Elevator integrated control device, danger failure detection method and device and medium

By replacing the digital isolator with a buffer and default level configuration module in the elevator integrated control device, the problem of increased size and cost caused by PWM signal cut-off control is solved, and the safety and reliability are improved.

CN120964534APending Publication Date: 2025-11-18INVT POWER ELECTRONICS SUZHOU CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511338088.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-18
Publication Date
2025-11-18

AI Technical Summary

Technical Problem

The use of digital isolators in existing elevator integrated control devices to cut off PWM signals leads to increased size and cost.

Method used

A buffer is used instead of a digital isolator. The PWM signal is cut off and controlled by the buffer and the default level configuration module. The failure state of the buffer is detected by the control module, thus meeting the elevator safety function requirements.

Benefits of technology

This reduces the size and cost of the device while enabling failure detection of the buffer, ensuring the safety and reliability of elevator operation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120964534A_ABST
    Figure CN120964534A_ABST
Patent Text Reader

Abstract

The invention discloses an elevator integrated control device, a danger failure detection method and device and a medium, relates to the technical field of elevators, and provides the elevator integrated control device for solving the problem that the size and cost are increased due to the fact that a digital isolator is used for achieving PWM signal cut-off control at present. And a digital isolator is replaced by the buffer to realize cut-off control of the PWM signal. Compared with a digital isolator, the buffer is smaller in size and lower in cost. Moreover, a common buffer has more paths of model selections, and supports the cut-off control of one buffer on six paths of PWM signals, so that the number of used devices is reduced only in one step. Moreover, although a default level configuration module needs to be used for performing failure detection on the buffer, simple default level configuration can be realized through simple devices with small volume and low cost, such as a pull-up / pull-down resistor, a three-state buffer and the like, and compared with the use of a digital isolator, the comprehensive cost is lower, and the circuit area is smaller.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of elevator technology, and in particular to an integrated elevator control device and a method, device, and medium for detecting dangerous failures. Background Technology

[0002] Elevators are classified as special safety equipment, and the safety requirements during operation are extremely stringent. Currently, Safety Torque Off (STO) and electronic star-locking have become essential safety functions in elevator operation control.

[0003] In related technologies, there exists a control device integrating electronic star-stop and STO functions. This device controls elevator operation through a switching module composed of Insulated-Gate Bipolar Transistors (IGBTs) (such as an inverter bridge with a three-phase full-bridge topology consisting of six IGBTs). This device controls the switching state of each IGBT device by outputting a pulse-width modulation (PWM) signal to achieve both STO and electronic star-stop functions. STO is achieved when all IGBT devices are off; electronic star-stop is achieved when only the upper or lower half-bridge IGBT devices are on.

[0004] Within the aforementioned device, the STO (Safety Toll Collection) function is primarily controlled via a digital isolator. This is due to the unique internal structure of the digital isolator, which eliminates the need to consider dangerous failure scenarios caused by input / output short circuits. In other words, a failure of the digital isolator can be considered a safety failure. Therefore, there is no need to add additional hardware circuitry and software logic for failure detection to the digital isolator, while still meeting the elevator's safety requirements, thus reducing the hardware and software costs of the device.

[0005] However, digital isolators are relatively large and expensive devices. Furthermore, digital isolators have a limited number of ports (typically a maximum of 4). To meet the need for cutting off multiple (e.g., 6) PWM signals, multiple digital isolators are generally required. This further increases the size and cost of the device, limiting its application in actual elevator operation control scenarios.

[0006] Therefore, those skilled in the art urgently need an integrated elevator control device to solve the problem of increased size and cost caused by the current use of digital isolators to achieve PWM signal cutoff control. Summary of the Invention

[0007] The purpose of this application is to provide an elevator integrated control device and a method, apparatus, and medium for detecting dangerous failures, so as to solve the problem of increased size and cost caused by the current use of digital isolators to realize PWM signal cutoff control.

[0008] To address the aforementioned technical problems, this application provides an integrated elevator control device, comprising: a PWM signal input terminal, a PWM signal output terminal, a safety torque cutoff module, an electronic star-sealing module, and a control module; it also includes: a buffer and a default level configuration module;

[0009] The buffer is connected in series in the signal path between the PWM signal input terminal and the PWM signal output terminal, and the first enable terminal of the buffer is connected to the safety torque cutoff module, and the second enable terminal of the buffer is connected to the control module; the buffer is used to: cut off the output of the PWM signal when the first enable terminal or the second enable terminal does not receive an enable signal;

[0010] The default level configuration module is connected to the input and output terminals of the buffer respectively, and is used to make the default level states of the input and output terminals of the buffer different.

[0011] The control module is used to: control the buffer to be in an enabled state and an disabled state respectively by outputting an enable signal; and determine the failure state of the buffer according to the actual level state at the input and output terminals of the buffer under different operating states.

[0012] In one optional embodiment, there are N safe torque cutoff modules, where N is any positive integer greater than 1;

[0013] The number of buffers is N, and the control module includes N output terminals;

[0014] The first enable terminals of the N buffers are respectively connected to the N safety torque cutoff modules, and the second enable terminals of the N buffers are respectively connected to the N output terminals of the control module; and the N buffers are cascaded to form a multi-level buffer structure.

[0015] The default level states of the input and output terminals of each buffer in the multi-level buffer structure are different.

[0016] The control module is used to control each buffer in the multi-level buffer structure to be in an enabled state and an disabled state respectively by outputting an enable signal; and to determine the failure state of the buffer according to the actual level state at the input and output terminals of the buffer under different working states.

[0017] In one optional embodiment, N=2, and the input terminal of the control module is connected to the output terminal of the PWM signal;

[0018] The control module is also used to: traverse each detection state; and after each traversal, obtain the actual level state at the PWM signal output terminal; and determine the failure state of each buffer based on the actual level state and the theoretical level state at the PWM signal output terminal.

[0019] There are four detection states: the first detection state, in which both the first-level buffer and the second-level buffer are disabled; the second detection state, in which the first-level buffer is enabled and the second-level buffer is disabled; the third detection state, in which the first-level buffer is disabled and the second-level buffer is enabled; and the fourth detection state, in which both the first-level buffer and the second-level buffer are enabled.

[0020] The theoretical level state is determined based on the current operating state of each buffer.

[0021] In one optional embodiment, the PWM signal has M channels, where M is any positive integer greater than 1;

[0022] The buffer includes M input terminals and output terminals;

[0023] The default level states corresponding to the M input terminals of the same buffer are the same, and the default level states corresponding to the M output terminals of the same buffer are the same.

[0024] In one optional embodiment, the default level configuration module includes: a pull-up resistor and a pull-down resistor;

[0025] The first end of the pull-up resistor / pull-down resistor is connected to the pull-up power supply / ground terminal, and the second end of the pull-up resistor / pull-down resistor is connected to the input / output terminal of the buffer.

[0026] To address the aforementioned technical problems, this application also provides a method for detecting hazardous failures, applied to the elevator integrated control device described above, the method comprising:

[0027] The buffer is controlled to be in an enabled state and an disabled state, respectively.

[0028] When the buffer is in the enabled state and the actual voltage levels at the input and output terminals of the buffer are inconsistent, it is determined that the buffer has an open-circuit failure.

[0029] When the buffer is in an disabled state and the actual voltage levels at the input and output terminals of the buffer are consistent, it is determined that the buffer has experienced a short-circuit failure.

[0030] In one optional embodiment, the number of buffers is two, and the two buffers are cascaded; the default level state corresponding to the input terminal of the first-stage buffer is low.

[0031] The method also includes:

[0032] The detection states are iterated through, and after each iteration, the actual level state at the PWM signal output terminal is obtained. There are four detection states: First detection state, where both the first-stage and second-stage buffers are disabled; Second detection state, where the first-stage buffer is enabled and the second-stage buffer is disabled; Third detection state, where the first-stage buffer is disabled and the second-stage buffer is enabled; Fourth detection state, where both the first-stage and second-stage buffers are enabled.

[0033] When the first detection state is traversed and the actual level state is high, it is determined that the first-level buffer has an open-circuit failure.

[0034] When the second detection state is traversed and the actual level state obtained is low, it is determined that the first-level buffer has a short circuit failure.

[0035] When the third detection state is traversed and the actual level state obtained is low, it is determined that the second-level buffer has an open circuit failure.

[0036] When the fourth detection state is traversed and the actual level state is obtained as high, it is determined that the second-level buffer has a short-circuit failure.

[0037] To address the aforementioned technical problems, this application also provides a hazardous failure detection device, applied to the elevator integrated control device described above, comprising:

[0038] An enable control module is used to control the buffer to be in an enabled state and an disabled state, respectively.

[0039] An open-circuit detection module is used to determine that the buffer has an open-circuit failure when the buffer is in the enabled state and the actual level states at the input and output terminals of the buffer are inconsistent.

[0040] A short-circuit detection module is used to determine that the buffer has a short-circuit failure when the buffer is in an disabled state and the actual voltage levels at the input and output terminals of the buffer are consistent.

[0041] To address the aforementioned technical problems, this application also provides a hazardous failure detection device, comprising:

[0042] Memory, used to store computer programs;

[0043] A processor is configured to implement the steps of the dangerous failure detection method described above when executing the computer program.

