Software update mechanism for time critical applications
By performing hardware self-testing and updating coordination in the control device, the software update downtime problem of time-critical applications is solved, and a safe and fast update process is realized, reducing equipment downtime and security risks.
Patent Information
- Application Number
- CN202380090803.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-01-16
- Publication Date
- 2025-08-05
AI Technical Summary
In the prior art, software updates for time-critical applications require stopping transportation or accessing the operation of related equipment, or there is a risk of security damage, resulting in increased equipment downtime and the possibility of human error.
By performing a hardware self-testing process in the control device, storing the results and checking whether the predetermined standards are met, software updates are performed only when the standards are met, avoiding repeated hardware self-testing, using the update coordination device for compatibility and trustworthiness checks, and selecting appropriate timings for updates.
It realizes software updates without interrupting the operation of the equipment, reduces equipment downtime, improves the security and reliability of the update, and ensures the safe status of the equipment during the update process.
Smart Images

Figure CN120435708A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to apparatus, methods, systems and computer program products that can be used to control software updates of time-critical applications or programs running, for example, in transportation or access related equipment such as elevators, escalators, moving walks, conveyors and automatic doors. Background Art
[0002] The following description of the background technology may include relevant insights, discoveries, understandings or disclosures, or relevant relationships, as well as disclosures that are not previously known but are provided herein as examples of one or more embodiments. Some of the examples may be specifically pointed out below, while other such contributions will be apparent from the relevant context.
[0003] The abbreviations used in this manual have the following meanings:
[0004] CPU: Central Processing Unit
[0005] I / O: Input / Output
[0006] IEC: International Electrotechnical Commission
[0007] SIL: Safety Integrity Level
[0008] SHA: Secure Hash Algorithm
[0009] Transportation or access-related equipment, such as elevators, escalators, moving walkways, conveyors, and automatic doors, includes multiple components, each equipped with a processor and memory. In the case of elevators, the processor runs, for example, elevator component-specific application software, such as control software for door operation, floor selection, drive and brake operation, safety-related operations, and so on. During the life of an elevator, new features and / or corrections to existing features are introduced in the form of new software versions. Furthermore, safety regulations, for example, may change during the life of a component. For these reasons, it may be necessary to update the application software of one or more components in order to take advantage of new features or corrections.
[0010] According to existing technology, the application software update process is traditionally performed manually on-site, for example, by an elevator service technician at the elevator site. Here, the service technician enters the elevator site, removes the elevator from normal operation, connects a programming tool such as a laptop to the elevator controller, and updates the software. The service technician then resumes normal elevator operation and verifies correct operation. However, this update procedure is labor-intensive, increases elevator downtime, and carries the risk of human error.
[0011] EP 3 915 912 A1 discloses a remote software update process for transport-related systems, such as elevators or escalators. This system includes multiple conveyor components and an update device that is communicatively connected to a remote update system. The update device can download software updates from the remote system and, during the download process, schedule the software updates for the conveyor components so that system downtime causes minimal disruption to users of the conveyor system. For example, the downtime required for the software update may occur during low-traffic periods, such as at night.
[0012] Transportation- or access-related equipment, such as elevators, also runs time-critical software or applications, which may also undergo updates. For example, modern elevator systems include advanced safety systems that include one or more electronic safety controllers. These controllers are, for example, programmable safety devices designed to meet specific safety requirements, such as those specified in the IEC 61508 safety standard for functional safety.
[0013] The safety controller runs safety software, an example of time-critical, real-time monitoring software. Using this software, the safety controller monitors various functions and operations of the elevator system to ensure safe elevator operation. For example, the safety controller receives information from various monitoring or sensor devices (such as controllers, cameras, door contacts, and / or limit switches) and determines the elevator's operating status based on this information. If the safety controller detects a safety-related issue, it generates a command to ensure a safe state for the elevator. A safe state for the elevator can be achieved through a safety shutdown, which interrupts the power supply to the elevator hoist and applies a safety brake to prevent movement of the elevator car.
[0014] However, in the event that a software update is required for a time-critical application (such as the monitoring software mentioned above), either the operation of the corresponding transport or access-related equipment must be stopped, or it must be accepted that the security of the transport or access-related equipment may be compromised due to the software update and related operations. Summary of the Invention
[0015] According to an example of an embodiment, a control device is provided, for example, comprising: a device configured to perform a hardware self-test process when receiving an instruction for performing a hardware self-test process; a device configured to store a result of the hardware self-test process in a memory; a device configured to check whether the result of the hardware self-test process meets a predetermined standard; and a device configured to perform a software update of a program running in the control device (110) to install and start a new program version, wherein, when switching to the new program version, if the check of the stored result of the hardware self-test process shows that the result meets the predetermined standard, the new program version is installed and started without performing a further hardware self-test process, or the new program version is installed and started before completing the further hardware self-test process.
[0016] Furthermore, according to an example of an embodiment, a method is provided, for example, comprising: performing a hardware self-test process when an instruction for performing a hardware self-test process is received; storing the result of the hardware self-test process in a memory; checking whether the result of the hardware self-test process meets a predetermined standard; and performing a software update of a program running in the control device (110) to install and start a new program version, wherein, when switching to the new program version, if the check of the stored result of the hardware self-test process indicates that the result meets the predetermined standard, the new program version is installed and started without performing a further hardware self-test process, or the new program version is installed and started before completing the further hardware self-test process.
[0017] According to further refinements, these examples may include one or more of the following features:
[0018] - the predetermined criteria may include at least one of: determining that the result of the hardware self-test process is present in the memory, determining that the result of the hardware self-test process is not corrupted based on an integrity check, or determining that a time interval to a most recent hardware self-test process is within a predetermined range;
[0019] - in case the examination of the stored results of the hardware self-test process indicates that the results do not meet the predetermined criteria, another hardware self-test process can be performed when installing and starting the new program version;
[0020] - the control device may be included in one of an electrical safety controller, a drive controller, or a monitoring device of a transportation or access related device, the transportation or access related device including one of an elevator, an escalator, a moving walkway, a conveyor, and an automatic door, wherein the control device may run a time-critical application as a program to be updated;
[0021] -The memory may be a volatile memory.
