Method and network coordinator for managing access to site control network of personnel flow system comprising passenger conveyor system
By using a pairing procedure with a predefined shared secret and a backup list recovery mechanism for the network coordinator device, the tedious pairing problem when the coordinator device is replaced is solved, the station control network is rebuilt safely and efficiently, and the normal transportation of the passenger transportation system is ensured.
Patent Information
- Application Number
- CN202380094179.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-03-29
- Publication Date
- 2025-09-12
AI Technical Summary
In the prior art, when replacing the coordinator device of the station control network, it is necessary to repeat the tedious and error-prone pairing procedure, resulting in the risk that the passenger transportation system cannot transport passengers normally for a long time.
The network coordinator device performs a pairing procedure with a predefined shared secret, allowing devices to enter the site control network and automatically restore the network configuration using a backup list when the coordinator device loses configuration information, simplifying the device joining process.
This enabled safe and efficient reconstruction of the station control network, reduced the risk of human error and equipment downtime, and ensured reliable operation of the passenger transportation system.
Smart Images

Figure CN120641345A_ABST
Abstract
Description
Technical Field
[0001] Exemplary and non-limiting embodiments of the present invention relate to the management of a control network adapted to communicatively couple a plurality of network nodes to one another that are involved in controlling the operation of people movement equipment such as elevators and / or escalators. Background Art
[0002] In addition to one or more elevators and / or one or more escalators, many advanced people flow systems also include various support systems for the actual transportation of passengers at the station, such as lighting and ventilation. In this regard, both the actual transportation system and the support systems typically operate under separate control systems. Furthermore, people flow systems typically include various devices that provide information to and / or receive information from the control system, such as a control panel (e.g., a call terminal) located at the station for receiving user input (e.g., a call for transportation from a passenger of the people flow system), a display device for displaying information to passengers, and one or more sensors arranged to monitor environmental characteristics of the station.
[0003] In order to effectively share information related to the control of various aspects of the people flow system, the various control systems and various other devices of the people flow system are typically communicatively coupled to each other via a communication network, which may be referred to as a site control network or site network. The site control network may be further connected to other networks provided at the site, such as one or more other site control networks and / or a building automation network.
[0004] On the one hand, efficient and reliable transmission of information through the site control network is often crucial for the proper and timely operation of the underlying personnel mobility equipment at the site, while on the other hand, allowing external devices to connect to the site control network can pose a security risk. Consequently, only those devices deemed essential to the operation of the personnel mobility equipment are typically allowed to join the site control network. To this end, the site control network typically includes a coordinator device that manages access to the site control network, for example, by tracking devices connected to the site control network and by allowing any new devices wishing to join the site control network through a pairing procedure that involves authentication of the device wishing to join the site control network.
[0005] While the use of a coordinator device is suitable for ensuring the secure operation of a site control network even when devices leave and join the site control network (e.g., due to the introduction of new devices to the people mobility equipment or the replacement of a malfunctioning device of the site control network with a new device), there are still challenges in replacing a coordinator device with a new device, which may be necessary, for example, due to a failure of the coordinator device or simply due to the need to upgrade the coordinator device. From a practical perspective, replacing a coordinator device with a new coordinator device may require re-establishing the site control network by repeating the pairing procedure for each device on the site control network with the new coordinator device, which in many cases requires manual work that is both tedious and prone to human error, thereby risking the long-term inability to transport passengers by operating the underlying people mobility equipment. Summary of the Invention
[0006] An object of the present invention is to provide a technique that facilitates efficient and secure re-establishment of a site control network that is used to control at least some aspects of the operation of a people flow system provided at a site when network configuration information is lost at a network coordinator entity of the site control network.
[0007] According to an example embodiment, a method for managing access to a control network of a people flow system is provided, wherein the people flow system includes a passenger conveyor system and a conveyor system controller, wherein a site control network communicatively couples the conveyor system controller to a network coordinator and one or more additional devices, the method comprising: allowing one or more additional devices to enter the site control network by the network coordinator via performing a corresponding pairing procedure with each of the one or more additional devices based on a predefined shared secret; adding, by the network coordinator, the corresponding device identifier ID of each additional device to a list of devices allowed to enter the site control network; sending the list from the network coordinator to an external entity for storage therein; and creating a restored site control network in the network coordinator or one of the replacement network coordinators after site network control information is lost in the network coordinator, the creation comprising receiving the list from the external entity; and automatically allowing a device to enter the restored site control network, provided that the device has its device ID included in the list and knows the predefined shared secret.
[0008] According to another example embodiment, a device for managing access to a control network of a people flow system is provided, wherein the control network includes a passenger conveyor system and a conveyor system controller, wherein a site control network communicatively connects the conveyor system controller to the device and one or more additional devices, the device being arranged to: allow one or more additional devices to enter the site control network by performing a corresponding pairing procedure with each of the one or more additional devices based on a predefined shared secret; add the corresponding device identifier ID of each additional device to a list of devices allowed to enter the site control network; send the list to an external entity for storage therein; and create a restored site control network after site network control information is lost in the device, the creation comprising the device being arranged to: receive the list from the external entity, and automatically allow another device to enter the restored site control network, provided that the other device has its device ID included in the list and knows the predefined shared secret.
[0009] According to another example embodiment, a control system for managing access to a control network of a people flow system is provided, wherein the people flow system includes a passenger conveyor system and a conveyor system controller, wherein a site control network communicatively couples the conveyor system controller to a network coordinator device and one or more additional devices, the control system comprising: a network coordinator device arranged to: allow one or more additional devices to enter the site control network by performing a corresponding pairing procedure with each of the one or more additional devices based on a predefined shared secret, add the corresponding device identifier ID of each other device to a list of devices allowed to enter the site control network, and send the list to an external entity for storage therein; and a replacement network coordinator device arranged to create a restored site control network after the site network control information is lost in the network coordinator device, the creation comprising the replacement network coordinator device being arranged to: receive the list from the external entity; and automatically allow the other device to enter the restored site control network, provided that the other device has its device ID included in the list and knows the predefined shared secret.
