D-Cube / D-Ocean Full Series (Commercial & Industrial Energy Storage and Large-Scale Energy Storage)
Document Number: HZ-SAF-001 Version: V1.0 Date: 2026-09-29
0. Document Description
0.1 Purpose
This specification describes the safety design principles, key settings, and determination criteria of the Hoenergy energy storage system in five aspects: electrical safety, battery and BMS safety, thermal runaway and fire protection, mechanical environment, and functional safety. It serves as a common basis for technical communication, bidding technical response, solution design, and grid-connection declaration.
This specification is a product safety documentation file; it is neither a regulatory standard nor a substitute for the mandatory regulations of the country where the project is located, the grid company's procedures, or the requirements of the fire protection authority. In case of conflict, the regulations of the project country and the grid-connection permit documents shall prevail.
0.2 Intended Readers and How to Read
| Reader | Suggested Reading |
|---|---|
| Customer decision-makers | Chapters 1, 2, and 4 → understand the product safety level in 30 minutes |
| Distributors / Integrators | Read the entire document, focusing on Section 2.3 Grid-Connection Protection and Section 4.3 Layout Spacing |
0.3 Referenced Documents
| Category | Standards |
|---|---|
| Battery and Energy Storage Systems | IEC 62619, EN IEC 62933-5-1, EN IEC 62933-5-2, UN 38.3, EU 2023/1542 Battery Regulation |
| Power Electronics and Grid Connection | IEC 62477-1, EN 50549-1 (Type B), IEC 61968 (anti-islanding), IEEE 1547 |
| Low-Voltage Installations | IEC 60364 (including Clause 7-722 for energy storage installations), IEC 60664-1 (clearance and creepage distances) |
| EMC | IEC 61000-6-2 (immunity), IEC 61000-6-4 (emission), IEC 61000-6-3/6-1 (residential environments) |
| Fire Protection and Thermal Runaway | UL 9540 / UL 9540A (North America), NFPA 855, IEC 62477-1 |
| Functional Safety | IEC 61508, ISO 13849-1, ISO 13849-5 |
| Cybersecurity | IEC 62443 series |
| Noise | ISO 3744, 2002/49/EC Environmental Noise Directive |
Parameters shall be subject to the latest version of their respective datasheets. Appendix C lists items that must be confirmed by the Product Department prior to external release.
1. General Principles of Safety Design
1.1 Core Principles
- Inherent Safety First: Eliminate hazards through structural and component-level design rather than compensating with alarms. Use LFP cells (whose thermal runaway onset temperature is significantly higher than that of NMC systems), a 1P series architecture without parallel circulating currents, and cluster-level independent fault domains.
- Multiple Independent Lines of Defense: A single sensor failure, a single communication interruption, or a single software fault must never lead to a hazardous state. Detection, early warning, suppression, and external coordination must be independent of one another.
- Fail-safe: The default state on power loss, out-of-control conditions, or disconnection must be safe—the PCS shall shut down rather than continue operating, and contactors shall release rather than close.
- No Automatic Recovery: After a fire-extinguishing or suppression action is executed, the system must not restart automatically; it may only be reset after personnel have identified the root cause.
- Diagnosable and Traceable: Every protection action shall be recorded as an event with a readable fault code; settings shall be queryable, calibratable, and auditable.
1.2 Four Lines of Defense
| Line of Defense | Objective | Typical Measures | Failure Consequence |
|---|---|---|---|
| First Line: Inherent Safety | Eliminate hazard origins | LFP cells, 1P series architecture, double-layer insulation and reliable grounding | Localized degradation, no propagation |
| Second Line: Detection and Early Warning | Early identification of thermal runaway precursors | Combustible gas detection (CO/H₂/VOC), cell-level temperature monitoring, smoke detection, audible and visual alarms, cloud push notifications | Alarm within 5–60 s |
| Third Line: Suppression and Extinguishing | Prevent propagation | Automatic aerosol release at cabinet or Pack level; Pack-level isolation | Propagation limited to a single cabinet or single compartment |
| Fourth Line: External Emergency Response | Last layer | Fire-protection interlock via dry-contact hardwired output, handed over to the station-level fire protection system (not dependent on the EMS being online) | Handled by the project's fire protection design |
1.3 Fault Classification and Automatic Response
The system is organized according to a three-level protection architecture. Each level follows a stepped sequence of "limit-exceeded detection → derating → zeroing → disconnection". Specific thresholds are given in Section 3.2 and Appendix A.
