# BattBox Technical Concept

**Document class:** Functional R&D specification  
**Revision:** 0.3  
**Status:** Indicative; not for manufacture

## 1. Purpose

This document defines the intended functions, interfaces, safety principles and verification programme for a dedicated portable-battery deposit module co-located with marketplace parcel lockers. It does not specify a certified construction. Dimensions, materials, ratings and sensor selections remain subject to engineering analysis, hazard testing, site conditions and partner approval.

## 2. System boundary

BattBox begins when a marketplace issues a deposit token and ends when the treatment partner records the downstream outcome. The physical module is one controlled node.

```text
Marketplace app
  -> short-lived deposit token
BattBox edge controller
  -> screen -> pouch bind -> net weight -> deposit event
BattBox platform
  -> ledger -> anomaly rules -> provisional reward -> fleet state
Service operator
  -> cassette swap -> controlled QA -> waste transfer
BCS / approved treatment partner
  -> received mass -> non-conformance -> treatment evidence
Marketplace app
  <- final reward and outcome status
```

## 3. General arrangement hypothesis

Indicative maximum envelope for site and supplier discussion:

- Height: 2,100 mm nominal.
- Width: 800 mm nominal.
- Depth: 650 mm nominal.
- HMI control target: approximately 1,100–1,200 mm above finished floor, subject to inclusive-design validation.
- Controlled aperture: approximately 420 × 65 mm, subject to acceptance-envelope and anti-reach testing.
- Separate rear service access.
- Anchored plinth or engineered interface to the host's foundation.
- Cabinet environmental and impact ratings to be selected after indoor/outdoor site classification.

The deposit module may share external architectural language and digital infrastructure with a parcel locker. It must not share an unassessed internal parcel compartment, loose material path or service procedure.

## 4. Functional modules

### 4.1 Human-machine interface

- High-contrast, daylight-readable display.
- Tactile physical cancel/help control if the final accessibility research supports it.
- Spoken or headphone-accessible guidance considered at Gate 1.
- QR imager capable of reading the marketplace token without capturing unnecessary surrounding imagery.
- Status beacon visible before a user starts a trip.
- Plain-language accepted and refused routes.

### 4.2 Safety-kit dispenser

- Dispenses a defined set of electrically insulating terminal tabs and one non-conductive, puncture-resistant, tamper-evident deposit pouch.
- Every pouch has a unique machine-readable ID and known tare range.
- The visible ID is random and rotating; it contains no name, email, address or marketplace identifier.
- The dispensing mechanism detects successful issue and prevents duplicate reward use.
- Material compatibility, flammability, tear, seal, shelf-life and treatment compatibility require testing.

“Fireproof pouch” must not be used as a marketing claim unless verified for the complete intended use. The pouch is one short-circuit and containment control; it does not make an unsafe battery safe.

### 4.3 Weigh tray

- Physically separate from the final cassette so existing contents do not affect the deposit weight.
- Known pouch tare subtracted from stable gross weight.
- Zero, drift, temperature and overload monitoring.
- In-service calibration and seal regime agreed with legal/metrology advisers because the measurement drives consumer value.
- Maximum net deposit hypothesis: 500 g.
- Plausibility rules compare declared class mix, stable weight curve, deposit count velocity and pouch ID.

### 4.4 Deposit interlock

- Two-stage shutter or equivalent anti-reach arrangement.
- Fail-closed after power, network, controller or sensor fault.
- Opens only for an issued, sealed and successfully weighed pouch.
- Confirms passage without retaining consumer-identifying imagery by default.
- Detects obstruction, tailgating and attempted retrieval.
- Manual service release accessible only under lockout.

### 4.5 Deposit path

- Short path target of 300 mm or less from controlled aperture to receiving surface.
- Low angle and energy; no free-fall onto a hard base.
- No crushing, shredding, powered sorting, vibration, screw conveyor or compaction.
- Smooth, non-cutting, serviceable surfaces.
- Geometry prevents a later pouch striking a concentrated sharp edge or exposed fastener.
- Jam inspection occurs from the service side under lockout.

### 4.6 Removable cassette

- Lidded metal or other fire-engineered construction agreed with the downstream partner.
- Pouch segregation or propagation-limiting features defined by fire testing.
- Presence, closed, lock and fill states monitored.
- Maximum safe mass compatible with manual-handling and service equipment.
- Unique cassette ID and tamper-evident service record.
- Cassette used for fixed-site containment is not automatically suitable as transport packaging; transport classification and packaging are a separate approval.

### 4.7 Sensor package

Candidate sensors for evaluation:

- Multiple temperature points.
- Fill height and/or mass.
- Door, cassette, shutter and service-lock states.
- Smoke/particulate detection where technically appropriate.
- Off-gas detection candidate for lithium-ion thermal-runaway precursors.
- Tilt, impact, water ingress and power health.

No single sensor is a safety guarantee. Detection strategy, alarm threshold, false-alarm handling, power backup, remote alerting and emergency response must be validated as a system.

### 4.8 Edge controller

- Secure boot, signed firmware and signed remote configuration.
- Hardware root or protected keys where proportionate.
- Encrypted communication and rotating device credentials.
- Local append-only event queue for temporary network loss.
- Watchdog, safe-state output and tamper evidence.
- No default remote command that can open the deposit shutter outside an active local flow.
- Time synchronisation and monotonic event sequence.

