Elevator service management system and program management method for elevator service

By introducing an elevator service management system into the elevator system, and using the management center to generate a dedicated downloader and management service processing program, the problems of illegal use and misuse in the elevator system are solved, and the management and operation of legitimate services are realized.

CN117699595BActive Publication Date: 2026-03-27HITACHI LTD
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-06-26
Publication Date
2026-03-27

AI Technical Summary

Technical Problem

Existing elevator remote management systems suffer from problems where unauthorized operations lead to the misuse or exploitation of services that should not be used.

Method used

By introducing an elevator service management system into the elevator system, the management center communicates with the controller to manage service processing programs, generate a dedicated downloader for downloading, and manage programs based on contract information and execution form information to prevent unauthorized use and misuse.

Benefits of technology

Effectively prevent the illegal use and misuse of elevator services, and ensure that the service is operated legally in accordance with the contract.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117699595B_ABST
    Figure CN117699595B_ABST
Patent Text Reader

Abstract

The present invention provides an elevator service management system and a program management method of an elevator service. By managing a program stored in a controller of an elevator system, illegal use or erroneous use of the elevator service is prevented. In an elevator service management system (1), a management center (2) has: a contract information database (100) that holds machine equipment information (101), contract form information (103), and execution form information (106); a program database (120) that holds processing programs of services corresponding to each execution form; and an update management section (141) that manages issuance of the processing programs held in the program database (120) to a controller (20) based on information of the contract information database (100). Also, the update management section (141) generates a downloader for the controller (20) that downloads the processing program based on the contract form information (103) of the service and the execution form information (106) of the processing program thereof, and provides the controller (20) with the downloader.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to an elevator service management system and a program management method of elevator service, which are suitable for an elevator service management system and a program management method of elevator service that manage a program of a service (elevator service) provided by an elevator system. BACKGROUND

[0002] In the past, an elevator system has been configured with a plurality of types of controllers, each of which mounts various controls and service functions as a program, and by setting the validity or invalidity of the program, it is possible to select or deselect a service provided to a user or the like.

[0003] Here, for example, Patent Literature 1 discloses a remote management system for an elevator, "provided with: a remote management device connected to a control panel of an elevator, which remotely manages the elevator based on remote management information corresponding to the elevator; and a regulation system which manages the remote management information".

[0004] PRIOR ART DOCUMENTS

[0005] PATENT LITERATURE

[0006] Patent Literature 1: International Publication No. 2022 / 064604

[0007] However, in the remote management system for an elevator described in Patent Literature 1 described above, since, as indicated in paragraph 〔0019〕 of Patent Literature 1, "with respect to a single remote management process, only at the time of startup, setting information related to the process, i.e., information indicating validity or invalidity, is stored to the control panel 9 as a remote management parameter, and a remote management program is executed in correspondence with the validity or invalidity", there is a problem that, by illegally operating the setting of the validity or invalidity of the above-described setting information, a service that should not be used is used, or an erroneous usage mode is performed. SUMMARY

[0008] The present application takes the above points into consideration and proposes an elevator service management system and a program management method of elevator service, which, by managing a program stored in a controller of an elevator system, can prevent illegal use or erroneous use of elevator service.

[0009] To solve the related problems, in the present application, there is provided an elevator service management system that manages a service provided from an elevator system based on a contract, the elevator service management system including: an elevator system having at least one controller that controls the operation of an elevator; and a management center communicably connected to the controller, which manages a processing program executed at the controller for providing the service, the management center having: a contract information database that holds machine equipment information indicating the structure of machines and equipment of the elevator system, contract form information indicating the contract form of the service, and execution form information indicating the execution form of the processing program of the service; a program database that holds the processing program of the service corresponding to each of the execution forms; and an update management section that manages the distribution of the processing program held at the program database to the controller based on the information of the contract information database, the update management section generating a downloader for the controller that downloads the processing program based on the contract form information of the service and the execution form information of the processing program thereof, and providing the downloader to the controller.

[0010] Further, to solve the related problems, in the present application, there is provided a program management method of an elevator service, which is implemented by an elevator service management system that manages a service provided from an elevator system based on a contract, the elevator service management system including: an elevator system having at least one controller that controls the operation of an elevator; and a management center communicably connected to the controller, which manages a processing program executed at the controller for providing the service, the management center having: a contract information database that holds machine equipment information indicating the structure of machines and equipment of the elevator system, contract form information indicating the contract form of the service, and execution form information indicating the execution form of the processing program of the service; a program database that holds the processing program of the service corresponding to each of the execution forms; and an update management section that manages the distribution of the processing program held at the program database to the controller based on the information of the contract information database, the update management section generating a downloader for the controller that downloads the processing program based on the contract form information of the service and the execution form information of the processing program thereof, and providing the downloader to the controller.

[0011] Effects of the Invention

[0012] According to the present application, it is possible to prevent illegal use or erroneous use of an elevator service. BRIEF DESCRIPTION OF DRAWINGS

[0013] Figure 1 is a diagram showing an example of the overall structure of an elevator service management system 1 according to a first embodiment of the present application.

[0014] Figure 2is a diagram showing a hardware configuration example of the controller 20.

[0015] Figure 3 is a diagram showing an internal configuration example of the elevator service management system 1.

[0016] Figure 4 is a diagram showing a data structure example of the contract form information 103.

[0017] Figure 5 is a diagram showing a data structure example of the execution form information 106.

[0018] Figure 6 is a diagram showing a data structure example of the authenticity confirmation unit 110.

[0019] Figure 7 is a diagram showing a data structure example of the program information 120.

[0020] Figure 8 is a flowchart showing a processing step example of the downloader generation processing.

[0021] Figure 9 is a diagram showing an example of a binary format of the downloader 84.

[0022] Figure 10 is a flowchart showing a processing step example of the service program download processing.

[0023] Figure 11 is a diagram showing a data structure example of the reply data 210.

[0024] Figure 12 is a diagram showing an internal configuration example of the elevator controller 6 after completion of the service program download processing.

[0025] Figure 13 is a flowchart showing a processing step example of the authenticity confirmation processing at the time of program startup.

[0026] Figure 14 is a flowchart showing a processing step example of the processing at the time of illegal detection.

[0027] Figure 15 is a flowchart showing a processing step example of the downloader update processing.

[0028] Figure 16 is a flowchart showing a processing step example of the processing at the time of contract form change.

[0029] Figure 17 is a flowchart showing a processing step example of the processing at the time of service erasure.

[0030] Figure 18is a view showing an example of the internal structure of the management center 2A in the elevator service management system 1A according to the second embodiment.

[0031] Figure 19 is a view showing an example of the data structure of the service information 301 and the execution structure information 306.

[0032] Figure 20 is a view showing an example of the display of the WEB page for selection of the execution structure of the service selection or the service program.

[0033] Figure 21 is a view showing an example of the display of the WEB page for selection of the execution structure of the service selection or the service program. Figure 20 is a view showing an example of the transition screen from the WEB page of

[0034] Figure 22 is a view showing an example of the display of the WEB page for service update.

[0035] Figure 23 is a view showing an example of the transition screen from the WEB page of Figure 22

[0036] Figure 24 is a view showing an example of the display of the WEB page for device selection.

[0037] Figure 25 is a view showing an example of the transition screen from the WEB page of Figure 24

[0038] Figure 26 is a view showing an example of the display of the WEB page in the series of processes for service approval (one).

[0039] Figure 27 is a view showing an example of the display of the WEB page in the series of processes for service approval (two).

[0040] Figure 28 is a view showing an example of the display of the WEB page in the series of processes for service approval (three).

[0041] Figure 29 is a view showing an example of the display of the WEB page in the series of processes for service approval (four).

[0042] Figure 30 is a flowchart showing an example of the processing steps of the service approval process.

[0043] Figure 31 is a view showing an example of the overall structure of the elevator service management system 1B according to the third embodiment.

[0044] Figure 32 is a view showing an example of the internal structure of the group management controller 5 in the third embodiment.​​

[0045] Figure 33 Fig. 3 is a diagram showing an example of the internal structure of the virtual machine 62 in the third embodiment.

[0046] Figure 34 Fig. 4 is a diagram showing an example of the overall structure of the elevator service management system 1C in the fourth embodiment.

[0047] Figure 35 Fig. 5 is a diagram showing an example of the internal structure of the elevator controller 6 in the fourth embodiment.

[0048] Figure 36 Fig. 6 is a diagram showing an example of the internal structure of the edge controller 51 in the fourth embodiment.

[0049] Explanation of Reference Numerals

[0050] 1, 1A, 1B, 1C Elevator service management system

[0051] 2, 2A Management center

[0052] 3, 13, 17, 18 Communication path

[0053] 4 Communication controller

[0054] 5 Group management controller

[0055] 6 Elevator controller

[0056] 7 Motor

[0057] 8 Car

[0058] 9 Counterweight

[0059] 10 Suspension rope

[0060] 11 Car controller

[0061] 12 Floor controller

[0062] 14 In-car button

[0063] 15 Up-and-down call button

[0064] 16 Elevator

[0065] 19 Elevator group

[0066] 20 Controller

[0067] 21 System bus

[0068] 22 Processor

[0069] 23 ROM

[0070] 24 RAM

[0071] 25 interface

[0072] 51, 52, 53 edge controller

[0073] 60 cloud system

[0074] 62 virtual machine

[0075] 70 management terminal

[0076] 80 firmware

[0077] 81 standard control program

[0078] 83, 84 downloader

[0079] 85 individual identifier

[0080] 100 contract information database (contract information)

[0081] 101 machine device information

[0082] 103 contract form information

[0083] 104 service ID

[0084] 105 contract type

[0085] 106 execution form information

[0086] 107 execution type

[0087] 108 program ID

[0088] 110 authenticity confirmation unit database (authenticity confirmation unit)

[0089] 111 digest value method

[0090] 113 password method

[0091] 120 program database (program information)

[0092] 121 controller firmware

[0093] 122, 125, 128 service program

[0094] 123 edge controller firmware

[0095] 124 client firmware

[0096] 126 cloud system firmware

[0097] 127 client firmware

[0098] 130 generation information database (generation information)

[0099] 131 contract information

[0100] 133 authenticity information

[0101] 135 program structure information

[0102] 140 management center control section

[0103] 141 update management section

[0104] 143 execution form selection section

[0105] 145 program selection section

[0106] 147 downloader generation section

[0107] 149 downloader issue section

[0108] 201 service list

[0109] 202 service number (service No)

[0110] 203 authenticity number

[0111] 204 authenticity confirmation information (combination authenticity)

[0112] 205 authenticity confirmation processing list

[0113] 206 authenticity confirmation processing program (authenticity processing)

[0114] 207 communication processing program (communication processing)

[0115] 210 reply data

[0116] 211 contract conditions (conditions)

[0117] 213 processing completed data

[0118] 220 buy service program (buy service)

[0119] 222 subscribe service program (subscribe service)

[0120] 300 service information database

[0121] 301 service information

[0122] 302 service ID

[0123] 303 service name

[0124] 304 service explanation

[0125] 305 contract form

[0126] 306 execution structure information

[0127] 307 structure ID

[0128] 308 structure description

[0129] 309 device

[0130] 310 network information

[0131] 340 management center control section

[0132] 341 association information extraction section

[0133] 343 display generation section

[0134] 345 service extraction section

[0135] 347 service voting section

[0136] 350 service selection screen

[0137] 360, 390 structure selection screen

[0138] 370 service update screen

[0139] 400 device selection screen

[0140] 410 service addition screen

[0141] 420, 430 service confirmation screen

[0142] 440 service voting screen

[0143] 450 service proposal screen

[0144] 500 robot

[0145] 501, 511 standard control program

[0146] 503, 513 downloader

[0147] 505, 515 individual identifier

[0148] 507, 517 condition

[0149] 509 subscription service

[0150] 519 collaboration service

[0151] 600 sensor

[0152] 601 standard control program

[0153] 603, 613 downloader

[0154] 605.615 individual identifier

[0155] 607, 617 condition

[0156] 609 buy service

[0157] 611 standard image processing program

[0158] 619 resolution service. DETAILED DESCRIPTION

[0159] Embodiments of the present application will be described in detail below with reference to the attached drawings.

