Real-time communication connection method and device for elevator faults

By analyzing the operational event sequence and main power status signal of the elevator control unit, potential communication failures are identified, a standby monitoring mode is initiated, and response load information is transmitted back. This resolves the "false online" state after elevator communication interruption and enables reliable recovery of elevator communication and timely reporting of fault information.

CN121872202APending Publication Date: 2026-04-17SHENZHEN CREATE RESOURCE ELECTROMECHANICS & TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
SHENZHEN CREATE RESOURCE ELECTROMECHANICS & TECH CO LTD
Filing Date
2026-02-10
Publication Date
2026-04-17

AI Technical Summary

Technical Problem

After a communication interruption, especially during a brief offline period caused by a sudden power disturbance or controller reset, the existing elevator system may enter a "false online" state, causing fault information to remain locally, making it difficult for traditional active reconnection mechanisms to identify and restore communication.

Method used

By analyzing the operating event sequence and main power status signal of the elevator control unit, potential communication failures are identified, a standby monitoring mode is initiated, the downlink command frame header characteristics of the remote monitoring center are captured, response payload information is generated, and the information is transmitted back through a preset channel to achieve implicit reconstruction of the bidirectional communication link.

Benefits of technology

It enables accurate identification of the uninitialized state of the communication module without relying on active reconnection and heartbeat mechanisms, improves the timely reporting of fault information and system robustness, and ensures reliable recovery from communication interruptions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121872202A_ABST
    Figure CN121872202A_ABST
Patent Text Reader

Abstract

The invention provides an elevator fault-oriented real-time communication connection method and device, and the method comprises the steps: determining an operation continuity abnormal signal based on an operation event sequence of an elevator control unit in a continuous operation process, and determining an elevator fault-oriented real-time communication connection state based on the operation continuity abnormal signal in combination with an elevator main power supply state signal and a door machine action signal; determining a potential failure judgment result of the communication function; starting a standby monitoring mode of a local communication module on the basis of a communication function potential failure judgment result under the condition that an active query instruction of the remote monitoring center is not received; downlink instruction frame header characteristics from a remote monitoring center are continuously captured based on a standby monitoring mode, a remote end communication activity indication signal is obtained, and a local communication module is triggered based on the remote end communication activity indication signal to generate response load information; and implicit reconstruction of the bidirectional communication link is completed based on the response load information. According to the invention, reliable recovery of elevator communication interruption is realized, and the timeliness of fault reporting and the robustness of the system are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of communication technology, and in particular to a real-time communication connection method and apparatus for elevator faults. Background Technology

[0002] Currently, elevator systems generally adopt a "proactive reconnection after failure" strategy after a communication interruption. That is, once the loss of connection with the remote monitoring center is detected, the local communication module immediately attempts to re-establish the network connection, for example by restarting the network interface, redialing, or resending the registration request.

[0003] However, during a brief offline period caused by a sudden power disturbance or controller reset, if the communication module itself has not yet completed initialization, but the upper-level control logic has resumed operation, the system may mistakenly determine that "communication function is normal," thus failing to trigger any recovery actions. In reality, due to the underlying communication driver not being ready or the network session context being lost, data still cannot be uploaded, resulting in a "false online" state. This type of state is difficult to identify by traditional active reconnection mechanisms, causing fault information to remain locally for an extended period. Summary of the Invention

[0004] This invention provides a real-time communication connection method and apparatus for elevator faults, which enables reliable recovery of elevator communication interruptions without relying on active reconnection or using a heartbeat mechanism, thereby improving the timeliness of fault reporting and system robustness.

