Protecting safety configuration updates in an elevator system

The safety device and network device system addresses unsafe elevator parameter updates by using digital signatures to validate and synchronize configurations, ensuring secure and compliant updates.

WO2026109149A1PCT designated stage Publication Date: 2026-05-28KONE OYJ
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
KONE OYJ
Filing Date
2024-11-22
Publication Date
2026-05-28

AI Technical Summary

Technical Problem

Elevator systems face challenges in safely updating safety configuration parameters due to potential mismatches or incorrect configurations, which can lead to non-compliance or unsafe behavior, especially when spare parts with default configurations are installed.

Method used

A safety device and network device system that uses digital signatures and verification processes to ensure authorized updates, including creating a data block with elevator equipment parameters, authorization information, and target equipment identification, and applying multiple digital signatures to validate and synchronize updates.

Benefits of technology

Ensures secure and synchronized parameter updates, preventing unsafe configurations and maintaining compliance by verifying the authenticity and validity of updates through a multi-layered digital signature process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2024083257_28052026_PF_FP_ABST
    Figure EP2024083257_28052026_PF_FP_ABST
Patent Text Reader

Abstract

According to an aspect, there is provided a safety device of an elevator system. The safety device is configured to receive a connection request comprising authorization information; determine based on the authorization information that the connection request is associated with a valid user license; receive an equipment parameter change request associated with a target elevator equipment, the elevator equipment parameter change request comprising at least one elevator equipment parameter and target elevator equipment identification information; create a data block comprising the at least one elevator equipment parameter, the authorization information and the target elevator equipment identification information; digitally sign the data block to generate a first digital signature; create a signed data block by adding the first digital signature to the data block; and transmit the signed data block to a network device for verification.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] PROTECTING SAFETY CONFIGURATION UPDATES IN AN ELEVATOR

[0002] SYSTEM

[0003] TECHNICAL FIELD

[0004] Various examples generally may relate to the field of elevator systems . In particular, some examples relate to a solution for protecting safety configuration updates in an elevator system .

[0005] BACKGROUND

[0006] Elevator equipment is normally factory configured with a required set of parameters , for example , according to a country speci fic code and standards . It is possible that there may be mistakes in the factory configured parameters or that some equipment may mal function at a site . Due to this , the parameters might need to be changed in a secure way . Further, when a spare spart is to be used, it may be that a factory ships the spare part with a default configuration . Then, when the spare is installed, the default configuration may be overwritten by an existing parameter configuration in a control system .

[0007] When performing parameter configuration updates , there are some challenges especially related to safety . I f setting parameters locally, there is chance of setting incorrect parameters either intentionally or unintentionally . Further, a parameter configuration may be correct in a safety device , but a service person may not synchroni ze the parameter configuration update to a control system . I f this goes unnoticed, then future spare parts will be loaded with the old parameter configuration .

[0008] It may also occur that , when a spare part installed with old or incorrect parameters is connected, the system evaluates the parameter configuration data available in existing components and data received from the spare part . I f the data in the spare part and in an existing part matches , then there is no problem . However, i f there is a mismatch with the data in the spare part and the existing part , a safety device may prefer to use the data in the spare part with an old or incorrect parameter configuration data . Thus , incorrect parameter configuration may lead to a non-compliance or unsafe behavior of the safety device .

[0009] SUMMARY

[0010] The scope of protection sought for various example embodiments of the disclosure is set out by the independent claims . The example embodiments and features , i f any, described in this speci fication that do not fall under the scope of the independent claims are to be interpreted as examples useful for understanding various example embodiments of the disclosure .

[0011] According to a first aspect , there is provided a safety device of an elevator system comprising at least one processor and at least one memory storing instructions that , when executed by the at least one processor, cause the safety device to at least perform : receiving a connection request comprising authori zation information; determining based on the authori zation information that the connection request is associated with a valid user license ; receiving an equipment parameter change request associated with a target elevator equipment , the elevator equipment parameter change request comprising at least one elevator equipment parameter and target elevator equipment identi fication information; creating a data block comprising the at least one elevator equipment parameter, the authori zation information and the target elevator equipment identi fication information; digitally signing the data block to generate a first digital signature ; creating a signed data block by adding the first digital signature to the data block; and transmitting the signed data block to a network device for veri fication .

[0012] In an implementation form of the first aspect , the at least one memory stores instructions that , when executed by the at least one processor, cause the safety device to at least perform : clearing the elevator equipment parameter change request from a memory after transmitting the signed data block .