[0044] To address the aforementioned technical problems, this application also provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the steps of the dangerous failure detection method described above.

[0045] This application provides an integrated elevator control device that uses a buffer instead of a digital isolator to cut off the PWM signal. When the buffer is enabled, the PWM signal can be output normally through the buffer without cutting off the PWM signal; when the buffer is disabled, the PWM signal cannot be output through the buffer, which is equivalent to cutting off the PWM signal. Based on this, the safety torque cutoff module and the control module can cut off the PWM signal through the buffer when the STO function needs to be executed, thus realizing the STO function.

[0046] On the other hand, buffers lack the short-circuit failure considerations of digital isolators, making their failure a dangerous one. Therefore, buffer failure detection is necessary to meet elevator safety requirements. Specifically, this method connects default level configuration modules to the buffer's input and output terminals, enabling the configuration of different default levels at these terminals. Based on this, the control module can determine whether the buffer failure is short-circuit or open-circuit by changing the buffer's enable state and checking if the actual level states at the buffer's input and output terminals are the same, thus meeting the elevator's functional safety requirements for detecting single-device failures. Furthermore, changing the buffer's default level does not affect the normal output of the PWM signal through the buffer, effectively ensuring normal control of the elevator operation.

[0047] Furthermore, buffers are smaller and less expensive than digital isolators. Common buffers also offer a wider range of models, supporting the cutoff control of up to six PWM signals from a single buffer, reducing the number of components used in a single step. While failure detection of the buffer requires a default level configuration module, simple default level configuration can be achieved using small, low-cost components such as pull-up / pull-down resistors and tri-state buffers, resulting in lower overall cost and smaller circuit area compared to using digital isolators.

[0048] The hazardous failure detection method, apparatus, and computer-readable storage medium provided in this application correspond to the aforementioned elevator integrated control device and have the same effect. Attached Figure Description

[0049] To more clearly illustrate the embodiments of this application, the accompanying drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0050] Figure 1 A schematic diagram of a contactless elevator operation control scheme;

[0051] Figure 2 This is a structural diagram of an elevator integrated control device provided in an embodiment of the present invention;

[0052] Figure 3 A structural diagram of a buffer and electronic star-sealing module provided in an embodiment of the present invention;

[0053] Figure 4 A structural diagram of an elevator system provided in an embodiment of the present invention;

[0054] Figure 5 This is a structural diagram of an STO dual redundancy scheme provided in an embodiment of the present invention;

[0055] Figure 6 A circuit diagram of a safe torque switching module provided in an embodiment of the present invention;

[0056] Figure 7 A circuit diagram of a driving module provided in an embodiment of the present invention;

[0057] Figure 8 A signal wiring diagram of a control module provided in an embodiment of the present invention;

[0058] Figure 9 A circuit diagram of an overvoltage and overcurrent detection module provided in an embodiment of the present invention;

[0059] Figure 10 This is a structural connection diagram of a watchdog reset chip provided in an embodiment of the present invention;

[0060] Figure 11 A flowchart of a hazardous failure detection method provided in an embodiment of the present invention;

[0061] Among them, 10 is the elevator integrated control device, 11 is the safety torque cutoff module, 12 is the electronic star-sealing module, 13 is the control module, 14 is the buffer, 15 is the default level configuration module, 16 is the overvoltage and overcurrent detection module, 17 is the low-dropout linear regulator module, 18 is the watchdog reset chip, 20 is the drive module, 30 is the switch module, 40 is the motor, 50 is the main board, 60 is the DSP board, and 70 is the low-voltage power supply. Detailed Implementation

[0062] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the protection scope of this application.

[0063] The core of this application is to provide an elevator integrated control device and a method, device, and medium for detecting dangerous failures.

[0064] To enable those skilled in the art to better understand the present application, the present application will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0065] In related technologies, such as Figure 1 As shown, there exists a control device integrating electronic star-off and STO functions. It controls the elevator's operation through a switching module composed of Insulated-Gate Bipolar Transistors (IGBTs) (such as an inverter bridge with a three-phase full-bridge topology consisting of six IGBTs). This device controls the switching state of each IGBT device by outputting a pulse width modulation (PWM) signal to achieve STO and electronic star-off functions. When all IGBT devices are off, the STO function is achieved; when only the upper or lower half-bridge IGBT devices are on (such as...), the electronic star-off function is achieved. Figure 1 When the upper half-bridge (Q1~Q3) is turned on and the lower half-bridge (Q4~Q6) is turned off, an electronic star-sealing function can be achieved. Specifically, the control that turns off all IGBT devices (i.e., the implementation of the STO function) can be achieved by cutting off the output of all PWM signals. That is, the controlled terminals of each IGBT device are left floating, entering the default off state.

[0066] Currently, elevators generally need to meet SIL3 level for functional safety. The structural safety constraints for elevator functional safety are shown in Table 1 below:

[0067] Table 1 Safety structural constraints for elevator functional safety

[0068]

[0069] As shown in Table 1 above, to meet the safety requirements of SIL3 level (SIL1~4 represent progressively higher functional safety levels), the aforementioned control devices commonly use two-stage digital isolators (i.e., two cascaded digital isolators for redundancy) to cut off the PWM signal. The reason is:

[0070] The digital isolator internally has two silicon dioxide (SiO2) high-voltage isolation capacitors connected in series between the input and output. These capacitors can withstand a continuous 5kV AC effective voltage (RMS) isolation voltage. Therefore, dangerous failure modes caused by input / output short circuits do not need to be considered, meaning the digital isolator can be considered to be in a safe failure state. In this case, the safe failure fraction SFF = (safe failure rate) + Dangerous detectable failure rate ) / (Safety Failure Rate) + Dangerous failure rate The diagnostic coverage rate (DC) is 1 (hazard detectable failure rate). ) / (Dangerous failure rate) The value is also 1; therefore, there is no need to set up additional corresponding dangerous failure detection schemes, and it can also meet the safety function requirements of elevators for SIL3 level.

[0071] However, the maximum number of signal paths supported by common digital isolators is currently only four. As in the example above, effective control of the elevator's switching module requires at least six PWM signals. Therefore, to achieve the cutoff control of these six PWM signals, at least two cascaded digital isolators are needed, i.e., at least four digital isolators. Furthermore, due to the large size and high cost of digital isolators, although they do not require additional fault detection circuits, they still contribute to increased size and cost, making them impractical for implementation.

[0072] To address the aforementioned problems, this application provides an integrated elevator control device, such as... Figure 2 As shown, it includes: PWM signal input terminal, PWM signal output terminal, safety torque cutoff module, electronic star-sealing module, control module, buffer and default level configuration module.

[0073] A buffer is connected in series in the signal path between the PWM signal input terminal and the PWM signal output terminal, and the first enable terminal of the buffer is connected to the safety torque cutoff module, and the second enable terminal of the buffer is connected to the control module; the buffer is used to cut off the output of the PWM signal when the first enable terminal or the second enable terminal does not receive an enable signal.

[0074] The default level configuration module is connected to the input and output terminals of the buffer respectively, and is used to make the default level states of the input and output terminals of the buffer different.

[0075] The control module is used to: control the buffer to be in the enabled and disabled states respectively by outputting the enable signal; and determine the failure state of the buffer based on the actual level state at the input and output terminals of the buffer under different operating states.

[0076] It should be noted that the key components of the elevator integrated control device provided in this application are the buffer and the default level configuration module. The buffer replaces the original digital isolator to control the cutoff of the PWM signal. The default level configuration module works with the control module to detect dangerous failures of the buffer, thus meeting the elevator's safety requirements. Other modules in the elevator integrated control device, and how they specifically implement the electronic star-sealing function and dangerous failure detection, will be described in subsequent embodiments and will not be discussed in this embodiment.

[0077] First, this embodiment is not limited to the number of buffers. Specifically, as shown in Table 1 above regarding elevator functional safety level requirements, a HFT of 1 is sufficient to meet the SIL3 level safety functional requirements, provided that effective detection of hazardous failures is achievable or no hazardous failures exist. Therefore, in an optional embodiment, if the elevator's safety functional requirements for the elevator integrated control device are SIL3 level, then as follows... Figure 3 As shown, there are two buffers, cascaded to form a two-stage buffer structure. This two-stage buffer structure enables dual-redundant control for PWM signal cutoff. The safety torque cutoff module and control module can improve the redundancy of PWM signal cutoff control by enabling the two cascaded buffers separately.

[0078] Furthermore, in one optional embodiment: when there are two STO control signals, redundant STO detection can be achieved through two-way safety torque cutoff modules. The two safety torque cutoff modules can each correspond to different buffers in the two-stage buffer structure, and each can implement its corresponding enable control. This ensures that the two STO detections, i.e., the triggering of the STO function, are completely independent, achieving better STO redundancy control.

[0079] However, it should be noted that the example above using a quantity of 2 is because, as shown in Table 1 above, HFT=1 is sufficient to meet the SIL3 level requirements. This application does not limit the number of buffers and other modules to a maximum of 2. A larger number of modules allows for higher HFT redundancy, resulting in greater safety functionality. Furthermore, if the actual application requires a lower safety level, only one buffer may be used. In other words, this embodiment does not impose any limit on the number of buffers; the appropriate number of buffers should be selected based on the specific elevator safety level requirements of the application.

