Elevator connection device confirmation system and elevator connection device confirmation method

By using the main controller to select the secondary controller in the elevator system and encrypt and decrypt, confirming whether the external equipment meets the specifications, the cost problem of the need for new equipment in the existing technology is solved, and low-cost equipment certification is achieved.

CN116620970BActive Publication Date: 2025-07-29HITACHI LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202310081982.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2022-02-21
Filing Date
2023-01-17
Publication Date
2025-07-29
Estimated Expiration
2043-01-17

AI Technical Summary

Technical Problem

The prior art requires new equipment control devices and network servers to confirm whether the external equipment connected to the elevator system is formal equipment, resulting in increased costs.

Method used

By setting up a main controller in the elevator system, selecting a secondary controller with the existing controller, encrypting the identification information using the encryption key obtained from the external device, and comparing it with the decrypted information to determine whether the external device meets the specifications.

Benefits of technology

No need to add new devices or channels to confirm whether the external device is a regular device, reducing costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116620970B_ABST
    Figure CN116620970B_ABST
Patent Text Reader

Abstract

The present invention provides an elevator connection device confirmation system and an elevator connection device confirmation method, which can confirm whether an external device is a regular device without adding new devices or channels. The main controller (50) of an elevator system (100) according to one aspect of the present invention includes: a communication path selection unit (52) that selects any one of a plurality of controllers as a sub-controller (60); an encryption unit (54) that encrypts information including at least the identification information of the sub-controller (60) using the public key (31) obtained from the node (30) to generate encrypted data; and a discrimination unit (59) that determines that the node (30) is an irregular device when the source information of the information group sent with the controller identified by the node (30) as the source is inconsistent with the information of the sub-controller (60).
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an elevator connection device confirmation system and an elevator connection device confirmation method. Background Art

[0002] In an elevator system, multiple controllers are connected via various channels. Various devices can be connected to this channel, but when a device that is not supposed to be connected in the elevator system, that is, an irregular device that does not conform to the specifications of the elevator system, is connected to the channel, there is a possibility of interfering with the operation of the elevator system.

[0003] As one of the representative devices connected to the elevator system, there is a maintenance tool used in maintenance work, etc. When the maintenance tool connected to the elevator system is not a regular device that conforms to the elevator specifications, there is a possibility of interfering not only with the maintenance work using the maintenance tool but also with the operation of the entire elevator system.

[0004] By using a maintenance tool certification information management system that confirms whether a maintenance tool is a regular device, it is possible to detect the case where an irregular device is connected to the elevator system. For example, in Patent Document 1, a maintenance tool certification information management system is disclosed, which includes a storage medium capable of operating in a manner of storing multiple commands; and at least one processor configured to send a certification information request to a network server and execute a command to access a device control device with a maintenance tool.

[0005] Prior Art Documents

[0006] Patent Documents

[0007] Patent Document 1: Japanese Unexamined Patent Application Publication No. 2019-23868 Summary of the Invention

[0008] Problems to be Solved by the Invention

[0009] However, in order to adopt the maintenance tool certification information management system described in Patent Document 1, it is necessary to newly set up a device control device for monitoring and / or controlling device components, a network server for managing certification information, and a communication path connecting between the device control device and the network server, resulting in an increase in adoption cost.

[0010] The present invention is made in consideration of the above situation, and an object of the present invention is to be able to confirm whether an external device connected to an elevator system is a regular device without adding new devices or channels.

[0011] Technical Solution for Solving the Problems

[0012] An elevator connection device confirmation system according to one aspect of the present invention is an elevator connection device confirmation system including a plurality of controllers for confirming an external device connected to an elevator system. A main controller constituted by any one of the plurality of controllers includes: a selection unit that selects any one of the plurality of controllers as a sub-controller; an encryption unit that encrypts information including at least the identification information of the sub-controller using an encryption key obtained from the external device to generate encrypted information; a transmission unit that transmits the encrypted information to the external device; and a discrimination unit that compares the source information of a group of information transmitted with the controller identified by the external device as the source with the information of the sub-controller selected by the selection unit, and determines that the external device is an unauthorized device that does not conform to the specifications of the elevator system when the two do not match, wherein the external device identifies the controller based on the identification information of the sub-controller obtained by decrypting the encrypted information.

[0013] In addition, an elevator connection device confirmation method according to one aspect of the present invention is an elevator connection device confirmation method executed by an elevator connection device confirmation system including a plurality of controllers for confirming an external device connected to an elevator system. The elevator connection device confirmation method according to one aspect of the present invention includes: a step in which a main controller constituted by any one of the plurality of controllers selects any one of the plurality of controllers as a sub-controller; a step in which the main controller encrypts information including at least the identification information of the sub-controller using an encryption key obtained from the external device to generate encrypted information; a step in which the main controller transmits the encrypted information to the external device; and a step in which the main controller compares the source information of a group of information transmitted with the controller identified by the external device as the source with the information of the selected sub-controller, and determines that the external device is an unauthorized device that does not conform to the specifications of the elevator system when the two do not match, wherein the external device identifies the controller based on the identification information of the sub-controller obtained by decrypting the encrypted information.

[0014] Advantages of the Invention

[0015] According to at least one aspect of the present invention, it is possible to confirm whether an external device connected to an elevator system is an authorized device without adding a new device or channel.

[0016] Problems, configurations, and effects other than those described above will be described in the following embodiments. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] Figure 1 is a diagram showing a schematic configuration example of an elevator system according to an embodiment of the present invention.

[0018] Figure 2It is a block diagram showing a structural example of a control system of a node, a main controller, and a sub - controller according to an embodiment of the present invention.

[0019] Figure 3 It is a block diagram showing a hardware structural example of each device constituting an elevator system according to an embodiment of the present invention.

[0020] Figure 4 It is a flowchart showing a flow example of an elevator connection device confirmation process performed by an elevator system according to an embodiment of the present invention.

[0021] Figure 5 It is a flowchart showing a flow example of an initial communication process and a primary communication process in an elevator connection device confirmation process performed by an elevator system according to an embodiment of the present invention.

[0022] Figure 6 It is a diagram showing a structural example of an initial information group according to an embodiment of the present invention.

[0023] Figure 7 It is a diagram showing a structural example of a primary information group according to an embodiment of the present invention.

[0024] Figure 8 It is a flowchart showing a flow example of a secondary communication process and a tertiary communication process in an elevator connection device confirmation process performed by an elevator system according to an embodiment of the present invention.

[0025] Figure 9 It is a diagram showing a structural example of a secondary information group according to an embodiment of the present invention.

[0026] Figure 10 It is a diagram showing a structural example of a tertiary information group according to an embodiment of the present invention.

[0027] Figure 11 It is a flowchart showing a flow example of a discrimination process in an elevator connection device confirmation process performed by an elevator system according to an embodiment of the present invention.

[0028] Figure 12 It is a flowchart showing a process flow example (1) in a main controller when it is determined that an additional node is an irregular device according to an embodiment of the present invention.

[0029] Figure 13 It is a flowchart showing a process flow example (2) in a main controller when it is determined that an additional node is an irregular device according to an embodiment of the present invention.

[0030] Figure 14 It is a flowchart showing a generation example of temporary data and a decision example (1) of a sub - controller according to an embodiment of the present invention.

[0031] Figure 15 It is a flowchart showing an example of generation of temporary data and an example of the process of determining the slave controller (2) according to an embodiment of the present invention.

[0032] Figure 16 It is a flowchart showing an example of generation of temporary data and an example of the process of determining the slave controller (3) according to an embodiment of the present invention.

[0033] Figure 17 It is a flowchart showing an example of generation of temporary data and an example of the process of determining the slave controller (4) according to an embodiment of the present invention.

