Article contents0%
- Start with a time-and-energy contract
- Do not ask one energy store to solve every interval
- Treat handoff as a voltage waveform, not a Boolean event
- Derate power and energy separately
- Keep conversion, battery safety and supervision independent
- Use the ADI design as bounded implementation evidence
- Validate the worst transition, not the nominal one
- Release the BBU as hardware, firmware and stored energy
- Conclusion
- Official references
Start with a time-and-energy contract #
An AI rack battery backup unit is not a large hold-up capacitor and it is not a facility UPS in miniature. It is a parallel energy source that must detect loss of the normal DC source, take control of the rack bus before IT gear crosses its undervoltage limit, sustain the agreed workload long enough for recovery or drain, and return to standby without fighting the rectifiers.
This guide is for rack-power, BBU/BMS and validation engineers plus BOM owners freezing that contract. The first design decision is not cell chemistry or converter topology. It is the power-versus-time envelope: what must bridge the first microseconds, what the BBU must deliver during the first milliseconds, and how much energy remains available at the lowest permitted state of charge, end-of-life capacity and hottest qualified condition.
The OCP Open Rack V3 BBU specifications provide a useful public 48V baseline: six 3kW modules in a shelf, 15kW at the documented backup condition, and a 240-second ride-through target. That boundary is not a universal AI-rack requirement. A 54V or 800V architecture, a different workload-drain policy or a different redundancy objective needs its own acceptance waveform and battery qualification. Vendor Reference Design
Do not ask one energy store to solve every interval #
Different events need different owners. Local DC-link and converter capacitance carries switching-cycle and control-loop gaps. The BBU converter must cover detection and source-transfer delay. Battery energy carries the minutes-scale service window. An upstream UPS, generator or workload migration plan decides what happens after that window.
These intervals cannot be collapsed into one “backup time” number:
| Interval | Primary owner | Release question |
|---|---|---|
| Switching cycles to control response | Converter and local capacitance | Does the load remain above UVLO while the source and BBU controls are still deciding? |
| Detection and BBU ramp | Bus capacitance plus BBU power stage | At worst load and source impedance, does the bus stay above the declared floor until BBU current arrives? |
| Sustained ride-through | Battery pack, BMS, bidirectional converter and cooling | Is the required power available at minimum SOC, EOL capacity and hot/cold cell limits? |
| Recovery or orderly drain | Facility source, rack manager and workload policy | What restores power or reduces load before the BBU reserve limit is reached? |
For capacitor-only hold-up, the usable energy between the normal bus and the load's undervoltage limit is \(\tfrac{1}{2}C(V_{start}^2-V_{min}^2)\). The available interval is that energy multiplied by conversion efficiency and divided by load power. This quickly exposes why capacitors are suited to a short bridge, not a four-minute rack obligation.
For the battery interval, start with delivered energy, not nameplate amp-hours. A 15kW load for 240 seconds is 3.6MJ, or 1kWh, delivered to the bus before converter and auxiliary losses. Then apply the program's redundancy, SOC, capacity-retention, temperature, cell-imbalance and converter-derating margins. If six modules are installed but the service claim is 5+1, the acceptance calculation must close with one module unavailable—not by dividing the shelf nameplate equally across all six.
Treat handoff as a voltage waveform, not a Boolean event #
The current OCP ORv3 BBU Module Rev. 1.4 text says the BBU monitors the busbar, activates discharge when it remains below 48.5V for 2ms ±0.1ms, and should ramp to full output within less than 2ms while the bus stays above 46V. The same public revision still marks parts of these timing statements “TBD.” Use them as the documented baseline to test against, but return the supplier's released limits and tolerances in the production interface specification.
The trigger is only one part of the waveform. Record at least the normal shelf voltage, source-collapse slew, BBU sense point and accuracy, qualification delay, current-ramp slope, minimum bus voltage, overshoot, current-share error, exit threshold and return delay. Place IT-gear UVLO and hot-swap thresholds on the same plot. A BBU can meet its own activation threshold and still reset a tray if connector drop or a remote-sense error moves the actual load below its limit.
OCP's shelf baseline uses a deliberate droop: approximately 48.0V at no load, 47.75V at half load and 47.5V at full load. The lower BBU curve lets the normal 50.5V-to-51V rectifier system carry the rack without circulating current. It also enables multiple BBU modules to share current when they start together. Replacing one module with a different voltage curve, sense calibration or firmware can create a current hog even if its nominal voltage and connector fit.