[0080] However, in practical applications, the safety requirements for elevators are generally no lower than SIL3 level. Therefore, this embodiment provides a suitable implementation scheme:

[0081] There are N safety torque cutoff modules, where N is any positive integer greater than 1; there are N buffers; and the control module includes N output terminals.

[0082] The first enable terminals of the N buffers are respectively connected to the N safety torque cutoff modules, and the second enable terminals of the N buffers are respectively connected to the N output terminals of the control module; and the N buffers are cascaded to form a multi-level buffer structure.

[0083] In a multi-level buffer structure, the input and output terminals of each buffer have different default voltage levels.

[0084] The control module is used to control each buffer in the multi-level buffer structure to be in an enabled or disabled state by outputting an enable signal; and to determine the failure state of the buffer based on the actual level of the input and output terminals of the buffer under different operating states.

[0085] In other words, this embodiment can achieve STO detection redundancy and PWM signal cutoff control redundancy with HFT=N-1. Furthermore, the STO detection and PWM signal cutoff control when triggering the STO function in each redundant branch are completely independent and do not affect each other, truly achieving STO redundancy with HFT=N-1. Since N is any positive integer greater than 1, it can effectively guarantee the SIL3 level safety function requirements during actual elevator operation.

[0086] Furthermore, when there are multiple buffers, the default level configuration module needs to configure the default level state of each buffer's input and output terminals separately. As explained above, the default level states of the buffer's input and output terminals in this device must be different. Common level states include high level (logic "1") and low level (logic "0"). That is, the default level states of the buffer's input and output terminals should be one high and one low. For cascaded buffers, since the input and output terminals of adjacent buffers are interconnected, they share the same default level state. Therefore, once the default level state of the input or output terminal of any one of the cascaded buffers is determined, the default level states of the input and output terminals of the remaining buffers are also determined accordingly.

[0087] return Figure 2 For example, assuming the default input level of the first-stage buffer is low, then the default output level of the first-stage buffer should be high. Similarly, if the default input level of the second-stage buffer is high, then the default output level of the second-stage buffer should be low. Figure 2 The two-level buffer structure shown has the following default level states for each node from input to output: low-high-low.

[0088] Furthermore, it should be noted that this embodiment does not limit the specific implementation form of the default level configuration module. It can be implemented through solutions such as pull-up circuits, pull-down circuits, tri-state buffers, level conversion chips, open collector (OC) or open drain (OD) structures. However, it should be noted that the purpose of this application is to reduce the overall size and cost of the control device. Therefore, the selection of the specific implementation scheme of the default level configuration module should also be based on the above requirements. Among them, a preferred implementation scheme is to implement the default level configuration module through pull-up circuits and pull-down circuits. The pull-up circuit is used to configure the default level state of the connection port to a high level, and the pull-down circuit is used to configure the default level state of the connection port to a low level.

[0089] That is, this application also provides an optional embodiment for the specific implementation of the default level configuration module, such as... Figure 3 As shown, the default level configuration module includes: pull-up resistors and pull-down resistors;

[0090] The first end of the pull-up / pull-down resistor is connected to the pull-up power supply / ground terminal, and the second end of the pull-up / pull-down resistor is connected to the input / output terminal of the buffer.

[0091] In this embodiment, the default level configuration can be achieved using only a single pull-up or pull-down resistor, resulting in a small circuit size and low cost. Therefore, even when replacing the digital isolator with a buffer, and it is necessary to configure the default level of the buffer's input and output terminals, the overall size and cost of the buffer and default level configuration module are still significantly lower than those of the digital isolator, making it more advantageous in practical applications.

[0092] On the other hand, based on the above default level configuration, the buffer failure can be detected by controlling the enable of the buffer through the control module. It is easy to see that if the buffer fails due to a short circuit, its input and output terminals are essentially connected regardless of whether the buffer is enabled, meaning that the actual voltage levels at both ends should be consistent. However, in reality, if the buffer is not enabled at this time, the actual voltage levels at both ends should be the same as its default voltage level, so the actual voltage levels should be different. That is, when the control module does not enable the buffer and the actual voltage levels at the input and output terminals of the buffer are the same, it can be determined that the buffer has failed due to a short circuit. Similarly, if the buffer fails with an open circuit, then regardless of whether the buffer is enabled, its input and output terminals are essentially disconnected. That is, the actual voltage levels at both ends depend on its default voltage level, and the actual voltage levels at both ends should be inconsistent. In this case, if the buffer is enabled, the actual voltage level at the output terminal should be equal to the actual voltage level at the input terminal, which is also equal to the default voltage level at the input terminal. Therefore, the actual voltage levels at both ends are the same. In other words, when the control module enables the buffer and the actual voltage levels at the input and output terminals of the buffer are different, it can be determined that the buffer has failed with an open circuit.

[0093] It should be noted that the above-described fault detection logic applies to both single and multiple buffers. For multiple buffers, only one detection based on the above logic is needed for each buffer. However, it is easy to see that when there are multiple buffers, as described in the above embodiment, multiple buffers should be cascaded to form a multi-level buffer structure. Therefore, starting from the second-level buffer, the actual level state of the input terminal of each level buffer is the actual level state of the output terminal of the previous level buffer. The actual level state of the input terminal of the first-level buffer is necessarily its default level state. Therefore, regardless of whether there is one or multiple buffers, when implementing the above method, it is only necessary to detect the actual level state of the output terminal of each buffer to know the actual level state of the input and output terminals of each buffer.

[0094] On the other hand, for scenarios where there are multiple buffers, particularly in the example above where there are two buffers (i.e., N=2), this application also provides another optional embodiment for hazardous failure detection:

[0095] The input terminal of the control module is connected to the output terminal of the PWM signal.

[0096] The control module is also used to: traverse each detection state; and after each traversal, obtain the actual level state at the PWM signal output terminal; and determine the failure state of each buffer based on the actual level state and the theoretical level state at the PWM signal output terminal.

[0097] There are four detection states: First detection state, both the first-level buffer and the second-level buffer are disabled; Second detection state, the first-level buffer is enabled and the second-level buffer is disabled; Third detection state, the first-level buffer is disabled and the second-level buffer is enabled; Fourth detection state, both the first-level buffer and the second-level buffer are enabled; The theoretical level state is determined based on the current working state of each buffer.

[0098] To better illustrate the hazardous failure detection scheme provided in this embodiment, the following description uses specific examples to illustrate the scheme:

[0099] like Figure 3 As shown, assuming the default level of the input terminal of the first-stage buffer is low, the default level of the output terminal of the first-stage buffer (which is the same as the input terminal of the second-stage buffer) should be high, and the default level of the output terminal of the second-stage buffer should be low. Furthermore, since this control device integrates STO and electronic star-blocking functions, in addition to the buffer (multi-stage buffer structure) used to implement the STO function, there will also be a hardware structure used to implement the electronic star-blocking function in the signal path between the PWM signal input terminal and the PWM signal output terminal, such as... Figure 3 The system uses three OR gate chips and three AND gate chips. It's easy to see that elevator functional safety requirements only cover the detection of dangerous failures of single components. Aside from not considering safety failures, there's no need to consider the simultaneous failure of multiple components. That is, when detecting a dangerous failure of a buffer, it's assumed that all other components are functioning normally. When there are multiple buffers, if a dangerous failure detection is performed on one buffer, it's assumed that the other buffers are functioning normally. To avoid unnecessary interference from irrelevant factors in the detection of dangerous failures of buffers, this example assumes that the electronic star-sealing function is disabled, i.e., the output of the second-level buffer (…). Figure 3 UH / VH / WH and UL / VL / WL in the figure represent the actual output of the PWM signal output terminal. Figure 3 (U+ / V+ / W+, U- / V- / W-). Additionally, assume that the first and second enable terminals of the buffer receive a low-level enable, and do not consider stopping the buffer's enable when the STO function is triggered by the safety torque switching module (i.e., ...). Figure 3(STO_EN1 and STO_EN2 are both 0), whether each buffer can function is entirely determined by the output of the control module.

[0100] Based on the above, the typical scenarios that may occur in a two-level buffer structure are as follows:

[0101] 1. Using the first-level buffer as the target for dangerous failure detection, the second-level buffer is assumed to be normal. However, there are two possible scenarios: the second-level buffer is enabled ( Figure 3 STO_SAFE2=0), the second-level buffer is not enabled ( Figure 3 (STO_SAFE2=1). Since the output of the second-stage buffer will inevitably be at its default level when the second-stage buffer is not enabled, it is impossible to detect the dangerous failure of the first-stage buffer through the output of the PWM signal. Therefore, to reduce unnecessary explanation, this embodiment will be explained using the second-stage buffer being enabled as an example.

[0102] 1-1. The control module enables the first-stage buffer ( Figure 3 (STO_SAFE1=0, i.e., the fourth detection state mentioned above).

[0103] 1-1-1. Assuming the first-stage buffer is functioning correctly, its output should be the same as its input, meaning the default input level should be low. Therefore, the second-stage buffer output should be low, and U+ / V+ / W+ and U- / V- / W- should also be low.

