Elevator lock circuit control system based on induction key
Through the elevator lock loop control system combining fingerprint recognition and multi-stage verification, the problem of erroneous operation and insufficient safety in traditional systems is solved, and the multiple safety and redundant design of elevator locks is realized to ensure the reliable operation and high availability of elevators.
Patent Information
- Application Number
- CN202510789559.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-13
- Publication Date
- 2025-09-02
- Estimated Expiration
- 2045-06-13
AI Technical Summary
Traditional induction key systems are prone to misoperation, delays and insufficient safety in elevator lock circuit control, and unauthorized users may enter specific areas in multi-story buildings, affecting the safety and convenience of elevators.
The elevator lock loop control system based on induction key is adopted, combined with mechanical lock core, micro servo motor, fingerprint recognition module and multi-stage verification process, and the main and backup control loop and loop switching logic controller are used to realize the multiple safety and redundant design of the elevator lock to ensure the reliability and maintainability of the elevator lock.
It improves the safety and reliability of elevator locks, prevents unauthorized operations, ensures that the elevator operates normally in the event of a failure, and improves the safety and maintenance efficiency of the system.
Smart Images

Figure CN120288605B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of elevator relay control, and in particular to an elevator lock circuit control system based on an induction key. Background Art
[0002] As the height of modern buildings continues to increase, elevators have become an indispensable means of transportation in daily life. The safety and convenience of elevators are crucial to the user experience. In some specific scenarios, such as hotels, office buildings, and residential communities, the use of elevators requires permission control to ensure that only authorized personnel can access specific floors.
[0003] To improve elevator safety and convenience, proximity key technology is gradually being applied to elevator lock circuit control. A proximity key is an authentication tool based on radio frequency identification (RFID) or near-field communication (NFC) technology. By pairing a proximity key with an elevator control system, more intelligent elevator access management can be achieved. The proximity key automatically recognizes the user when they approach the elevator and controls functions such as elevator start and floor selection through authorization verification. However, in traditional proximity key systems, users need to manually operate the sensing device, which can easily lead to misoperation or delays. Furthermore, in multi-story buildings, the elevator lock circuit control system needs to ensure effective isolation between different floors to prevent unauthorized users from entering specific areas, thereby affecting elevator safety. Summary of the Invention
[0004] Based on this, it is necessary for the present invention to provide an elevator lock loop control system based on an induction key to solve at least one of the above technical problems.
[0005] To achieve the above purpose, an elevator lock circuit control system based on an induction key includes:
[0006] The elevator lock body has a built-in mechanical lock core, an actuator, a power supply circuit, a verification module, and a storage module. The actuator is a micro servo motor, and its drive gear is engaged with the rack of the mechanical lock core. The control signal corresponding to the drive gear is triggered after authorization by the verification module, and the operating status of the drive gear is recorded by the storage module. The storage module records the identity information of the operation and maintenance personnel, the unlocking time, the operating status, and the corresponding loop operation log, and transmits them to the cloud server through an encryption protocol;
[0007] An induction key, on which a corresponding key chip and a fingerprint recognition module are integrated, is inserted into the mechanical lock cylinder corresponding to the elevator lock body, is activated by the power supply circuit, and transmits the fingerprint information collected by the fingerprint recognition module to the verification module to execute the corresponding multi-level verification workflow;
[0008] The main control circuit includes a first DC24V safety power supply, a first optical coupling isolation relay K1, and a first dual-coil magnetic latching relay KM1, wherein the coil of K1 is controlled by the authorization verification signal of the verification module, the normally closed contact of K1 is connected in series in the holding coil circuit of KM1, and the main contact of KM1 controls the on and off of the main power supply of the elevator;
[0009] The backup control circuit includes a second DC24V safety power supply, a second time delay relay K2, and a second magnetic latching relay KM2. The delayed closing contact of K2 is connected in series with the operating coil of KM2, and the main contact of KM2 is connected in parallel with the main contact of KM1 to form redundant control;
[0010] The main control circuit and the backup control circuit adopt a master-slave parallel architecture to form a dual redundant elevator lock control circuit;
[0011] The loop switching logic controller monitors the current status of the main control loop in real time. When a K1 fault corresponding to the main control loop is detected, the backup control loop is automatically activated and a maintenance alarm is issued through the corresponding human-machine interface HMI.
[0012] Furthermore, the verification module includes a fingerprint feature comparison unit, a physical key decoding unit, and a real-time clock verification unit. The multi-level verification workflow includes:
[0013] The first stage verification is to obtain the digital signature corresponding to the key chip in the induction key through the physical key decoding unit, and verify the digital signature corresponding to the key chip through the RSA-2048 algorithm to confirm the validity of the physical key corresponding to the digital signature;
[0014] In the second stage of verification, the fingerprint feature comparison unit uses a deep learning algorithm to compare the feature points corresponding to the fingerprint information collected by the fingerprint recognition module with the corresponding built-in fingerprint feature points, and sets the matching threshold to 0.98 similarity;
[0015] The third stage verification is to check whether the unlocking operation time corresponding to the induction key is within the preset maintenance time window through the real-time clock verification unit. The preset maintenance time window is set to reject if the deviation exceeds ±15 minutes;
[0016] Dynamic password verification: a one-time 6-digit verification code is generated for each stage of verification operation, which needs to be confirmed through the operation and maintenance personnel's mobile phone APP;
[0017] All the above verification steps must be completed in sequence within 8 seconds. If the timeout is exceeded, the system will be locked for 5 minutes. If it does not time out, the corresponding authorization verification signal will be generated in response.
