Elevator system and elevator control method

By introducing a mechanism for acquiring accident information, confirming countermeasures, and setting an update period into the elevator system, the problems of flexibility in responding to safety accidents in the elevator system and the impact on the operating rate are solved, thus achieving safe and efficient operation of the elevator system.

CN120646626APending Publication Date: 2025-09-16HITACHI LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202411724392.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2024-03-13
Filing Date
2024-11-28
Publication Date
2025-09-16

AI Technical Summary

Technical Problem

Existing technologies cannot effectively deal with safety accidents in elevator systems, especially external attacks, and it is difficult to implement unified control program corrections without affecting the operating rate.

Method used

The accident information acquisition unit, countermeasure confirmation unit, equipment update determination unit, and update period setting unit are used to obtain accident information, confirm countermeasures, determine the equipment that needs to be updated, and set the implementation period of the accident countermeasures based on the elevator's structural information and operating conditions.

Benefits of technology

It can quickly and appropriately respond to safety accidents in the elevator system, identify the parts related to the accident and implement corrective measures, ensuring that the elevator takes safety measures at the appropriate time and reducing the impact on the operating rate.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120646626A_ABST
    Figure CN120646626A_ABST
Patent Text Reader

Abstract

The invention relates to an elevator system and an elevator control method. Accident countermeasures for elevators such as elevators can be appropriately taken. The elevator control system is provided with: an accident information acquisition unit (59) that acquires accident information for an elevator; a countermeasure confirmation unit (54) that confirms countermeasures for the accident information acquired by the accident information acquisition unit (59); an updated equipment determination part (56) which determines updated equipment of the elevator requiring accident countermeasures according to the countermeasures confirmed by the countermeasure confirmation part (54); and an update time setting unit (58) that sets the implementation time of the accident countermeasures of the update equipment on the basis of the configuration information and the operating condition of the elevator.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an elevator system and an elevator control method. Background Art

[0002] Elevator and other lift control systems communicate with control centers via telephone lines or dedicated lines. Computer-based control systems are susceptible to unauthorized attacks via these lines. Therefore, like conventional computers, elevator and other lift control systems require countermeasures against unauthorized attacks and other incidents.

[0003] Patent Document 1 describes a technique for managing setting information for accidents in an elevator. Patent Document 1 describes a technique for calculating recommended settings of elevator setting information included in elevator attribute information based on accident information and elevator attribute information.

[0004] Prior art literature

[0005] Patent Document 1: Japanese Patent No. 5558194 Summary of the Invention

[0006] Problems to be solved by the invention

[0007] According to the technology described in Patent Document 1, it is possible to provide evaluation of parameters and recommended parameter values ​​for accidents, namely, failures.

[0008] However, sometimes it's not possible to address an incident simply by changing configuration information. For example, security incidents, such as external attacks, cannot be addressed by changing configuration information. In security incidents, there's a problem where it's unclear what hardware or software modifications are required when the incident occurs.

[0009] Furthermore, the technique described in Patent Document 1 does not mention the timing of applying the recommended setting value to the elevator system. Elevator systems are always in operation, so it is difficult to apply a correction program to the control program as an accident countermeasure to all elevator systems simultaneously.

[0010] Furthermore, elevators have various optional features, not just the number of floors. Therefore, even standard control functions can vary significantly depending on the installation and operating environment. Therefore, implementing uniform accident countermeasures is likely to significantly impact the operating rate in these environments, particularly in terms of operation.

[0011] In view of this, an object of the present invention is to provide an elevator system and an elevator control method that can appropriately take measures to deal with accidents of elevators such as elevators.

[0012] Means for solving problems

[0013] In order to solve the above-mentioned problems, for example, the configuration described in the claims is adopted.

[0014] The present application includes multiple means for solving the above-mentioned problems. If one example is cited, as an elevator control system, it has: an accident information acquisition unit, which acquires accident information; a countermeasure confirmation unit, which confirms the countermeasures for the accident information acquired by the accident information acquisition unit; an updated equipment determination unit, which determines the updated equipment of the elevator that requires accident countermeasures based on the countermeasures confirmed by the countermeasure confirmation unit; and an update period setting unit, which sets the implementation period of the accident countermeasures for the updated equipment based on the structural information and operating conditions of the elevator.

[0015] Effects of the Invention

[0016] According to the present invention, when an accident occurs in an elevator system, it is possible to extract the parts related to the accident, determine the correction measures for the determined parts, and then determine the application period of the accident countermeasures based on the structural information and operating conditions of the corresponding elevator.

[0017] Other problems, structures, and effects than those described above will become clear from the following description of the embodiments. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] Figure 1 This is a diagram showing an example of the overall configuration of an elevator system according to an embodiment of the present invention.

[0019] Figure 2 This is a block diagram showing a hardware configuration example of a controller included in an elevator system according to an embodiment of the present invention.

[0020] Figure 3 This is a diagram showing an example of a software configuration implemented in an elevator system according to an example embodiment of the present invention.

[0021] Figure 4 This is a block diagram showing the functional configuration of an elevator system according to an example embodiment of the present invention.

[0022] Figure 5 This is a diagram showing an example of accident information according to an embodiment of the present invention.

[0023] Figure 6 This is a diagram showing an example of a security database according to an embodiment of the present invention.

[0024] Figure 7 This is a diagram showing an example of a shipped product database according to an embodiment of the present invention.

[0025] Figure 8 This is a flowchart showing an example of accident response processing according to one embodiment of the present invention.

[0026] Figure 9 This is a flowchart showing an example of category extraction processing according to one embodiment of the present invention.