[0010] According to another exemplary embodiment, a computer program for managing access to a control network is provided, the computer program comprising a computer readable program code configured to cause at least the method according to the aforementioned exemplary embodiment to be performed when the program code is executed on one or more computing devices.
[0011] The computer program according to the above-described example embodiments may be embodied on a volatile or non-volatile computer-readable recording medium, for example as a computer program product comprising at least one computer-readable non-transitory medium having program code stored thereon, which, when executed by one or more computing devices, causes the computing devices to at least perform the method according to the example embodiments described hereinabove.
[0012] The exemplary embodiments of the invention presented in this patent application should not be interpreted as limiting the applicability of the appended claims. The verb "comprise" and its derivatives are used in this patent application as open limitations that do not exclude the presence of unrecited features. Unless expressly stated otherwise, the features described below are freely combinable with each other.
[0013] Certain features of the invention are set forth in the appended claims. However, the invention in its various aspects, both as to its construction and its method of operation, together with additional objects and advantages thereof, will be best understood from the following description of certain exemplary embodiments when read in connection with the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] Embodiments of the invention are illustrated by way of example and not limitation in the figures of the accompanying drawings in which:
[0015] Figure 1 A block diagram illustrating some logical elements of a personnel flow system according to an example;
[0016] Figure 2 A method according to an example is shown;
[0017] Figure 3 A block diagram illustrating some logical elements of a personnel flow system according to an example;
[0018] Figure 4 A method according to an example is shown; and
[0019] Figure 5 An apparatus according to an example is schematically shown. DETAILED DESCRIPTION
[0020] Figure 1A block diagram of some logical elements of a people flow system 100 according to an example is shown, including a passenger conveyor system 101 and a conveyor system controller 110, wherein the passenger conveyor system 101 may include one or more elevators and / or one or more escalators arranged at a station for transporting passengers. The people flow system 100 may also be referred to as a passenger conveyor system. The conveyor system controller 110 may be communicatively coupled to one or more additional devices 130 via a communication network 105, the conveyor system controller 110 and the one or more additional devices 130 thus acting as respective nodes of the communication network 105, and they may also be considered as respective elements of a control system 102 associated with the people flow system 100. In this regard, Figure 1 The example of shows further devices 130 - 1 and 130 - 2 representing one or more further devices 130 , while any single further device may be referred to as further device 130 - k .
[0021] The control system 102 also includes a network coordinator 120 coupled to the communication network 105, which may be implemented as a network coordinator device (eg, a separate device) from other nodes of the communication network 105. Figure 1 ) or implemented as an element integrated into another node of the communication network 105. As an example of the latter, the network coordinator can be implemented as part of the conveyor system controller 110.
[0022] The one or more additional devices 130 coupled to the communication network 105 may include one or more devices operating at a site to provide information suitable for controlling one or more aspects of the operation of the passenger conveyor system 101 to the conveyor system controller 110, and within the framework of the present disclosure, such devices may also be referred to as corresponding data source devices. Additionally or alternatively, the one or more additional devices coupled to the communication network 105 may include one or more devices that receive information regarding the operation and / or use of the people flow system 100 from the conveyor system controller 110 and further provide this information to passengers of the passenger conveyor system 101 at the site. Within the framework of the present disclosure, such devices may also be referred to as corresponding data sink apparatuses 140. Therefore, the communication network 105 is used to couple the one or more additional devices 130 operating at the site to the conveyor system controller 110 and to each other, and therefore, the communication network 105 may also be referred to as a site control network or a site network.
[0023] Figure 1The example further illustrates a server entity 150, to which the network coordinator 120 may be communicatively coupled. The server entity 150 is not included in the site control network 105, but may be communicatively coupled to the network coordinator 120 independently of the site control network 105, and thus may also be referred to as an external server entity. The server entity 150 may be provided as a server device (which may be provided at the site or at a remote location) or as a plurality of server devices (typically provided at a remote location) arranged to provide cloud computing services.
[0024] The conveyor system controller 110 may be arranged to control one or more aspects of the operation of the passenger conveyor system 101, wherein the manner in which the passenger conveyor system 101 is controlled may be based at least in part on data received via the site control network 105 from one or more data source devices included in the site control network 105. In this regard, the conveyor system controller 110 may include one or more controller devices, such as, for example, one or more elevator system controllers and / or one or more escalator system controllers, depending on the configuration of the passenger conveyor system 101 operating at the site. Each controller device of the conveyor system controller 110 may include a computer device including one or more processors and one or more memories storing one or more computer programs, wherein the one or more processors may execute the one or more computer programs stored in the one or more memories to cause the computer device to operate as a corresponding controller device of the conveyor system controller 110. Reference will be made later herein to Figure 5 A more detailed example describing this is given below.
[0025] In this regard, it is worth noting that in the context of the present disclosure, the aspects of interest relating to the people flow system 100 are aspects of managing the site control network 105 and, accordingly, any aspects relating to the structure and operation of the passenger conveyor system 101 and any aspects relating to the operation of the conveyor system controller 110 may be provided using techniques known in the art and, therefore, any detail in this regard is described herein only to the extent necessary to describe examples relating to the management of the site control network 105 in accordance with the present disclosure.
[0026] As previously described, the additional devices 130-k connected to the station control network 105 may include data source devices that may be operated at the station and are arranged to receive, capture, and / or otherwise acquire data suitable for controlling one or more aspects of the operation of the passenger conveyor system 101 and for transmitting the acquired data therein to the conveyor system controller 110 via the communication station control network 105. The data source devices may also be arranged to transmit the corresponding acquired data therein to one or more other nodes of the station control network 105 via the station control network 105 and / or receive information, such as control data, from the conveyor system controller 110 via the station control network 105.