## 5. State machine

```text
OUT_OF_SERVICE
  -> self-test pass
READY
  -> valid single-use token
SCREENING
  -> accepted declaration / no blocking status
KIT_ISSUED
  -> bound pouch read + stable weight
WEIGHED
  -> interlock clear
DEPOSIT_OPEN
  -> passage detected + shutter closed
DEPOSIT_RECORDED
  -> signed event acknowledged or queued
READY
```

Any power, temperature, gas, cassette, shutter, door, overload, jam or integrity fault transitions to an appropriate fail-closed state. Thermal or gas alarms follow a separate emergency state that cannot be cleared remotely without the approved inspection protocol.

## 6. Data interfaces

### Marketplace to BattBox

- Token identifier, expiry, nonce and permitted campaign.
- Optional accessibility preference if expressly chosen and necessary.
- No name, email, address, order history or raw marketplace account identifier.

### BattBox to marketplace

- Deposit reference mapped through a controlled token exchange.
- Status: initiated, accepted, provisional, verified, adjusted, voided or appealed.
- Reward amount and reason code.
- Consumer-safe outcome message.

### Operator / treatment

- Cassette and pouch ID ranges.
- Accepted net mass and on-site timestamps.
- Collection, controlled-facility receipt and QA results.
- Non-conforming waste categories.
- Treatment batch reference and mass reconciliation.

## 7. Non-functional requirements

| Area | Gate 1 hypothesis |
|---|---|
| Availability | 95% during published service hours in pilot |
| Consumer flow | Median under 75 seconds after first use |
| Weight integrity | Within tolerance agreed after metrology review |
| Event durability | No acknowledged deposit event lost after power/network failure test |
| Privacy | No personal data printed on pouch; no retained consumer image by default |
| Security | Signed code/configuration, least privilege, protected service mode |
| Accessibility | Tested with target users; reach, vision, dexterity and cognition included |
| Service | Cassette exchange target under 10 minutes after safe lockout |
| Claims | Collected, accepted and treated mass always distinct |

## 8. Prototype test programme

### Mechanical

- Aperture reach and retrieval resistance.
- Pouch snag, seal, tear, puncture and drop tests.
- Maximum foreseeable load and misuse.
- Shutter obstruction, tailgating and pinch hazards.
- Cassette insertion, latching, lifting and drop.
- Impact, tilt, vandalism and anchoring.
- Indoor and, if proposed, outdoor temperature, moisture and ingress.

### Electrical and controls

- Power loss at every state.
- Sensor open/short/stuck and implausible readings.
- Network loss, delayed events and duplicate delivery.
- Firmware rollback, unsigned update and expired certificate.
- Emergency-stop / lockout behaviour.
- Earthing, electrical safety and EMC pre-compliance.

### Thermal / fire

- Competent fire engineer defines test cells, charge state, initiation method and pass/fail criteria.
- Detection time and remote alert path.
- Propagation between representative accepted pouches.
- Hot gas, smoke, ejection and cabinet surface temperature.
- Effect of fill level, door state and candidate suppression/containment measures.
- Safe exclusion, response and post-event recovery.

### Metrology and rewards

- Zero, drift, temperature sensitivity and off-centre load.
- Pouch tare distribution and incorrect-pouch detection.
- Repeatability across accepted mass range.
- Fraud cases: added stones, liquid, metal objects, repeated pouch, unstable placement and over-cap deposits.

### Human factors

- Can participants identify refused examples before travelling?
- Can they apply terminal isolation safely and correctly?
- Can they finish without putting hands through an opening?
- Do instructions avoid encouraging unsafe battery removal from devices?
- Can wheelchair users and people with low vision, colour-vision differences, limited dexterity or lower digital confidence complete the flow?

## 9. Engineering deliverables

1. System requirements and traceability matrix.
2. Hazard analysis and preliminary hazard log.
3. General arrangement and detailed CAD controlled by a qualified manufacturer.
4. Electrical architecture and safety functions.
5. Firmware and backend threat models.
6. Interface-control documents for marketplace, operator and BCS.
7. Verification plan, test protocols and evidence pack.
8. Installation, inspection, service, collection, quarantine and emergency manuals.
9. Conformity, permitting, insurance and accessibility evidence index.
10. Configuration and change-control plan.

## 10. Open engineering decisions

- Exact battery dimensions, cell types and energy cap.
- Pouch construction, treatment compatibility and terminal-tab design.
- Cassette propagation-control strategy.
- Sensor set and validated alarm thresholds.
- Indoor-only versus outdoor pilot.
- Mains, solar/backup and safe power-loss design.
- Applicable UK product safety, machinery, electrical, radio and construction requirements.
- Whether the scale and consumer-reward relationship creates additional metrology duties.
- Transport packaging and dangerous-goods classification.
- Fire-service access, siting separation and emergency signage.

## 11. Technical disclaimer

The drawings and numbers in the interactive prototype are functional placeholders. They are not fabrication dimensions, approved safety distances, fire ratings, IP/IK claims or certifications. No public battery collection should use this design until competent specialists have completed the engineering, legal, fire, insurer, treatment and authority approvals.