[0104] 1-1-2. Assuming the first-stage buffer fails due to a short circuit, the output of the first-stage buffer should be the same as its input, i.e., the default level of the input is low. Therefore, the output of the second-stage buffer should be low, and U+ / V+ / W+ and U- / V- / W- should be low.

[0105] 1-1-3. Assuming the first-stage buffer fails due to open circuit, the output of the first-stage buffer is independent of the input and should be the default high level at the output terminal. In this case, the output of the second-stage buffer should be high, and U+ / V+ / W+ and U- / V- / W- should be high.

[0106] As can be seen from the above, in case 1-1, the result of 1-1-3 is different from and unique to cases 1-1-1 and 1-1-2. That is, in case 1-1, as long as the output of the PWM signal is detected to be high, it indicates that the first-stage buffer has an open-circuit failure. In other words, the fourth detection state can effectively detect the open-circuit failure of the first-stage buffer.

[0107] 1-2. The control module has not enabled the first-stage buffer. Figure 3 (STO_SAFE1=1, i.e., the third detection state mentioned above).

[0108] 1-2-1. Assuming the first-stage buffer is functioning correctly, but since it is not enabled, its output is independent of its input and remains at the default high level. Consequently, the second-stage buffer output should be high, and U+ / V+ / W+ and U- / V- / W- should also be high.

[0109] 1-2-2. Assuming the first-stage buffer fails due to a short circuit, its output should be the same as its input, regardless of whether the first-stage buffer is enabled or not; that is, the default input level should be low. Therefore, the output of the second-stage buffer should be low, and U+ / V+ / W+ and U- / V- / W- should also be low.

[0110] 1-2-3. Assuming the first-stage buffer fails due to open circuit, the output of the first-stage buffer is independent of the input and should be the default high level at the output terminal. In this case, the output of the second-stage buffer should be high, and U+ / V+ / W+ and U- / V- / W- should be high.

[0111] As can be seen from the above, in cases 1-2, the result of 1-2-2 is different from and unique to cases 1-2-1 and 1-2-3. That is, in case 1-2, as long as the output of the PWM signal is detected to be low, it indicates that the first-stage buffer has a short circuit failure. In other words, the third detection state can effectively detect the short circuit failure of the first-stage buffer.

[0112] Furthermore, by summarizing all possible scenarios for dangerous failure detection of the first-stage buffer (including the first and second detection states not mentioned above; however, it should be noted that the omission of the first and second detection states does not mean they are useless, but rather that they are not required when detecting dangerous failure of the first-stage buffer), the detection results shown in Table 2 below can be obtained.

[0113] Table 2 Summary of Hazardous Failure Detection Results for the First-Level Buffer

[0114]

[0115] In Table 2 above, the first and third rows represent situations 1-1 and 1-2, respectively, which are the fourth and third detection states. The bold columns represent situations 1-1-3 and 1-2-2, which are the situations in which the specific dangerous failure state of the first-stage buffer can be detected.

[0116] 2. Using the second-level buffer as the target for dangerous failure detection, the first-level buffer is assumed to be functioning correctly. However, there are two possible scenarios: the first-level buffer is enabled ( Figure 3 STO_SAFE1=0), Level 1 buffer is not enabled ( Figure 3(STO_SAFE1=1). Since the difference between enabling and disabling the first-stage buffer lies only in whether the actual input level of the second-stage buffer is low or high, and the principle is the same, this embodiment will only describe one case in detail to reduce unnecessary explanations. Furthermore, since case 1 above uses the enabling of another buffer as an example, for a more comprehensive explanation, case 2 will be described with the first-stage buffer disabled (i.e., the first and third detection states; if the first-stage buffer is enabled, then the corresponding second and fourth detection states).

[0117] 2-1. Enable the second-stage buffer in the control module ( Figure 3 (STO_SAFE2=0, i.e., the third detection state mentioned above).

[0118] 2-1-1. Assuming the second-stage buffer is functioning correctly, its output should be the same as its input, meaning the input should be at a default high level. Therefore, U+ / V+ / W+ and U- / V- / W- should also be high.

[0119] 2-1-2. Assuming the second-stage buffer fails due to a short circuit, the output of the second-stage buffer should be the same as its input, i.e., the default level of the input should be high. Therefore, U+ / V+ / W+ and U- / V- / W- should be high.

[0120] 2-1-3. Assuming the second-stage buffer fails due to open circuit, the output of the second-stage buffer is independent of the input and should be at the default low level. In this case, U+ / V+ / W+ and U- / V- / W- should be low.

[0121] As can be seen from the above, in case 2-1, the result of 2-1-3 is different from and unique to cases 2-1-1 and 2-1-2. That is, in case 2-1, as long as the output of the PWM signal is detected to be low, it indicates that the second-stage buffer has an open-circuit failure. In other words, the third detection state can effectively detect the open-circuit failure of the second-stage buffer.

[0122] 2-2. The control module has not enabled the second-stage buffer. Figure 3 (STO_SAFE2=1, i.e., the first detection state mentioned above).

[0123] 2-2-1. Assuming the second-stage buffer is functioning correctly, but since it is not enabled, its output is independent of its input and remains at the default low level. Consequently, U+ / V+ / W+ and U- / V- / W- should be low.

[0124] 2-2-2. Assuming the second-stage buffer fails due to a short circuit, its output should be the same as its input, regardless of whether the second-stage buffer is enabled or not; that is, the default input level should be high. Therefore, U+ / V+ / W+ and U- / V- / W- should be high.

[0125] 2-2-3. Assuming the second-stage buffer fails due to open circuit, the output of the second-stage buffer is independent of the input and should be at the default low level. In this case, U+ / V+ / W+ and U- / V- / W- should be low.

[0126] As shown above, in case 2-2, the result of 2-2-2 is different from and unique to cases 2-2-1 and 2-2-1. That is, in case 2-2, if the output of the PWM signal is detected to be high, it indicates that the second-stage buffer has short-circuited. In other words, the first detection state can effectively detect short-circuit failures in the second-stage buffer.

[0127] Furthermore, by summarizing all possible scenarios for dangerous failure detection of the second-level buffer (including the second and fourth detection states not mentioned above; however, it should be noted that the second and fourth detection states were not described above simply because their principles are the same as the first and third detection states, and therefore were not repeated), the detection results shown in Table 3 below can be obtained.

[0128] Table 3 Summary of Hazardous Failure Detection Results for Second-Level Buffers

[0129]

[0130] In Table 3 above, the third and fourth rows represent situations 2-1 and 2-2, respectively, which are the third detection state and the first detection state. The bold columns represent situations 2-1-3 and 2-2-2, which are situations where the specific dangerous failure state of the second-level buffer can be detected.

[0131] In summary, this embodiment provides another dangerous failure detection scheme. Even when there are two buffers, it is not necessary to acquire the actual output level of each buffer. The control module only needs to acquire the actual level at the PWM signal output terminal to complete the dangerous failure detection of both buffers. On the one hand, this reduces the number of signals that the control module needs to acquire and lowers the complexity of the detection logic. On the other hand, the PWM signal output terminal is a readily available signal port, eliminating the need for additional ports or pins for the control module to acquire the actual level, making dangerous failure detection of the buffers easier to implement.

[0132] On the other hand, this embodiment is not limited to the number of ports of the buffer. The number of ports of the buffer should be determined according to the object to be cut off, that is, the number of PWM signals. Based on this, this application provides an optional embodiment:

[0133] There are M PWM signals, where M is any positive integer greater than 1; the buffer includes M input terminals and output terminals.

[0134] For example, as described in the relevant technical section above, in one possible application scenario, there are 6 PWM signals, i.e., M=6. In this case, the buffer is as follows: Figure 3 As shown, this is a 6-channel buffer.

[0135] It should be noted that when the buffer has multiple input and output terminals, this embodiment does not restrict whether the default level states of different input / output terminals are the same, as long as the default level states of the corresponding input and output terminals are different. However, to facilitate the detection of dangerous failures of the buffer, this embodiment further provides an optional embodiment, such as... Figure 3 As shown:

[0136] The default level states of the M input terminals of the same buffer are the same, and the default level states of the M output terminals of the same buffer are the same.

[0137] Based on the configuration of this embodiment, when detecting the failure state of the buffer, the control module only needs to record the default level state of one input and one output terminal of the buffer, instead of recording each one. This reduces the storage space occupied by the control module and also improves the efficiency of the control module in detecting the failure state of the buffer.

[0138] In summary, the elevator integrated control device provided in this application can replace contactors to control elevator operation, supports STO and electronic star-sealing functions, and supports failure detection of each component in the device, ensuring compliance with elevator functional safety requirements. Furthermore, this device uses buffers instead of digital isolators to control the cutoff of PWM signals. On one hand, buffers significantly reduce size and cost compared to digital isolators. Moreover, buffers offer a wider range of port options; a single buffer can control the cutoff of all PWM signals, further reducing the device's size and cost. On the other hand, although each buffer channel is independent and subject to dangerous failures, this device incorporates a danger detection mechanism for each channel. By setting the default voltage levels of the buffer's input and output terminals to different levels, and based on the characteristics of short-circuit and open-circuit failures in the buffer, various possible scenarios are simulated using buffer enable control. This allows for dangerous failure detection of the buffer based on the actual voltage levels of the buffer's input and output terminals, ensuring compliance with elevator functional safety requirements.