[0027] Similarly, the additional devices 130-k coupled to the station control network 105 may include a data sink device that may be arranged to receive information regarding the operation and / or use of the people flow system 100 from the conveyor system controller 110 via the station control network 105 and, for example, present the received information to passengers of the passenger conveyor system 101 at the station and / or store the received information therein, for example, for monitoring or analysis purposes. The data sink device may also be arranged to receive corresponding data from one or more additional devices coupled to the station control network 105 (e.g., from one or more data source devices) via the station control network 105 and / or transmit information (e.g., a request to receive certain data) to, for example, the conveyor system controller 110 via the station control network 105.
[0028] The one or more additional devices 130 of the site control network 105 may also include one or more network traffic management apparatuses, such as network traffic management apparatuses suitable for segmenting the site control network 105 and / or for extending the coverage of the site control network 105 (if provided as a wireless communication network). Although the operation of such traffic management apparatuses may involve receiving and transmitting data via the site control network 105, such apparatuses may not strictly constitute data source apparatuses or data sink apparatuses within the meaning of the present disclosure.
[0029] Each of the one or more further devices 130 may include a respective computer device including one or more processors and one or more memories storing one or more executable computer programs, and the one or more processors of the respective computer device executing the one or more executable computer programs stored at the one or more memories of the respective computer device causes the respective computer device to function as the respective further device 130-k. Figure 5 A more detailed example describing this is given below.
[0030] In the framework of the present disclosure, the term data source device is used as a general term that is intended to include any device operating at a station and coupled to the station control network 105 for receiving, capturing, or otherwise acquiring information applicable to controlling at least one aspect of the operation of the passenger conveyor system 101 via operation of the conveyor system controller 110. Non-limiting examples of such data source devices include the following:
[0031] - A user interface device, such as a call panel that can be used to receive transportation calls from station passengers and / or other types of control panels that can be used to enter user input to operate the passenger conveyor system 101.
[0032] - The sensor arrangement comprises one or more sensors arranged to monitor corresponding environmental characteristics at a general station or at a certain location of the people flow system 100, such as the presence of one or more passengers, temperature, light level, etc.
[0033] Furthermore, in the framework of the present disclosure, the term data sink device is used as a general term that is intended to encompass any device operating at a station and connected to the station control network 105 for receiving information describing the operation and / or use of the people flow system 100 from the conveyor system controller 110 or from another node of the station control network 105, to enable the display of the received information to passengers of the passenger conveyor system 101 at the station, to control at least some aspects of the lighting at the station associated with the people flow system 100, and / or to enable monitoring or analysis of the operation of the people flow system 100. Non-limiting examples of such data sink devices include the following:
[0034] - A display device for displaying at a station information about one or more aspects of the overall operating status of the passenger conveyor system 101 or the personnel flow system 100 and / or guidance information for passengers of the passenger conveyor system 101 in view of the overall current operating status of the passenger conveyor system 101 or the personnel flow system 100.
[0035] - Control means for controlling other types of lighting and / or visual effects provided to passengers of the passenger conveyor system 101 or people flow system 100 at the station.
[0036] - A monitoring device for storing data describing the operating status of the passenger conveyor system 101 or the people flow system 100 in order to subsequently analyze the operation of the passenger conveyor system 101 or the people flow system 100.
[0037] The site control network 105 may include a wireless communication network, a wired communication network, or a combination of wireless and wired communication networks. For purposes of example, hereinafter, the use of a wireless communication network is assumed, and the operations described with reference to the wireless communication network are applicable to scenarios where a wired network or a combination of wireless and wired networks is applied instead, mutatis mutandis.
[0038] As an example in this regard, the site control network 105 can be provided using suitable short-range wireless communication technologies known in the art, which can enable communication within a range of from a few meters to up to one hundred meters. Examples of suitable short-range wireless communication technologies include Bluetooth, Bluetooth Low Energy (BLE), ZigBee, WLAN / Wi-Fi according to the IEEE 802.11 family of standards, and the like. The selection of wireless communication technology and network topology applied to a particular implementation of the site control network 105 can depend on, for example, the desired communication range and / or requirements regarding the energy efficiency of the applied communication technology. As a non-limiting example in this regard, the site control network 105 can be provided using a wireless mesh network model, such as a mesh network according to the Bluetooth or BLE mesh network protocols known in the art.
[0039] The network coordinator 120 may include a computer device including one or more processors and one or more memories storing one or more computer programs, wherein the one or more processors may execute the one or more computer programs stored in the one or more memories to cause the computer device to operate as the network coordinator 120 according to the present disclosure. Figure 5 A more detailed example of this is described below. As previously mentioned, according to an example, the network coordinator 120 can be implemented in a device separate from the other nodes of the site control network 105, for example, as a dedicated network coordinator device, while in another example, the network coordinator 120 can be implemented as an entity of another node of the site control network 105, for example, as part of the conveyor system controller 110. However, for clarity of description, in the following examples, by referring to the network coordinator 120 as the network coordinator device 120, it is (implicitly) assumed that the network coordinator 120 is implemented in a device separate from the other nodes of the site control network, while explicit references to other ways of implementing the network coordinator 120 are provided where applicable.
