Car safety control method, electronic device and storage medium
Through the dual-subsystem safety control method, the elevator car door and hall door lock switches are bypassed separately to ensure that the elevator confirms each other and enters the slightly level state when leveling, solving the safety control problem of accidental movement of the elevator and improving the safety and response speed of the elevator.
Patent Information
- Application Number
- CN202411341861.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-25
- Publication Date
- 2025-09-30
- Estimated Expiration
- 2044-09-25
AI Technical Summary
In an elevator system, how to effectively control the safety status of the car to prevent accidental movement caused by a single component failure, especially when the hall door or car door is not locked or closed, to ensure passenger safety.
A dual-subsystem safety control method is adopted. The first subsystem and the second subsystem are connected to the car door lock switch and the hall door lock switch respectively. These switches are bypassed when the signals are abnormal. Before entering the micro-level state, mutual confirmation is made to ensure that both subsystems are ready before entering the micro-level state to avoid dangers caused by separate bypasses.
It improves the response speed of elevator safety control, reduces the time requirement for real-time safety communication, reduces the occurrence of people being trapped in elevators, and ensures passenger safety.
Smart Images

Figure CN119018739B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of elevator safety technology, and in particular to a car safety control method, electronic equipment and storage medium. Background Art
[0002] Elevators are widely used in our daily lives. With the occurrence of some elevator accidents, people are very concerned about the elevator safety function. Therefore, multiple safety switches and relays are usually set up in the elevator to form a safety circuit. The signals of these safety switches and relays can indicate the status of components in different positions of the elevator, and then determine whether the elevator is safe.
[0003] During elevator leveling and re-leveling, if the hall door is not locked or the car door is not closed, any single component failure in the elevator system may cause the car to move unexpectedly away from the landing, posing a serious risk to the personal safety of passengers. Therefore, given the presence of multiple safety switches in the elevator system, how to implement safety control on the car to prevent accidental movement is a problem that needs to be solved. Summary of the Invention
[0004] In order to solve the above technical problems, the present invention provides a car safety control method.
[0005] In a first aspect, the present invention provides a car safety control method, characterized in that it is applied to a safety control system, the safety control system including a power supply, a power supply line, a safety execution subsystem and a main motor connected in sequence, and a first subsystem and a second subsystem communicating with each other, the first subsystem and / or the second subsystem further communicating with a logic control system of the elevator, the input end of the first subsystem being connected to at least a car door lock switch and a leveling sensor, the input end of the second subsystem being connected to at least a hall door lock switch; the output ends of the two subsystems being respectively connected to different voting switches on the power supply line; when a signal switch at the input end of any subsystem is abnormal, the corresponding voting switch is controlled to switch to an off state to cut off the power supply, and the safety execution subsystem controls the main motor to stop running when the power supply is cut off;
[0006] The method comprises:
[0007] When any of the micro-stationary state triggering conditions is met, the first subsystem and the second subsystem communicate with each other to confirm whether the two subsystems are ready to enter the micro-stationary state;
[0008] When it is confirmed that both subsystems are ready to enter the micro-level state, the first subsystem and the second subsystem respectively enter the micro-level state;
[0009] The first subsystem bypasses the car door lock switch when entering the slightly leveled state; the second subsystem bypasses the hall door lock switch when entering the slightly leveled state;
[0010] Among them, the micro-leveling state triggering condition includes a first triggering condition and a second triggering condition. The first triggering condition is that the logic control system sends a request to enter the micro-leveling state to the first subsystem and / or the second subsystem when the car is leveled and re-leveled. The second triggering condition is that the first subsystem determines that the car is currently in the leveling area through the signal of the leveling sensor.
[0011] In a second aspect, the present invention provides an electronic device, comprising:
[0012] at least one processor; and
[0013] a memory communicatively connected to the at least one processor; wherein,
[0014] The memory stores a computer program that can be executed by the at least one processor. The computer program is executed by the at least one processor so that the at least one processor can execute the elevator car safety control method described in the first aspect of the present invention.
[0015] In a third aspect, the present invention provides a computer-readable storage medium storing computer instructions, wherein the computer instructions are used to enable a processor to implement the elevator safety control method described in the first aspect of the present invention when executed.
[0016] In the above-mentioned car safety control method, since the main motor can be stopped when any signal switch is abnormal, the abnormal signal of the signal switch can be responded to in real time. There is no need for the two subsystems to exchange information and make judgments before taking control actions. The response time requirements for real-time safety communication between the two subsystems can be reduced, the response speed is improved, and the safety of the elevator is guaranteed.
[0017] When entering the slightly leveled state, the first and second subsystems bypass the car door lock switches and hall door lock switches, respectively. Therefore, before entering the slightly leveled state, the two subsystems communicate with each other to confirm whether the other subsystem has accurately entered the slightly leveled state. When both subsystems are ready to enter the slightly leveled state, they each enter the slightly leveled state. This avoids the danger of a single subsystem bypassing the door lock switches due to one subsystem not being ready to enter the slightly leveled state while the other subsystem is already in the slightly leveled state. Furthermore, the two subsystems communicate only when entering the slightly leveled state and do not need to communicate with each other during elevator operation. This prevents accidental movement of the elevator car while also reducing the response time requirements for real-time safety communication between the two subsystems. This reduces the requirements for the elevator's electrical environment for safety communication and reduces the likelihood of people being trapped in the elevator.