| Level | Definition | Automatic System Action | Reset Method |
|---|---|---|---|
| L1 Notification | Parameter deviation with no risk (high SoC, large cell voltage difference) | Reduce power to 50% of rated | Automatic after conditions recover |
| L2 Warning | Approaching limits (temperature close to threshold, large voltage difference) | Request the corresponding direction power to 0 | Automatic after conditions recover (with hysteresis) |
| L3 Protection | Limit exceeded or internal fault (level-3 over-temperature, level-3 over-voltage, sampling anomaly) | Output fault dry contact to PCS for shutdown; in extreme cases, DC shunt trip | Manual reset; automatic restart is not allowed |
| L4 Emergency | Endangering safety (signs of thermal runaway, gas alarm, fire extinguishing discharge) | Automatic fire suppression + shutdown + fire alarm signal output | Manual reset after root cause is identified; extinguishing agent must be replaced |
Reset Rules (Fundamental Safety Design Convention):
- Process quantity protections such as temperature, current, and voltage difference belong to the auto-reset category, but all are equipped with hysteresis to avoid repeated switching near the thresholds;
- Level-3 voltage protection, sampling line anomaly, total voltage anomaly, collective anomaly, fuse fault, leakage current, main switch sticking/open, control board fault, software mismatch belong to latched faults and must be restored after power-off or manual intervention;
- After fire-extinguishing discharge, the system does not enter any automatic recovery path.
2. Electrical Safety
2.1 Hazardous Voltage Identification
The DC-side nominal voltage of the D-Cube / D-Ocean series is 832 V (D-Cube-261D, S125/261, F135/261) and 1331.2 V (F215/418, D-Ocean-5016D), with an AC-side voltage of 400 V or 690/800 V, all exceeding the safety limits of 60 V DC / 50 V AC and therefore classified as hazardous voltage. As a result:
- Both the DC side and AC side must be designed as hazardous voltage circuits; the cabinet must be equipped with a locked protective door, and the position of the door lock must be indicated on the drawings;
- Clearances and creepage distances shall be selected according to the tables in IEC 60664-1. The input end is an indoor cabinet with Overvoltage Category II and Pollution Degree 2; for container scenarios, Pollution Degree 3 shall be applied. The specific values shall be calculated by the structural and safety compliance engineers on a per-model basis according to the overall OVC / CTI parameters, and this specification does not list fixed millimeter values.
2.2 Primary System and Protection Configuration
| Item | Configuration |
|---|---|
| Insulation Withstand Voltage | ≥ 100 MΩ @ 2500 VDC / 60 s |
| Protective Earthing | The cabinet PE busbar is continuously and reliably connected to the grid PE; grounding resistance < 4 Ω |
| DC Input Protection | AC included (DC circuit breakers/DC breaker/fuses, insulation monitoring) |
| AC Output Protection | AC included (circuit breaker + disconnector) |
| Surge Protection | Type II on the DC side, Type II on the AC side |
| Insulation Monitoring | Online insulation monitoring between the DC bus and ground; alarms and power limitation per logic upon anomaly |
| DC Component | PCS output DC component < 0.5% |
| Harmonics | THDi < 3% @ rated output power, PF adjustable −1 ~ +1 |
Grounding System: In a TN-S system, PE must be continuous throughout the entire path, and the cabinet PE busbar serves as the collection point for the enclosure. The PE busbar and the grounding electrode (supplementary grounding) are two different concepts. TN-S generally does not mandate supplementary grounding, but its implementation is recommended.
Grid Protection Settings: The PCS is factory-configured with generic protection setpoints. Before grid-connected operation, these setpoints must be reconfigured and confirmed in accordance with the grid connection codes and type-certification documents of the utility in the target country, including but not limited to overvoltage/undervoltage, overfrequency/underfrequency, anti-islanding, and impedance protection. A system that has not been configured in accordance with local codes must not be connected to the grid. Protection setpoints are project-specific configurations and must be recorded and archived.
