Elevator outbound call firmware upgrade system and method
By sending silent requests and broadcasting firmware upgrade packages on the elevator outbound call node bus, the low efficiency and aesthetic problems caused by the need to dismantle the node box for upgrade in the existing technology are solved, efficient firmware upgrades are achieved, and costs are saved.
Patent Information
- Application Number
- CN202310012635.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-01-05
- Publication Date
- 2025-09-30
- Estimated Expiration
- 2043-01-05
AI Technical Summary
Software upgrades for existing elevator outbound call nodes require disassembly of the node box, resulting in large investment in manpower and material resources, low efficiency, and potential damage to the aesthetics of the facility.
Connect the elevator outbound call node bus via a handheld device, send a system silent request to put all devices except the outbound call node into silent mode, broadcast the firmware upgrade package, and perform an integrity check to achieve group upgrade of the outbound call node.
Efficient firmware upgrades are achieved without disassembling the outbound call node, saving manpower and time costs and improving upgrade efficiency and convenience.
Smart Images

Figure CN116260717B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of elevators and relates to elevator control technology, in particular to an elevator outbound call firmware upgrade system and method. Background Art
[0002] In the elevator industry, outbound call nodes, as the primary interface for human-machine interaction, need to meet diverse functional requirements. In particular, some special occasions require customized development based on actual usage. However, elevator manufacturers prioritize standardized production and improved efficiency, leading to a conflict between the two. Therefore, manufacturers currently typically employ non-standard product processing procedures. When standardized products require non-standard software upgrades, or when batch issues arise due to manufacturing issues, outbound call node software updates and repairs are necessary.
[0003] When an update requirement similar to the above occurs, the current method generally adopts the method of removing the outbound call node box and upgrading the software of each outbound call node. First, this method requires a large amount of manpower and material resources and is very inefficient. Second, the process of removing the outbound call node box and restoring it is very likely to damage the aesthetics of the original facilities, leading to customer complaints and other situations.
[0004] To this end, the present invention proposes an elevator outbound call firmware upgrade system and method. Summary of the Invention
[0005] The purpose of this application is to provide an elevator outbound call firmware upgrade system and method. While fully considering reliability, this system aims to improve the efficiency and convenience of outbound call node firmware upgrades. Based on the existing elevator control system, this system achieves group upgrades of outbound call node firmware without disassembling or installing system node facilities, significantly saving labor and time costs.
[0006] To achieve the above objectives, the present application provides a method for upgrading elevator outbound call firmware, comprising the following steps:
[0007] The handheld device is connected to the elevator outbound call node bus, and after passing the device authentication, it obtains the outbound call node information and sends a system silent request;
[0008] Check whether all bus devices have entered silent mode. After confirming that all devices except outbound call nodes on the bus have entered silent mode, send the firmware upgrade command.
[0009] Check whether all outbound nodes have entered the firmware upgrade state. If all outbound nodes have entered the firmware upgrade state, broadcast the firmware upgrade package in sequence.
[0010] After the firmware upgrade package is broadcasted, the integrity check of the firmware package is performed on each outbound node. If any firmware upgrade package is found to be missing, all missing firmware packages of the outbound node are resent.
[0011] If the above integrity check passes, an exit command is sent to the outbound node. After receiving the command, the outbound node writes the user program segment integrity flag into an independent storage location and exits the firmware upgrade state.
[0012] Preferably, the step of sending a system silence request includes:
[0013] Step E1: The handheld device sends a system silence request command frame to the control system mainboard, where the system silence request command frame includes a four-byte random data (R_D0);
[0014] Step E2: After receiving the data, the system mainboard returns three groups of four-byte data (A1, A2, A3). The data is read by the system mainboard from three fixed positions in the code book;
[0015] Step E3: After receiving the three sets of data, the handheld device performs basic operations on each of them with the data R_D0, wherein A1 is XORed with R_D0 to obtain A11, A2 is ORed with R_D0 to obtain A21, and A3 is ANDed with R_D0 to obtain A31;
[0016] Step E4: After the handheld device completes the calculation, it sends A11, A21, and A31 to the system mainboard for confirmation. If the system mainboard's calculation results are consistent with the above method, the system mainboard broadcasts the system silent command three times. At this time, all nodes on the system bus enter silent mode.
[0017] Preferably, the codebook supports remote updating.