[0018] It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the present invention, nor is it intended to limit the scope of the present invention. Other features of the present invention will become readily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0020] Figure 1 This is a schematic diagram of the structure of a safety control system provided by an embodiment of the present invention;
[0021] Figure 2 This is a flow chart of a car safety control method provided by an embodiment of the present invention;
[0022] Figure 3 This is a schematic diagram of a process in which a first subsystem enters a slightly level state, provided by an embodiment of the present invention;
[0023] Figure 4 This is a schematic diagram of a process in which a second subsystem enters a slightly level state, provided by an embodiment of the present invention;
[0024] Figure 5 This is a flow chart of a car safety control method provided by an embodiment of the present invention;
[0025] Figure 6 This is a schematic diagram of a process of a first subsystem exiting a micro-level state provided by an embodiment of the present invention;
[0026] Figure 7 This is a schematic diagram of a process of a second subsystem exiting a micro-level state provided by an embodiment of the present invention;
[0027] Figure 8 It is a structural diagram of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0028] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present invention.
[0029] The present invention provides a car safety control method, which is applied to a safety control system, such as Figure 1 As shown in the schematic diagram of the safety control system structure, the safety control system includes a power supply 3, a power supply line 4, a safety execution subsystem 5 and a main motor 6 connected in sequence, and a first subsystem 1 and a second subsystem 2 that communicate with each other. Optionally, the first subsystem 1 and the second subsystem 2 also include a controller and a bus communication transceiver connected to the controller. The two bus communication transceivers are connected through a safety communication bus, so that the two controllers can exchange signals through communication to realize communication between the two subsystems.
[0030] The first subsystem 1 and / or the second subsystem 2 also communicate with the logic control system of the elevator. The logic control system may include various main control panels of the elevator. The input end of the first subsystem 1 is connected to at least the car door lock switch and the leveling sensor, and the input end of the second subsystem 2 is connected to at least the hall door lock switch; the output ends of the two subsystems are respectively connected to different voting switches on the power supply line 4; when the signal switch at the input end of any subsystem is abnormal, the corresponding voting switch is controlled to switch to the disconnected state to cut off the power supply, and the safety execution subsystem 5 controls the main motor 6 to stop running when the power supply 3 is cut off.
[0031] The main motor 6, also known as the elevator traction machine, is the elevator's power source, also known as the main unit. Its function is to deliver and transmit power to operate the elevator. It consists of a motor, brake, coupling, reduction gear, traction sheave, frame, guide pulley, and an auxiliary handwheel. If the main motor 6 stops operating due to an abnormality in the signal switch, the motor in the main motor 6 stops operating and the brake engages, preventing accidents and ensuring passenger safety. Because the two subsystems operate and process data independently, each processing different types of data (signals), each subsystem concentrates less signal information on the status of the processed data and responds quickly. Since the main motor stops operating when any signal switch fails, it can respond to abnormal signal signals from the signal switch in real time, eliminating the need for the two subsystems to exchange information and determine signals before taking control actions. This improves response speed and further ensures elevator safety.
[0032] In an optional example, under normal conditions, the voting switches on the power supply line 4 are all in a closed state, the power supply 3 supplies power to the safety execution subsystem 5 and the main motor 6, and the main motor 6 operates normally. When the first subsystem 1 detects that a signal switch in the car is abnormal, it controls the voting switch connected to it to switch to a disconnected state (at this time, the voting switch connected to the second subsystem 2 is still in a closed state), the power supply 3 of the safety execution subsystem 5 and the main motor 6 is cut off, and the safety execution subsystem 5 controls the main motor 6 to stop running to ensure the safety of the elevator.
[0033] Optionally, the signal switch connected to the first subsystem 1 further includes at least one of an inspection switch, an inspection operation switch, a limit switch, a safety clamp safety switch, a slack rope safety switch, and a mechanical stop safety switch. The signal switch connected to the second subsystem 2 further includes at least one of an emergency electric transfer switch, an emergency electric operation switch, a buffer safety switch, and a speed limiter safety switch.
[0034] In one embodiment of the present invention, a car safety control method is provided, which can be used to perform safety control on the car to prevent the elevator from moving unexpectedly. The method can be executed by a safety control system, which can be implemented in the form of hardware and / or software, and the safety control system can be configured in an electronic device. Figure 2 This is a flow chart of the car safety control method, as shown in Figure 2 As shown, the car safety control method includes:
[0035] Car safety control methods include:
[0036] S201: When any of the micro-level state triggering conditions is met, the first subsystem and the second subsystem communicate with each other to confirm whether the two subsystems are ready to enter the micro-level state.
[0037] The slightly flat state trigger condition includes a first trigger condition and a second trigger condition.