[0040] The network coordinator device 120 may be arranged to manage other devices at the site that join the site control network 105. In this regard, the network coordinator device 120 may be arranged to allow one or more additional devices 130 to enter the site control network 105 and facilitate and / or implement a recovery mechanism that enables the site control network 105 to be recovered in the event of a failure that results in the loss of network configuration data required to manage the site control network 105. This may be performed, for example, by the network coordinator device 120 Figure 2 The method 200 shown is provided, and the method 200 may include the following steps:
[0041] - allowing one or more further devices 130 to enter the site control network 105 via performing a respective pairing procedure with each of the one or more further devices 130 based on a predefined shared secret (block 202);
[0042] - adding the corresponding device ID of each additional device 130 - k to the list of devices allowed into the site control network 105 (block 204 );
[0043] - transmitting said list to the server entity 150 for storage therein (block 206); and
[0044] - After the site network configuration information is lost in the network coordinator device 120, creating a restored site control network 105' at the network coordinator device 120 (block 208), said creation comprising:
[0045] o receiving a list of devices allowed to enter the site control network 105 from the server entity 150 (block 208a);
[0046] o Automatically allowing a device into the restored site control network 105 ′ (block 208 b ), provided that the device has its device ID included in the received list and knows the predefined shared secret.
[0047] The corresponding operations described with reference to the method steps represented by blocks 202 to 208 may be varied or supplemented in various ways, for example, according to the examples described above and / or below. In addition, the method 200 may be supplemented with one or more additional steps, and the order of performing at least some of the method steps may be different. Figure 2 The order depicted is different.
[0048] The shared secret used in the pairing procedure (see block 202) and in the creation of the restored site control network 105′ may be pre-stored at the network coordinator device 120 and one or more additional devices 130 and may be referred to as a pre-defined shared secret. The pre-defined shared secret may be stored at the network coordinator device 120 and one or more additional devices 130, for example, at the time of manufacture, configuration, or reconfiguration to operate as part of the site control network 105. Thus, knowledge of the pre-defined shared secret by a device may serve as an indication (to the site coordinator device) that the respective device is configured to operate as part of the site control network 105. Specifically, knowledge of the pre-defined shared secret by a device may serve as an indication that the respective device originated from a particular manufacturer and / or is otherwise pre-approved for access to the site control network 105. Thus, the pre-defined shared secret may be applied at the network coordinator device 120 to verify that a device attempting to join the site control network 105 has permission to join the network and / or to transmit sensitive information (e.g., one or more encryption keys) between the network coordinator device 120 and the respective device. The predefined shared secret may comprise a (pseudo)random bit sequence of a desired length.
[0049] Before describing the respective operations of blocks 202 through 208 in further detail via respective examples, some aspects related to creating the site control network 105 prior to performing the method 200 are described below.
[0050] Creation of the site control network 105 may include the network coordinator device 120 defining a network link key required for communication over the site control network 105, wherein the network link key may include a (pseudo)random bit sequence of a desired length. The network coordinator 120 may initialize the site control network 105 by allowing the conveyor system controller 110 to access the site control network 105. This may be accomplished via a pairing procedure executed with the conveyor system controller 110, which may include, for example, the following steps:
[0051] - receiving respective user input at the network coordinator device 120 and the conveyor system controller 110 (eg, via their respective user interfaces) to initiate a pairing procedure;
[0052] - Authenticating the conveyor system controller 110 at the network coordinator device 120;
[0053] - verifying at the network coordinator device 120 that the conveyor system controller 110 knows the predefined shared secret; and
[0054] - in response to successful authentication, transmitting the network link key (possibly along with other network information) from the network coordinator device 120 to the conveyor system controller 110 as data encrypted using a predefined shared secret or using an encryption key derived based on the predefined shared secret;
[0055] In this regard, the pairing procedure between the network coordinator device 120 and the conveyor system controller 110 can be provided in the manner described below, mutatis mutandis, for the corresponding pairing procedure performed between the network coordinator device 120 and the corresponding additional device 130-k. In the case where the network coordinator 120 is provided as an entity of the conveyor controller 110, the pairing procedure between the network coordinator 120 and the conveyor system controller 110 is not necessary and can be omitted.
[0056] After creating the site control network 105 and admitting the conveyor system controller 110 to the site control network 105, the network coordinator device 120 may proceed to admit one or more additional devices 130 to the site control network 105 via corresponding pairing procedures performed between the network coordinator device 120 and the corresponding additional devices 130-k (see block 202). These pairing procedures are substantially similar to the pairing procedures described above between the network coordinator 120 and the conveyor system controller 110, and thus may include, for example, the following steps for each of the one or more additional devices 130:
[0057] - receiving respective user inputs at the network coordinator device 120 and at the respective further devices 130 - k to initiate a pairing procedure;
[0058] - authenticating the respective further device 130 - k at the network coordinator device 120 ;
[0059] - verifying at the network coordinator device 120 that the respective further device 130 - k knows the predefined shared secret; and
[0060] In response to successful authentication, transmitting the network link key from the network coordinator device 120 to the respective further device 130 - k as (a part of) data encrypted using the predefined shared secret or using an encryption key derived based on the predefined shared secret.
[0061] In this regard, the network coordinator device 120 and the respective further device 130-k may receive respective user inputs, for example via their respective user interfaces, to initiate a pairing procedure. This may involve the user operating a (physical) button or key provided in the respective device 120, 130-k, or entering respective user inputs via respective user interfaces provided for the respective device 120, 130-k. Initiating the pairing procedure at the respective device 120, 130-k may result in signaling between the respective devices 120, 130, which may involve the respective further device 130-k transmitting at least one message serving as a request for admission to the site control network 105, and the network coordinator device 120 responding to the request by transmitting at least one message serving as an invitation to continue the admission procedure. Furthermore, the aforementioned message exchange may be preceded by the network coordinator device 120 indicating the availability of the site control network 105 by broadcasting one or more messages including information regarding the characteristics of the site control network 105. As part of this signaling exchange, the network coordinator device 120 may learn the device ID of the respective further device 130 - k (and vice versa) via one or more messages received from the respective further device 130 - k .