[0018] Preferably, the handheld device sends three frames of associated four-byte data D1, D2, and D3 three times in sequence. Each outbound call node starts timing when it receives the first frame command request. If the above data content is received continuously within 5 seconds and meets the calculation rules, it enters the firmware upgrade state and erases all user program segments and user program segment integrity flags.
[0019] Preferably, if all outbound call nodes fail to enter the state for three consecutive times, the firmware upgrade is exited and an abnormal result is displayed.
[0020] Preferably, the firmware upgrade package includes a segment number and a data content correctness check field. When each outbound call node is in the firmware upgrade state and receives a correct data packet, it erases the user flash and writes the upgrade data to the corresponding address in sequence according to the data packet segment number.
[0021] Preferably, after the integrity check of all outbound call nodes is completed, if there is a situation where the upgrade package of an individual outbound call node is missing, the handheld device performs a firmware upgrade on the outbound call node of the specified outbound call node;
[0022] At this time, other outbound nodes no longer participate in the firmware update, and the firmware update is performed between the designated outbound node and the handheld device using a question-and-answer method or a broadcast method.
[0023] An elevator outbound call firmware upgrade system includes a handheld device, an elevator outbound call node bus, a control system mainboard, and several outbound call nodes;
[0024] The handheld device is connected to the elevator outbound call node bus and is used to obtain outbound call node distribution information after passing device authentication;
[0025] The elevator outbound call node bus is connected to the control system mainboard and is used to receive a system silence request sent by a handheld device;
[0026] The control system mainboard is used to control all devices except the outbound call node to enter the silent mode and then send a firmware upgrade command;
[0027] All outbound call nodes enter the firmware upgrade state and perform firmware upgrade.
[0028] Compared with the prior art, the present invention has the following beneficial effects:
[0029] The present invention is connected to the communication bus of the outbound call through a handheld device. After the handheld device sends an outbound call upgrade command request, all nodes of the elevator control system enter the silent mode. Then the handheld device requests the control system for outbound call distribution information. The handheld device broadcasts and issues the outbound call upgrade command. After all outbound call nodes receive and verify that it is correct, they enter the firmware upgrade state and wait for the next command. In addition, the handheld device starts to poll all outbound call nodes to see whether they have entered the firmware upgrade state. After the check is completed, the firmware upgrade package is started to be broadcast. Finally, the integrity of the firmware package is confirmed for all outbound call nodes involved in the upgrade. The present invention realizes batch upgrade of the firmware of all outbound calls through the existing outbound call bus of the elevator control system without damaging or disassembling the outbound call device. BRIEF DESCRIPTION OF THE DRAWINGS
[0030] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the prior art and the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0031] Figure 1 This is a schematic diagram of electrical connections for an elevator outbound call firmware upgrade system according to the present invention;
[0032] Figure 2 This is a logic diagram of the elevator outbound call firmware upgrade method of the present invention;
[0033] Figure 3 This is a flow chart of the outbound call node firmware upgrade process during power-off and transmission resumption according to the present invention. DETAILED DESCRIPTION
[0034] To make the purpose, technical solutions, and advantages of the embodiments of this application more clear, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the drawings in the embodiments of this application. Obviously, the described embodiments are part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0035] Please refer to the Figure 1 , is an electrical connection diagram of an elevator outbound call firmware upgrade system proposed by the present invention, such as Figure 1 As shown, the handheld device is connected to the elevator outbound call node bus, and after passing the device authentication, the outbound call node distribution information is obtained;
[0036] This step is mainly used to confirm the outbound call nodes mounted on the system, such as the node confirmation of the front and back doors, node filtering of the non-stop layer, and the online status confirmation of the outbound call nodes;
[0037] It should be noted that this information should also include the version information of the software and hardware of the outbound call node, which is used to handle MCU compatibility issues, such as whether the Flash capacity supports the current firmware upgrade; since the elevator outbound call node bus connected to the control system is also connected to devices such as the car board, car top board, and main control board, in order to improve the stability and speed of bus-based firmware upgrades, it is necessary to put system nodes other than the outbound call node into silent mode, and send a system silent request through a handheld device. The devices on the entire elevator outbound call node bus enter a master-slave communication mode (question-and-answer mode), and only respond when the handheld device inquires the designated node.
[0038] like Figure 2 FIG. 1 is a logic diagram of a method for upgrading elevator outbound call firmware proposed by the present invention. The method for upgrading elevator outbound call firmware mainly includes the following steps:
[0039] Step 1: The handheld device is connected to the elevator outbound call node bus. After passing the device authentication, it obtains the outbound call node related information and sends a system silent request.
