Elevator safety control device and elevator safety control system
By using multiple safety control devices to connect to the network in the elevator, self- and agency safety control in abnormal situations is achieved, the problem of lowering the elevator operation rate is solved, and the normal operation of the elevator is ensured.
Patent Information
- Application Number
- CN202080107098.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-11-20
- Publication Date
- 2025-08-26
- Estimated Expiration
- 2040-11-20
AI Technical Summary
When an abnormality occurs in the elevator, the prior art cannot effectively maintain the operating rate, resulting in a decrease in the operating rate of the elevator.
Multiple security control devices are used to connect to the network, and self-safety control and agency security control are performed through the communication and processing unit to ensure that the elevator can still be effectively controlled under abnormal conditions.
Even if an abnormality occurs in the elevator, it can effectively suppress the reduction of the operation rate and ensure the normal operation of the elevator.
Smart Images

Figure CN116390890B_ABST
Abstract
Description
Technical Field
[0001] The invention relates to a safety control device for an elevator and a safety control system for an elevator. Background Art
[0002] Patent Document 1 discloses an example of a control method for an elevator with multiple cars. In this control method, each car detects an abnormality based on a check code communicated between them. When an abnormality is detected, a random car is moved to a parking position. The elevator then operates using the remaining cars in the car group that have not yet stopped.
[0003] Prior art literature
[0004] Patent Literature
[0005] Patent Document 1: Japanese Patent Application No. 2009-539726 Summary of the Invention
[0006] Problems to be solved by the invention
[0007] However, in the method of Patent Document 1, if an abnormality occurs in the device that performs safety control of the car, the elevator cannot continue to operate, and thus the operating rate of the elevator may decrease.
[0008] The present invention has been made to solve such a problem and provides a safety control device and a safety control system that can suppress a decrease in the operating rate even if an abnormality occurs in an elevator.
[0009] Means for solving problems
[0010] The safety control device of the elevator of the present invention is any safety control device among a plurality of safety control devices corresponding one-to-one to a plurality of cars in the elevator that are raised and lowered in the shaft, and is a safety control device corresponding to the first car among the plurality of cars and not corresponding to the second car among the plurality of cars under normal circumstances. The safety control device of the elevator comprises: a communication unit, which is connected to a network to which operation information is input from a plurality of nodes that respectively obtain operation information of at least any one of the plurality of cars, and communicates with other safety control devices corresponding to the second car through the network; an output unit, which outputs a first stop instruction for stopping the first car and a second stop instruction for stopping the second car; and a processing unit, which uses the operation information of the first car obtained through the communication unit to perform self-safety control of the first car to control the output of the first stop instruction of the output unit, and when an abnormality occurs in the other safety control device corresponding to the second car, uses the operation information of the second car obtained through the communication unit to perform alternative safety control of the second car to control the output of the second stop instruction of the output unit.
[0011] The safety control system of the elevator of the present invention comprises: a plurality of safety control devices, which correspond one-to-one to a plurality of elevator cars that are raised and lowered in a shaft of the elevator; a plurality of nodes, which respectively obtain operating information of at least any one of the plurality of elevator cars; and a network, to which operating information is input from each of the plurality of nodes. The plurality of safety control devices include: a first safety control device, which corresponds to a first car among the plurality of cars; and a second safety control device, which corresponds to a second car among the plurality of cars. The second safety control device comprises: a second communication unit, which is connected to the network and communicates with the first safety control device through the network; a second output unit, which outputs a second stop instruction for stopping the second car; and a second processing unit, which uses the operating information of the second car obtained through the second communication unit to perform a second processing on the second output unit. 2 stop instructions for self-safety control of the second car, and when an abnormality occurs in the second safety control device, the self-safety control of the second car is terminated. The first safety control device comprises: a first communication unit, which is connected to the network and communicates with the second safety control device through the network; a first output unit, which outputs the first stop instruction and the second stop instruction for stopping the first car; and a first processing unit, which uses the operation information of the first car obtained through the first communication unit to control the output of the first stop instruction of the first output unit for self-safety control of the first car, and when an abnormality occurs in the second safety control device, uses the operation information of the second car obtained through the first communication unit to control the output of the second stop instruction of the first output unit.
[0012] Effects of the Invention
[0013] According to the safety control device or the safety control system of the present invention, even if an abnormality occurs in an elevator, a decrease in the operating rate can be suppressed. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] Figure 1 This is a block diagram of an elevator according to the first embodiment.
[0015] Figure 2 This is a configuration diagram of the safety control system according to the first embodiment.
[0016] Figure 3 This is a sequence diagram showing an example of the operation of the safety control system according to the first embodiment.
[0017] Figure 4 This is a sequence diagram showing an example of the operation of the safety control system according to the first embodiment.
[0018] Figure 5 This is a sequence diagram showing an example of the operation of the safety control system according to the first embodiment.
[0019] Figure 6AThis is a diagram showing an example of allocation of processing resources in the safety control system according to the first embodiment.
[0020] Figure 6B This is a diagram showing an example of allocation of processing resources in the safety control system according to the first embodiment.
[0021] Figure 7A This is a diagram showing an example of setting a prohibited travel section in the safety control system according to the first embodiment.
[0022] Figure 7B This is a diagram showing an example of setting a prohibited travel section in the safety control system according to the first embodiment.
[0023] Figure 8 This is a flowchart showing an example of the operation of the safety control system according to the first embodiment.
[0024] Figure 9 This is a flowchart showing an example of the operation of the safety control system according to the first embodiment.
[0025] Figure 10 This is a hardware configuration diagram of the main parts of the safety control system according to the first embodiment. DETAILED DESCRIPTION
[0026] The embodiment for implementing the present invention will be described with reference to the accompanying drawings. In each figure, the same or corresponding parts are denoted by the same reference numerals, and repeated descriptions are appropriately simplified or omitted.
[0027] Implementation method 1.
[0028] Figure 1 This is a block diagram of the elevator 1 according to the first embodiment.
[0029] Elevator 1 is used in a building with multiple floors. A hoistway 2 for elevator 1 is located in the building. Hoistway 2 is a vertically long space spanning multiple floors. Hoistway 2 has a pit 3 at its bottom. Multiple landings 4 for elevator 1 are located in the building. Each landing 4 is located adjacent to hoistway 2 at any floor.
[0030] The elevator 1 includes a plurality of cars 5 , a plurality of landing doors 6 , a plurality of opening and closing detectors 7 , a plurality of position detectors 8 , maintenance equipment 9 , a network 10 , and a plurality of control panels 11 .
[0031] Each car 5 is a device that transports users between multiple floors by rising and falling in the vertical direction in the hoistway 2. Each car 5 is raised and lowered in the hoistway 2 by, for example, a traction machine not shown in the figure. In this example, multiple cars 5 are raised and lowered in the same hoistway 2. The multiple cars 5 that are raised and lowered in the same hoistway 2 are configured to overlap with each other in the horizontal projection plane. That is, the multiple cars 5 that are raised and lowered in the same hoistway 2 are respectively configured so that at least a portion of them overlap with each other when projected onto the horizontal plane passing through the hoistway 2. In this example, the elevator 1 is a double-car system in which two cars 5 are raised and lowered in the same hoistway 2. One of the two cars 5 that are raised and lowered in the same hoistway 2 is raised and lowered in the hoistway 2 at a position above the other car 5.
[0032] Each landing door 6 corresponds to an arbitrary floor. Each landing door 6 is provided at the landing 4 of the corresponding floor. Each landing door 6 divides the landing 4 from the shaft 2. Each landing door 6 is a device that opens and closes when an arbitrary car 5 stops adjacent to the corresponding floor so that users can get on and off the car 5.
[0033] Each opening / closing detector 7 corresponds to an arbitrary landing door 6. Each opening / closing detector 7 is provided at the corresponding landing door 6. Each opening / closing detector 7 is a device such as a door switch that detects the opening / closing of the corresponding landing door 6.