[0160] In addition, the following description and drawings are provided for illustration of the present application, and appropriate omissions and simplifications are made for the sake of clarity. Further, the characteristic combinations described in the embodiments are not necessarily all essential in the means for solving the problems of the present application. The present application is not limited to the embodiments, and all applications consistent with the idea of the present application are included in the technical scope of the present application. As for the present application, various additions, changes, and the like can be made within the scope of the present application by those skilled in the art. The present application can be implemented in other various forms. Each of the constituent elements can be either a plurality or a single unless specifically limited. The constituent elements can be combined with other elements or can be divided into a plurality of elements.

[0161] In the following description, various information is sometimes expressed as "table", "list", "queue", and the like, but can be expressed in data structures other than these. In order to express independence from data structures, "XX table", "XX list", and the like are sometimes referred to as "XX information". In describing the contents of each information, "identification information", "identifier", "name", "ID", "number", and the like are used, but these can be replaced with each other.

[0162] Further, in the following description, in the case of describing without distinguishing elements of the same kind, a reference numeral or a common number in a reference numeral is used, and in the case of distinguishing elements of the same kind, a reference numeral of the element is sometimes used, or an ID assigned to the element is used instead of the reference numeral.

[0163] Further, in the following description, there are cases where the processing performed by executing a program is described, but the program performs the determined processing while appropriately using a storage resource (for example, a memory) and / or an interface device (for example, a communication port) and the like by being executed by at least one or more processors (for example, a CPU), and thus the subject of the processing can be the processor. Also, the subject of the processing performed by executing the program can be a controller, an apparatus, a system, a computer, a node, a storage system, a storage apparatus, a server, a management computer, a client, or a host having the processor. The subject of the processing performed by executing the program (for example, the processor) can include a hardware circuit that performs a part or all of the processing. For example, the subject of the processing performed by executing the program can include a hardware circuit that performs encryption and decryption, or compression and decompression. The processor functions as a functional unit that realizes a given function by acting in accordance with the program. The apparatus and the system including the processor are apparatuses and systems including the functional unit.

[0164] A program can be installed from a program resource to an apparatus such as a computer. The program resource can be, for example, a program distribution server or a non-transitory storage medium that is readable by a computer. In the case where the program resource is a program distribution server, the program distribution server includes a processor (for example, a CPU) and a non-transitory storage resource, and the storage resource can further store a distribution program and a program that is a distribution object. Then, the processor of the program distribution server can distribute the program that is the distribution object to other computers by executing the distribution program by the processor of the program distribution server. Further, in the following description, two or more programs can be realized as one program, or one program can be realized as two or more programs.

[0165] (1) First Embodiment

[0166] (1-1) Overall Structure

[0167] Figure 1 is a diagram that shows an example of the overall structure of the elevator service management system 1 according to the first embodiment of the present application. In addition, in Figure 1 , the internal structure of only one elevator 16 is shown in detail for the sake of simplification of the explanation.

[0168] The elevator service management system 1 according to the present embodiment is a system that manages a program (a service program) that provides a service of an elevator system including one or more elevators 16. Therefore, the elevator service management system 1 is the elevator system, or a system constituted by the elevator system and a given constituent element.

[0169] The elevator system having one or more elevators 16 is connected to a management center 2 provided remotely, for example, for the purpose of managing, monitoring, and maintaining each elevator 16. That is, the elevator service management system 1 (elevator system) has one or more elevators 16, and a management center 2 connected to the elevators 16 via a communication path 3. Hereinafter, the further detailed structure of the elevator service management system 1 will be described with reference to Figure 1

[0170] The management center 2 is connected to a communication controller 4 via the communication path 3. The internal structure of the management center 2 will be described later with reference to Figure 3

[0171] The communication controller 4 is a controller having a function of mediating communication for the purpose of realizing data transmission and reception, remote operation, and remote maintenance between the management center 2 and the elevators 16. The communication controller 4 is connected to a group management controller 5 via a communication path 18.

[0172] The group management controller 5 is a controller for improving the operation efficiency of the elevators 16 by controlling a plurality of elevators 16 as a group 19. The group management controller 5 is connected to a plurality of elevator controllers 6 via a communication path 17. Alternatively, the management center 2, the elevators 16, and the communication controller 4 can be connected via the communication path 18 by a terminal for managing the elevators, i.e., a management terminal 70, instead of or in addition to the group management controller 5.

[0173] The elevator controller 6 controls a host, i.e., a motor 7, to control the movement of a hoist rope 10 connecting a car 8 and a counterweight 9, thereby making the car 8 move up and down and stop, and providing a service of moving up and down to a user. The elevator controller 6 is connected to one car controller 11 and a plurality of floor controllers 12 corresponding to the number of floors of a building provided, via a communication path 13. Alternatively, a structure of an elevator system in which the group management controller 5 is not provided is also conceivable, in which case the communication controller 4 is connected to the elevator controller 6 or the communication path 17.

[0174] The car controller 11 notifies the elevator controller 6 of a change in state as an operation and an instruction of a user by monitoring the state of a car-in button 14 (specifically, for example, a destination floor button and a door opening / closing button) provided in the car 8, as the on / off state of the button.

[0175] The floor controller 12 notifies the elevator controller 6 of a change in state as an operation and an instruction of a user in each floor, for example, by monitoring the state of an up / down call button 15 provided in each floor.

[0176] ​​Further, in the elevator system of the elevator service management system 1, a structure is also envisaged in which the cloud system 60 is connected to the communication controller 4 via the communication path 3. Furthermore, in the present elevator system, in order to expand the processing performance and the functions of the various operation controllers (the communication controller 4, the group management controller 5, the elevator controller 6, the car controller 11, the floor controller 12), controllers are sometimes additionally added. Hereinafter, such added controllers will be referred to as edge controllers 51, 52, 53. In Figure 1 , edge controllers 51 connected to the communication path 13, edge controllers 52 connected to the communication path 17, and edge controllers 53 connected to the communication path 18 are shown, and by providing one or more of these edge controllers, expansion of the processing performance and the functions of the elevator system becomes easy.

[0177] As above, the elevator system of the elevator service management system 1 is a layered decentralized system composed of a plurality of operation controllers. Hereinafter, these operation controllers (the communication controller 4, the group management controller 5, the elevator controller 6, the car controller 11, the floor controller 12, the edge controllers 51 to 53) will be collectively referred to as "controllers 20". Furthermore, the virtual machine 62 (refer to Figure 33 ) operating on the cloud system 60 can also be regarded as the same structure as the controllers 20 in terms of being able to execute a service program. In the elevator service management system 1, the number and the combination of the plurality of controllers 20 can be arbitrarily constituted according to the requirements of the customer, and therefore the elevator system of the elevator service management system 1 can also be said to be a customized system.

[0178] (1-2) Hardware structure

[0179] Figure 2 is a diagram showing an example of the hardware structure of the controllers 20. The controllers 20 are computers, and as shown in Figure 2 , are provided with a processor 22, a ROM (Read Only Memory) 23, a RAM (Random Access Memory) 24, and an interface (IF) that undertakes input and output and communication. These respective constituent elements are connected to each other by a system bus 21.

[0180] The processor 22 is specifically, for example, an MCU (Micro Controller Unit) or an MPU (MicroProcessor Unit), and can also be a CPU (Central Processing Unit) or the like that is a higher-order concept of these.

[0181] In the controller 20, the processor 22, the ROM 23, and the RAM 24 constitute a processing section. Specifically, the ROM 23 is a nonvolatile memory that stores binary data (firmware 80) of various programs that realize the control and the service processing involved in the present embodiment. The processor 22 reads and executes the above programs from the ROM 23, or reads out the above programs from the ROM 23 and loads them into the RAM 24, and then executes. The RAM 24 is a volatile memory that is temporarily written with variables, parameters, and the like generated in the middle of the processing execution of the above programs by the processor 22, and reads and writes these variables and parameters and the like from the processor 22 as appropriate.

[0182] Further, the ROM 23 sometimes has an area that is restricted from access and an area that is not restricted. In the case of having these areas, the ROM 23 stores, for example, the individual identifier 85 in the former area, and the firmware 80 in the latter area (refer to the description of the firmware 80 below). Figure 3

[0183] The interface 25 is a communication interface that enables the transmission and reception of data between devices such as the controllers 20. The interface 25 is specifically, for example, a GPIO (General Purpose Input / Output), a serial communication device in a form of a multi-drop connection such as RS-485, and the like, and enables the transmission and reception of data based on wired / wireless communication via a wired communication path such as a LAN (Local Area Network), a WAN (Wide Area Network) that provides multiple topologies, and further via a RAN (Radio Area Network) that is a wireless communication path, and the like.

[0184] (1-3) Update management of firmware 80

[0185] Figure 3 is a diagram that shows an example of the internal structure of the elevator service management system 1. In Figure 3 , the internal structure of the management center 2 that performs the update management of the firmware 80 is shown in detail, focusing on the firmware 80 mounted on the controller 20. In addition, in Figure 3 , the elevator controller 6 is used as an example of the controller 20, but is not limited thereto, and can be replaced with another controller.

[0186] (1-3-1) Structure on the controller 20 side

[0187] As shown in Figure 3 , the firmware 80 is constituted at least by the standard control program 81 involved in the operation control of the elevator 16, and the downloader 83 at the time of shipment of the elevator controller 6. Further, as shown in Figure 2 ​As described in the explanation of the individual identifier 85, the information for identifying the controller 20, that is, the individual identifier 85 is stored in the ROM 23.

[0188] The standard control program 81 is a program that controls the state of the elevator system by controlling the operation of the elevator 16, specifically, for example, the standard control can be performed at normal times, on the other hand, the control to the safety state can be performed when an abnormality such as an illegal occurs. Here, the control content of the safety state can be variously set according to the abnormality that occurs, for example, the setting to move the car 8 to the nearest floor and perform the door opening operation, and the like.

[0189] The downloader 83 is a program that performs the download of the service program (a program for service processing that provides the service of the elevator) for the time of shipment (initial use). The downloader 83 notifies the management center 2 of the individual identifier 85 at the time of initial start. Since the individual identifier 85 is important information, the notification is performed by implementing a countermeasure such as encryption, for example. The management center 2 generates the downloader 84 as a new downloader program based on the contract information corresponding to the individual identifier 85, and transmits to the controller 20. Then, based on the reception of the new downloader 84, the downloader 83 replaces itself and the new downloader 84.

[0190] (1-3-2) Structure on the management center 2 side

[0191] As shown in Figure 3 , the management center 2 is provided with a contract information database (DB) 100, a authenticity confirmation unit database (DB) 110, a program database (DB) 120, a generation information database (DB) 130, and a management center control section 140. The contract information DB 100, the authenticity confirmation unit DB 110, the program DB 120, and the generation information DB 130 are each a storage unit such as a database that stores information (data), and the management center control section 140 is a control unit that provides various functions by executing a program by a processor.

[0192] (1-3-2-1) Contract information DB 100

[0193] The contract information DB 100 manages information related to the contract of each customer, specifically, the machine equipment information 101 of the elevator system, the contract form information 103, and the execution form information 106. In the following explanation, these information managed by the contract information DB 100 are sometimes collectively described as the contract information 100.

