Network security protection system and method for traction battery, and related device

By adopting a separate control and management approach in the power battery network security protection system, and utilizing an independent first computing module to perform security audits on scheduling and control commands, the vulnerability issues in power battery network security protection have been resolved, effectively resisting malicious attacks and ensuring system stability.

WO2026158209A1PCT designated stage Publication Date: 2026-07-30FUJIAN NEBULA ELECTRONICS CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
FUJIAN NEBULA ELECTRONICS CO LTD
Filing Date
2026-01-19
Publication Date
2026-07-30

AI Technical Summary

Technical Problem

Existing power battery network security protection systems have security vulnerabilities when facing cyberattacks, which can easily lead to serious safety accidents, such as vehicle loss of control, battery fires and explosions.

Method used

A separate control and management system is adopted. The first calculation module performs security review on the scheduling and control commands, which is independent of the second calculation module, to ensure the compliance of the commands and prevent malicious attacks.

Benefits of technology

Even if attackers breach the system, the independent operation of the first computing module can prevent destructive attacks, ensure the stability of the last line of defense, enhance security without affecting normal management and control, and resist deliberate sabotage from within the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2026073333_30072026_PF_FP_ABST
    Figure CN2026073333_30072026_PF_FP_ABST
Patent Text Reader

Abstract

The present invention is applicable to the technical field of battery security, and particularly relates to a network security protection system and method for a traction battery, and a related device. The network security protection system is used for performing data transmission between an energy storage device and a cloud platform. The network security protection system comprises a collection control module, a first calculation module, a second calculation module and a communication module. Compared with the prior art, the present invention has the advantages that security examination is performed on a scheduling control command by means of a first calculation module, such that a malicious control command can be rejected when a cloud platform end is controlled by an attacker, so as not to generate a destructive attack effect; and even if the attacker has invaded the interior of a traction battery security system, since the first calculation module and a second calculation module are subjected to management and control separation, the first calculation unit module runs independently, such that the attacker cannot affect same. The first calculation module only checks whether a control operation is destructive in the current environment, and does not perform other operations, thereby not generating interference with normal management control.
Need to check novelty before this filing date? Find Prior Art

Description

Network security protection systems, methods and related equipment for power batteries Technical Field

[0001] This invention relates to the field of battery safety technology, and in particular to a network security protection system, method and related equipment for power batteries. Background Technology

[0002] As global energy and environmental issues become increasingly prominent, battery energy density and manufacturing technology are constantly improving, leading to the rapid rise of related industries such as power batteries and electric vehicles. Simultaneously, as core equipment in new energy technologies, the management, storage, and use of power batteries are becoming increasingly intelligent. However, this rapid development has also introduced new cybersecurity challenges. For example, compared to gasoline vehicles and battery systems, highly integrated and intelligent new energy facilities such as electric vehicles, battery management systems, and energy storage stations are more vulnerable to cyberattacks. Furthermore, for ordinary information systems, the main losses from malicious cyberattacks are the loss of data and information system availability or the leakage of privacy and secrets. Since power battery devices are connected to high-voltage electrical systems, attacks on their controllers, management systems, and other components could potentially lead to vehicle loss of control, battery fires and explosions, and other life-threatening situations with extremely serious consequences.

[0003] Existing technical solutions simply combine common network information system security technologies and apply them to specific energy scenarios. They still inherit the traditional security technology's boundary protection approach, preventing network attacks by strictly defining boundaries and implementing access control. However, it has been proven that despite the deployment of various security measures and equipment, network attacks still occur frequently due to the existence and unpredictability of various security vulnerabilities.

[0004] Therefore, there is an urgent need for a new network security protection system, method, and related equipment for power batteries to solve the above problems. Technical issues

[0005] This invention provides a network security protection system, method, and related equipment for power batteries, aiming to separate the management and control of control commands, thereby improving the network security of power batteries. Technical solutions

[0006] In a first aspect, the present invention provides a network security protection system for a power battery, the network security protection system being used for data transmission between an energy storage device and a cloud platform, the network security protection system comprising a data acquisition and control module, a first computing module, a second computing module, and a communication module; wherein,

[0007] The acquisition and control module is used to acquire the indicator data information of the energy storage device and send the indicator data information to the first calculation module; wherein, the indicator data information includes battery temperature, battery voltage, battery current, battery internal resistance and insulation resistance.