The synchronized signals are therefore electrical interfaces, not optional management conveniences. SYNC_START_L coordinates discharge entry; SYNC_STOP_L coordinates exit. The BBU current-share bus and remote-sense pair must also survive a missing module, one late module and a broken signal. The PMI or rack manager may command modes and collect evidence, but loss of management communication must not remove autonomous ride-through protection.
Derate power and energy separately #
Battery capacity determines how long the rack can run. Cell impedance and the converter determine whether it can supply the first high-power pulse without crossing a voltage, current or temperature limit. A pack can pass a low-rate capacity test and still fail the rack load step.
Freeze two derating surfaces:
- Energy surface: usable watt-hours versus SOC, SOH/capacity retention,
cell temperature, discharge rate and minimum cell-voltage limit.
- Power surface: allowable kilowatts versus cell impedance, converter and
inductor temperature, airflow, bus voltage, pulse duration and recovery time.
OCP Rev. 1.4 sets a public life boundary of 3kW for at least four minutes at the specified periodic-charge threshold over at least four years at 35°C long-term maximum BBU ambient. It also calls for a 90-day SOH test. Only one module in a shelf should perform the test at a time, and the specification preserves at least a 90-second, 3kW reserve during or immediately after the SOH discharge. Those conditions show why a laboratory test at fresh-pack, full-SOC room temperature is not release evidence.
Recharge is a rack-load event too. The public module specification permits the system to delay or override charge current and requires a one-minute delay after discharge so the rack can establish the charging policy; cells may need longer to cool. Thousands of BBUs beginning charge together can become a new facility step. The rack manager should stagger or cap recharge based on available shelf headroom without disabling the BMS's local safety limits.
Keep conversion, battery safety and supervision independent #
A practical BBU has three protection domains:
1. Power path: bidirectional buck/boost stage, phase-current sensing, ORing, bus and battery overcurrent/overvoltage protection, hot-swap behavior and a fail-safe direction state. 2. Battery pack: cell voltage and temperature monitoring, coulomb counting, balancing, charge/discharge FET control, pack fuse and permanent-fault latch. 3. Supervisor: state machine, SOC/SOH calculation, synchronized start/stop, Modbus/CAN/PMI telemetry, event log and service policy.
No single MCU task should be the only barrier to a destructive short, overcharge or overtemperature event. OCP requires fuses at safety-critical paths including the battery-pack/discharger input and charger input, and requires the main-fuse state to be reported. The current module specification also lists permanent faults that cannot be cleared by an MCU reset. Supplier documentation must map every threshold to the hardware or firmware element that detects it, the action it takes and the conditions for replacement or retry.
Hot service needs the same precision. Rev. 1.4 calls for hot-swap or equivalent circuits on connections to the busbar, and defines PSKILL as a short-pin signal for rapid shutdown to mitigate hot-unplug arcing. “Hot-swappable module” does not authorize removing the entire energized shelf; the mechanical connector, mate order, isolation procedure and discharge time remain part of the rack service specification.
Use the ADI design as bounded implementation evidence #
Analog Devices publishes a current ORv3 BBU reference implementation around a multiphase bidirectional converter, battery monitor, power-system manager and two microcontrollers. Its measured boundary is especially useful because it separates charge and discharge conditions: 30V-to-44V battery input and 47.5V-to-48V bus output in discharge, versus 49V-to-53V input during charge. ADI reports average discharge efficiency of 98.5% at half load and 98% at the 63.2A full-load point, with 97% average charge efficiency at 5A. Those results belong to that reference configuration, switching frequencies and thermal implementation; they are not generic LT8228 guarantees. Vendor Reference Design
| Current orderable example | Role in the published reference architecture | RFQ and substitution boundary |
|---|---|---|
| LT8228IFE#PBF / LT8228IFE#TRPBF | Production, recommended-for-new-designs bidirectional synchronous buck/boost controller | Preserve grade and carrier suffix, direction-state logic, external FET/inductor design and compensation. It is not a complete 3kW module. |
| LT8551IUKG#PBF / LT8551IUKG#TRPBF | Production, recommended-for-new-designs multiphase expander used with LT8228 to extend the discharge power stage | Phase count, current sensing, gate-drive layout and thermal sharing must be requalified together. |
| ADBMS6948WFSCCSZM-RL | Recommended-for-new-designs 16-channel battery-pack monitor with coulomb counting in the ADI BBU architecture | Confirm the exact data-sheet revision, cell configuration, communication isolation, production availability and programmed BMS policy. |
The reference also identifies MAX32690 for overall module control, LTC2971 for precision path sensing and droop control, MAX31760 for fan control, and a separate low-power controller for battery-health tasks. Do not copy the list into a production BOM without the released schematics, firmware, magnetics, MOSFETs, sensing, pack and safety evidence. Its value is the partition: high- power conversion, battery safety and supervisory control remain separately testable.