[0194] The machine equipment information 101 is information related to the machine and the equipment that constitute the elevator system. The machine equipment information 101 is specifically, for example, information indicating the presence or absence of each constituent element, and the number or connection form, and the like, and can include the individual identifier 85 of each constituent element.

[0195] The contract form information 103 is information related to the form of the contract for each client, and is information related to the form of the service provided by the contract. Figure 4 is a diagram showing an example of the data structure of the contract form information 103. As shown in Figure 4 , the contract form information 103 has a service ID 104 showing an identifier of the service process provided, and a contract type 105 showing the category of the contract. There are three modes of "subscription", "buy-in", and "wipe-out" in the contract type 105, for example. "Subscription" is a contract form in which a given limit is set to the time or the number of times of use of the service, and the like. "Buy-in" is a contract form in which the service can be used in principle forever. "Wipe-out" is a contract form meaning the cancellation of the service, and requires the service program of the service to be deleted or replaced. There are two modes of "update (execution form maintained)" and "execution form changed (controller, edge controller, cloud)" in "subscription". There are two modes of the case where the service of the subscription contract is changed to buy-in by "contract change" at the time of update, and the case where buy-in is made by "new" in "buy-in".

[0196] The execution form information 106 is information related to the execution form of the service process of providing the service. Figure 5 is a diagram showing an example of the data structure of the execution form information 106. As shown in Figure 5 , the execution form information 106 has an execution type 107 and a program ID 108 showing an identifier of the program executed in the service process. More specifically, the program ID 108 is an identifier of the program executed in the remote system or the manipulation controller in the service process. The execution type 107 specifically exists in three categories of local execution in the controller 20, remote execution in the edge controller 51, 52, 53, and remote execution in the cloud system 60, for example.

[0197] (1-3-2-2) Authenticity Confirmation Unit DB 110

[0198] The authenticity confirmation unit DB 110 manages information related to the means of confirming the authenticity of the program (the firmware 80), and specifically, manages the digest value method 111 for confirming the authenticity of the firmware 80 and the password method 113 for the firmware 80. In the following description, these information managed by the authenticity confirmation unit DB 110 are sometimes collectively described as the authenticity confirmation unit 110.

[0199] Figure 6 is a diagram showing an example of the data structure of the authenticity confirmation unit 110. As shown in Figure 6As shown, the authenticity verification unit 110 manages the digest value method 111 and the password method 113 by combining the verification unit ID 115 used to distinguish verification units and the verification processing programs (verification processing 116 for A, verification processing 117 for B, and verification processing 118 for C) corresponding to the type of processor 22 used in the elevator system (e.g., CPU A, CPU B, CPU C). Specific examples of the digest value method 111 include hash values ​​and MAC (Message Authentication Code), and specific examples of the password method 113 include AES (Advanced Encryption Standard). Furthermore, the authenticity verification unit 110 expects to use an individual identifier 85 specifically for the controller 20, but is not limited to this.

[0200] (1-3-2-3) Program DB120

[0201] Program DB120 manages information about each service processing program (firmware 80) that provides services. In the following description, the information managed by program DB120 will sometimes be referred to as program information 120.

[0202] Figure 7 This is a diagram illustrating an example of the data structure used to represent program information 120. For example... Figure 7 As shown, program information 120 needs to prepare firmware 80 corresponding to the type of processor 22 (e.g., CPU A, CPU B, CPU C) mounted on controller 20. Furthermore, in the case where the elevator system is connected to cloud system 60, a program corresponding to the type of cloud system 60 also needs to be prepared.

[0203] exist Figure 7 The image shows an example of how program information 120 manages service programs corresponding to three types of processors 22 (CPU A, CPU B, CPU C) and three types of cloud systems 60 (Cloud X, Cloud Y, Cloud Z) for a single service process. Cloud X, Cloud Y, and Cloud Z are environments in which virtual machines, equivalent to controller 20, operate. Furthermore, each service program managed by program information 120 is assigned... Figure 5 The program ID 108 of the execution form information 106 shown.

[0204] More specifically, Figure 7 In the program information 120, there is a service program 122, which is the firmware 121 for the controller and manages the service processing of the firmware 80 that is executed locally on the controller 20.

[0205] also, Figure 7The program information 120 manages, as the edge controller firmware 123, service programs 125 used for service processing performed in the edge controllers 51, 52, 53. In addition, the service programs 125 and the client firmware 124 executed in the controller 20 for remotely using the programs are managed in combination.

[0206] Further, Figure 7 The program information 120 manages, as the cloud system firmware 126, service programs 128 used for service processing performed in the cloud system 60. The service programs 128 and the client firmware 127 executed in the controller 20 for remotely using the programs are also managed in combination.

[0207] (1-3-2-4) Generation information DB 130

[0208] The generation information DB 130 manages information related to the downloader generated in the management center control section 140, and specifically manages contract information 131, authenticity information 133, and program structure information 135. Generally, the existing downloader is a general program for downloading binary data, and there is no great change in the manner. Therefore, sometimes the action of the downloader and the contents of communication are analyzed. In contrast, in the present embodiment, by generating the downloader for each client in combination of various information such as structure information specific to the machine device, contract forms such as subscription, purchase, and the form of executing the service processing, it is possible to make the above analysis difficult. Further, even in the case where the service processing (i.e., the service program) is illegally copied by analyzing the downloader, it is possible to make long-term illegal use difficult.

[0209] (1-3-2-5) Management center control section 140

[0210] As shown in FIG. 1, the management center control section 140 is configured of an update management section 141, an execution form selection section 143, a program selection section 145, a downloader generation section 147, and a downloader release section 149. The functions of each section of the management center control section 140 are realized by reading out and executing a given program in the computer of the management center 2 by the processor. Figure 3 The update management section 141 is a processing section that governs the overall control in the management center control section 140, and in addition to controlling the actions of the other processing sections, manages the contract information 100, the authenticity confirmation unit 110, the program information 120, and the generation information 130, and further manages the update status of each.

[0211] The execution form selection section 143 selects an appropriate execution form based on the contract information 100.

[0212]

[0213] ​The program selection section 145 selects a combination of programs (firmware) corresponding to the execution form selected by the execution form selection section 143 from the program information 120.

[0214] The downloader generation section 147 generates a downloader for appropriately downloading the firmware selected by the program selection section 145.

[0215] The downloader distribution section 149 distributes the downloader generated by the downloader generation section 147 to the controller 20 (e.g., the elevator controller 6) as an object.

[0216] (1-4) Generation of downloader

[0217] Hereinafter, the downloader generation processing by which the management center control section 140 generates the downloader 84 that is dedicated to the controller 20 based on the contract information 100 will be described.

[0218] Figure 8 is a flowchart showing an example of the processing steps of the downloader generation processing. Further, Figure 9 is a diagram showing an example of the binary format of the downloader 84.

[0219] According to Figure 8 , first, the update management section 141 of the management center control section 140 acquires the machine device information 101, the contract form information 103, and the execution form information 106 of the customer who is an object from the contract information 100 (step S100). Through this processing, the update management section 141 can acquire the combination of the service ID 104 and the contract type 105 with respect to the contract of the customer who is an object. Hereinafter, the processing of steps S102 to S110 is performed from among the acquired combinations to select one service ID 104.

[0220] Next, the execution form selection section 143 identifies which machine can be used in the provision of the service corresponding to the selected service ID 104 based on the machine device information 101 and the execution form information 106 acquired in step S100 (step S102). Specifically, the execution form selection section 143 identifies the controller 20, the edge controllers 51, 52, and 53, or the cloud system 60 as the usable machine.

[0221] Next, the program selection section 145 selects the program corresponding to the controller 20, the edge controllers 51, 52, and 53, or the cloud system 60 from the program information 120 based on the result of the identification of step S102 (step S104). Through this processing, the program selection section 145 can acquire the program ID 108 corresponding to the service ID 104.

[0222] Next, the downloader generation unit 147 selects either digest value method 111 or password method 113 from the authenticity verification unit 110 (step S106). Through this process, the downloader generation unit 147 can obtain the program for authenticity verification processing. Figure 6 The program ID 108 shown is for A (confirmation process 116), B (confirmation process 117), and C (confirmation process 118). Furthermore, as an example of the selection method for the authenticity verification unit in step S106, a selection method based on random number generation using the elevator system's operating status as a seed is envisioned; however, this embodiment is not limited to this selection method.

[0223] Next, the downloader generation unit 147 checks whether the authenticity verification unit (the program for authenticity verification processing) selected in step S106 exists in the temporary authenticity verification program list that lists the programs for authenticity verification processing (step S108).

[0224] In step S108, if the authenticity verification unit (the program for authenticity verification processing) selected in step S106 is not present in the temporary authenticity verification program list ("new" in step S106), the downloader generation unit 147 adds the program to the authenticity verification program list (step S110) and proceeds to step S112. On the other hand, if in step S108 the authenticity verification unit (the program for authenticity verification processing) selected in step S106 is present in the temporary authenticity verification program list ("existing" in step S106), the downloader generation unit 147 does not execute the processing in step S110 and proceeds to step S112.

[0225] In step S112, the management center control unit 140 (e.g., update management unit 141) checks whether there are any unprocessed service IDs 104 that were obtained in step S100 and have not been processed in steps S102 to S110. If there are still unprocessed service IDs 104 ("Yes" in step S112), the process returns to step S102 and selects one unprocessed service ID 104 to repeat the processing.

[0226] On the other hand, if there are no unprocessed service IDs 104 remaining in step S112 ("none" in step S112), the downloader generation unit 147 transforms the service ID 104 into a service number (service No) 202 (step S114). Service No. 202 is a new number specifically used for individual identifiers 85 (a new number for each individual identifier 85). By setting service No. 202, it is possible to make it difficult to deduce the unique service ID 104 in the elevator system.

[0227] Next, the downloader generation unit 147 performs the combined execution of the transformed service No. 202 using the authenticity verification unit 110, and temporarily stores the execution result as authenticity verification information (combined authenticity) 204 (step S1 16).

[0228] Finally, the downloader generation unit 147 links the service list 201, the authenticity confirmation information 204, the authenticity confirmation processing list 205, and the communication processing program 207 that communicates with this information to generate the downloader 84 (step S118).

[0229] Here, service list 201 is a list having at least one combination of elements including service No. 202 transformed in step S114 and authenticity number (authenticity No) 203 representing the order of authenticity verification processing procedures on the temporary authenticity verification procedure list generated in step S108. Authenticity verification processing list 205 is a list of authenticity verification processing procedures (authenticity verification processing procedure 206) corresponding to the temporary authenticity verification procedure list. Furthermore, communication processing procedure 207 is a program generated corresponding to the combination of the machine equipment shown in machine equipment information 101 and the communication path forming the path to that machine equipment. Figure 9 An example of the binary format of the downloader 84 generated as described above is shown.

[0230] The management center control unit 140 can generate a downloader specifically for contract information 100 by configuring the downloader 84 with the structure described above. This downloader 84 effectively utilizes the authenticity verification unit 110 by assigning different authenticity verification units 110 to each service process and by applying the authenticity verification unit 110 to combinations of service processes. This makes it difficult to illegally copy the downloader 84 to other controllers, or to illegally copy a portion of the service process (program) and activate it in other controllers.

[0231] in addition, Figure 9 Although not illustrated, in this embodiment, it is preferable to configure the downloader 84 as a data format specifically for the individual identifier 85 of the controller 20. Specifically, for example, it is conceivable to encrypt the downloader 84 using the individual identifier 85. In this case, the encryption and decryption processes are stored in an area of ​​the ROM 23 that is similarly restricted to access as the individual identifier 85.