[0034] Each position detector 8 is provided in the hoistway 2. Each position detector 8 is a device for detecting the position of any car 5 among the plurality of cars 5. Each position detector 8 is, for example, a position switch that operates when any car 5 is at a corresponding position. Each position detector 8 is, for example, a position sensor that detects the position of any car 5 when the car 5 is within a detection range.
[0035] The maintenance device 9 is a device operated by a maintenance person when performing maintenance and inspection work. The maintenance device 9 is, for example, a pit switch installed in the pit 3. A plurality of maintenance devices 9 may be installed in the elevator 1.
[0036] The network 10 is a communication network used to communicate information within the elevator 1. For example, the network 10 is a LAN (Local Area Network). The network 10 is composed of communication lines and communication equipment. The network 10 can be wired, wireless, or a combination of wired and wireless. The network 10 is not limited to a specific topology. Highly reliable communication is performed within the network 10, accompanied by error detection and other features.
[0037] The plurality of control panels 11 correspond one-to-one to the plurality of cars 5. The control panels 11 are devices for controlling the operation and the like of the corresponding cars 5. Each control panel 11 is connected to a network 10.
[0038] The elevator 1 includes a safety control system 12. The safety control system 12 includes a plurality of safety control devices 13, a plurality of door nodes 14, a plurality of hoistway nodes 15, a plurality of car nodes 16, and a maintenance node 17. The safety control system 12 includes a network 10 of the elevator 1.
[0039] The plurality of safety control devices 13 correspond one-to-one to the plurality of control panels 11. Each safety control device 13 is mounted on the corresponding control panel 11. Each safety control device 13 corresponds to the same car 5 as the car 5 corresponding to the control panel 11. Each safety control device 13 is connected to the network 10. Each safety control device 13 is a device that performs safety control, etc., for the corresponding car 5.
[0040] Each door node 14 corresponds to an arbitrary opening / closing detector 7. Each door node 14 is connected to the corresponding opening / closing detector 7. Each door node 14 obtains information on the opening / closing detection of the landing door 6 by the corresponding opening / closing detector 7. The opening / closing detection information of the landing door 6 is an example of operating information of each car 5. The operating information of the car 5 is information used for the operation of the car 5 or information that affects the operation of the car 5. Each door node 14 is an example of a node that obtains operating information of at least one car 5. Each door node 14 is connected to the network 10.
[0041] Each hoistway node 15 corresponds to an arbitrary position detector 8. Each hoistway node 15 is connected to the corresponding position detector 8. Each hoistway node 15 obtains information on the position detection of the car 5 performed by the corresponding position detector 8. The position detection information of the car 5 is an example of operating information of the car 5. Each hoistway node 15 is an example of a node that obtains operating information of at least any one car 5. Each hoistway node 15 is connected to the network 10.
[0042] Each car node 16 corresponds to an arbitrary car 5. Each car node 16 is set in the corresponding car 5. Each car node 16 is connected to the detection device set in the corresponding car 5. The detection device set in the car 5 is, for example, a position sensor that detects the position of the car 5, a speed sensor that detects the speed of the car 5, an acceleration sensor that detects the acceleration of the car 5, or a load sensor that detects the load of the car 5. The detection device set in the car 5 can also be a distance sensor that detects the distance between other cars 5 that are arranged to overlap with each other in the horizontal projection plane. In addition, a door switch is connected, which detects the opening and closing of the door of the car 5. Each car node 16 obtains detection information from the detection device set in the corresponding car 5. The information detected by the detection device set in the car 5 is an example of the operation information of the car 5. Each car node 16 is an example of a node that obtains the operation information of at least any one car 5. Each car node 16 is connected to the network 10.
[0043] The maintenance node 17 is connected to the maintenance device 9. When the maintenance device 9 is operated, the maintenance node 17 obtains information about the operation. The operation information of the maintenance device 9 is an example of operating information of each car 5. The maintenance node 17 is an example of a node that obtains operating information of at least one car 5. The maintenance node 17 is connected to the network 10. Furthermore, if multiple maintenance devices 9 are installed in the elevator 1, multiple maintenance nodes 17 corresponding to each maintenance device 9 may be provided.
[0044] Each node in the safety control system 12 may also play multiple roles as a node for obtaining operation information of at least one car 5. For example, any node may also have some or all of the functions of the door node 14, the hoistway node 15, the car node 16, and the maintenance node 17.
[0045] Figure 2 This is a configuration diagram of the safety control system 12 according to the first embodiment.
[0046] The safety control system 12 includes a plurality of individual safety circuits 18 and an overall safety circuit 19. The individual safety circuits 18 correspond one-to-one to the control panels 11. Each individual safety circuit 18 is mounted on, for example, the corresponding control panel 11. Each individual safety circuit 18 corresponds to the same car as the car 5 corresponding to the control panel 11. When each individual safety circuit 18 is disconnected, the power supply to the hoisting machine that raises and lowers the car 5 corresponding to the individual safety circuit 18 and the brake that brakes the hoisting machine are disconnected. In this case, the car 5 is brought to an emergency stop. The overall safety circuit 19 is mounted on, for example, at least one of the control panels 11. When the overall safety circuit 19 is disconnected, the power supply to all hoisting machines and brakes is disconnected. In this case, all cars 5 are brought to an emergency stop.
[0047] The safety control system 12 includes a plurality of travel control devices 20. The plurality of travel control devices 20 correspond one-to-one to the plurality of control panels 11. Each travel control device 20 is mounted on, for example, the corresponding control panel 11. Each travel control device 20 corresponds to the same car as the car 5 corresponding to the control panel 11. Each travel control device 20 is a device that controls the travel of the corresponding car 5. When a floor stop instruction is input, each travel control device 20 causes the corresponding car 5 to stop at an arbitrary floor. At this time, the car 5 stops at, for example, the nearest floor. Alternatively, when a floor is specified in the floor stop instruction, the car 5 may also stop at the specified floor.
[0048] Each safety control device 13 includes an input unit 21, a communication unit 22, a duplicated output unit 23, and a duplicated processing unit 24. Although not shown, the input unit 21 is also duplicated, and the signals input from each input unit 21 are compared by the processing unit 24. The duplicated output units 23 are configured to be identical to each other. The duplicated output units 23 are configured so that, for example, when a malfunction occurs in the output unit 23 of one operating party, the output unit 23 of the other party can be controlled. The duplicated processing units 24 are configured to be identical to each other. The duplicated processing units 24 are configured so that, for example, when a malfunction occurs in the processing unit 24 of one operating party, the processing unit 24 of the other party can be controlled.
[0049] The input unit 21 is a portion that receives information from equipment that is not connected to the safety control device 13 via the network 10. Equipment that inputs information to the input unit 21 of the safety control device 13 is, for example, an encoder or the like provided on a traction machine or speed governor that raises or lowers the car 5 corresponding to the safety control device 13. The information input to the input unit 21 of the safety control device 13 is, for example, operational information about the car 5 corresponding to the safety control device 13.
[0050] The communication unit 22 communicates with devices connected to the safety controller 13 via the network 10. The communication unit 22 receives operating information from each node. The communication unit 22 of a safety controller 13 receives operating information from other safety controllers 13 via the input unit 21 and the communication unit 22. The communication unit 22 of a safety controller 13 transmits the operating information received via the input unit 21 and the communication unit 22 to the other safety controllers 13. The communication unit 22 of each safety controller 13 communicates information indicating the status of the safety controller 13 with other safety controllers 13.
[0051] The output unit 23 is a portion that outputs a stop command for stopping at least any one of the plurality of cars 5. The output unit 23 includes an emergency stop unit 25 and a floor stop unit 26.
[0052] The emergency stop unit 25 is a portion that outputs an emergency stop command, which is a stop command for causing an emergency stop of any of the cars 5. The emergency stop unit 25 is connected to each of the individual safety circuits 18 and the overall safety circuit 19. By outputting the emergency stop command, the emergency stop unit 25 disconnects the individual safety circuits 18 or the overall safety circuit 19, for example, using a relay. Alternatively, the emergency stop command output by the emergency stop unit 25 may be, for example, an STO (Safe Torque Off) or SBC (Safe Brake Control) signal that disconnects the power supply to the hoisting machine that raises or lowers any of the cars 5 and the brake that brakes the hoisting machine.