[0027] Figure 10 This is a diagram showing an example of an accident response state according to an embodiment of the present invention.

[0028] Figure 11 This is a flowchart showing an example of the correspondence confirmation process according to one embodiment of the present invention.

[0029] Figure 12 This is a flowchart showing an example of device update determination processing according to one embodiment of the present invention.

[0030] Figure 13 This is a flowchart showing an example of update time setting processing according to one embodiment of the present invention.

[0031] Figure 14 This is a diagram showing an example of an update condition table according to an embodiment of the present invention.

[0032] Figure 15 This is a flowchart showing an example of correction confirmation processing according to one embodiment of the present invention.

[0033] Figure 16 This is a diagram showing an example of a correction confirmation state according to an embodiment of the present invention.

[0034] Figure 17 This is a flowchart showing an example of the operation control process (during normal operation) according to one embodiment of the present invention.

[0035] Figure 18 This is a flowchart showing an example of the operation control process (an example of the process during a late-night stop) according to one embodiment of the present invention.

[0036] Figure 19 This is a flowchart showing an example of the operation control process (when date and time are specified) according to one embodiment of the present invention.

[0037] Figure 20 This is a flowchart showing an example of the operation control process (an example of the process at a designated date and time) according to one embodiment of the present invention.

[0038] Figure 21 This is a block diagram showing the functional configuration of an elevator control system according to a modified example of one embodiment of the present invention. DETAILED DESCRIPTION

[0039] Hereinafter, an elevator system and an elevator control method according to an embodiment of the present invention (hereinafter referred to as "this embodiment") will be described with reference to the accompanying drawings. In this embodiment, an elevator system applied to an elevator will be described as an example of an elevator.

[0040] [Example of overall structure of elevator system]

[0041] Figure 1 The following shows an example of the structure of the elevator system of this embodiment. Figure 1 In the example of FIG, for simplicity of description, the structure of one elevator 15 is shown, but a plurality of elevators 15 are provided.

[0042] The elevator 15 is operated under the control of the group control controller 4 and the elevator controller 5 constituting the elevator system.

[0043] That is, the elevator controller 5 controls the motor 6 to control the movement of the rope 9 connecting the car 7 and the counterweight 8. Furthermore, the elevator controller 5 realizes the up and down movement and the stop of the car 7, and provides the user with an up and down service.

[0044] The elevator controller 5 is connected to one car controller 10 and a plurality of floor controllers 11 via a communication path 12. The communication path 12 is a 1-to-N or N-to-N (N is an arbitrary integer) multi-drop communication device.

[0045] The car controller 10 is connected to an operating panel 13 that manages the destination floor buttons and door opening and closing buttons installed in the car 7. The car controller 10 also monitors the user's button operation status and transmits the operation status to the elevator controller 5. The floor controller 11 also includes a destination floor reservation system in place of the up and down buttons 14, which allows users to register any professional department in advance.

[0046] The group control controller 4 is connected to the plurality of elevator controllers 5 via a communication path 16. The communication path 16 is a 1-to-N multipoint communication device.

[0047] The plurality of elevators 15 are grouped together into an elevator group 18 which is a controller that performs operation management.

[0048] The center 1 is connected to a communication controller 3 via a communication path 2. For example, a mobile closed network such as a dedicated line or a public line such as the Internet is used as the communication path 2. The communication controller 3 is responsible for performing communication between the center 1 and the elevators for data transmission, remote maintenance, and remote operation.

[0049] Because a plurality of elevator groups 18 are required depending on the building, the communication controller 3 is connected to a plurality of group management controllers 4 via a communication path 17. The communication path 17 is a 1-to-N multipoint communication device.

[0050] The elevator system of this example also includes a maintenance terminal 20 for maintenance work on the controllers 3, 4, 5 and the communication paths 12, 16, and 17. The maintenance terminal 20 is connected to a maintenance port mounted on the board of the group control controller 4 and the communication paths 12, 16, and 17 to operate the maintenance object.

[0051] Furthermore, a management terminal 19 is connected to the communication path 17. The management terminal 19 is installed in, for example, a management department of a building where an elevator system is installed, and manages the operating status of the elevators.

[0052] [Controller hardware structure]

[0053] Figure 2 express Figure 1 The hardware configuration examples of the controllers 3, 4, 5, 10, and 11 are shown.

[0054] That is, the communication controller 3, the group management controller 4, the elevator controller 5, the car controller 10, and the floor controller 11 are composed of computers. Figure 2 In the present invention, they are collectively referred to as controller 30.

[0055] Controller 30 includes an MPU (Micro Processing Unit) 31, also known as a microcomputer, connected to a system bus 35; a ROM (Read Only Memory) 32; a RAM (Random Access Memory) 33; and a communication interface 34. There are also microcontrollers (MCUs) similar to MPUs. The higher-level concepts of MCUs and MPUs include a CPU (Central Processing Unit).

[0056] Firmware 40, which is a binary image of program code that implements the various functions of this example, is stored in ROM 32. In firmware 40, MPU 31 reads the program code from ROM 32, loads it into RAM 33, and executes the loaded program code. Alternatively, firmware 40 may directly read the program code from ROM 32 and execute it directly.

[0057] Variables, parameters, and the like generated during the execution of processing in the MPU 31 are temporarily written into the RAM 33 , and these variables, parameters, and the like are read out from the MPU 31 as appropriate.

[0058] Furthermore, when a non-volatile RAM such as NVRAM (Non-Volatile Random Access Memory) is used as the RAM 33 , data may be stored in the RAM 33 .

[0059] The controller 30 transmits and receives data via the communication interface 34 via a communication path (network) connecting the controllers.