[0018] Furthermore, the execution logic corresponding to the elevator lock circuit control system based on the induction key is specifically as follows:
[0019] When the corresponding authorization verification signal is verified, the coil corresponding to the first optocoupler isolation relay K1 is energized, the normally closed contact corresponding to K1 is disconnected, the holding coil corresponding to the first double-coil magnetic latching relay KM1 is de-energized, and the main contact of KM1 is switched to the open state to cut off the main power supply of the elevator;
[0020] When the main control circuit fails, the circuit switching logic controller switches and triggers the second time delay relay K2 to delay closing. After the action coil of the second magnetic latching relay KM2 is energized, its main contacts are switched to maintain the corresponding power-off state of the elevator.
[0021] Furthermore, the first dual-coil magnetic latching relay KM1 includes an actuating coil and a holding coil, including:
[0022] The action coil is directly driven by the authorization verification signal corresponding to the verification module, which is used to quickly respond to the elevator lock command;
[0023] The holding coil is kept in the de-energized state through the normally closed contact of K1, and the backup control circuit takes over control only when K1 fails.
[0024] Furthermore, a transient voltage suppressor diode TVS is connected in series in the driving circuit of the action coil to eliminate the corresponding reverse electromotive force when the first dual-coil magnetic latching relay KM1 is switched.
[0025] Furthermore, a signal amplification circuit is provided between the input side of the first optocoupler isolation relay K1 and the verification module, for increasing the current drive corresponding to the authorization verification signal to the required threshold of 0.4A for the coil of K1 to ensure that the coil of K1 is reliably attracted.
[0026] Furthermore, an RC buffer circuit is connected in parallel to the output end of the signal amplifying circuit to absorb transient pulses generated when the coil of K1 is disconnected.
[0027] Furthermore, the delay time of the second time delay relay K2 is adjustable and can be set to three levels of 50ms, 100ms or 200ms through the dip switch, so that the delayed closing contact of K2 delays the action after the main control circuit fails, avoiding instantaneous competition conflict with the main control circuit.
[0028] Furthermore, the delayed closing contact of K2 is a double-contact structure, in which one pair of contacts is used to control the action coil of KM2, and the other pair of contacts is connected to the loop switching logic controller as a status feedback signal. The loop switching logic controller also includes a fault counter. When the number of faults in the main control loop exceeds 3 times, the backup control loop is forcibly locked and the corresponding human-machine interaction interface HMI is triggered to issue an audible and visual alarm.
[0029] Furthermore, the main contacts of KM2 and the main contacts of KM1 adopt a cross-interlocking layout. When the main contacts of KM1 cannot be disconnected due to adhesion, the mechanical structure corresponding to the main contacts of KM2 is controlled to forcibly push open the main contacts of KM1.
[0030] Beneficial effects of the present invention:
[0031] The elevator lock and elevator circuit control system based on the induction key proposed in the present invention is generally composed of an elevator lock body, an induction key, a main control circuit, a backup control circuit, and a circuit switching logic controller. Compared with the existing technology, the beneficial effect of this application is that the elevator lock control system of the present invention has a multiple security and redundancy design, which effectively improves the safety, reliability, and maintainability of the elevator lock. First, the elevator lock body has a built-in mechanical lock cylinder, an actuator, a verification module, and a storage module. Combined with a micro servo motor and a precise gear transmission mechanism, it can accurately control the opening and closing of the lock cylinder. Through the authorization of the verification module, the security of the unlocking process is ensured. All operation logs, such as the identity of the operation and maintenance personnel and the unlocking time, are encrypted and stored and transmitted to the cloud server in real time for easy traceability and security management. Secondly, the induction key combines fingerprint recognition technology for multi-level identity authentication, which greatly enhances the security of the unlocking process and avoids unauthorized operation. Through intelligent verification and identity confirmation, the system effectively prevents illegal unlocking and delayed operation. Then, a primary and backup control loop was designed to enhance the stability and fault tolerance of the elevator locks through redundant control loops. In the event of a failure in the primary control loop, the backup control loop automatically takes over, ensuring the normal operation of the elevator lock system in the event of a failure, thus ensuring the continuity and safety of elevator use. Finally, a corresponding loop switching logic controller was set up to monitor the operating status of the primary control loop in real time. In the event of a failure, it automatically switches to the backup loop and issues a maintenance alarm, prompting operators to promptly address the problem. This redundant design ensures the high availability and reliability of the elevator lock system, thereby improving system safety and maintenance efficiency. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] Other features, objects and advantages of the present invention will become more apparent upon reading the detailed description of non-limiting embodiments thereof made with reference to the following drawings:
[0033] Figure 1This is a schematic diagram of the structure of an elevator lock circuit control system based on an induction key according to the present invention;
[0034] Figure 1 The markings are: 1. Elevator lock body; 2. Induction key; 3. Port corresponding to the main control circuit; 4. Port corresponding to the backup control circuit; 5. Circuit switching logic controller;
[0035] Figure 2 Schematic diagram of the structural connection of the dual redundant elevator lock control circuit of the present invention. DETAILED DESCRIPTION
[0036] The following is a clear and complete description of the technical system of the present invention in conjunction with the accompanying drawings. Obviously, the embodiments described are part of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without making any creative efforts are within the scope of protection of the present invention.