[0038] The first trigger condition is that the logic control system sends a request to enter a slightly leveled state to the first subsystem and / or the second subsystem when the car is leveled or re-leveled.
[0039] Car leveling and re-leveling specifically refers to the elevator entering a slightly leveled state from a leveling state. The leveling state means that after the elevator car reaches the destination floor, the car is in the leveling area (the car sill and the floor sill reach the same level), which can be detected by a leveling sensor. The slightly leveled state refers to further pursuing higher accuracy and stability on the basis of the leveling state.
[0040] Among them, at least one of the first subsystem and the second subsystem communicates with the logic control system, that is, when any subsystem receives the request to enter the micro-stationary state sent by the logic control system, the two subsystems open a communication channel and communicate with each other. Specifically, the subsystem that receives the request to enter the micro-stationary state can actively send a request to enter the micro-stationary state to the other subsystem, and the subsystem that receives the request to enter the micro-stationary state is ready to enter the micro-stationary state and feeds back the information of preparing to enter the micro-stationary state. Then, both subsystems can determine whether both subsystems are ready to enter the micro-stationary state.
[0041] The second trigger condition is when the first subsystem determines the elevator car is currently in the leveling zone, using a signal from the leveling sensor. That is, only the first subsystem can determine whether the elevator is currently in the leveling state using the leveling sensor connected to it. When the first subsystem determines the elevator is currently in the leveling state, it prepares to enter the leveling state. If only the second trigger condition is met, the first subsystem proactively sends a request to the second subsystem to enter the slightly leveling state, prompting the second subsystem to prepare for entering the slightly leveling state.
[0042] S202: When it is confirmed that both subsystems are ready to enter the micro-level state, the first subsystem and the second subsystem enter the micro-level state respectively.
[0043] When both subsystems are ready to enter the slightly leveled state, that is, both subsystems determine that the parameters of the current elevator components meet the requirements for entering the slightly leveled state and the car has not moved unexpectedly, each subsystem can confirm through a signal switch connected to the input end, or the logic control system can send relevant instructions.
[0044] S203. The first subsystem bypasses the car door lock switch when entering the slightly leveled state; the second subsystem bypasses the hall door lock switch when entering the slightly leveled state.
[0045] The elevator's car door lock switch and hall door lock switch are both important components of the elevator safety system. Through a combination of mechanical and electrical functions, the car door lock switch and hall door lock switch prevent the car door and hall door from opening under external forces, thereby protecting passenger safety. When the car door lock switch and hall door lock switch are open, the first and second subsystems detect an abnormality and, in turn, disconnect the voting switch on the power supply line, stopping the main motor and bringing the elevator to a safe stop.
[0046] The elevator car needs to reach the target floor safely, accurately and quickly. Since the sill of the car's stop position may not be flush with the floor, or the car's stop position may change due to passengers or cargo entering and exiting the car, it is necessary to open the car door lock switch and the hall door lock switch to align the car sill with the floor. Therefore, when the elevator leveling sensor indicates that the car is in the leveling area, that is, micro-leveling operation is allowed, it is in compliance with safety standards to open the car door lock switch and the hall door lock switch and continue to operate in the micro-leveling state.
[0047] The first subsystem bypasses the car door lock switch when entering the slightly leveled state, that is, the first subsystem cancels the detection and confirmation of the car door safety (whether the car door is locked). The second subsystem bypasses the hall door lock switch when entering the slightly leveled state, that is, the first subsystem cancels the detection and confirmation of the hall door safety (whether the hall door is locked). This can avoid the accidental triggering of the voting switch on the power supply line due to the opening of the car door lock and the hall door lock when the elevator enters the slightly leveled state, that is, avoids the accidental triggering of the elevator safety stop, and ensures the normal operation of the elevator on the basis of ensuring the safety of the elevator.
[0048] In addition, it should be noted that during the car safety control process of S201-S203, the signals of other signal switches in the safety control system are always monitored. When there are signal abnormalities in other signal switches, the voting switch on the power supply line will still be triggered to disconnect, causing the elevator to stop safely.
[0049] In the above-described elevator car safety control method, since the main motor is stopped when any signal switch is abnormal, the abnormal signal from the signal switch can be responded to in real time. This eliminates the need for the two subsystems to exchange information and make judgments before taking control actions. This reduces the response time requirements for real-time safety communication between the two subsystems, improves response speed, and ensures elevator safety. The first and second subsystems bypass the car door lock switch and hall door lock switch connections when entering the micro-leveling state. Therefore, before entering the micro-leveling state, the two subsystems communicate with each other to confirm whether the other subsystem has correctly entered the micro-leveling state. When both subsystems are ready to enter the micro-leveling state, they each enter the micro-leveling state. This avoids the danger of a single subsystem bypassing the door lock switch due to one subsystem not being ready to enter the micro-leveling state while the other subsystem has. Furthermore, the two subsystems communicate only when entering and exiting the micro-leveling state, and do not need to communicate with each other during elevator operation and micro-leveling. This prevents accidental movement of the elevator car while also reducing the response time requirements for real-time safety communication between the two subsystems, lowering the requirements for the elevator's electrical environment for safety communication, and reducing the likelihood of people being trapped in the elevator.