[0060] As a communication path, for example, a multi-point serial communication device such as RS-485 can be used. Furthermore, wired communication paths that provide multiple topologies such as Ethernet (registered trademark), namely LAN (Local Area Network) and WAN (Wide Area Network), can also be used as a communication path. Alternatively, wireless communication paths such as RAN (Radio Area Network) and Wi-Fi (registered trademark), or infrastructure wireless communication can also be used as a communication path.

[0061] The network configuration based on the communication path described here is an example, and various network configurations can be applied to the system of this example.

[0062] [Software Structure]

[0063] Figure 3 The structure of the firmware 40 which is software installed in the controller 30 constituting the elevator system is shown.

[0064] Firmware 40 can be broadly classified as consisting of a program 41 for the elevator controller 5 that controls the operation of the elevator 15, and an operating system 42 (OS) for managing and controlling the hardware of the controller 30. Furthermore, firmware 40 is comprised of various libraries 43 utilized by program 41 and device drivers 44 used by OS 42 to control arbitrary devices.

[0065] The elevator control program 41 is composed of a standard program 45 for controlling the elevator 15, an option program 46 for option control, and an order program 47 for responding to specifications that differ depending on the shipped product.

[0066] The standard program 45 of the elevator 15 can be roughly classified into an operation control program 48 and a safety control program 49. These programs are modularized and subdivided according to the control content, etc. The management of the combination of these subdivided modules is called structure management.

[0067] In addition, there are cases where a ROM monitor or simple task management is used instead of an OS.

[0068] Figure 4This shows the functional structure from the perspective of processing performed by the elevator system.

[0069] The elevator 15 generates information related to the malfunction occurring in the equipment as the accident information 50. The accident information acquisition unit 59 acquires the generated accident information 50.

[0070] The accident information 50 includes at least the error code and the time when the fault occurs, which are determined when the firmware 40 of the controller 30 is designed. In addition, the accident information 50 is sometimes generated by the relevant personnel 51 such as the manager and maintenance personnel of the elevator 15 and the user of the elevator 15. Figure 5 Described in detail.

[0071] The security database 60 is composed of a vulnerability information database 64 , a countermeasure information database 66 , and a security incident information database 62 .

[0072] The vulnerability information database 64 manages vulnerability information 68 .

[0073] The countermeasure information database 66 manages information on countermeasures corresponding to vulnerabilities.

[0074] The safety incident information database 62 manages the relationship between vulnerabilities and countermeasures corresponding to the firmware 40 , which is a set of hardware and software constituting the controller 30 of the elevator 15 .

[0075] The vulnerability information 68 includes, for example, public information managed by a system such as CVSS (Common Vulnerability Scoring System) and private information specific to the elevator 15. The vulnerability information 68 may also express the severity of the vulnerability as a score.

[0076] The countermeasure information 66 includes information on correction codes and so-called patch codes for alleviating or eliminating the problem. If there is no patch code, the countermeasure information 66 may include, for example, avoidance measures and avoidance procedures.

[0077] The shipped product database 70 is composed of an operation information database 72 , a configuration information database 74 , and a countermeasure schedule database 76 .

[0078] The operation information database 72 manages the operation status corresponding to the elevator 15 and the operation information transmitted from the elevator 15 .

[0079] The structure information database 74 is managed in Figure 3 The various components constituting the firmware 40 are described in .

[0080] The countermeasure schedule database 76 manages a schedule for implementing countermeasures based on the operation information of each elevator 15 in accordance with the accident information 50 .

[0081] In addition, there is sometimes also structure management for each hardware that constitutes the elevator system. Figure 7 Described in detail.

[0082] The category extraction unit 52 extracts the accident information 50 .

[0083] The countermeasure confirmation unit 54 extracts security incident information 62 from the security database 60 corresponding to the extracted hardware or software component. The security incident information 62 is also referred to as a security incident information database 62. For other information, the database and the information may be denoted by the same reference numerals.

[0084] The security incident information 62 extracted from the security incident information database 62 is associated with the vulnerability information 68 in the corresponding vulnerability information database 64 and the countermeasure information 66 in the countermeasure information database 66 for alleviating or eliminating the vulnerability indicated by the vulnerability information 68 , and is managed by the security database 60 .

[0085] The update device determination unit 56 determines the product corresponding to the product number from the configuration information database 74 of the shipped product database 70 that manages the information of each product number. Figure 12 is described in .

[0086] The update period setting unit 58 sets the period for applying the countermeasures for the vulnerability based on the pre-set conditions. Figure 13 and Figure 14 is described in .

[0087] With the above configuration, information related to security is managed by the security database 60. Information related to shipped products is managed by the shipped product database 70. In this example, by managing security information and shipped product information in a coordinated manner, appropriate security measures can be taken.

[0088] That is, the elevator 15 utilizes different information such as shipping products with different internal structures and shipping products with the same internal structure but different operating conditions, and thus can implement appropriate measures at appropriate timing for each elevator 15 as safety measures.

[0089] [Accident Information]

[0090] Figure 5 Indicates accident information 50 when a fault occurs.

[0091] Accident information 50 consists of an identification number 151 for identifying the occurrence of the fault, a product number 152 assigned to the elevator 15 and its internal controller, an error code 153 issued by the elevator system, the elevator status 154, and a category 155 indicating the location of the fault. The identification number 151 is issued when the accident information 50 arrives at the center 1.

[0092] The category 155 is divided into a controller category 200 and a controller internal structure category 210 .