[0008] The first calculation module is used to send the received indicator data information to the second calculation module, and to receive the instructions fed back by the communication module and the instructions fed back by the second calculation module, and to perform security review on the instructions fed back by each module according to the configuration parameters corresponding to the energy storage device; wherein, the first calculation module is implemented by running an independent review program on an independent chip or an independent core in a multi-core processor;

[0009] The second calculation module is used to encapsulate the received indicator data information and send it to the communication module; wherein, the second calculation module is implemented based on a preset operating system;

[0010] The communication module is used to send the encapsulated indicator data information to the cloud platform.

[0011] Preferably, the communication module is further configured to receive a first scheduling control instruction sent by the cloud platform based on the encapsulated indicator data information, and send the first scheduling control instruction to the second computing module.

[0012] Preferably, the second calculation module is further configured to generate a second scheduling control instruction based on the indicator data information, and send the second scheduling control instruction and the received first scheduling control instruction to the first calculation module.

[0013] Preferably, the first calculation module is further configured to perform a security review on the first scheduling control instruction and the second scheduling control instruction based on the configuration parameters corresponding to the energy storage device, and determine whether there are any security issues with the first scheduling control instruction and the second scheduling control instruction; if so, the execution of the first scheduling control instruction and / or the second scheduling control instruction is suspended; if not, the first scheduling control instruction and the second scheduling control instruction are sent to the acquisition control module.

[0014] Preferably, the configuration parameters include the number of batteries in the energy storage device and the battery performance parameters.

[0015] Preferably, the acquisition and control module is further configured to send the received first scheduling control command and second scheduling control command to the energy storage device.

[0016] Secondly, the present invention also provides a network security protection method for a power battery, the network security protection method being based on a network security protection system for a power battery as described in any of the above embodiments, the network security protection method comprising the following steps:

[0017] S201. Obtain the indicator data information of the energy storage device through the acquisition and control module; wherein, the indicator data information includes the battery temperature information, voltage information and battery capacity information of the energy storage device;

[0018] S202. The second calculation module generates a second scheduling control instruction based on the indicator data information, and encapsulates the indicator data information to obtain encapsulated indicator data information.

[0019] S203, The communication module sends the encapsulation index data information to the cloud platform, and the cloud platform generates a first scheduling control instruction based on the encapsulation index data information;

[0020] S204. The first calculation module performs security verification on the first scheduling control command and the second scheduling control command according to the configuration parameters corresponding to the energy storage device, and determines whether there is a security problem with the first scheduling control command and the second scheduling control command; if so, the first scheduling control command and / or the second scheduling control command is terminated; if not, the first scheduling control command and the second scheduling control command are sent to the energy storage device through the acquisition control module to perform the corresponding operation.

[0021] Preferably, the configuration parameters include the number of batteries in the energy storage device and the battery performance parameters.

[0022] Thirdly, the present invention also provides a computer device, including: a memory, a processor, and a network security protection program for a power battery stored in the memory and executable on the processor, wherein when the processor executes the network security protection program for the power battery, it implements the steps in the network security protection method for the power battery as described in any of the above embodiments.

[0023] Fourthly, the present invention also provides a computer-readable storage medium storing a network security protection program for a power battery, wherein when the network security protection program for the power battery is executed by a processor, it implements the steps in the network security protection method for a power battery as described in any of the above embodiments. Beneficial effects

[0024] Compared to existing technologies, this invention performs security audits on scheduling and control commands through a first computing module. This allows it to reject malicious commands that could cause destructive attacks when the cloud platform is controlled by an attacker. Even if an attacker has breached the power battery safety system, the separation of control between the first and second computing modules ensures that the first computing module operates independently, preventing the attacker from influencing it and thus guaranteeing the stability of the last line of defense. Furthermore, the first computing module only checks whether control operations are destructive in the current environment, without performing other operations or interfering with normal management and control. During normal operation and maintenance, the first computing module is completely transparent to administrators and users, without affecting the overall system's business logic, thus improving security with minimal changes to the original structure. This can largely resist intentional sabotage by internal personnel via the network. Attached Figure Description