[0037] In addition, the accompanying drawings are merely schematic illustrations of the present invention and are not necessarily drawn to scale. Identical reference numerals in the figures denote identical or similar parts, and thus repetitive descriptions thereof will be omitted. Some of the block diagrams shown in the accompanying drawings are functional entities that do not necessarily correspond to physically or logically independent entities. These functional entities may be implemented in software, in one or more hardware control units or integrated circuits, or in different networks and / or processor systems and / or microcontroller systems.
[0038] It should be understood that although the terms "first," "second," and the like may be used herein to describe various elements, these elements should not be limited by these terms. These terms are used solely to distinguish one element from another. For example, a first element may be referred to as a second element, and similarly, a second element may be referred to as a first element, without departing from the scope of the exemplary embodiments. The term "and / or" as used herein includes any and all combinations of one or more of the listed associated items.
[0039] To achieve this, please refer to Figures 1 to 2 The present invention provides an elevator lock circuit control system based on an induction key, please refer to Figure 1 FIG. 1 is a schematic diagram of the structure of an elevator lock circuit control system based on an induction key according to the present invention, wherein the system includes:
[0040] The elevator lock body 1 has a built-in mechanical lock cylinder, an actuator, a power supply circuit, a verification module, and a storage module. The actuator is a micro servo motor, and its drive gear is engaged with the rack of the mechanical lock cylinder. The control signal corresponding to the drive gear is triggered after authorization by the verification module, and the operating status of the drive gear is recorded by the storage module. The storage module records the identity information of the operation and maintenance personnel, the unlocking time, the operating status, and the corresponding loop operation log, and transmits them to the cloud server through an encryption protocol;
[0041] In an embodiment of the present invention, an elevator lock body 1 is installed next to the elevator car door. The mechanical lock core inside it is made of high-strength alloy material and has an anti-theft function. The actuator uses a micro servo motor model XX-MS05. A drive gear is installed on the motor output shaft. The gear precisely meshes with the rack on the mechanical lock core to ensure that the motor can smoothly drive the mechanical lock core to move when it is running. The verification module uses a microcontroller based on the ARM Cortex-M3 core with powerful data processing and verification capabilities. The storage module uses a Samsung K9F1G08U0M type NAND flash memory chip that can store a large amount of information. The power supply circuit uses an AC / DC conversion module to convert the 220V AC power in the elevator car into 24V DC power to power each module. When the operation and maintenance personnel perform the unlocking operation, the induction key is inserted into the mechanical lock core, and the power supply circuit activates the verification module. The verification module verifies the information transmitted by the induction key. If the verification is successful, the output control signal triggers the micro servo motor to operate, and the drive gear drives the mechanical lock core to open the elevator lock. At the same time, the storage module records the identity information of the operation and maintenance personnel identified by the induction key chip, the unlocking time accurate to the second, the operating status of the micro-servo motor drive gear (such as forward rotation to open, reverse rotation to close), and the circuit operation log of the entire unlocking process. The storage module packages these recorded data and transmits them to the cloud server through encryption protocols (such as the AES-256 encryption algorithm) to ensure secure data storage and subsequent traceability.
[0042] Preferably, the induction key 2 is integrated with a corresponding key chip and a fingerprint recognition module, which is inserted into the mechanical lock cylinder corresponding to the elevator lock body 1 and activated by the power supply circuit and transmits the fingerprint information collected by the fingerprint recognition module to the verification module to execute the corresponding multi-level verification workflow;
[0043] In an embodiment of the present invention, the inductive key 2 adopts an integrated design, integrating a key chip (such as the NXP MIFARE Ultralight C chip) and a fingerprint recognition module (such as the GT-F1511 fingerprint recognition chip from Goodix Technology) into a compact housing. When an operator brings the inductive key close to the elevator lock body 1, they insert the inductive key 2 into the mechanical lock cylinder of the elevator lock body 1. At this time, the power supply circuit in the elevator lock body 1 establishes an electrical connection with the inductive key 2 through the mechanical lock cylinder, powering the inductive key 2 and activating the key chip and fingerprint recognition module. The fingerprint recognition module begins operation. The operator presses their finger on the fingerprint recognition area. The module collects fingerprint information using optical imaging technology. After pre-processing the collected fingerprint image data (such as grayscale and filtering), the collected fingerprint image data is transmitted as a digital signal via a connection line to the verification module in the elevator lock body 1. After receiving the fingerprint information, the verification module compares it with the operator's fingerprint template pre-stored in the storage module and executes the corresponding multi-level verification workflow. For example, it first performs rapid feature point matching to preliminarily screen similar fingerprints, and then performs detailed feature comparison to ensure the accuracy of the fingerprint match.