[0034] Figure 18 It is a flowchart showing an example of generation of temporary data and an example of the process of determining the slave controller (5) according to an embodiment of the present invention.

[0035] Figure 19 It is a flowchart showing an example of generation of temporary data and an example of the process of determining the slave controller (6) according to an embodiment of the present invention. Detailed Embodiment

[0036] Hereinafter, an example of a method for implementing the present invention (hereinafter referred to as "embodiment") will be described with reference to the accompanying drawings. The present invention is not limited to the embodiment, and various numerical values in the embodiment are examples. In addition, in this specification and the drawings, the same reference numerals are assigned to the same components or components having substantially the same function, and redundant description is omitted.

[0037] <Schematic Structure of Elevator System>

[0038] First, with reference to Figure 1 , the structure of an elevator system 100 (an example of an elevator connection device confirmation system) according to an embodiment of the present invention will be described. Figure 1 It is a diagram showing an example of the schematic structure of the elevator system 100.

[0039] As Figure 1 shows, the elevator system 100 includes a central device 1, a communication controller 3, a group management controller 4, an elevator 15, a maintenance terminal 19, and a management terminal 20.

[0040] The central device 1 is provided at a location far from the building where the elevator 15 is installed, and is a device for managing, monitoring, maintaining, etc. the elevator 15 connected via the network 2. The network 2 is composed of, for example, a closed network such as a dedicated line or a public line such as the Internet.

[0041] The maintenance terminal 19 is a portable terminal held by maintenance personnel (not shown) of the elevator 15 and is connected to the network 2. The maintenance terminal 19 acquires the operation data at the time of elevator 15 failure or displays the inspection contents of the operation on the screen according to the operations performed by the maintenance personnel.

[0042] The management terminal 20 is a device for monitoring and operating the operation of the elevator 15 and is composed of a general-purpose PC (Personal Computer) or a dedicated device. The management terminal 20 is installed, for example, in the management room (not shown) of the building where the elevator 15 is installed and is connected to the channel 17.

[0043] The communication controller 3 is a controller that controls data exchange between the control center device 1 and the elevator 15 and is used to perform remote operations and remote maintenance communications performed by the maintenance terminal 19, and is connected to the network 2 and the channel 17.

[0044] The group management controller 4 is a controller that collectively manages and operates a collection of multiple elevators 15 as an elevator group 18 and is connected to the channel 17 and the channel 16. The elevator group 18 is set, for example, in units such as the installation location and use of the elevator 15, and the building where the elevator 15 is installed.

[0045] The elevator controller 5 is provided for each of the multiple elevators 15 and is a controller that controls the operation of the elevator 15 and is connected to the channel 16 and the channel 12. The elevator controller 5, for example, operates the movement of the suspension cable 9 connecting the car 7 and the counterweight 8 by controlling the main machine of the elevator 15, that is, the motor 6, to lift, lower, or stop the car 7, thereby providing a lifting and lowering service to the user.

[0046] In addition, only one car 7 is shown in Figure 1 but one or more are provided for each of the multiple elevators 15.

[0047] The elevator controller 5 is connected to the group management controller 4 via the channel 16 and is connected to the car controller 10 and the floor controller 11 via the channel 12. Figure 1 In

[0048] only one floor controller 11 is shown, but actually multiple are provided corresponding to the number of floors in the building.

[0049] The car controller 10 monitors the operation status of the destination floor button and the door opening / closing button 13 provided in the car 7 by the user (not shown) and notifies the elevator controller 5 of the acquired operation content regarded as a change in the operation status.

[0050] As a newly connected node 30 to the elevator system 100, for example, there are maintenance terminals for performing maintenance inspections of the elevator system 100, sensors or cameras for providing new data to the elevator system 100, edge controllers for providing new processing and functions, communication controllers for connecting to other systems or networks not shown, and the like. As new data, for example, there are measured values of the number of people in the car 7 or on the floor, and as new processing and functions, for example, there are results of predicting the flow of people using AI (Artificial Intelligence), that is, inference results on how many passengers will use the elevator 15. In addition, the node 30 is not limited to the device that provides such information, processing, and functions.

[0051] The newly added node 30 can be connected to one or more of the channels 12, 16, and 17. In addition, Figure 1 The network structure composed of the shown channels is an example, and the network structure of the present invention is not limited to Figure 1 the example shown. In addition, the device structure of the elevator system of the present invention is also not limited to Figure 1 the example shown.

[0052] In the present embodiment, any one of the communication controller 3, the group management controller 4, the elevator controller 5, the car controller 10, the floor controller 11, the maintenance terminal 19, and the management terminal 20 is set as the main controller 50 or the sub - controller 60 (both refer to Figure 2 ). In addition, when there are other controllers in the elevator system, such a controller may also be set as the main controller 50 or the sub - controller 60.

[0053] The main controller 50 is a controller that performs the authentication process of the newly added node 30. The sub - controller 60 is a controller that constitutes the communication path of the information group for authenticating the node 30 and is selected by the main controller 50. The selection of the sub - controller 60 by the main controller 50 is based on the processed information of the operation information of the elevator 15 (such as a random number with the value shown in the operation information as the seed). The method for the main controller 50 to select the sub - controller 60 will be described later.

[0054] <Structure of the control system of nodes, main controller, and sub - controller>

[0055] Next, with reference to Figure 2 , the structure of the control system of the node 30, the main controller 50, and the sub - controller 60 will be described. Figure 2 is a block diagram showing an example of the structure of the control system of the node 30, the main controller 50, and the sub - controller 60. The node 30, the main controller 50, and the sub - controller 60 are respectively communicably connected to each other via any one of the channels 12, 16, and 17, that is, the communication path Nt.

[0056] [Node]

[0057] The node 30 connected to the new elevator system 100 (reference Figure 1 ) has a public key 31 and a private key N32 paired with the public key 31. In addition, the node 30 has a decryption unit 33, a message group generation unit 34, and a communication unit 35.

[0058] The decryption unit 33 decrypts the encrypted data included in the primary message group P2 (reference Figure 7 ) sent from the main controller 50 and encrypted using the public key 31, and outputs the decrypted information to the message group generation unit 34.

[0059] When the node 30 is connected to any communication path of the elevator system 100, the message group generation unit 34 generates an initial message group P1 (reference Figure 6 ) including the public key 31 and the identification information of this node, and outputs the initial message group P1 to the communication unit 35. In addition, the message group generation unit 34 generates a secondary message group P3 (reference Figure 9 ) using the information input from the decryption unit 33, and outputs the secondary message group P3 to the communication unit 35.

[0060] The communication unit 35 performs the process of sending the initial message group P1 generated by the message group generation unit 34 to the main controller 50, the process of receiving the primary message group P2 sent from the main controller 50 and outputting it to the decryption unit 33, and the process of sending the secondary message group P3 generated by the message group generation unit 34 to the sub-controller 60.

[0061] [Main Controller]

[0062] The main controller 50 has a private key M53. The private key M53 (an example of the second private key) is a shared key held only by the main controller 50. In addition, the main controller 50 has a temporary data generation unit 51, a communication path selection unit 52, an encryption unit 54, a message group generation unit 55, a communication unit 56, an address determination unit 57, a decryption unit 58, and a discrimination unit 59.

[0063] The temporary data generation unit 51 (an example of the temporary information generation unit) generates temporary data (an example of the temporary information) using the operation information of the elevator 15 (reference Figure 1 ) obtained via the communication path Nt. The temporary data is processed information of the operation data (an example of the operation information), such as a random number value seeded by the position of the car 7 (car position) as the operation data, or a hash value obtained by inputting the car position to a specified hash function. In addition, the temporary data may also be the operation data itself (data before processing).