[0025] The present invention will now be described in detail with reference to the accompanying drawings. The above and other aspects of the present invention will become clearer and more readily understood through the detailed description following the accompanying drawings. In the drawings:

[0026] Figure 1 is a schematic diagram of the network security protection system for power batteries provided in an embodiment of the present invention;

[0027] Figure 2 is a flowchart of the network security protection method for power batteries provided in an embodiment of the present invention;

[0028] Figure 3 is a schematic diagram of the structure of the computer device provided in an embodiment of the present invention. Embodiments of the present invention

[0029] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the invention. Example 1

[0030] This invention provides a network security protection system 100 for a power battery. Referring to Figure 1, which is a schematic diagram of the structure of the network security protection system 100 for a power battery according to this invention, the network security protection system is used for data transmission between energy storage devices and a cloud platform. The network security protection system includes a data acquisition and control module 101, a first calculation module 102, a second calculation module 103, and a communication module 104.

[0031] The acquisition and control module 101 is used to collect indicator data information of the energy storage device and send the indicator data information to the first calculation module 102. The indicator data information includes battery parameters such as battery temperature, battery voltage, battery current, battery internal resistance, and insulation resistance. Specifically, the acquisition and control module 101 receives the indicator data information through a preset network protocol. The preset network protocol can be set according to actual conditions, such as MQTT (Message Queuing Telemetry Transport), AMQP (Advanced Message Queuing Protocol), STOMP (Simple Text Oriented Messaging Protocol), etc. It should be noted that the above protocols are only examples, and other types of protocols are also feasible.

[0032] The first calculation module 102 is used to send the received indicator data information to the second calculation module 103, and to receive instructions from the communication module 104 and the second calculation module 103, and to perform security reviews on the received instructions from each module according to the configuration parameters corresponding to the energy storage device. The first calculation module 102 is implemented based on an independent chip or an independent core in a multi-core processor running an independent review program. Its related functions are directly implemented within chips such as FPGAs, resulting in a very small attack surface. Furthermore, the first calculation module 102 only performs security reviews, determining whether the feedback instructions and the configuration parameters corresponding to the energy storage device are destructive in the current environment. It does not perform other operations or interfere with normal management and control. During normal operation and maintenance, the first calculation module 102 is completely transparent to administrators and users, does not affect the operating logic of the entire power battery network security protection system, and improves security while requiring minimal changes to the original structure.

[0033] Specifically, the first calculation module 102 is an HEM-P2P50 chip, which stores configuration parameters for various energy storage devices and runnable audit control algorithms. These audit control algorithms perform security verification on received scheduling control commands. The audit control algorithms can be SOX algorithms, MPPT (Maximum Power Point Tracking) algorithms, battery balancing algorithms, etc. Other types of control algorithms are also feasible and can be configured according to the specific energy storage device. Taking the SOX algorithm as an example, SOX is a set of algorithms used to describe the estimation of battery state, applicable to electric vehicles, energy storage systems, and portable devices. It provides comprehensive monitoring and evaluation of battery state, helping to optimize battery efficiency and extend battery life. It includes various algorithms such as SOC (State of Charge, remaining percentage of charge), SOH (State of Health, battery health), SOP (State of Power, allowable charge / discharge current value for lithium batteries), and SOE (State of Energy, remaining energy). These algorithms together constitute a comprehensive assessment of battery state.

[0034] The second calculation module 103 is used to encapsulate the received indicator data information and send it to the communication module 104. Specifically, the second calculation module 103 is responsible for running application software that implements various functions such as network communication, task scheduling, and security management, processing the received data, and generating scheduling control instructions. The second calculation module 103 is a Chipown D9340 chip, which deploys a Linux or ARM operating system. The operating system is reinstalled with energy management system software to provide edge computing capabilities, thereby calculating the second scheduling control instructions based on the indicator data information of the energy storage device. The second calculation module 103 is implemented based on a preset operating system, which can be ARM or Linux. This preset operating system is capable of implementing application software with various functions such as network communication, task scheduling, and security management, offering rich functionality and a larger attack surface.