[0093] The controller type 200 is classified into communication 201 corresponding to the communication controller 3 , group management 202 corresponding to the group control controller 4 , elevator 203 corresponding to the elevator 15 , car 204 corresponding to the car controller 10 , and floor 205 corresponding to the floor controller 11 .

[0094] The structure category 210 is classified into an operation control 211 corresponding to the operation control program 48, a security control 212 corresponding to security control, an option 213 corresponding to an option, an order 214 corresponding to an order, an OS 215 corresponding to an OS, a library 216 corresponding to a library, and a device driver 217 corresponding to a device driver. All of these are information contained within the firmware 40.

[0095] By configuring the accident information 50 in this manner, it is possible to collect information on the elevator 15 necessary for identifying the cause of a problem and to associate it with safety accident information described later. The relationship between the error code 153 and the category 155 is managed by the safety accident information database 62 described later.

[0096] The accident information 50 is sometimes generated by the elevator 15, and sometimes issued by a person related to the elevator 15, such as a maintenance person or a user. When the elevator 15 is operating alone, it is not connected to the center 1, so the accident information 50 is issued by the latter person 51 related to the elevator.

[0097] [Structure of the security database]

[0098] Figure 6 The structure of the security database 60 is shown.

[0099] The vulnerability information database 64 within the security database 60 includes at least vulnerability numbers 80, category information 155 associated with the vulnerability, and patches, workarounds, and mitigation measures 81 corresponding to the vulnerability. An example of vulnerability number 80 is a CVE (Common Vulnerabilities and Exposures) (registered trademark) number managed by CVSS. Alternatively, product development departments may have their own unique managed numbers.

[0100] A patch is code that corrects a vulnerability. Furthermore, even if a vulnerability is identified, patches / avoidance and mitigation measures 81 may not be created. Furthermore, patches / avoidance and mitigation measures 81 may be updated or deprecated depending on the content of the mitigation measures, and are generally assigned version numbers corresponding to these changes.

[0101] The safety accident information 62 in the safety database 60 includes at least a safety accident number 82, an error code 153 output by the firmware 40, a status 154 of the elevator system associated with the error code 153, a category 155 associated with the error code 153, and a countermeasure number 86 corresponding to the accident.

[0102] The countermeasure information database 66 includes at least a countermeasure number 86 , a vulnerability number 80 , and a countermeasure history 89 .

[0103] By configuring the safety database 60 in this manner, it is possible to collectively manage the relationship between the error code and the state of the elevator system by identifying vulnerabilities and countermeasures, and identifying malfunctions as accidents, using countermeasure information.

[0104] [Structure of the shipped product database]

[0105] Figure 7 The structure of the shipped product database 70 is shown.

[0106] The shipped product database 70 is a database for managing product information 90 associated with each elevator.

[0107] The operation information database 72 stores and manages the dynamic information of the elevator 15, such as the operation and stop at the current time point, the car position, the stop floor number, the number of people in the car, and the opening and closing status of the car door, as operation information 100.

[0108] The operation information database 72 also stores the number of times 101 various control programs constituting the firmware 40 are operated within a predetermined time, and frequency information 102 of the control programs based on predetermined criteria, such as high frequency / low frequency / unused.

[0109] The configuration information database 74 stores and manages various configuration information 110 of the elevator 15 for each shipped product.

[0110] For example, the configuration information database 74 manages configuration and version information 111 of the standard program 45 common to the programs of the elevator 15 and manages configuration and version information 112 within the operation control program 48 .

[0111] Furthermore, the configuration information database 74 manages the internal configuration and version information 113 of the security control program 49 .

[0112] Furthermore, the configuration information database 74 manages configuration and version information 114 of the library 43 used by the program 41 of the elevator 15 .

[0113] The configuration information database 74 also manages the configuration and version information 115 within the OS 42 and the configuration and version information 116 of the device driver 44 corresponding to the device controlled by the OS 42 .

[0114] Furthermore, the configuration information database 74 manages order information 117 corresponding to each customer's request and option information 118 indicating a function selected from the optional functions.

[0115] In addition, although the example here is to assign a version to each component, the present invention is not limited to this. For example, there is also a case where the OS 42, the library 43, and the device driver 44 are collectively assigned a version.

[0116] The countermeasure schedule database 76 stores and manages countermeasure timing 121 for vulnerabilities of shipped products and countermeasure implementation history 128, which serves as countermeasure schedule information 120. Countermeasure timing 121 can be any of immediate 122, regular inspection 123, postponement to an arbitrary date and time 124, standby 125 when no countermeasure is available, and completion 126.

[0117] The immediate time 122 does not mean that the elevator 15 is stopped immediately, but rather means a time to minimize the influence on the operation of the elevator 15 and to ensure that countermeasures can be implemented safely.

[0118] The history 128 may also be installed as a list consisting of the date and time when the countermeasure was implemented, and the version of the patch / avoidance and mitigation measures 81.

[0119] In this way, the operating status of the elevator 15 is grasped based on the shipped product database 70, and the structural elements that may cause safety accidents are managed. This allows management of the scheduling and history of countermeasure implementation according to the unique operating status of the elevator.

[0120] [Handling of incidents]

[0121] Figure 8 and Figure 9 This is a flowchart showing an example of processing when a malfunction occurs. Figure 8 and Figure 9 The example of is an example of handling when the accident is a known safety accident and a countermeasure exists.

[0122] First, if Figure 8 As shown, the center 1 receives the accident information 50 (step S10). Next, the category extraction unit 52 extracts the category information 155 from the accident information 50 (step S11).

[0123] Then, the countermeasure confirmation unit 54 searches the security accident information database 62 for security accident information corresponding to the error code 153 , status information 154 , and type information 155 of the accident information 50 (step S12 ).