[0050] In one embodiment A of the present invention, the logic control system communicates with at least the first subsystem, that is, the logic control system communicates with the first subsystem and may also communicate with the second subsystem. The first subsystem and the second subsystem confirm whether the subsystems are ready to enter the micro-level state through mutual communication, including the following steps:
[0051] When the first subsystem receives the request to enter the micro-stationary state sent by the logic control system and the second trigger condition is met, the first subsystem prepares to enter the micro-stationary state and sends a request to enter the micro-stationary state to the second subsystem;
[0052] When the second subsystem receives the request to enter the micro-stationary state sent by the first subsystem, it determines that the first subsystem is ready to enter the micro-stationary state, and feeds back a signal of preparing to enter the micro-stationary state to the first subsystem.
[0053] That is, in this embodiment, there are two situations. The first situation is that the logic control system only communicates with the first subsystem, and the logic control system can only send a request to enter the micro-level state to the first subsystem. The first situation is that the logic control system communicates with the first subsystem and the second subsystem at the same time, and the logic control system sends a request to enter the micro-level state to the first subsystem and / or the second subsystem. In general, at least the first subsystem receives the request to enter the micro-level state sent by the logic control system, and the first subsystem triggers the second subsystem to enter the micro-level state.
[0054] Because the first subsystem's input is connected to a leveling sensor, it can determine whether the second trigger condition has been met. This means the leveling sensor determines whether the current car is in the leveling zone. If it is, it determines that it can enter the slightly leveled state. It then communicates with the second subsystem. Upon receiving the slightly leveled state entry request from the first subsystem, the second subsystem determines that the current car is in the leveling zone and that the first subsystem is ready to enter the slightly leveled state. Therefore, the second subsystem can also prepare to enter the slightly leveled state and feed back a signal indicating its readiness to enter the slightly leveled state to the first subsystem. At this point, both subsystems can confirm that they are both ready to enter the slightly leveled state, and both subsystems can enter the slightly leveled state.
[0055] It should be noted that after confirming that both subsystems are ready to enter the micro-level state, the two subsystems do not need to communicate in real time, but instead independently control the subsystems to enter the micro-level state, which can reduce the requirements of the safety communication function on the communication response time and the elevator electrical environment.
[0056] Optionally, after the first subsystem sends the request to enter the micro-ping state to the second subsystem, the first subsystem further performs the following steps:
[0057] When no signal indicating that the second subsystem has entered the slightly flat state is received within the preset communication period, determining whether the second trigger condition is currently met;
[0058] If not, the voting switch corresponding to the first subsystem is controlled to be switched to the off state;
[0059] If so, determine whether there is any communication anomaly between the two subsystems within the preset communication period;
[0060] If there is a communication anomaly, the voting switch corresponding to the first subsystem is controlled to switch to the disconnected state; if there is no communication anomaly, a request to enter the micro-level state is continued to be sent to the second subsystem.
[0061] In the present invention, generally speaking, when the two subsystems are communicating normally and the elevator is operating normally, after the first subsystem sends a request to the second subsystem, it will receive feedback from the second subsystem within a preset communication cycle. Therefore, when the first subsystem does not receive feedback from the second subsystem within the preset communication cycle, it first determines whether the car is in the leveling area to monitor in real time whether there is any unexpected movement during the process of the elevator entering the slightly leveled state. If it is not in the leveling area, the safety strategy is executed to disconnect the voting switch connected to the first subsystem so that the elevator can be safely stopped and the safety of the passengers can be guaranteed. If it is in the leveling area, the communication status of the two subsystems is detected. If there is a communication anomaly, the safety strategy can be executed to ensure the safety of the passengers. If there is no communication anomaly and the current conditions for safely entering the slightly leveled state are still met, the request to enter the slightly leveled state can continue to be sent to the second subsystem.
[0062] In order to describe in detail the process of the two subsystems entering the slightly level state in this embodiment, the process diagrams of the two subsystems entering the slightly level state are respectively used for explanation.
[0063] Figure 3 This is a schematic diagram of the process of the first subsystem entering the slightly flat state in this embodiment. Figure 3 As shown, the following steps are performed in the first subsystem:
[0064] A11, the first subsystem 1 starts;
[0065] A12. Operate in normal state;
[0066] A13, receiving a request to enter a micro-level state from the logic control system;
[0067] A14. Determine whether the current area is leveling;
[0068] If not, return to A13; if so, execute A15;
[0069] A15. Sending a request to the second subsystem to enter a micro-level state;
[0070] A16. (Within a preset communication period) determining whether a message is received that the second subsystem is (preparing to) enter a micro-level state;
[0071] If yes, go to A110, if no, go to A17;
[0072] A17, determine whether the current area is leveling;
[0073] If yes, execute A19, if no, execute A18;
[0074] A18, enter the safe state, the elevator stops;
[0075] A19. Determine whether the communication is abnormal within n cycles;
[0076] If yes, execute A18; if no, return to execute A15.