[0013] In an implementation form of the first aspect , the at least one memory stores instructions that , when executed by the at least one processor, cause the safety device to at least perform : prior to creating the data block, determining that information in the data block is valid for the type of the elevator equipment .

[0014] In an implementation form of the first aspect , the at least one memory stores instructions that , when executed by the at least one processor, cause the safety device to at least perform : receiving a double signed data block from the network device , the double signed data block comprising the first signed data block signed by the network device with a second digital signature ; veri fying the double signed data block and its content ; and updating the target elevator equipment with the at least one elevator equipment parameter in response to a success ful veri fication .

[0015] In an implementation form of the first aspect , veri fying the double signed data block and its content comprises at least one of : veri fying the second digital signature of the second signed block; veri fying that the first digital signature is present ; veri fying the target the elevator equipment identi fication information; and veri fying the authori zation information .

[0016] In an implementation form of the first aspect , the at least one memory stores instructions that , when executed by the at least one processor, cause the safety device to at least perform : determining that a parameter switch setting is enabled; and accepting the double signed data block in response to the success ful veri fication and the determination that the parameter switch setting is enabled .

[0017] In an implementation form of the first aspect , the at least one memory stores instructions that , when executed by the at least one processor, cause the safety device to at least perform : transmitting an indication that the safety device accepted the at least one elevator equipment parameter .

[0018] In an implementation form of the first aspect , the at least one memory stores instructions that , when executed by the at least one processor, cause the safety device to at least perform : transmitting the accepted at least one elevator equipment parameter to the network device .

[0019] In an implementation form of the first aspect , the authori zation information comprises at least one of user license information and user identi fication information .

[0020] According to a second aspect , there is provided a network device comprising at least one processor and at least one memory storing instructions that , when executed by the at least one processor, cause the network device to at least perform : receiving, from a safety device , a digitally signed data block comprising a data block and a first digital signature of the data block, the data block comprising at least one elevator equipment parameter, authori zation information and target elevator equipment identi fication information; determining that the first digital signature of the data block is valid; determining that the data block is valid; digitally signing the digitally signed data block to generate a second digital signature ; creating a double signed data block by adding the second digital signature to the digitally signed data block; and transmitting the double signed data block to the safety device .

[0021] In an implementation form of the second aspect , the at least one memory stores instructions that , when executed by the at least one processor, cause the network device to at least perform : receiving an indication that the safety device accepted the at least one elevator equipment parameter .

[0022] In an implementation form of the second aspect , the at least one memory stores instructions that , when executed by the at least one processor, cause the network device to at least perform : receiving the accepted at least one elevator equipment parameter from the safety device .

[0023] In an implementation form of the second aspect , the authori zation information comprises at least one of user license information and user identi fication information .

[0024] According to a third aspect , there is provided a system comprising a safety device according to the first aspect and a network device according to the second aspect .

[0025] According to a fourth aspect , there is provided a method comprising : receiving a connection request comprising authori zation information; determining based on the authori zation information that the connection request is associated with a valid user license ; receiving an equipment parameter change request associated with a target elevator equipment , the elevator equipment parameter change request comprising at least one elevator equipment parameter and target elevator equipment identi fication information; creating a data block comprising the at least one elevator equipment parameter, the authori zation information and the target elevator equipment identi fication information; digitally signing the data block to generate a first digital signature ; creating a signed data block by adding the first digital signature to the data block; and transmitting the signed data block to a network device for veri fication . The method may be a computer- implemented method .

[0026] In an implementation form of the fourth aspect , the method comprises clearing the elevator equipment parameter change request from a memory after transmitting the signed data block .

[0027] In an implementation form of the fourth aspect , the method comprises , prior to creating the data block, determining that information in the data block is valid for the type of the elevator equipment .

[0028] In an implementation form of the fourth aspect , the method comprises : receiving a double signed data block from the network device , the double signed data block comprising the first signed data block signed by the network device with a second digital signature ; veri fying the double signed data block and its content ; and updating the target elevator equipment with the at least one elevator equipment parameter in response to a success ful veri fication . In an implementation form of the fourth aspect , the method comprises : veri fying the second digital signature of the second signed block; veri fying that the first digital signature is present ; veri fying the target the elevator equipment identi fication information; and veri fying the authori zation information .

[0029] In an implementation form of the fourth aspect , the method comprises : determining that a parameter switch setting is enabled; and accepting the double signed data block in response to the success ful veri fication and the determination that the parameter switch setting is enabled .

[0030] In an implementation form of the fourth aspect , the method comprises transmitting an indication that the safety device accepted the at least one elevator equipment parameter .

[0031] In an implementation form of the fourth aspect , the method comprises transmitting the accepted at least one elevator equipment parameter to the network device .