[0062] Authentication involved in a pairing procedure between the network coordinator device 120 and the respective additional device 130-k may be performed to verify at the network coordinator device 120 that the pairing procedure indeed involves the respective additional device 130-k (and not another device within the operating range of the network coordinator device 120), and may involve, for example, the coordinator device 120 receiving confirmation of the identity of the respective additional device 130-k as user input provided therefor. As an example in this regard, authentication may involve the coordinator device 120 receiving, via a user interface provided thereto, confirmation that a predefined code displayed via a user interface of the respective additional device 130-k has an expected value, or the coordinator device 120 receiving, via a user interface provided thereto, a code displayed via a user interface of the respective additional device 130-k and verifying that the received code has an expected value.
[0063] Still referring to the pairing procedure between the network coordinator device 120 and the respective other device 130-k, as an example, the network coordinator device 120 verifies that the respective other device 130-k knows the predefined shared secret, which can include a challenge-response authentication according to a predefined process. In this regard, the challenge-response procedure can also be used to confirm to the respective other device 130-k that the network coordinator 120 knows the predefined shared secret, and thus the respective other device 130-k has established a connection with the device that actually manages access to the site control network 105.
[0064] As previously described, after successful authentication, the network coordinator device 120 may transmit the network link key to the respective other devices 130-k as encrypted data, where the encrypted data may also include other information related to the site control network 105 and / or communications through the site control network 105. According to one example, the data transmitted from the network coordinator device 120 to the respective other devices 130-k may be encrypted using a predefined shared secret, while according to another example, the encryption may be performed using an encryption key derived based on the predefined shared secret. In the latter example, the encryption key may be a device-pair-specific encryption key, and the encryption key may be derived at both devices 120 and 130-k using a predefined process and / or algorithm provided for this purpose.
[0065] Once one or more additional devices 130 are admitted to the site control network 105 via a corresponding pairing procedure, each additional device 130-k is able to communicate via the site control network 105 using the network link key obtained during the pairing procedure. In this regard, the predefined shared secret may also subsequently be used, for example, at the network coordinator device 120 to automatically authenticate the respective additional device 130-k when the respective additional device 130-k (e.g., via a challenge-response process) (re)connects to the site control network.
[0066] By applying a pairing procedure according to the method 210 (or otherwise), allowing one or more additional devices 130 to enter the site control network 105 is used to ensure that only known, trusted devices are allowed to join and connect to the site control network 105, thereby significantly reducing the risk of unauthorized access to the site control network 105, which could jeopardize the reliable and safe operation of the passenger conveyor system 101 and therefore even pose a risk to passenger safety.
[0067] With reference now to the aspect of adding the respective device IDs of one or more additional devices 130 to the list of devices permitted to access the site control network 105 (see block 204), in the event that the network coordinator 120 is provided as a network coordinator device 120 that is separate from other nodes of the site control network (and therefore separate from the conveyor system controller 110), the device ID of the conveyor system controller 110 may also be added to the list of devices permitted to access the site control network 105. As used herein, the term "list" is to be interpreted broadly to include any data structure that can be applied to store a set of device IDs. The respective device ID assigned to a device (e.g., assigned to the conveyor system controller 110 or to any of the one or more additional devices 130) may include, for example, a serial number of the respective device 110, 130-k, an address assigned to the respective device 110, 130-k (e.g., a media access control (MAC) layer address of the respective device 110, 130-k), a name assigned to the respective device 110, 130-k, and the like.
[0068] Furthermore, in this regard, the list of devices allowed to enter the site control network 105 may constitute part of the site control network configuration information stored at the network coordinator device 120. The site control network configuration information may be stored, for example, in the form of a network configuration table or a network configuration database, which may include a respective entry for each of the devices 110, 130-k allowed to enter the site control network 105, wherein the entry relating to the respective allowed device 110, 130-k includes at least a device ID of the respective device 110, 130-k, and it may include further information relating to the respective device 110, 130-k, such as a respective device-pair-specific encryption key derived for the respective device 110, 130-k.
[0069] Referring now to the aspect of transmitting the list of devices allowed into the site control network 105 to the server entity 150 (see box 206), the transmission of the list to the server entity 150 may be performed over a secure connection to ensure confidentiality of the transmitted data, wherein security mechanisms known in the art may be applied to protect the data transmitted from the network coordinator device 120 to the server entity 150.
[0070] The list of devices allowed to access the site control network 105 is transmitted to the server entity 150 for providing a backup copy of the list to address the potential loss of the site network configuration information (or a portion thereof) at the network coordinator device 120, for example due to a malfunction or due to human error, which could result in the network coordinator device 120 partially or completely losing its ability to manage the site control network 105 in a manner that ensures the security of the site control network 105. As previously mentioned, in previously known methods, this situation would be addressed by re-establishing the site control network 105 by repeating the corresponding pairing procedure with one or more additional devices 130, for example, according to the operations described above with reference to block 202. However, this method requires manual work that is both tedious and prone to human error, thereby posing the risk of prolonged passenger transportation failure through the operation of the passenger transportation system 101.
[0071] With reference now to the aspect of creating a restored site control network 105′ following a loss of at least part of the site network configuration information (see block 208), the network coordinator device 120 may have recourse to a previously transmitted backup copy of the list of devices allowed into the site control network 105 for storage at the server entity 150 and therein for subsequent access by the network coordinator device 120. Creating the restored site control network 105′ based on the copy of the list of devices allowed into the site control network 105 essentially includes two stages, namely, receiving a copy of the list of devices allowed into the site control network 105 from the server entity 150, and re-admitting the corresponding additional devices 130-k using the device IDs in the list via a simplified process that avoids the additional burden of repeating a full-scale pairing procedure for one or more additional devices 130, e.g., in accordance with the operations described above with reference to block 202.