[0064] The communication path selection unit 52 (an example of a selection unit) selects an information group for authentication (primary information group P2, secondary information group P3, tertiary information group P4 (refer to Figure 10 )) of the sub - controller 60 that constitutes the node 30 based on the operation information of the elevator 15 obtained via the communication path Nt. For example, the communication path selection unit 52 can refer to the call information as operation data and select the floor controller 11 (refer to Figure 1 ) of the floor where no call registration (no call has occurred) exists as the sub - controller 60. For the selection example of the sub - controller 60 by the communication path selection unit 52, refer to Figures 14 - 19 which will be described later.

[0065] The encryption unit 54 encrypts the identification information of the sub - controller 60 (hereinafter referred to as "sub - information") selected by the communication path selection unit 52 and the temporary data generated by the temporary data generation unit 51 using the public key 31 obtained from the node 30 to generate encrypted temporary data (refer to Figure 7 ).

[0066] The information group generation unit 55 generates a primary information group P2 (refer to Figure 7 ) including the encrypted temporary data generated by the encryption unit 54 and outputs the primary information group P2 to the communication unit 56. For the structural example of the primary information group P2, refer to the detailed description in Figure 7 which will be described later.

[0067] The communication unit 56 (an example of a transmission unit) performs the process of receiving the initial information group P1 (refer to Figure 6 ) sent from the node 30, the process of sending the primary information group P2 (refer to Figure 7 ) generated by the information group generation unit 55 to the node 30, and the process of receiving the secondary information group P3 sent from the sub - controller 60 and outputting it to the address determination unit 57.

[0068] The address determination unit 57 determines whether the node 30 is a regular device that conforms to the specifications of the elevator system 100 by referring to the identification information of the node 30 included in the initial information group P1 sent from the node 30. Then, the address determination unit 57 outputs the determination result to the decryption unit 58.

[0069] The decryption unit 58 decrypts the encrypted temporary data included in the secondary information group P3 (refer to Figure 9 ) sent from the sub - controller 60 using the private key M53. Then, the decryption unit 58 outputs the decrypted temporary data to the discrimination unit 59.

[0070] The discrimination unit 59 discriminates whether the node 30 is a regular device conforming to the specifications of the elevator system 100 by comparing the information in the triple information group P4 decrypted by the decryption unit 58 with the information possessed by the main controller 50. That is, the discrimination unit 59 performs the authentication (discrimination) process of the node 30. In addition, when the discrimination unit 59 discriminates that the node 30 is an irregular device, it performs processes such as notifying other controllers of this message and instructing the car 7 of the elevator 15 in operation to stop at the nearest floor.

[0071] Regarding the discrimination process of the node 30 by the discrimination unit 59, refer to the following Figure 11 for a detailed description. Regarding the process performed by the discrimination unit 59 when it is determined that the node 30 is an irregular device, refer to the following Figure 12 and Figure 13 for a detailed description.

[0072] [Sub - controller]

[0073] The sub - controller 60 has a communication unit 61 and an information group transmission unit 62. The communication unit 61 performs the process of receiving the secondary information group P3 sent from the node 30 and outputting it to the information group transmission unit 62, and the process of sending the triple information group P4 (refer to Figure 10 ) generated by the information group transmission unit 62 to the main controller 50.

[0074] The information group transmission unit 62 extracts the encrypted temporary data from the secondary information group P3 sent from the node 30, generates a triple information group P4 including this encrypted temporary data and its own (sub - controller 60) identification information (refer to Figure 10 ), and outputs this triple information group P4 to the communication unit 61.

[0075] <Example of the hardware structure of a computer>

[0076] Next, regarding the structure (hardware structure) of the control systems of the respective devices (communication controller 3, group management controller 4, elevator controller 5, car controller 10, floor controller 11, maintenance terminal 19, and management terminal 20) constituting the Figure 1 shown elevator system 100, refer to Figure 3 for an explanation.

[0077] Figure 3 is a block diagram showing an example of the hardware structure of the respective devices constituting the elevator system 100. Figure 3 The computer 200 shown is used as the hardware of a so - called computer.

[0078] The computer 200 has a CPU (Central Processing Unit) 201, a ROM (Read Only Memory) 202, a RAM (Random Access Memory) 203, a non-volatile memory 204, and a communication I / F (Interface) 205, which are respectively connected to the bus B.

[0079] The CPU 201 reads the program code of the software that implements the respective functions of the present embodiment from the ROM 202, deploys it to the RAM 203, and executes it. Alternatively, there is also a case where the CPU 201 directly reads the program code from the ROM 202 and directly executes it. In addition, instead of the CPU 201, the computer 200 may include a processing device such as an MPU (Micro-Processing Unit).

[0080] In the RAM 203, variables, parameters, etc. generated during the arithmetic processing performed by the CPU 201 are temporarily written.

[0081] The respective functions of the decryption unit 33, the information group generation unit 34 of the node 30, the temporary data generation unit 51, the communication path selection unit 52, the encryption unit 54, the information group generation unit 55, the address determination unit 57, the decryption unit 58, the discrimination unit 59, and the information group transmission unit 62 of the sub-controller 60 are implemented by the CPU 201 reading and executing the program for implementing each function from the ROM 202.

[0082] As the non-volatile memory 204, for example, an HDD (Hard Disk Drive), an SSD (Solid State Drive), a floppy disk, an optical disk, a magneto-optical disk, a CD-ROM, a CD-R, a non-volatile memory card, etc. can be used. In this non-volatile memory 204, an OS (Operating System), various parameters, and programs for operating the computer 200 are recorded. In addition, the program may also be stored in the ROM 202.

[0083] The program is stored in the form of program code that can be read by the computer, and the CPU 201 sequentially executes actions corresponding to the program code. That is, the ROM 202 or the non-volatile memory 204 is used as an example of a non-transitory recording medium that stores the program executed by the computer and can be read by the computer.

[0084] In addition, in the non-volatile memory 204, data generated in each controller or transmitted via the channel Nt (refer to Figure 2)The operation data of elevator 15 obtained from other controllers. As the operation data of elevator 15, for example, there is the position information of car 7, the car speed information, the load information of car 7, the number of people moved (transported) by car 7, the operation times information of elevator 15, the destination floor information of elevator 15, the stop times information of elevator 15 on each floor, etc.

[0085] The communication I / F 205 is composed of a communication device that controls communication with other devices. As the network for which the communication I / F 205 performs communication control, for example, there is serial communication in a multi-point mode such as RS-485, and a channel that provides various topologies such as Ethernet (registered trademark). As the channel that provides various topologies, there are LAN (Local Area Network), WAN (Wide Area Network) as wired channels, and RAN (Radio Area Network) as a wireless channel, etc.

[0086] In addition, for example, as the network for which the communication I / F 205 performs communication control, there is wireless such as Wi-Fi (registered trademark) and wireless in a wireless communication infrastructure. The functions of the communication unit 35 of node 30, the communication unit 56 of the main controller 50, and the communication unit 61 of the sub-controller 60 are implemented by the communication I / F 205.

[0087] <Overview of elevator connection device confirmation process>

[0088] Next, with reference to Figure 4 , an overview of the elevator connection device confirmation process performed by the elevator system 100 will be described. Figure 4 is a flowchart showing an example of the process of the elevator connection device confirmation process performed by the elevator system 100.

[0089] First, node 30 (refer to Figure 2 ) executes initial communication processing to generate an initial information group P1, and sends the generated initial information group P1 to the main controller 50 (step S1). Next, the main controller 50 executes primary communication processing based on the information included in the received initial information group P1 to generate a primary information group P2, and sends the generated primary information group P2 to node 30 (step S2). Next, node 30 uses the information included in the received primary information group P2 to execute secondary communication processing to generate a secondary information group P3, and sends the generated secondary information group P3 to the sub-controller 60 (step S3).