[0035] The communication module 104 is used to send the encapsulated indicator data information to the cloud platform. Specifically, the communication module 104 can send the indicator data information to a centralized management system such as a control center or cloud platform via communication interfaces such as Bluetooth, Wi-Fi, Ethernet, 4G / 5G, or RS485.

[0036] In this embodiment of the invention, the communication module 104 is further configured to receive a first scheduling control instruction sent by the cloud platform based on the encapsulated indicator data information, and send the first scheduling control instruction to the second calculation module 103.

[0037] In this embodiment of the invention, the second calculation module 103 is further configured to generate a second scheduling control instruction based on the indicator data information, and send the second scheduling control instruction and the received first scheduling control instruction to the first calculation module 102.

[0038] In this embodiment of the invention, the first calculation module 102 is further configured to perform a security review on the first scheduling control instruction and the second scheduling control instruction according to the configuration parameters corresponding to the energy storage device, and determine whether there are any security issues with the first scheduling control instruction and the second scheduling control instruction; if so, the execution of the first scheduling control instruction and / or the second scheduling control instruction is suspended; if not, the first scheduling control instruction and the second scheduling control instruction are sent to the acquisition control module 101.

[0039] Specifically, because the second calculation module 103 can perform complex calculations and generate precise control commands, its attack surface is large. The first calculation module 102, on the other hand, is only responsible for security review of the first and second scheduling control commands. Its algorithm is relatively simple and does not rely on the operating system or other application software, resulting in a small attack surface and making it difficult to be attacked by network attacks. The network security protection system of this invention can be implemented as an energy storage station gateway, or as a Battery Management System (BMS), charging pile controller, etc. By separating management and execution through the first calculation module 102 and the second calculation module 103, the power battery network system is protected. This ensures that even if the energy storage device, charging pile, or vehicle network system has been attacked by hackers, it can still largely prevent the power battery network system from being maliciously attacked and causing dangerous situations such as fires and explosions. Even if hackers use social engineering or other means to control internal staff and allow them to damage the power battery network system, this invention can resist such attacks to a certain extent and achieve a balance between security and ease of use.

[0040] Security issues refer to problems where the first and second scheduling control commands may cause energy storage device malfunctions or safety accidents. For example, the first calculation module 102 uses the SOX algorithm to parse the first scheduling control command based on the configuration information corresponding to the energy storage device. If the compliant parameters in the command are 0xx3-0xx9, but the received first scheduling control command contains a parameter of 0xxA, then the first scheduling control command is considered a high-risk command, and forwarding it is refused, with a warning to the system administrator that the system may be under attack. If the parameter in the first scheduling control command is 0xx4, it is determined to be a normal control command, and the command is sent to the acquisition and control module 101 to be transmitted to the energy storage device. It should be noted that both the first and second scheduling control commands may have security issues. If the parameters in both scheduling control commands are non-compliant, both commands are suspended. If the parameters in one scheduling control command are non-compliant while the parameters in the other are compliant, the scheduling control command with the non-compliant parameters is suspended, and the other scheduling control command is sent.

[0041] In this embodiment of the invention, the configuration parameters include the number of batteries in the energy storage device and the battery performance parameters.

[0042] In this embodiment of the invention, the acquisition and control module 101 is further configured to send the received first scheduling control instruction and second scheduling control instruction to the energy storage device.