[0053] The floor stop unit 26 is a portion that outputs a floor stop command, which is a stop command for causing the car 5 to stop at a certain floor. The floor stop unit 26 is connected to each of the travel control devices 20. The floor stop unit 26 outputs a floor stop command to the travel control unit corresponding to the car 5 to be stopped, thereby causing the car 5 to stop at a certain floor.
[0054] The processing unit 24 is a part that performs information processing in the safety control device 13. The information processing performed in the processing unit 24 includes communication processing, safety control processing, substrate diagnostic processing, and allowed delay processing. Communication processing is processing for communication between the safety control device 13 and external devices. Safety control processing is processing related to safety control such as output control of the stop instruction of the stop unit. Substrate diagnostic processing is processing for diagnosing the status of the substrate including the processing unit 24. Substrate diagnostic processing includes, for example, memory checking or CPU core diagnosis (CPU: Central Processing Unit; Central Processing Unit) and other processing. Allowed delay processing is processing other than communication processing, safety control processing, and substrate diagnostic processing, and is processing that allows delay. Allowed delay processing includes, for example, recording and other processing.
[0055] The processing unit 24 of the safety controller 13 is equipped with a self-diagnostic function for the safety controller 13. Self-diagnosis of the safety controller 13 includes detecting abnormalities occurring within the safety controller 13. Self-diagnosis of the safety controller 13 may also include detecting communication abnormalities related to the safety controller 13. When the processing unit 24 of the safety controller 13 detects an abnormality through self-diagnosis, it transmits error information as status information of the safety controller 13 to other safety controllers 13 via the communication unit 22. When error information is transmitted as status information from another safety controller 13, the processing unit 24 determines that an abnormality has occurred in the other safety controller 13. Alternatively, when the processing unit 24 of the safety controller 13 detects an abnormality through self-diagnosis, it may cause the communication unit 22 to stop transmitting status information of the safety controller 13 to other safety controllers 13. In this case, if no status information is transmitted from another safety controller 13, the processing unit 24 determines that an abnormality has occurred in the other safety controller 13. Thus, even when another safety control device 13 stops abnormally irrelevant to the self-diagnosis, the processing unit 24 can determine that an abnormality has occurred in the other safety control device 13 .
[0056] In the safety control system 12, each node has components corresponding to part or all of the input unit 21, communication unit 22, and processing unit 24, similar to the safety control device 13. Each node can also perform self-diagnosis, similar to the safety control device 13. The processing unit 24 of each safety control device 13 detects abnormalities in each node based on, for example, error signals output as a result of self-diagnosis. Alternatively, the processing unit 24 of each safety control device 13 can detect abnormalities in each node based on, for example, the failure to transmit operating information. Furthermore, abnormalities in each node may include not only abnormalities occurring in the node itself but also abnormalities in devices connected to the node that obtain operating information.
[0057] Here, each safety control device 13 can also communicate with each other, for example, information about abnormalities determined to have occurred in the safety control device 13, information about devices connected to the safety control device 13, and part or all of the information about each device connected to each node collected by the safety control device 13, together with the status information of the safety control device 13.
[0058] Next, use Figure 3 An example of the operation of the safety control system 12 in normal times will be described.
[0059] Figure 3 This is a sequence diagram showing an example of the operation of the safety control system 12 according to the first embodiment.
[0060] In this example, the plurality of cars 5 include a car 5a and a car 5b. The plurality of control panels 11 include a control panel 11a and a control panel 11b. The control panel 11a corresponds to the car 5a. The control panel 11b corresponds to the car 5b. The plurality of safety control devices 13 include a safety control device 13a and a safety control device 13b. The safety control device 13a is mounted on the control panel 11a. The safety control device 13b is mounted on the control panel 11b. The plurality of car nodes 16 include a car node 16a and a car node 16b. The car node 16a is provided in the car 5a. The car node 16b is provided in the car 5b.
[0061] In this example, safety control system 12 has a multi-master architecture consisting of multiple hosts. A host is a device that obtains operational information from at least one node via network 10. In this example, each safety control device 13 is a host. Alternatively, multiple hosts can function as both master and slave. In this example, safety control device 13a is the main master. Safety control device 13b is the sub master.
[0062] The communication unit 22 of the safety control device 13a transmits information indicating the status of the safety control device 13a and operating information obtained through the input unit 21, etc., to the safety control device 13b. Based on the received information, the safety control device 13a determines that no abnormality has occurred in the safety control device 13b. At this point, the safety control device 13a continues its normal operation.
[0063] The communication unit 22 of the safety control device 13b transmits information indicating the status of the safety control device 13b and operating information obtained through the input unit 21, etc., to the safety control device 13a. Based on the received information, the safety control device 13b determines that no abnormality has occurred in the safety control device 13a. At this point, the safety control device 13b continues its normal operation.
[0064] The car node 16a sends the obtained operating information of the car 5a to the communication unit 22 of the safety control device 13a. The car node 16b sends the obtained operating information of the car 5b to the communication unit 22 of the safety control device 13b. Each door node 14 sends the obtained operating information to the communication unit 22 of the safety control device 13a, which serves as the master host. Each hoistway node 15 sends the obtained operating information to the communication unit 22 of the safety control device 13a, which serves as the master host. The maintenance node 17 sends the obtained operating information to the communication unit 22 of the safety control device 13a, which serves as the master host. The communication unit 22 of the safety control device 13a sends information including the operating information of the car 5b collected from each node to the communication unit 22 of the safety control device 13b.
[0065] The processing unit 24 of the safety control device 13a uses the operating information of the car 5a obtained through the input unit 21 and the communication unit 22 to perform self-safety control of the car 5a as safety control processing. Here, the self-safety control in the safety control device 13a is the safety control of the car 5a corresponding to the safety control device 13a itself. The safety control of the car 5a includes the output control of the stop signal for stopping the car 5a by the output unit 23. In the safety control of the car 5a, the stop signal for the car 5a is output, for example, when the car 5a approaches another car 5, when the car 5a is in an overspeed state, or when the car 5a is traveling with the car door 5a or the landing door 6 open. In addition, the safety control of the car 5a may also include the setting of a prohibited travel section for the car 5a. The prohibited travel section of the car 5a is a section in the hoistway 2 where the car 5a is not allowed to travel. Alternatively, when the maintenance equipment 9 has been operated, the safety control device 13a uses the output unit 23 to output a signal to stop all cars 5, prohibiting automatic travel in all sections, and then allowing the operation of the corresponding car 5 only through manual operation of the car 5 by the maintenance personnel.
[0066] The processing unit 24 of the safety control device 13b uses the operating information of the car 5b obtained through the input unit 21 and the communication unit 22 to perform self-safety control of the car 5b as a safety control process. Here, the self-safety control in the safety control device 13b is the safety control of the car 5b corresponding to the safety control device 13b itself. The safety control of the car 5b includes the output control of the stop signal for stopping the car 5b by the output unit 23. In the safety control of the car 5b, the stop signal for the car 5b is output, for example, when the car 5b approaches another car 5, when the car 5b is in an overspeed state, or when the car 5b is traveling with the car door 5b or the landing door 6 open. In addition, the safety control of the car 5b may also include the setting of a prohibited travel section for the car 5b. The prohibited travel section of the car 5b is a section in the hoistway 2 where the car 5b is not allowed to travel. Alternatively, when the maintenance equipment 9 has been operated, the safety control device 13b uses the output unit 23 to output a signal to stop all cars 5, prohibiting automatic travel in all sections, and then allowing the operation of the corresponding car 5 only through manual operation of the car 5 by the maintenance personnel.
[0067] Next, use Figure 4 and Figure 5 An example of the operation of the safety control system 12 when an abnormality occurs will be described.
[0068] Figure 4 and Figure 5 This is a sequence diagram showing an example of the operation of the safety control system 12 according to the first embodiment.
