Skip to content

Energy Storage System Safety Specifications

D-Cube / D-Ocean Full Series (Commercial & Industrial Energy Storage and Large-Scale Energy Storage)

Document Number: HZ-SAF-001 Version: V1.0 Date: 2026-09-29


0. Document Description

0.1 Purpose

This specification describes the safety design principles, key settings, and determination criteria of the Hoenergy energy storage system in five aspects: electrical safety, battery and BMS safety, thermal runaway and fire protection, mechanical environment, and functional safety. It serves as a common basis for technical communication, bidding technical response, solution design, and grid-connection declaration.

This specification is a product safety documentation file; it is neither a regulatory standard nor a substitute for the mandatory regulations of the country where the project is located, the grid company's procedures, or the requirements of the fire protection authority. In case of conflict, the regulations of the project country and the grid-connection permit documents shall prevail.

0.2 Intended Readers and How to Read

Reader Suggested Reading
Customer decision-makers Chapters 1, 2, and 4 → understand the product safety level in 30 minutes
Distributors / Integrators Read the entire document, focusing on Section 2.3 Grid-Connection Protection and Section 4.3 Layout Spacing

0.3 Referenced Documents

Category Standards
Battery and Energy Storage Systems IEC 62619, EN IEC 62933-5-1, EN IEC 62933-5-2, UN 38.3, EU 2023/1542 Battery Regulation
Power Electronics and Grid Connection IEC 62477-1, EN 50549-1 (Type B), IEC 61968 (anti-islanding), IEEE 1547
Low-Voltage Installations IEC 60364 (including Clause 7-722 for energy storage installations), IEC 60664-1 (clearance and creepage distances)
EMC IEC 61000-6-2 (immunity), IEC 61000-6-4 (emission), IEC 61000-6-3/6-1 (residential environments)
Fire Protection and Thermal Runaway UL 9540 / UL 9540A (North America), NFPA 855, IEC 62477-1
Functional Safety IEC 61508, ISO 13849-1, ISO 13849-5
Cybersecurity IEC 62443 series
Noise ISO 3744, 2002/49/EC Environmental Noise Directive

Parameters shall be subject to the latest version of their respective datasheets. Appendix C lists items that must be confirmed by the Product Department prior to external release.


1. General Principles of Safety Design

1.1 Core Principles

  1. Inherent Safety First: Eliminate hazards through structural and component-level design rather than compensating with alarms. Use LFP cells (whose thermal runaway onset temperature is significantly higher than that of NMC systems), a 1P series architecture without parallel circulating currents, and cluster-level independent fault domains.
  2. Multiple Independent Lines of Defense: A single sensor failure, a single communication interruption, or a single software fault must never lead to a hazardous state. Detection, early warning, suppression, and external coordination must be independent of one another.
  3. Fail-safe: The default state on power loss, out-of-control conditions, or disconnection must be safe—the PCS shall shut down rather than continue operating, and contactors shall release rather than close.
  4. No Automatic Recovery: After a fire-extinguishing or suppression action is executed, the system must not restart automatically; it may only be reset after personnel have identified the root cause.
  5. Diagnosable and Traceable: Every protection action shall be recorded as an event with a readable fault code; settings shall be queryable, calibratable, and auditable.

1.2 Four Lines of Defense

Line of Defense Objective Typical Measures Failure Consequence
First Line: Inherent Safety Eliminate hazard origins LFP cells, 1P series architecture, double-layer insulation and reliable grounding Localized degradation, no propagation
Second Line: Detection and Early Warning Early identification of thermal runaway precursors Combustible gas detection (CO/H₂/VOC), cell-level temperature monitoring, smoke detection, audible and visual alarms, cloud push notifications Alarm within 5–60 s
Third Line: Suppression and Extinguishing Prevent propagation Automatic aerosol release at cabinet or Pack level; Pack-level isolation Propagation limited to a single cabinet or single compartment
Fourth Line: External Emergency Response Last layer Fire-protection interlock via dry-contact hardwired output, handed over to the station-level fire protection system (not dependent on the EMS being online) Handled by the project's fire protection design

1.3 Fault Classification and Automatic Response

The system is organized according to a three-level protection architecture. Each level follows a stepped sequence of "limit-exceeded detection → derating → zeroing → disconnection". Specific thresholds are given in Section 3.2 and Appendix A.