[0022] According to an example of an embodiment, there is provided, for example, an update coordination device comprising: a device configured to receive a new program version of a program to be updated in a control device; a device configured to instruct the control device to perform a hardware self-test process when the new program version is received; and a device configured to initiate a software update to a new program version at the control device of the program to be updated by switching the control device to the new program version.
[0023] In addition, according to an example of an embodiment, there is provided, for example, an update coordination method, comprising: receiving a new program version of a program to be updated in a control device; when the new program version is received, instructing the control device to perform a hardware self-test process; and initiating a software update to the new program version at the control device of the program to be updated by switching the control device to the new program version.
[0024] According to further refinements, these examples may include one or more of the following features:
[0025] - the compatibility of a new program version of the program with the control device can be checked, wherein the software update can be started only if the compatibility check is successful;
[0026] - it can be checked whether a new program version of a program is indicated as being received from a trusted source and is signed, wherein the software update can only be started if a corresponding indication is detected;
[0027] - a software update of a program to be updated can be started at the control device at a predetermined timing determined based on the operating state of the control device;
[0028] - the predetermined timing can be determined based on at least one of: a diagnostic time interval of the control device; or an idle time slot of a time-critical application running on the control device, the idle time slot being related to an input filtering time, an idle time of a time-triggered communication protocol, a mutual authentication delay, a message loss delay, and a message loss period;
[0029] - The update coordination device may be a part of the control device, connected to the control device as a separate entity, or a software module running on the control device.
[0030] According to an example of an embodiment, there is provided, for example, a control device comprising: a control device; an update coordination device; and a memory; wherein, when the update coordination device receives a new program version of a program to be updated in the control device, the update coordination device is configured to instruct the control device to perform a hardware self-test process, and the control device is configured to perform the hardware self-test process and store the result of the hardware self-test process in the memory; the control device is configured to: when the update coordination device initiates a software update of the program to be updated to a new program version, check whether the result of the hardware self-test process meets a predetermined standard, wherein, when switching to a new program version, if the check of the stored result of the hardware self-test process indicates that the result meets the predetermined standard, the new program version is installed and started on the control device, without performing another hardware self-test process, or the installation and startup are performed before completing the other hardware self-test process.
[0031] In addition, according to an example of an embodiment, a control method is provided, for example, which includes: when a new program version of a program to be updated in a control device is received, instructing the control device to perform a hardware self-test process, performing the hardware self-test process and storing the result of the hardware self-test process in a memory, and when initiating a software update to update the program to be updated to the new program version, checking whether the result of the hardware self-test process meets a predetermined standard, wherein, when switching to a new program version, if the check of the stored result of the hardware self-test process indicates that the result meets the predetermined standard, the new program version is installed and started on the control device, and there is no need to perform another hardware self-test process, or the installation and startup are performed before completing the other hardware self-test process.
[0032] According to further refinements, these examples may include one or more of the following features:
[0033] - the predetermined criteria may include at least one of: determining that the result of the hardware self-test process is present in the memory, and determining that the result of the hardware self-test process is not corrupted based on an integrity check, or determining that a time interval to a most recent hardware self-test process is within a predetermined range;
[0034] - in case the examination of the stored results of the hardware self-test process indicates that the results do not meet the predetermined criteria, another hardware self-test process can be performed when installing and starting the new program version;
[0035] - the update coordination device may be configured to check the compatibility of the new program version of the program with the control device, wherein the software update is only initiated if the compatibility check is successful;
[0036] - the update coordination means may be configured to check whether a new program version of the program is indicated as being received from a trusted source and signed, wherein the software update may be initiated only if a corresponding indication is detected;
[0037] - a software update of a program to be updated can be started at the control device at a predetermined timing determined based on the operating state of the control device;
[0038] - the predetermined timing can be determined based on at least one of: a diagnostic time interval of the control device; or an idle time slot of a time-critical application running on the control device in relation to input filtering time, idle time of a time-triggered communication protocol, reciprocity verification delay, message loss delay and message loss period;
[0039] - the update coordination device may be part of the control device, connected to the control device as a separate entity, or a software module running on the control device;
[0040] - the control device may be included in one of an electrical safety controller, a drive controller, or a monitoring device, wherein the control device may be configured to control transportation or access related equipment including one of an elevator, an escalator, a moving walkway, a conveyor, and an automatic door, wherein the program to be updated is a time-critical application;
[0041] -The memory may be a volatile memory.
[0042] Furthermore, according to an example of an embodiment, there is provided, for example, a computer program comprising instructions which, when executed by a device, cause the device to perform at least any of the methods defined above.
[0043] Furthermore, according to an example of an embodiment, there is provided, for example, a method computer-readable medium comprising instructions which, when executed by a device, cause the device to perform at least any of the methods defined above.
[0044] Furthermore, according to an example of an embodiment, there is provided a computer program product, for example for a computer, comprising software code portions for performing any of the methods defined above when said product runs on a computer.
[0045] According to a further improvement, the computer program product may comprise a computer-readable medium on which the software code portions are stored, and / or the computer program product may be directly loaded into an internal memory of a computer, or may be transmitted via a network by means of at least one of an upload, download and push process. BRIEF DESCRIPTION OF THE DRAWINGS
[0046] Some embodiments of the present invention are described below by way of example only with reference to the accompanying drawings, in which:
[0047] Figure 1 shows a schematic diagram illustrating the configuration of transportation or access related equipment (such as an elevator) according to some examples of the embodiments;
[0048] Figure 2 A flowchart illustrating processing performed in a control device during a software update process according to some examples of the embodiments;
[0049] Figure 3 A flowchart illustrating processing performed in a controller (such as a security controller) during a software update process according to some examples of the embodiments;
[0050] Figure 4 a flowchart illustrating processing performed in an update coordinator during a software update process according to some examples of the embodiments; and
[0051] Figure 5 Diagram showing configurations of control devices according to some examples of the embodiments. DETAILED DESCRIPTION
[0052] In the following, we will use Figure 1 The configuration of an elevator system including a safety controller is depicted and explained as an example of a control device for a transportation or access-related system to which the embodiments are applicable, to describe various exemplary embodiments. However, it will be apparent to those skilled in the art that the principles of the embodiments can also be applied to other types of transportation or access-related systems having different types of configurations. In other words, the examples of the embodiments of the present invention are applicable to various types of control devices and transportation or access-related systems, such as drive controllers or other controllers, escalator systems, moving walkway systems, conveyor systems, automatic doors, etc., in which the program to be updated is currently running.