[0069] exist Figure 4 , an example is shown in which an abnormality occurs in the safety control device 13b serving as the slave.
[0070] The processing unit 24 of the safety control device 13a determines that an abnormality has occurred in the safety control device 13b based on the status information sent from the safety control device 13b. At this time, the processing unit 24 of the safety control device 13a determines whether it can perform safety control of the car 5b. For example, when the output unit 23 of the safety control device 13a cannot output a stop signal to stop the car 5b, the processing unit 24 of the safety control device 13a determines that it cannot perform safety control of the car 5b. For example, when the processing unit 24 of the safety control device 13a cannot ensure sufficient processing resources, the processing unit 24 of the safety control device 13a determines that it cannot perform safety control of the car 5b. For example, when the processing unit 24 of the safety control device 13a cannot obtain operating information such as the position and speed of the car 5b, the processing unit 24 of the safety control device 13a determines that it cannot perform safety control of the car 5b.
[0071] When the safety control of the car 5b can be performed on behalf of the car 5b, the processing unit 24 of the safety control device 13a performs the safety control of the car 5b as the safety control process. Here, the safety control of the car 5b performed by the safety control device 13a is the safety control of the car 5b that the safety control device 13a does not normally perform.
[0072] In this example, the safety control device 13a that performs safety control is an example of the first safety control device 13. The car 5 corresponding to the first safety control device 13 is the first car 5. The stop command for stopping the first car 5 is the first stop command. The input unit 21 of the first safety control device 13 is the first input unit 21. The communication unit 22 of the first safety control device 13 is the first communication unit 22. The output unit 23 of the first safety control device 13 is the first output unit 23. The processing unit 24 of the first safety control device 13 is the first processing unit 24. Furthermore, the safety control device 13b that performs safety control is an example of the second safety control device 13. The car 5 corresponding to the second safety control device 13 is the second car 5. The stop command for stopping the second car 5 is the second stop command. The input unit 21 of the second safety control device 13 is the second input unit 21. The communication unit 22 of the second safety control device 13 is the second communication unit 22. The output unit 23 of the second safety control device 13 is the second output unit 23. The processing unit 24 of the second safety control device 13 is the second processing unit 24.
[0073] When the communication unit 22 of the safety control device 13a starts acting as the safety control unit for the car 5b, it sends an acting notification to the communication unit 22 of the safety control device 13b. The communication unit 22 of the safety control device 13a then sends an instruction to the car node 16b of the car 5b corresponding to the safety control device 13b, instructing it to change the output destination of the operation information to the communication unit 22 of the safety control device 13a. Upon receiving the output destination change instruction, the car node 16b transmits the operation information of the car 5b to the communication unit 22 of the safety control device 13a.
[0074] The processing unit 24 of the safety control device 13a uses the operating information of the car 5a and the operating information of the car 5b obtained through the communication unit 22, etc. to perform both self-safety control of the car 5a and proxy safety control of the car 5b. Here, the operating information such as the position and speed of the car 5b is obtained, for example, by the position detector 8 installed in the hoistway 2 and the position sensor and speed sensor installed in the car 5b. The position of the car 5b can also be estimated based on the distance obtained by the distance sensor installed in the other car 5 arranged so as to overlap with the car 5b in the horizontal projection plane, which detects the distance between the car 5b and the car 5b.
[0075] If the processing unit 24 of the safety control device 13b detects an abnormality through self-diagnosis or the like, it stops the self-safety control of the car 5b and restarts it. The safety control device 13b may be restarted, for example, after the safety control device 13a starts acting as the safety control for the car 5b. Alternatively, the safety control device 13b may be restarted after the abnormality is detected, without waiting for the safety control device 13a to start acting as the safety control for the car 5b.
[0076] The processing unit 24 of the safety controller 13b performs self-diagnosis after restarting. If no abnormality is detected in the self-diagnosis, the communication unit 22 of the safety controller 13b transmits the self-diagnosis result to the communication unit 22 of the safety controller 13a as status information.
[0077] The communication unit 22 of the safety control device 13a, which has received the result of the self-diagnosis, transmits an alternate termination notification to the communication unit 22 of the safety control device 13b. Then, the safety control device 13a terminates the alternate safety control of the car 5b.
[0078] Upon receiving the notification of the termination of the proxy operation, the communication unit 22 of the safety control device 13b sends a command to the car node 16b of the car 5b corresponding to the safety control device 13b, instructing it to change the output destination of the operation information to the communication unit 22 of the safety control device 13b. Upon receiving the output destination change command, the car node 16b transmits the operation information of the car 5b to the communication unit 22 of the safety control device 13b. The processing unit 24 of the safety control device 13b resumes self-safety control of the car 5b. The safety control system 12 then returns to normal operation.
[0079] exist Figure 5 , an example is shown in which an abnormality occurs in the safety control device 13a serving as the master host.
[0080] The processing unit 24 of the safety control device 13b determines that an abnormality has occurred in the safety control device 13a based on the status information sent from the safety control device 13a. At this time, the processing unit 24 of the safety control device 13b determines whether it can take over the safety control of the car 5a.
[0081] When the safety control of the car 5a can be performed on behalf of the car 5a, the processing unit 24 of the safety control device 13b performs the safety control of the car 5a as the safety control processing. Here, the safety control of the car 5a performed by the safety control device 13b is the safety control of the car 5a that the safety control device 13b does not perform under normal circumstances.
[0082] In this example, the safety control device 13 b that performs safety control is an example of the first safety control device 13 . The safety control device 13 a that performs safety control is an example of the second safety control device 13 .
[0083] When the communication unit 22 of the safety control device 13b starts acting as the safety control unit for the car 5a, it sends an acting notification to the communication unit 22 of the safety control device 13a. The communication unit 22 of the safety control device 13b sends an instruction to the car node 16a of the car 5a corresponding to the safety control device 13a to change the output destination of the operating information to the communication unit 22 of the safety control device 13b. The car node 16a that has received the output destination change instruction sends the operating information of the car 5a to the communication unit 22 of the safety control device 13b. In addition, the communication unit 22 of the safety control device 13b sends an instruction to each node, such as the door node 14, the hoistway node 15, and the maintenance node 17, to change the output destination of the operating information to the communication unit 22 of the safety control device 13b. Each node that has received the output destination change instruction sends the acquired operating information to the communication unit 22 of the safety control device 13b.
[0084] The processing unit 24 of the safety control device 13b performs both self-safety control of the car 5b and proxy safety control of the car 5a using the operation information of the car 5a and the operation information of the car 5b acquired through the communication unit 22 or the like.
[0085] If the processing unit 24 of the safety control device 13a detects an abnormality through self-diagnosis or the like, it stops the self-safety control of the car 5b and restarts it. The safety control device 13a may be restarted, for example, after the safety control device 13b starts acting as the safety control for the car 5a. Alternatively, the safety control device 13a may be restarted after the abnormality is detected, without waiting for the safety control device 13b to start acting as the safety control for the car 5a.
[0086] The processing unit 24 of the safety controller 13a performs self-diagnosis after restarting. If no abnormality is detected in the self-diagnosis, the communication unit 22 of the safety controller 13a transmits the self-diagnosis result to the communication unit 22 of the safety controller 13b as status information.
[0087] The communication unit 22 of the safety control device 13b that has received the result of the self-diagnosis transmits an alternate termination notification to the communication unit 22 of the safety control device 13a. Then, the safety control device 13b terminates the alternate safety control of the car 5a.
[0088] The communication unit 22 of the safety control device 13a, which has received the notification of the termination of the proxy operation, sends an instruction to the car node 16a of the car 5a corresponding to the safety control device 13a, to change the output destination of the operation information to the communication unit 22 of the safety control device 13a. The car node 16a, which has received the instruction to change the output destination, sends the operation information of the car 5a to the communication unit 22 of the safety control device 13a. In addition, the communication unit 22 of the safety control device 13a sends an instruction to each node, such as the door node 14, the hoistway node 15, and the maintenance node 17, to change the output destination of the operation information to the communication unit 22 of the safety control device 13a. Each node that has received the instruction to change the output destination sends the obtained operation information to the communication unit 22 of the safety control device 13a. The processing unit 24 of the safety control device 13a resumes the self-safety control of the car 5a. Then, the safety control system 12 returns to normal operation.