[0232] Furthermore, in this embodiment, the management center 2 (management center control unit 140) can further improve the effectiveness of preventing illegal copying and misuse of the program by appropriately regenerating the new downloader 84. Specific timing for regeneration could include, for example, changes in the contract form, changes in the execution form, or periodic timing.

[0233] In addition, Figure 9 The update downloader 84 is shown, but the original downloader 83 can also have the same binary format.

[0234] (1-5) Downloading the service program

[0235] Figure 10 This is a flowchart illustrating the processing steps of a service program's download process. See below for reference. Figure 10 To explain by means of Figure 8 The controller 20, after updating its own downloader 83, uses the downloader 84 to download the service program based on contract information 100 from the management center 2.

[0236] according to Figure 10 First, the controller 20 sends multiple services No. 202 to the management center 2 based on the service list 201 of the downloader 84 (step S200).

[0237] Management Center 2 receives Service No. 202 sent by Controller 20 in step S200 (step S250), transforms the received Service No. 202 into Service ID 104, and selects the program corresponding to the transformed Service ID 104 from Program DB120 (step S252). Additionally, Figure 10 The processing of Management Center 2 shown is mainly performed by Management Center Control Unit 140, which is also common to the processing of Management Center 2 in other flowcharts described later.

[0238] Next, the management center 2 extracts a portion of the contract form information 103 corresponding to the aforementioned service ID 104 to generate contract conditions 211 (step S254). (This will be discussed later.) Figure 11 In the above, contract condition 211 is omitted and recorded as condition 211. Contract condition 211 generated in step S254 is data representing service No. 202, subscription or purchase information, and contract period, etc.

[0239] Next, the management center 2 uses the authenticity verification unit 110 corresponding to service No. 202 to perform the given processing on the program selected in step S252, and generates the processed data 213 (step S256).

[0240] Next, the management center 2 confirms whether there is an unprocessed service No 202 with respect to the service No 202 received in step S250 (step S258). In a case where there is an unprocessed service No 202 (YES in step S258), the process returns to step S252.

[0241] In step S258, in a case where the process on all service Nos 202 is completed (NO in step S258), the management center 2 generates the reply data 210 by combining the contract condition 211 generated in step S254 and the processed data 213 generated in step S256 (step S260).

[0242] Figure 11 is a diagram showing an example of a data structure of the reply data 210. As shown in Figure 11 , the reply data 210 is configured by one or more combinations of the contract condition 211 and the corresponding processed data 213.

[0243] Then, the management center 2 transmits the reply data 210 generated in step S260 to the controller 20 (step S262). As described above, the processed data 213 obtained by performing the authenticity confirmation process based on the authenticity confirmation unit 110 on the program corresponding to the service ID 104 is included in the reply data 210.

[0244] In addition, the configuration at the time of communication of the program corresponding to the service ID 104 can sometimes differ depending on the selection result of the mode of the authenticity confirmation unit at the time of generation of the downloader 84 (see step S106 of Figure 8 ). For example, in a case where the digest value mode 111 is the HASH function, the transmitted data becomes binary data in which the program body and the digest value of the program are combined. Further, in a case where the cryptographic mode 113 is an arbitrary encryption algorithm, the transmitted data becomes binary data obtained by encrypting the above program.

[0245] The controller 20, if the reply data 210 is received from the management center 2 (step S202), separates the received reply data 210 into the contract condition 211 and the processed data 213 (step S204).

[0246] Next, the controller 20 extracts the service No 202 from the received contract condition 211, and performs the process based on the authenticity confirmation unit 110 on the combination thereof (step S206). Then, the controller 20 compares the execution result of step S206 and the authenticity confirmation information 204 of the corresponding combination (step S208).

[0247] In the case where the execution result of step S206 does not agree with the authenticity confirmation information 204 in step S208, the controller 20 judges that an illegal state has occurred (illegal in step S208) and causes the elevator system to shift to a safe state by the standard control program 81 (step S222).

[0248] On the other hand, in the case where the execution result of step S206 agrees with the authenticity confirmation information 204 in step S208, it is judged that the controller 20 is normal (normal in step S208) and the authenticity confirmation processing is performed by the authenticity confirmation processing program indicated by the corresponding authenticity No 203 for the processing completed data 213 associated with each contract condition 211 that becomes the basis of the comparison object (step S210). Then, the controller 20 confirms the execution result of the authenticity confirmation processing in step S210 (step S212).

[0249] In the case where the authenticity confirmation processing does not normally end in step S212, the controller 20 judges that an illegal state has occurred (illegal in step S212) and causes the elevator system to shift to a safe state by the standard control program 81 (step S222).

[0250] On the other hand, in the case where the authenticity confirmation processing normally ends in step S212, the controller 20 judges that it is normal (normal in step S212) and, for the program for which the authenticity confirmation processing was performed, refers to the corresponding contract condition 211 to confirm which contract form (for example, subscription or buy) it corresponds to (step S214).

[0251] In the case where the contract form is "subscription" in step S214 (subscription in step S214), the controller 20 stores the program after the authenticity confirmation processing described above as the subscription service program 222 together with the contract condition 211 described above to the RAM 24 (step S216). On the other hand, in the case where the contract form is "buy" in step S214 (buy in step S214), the controller 20 stores the program after the authenticity confirmation processing described above as the buy service program 220 together with the contract condition 211 described above to the ROM 23 (step S218). In addition, in the drawings and the following description, the buy service program 220 will be sometimes referred to as the buy service 220 and the subscription service program 222 will be sometimes referred to as the subscription service 222.

[0252] Then, after the step S216 and the step S218, the controller 20 confirms whether or not there is the processing completion data 213 which does not end the above-described steps S210 to S218 (step S220), and in the case where there is the corresponding processing completion data 213 (YES in the step S220), returns to the step S210 and repeats the processing. Further, in the case where there is not the corresponding processing completion data 213 (NO in the step S220), the controller 20 ends the download processing of the service program.

[0253] Figure 12 is a diagram showing an example of the internal structure of the elevator controller 6 after the completion of the download processing of the service program. As shown in Figure 12 , in the elevator controller 6 after the completion of the download processing of the service program, the standard control program 81, the individual identifier 85, the new downloader 84 which is specific to the controller 20, the purchased service 220 which is the purchased service program, and the condition data (condition 211) which is attached to the purchased service 220 are stored in the ROM 23. Further, the subscription service 222 which is the service program in the subscription, and the condition data (condition 211) which is attached to the subscription service 222 are stored in the RAM 24.

[0254] As described above, in the elevator service management system 1, by downloading the service program using the downloader 84 which is specific to the elevator controller 6, it is possible to prevent illegal rollback of the firmware caused by illegal use of the old downloader 83 at the time of shipment.

[0255] (1-6) Confirmation processing of the service program at the program startup

[0256] Figure 13 is a flowchart showing an example of the processing steps of the authenticity confirmation processing at the program startup. Figure 13 The processing shown in Figure 13 is processing which judges illegal conditions related to the service program by performing the authenticity confirmation processing and the like at the program startup, and moves the elevator system to a safe state when judged as illegal. In addition, Figure 13 , the processing shown in Figure 13 can also be performed by the downloader 84 after the update.

[0257] According to Figure 13First, in the controller 20, the downloader 83 confirms the contract conditions 211 stored in the ROM 23, the contract conditions 211 stored in the RAM 24, and the service list 201 held in the downloader 83 (step S300), and determines whether the respective service Nos 202 are identical (step S302).

[0258] In the case where the service Nos 202 are not identical in step S302 (NO in step S302), the downloader 83 judges that an illegal condition has occurred, and causes the elevator system to shift to a safe state by the standard control program 81 (step S318). On the other hand, in the case where the service Nos 202 are identical in step S302 (YES in step S302), the downloader 83 executes the authenticity confirmation unit 110 with respect to the service Nos 202 contained in the contract conditions 211 stored in the ROM 23 and the service Nos 202 contained in the contract conditions 211 stored in the RAM 24 in the order of the service Nos 202 held in the service list 201 (step S304).

[0259] Next, the downloader 83 compares the execution result of step S304 and the combined authenticity confirmation information 204 (step S306). In the case where the comparison result in step S306 is not identical (NO in step S306), the downloader 83 judges that an illegal condition has occurred, and causes the elevator system to shift to a safe state by the standard control program 81 (step S318).

[0260] On the other hand, in the case where the comparison result in step S306 is identical (YES in step S306), the downloader 83 selects the authenticity confirmation processing program 206 of the authenticity confirmation processing list 205 corresponding to the respectively assigned authenticity Nos 203 shown in the service list 201 with respect to the program on the ROM 23 and the program on the RAM 24 corresponding to the service Nos 202 of the service list 201 (step S308). Then, the downloader 83 executes the authenticity confirmation processing program 206 selected in step S308 (step S310), and confirms the execution result (step S312).

[0261] In the case where the execution result in step S312 is abnormal (NO in step S312), the downloader 83 judges that an illegal condition has occurred, and causes the elevator system to shift to a safe state by the standard control program 81 (step S318).

[0262] On the other hand, in a case where the result is normal in step S312 (YES in step S312), the downloader 83 confirms whether there is a service No 202 for which the authenticity confirmation unit has not been executed among the service Nos 202 registered in the service list 201 (step S314). In a case where there is a service No 202 for which the authenticity confirmation unit has not been executed (YES in step S314), the process returns to step S308, and the process is repeated for the corresponding service No 202. On the other hand, in a case where the authenticity confirmation unit has been executed for all the service Nos 202 (NO in step S314), the downloader 83 causes the standard control program 81 to start by normal control (step S316), and ends the process.

[0263] As described above, in the elevator service management system 1, by executing the authenticity confirmation process at the time of program startup, execution of illegal copies based on a part of the service process (the service program 122, etc.) can be prevented.

[0264] (1-7) Process at the Time of Illegal Detection

[0265] Figure 14 is a flowchart of a process example of the process at the time of illegal detection. In the process shown in Figure 13 , when illegal detection of the service program is detected, the controller 20 (the downloader 83) takes a response to move the elevator system to a safe state, but Figure 14 , as another response method at the time of illegal detection of the service program, illegal information is transmitted to the management center 2. In addition, the process of Figure 13 and the process of Figure 14 may be executed in combination. Furthermore, hereinafter, the process of Figure 14 will be described using the downloader 83 before update in the controller 20, but the process of Figure 14 can also be executed by the downloader 84 after update.

[0266] According to Figure 14 , first, in the controller 20, the downloader 83 confirms the contract conditions 211 stored in the ROM 23, the contract conditions 211 stored in the RAM 24, and the service list 201 held in the downloader 83 (step S400), and determines whether the respective service Nos 202 are consistent (step S402).

[0267] In a case where the service Nos 202 are not consistent in step S402 (NO in step S402), the downloader 83 determines that an illegal situation has occurred, generates illegal information of "service inconsistency" including information of the service No 202 for which inconsistency is confirmed (step S404), and transmits the generated illegal information to the management center 2 (step S406).

[0268] Further, when the controller 20 (the downloader 83) transmits the illegal information to the management center 2 in step S406, it is desirable to transmit the illegal information on the basis of, for example, encryption using the individual identifier 85 of the controller 20. After the processing in step S406, the processing on the controller 20 side is ended, and on the management center 2 side which receives the illegal information, the processing after step S450 described later is executed.

[0269] On the other hand, in the case where the service Nos 202 coincide in step S402 (YES in step S402), the downloader 83 executes the authenticity confirmation unit 110 for the service Nos 202 included in the contract condition 211 stored in the ROM 23 and the service Nos 202 included in the contract condition 211 stored in the RAM 24 in conjunction with the order of the service Nos 202 stored in the service list 201 (step S408).