[0040] In this application, the steps of sending a system silent request include:
[0041] Step E1: The handheld device sends a system silence request command frame to the control system mainboard, where the system silence request command frame includes a four-byte random data (R_D0);
[0042] Step E2: After receiving the data, the system motherboard returns three groups of four-byte data (A1, A2, A3). The data is read by the system motherboard from three fixed positions in the code book. The code book supports remote update.
[0043] Step E3: After receiving the three sets of data, the handheld device performs basic operations on each of them with the data R_D0, wherein A1 is XORed with R_D0 to obtain A11, A2 is ORed with R_D0 to obtain A21, and A3 is ANDed with R_D0 to obtain A31;
[0044] Step E4: After the handheld device completes the calculation, it sends A11, A21, and A31 to the system mainboard for confirmation. If the system mainboard's calculation results are consistent with the above method, the system mainboard broadcasts the system silent command three times. At this time, all nodes on the system bus enter silent mode.
[0045] It should be noted that the system mainboard's dwell time on R_D0 is only 5 seconds, so the above process needs to be completed within 5 seconds.
[0046] Step 2: Check whether all bus devices have entered silent mode. After confirming that all devices on the bus except the outbound call nodes have entered silent mode, send the firmware upgrade command;
[0047] This command must be completed within 5 seconds, otherwise the outbound node will not respond to the upgrade command;
[0048] In this application, the handheld device sends three frames of associated four-byte data D1, D2, and D3 three times in a row, where D3 = D1 + D2, D2 = D1^0x5A5A5A5A, and D1 = R_D0;
[0049] Each outbound call node starts timing when it receives the first frame command request. If it receives the above data content continuously within 5 seconds and meets the above calculation rules, it enters the firmware upgrade state and erases all user program segments and user program segment integrity flags;
[0050] Otherwise, you cannot enter the firmware upgrade state;
[0051] Step 3: Check whether all outbound nodes have entered the firmware upgrade state. If all outbound nodes have entered the firmware upgrade state, broadcast the firmware upgrade package in sequence. Otherwise, repeat step 2. If all outbound nodes have not entered the state for three consecutive times, exit the firmware upgrade and display the abnormal result.
[0052] In this application, the firmware upgrade package should contain a segment number and data content correctness check field. When each outbound call node is in the firmware upgrade state and receives the correct data packet, it will erase the user flash and write the upgrade data to the corresponding address in sequence according to the data packet segment number.
[0053] Step 4: After the firmware upgrade package is broadcast, the firmware package integrity check is performed on each outbound node (W1-Wn). If a firmware upgrade package is missing, all missing firmware packages of the outbound node are resent. If the firmware package integrity check fails three times in a row, the integrity check is jumped to the next outbound node;
[0054] Step 5: If the above integrity check passes, an exit command is sent to the outbound node. After receiving the command, the outbound node writes the user program segment integrity flag into an independent storage location and exits the firmware upgrade state.
[0055] It should be noted that after the integrity check of all outbound call nodes is completed, if there is a situation where the upgrade package of an individual outbound call node is missing, the handheld device can perform a firmware upgrade for the outbound call node of the specified outbound call node; at this time, other outbound call nodes will no longer participate in the firmware update, and the firmware update will be performed between the specified outbound call node and the handheld device using a question-and-answer method or a broadcast method.
[0056] Among them, the outbound call node in the system performs an integrity check on the user program segment every time it is powered on. If the calculation result is not synchronized with the stored integrity flag, the outbound call node remains in the firmware upgrade state and cannot jump to the user program segment to run.
[0057] When the outbound call node is in the firmware upgrade state, characteristic characters need to be displayed to distinguish the normal use state.
[0058] like Figure 3 As shown, when the handheld device of the present invention performs a firmware upgrade on an outbound call node, it records the segment number of the successfully issued program package. If a power outage occurs during the upgrade process, the firmware upgrade can be continued after the power is restored. The steps are as follows:
[0059] After power is restored, the user segment program integrity check fails after each outbound call node is powered on, and only the boot program segment is run, which is in the firmware upgrade state.
[0060] The handheld device continues to send the remaining firmware packages according to the stored package sending records.
[0061] After all firmware packages are sent, perform a complete verification of the user segment program.