[0139] On the other hand, the above embodiments mainly describe the part of the elevator integrated control device provided in this application that addresses the problem of large size and cost of the digital isolator. Other parts of the device are unrelated to solving the above problems, therefore this application does not limit specific implementation schemes, and they have not been described in detail in the above embodiments. However, to better illustrate the elevator integrated control device provided in this application, the following embodiments will provide a detailed description of other parts of the device.

[0140] like Figure 2 As shown, the elevator integrated control device provided in this application mainly includes: a PWM signal input terminal, a PWM signal output terminal, a safety torque cutoff module, an electronic star-sealing module, a control module, a buffer, and a default level configuration module. The functions and specific implementation schemes of the buffer, the default level configuration module, and the control module, including PWM signal cutoff control and buffer hazard failure detection, have been described in detail in the above embodiments. The PWM signal input terminal and the PWM signal output terminal are the ports through which the device receives PWM signals and outputs unprocessed PWM signals after processing by the device. The control module 13 is used to detect whether the safety torque cutoff module 11, the electronic star-sealing module 12, and the buffer 14 are abnormal, and triggers an STO (Safety Torque Toll Collection) action or an electronic star-sealing action when an abnormality occurs. The above functions can be implemented using devices with signal processing capabilities, such as microcontroller units (MCUs) and digital signal processors (DSPs).

[0141] Furthermore, such as Figure 4 The diagram illustrates a possible elevator operation control system. This device controls the elevator switching module through a series of externally input signals. Specifically, the main board 50 outputs STO control signals and star-sealing control signals that satisfy the STO and electronic star-sealing control timing sequences based on the elevator's current operating status; the DSP board 60 outputs PWM signals to control the elevator motor 40; and the low-voltage power supply 70 provides the STO control signals in the form of power signals. In addition, the elevator system includes other hardware structures necessary for safe elevator operation, such as a power frequency transformer to convert 220V AC to 110VAC (possibly 125VAC for higher floors due to larger voltage drops from door locks), and a series of safety switches required for normal elevator operation, such as speed governors, buffers, and safety brakes.

[0142] The power output from the power frequency transformer passes through a series of safety switches and door lock switches before reaching the door lock. The voltage at this door lock end is controlled by relay Y1 of the contactor controlled by the main board 50 and then supplied to the low-voltage power supply 70, which outputs STO control signals (STO24V1 / STOCOM1 and STO24V2 / STOCOM2) in the form of power signals. These signals serve as input signals for the dual-channel redundant STO detection in the safety torque cutoff and electronic star-sealing device 10. Simultaneously, the DSP board 60 sends PWM signals (EPWM1A / EPWM2A / EPWM3A, EPWM1B / EPWM2B / EPWM3B) to the safety torque cutoff and electronic star-sealing device 10. Based on the implementation scheme described in the above embodiment, the safety torque cutoff and electronic star-sealing device 10 achieves STO and electronic star-sealing functions that meet the functional safety SIL3 requirements. The processed PWM signals are sent to the drive module 20, generating six drive signals for the control switch module 30 to control the operation, stop, and three-phase winding short-circuiting of the synchronous motor 40 to achieve electronic star-sealing.

[0143] At this time, the STO function is implemented as follows: the safety switch or the door lock switch is disconnected, causing the voltage at the end of the door lock to be de-energized; the two STO control signals ST024V1 / STOGND1 and ST024V2 / STOGND2 generated by the low-voltage power supply 70 are de-energized; after being processed by the safety torque cutoff module 11, the control buffer cuts off PWMUH / VH / WH and PWMUL / VL / WL; at this time, the electronic star-sealing signal is not enabled, and U+ / V+ / W+ and U- / V- / W- input to the drive module 20 are cut off. The six PWM signals processed by the drive module 20 stop emitting waves, thereby controlling the motor 40 to stop.

[0144] The electronic star-sealing function is implemented as follows: the main board 50 outputs a star-sealing control signal through communication with the safety torque cutoff and electronic star-sealing device 10; after logic processing by the electronic star-sealing module 12, U+ / V+ / W+ are always high and U- / V- / W- are always low; after processing by the drive module 20, the upper three-bridge switch tube of the switch module 30 is turned off and the lower three-bridge switch tube is turned on; thereby realizing the short circuit of the three-phase windings of the motor 40 and realizing the electronic star-sealing function.

[0145] In this system, the mainboard 50 is a crucial component for controlling the elevator timing. For example, when the elevator is stopped, the STO (Safe Torque Trigger) action lasts for a certain period, such as 100ms. The mainboard 50 then sends a star-sealing control signal to the safety torque cutoff and electronic star-sealing device 10. Upon receiving this signal, the control module 13 in the safety torque cutoff and electronic star-sealing device 10 controls the star-sealing enable signal FX to go high, triggering the electronic star-sealing function. When the elevator enters the running state, the mainboard 50 first sends a star-sealing enable removal command to the control module 13. Upon receiving this command, the control module 13 controls FX to go low. After a certain period, such as 100ms, the mainboard 50 controls the running contactor DO to engage, energizing ST024V1 / STOGND1 and ST024V2 / STOGND2 to 24V, thus removing the STO action.

[0146] The different operating states identified by the motherboard 50 are communicated with the DSP board 60 and the safety torque cutoff and electronic star-sealing device 10 via communication. The interaction with the DSP board 60 requires a fast response time, such as… Figure 4 As shown, communication is typically via a Serial Peripheral Interface (SPI). However, the interaction response time requirements between the motherboard 50 and the safety torque cutoff and electronic star-sealing device 10 are not high. Considering cost, such as... Figure 4 As shown, communication can be achieved via serial port (RX / TX).

[0147] As for the safety torque cutoff module 11 in this device, the safety torque cutoff module 11 is connected to the STO control signal and the self-test signal respectively (the self-test signal is issued by the control module 13 and is used to detect whether the control module itself has failed. That is, in addition to STO detection, the safety torque cutoff module 11 is also used to detect whether the control module 13 has failed). The safety torque cutoff module 11 is used to cut off the PWM signal when it fails to receive the normal STO control signal and the self-test signal at the same time.

[0148] The electronic star-sealing module 12 is connected to the control module 13. The electronic star-sealing module 12 is used to perform electronic star-sealing processing on the PWM signal when it receives the star-sealing enable signal sent by the control module 13.

[0149] The control module 13 receives the satellite sealing control signal and is also used to: send a satellite sealing enable signal to the electronic satellite sealing module 12 when the satellite sealing control signal is received; detect whether the safety torque cutoff module 11 and the electronic satellite sealing module 12 are faulty; if the safety torque cutoff module 11 is faulty, cut off the PWM signal or send a satellite sealing enable signal to the electronic satellite sealing module 12; if the electronic satellite sealing module 12 is faulty, cut off the PWM signal.

[0150] Furthermore, as described in the above embodiments, to achieve the required elevator functional safety level SIL3, dual STO detection can be implemented, namely, dual STO control signals and dual safety torque cutoff modules 11. In this case, a possible structure of the device is as follows: Figure 5 As shown (the two-level buffer structure and control module are omitted). The same principle applies to additional redundancy settings, which will not be elaborated upon in this embodiment.

[0151] Furthermore, regarding the specific implementation of the aforementioned safety torque cutoff module 11, this embodiment also provides an optional embodiment:

[0152] like Figure 6 As shown, the STO control signals are power signals (STO24V1, STO24V2, +24V). The safety torque cutoff module 11 includes two isolation units.

[0153] The two isolation units are connected in series to form a two-stage isolation circuit; the input terminal of the two-stage isolation circuit is connected to the self-test signal (TEST); the power supply terminal of the intermediate circuit of the two-stage isolation circuit is connected to the STO control signal; the signal output from the output terminal of the two-stage isolation circuit is used as the output signal of the safety torque cut-off module 11.

[0154] Specifically, such as Figure 6As shown, the two isolation units can be optocouplers. The two optocouplers are connected in series to form a two-stage optocoupler isolation circuit, isolating the circuit into three voltage levels. The input and output voltages of the two-stage isolation circuit are supplied by the default power supply (+5V), while the voltage of the intermediate circuit is provided by the STO control signal. Based on this structure, if the safety torque cut-off module 11 receives the STO control signal, the intermediate circuit of the two-stage isolation circuit is energized and can transmit signals normally (i.e., the self-test signal TEST). At this time, the two-stage isolation circuit outputs the same signal (point X) as the received signal. That is, if there is no STO control signal input, there is no signal output at point X. Triggering the STO action at this time also satisfies the STO detection requirement. If there is an STO control signal input but the self-test signal TEST is abnormal, the signal output at point X is also an abnormal self-test signal TEST. Triggering the STO action at this time also satisfies the failure detection requirement of control module 13. Only when there is an STO control signal input and the self-test signal TEST is normal will the normal self-test signal TEST be output at point X. If the control module 13 detects that the signal at point X is not the normal self-test signal TEST, it indicates that the safety torque cut-off module 11 has failed.