[0089] Next, use Figure 6A and Figure 6B , an example of securing processing resources in the processing unit 24 of the safety control device 13 when performing substitute safety control will be described.
[0090] Figure 6A and Figure 6BThis is a diagram showing an example of allocation of processing resources in the safety control system 12 according to the first embodiment.
[0091] For example, when determining whether to perform safety control on behalf of the processing unit 24, the processing unit 24 calculates the remaining processing resources of the processing unit 24. For example, the processing unit 24 calculates the remaining processing resources as the ratio of the processing time obtained by adding the processing time allowed for delayed processing and the idle time. The processing unit 24 compares the calculated remaining processing resources with a pre-set threshold. Here, the threshold is set based on, for example, the amount of processing required to perform safety control on behalf of the safety control device 13. In addition, the threshold related to the performance of the safety control device 13 as a sub-host and the threshold related to the performance of the safety control device 13 as a master host can also be different values.
[0092] exist Figure 6A , an example is shown in which the remaining amount of processing resources in the processing unit 24 is larger than a threshold value.
[0093] For example, the processing unit 24 allocates part or all of its idle time to proxy security control processing. If the processing resources required for proxy security control are insufficient, the processing unit 24 suspends part or all of the permitted delay processing. The processing unit 24 allocates the processing resources freed up by suspending the permitted delay processing to proxy security control processing.
[0094] On the other hand, Figure 6B , an example is shown in which the remaining amount of processing resources in the processing unit 24 is smaller than a threshold value.
[0095] The processing unit 24 allocates idle time to the processing of proxy safety control. In the case where the processing resources required for proxy safety control are insufficient, the processing unit 24 suspends all allowed delayed processing. The processing unit 24 allocates the processing resources raised due to the suspension of allowed delayed processing to the processing of proxy safety control. In the case where the processing resources required for proxy safety control are still insufficient, the processing unit 24 reduces at least a part of the substrate diagnostic processing. For example, the processing unit 24 subdivides the processing for items that can be time-shared in the substrate diagnostic processing, reduces the diagnostic items in each cycle of the substrate diagnostic processing, and thus reduces the proportion of the substrate diagnostic processing in the processing resources. The processing unit 24 allocates the processing resources raised due to the reduction of the substrate diagnostic processing to the processing of proxy safety control.
[0096] Alternatively, the processing unit 24 may determine that the safety control cannot be performed if the processing time obtained by adding the processing time of the allowed delay processing and the substrate diagnosis processing and the idle time is insufficient for the processing resources required for performing the safety control.
[0097] Next, use Figure 7A and Figure 7B Another example of the operation of the safety control system 12 when an abnormality occurs will be described.
[0098] Figure 7A and Figure 7B This is a diagram showing an example of setting a prohibited travel section in the safety control system 12 according to the first embodiment.
[0099] Here, an example is shown in which an abnormality occurs in the car node 16 of the car 5 that is being raised or lowered in the same hoistway 2. When an abnormality occurs in the car node 16 of the upper car 5, the processing unit 24 of the safety control device 13 corresponding to the upper car 5 causes the output unit 23 to output a stop command to stop the upper car 5.
[0100] exist Figure 7A , an example is shown in which the upper car 5 stops at a position where any position detector 8 can detect the position.
[0101] The processing unit 24 of the safety control device 13 corresponding to the lower car 5 determines that an abnormality has occurred in the car node 16 based on information from the car node 16 of the upper car 5 or the safety control device 13 corresponding to the upper car 5. The communication unit 22 of the safety control device 13 corresponding to the lower car 5 obtains the stop position of the upper car 5 through the hoistway node 15. The processing unit 24 of the safety control device 13 corresponding to the lower car 5 sets the section including the stop position of the upper car 5 as the prohibited travel section of the lower car 5. When the upper car 5 is stopped at a parking position on any floor, the prohibited travel section of the lower car 5 is set to, for example, a section including only that floor.
[0102] In addition, when there is a car 5 in the elevator 1 that is traveling in a different shaft 2 from the stopped upper car 5, the processing unit 24 of the safety control device 13 corresponding to the car 5 may not set a prohibited travel section for the car 5.
[0103] Furthermore, when an abnormality occurs in any of the safety control devices 13 in the safety control system 12, a prohibited travel section can also be set in the same manner. For example, there is a case where, when an abnormality occurs in the safety control device 13 corresponding to the upper car 5, the processing unit 24 of the safety control device 13 stops the upper car 5. In this case, the processing unit 24 of the safety control device 13 corresponding to the lower car 5 determines that an abnormality has occurred in the safety control device 13 corresponding to the upper car 5. The communication unit 22 of the safety control device 13 corresponding to the lower car 5 obtains the stop position of the upper car 5 through the hoistway node 15. The processing unit 24 of the safety control device 13 corresponding to the lower car 5 sets the section including the stop position of the upper car 5 as the prohibited travel section of the lower car 5.
[0104] Furthermore, when the car 5 is stopped by a stop command, the safety control device 13 may specify a floor and stop the car 5. The specified floor is, for example, a floor whose position can be detected by any position detector 8.
[0105] On the other hand, Figure 7B , an example is shown in which the upper car 5 stops at a position where the position detector 8 cannot detect the position.
[0106] In this case, the processing unit 24 of the safety control device 13 corresponding to the lower car 5 estimates the stopped position of the upper car 5 based on operational information such as the position and speed of the car 5 obtained immediately before the abnormality occurred. The processing unit 24 of the safety control device 13 corresponding to the lower car 5 sets the section containing the estimated stopped position of the upper car 5 as the prohibited travel section for the lower car 5. The prohibited travel section set in this case is set to be larger than the prohibited travel section set when the upper car 5 stops at a position where the position detector 8 can detect its position. The prohibited travel section set in this case may also be a section that spans multiple floors.
[0107] Next, use Figure 8 and Figure 9 An operation example of the safety control system 12 will be described.
[0108] Figure 8 and Figure 9 This is a flowchart showing an example of the operation of the safety control system 12 according to the first embodiment.
[0109] exist Figure 8In step S01, the processing unit 24 of each safety control device 13 determines whether an abnormality has occurred. If it is determined that an abnormality has occurred in any safety control device 13 based on the information from the node, the operation of the safety control system 12 proceeds to step S02. If it is determined that an abnormality has occurred in any safety control device 13, the operation of the safety control system 12 proceeds to step S03. Figure 9 If it is determined that no abnormality has occurred, the operation of the safety control system 12 proceeds to step S01 again.
[0110] In step S02, the processing unit 24 of the safety control device 13, which has determined based on information from the node that an abnormality has occurred, determines in which node the event occurred. If the event is determined to be an abnormality at the door node 14, the operation of the safety control system 12 proceeds to step S03. If the event is determined to be an abnormality at the hoistway node 15, the operation of the safety control system 12 proceeds to step S04. If the event is determined to be an abnormality at the car node 16, the operation of the safety control system 12 proceeds to step S05. If the event is determined to be an abnormality at the maintenance node 17, the operation of the safety control system 12 proceeds to step S07.
[0111] In step S03, the processing unit 24 of each safety control device 13 sets a prohibited travel section for the corresponding car 5 for the landing door 6 provided with the opening and closing detector 7 corresponding to the door node 14 in which an abnormality is detected. The prohibited travel section set at this time includes the position where the landing door 6 passes on the shaft 2 side. Here, the safety control device 13 corresponding to the car 5 that may pass through the set prohibited travel section outputs a stop command to stop the car 5. In addition, the processing unit 24 of the safety control device 13 on the shaft 2 side where the corresponding car 5 does not pass through the landing door 6 may not set a prohibited travel section for the car 5. Then, the operation of the safety control system 12 enters step S09.