[0053] It should be noted that the following examples and embodiments are to be understood as illustrative examples only. Although the specification may refer to "one," "an," or "some" examples or embodiments in several places, this does not necessarily mean that each such reference relates to the same example or embodiment, or that the feature applies only to a single example or embodiment. Individual features of different embodiments may also be combined to provide other embodiments. Furthermore, terms such as "include" and "comprising" should be understood as not limiting the described embodiments to consisting only of those features that have been mentioned; such examples and embodiments may also include features, structures, units, modules, etc. that have not been specifically mentioned.
[0054] The general elements and functions of the controllers and components of the described transport or access-related systems (the details of which also depend on the actual type of device or function management system) are known to those skilled in the art, and therefore a detailed description thereof is omitted herein. However, it should be noted that, in addition to those described in further detail below, several additional devices and functions may be employed in a system to which the principles of the described embodiments are applied.
[0055] In addition, the control device or update coordination device, the elements or parts of the control equipment and the corresponding functions described herein, as well as other elements, functions or applications, can be implemented using software, such as a computer program product for a computer and / or hardware. To perform their respective functions, the corresponding devices, elements or functions may include several devices, modules, units, components, etc. (not shown) required for control, processing and / or communication / signaling functions. Such devices, modules, units and components may include, for example, one or more processors or processor circuits including one or more processing sections for executing instructions and / or programs and / or for processing data, storage or memory units or devices (such as ROM, RAM, EEPROM, etc.) for storing instructions, programs and / or data and serving as working areas for the processors or processing circuits, etc., input or interface devices (such as floppy disks, CD-ROMs, EEPROMs, etc.) for inputting data and instructions via software, user interfaces (such as screens, keyboards, etc.) for providing users with monitoring and control capabilities, and other interfaces or devices (such as wired and wireless interface devices, etc.) for establishing links and / or connections under the control of the processor unit or section. It should be noted that in this specification, a processing portion should not be considered to mean only a physical portion of one or more processors, but may also be considered a logical division of the mentioned processing tasks performed by one or more processors.
[0056] As used in this application, the term "processor" or "circuitry" may refer to a purely hardware circuit implementation (e.g., an implementation solely in analog and / or digital circuitry) and / or a combination of hardware circuitry and software, such as (as applicable) a combination of analog and / or digital hardware circuitry and software / firmware and / or any portion of a hardware processor with software (including a digital signal processor), software, and memory, which work together to enable a device, such as a controller, to perform various functions, as well as hardware circuitry and / or processors as another example. As used herein, the term processor or circuitry also covers an implementation of merely a hardware circuitry or processor (or multiple processors) or a portion of a hardware circuitry or processor and its (or their) accompanying software and / or firmware.
[0057] As used herein, “at least one of” and “at least one of” and similar expressions (wherein a list of two or more elements is linked by “and” or “or”) mean at least any one of the elements, or at least any two or more of the elements, or at least all of the elements.
[0058] Figure 1 Shown are schematic diagrams illustrating the configuration of a transportation or access related system, such as an elevator, according to some examples of the embodiments.
[0059] Specifically, Figure 1 An example is schematically shown, in which in an elevator system a safety controller runs a program as a time-critical application, which program is the target of an update process.
[0060] The elevator system includes an elevator shaft 101 in which elevator cars 102 move to serve different floors. Figure 1 In FIG, the elevator car 102 can stop at the first floor 103, the second floor 104, the third floor 105, and the fourth floor 106. The floors can be any floors in the building, and are not necessarily the first and second floors of the building. The first floor 103 can be, for example, a garage, and the second floor 104 can be ground level. A landing door can be arranged in front of the elevator car 102 in each floor. Figure 1 In FIG, the elevator comprises a drive unit such as a motor 108, which is configured to move the elevator car via hoisting ropes, wherein the motor 108 is controlled by an elevator control 120. However, this arrangement is only an example.
[0061] An update coordinator 111 for updating elevator component software may be arranged in connection with the control device and / or integrated with the control apparatus 110 into the control device 120. The update coordinator 111 is communicatively connected to the elevator components, wherein the update coordinator 111 comprises or is connected to a processor and a memory.
[0062] For example, the update coordinator 111 may be a separate processing unit, or it may be a functionality added to some existing elevator control units and / or elevator controllers.In one exemplary embodiment, an elevator system includes elevator components, each of which includes a memory and a processor that runs component-specific application software. The control device 110 can be an elevator control unit (e.g., a unit that receives landing calls and calculates a motion profile for elevator car service), a drive unit (e.g., a unit that provides a power signal to a hoisting motor to move the elevator car according to a motion profile), a safety controller (e.g., a unit programmable safety device that meets EN 61508 safety integrity level (SIL 3)), a brake controller (e.g., a unit that provides current / interrupts the current supply to the electromagnet of the hoisting machinery brake to release / engage the brake), a call giving unit (e.g., a unit for inputting a manual service request from a passenger), a car control panel, a destination operating panel, a door operator (e.g., a unit for opening / closing elevator doors), an elevator car position detection unit, a check drive unit (e.g., a unit for manually checking the drive), a group control unit (e.g., a unit for allocating service requests to different elevators), an overspeed regulator unit (e.g., a unit for monitoring overspeed conditions in the elevator car), sensors for measuring elevator operating parameters (e.g., safety contacts, temperature sensors, cameras), a voice intercom device, etc.
[0063] In the following example, it is assumed that the control device 110 includes a safety controller according to SIL 3 runtime critical software to be updated.
[0064] The elevator system includes, for example, a plurality of monitoring devices or sensors ( Figure 1 The electronic safety controller 110 (not shown) is configured to collect safety-related information of the elevator system. The electronic safety controller 110, which runs safety software, is configured to receive the safety-related information, determine the operating status of the elevator system based on the received information, and generate a command to ensure a safe state of the conveyor system if a safety-related issue is detected (e.g., an emergency stop of the cabin 102).
[0065] It should be noted that the elevator components (eg the control device 110 ) may be communicatively connected to the update coordinator 111 , eg via a serial data bus (eg a CAN bus, a LAN bus or Ethernet).