[0155] It should be noted that the circuit structure described above in this embodiment is only a basic structure of the safety torque cutting-off module 11. Other circuit structures can be added based on other needs. For example... Figure 6 In this embodiment, the addition of a buffer can achieve rectification of the output signal, the addition of a resistor-capacitor (RC) filter circuit can achieve filtering of the output signal, and so on. This embodiment does not limit this.

[0156] Furthermore, based on the safety torque cutoff module 11 provided in the above embodiment, when the safety torque cutoff module 11 is not faulty and is connected to the STO control signal, the safety torque cutoff module 11 will output its connected self-test signal TEST. Since the self-test signal TEST is output by the control module 13, and the safety torque cutoff module 11 is fault-detected by the control module 13, the control module 13 can detect its failure by detecting the output of the safety torque cutoff module 11. Based on this, this embodiment provides an optional failure detection scheme:

[0157] If the output signal of the safety torque cut-off module 11 is a pulse signal with a frequency different from that of the self-test signal, then the safety torque cut-off module 11 is determined to be faulty.

[0158] It should be noted that even in Figure 6In the circuit structure shown, a buffer is added to the output of the two-stage isolation circuit. The signal output after passing through the buffer is also a self-test signal TEST, and it has the same frequency as the self-test signal TEST (it is easier to detect whether the frequency of the signals is the same than to directly detect whether the signal waveforms are exactly the same). As described in the above embodiment, the failure detection of the control module 13 can be achieved by the control module 13 and the safety torque cutoff module 11 agreeing on a specific pulse signal with a fixed frequency (such as a pulse signal with a frequency of 1kHz and a pulse width of 200µs). At this time, the frequency of the pulse signal is known to the control module 13. If the safety torque cutoff module 11 has not failed, then when there is an STO control signal input, the signals STO1_FB / STO2_FB output by the safety torque cutoff module 11 should also have the same frequency. Based on this characteristic, the control module 13 can detect whether the safety torque cutoff module 11 has failed.

[0159] In addition, based on the safety torque cutting-off module 11 provided in the above embodiments, this embodiment also provides a further implementation scheme, such as... Figure 6 As shown, the safety torque cutoff module 11 also includes a DC-DC conversion unit.

[0160] The input terminal of the DC-DC converter is connected to the output terminal of the two-stage isolation circuit. The signal output from the two-stage isolation circuit is the first output signal of the safety torque cutoff module 11, which is output to the control module 13 to detect whether the safety torque cutoff module 11 has failed. The signal output from the DC-DC converter is the second output signal of the safety torque cutoff module 11, which is output to the cutoff control module 14 to control whether to cut off the PWM signal.

[0161] As can be seen from the above embodiments, in one optional implementation, the safety torque cutoff module 11 only needs to output a specific signal to enable the buffer 14 to achieve the cutoff control of the PWM signal. The buffer 14 generally requires a specific level signal to achieve enable control. However, in the specific circuit structure of the safety torque cutoff module 11 provided in the above embodiments, if the self-test signal TEST is a fixed-frequency pulse signal, then the safety torque cutoff module 11 will also output a fixed-frequency pulse signal under normal operating conditions, which cannot meet the control requirements of the buffer 14. Therefore, this embodiment adds a DC-DC conversion unit to convert the pulse signal output by the safety torque cutoff module 11 into a DC signal (equivalent to a high-level or low-level signal), thereby meeting the control requirements of the buffer 14.

[0162] Combination Figure 6The circuit structure shown has two signal outputs for the safety torque cutoff module 11: one is an output signal (STO1_FB / STO2_FB) used to detect whether the safety torque cutoff module 11 has failed, and the other is an output signal (STO_EN1 / STO_EN2) used to enable the buffer 14, satisfying the different output needs of the control module 13 and the buffer 14 respectively. Additionally, for... Figure 6 The dual-redundant safety torque cutoff module 11 shown is configured such that its two output enable signals should correspond to the first-stage buffer and the second-stage buffer in the two-stage buffer structure, respectively. Figure 3 As shown.

[0163] Furthermore, this embodiment does not limit the specific implementation of the DC-DC conversion unit. DC-DC conversion is a common function in current circuits and has various implementation schemes, including DC-DC converters; this embodiment does not limit this. However, this embodiment also provides an optional implementation scheme for the DC-DC conversion unit, such as... Figure 6 As shown, the DC-DC conversion unit is a resistor-capacitor (RC) filter unit. Through the RC filter unit, the pulse signals STO1_FB / STO2_FB can be deeply filtered, thereby converting them into DC signals STO_EN1 / STO_EN2.

[0164] As explained above, Functional Safety Indicator (SIL3) only needs to consider the failure of a single component. When a single component in a detection circuit fails, it is either a safe failure that has no impact on the function, or a dangerous failure that differs from the designed function. Assuming a dangerous failure occurs in one of the above circuits, when the door is closed and the STO is released, ST024V1 / STOGND1 and ST024V2 / STOGND2 receive 24V, and STO1_FB is not a pulse signal. The control module can detect this dangerous failure, thus meeting the elevator's functional safety requirements.

[0165] When the safety or door lock fails, ST024V1 / STOGND1 and ST024V2 / STOGND2 lose power. Functional safety SIL3 only needs to consider the failure of a single device. Dual-channel detection can ensure that at least one of STO1_FB / STO2_FB is high (assuming the buffer is enabled at a low level, and it is only enabled when both enable terminals of the buffer receive a low level), and at least one of STO_EN1 / STO_EN2 is high.

[0166] On the other hand, regarding the specific implementation of the electronic star-sealing module 12, this embodiment also provides an optional implementation scheme, wherein the electronic star-sealing module 12 includes: a first logic processing unit and a second logic processing unit.

[0167] The first logic processing unit is used to process the PWM signal of the upper bridge switch transistor of the corresponding elevator switch module 30 into a high-level signal when the star-sealing enable signal is received.

[0168] The second logic processing unit is used to process the PWM signal of the lower bridge switch transistor of the elevator switching module 30 in the PWM signal into a low-level signal when the star-sealing enable signal is received.

[0169] As described in the above embodiments regarding the electronic star-sealing function, the electronic star-sealing function is achieved when the three-phase windings of the motor 40 are short-circuited via the switching module 30. The short-circuiting of the three-phase windings of the motor 40 can be achieved by controlling the three IGBT devices of one half-bridge in the switching module 30 to be turned on and the three IGBT devices of the other half-bridge to be turned off. However, in this embodiment, the electronic star-sealing function is achieved by controlling the three IGBT devices of the upper half-bridge to be turned off and the three IGBT devices of the lower half-bridge to be turned on. This is because the upper half-bridge is connected to a power supply (drive signals VGUH / UL / UW). If the electronic star-sealing is achieved by turning on the three IGBT devices of the upper half-bridge, the three-phase windings of the motor 40 will be connected to a high-voltage power supply, causing the star-sealing to fail and potentially exacerbating the runaway.

[0170] Furthermore, regarding the specific implementation of the second and third logic processing units in the above embodiments, this embodiment also provides an optional implementation scheme, such as... Figure 3 As shown:

[0171] The star-blocking enable signal FX is a high-level signal; the second logic processing unit includes an OR gate chip; the third logic processing unit includes a series NOT gate chip and an AND gate chip; wherein, the output terminal of the NOT gate chip is connected to the input terminal of the AND gate chip, and the input terminal of the NOT gate chip is connected to the star-blocking enable signal.

[0172] As can be seen from the above embodiments, to achieve electronic star-blocking by turning off the three IGBT devices in the upper half-bridge and turning on the three IGBT devices in the lower half-bridge, it is required that the three signals U+ / V+ / W+ corresponding to the upper half-bridge in the processed 6-channel PWM signals be at a high level, and the three signals U- / V- / W- corresponding to the lower half-bridge be at a low level. At this time, regardless of the original PWM signals UH / VH / WH / UL / VL / WL, by performing an OR operation between UH / VH / WH and logic "1", and an AND operation between UL / VL / WL and logic "0", it is certain that UH / VH / WH=1 and UL / VL / WL=0. In this embodiment, the star-blocking enable signal FX, which is effective at a high level (i.e., logic "1"), can be processed by a NOT gate to obtain another signal NFX, which is equivalent to logic "0", and is used for AND operation with UL / VL / WL. Similarly, if the star-blocking enable signal FX=0, then the OR process will not affect the original upper half-bridge PWM signal, i.e., U+ / V+ / W+=UH / VH / WH. And, if NFX=1, then the AND process will not affect the original lower half-bridge PWM signal, i.e., U- / V- / W-=UL / VL / WL. In summary, the electronic star-blocking function processing logic is shown in Table 4 below:

[0173] Table 4 Logic Processing of Electronic Star-Sealing Device

[0174]

[0175] Furthermore, this embodiment also provides a specific structure of the driving module 20, such as... Figure 7 As shown: The upper and lower bridge drives of the three bridge arms of the switching module 30 are controlled by two drive optocouplers 1 and 2, respectively. Drive optocoupler 1 controls the drive of the upper bridge, and drive optocoupler 2 controls the drive of the lower bridge. When the frequency converter is powered on, the drive module 20 generates power supplies (VGE_Q1~Q6) for the upper and lower bridge drive optocouplers. The drive optocouplers are only controlled by the voltage between U+ / V+ / W+ and U- / V- / W-. Taking phase U as an example, when U+ is high and U- is low, the upper bridge of phase U is turned off, and the lower bridge of phase U is turned on. According to Table 4, when FX=1, the upper bridge of the switching module 30 is turned off and the lower bridge is turned on, thereby realizing the short circuit of the three-phase windings of the motor 40 and realizing the electronic star-sealing function. It should also be noted that since the drive module 20 is not part of the elevator integrated control device 10 provided in this application, it is not necessary to set up a corresponding dangerous failure detection scheme in this device.