[0112] In step S04, the processing unit 24 of each safety control device 13 sets a prohibited travel section for the corresponding car 5 for the position detector 8 corresponding to the hoistway node 15 where an abnormality has been detected. The prohibited travel section set at this time includes the position where the position detector 8 is installed. Here, the safety control device 13 corresponding to the car 5 that may pass through the set prohibited travel section outputs a stop command to stop the car 5. In addition, the processing unit 24 of the safety control device 13 for the corresponding car 5 that does not pass through the position of the position detector 8 may not set a prohibited travel section for the car 5. Then, the operation of the safety control system 12 enters step S09.
[0113] In step S05, the safety control device 13 corresponding to the car 5 provided with the car node 16 where the abnormality is detected outputs a stop command to stop the car 5. Then, the operation of the safety control system 12 proceeds to step S06.
[0114] In step S06, the processing unit 24 of the safety control device 13 corresponding to the car 5 other than the car 5 in which the abnormality is detected is installed sets a prohibited travel section for the corresponding car 5. The prohibited travel section set in this case includes the stopped position of the car 5 that has stopped in response to the stop signal. The processing unit 24 of the safety control device 13 corresponding to the other car 5 that does not overlap with the stopped car 5 in the horizontal projection plane does not need to set a prohibited travel section for the other car 5. The operation of the safety control system 12 then proceeds to step S09.
[0115] In step S07, at least one of the safety control devices 13 outputs a stop command to stop all the cars 5. The stop command output here may be, for example, an emergency stop command to the entire safety circuit 19. Then, the operation of the safety control system 12 proceeds to step S08.
[0116] In step S08, the processing unit 24 of each safety control device 13 sets the prohibited travel section of the corresponding car 5. The prohibited travel section set at this time is the entire section in the hoistway 2. In addition, the prohibited travel section of the car 5 set here is the section in the hoistway 2 where automatic travel of the car 5 is prohibited. Then, the operation of the safety control system 12 proceeds to step S09.
[0117] In step S09, the node in which the abnormality is detected performs restart and self-diagnosis. Then, the operation of the safety control system 12 proceeds to step S10.
[0118] In step S10, the node that performed self-diagnosis determines whether an abnormality was detected during the self-diagnosis. If no abnormality was detected, the operation of the safety control system 12 proceeds to step S11. If an abnormality was detected, the operation of the safety control system 12 ends after, for example, notifying the elevator 1 maintenance company.
[0119] In step S11, the processing unit 24 of each safety control device 13 cancels the set prohibited travel zone. The processing unit 24 of each safety control device 13 returns to normal operation. Then, the operation of the safety control system 12 proceeds to step S01.
[0120] exist Figure 9In step S12, it is determined whether there is another safety control device 13 that can output the stop command of the car 5 corresponding to the safety control device 13 that has experienced an abnormality from the output unit 23. This determination is performed, for example, by each safety control device 13 that has determined that the other safety control device 13 is abnormal determines whether it can output the stop command for the safety control device 13 itself. If there is a safety control device 13 that can output the stop command, the operation of the safety control system 12 proceeds to step S13. If there is no safety control device 13 that can output the stop command, the operation of the safety control system 12 proceeds to step S22.
[0121] In step S13, the safety control device 13, which can replace the output of the stop command to the car 5 corresponding to the safety control device 13 in which the abnormality has occurred, determines whether it can obtain the operating information required for the replacement of safety control, such as the position and speed of the car 5. If the required operating information can be obtained, the operation of the safety control system 12 proceeds to step S14. If the required operating information cannot be obtained, the operation of the safety control system 12 proceeds to step S18.
[0122] In step S14, the safety control device 13 that can obtain the necessary operating information performs safety control of the car 5 corresponding to the safety control device 13 that has experienced the abnormality. As a result, the elevator 1 continues to operate. Then, the operation of the safety control system 12 proceeds to step S15.
[0123] In step S15, the safety control device 13 in which an abnormality has occurred performs restart and self-diagnosis. Then, the operation of the safety control system 12 proceeds to step S16.
[0124] In step S16, the safety control device 13 that has performed self-diagnosis determines whether an abnormality is detected in the self-diagnosis. If no abnormality is detected, the operation of the safety control system 12 proceeds to step S17. If an abnormality is detected, the safety control system 12 notifies the elevator 1 maintenance company, etc., for example. Then, the operation of the safety control system 12 proceeds to step S17 while the safety control device 13 that is performing the substitute safety control continues to perform the substitute safety control. Figure 8 At this time, since the elevator 1 is performing fallback operation without any of the safety control devices 13 being actuated, it is preferable to perform early maintenance work such as equipment replacement in the elevator 1 .
[0125] In step S17, the safety control device 13 that is currently performing the substitute safety control ends the substitute safety control. The safety control device 13 that has experienced the abnormality restarts the safety control of the corresponding car 5. Then, the operation of the safety control system 12 enters Figure 8 Step S01.
[0126] In step S18, the safety control device 13, which can output a stop command for the car 5 corresponding to the abnormality, stops the car 5 at a floor where the position detector 8 can detect the position of the car 5. Then, the operation of the safety control system 12 proceeds to step S19.
[0127] In step S19, the safety control device 13 in which an abnormality has occurred performs restart and self-diagnosis. Then, the operation of the safety control system 12 proceeds to step S20.
[0128] In step S20, the safety control device 13 that has performed self-diagnosis determines whether an abnormality is detected in the self-diagnosis. If no abnormality is detected, the operation of the safety control system 12 proceeds to step S21. If an abnormality is detected, the operation of the safety control system 12 proceeds to step S23.
[0129] In step S21, the safety control device 13 that has been performing the output of the stop command ends the output of the stop command. The safety control device 13 that has experienced the abnormality restarts the safety control of the corresponding car 5. Then, the operation of the safety control system 12 enters Figure 8 Step S01.
[0130] In step S22, the safety control device 13 that has detected the occurrence of the abnormality outputs a stop command to stop the car 5. Then, the operation of the safety control system 12 proceeds to step S23.
[0131] In step S23, the processing unit 24 of the safety control device 13 other than the safety control device 13 that has detected the occurrence of the abnormality sets a prohibited travel section for the corresponding car 5. The prohibited travel section set in this case includes the stopped position of the car 5 that has stopped in response to the stop signal. The processing unit 24 of the safety control device 13 corresponding to another car 5 that does not overlap with the stopped car 5 in the horizontal projection plane may not set a prohibited travel section for the other car 5. The operation of the safety control system 12 then terminates, for example, after notifying the elevator 1 maintenance company or the like.
[0132] Alternatively, the safety control system 12 may have a single-host architecture, consisting of a single host. In this case, operational information from each node is distributed to other safety control devices 13 via the master safety control device 13. Furthermore, in a single-host architecture, the master safety control device 13 may be switchable. Alternatively, if an abnormality occurs in the master safety control device 13, another safety control device 13 may be switched to become the master. This other safety control device 13 then performs safety control and collects and distributes operational information on behalf of the previously master safety control device 13.
[0133] Furthermore, the elevator 1 may be a multi-car system in which three or more cars 5 are raised and lowered in the same hoistway 2. Furthermore, the elevator 1 may be an elevator 1 in which the multiple cars 5 are arranged so that none of the cars 5 overlap each other in a horizontal projection plane. In this case, the elevator 1 may also be equipped with a group management device for managing call allocation, etc. Furthermore, when a building is equipped with multiple double-car or multi-car elevators 1, the safety control system 12 may be applied individually to each double-car or multi-car elevator 1.