[0077] A110 (first subsystem) enters the slightly level state and bypasses the car door lock switch.
[0078] Figure 4 This is a schematic diagram of the process of the second subsystem entering the slightly flat state in this embodiment. Figure 4 As shown, the following steps are performed in the second subsystem:
[0079] A21, the second subsystem starts;
[0080] A22, operate in normal state;
[0081] A23, determining whether a request for the first subsystem to enter a micro-level state is received;
[0082] If not, execute A24; if so, execute A26 to enter the micro-level state;
[0083] A24. Detect whether there is communication anomaly within n communication cycles;
[0084] If yes, execute A25, if not, return to A22;
[0085] A25, enter the safe state, the elevator stops;
[0086] A26, enter the slightly level state and bypass the hall door lock switch;
[0087] A27. Send information to the first subsystem indicating that the system has entered a micro-level state.
[0088] In one embodiment B of the present invention, the logic control system communicates with at least the second subsystem, that is, the logic control system communicates with the second subsystem and may also communicate with the first subsystem. The first subsystem and the second subsystem communicate with each other to confirm whether the two subsystems are ready to enter the micro-level state, including the following steps:
[0089] The second subsystem prepares to enter the micro-level state upon receiving the micro-level state entry request sent by the logic control system, and sends the micro-level state entry request to the first subsystem;
[0090] When the first subsystem receives the request to enter the micro-stationary state sent by the second subsystem, it determines that the second subsystem is ready to enter the micro-stationary state, and judges whether the second trigger condition is currently met. If the second trigger condition is met, the first subsystem feeds back a signal of preparing to enter the micro-stationary state to the second subsystem.
[0091] After the second subsystem sends a request to enter the micro-ping state to the first subsystem, the second subsystem further performs the following steps:
[0092] When no signal indicating that the first subsystem has entered the micro-stationary state is received within the preset communication period, determining whether there is a communication anomaly between the two subsystems within the preset communication period;
[0093] If yes, the voting switch corresponding to the second subsystem is controlled to be switched to the off state;
[0094] If not, continue to send a request to enter the micro-level state to the first subsystem.
[0095] In general, at least the second subsystem receives the request to enter the slightly leveled state sent by the logic control system, and the second subsystem triggers the first subsystem to enter the slightly leveled state. The specific process and principle are similar to those of the above-mentioned embodiment A. Please refer to the relevant description in embodiment A. The main difference is that the first subsystem is connected to the leveling sensor. When the first subsystem receives the request to enter the slightly leveled state sent by the second subsystem, it is necessary to determine whether the current car is in the leveling area to determine the feasibility of entering the slightly leveled state.
[0096] In addition, in other embodiments, when the logic control system sends a request to enter the slightly leveled state to the first subsystem and the second subsystem at the same time, the process of the two subsystems executing the car safety control method is similar to the control process of the above two embodiments and will not be repeated.
[0097] In one embodiment of the present invention, Figure 5 The car safety control method flow chart shown in FIG. 1 further includes the following steps:
[0098] S501. When the conditions for exiting the micro-level state are met, the first subsystem and the second subsystem communicate with each other to confirm whether both subsystems are ready to exit the micro-level state.
[0099] Among them, the exit conditions of the slightly level state include a first exit condition and a second exit condition. The first exit condition includes the logic control system sending a request to exit the slightly level state to the first subsystem and / or the second subsystem when the car is leveled and re-leveled. The second exit condition includes the first subsystem determining that the car is currently in a non-level area through the signal of the leveling sensor.
[0100] The principles for setting the conditions for exiting the slightly leveled state are roughly the same as those for entering the slightly leveled state. Regarding the second exit condition, when the car is in a non-leveling area, it means that the car has moved from a leveling area to a non-leveling area. For passenger safety, the car door lock switch and the hall door lock switch must be locked. Therefore, when the second exit condition is met, the slightly leveled state must be exited, and the car door lock switch and the hall door lock switch must be bypassed.
[0101] S502: When it is confirmed that both subsystems are ready to exit the micro-level state, the first subsystem and the second subsystem exit the micro-level state respectively.
[0102] When both subsystems are ready to exit the slightly level state, that is, both subsystems determine that the parameters of the current elevator components meet the requirements for exiting the slightly level state, the two subsystems can exit the slightly level state independently.
[0103] S503, the first subsystem cancels the bypass car door lock switch when exiting the slightly leveled state; the second subsystem cancels the bypass hall door lock switch when exiting the slightly leveled state;
[0104] When exiting the micro-leveling state, the signals of the car door lock switch and the hall door lock switch are monitored again, so that the elevator can operate normally while ensuring the safety of passengers.
[0105] The above steps S501-S503 occur after the first subsystem and the second subsystem enter a slightly flat state.