[0032] In an implementation form of the fourth aspect , the authori zation information comprises at least one of user license information and user identi fication information .

[0033] According to a fi fth aspect , there is provided a method comprising : receiving, from a safety device , a digitally signed data block comprising a data block and a first digital signature of the data block, the data block comprising at least one elevator equipment parameter, authori zation information and target elevator equipment identi fication information; determining that the first digital signature of the data block is valid; determining that the data block is valid; digitally signing the digitally signed data block to generate a second digital signature ; creating a double signed data block by adding the second digital signature to the digitally signed data block; and transmitting the double signed data block to the safety device . The method may be a computer-implemented method .

[0034] In an implementation form of the fi fth aspect , the method comprises receiving an indication that the safety device accepted the at least one elevator equipment parameter .

[0035] In an implementation form of the fi fth aspect , the method comprises receiving the accepted at least one elevator equipment parameter from the safety device .

[0036] In an implementation form of the fi fth aspect , the authori zation information comprises at least one of user license information and user identi fication information .

[0037] According to a sixth aspect , there is provided a computer program comprising instructions which, when the program is executed by at least one processor, cause a safety device to perform the method of the fourth aspect .

[0038] According to a seventh aspect , there is provided a computer program comprising instructions which, when the program is executed by at least one processor, cause a network device to perform the method of the fi fth aspect .

[0039] According to an eighth aspect , there is provided a computer-readable medium comprising a computer program comprising instructions which, when the program is executed by at least one processor, cause a safety device to perform the method of the fourth aspect .

[0040] According to a ninth aspect , there is provided a computer-readable medium comprising a computer program comprising instructions which, when the program is executed by at least one processor, cause a network device to perform the method of the fi fth aspect .

[0041] According to a tenth aspect , there is provided a safety device of an elevator system comprising means for : receiving a connection request comprising authori zation information; determining based on the authori zation information that the connection request is associated with a valid user license ; receiving an equipment parameter change request associated with a target elevator equipment , the elevator equipment parameter change request comprising at least one elevator equipment parameter and target elevator equipment identi fication information; creating a data block comprising the at least one elevator equipment parameter, the authori zation information and the target elevator equipment identi fication information; digitally signing the data block to generate a first digital signature ; creating a signed data block by adding the first digital signature to the data block; and transmitting the signed data block to a network device for veri fication .

[0042] According to an eleventh aspect , there is provided a network device comprising means for : receiving, from a safety device , a first digitally signed data block comprising a data block and a first digital signature of the data block, the data block comprising at least one elevator equipment parameter, authori zation information and target elevator equipment identi fication information; determining that the first digital signature of the data block is valid; determining that the data block is valid; digitally signing the digitally signed data block to generate a second digital signature ; creating a double signed data block by adding the second digital signature to the first digitally signed data block; and transmitting the double signed data block to the safety device .

[0043] BRIEF DESCRIPTION OF THE DRAWINGS

[0044] The accompanying drawings , which are included to provide a further understanding of the invention and constitute a part of this speci fication, illustrate examples of the invention and together with the description help to explain the principles of the invention . In the drawings :

[0045] FIG . 1 illustrates a flow diagram of a method according to an example embodiment .

[0046] FIG . 2 illustrates a flow diagram of a method according to an example embodiment .

[0047] FIG . 3 illustrates a flow diagram of a method according to an example embodiment .

[0048] FIG . 4 illustrates a block diagram of a safety device according to an example embodiment .

[0049] FIG . 5 illustrates a block diagram of a network device according to an example embodiment .

[0050] DETAILED DESCRIPTION

[0051] Various examples and embodiments discussed below illustrate a solution for protecting safety configuration updates in an elevator system . FIG . 1 illustrates a flow diagram of a method according to an example embodiment . The method may be implemented, for example , by a safety device of an elevator system .

[0052] At 100 , a connection request comprising authori zation information may be received . The connection request may indicate to the safety device that the user is about to perform some operations with a service device used by the user . The authori zation information may comprise , for example , at least one of user license information and user identi fication information . In an example embodiment , prior to receiving the equipment parameter change request , the service device may have set a parameter enable switch to ON position at the safety device .

[0053] At 102 , it may be determined based on the authori zation information that the connection request is associated with a valid user license . In other words , when the service person uses the service device , the user has to be authori zed, for example , have a valid license , in order to interact with the safety device . I f user identi fication information is used, the user identi fication information can be used to determine whether there exists license information associated with the user . I f the safety device determines that the user license is not valid, the safety device may send to the service device an indication that an invalid user license was used . In response to determining that an invalid user license was used, the safety device discards the elevator equipment parameter change request .