[0134] As described above, the safety control system 12 of embodiment 1 includes a plurality of safety control devices 13, a plurality of nodes, and a network 10. The plurality of safety control devices 13 correspond one-to-one to the plurality of cars 5. Each node obtains the operating information of at least any one of the cars 5. The operating information is input from each node to the network 10. The plurality of safety control devices 13 include a first safety control device 13 and a second safety control device 13. The first safety control device 13 corresponds to the first car 5 among the plurality of cars 5. The second safety control device 13 corresponds to the second car 5 among the plurality of cars 5. The second safety control device 13 includes a second communication unit 22, a second output unit 23, and a second processing unit 24. The second communication unit 22 is connected to the network 10. The second communication unit 22 communicates with the first safety control device 13 via the network 10. The second output unit 23 outputs a second stop instruction. The second stop instruction is an instruction to stop the second car 5. The second processing unit 24 uses the operating information of the second car 5 obtained through the second communication unit 22 to perform self-safety control of the second car 5. The self-safety control of the second car 5 includes controlling the output of the second stop instruction by the second output unit 23. The second processing unit 24 terminates the self-safety control of the second car 5 when an abnormality occurs in the second safety control device 13. The first safety control device 13 includes a first communication unit 22, a first output unit 23, and a first processing unit 24. The first communication unit 22 is connected to the network 10. The first communication unit 22 communicates with the second safety control device 13 through the network 10. The first output unit 23 outputs a first stop instruction and a second stop instruction. The first stop instruction is an instruction to stop the first car 5. The first processing unit 24 uses the operating information of the first car 5 obtained through the first communication unit 22 to perform self-safety control of the first car 5. The self-safety control of the first car 5 includes controlling the output of the first stop instruction by the first output unit 23. When an abnormality occurs in the second safety control device 13, the first processing unit 24 performs alternative safety control of the second car 5 using the operating information of the second car 5 obtained through the first communication unit 22. The alternative safety control of the second car 5 includes control of the output of the second stop command by the second output unit 23.
[0135] Furthermore, the first car 5 and the second car 5 are arranged so as to overlap each other in the horizontal projection plane.
[0136] With such a structure, even if an abnormality occurs in the second safety control device 13 corresponding to the second car 5, the safety control of the second car 5 is performed in the first safety control device 13. Therefore, the elevator 1 can continue to operate. As a result, the operating rate of the elevator 1 is not easily reduced. In particular, when the first car 5 and the second car 5 are raised and lowered in the same shaft 2, the stop of the second car 5 will also affect the operation of the first car 5. In this way, the occurrence of chain effects on the operation can be suppressed, and thus the reduction in the operating rate of the elevator 1 can be more effectively suppressed. In addition, multiple safety control devices 13 obtain the operating information of each car 5 through the network 10. Therefore, there is no need to set up a separate communication line for each combination of the safety control device 13 and the node. As a result, the amount of wiring in the elevator 1 can be suppressed.
[0137] Furthermore, when performing the alternate safety control of the second car 5, the first processing unit 24 stops at least a part of the delay-permitting process of allowing the delay.
[0138] Furthermore, when performing the alternate safety control of the second car 5, the first processing unit 24 determines whether the ratio of the processing time obtained by adding the processing time allowed for delayed processing and the idle time to the processing resources is less than a preset threshold value. If it is determined that the ratio is less than the threshold value, the first processing unit 24 reduces at least a portion of the board diagnostic processing for diagnosing the status of the board including the first processing unit 24.
[0139] This structure prioritizes securing the processing resources required for proxy safety control. This prevents situations where proxy safety control cannot be performed due to insufficient processing resources. Consequently, elevator 1 is able to continue operating more frequently, making it less likely that the elevator's operating rate will decrease.
[0140] Furthermore, the second processing unit 24 performs self-diagnosis after an abnormality occurs in the second safety control device 13. If no abnormality is detected in the second safety control device 13 during the self-diagnosis, the second processing unit 24 resumes the self-safety control of the second car 5. If no abnormality is detected in the second safety control device 13 during the self-diagnosis, the first processing unit 24 ends the alternate safety control of the second car 5.
[0141] With such a configuration, the safety control system 12 is automatically restored. As a result, the elevator 1 can continue to operate more stably.
[0142] Furthermore, the plurality of nodes include a door node 14. The door node 14 is connected to an opening / closing detector 7. The opening / closing detector 7 detects the opening / closing of a landing door 6 at any floor. When an abnormality occurs in a door node 14, each safety control device 13 sets a section including the position of the landing door 6 where the opening / closing detector 7 connected to the door node 14 is installed as a prohibited travel section for the corresponding car 5.
[0143] In addition, the plurality of nodes include a hoistway node 15. The hoistway node 15 is connected to a position detector 8. The position detector 8 detects the position of at least one car 5 in the hoistway 2. When an abnormality occurs in the hoistway node 15, each safety control device 13 sets the section including the position of the position detector 8 connected to the hoistway node 15 as a prohibited travel section for the corresponding car 5.
[0144] The plurality of nodes include a car node 16. The car node 16 is provided in an arbitrary car 5. The car node 16 obtains operation information of the car 5. When an abnormality occurs in the car node 16, the safety control device 13 corresponding to the car 5 stops the corresponding car 5.
[0145] In addition, when an abnormality occurs in the car node 16, the safety control device 13 corresponding to other cars 5 that are configured to overlap with the car 5 in the horizontal projection plane sets the interval including the stop position of the car 5 where the car node 16 is installed as the prohibited travel interval of the corresponding car 5.
[0146] Furthermore, when an abnormality occurs in any of the safety control devices 13, the safety control device 13 in which the abnormality occurred stops the corresponding car 5. While the car 5 is stopped, the safety control devices 13 corresponding to the other cars 5 arranged so as to overlap with the car 5 in the horizontal projection plane set the section including the stopped position of the car 5 corresponding to the safety control device 13 in which the abnormality occurred as the prohibited travel section for the corresponding car 5.
[0147] With such a configuration, even when an abnormality occurs in each node or each safety control device 13, the operation of the elevator 1 can be continued within the operable range of the car 5. This makes it less likely that the convenience of the user will be reduced.
[0148] In addition, the plurality of nodes include a maintenance node 17. The maintenance node 17 is connected to the maintenance device 9. The maintenance device 9 is operated when performing maintenance inspections. When the maintenance device 9 is operated, each safety control device 13 sets all sections of the hoistway 2 as the automatically prohibited travel section of the corresponding car 5.
[0149] With such a configuration, when performing maintenance and inspection, the operation of the car 5 is stopped. This improves the safety of the work performed by the maintenance personnel performing maintenance and inspection in the hoistway 2 and the like.
[0150] Next, use Figure 10 An example of the hardware configuration of the safety control system 12 will be described.
[0151] Figure 10 This is a hardware configuration diagram of the main parts of the safety control system 12 according to the first embodiment.
[0152] The various functions of the safety control system 12 can be implemented by a processing circuit. The processing circuit includes at least one processor 100a and at least one memory 100b. The processing circuit includes the processor 100a, the memory 100b, and at least one dedicated hardware 200. Alternatively, the processing circuit may include at least one dedicated hardware 200 instead of the processor 100a and the memory 100b.
[0153] When the processing circuit includes a processor 100a and a memory 100b, the various functions of the safety control system 12 are implemented using software, firmware, or a combination of software and firmware. At least one of the software and firmware is described as a program. This program is stored in the memory 100b. The processor 100a implements the various functions of the safety control system 12 by reading and executing the program stored in the memory 100b.
[0154] The processor 100a is also known as a CPU, a processing device, an arithmetic device, a microprocessor, a microcomputer, or a DSP. The memory 100b is composed of, for example, nonvolatile or volatile semiconductor memory such as RAM (Random Access Memory), ROM (Read Only Memory), flash memory, EPROM (Erasable Programmable Read Only Memory), or EEPROM (Electrically Erasable Programmable Read Only Memory).
[0155] When the processing circuit includes dedicated hardware 200, the processing circuit is implemented by, for example, a single circuit, a complex circuit, a programmed processor, a parallel programmed processor, an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array), or a combination thereof.
[0156] Each function of the safety control system 12 can be implemented separately by the processing circuit. Alternatively, each function of the safety control system 12 can be implemented collectively by the processing circuit. Each function of the safety control system 12 can also be implemented partially by dedicated hardware 200 and partially by software or firmware. In this way, the processing circuit implements each function of the safety control system 12 through dedicated hardware 200, software, firmware, or a combination thereof.
[0157] Industrial applicability
[0158] The safety control system of the present invention can be applied to elevators. The safety control device of the present invention can be applied to the safety control system.