[0043] Compared to existing technologies, this invention performs security audits on scheduling and control commands through a first computing module. This allows it to reject malicious commands that could cause destructive attacks when the cloud platform is controlled by an attacker. Even if an attacker has breached the power battery safety system, the separation of control between the first and second computing modules ensures that the first computing module operates independently, preventing the attacker from influencing it and thus guaranteeing the stability of the last line of defense. Furthermore, the first computing module only checks whether control operations are destructive in the current environment, without performing other operations or interfering with normal management and control. During normal operation and maintenance, the first computing module is completely transparent to administrators and users, without affecting the overall system's business logic, thus improving security with minimal changes to the original structure. This can largely resist intentional sabotage by internal personnel via the network. Example 2

[0044] Referring to Figure 2, the present invention also provides a network security protection method for power batteries. The network security protection method is based on the network security protection system 100 for power batteries as described in any of the above embodiments, and includes the following steps:

[0045] S201. The energy storage device's indicator data information is acquired through the acquisition and control module 101; wherein, the indicator data information includes the battery temperature information, voltage information, and battery capacity information in the energy storage device;

[0046] S202. The second calculation module 103 generates a second scheduling control instruction based on the indicator data information, and encapsulates the indicator data information to obtain encapsulated indicator data information.

[0047] S203, The communication module 104 sends the encapsulation index data information to the cloud platform, and the cloud platform generates a first scheduling control instruction based on the encapsulation index data information.

[0048] S204. The first calculation module 102 performs security verification on the first scheduling control command and the second scheduling control command according to the configuration parameters corresponding to the energy storage device, and determines whether there is a security problem with the first scheduling control command and the second scheduling control command; if so, the first scheduling control command and / or the second scheduling control command is terminated; if not, the first scheduling control command and the second scheduling control command are sent to the energy storage device through the acquisition control module 101 to perform the corresponding operation.

[0049] In this embodiment of the invention, the configuration parameters include the number of batteries in the energy storage device and the battery performance parameters.

[0050] Specifically, the first calculation module 102 is an HEM-P2P50 chip, which stores configuration parameters for various energy storage devices and runnable audit control algorithms. These audit control algorithms perform security verification on received scheduling control commands. The audit control algorithm can be one of the following: SOX algorithm, MPPT (Maximum Power Point Tracking) algorithm, battery balancing algorithm, etc. Other types of control algorithms are also feasible and can be configured according to the specific energy storage device. Taking the SOX algorithm as an example, SOX is a set of algorithms used to describe the estimation of battery state, applicable to electric vehicles, energy storage systems, and portable devices. It provides comprehensive monitoring and evaluation of battery state, helping to optimize battery efficiency and extend battery life. It includes various algorithms such as SOC (State of Charge, remaining percentage of charge), SOH (State of Health, battery health), SOP (State of Power, allowable charge / discharge current value for lithium batteries), and SOE (State of Energy, remaining energy). These algorithms together constitute a comprehensive assessment of battery state.

[0051] The second calculation module 103 is used to encapsulate the received indicator data information and send it to the communication module 104. Specifically, the second calculation module 103 is responsible for running application software that implements various functions such as network communication, task scheduling, and security management, processing the received data, and generating scheduling control instructions. The second calculation module 103 uses a Chipown D9340 chip, which deploys a Linux operating system or ARM, and the operating system is reinstalled with energy management system software to provide edge computing capabilities, thereby calculating the second scheduling control instructions based on the indicator data information of the energy storage device.

[0052] Because the second calculation module 103 can perform complex calculations and generate precise control commands, its attack surface is large. The first calculation module 102, on the other hand, is only responsible for security review of the first and second scheduling control commands. Its algorithm is relatively simple and does not rely on the operating system or other application software, resulting in a small attack surface and making it difficult to be attacked by network attacks. The network security protection system of this invention can be implemented as an energy storage station gateway, or as a Battery Management System (BMS), charging pile controller, etc. By separating management and execution through the first calculation module 102 and the second calculation module 103, the power battery network system is protected. This ensures that even if the energy storage device, charging pile, or vehicle network system has been attacked by hackers, it can still largely prevent the power battery network system from being maliciously attacked and causing dangerous situations such as fires and explosions. Even if hackers use social engineering or other means to control internal staff and allow them to damage the power battery network system, this invention can resist such attacks to a certain extent and achieve a balance between security and ease of use.