2.3 Grid-Tie Protection and Decoupling Protection (Key Point)
PCS internal protection and point-of-common-coupling (PCC) decoupling protection are two distinct matters:
- PCS internal protection (overvoltage, undervoltage, overfrequency, underfrequency, anti-islanding, impedance protection, and the 16 categories of grid fault codes) protects the PCS itself;
- Decoupling protection protects the grid and on-site personnel, and must be independent of the PCS.
Acceptance by market:
| Market | Reference | Is PCS built-in protection accepted as decoupling protection? | Delivery requirement |
|---|---|---|---|
| France | NF C 13-100 / NF C 15-100 (Enedis) | ❌ No | Independent protection relay required (Enedis-approved models, such as Schneider Sepam, ABB REF615) |
| Spain | Regional utility grid code | ❌ No | Independent relay |
| Germany | VDE-AR-N 4105 | ✅ Acceptable | Type certification + redundant backup required |
| Italy | CEI 0-21 | ✅ Acceptable | Same as above; redundancy required |
| United Kingdom | G99 | ✅ Acceptable | Redundancy required; ENA Type Test Register entry must be completed before grid connection |
| Poland / Czech Republic / Lithuania / Bulgaria | National grid connection codes | 【To be confirmed】 | Follow local grid connection permit documents; independent relay recommended |
Other grid-tie functions: primary frequency regulation, AGC response, scheduled power curve tracking, anti-islanding, active/reactive power limiting, LVRT (if required by the project).
Time reference: dispatch and power control accuracy depend on the time reference. IEC 104 protocol projects must be configured with a reliable clock source, and timestamp consistency must be checked at delivery; the criteria are provided in Appendix A.
2.4 Short Circuit and Overload
- The DC-side fuse/circuit breaker shall be selected based on the maximum short-circuit current, with a breaking capacity no less than the system's prospective short-circuit current;
- The rated current of the AC-side circuit breaker shall be calculated as P / (√3 · U · cosφ) and verified against short-circuit withstand capability;
- The PCS is capable of overload operation at 110% of rated power. Short-term overload shall not be used as a normal operating mode.
3. Battery and BMS Safety
3.1 Cell and System Configuration
| Item | Parameter |
|---|---|
| Cell chemistry | LFP, with a thermal runaway onset temperature significantly higher than that of the NMC system |
| Cell specification | 3.2 V / 314 Ah (HTHIUM) |
| Typical configurations | D-Cube-261D / S125-261: 260S1P, 832 V; F215-418: 416S1P, 1331.2 V |
| Topology | 1P series, topologically eliminating parallel circulating current and its amplification |
| Cluster architecture | One PCS corresponds to one battery cluster; a fault in a single cluster does not affect other clusters |
| C-rate | ≤ 0.5P |
| Capacity and cycle life | 261 kWh @ 0.5P/0.5P, DoD 95%, cycle life ≥ 6000 cycles |
| Liquid cooling temperature difference | Inter-cell ΔT ≤ 2.5 °C (S/H/F series ≤ 3 °C) |
3.2 Protection Windows and Action Chains
The BMS continuously monitors the following quantities. Each quantity follows a three-level stepped action, with hysteresis between levels to prevent repeated toggling:
| Monitored Quantity | L1 | L2 | L3 (Shutdown + Fault Dry Contact) |
|---|---|---|---|
| Cell charge overvoltage | Reduce power by 50% | Charge power request to 0 | Shunt trip, manual recovery |
| Cell discharge undervoltage | Power limit | Discharge power request to 0 | Fault dry contact output, PCS shutdown |
| Total voltage too high / too low | Reduce power | Zero out / power limit | Shunt trip / fault dry contact |
| Excessive cell voltage deviation | Charge power reduced to 50% | Charge power to 0 | Fault dry contact output |
| Charge temperature too high | Reduce power by 50% | Charge power to 0 | Fault dry contact output |
| Charge temperature too low | Reduce power by 50% | Charge power to 0 | Fault dry contact output |
| Discharge temperature too low | Reduce power by 50% | Discharge power to 0 | Fault dry contact output |
| Excessive cell temperature deviation | Reduce power by 50% | Charge power to 0 | Fault dry contact output |
| Charge / discharge overcurrent | Reduce power by 50% | Corresponding power to 0 | Fault dry contact output |
| SoC out of range | Prohibit corresponding charge / discharge direction | — | — |
| Sampling line abnormality | Power reduced to 0 | — | Fault dry contact output, PCS shutdown |
| Daisy chain / PCS communication interruption | Reduce power | Power reduced to 0 | Fault dry contact output |
Sampling Validity Self-Check: The BMS continuously verifies voltage sampling (highest > 4.5 V and lowest < 2 V is judged as abnormal), temperature sampling (outside the −40 to 125 °C range is judged as abnormal), and consistency between the total voltage and the sum of cell voltages (deviation > 10% is judged as abnormal). If any item is abnormal, L3 in the table above is applied—"operating with faults" is not permitted when sampling fails.