[0044] Preferably, the main control circuit includes a first DC24V safety power supply, a first optocoupler isolation relay K1 and a first double-coil magnetic latching relay KM1, wherein the coil of K1 is controlled by the authorization verification signal of the verification module, the normally closed contact of K1 is connected in series in the holding coil circuit of KM1, and the main contact of KM1 controls the on and off of the main power supply of the elevator;
[0045] In the embodiment of the present invention, a main control circuit is built in the elevator control cabinet, and the first DC24V safety power supply of the Meanwell S-100-24 type is selected. The power supply has overvoltage and overcurrent protection functions and can stably output 24V DC power. The first optocoupler isolation relay K1 is the Omron G3VM-61GR type. The signal amplification circuit is connected between its input side and the verification module. The signal amplification circuit adopts a transistor amplification circuit with the NPN transistor S8050 as the core component. By reasonably setting the resistance values of the base resistor, emitter resistor and collector resistor, the authorization verification signal current output by the verification module is amplified to 0.4A, which meets the requirements for reliable attraction of the K1 coil. Current drive threshold. When the verification module outputs the authorization verification signal, the signal is amplified by the amplifier circuit and drives the coil of K1 to disconnect its normally closed contact. The first double-coil magnetic latching relay KM1 uses Panasonic HH54P-L type. Its holding coil circuit is connected in series with the normally closed contact of K1. When the normally closed contact of K1 is disconnected, the holding coil of KM1 loses power, and the main contact of KM1 operates to control the on and off of the elevator main power supply. At the output end of the signal amplification circuit, an RC snubber circuit consisting of a 0.1μF capacitor and a 100Ω resistor is connected in parallel. When the coil of K1 is disconnected, the transient pulse generated is absorbed by the RC snubber circuit to avoid damage to other circuit components.
[0046] Preferably, the backup control circuit includes a second DC24V safety power supply, a second time delay relay K2 and a second magnetic latching relay KM2, the delayed closing contact of K2 is connected in series with the action coil of KM2, and the main contact of KM2 is connected in parallel with the main contact of KM1 to form redundant control;
[0047] In this embodiment of the present invention, a backup control circuit is built adjacent to the main control circuit in the elevator control cabinet. A second DC24V safety power supply (Model LM25-24S24) is used, which also provides reliable power supply protection. The second time delay relay K2 is a Schneider LRD-02C model. Its delayed closing contact is connected in series with the operating coil of the second magnetic latching relay KM2 (Model HF115F-2H-S). The delay time of K2 can be set to 50ms, 100ms, or 200ms via the DIP switch on the elevator control cabinet. In the third gear, when the main control circuit fails, such as the K1 coil burns out or the contacts stick, the circuit switching logic controller detects the abnormal current in the main control circuit. After the set delay time, the delayed closing contact of K2 closes, connecting the action coil of KM2, so that the main contact of KM2 is actuated and connected in parallel with the main contact of KM1 to achieve redundant control of the elevator main power supply. The delayed closing contact of K2 adopts a double-contact structure. One pair of contacts controls the action coil of KM2, and the other pair of contacts is connected to the circuit switching logic controller as a status feedback signal. The circuit switching logic controller adopts the STM32F407 microcontroller. It has a built-in fault counter. When it detects that the number of faults in the main control circuit exceeds 3 times, the backup control circuit will be forcibly locked to prohibit it from operating again, and the human-machine interface HMI in the elevator car (such as Kunlun Tongtai TPC7062KX touch screen) will be triggered to issue an audible and visual alarm to remind the operation and maintenance personnel to carry out timely maintenance. The main contacts of KM2 and KM1 adopt a cross-interlocking layout. When the elevator lock control circuit is installed, through the mechanical structure design, when the main contacts of KM1 cannot be disconnected due to adhesion, the mechanical push rod corresponding to the main contact of KM2 can forcibly push open the main contacts of KM1 to ensure that the main power supply of the elevator can be reliably cut off.
[0048] The main control circuit and the backup control circuit adopt a master-slave parallel architecture to form a dual redundant elevator lock control circuit (such as Figure 2 shown);
[0049] Preferably, the circuit switching logic controller 5 monitors the current status corresponding to the main control circuit in real time, automatically activates the backup control circuit when a K1 fault corresponding to the main control circuit is detected, and issues a maintenance alarm through the corresponding human-machine interface HMI.
[0050] In an embodiment of the present invention, a circuit switching logic controller 5 is installed in the elevator control cabinet. The circuit switching logic controller uses an STM32F407 microcontroller as its core and monitors the current status of the main control circuit in real time through a current transformer. The current transformer is a LEM LA25-NP type. It converts the current in the main control circuit into a weak current signal and transmits it to the ADC (analog-to-digital converter) interface of the circuit switching logic controller. The circuit switching logic controller determines whether the main control circuit is operating normally based on the collected current signal. For example, when the main control circuit is normal, the current is within a stable operating current range. If K1 fails, such as a coil open circuit, the current will become zero, or if the contacts stick, the current will increase abnormally. Once a main control circuit fault is detected, the circuit switching logic controller immediately issues a control signal to activate the backup control circuit and simultaneously sends a fault message to the human-machine interface (HMI). After receiving the message, the HMI displays a main control circuit fault prompt on the screen and activates a buzzer to sound an alarm, reminding elevator operation and maintenance personnel to promptly perform maintenance and repair on the main control circuit, ensuring the reliable operation of the elevator lock circuit control system.