[0124] The countermeasure confirmation unit 54 confirms whether or not there is an accident through the search in step S12 (step S13 ).

[0125] If there is relevant safety accident information in step S13 (Yes in step S13), the updating device determination unit 56 determines the target elevator 15 (step S13). Then, the updating time setting unit 58 determines the updating time corresponding to each target elevator 15 (step S14).

[0126] If no corresponding security incident information is found in step S13 (No in step S13), the updated device determination unit 56 registers the security incident information in the security incident information database 62 (step S15). In this case, the updated device determination unit 56 reassigns the vulnerability number 80 and updates the vulnerability information database 64 with the patch / avoidance and mitigation measures 81 empty.

[0127] Thereafter, in step S14, the update time setting unit 58 determines an update time corresponding to each target elevator 15.

[0128] Figure 9 The processing of the category extraction unit 52 is shown.

[0129] The category extraction unit 52 searches the safety accident information database 62 for the error code 153 described in the accident information 50 (step S16 ), and determines whether the error code 153 exists (step S17 ).

[0130] If the error code 153 exists in step S17 (YES in step S17 ), the category extraction unit 52 searches for the category 155 having the error code 153 (step S18 ), and determines whether the category 155 exists (step S19 ).

[0131] If the category 155 exists in step S19 (YES in step S19 ), the category extraction unit 52 extracts the category 155 and stores it (step S20 ).

[0132] If there is no category 155 in step S19 (No in step S19 ), the category extraction unit 52 ends the extraction of categories.

[0133] In addition, in step 17, when the error code 153 is not recorded in the accident information 50 (No in step S17), or when the error code 153 does not exist even if a search is performed, the category extraction unit 52 stores the category 155 recorded in the accident information 50 (step S21) and ends the extraction process.

[0134] By setting the incident response process in this manner, when a security incident occurs, the category extraction unit 52 can classify the incident into known vulnerabilities with countermeasures, known vulnerabilities with no countermeasures, and unknown vulnerabilities, and respond accordingly.

[0135] [Example of accident response (known: there is a correction method)]

[0136] Figure 10 This section shows an example of incident response when an undesirable situation occurs and a corresponding strategy is in place.

[0137] Should Figure 10 The example is a case where the elevators 15 are the first elevator, the second elevator, and the third elevator. Figure 10 In the figure, a, b, and c after the reference numerals represent information of the first elevator, the second elevator, and the third elevator, respectively.

[0138] Figure 10 A in the table indicates that the update period has been set.

[0139] The frequency information 102 of each elevator 15 in the operation information database 72 is set as high frequency 102a, unused 102b, and low frequency 102c. Here, for example, the correspondence between the frequency information 102 and the countermeasure timing 121 is set in advance.

[0140] Furthermore, the countermeasure timing information 121 a , 121 b , and 121 c of each elevator 15 in the countermeasure schedule database 76 is set to immediate 122 , postponed 124 , and periodic inspection 123 .

[0141] According to such countermeasure timing information 121a, 121b, and 121c, the instant 122 of the first elevator becomes the fastest countermeasure implementation.

[0142] Figure 10 B in FIG. 1 represents the state at the time when the countermeasure of instant 122 is applied to the first elevator.

[0143] Since the immediate countermeasure application has been implemented for the first elevator, the countermeasure timing information 121a is set to completion 126. As the countermeasure implementation history information 128a, immediate 122 is recorded.

[0144] The countermeasure timing information 121b of the second elevator maintains the extension 124. In addition, since no countermeasure has been implemented, the history information 128b is blank (-).

[0145] Similarly, the countermeasure timing information 121c of the third elevator maintains the periodic inspection 123. In addition, since no countermeasure has been implemented, the history information 128c is blank (-).

[0146] Figure 10 C in the figure represents a state in which the same safety accident occurs (occurs again).

[0147] Since the status is immediately applied, the countermeasure timing information 121a, 121b, and 121c of each elevator 15 indicates completion 126 for the first elevator, postponement 124 for the second elevator, and regular inspection 123 for the third elevator.

[0148] Therefore, in order to implement a countermeasure for the elevator 15 to which the countermeasure is not applied, the countermeasure timing information 121b of the second elevator is reset to the immediate 122. Similarly, the countermeasure timing information 121c of the third elevator is reset to the immediate 122.

[0149] [Countermeasure confirmation and processing]

[0150] Figure 11 This is a flowchart showing the process of confirming whether there is a countermeasure when a problem occurs.

[0151] First, the countermeasure confirmation unit 54 searches the security incident information database 62 for the category 155 and the error code 153 (step S30 ), and determines whether there is a search result (step S31 ).

[0152] If there is a search result in step S31 (Yes in step S31), the countermeasure confirmation unit 54 searches the countermeasure information database 66 based on the countermeasure number 86 in the search result (step S32) and determines whether there is countermeasure information (step S33). If there is countermeasure information in step S33 (Yes in step S33), the countermeasure confirmation unit 54 searches the vulnerability information database 64 based on the vulnerability number 80 in the search result (step S34) and determines whether there is vulnerability information (step S35).

[0153] If vulnerability information exists in step S35 (YES in step S35), the countermeasure confirmation unit 54 compares the original category 155 with the search result category 155 (step S36) and determines whether they match (step S37). If the comparison result in step S37 matches (YES in step S37), the countermeasure confirmation unit 54 checks whether the patch / avoidance and mitigation measures 81 are stored (step S38).