[0054] At 104 , an equipment parameter change request associated with a target elevator equipment may be received, the elevator equipment parameter change request comprising at least one elevator equipment parameter and target elevator equipment identi fication information . The equipment parameter change request may be received, for example , from the service device operated by the user .

[0055] At 106 , a data block comprising the at least one elevator equipment parameter, the authori zation information and the target elevator equipment identi fication information may be created . In an example embodiment , prior to creating the data block, it may be determined that the information in the data block is valid for the type of the elevator equipment .

[0056] At 106 , the data block may be digitally signed to generate a first digital signature . The digital signature may be generated using, for example , a secret key associated with the safety device or any other digital signature generation technique .

[0057] At 108 , a signed data block may be created by adding the first digital signature to the data block . The digital signature enables a recipient of the signed data block to veri fy the origin of the sender and integrity of the received information .

[0058] At 110 , the signed data block may be transmitted to a network device for veri fication .

[0059] In an example embodiment , the elevator equipment parameter change request may be cleared from a memory after transmitting the signed data block . This creates a situation in which, right after transmitting the signed data block, the safety device cannot perform any parameter updates as it does not store the request anymore . Instead, it has to wait for a response from the network device prior to making any updates . In an example embodiment , a double signed data block may be received from the network device , the double signed data block comprising the signed data block signed by the network device with a second digital signature . In other words , at this point there are two separate digital signatures in the information received by the safety device . The double signed data block and its content may be veri fied, and the target elevator equipment may be updated with the at least one elevator equipment parameter in response to a success ful veri fication . The veri fication may comprise at least one of the following : veri fying the second digital signature of the double signed block; veri fying that the first digital signature is present ; veri fying the authori zation information; and veri fying the target the elevator equipment identi fication information .

[0060] In an example embodiment , it may be determined that a parameter switch setting is enabled at the safety device . I f the parameter switch setting is enabled, it means that the user is physically present at the elevator site while modi fying safety parameter . The double signed data block may be accepted in response to the success ful veri fication and the determination that the parameter switch setting is enabled .

[0061] In an example embodiment , an indication that the safety device accepted the at least one elevator equipment parameter may be transmitted by the safety device to the network device . In an example embodiment , the safety device may additionally transmit the accepted at least one elevator equipment parameter to the network device for automatic backup by the network device .

[0062] In an example embodiment , version information associated with the target elevator equipment may be added to the data block prior to digitally signing the data block . When the safety device then receives the version information in the double signed data block and the version information indicates an outdated version, the safety device is able to prohibit updating to the outdated version .

[0063] FIG . 2 illustrates a flow diagram of a method according to an example embodiment . The method may be implemented, for example , by a network device , for example , a cloud node , associated with an elevator system .

[0064] At 200 , a digitally signed data block comprising a data block and a first digital signature of the data block may be received, for example , from a safety device of the elevator system . The data block comprises at least one elevator equipment parameter, authori zation information and target elevator equipment identi fication information . The safety device may send the digitally signed data block to the network device in response to receiving an equipment parameter change request associated with a target elevator equipment . In an example embodiment , the digital signature may have been generated using a private key associated with the safety device . The authori zation information may comprise , for example , at least one of user license information and user identi fication information .

[0065] At 202 , it may be determined that the first digital signature of the data block is valid . The validity of the digital signature may be veri fied, for example , by using a public key of the safety device . I f the digital signature is determined to be invalid, the network device may record this to an audit log .

[0066] At 204 , it may be determined that the data block is valid . This may comprise , for example , validating that the at least one elevator equipment parameter is correct for the target elevator equipment . I f the data block is determined to be invalid, the network device may record this to an audit log .

[0067] At 206 , the digitally signed data block may be again digitally signed to generate a second digital signature .

[0068] At 208 , a double signed data block may be created by adding the second digital signature to the digitally signed data block . In other words , the second signed data block now includes a digital signature both from the safety device and the network device .

[0069] At 210 , the double signed data block may be transmitted to the safety device .

[0070] In an example embodiment , an indication that the safety device accepted the at least one elevator equipment parameter may be received from the safety device . The network device may record this information to the audit log .

[0071] In an example embodiment , the accepted at least one elevator equipment parameter may be received from the safety device . The network device may store this information as back-up information for the target elevator equipment .

[0072] FIG . 3 illustrates a flow diagram of a method according to an example embodiment .