[0270] Next, the downloader 83 compares the execution results in step S408 and the combined authenticity confirmation information 204 (step S410). In the case where the comparison result in step S410 does not coincide (NO in step S410), the downloader 83 determines that an illegal situation has occurred, generates illegal information of "combination disagreement" including information indicating the combination in disagreement (step S412), and transmits the generated illegal information to the management center 2 (step S406).

[0271] On the other hand, in the case where the comparison result in step S410 coincides (YES in step S410), the downloader 83 selects the authenticity confirmation processing program 206 of the authenticity confirmation processing list 205 corresponding to the respectively assigned authenticity Nos 203 shown in the service list 201 for the program on the ROM 23 and the program on the RAM 24 corresponding to the service Nos 202 of the service list 201 (step S414). Then, the downloader 83 executes the authenticity confirmation processing program 206 selected in step S412 (step S416), and confirms the execution result (step S418).

[0272] In the case where the execution result in step S418 is abnormal (ABNORMAL in step S418), the downloader 83 determines that an illegal situation has occurred, generates illegal information of "authenticity confirmation failure" including the service No 202 for which the authenticity confirmation has failed (step S420), and transmits the generated illegal information to the management center 2 (step S406).

[0273] On the other hand, in a case where the result is normal in step S418 (YES in step S418), the downloader 83 confirms whether there is a service No. 202 for which the authenticity confirmation unit has not been executed among the service Nos. 202 registered in the service list 201 (step S422). In a case where there is a service No. 202 for which the authenticity confirmation unit has not been executed (YES in step S422), the process returns to step S414, and the process is repeated for the corresponding service No. 202. On the other hand, in a case where the authenticity confirmation unit has been executed for all the service Nos. 202 (NO in step S422), the downloader 83 causes the standard control program 81 to start by normal control (step S424), and the process ends.

[0274] In a case where illegal information is sent from the controller 20 in step S406, the management center 2 (management center control section 140) receives the illegal information (step S450). Then, in a case where the received illegal information is encrypted, the management center 2 decrypts it to interpret the illegal information (step S452).

[0275] Specifically, in a case where the illegal information is "service inconsistency" illegal information, it means that the total number of services being used is inappropriate (the number of services is too small or too large). In a case where the illegal information is "combination inconsistency" illegal information, it means that although the number of services being used is appropriate (identical), the contents of the services are inappropriate (the contents of the services are different, or the order of the registered services is different). In a case where the illegal information is "authenticity confirmation failure" illegal information, it means that the program (service program) in the RAM 24 or the ROM 23 corresponding to the corresponding service is different from that of the regular product, or the authenticity confirmation unit is different from the regular one (i.e., the downloader 83 is not regular).

[0276] Then, the management center 2 records the interpretation result of the illegal information as described above in the contract information DB 100 (step S454), and the process ends.

[0277] By the illegal detection process as described above, the elevator service management system 1 can not only detect and grasp the illegal condition related to the service program stored in the ROM 23 and the RAM 24 of the controller 20, but also determine the individual identifier 85 to which the illegal condition is related. Therefore, the management center 2 can also identify the specific controller 20 in which the illegal condition is detected based on the interpretation result of the illegal information recorded in the contract information 100 and the machine equipment information 101 of the contract information 100.

[0278] (1-8) Downloader update process

[0279] Figure 15is a flowchart showing a processing step example of the downloader update processing. The elevator service management system 1, upon a change in the contract information 100, performs the downloader update processing to update the downloader of the controller 20 from the downloader 83 up to now to the downloader 84 corresponding to the changed contract information 100.

[0280] According to Figure 15 , first, the management center 2 (hereinafter, also can be said as the management center control section 140) detects a change in the contract information managed in the contract information DB 100 in association with an update of the contract information (step S500).

[0281] Next, the management center 2 generates the new downloader 84 involved in the update by the downloader generation processing shown in Figure 8 . Then, the management center 2 encrypts the generated downloader 84 as described in the explanation of Figure 8 .

[0282] Next, the management center 2 transmits the downloader 84 encrypted in step S504 to the controller 20 involved in the update as an update event (step S506). Thereafter, the management center 2 waits for the progress of the processing in the controller 20 of the transmission destination of the downloader 84, and if the service No 202 is transmitted from the controller 20 (corresponding to step S200 of Figure 10 ), these are transmitted (corresponding to step S250 of Figure 10 ).

[0283] On the other hand, the controller 20 involved in the update receives the encrypted downloader 84 transmitted from the management center 2 in step S506 (step S550), and decrypts it (step S552). For example, the decryption processing using the individual identifier 85 effectively is installed in advance in a boot loader or the like, and the decryption processing is performed using the boot loader or the like.

[0284] Next, the controller 20 overwrites or rewrites the downloader 83 stored in the ROM 23 with the decrypted new downloader 84 (step S554).

[0285] Then, the controller 20 executes the new downloader 84 based on the operation state of the elevator system (step S556). Specifically, for example, in the case where the entire elevator system is in a safe state, the controller 20 executes the downloader 84. Or, at the restart of the elevator system at the end of the periodic maintenance, the controller 20 executes the downloader 84. By thus executing the new downloader 84 involved in the update of the contract information, the controller 20 starts the download processing of the service program as described in the explanation of Figure 10 , and transmits a plurality of service Nos 202 to the management center 2 based on the service list 201 of the downloader 84 (step S200).

[0286] By executing the downloader update processing as above, the elevator service management system 1 can promptly replace the existing downloader 83 with the latest downloader 84 corresponding to the update of the contract information, in a case where the management information (contract information) of the contract information DB 100 has changed.

[0287] (1-9) Processing at the time of contract form change

[0288] Figure 16 is a flowchart showing a processing step example of the processing at the time of contract form change. The elevator service management system 1 executes the processing at the time of contract form change shown in Figure 16 , in a case where the contract state is changed from a case where the service is utilized by local execution in the contract form of "subscription" to a case of "purchase".

[0289] According to Figure 16 , first, the management center 2 (hereinafter, the management center control section 140 can also be referred to) detects a change in the contract information managed in the contract information DB 100 in association with the change in the contract form (step S600).

[0290] Next, the management center 2 corrects the conditions 211 for the service whose contract form is changed from subscription to purchase (step S602). Then, the management center 2 encrypts the corrected conditions 211 (step S604).

[0291] Next, the management center 2 transmits the conditions 211 encrypted in step S604 to the controller 20 involved in the change as a change event (step S606). Thereafter, the management center 2 stands by until the corrected results of the conditions 211 are transmitted from the controller 20 in step S662 described later.

[0292] On the other hand, the controller 20 involved in the change receives the encrypted conditions 211 transmitted from the management center 2 in step S606 (step S650), and decrypts them (step S652).

[0293] Next, in the controller 20, the downloader 83 (may be the downloader 84) searches for the service corresponding to the conditions 211 decrypted in step S652 (step S654), and confirms the search result (step S656).

[0294] In a case where the corresponding service can be searched for in step S656 (YES in step S656), the downloader 83 corrects the conditions 211 stored in the RAM 24 on the basis of the search result (step S658).

[0295] Then, the downloader 83 moves the condition 211 corrected in step S658 and the subscription service 222 stored in the RAM 24 in correspondence with the condition 211 to the ROM 23 (step S660). As an example of the moving process in step S660, consider that the subscription service 222 is temporarily stopped, and the subscription service 222 stored in the RAM 24 is moved to the ROM 23. Further, the downloader 83 can also clear the area of the RAM 24 after the moving. Furthermore, the downloader 83 can also write a return command to the entry point of the cleared area. Figure 12

[0296] After that, the downloader 83 transmits the result of the moving process in step S660 as the correction result of the condition 211 to the management center 2 (step S662).

[0297] On the other hand, in a case where the corresponding service cannot be searched in step S656 (NO in step S656), the downloader 83 transmits the meaning that the corresponding service does not exist as the correction result of the condition 211 to the management center 2 (step S662).

[0298] Then, by accepting the transmission of the correction result of the condition 211 in step S662, the management center 2 receives the correction result (step S608), and confirms the content of the correction result (step S610).

[0299] In a case where the correction result indicates that there is no service whose contract form is changed from "subscription" to "purchase" in step S610 (NO in step S610), the management center 2 judges that an illegal situation occurs, records information indicating illegality to the contract information DB 100 (step S612), and ends the process abnormally.

[0300] On the other hand, in a case where the correction result indicates the result of the moving process of the program in step S660 in step S610 (YES in step S610), the management center 2 judges that the change of the contract form from "subscription" to "purchase" is normally performed for the service, and ends the process normally.

[0301] Further, as a variation of the process at the time of the contract form change, in a case where the contract form is changed from "subscription" to "purchase" for a part of services among a plurality of services existing in the contract with the contract form of "subscription", the management center 2 can also generate a dedicated downloader for a combination of the programs of the services other than the subscription service 222 moved from the RAM 24 to the ROM 23 by the process of step S660 of the controller 20, and transmit to the controller 20.

[0302] ​By executing the contract form change time processing as above, the elevator service management system 1 can detect irregularities related to service processing at the time of changing the contract form from "subscription" to "purchase". Also, at the time of changing the contract form of the service from "purchase" to "subscription", the change is made to move the corresponding program from the ROM 23 to the RAM 24 in the program move processing at step S660, and execute the service processing corresponding to the changed contract form. Figure 16 The same contract form change time processing is performed, as a result of which the elevator service management system 1 can detect irregularities related to service processing at the time of changing the contract form.

[0303] (1-10) Service erasure time processing

[0304] Figure 17 is a flowchart showing an example of processing steps of service erasure time processing. The elevator service management system 1 executes the service erasure time processing shown in Figure 17 in the case of erasing the service in conjunction with a change in contract status, such as the elimination of subscription of the service, or the elimination of the purchased service. The service erasure time processing shown in

[0305] According to Figure 17 , first, the management center 2 (hereinafter, the management center control section 140 can also be referred to) registers the erasure of the service contract in the contract information DB 100 (step S700). Specifically, the management center 2 corrects the conditions 211 of the corresponding service to an erased state. Also, the management center 2 gives the conditions 211 an instruction (erasure operation instruction) of whether to execute the erasure operation immediately or to reserve it. Then, the management center 2 encrypts the conditions 211 corrected to the erased state (step S702).

[0306] Next, the management center 2 transmits the conditions 211 encrypted in step S702 to the controller 20 involved in the erasure as an erasure event (step S704). Thereafter, the management center 2 stands by until an instruction result is transmitted from the controller 20 at step S766 described later.

[0307] On the other hand, the controller 20 involved in the erasure receives the encrypted conditions 211 transmitted from the management center 2 in step S704 (step S750), and decrypts them (step S752).

[0308] Next, in the controller 20, the downloader 83 (may also be the downloader 84) searches for the service corresponding to the conditions 211 decrypted in step S752 (step S754), and confirms the search result (step S756).

[0309] In the case where the corresponding service can be searched for in step S756 (YES in step S756), the downloader 83 confirms the instruction content thereof with reference to the erasure operation instruction given to the above conditions 211 (step S758), and confirms the instruction content thereof (step S760).

[0310] In the case where the erasure operation instruction is immediate execution (YES in step S760), the downloader 83 stops the service of the object, and corrects the service program of the service stored in the ROM 23 or the RAM 24 (step S762). In the case where the erasure operation instruction is reservation (NO in step S760), the downloader 83 corrects the condition 211 of the service of the object stored in the ROM 23 or the RAM 24 to the erasure state (step S764).

[0311] After the processing in step S762 and step S764, the downloader 83 transmits the processing result of step S762 or step S764 as an instruction result indicating that the erasure operation instruction is normally processed to the management center 2 (step S766).