[0154] Then, if there is no information or if there is no match in each of steps S31 , S33 , S35 , and S37 (No in steps S31 , S33 , S35 , and S37 ), the countermeasure confirmation unit 54 ends the countermeasure confirmation process.

[0155] By performing such a countermeasure confirmation process, when a security incident occurs, the countermeasure confirmation unit 54 can confirm the vulnerability information corresponding to the security incident and whether or not a countermeasure exists for the information.

[0156] [Update device decision processing]

[0157] Figure 12 This is a flowchart showing a process for applying a countermeasure to determine a device to be updated when a malfunction occurs.

[0158] First, the updated device determination unit 56 searches the structural information database 74 for the elevator 15 and internal controller with the product number 152 whose structural information 110 matches the structural type 210 of the accident information 50 (step S40), and determines whether there is one (step S41).

[0159] When the search result exists in the determination of step S41 (YES in step S41 ), the updated device determination unit 56 stores the corresponding product number 152 in, for example, a search result list (step S42 ).

[0160] If there is no search result in step S41 (No in step S41 ), the update device determination process ends.

[0161] By executing such an update device determination process, when a security incident occurs, the update device determination unit 56 can extract shipped products related to the security incident.

[0162] [Update time setting process]

[0163] Figure 13 Flowchart and Figure 14 The update condition table shows the process of determining the update period of the update target device selected in Example 11 when a malfunction occurs.

[0164] exist Figure 12 When a device is determined in the process shown, the update time setting unit 58 selects the update condition table 130 ( Figure 14 ) to retrieve the update conditions (step S50).

[0165] like Figure 14As shown, the update table 130 sets conditions for each category. Update conditions are set for each of the options 137, order 138, operation control 132, security control 131, library 134, OS 135, and device driver 136.

[0166] The options 137, orders 138, operation control 132, and safety control 131 are independently developed, and conditions are evaluated using predetermined error codes, frequency thresholds, and number thresholds.

[0167] Furthermore, the category for functions requiring immediate countermeasures is "Immediate." In this example, security control 131 related to security is set to "Immediate." Libraries 134, OS 135, and device drivers 136 may be commercially available or developed by third parties, such as open source. Therefore, severity information based on the CVE can be utilized. In this case, in addition to frequency and count thresholds, conditional evaluation based on severity can also be performed.

[0168] Return to Figure 13 The update time setting unit 58 evaluates the update condition as the search result (step S51). Then, the update time setting unit 58 updates the countermeasure schedule database 76 based on the evaluation result (step S52).

[0169] In addition, when the system of this example is operated by a single elevator 15, since it is not connected to the center 1, the update time setting unit 58 cannot confirm the operating status. In this case, the update time setting unit 58 uses another update condition table 140 to determine the update time. Figure 5 The controller type 200 and the structure type 210 described above represent arbitrary structural elements of the elevator 15. Furthermore, the update condition table 140 is configured to provide predetermined update periods, such as immediate and periodic inspections, in accordance with the error codes 53 associated with the structural elements.

[0170] Furthermore, in the elevator system of this example, the conditional settings described so far are merely examples, and other setting conditions may be employed. Specifically, the update period is preferably set based on the operating status of the updated equipment, the importance of the updated equipment, and the severity of the accident. However, any of these requirements may be omitted depending on the circumstances.

[0171] In this way, by combining the type of the structural element of the elevator 15 and the condition of the error code assigned to the structural element, it is possible to set the update time according to the structure and operation status of each elevator 15.

[0172] [Correction confirmation process]

[0173] Figure 15This is a flowchart showing an example of processing when a policy for coping with a vulnerability of the present invention is completed.

[0174] The countermeasure confirmation unit 54 registers the created countermeasure, i.e., patch / avoidance and mitigation measure 81, in the vulnerability information database 64 and updates the database (step S60). The countermeasure confirmation unit 54 then searches the countermeasure information database 66 for the countermeasure number 86 corresponding to the updated vulnerability number 80 (step S61).

[0175] Then, the countermeasure confirmation unit 54 searches the countermeasure schedule information 120 corresponding to the countermeasure number 86 from the countermeasure schedule database 76 (step S62 ), and determines whether the countermeasure schedule information 120 exists (step S63 ).

[0176] If there are any search results in step S63 (YES in step S63), the action confirmation unit 54 confirms that the action timer 121 of the action schedule information 120 is set to standby (step S64). The update time setting unit 58 then performs the update time setting process described above, sets the update time again (step S65), and returns to the action schedule number search in step S62.

[0177] If there are no search results in step S63 (No in step S63 ), the countermeasure confirmation unit 54 ends the correction confirmation process.

[0178] By executing such a correction confirmation process, the update period setting unit 58 can reset the update period according to the structure and operating status of each elevator when the preparation of the response policy is completed for a case that is in a standby state due to the absence of a response policy for vulnerability.

[0179] [Correction Confirmation Status]

[0180] Figure 16 Indicates an example of the modification confirmation status. Figure 16 Examples with Figure 10 Similarly, in the example of , there are three elevators 15 , namely, a first elevator, a second elevator, and a third elevator. The a, b, and c after the reference numerals represent information of the first elevator, the second elevator, and the third elevator, respectively.

[0181] Figure 16 A in the table indicates a state where a countermeasure for a vulnerability has not yet been determined.

[0182] The frequency information 102 of each elevator 15 in the operation information database 72 is high frequency 102a, unused 102b, and unused 102c. Since there is no corresponding strategy, the countermeasure timing information 121a, 121b, and 121c of each elevator 15 in the countermeasure schedule database 76 is in standby 125.

[0183] Figure 16 B in FIG. 1 represents an update status of the countermeasure schedule when the countermeasure is determined.