[0066] Basically, to update the software of components of a transportation or access system (such as an elevator system), a remote update system 112 is used to transmit and / or create updated software and / or updated software components. The update coordinator 111 can be configured to download the updated software from the remote update system 112 using a transmission protocol (e.g., TCP / IP) accepted between the update device and the remote update system.
[0067] Remote update system 112 comprises, for example, a remote computing device, such as a server or cloud service. At least one communication channel is arranged between the transport- or access-related system (particularly its update coordinator 111) and remote update system 112. For example, when a new software version becomes available, update coordinator 111 downloads the software update from remote update system 112 via the at least one communication channel, based on a request from the remote update system and / or based on a request from the transport- or access-related system. For example, remote update system 112 may notify update coordinator 111 of a new software update. For example, update coordinator 111 may request information about software updates from remote update system 112 and request or select a specific update.
[0068] Transport- or access-related system software (such as update coordinator 111) can perform the download of new software versions as a background download and / or without disrupting the operation of the transport- or access-related system. Thus, interruptions in data communications or slow transmission speeds do not result in interruptions in the operation of components of the transport- or access-related system. When the transport- or access-related system begins receiving data, it stores it in memory and continues transmitting data as long as the transmission of the update data is complete. If the transmission is interrupted, the transmission can be resumed when the required system is operational and / or, for example, when operation of the communication channel can be restored. Once the entire software has been transferred, the update, i.e., the installation of the software update, can begin at the desired time. In some cases, the installation time or moment can be selected to minimize disruption to the user's operation, such as at a certain time, such as at night.
[0069] For example, the remote update system 112 is configured to send the update software data on segments or blocks in the form of a linked list. Each segment or block has an identifier. The update coordinator 111 is configured to reassemble the downloaded update software from the segments or blocks based on the corresponding identifiers.
[0070] The update coordinator 111 is configured to schedule software updates for elevator components while verifying the integrity of the downloaded update software, ensuring that all segments / blocks have been downloaded. This can mean that in the event of a communication interruption or loss of some segments or blocks, the update device can resume the software download without having to reload the entire software. This can also be used to verify that the software has been successfully transferred and stored to the memory, e.g., without any errors.
[0071] In addition, the update coordinator 111 can request the remote update system 112 to resend one or more identified data segments or blocks if the integrity verification fails. This can mean that when communication is interrupted or some segments or blocks are lost, the update coordinator 111 can resume the software download without reloading the entire software.
[0072] The connection between the update coordinator 111 and the remote update system 112 may be any suitable physical medium, including, for example, a data cable and / or a wireless network, such as a cellular network.
[0073] The software to be updated (e.g. the application software of the control device 110 ) comprises, for example, an installation key (e.g. an encryption key) which is associated with a specific counterpart of an elevator component (e.g. the control device 110 ), so that the application software can only be successfully installed in the elevator component associated with the corresponding installation key (i.e. the control device 110 (safety controller)).
[0074] However, software updates of time-critical applications, such as the safety application running at the safety controller 110, are more difficult because it is necessary to stop the operation of the entire system (elevator system) or accept that the safety of the elevator may be compromised, for example due to restarting the control device after the software update.
[0075] Thus, according to an example embodiment of the present invention, a solution is provided for software updates of components in which, for example, time-critical programs are running, such as monitoring applications running on a programmable electronic safety controller. Specifically, according to this example embodiment, the update is performed during operation without requiring the elevator system to be removed from service. The proposed measures can eliminate or at least significantly reduce downtime for updated components, such as elevator safety systems.
[0076] Specifically, according to an example embodiment, a power-on software update process is performed that relies on the previous (most recent) hardware self-test results of the component to be updated (i.e., the safety controller 110). The referenced hardware self-test results are verified by a suitable integrity check, for example, by using a hash function such as SHA 256.
[0077] For example, according to an example embodiment, update coordinator 111 may receive a software update from an update provider (remote update system 112) via a remote communication link. The component to be updated (here, safety controller 110) then performs a hardware self-test. This may be triggered, for example, by a corresponding command or instruction from update coordinator 111 receiving the software update. The results of the hardware self-test are recorded in the safety controller's memory. It should be noted that the instruction for triggering the hardware self-test may be received from either an internal source (i.e., an automated self-test) or an external source.
[0078] The hardware self-test performed by the safety controller 110 includes, for example, a plurality of tests, such as checking the functionality of the controller's CPU, peripheral devices of the CPU, checking the functionality of memory elements (such as read-only memory (ROM) and random access memory (RAM)) (e.g., by using a checksum), checking peripheral elements (such as storage devices), etc. The hardware self-test requires a certain amount of time, depending on the number of components to be checked and the steps to be performed.
[0079] Furthermore, according to an example embodiment, new software versions received by the update coordinator must be trusted, signed software. For example, secure boot mechanisms are applied to ensure absolute integrity (corruption) and non-repudiation (digital signatures). For example, according to an example embodiment, signed software contains trusted information about the specified hardware, enabling the software to identify the hardware. Furthermore, currently running software can discard incompatible new software packages sent to it.
[0080] According to an example embodiment, the update coordinator 111 performs compatibility testing to ensure that the new software version is compatible and can run on the specified components. When the update coordinator 111 is, for example, a software module located in the memory of the security controller 110, the compatibility test is performed in parallel with the operation using the previous version of the program, i.e., without affecting the current operation.
[0081] After the above measures, at least after the hardware self-test, the update coordinator 111 performs a software switch to the new software version. In this regard, it checks whether the stored hardware self-test results meet predefined criteria. If so, a rapid software restart is performed during the restart process of the new software version by skipping the hardware self-test—that is, without performing (another) hardware self-test or before completing (another) hardware self-test. This means that the safety controller operates with the new software version without interrupting its power supply. In other words, even if a new hardware self-test (has already) started in the background, it does not have to wait for its completion before starting the new software version. This speeds up the startup of the new software version. This also applies when starting the new software version without performing (i.e., starting) another hardware self-test.
[0082] That is, according to an example of an embodiment, the switching time to a new software version is reduced by referring to the most recent hardware self-test results, wherein a suitable integrity checking method is employed.