[0051] Furthermore, the verification module includes a fingerprint feature comparison unit, a physical key decoding unit, and a real-time clock verification unit. The multi-level verification workflow includes:
[0052] The first stage verification is to obtain the digital signature corresponding to the key chip in the induction key through the physical key decoding unit, and verify the digital signature corresponding to the key chip through the RSA-2048 algorithm to confirm the validity of the physical key corresponding to the digital signature;
[0053] In an embodiment of the present invention, the first-level verification process is implemented by a physical key decoding unit, which has a built-in RSA-2048 algorithm public key and signature verification module. When the sensor key is inserted into the elevator lock body, the power supply circuit activates the key chip, and the chip outputs its pre-stored digital signature (256 bytes in length, compliant with the PKCS#1 v2.2 standard). The physical key decoding unit reads the signature via the SPI interface at a 1MHz clock frequency and calls a hardware encryption engine (such as the ATECC608A security chip) to perform signature verification. The verification process strictly follows the RSA-2048 algorithm process: first, the signature is decrypted by modular exponentiation to obtain a hash digest. Then, the SHA-256 algorithm is used to calculate the theoretical digest of the key chip's UID (unique identifier, 16 bytes) and a preset salt value (8 bytes). Finally, the two digests are compared to see if they are completely consistent. If the digests match and the signature is valid, a verification pass signal is output to the next level; otherwise, the error code "E21" is triggered and the subsequent verification process is terminated.
[0054] Preferably, in the second stage verification, the fingerprint feature comparison unit uses a deep learning algorithm to compare the feature points corresponding to the fingerprint information collected by the fingerprint recognition module with the built-in corresponding fingerprint feature points, and sets the matching threshold to 0.98 similarity;
[0055] In an embodiment of the present invention, the second-stage verification process is performed by a fingerprint feature comparison unit, which integrates an STM32H7 series MCU and a capacitive fingerprint sensor (resolution 508DPI). After the fingerprint recognition module collects the user's fingerprint image, it generates a feature point topology map through an adaptive binarization algorithm (threshold set to a grayscale value of 128) and a thinning algorithm (Zhang-Suen skeleton extraction), extracting at least 40 feature points (including bifurcation points, endpoints, and core point coordinates). The deep learning model uses a pre-trained MobileNetV3 (the model size after quantization is 1.2MB). The input is a normalized fingerprint image of 64×64 pixels. The output layer uses cosine similarity to calculate the match between the current fingerprint and a pre-stored template (stored in the encrypted FLASH partition). The system sets the similarity threshold to 0.98 (corresponding to a false positive rate (FAR) of ≤0.001%). Only when the output value is ≥0.98 is it judged as a legitimate fingerprint. The comparison process takes no more than 2 seconds. If it times out or does not reach the threshold, the error code "E22" is recorded and a three-try limit is initiated.
[0056] Preferably, the third stage verification is to check whether the unlocking operation time corresponding to the induction key is within a preset maintenance time window through the real-time clock verification unit, and the preset maintenance time window is set to reject if the deviation exceeds ±15 minutes;
[0057] In an embodiment of the present invention, the third-stage verification process relies on a real-time clock verification unit (RTC) using the DS3231 high-precision RTC chip (with an accuracy of ±2ppm and an annual deviation of less than 1 minute). The system pre-stores a maintenance time window (e.g., 09:00-17:00). During unlocking operations, the RTC outputs the current UTC time (in Unix timestamp format, accurate to the second) via the I2C interface and compares it with the start and end times of the preset window. The time verification logic requires that the operation time must fall completely within the window, with a maximum allowable deviation of ±15 minutes (e.g., if the window ends at 17:00, the actual operation time must not be later than 17:15). If the time deviation exceeds the limit or the RTC battery fails (voltage below 2.5V), an error code "E23" is triggered and unlocking is prohibited. All time comparison operations are performed by a hardware comparator (e.g., a 74HC85), ensuring a response time of less than 50ms.
[0058] Preferably, dynamic password verification is used, and a one-time 6-digit verification code is generated for each stage of verification operation, which needs to be confirmed through the operation and maintenance personnel's mobile phone APP;
[0059] In an embodiment of the present invention, the dynamic password verification process is implemented through the TOTP (time-based one-time password) algorithm. Each time the system verifies, a 6-digit verification code (range 000000-999999) is generated by combining the HMAC-SHA1 algorithm (key length 160 bits) with the current timestamp (30 seconds period). The verification code is sent to the preset operation and maintenance management platform through the ESP32 Wi-Fi module and synchronously displayed on the OLED screen (128×64 pixels) of the elevator lock body. The operation and maintenance personnel must enter the verification code through the mobile phone APP (integrated with the Google Authenticator protocol) within 30 seconds. The system receives the confirmation package returned by the APP through the UDP protocol (port number 5683). If the verification code matches and has not expired, a pass signal is output; otherwise, the error code "E24" is recorded and the verification function is frozen for 1 minute.
[0060] Preferably, all the above verification steps must be completed in sequence within 8 seconds. If the timeout is exceeded, the system will be locked for 5 minutes. If the timeout does not expire, the corresponding authorization verification signal will be generated in response.