Important: Low-Temperature Charging Restriction Charging batteries at low temperature will cause lithium plating, which constitutes irreversible damage. The system imposes an independent low-temperature threshold for charging that is far more stringent than that for discharging (derating begins and charging is prohibited within the approximate range of 0 to 3 °C). The −25 °C lower operating temperature limit of the D-Cube-S125/261-EU applies only to discharging conditions. In any environment below the charging temperature threshold, the system must be in a discharge-limited or charge/discharge-prohibited state, and charging must not be attempted on the grounds that the temperature is "within the operating temperature range".
Protection setpoints vary with cell batch and software version; typical values are provided in Appendix A.1. The "Protection Setpoint Table" delivered with the cabinet is the final authoritative reference and must not be modified by the user or integrator.
3.3 Balancing Strategy and Adjustable Parameters
| Method | Principle | Features |
|---|---|---|
| Passive Balancing | Cells with high SoC are discharged through resistors to dissipate energy | Simple structure, low cost; generates heat, slow speed (hour-level), balancing current < 1 A |
| Active Balancing | Energy is transferred between cells via capacitors/inductors/DC-DC | Retains energy, minute-level; current 1–10 A, can increase usable capacity and extend lifetime |
The D-Cube platform supports series configurations of 260S / 416S, and the balancing strategy is executed according to product design values. Parameters such as balancing current and protection settings are not open to users or integrators for modification — modification will result in loss of certification compliance and warranty eligibility.
3.4 Battery Compartment Structural Protection
- Liquid cooling and high-voltage components are physically separated, and the intake and exhaust vents of the battery compartment are equipped with rain-proof and dust-proof covers;
- Thermal insulation and structural limiters are provided between modules to prevent thermal runaway of individual cells from spreading to adjacent modules;
- The combustible gas detector inside the compartment is located at the top reflux zone (the path of rising hot gas) to ensure early response.
3.5 Sampling Continuity in Static Low-Power Mode
The system enters low-power operation in a static state (no charging or discharging), reducing auxiliary power and control power consumption. The entry conditions are an average cell voltage below approximately 3.1 V, a detected current below approximately 2 A, sustained for more than 5 minutes; the system automatically exits when the current rises above the threshold.
In low-power mode: passive balancing can be enabled; sampling slaves wake up periodically for data acquisition and communication (wake-up cycle of approximately 30 minutes, single duration of approximately 8 seconds); the sleep status is reported to the master controller.
Safety Note: The low-power mode is only effective in a static state with no charging or discharging. The wake-up acquisition of sampling slaves ensures that protection data is not interrupted. The low-power mode must not be used in operating states, nor does it alter any protection thresholds in Section 3.2. The conditions for enabling balancing in low-power mode are the same as in the regular static state.
4. Thermal Runaway and Fire Protection
4.1 Detection: Three-Level Warning
| Level | Detector | Coverage Target | Typical Response |
|---|---|---|---|
| Level 1 (Early) | Combustible gas detector (CO / H₂ / VOC) | Gas produced from thermal runaway precursors, 30–60 s earlier than temperature rise and smoke | Audible and visual alarm + cloud push notification |
| Level 2 | Temperature detection (per-cell temperature + distributed temperature sensors) | Abnormal local temperature rise rate | Audible and visual alarm + power limiting |
| Level 3 | Smoke detection | Visible smoke | Triggers fire suppression linkage |
Temperature rise rate criterion: Set a threshold on the per-cell temperature change rate (°C/s) to identify anomalies before reaching the absolute temperature threshold, avoiding delays.
4.2 Suppression: Automatic Fire Extinguishing
| Model | Extinguishing Agent |
|---|---|
| D-Cube-Series | Pack-level aerosol + battery compartment aerosol + water firefighting interface |
| D-Ocean-Series | Pack-level aerosol + compartment aerosol + water firefighting interface |
Design Highlights:
- After the extinguishing agent is released, automatic reset is not performed; the system enters a latched state and must be manually reset after the cause has been identified.