[0073] At 306 , a service device 300 operated by a user may send a connection request comprising authori zation information to a safety device 302 . The connection request may indicate to the safety device 302 that the user is about to perform some operations with the service device 300 . In an example embodiment , prior to receiving the equipment parameter change request , the service device 300 may have set a parameter enable switch to ON position at the safety device 302 . The authori zation information may comprise , for example , at least one of user license information and user identi fication information .

[0074] At 308 , the safety device 302 determines based on the authori zation information whether the connection request is associated with a valid user license . In other words , when the service person uses the service device , the service user has to have a valid license in order to interact with the safety device . I f the safety device determines that the user license is not valid, at 310 the safety device 302 may send to the service device 300 an indication that an expired or invalid user license was used . In response to determining that an invalid user license was used, the safety device 302 discards the elevator equipment parameter change request . I f the safety device determines that the user license is valid, at 312 the safety device 302 may send an acknowledgement to the service device 300 that a valid user license was used .

[0075] At 314 , the service device 300 sends an equipment parameter change request associated with a target elevator equipment to the safety device 302 , the elevator equipment parameter change request comprising an elevator equipment parameter set ( i . e . , at least one elevator equipment parameter ) and target elevator equipment identi fication information . The purpose of the request is to initiate a validation process of the elevator equipment parameter set . In an example embodiment , the elevator equipment parameter change request may be cleared from a memory of the safety device 302 after transmitting the signed data block . This creates a situation in which, right after transmitting the signed data block, the safety device 302 cannot perform any parameter updates as it does not store the request anymore . Instead, it has to wait for a response from the network device 304 prior to making any updates .

[0076] At 316 , the safety device 302 checks whether the elevator equipment parameter set is valid . The validity may indicate , for example , whether the elevator equipment parameter set is valid for a speci fic hardware type of the target elevator equipment . I f the elevator equipment parameter set is not valid, at 318 the safety device 302 sends an indication to the service device 300 that the elevator equipment parameter set is not valid . In this case , no updates are done .

[0077] At 320 , when the elevator equipment parameter set is valid, the safety device 302 creates a data block comprising the elevator equipment parameter set , the authori zation information and the target elevator equipment identi fication information . In an example embodiment , version information associated with the target elevator equipment may be added to the data block prior to digitally signing the data block .

[0078] At 322 , the safety device 302 signs the data block to generate a first digital signature . In an example embodiment , the first digital signature may be generated using a private key associated with the safety device . It other embodiments , other digital signature creation techniques may be used .

[0079] At 324 , the safety device 302 sends the signed data block to the network device 304 .

[0080] At 326 , the network device 304 first checks whether the first digital signature is valid . This can be done , for example , using a public key of the safety device 302 . I f the first digital signature is not valid, at 328 this may be recorded in an audit log . The erroneous digital signature may be caused, for example , by a malicious attempt to update the elevator equipment parameter set . At 330 , it has been determined that the first digital signature is valid and a further determination is made whether the data block is valid . The data block is not valid, for example , when the data block is not compatible with the target elevator equipment . At 332 , information about the invalidity may be stored in the audit log .

[0081] At 334 , the digitally signed data block received from the safety device 302 is digitally signed again by the network device 304 to generate a second digital signature . The network device 304 then creates a double signed data block by adding the second digital signature to the digitally signed data block received from the safety device 302 . In an example embodiment , the second digital signature may be generated using a private key associated with the network device . It other embodiments , other digital signature creation techniques may be used .

[0082] At 336 , the network device 304 sends the double signed data block to the safety device 302 . In other words , at this point there are two separate digital signatures in the information sent to the safety device 302 .

[0083] At 338 , the safety device 302 veri fies the double signed data block . In an example embodiment , the veri fication may result in that a valid signature ( or signatures ) is missing . Due to this , the safety device 302 may determine that the update is not reliable as signatures are missing . In another example embodiment , additionally or alternatively, the veri fication may result in that the data block is not valid . Due to this , the safety device 302 may determine that the data block is not compatible , for example , the data block is outdated . In another example embodiment , additionally or alternatively, the veri fication may check the validity of the authori zation information and the target elevator equipment identi fication information . The validity check may check, for example , that the authori zation information is not expired and that the target elevator equipment identi fication information matches with that of the target elevator equipment to be updated . In another example embodiment , additionally or alternatively, the veri fication may check that the parameter switch setting is enabled at the safety device . I f the parameter switch setting is not enabled, it may mean that the user is not present at the elevator site to validate the behavior of the equipment .

[0084] At 340 , the safety device 302 may update the target elevator equipment after success ful veri fications .

[0085] In an example embodiment , an indication that the safety device 302 accepted the elevator equipment parameter set may be transmitted to the network device 304 . In an example embodiment , the safety device 302 may additionally transmit the accepted elevator equipment parameter set to the network device 304 for automatic backup by the network device 304 .