Level Definition Automatic System Action Reset Method
L1 Notification Parameter deviation with no risk (high SoC, large cell voltage difference) Reduce power to 50% of rated Automatic after conditions recover
L2 Warning Approaching limits (temperature close to threshold, large voltage difference) Request the corresponding direction power to 0 Automatic after conditions recover (with hysteresis)
L3 Protection Limit exceeded or internal fault (level-3 over-temperature, level-3 over-voltage, sampling anomaly) Output fault dry contact to PCS for shutdown; in extreme cases, DC shunt trip Manual reset; automatic restart is not allowed
L4 Emergency Endangering safety (signs of thermal runaway, gas alarm, fire extinguishing discharge) Automatic fire suppression + shutdown + fire alarm signal output Manual reset after root cause is identified; extinguishing agent must be replaced

Reset Rules (Fundamental Safety Design Convention):

  • Process quantity protections such as temperature, current, and voltage difference belong to the auto-reset category, but all are equipped with hysteresis to avoid repeated switching near the thresholds;
  • Level-3 voltage protection, sampling line anomaly, total voltage anomaly, collective anomaly, fuse fault, leakage current, main switch sticking/open, control board fault, software mismatch belong to latched faults and must be restored after power-off or manual intervention;
  • After fire-extinguishing discharge, the system does not enter any automatic recovery path.

2. Electrical Safety

2.1 Hazardous Voltage Identification

The DC-side nominal voltage of the D-Cube / D-Ocean series is 832 V (D-Cube-261D, S125/261, F135/261) and 1331.2 V (F215/418, D-Ocean-5016D), with an AC-side voltage of 400 V or 690/800 V, all exceeding the safety limits of 60 V DC / 50 V AC and therefore classified as hazardous voltage. As a result:

  • Both the DC side and AC side must be designed as hazardous voltage circuits; the cabinet must be equipped with a locked protective door, and the position of the door lock must be indicated on the drawings;
  • Clearances and creepage distances shall be selected according to the tables in IEC 60664-1. The input end is an indoor cabinet with Overvoltage Category II and Pollution Degree 2; for container scenarios, Pollution Degree 3 shall be applied. The specific values shall be calculated by the structural and safety compliance engineers on a per-model basis according to the overall OVC / CTI parameters, and this specification does not list fixed millimeter values.

2.2 Primary System and Protection Configuration

Item Configuration
Insulation Withstand Voltage ≥ 100 MΩ @ 2500 VDC / 60 s
Protective Earthing The cabinet PE busbar is continuously and reliably connected to the grid PE; grounding resistance < 4 Ω
DC Input Protection AC included (DC circuit breakers/DC breaker/fuses, insulation monitoring)
AC Output Protection AC included (circuit breaker + disconnector)
Surge Protection Type II on the DC side, Type II on the AC side
Insulation Monitoring Online insulation monitoring between the DC bus and ground; alarms and power limitation per logic upon anomaly
DC Component PCS output DC component < 0.5%
Harmonics THDi < 3% @ rated output power, PF adjustable −1 ~ +1

Grounding System: In a TN-S system, PE must be continuous throughout the entire path, and the cabinet PE busbar serves as the collection point for the enclosure. The PE busbar and the grounding electrode (supplementary grounding) are two different concepts. TN-S generally does not mandate supplementary grounding, but its implementation is recommended.

Grid Protection Settings: The PCS is factory-configured with generic protection setpoints. Before grid-connected operation, these setpoints must be reconfigured and confirmed in accordance with the grid connection codes and type-certification documents of the utility in the target country, including but not limited to overvoltage/undervoltage, overfrequency/underfrequency, anti-islanding, and impedance protection. A system that has not been configured in accordance with local codes must not be connected to the grid. Protection setpoints are project-specific configurations and must be recorded and archived.