[0053] Security issues refer to problems where the first and second scheduling control commands may cause energy storage device malfunctions or safety accidents. For example, the first calculation module 102 uses the SOX algorithm to parse the first scheduling control command based on the configuration information corresponding to the energy storage device. If the compliant parameters in the command are 0xx3-0xx9, but the received first scheduling control command contains a parameter of 0xxA, then the first scheduling control command is considered a high-risk command, and forwarding it is refused, with a warning to the system administrator that the system may be under attack. If the parameter in the first scheduling control command is 0xx4, it is determined to be a normal control command, and the command is sent to the acquisition and control module 101 to be transmitted to the energy storage device. It should be noted that both the first and second scheduling control commands may have security issues. If the parameters in both scheduling control commands are non-compliant, both commands are suspended. If the parameters in one scheduling control command are non-compliant while the parameters in the other are compliant, the scheduling control command with the non-compliant parameters is suspended, and the other scheduling control command is sent.

[0054] The network security protection method for the power battery can implement the steps of the network security protection system 100 for the power battery in the above embodiments and can achieve the same technical effect. Refer to the description in the above embodiments, which will not be repeated here. Example 3

[0055] This invention also provides a computer device. Please refer to Figure 3, which is a schematic diagram of the structure of the computer device provided in this invention. The computer device 300 includes: a memory 302, a processor 301, and a network security protection program for a power battery stored in the memory 302 and capable of running on the processor 301.

[0056] The processor 301 calls the network security protection program for the power battery stored in the memory 302 and executes the steps in the network security protection method for the power battery provided in this embodiment of the invention. Referring to Figure 2, the specific steps include:

[0057] A network security protection method for a power battery, the network security protection method being based on a network security protection system for a power battery as described in any of the above embodiments, the network security protection method comprising the following steps:

[0058] S201. The energy storage device's indicator data information is acquired through the acquisition and control module 101; wherein, the indicator data information includes the battery temperature information, voltage information, and battery capacity information in the energy storage device;

[0059] S202. The second calculation module 103 generates a second scheduling control instruction based on the indicator data information, and encapsulates the indicator data information to obtain encapsulated indicator data information.

[0060] S203, The communication module 104 sends the encapsulation index data information to the cloud platform, and the cloud platform generates a first scheduling control instruction based on the encapsulation index data information;

[0061] S204. The first calculation module 102 performs security verification on the first scheduling control command and the second scheduling control command according to the configuration parameters corresponding to the energy storage device, and determines whether there is a security problem with the first scheduling control command and the second scheduling control command; if so, the first scheduling control command and / or the second scheduling control command is terminated; if not, the first scheduling control command and the second scheduling control command are sent to the energy storage device through the acquisition control module 101 to perform the corresponding operation.

[0062] The computer device 300 provided in this embodiment of the invention can implement the steps in the network security protection method for power batteries as described in the above embodiments, and can achieve the same technical effect. Refer to the description in the above embodiments, which will not be repeated here. Example 4

[0063] This invention also provides a computer-readable storage medium storing a network security protection program for a power battery. When executed by a processor, the network security protection program for the power battery implements the various processes and steps in the network security protection method for the power battery provided in this invention and achieves the same technical effect. To avoid repetition, it will not be described again here.

[0064] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The program can be stored in a computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. The storage medium can be a magnetic disk, optical disk, read-only memory (ROM), or random access memory (RAM), etc. Example 5

[0065] This invention also provides an implementation scheme for data processing algorithms with low computing power requirements, resulting in lower costs. Specifically, when computing power is sufficient, the first computing module 102 and the second computing module 103 are implemented using different computing cores in a multi-core processor. For example, one core of the Chipown D9340 chip can be used in the bare system to implement the review and control algorithm of the first computing module 102 (i.e., an independent review program running on an independent core in a multi-core processor) to perform security verification on the received scheduling control instructions.

[0066] The second computing module 103 can use the 0 core in the SemiDrive D9340 chip, which runs the Linux operating system and has energy management system software installed to provide edge computing capabilities. It can calculate the second scheduling control command based on the index data information of the energy storage device, and send the first scheduling command and the second scheduling control command to the first computing module 102 through inter-core communication.

[0067] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.

[0068] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal (which may be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in the various embodiments of the present invention.