[0106] In an optional embodiment B, the logic control system communicates with at least the second subsystem; the first subsystem and the second subsystem confirm through mutual communication whether both subsystems are ready to exit the micro-level state, including:
[0107] When the second subsystem receives the request to exit the micro-level state sent by the logic control system, it prepares to exit the micro-level state and sends the request to exit the micro-level state to the first subsystem;
[0108] When the first subsystem receives the request to exit the micro-level state sent by the second subsystem, it determines that the second subsystem is ready to exit the micro-level state, and feeds back a signal of preparing to exit the micro-level state to the second subsystem.
[0109] In order to describe in detail the process of the two subsystems exiting the micro-level state in this embodiment, the process of the two subsystems exiting the micro-level state is now explained with reference to the schematic diagrams of the process.
[0110] Figure 6 This is a schematic diagram of the process of the first subsystem exiting the micro-level state in this embodiment, as shown in FIG. Figure 6 As shown, the following steps are performed in the first subsystem:
[0111] B11, initial state: in slightly flat state, bypass car door lock switch;
[0112] B12. Determine whether it is in the leveling area.
[0113] When in a slightly flat state, it is necessary to determine whether the car is in the flat area. If so, execute B14, otherwise execute B13 to enter the safe state;
[0114] B13, enter the safe state, the elevator stops;
[0115] B14, determining whether a request to exit the micro-leveling state is received from the control board;
[0116] If yes, execute B15-B17, if no, return to B11;
[0117] B15. Cancel the bypass car door lock;
[0118] B16. Sending a request to exit the micro-level state to the second subsystem;
[0119] B17, determining whether a message is received that the second subsystem has exited the micro-leveling state;
[0120] If yes, execute B110, if no, execute B18;
[0121] B18. Determine whether it is in the leveling area;
[0122] If yes, execute B19, if no, execute B13 to enter the safe state;
[0123] B19. Determine whether there is any abnormality within n communication cycles;
[0124] If yes, execute B13 to enter the safe state; if no, return to execute B16;
[0125] B110. Exit the micro-level state and return to normal state.
[0126] That is, re-monitor the signal of the car door lock switch to ensure the safety of the elevator during operation.
[0127] Figure 7 This is a schematic diagram of the process of the second subsystem exiting the micro-level state in this embodiment. Figure 7 As shown, the following steps are performed in the second subsystem:
[0128] B21, initial state: in a slightly flat state, bypassing the hall door lock switch;
[0129] B22. Determine whether a request to exit the micro-ping state from the first subsystem is received.
[0130] If yes, execute B25, if no, execute B23 to enter communication judgment;
[0131] B23. Determine whether there is any abnormality within n communication cycles;
[0132] If yes, execute B24 to enter the safe state, otherwise return to B21;
[0133] B24, enter the safe state, the elevator stops;
[0134] B25, cancel the bypass hall door lock switch;
[0135] B26. Sending an exit micro-level status to the first subsystem;
[0136] B27. Determine whether a confirmation signal returned by the first subsystem is received;
[0137] If yes, execute B29, if no, execute B28;
[0138] B28. Determine whether there is any abnormality within n communication cycles;
[0139] If yes, execute B23 to enter the safe state; if no, execute B26.
[0140] B28. Exit the micro-level state and return to normal state.
[0141] The above-mentioned car safety control method involves the specific process of the two subsystems entering and exiting the slightly leveled state. First of all, it should be made clear that the two subsystems need to communicate with each other for confirmation only before entering and exiting the slightly leveled state. After the confirmation is completed, the two subsystems work independently without the need for real-time communication, which reduces the response time of the real-time safety communication between the two subsystems and the requirements of the elevator communication environment, improves the response speed, and ensures the safety of the elevator.
[0142] In one embodiment of the present invention, a safety control system is also provided. Figure 1 This is a schematic diagram of the structure of a safety control system provided in this embodiment. Figure 1 As shown, the safety control system includes a power supply, a power supply circuit, a safety execution subsystem, and a main motor connected in sequence, as well as a first subsystem and a second subsystem communicating with each other. The first subsystem and / or the second subsystem also communicate with the logic control system of the elevator. The input end of the first subsystem is connected to at least the car door lock switch and the leveling sensor, and the input end of the second subsystem is connected to at least the hall door lock switch. The output ends of the two subsystems are respectively connected to different voting switches on the power supply circuit. When the signal switch at the input end of any subsystem is abnormal, the corresponding voting switch is controlled to switch to the off state to cut off the power supply. When the power supply is cut off, the safety execution subsystem controls the main motor to stop running.
[0143] When any of the micro-stationary state triggering conditions is met, the first subsystem and the second subsystem communicate with each other to confirm whether the two subsystems are ready to enter the micro-stationary state;
[0144] When it is confirmed that both subsystems are ready to enter the micro-level state, the first subsystem and the second subsystem respectively enter the micro-level state;
[0145] The first subsystem bypasses the car door lock switch when entering the slightly leveled state; the second subsystem bypasses the hall door lock switch when entering the slightly leveled state;
[0146] Among them, the micro-leveling state triggering condition includes a first triggering condition and a second triggering condition. The first triggering condition is that the logic control system sends a request to enter the micro-leveling state to the first subsystem and / or the second subsystem when the car is leveled and re-leveled. The second triggering condition is that the first subsystem determines that the car is currently in the leveling area through the signal of the leveling sensor.