[0312] In addition, in the case where the corresponding service cannot be searched in step S756 (NO in step S756), since the erasure operation instruction of the service program cannot be executed, the downloader 83 transmits an instruction result indicating an abnormality to the management center 2 in step S766.

[0313] Then, by accepting the transmission of the instruction result in step S766, the management center 2 receives the instruction result (step S706), and confirms the content of the instruction result (step S708).

[0314] In the case where the instruction result is abnormal in step S708 (YES in step S708), the management center 2 judges that an illegal situation has occurred, records information indicating the illegal content to the contract information DB 100 (step S710), and ends the processing abnormally.

[0315] On the other hand, in the case where the instruction result is normal in step S708 (NO in step S708), the management center 2 does not perform the processing of step S710 and ends the processing normally.

[0316] By executing the service erasure time processing as described above, the elevator service management system 1 can prevent illegal use of the service processing at the service erasure time.

[0317] As described above, according to the elevator service management system 1 according to the present embodiment, by performing the update (which can include addition, change, and erasure) of the service providing program corresponding to the machine structure such as the controller 20 in the elevator system, the contract form of the service, or the system structure, the illegal use or erroneous use of the service can be prevented.

[0318] (2) Second Embodiment

[0319] The elevator service management system 1A according to the second embodiment has a function of displaying services (service processes) that the elevator system can provide, in addition to the functions of the elevator service management system 1 according to the first embodiment. In the elevator service management system 1A according to the second embodiment, the description of the structures common to the elevator service management system 1 is omitted.

[0320] (2-1) Internal structure of management center 2A

[0321] Figure 18 is a diagram showing an example of the internal structure of the management center 2A in the elevator service management system 1A according to the second embodiment. The management center 2A is a constituent element corresponding to the management center 2 in the first embodiment, and functions as a center for managing the services provided by the elevator system. Figure 3 As a difference from the management center 2 shown in FIG. 8, the management center 2A is provided with a service information database (DB) 300 and a management center control section 340. In addition, although not shown in FIG. 9, the management center 2A can also be provided with a structure such as the authenticity confirmation unit DB 110 and the generation information 130, as in the management center 2. Further, the management center control section 340 can also have a structure of each section of the management center control section 140 shown in FIG. 8. Figure 18 Figure 3

[0322] The service information DB 300 manages information related to the services that the elevator system can provide. Specifically, the service information DB 300 manages service information 301 that holds basic information related to each service, and execution structure information 306 that holds information related to the execution structure required for providing the service.

[0323] Figure 19 is a diagram showing an example of the data structure of the service information 301 and the execution structure information 306. In the case of Figure 19 , the service information 301 is composed of a service ID 302 that indicates an identifier of the service, a service name 303 that indicates a name of the service, a service explanation 304 that indicates an explanation of the service, and a contract form 305 that indicates a form of the service. In addition, the data structure of the service information 301 can have at least the contract form 305, and is not limited to the example of Figure 19 .

[0324] Further, in the case of Figure 19 ​​In the case where the execution structure information 306 has the contract form 305, the execution structure information 306 has the structure ID 307 indicating an identifier given to each execution structure, the structure description 308 indicating a description of the execution structure, the device 309 indicating a device required for providing the service, and the network information 310 indicating a communication path connecting the devices 309 and a network of the path. In addition, the data structure of the execution structure information 306 can have only the device 309, and is not limited to the above. Figure 19

[0325] Further, as shown in FIG. 3, in the service information DB 300, the information required for providing each service is managed by associating one or more execution structure information 306 related to the execution structure of the corresponding service with each service information 301. Figure 19

[0326] The management center control section 340 is configured of an association information extraction section 341, a display generation section 343, a service extraction section 345, and a service voting section 347. The functions of each section of the management center control section 340 are realized by a processor reading and executing a given program in the computer of the management center 2A.

[0327] The association information extraction section 341 reads the service information 301 and the execution structure information 306 from the service information DB 300 to extract the contract form 305 and the like (machine and structure) of the execution structure information 306 associated with the service information 301.

[0328] The display generation section 343 generates a code of a WEB page or the like as information for display on a display device such as a monitor based on the information extracted by the association information extraction section 341. In addition, the code or the like for accepting the operation result of the selection or the like of the user is also included in the information for display on the display device.

[0329] Then, the management center control section 340 displays the WEB page or the like by using the code or the like generated by the display generation section 343 to be able to display the information related to the service (service process) that the elevator system can provide to the user, and accept the given selection operation or the like.

[0330] (2-2) Display structure

[0331] Hereinafter, the functions that the elevator service management system 1A can provide will be described with reference to an example of a display screen of the WEB page that the management center 2A of the present embodiment can output.

[0332] (2-2-1) Service selection, execution structure selection

[0333] Figure 20 is a drawing showing an example of the display of the WEB page for the selection of the service or the execution structure of the service process. Further,​​Figure 21 is a transition screen from the WEB page of Figure 20 Fig. 11 is a view showing an example of the service selection screen 350. Note that the following description is a description of the case where the service selection screen 350 is designed as a window or a dialog box on the Windows system, which corresponds to a general OS (Operating System), but the display method and the display design of the screen in the present embodiment are not limited to this. Also, the same applies to the other display examples described later.

[0334] Figure 20 The service selection screen 350 exemplified in Fig. 11 is a display screen provided to the user in order to select a service to be used or an execution structure thereof. In the service selection screen 350, each service in which information is held in the service information 301 is displayed in a list based on the information extracted from the service information DB 300 by the association information extraction section 341.

[0335] In the list display of each service in the service selection screen 350, specifically, the number 351 corresponds to the service ID 302, the name 352 corresponds to the service name 303, and the explanation 353 corresponds to the service explanation 304. Also, the radio button 354 is a button operated when the service to be selected is selected. Also, the OK button 355 is a button operated when the selection of the service in the display state of the service selection screen 350 is confirmed, and the cancel button 356 is a button operated when the selection of the service in the service selection screen 350 is aborted.

[0336] Also, in the service selection screen 350, the numbers 351 and the names 352 of each service are underlined, which means that a hyperlink is added. At the destination of the hyperlink, a window or a dialog box such as the structure selection screen 360 shown in Fig. 12 is associated. Figure 20 Figure 21

[0337] The structure selection screen 360 is a display screen provided to the user in order to select an execution structure for the service selected in the service selection screen 350, that is, the service for which the hyperlink is operated. In the structure selection screen 360, information is displayed in a list for each combination (structure ID 307) of the execution structures required for the provision of the selected service, and these display information is constituted by information extracted mainly from the execution structure information 306 by the association information extraction section 341.

[0338] ​​In the display structure of the structure selection screen 360, specifically, the name 361 corresponds to the service name 303, the explanation 362 corresponds to the structure explanation 308, the device 363 corresponds to the device 309, and the network 364 corresponds to the network information 310. Further, the radio button 365 is a button operated when the execution structure of the selection object is selected. Further, the OK button 366 is a button operated when the selection of the execution structure in the display state of the structure selection screen 360 is determined, and the cancel button 367 is a button operated when the selection of the execution structure in the structure selection screen 360 is aborted (returning to the service selection screen 350 of the hyperlink source).

[0339] For example, in a case where any one of the structures X, Y, and Z is selected in the structure selection screen 360, the corresponding radio button 365 becomes the selection state (indicated by a black circle in other drawings) by the press operation of the user. Thereafter, if the OK button 366 is pressed by the user, an event of updating the contract information DB 100 occurs. Figure 21

[0340] As described above, by displaying the service selection screen 350 and the structure selection screen 360 based on the information managed in the contract information DB 100, the user can select the machine in the service utilization selection. Then, as a starting point of the selection of the service process, the various databases of the management center 2A are updated in correspondence with the button class situation and the maintenance or change of the contract form or the execution form, whereby the elevator service management system 1A can promptly update the service process, the program structure, and the execution form.

[0341] (2-2-2) Service update after the start of service utilization

[0342] Figure 22 is a drawing showing an example of the display of a WEB page for service update. Further, Figure 23 is a drawing showing an example of a transition screen from the WEB page of Figure 22 .

[0343] Figure 22 The service update screen 370 exemplified in the above is a screen displaying the contract state of the service after the start of the utilization of the service process. The user can perform the operation of selecting and updating the contract state of the service in the service update screen 370, and the elevator service management system 1 updates the state of the elevator system in correspondence with the operation of the service update screen 370.

[0344] As with the service selection screen 350 of Figure 20 , in the service update screen 370, each service in which the information is held in the service information 301 is displayed in a list based on the information extracted from the service information DB 300 by the association information extraction section 341.

[0345] ​In the list display of the services in the service update screen 370, specifically, the number 371 corresponds to the service ID 302, the name 372 corresponds to the service name 303, and the explanation 373 corresponds to the service explanation 304.

[0346] Further, the subscription 374 and the buy 375 represent the contract form of the existing service, the continuation 376 and the buy 377 represent the contract form of the service which becomes the contract expiration, and the subscription 378 and the buy 379 represent the contract form of the newly proposed service.

[0347] Specifically, in the case of Figure 22 , the service A is shown as the existing (in use) service, and the contract is made in the "subscription" form (the subscription 374). Then, for the service B which becomes the contract expiration, the continuation of the contract is selected (the continuation 376). Further, the service C is the service which proposes the new service processing, and in the case where the user makes the contract for this service C, the subscription 378 or the buy 379 is selected in correspondence with the desired contract form. In addition, the case where the buy 375 is selected means that the contract form of the service A in use is changed from "subscription" to "buy", and the case where the buy 377 is selected means that the contract update is made for the service B which becomes the contract expiration in the contract form of "buy".

[0348] Then, the OK button is a button which is operated when the update of the service is determined in the structure selected in the service update screen 370, and the cancel button 381 is a button which is operated when the update of the service in the service update screen 370 is aborted.

[0349] In addition, in the service update screen 370, the number 371 and the name 372 are attached with the hyperlink in the same manner as in the service selection screen 350, and the window or the dialog associated with the structure selection screen 390 shown in Figure 20 is linked to the destination of the hyperlink. Figure 23

[0350] Figure 23 The structure selection screen 390 is a display screen which is provided to the user in order to select the execution structure for the service selected in the service update screen 370 (i.e., the service for which the hyperlink is operated). In the structure selection screen 390, the information is listed by each combination (structure ID 307) of the execution structures required for the provision of the service selected in the service update screen 370, and these display information is constituted by the information extracted by the association information extraction section 341 mainly from the execution structure information 306.

[0351] Each display structure (name 391, explanation 392, device 393, network 394, radio button 395, OK button 396, cancel button 397) of the structure selection screen 390 corresponds to the display structure of the service selection screen 350. Figure 21 ​The structure selection screen with the same name in 360 is the same, so detailed explanation is omitted.

[0352] If the user presses the OK button 396 in the structure selection screen 390, the selection state is confirmed and the user returns to the service update screen 370. Then, if the user presses the OK button 380 in the service update screen 370, an event to update the contract information DB100 occurs.

[0353] As described above, the elevator service management system 1A starts with the update of the user's contract status and updates the various databases of the management center 2A in accordance with the status of the button types in the service update screen 370 and the structure selection screen 390, corresponding to the maintenance or change of the contract form or execution form of the service (service processing). In this way, the service processing, program structure and execution form can be updated quickly.

[0354] (2-2-3) Additional services from device selection

[0355] Figure 24 This is a diagram showing an example of a web page used for device selection. Furthermore, Figure 25 It means from Figure 24 An example of a transition screen that appears when a web page starts.

[0356] Figure 24 The equipment selection screen 400 shown in the example displays the existing equipment in the elevator system. Furthermore, Figure 25 The service addition screen 410 shown in the example is a transitional screen displayed when selecting a device selection screen 400 via a hyperlink, provided to the user for adding new service processing.