[0061] In an embodiment of the present invention, the above corresponding full-process timing is strictly controlled by a hardware timer (such as the TIM2 timer of STM32, with a clock source of 72MHz). After the system is powered on, an 8-second countdown is started, and each verification step is executed in sequence: the first-level stage takes ≤1.5 seconds (including SPI communication and RSA operation), the second-level stage ≤2 seconds (fingerprint collection and model reasoning), the third-level stage ≤50ms (time comparison), and the dynamic password verification stage ≤4 seconds (verification code generation and network transmission). If any stage times out or the total time exceeds 8 seconds, the power supply circuit is immediately cut off, the locking state is activated (lasting 5 minutes, timed by the alarm function of DS3231), and the error code "E25" is recorded. After all verifications are completed normally, the system outputs a 12V / 100ms pulse signal to the actuator to drive the mechanical lock cylinder to unlock, and store the operation log (including the time consumed in each stage and the verification results).
[0062] Furthermore, the execution logic corresponding to the elevator lock circuit control system based on the induction key is specifically as follows:
[0063] When the corresponding authorization verification signal is verified, the coil corresponding to the first optocoupler isolation relay K1 is energized, the normally closed contact corresponding to K1 is disconnected, the holding coil corresponding to the first double-coil magnetic latching relay KM1 is de-energized, and the main contact of KM1 is switched to the open state to cut off the main power supply of the elevator;
[0064] In the embodiment of the present invention, when the authorization verification signal corresponding to the verification module passes, the system outputs a 24V DC voltage signal to the driving end of the first optocoupler isolation relay K1. After the signal is isolated and converted by the LED-phototransistor inside the TLP281-4 optocoupler chip, the K1 coil (impedance 1.2kΩ) is driven to be energized. The normally closed contact of K1 (rated current 10A) is changed from closed to open within 20ms, cutting off the power supply circuit of the holding coil (impedance 2.4kΩ) of the first dual-coil magnetic latching relay KM1. KM1 adopts a bistable structure. After the holding coil loses power, the internal permanent magnet makes the main contact (silver tin oxide material) open. ) switches from the closed state to the open state, disconnecting the three-phase line of the elevator main power supply (AC380V / 32A). The arc generated at the moment the main contacts are disconnected is suppressed by the RC absorption circuit (0.1μF+100Ω) connected in parallel at both ends of the contacts to ensure that the disconnection time is less than 15ms. The system monitors the main circuit current in real time through the Hall current sensor (ACS712-30A). When it detects that the current drops below 0.5A and lasts for 10ms, it determines that the power is successfully disconnected and displays the "Main circuit disconnected" status indication on the HMI interface.
[0065] Preferably, when the main control circuit fails, the circuit switching logic controller switches and triggers the second time delay relay K2 to delay closing, and the action coil of the second magnetic latching relay KM2 switches its main contacts after being energized to maintain the corresponding power-off state of the elevator.
[0066] In the embodiment of the present invention, when the circuit switching logic controller detects an abnormal current in the main circuit (continuously below 0.3A for more than 50ms) through the current comparator (LM393), the backup control circuit is immediately triggered, first cutting off the power supply to the K1 coil and simultaneously sending a start signal to the second time delay relay K2 (model H3Y-4, time range 0.1-3s). The delayed closing contact of K2 closes after a preset 200ms delay, which is accurately set by an internal adjustable resistor (500kΩ potentiometer). After the contact is closed, the second DC24V power supply is connected to the 1N4007 A diode supplies power to the operating coil (1.8kΩ impedance) of the second magnetic latching relay, KM2, driving its main contacts to switch states within 35ms. KM2's main contacts utilize a forced-open mechanism. When connected in parallel with KM1's main contacts, if KM1's contacts become stuck, KM2's mechanical push rod (stainless steel, 3mm travel) physically separates them. After the backup circuit is activated, the system continuously monitors the voltage across KM2's contacts. When the voltage difference is less than 5V, the system determines the switchover is successful and transmits a "backup circuit enabled" signal to the central monitoring system via the RS485 interface. Simultaneously, K2's other set of normally open contacts closes, illuminating a red fault indicator (LED, 630nm wavelength).
[0067] Furthermore, the first dual-coil magnetic latching relay KM1 includes an actuating coil and a holding coil, including:
[0068] The action coil is directly driven by the authorization verification signal corresponding to the verification module, which is used to quickly respond to the elevator lock command;
[0069] In this embodiment of the present invention, the authorization verification signal (DC24V±5%, 500mA) generated by the verification module is directly connected to the action coil of the first dual-coil magnetic latching relay KM1 (model: JZC-32F / 24V, DC resistance 60Ω±5%) through a 2.5mm² shielded cable. An SMBJ26CA bidirectional TVS diode (breakdown voltage 28.5V-31.4V, peak pulse power 600W) is installed in series in the drive circuit. The diode is welded between the positive input terminal and the ground terminal of the coil in the form of an axial lead, and the lead length does not exceed 5m. When the authorization signal is triggered, a TVS diode clamps the reverse electromotive force (measured peak value up to -45V) generated when the actuating coil is de-energized to below -30V, protecting the MOSFET switch (model: IRF540N, Vds = 100V) in the driver circuit. The actuating coil excitation time is controlled within 80ms ± 5ms. This time parameter is precisely adjusted using an RC network consisting of a timing capacitor (100μF / 50V electrolytic capacitor) and a current-limiting resistor (15Ω / 5W cement resistor) in the driver circuit. During relay operation, a LEM LA55-P current sensor monitors the coil current waveform in real time, ensuring that the operating current remains within the 350-450mA range for at least 50ms to meet the KM1's reliable engagement requirements. During the driver circuit PCB layout, the trace distance between the TVS diode and the actuating coil pins is strictly controlled to within 10mm, and 2oz thick copper foil is used to reduce line impedance.