[0086] FIG . 4 illustrates a block diagram of a safety device 302 according to an example embodiment . The safety device 302 comprises one or more processors 400 , and one or more memories 402 that comprise computer program code 404 , and / or a communication interface 406 for wired and / or wireless communication . Although the safety device 302 is depicted to include only one processor 400 , the safety device 302 may include more than one processor . In an example , the memory 402 is capable of storing instructions , such as an operating system and / or various applications .

[0087] Furthermore , the processor 400 is capable of executing the stored instructions . In an example embodiment , the processor 400 may be embodied as a multi-core processor, a single core processor, or a combination of one or more multi-core processors and one or more single core processors . For example , the processor 400 may be embodied as one or more of various processing devices , such as a coprocessor, a microprocessor, a controller, a digital signal processor ( DSP ) , a processing circuitry with or without an accompanying DSP, or various other processing devices including integrated circuits such as , for example , an application speci fic integrated circuit (AS IC ) , a field programmable gate array ( FPGA) , a microcontroller unit (MCU) , a hardware accelerator, a special-purpose computer chip, or the like . In an example embodiment , the processor 400 may be configured to execute hard-coded functionality . In an example embodiment , the processor 400 is embodied as an executor of software instructions , wherein the instructions may speci fically configure the processor 400 to perform the algorithms and / or operations described herein, when the instructions are executed, for example , at least some steps discussed relating to FIG . 1 and FIG . 3 .

[0088] The memory 402 may be embodied as one or more volatile memory devices , one or more non-volatile memory devices , and / or a combination of one or more volatile memory devices and non-volatile memory devices . For example , the memory 402 may be embodied as semiconductor memories ( such as mask ROM, PROM (programmable ROM) , EPROM ( erasable PROM) , flash ROM, RAM ( random access memory) , etc . ) . The at least one memory 402 may store program instructions that , when executed by the at least one processor 400 , cause the safety device 302 to perform the functionality of the various embodiments discussed herein . Further, in an embodiment , at least one of the processor 400 and the memory 402 may constitute means for implementing the discussed functionality . A computer program may comprise instructions which, when the program is executed by the at least one processor 400 , may cause the safety device 302 to perform any of the methods described above . Furthermore , a computer- readable medium may comprise the computer program .

[0089] FIG . 5 illustrates a block diagram of a network device 304 according to an example embodiment . The network device 304 comprises one or more processors 500 , and one or more memories 502 that comprise computer program code 504 , and / or a communication interface 506 for wired and / or wireless communication . Although the network device 304 is depicted to include only one processor 500 , the network device 304 may include more than one processor . In an example , the memory 502 is capable of storing instructions , such as an operating system and / or various applications .

[0090] Furthermore , the processor 500 is capable of executing the stored instructions . In an example embodiment , the processor 500 may be embodied as a multi-core processor, a single core processor, or a combination of one or more multi-core processors and one or more single core processors . For example , the processor 500 may be embodied as one or more of various processing devices , such as a coprocessor, a microprocessor, a controller, a digital signal processor ( DSP ) , a processing circuitry with or without an accompanying DSP, or various other processing devices including integrated circuits such as , for example , an application speci fic integrated circuit (AS IC ) , a field programmable gate array ( FPGA) , a microcontroller unit (MCU) , a hardware accelerator, a special-purpose computer chip, or the like . In an example embodiment , the processor 500 may be configured to execute hard-coded functionality . In an example embodiment , the processor 500 is embodied as an executor of software instructions , wherein the instructions may speci fically configure the processor 500 to perform the algorithms and / or operations described herein, when the instructions are executed, for example , at least some steps discussed relating to FIG . 2 and FIG . 3 .

[0091] The memory 502 may be embodied as one or more volatile memory devices , one or more non-volatile memory devices , and / or a combination of one or more volatile memory devices and non-volatile memory devices . For example , the memory 502 may be embodied as semiconductor memories ( such as mask ROM, PROM (programmable ROM) , EPROM ( erasable PROM) , flash ROM, RAM ( random access memory) , etc . ) .

[0092] The at least one memory 502 may store program instructions that , when executed by the at least one processor 500 , cause the network device 304 to perform the functionality of the various embodiments discussed herein . Further, in an embodiment , at least one of the processor 500 and the memory 502 may constitute means for implementing the discussed functionality . A computer program may comprise instructions which, when the program is executed by the at least one processor 500 , may cause the network device 304 to perform any of the methods described above . Furthermore , a computer- readable medium may comprise the computer program .