[0184] The frequency information 102 of each elevator 15 in the operation information database 72 is high frequency 102c, unused 102b, and low frequency 102c. The third elevator 15 is an example of an elevator that has changed from unused to low frequency 102c due to the operation of the vulnerable object during the period until the countermeasure is completed.

[0185] Thus, the countermeasure timings 121 a , 121 b , and 121 c are immediate 122 , delayed 124 , and periodic check 123 .

[0186] In this way, when the creation of the countermeasure action for the vulnerability is completed, the countermeasure schedule database 76 can be quickly updated.

[0187] [Example of operation control]

[0188] Next, according to the countermeasure schedule information 120, refer to Figures 17 to 20 The following describes the adjustment process for the operation control of the elevator 15. The adjustment process for the operation control of the elevator 15 is executed, for example, by the group control controller 4 based on the countermeasure schedule information 120 created by the center 1. Instead of the group control controller 4, an individual elevator controller 5 may be used.

[0189] Figure 17 This is a flowchart showing an example of a case where an update is performed immediately.

[0190] Figure 17 The example is a process for quickly applying a countermeasure when the countermeasure timing 121 in the countermeasure schedule information 120 is set to immediate 122 .

[0191] First, the group control controller 4 performs an operation prediction of the target elevator 15 (step S70). Then, based on the prediction result of the operation in the near future, the group control controller 4 secures an update time for applying the patch 81 serving as a countermeasure (step S71).

[0192] For example, the group management controller 4 secures an update time period based on a time period when the operation of the elevators 15 is predicted to be low or stopped. The update time for applying the patch 81 includes the download time of the patch 81 and the time for reflecting the patch 81 on the firmware 40.

[0193] Then, the group management controller 4 determines whether the countermeasure time has been secured (step S72).

[0194] If the update time is available in step S72 (Yes in step S72), the group control controller 4 or the elevator controller 5 downloads the patch 81 that serves as the solution (step S73). The elevator 15 temporarily stops operating after the update time period arrives (step S74). The group control controller 4 or the elevator controller 5 then applies the downloaded solution (step S75). After the solution is complete, the elevator 15 resumes operation (step S76).

[0195] If the update time cannot be secured in step S72 (No in step S72), the group management controller 4 determines whether retry is permitted within a preset number of times (step S77).

[0196] In step S77 , if the number of retries is within the permitted number (“permit” in step S77 ), the group management controller 4 waits for a preset time (step S78 ), and then returns to the process of step S70 .

[0197] In step S77, if the number of allowed retries has been exceeded ("exceeded" in step S77), the group management controller 4 changes the setting to postponement and ends the process (step S79). Here, the postponement is, for example, until midnight.

[0198] By executing such processing, the group control controller 4 can implement measures against vulnerabilities that minimize the impact on the operation of the elevator 15 when the immediate 122 is set. In addition, if the update time cannot be guaranteed during normal operation, the operation can be postponed until late at night when the operation is almost stopped. This allows the group control controller 4 to cope with situations where updates cannot be performed during the day.

[0199] Figure 18 This is a flowchart showing an example of a case where an update is performed at a set time (here, late at night).

[0200] When the preset midnight time period comes, the group management controller 4 downloads the patch 81 as a countermeasure (step S80 ).

[0201] Then, the group management controller 4 checks the stop state of the elevator 15 (step S81), and determines whether the elevator 15 is currently stopped (step S82).

[0202] If it is determined in step S82 that the elevator 15 is stopped (Yes in step S82), the group control controller 4 applies the patch 81 downloaded in step S80 (step S84). When the application of the countermeasure is completed, the group control controller 4 restarts the operation of the corresponding elevator 15 (step S85).

[0203] If it is determined in step S82 that the system is in operation (No in step S82 ), the group management controller 4 waits for a preset time (step S83 ) and repeats the process from step S81 .

[0204] Figure 19 This is a flowchart showing an example of a case where an update is performed at a designated date and time.

[0205] First, the center 1 specifies the date and time when the countermeasure is to be applied (step S90 ). The date and time when the countermeasure is to be applied may be remotely set from the management terminal 19 .

[0206] When the date and time for applying the countermeasure is set, the group management controller 4 reserves and secures the corresponding date and time as the update operation time during the operation process (step S91 ), and determines whether the reservation is successful (step S92 ).

[0207] If the assurance is successful in step S92 (YES in step S92 ), the group management controller 4 or the elevator controller 5 downloads the patch 81 serving as a countermeasure (step S93 ).

[0208] If the assurance is unsuccessful in step S92 (No in step S92), the group management controller 4 updates the countermeasure schedule as a regular inspection (step S94).

[0209] When the guaranteed date and time arrives, the group control controller 4 temporarily stops the operation of the elevator 15 (step S95) and applies the patch 81 (step S96). Then, when the application of the countermeasure is completed, the group control controller 4 restarts the operation of the elevator 15 (step S96).

[0210] By performing this update timing adjustment process, even if immediate application is not possible, late-night application can be reliably performed instead. Furthermore, even if the desired date and time cannot be guaranteed, regular inspection application can be reliably performed instead. Furthermore, during regular inspections, maintenance personnel can implement countermeasures using the maintenance terminal 20.

[0211] [Modification]

[0212] In addition, the embodiment examples described so far are described in detail in order to explain the present invention in an easily understandable manner, and are not necessarily limited to those having all the described configurations.

[0213] For example, it is also possible to apply artificial intelligence (AI) to perform vulnerability-related object estimation processing.