2.3 Grid-Tie Protection and Decoupling Protection (Key Point)

PCS internal protection and point-of-common-coupling (PCC) decoupling protection are two distinct matters:

  • PCS internal protection (overvoltage, undervoltage, overfrequency, underfrequency, anti-islanding, impedance protection, and the 16 categories of grid fault codes) protects the PCS itself;
  • Decoupling protection protects the grid and on-site personnel, and must be independent of the PCS.

Acceptance by market:

Market Reference Is PCS built-in protection accepted as decoupling protection? Delivery requirement
France NF C 13-100 / NF C 15-100 (Enedis) ❌ No Independent protection relay required (Enedis-approved models, such as Schneider Sepam, ABB REF615)
Spain Regional utility grid code ❌ No Independent relay
Germany VDE-AR-N 4105 ✅ Acceptable Type certification + redundant backup required
Italy CEI 0-21 ✅ Acceptable Same as above; redundancy required
United Kingdom G99 ✅ Acceptable Redundancy required; ENA Type Test Register entry must be completed before grid connection
Poland / Czech Republic / Lithuania / Bulgaria National grid connection codes 【To be confirmed】 Follow local grid connection permit documents; independent relay recommended

Other grid-tie functions: primary frequency regulation, AGC response, scheduled power curve tracking, anti-islanding, active/reactive power limiting, LVRT (if required by the project).

Time reference: dispatch and power control accuracy depend on the time reference. IEC 104 protocol projects must be configured with a reliable clock source, and timestamp consistency must be checked at delivery; the criteria are provided in Appendix A.

2.4 Short Circuit and Overload

  • The DC-side fuse/circuit breaker shall be selected based on the maximum short-circuit current, with a breaking capacity no less than the system's prospective short-circuit current;
  • The rated current of the AC-side circuit breaker shall be calculated as P / (√3 · U · cosφ) and verified against short-circuit withstand capability;
  • The PCS is capable of overload operation at 110% of rated power. Short-term overload shall not be used as a normal operating mode.

3. Battery and BMS Safety

3.1 Cell and System Configuration

Item Parameter
Cell chemistry LFP, with a thermal runaway onset temperature significantly higher than that of the NMC system
Cell specification 3.2 V / 314 Ah (HTHIUM)
Typical configurations D-Cube-261D / S125-261: 260S1P, 832 V; F215-418: 416S1P, 1331.2 V
Topology 1P series, topologically eliminating parallel circulating current and its amplification
Cluster architecture One PCS corresponds to one battery cluster; a fault in a single cluster does not affect other clusters
C-rate ≤ 0.5P
Capacity and cycle life 261 kWh @ 0.5P/0.5P, DoD 95%, cycle life ≥ 6000 cycles
Liquid cooling temperature difference Inter-cell ΔT ≤ 2.5 °C (S/H/F series ≤ 3 °C)

3.2 Protection Windows and Action Chains

The BMS continuously monitors the following quantities. Each quantity follows a three-level stepped action, with hysteresis between levels to prevent repeated toggling:

Monitored Quantity L1 L2 L3 (Shutdown + Fault Dry Contact)
Cell charge overvoltage Reduce power by 50% Charge power request to 0 Shunt trip, manual recovery
Cell discharge undervoltage Power limit Discharge power request to 0 Fault dry contact output, PCS shutdown
Total voltage too high / too low Reduce power Zero out / power limit Shunt trip / fault dry contact
Excessive cell voltage deviation Charge power reduced to 50% Charge power to 0 Fault dry contact output
Charge temperature too high Reduce power by 50% Charge power to 0 Fault dry contact output
Charge temperature too low Reduce power by 50% Charge power to 0 Fault dry contact output
Discharge temperature too low Reduce power by 50% Discharge power to 0 Fault dry contact output
Excessive cell temperature deviation Reduce power by 50% Charge power to 0 Fault dry contact output
Charge / discharge overcurrent Reduce power by 50% Corresponding power to 0 Fault dry contact output
SoC out of range Prohibit corresponding charge / discharge direction — —
Sampling line abnormality Power reduced to 0 — Fault dry contact output, PCS shutdown
Daisy chain / PCS communication interruption Reduce power Power reduced to 0 Fault dry contact output

Sampling Validity Self-Check: The BMS continuously verifies voltage sampling (highest > 4.5 V and lowest < 2 V is judged as abnormal), temperature sampling (outside the −40 to 125 °C range is judged as abnormal), and consistency between the total voltage and the sum of cell voltages (deviation > 10% is judged as abnormal). If any item is abnormal, L3 in the table above is applied—"operating with faults" is not permitted when sampling fails.