[0093] One or more of the above discussed examples and example embodiments may enable a solution in which the process of veri fying an update request can be automated . Further, one or more of the above discussed examples and example embodiments may enable a solution in which the security of the update procedure is enhanced . Further, one or more of the above discussed examples and example embodiments may enable a solution in which elevator equipment data is kept synchroni zed with the cloud, i . e . the network device , all the time . Further, one or more of the above discussed examples and example embodiments may enable a solution which prevents the risk of losing compliance and / or a safety function of an elevator due to an incorrect parameter configuration or a malicious attack . Further, one or more of the above discussed examples and example embodiments may enable a solution in which only authori zed personnel ( for example , a group of people ) can perform safety configuration updates .

[0094] The examples discussed above may be implemented in software , hardware , application logic or a combination of software , hardware and application logic . The example devices can store information relating to various methods described herein . This information can be stored in one or more memories , such as a hard disk, a solid state drive ( SSD) , an optical disk, a magneto-optical disk, an RAM, and the like . One or more databases can store the information used to implement the examples . The databases can be organi zed using data structures ( e . g . , records , tables , arrays , fields , graphs , trees , lists , and the like ) included in one or more memories or storage devices listed herein . The methods described with respect to the examples can include appropriate data structures for storing data collected and / or generated by the methods of the devices and subsystems of the examples in one or more databases .

[0095] The components of the examples may include computer readable medium or memories for holding instructions programmed according to the teachings and for holding data structures , tables , records , and / or other data described herein . In an example , the application logic, software or an instruction set is maintained on any one of various conventional computer-readable media . In the context of this document , a "computer-readable medium" may be any media or means that can contain, store , communicate , propagate or transport the instructions for use by or in connection with an instruction execution system, apparatus , or device , such as a computer . A computer-readable medium may include a computer- readable storage medium that may be any media or means that can contain or store the instructions for use by or in connection with an instruction execution system, apparatus , or device , such as a computer . A computer readable medium can include any suitable medium that participates in providing instructions to a processor for execution . Such a medium can take many forms , including but not limited to , non-volatile media, volatile media, transmission media, and the like .

[0096] While there have been shown and described and pointed out fundamental novel features as applied to preferred examples thereof , it will be understood that various omissions and substitutions and changes in the form and details of the devices and methods described may be made by those skilled in the art without departing from the spirit of the disclosure . For example , it is expressly intended that all combinations of those elements and / or method steps which perform substantially the same function in substantially the same way to achieve the same results are within the scope of the disclosure . Moreover, it should be recogni zed that structures and / or elements and / or method steps shown and / or described in connection with any disclosed form or example may be incorporated in any other disclosed or described or suggested form as a general matter of design choice . Furthermore , in the claims means-plus- function clauses are intended to cover the structures described herein as performing the recited function and not only structural equivalents , but also equivalent structures .

[0097] The applicant hereby discloses in isolation each individual feature described herein and any combination of two or more such features , to the extent that such features or combinations are capable of being carried out based on the present speci fication as a whole , in the light of the common general knowledge of a person skilled in the art , irrespective of whether such features or combinations of features solve any problems disclosed herein, and without limitation to the scope of the claims . The applicant indicates that the disclosed aspects / embodiments may consist of any such individual feature or combination of features . In view of the foregoing description it will be evident to a person skilled in the art that various modi fications may be made within the scope of the disclosure .

Claims

CLAIMS1. A safety device (302) of an elevator system, comprising : at least one processor (400) ; and at least one memory (402) storing instructions that, when executed by the at least one processor (400) , cause the safety device (302) to at least perform: receiving a connection request comprising authorization information; determining based on the authorization information that the connection request is associated with a valid user license; receiving an equipment parameter change request associated with a target elevator equipment, the elevator equipment parameter change request comprising at least one elevator equipment parameter and target elevator equipment identification information; creating a data block comprising the at least one elevator equipment parameter, the authorization information and the target elevator equipment identification information; digitally signing the data block to generate a first digital signature; creating a signed data block by adding the first digital signature to the data block; and transmitting the signed data block to a network device for verification.

2. The safety device (302) according to claim 1, wherein the at least one memory (402) stores instructions that, when executed by the at least one processor (400) , cause the safety device (302) to at least perform: clearing the elevator equipment parameter change request from a memory after transmitting the signed data block.

3. The safety device (302) according to claim 1 or 2, wherein the at least one memory (402) stores instructions that, when executed by the at least one processor (400) , cause the safety device (302) to at least perform: prior to creating the data block, determining that information in the data block is valid for the type of the elevator equipment.