[0090] Next, the sub - controller 60 performs a three - time communication process based on the information included in the received secondary information group P3 to generate a three - time information group P4, and sends the generated three - time information group P4 to the main controller 50 (step S4). Next, the main controller 50 performs a discrimination process based on the information included in the received three - time information group P4 (step S5).

[0091] <Details of the elevator connection device confirmation process>

[0092] Next, referring to Figure 5 、 Figure 8 、 Figure 11 , the details of the elevator connection device confirmation process performed by the elevator system 100 will be described. Figure 5 is a flowchart showing an example of the flow of the initial communication process and the primary communication process in the elevator connection device confirmation process performed by the elevator system 100. Figure 8 is a flowchart showing the flow of the secondary communication process and the tertiary communication process in the elevator connection device confirmation process performed by the elevator system 100. Figure 11 is a flowchart showing an example of the flow of the discrimination process in the elevator connection device confirmation process performed by the elevator system 100.

[0093] [Initial communication process and primary communication process]

[0094] First, referring to Figure 5 , the initial communication process and the primary communication process in the elevator connection device confirmation process will be described. First, the communication unit 35 of the node 30 (refer to Figure 2 ) determines whether it has been connected to the channel Nt of the elevator system 100 (refer to Figure 2 ) (step SA1). In step SA1, when it is determined that the connection to the channel Nt has not been made (the case where the determination in step SA1 is no), the communication unit 35 repeats the determination in step SA1.

[0095] On the other hand, in step SA1, when it is determined that the connection to the channel Nt has been made (the case where the determination in step SA1 is yes), the information group generation unit 34 generates an initial information group P1 including public key information and sends it to the main controller 50 (step SA2). The processes of step SA1 and step SA2 are Figure 4 the initial communication process of step S1 of

[0096] [Structure of the initial information group]

[0097] Here, referring to Figure 6 , the structure of the initial information group P1 will be described. Figure 6 is a diagram showing an example of the structure of the initial information group P1.

[0098] As Figure 6As shown, the initial information group P1 has a transmission source information field F1, a transmission destination information field F2, a public key information field F3, a node identification information field F4, and a check data field F5.

[0099] In the transmission source information field F1, the information of the transmission source of the initial information group P1, that is, itself (node 30), is stored (transmission source information). In the transmission destination information field F2, the information of the transmission destination of the initial information group P1, that is, the main controller 50, is stored (transmission destination information).

[0100] For example, in the case of RS-485 compliant communication, the transmission source information is the device ID. Additionally, in the case of communication using Ethernet (registered trademark), it is the MAC (Media Access Control) address or IP (Internet Protocol) address of the device. The transmission destination information can be constituted by the same information as the transmission source information. However, in a network where information groups are transmitted through broadcast communication, the broadcast address is stored in the transmission destination information.

[0101] The public key 31 is stored in the public key information field F3 (refer to Figure 2 ). The identification information of this node (node 30) is stored in the node identification information field F4 (node identification information). As the node identification information, for example, there are the model number, serial number, etc. of node 30. Error detection codes such as checksum are stored in the check data field F5.

[0102] The initial information group P1 is constituted by plaintext and is assumed to be transmitted through unencrypted communication. However, the information group can also be encrypted and transmitted through encrypted communication. Similarly, the first information group P2 to the third information group P4 themselves can also be encrypted and transmitted through encrypted communication.

[0103] In addition, there are cases where node 30 is a node that deliberately performs illegal acts or launches a DoS (Denial of Services) attack after connecting to the channel Nt. Thus, when the number of transmissions of the initial information group P1 sent by node 30 is too large (above the specified threshold number), this node 30 can be immediately judged as an illegal node at this time.

[0104] Return Figure 5 Continue the description. The main controller 50 receives the initial information group P1 sent from node 30 in step SA2 (step SB1). Next, the communication path selection unit 52 of the main controller 50 (refer to Figure 2 ) selects a specific controller as the secondary controller 60 based on the operation data of the elevator 15 (step SB2).

[0105] For example, the communication path selection unit 52 can obtain call information as operation data and select the controller with the fewest call registrations as the sub-controller 60.

[0106] In addition, in the present embodiment, an example is given in which the selection process of the sub-controller 60 by the main controller 50 is triggered by receiving the initial information group P1, but the present invention is not limited thereto. It may also be executed at each predetermined cycle set in the main controller 50, or at the timing when the number of operations of the elevator 15 reaches a predetermined threshold number of operations, etc., at the timing of achieving a certain condition. Or, it may be executed at random time units. By performing such processing, it is possible to make it more difficult for a third party to detect the authentication process of the execution node 30.

[0107] Next, the temporary data generation unit 51 of the main controller 50 generates temporary data using the operation data (step SB3). For example, the temporary data generation unit 51 generates a random number seeded with operation data such as the car position, or a hash value obtained by inputting the operation data into a predetermined hash function, and uses it as the temporary data.

[0108] Next, the encryption unit 54 of the main controller 50 encrypts the temporary data generated in step SB3 using the private key M53 to generate encrypted temporary data (step SB4). Next, the information group generation unit 55 of the main controller 50 encrypts the encrypted temporary data generated in step SB4 and the information (sub-information) of the sub-controller 60 selected in step SB2 using the public key included in the initial information group P1 received in step SB1 to generate encrypted data (an example of encrypted information) (step SB5).

[0109] Next, the information group generation unit 55 of the main controller 50 generates a primary information group P2 including the encrypted data generated in step SB5 and its own information (main controller 50) (step SB6). Then, the communication unit 56 transmits the primary information group P2 to the node 30 (step SB7). The processing of steps SB1 to SB7 is Figure 4 the primary communication processing of step S2.

[0110] In addition, Figure 5 in the example shown, an example is given in which the main controller 50 generates temporary data after selecting the sub-controller 60, but the present invention is not limited thereto. The main controller 50 may also select the sub-controller 60 after generating the temporary data.

[0111] [Structure of the primary information group]

[0112] Here, with reference to Figure 7 , the structure of the primary information group P2 will be described. Figure 7 is a diagram showing an example of the structure of the primary information group P2.

[0113] As Figure 7 shown, the primary information group P2 has a transmission source information field F21, a transmission destination information field F22, an encrypted data field F23, and a check data field F24.

[0114] In the transmission source information field F21, information (transmission source information) of the transmission source of the primary information group P2, that is, itself (the main controller 50), is stored. In the transmission destination information field F22, information (transmission destination information) of the transmission destination of the primary information group P2, that is, the node 30, is stored.

[0115] In the encrypted data field F23, the encrypted data generated by the encryption unit 54 of the main controller 50 is stored. The encrypted data consists of the identification information (secondary information) of the sub - controller 60 and encrypted temporary data. An error detection code such as a checksum is stored in the check data field F24.

[0116] [Secondary communication processing and tertiary communication processing]

[0117] Next, with reference to Figure 8 , the secondary communication processing and the tertiary communication processing in the elevator connection device confirmation processing will be described. First, the communication unit 35 of the node 30 (refer to Figure 2 ) receives the primary information group P2 sent from the main controller 50 (step SA3). Next, the decryption unit 33 of the node 30 decrypts the encrypted data included in the primary information group P2 received in step SA3 using the private key N32 corresponding to the public key 31 (step SA4).

[0118] Next, the information group generation unit 34 of the node 30 extracts the encrypted temporary data from the encrypted data decrypted in step SA4 and stores it in the secondary information group P3 (step SA5). Next, the information group generation unit 34 sets the secondary information (identification information of the sub - controller 60) included in the encrypted data decrypted in step SA4 to the transmission destination information field F32 of the secondary information group P3 (refer to Figure 9 ) (step SA6).