[0072] Aspects of creating the restored site control network 105' (see block 208) may include the network coordinator device 120 defining a new network link key to be applied for secure communications on the restored site control network 105'. In this regard, the new network link key may be the same as that previously applied to the site control network 105, but more typically, the creation of the restored site control network 105' may include the network coordinator device 120 generating a new network link key, independent of the network link key applied to the site control network 105 before the network configuration information was lost at the network coordinator device 120. Similar to the network link key applied to the site control network 105, the new network link key for the restored site control network 105' may also include a (pseudo)random bit sequence of a desired length. The creation of the restored site control network 105' may further involve the network coordinator device 120 initiating the broadcast of one or more messages indicating the availability of the restored site control network 105', wherein the one or more messages may include information regarding characteristics of the restored site control network 105'. The network coordinator 120 may initialize the restored site control network 105' by allowing the conveyor system controller 110 to enter the restored site control network 105'. This may be accomplished, for example, by executing a pairing procedure with the conveyor system controller 110 along the lines previously described.
[0073] Aspects of the network coordinator device 120 receiving a list of devices allowed to enter the site control network 105 from the server entity 150 (see box 208a) may include transmitting the list from the server entity 150 to the network coordinator device 120 over a secure connection to ensure confidentiality of the transmitted data, wherein security mechanisms known in the art may be applied to protect data transmitted from the server entity 150 to the network coordinator device 120.
[0074] The aspect of the network coordinator device 120 automatically allowing a device having its device ID on a list of devices allowed to the site control network 105 and knowing the predefined shared secret to enter the restored site control network 105′ (see block 208b) may involve the network coordinator device 120 allowing the device having its device ID on the list via the following steps:
[0075] - verifying at the network coordinator device 120 that the respective device has its device ID on the list of devices allowed into the site control network 105 and that it knows the predefined shared secret; and
[0076] - In response to successful authentication, transmitting a new network link key from the network coordinator device 120 to the respective apparatus, the new network link key enabling communication over the site control network (105) with data encrypted using a predefined shared secret or using an encryption key derived based on the predefined shared secret.
[0077] For clarity, devices attempting to connect to the restored site control network 105' are referred to below as candidate devices. This method for allowing candidate devices to access the restored site control network 105' is applicable to allowing one or more additional devices 130 and the conveyor system controller 110 to access the restored site control network 105'. According to an example, the aforementioned verification process may include the network coordinator device 120 performing a challenge-response authentication with the candidate device according to a predefined process to confirm that the candidate device knows a predefined shared secret. The challenge-response process may also be used to confirm to the candidate device that the network coordinator 120 knows the predefined shared secret, thereby verifying it as the device that truly manages access to the restored site control network 105'. In another example, verification may involve the candidate device signing its device ID with the predefined shared secret and sending the signed device ID to the network coordinator device 120. Successful verification of the signature may indicate successful verification of the candidate device. In this regard, signing and verifying the device ID may be performed using mechanisms known in the art.
[0078] After successfully authenticating the candidate device, the network coordinator device 120 may transmit the new network link key to the candidate device as encrypted data, where the encrypted data may also include other information related to communications through the restored site control network 105' and / or the restored site control network 105'. According to one example, this data transmitted from the network coordinator device 120 to the candidate device may be encrypted using a predefined shared secret, while according to another example, the encryption may be performed using an encryption key derived based on the predefined shared secret. In the latter example, the encryption key may be a device-pair-specific encryption key, and the encryption key may be derived at the network coordinator device 120 and at the candidate device using a predefined process and / or algorithm provided for this purpose.
[0079] Thus, simplified restoration of the site control network 105 according to the operations described with reference to box 208 enables one or more additional devices 130 that were previously allowed to the site control network 105 via the pairing process to be allowed to enter the restored site control network 105' in a secure manner without having to repeat the full pairing process for each of the one or more additional devices 130, thereby avoiding manual work that is both time-consuming and error-prone.
[0080] The security of the admission process according to the operations associated with block 208b may be further enhanced, for example, by taking one or more of the following measures:
[0081] The network coordinator device 120 may be arranged to grant use of each device ID included in the list of devices allowed into the site control network 105 for re-admission only once.
[0082] The network coordinator device 120 may be arranged to grant admission to the restored site control network 105' only during a time period of predefined duration immediately after (immediately after) creation of the restored site control network 105'. In a non-limiting example, the time period may have a duration in the range from a few minutes to a few hours.
[0083] The network coordinator device 120 may be arranged to grant re-admission to the site control network only for a time period of predefined duration initiated by a user input received via a user interface provided for the network coordinator device 120 .
[0084] Each of the above exemplary methods serves to reduce the risk of a malicious party having gained access to both the device ID and the predefined shared secret of some other apparatus 130 - k and attempting to use these pieces of information to access the recovered site control network 105 ′.
[0085] Each of the one or more further devices 130 may be arranged to react to the loss of the site control network 105 in a manner that enables timely re-admission to the restored site control network 105'. Non-limiting examples of this include the following:
[0086] The further devices 130 - k may be arranged to respond to an inability to communicate over the site control network 105 by automatically sending requests to join a network of a similar type to the site control network 105 , wherein these requests may be sent according to a predefined schedule (eg at predefined time intervals).
[0087] The further device 130 - k may be arranged to respond to an inability to communicate over the site control network 105 by sending a request to join a network of a similar type to the site control network 105 in response to receiving a message indicating the availability of such a network.
[0088] In both of the above examples, the automatic transmission of the request may be initiated by the loss of the site control network 105 for a period of time that lasts longer than a predetermined threshold duration.
[0089] Reference above Figure 1 and Figure 2In the described example, both the initial creation of the site control network 105 and its recovery by creating a restored site control network 105′ after a loss of site network configuration data occur at the (same) network coordinator device 120. However, in some cases, a failure resulting in the loss of site network configuration information at the network coordinator device 120 may result in the network coordinator device 120 being replaced with a new network coordinator device, and situations requiring the creation of a restored site control network 105′ may also occur when the network coordinator device 120 is replaced with a new network coordinator device due to hardware and / or software upgrades.
