While steps herein may be presented in a particular order, in some cases the order can be changed so that certain inputs are provided at different times or in a different order without changing the functionality of the described systems and methods. Disclosed procedures can also be performed in a different order. Furthermore, the various calculations herein need not be performed in the order disclosed, and other examples using alternative orders of calculations can be readily implemented. In addition to reordering, calculations can also be decomposed into sub-calculations that produce the same result.

Claims

1. a first battery unit including a first battery and a first battery management system (BMS); a second battery unit including a second battery and a second BMS; a controller communicatively coupled to the first BMS and the second BMS; A system comprising: The controller receiving first battery data and first aggregated limit data from the first BMS, the first battery data including a first current limit or a first power limit associated with the first battery, the first aggregated limit data being determined by the first BMS and based at least in part on the first battery data and at least in part on second battery data; receiving the second battery data and second aggregated limit data from the second BMS, the second battery data including a second current limit or a second power limit associated with the second battery, the second aggregated limit data being determined by the second BMS and based at least in part on the first battery data and at least in part on the second battery data; determining an activation limit based at least in part on the first aggregate limit data and the second aggregate limit data; determining a torque value for the electric motor based at least in part on the operating limits; controlling the electric motor based at least in part on the torque value; configured to perform operations including system.

2. The first BMS is communicatively coupled to the second BMS, and the operation comprises: Transmitting the first battery data from the first BMS to the second BMS; transmitting the second battery data from the second BMS to the first BMS; The system of claim 1 further comprising:

3. Determining the activation limit comprises: comparing the first aggregated limit data with the second aggregated limit data as a comparison; selecting an aggregate lower limit as the activation limit based at least in part on the comparison; and 3. The system of claim 1 or claim 2, comprising:

4. The first aggregation restriction data or the second aggregation restriction data is a combination of the first current limit and the second current limit; a lookup table entry based at least in part on the first current limit and the second current limit; or dynamic limiting based on observed characteristics of the first battery or the second battery, the observed characteristics including at least one of impedance, slew rate, or overshoot; The system of claim 1 , comprising at least one of:

5. The operation is determining that observed operating conditions are within ranges associated with the operational limits, the observed operating conditions including at least one of power usage, current usage, or voltage usage; determining that a fault condition has occurred, the fault condition indicating that at least one of the first battery unit or the second battery unit is malfunctioning; and The system of claim 1 , further comprising:

6. receiving first battery data and first aggregate limit data from a first battery unit, the first battery data including a first current limit or a first power limit associated with the first battery, the first aggregate limit data being determined by a first battery management system and based at least in part on the first battery data and at least in part on second battery data; receiving second battery data and second aggregate limit data from a second battery unit, the second battery data including a second current limit or a second power limit associated with the second battery, the second aggregate limit data being determined by a second battery management system and based at least in part on the first battery data and at least in part on the second battery data; determining an activation limit based at least in part on the first aggregate limit data and the second aggregate limit data; determining a load value based at least in part on the operational limits; and controlling an electric device based at least in part on the load value; A method comprising:

7. the electrical device is a motor; determining that the operational limit does not meet or exceed a threshold; determining that a fault condition has occurred; controlling the motor to execute a safe stopping trajectory for the vehicle; The method of claim 6 further comprising:

8. determining that the first aggregate restricted data does not meet or exceed a restricted threshold; determining that the first battery unit is malfunctioning; The method of claim 6 or claim 7, further comprising:

9. The method of claim 6 , further comprising transmitting a portion of the first battery data to the second battery unit.

10. The first battery data is Voltage limit data, temperature data, connection data, the operating state of the battery, The operating state of the system, or Battery status, The method of any one of claims 6 to 9, comprising at least one of:

11. A non-transitory computer-readable medium storing instructions executable by a processor, the instructions, when executed, causing the processor to: receiving, at a controller, first battery data and first aggregate limit data from a first battery unit, the first battery data including a first current limit or a first power limit associated with the first battery, the first aggregate limit data being determined by a first battery management system and based at least in part on the first battery data and at least in part on second battery data; receiving, at the controller, second battery data and second aggregate limit data from a second battery unit, the second battery data including a second current limit or a second power limit associated with a second battery, the second aggregate limit data being determined by a second battery management system and based at least in part on the first battery data and at least in part on the second battery data; determining an operating limit based at least in part on the first battery data and the second battery data; determining a load value for an electrical component based at least in part on the operational limits; controlling the electrical component based at least in part on the load value; A non-transitory computer-readable medium for causing operations to be performed, including:

12. The instructions, when executed, cause the processor to: determining an aggregate under-battery limit based at least in part on the first aggregate limit data and the second aggregate limit data; selecting the aggregate battery under-limit; The non-transitory computer-readable medium of claim 11 , further comprising:

13. The instructions, when executed, cause the processor to: generating an aggregate battery limit based at least in part on the first battery data and the second battery data; The non-transitory computer-readable medium of claim 11 , further comprising:

14. The instructions, when executed, cause the processor to: determining that a difference between the first aggregated restricted data and the second aggregated restricted data meets or exceeds a difference threshold; determining a fault in a first coupling between the first battery unit and the controller or a second coupling between the second battery unit and the controller; 13. The non-transitory computer-readable medium of claim 11 or claim 12, further comprising:

Citation Information

Patent Citations

  • Power storage system

    JP2012050157A