- The extinguishing agent is a single-use consumable and must be replaced after discharge; the system must not be put back into operation until replacement has been completed.
- The discharge action opens both the DC breaker of the cabinet and the AC main incoming line; the other cabinets in parallel units stop running synchronously, and the total system power drops to zero, preventing operation with an active fault.
- The water firefighting interface only provides the signal and piping interface; the actual water spray is executed by the project's fire protection design (most local fire authorities require an external water system).
- The purpose of suppression is to limit propagation, which is not the same as "extinguishing"; fire handling must still be carried out in accordance with the local fire emergency plan.
- A perfluorohexanone-type halon-substitute extinguishing agent is used. At normal release quantities, it has no significant toxicity to personnel and no corrosive effect on precision electronic equipment, but the area must be ventilated after release.
4.3 Layout, Spacing and Separation
- Spacing between cabinets shall be determined in accordance with the fire codes of the country where the project is located and the opinions of the local fire authority. The EU has no unified mandatory spacing requirement; the 1.5 m unit spacing in NFPA 855 applies only to markets that adopt that standard; the UK refers to PAS 63100; in Poland (PSP), the Czech Republic (HOŘ), and France/Spain (SDIS), the spacing shall be subject to the approval of the local fire authority;
- In sensitive locations such as residential areas, schools and hospitals, increased spacing or additional fire barriers shall be provided;
- For indoor deployment, the smoke detection interlock must simultaneously shut down the air conditioning and activate emergency exhaust ventilation (supply air will feed combustion and dilute smoke); this interlock logic must be verified by on-site testing during the commissioning phase;
- Battery cabinets and PCS cabinets should be physically separated to avoid heat concentration.
4.4 Fire Linkage Matrix
The sequence of the detect–alarm–suppress–disconnect stages is as follows. Alarm and suppression are distinct action levels: alarms can self-reset, suppression cannot.
| Trigger Source | Criterion | Cabinet-Level Action | Cross-Cabinet / Station-Level Action | Signal Output |
|---|---|---|---|---|
| Combustible gas (H₂/CO/VOC) | Exceeds the configured percentage of lower explosive limit | Audible-visual alarm, linked to supply/exhaust ventilation system | Cloud alarm | Gas-detect dry contact |
| Smoke detector | Photoelectric obscuration attenuation out of limit | Audible-visual alarm activated | Cloud alarm | Smoke-detect feedback dry contact |
| Heat detector | Exceeds alarm setpoint | Audible-visual alarm, power derated to 0 | Cloud alarm | Heat-detect feedback dry contact |
| Pack-internal thermal wire | Approximately 185 ± 10 °C | Triggers Pack-internal aerosol (independent of cabinet-wide fire extinguishing) | Cloud alarm | Pack suppression status |
| Fire-extinguishing discharge loop | Smoke/heat detector meets discharge condition | Release extinguishing agent, shut down, disconnect DC circuit breaker and AC main incoming line | Other cabinets in the paralleled unit shut down synchronously; total system power = 0 | Discharge feedback dry contact → station-level fire system |
| External fire signal | Station-level fire system activates | Disconnect circuit breaker | Whole station shuts down | — |
| Emergency stop (cabinet / station) | Hard-wired normally-closed loop opens | PCS shuts down immediately, reports emergency-stop fault; main incoming circuit breaker disconnects | A single-cabinet emergency stop drives the whole station to total power = 0 | Emergency-stop dry contact + audible-visual alarm |
Three key conventions of the linkage chain:
- Hardware-wired takes precedence over software: The emergency-stop loop and fire feedback reach the PCS and main incoming circuit breaker directly via dry contacts; their action does not depend on EMS or cloud platform availability. The role on the EMS side is to receive feedback, report alarms, and display operating status.
- A single-point trigger drives the whole station to zero: If any cabinet triggers an emergency stop or fire-extinguishing discharge, all other cabinets in the same paralleled grid stop operating and total system power becomes 0, preventing any faulty zone from continuing to charge or discharge. Recovery must be performed cabinet by cabinet after manual confirmation.
- Discharge is an irreversible action: Once the extinguishing loop is activated, the cabinet enters a latched state; the extinguishing agent must be replaced and the system manually reset — operation must not resume after a simple reset.