[0147] The safety control system provided by the embodiment of the present invention can execute the elevator car safety control method provided by any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method.
[0148] Figure 8 A schematic block diagram of an electronic device 40 that can be used to implement an embodiment of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital assistants, cellular phones, smartphones, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are provided as examples only and are not intended to limit the implementation of the present invention described and / or claimed herein.
[0149] like Figure 8 As shown, the electronic device 40 includes at least one processor 41 and a memory, such as a read-only memory (ROM) 42, a random access memory (RAM) 43, etc., which is communicatively connected to the at least one processor 41. The memory stores a computer program that can be executed by the at least one processor, and the processor 41 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 42 or the computer program loaded from the storage unit 48 into the random access memory (RAM) 43. Various programs and data required for the operation of the electronic device 40 can also be stored in the RAM 43. The processor 41, ROM 42, and RAM 43 are connected to each other via a bus 44. An input / output (I / O) interface 45 is also connected to the bus 44.
[0150] Multiple components in the electronic device 40 are connected to the I / O interface 45, including an input unit 46, such as a keyboard, a mouse, etc.; an output unit 47, such as various types of displays, speakers, etc.; a storage unit 48, such as a magnetic disk, an optical disk, etc.; and a communication unit 49, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 49 allows the electronic device 40 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.
[0151] The processor 41 can be any general-purpose and / or specialized processing component with processing and computing capabilities. Some examples of the processor 41 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various specialized artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The processor 41 executes the various methods and processes described above, such as the elevator car safety control method.
[0152] In some embodiments, the car safety control method can be implemented as a computer program that is tangibly contained in a computer-readable storage medium, such as a storage unit 48. In some embodiments, part or all of the computer program can be loaded and / or installed on the electronic device 40 via the ROM 42 and / or the communication unit 49. When the computer program is loaded into the RAM 43 and executed by the processor 41, one or more steps of the car safety control method described above can be performed. Alternatively, in other embodiments, the processor 41 can be configured to execute the car safety control method in any other suitable manner (e.g., by means of firmware).
[0153] Various embodiments of the systems and techniques described above can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), system-on-chip systems (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include being implemented in one or more computer programs that are executable and / or interpreted on a programmable system that includes at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.
[0154] Computer programs for implementing the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the computer program is executed by the processor, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The computer program may be executed entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.
[0155] In the context of the present invention, computer-readable storage media can be tangible media that can contain or store a computer program for use with an instruction execution system, device or equipment or used in combination with an instruction execution system, device or equipment. Computer-readable storage media can include but are not limited to electronic, magnetic, optical, electromagnetic, infrared or semiconductor systems, devices or equipment, or any suitable combination of the foregoing. Alternatively, computer-readable storage media can be machine-readable signal media. More specific examples of machine-readable storage media can include electrical connections based on one or more lines, portable computer disks, hard disks, random access memories (RAM), read-only memories (ROM), erasable programmable read-only memories (EPROM or flash memory), optical fibers, portable compact disk read-only memories (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0156] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).
[0157] The systems and techniques described herein can be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer with a graphical user interface or web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.
[0158] A computing system may include clients and servers. The clients and servers are typically remote from each other and typically interact via a communication network. This client-server relationship arises through computer programs running on the respective computers, creating a client-server relationship. The server may be a cloud server, also known as a cloud computing server or cloud host. This server is a hosting product within the cloud computing service ecosystem that addresses the management difficulties and limited scalability of traditional physical hosting and VPS services.
[0159] It should be understood that the various forms of the processes shown above can be used to reorder, add, or delete steps. For example, the steps described in the present invention can be performed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved. This is not limited herein.
[0160] The above specific embodiments do not limit the scope of protection of the present invention. Those skilled in the art will appreciate that various modifications, combinations, sub-combinations, and substitutions may be made based on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention are intended to be included within the scope of protection of the present invention.
Claims
1. A car safety control method, characterized in that: Applied to a safety control system, the safety control system includes a power supply, a power supply circuit, a safety execution subsystem, and a main motor connected in sequence, as well as a first subsystem and a second subsystem communicating with each other, the first subsystem and / or the second subsystem further communicating with a logic control system of the elevator, the input end of the first subsystem being connected to at least a car door lock switch and a leveling sensor, and the input end of the second subsystem being connected to at least a hall door lock switch; the output ends of the two subsystems being connected to different voting switches on the power supply circuit; when a signal switch at the input end of any subsystem is abnormal, the corresponding voting switch is controlled to switch to an off state to cut off the power supply, and the safety execution subsystem controls the main motor to stop running when the power supply is cut off; The method comprises: When any of the micro-stationary state triggering conditions is met, the first subsystem and the second subsystem communicate with each other to confirm whether the two subsystems are ready to enter the micro-stationary state; When it is confirmed that both subsystems are ready to enter the micro-level state, the first subsystem and the second subsystem respectively enter the micro-level state; The first subsystem bypasses the car door lock switch when entering the slightly leveled state; the second subsystem bypasses the hall door lock switch when entering the slightly leveled state; Among them, the micro-leveling state triggering condition includes a first triggering condition and a second triggering condition. The first triggering condition is that the logic control system sends a request to enter the micro-leveling state to the first subsystem and / or the second subsystem when the car is leveled and re-leveled. The second triggering condition is that the first subsystem determines that the car is currently in the leveling area through the signal of the leveling sensor.