[0119] Next, the communication unit 35 of the node 30 sends the secondary information group P3 to the sub - controller 60 (step SA7). The processing of steps SA1 - SA7 is Figure 4 the secondary communication processing of step S3 of . After the processing of step SA7, all the processing (initial communication processing and secondary communication processing) performed by the node 30 ends.

[0120] [Structure of the secondary information group]

[0121] Here, with reference to Figure 9 , the structure of the secondary information group P3 will be described.Figure 9 This is a diagram showing the structural example of the secondary information group P3.

[0122] As Figure 9 shown, the secondary information group P3 has a source information field F31, a destination information field F32, a main controller identification information field F33, an encrypted temporary data field F34, and a check data field F35.

[0123] In the source information field F31, the information of the source of the secondary information group P3 itself (node 30) (source information) is stored. In the destination information field F32, the information of the destination of the secondary information group P3, i.e., the secondary controller 60 (destination information), is stored.

[0124] In the main controller identification information field F33, the identification information of the main controller 50 is stored. The identification information of the main controller 50 is used as the information of the destination of the generated tertiary information group P4 in the secondary controller 60 that has received the secondary information group P3. In the encrypted temporary data field F34, the encrypted temporary data extracted from the primary information group P2 is stored. In the check data field F35, error detection codes such as checksums are stored.

[0125] Return Figure 8 Continue the explanation. The communication unit 61 of the secondary controller 60 (refer to Figure 2 ) receives the secondary information group P3 sent from node 30 in step SA5 (step SC1). Then, the information group transmission unit 62 of the secondary controller 60 generates a tertiary information group P4 including the encrypted temporary data and the source information included in the secondary information group P3 received in step SC1 (step SC2). Then, the communication unit 61 of the secondary controller 60 sends this tertiary information group P4 to the main controller 50 (step SC3). The processing of steps SC1 to SC3 is Figure 4 the tertiary communication processing of step S4. After the processing of step SC3, the processing performed by the secondary controller 60 ends.

[0126] [Structure of the tertiary information group]

[0127] Here, referring to Figure 10 , the structure of the tertiary information group P4 will be described. Figure 10 This is a diagram showing the structural example of the tertiary information group P4.

[0128] As Figure 10 shown, the tertiary information group P4 has a source information field F41, a destination information field F42, an encrypted temporary data field F43, and a check data field F44.

[0129] Save the information of the source of transmission of the triple information group P4, which is itself (the slave controller 60), in the transmission source information field F41 (transmission source information). Save the information of the destination of transmission of the triple information group P4, which is the master controller 50, in the transmission destination information field F42 (transmission destination information). Save the encrypted temporary data extracted from the secondary information group P3 in the encrypted temporary data field F43. Save error detection codes such as checksums in the check data field F44.

[0130] [Discrimination process]

[0131] Next, a description will be given of the discrimination process in the elevator connection device confirmation process with reference to Figure 11 . First, the discrimination unit 59 of the master controller 50 (refer to Figure 2 ) determines whether the triple information group P4 has been received from the slave controller 60 within a specified threshold time (step SB8). Determining whether it is within the threshold time is the elapsed time since the master controller 50 sent the single information group P2 to the node 30 in Figure 5 step SB7.

[0132] In the case where the node 30 is not a regular device, the node 30 cannot correctly perform the secondary communication process. That is, it cannot decrypt the encrypted data included in the single information group P2 sent from the master controller 50 and cannot obtain the information of the slave controller 60 included in the encrypted data. In addition, the non-regular device node 30 also cannot obtain the encrypted temporary data included in the encrypted data.

[0133] Thus, the non-regular device node 30 cannot perform the secondary communication process of generating the secondary information group P3 with the destination of the slave controller 60 and including the encrypted temporary data based on the single information group P2 sent from the master controller 50 and sending the secondary information group P3 to the slave controller 60. Therefore, the slave controller 60 also cannot perform the tertiary communication process of generating the triple information group P4 based on the secondary information group P3 received from the node 30 and sending it to the master controller 50.

[0134] That is, when the node 30 is a non-regular device, the master controller 50 will not receive the triple information group P4 from the slave controller 60 within the specified threshold time after sending the single information group P2 to the node 30. Therefore, when the triple information group P4 has not been received within the specified threshold time after sending the single information group P2 to the node 30, it can be determined that the node 30 is a non-regular device.

[0135] In step SB8, when it is determined that the information group P4 has not been received three times from the slave controller 60 within the threshold time (the case where the determination in step SB8 is NO), the discrimination unit 59 of the master controller 50 determines that the additional node 30 is a non-compliant node, that is, a node of a non-regular device (step SB9). After the processing in step SB9, the master controller 50 ends the discrimination process.

[0136] On the other hand, in step SB8, when it is determined that the information group P4 has been received three times from the slave controller 60 within the specified threshold time (the case where the determination in step SB8 is YES), the discrimination unit 59 determines whether the source information included in the three information groups P4 is Figure 5 identical to the information of the slave controller 60 selected in step SB2 of

[0137] (step SB10). In step SB10, when it is determined that the two pieces of information are inconsistent (the case where the determination in step SB10 is NO), the discrimination unit 59 performs the processing in step SB9. That is, it is determined that the additional node 30 is a non-regular device. Figure 2 ) (step SB11).

[0138] Next, the discrimination unit 59 determines whether the temporary data included in the decrypted encrypted data is Figure 5 identical to the temporary data generated in step SB3 of

[0139] (step SB12). In step SB12, when it is determined that the two pieces of data are inconsistent (the case where the determination in step SB12 is NO), the processing in step SB9 is performed. That is, it is determined that the additional node 30 is a non-regular device. Figure 4 On the other hand, in step SB12, when it is determined that the two pieces of data are consistent (the case where the determination in step SB12 is YES), the discrimination unit 59 determines that the additional node is a compliant node, that is, a regular device (step SB13). The processing in steps SB8 to SB13 is

[0140] [Processing When a Non-Regular Device is Detected]

[0141] Next, the processing in the master controller 50 when it is determined that the additional node 30 is a non-regular device will be described with reference to Figure 12 and Figure 13 (step SB13). After the processing in step SB9 or step SB13, all the processing (one-time communication processing and discrimination processing) performed by the master controller 50 ends.Figure 12 This is a flowchart showing the process (1) in the main controller 50 when it is determined that the added node 30 is a non-regular device. Figure 13 This is a flowchart showing the process (2) in the main controller 50 when it is determined that the added node 30 is a non-regular device.

[0142] First, refer to Figure 12 An explanation of the process (1) will be given. First, when the discrimination unit 59 of the main controller 50 (refer to Figure 2 ) determines that the node 30 is not a regular device, i.e., a non-regular device, it stores the information of the node 30 determined to be a non-regular device (hereinafter also referred to as the illegal node 30) as illegal information (step S11). The illegal information includes at least the information of the illegal node 30 (identification information, etc.), for example, it consists of a device ID, serial number, MAC address, IP address, etc.

[0143] Next, the discrimination unit 59 of the main controller 50 notifies the other controllers of the illegal information stored in step S11 via the communication unit 56 (step S12). The notification (communication) is performed, for example, in a multi-point manner for all the controllers connected to the channel Nt (refer to Figure 2 ) in serial communication when multiple devices are connected to the channel Nt.

[0144] In addition, when communication is performed based on a specification such as Ethernet (registered trademark) in the channel Nt, the notification of the illegal information is performed via broadcast communication for all the controllers connected to the channel Nt. Each controller that has received the illegal information can, for example, perform processing such as rejecting communication with the node 30 based on the information of the node 30 included in the received illegal information.