[0083] Furthermore, according to an example embodiment, the hardware self-test results are stored in memory. When power is not interrupted during the switchover, the hardware self-test results are present in memory. Therefore, the new software assumes the hardware is fully operational without having to wait for the first self-test to complete. This allows normal operation to resume immediately after switching to the new software.
[0084] According to an example of an embodiment, the memory is a volatile memory. In this case, when a power outage occurs, the volatile memory content will be lost or at least corrupted. This will trigger a complete hardware self-test.
[0085] According to a further example of an embodiment, the memory is a non-volatile memory, such as an EEPROM. In this case, a device (such as a timer) for calculating the time since the most recent hardware self-test is provided. In other words, the time since the most recent self-test process is also measured or counted during a power outage. In other words, it is necessary to ensure that there is no power cycle or to keep tracking the time during a power outage, i.e., to keep tracking the time interval. For example, it is necessary to determine that the time interval measured from the most recent hardware self-test process is within a predetermined range. If the time interval since the most recent self-test process exceeds a predetermined limit, a new hardware self-test will be performed. The device for calculating the time since the most recent hardware self-test can be, for example, an independent timer with a backup battery.
[0086] According to an example of embodiment, the criteria to be met include that the hardware self-test result is present in the memory and that it is not corrupted, which can be determined by using an integrity mechanism based on, for example, a hash function.Alternatively or additionally, information about the time interval since the most recent hardware self-test is checked.
[0087] As described above, by means of the above measures, normal operation can be performed immediately after the software switch without interrupting the power supply to the safety controller. Due to the fast update process, according to an example of an embodiment, the software update in operation can be scheduled for a specified time. For example, the idle time slots of the real-time safety controller software can be used. This is based on the properties of the time-critical software, such as the configuration of the safety application. Safety decisions are usually made based on cyclic operations, which include specific time delays and error recovery techniques. For example, there are electrical / mechanical filtering times required for specific input sources. In addition, for time-triggered network solutions, the pace of the network cycle is taken into account. In addition, for redundant networks, there is a reciprocal verification delay. In addition, there is the possibility of message loss caused by transmission errors (in the example of SIL, the corresponding SIL node is lost for that cycle).
[0088] According to an example embodiment, these intervals are used for software updates. Specifically, the timing for software updates is selected by utilizing, for example, input filtering time, idle time for time-triggered communication protocols, mutual authentication delay, and message loss delay / loss period. It should be noted that these time intervals can also be used for SIL devices, such as safety controllers.
[0089] Due to the short amount of time required to complete the update, as described above, examples of the embodiments enable hardware diagnostic time interval limits to not be exceeded due to the fast restart capability.
[0090] The examples of embodiments are not limited to SIL-rated safety devices. Instead, as already mentioned, other time-critical applications can also be targeted, for example in door operators or elevator drive units, where system downtimes can be minimized accordingly.
[0091] As described above, by means of the present invention, an uninterrupted or at least more continuous safety monitoring cycle can be achieved, so that elevator downtime is reduced and / or more safety-related problems can be noticed.
[0092] Figure 2 1 shows a flow chart of the processing performed in the control device of the transportation or access related system according to some examples of the embodiment. Figure 2 The example involves Figure 1 The process performed by the control device 120 is shown.
[0093] Specifically, it is assumed that control device 120 includes a control device 110 (such as an electronic safety controller or a drive controller), an update coordination device 111, and a memory. For example, control device 120 controls transportation- or access-related equipment such as an elevator, escalator, moving walkway, conveyor, or automatic door. Furthermore, according to an example embodiment, the program to be updated is a time-critical application.
[0094] The update coordination device 111 may be a part of the control device 110 , or it may be connected to the control device 110 as a separate entity, or it may be a software module running on the control device 110 .
[0095] In S200, the update coordination device 111 receives a new program version of a program to be updated in the control device 110. The update coordination device 111 instructs the control device 110 to perform a hardware self-test process.
[0096] According to an example of an embodiment, the update coordination device 111 checks the compatibility of the new program version of the program with the control device 110. The software update is initiated only if the compatibility check is successful.
[0097] Furthermore, according to an example of an embodiment, the update coordination device 111 checks whether the new program version of the program is indicated as being received from a trusted source and signed. The software update is initiated only when a corresponding indication is detected.
[0098] In S210 , the control device 110 performs the instructed hardware self-test process and stores the result of the hardware self-test process in a memory.
[0099] In S220 , when the update coordination device 111 initiates a software update of a program to be updated to a new program version, it checks whether the result of the hardware self-test process meets a predetermined standard.
[0100] For example, according to an example of an embodiment, the predetermined criterion includes at least one of determining that the result of the hardware self-test process is present in the memory and determining that the result of the hardware self-test process is not corrupted (which may be based on an integrity check (eg, a hash function)).
[0101] According to an example of an embodiment, a software update of a program to be updated is initiated at the control device 110 at a predetermined timing determined based on the operating state of the control device 110. For example, the predetermined timing is determined based on at least one of: a diagnostic time interval of the control device 110, or an idle time slot of a time-critical application running on the control device 110, which is related to an input filtering time, an idle time of a time-triggered communication protocol, a mutual authentication delay, a message loss delay, and a message loss period.
[0102] In S230 , it is determined whether the result of the hardware self-test meets a predetermined standard.
[0103] If the determination in S230 is affirmative (yes), then in S240, when switching to the new program version, the new program version is installed and started at control device 110 without performing another hardware self-test process or before completing another hardware self-test process. In other words, according to this example embodiment, even if a new hardware self-test is started in the background, it is not necessary to wait for completion before starting the new software version. Therefore, the startup of the new software version can be accelerated. This also applies when starting the new software version without performing (i.e., starting) another hardware self-test.
[0104] Otherwise, in a case where the decision in S230 is negative (No), the control device 110 performs another hardware self-test process when the new program version is installed and started.
[0105] Figure 3 1 shows a flow chart of the processing performed in a control device for a transport or access related system according to some examples of the embodiment. Figure 3 The example involves Figure 1 The process performed by the control device 110 is shown.
[0106] Specifically, assume that control device 110 is included in, for example, an electronic safety controller, a drive controller, or a monitoring device. For example, control device 110 is used to control transportation or access-related equipment such as an elevator, an escalator, a moving walkway, a conveyor, or an automatic door. Furthermore, according to an example embodiment, the program to be updated is a time-critical application.