The specific thresholds for detection and suppression (smoke dB/m, heat °C, gas %LEL) are product-defined values, determined by the detector model and safety evaluation conclusions. This specification does not list specific numerical values.
5. Mechanical, Environmental, and EMC
5.1 Protection and Structure
| Item | D-Cube-S125/261 EU | D-Cube-261D | D-Cube-A Series | D-Ocean-5016D |
|---|---|---|---|---|
| Protection rating | IP55 | IP55 | IP54 | IP55 |
| Total weight | 2.5 t | 2.4 t | 0.5–0.7 t | 41.5 t |
| Cable inlet/outlet | Bottom in / Bottom out | Bottom in / Bottom out | Bottom in / Bottom out | Bottom in / Bottom out |
Tip
Parameters of other models are not listed; for detailed information, please refer to the corresponding product page Click to jump to product page
- The cabinet door is a locked protective door; the lock position is marked on the product page documentation;
- Cabinets of 2.5 t and above must be handled by forklift or hoisting, manual carrying is prohibited;
- Transportation follows the ISTA packaging levels for vibration and drop requirements; the factory SoC of batteries inside the cabinet is 30–40%, and charging/discharging is prohibited during transportation.
5.2 Environmental Adaptability
| Item | D-Cube Series |
|---|---|
| Operating Temperature | −25 ~ 55 °C (derating above 45 °C) |
| Humidity | 5–95%, non-condensing |
| Altitude | ≤ 3000 m (derating above 2000 m) |
Condensation Control: indoor BESS must be equipped with air conditioning featuring reheating dehumidification, with the dew point set according to site conditions (not lower than 5 °C), and the battery inlet air temperature must be kept ≤ 28 °C; otherwise, the system will automatically reduce power output. A short circuit between the hot and cold air paths will prevent the batteries from actually being cooled, so the forced cooling channel must be properly sealed.
High-Dust Environments (such as sawmill workshops): dust-proof protection must be added to the intake and exhaust vents, and the impact of accumulated dust should be assessed in combination with the BMS temperature data.
5.3 EMC
- Immunity IEC 61000-6-2; Emission IEC 61000-6-4 (industrial) or 6-3/6-1 (residential/commercial);
- Both the DC side and the AC side are equipped with Type II SPDs, and the SPD status is reported via communication;
- THDi < 3% @ rated output; DC component < 0.5%.
6. Liquid Cooling System Safety
The liquid cooling system is not an auxiliary system; its failure is equivalent to the battery losing its primary heat dissipation capability.
| Item | Requirement / Set Value |
|---|---|
| System pressure | 250 kPa |
| Primary (single-unit) pressure | 350 kPa |
| Pressure drop / leakage criteria | Primary pressure drop < 3 kPa; system leakage < 3 kPa |
| Medium | Ethylene glycol aqueous solution; freezing point aligned with the minimum ambient temperature |
| Leakage detection | Standard-equipped; alarm and entry into power-limiting/shutdown logic upon leakage |
| Electrical isolation | The liquid cooling circuit is insulated and isolated from the electrical circuit; the piping has no conductive connection |
Low-Temperature Operation: When the ambient temperature is below the freezing point, the startup procedure must first establish circulation and complete pipeline preheating to prevent local freezing that would cause volumetric expansion damage. Relevant protections are built into the system logic and must not be bypassed.
7. Functional Safety and System-Level Security
7.1 3S Closed-Loop Safety Architecture
| Layer | Responsibilities |
|---|---|
| BMS | Cell-level sensing and the first line of protection: voltage, temperature, current, insulation, SoC/SOH |
| PCS | Executes power commands and provides the second line of protection: overcurrent, anti-islanding, grid abnormalities, off-grid power factor, and load-bearing constraints |
| EMS | Policy-layer safety constraints: power upper limits, SoC window, alarm escalation, external dispatch response |
| Upper-level monitoring / Cloud platform | Observability, event logging, remote diagnostics |
Key Principles:
- Protection commands travel via dry-contact hard-wired lines: When the BMS triggers protection or detects a fault, it directly notifies the PCS via dry contacts to execute shutdown (disconnecting the DC contactor), without forwarding through the EMS. The EMS's role in this chain is limited to receiving feedback, reporting alarms, and displaying operational status.