Validate the worst transition, not the nominal one #
Build the validation matrix before selecting capacity. Each test should capture bus voltage at the shelf and farthest load, source current, every BBU module current, pack current and cell minimum, SYNC_START_L/SYNC_STOP_L, IT-gear UVLO, converter temperature and the first-fault log on one timebase.
Include at least:
- full load with one BBU module unavailable and minimum approved SOC;
- highest qualified ambient after the specified service-life/capacity model;
- cold cells at their highest permitted impedance;
- a source brownout that hovers around the trigger before collapsing;
- simultaneous rack load step and source loss;
- one module starting late, current-share open, remote-sense open and PMI loss;
- downstream short, blown fuse, stuck direction command and failed auxiliary
bias;
- source recovery during peak discharge, followed by delayed/staggered charge;
- SOH test interruption with the specified remaining reserve; and
- controlled exhaustion: workload drain or transfer before the reserve floor.
Do not accept a controller log without the analog waveform. Conversely, do not accept a clean voltage trace without the module identities, firmware checksum, SOC/SOH estimate, cell temperatures and fault record that explain the test state. The PMBus and AVSBus telemetry guide describes how to preserve first-fault evidence through a brownout; the BBU release must keep its own BMS and converter logs aligned to that rack timeline.
Release the BBU as hardware, firmware and stored energy #
An RFQ for “six 3kW ORv3 BBU modules” is incomplete. Require:
- exact module, shelf, battery-pack, cell, fuse, connector and firmware order
identities, including approved alternates and change-notification policy;
- normal/peak power, pulse duration, 5+1 requirement, bus-voltage waveform,
trigger tolerance, ramp, droop, current-share and recovery limits;
- usable energy and power derating versus SOC, SOH, cell temperature, age and
cycle history, plus the EOL replacement threshold;
- charger/discharger efficiency and loss maps, cooling requirement, fan policy,
auxiliary consumption and hottest-component limits;
- cell-monitor accuracy, balancing policy, pack-current calibration, safety
thresholds, fuse interrupt rating, permanent-fault list and thermal-event containment evidence;
- Modbus/CAN/PMI maps, addresses, synchronized signals, log schema, firmware
image/checksum, update/recovery policy and behavior during communication loss; and
- production test, 90-day SOH procedure, spare/storage/shipping SOC, service
instructions, hazardous-goods documents and end-of-life handling.
The OCP ORv3 shelf, busbar, BBU and PMI guide defines the baseline rack interfaces. This article adds the energy, aging and waveform evidence needed to release the BBU itself. For an 800V distribution system, the solid-state breaker guide sets the separate fault-isolation boundary; a 48V BBU architecture does not by itself prove safe reverse-feed behavior on an HVDC bus.
Conclusion #
Size an AI rack BBU from the load's voltage-versus-time requirement and the minimum available battery state, not from a fresh-pack energy label. Assign the first control-loop gap to local capacitance, the source-transfer interval to the BBU power stage, the sustained window to a derated battery pack, and the end of that window to a declared facility or workload action.
Then qualify the complete transition with one module unavailable, aged and temperature-limited cells, real busbar drop, synchronized current sharing and the production firmware image. That evidence turns “240 seconds of backup” from a brochure claim into a repeatable rack-level service contract and gives procurement an exact hardware, battery and configuration boundary to source.
Official references #
- OCP Open Rack V3 BBU Module specification Rev. 1.4
- OCP Open Rack V3 BBU Shelf specification Rev. 1.1
- OCP Rack and Power specifications index
- Analog Devices Smart Battery Backup Part 1: Electrical and Mechanical Design
- Analog Devices Smart Battery Backup Part 2: BBU Microcontroller Functions
- Analog Devices Smart Battery Backup Part 3: Battery Management System
- Analog Devices ORv3 BBU reference-design resources
- Analog Devices LT8228 bidirectional controller product page
- Analog Devices LT8551 multiphase expander product page
- Analog Devices ADBMS6948 battery monitor product page
- Texas Instruments BBU design resources
- Texas Instruments TIDA-00705 server-BBU bidirectional DC/DC reference
Need stock, date-code or package confirmation?
Send the part number, quantity, target date code and packaging requirements. LimChip will check available lots and RFQ details before you place the order.
Send RFQ