[0214] Figure 21 An example of the structure in this case is shown. Figure 21 is Figure 4 In the illustrated configuration of the elevator system, the category extraction unit 52 and the countermeasure confirmation unit 54 are replaced with a safety countermeasure generation AI execution unit 200 .

[0215] right Figure 21 The structure of the security countermeasure generation AI execution unit 200 is explained. It takes the vulnerability information 64, security accident information 62, countermeasure information 66 managed by the security database 60 and the structural information 74 managed by the shipped product database 70 as input, and accumulates the learning results in the large-scale language model 210, thereby being able to learn accidents, vulnerabilities and correlations.

[0216] By using the learned large-scale language model 210 , the safety countermeasure generation AI execution unit 200 takes the generated accident information 50 as input and generates information related to the safety accident information 62 corresponding to the accident.

[0217] Furthermore, by learning the operation information 72 of each elevator 15 managed in the shipped product database 70 as input to the safety measure generation AI execution unit 200 , an update period can be generated based on the operation status corresponding to the update period setting unit 58 .

[0218] Based on the information generated by the security countermeasure generation AI execution unit 200, Figure 4 Similarly, the update device determination unit 56 determines the device to be updated, and the update time setting unit 58 sets the update time based on the configuration and operation information of each update device.

[0219] In this way, the safety countermeasure generation AI execution unit 200 accumulates learning results in the large-scale language model 210 , thereby being able to automatically and appropriately determine the vulnerability and countermeasure method corresponding to the generated accident information 50 .

[0220] Furthermore, in the above-described embodiment, the present invention is applied to an elevator system, but the present invention can also be applied to lift systems other than elevators.

[0221] In addition, Figure 1 、 Figure 2 、 Figure 4 、 Figure 21 In the structural diagrams shown, the control lines and information lines are only those considered necessary for explanation, and not all control lines and information lines are shown in the product. In reality, it can be assumed that almost all the components are connected to each other.

[0222] in addition, Figure 8 、 Figure 9 、 Figure 11 、 Figure 12 、 Figure 13 、 Figure 15 、 Figure 17 、 Figure 18 、 Figure 19 、 Figure 20 The process flow shown in the flowchart is merely an example, and if the process results are the same, the process order may be partially changed or a plurality of processes may be executed simultaneously.

[0223] In addition, in the above-mentioned embodiment, Figure 3 The execution of the program structured as shown constitutes Figure 4 The system shown, however, the program in this case may be prepared in a storage device within the computer system or may be placed in an external memory, IC card, SD card, optical disk or other recording medium for transmission.

[0224] Description of Reference Numerals

[0225] 1…Center, 2…Communication path, 3…Communication controller, 4…Group management controller, 5…Elevator controller, 6…Motor, 8…Counterweight, 9…Rope, 10…Controller, 11…Floor controller, 12…Communication path, 15…Error code, 13…Operation panel, 14…Up / Down buttons, 15…Elevator, 16, 17…Communication path, 18…Elevator group, 19…Management terminal, 20…Maintenance terminal, 30…Controller, 31…MPU, 32…ROM, 33…RAM, 34…Communication interface, 35…System bus, 40…Firmware, 41…Program, 42…Operating system, 43…Library, 44…Device driver, 45…Standard program, 46…Optional program, 47… 7…Order program, 48…Operation control program, 49…Safety control program, 50…Accident information, 52…Category extraction unit, 54…Countermeasure confirmation unit, 56…Update device determination unit, 58…Update period setting unit, 59…Accident information acquisition unit, 60…Security database, 62…Safety accident information database (safety accident information), 64…Vulnerability information database (vulnerability information), 66…Countermeasure information database (countermeasure information), 70…Shipped product database, 72…Operation information database, 74…Structural information database, 76…Countermeasure schedule database, 78…Countermeasure schedule database, 200…Safety countermeasure generation AI execution unit, 210…Large-scale language model

Claims

1. An elevator system, characterized in that: have: an accident information acquisition unit that acquires accident information about the elevator; a countermeasure confirmation unit configured to confirm a countermeasure for the accident information acquired by the accident information acquisition unit; an updated equipment determination unit that determines updated equipment for the elevator requiring accident countermeasures based on the countermeasures confirmed by the countermeasure confirmation unit; and An update period setting unit sets a period for implementing accident countermeasures for the updated equipment based on the structural information and operating conditions of the elevator.

2. The elevator system according to claim 1, characterized in that The update period setting unit sets an implementation period of accident countermeasures based on an operating status of the update device, an importance of the update device, and a severity of an accident.

3. The elevator system according to claim 2, characterized in that The update period setting unit sets the execution period of the accident countermeasure to either a late night time period or a regular inspection period.

4. The elevator system according to claim 1, wherein: When the countermeasure implementation timing is set to immediate application, the update period setting unit controls the system of the elevator so as to ensure the implementation time of the countermeasure application.

5. The elevator system according to claim 1, wherein: The countermeasure confirmation unit causes a large-scale language model to learn and accumulate incidents, vulnerabilities, and correlations, and estimates vulnerability-related objects through analysis using the learned large-scale language model.

6. A method for controlling an elevator, characterized in that: Include: Accident information acquisition and processing: obtaining accident information; Countermeasure confirmation processing, confirming the countermeasures for the accident information obtained through the accident information acquisition processing; an equipment update decision process for determining an equipment update for an elevator requiring an accident countermeasure based on the countermeasure confirmed by the countermeasure confirmation process; as well as The update period setting process sets the implementation period of the accident countermeasures of the updated equipment based on the structural information and operating conditions of the elevator.

Citation Information

Patent Citations

  • Pattern generator of electronic sewing machine

    JP1980058194A