Multi-Level ESS Network Isolation for Secure Remote Operation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

ESS systems face risks of accidents, malfunctions, and security breaches due to unauthorized access and abnormal operating conditions, particularly when operated remotely over networks, without effective security management systems.

Innovation Solution

A multi-level ESS security management system with monitoring and security means to detect abnormalities and block unauthorized access or operations, utilizing a network switch and physical switches to maintain safety, including a monitoring means with multiple levels connected via network communication and physical switches to manage battery states and operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If ESS is operated remotely over a network, then operational convenience is improved, but security vulnerability increases due to potential hacking and unauthorized access

Engineering Contradiction:
Improveremote operationVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system divides network security management into multiple hierarchical levels (level 1: module BMS, level 2: pack BMS, level 3: system BMS with PMS, level 4: top-level EMS), with each level having specific monitoring and control functions. This segmentation allows remote operation while distributing security responsibilities across different layers, reducing the attack surface at any single level.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a dual-domain switch control system that acts as an intermediary between the network and the ESS control systems. This intermediary layer includes both network switches and physical switches, providing an additional security barrier that can block unauthorized access before it reaches the core ESS control systems, thus enabling safe remote operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If security monitoring is implemented through network switches only, then system simplicity is maintained, but security effectiveness is insufficient against determined attacks

Engineering Contradiction:
Improvesecurity system structureVSAvoidsecurity protection
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The security system is segmented into two distinct domains: network domain (network switches for monitoring and control) and physical domain (physical switches for blocking). This segmentation allows the system to maintain simplicity in the network domain while adding robust physical security measures, achieving enhanced protection without excessive overall complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The dual-domain switch control system is configured in advance to provide security cushioning. The physical switches are pre-positioned to block access to control systems, and the system is programmed with security protocols that automatically activate protective measures before unauthorized access can cause harm. This prior cushioning ensures that even if network security is breached, the physical domain remains protected.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

3Measurement precision

If multi-level monitoring is implemented, then monitoring capability is improved, but system complexity increases

Engineering Contradiction:
Improvemonitoring capabilityVSAvoidmonitoring system structure
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The monitoring system is divided into four hierarchical levels, each with specific monitoring responsibilities. Level 1 (module BMS) monitors individual battery cells, level 2 (pack BMS) monitors battery packs, level 3 (system BMS with PMS) monitors the entire battery system including thermal management, and level 4 (top-level EMS) monitors overall ESS operation. This segmentation allows comprehensive monitoring while distributing complexity across manageable layers.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each monitoring level is designed with multi-functionality to reduce overall system complexity. The BMS units at different levels can perform multiple functions including voltage monitoring, current measurement, temperature sensing, communication management, and control signal generation. This universality allows a single component design to serve multiple purposes across different monitoring levels, reducing the need for specialized components at each level.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250280010A1ESS security management system
Publication Date: 2025.09.04 STANDARD ENERGY INC
  • US20250280010A1 patent drawing
  • US20250280010A1 patent drawing
  • US20250280010A1 patent drawing

AI summary

The present disclosure relates to an ESS security management system comprising: a monitoring means for observing an ESS state; and a security means for blocking or stopping an ESS operation of other domains separate from a network switch with respect to unauthorized access or abnormal state of an ESS and, more specifically, to an ESS security management system for safely managing the system through multi-level network management in order to maintain ESS network security.