[0005] In a first aspect, the present invention provides a real-time communication connection method for elevator malfunctions, comprising: Based on the sequence of operating events of the elevator control unit during continuous operation, an abnormal signal of continuous operation is determined, and based on the abnormal signal of continuous operation combined with the elevator main power status signal and the door operator action signal, the potential failure judgment result of the communication function is determined. Based on the potential failure determination result of the communication function, and without receiving an active query instruction from the remote monitoring center, the standby listening mode of the local communication module is activated. Based on the standby monitoring mode, the downlink command frame header features from the remote monitoring center are continuously captured to obtain the remote end communication activity indication signal, and the local communication module is triggered to generate response payload information based on the remote end communication activity indication signal. The response payload information is transmitted back to the remote monitoring center based on the preset communication channel, thereby completing the implicit reconstruction of the two-way communication link.

[0006] Secondly, the present invention also provides a real-time communication connection device for elevator faults, applied to the real-time communication connection method for elevator faults as described in the first aspect; the device includes: The communication function monitoring module is used to determine the operation continuity abnormal signal based on the operation event sequence of the elevator control unit during continuous operation, and to determine the potential failure judgment result of the communication function based on the operation continuity abnormal signal combined with the elevator main power status signal and the door operator action signal. The monitoring mode activation module is used to activate the standby monitoring mode of the local communication module based on the potential failure determination result of the communication function and without receiving an active query instruction from the remote monitoring center. The remote communication triggering module is used to continuously capture the downlink instruction frame header features from the remote monitoring center based on the standby listening mode, obtain the remote end communication activity indication signal, and trigger the local communication module to generate response payload information based on the remote end communication activity indication signal. The communication restoration module is used to transmit the response payload information back to the remote monitoring center based on a preset communication channel, thereby completing the implicit reconstruction of the bidirectional communication link.

[0007] Thirdly, the present invention also provides an electronic device, comprising: a memory for storing computer software programs; and a processor for reading and executing the computer software programs, thereby realizing the real-time communication connection method for elevator faults as described above.

[0008] Fourthly, the present invention also provides a non-transitory computer-readable storage medium storing a computer software program, which, when executed by a processor, implements the real-time communication connection method for elevator faults as described above.

[0009] Fifthly, the present invention also provides a computer program product, including a computer program that, when executed by a processor, implements the real-time communication connection method for elevator faults as described above.

[0010] The real-time communication connection method for elevator faults provided in this invention determines the continuity anomaly signal by analyzing the event sequence of continuous operation of the elevator control unit. Combined with the elevator main power supply status signal and door operator action signal, it obtains a potential communication function failure judgment result. This accurately identifies "false online" states caused by incomplete initialization of the communication module, incomplete underlying driver readiness, or loss of network session context, preventing the system from misjudging the communication function as normal and failing to trigger recovery actions. Based on the potential communication function failure judgment result, the local communication module is activated in standby listening mode when no active query command is received from the remote monitoring center, putting the local communication module in a ready state. The standby listening mode continuously captures the downlink command frame header characteristics of the remote monitoring center to obtain the remote end communication activity indication signal, thereby triggering the local communication module to generate response payload information. This achieves accurate perception of the remote end communication status and completes local response preparation. The response payload information is transmitted back through the preset communication channel, and the implicit reconstruction of the two-way communication link is completed, so that the fault information stuck locally can be successfully uploaded to the remote monitoring center. This achieves reliable recovery of elevator communication interruption without relying on active reconnection or using a heartbeat mechanism, and improves the timeliness of fault reporting and system robustness. Attached Figure Description

[0011] Figure 1 This is a flowchart of a real-time communication connection method for elevator faults provided in an embodiment of the present invention; Figure 2 This is a structural diagram of a real-time communication connection device for elevator faults provided in an embodiment of the present invention; Figure 3 An embodiment diagram of the electronic device provided in this invention; Figure 4 An embodiment diagram of a computer-readable storage medium provided in accordance with the present invention. Detailed Implementation

[0012] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0013] Optionally, see Figure 1 , Figure 1 This is a flowchart of a real-time communication connection method for elevator faults provided by the present invention. In this embodiment of the invention, the executing entity of the real-time communication connection method for elevator faults is an elevator management device. Therefore, the real-time communication connection method for elevator faults includes: Step 10: Based on the sequence of operating events of the elevator control unit during continuous operation, determine the abnormal signal of continuous operation, and based on the abnormal signal of continuous operation combined with the elevator main power status signal and the door operator action signal, determine the potential failure judgment result of the communication function.