[0070] Preferably, the holding coil is maintained in a de-energized state through the normally closed contact of K1, and the backup control circuit takes over control only when K1 fails.
[0071] In this embodiment of the present invention, the power supply circuit for the holding coil (model: JZC-32F / 24V, DC resistance 120Ω±5%) is formed through the normally closed contacts (rated parameters: 1A / 30VDC) of the first optocoupler isolation relay K1 (model: G3VM-61VR1). A 0.1μF / 100V CBB capacitor is connected in parallel across the normally closed contacts to suppress voltage spikes caused by contact bounce. Under normal operating conditions, when the K1 coil is not powered, its normally closed contacts remain closed. The negative pole of the holding coil is grounded through a 6A / 250V fuse (model: F6AL250V). At this time, the measured voltage across the holding coil is less than 0.5V. When a K1 fault (contact sticking) occurs, the normally open contacts of the second time delay relay K2 (model: H3Y-4) in the backup control circuit close after a 200ms delay, providing a DC24V holding voltage to the holding coil through a 2A resettable fuse (model: MF-R020). The holding coil's continuous operating current is limited to 200mA±10% by an LM317 adjustable voltage regulator. This current value ensures that KM1 maintains a stable released position when power is removed. An AZ23C5V1 Zener diode (Vz=5.1V±5%) installed in the loop protects the holding coil from overvoltage. When the voltage across the coil exceeds 5.5V, a comparator (LM2903) triggers a fault alarm signal. All cable connections use crimp terminals (JST XA-04P), with a contact resistance of less than 10mΩ and an insulation resistance greater than 100MΩ as tested by a 500V megohmmeter.
[0072] Furthermore, a transient voltage suppressor diode TVS is connected in series in the driving circuit of the action coil to eliminate the corresponding reverse electromotive force when the first dual-coil magnetic latching relay KM1 is switched.
[0073] Furthermore, a signal amplification circuit is provided between the input side of the first optocoupler isolation relay K1 and the verification module, for increasing the current drive corresponding to the authorization verification signal to the required threshold of 0.4A for the coil of K1 to ensure that the coil of K1 is reliably attracted.
[0074] Furthermore, an RC buffer circuit is connected in parallel to the output end of the signal amplifying circuit to absorb transient pulses generated when the coil of K1 is disconnected.
[0075] Furthermore, the delay time of the second time delay relay K2 is adjustable and can be set to three levels of 50ms, 100ms or 200ms through the dip switch, so that the delayed closing contact of K2 delays the action after the main control circuit fails, avoiding instantaneous competition conflict with the main control circuit.
[0076] Furthermore, the delayed closing contact of K2 is a double-contact structure, in which one pair of contacts is used to control the action coil of KM2, and the other pair of contacts is connected to the loop switching logic controller as a status feedback signal. The loop switching logic controller also includes a fault counter. When the number of faults in the main control loop exceeds 3 times, the backup control loop is forcibly locked and the corresponding human-machine interaction interface HMI is triggered to issue an audible and visual alarm.
[0077] Furthermore, the main contacts of KM2 and the main contacts of KM1 adopt a cross-interlocking layout. When the main contacts of KM1 cannot be disconnected due to adhesion, the mechanical structure corresponding to the main contacts of KM2 is controlled to forcibly push open the main contacts of KM1.
[0078] The present invention is therefore intended to be illustrative and non-restrictive in all respects, with the scope of the invention being defined by the appended claims rather than the foregoing description, and all changes that come within the meaning and range of equivalents of the application documents are intended to be embraced therein.
[0079] The foregoing description is intended only to provide specific embodiments of the present invention, which will enable those skilled in the art to understand and implement the present invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention is not intended to be limited to the embodiments shown herein, but is to be construed in the widest possible manner consistent with the principles and novel features disclosed herein.