Important: Low-Temperature Charging Restriction Charging batteries at low temperature will cause lithium plating, which constitutes irreversible damage. The system imposes an independent low-temperature threshold for charging that is far more stringent than that for discharging (derating begins and charging is prohibited within the approximate range of 0 to 3 °C). The −25 °C lower operating temperature limit of the D-Cube-S125/261-EU applies only to discharging conditions. In any environment below the charging temperature threshold, the system must be in a discharge-limited or charge/discharge-prohibited state, and charging must not be attempted on the grounds that the temperature is "within the operating temperature range".

Protection setpoints vary with cell batch and software version; typical values are provided in Appendix A.1. The "Protection Setpoint Table" delivered with the cabinet is the final authoritative reference and must not be modified by the user or integrator.

3.3 Balancing Strategy and Adjustable Parameters

Method Principle Features
Passive Balancing Cells with high SoC are discharged through resistors to dissipate energy Simple structure, low cost; generates heat, slow speed (hour-level), balancing current < 1 A
Active Balancing Energy is transferred between cells via capacitors/inductors/DC-DC Retains energy, minute-level; current 1–10 A, can increase usable capacity and extend lifetime

The D-Cube platform supports series configurations of 260S / 416S, and the balancing strategy is executed according to product design values. Parameters such as balancing current and protection settings are not open to users or integrators for modification — modification will result in loss of certification compliance and warranty eligibility.

3.4 Battery Compartment Structural Protection

  • Liquid cooling and high-voltage components are physically separated, and the intake and exhaust vents of the battery compartment are equipped with rain-proof and dust-proof covers;
  • Thermal insulation and structural limiters are provided between modules to prevent thermal runaway of individual cells from spreading to adjacent modules;
  • The combustible gas detector inside the compartment is located at the top reflux zone (the path of rising hot gas) to ensure early response.

3.5 Sampling Continuity in Static Low-Power Mode

The system enters low-power operation in a static state (no charging or discharging), reducing auxiliary power and control power consumption. The entry conditions are an average cell voltage below approximately 3.1 V, a detected current below approximately 2 A, sustained for more than 5 minutes; the system automatically exits when the current rises above the threshold.

In low-power mode: passive balancing can be enabled; sampling slaves wake up periodically for data acquisition and communication (wake-up cycle of approximately 30 minutes, single duration of approximately 8 seconds); the sleep status is reported to the master controller.

Safety Note: The low-power mode is only effective in a static state with no charging or discharging. The wake-up acquisition of sampling slaves ensures that protection data is not interrupted. The low-power mode must not be used in operating states, nor does it alter any protection thresholds in Section 3.2. The conditions for enabling balancing in low-power mode are the same as in the regular static state.


4. Thermal Runaway and Fire Protection

4.1 Detection: Three-Level Warning

Level Detector Coverage Target Typical Response
Level 1 (Early) Combustible gas detector (CO / H₂ / VOC) Gas produced from thermal runaway precursors, 30–60 s earlier than temperature rise and smoke Audible and visual alarm + cloud push notification
Level 2 Temperature detection (per-cell temperature + distributed temperature sensors) Abnormal local temperature rise rate Audible and visual alarm + power limiting
Level 3 Smoke detection Visible smoke Triggers fire suppression linkage

Temperature rise rate criterion: Set a threshold on the per-cell temperature change rate (°C/s) to identify anomalies before reaching the absolute temperature threshold, avoiding delays.