[0014] Optionally, the elevator management device collects all operating events generated by the elevator control unit during continuous operation in real time, forming an operating event sequence. The elevator control unit refers to the core control component responsible for controlling all elevator movements, including lifting, opening and closing doors, and stopping at floors.

[0015] Continuous operation refers to the complete operation phase of the elevator from the start of a normal start-up to before it stops due to abnormal factors such as malfunction or shutdown command, during which there is no prolonged inactivity (prolonged inactivity is defined as no operation for 30 seconds or more).

[0016] Operational events refer to various operation-related actions and status changes that occur during the continuous operation of an elevator and can be detected and recorded by the elevator control unit, including but not limited to elevator start-up, elevator acceleration, elevator constant speed, elevator deceleration, elevator stopping at a designated floor, elevator door opening, elevator door closing, elevator overload warning, and elevator malfunction shutdown.

[0017] The operation event sequence refers to the ordered set formed by the elevator management device after collecting and organizing all operation events generated by the elevator control unit during continuous operation in chronological order. Each operation event corresponds to a unique collection time point, with time accuracy down to the millisecond level.

[0018] Optionally, the elevator management device performs event-by-event verification and analysis on the collected sequence of operating events to determine whether there is an operational continuity anomaly and to identify the operational continuity anomaly signal. An operational continuity anomaly refers to a situation where, during continuous elevator operation, the order or time interval of operating events does not conform to the normal operating rules of the elevator, or there are instances of missing, redundant, or disordered events, resulting in the elevator's operational state being unable to maintain continuity and stability. The operational continuity anomaly signal is a signal generated by the elevator management device after detecting an operational continuity anomaly to identify the existence of the anomaly. This signal is only used for subsequent potential failure determination of communication functions and is not transmitted externally. The signal generation follows the principle of "generated if there is an anomaly, not generated if there is no anomaly"; no corresponding signal is generated when there is no anomaly.

[0019] Optionally, the verification and analysis of the running event sequence in this embodiment of the invention adopts a combination of time sequence verification and logical sequence verification. The specific process is as follows: The acquisition time point of each running event in the running event sequence is checked one by one, and the time interval between two adjacent running events is calculated. If the time interval between two adjacent running events exceeds the normal time interval range of the corresponding event combination, it is determined to be an abnormal time interval, belonging to an abnormal running continuity. The event logical sequence of normal elevator operation (e.g., "start → accelerate → constant speed → deceleration → stop → door open → door close → next start") is compared one by one, and the occurrence order of events in the running event sequence is checked. If there are cases of reversed logical order (e.g., "door close → stop"), missing logical events (e.g., "no stop event after deceleration"), or redundant logical events (e.g., "door open event repeatedly occurs after stop"), it is determined to be an abnormal logical sequence, belonging to an abnormal running continuity.

[0020] The normal time interval ranges for different combinations of operating events are preset based on the elevator's rated operating parameters. These preset normal time interval ranges have all been verified through actual elevator operation tests to ensure they conform to normal elevator operation patterns. The specific preset rules are as follows: the normal time interval for elevator start-up and acceleration events is 1 to 3 milliseconds; the normal time interval for elevator acceleration and constant speed events is 5 to 8 milliseconds; the normal time interval for elevator constant speed and deceleration events is determined based on the elevator's floor height: 10 to 15 milliseconds for single-floor operation (adjacent floors), and an increase of 3 to 5 milliseconds for operation on two or more floors; the normal time interval for elevator deceleration and stopping events is 4 to 6 milliseconds; the normal time interval for elevator stopping and door opening events is 2 to 4 milliseconds; the normal time interval for elevator door opening and closing events is 3000 to 6000 milliseconds (i.e., 3 to 6 seconds); and the normal time interval for elevator door closing and the next start event is 1 to 3 milliseconds.

