ZEKLAREnergy
EN / IT
BACK TO ZEKLAR ENERGY/energy/e-ion-bms
Product· grid

E-ION

Distributed intelligence for storage and battery assets.

E-ION is a distributed battery management system for storage and grid assets: each cell module runs its own State-of-Health model locally and balances the pack chemically, with no omniscient central node. Intelligence lives on the module's low-cost hardware, in hard real time and at a functional-safety grade. From vehicle packs to stationary storage plants, every cell knows itself.

+30% PACK LIFE EXTENSION<3 ms SOH INFERENCE LATENCY48 kB FIRMWARE FOOTPRINT PER CELLADVISORY MODE · READ-ONLY+30% PACK LIFE EXTENSION<3 ms SOH INFERENCE LATENCY48 kB FIRMWARE FOOTPRINT PER CELLADVISORY MODE · READ-ONLY
01In figuresFIELD DATA
+30%
pack life extension
<3 ms
SoH inference latency
48 kB
firmware footprint per cell
02The problem

A centralised BMS sees the battery as a monolith.

Traditional systems aggregate the pack into a single controller and mask per-cell chemical drift until the damage is done: lost capacity, hotspots, accelerated degradation. As scale grows, dozens or hundreds of modules in a storage plant, the central compute bottleneck and single point of failure become untenable. Intelligence needs to sit on the cell, not upstream of it.

03What it does04
01

Per-cell State-of-Health

Each module autonomously estimates its own cell's health and degradation with a physics-empirical model, catching drift before it becomes failure.

02

Predictive chemical balancing

A short-horizon predictive control loop, computed locally every few milliseconds, equalises the pack at the chemical level and extends service life.

03

Intelligence with no central node

A network of agents over a fieldbus: modules negotiate decisions peer-to-peer and a lightweight supervisor aggregates them, without centralising compute or creating a single point of failure.

04

Certifiable functional safety

Rust no_std firmware engineered for IEC 61508, with MC/DC coverage and requirements traceability, ready for the asset's certification pathway.

04How it works04 STEPS
01

Sense

Each module acquires its cell's voltage, current and temperature in real time.

02

Infer

The State-of-Health model runs on the local microcontroller in a few milliseconds.

03

Balance

Each cell computes its own balancing action and negotiates it with neighbouring modules.

04

Aggregate

The supervisor composes the global pack state for oversight and diagnostics.

05Architecture

E-ION distributes intelligence across the pack: every cell module is an autonomous agent that senses, infers and balances locally, and negotiates decisions with its neighbours over a fieldbus. There is no omniscient central node and no single point of failure; a lightweight supervisor merely aggregates the global state.

01Cell sensingEach module acquires its cell's voltage, current and temperature in real time on the low-cost STM32 microcontroller, with integrated signal conditioning.
02State-of-Health inferenceA physics-empirical model runs locally in a few milliseconds and estimates the cell's health and degradation, catching chemical drift before it becomes failure, with a 48 kB firmware footprint per cell.
03Negotiated balancingA short-horizon predictive control loop computes each cell's balancing action and negotiates it peer-to-peer over CANopen, equalising the pack at the chemical level without centralising compute.
04Supervision and diagnosticsA lightweight supervisor aggregates module states for diagnostics and exposes them to SCADA/EMS for stationary storage; it is not in the safety-critical path, so its failure does not stop the pack.
06Specifications
Pack life extension+30%
SoH inference latency<3 ms
Firmware footprint per cell48 kB
Functional safetyIEC 61508
FieldbusCANopen
MicrocontrollerSTM32
Firmware languageRust no_std
Supported chemistriesNMC / LFP
07Deployment

Cloud (twin and analytics)

Cloud hosts the Simulink digital twin and the Python ML pipeline for training and fleet analytics; safety control always stays on the modules, never in cloud. Only aggregated diagnostic data goes up.

On-premise / plant

For stationary storage, the supervisor and SCADA/EMS integration run within the plant perimeter; distributed intelligence is already on the modules and needs no connectivity to operate.

Embedded air-gapped

In vehicle packs or isolated assets the system is inherently air-gapped: every cell knows itself and operates with no network. Firmware updates happen only via a maintenance procedure with signed artifacts.

08Security & compliance

Functional safety

Rust no_std firmware engineered for IEC 61508, with MC/DC coverage and full requirements traceability: the evidence package accompanies the asset along its SIL certification path.

Data sovereignty

Cell data never leaves the pack to operate: the safety decision is local. Only aggregated diagnostics, under the asset owner's control, is exposed to SCADA/EMS or exported to cloud.

Access and audit

Firmware updates and configuration changes are signed, versioned and logged; the supervisor keeps an immutable log of safety events, protection activations and degradation states for post-event analysis.

Encryption and integrity

Supervisor communications and links to SCADA/EMS are encrypted; every firmware image is signed and verified before execution, so a module never runs unauthenticated code.

09Integrations
CANopen and industrial fieldbusesLow-cost STM32 microcontrollersSimulink digital twinNMC, LFP and related chemistriesSCADA / EMS for stationary storagePython ML pipeline for training
10FAQ

What happens if a module fails?

Since there is no omniscient central node, a module failure does not stop the pack: neighbouring modules keep operating and negotiating, and the supervisor flags the degraded module for maintenance. There is no single point of failure.

Why Rust firmware and not C?

Rust no_std eliminates entire classes of memory errors at compile time, a decisive advantage for the IEC 61508 path where safety must be demonstrated. MC/DC coverage and requirements traceability complete the certification package.

Does it work with our cell chemistry?

The State-of-Health model is calibrated for NMC, LFP and related chemistries; the Simulink digital twin allows recalibration to a specific chemistry before deployment.

Is connectivity needed for balancing?

No. Balancing and SoH inference run entirely on the modules over the local CANopen bus; cloud is only for training and fleet analytics. The pack stays fully functional offline.

How does it integrate with our EMS?

The supervisor aggregates pack state and exposes it to SCADA/EMS for stationary storage, providing State-of-Health, alarms and available capacity without exposing the underlying safety compute.

11The markGRID 64 · STROKE 5

The mark encodes the mechanism, not the sector: la sbarra e le derivazioni asimmetriche verso i nodi.

44302216
ProofDeployed in production: read the case study
12Other products · ZEKLAR Energy

ZEKLAR software technology 4.0/5.0

Let's talk
ZEKLAR · SOFTWARE THAT MAKES THE DIFFERENCE.
ZEKLAR · VAT L81419031T · info@zeklar.com© 2026