[0090] in this regard, Figure 3 FIG. 1 is a block diagram showing some logical elements of a personnel flow system 100 according to another example, which includes a network coordinator 120 in addition to the network coordinator 120. Figure 1 Specifically, the site control network 105 may initially use the network coordinator 120 ( Figure 1 ), the network coordinator 120 may be replaced by a network coordinator 120′ ( Figure 3 Following the ideas described above for the “original” network coordinator 120, according to one example, the replacement network coordinator 120′ may be implemented in a device separate from the other nodes of the restored site control network 105′, for example, as a replacement network coordinator device (e.g., Figure 3 ), while in another example, the replacement network coordinator 120 ′ may be implemented as an entity of another node of the restored site control network 105 ′, for example, as part of the conveyor system controller 110 .
[0091] also, Figure 4 A method 200' is shown, which is a variation of the method 200, wherein the corresponding operations associated with blocks 202 to 206 of the method 200' are similar to those of the method 200 and can be implemented as described above. In contrast, the corresponding operations associated with block 208' are implemented by the replacement network coordinator 120' (e.g., by a replacement coordinator device) rather than implementing the corresponding operations of block 208 (of the method 200) in the network coordinator device 120.
[0092] Thus, in the method 200′, the replacement network coordinator device 120′ may be introduced into the control system 102 of the human mobility system 100 prior to the operations associated with block 208′, and the operations associated with block 208′ may include the following steps performed at the replacement network coordinator device 120′:
[0093] - Creating a restored site control network 105' at a replacement network coordinator 120' following loss of site network configuration information at the network coordinator (120), said creation comprising:
[0094] o receiving a list of devices allowed to enter the site control network 105 from the server entity 150 (208a), and
[0095] o Automatically allowing a device to enter the restored site control network 105 ′, provided that the device has its device ID included in the received list and knows the corresponding shared secret established between the site network coordinator 120 and a corresponding one of the one or more further devices 130 - k ( 208 b ).
[0096] The examples provided above for implementing the operations of block 208 of method 200 apply mutatis mutandis to the operations of block 208 ′ of method 200 ′, except that these operations are performed by the replacement network coordinator 120 ′ instead of the (original) network coordinator 120 .
[0097] In the example described above, a copy of the list of devices allowed to enter the site control network 105 is transmitted for storage in the server entity 150 and transmitted from the server entity to one of the (original) network coordinator 120 and the replacement network coordinator 120', whichever is used to create the restored site control network 105'. In a corresponding variation of the above example, the list of devices allowed to enter the site control network 105 may be transmitted for storage in and received from another entity to create the restored site control network 105', which may include, for example, the conveyor controller 110. However, this variation does not apply to the case where the network coordinator is provided as an entity of the conveyor system controller 120.
[0098] In accordance with the foregoing, each of the conveyor controller 110, the network coordinator 120, the replacement network coordinator 120', and the one or more additional devices 130 may include or may be provided using one or more computer devices, each computer device including a respective one or more processors, the one or more processors being arranged to execute one or more computer programs to provide at least some aspects of the operation of a respective one of the conveyor controller 110, the network coordinator 120, the replacement network coordinator 120', and the one or more additional devices 130. As an example in this regard, a system composed of Figure 5 The computer device 300 is shown in the block diagram.
[0099] Device 300 includes a processor 310 and a memory 320. Memory 320 can store data and computer program code 325. Device 300 may also include a communication component 330 for wired or wireless communication with other devices and / or user I / O (input / output) components 340. Other devices and / or user I / O components 340 may be arranged, together with processor 310 and a portion of computer program code 325, to provide a user interface for receiving input from a user and / or providing output to a user. In particular, the user I / O components may include user input devices, such as one or more keys or buttons, a keyboard, a touch screen or touchpad, etc. The user I / O components may include output devices, such as a display or touch screen. The components of device 300 are communicatively coupled to each other via a bus 350, which enables the transmission of data and control information between the components.
[0100] The memory 320 and a portion of the computer program code 325 stored therein may be further arranged to, in conjunction with the processor 310, cause the device 300 to perform at least some aspects of the operation of a respective one of the conveyor controller 110, the network coordinator 120, the replacement network coordinator 120′, and the one or more additional devices 130. The processor 310 is configured to read from and write to the memory 320. Although the processor 310 is depicted as a respective single component, it may be implemented as one or more respective separate processing components. Similarly, although the memory 320 is depicted as a respective single component, it may be implemented as one or more respective separate components, some or all of which may be integrated / removable and / or may provide permanent / semi-permanent / dynamic / cached storage.
[0101] The computer program code 325 may include computer-executable instructions that, when loaded into the processor 410, implement at least some aspects of the operation of the conveyor controller 110, the network coordinator 120, the replacement network coordinator 120′, and a corresponding one of the one or more additional devices 130. As an example, the computer program code 425 may include a computer program comprised of one or more sequences of one or more instructions. The processor 310 may load and execute the computer program by reading the one or more sequences of one or more instructions included therein from the memory 320. The one or more sequences of one or more instructions may be configured to, when executed by the processor 310, cause the device 300 to perform at least some aspects of the operation of the conveyor controller 110, the network coordinator 120, the replacement network coordinator 120′, and a corresponding one of the one or more additional devices 130. Thus, the device 300 may include at least one processor 310 and at least one memory 320 including computer program code 325 for one or more programs, the at least one memory 320 and the computer program code 325 being configured to, together with the at least one processor 310, cause the device 300 to perform at least some aspects of the operation of a corresponding one of the conveyor controller 110, the network coordinator 120, the replacement network coordinator 120' and the one or more additional devices 130.