Claims
1. An elevator lock circuit control system based on an induction key, characterized in that: include: The elevator lock body has a built-in mechanical lock core, an actuator, a power supply circuit, a verification module, and a storage module. The actuator is a micro servo motor, and its drive gear is engaged with the rack of the mechanical lock core. The control signal corresponding to the drive gear is triggered after authorization by the verification module, and the operating status of the drive gear is recorded by the storage module. The storage module records the identity information of the operation and maintenance personnel, the unlocking time, the operating status, and the corresponding loop operation log, and transmits them to the cloud server through an encryption protocol; An induction key, on which a corresponding key chip and a fingerprint recognition module are integrated, is inserted into the mechanical lock cylinder corresponding to the elevator lock body, is activated by the power supply circuit, and transmits the fingerprint information collected by the fingerprint recognition module to the verification module to execute the corresponding multi-level verification workflow; The main control circuit includes a first DC24V safety power supply, a first optical coupling isolation relay K1, and a first dual-coil magnetic latching relay KM1, wherein the coil of K1 is controlled by the authorization verification signal of the verification module, the normally closed contact of K1 is connected in series in the holding coil circuit of KM1, and the main contact of KM1 controls the on and off of the main power supply of the elevator; The backup control circuit includes a second DC24V safety power supply, a second time delay relay K2, and a second magnetic latching relay KM2. The delayed closing contact of K2 is connected in series with the operating coil of KM2, and the main contact of KM2 is connected in parallel with the main contact of KM1 to form redundant control. The delay time of the second time delay relay K2 is adjustable and can be set to three levels of 50ms, 100ms, or 200ms by a dip switch, so that the delayed closing contact of K2 delays the action after a main control circuit fails, thereby avoiding instantaneous competition and conflict with the main control circuit. The delayed closing contact of K2 is a double-contact structure, in which one pair of contacts is used to control the operating coil of KM2, and the other pair of contacts is connected to the loop switching logic controller as a status feedback signal. The loop switching logic controller also includes a fault counter. When the number of faults in the main control circuit exceeds three, the backup control circuit is forcibly locked and the corresponding human-machine interface HMI is triggered to emit an audible and visual alarm. The main control circuit and the backup control circuit adopt a master-slave parallel architecture to form a dual redundant elevator lock control circuit; The loop switching logic controller monitors the current status of the main control loop in real time. When a K1 fault corresponding to the main control loop is detected, the backup control loop is automatically activated and a maintenance alarm is issued through the corresponding human-machine interface HMI.
2. The elevator lock loop control system based on induction key according to claim 1, wherein the verification module includes a fingerprint feature comparison unit, a physical key decoding unit and a real-time clock verification unit, characterized in that: The multi-level verification workflow includes: The first stage verification is to obtain the digital signature corresponding to the key chip in the induction key through the physical key decoding unit, and verify the digital signature corresponding to the key chip through the RSA-2048 algorithm to confirm the validity of the physical key corresponding to the digital signature; In the second stage of verification, the fingerprint feature comparison unit uses a deep learning algorithm to compare the feature points corresponding to the fingerprint information collected by the fingerprint recognition module with the corresponding built-in fingerprint feature points, and sets the matching threshold to 0.98 similarity; The third stage verification is to check whether the unlocking operation time corresponding to the induction key is within the preset maintenance time window through the real-time clock verification unit. The preset maintenance time window is set to reject if the deviation exceeds ±15 minutes; Dynamic password verification: a one-time 6-digit verification code is generated for each stage of verification operation, which needs to be confirmed through the operation and maintenance personnel's mobile phone APP; All the above verification steps must be completed in sequence within 8 seconds. If the timeout is exceeded, the system will be locked for 5 minutes. If it does not time out, the corresponding authorization verification signal will be generated in response.
3. The elevator lock circuit control system based on induction key according to claim 2 is characterized in that: The execution logic corresponding to the elevator lock circuit control system based on the induction key is specifically as follows: When the corresponding authorization verification signal is verified, the coil corresponding to the first optocoupler isolation relay K1 is energized, the normally closed contact corresponding to K1 is disconnected, the holding coil corresponding to the first double-coil magnetic latching relay KM1 is de-energized, and the main contact of KM1 is switched to the open state to cut off the main power supply of the elevator; When the main control circuit fails, the circuit switching logic controller switches and triggers the second time delay relay K2 to delay closing. After the action coil of the second magnetic latching relay KM2 is energized, its main contacts are switched to maintain the corresponding power-off state of the elevator.
4. The elevator lock circuit control system based on induction key according to claim 1 is characterized in that: The first dual-coil magnetic latching relay KM1 includes an actuating coil and a holding coil, including: The action coil is directly driven by the authorization verification signal corresponding to the verification module, which is used to quickly respond to the elevator lock command; The holding coil is kept in the de-energized state through the normally closed contact of K1, and the backup control circuit takes over control only when K1 fails.
5. The elevator lock circuit control system based on induction key according to claim 4 is characterized in that: A transient voltage suppression diode TVS is connected in series in the driving circuit of the action coil to eliminate the corresponding reverse electromotive force when the first double-coil magnetic latching relay KM1 is switched.
6. The elevator lock circuit control system based on induction key according to claim 1 is characterized in that: A signal amplification circuit is provided between the input side of the first optocoupler isolation relay K1 and the verification module, for increasing the current drive corresponding to the authorization verification signal to the required threshold of 0.4A for the coil of K1 to ensure that the coil of K1 is reliably attracted.
7. The elevator lock circuit control system based on induction key according to claim 6 is characterized in that: An RC buffer circuit is connected in parallel to the output end of the signal amplifying circuit to absorb transient pulses generated when the coil of K1 is disconnected.
8. The elevator lock circuit control system based on induction key according to claim 1 is characterized in that: The main contacts of KM2 and KM1 are arranged in a cross-interlocking manner. When the main contacts of KM1 cannot be disconnected due to adhesion, the mechanical structure corresponding to the main contacts of KM2 is controlled to forcibly push open the main contacts of KM1.
Citation Information
Patent Citations
Elevator door lock safety system
CN108190703A
Elevator key use and management method and system
CN119723712A