4.2 Suppression: Automatic Fire Extinguishing

Model Extinguishing Agent
D-Cube-Series Pack-level aerosol + battery compartment aerosol + water firefighting interface
D-Ocean-Series Pack-level aerosol + compartment aerosol + water firefighting interface

Design Highlights:

  • After the extinguishing agent is released, automatic reset is not performed; the system enters a latched state and must be manually reset after the cause has been identified.
  • The extinguishing agent is a single-use consumable and must be replaced after discharge; the system must not be put back into operation until replacement has been completed.
  • The discharge action opens both the DC breaker of the cabinet and the AC main incoming line; the other cabinets in parallel units stop running synchronously, and the total system power drops to zero, preventing operation with an active fault.
  • The water firefighting interface only provides the signal and piping interface; the actual water spray is executed by the project's fire protection design (most local fire authorities require an external water system).
  • The purpose of suppression is to limit propagation, which is not the same as "extinguishing"; fire handling must still be carried out in accordance with the local fire emergency plan.
  • A perfluorohexanone-type halon-substitute extinguishing agent is used. At normal release quantities, it has no significant toxicity to personnel and no corrosive effect on precision electronic equipment, but the area must be ventilated after release.

4.3 Layout, Spacing and Separation

  • Spacing between cabinets shall be determined in accordance with the fire codes of the country where the project is located and the opinions of the local fire authority. The EU has no unified mandatory spacing requirement; the 1.5 m unit spacing in NFPA 855 applies only to markets that adopt that standard; the UK refers to PAS 63100; in Poland (PSP), the Czech Republic (HOŘ), and France/Spain (SDIS), the spacing shall be subject to the approval of the local fire authority;
  • In sensitive locations such as residential areas, schools and hospitals, increased spacing or additional fire barriers shall be provided;
  • For indoor deployment, the smoke detection interlock must simultaneously shut down the air conditioning and activate emergency exhaust ventilation (supply air will feed combustion and dilute smoke); this interlock logic must be verified by on-site testing during the commissioning phase;
  • Battery cabinets and PCS cabinets should be physically separated to avoid heat concentration.

4.4 Fire Linkage Matrix

The sequence of the detect–alarm–suppress–disconnect stages is as follows. Alarm and suppression are distinct action levels: alarms can self-reset, suppression cannot.

Trigger Source Criterion Cabinet-Level Action Cross-Cabinet / Station-Level Action Signal Output
Combustible gas (H₂/CO/VOC) Exceeds the configured percentage of lower explosive limit Audible-visual alarm, linked to supply/exhaust ventilation system Cloud alarm Gas-detect dry contact
Smoke detector Photoelectric obscuration attenuation out of limit Audible-visual alarm activated Cloud alarm Smoke-detect feedback dry contact
Heat detector Exceeds alarm setpoint Audible-visual alarm, power derated to 0 Cloud alarm Heat-detect feedback dry contact
Pack-internal thermal wire Approximately 185 ± 10 °C Triggers Pack-internal aerosol (independent of cabinet-wide fire extinguishing) Cloud alarm Pack suppression status
Fire-extinguishing discharge loop Smoke/heat detector meets discharge condition Release extinguishing agent, shut down, disconnect DC circuit breaker and AC main incoming line Other cabinets in the paralleled unit shut down synchronously; total system power = 0 Discharge feedback dry contact → station-level fire system
External fire signal Station-level fire system activates Disconnect circuit breaker Whole station shuts down —
Emergency stop (cabinet / station) Hard-wired normally-closed loop opens PCS shuts down immediately, reports emergency-stop fault; main incoming circuit breaker disconnects A single-cabinet emergency stop drives the whole station to total power = 0 Emergency-stop dry contact + audible-visual alarm

Three key conventions of the linkage chain:

  1. Hardware-wired takes precedence over software: The emergency-stop loop and fire feedback reach the PCS and main incoming circuit breaker directly via dry contacts; their action does not depend on EMS or cloud platform availability. The role on the EMS side is to receive feedback, report alarms, and display operating status.
  2. A single-point trigger drives the whole station to zero: If any cabinet triggers an emergency stop or fire-extinguishing discharge, all other cabinets in the same paralleled grid stop operating and total system power becomes 0, preventing any faulty zone from continuing to charge or discharge. Recovery must be performed cabinet by cabinet after manual confirmation.
  3. Discharge is an irreversible action: Once the extinguishing loop is activated, the cabinet enters a latched state; the extinguishing agent must be replaced and the system manually reset — operation must not resume after a simple reset.