[0107] In S300 , when an instruction (provided internally or externally) for performing a hardware self-test process is received, the hardware self-test process is performed.
[0108] In S310 , the result of the hardware self-test process is stored in a memory, such as a volatile memory or another suitable memory.
[0109] In S320 , a software update of the program running in the control device 110 is performed to install and start a new program version.
[0110] In this regard, in S330 , it is checked whether the result of the hardware self-test process stored in the memory satisfies a predetermined standard.
[0111] For example, according to an example of an embodiment, the predetermined criterion includes at least one of determining that the result of the hardware self-test process is present in the memory and determining that the result of the hardware self-test process is not corrupted (which may be based on an integrity check (eg, a hash function)).
[0112] That is, according to an example of an embodiment, when the inspection indication result of the stored result of the hardware self-test process meets the predetermined standard, when switching to a new program version, the new program version is installed and started without performing another hardware self-test process, or before completing another hardware self-test process, that is, skipping another hardware self-test.
[0113] On the other hand, according to an example of an embodiment, in case the check of the stored result of the hardware self-test process indicates that the result does not meet the predetermined standard, another hardware self-test process is performed when a new program version is installed and started.
[0114] Figure 4 1 shows a flow chart of the processing performed in the update coordinator for transport or access related systems according to some examples of the embodiment. Figure 4 The example involves Figure 1 The process performed by the update coordinator 111 is shown.
[0115] Specifically, it is assumed that update coordinator 111 is included in, for example, control device 120, which controls transportation or access-related equipment including one of an elevator, escalator, moving walkway, conveyor, and automatic door. Furthermore, according to an example embodiment, the program to be updated is a time-critical application. Update coordinator 111 may be part of control device 110, or it may be connected to control device 110 as a separate entity, or it may be a software module running on control device 110.
[0116] In S400 , the update coordination device 111 receives a new program version of a program to be updated in the control device 110 .
[0117] According to an example of embodiment, the update coordination device 111 checks the compatibility of the new program version of the program with the control device 110. Only when the compatibility check is successful is the software update initiated.
[0118] Furthermore, according to an example of an embodiment, the update coordination device 111 checks whether the new program version of the program is indicated as being received from a trusted source and signed. The software update is initiated only when a corresponding indication is detected.
[0119] In S410 , upon receiving the new program version, the update coordination device 111 instructs the control device 110 to perform a hardware self-test process.
[0120] In S420 , the update coordination device 111 initiates a software update at the control device 110 of the program to be updated to the new program version by switching the control device 110 to the new program version.
[0121] According to an example of an embodiment, the update coordination device 111 initiates a software update of a program to be updated at the control device 110 at a predetermined timing determined based on the operating state of the control device 110. For example, the predetermined timing is determined based on at least one of: a diagnostic time interval of the control device 110, or an idle time slot of a time-critical application running on the control device 110, which is related to an input filtering time, an idle time of a time-triggered communication protocol, a mutual authentication delay, a message loss delay, and a message loss period.
[0122] Figure 5 A diagram illustrating the configuration of a control device (such as control device 120 according to some examples of embodiments) for a transport or access-related system is shown, configured to implement the process for software updates as described in conjunction with some examples of embodiments. It should be noted that control device 120 may include additional elements or functions in addition to those described below. Furthermore, even when reference is made to a device such as a controller, the device or function may be another device or function with a similar task, such as a chipset, chip, module, application, etc., which may also be part of the controller or attached to the controller as a separate device. It should be understood that each block and any combination thereof may be implemented by various means or combinations thereof, such as hardware, software, firmware, one or more processors, and / or circuits.
[0123] Figure 5The control device 120 shown may include processing circuitry, processing functions, control units or processors 1201, such as a CPU or the like, which are adapted to execute instructions given by a program or the like associated with a control process. The processor 1201 may include one or more processing parts or functions dedicated to a specific process as described below, or the processing may be run in a single processor or processing function. For example, the parts for performing such specific processing may also be provided as discrete components or within one or more further processors, processing functions or processing parts, such as in one physical processor like a CPU or in one or more physical or virtual entities. Reference numerals 1202 and 1203 indicate input / output (I / O) units or functions (interfaces) connected to the processor or processing function 1201. The I / O unit 1202 may be used to communicate with elements or functions of a transport or access related system, for example, as in conjunction with Figure 1 The I / O unit 1203 can be used to communicate with the remote update system 112, for example, in conjunction with Figure 1 As described above. I / O units 1202 and 1203 may be combined units including interfaces or communication devices to several components, or may include a distributed structure with multiple different interfaces for different components. Reference numeral 1204 denotes a memory, which may be used, for example, to store data (such as the results of hardware self-tests) and programs to be executed by processor or processing function 1201 and / or serve as working storage for processor or processing function 1201. It should be noted that memory 1204 may be implemented using one or more memory sections of the same or different types of memory.
[0124] The processor or processing function 1201 is configured to perform the update control processing associated with the above process. In particular, the processor or processing circuit or function 1201 includes one or more of the following sub-parts. Sub-part 1205 is a processing part that can be used as an update coordination part. Part 1205 can be configured to perform according to Figure 4 Furthermore, the processor or processing circuit or function 1201 may include a sub-portion 1206 that may function as a control portion. Portion 1206 may be configured to execute the processing according to Figure 3 The processing of the processing.
[0125] It should be understood that
[0126] -Embodiments suitable for implementation as software code or portion thereof and running using a processor or processing functionality are independent of the software code and may be specified using any known or future developed programming language, such as a high-level programming language, such as objective-C, C, C++, C#, Java, Python, Javascript, other scripting languages, etc., or a low-level programming language, such as machine language or assembler.
[0127] -The implementation of the embodiments is hardware-independent and can be implemented using any known or future developed hardware technology or any mixture of these technologies, such as a microprocessor or CPU (Central Processing Unit), MOS (Metal Oxide Semiconductor), CMOS (Complementary MOS), BiMOS (Bipolar MOS), BiCMOS (Bipolar CMOS), ECL (Emitter Coupled Logic) and / or TTL (Transistor-Transistor Logic).