[0159] Description of labels
[0160] 1: Elevator; 2: Hoistway; 3: Pit; 4: Landing; 5, 5a, 5b: Car; 6: Landing door; 7: Opening and closing detector; 8: Position detector; 9: Maintenance equipment; 10: Network; 11, 11a, 11b: Control panel; 12: Safety control system; 13, 13a, 13b: Safety control device; 14: Door node; 15: Hoistway node; 16, 16a, 16b: Car node; 17: Maintenance node; 18: Individual safety circuit; 19: Overall safety circuit; 20: Travel control device; 21: Input unit; 22: Communication unit; 23: Output unit; 24: Processing unit; 25: Emergency stop unit; 26: Floor stop unit; 100a: Processor; 100b: Memory; 200: Special hardware.
Claims
1. A safety control device for an elevator, wherein: The elevator safety control device is any one of a plurality of safety control devices corresponding one-to-one to a plurality of cars in the elevator that ascend and descend in a hoistway, and is a safety control device corresponding to a first car among the plurality of cars and not corresponding to a second car among the plurality of cars under normal circumstances. The safety control device of the elevator has: a communication unit connected to a network to which operation information is input from a plurality of nodes that respectively obtain operation information of at least any one of the plurality of cars, and communicating with another safety control device corresponding to the second car via the network; an output unit that outputs a first stop instruction for stopping the first car and a second stop instruction for stopping the second car; and A processing unit that uses the operating information of the first car obtained through the communication unit to perform self-safety control of the first car to control the output of the first stop instruction of the output unit, and uses the operating information of the second car obtained through the communication unit to perform alternative safety control of the second car to control the output of the second stop instruction of the output unit when an abnormality occurs in other safety control devices corresponding to the second car.
2. The safety control device for an elevator according to claim 1, wherein: The processing section suspends at least a part of the allowed delay processing of the allowed delay when performing the alternate safety control of the second car.
3. The safety control device for an elevator according to claim 2, wherein: When the processing unit performs alternative safety control of the second car, and the proportion of the processing time obtained by adding the processing time of the allowed delayed processing and the idle time in the processing resources is less than a predetermined threshold value, at least a part of the substrate diagnostic processing for diagnosing the status of the substrate including the processing unit is reduced.
4. The safety control device for an elevator according to any one of claims 1 to 3, wherein: The first car and the second car are arranged so as to overlap each other in a horizontal projection plane.
5. An elevator safety control system, wherein: The elevator safety control system has: Multiple safety control devices, which correspond one-to-one to multiple cars in the elevator that move up and down in the hoistway; a plurality of nodes, each of which obtains operation information of at least any one of the plurality of cars; as well as a network to which operation information is input from each of the plurality of nodes, The multiple safety control devices include: a first safety control device corresponding to a first car among the plurality of cars; and a second safety control device corresponding to a second car among the plurality of cars; The second safety control device comprises: a second communication unit connected to the network and communicating with the first safety control device via the network; a second output unit that outputs a second stop instruction for stopping the second car; and a second processing unit that uses the operation information of the second car obtained through the second communication unit to perform self-safety control of the second car to control the output of the second stop instruction of the second output unit, and terminates the self-safety control of the second car when an abnormality occurs in the second safety control device; The first safety control device comprises: a first communication unit connected to the network and communicating with the second safety control device via the network; a first output unit that outputs a first stop command for stopping the first car and the second stop command; and The first processing unit uses the operating information of the first car obtained through the first communication unit to perform self-safety control of the first car to control the output of the first stop instruction of the first output unit, and when an abnormality occurs in the second safety control device, uses the operating information of the second car obtained through the first communication unit to perform alternative safety control of the second car to control the output of the second stop instruction of the first output unit.
6. The elevator safety control system according to claim 5, wherein: The first processing section suspends at least a part of a permitted delay process of permitting a delay when performing the alternate safety control of the second car.
7. The elevator safety control system according to claim 6, wherein: When the first processing unit performs alternative safety control of the second car, and the proportion of the processing time obtained by adding the processing time of the allowed delayed processing and the idle time in the processing resources is less than a predetermined threshold, at least a part of the substrate diagnosis processing for diagnosing the status of the substrate including the first processing unit is reduced.
8. The elevator safety control system according to claim 5, wherein: The second processing unit performs self-diagnosis after an abnormality occurs in the second safety control device, and restarts the self-safety control of the second car when no abnormality is detected in the second safety control device during the self-diagnosis. The first processing section ends the alternate safety control of the second car when no abnormality is detected in the second safety control device during the self-diagnosis.
9. The elevator safety control system according to claim 6, wherein: The second processing unit performs self-diagnosis after an abnormality occurs in the second safety control device, and restarts the self-safety control of the second car when no abnormality is detected in the second safety control device during the self-diagnosis. The first processing section ends the alternate safety control of the second car when no abnormality is detected in the second safety control device during the self-diagnosis.
10. The elevator safety control system according to claim 7, wherein: The second processing unit performs self-diagnosis after an abnormality occurs in the second safety control device, and restarts the self-safety control of the second car when no abnormality is detected in the second safety control device during the self-diagnosis. The first processing section ends the alternate safety control of the second car when no abnormality is detected in the second safety control device during the self-diagnosis.
11. The safety control system for an elevator according to any one of claims 5 to 10, wherein: The plurality of nodes include a door node connected to an opening / closing detector, the opening / closing detector detecting the opening / closing of a landing door at any floor. When an abnormality occurs in the door node, each of the plurality of safety control devices sets a section including a position passing through the landing door as an automatic travel prohibition section for the corresponding car among the plurality of cars.
12. The safety control system for an elevator according to any one of claims 5 to 10, wherein: The plurality of nodes include a hoistway node connected to a position detector, wherein the position detector detects the position of at least any one of the plurality of cars in the hoistway. When an abnormality occurs in the hoistway node, each of the plurality of safety control devices sets a section including the position where the position detector is installed as a prohibited travel section for the corresponding car among the plurality of cars.
13. The safety control system for an elevator according to any one of claims 5 to 10, wherein: The plurality of nodes include a maintenance node connected to a maintenance device, the maintenance device being operated when performing maintenance inspection work. When the maintenance equipment is operated, each of the plurality of safety control devices sets all sections as a prohibited travel section for the corresponding car among the plurality of cars.
14. The safety control system for an elevator according to any one of claims 5 to 10, wherein: At least any one of the plurality of cars is arranged so as to overlap with each other in a horizontal projection plane.
15. The safety control system for an elevator according to claim 14, wherein: The plurality of nodes include a car node, which is set at any car among the plurality of cars to obtain the operation information of the car. When an abnormality occurs in the car node, the safety control device corresponding to the car among the plurality of safety control devices stops the car. When an abnormality occurs at the car node, the safety control device among the multiple safety control devices that corresponds to other cars that are arranged to overlap with the car in the horizontal projection plane sets the interval including the stop position of the car where the car node is located as a prohibited travel interval for the other cars.
16. The safety control system for an elevator according to claim 14, wherein: When an abnormality occurs in any of the plurality of safety control devices, the safety control device in which the abnormality occurs stops the corresponding car. During the period when the car is stopped, the safety control device among the multiple safety control devices that corresponds to other cars that are arranged to overlap with the car in the horizontal projection plane will set the interval including the stop position of the car corresponding to the safety control device in which the abnormality has occurred as the prohibited travel interval of the other car.
17. The safety control system for an elevator according to claim 15, wherein: When an abnormality occurs in any of the plurality of safety control devices, the safety control device in which the abnormality occurs stops the corresponding car. During the period when the car is stopped, the safety control device among the multiple safety control devices that corresponds to other cars that are arranged to overlap with the car in the horizontal projection plane will set the interval including the stop position of the car corresponding to the safety control device in which the abnormality has occurred as the prohibited travel interval of the other car.
Citation Information
Patent Citations
Operation with fewer than all cars in the hoistway after a communication failure between some or all elevator cars
JP2009539726A
Security system and method of multi-lift cage elevator
CN101296855A
Remote monitoring failure reporting alternate system
JP2010020376A