[0357] Figure 24 The device selection screen 400 is a window or dialog box composed of the following elements: (refer to structure ID307). Figure 19 The corresponding number is 401; and the equipment is 309 (reference). Figure 19 The device selection screen 400 includes the device 402 corresponding to the device selection; the OK button 403 which operates when the device selection status is confirmed; and the Cancel button 404 which operates when the device selection is terminated. In the device selection screen 400, a hyperlink is attached to either device 401 or device 402. If either of them is selected, a service addition screen 410 related to the service of the selected object is displayed.

[0358] Figure 25 The service add-on screen 410 is characterized by having... Figure 22The service update screen 370 has the same display structure as the screen, specifically, it is a window or dialog box consisting of number 411, name 412, description 413, subscription 414, buy 415, continue 416, buy 417, OK button 418 and cancel button 419.

[0359] In the initial service addition screen 410 displayed by selecting a hyperlink on the device selection screen 400, the radio buttons for Subscribe 414, Buy 415, Continue 416, and Buy 417 are displayed in an unselected state. Subsequently, the radio button corresponding to the user's desired service and its contract type is selected. If the OK button 418 is pressed, an event occurs to update the contract information DB100.

[0360] As described above, users can use the device selection screen 400 and the service addition screen 410 to select new service contracts or updates from the device. The elevator service management system 1A can respond to these screen operations (selection status of radio buttons) to generate the status of adding new services, and then update various databases of the management center 2A.

[0361] (2-2-4) Service approval based on voting on proposals

[0362] This refers to the approval of services in the elevator system, which is determined by multiple relevant parties (such as elevator owners, managers, or users).

[0363] Figure 26-29 These are examples of web page displays representing a series of processes in the service approval process (Figures 1-4). More specifically, Figure 26 , Figure 27 This is an example of a service confirmation screen display. Figure 28 This is an example of how the voting screen is displayed. Figure 29 This is an example of a service proposal screen display.

[0364] The following is for reference. Figure 26-29 The following examples illustrate a multi-stage service approval process: the owner submits a service utilization proposal, multiple users express their opinions on whether to approve or disapprove of the proposal, these opinions are aggregated, and based on arbitrary judgment criteria, the overall approval or disapproval of the users, or other options, are presented to the owner.

[0365] first, Figure 26 The service confirmation screen 420 shown in the example is a display screen provided to the proposer (here, the owner or manager of the elevator system). Furthermore, Figure 27 The service confirmation screen 430 shown in the example is from... Figure 26one of the display screens to which the service confirmation screen 420 transitions, indicates the contents of the proposal for service contract change. Also, the display structure of the service confirmation screen 420, 430 is the same as that of the aforementioned service update screen 370 and service addition screen 410.

[0366] Figure 26 The service confirmation screen 420 illustrated is displayed in the same manner as the service update screen 370. Figure 22 The service confirmation screen 420 illustrated is displayed in the same manner as the service update screen 370.

[0367] In the present example, from such a current contract status, as a new contract status proposal, the owner (may also be the manager) of the elevator changes the contract form of the service B to "buy". At this time, in the service confirmation screen 420, for the service B, the single selection button 424 of "buy" is set to the selected state in place of the single selection button 423, and the owner performs a push operation on the OK button 427.

[0368] If the OK button 427 is pushed as described above, the selection of the owner is decided, and the service confirmation screen 420 transitions to the service confirmation screen 430 illustrated. Figure 27 In the service confirmation screen 430, for the service B, the single selection button 424 of "buy" is in the selected state.

[0369] Then, if the selection of the owner described above is decided, the proposal from the owner for the new contract status of the service is displayed as a service voting screen 440 having the same display structure as the service confirmation screen 430 in the terminals of the plurality of users. Also, since the service voting screen 440 is assumed to be displayed in the terminals of the users different from the service confirmation screen 420, 430 displayed in the terminal of the owner, in the display structure of the service voting screen 440 illustrated, Figure 28

[0370] Next, the users express their opinions on whether to agree or disagree with the proposal for the new contract information of the service displayed in the service voting screen 440.

[0371] ​Specifically, a user who approves the proposal does so by pressing the OK button 447 without changing the selection state of the radio button displayed on the service voting screen 440. The service voting unit 347 of the management center control unit 340, by summarizing the occurrence of this approval event, determines, for example, that the proposal has received general approval (agreement) from the users if it exceeds half of the total number of users. This allows the elevator system owner (or manager) to generate an approval authorization for the contract change shown in the proposal.

[0372] On the other hand, a user who disagrees with a proposal from the owner, after changing the selection state of the radio button displayed on the service voting screen 440 to the desired selection state, presses the OK button 447. In this case, a service proposal event occurs that differs from the original proposal. If a service proposal event occurs, the service voting screen 440 displayed on the user's terminal transitions to... Figure 29 The example shown is service proposal screen 450. Service proposal screen 450 is used to select a new proposal (another service proposal).

[0373] exist Figure 29 In the case of the service proposal screen 450 shown, if the user wants to "continue" for service B instead of "buy" as proposed by the owner, the radio button 453 is changed to a selection state. Then, if the user presses the confirmation button 457 used to confirm the change of the service proposal screen 450, a given event (an event for other service proposals) occurs, which is different from the aforementioned approval event.

[0374] If an event occurs involving another service proposal, the service voting unit 347 obtains information from radio buttons 441-446 and 451-456 on the service voting screen 440 and the service proposal screen 450, and sums them up. At this point, for example, if the number of users selecting "Buy" (selected state of radio button 443) for the owner's initial proposal, service B, is less than half the total number of users, the service voting unit 347 determines that the users' overall approval (agreement) is not obtained, and the elevator system owner (or manager) may issue a rejection notice for the contract change shown in the initial proposal. Furthermore, if the number of users selecting "Continue" for service B exceeds half the total number of users, the service voting unit 347 determines that the users' overall approval (agreement) is obtained for the aforementioned other service proposals, and the elevator system owner (or manager) may issue a request to reconsider the contract change shown in the initial proposal.

[0375] Figure 30is a flowchart showing an example of a processing step of a service approval process. The service approval process is described with reference to Figure 26-29 The above-described process of performing the multi-stage service approval is performed by the management center control section 340.

[0376] According to Figure 30 First, the service voting section 347 performs service confirmation (step S800). In step S800, the service voting section 347 causes the display generation section 343 to generate a service confirmation screen 420 and display it on the terminal of the proposer (e.g., the owner or the manager of the elevator system, etc.).

[0377] Next, in the case where the service confirmation screen 420 displayed in step S800 is operated (the display content is changed like the service confirmation screen 430), since the service is changed, the service voting section 347 performs service voting (step S802). In step S802, the service voting section 347 causes the display generation section 343 to generate a service voting screen 440 based on the information determined in the service confirmation screen 430 and display it on the terminal of the voter (e.g., the plurality of users).

[0378] After that, the service voting section 347 determines whether or not the voting of the voter is ended (step S804). The determination of the end can be a determination based on a time limit, a determination based on the number of people who are voting, etc. In the case where the voting is not ended (NO in step S804), step S804 is repeated until the determination of the end is made.

[0379] If the voting is ended in step S804 (YES in step S804), the service voting section 347 totals the voting results based on the given condition (step S806). An example of the given condition in the total is Figure 28 as described above in the explanation of the service voting screen 440.

[0380] Then, the service voting section 347 notifies the proposer of the total result of step S806 (step S808). At the time of the notification of the total result, it is sufficient that the display generation section 343 generates a WEB page or the like based on the given display structure.

[0381] By performing the process as described above, in the elevator service management system 1A, it is possible to implement the approval related to the change of the service process by taking into account the opinions of the plurality of relevant persons, and it is possible to implement the selection of the service process and the service contract.

[0382] In addition, in the above description, the form in which the selection (proposal) of the owner and the votes of the plurality of users with respect to the selection are combined to implement the service approval was described in detail, but the present embodiment is not limited to this combination, and for example, a form in which the aggregation result of the selections (proposals) of the plurality of users and the approval of the owner with respect to the aggregation result are combined to implement the service approval or the like can be used.

[0383] (3) Third Embodiment

[0384] The elevator service management system 1B according to the third embodiment of the present application has a function of providing a new service (hereinafter also referred to as a robot collaborative service) in cooperation with an elevator system by a device (mobile body) capable of autonomous movement in addition to the functions of the elevator service management system 1 according to the first embodiment (or the elevator service management system 1A according to the second embodiment).

[0385] Figure 31 is a diagram showing an example of the overall structure of the elevator service management system 1B according to the third embodiment. In Figure 31 , the same structures as those of the elevator service management system 1 among the structures of the elevator service management system 1B are denoted by common reference numerals, and the descriptions thereof are omitted.

[0386] As shown in Figure 31 , the elevator service management system 1B is configured by connecting the robot 500 to the elevator service management system 1 according to the first embodiment shown in Figure 1 via the communication path 3. The robot 500 is an example of a device (mobile body) capable of autonomous movement. Since the robot 500 is an autonomous mobile body, the robot 500 and the communication path 3 can be said to be generally connected on the basis of wireless, but are not limited thereto.

[0387] The robot 500 is equipped with various sensors. The various sensors are specifically, for example, a GNSS (Global Navigation Satellite System), an acceleration sensor, an image sensor, or a LiDAR (Light Detection And Ranging), or the like.

[0388] In the elevator service management system 1B, the virtual machine 62 (refer to Figure 33The virtual machine 62 processes the robot-related data (specifically, position information, motion information, image information, or surrounding environment information) obtained from various sensors of the robot 500, performs calculations to generate new data, controls, or instructions, and sends the control or instructions as the processing result of this service processing to the group management controller 5. The processing of the virtual machine 62 can be executed according to the instructions from the management center 2 (management center control unit 140). Furthermore, the group management controller 5 performs control calculations based on the received control or instructions to improve the operating efficiency of the managed elevator group 19, and sends the new control or instructions obtained through calculations to the subordinate elevator controllers 6.

[0389] The elevator service management system 1B described in this embodiment is configured as described above using a service collaboration system structure based on a cloud system 60, enabling a new collaborative service where autonomously operating devices (mobile bodies) and the elevator system collaborate.

[0390] In this embodiment, information related to the robot 500 is added to the machine equipment information 101 in the contract information DB100 of the management center 2. Specifically, the machine equipment information 101 adds information representing the cloud system 60, the robot 500, and the communication path 3, which serves as the communication path information between the two. Furthermore, the contract form of the robot collaboration service maintained in the contract form information 103 of the contract information DB100 is set to, for example, "subscription". In addition, regarding the execution form information 106 related to the robot collaboration service, the group management controller 5 becomes the client processing unit, and the cloud system 60 becomes the service processing unit.

[0391] Figure 32 This is a diagram illustrating an example of the internal structure of the group management controller 5 in the third embodiment. Figure 33 This is a diagram illustrating an example of the internal structure of the virtual machine 62 in the third embodiment.

[0392] like Figure 32 As shown, in the group management controller 5, the ROM 23 stores the standard control program 501 for managing the elevator group 19 and the individual identifier 505 assigned to each group management controller 5. In addition, the RAM 24 of the group management controller 5 stores the contract conditions (condition 507) corresponding to the robot collaboration service using the cloud system 60, and the client program (subscription service 509) for subscribing to the robot collaboration service executed in the cloud system 60.

[0393] On the other hand, such as Figure 33As shown, in the cloud system 60, a standard control program 511 for the robot collaboration service, and an individual identifier 515 given to each virtual machine 62 are stored in the ROM 23 of the virtual machine 62. Further, a contract condition (condition 517) corresponding to the robot collaboration service, and a service program (collaboration service 519) for subscription of the robot collaboration service executed in the cloud system 60 are stored in the RAM 24 of the virtual machine 62.