The specific thresholds for detection and suppression (smoke dB/m, heat °C, gas %LEL) are product-defined values, determined by the detector model and safety evaluation conclusions. This specification does not list specific numerical values.

5. Mechanical, Environmental, and EMC

5.1 Protection and Structure

Item D-Cube-S125/261 EU D-Cube-261D D-Cube-A Series D-Ocean-5016D
Protection rating IP55 IP55 IP54 IP55
Total weight 2.5 t 2.4 t 0.5–0.7 t 41.5 t
Cable inlet/outlet Bottom in / Bottom out Bottom in / Bottom out Bottom in / Bottom out Bottom in / Bottom out

Tip

Parameters of other models are not listed; for detailed information, please refer to the corresponding product page Click to jump to product page

  • The cabinet door is a locked protective door; the lock position is marked on the product page documentation;
  • Cabinets of 2.5 t and above must be handled by forklift or hoisting, manual carrying is prohibited;
  • Transportation follows the ISTA packaging levels for vibration and drop requirements; the factory SoC of batteries inside the cabinet is 30–40%, and charging/discharging is prohibited during transportation.

5.2 Environmental Adaptability

Item D-Cube Series
Operating Temperature −25 ~ 55 °C (derating above 45 °C)
Humidity 5–95%, non-condensing
Altitude ≤ 3000 m (derating above 2000 m)

Condensation Control: indoor BESS must be equipped with air conditioning featuring reheating dehumidification, with the dew point set according to site conditions (not lower than 5 °C), and the battery inlet air temperature must be kept ≤ 28 °C; otherwise, the system will automatically reduce power output. A short circuit between the hot and cold air paths will prevent the batteries from actually being cooled, so the forced cooling channel must be properly sealed.

High-Dust Environments (such as sawmill workshops): dust-proof protection must be added to the intake and exhaust vents, and the impact of accumulated dust should be assessed in combination with the BMS temperature data.

5.3 EMC

  • Immunity IEC 61000-6-2; Emission IEC 61000-6-4 (industrial) or 6-3/6-1 (residential/commercial);
  • Both the DC side and the AC side are equipped with Type II SPDs, and the SPD status is reported via communication;
  • THDi < 3% @ rated output; DC component < 0.5%.

6. Liquid Cooling System Safety

The liquid cooling system is not an auxiliary system; its failure is equivalent to the battery losing its primary heat dissipation capability.

Item Requirement / Set Value
System pressure 250 kPa
Primary (single-unit) pressure 350 kPa
Pressure drop / leakage criteria Primary pressure drop < 3 kPa; system leakage < 3 kPa
Medium Ethylene glycol aqueous solution; freezing point aligned with the minimum ambient temperature
Leakage detection Standard-equipped; alarm and entry into power-limiting/shutdown logic upon leakage
Electrical isolation The liquid cooling circuit is insulated and isolated from the electrical circuit; the piping has no conductive connection

Low-Temperature Operation: When the ambient temperature is below the freezing point, the startup procedure must first establish circulation and complete pipeline preheating to prevent local freezing that would cause volumetric expansion damage. Relevant protections are built into the system logic and must not be bypassed.


7. Functional Safety and System-Level Security

7.1 3S Closed-Loop Safety Architecture

Layer Responsibilities
BMS Cell-level sensing and the first line of protection: voltage, temperature, current, insulation, SoC/SOH
PCS Executes power commands and provides the second line of protection: overcurrent, anti-islanding, grid abnormalities, off-grid power factor, and load-bearing constraints
EMS Policy-layer safety constraints: power upper limits, SoC window, alarm escalation, external dispatch response
Upper-level monitoring / Cloud platform Observability, event logging, remote diagnostics

Key Principles:

  1. Protection commands travel via dry-contact hard-wired lines: When the BMS triggers protection or detects a fault, it directly notifies the PCS via dry contacts to execute shutdown (disconnecting the DC contactor), without forwarding through the EMS. The EMS's role in this chain is limited to receiving feedback, reporting alarms, and displaying operational status.
  2. The EMS policy dispatch must not override the hardware protection boundaries of the BMS/PCS—no matter how abnormal the upper-level commands are, they must be intercepted at the hardware protection stage.
  3. During cascaded operation, maintain independent protection for each cluster; it is forbidden to use one cluster's controller to protect another cluster.
  4. One PCS corresponds to one battery cluster; a single-cluster fault must not propagate to other clusters; when a cabinet is taken out of service, the system redistributes power according to the actual number of working PCSes, and the total output is correspondingly reduced without over-generation.