[0128] - embodiments may be implemented as separate devices, apparatuses, units, components or functions, or in a distributed manner, e.g., one or more processors or processing functions may be used or shared in a process, or one or more processing portions or processing parts may be used and shared in a process, where one physical processor or more than one physical processor may be used to implement one or more processing portions dedicated to a particular process being described,
[0129] - the device may be implemented by a semiconductor chip, a chipset, or a (hardware) module including such a chip or chipset;
[0130] - The embodiments may also be implemented as any combination of hardware and software, such as ASIC (Application Specific IC (Integrated Circuit)) components, FPGA (Field Programmable Gate Array) or CPLD (Complex Programmable Logic Device) components or DSP (Digital Signal Processor) components.
[0131] The embodiments may also be implemented as a computer program product including a computer usable medium having computer readable program code embodied therein, the computer readable program code being adapted to perform the processes described in the embodiments, wherein the computer usable medium may be a non-transitory medium.
[0132] Although the present invention has been described herein before with reference to specific embodiments thereof, the present invention is not limited thereto and various modifications may be made thereto.
Claims
1. A control device (110), comprising: a device configured to perform a hardware self-test process upon receiving an instruction for performing the hardware self-test process; a device configured to store results of said hardware self-test process in a memory; a device configured to check whether a result of the hardware self-test process meets a predetermined standard; and means configured to carry out a software update of a program running in said control device (110) to install and start a new program version, Wherein, when switching to the new program version, when the inspection of the stored results of the hardware self-test process indicates that the results meet the predetermined criteria, the new program version is installed and started without performing another hardware self-test process or before completing another hardware self-test process.
2. The control device (110) according to claim 1, wherein the predetermined criteria include at least one of the following: determining that the results of the hardware self-test process are present in the memory, Determining based on an integrity check that the results of the hardware self-test process are not corrupted, or It is determined that the time interval since the most recent hardware self-test procedure is within a predetermined range.
3. The control device (110) according to claim 1 or 2, wherein: In case a check of the stored results of the hardware self-test process indicates that the results do not meet the predetermined criteria, another hardware self-test process is performed when a new program version is installed and started.
4. The control device (110) according to any one of claims 1 to 3, wherein: The control device (110) is included in one of an electronic safety controller, a drive controller or a monitoring device of a transport or access related device, wherein the transport or access related device includes one of an elevator, an escalator, a moving walkway, a conveyor and an automatic door. In this case, the control device runs a time-critical application as the program to be updated.
5. The control device (110) according to any one of claims 1 to 3, wherein: The memory is a volatile memory.
6. An update coordination device (111), comprising: a device configured to receive a new program version of a program to be updated in the control device (110); a device configured to instruct the control device (110) to perform a hardware self-test process when the new program version is received; and Means configured to initiate a software update of a program to be updated to a new program version at the control device (110) by switching the control device (110) to the new program version.
7. The update coordination device (111) according to claim 6, further comprising: Means are configured to check compatibility of a new program version of the program with the control device, wherein the software update is initiated only if the check for compatibility is successful.
8. The update coordination device (111) according to claim 6 or 7, further comprising: A device configured to check whether a new program version of the program is indicated as being received from a trusted source and signed, wherein the software update is initiated only if a corresponding indication is detected.
9. The update coordination device (111) according to any one of claims 6 to 8, wherein: At a predetermined timing determined based on an operating state of the control device (110), software update of a program to be updated is started at the control device (110).
10. The update coordination device (111) according to claim 9, wherein the predetermined timing is determined based on at least one of the following: a diagnostic time interval of the control device (110); or An idle time slot for a time-critical application running on the control device (110) is related to input filtering time, idle time of a time-triggered communication protocol, reciprocity verification delay, message loss delay and message loss period.
11. The update coordination device (111) according to any one of claims 6 to 10, wherein the update coordination device is part of the control device (110), connected to the control device (110) as a separate entity, or is a software module running on the control device (110).
12. A control device (120), comprising: Control device (110); Update coordination device (111); and Memory; Wherein, when the update coordination device (111) receives a new program version of a program to be updated in the control device (110), the update coordination device (111) is configured to instruct the control device (110) to perform a hardware self-test process, The control device (110) is configured to perform the hardware self-test process and store the result of the hardware self-test process in the memory; The control device (110) is configured to check whether the result of the hardware self-test process meets a predetermined standard when the update coordination device (111) starts a software update of a program to be updated to a new program version, Wherein, when switching to the new program version, when checking the stored result of the hardware self-test process indicates that the result meets the predetermined standard, the new program version is installed and started at the control device (110) without performing another hardware self-test process or before completing another hardware self-test process.
13. The control device (120) according to claim 12, wherein the predetermined criteria comprises at least one of the following: determining that the results of the hardware self-test process are present in the memory, Determining based on an integrity check that the results of the hardware self-test process are not corrupted, or It is determined that the time interval since the most recent hardware self-test procedure is within a predetermined range.
14. The control device (120) according to claim 12 or 13, wherein: In case that the examination of the stored result of the hardware self-test process indicates that the result does not meet the predetermined criterion, the control device (110) is configured to perform another hardware self-test process when installing and starting the new program version.
15. The control device (120) according to any one of claims 12 to 14, wherein the update coordination means (111) is configured to check compatibility of a new program version of the program with the control device, wherein the software update is initiated only if the compatibility check is successful.
16. The control device (120) according to any one of claims 12 to 15, wherein: The update coordination device (111) is configured to check whether the new program version of the program is indicated as being received from a trusted source and signed, wherein the software update is initiated only when a corresponding indication is detected.
17. The control device (120) according to any one of claims 12 to 16, wherein: At a predetermined timing determined based on an operating state of the control device (110), software update of a program to be updated is started at the control device (110).
18. The control device (120) according to claim 17, wherein The predetermined timing is determined based on at least one of the following: a diagnostic time interval of the control device (110); or An idle time slot for a time-critical application running on the control device (110) is related to input filtering time, idle time of a time-triggered communication protocol, reciprocity verification delay, message loss delay and message loss period.
19. The control device (120) according to any one of claims 12 to 18, wherein the update coordination device (111) is part of the control device (110), is connected to the control device (110) as a separate entity, or is a software module running on the control device (110).