[0145] By performing such processing with the main controller 50 and other controllers, no matter what actions the non-regular device node 30 takes, the elevator system 100 can ignore them. Thus, according to this embodiment, even when a non-regular device is connected to the channel Nt, the operation of the elevator 15 (refer to Figure 1 ) can continue.

[0146] In addition, according to this embodiment, when a non-regular device node 30 is connected, this situation can be immediately detected by the main controller 50, so it is possible to prevent failures from occurring in the operation of the elevator system 100 due to the connection of the non-regular device node 30. In addition, when the node 30 is a non-regular device added for the purpose of illegal behavior, it is also possible to prevent the execution of illegal behavior by performing processing such as rejecting communication with the node 30.

[0147] Next, refer to Figure 13A description will be given of processing example (2). First, when the discrimination unit 59 of the main controller 50 determines that the node 30 is an irregular device, an instruction is given to the corresponding controller to stop the car 7 of the elevator 15 at the nearest floor (step S21). Figure 1 )

[0148] For example, when an illegal node 30 is connected to the Figure 1 channel 17, the main controller 50 instructs the group management controller 4 to stop the car 7 at the nearest floor. When an illegal node 30 is connected to the channel 16, the main controller 50 instructs the elevator controller 5 to stop the car 7 at the nearest floor. In addition, when an illegal node 30 is connected to the channel 12, the main controller 50 instructs the elevator controller 5 to stop the car 7 at the nearest floor. By performing such processing, the safety of the users of the elevator 15 can be ensured even when an illegal node 30 is connected.

[0149] Next, the discrimination unit 59 of the main controller 50 notifies the superior controller of the occurrence of an illegal act via the communication unit 56 (step S22). For example, when an illegal node 30 is connected to the Figure 1 channel 17, the main controller 50 notifies the communication controller 3 of the occurrence of an illegal act. When an illegal node 30 is connected to the channel 16, the main controller 50 notifies the group management controller 4 of the occurrence of an illegal act. In addition, when an illegal node 30 is connected to the channel 12, the main controller 50 notifies the elevator controller 5 of the occurrence of an illegal act. The controller that has received the notification of the occurrence of an illegal act can quickly reach the top-level central device 1 by further transmitting the notification of the occurrence of an illegal act to the superior controller.

[0150] [Example of generation of temporary data and example of determination of sub-controller]

[0151] Next, a description will be given of the example of generation of temporary data performed by the temporary data generation unit 51 (reference Figures 14 - 19 ) of the main controller 50 and the example of selection of the sub-controller 60 by the communication path selection unit 52 of the main controller 50. Figure 2 )

[0152] Figure 14 is a flowchart showing an example of the process of the example of generation of temporary data and the determination example (1) of the sub-controller 60, Figure 15 is a flowchart showing an example of the process of the example of generation of temporary data and the determination example (2) of the sub-controller 60. Figure 16 is a flowchart showing an example of the process of the example of generation of temporary data and the determination example (3) of the sub-controller 60, Figure 17It is a flowchart showing an example of the process of generating temporary data and an example of the decision-making process (4) of the sub-controller 60. Figure 18 It is a flowchart showing an example of the process of generating temporary data and an example of the decision-making process (5) of the sub-controller 60, Figure 19 It is a flowchart showing an example of the process of generating temporary data and an example of the decision-making process (6) of the sub-controller 60.

[0153] [Example (1): Operating data for temporary data = car position information, operating data for sub-controller 60 selection = call information]

[0154] First, refer to Figure 14 , and an example of the generation example of the temporary data by the main controller 50 and the decision example (1) of the sub-controller 60 will be described.

[0155] First, the temporary data generation unit 51 of the main controller 50 (refer to Figure 2 ) obtains the position information (car information) of the car 7 (refer to Figure 1 ) via the communication unit 56 as the operating data of the elevator 15 (step S31).

[0156] Next, the temporary data generation unit 51 of the main controller 50 generates temporary data with the car position information obtained in step S31 as the input value (step S32). The temporary data can be generated, for example, by inputting the car position information to a random number generation function or a hash value function. That is, the temporary data generation unit 51 can obtain a random number or a hash value with the car position information as the input value as the temporary data.

[0157] Next, the communication path selection unit 52 of the main controller 50 obtains call information as the operating data (step S33).

[0158] Next, based on the call information obtained in step S33, the communication path selection unit 52 selects a specified controller as the sub-controller 60 (step S34). For example, the communication path selection unit 52 can input the call registration information of each car 7 included in the call information to a minimum value function, and select a controller based on the obtained output value. Thus, the controller with the fewest call registrations is selected as the sub-controller 60.

[0159] By performing such processing by the communication path selection unit 52, the car controller 10 that controls the operation of the car 7 with the fewest call registrations, including the car 7 with zero call registrations, is selected as the sub-controller 60. That is, the car controller 10 with spare capacity is selected as the sub-controller 60 that constitutes the transmission path of the information group. Therefore, by executing the elevator connection device confirmation method of the present embodiment, the influence on the normal operation of the elevator 15 can be suppressed to the minimum.

[0160] [Example (2): Operating data for temporary data = car speed information, operating data for sub - controller 60 selection = call information]

[0161] Next, referring to Figure 15 , an example of the generation of temporary data by the main controller 50 and a decision example (2) of the sub - controller 60 will be described.

[0162] First, the temporary data generation unit 51 of the main controller 50 acquires the speed information of the car 7 (car speed information) via the communication unit 56 as the operating data of the elevator 15 (step S41).

[0163] Next, the temporary data generation unit 51 of the main controller 50 generates temporary data with the car speed information obtained in step S41 as the input value (step S42). The temporary data can be generated, for example, by inputting the car speed information to a random number generation function or a hash value function. That is, the temporary data generation unit 51 can obtain a random number or a hash value, etc., with the car speed information as the input value as the temporary data.

[0164] Next, the communication path selection unit 52 of the main controller 50 acquires the destination floor information of the car 7 as the operating data (step S43).

[0165] Next, based on the destination floor information acquired in step S43, the communication path selection unit 52 selects a specified controller as the sub - controller 60 (step S44). For example, the communication path selection unit 52 can input the destination floors included in the destination floor information to a minimum value function and select the sub - controller 60 based on the obtained output value. Thus, the controller with the least number of destination floor registrations is selected as the sub - controller 60.

[0166] By performing such processing by the communication path selection unit 52, the floor controller 11 provided on the floor with the least number of destination floor registrations, including the floor where the destination floor registration is zero, is selected as the sub - controller 60. That is, the floor controller 11 with spare capacity is selected as the sub - controller 60 that constitutes the transmission path of the information group. Therefore, by executing the elevator connection device confirmation method of the present embodiment, the influence on the normal operation of the elevator 15 can be suppressed to the minimum.

[0167] [Example (3): Operating data for temporary data and operating data for sub - controller 60 selection = car load information]

[0168] Next, referring to Figure 16 , an example of the generation of temporary data by the main controller 50 and a decision example (3) of the sub - controller 60 will be described.

[0169] First, the temporary data generation unit 51 of the main controller 50 acquires the load information (car load information) of the car 7 via the communication unit 56 as the operation data of the elevator 15 (step S51).

[0170] Next, the temporary data generation unit 51 of the main controller 50 generates temporary data with the car load information acquired in step S51 as the input value (step S52). The temporary data can be generated, for example, by inputting the car load information into a random number generation function or a hash value function. That is, the temporary data generation unit 51 can obtain a random number or a hash value, etc., with the car load information as the input value as the temporary data.