[0069] The embodiments of the present invention have been described above with reference to the accompanying drawings. The disclosed embodiments are merely preferred embodiments of the present invention. However, the present invention is not limited to the specific embodiments described above. The specific embodiments described above are merely illustrative and not restrictive. Those skilled in the art can make many equivalent changes in form without departing from the spirit and scope of the claims of the present invention, and all such changes are within the protection scope of the present invention.

Claims

1. A network security protection system for power batteries, characterized in that, The network security protection system is used for data transmission between the energy storage device and the cloud platform. The network security protection system includes a data acquisition and control module, a first computing module, a second computing module, and a communication module; wherein... The acquisition and control module is used to acquire the index data information of the energy storage device and send the index data information to the first calculation module; wherein, the index data information includes battery temperature, battery voltage, battery current, battery internal resistance and insulation resistance; The first calculation module is used to send the received indicator data information to the second calculation module, and to receive the instructions fed back by the communication module and the instructions fed back by the second calculation module, and to perform security review on the instructions fed back by each module according to the configuration parameters corresponding to the energy storage device; wherein, the first calculation module is implemented based on an independent review program running on an independent chip or an independent core in a multi-core processor; The second calculation module is used to encapsulate the received indicator data information and send it to the communication module; wherein, the second calculation module is implemented based on a preset operating system; The communication module is used to send the encapsulated indicator data information to the cloud platform.

2. The network security protection system for power batteries as described in claim 1, characterized in that, The communication module is also used to receive a first scheduling control instruction sent by the cloud platform based on the encapsulated indicator data information, and to send the first scheduling control instruction to the second computing module.

3. The network security protection system for power batteries as described in claim 2, characterized in that, The second calculation module is further configured to generate a second scheduling control instruction based on the indicator data information, and send the second scheduling control instruction and the received first scheduling control instruction to the first calculation module.

4. The network security protection system for power batteries as described in claim 3, characterized in that, The first calculation module is further configured to perform a security review on the first scheduling control instruction and the second scheduling control instruction based on the configuration parameters corresponding to the energy storage device, and determine whether there are any security issues with the first scheduling control instruction and the second scheduling control instruction; if so, the execution of the first scheduling control instruction and / or the second scheduling control instruction is suspended; if not, the first scheduling control instruction and the second scheduling control instruction are sent to the acquisition and control module.

5. The network security protection system for power batteries as described in claim 4, characterized in that, The configuration parameters include the number of batteries in the energy storage device and the battery performance parameters.

6. The network security protection system for power batteries as described in claim 4, characterized in that, The acquisition and control module is also used to send the received first scheduling control command and second scheduling control command to the energy storage device.

7. A network security protection method for a power battery, said network security protection method being based on the network security protection system for a power battery as described in any one of claims 1-6, characterized in that, The network security protection method includes the following steps: S201. Obtain the indicator data information of the energy storage device through the acquisition and control module; wherein, the indicator data information includes the battery temperature information, voltage information and battery capacity information of the energy storage device; S202. The second calculation module generates a second scheduling control instruction based on the indicator data information, and encapsulates the indicator data information to obtain encapsulated indicator data information. S203, The communication module sends the encapsulation index data information to the cloud platform, and the cloud platform generates a first scheduling control instruction based on the encapsulation index data information; S204. The first calculation module performs security verification on the first scheduling control command and the second scheduling control command according to the configuration parameters corresponding to the energy storage device, and determines whether there is a security problem with the first scheduling control command and the second scheduling control command; if so, the first scheduling control command and / or the second scheduling control command is terminated; if not, the first scheduling control command and the second scheduling control command are sent to the energy storage device through the acquisition control module to perform the corresponding operation.

8. The network security protection method for power batteries as described in claim 7, characterized in that, The configuration parameters include the number of batteries in the energy storage device and the battery performance parameters.

9. A computer device, characterized in that, include: A memory, a processor, and a network security protection program for a power battery stored in the memory and executable on the processor, wherein the processor, when executing the network security protection program for the power battery, implements the steps in the network security protection method for the power battery as described in any one of claims 7-8.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a network security protection program for the power battery, which, when executed by a processor, implements the steps of the network security protection method for the power battery as described in any one of claims 7-8.