[0062] The above formulas are all calculated by removing dimensions and taking their numerical values. The formula is a formula that is closest to the actual situation obtained by collecting a large amount of data and performing software simulation. The preset parameters and preset thresholds in the formula are set by technicians in this field according to actual conditions or obtained by simulating a large amount of data.
[0063] It should also be noted that, in this specification, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of additional identical elements in the process, method, article, or apparatus comprising the element.
[0064] The above description of the disclosed embodiments is intended to enable one skilled in the art to implement or use the present application. Various modifications to these embodiments will be readily apparent to one skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application is not limited to the embodiments shown herein, but is intended to conform to the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A method for upgrading elevator outbound call firmware, characterized in that: The following steps are involved: The handheld device is connected to the elevator outbound call node bus, and after passing the device authentication, it obtains the outbound call node information and sends a system silent request; Check whether all bus devices have entered silent mode. After confirming that all devices except outbound call nodes on the bus have entered silent mode, send the firmware upgrade command. Check whether all outbound nodes have entered the firmware upgrade state. If all outbound nodes have entered the firmware upgrade state, broadcast the firmware upgrade package in sequence. After the firmware upgrade package is broadcasted, the integrity check of the firmware package is performed on each outbound node. If any firmware upgrade package is found to be missing, all missing firmware packages of the outbound node are resent. If the above integrity check passes, an exit command is sent to the outbound node. After receiving the command, the outbound node writes the user program segment integrity flag to an independent storage location and exits the firmware upgrade state. The steps for sending a system quiesce request include: The handheld device sends a system silence request command frame to the control system mainboard. The system silence request command frame includes a four-byte random data R_D0; After receiving the data, the control system main board returns three groups of four-byte data (A1, A2, A3), which are read by the system main board from three fixed positions in the code book; After receiving the three sets of data, the handheld device performs basic operations with the data R_D0 respectively. A1 and R_D0 perform an XOR operation to obtain A11, A2 and R_D0 perform an OR operation to obtain A21, and A3 and R_D0 perform an AND operation to obtain A31. After the handheld device completes the calculation, it sends A11, A21, and A31 to the system motherboard for confirmation. If the system motherboard's calculation results are consistent with the above method, the system motherboard broadcasts the system silent command three times. At this time, all nodes on the system bus enter silent mode.
2. The elevator outbound call firmware upgrade method according to claim 1, characterized in that: The password book supports remote update.
3. The elevator outbound call firmware upgrade method according to claim 2, characterized in that: The handheld device sends three frames of associated four-byte data D1, D2, and D3 three times in sequence. Each outbound call node starts timing when it receives the first frame command request. If the above data content is received continuously within 5 seconds and meets the calculation rules, it enters the firmware upgrade state and erases all user program segments and user program segment integrity flags.
4. The elevator outbound call firmware upgrade method according to claim 3, characterized in that: If all outbound call nodes fail to enter the status for three consecutive times, the firmware upgrade will be exited and abnormal results will be displayed.
5. The elevator outbound call firmware upgrade method according to claim 4, characterized in that: The firmware upgrade package contains the segment number and data content correctness check field. When each outbound node is in the firmware upgrade state and receives the correct data packet, it erases the user flash and writes the upgrade data to the corresponding address in sequence according to the data packet segment number.
6. The elevator outbound call firmware upgrade method according to claim 5, characterized in that: After the integrity check of all outbound call nodes is completed, if there is a situation where the upgrade package of some outbound call nodes is missing, the handheld device will upgrade the firmware of the outbound call node of the specified outbound call node; At this time, other outbound nodes no longer participate in the firmware update, and the firmware update is performed between the designated outbound node and the handheld device using a question-and-answer method or a broadcast method.
7. An elevator outbound call firmware upgrade system, used to run an elevator outbound call firmware upgrade method according to any one of claims 1 to 6, characterized in that: Including handheld devices, elevator outbound call node bus, control system mainboard and several outbound call nodes; The handheld device is connected to the elevator outbound call node bus and is used to obtain outbound call node distribution information after passing device authentication; The elevator outbound call node bus is connected to the control system mainboard and is used to receive a system silence request sent by a handheld device; The control system mainboard is used to control all devices except the outbound call node to enter the silent mode and then send a firmware upgrade command; All outbound call nodes enter the firmware upgrade state and perform firmware upgrade.
Citation Information
Patent Citations
Elevator control system program upgrading method, elevator control system and elevator device
CN109189461A