[0176] However, in the electronic star-sealing module 12 provided in the above embodiments, logic processing modules such as NOT gate chips, AND gate chips and OR gate chips are introduced. These are part of the device and their functional safety under single failure needs to be considered.

[0177] Specifically, considering that NFX is obtained by processing FX with a NOT gate chip; U+ / V+ / W+ is obtained by processing UH / VH / WH and FX with an OR gate chip after buffer processing; and U- / V- / W- is obtained by processing UL / VL / WL and NFX with NFX after buffer processing, functional safety needs to consider the failure of these newly added chips. This is because U+ / V+ / W+ and U- / V- / W- after processing by the electronic star-sealing module 12 will affect the drive's waveform, which is a dangerous failure. If the chip failure cannot be detected, the safety failure score (SFF) and diagnostic coverage (DC) will be affected and reduced, thus failing to meet the functional safety SIL3 requirement. Furthermore, since functional safety only needs to consider the failure of a single device, and the elevator's operating status is sent in real time by the main board 50 to the control module 13 of this STO via communication, the single chip failure cases in the electronic star-sealing module 12 are summarized in Table 5 below.

[0178] Table 5 Summary of feedback when no device failure was detected during the star-sealing detection in various elevator states

[0179]

[0180] This embodiment, in conjunction with Table 5 below, details how to detect a single failure of an electronically sealed chip using the PESSRAL (Elevator Safety Related Programmable Electronic System) scheme (i.e., through control module 13):

[0181] 1. NOT gate chip failure:

[0182] 1-1: The NOT gate chip's input and output are short-circuited, i.e., NFX = FX. In this case, the theoretical results of FX and NFX in the four elevator states in Table 5 can all identify this type of failure.

[0183] 1-2: The NOT gate chip output is open, meaning NFX is always low. In this case, the theoretical results of NFX for the first three elevator states in Table 5 can all identify this type of failure.

[0184] 2. OR gate chip failure:

[0185] 2-1: The OR gate chip output and FX are short-circuited, meaning U+ / V+ / W+ are always equal to FX. In this case, the theoretical results of U+ / V+ / W+ under the second elevator state in Table 5 can be used to identify this type of failure.

[0186] 2-2: The OR gate chip output and UH / VH / WH are short-circuited, meaning U+ / V+ / W+ is always UH / VH / WH. In this case, the theoretical results of U+ / V+ / W+ in the fourth elevator state in Table 5 can be used to identify this type of failure.

[0187] 2-3: The OR gate chip output is open, meaning U+ / V+ / W+ is always 0. In this case, the theoretical results of U+ / V+ / W+ under the second and fourth elevator states in Table 5 can be used to identify this type of failure.

[0188] 3. AND gate chip failure:

[0189] 3-1: The AND gate chip output and NFX are short-circuited, meaning U- / V- / W- are always NFX. In this case, the theoretical results of U- / V- / W- in the first three elevator states in Table 5 can all identify this type of failure.

[0190] 3-2: The AND gate chip output and UL / VL / WL are short-circuited, meaning U- / V- / W- is always UL / VL / WL. At this time, according to the theoretical results of U- / V- / W- under the four elevator operating states in Table 5, the output during failure is consistent with the output during normal operation. This type of failure can be considered a safety failure and does not affect the safety failure score (SFF) or the fault diagnosis rate (DC).

[0191] 3-3: The AND gate chip output is open, meaning U- / V- / W- is always 0. In this case, the theoretical results of U- / V- / W- in the second elevator state in Table 5 can be used to identify this type of failure.

[0192] Therefore, by detecting FX, NFX, U+ / V+ / W+, and U- / V- / W-, the failure status of each component in the electronic star-sealing module 12 can be detected, ensuring that the safety failure fraction (SFF) and fault diagnosis rate (DC) are both equal to 1, without affecting functional safety. In view of this, and in conjunction with the failure detection of the safety torque cutoff module 11 in other embodiments described above, this embodiment also provides a further failure detection scheme, such as... Figure 8 As shown:

[0193] The control module 13 is also connected to the output terminals of the OR gate chip, AND gate chip, and NOT gate chip respectively, and is used to determine whether the electronic star-sealing module 12 is faulty based on the output signals of the OR gate chip, AND gate chip, and NOT gate chip.

[0194] Specifically by Figure 8It can be seen that the control module 13 has 4 signal outputs, namely the self-test signal TEST, STO_SAFE1, STO_SAFE1 (used to control the buffer enable, i.e., trigger the STO function), and FX (used to trigger the electronic star-sealing function). It also has 9 signal inputs (used for failure detection feedback signals), namely STO1_FB / STO2_FB (used to detect whether the two safety torque cutoff modules 11 have failed), NFX (used to detect whether the NOT gate chip in the electronic star-sealing module 12 has failed), U+ / V+ / W+ (used to detect whether the OR gate chip in the electronic star-sealing module 12 has failed), and U- / V- / W- (used to detect whether the AND gate chip in the electronic star-sealing module 12 has failed).

[0195] As can be seen from the above embodiments, regardless of which device in this device fails, protection can be provided by triggering the STO function. Therefore, when any of the above nine feedback signals is abnormal, the control module 13 can trigger the STO function by pulling the STO_SAFE signal low.

[0196] Based on this, this embodiment can realize the single failure detection of all components in the safety torque cutoff and electronic star-sealing device 10, thereby ensuring that the safety level of this device can meet the needs of elevator operation.

[0197] On the other hand, to further improve the functional safety of this device, this embodiment also provides an optional implementation scheme from other aspects, such as... Figure 9 As shown, this device also includes an overvoltage and overcurrent detection module 16.

[0198] Specifically, the overvoltage and overcurrent detection module 16 includes a resettable fuse and a Zener diode (when the power supply VIN is 5V, a 5.1V Zener diode can be used). Based on this, the +5VIN main feedback from the underlying driver board passes through the resettable fuse and the 5.1V Zener diode; when +5VIN is overvoltage, the Zener diode stabilizes the voltage at 5.1V; when +5VIN is overcurrent, the impedance of the resettable fuse surges, limiting the current rise and thus achieving overcurrent protection.

[0199] Similarly, this embodiment also provides another optional implementation scheme, such as... Figure 10 As shown, the device also includes a low-dropout linear regulator (LDO) module 17 and a watchdog reset chip 18.

[0200] The LDO module 17 converts +5V to +3.3V output, providing a power signal at another voltage level. The watchdog reset chip 18 detects whether the +5V and +3.3V power signals are undervoltage. If undervoltage occurs, it resets the control module 13 to implement undervoltage protection.

[0201] In summary, this embodiment further describes other hardware structures in the elevator integrated control device 10 provided in this application. It provides a contactless STO and electronic star-sealing function implementation scheme. While ensuring control of the elevator's STO and electronic star-sealing functions, each added functional module can detect whether it has failed and trigger corresponding protection actions upon failure, ensuring that the functional safety of the device in implementing the STO and electronic star-sealing functions meets the needs of actual elevator application scenarios.

[0202] In the above embodiments, an elevator integrated control device has been described in detail. This application also provides an embodiment corresponding to a scheme for detecting dangerous failure of the buffer in an elevator integrated control device. Figure 11 As shown, a method for detecting hazardous failures, applied to an elevator integrated control device provided in the above embodiments, includes:

[0203] S11: Controls the buffer to be in the enabled and disabled states respectively.

[0204] S12: When the buffer is in the enabled state and the actual level states at the input and output terminals of the buffer are inconsistent, it is determined that the buffer has an open circuit failure.

[0205] S13: When the buffer is in an disabled state and the actual level states at the input and output terminals of the buffer are consistent, it is determined that the buffer has a short-circuit failure.

[0206] Furthermore, as described in the embodiments of the above-described device, this application also provides another method for detecting dangerous failures, specifically for application scenarios where the number of buffers is two:

[0207] There are two buffers, cascaded together; the default voltage level of the input of the first-stage buffer is low. The specific method includes:

[0208] S21: Traverse each detection state and obtain the actual level state at the PWM signal output terminal after each traversal; there are 4 detection states: first detection state, both the first-level buffer and the second-level buffer are disabled; second detection state, the first-level buffer is enabled and the second-level buffer is disabled; third detection state, the first-level buffer is disabled and the second-level buffer is enabled; fourth detection state, both the first-level buffer and the second-level buffer are enabled.

[0209] S22: When traversing the first detection state and the actual level state obtained is high, it is determined that the first-level buffer has an open circuit failure.

[0210] S23: When traversing the second detection state and the actual level state obtained is low, it is determined that the first-level buffer has a short-circuit failure.

[0211] S24: When traversing the third detection state and the actual level state obtained is low, it is determined that the second-level buffer has an open circuit failure.