[0394] In the elevator service management system 1B related to the present embodiment, by being configured as the system configuration as described above, the management center control section 140 of the management center 2 can generate the downloader 503, 513 for the addition of the robot 500, which is an autonomous mobile machine, and the addition of the service processing, in the same manner as in the first embodiment. The downloader 503 is stored in the ROM 23 of the group management controller 5, and the downloader 513 is stored in the ROM 23 of the virtual machine 62. Then, by generating and retaining such downloaders 503, 513, in the elevator service management system 1B, it becomes difficult to illegally copy and execute the processing program related to the machine and the service processing.

[0395] (4) Fourth Embodiment

[0396] The elevator service management system 1C related to the fourth embodiment of the present application has a function of providing a new service (hereinafter also referred to as a sensor collaboration service) in cooperation with an elevator system using a device having an intelligent function (for example, an intelligent sensor) in addition to the functions of the elevator service management system 1 related to the first embodiment (or the elevator service management system 1A related to the second embodiment).

[0397] Figure 34 is a diagram showing an example of the overall configuration of the elevator service management system 1C related to the fourth embodiment. In Figure 34 , the same configuration as in the elevator service management system 1 is denoted by a common reference numeral, and the description thereof is omitted.

[0398] As shown in Figure 34 , in the elevator service management system 1C, the edge controller 51 and the sensor 600 are connected to the communication path 13 to configure. The sensor 600 is an intelligent sensor in which a sensor and a signal processing circuit are integrated, and is, for example, an image sensor. In addition, in Figure 34 , the sensor 600 is provided as one for simplicity, but the number of sensors 600 to be provided is not limited to one. For example, in the case where the sensor 600 is provided as an image sensor, it is assumed that a plurality of sensors 600 are laid in each floor and in the car 8.

[0399] The edge controller 51 connected to the sensor 600 via the communication path 13 uses the information detected or processed by the sensor 600 to execute a specific service process (for example, an image analysis service process if the sensor 600 is provided as an image sensor, which performs image analysis), and transmits the processing result of the image analysis service process (for example, the number of people as a processing result of image analysis) to the elevator controller 6.

[0400] The elevator service management system 1C according to the present embodiment can realize a new sensor cooperation service in which the sensor 600 such an additional device (machine) and the elevator system cooperate, by being provided as a system structure capable of executing a specific service process such as the above-described image analysis service process.

[0401] In addition, in the present embodiment, in the contract information DB 100 of the management center 2, information related to the edge controller 51 and the sensor 600 is added to the machine device information 101. Specifically, the machine device information 101 adds information indicating the edge controller 51, the sensor 600, and the communication path 13 as communication path information of both. Further, the contract form of the sensor cooperation service held in the contract form information 103 of the contract information DB 100 is provided as "buy", for example. Further, with respect to the execution form information 106 related to the sensor cooperation service, the elevator controller 6 becomes a client process, and the edge controller 51 becomes a service process.

[0402] Figure 35 is a diagram indicating an example of the internal structure of the elevator controller 6 in the fourth embodiment, Figure 36 is a diagram indicating an example of the internal structure of the edge controller 51 in the fourth embodiment.

[0403] As shown in Figure 35 , in the elevator controller 6, a standard control program 601 for managing the elevators 16, an individual identifier 605 assigned to each elevator controller 6, a contract condition (condition 607) corresponding to the image analysis service, and a client program (buy service 609) for using the image analysis service executed in the edge controller 51 are stored in the ROM 23.

[0404] On the other hand, as shown in Figure 36 , in the edge controller 51, a standard image processing program (standard image processing program 612) for the image analysis service, and an individual identifier 85 assigned to each edge controller 51 are stored in the ROM 23. Further, in the RAM 24 of the edge controller 51, a contract condition (condition 617) corresponding to the image analysis service, and a program (analysis service 619) for buying the image analysis service executed in the edge controller 51 are stored.

[0405] In the elevator service management system 1C according to this embodiment, by setting up the system structure as described above, the management center control unit 140 of the management center 2 can generate downloaders 603 and 613 specifically for adding intelligent machines such as sensor 600 and adding service processing using the same method as in the first embodiment. Downloader 603 is stored in the ROM 23 of elevator controller 6, and downloader 613 is stored in the ROM 23 of edge controller 51. Then, by generating and maintaining such downloaders 603 and 613, it is difficult to illegally copy and execute the processing programs involved in machine and service processing in the elevator service management system 1C.

[0406] In addition, such as Figure 35 As shown, in this example, the client program (purchase service 609) used to utilize the image parsing service is set to purchase and stored in the ROM 23 of the elevator controller 6. However, even if the purchase service 609 on the elevator controller 6 side is illegally copied and executed on another elevator controller 6, if the machine itself of the edge controller 51 is changed, or if the parsing service 619 on the edge controller 51 side is updated, there will be a need to update the purchase service 609 on the elevator controller 6 side. Therefore, in the elevator service management system 1C, even if the purchased service program (purchase service 609) is illegally copied on the elevator controller 6 side, the new edge controller 51 or the new parsing service 619 cannot be used, thus preventing illegal use or incorrect use of the service.

[0407] As explained above, the elevator service management systems 1, 1A to 1C involved in each embodiment of the present invention update the service program by performing updates (which may include additions, changes, and deletions) corresponding to the machine structure such as the controller in the elevator system, the service contract form, or the system structure. This makes it difficult to operate the setting information and program related to service processing, and can prevent the illegal use or misuse of the service.

Claims

1. An elevator service management system that manages a service provided from an elevator system based on a contract, characterized by, Possessing: an elevator system having at least one controller that controls the operation of an elevator; and a management center communicably connected to the controller that manages processing programs executed at the controller for providing the service, the management center having: a contract information database that holds machine equipment information indicating the structure of machines and equipment of the elevator system, contract form information indicating the contract form of the service, and execution form information indicating the execution form of the processing program of the service; a program database that holds the processing program of the service corresponding to each of the execution forms; and an update management section that manages the distribution of the processing program held at the program database to the controller based on the information of the contract information database, the update management section generating a downloader for the controller that downloads the processing program based on the contract form information of the service and the execution form information of the processing program thereof, and providing the controller with the downloader.

2. The elevator service management system according to claim 1, wherein the update management section generates the downloader with a genuineness confirmation unit that confirms the genuineness of the downloaded processing program, the controller, when downloading the processing program from the program database using the downloader provided from the update management section, confirms the genuineness of the processing program using the genuineness confirmation unit of the downloader, and in a case where the genuineness is confirmed, stores the processing program in a storage area thereof.

3. The elevator service management system according to claim 2, wherein the genuineness confirmation unit included in the downloader has a function of confirming the genuineness of the combination of the processing programs downloaded by the downloader.

4. The elevator service management system according to claim 2, wherein the controller, in a case where the downloader provided from the update management section cannot be executed, or in a case where the genuineness of the processing program downloaded using the downloader cannot be confirmed, executes control that causes the elevator to transition to a given safe state in correspondence with the operation state of the elevator.

5. The elevator service management system according to claim 2, wherein the update management section updates the downloader and the genuineness confirmation unit at the time of contract change of the service or periodically.

6. The elevator service management system according to claim 1, wherein in a case where the contract form of the service is changed from a first contract form that sets a limit on the use period or the number of uses of the service to a second contract form that does not set a limit on the use period or the number of uses of the service, the downloader held by the controller moves the processing program of the service corresponding to the second contract form from a storage area of a volatile memory to a storage area of a non-volatile memory, the update management section generates a new downloader that is specific to the combination of the processing programs of the service that contract in the first contract form except for the moved processing program.

7. The elevator service management system according to claim 2, wherein In a case where erasure of the service occurs in conjunction with a change in the contract status, the controller held by the download unit sets the processing program of the service that is an erasure target to an invalid state, and updates the processing programs of other services that are not erasure targets to program configurations corresponding to the latest contract form and execution form by the download unit corresponding to the latest contract form.

8. The elevator service management system according to claim 1, wherein the management center further has: an association information extraction section that extracts a machine and equipment involved in the service, a contract form of the service, and an execution structure required for providing the service; and a display generation section that generates display information based on the extraction result of the association information extraction section, and outputs the display information in a manner that enables selection operation of at least either of the contract form or the execution structure of the service, the management center updates the contract information of the service based on the result of the selection operation of the display information output by the display generation section by the user.

9. The elevator service management system according to claim 8, wherein in a case where at least either of the services is utilized in the elevator system, the association information extraction section extracts the service that is utilized, the contract form of the service, and the execution structure of the processing program of the service from the machine equipment information, the contract form information, and the execution form information held in the contract information database, the display generation section generates and outputs display information based on the extraction result of the association information extraction section, the management center updates the contract information of the service utilized in the elevator system based on the result of the selection operation of the display information output by the display generation section by the user.

10. The elevator service management system according to claim 8, wherein the association information extraction section extracts the service that can be utilized, the contract form of the service, and the execution structure of the processing program of the service from the machine equipment information, the contract form information, and the execution form information held in the contract information database, the display generation section generates and outputs a display screen that enables selection of the service that can be utilized in the existing equipment in the elevator system based on the extraction result of the association information extraction section, the management center updates the contract information of the service utilized in the elevator system based on the result of the selection operation of the display information output by the display generation section by the user.

11. The elevator service management system according to any one of claims 8 to 10, wherein the display generation section generates and outputs first display information that represents information related to the service that can be utilized in the elevator system based on the extraction result of the association information extraction section, and in a case where selection operation of changing the proposer proposal service has been performed with respect to the first display information, generates and outputs second display information that represents the proposal content of the proposer based on the result of the selection operation, The management center also has a service voting section that totals the results of selection operations from voters for the second display information output by the display generation section, and determines adoption of the proposal content according to given conditions.

12. The elevator service management system according to claim 1, wherein the elevator system is communicably connected with a cloud system, in a case where a given service that cooperates with the cloud system is provided, a processing program of the service is executed by a virtual machine that operates on the cloud system instead of the controller.

13. The elevator service management system according to claim 12, wherein a mobile body that autonomously operates is communicably connected with the cloud system, a specific service in which the elevator system and the mobile body cooperate is provided by a virtual machine that operates on the cloud system using information obtained from the mobile body instead of the controller.

14. The elevator service management system according to claim 1, wherein the elevator system further has: an edge controller that is added for processing performance and functional expansion of the controller; and a device with an intelligent function that is communicably connected with the edge controller, a specific service in which the elevator system and the device cooperate is provided by the edge controller using information obtained from the device instead of the controller.

15. A program management method of an elevator service, implemented by an elevator service management system that manages a service provided from an elevator system based on a contract, characterized by the elevator service management system having: an elevator system having at least one controller that controls an action of an elevator; and a management center that is communicably connected with the controller, and manages a processing program executed by the controller for providing the service, the management center having: a contract information database that holds machine equipment information indicating a structure of machines and devices of the elevator system, contract form information indicating a contract form of the service, and execution form information indicating an execution form of a processing program of the service; a program database that holds the processing program of the service corresponding to each of the execution forms; and an update management section that manages distribution of the processing program held in the program database to the controller based on information of the contract information database, the update management section generating a downloader for the controller that downloads the processing program based on the contract form information of the service and the execution form information of the processing program thereof, and providing the controller with the downloader.

Citation Information

Patent Citations

  • Remote management device and remote management system

    WO2022064604A1

  • Elevator maintenance contract system, maintenance center, and elevator maintenance contract method and program

    JP2003091608A

  • Remote monitoring information management method and remote monitoring system for elevator

    JP2019202845A