7.2 Off-Grid / Microgrid Operational Safety Constraints (R1–R6)

In off-grid operation, the PCS must provide voltage and frequency support, and the load characteristics directly determine safety. During the design phase, loads must be verified item by item according to the following table:

Rule Load Type Maximum Loading Ratio Mandatory Requirement
R1 Pure resistive (electric water heaters, incandescent lamps) ≤ 100% (80% recommended) —
R2 Pure inductive / impact loads (direct-on-line motors, water pumps, line-frequency air conditioners) ≤ 15–20% Prioritize conversion to variable-frequency type
R3 Variable-frequency type (variable-frequency air conditioners, variable-frequency water pumps) ≤ 60%; variable-frequency air conditioner + lighting mixed ≤ 70% —
R4 Tungsten lamps / AC charging stations Treated as inductive loads Must pass through a DyN11 isolation transformer, otherwise the DC component will trigger an insulation alarm
R5 Power factor cosφ ≥ 0.8 Below this value the PCS may derate or trip
R6 Single phase Single-phase rating = PCS / 3 (125 kW PCS single phase ≈ 41.7 kW) Supports 100% unbalanced loading

Multi-Module Load Application: When multiple PCS modules operate in parallel to carry loads, a single load application shall not exceed 40% of the rated capacity, and the remaining loads shall be soft-started in batches with intervals of 5–10 s. Excessive load application will trigger inter-module circulating current protection and cause a trip.

STS Selection Constraint:

STS rated power ≥ Energy storage charging power + Load power consumption

Failure to meet this requirement under any operating condition will result in overload tripping.

7.3 Functional Safety Integrity

The protection chain (detection → decision → actuation) is evaluated for PL following the ISO 13849-1 approach. Target PL levels for the core safety functions:

Safety Function Target PL
Emergency stop (station-level + cabinet-level) PL d
DC/AC-side protective disconnection PL d
Fire suppression system activation PL d
Insulation monitoring and interlock PL c
Power derating / shutdown on temperature anomaly PL c

Specific PL declarations and verifications (FMEDA, hardware redundancy, diagnostic coverage) are provided by the Product Department; see Appendix C. Do not commit to a specific PL level on behalf of the customer in tender documents until written confirmation is obtained from the Product Department.

7.4 Network Security

  • The product complies with the relevant requirements of the IEC 62443 series. The Security Level (SL) targets are specified in Annex C.
  • The control system must not use the factory default passwords; default passwords must be mandatorily changed upon delivery.
  • Maintenance interfaces such as debug ports, USB ports, and SD card slots must be disabled or controlled after delivery.
  • Remote operation and maintenance must be performed via VPN. Device management ports must not be directly exposed to the public network.

Appendix B Glossary

Chinese English Description
State of Charge SoC Percentage of remaining capacity
State of Health SoH Ratio of current capacity to its initial value
Depth of Discharge DoD Ratio of discharged capacity to rated capacity
Thermal Runaway Thermal Runaway Uncontrollable chain reaction of self-heating inside a battery
Anti-islanding Anti-islanding Prevention of continued power export once the point of common coupling is disconnected
Coupling Protection Coupling Protection Protective relay independent of the grid-tied equipment
Type B Type B Full-function grid-tied unit defined in EN 50549
Cluster Cluster A battery assembly managed by a single PCS
Fire Alarm Interlock Fire Alarm Interlock Output of control signals to the station-level fire protection system
Aerosol Extinguishing Aerosol Extinguishing Halocarbon clean-gas-based suppression method