- The EMS policy dispatch must not override the hardware protection boundaries of the BMS/PCS—no matter how abnormal the upper-level commands are, they must be intercepted at the hardware protection stage.
- During cascaded operation, maintain independent protection for each cluster; it is forbidden to use one cluster's controller to protect another cluster.
- One PCS corresponds to one battery cluster; a single-cluster fault must not propagate to other clusters; when a cabinet is taken out of service, the system redistributes power according to the actual number of working PCSes, and the total output is correspondingly reduced without over-generation.
7.2 Off-Grid / Microgrid Operational Safety Constraints (R1–R6)
In off-grid operation, the PCS must provide voltage and frequency support, and the load characteristics directly determine safety. During the design phase, loads must be verified item by item according to the following table:
| Rule | Load Type | Maximum Loading Ratio | Mandatory Requirement |
|---|---|---|---|
| R1 | Pure resistive (electric water heaters, incandescent lamps) | ≤ 100% (80% recommended) | — |
| R2 | Pure inductive / impact loads (direct-on-line motors, water pumps, line-frequency air conditioners) | ≤ 15–20% | Prioritize conversion to variable-frequency type |
| R3 | Variable-frequency type (variable-frequency air conditioners, variable-frequency water pumps) | ≤ 60%; variable-frequency air conditioner + lighting mixed ≤ 70% | — |
| R4 | Tungsten lamps / AC charging stations | Treated as inductive loads | Must pass through a DyN11 isolation transformer, otherwise the DC component will trigger an insulation alarm |
| R5 | Power factor | cosφ ≥ 0.8 | Below this value the PCS may derate or trip |
| R6 | Single phase | Single-phase rating = PCS / 3 (125 kW PCS single phase ≈ 41.7 kW) | Supports 100% unbalanced loading |
Multi-Module Load Application: When multiple PCS modules operate in parallel to carry loads, a single load application shall not exceed 40% of the rated capacity, and the remaining loads shall be soft-started in batches with intervals of 5–10 s. Excessive load application will trigger inter-module circulating current protection and cause a trip.
STS Selection Constraint:
STS rated power ≥ Energy storage charging power + Load power consumption
Failure to meet this requirement under any operating condition will result in overload tripping.
7.3 Functional Safety Integrity
The protection chain (detection → decision → actuation) is evaluated for PL following the ISO 13849-1 approach. Target PL levels for the core safety functions:
| Safety Function | Target PL |
|---|---|
| Emergency stop (station-level + cabinet-level) | PL d |
| DC/AC-side protective disconnection | PL d |
| Fire suppression system activation | PL d |
| Insulation monitoring and interlock | PL c |
| Power derating / shutdown on temperature anomaly | PL c |
Specific PL declarations and verifications (FMEDA, hardware redundancy, diagnostic coverage) are provided by the Product Department; see Appendix C. Do not commit to a specific PL level on behalf of the customer in tender documents until written confirmation is obtained from the Product Department.
7.4 Network Security
- The product complies with the relevant requirements of the IEC 62443 series. The Security Level (SL) targets are specified in Annex C.
- The control system must not use the factory default passwords; default passwords must be mandatorily changed upon delivery.
- Maintenance interfaces such as debug ports, USB ports, and SD card slots must be disabled or controlled after delivery.
- Remote operation and maintenance must be performed via VPN. Device management ports must not be directly exposed to the public network.
Appendix B Glossary
| Chinese | English | Description |
|---|---|---|
| State of Charge | SoC | Percentage of remaining capacity |
| State of Health | SoH | Ratio of current capacity to its initial value |
| Depth of Discharge | DoD | Ratio of discharged capacity to rated capacity |
| Thermal Runaway | Thermal Runaway | Uncontrollable chain reaction of self-heating inside a battery |
| Anti-islanding | Anti-islanding | Prevention of continued power export once the point of common coupling is disconnected |
| Coupling Protection | Coupling Protection | Protective relay independent of the grid-tied equipment |
| Type B | Type B | Full-function grid-tied unit defined in EN 50549 |
| Cluster | Cluster | A battery assembly managed by a single PCS |
| Fire Alarm Interlock | Fire Alarm Interlock | Output of control signals to the station-level fire protection system |
| Aerosol Extinguishing | Aerosol Extinguishing | Halocarbon clean-gas-based suppression method |