4. The safety device (302) according to any one of claims 1 - 3, wherein the at least one memory (402) stores instructions that, when executed by the at least one processor (400) , cause the safety device (302) to at least perform: receiving a double signed data block from the network device, the double signed data block comprising the signed data block signed by the network device with a second digital signature; verifying the double signed data block and its content; and updating the target elevator equipment with the at least one elevator equipment parameter in response to a successful verification.

5. The safety device (302) according to claim 4, wherein verifying the double signed data block and its content comprises at least one of: verifying the second digital signature of the double signed block; verifying that the first digital signature is present ; verifying the target the elevator equipment identification information; and verifying the authorization information.

6. The safety device (302) according to any one of claims 4 - 5, wherein the at least one memory (402) stores instructions that, when executed by the at least one processor (400) , cause the safety device (302) to at least perform: determining that a parameter switch setting is enabled; and accepting the double signed data block in response to the successful verification and the determination that the parameter switch setting is enabled .

7. The safety device (302) according to any one of claims 4 - 6, wherein the at least one memory (402) stores instructions that, when executed by the at least one processor (400) , cause the safety device (302) to at least perform: transmitting an indication that the safety device accepted the at least one elevator equipment parameter .

8. The safety device (302) according to any one of claims 4 - 7, wherein the at least one memory (402) stores instructions that, when executed by the at least one processor (400) , cause the safety device (302) to at least perform: transmitting the accepted at least one elevator equipment parameter to the network device.

9. The safety device (302) according to any one of claims 1 - 8, wherein the authorization information comprises at least one of user license information and user identification information.

10. A network device (304) , comprising: at least one processor (500) ; andat least one memory (502) storing instructions that, when executed by the at least one processor (500) , cause the network device (304) to at least perform: receiving, from a safety device, a digitally signed data block comprising a data block and a first digital signature of the data block, the data block comprising at least one elevator equipment parameter, authorization information and target elevator equipment identification information; determining that the first digital signature of the data block is valid; determining that the data block is valid; digitally signing the digitally signed data block to generate a second digital signature; creating a double signed data block by adding the second digital signature to the digitally signed data block; and transmitting the double signed data block to the safety device.

11. The network device (304) according to claim 10, wherein the at least one memory (502) stores instructions that, when executed by the at least one processor (500) , cause the network device (304) to at least perform: receiving an indication that the safety device accepted the at least one elevator equipment parameter.

12. The network device (304) according to claim 10 or 11, wherein the at least one memory (502) stores instructions that, when executed by the at least one processor (500) , cause the network device (304) to at least perform: receiving the accepted at least one elevator equipment parameter from the safety device.

13. The network device (303) according to any one of claims 10 - 12, wherein the authorization information comprises at least one of user license information and user identification information.

14. A system comprising: a safety device (302) according to any one of claims 1 - 9; and a network device (304) according to any one of claims 10 - 13.

15. A computer-implemented method comprising: receiving a connection request comprising authorization information; determining based on the authorization information that the connection request is associated with a valid user license; receiving an equipment parameter change request associated with a target elevator equipment, the elevator equipment parameter change request comprising at least one elevator equipment parameter and target elevator equipment identification information; creating a data block comprising the at least one elevator equipment parameter, the authorization information and the target elevator equipment identification information; digitally signing the data block to generate a first digital signature; creating a signed data block by adding the first digital signature to the data block; and transmitting the signed data block to a network device for verification.

16. A computer-implemented method comprising: receiving, from a safety device a digitally signed data block comprising a data block and a first digital signature of the data block, the data blockcomprising at least one elevator equipment parameter, authori zation information and target elevator equipment identi fication information; determining that the first digital signature of the data block is valid; determining that the data block is valid; digitally signing the digitally signed data block to generate a second digital signature ; creating a double signed data block by adding the second digital signature to the digitally signed data block; and transmitting the double signed data block to the safety device .17 . A computer program comprising instructions which, when the program is executed by at least one processor, cause a safety device ( 302 ) to perform the method of any of claims 15 - 16 .18 . A computer-readable medium comprising a computer program comprising instructions which, when the program is executed by at least one processor, cause a network device ( 304 ) to perform the method of any of claims 15 - 16 .

Citation Information

Patent Citations

  • Verification of authenticity of a maintenance means connected to a controller of a passenger transportation / access device of a building and provision and obtainment of a license key for use therein

    US10361867B2

  • Method to update safety related software

    US20180157482A1

  • Updating digital certificates of a lift system with a mobile terminal

    WO2023217572A1

  • Software update mechanism for time critical applications

    WO2024153308A1