20. The control device (120) according to any one of claims 12 to 19, wherein: The control device (110) is included in one of an electronic safety controller, a drive controller or a monitoring device, wherein the control device (120) is configured to control a transport or access related device, wherein the transport or access related device comprises one of an elevator, an escalator, a moving walkway, a conveyor and an automatic door, wherein the program to be updated is a time critical application.
21. The control device (120) according to any one of claims 12 to 20, wherein the memory is a volatile memory.
22. A control method comprising: When receiving an instruction for performing a hardware self-test process, performing the hardware self-test process; storing the results of the hardware self-test program in a memory; Checking whether the result of the hardware self-test process meets a predetermined standard; and performing a software update of a program running in said control device (110) in order to install and start a new program version, Wherein, when switching to the new program version, when the inspection of the stored results of the hardware self-test process indicates that the results meet the predetermined criteria, the new program version is installed and started without performing another hardware self-test process or before completing another hardware self-test process.
23. The control method according to claim 22, wherein: The predetermined criteria include at least one of the following: determining that the results of the hardware self-test process are present in the memory, Determining based on an integrity check that the results of the hardware self-test process are not corrupted, or It is determined that the time interval since the most recent hardware self-test procedure is within a predetermined range.
24. The control method according to claim 22 or 23, further comprising: In case a check of the stored result of the hardware self-test process indicates that the result does not meet the predetermined criterion, another hardware self-test process is performed when the new program version is installed and started.
25. The control method according to any one of claims 22 to 24, wherein: The method is performed in one of an electronic safety controller, a drive controller, or a monitoring device of a transportation or access related device, the transportation or access related device including one of an elevator, an escalator, a moving walkway, a conveyor, and an automatic door, Among the programs to be updated are time-critical applications.
26. The control method according to any one of claims 22 to 25, wherein: The memory is a volatile memory.
27. An update coordination method, comprising: receiving a new program version of a program to be updated in a control device (110); When the new program version is received, instructing the control device (110) to perform a hardware self-test process; and By switching the control device (110) to the new program version, a software update of the program to be updated to the new program version is initiated at the control device (110).
28. The update coordination method according to claim 27, further comprising: A new program version of the program is checked for compatibility with the control device, wherein the software update is initiated only if the compatibility check is successful.
29. The update coordination method according to claim 27 or 28, further comprising: A check is made as to whether a new program version of the program is indicated as being received from a trusted source and as being signed, wherein the software update is initiated only if a corresponding indication is detected.
30. The update coordination method according to any one of claims 27 to 29, wherein: At a predetermined timing determined based on an operating state of the control device (110), software update of a program to be updated is started at the control device (110).
31. The update coordination method according to claim 30, wherein the predetermined timing is determined based on at least one of the following: a diagnostic time interval of the control device (110); or An idle time slot for a time-critical application running on the control device (110) is related to input filtering time, idle time of a time-triggered communication protocol, reciprocity verification delay, message loss delay and message loss period.
32. Update coordination method according to any one of claims 27 to 31, wherein the method is executed in the control device (110), in a separate entity connected to the control device (110), or by a software module running on the control device (110).
33. A control method comprising: When a new program version of a program to be updated in a control device is received, the control device (110) is instructed to perform a hardware self-test process, performing the hardware self-test process and storing the result of the hardware self-test process in a memory, and When starting a software update of a program to be updated to said new program version, checking whether the result of said hardware self-test process meets a predetermined standard, Wherein, when switching to the new program version, when checking the stored result of the hardware self-test process indicates that the result meets the predetermined standard, the new program version is installed and started at the control device (110) without performing another hardware self-test process or before completing another hardware self-test process.
34. The control method according to claim 33, wherein: The predetermined criteria include at least one of the following: determining that the results of the hardware self-test process are present in the memory, Determining based on an integrity check that the results of the hardware self-test process are not corrupted, or It is determined that the time interval since the most recent hardware self-test procedure is within a predetermined range.
35. The control method according to claim 33 or 34, further comprising: In case a check of the stored result of the hardware self-test process indicates that the result does not meet the predetermined criterion, another hardware self-test process is performed when the new program version is installed and started.
36. The control method according to any one of claims 33 to 35, further comprising checking compatibility of a new program version of the program with the control device, wherein the software update is initiated only if the compatibility check is successful.
37. The control method according to any one of claims 33 to 36, further comprising: A check is made as to whether a new program version of the program is indicated as being received from a trusted source and as being signed, wherein the software update is initiated only if a corresponding indication is detected.
38. The control method according to any one of claims 33 to 37, wherein: At a predetermined timing determined based on an operating state of the control device (110), software update of a program to be updated is started at the control device (110).
39. The control method according to claim 38, wherein: The predetermined timing is determined based on at least one of the following: a diagnostic time interval of the control device (110); or An idle time slot for a time-critical application running on the control device (110) is related to input filtering time, idle time of a time-triggered communication protocol, reciprocity verification delay, message loss delay and message loss period.
40. The control method according to any one of claims 33 to 39, wherein: The control method is executed in one of an electronic safety controller, a drive controller, or a monitoring device, wherein the electronic safety controller or the drive controller controls transportation- or access-related equipment including one of an elevator, an escalator, a moving walkway, a conveyor, and an automatic door, and wherein the program to be updated is a time-critical application.
41. The control method according to any one of claims 22 to 40, wherein: The memory is a volatile memory.
42. A computer program comprising instructions which, when executed by an apparatus, cause the apparatus to perform at least the method of any one of claims 22 to 26, any one of claims 27 to 32 or any one of claims 33 to 41.
43. A computer-readable medium comprising instructions that, when executed by a device, cause the device to at least perform the method of any one of claims 22 to 26, any one of claims 27 to 32, or any one of claims 33 to 41.
44. A computer program product for a computer, comprising software code portions for performing the method of any one of claims 22 to 26, any one of claims 27 to 32 or any one of claims 33 to 41 when said product is run on said computer.
45. The computer program product of claim 44, wherein: The computer program product comprises a computer-readable medium having the software code portions stored thereon, and / or The computer program product may be directly loaded into the internal memory of the computer or may be transmitted via a network by means of at least one of an upload, download and push process.
Citation Information
Patent Citations
A people conveyor system and a method for updating software of a people conveyor component in a people conveyor system
EP3915912A1