[0021] In one embodiment, the rated speed of an elevator is 1.5 m / s and the rated operating floors are floors 1 to 10. The elevator management device collects the continuous operating events of the elevator control unit with millisecond precision to form a sequence of operating events. The specific sequence is as follows (in chronological order, the time points in parentheses are the collection time points, unit: milliseconds): Elevator start (10) → Elevator acceleration (12) → Elevator constant speed (18) → Elevator deceleration (33) → Elevator stop (38) → Elevator door open (41) → Elevator door close (3043) → Elevator start (3045) → Elevator acceleration (3047) → Elevator constant speed (3053) → Elevator deceleration (3068) → Elevator stop (3073).

[0022] The sequence of running events was verified and analyzed: The time intervals between adjacent events were calculated as follows: from start to acceleration (2 milliseconds, within the normal range of 1-3 milliseconds), from acceleration to constant speed (6 milliseconds, within the normal range of 5-8 milliseconds), from constant speed to deceleration (15 milliseconds, this elevator is operating on a single floor, within the normal range of 10-15 milliseconds), from deceleration to stopping (5 milliseconds, within the normal range of 4-6 milliseconds), from stopping to door opening (3 milliseconds, within the normal range of 2-4 milliseconds), from door opening to door closing (3002 milliseconds, within the normal range of 3000-6000 milliseconds), from door closing to the next start (2 milliseconds, within the normal range of 1-3 milliseconds), from the next start to acceleration (2 milliseconds, within the normal range), from acceleration to constant speed (6 milliseconds, within the normal range), from constant speed to deceleration (15 milliseconds, single-floor operation, within the normal range), and from deceleration to stopping (5 milliseconds, within the normal range). The time intervals of all adjacent events did not exceed the preset normal range, and the time sequence verification was successful. Comparing the elevator's normal operating logic sequence—"start → accelerate → constant speed → decelerate → stop → door open → door close → next start"—the sequence of events matches perfectly, with no logical inversions, missing events, or redundancy. Therefore, the logical sequence verification is successful. Consequently, it is determined that this operating event sequence has no operational continuity anomalies, and no operational continuity anomaly signal is generated.

[0023] In another embodiment, using the same elevator, the sequence of collected running events is as follows (the time points in parentheses are the collection times, in milliseconds): elevator start (10) → elevator acceleration (13) → elevator constant speed (19) → elevator deceleration (34) → elevator stop (39) → elevator door open (42) → elevator door close (3044) → elevator acceleration (3046). The elevator management device performs verification analysis on this sequence. In the time sequence verification, the time interval between door closing and elevator acceleration is 2 milliseconds, which is within the normal range. However, in the logical sequence verification, no elevator start event occurs after the door closing event, and the elevator acceleration event occurs directly, which violates the normal logical sequence of "door closing → next start → acceleration". This is a logical event missing event and is judged as an abnormality in running continuity. The elevator management device generates an abnormality signal in running continuity.

[0024] Furthermore, based on the generated operational continuity anomaly signal, combined with the elevator main power supply status signal and the door operator action signal, the elevator management device determines the potential failure judgment result of the communication function, specifically as described in steps 101 to 104. The potential failure judgment result of the communication function includes "potential failure exists" and "potential failure does not exist." The elevator main power supply status signal refers to the working status signal of the elevator main power supply collected by the elevator management device, used to identify whether the elevator main power supply is supplying power normally (normal power supply or power failure); the door operator action signal refers to the action status signal of the elevator door operator collected by the elevator management device, used to identify whether the elevator door operator is in a normal operating state (door open, door closed, stationary).

[0025] Step 20: Based on the potential failure judgment result of the communication function, and without receiving an active query instruction from the remote monitoring center, start the standby listening mode of the local communication module.