[0212] S25: When traversing the fourth detection state and the actual level state obtained is high, it is determined that the second-level buffer has a short-circuit failure.

[0213] Since the methods provided in the above embodiments are all specifically described in the embodiments of the apparatus section, please refer to the embodiments of the apparatus section above for the embodiments of the method section, and they will not be repeated here.

[0214] The above embodiments provide a method for detecting hazardous failures. This application also provides an embodiment of a corresponding hazardous failure detection device. It should be noted that this application describes the device embodiment from two perspectives: one based on functional modules, and the other based on hardware.

[0215] From the perspective of functional modules, this embodiment provides a hazardous failure detection device, including:

[0216] The enable control module is used to control the buffer to be in the enabled and disabled states respectively.

[0217] The open-circuit detection module is used to determine if the buffer has an open-circuit failure when the buffer is in the enabled state and the actual voltage levels at the input and output terminals of the buffer are inconsistent.

[0218] The short-circuit detection module is used to determine that the buffer has a short-circuit failure when the buffer is in an disabled state and the actual voltage levels at the input and output terminals of the buffer are the same.

[0219] Since the embodiments of the apparatus and the embodiments of the method correspond to each other, please refer to the description of the embodiments of the method for the embodiments of the apparatus, which will not be repeated here.

[0220] This application also provides a hazardous failure detection device comprising: a memory for storing a computer program; and a processor for executing the computer program to implement the steps of a hazardous failure detection method as described in the above embodiments.

[0221] The hazardous failure detection device provided in this embodiment may include, but is not limited to, computers, workstations, etc.

[0222] The processor may include one or more processing cores, such as a quad-core processor or an octa-core processor. The processor can be implemented using at least one of the following hardware forms: Digital Signal Processor (DSP), Field-Programmable Gate Array (FPGA), or Programmable Logic Array (PLA). The processor may also include a main processor and coprocessors. The main processor, also known as the Central Processing Unit (CPU), is used to process data in the wake-up state; the coprocessors are low-power processors used to process data in the standby state. In some embodiments, the processor may integrate a Graphics Processing Unit (GPU), which is responsible for rendering and drawing the content to be displayed on the screen. In some embodiments, the processor may also include an Artificial Intelligence (AI) processor, which handles computational operations related to machine learning.

[0223] The memory may include one or more computer-readable storage media, which may be non-transitory. The memory may also include high-speed random access memory and non-volatile memory, such as one or more disk storage devices or flash memory devices. In this embodiment, the memory is used to store at least the following computer program, which, after being loaded and executed by a processor, is capable of implementing the relevant steps of a hazardous failure detection method disclosed in any of the foregoing embodiments. In addition, the resources stored in the memory may also include an operating system and data, and the storage method may be temporary or permanent. The operating system may include Windows, Unix, Linux, etc. The data may include, but is not limited to, a hazardous failure detection method.

[0224] In some embodiments, a hazardous failure detection device may further include a display screen, an input / output interface, a communication interface, a power supply, and a communication bus.

[0225] Those skilled in the art will understand that the structures described in the above embodiments do not constitute a limitation on a single hazardous failure detection device, and may include more or fewer components than those described above.

[0226] This application provides a hazardous failure detection device, which includes a memory and a processor. When the processor executes a program stored in the memory, it can implement the following method: a hazardous failure detection method.

[0227] Finally, this application also provides an embodiment corresponding to a computer-readable storage medium. The computer-readable storage medium stores a computer program, which, when executed by a processor, implements the steps described in the above method embodiments.

[0228] It is understood that if the methods in the above embodiments are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and executes all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0229] The above provides a detailed description of an elevator integrated control device and a method, apparatus, and medium for detecting hazardous failures provided in this application. The various embodiments in the specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For the apparatus disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple; relevant parts can be referred to in the method section. It should be noted that those skilled in the art can make several improvements and modifications to this application without departing from the principles of this application, and these improvements and modifications also fall within the protection scope of this application.

[0230] It should also be noted that, in this specification, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

Claims

1. An integrated elevator control device, comprising: The system comprises a PWM signal input terminal, a PWM signal output terminal, a safety torque cutoff module, an electronic star-sealing module, and a control module; characterized in that it further includes a buffer and a default level configuration module. The buffer is connected in series in the signal path between the PWM signal input terminal and the PWM signal output terminal, and the first enable terminal of the buffer is connected to the safety torque cutoff module, and the second enable terminal of the buffer is connected to the control module; the buffer is used to: cut off the output of the PWM signal when the first enable terminal or the second enable terminal does not receive an enable signal; The default level configuration module is connected to the input and output terminals of the buffer respectively, and is used to make the default level states of the input and output terminals of the buffer different. The control module is used to: control the buffer to be in an enabled state and an disabled state respectively by outputting an enable signal; and determine the failure state of the buffer according to the actual level state at the input and output terminals of the buffer under different operating states.

2. The elevator integrated control device according to claim 1, characterized in that, The number of safety torque cutoff modules is N, where N is any positive integer greater than 1; The number of buffers is N, and the control module includes N output terminals; The first enable terminals of the N buffers are respectively connected to the N safety torque cutoff modules, and the second enable terminals of the N buffers are respectively connected to the N output terminals of the control module; and the N buffers are cascaded to form a multi-level buffer structure. The default level states of the input and output terminals of each buffer in the multi-level buffer structure are different. The control module is used to control each buffer in the multi-level buffer structure to be in an enabled state and an disabled state respectively by outputting an enable signal; and to determine the failure state of the buffer according to the actual level state at the input and output terminals of the buffer under different working states.

3. The elevator integrated control device according to claim 2, characterized in that, N=2, and the input terminal of the control module is connected to the output terminal of the PWM signal; The control module is also used to: traverse each detection state; and after each traversal, obtain the actual level state at the PWM signal output terminal; The failure state of each buffer is determined based on the actual level state and the theoretical level state at the PWM signal output terminal. There are four detection states: the first detection state, in which both the first-level buffer and the second-level buffer are disabled; the second detection state, in which the first-level buffer is enabled and the second-level buffer is disabled; the third detection state, in which the first-level buffer is disabled and the second-level buffer is enabled; and the fourth detection state, in which both the first-level buffer and the second-level buffer are enabled. The theoretical level state is determined based on the current operating state of each buffer.

4. The elevator integrated control device according to any one of claims 1 to 3, characterized in that, The PWM signal has M channels, where M is any positive integer greater than 1; The buffer includes M input terminals and output terminals; The default level states corresponding to the M input terminals of the same buffer are the same, and the default level states corresponding to the M output terminals of the same buffer are the same.

5. The elevator integrated control device according to claim 1, characterized in that, The default level configuration module includes: pull-up resistors and pull-down resistors; The first end of the pull-up resistor / pull-down resistor is connected to the pull-up power supply / ground terminal, and the second end of the pull-up resistor / pull-down resistor is connected to the input / output terminal of the buffer.

6. A method for detecting hazardous failures, characterized in that, The method, applied to the elevator integrated control device as described in claim 1, includes: The buffer is controlled to be in an enabled state and an disabled state, respectively. When the buffer is in the enabled state and the actual voltage levels at the input and output terminals of the buffer are inconsistent, it is determined that the buffer has an open-circuit failure. When the buffer is in an disabled state and the actual voltage levels at the input and output terminals of the buffer are consistent, it is determined that the buffer has experienced a short-circuit failure.

7. The hazardous failure detection method according to claim 6, characterized in that, The number of buffers is two, and the two buffers are cascaded together; the default level state corresponding to the input terminal of the first-stage buffer is low. The method also includes: The detection states are iterated through, and after each iteration, the actual level state at the PWM signal output terminal is obtained. There are four detection states: First detection state, where both the first-stage and second-stage buffers are disabled; Second detection state, where the first-stage buffer is enabled and the second-stage buffer is disabled; Third detection state, where the first-stage buffer is disabled and the second-stage buffer is enabled; Fourth detection state, where both the first-stage and second-stage buffers are enabled. When the first detection state is traversed and the actual level state is high, it is determined that the first-level buffer has an open-circuit failure. When the second detection state is traversed and the actual level state obtained is low, it is determined that the first-level buffer has a short circuit failure. When the third detection state is traversed and the actual level state obtained is low, it is determined that the second-level buffer has an open circuit failure. When the fourth detection state is traversed and the actual level state is obtained as high, it is determined that the second-level buffer has a short-circuit failure.

8. A hazardous failure detection device, characterized in that, The elevator integrated control device as described in claim 1 includes: An enable control module is used to control the buffer to be in an enabled state and an disabled state, respectively. An open-circuit detection module is used to determine that the buffer has an open-circuit failure when the buffer is in the enabled state and the actual level states at the input and output terminals of the buffer are inconsistent. A short-circuit detection module is used to determine that the buffer has a short-circuit failure when the buffer is in an disabled state and the actual voltage levels at the input and output terminals of the buffer are consistent.

9. A hazardous failure detection device, characterized in that, include: Memory, used to store computer programs; A processor, configured to implement the steps of the hazardous failure detection method as described in claim 6 or 7 when executing the computer program.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the steps of the hazardous failure detection method as described in claim 6 or 7.