[0171] Next, the communication path selection unit 52 of the main controller 50 selects a specified controller as the sub - controller 60 based on the information on the distribution position of the random number or hash value with the car load information as the input value generated in step S52 (step S53). Specifically, the communication path selection unit 52 divides the numerical range in which a random number or hash value can be generated according to the number of sub - controllers 60, and selects the sub - controller 60 according to which data range the actually generated random number or hash value belongs to.

[0172] [Example (4): Operation data for temporary data and operation data for selecting the sub - controller 60 = operation count information]

[0173] Next, refer to Figure 17 , and an example (4) of the generation of temporary data by the main controller 50 and the determination of the sub - controller 60 will be described.

[0174] First, the temporary data generation unit 51 of the main controller 50 acquires the information on the operation count of the elevator 15 via the communication unit 56 as the operation data of the elevator 15 (step S61).

[0175] Next, the temporary data generation unit 51 of the main controller 50 generates temporary data with the operation count information acquired in step S61 as the input value (step S62). The temporary data can be generated, for example, by inputting the operation count information into a random number generation function or a hash value function. That is, the temporary data generation unit 51 can obtain a random number or a hash value, etc., with the operation count information as the input value as the temporary data.

[0176] Next, the communication path selection unit 52 of the main controller 50 selects a specified controller as the sub - controller 60 based on the magnitude of the operation count value (step S63). For example, the communication path selection unit 52 can select the elevator controller 5 of the elevator 15 with the smallest operation count as the sub - controller 60.

[0177] In addition, the communication path selection unit 52 may also select the elevator controller 5 of the elevator 15 with the running times being the median or the maximum as the secondary controller 60. That is, the value used to select the secondary controller 60 can be any value as long as it can select any elevator controller 5 value.

[0178] [Example (5): Operation data for temporary data and operation data for selecting the secondary controller 60 = Passenger movement information]

[0179] Next, referring to Figure 18 , an example (5) of the generation of temporary data by the main controller 50 and the determination of the secondary controller 60 will be described.

[0180] First, the temporary data generation unit 51 of the main controller 50 obtains information on the number of passengers moving (transported) in the elevator 15 via the communication unit 56 as the operation data of the elevator 15 (step S71).

[0181] Next, the temporary data generation unit 51 of the main controller 50 generates temporary data with the passenger movement information obtained in step S71 as the input value (step S72). The temporary data can be generated, for example, by inputting the passenger movement information into a random number generation function or a hash value function. That is, the temporary data generation unit 51 can obtain a random number or a hash value, etc. with the passenger movement information as the input value as the temporary data.

[0182] Next, the communication path selection unit 52 of the main controller 50 selects a specified controller as the secondary controller 60 based on the amount of passenger movement (step S73). For example, the communication path selection unit 52 can select the elevator controller 5 of the elevator 15 with the least number of passengers as the secondary controller 60. In addition, the communication path selection unit 52 may also select the elevator controller 5 of the elevator 15 with the median or the most number of passengers as the secondary controller 60. That is, the value used to select the secondary controller 60 can be any value as long as it can select any elevator controller 5 value.

[0183] [Example (6): Operation data for temporary data and operation data for selecting the secondary controller 60 = Elevator stop times information]

[0184] Next, referring to Figure 19 , an example (6) of the generation of temporary data by the main controller 50 and the determination of the secondary controller 60 will be described.

[0185] First, the temporary data generation unit 51 of the main controller 50 obtains information on the number of stops of the car 7 on each floor via the communication unit 56 as the operation data of the elevator 15 (step S81).

[0186] Next, the temporary data generation unit 51 of the main controller 50 generates temporary data with the stop count information acquired in step S81 as the input value (step S82). The temporary data can be generated, for example, by inputting the stop count information to a random number generation function or a hash value function. That is, the temporary data generation unit 51 can obtain a random number, a hash value, etc. with the stop count information as the input value as the temporary data.

[0187] Next, the communication path selection unit 52 of the main controller 50 selects a prescribed controller as the sub-controller 60 based on the number of stops (step S83). For example, the communication path selection unit 52 can select the floor controller 11 of the floor with the fewest stop counts of the car 7 as the sub-controller 60. In addition, the communication path selection unit 52 can also select the floor controller 11 of the floor with the median or the most stop counts of the elevator 15 as the sub-controller 60. That is, as long as the value for selecting the sub-controller 60 is a value that can select any floor controller 11, it can be any value.

[0188] In addition, the combination of the temporary data and the sub-controller 60 in the above examples (1) to (6) is only an example, and the examples of the combination of the temporary data and the sub-controller 60 are not limited to these. In addition, the temporary data can also be generated based on operation data other than the operation data shown in examples (1) to (6).

[0189] <Various effects>

[0190] In the above-described embodiment, the main controller 50 of the elevator system 100 includes a communication path selection unit 52, an encryption unit 54, a communication unit 56, and a discrimination unit 59 (all refer to Figure 2 ). The communication path selection unit 52 selects any one of the plurality of controllers as the sub-controller 60. The encryption unit 54 encrypts information including at least the identification information of the sub-controller 60 using the public key 31 acquired from the slave node 30, thereby generating encrypted data. The communication unit 56 transmits the encrypted data to the node 30. The discrimination unit 59 compares the source information of the information group transmitted with the controller identified by the node 30 as the source with the information of the sub-controller 60 selected by the communication path selection unit 52, where the node 30 identifies the controller based on the identification information of the sub-controller 60 obtained by decrypting the encrypted data by the node 30. Then, when the two pieces of information do not match, the communication path selection unit 52 determines that the node 30 is an unauthorized device that does not conform to the specifications of the elevator system 100.

[0191] Therefore, according to the present embodiment, without adding a new device or channel, it is possible to confirm whether an external device (node 30) connected to the elevator system 100 is an authorized device only by using the existing structure. Thus, it is possible to save the cost of a mechanism for authenticating newly added nodes 30.

[0192] In addition, in the above-described embodiment, the combination of the main controller 50, the sub-controller 60, and the node 30 is dynamically generated by the main controller 50 selecting the sub-controller 60. Then, the authentication of the node 30 is performed by transmitting information groups (initial information group P1 to tertiary information group P4) between these devices. Therefore, according to the present embodiment, it is possible to make it difficult for a third party who wants to perform an illegal act to analyze the authentication method of the node 30.

[0193] In addition, in the above-described embodiment, the communication path selection unit 52 of the main controller 50 selects any one of the plurality of controllers as the sub-controller 60 based on the operation information of the elevator 15 acquired from the elevator system 100 or the processed information of the operation information. That is, in the present embodiment, the sub-controller 60 that constitutes the communication path of the various information groups for authenticating the node 30 is determined based on data that changes constantly and flows, that is, operation data. Thus, the probability that the communication path of the information group for authenticating the node 30 is detected by a third party can be reduced.

[0194] In addition, in the above-described embodiment, the determination unit 59 of the main controller 50 compares the temporary data generated by the temporary data generation unit 51 with the temporary data extracted and decrypted from the tertiary information group P4 transmitted by the sub-controller 60. If the two pieces of information do not match, it is determined that the node 30 is an unauthorized device. In the present embodiment, the temporary data is generated using data that changes constantly and flows, that is, operation data or processed data of the operation data. That is, in the present embodiment, fixed information such as the serial number and MAC address of the node 30 is not used for authentication. Thus, according to the present embodiment, even in the case where a node of an unauthorized device that fakes and copies this information is added, it is possible to prevent the node from being erroneously authenticated as an authorized device.