2. The method according to claim 1, wherein The logic control system communicates with at least the first subsystem; The first subsystem and the second subsystem communicate with each other to confirm whether the two subsystems are ready to enter the micro-level state, including: When the first subsystem receives the request to enter the micro-stationary state sent by the logic control system and the second trigger condition is met, the first subsystem prepares to enter the micro-stationary state and sends a request to enter the micro-stationary state to the second subsystem; When the second subsystem receives the request to enter the micro-stationary state sent by the first subsystem, it determines that the first subsystem is ready to enter the micro-stationary state, and feeds back a signal of preparing to enter the micro-stationary state to the first subsystem.
3. The method according to claim 2, wherein After the first subsystem sends a request to enter a micro-ping state to the second subsystem, the first subsystem further performs the following steps: When no signal indicating that the second subsystem has entered the slightly flat state is received within a preset communication period, determining whether the second trigger condition is currently met; If not, controlling the voting switch corresponding to the first subsystem to switch to an off state; If so, determine whether there is any communication anomaly between the two subsystems within the preset communication period; If there is a communication abnormality, controlling the voting switch corresponding to the first subsystem to switch to an off state; If there is no communication abnormality, continue to send a request to enter the micro-ping state to the second subsystem.
4. The method according to claim 1, wherein The logic control system communicates with at least the second subsystem; The first subsystem and the second subsystem communicate with each other to confirm whether the two subsystems are ready to enter the micro-level state, including: The second subsystem prepares to enter the micro-stationary state upon receiving the micro-stationary state entry request sent by the logic control system, and sends the micro-stationary state entry request to the first subsystem; When the first subsystem receives the request to enter the micro-stationary state sent by the second subsystem, it determines that the second subsystem is ready to enter the micro-stationary state, and judges whether the second trigger condition is currently met. If the second trigger condition is met, the first subsystem feeds back a signal to the second subsystem that it is ready to enter the micro-stationary state.
5. The method according to claim 4, wherein After the second subsystem sends a request to enter a micro-ping state to the first subsystem, the second subsystem further performs the following steps: When no signal indicating that the first subsystem has entered the micro-stationary state is received within the preset communication period, determining whether there is a communication anomaly between the two subsystems within the preset communication period; If so, controlling the voting switch corresponding to the second subsystem to switch to an off state; If not, continue to send a request to enter the micro-level state to the first subsystem.
6. The method according to any one of claims 1 to 5, wherein: Also includes: When the micro-level state exit condition is met, the first subsystem and the second subsystem communicate with each other to confirm whether the two subsystems are ready to exit the micro-level state; When it is confirmed that both subsystems are ready to exit the micro-level state, the first subsystem and the second subsystem exit the micro-level state respectively; The first subsystem cancels the bypass car door lock switch when exiting the micro-leveling state; the second subsystem cancels the bypass hall door lock switch when exiting the micro-leveling state; Among them, the micro-leveling state exit conditions include a first exit condition and a second exit condition. The first exit condition includes the logic control system sending a micro-leveling state exit request to the first subsystem and / or the second subsystem when the car is leveled and re-leveled. The second exit condition includes the first subsystem determining that the car is currently in a non-leveling area through the signal of the leveling sensor.
7. The method according to claim 6, wherein The logic control system communicates with at least the first subsystem; The first subsystem and the second subsystem communicate with each other to confirm whether the two subsystems are ready to exit the micro-level state, including: When the first subsystem receives the request to exit the slightly leveled state sent by the logic control system and detects that the current car is in the leveling area, it prepares to exit the slightly leveled state and sends a request to exit the slightly leveled state to the second subsystem; When the second subsystem receives the request to exit the micro-stationary state sent by the first subsystem, it determines that the first subsystem is ready to exit the micro-stationary state, and feeds back a signal of preparing to exit the micro-stationary state to the first subsystem.
8. The method according to claim 6, wherein The logic control system communicates with at least the second subsystem; The first subsystem and the second subsystem communicate with each other to confirm whether the two subsystems are ready to exit the micro-level state, including: When the second subsystem receives the request to exit the micro-level state sent by the logic control system, it prepares to exit the micro-level state and sends the request to exit the micro-level state to the first subsystem; When the first subsystem receives the request to exit the micro-stationary state sent by the second subsystem, it determines that the second subsystem is ready to exit the micro-stationary state, and feeds back a signal of preparing to exit the micro-stationary state to the second subsystem.
9. An electronic device, characterized in that: The electronic device comprises: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor. The computer program is executed by the at least one processor to enable the at least one processor to execute the car safety control method according to any one of claims 1 to 8.
10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the elevator car safety control method according to any one of claims 1 to 8 when executed.