[0102] Computer program code 325 may be provided, for example, as a computer program product including at least one computer-readable non-transitory medium having computer program code 325 stored thereon, which, when executed by processor 310, causes device 300 to perform at least some aspects of the operation of a corresponding one of conveyor controller 110, network coordinator 120, replacement network coordinator 120', and one or more additional devices 130. The computer-readable non-transitory medium may include a memory device, a recording medium, or another article of manufacture tangibly embodying the computer program. As another example, the computer program may be provided as a signal configured to reliably transmit the computer program.
[0103] References to processors herein should not be understood as covering only programmable processors, but also special purpose circuits such as field programmable gate arrays (FPGAs), application specific circuits (ASICs), signal processors, etc. Features described in the preceding description may be used in combinations other than those explicitly described.
Claims
1. A method (200, 200') for managing access to a site control network (105) of a people flow system (101), the people flow system comprising a passenger conveyor system (101) and a conveyor system controller (110), wherein the site control network (105) communicatively couples the conveyor system controller (110) to a network coordinator (120) and one or more further devices (130), the method (220) comprising: allowing (202) the one or more further devices (130) to enter the site control network (105) by the network coordinator (120) via performing a respective pairing procedure with each of the one or more further devices (130) based on a predefined shared secret; adding (204) the corresponding device identifier ID of each additional device (130-k) to a list of devices allowed to enter the site control network (105) by the network coordinator (120); transmitting (206) the list from the network coordinator (120) to an external entity (110, 150) for storage therein; and After site network control information is lost in the network coordinator (120), creating (208, 208') a restored site control network (105') in one of the network coordinator (120) or a replacement network coordinator (120'), the creating (208, 208') comprising: receiving (208a, 208a') the list from the external entity (110, 150); and A device is automatically admitted (208b, 208b') to the restored site control network (105), provided that the device has its device ID included in the list and knows the predefined shared secret.
2. The method (200) according to claim 1, wherein The restoring (208) is performed in the network controller (120).
3. The method (200') according to claim 1, wherein: The restoring (208') is performed in the replacement network controller (120').
4. The method (200, 200') according to any one of claims 1 to 3, wherein: The external entities include an external server entity (150) communicatively coupled to the network coordinator (120) independently of the site control network (105).
5. The method (200, 200') according to any one of claims 1 to 3, wherein The external entity includes the conveyor system controller (110).
6. The method (200, 200') according to any one of claims 1 to 5, wherein: Each device ID included in the list may only be used once to allow entry into the restored site control network (105').
7. The method (200, 200') according to any one of claims 1 to 6, wherein: Re-admission to the restored site control network is granted only during a time period of a predefined duration after creation of the restored site control network (105').
8. The method (200, 200') according to any one of claims 1 to 6, wherein: Re-admission to the restored site control network is granted only during a time period of predefined duration initiated in response to user input received via a user interface provided for a respective one of the network coordinator (120) or the replacement network coordinator (120').
9. The method (200, 200') according to any one of claims 1 to 8, wherein Said permission (202) includes: receiving, at the network coordinator (120) and at the respective other devices (130-k), respective user inputs initiating the pairing procedure; authenticating the respective further device at the network coordinator (120); verifying at the network coordinator (120) that the respective further device knows the predefined shared secret; and In response to successful authentication, a network link key is transmitted from the network coordinator (120) to the corresponding further device (130-k), the network link key enabling communication over the site control network (105) of data encrypted using the predefined shared secret or using an encryption key derived based on the predefined shared secret.
10. The method (200, 200') according to any one of claims 1 to 9, wherein The automatic permission (208b) includes: verifying at the network coordinator (120) that the device has its device ID included in the list and knows the predefined shared secret; and In response to successful authentication, a new network link key is transmitted from the network coordinator (120) to the device, the new network link key enabling communication over the restored site control network (105') with data encrypted using the predefined shared secret or using an encryption key derived based on the predefined shared secret.
11. The method according to any one of claims 1 to 10, wherein The predefined shared secret is pre-stored at the network coordinator (120) and at the one or more further devices (130).
12. An apparatus (120) for managing access to a site control network (105) of a people flow system (101), the people flow system comprising a passenger conveyor system (101) and a conveyor system controller (110), wherein: The site control network (105) communicatively couples the conveyor system controller (110) to the device (120) and one or more additional devices (130), the device (120) being arranged to: allowing the one or more further devices (130) to enter the site control network (105) via performing a respective pairing procedure with each of the one or more further devices (130) based on a predefined shared secret; adding a corresponding device identifier ID of each additional device (130-k) to a list of devices allowed to enter the site control network (105); sending the list to an external entity (110, 150) for storage therein; and Creating a restored site control network (105') after loss of site network control information in the device (120), said creating comprising the device (120) being arranged to: receiving said list from said external entity (110, 150), and Another device is automatically allowed to enter the restored site control network (105), provided that the other device has its device ID included in the list and knows the predefined shared secret.
13. A control system (102) for managing access to a site control network (105) of a people flow system (101), the people flow system comprising a passenger conveyor system (101) and a conveyor system controller (110), wherein: The site control network (105) communicatively couples the conveyor system controller (110) to a network coordinator device (120) and one or more additional devices (130), the control system (102) including: The network coordinator device (120) is arranged to: allowing the one or more further devices (130) to enter the site control network (105) via performing a respective pairing procedure with each of the one or more further devices (130) based on a predefined shared secret, adding the respective device identifier ID of each additional device (130-k) to a list of devices allowed into the site control network (105), and transmitting the list to an external entity (110, 150) for storage therein; and A replacement network coordinator device (120'), the replacement network coordinator device being arranged to create a restored site control network (105') following loss of site network control information in the network coordinator device (120), the creation comprising the replacement network coordinator device (120') being arranged to: receiving said list from said external entity (110, 150); and Another device is automatically allowed to enter the restored site control network (105), provided that the other device has its device ID included in the list and is known to have the predefined shared secret.
14. A computer program comprising computer readable program code configured to cause at least the method according to any one of claims 1 to 11 to be performed when said program code is executed on one or more computing devices.