[0195] In addition, in the above-described embodiment, for the encrypted data encrypted using the public key 31 acquired from the node 30 in the main controller 50, the private key N32 corresponding to the public key 31 is used for decryption in the node 30. That is, when the node 30 is an unauthorized device, since the node 30 does not hold the public key 31, neither the generation of the encrypted data in the main controller 50 nor the decryption of the encrypted data by the node 30 can be performed, and the subsequent authentication process cannot be performed. Thus, according to the present embodiment, the determination unit 59 of the main controller 50 can easily determine that the node is an unauthorized device even in the case where a node of an unauthorized device is added.

[0196] In addition, in the above-described embodiment, the encryption unit 54 of the main controller 50 includes the temporary data (encrypted temporary data) encrypted using the private key M53 in the encrypted data, and the decryption unit 58 decrypts the encrypted temporary data included in the three-message group P4 sent from the sub-controller 60 using the private key M53. When the node 30 is an unauthorized device and cannot appropriately process the first-message group P2 sent from the main controller 50, the three-message group P4 including the encrypted temporary data will not be sent from the sub-controller 60 to the main controller 50. That is, according to this embodiment, the discrimination unit 59 of the main controller 50 can easily determine that the node is an unauthorized device even in the case of a node with an unauthorized device added.

[0197] In addition, in the above-described embodiment, when the time from when the communication unit 56 of the main controller 50 sends the first-message group P2 including the encrypted data to the node 30 until receiving the three-message group P4 from the sub-controller 60 exceeds the specified threshold time, the discrimination unit 59 of the main controller 50 determines that the node 30 is an unauthorized device. When the node 30 is an unauthorized device, the secondary communication process of sending the second-message group P3 from the node 30 to the sub-controller 60 and the tertiary communication process of sending the three-message group P4 from the sub-controller 60 to the main controller 50 will not be appropriately executed. Therefore, the communication unit 56 of the main controller 50 cannot receive the three-message group P4 whose source is the sub-controller 60 within the specified threshold time after sending the first-message group P2 from the main controller 50 to the node 30.

[0198] Thus, according to this embodiment, the discrimination unit 59 of the main controller 50 can also easily determine whether the node 30 is a regular device based on the time from when the main controller 50 sends the first-message group P2 to the node 30 until receiving the three-message group P4.

[0199] In addition, the above-described embodiment has described the structures of the device and the system in detail and specifically for easy understanding of the present invention, and is not limited to having all the structures described.

[0200] In addition, Figures 1 - 3 The control lines or information lines shown by solid lines in the figure show those considered necessary for explanation, and do not necessarily show all the control lines and information lines on the product. In fact, it can also be considered that almost all the structures are interconnected.

[0201] In addition, in this specification, the processing steps of describing the processing in time sequence include the processing that is sequentially executed in the recorded order in time sequence, and also include the processing that is not necessarily in time sequence, but is executed in parallel or individually (for example, parallel processing or object-based processing).

[0202] Furthermore, with respect to each component of the elevator system according to one embodiment of the present invention described above, as long as the respective hardware can transmit and receive information to and from each other via a network, it can be implemented by any hardware. In addition, the processing performed by a certain processing unit can be implemented by one piece of hardware or by distributed processing performed by a plurality of pieces of hardware.

[0203] Explanation of Reference Numerals

[0204] 1... Central device, 3... Communication controller, 4... Group management controller, 5... Elevator controller, 10... Car controller, 11... Floor controller, 12... Channel, 15... Elevator, 16... Channel, 17... Channel, 19... Maintenance terminal, 20... Management terminal, 30... Node, 31... Public key, 33... Decryption unit, 34... Information group generation unit, 35... Communication unit, 50... Main controller, 51... Temporary data generation unit, 52... Communication path selection unit, 54... Encryption unit, 55... Information group generation unit, 56... Communication unit, 57... Address determination unit, 58... Decryption unit, 59... Discrimination unit, 60... Sub controller, 61... Communication unit, 62... Information group transmission unit, 100... Elevator system, M53... Private key, N32... Private key, P1... Initial information group, P2... Primary information group, P3... Secondary information group, P4... Tertiary information group.

Claims

1. An elevator connection device confirmation system including a plurality of controllers for confirming an external device connected to an elevator system, characterized in that: A main controller constituted by any one of the plurality of controllers includes: A selection unit that selects any one of the plurality of controllers as a sub - controller; An encryption unit that uses an encryption key obtained from the external device to encrypt information including at least the identification information of the sub - controller to generate encrypted information; A transmission unit that transmits the encrypted information to the external device; and A discrimination unit that compares the source information of an information group transmitted with the controller identified by the external device as the source with the information of the sub - controller selected by the selection unit, and discriminates that the external device is an irregular device that does not conform to the specifications of the elevator system when the two are inconsistent, where the external device identifies the controller based on the identification information of the sub - controller obtained by decrypting the encrypted information.

2. The elevator connection device confirmation system according to claim 1, characterized in that: The selection unit selects any one of the plurality of controllers as the sub - controller based on the operation information of the elevator obtained from the elevator system or the processed information of the operation information.

3. The elevator connection device confirmation system according to claim 2, characterized in that: The main controller further includes a temporary information generation unit that generates temporary information using the operation information of the elevator obtained from the elevator system or the processed information of the operation information, The encryption unit includes the temporary information generated by the temporary information generation unit in the encrypted information, The encrypted temporary information is included in the information group, The discrimination unit compares the temporary information generated by the temporary information generation unit with the temporary information extracted from the information group and decrypted, and determines that the external device is the irregular device when the two are inconsistent.

4. The elevator connection device confirmation system according to claim 3, characterized in that: The encryption key is a public key, and the external device decrypts the encrypted information using a private key corresponding to the public key.

5. The elevator connection device confirmation system according to claim 4, characterized in that: The encryption unit includes the temporary information encrypted with a second private key different from the private key in the encrypted information, It further includes a decryption unit that decrypts the encrypted temporary information included in the information group using the second private key and outputs it to the discrimination unit.

6. The elevator connection device confirmation system according to claim 5, characterized in that: The operation information of the elevator used by the selection unit or the discrimination unit includes at least one of the position information of the elevator car, the speed information of the car, the load information of the car, the call information of the elevator, the destination floor information of the elevator, the number of operations of the elevator, and the number of transported passengers of the elevator.

7. The elevator connection device confirmation system according to claim 6, characterized in that: When the time from when the sending unit sends the encrypted information to the external device until the information group is received by the discrimination unit exceeds a specified threshold time, it is determined that the external device is the irregular device.

8. The elevator connection device confirmation system according to any one of claims 1 to 7, characterized in that: When the discrimination unit determines that the external device is an irregular device, it notifies each of the plurality of controllers of the fact that the external device is an irregular device.

9. The elevator connection device confirmation system according to claim 8, characterized in that: When the discrimination unit determines that the external device is the irregular device, it gives an instruction to the controller that controls the operation of the elevator to stop the car of the elevator at the nearest floor.

10. An elevator connection device confirmation method performed by an elevator connection device confirmation system including a plurality of controllers for confirming an external device connected to an elevator system, characterized in that, Comprising: A step in which a main controller constituted by any one of the plurality of controllers selects any one of the plurality of controllers as a sub-controller; A step in which the main controller encrypts information including at least the identification information of the sub-controller using an encryption key obtained from the external device to generate encrypted information; A step in which the main controller sends the encrypted information to the external device; and A step in which the main controller compares the source information of the information group sent from the controller identified by the external device as the source with the information of the selected sub-controller, and determines that the external device is an irregular device that does not conform to the specifications of the elevator system when the two do not match, wherein the external device identifies the controller based on the identification information of the sub-controller obtained by decrypting the encrypted information.

Citation Information

Patent Citations

  • Service tool authentication information management

    JP2019023868A

  • Authentication system and authentication method

    CN104349947A

  • Elevator

    JP2013023356A