[0026] Optionally, this embodiment of the invention only handles the case where the potential failure determination result of the communication function is "potential failure exists". If the potential failure determination result of the communication function is "no potential failure exists", the elevator management device will not perform the subsequent operations of this step, and the local communication module will maintain the normal working mode (the normal working mode means that the local communication module transmits elevator operation data to the remote monitoring center according to a preset cycle, and passively receives instructions from the remote monitoring center).

[0027] Furthermore, the elevator management device performs real-time judgment on whether it has received an active query command from the remote monitoring center. This active query command from the remote monitoring center refers to a query command sent proactively to the elevator management device by the remote monitoring center to obtain information such as the elevator's current operating status and communication status. This command has a unique identifier that can be accurately identified by the elevator management device. The command content includes, but is not limited to, querying the elevator's operating status, querying the communication link status, and querying elevator fault information. The judgment process is as follows: the elevator management device monitors the receiving port of its local communication module in real time. If it detects a command with the unique identifier, it determines that it has received an active query command from the remote monitoring center. At this time, the elevator management device responds to the query command according to the normal procedure and does not execute the standby listening mode activation operation. If, within a preset judgment time (the preset judgment time is set to 10 seconds, which can be adjusted according to actual communication needs), it is determined that it has not received an active query command from the remote monitoring center.

[0028] Furthermore, if it is determined that no active query instruction has been received from the remote monitoring center, the elevator management device sends a standby monitoring mode start instruction to the local communication module, triggering the local communication module to switch from the current working mode (if it is the normal working mode) to the standby monitoring mode.

[0029] The local communication module refers to the communication component integrated on the elevator management device, used to realize data transmission and command interaction between the elevator management device and the remote monitoring center. The standby listening mode refers to the working mode in which the local communication module reduces its own power consumption (power consumption is reduced to less than 30% of the normal working mode), disables the active data transmission function, and only retains the high-sensitivity listening function of the receiving port. In this mode, the local communication module does not actively transmit any data to the remote monitoring center, but only continuously listens for downlink commands from the remote monitoring center to ensure that it can quickly capture downlink signals sent by the remote monitoring center, while reducing elevator energy consumption.

[0030] It should be noted that the activation of the standby monitoring mode is unique. Once the elevator management device determines that the conditions of "potential failure of communication function" and "no active query instruction received from the remote monitoring center" are met, the standby monitoring mode will only be activated once. It will not exit this mode until the subsequent steps trigger the generation of response payload information, and will switch to temporary communication mode to complete the return of response payload information.

[0031] In one embodiment, for example, if the communication function potential failure determination result output in step 10 is "potential failure exists", the elevator management device begins to execute this step. First, the elevator management device confirms that the determination result is "potential failure exists", initiates the judgment process for the active query command from the remote monitoring center, and sets the judgment time to 10 seconds to monitor the receiving port of the local communication module in real time.

[0032] Within a 10-second judgment period, the local communication module's receiving port did not detect any instruction with a unique identifier for an active query instruction from the remote monitoring center. At this point, the elevator management device determined that no active query instruction from the remote monitoring center had been received. Subsequently, the elevator management device sent a standby listening mode activation command to the local communication module. Upon receiving this command, the local communication module immediately adjusted its operating parameters, reducing its power consumption (from 5 watts in normal operating mode to below 1.5 watts), disabling the active data transmission function, ceasing the transmission of any elevator operation data to the remote monitoring center, and retaining only the high-sensitivity listening function of the receiving port, entering standby listening mode to continuously listen for downlink instructions from the remote monitoring center.

[0033] In another embodiment, for example, if the communication function potential failure determination result output in step 10 is "potential failure exists," the active query instruction judgment process is initiated, and the judgment duration is set to 10 seconds. In the 3rd second of the judgment duration, the local communication module receiving port detects an instruction with a unique identifier for the remote monitoring center's active query instruction. The instruction content is "Query the current communication link status of the elevator." It immediately determines that it has received the active query instruction from the remote monitoring center, stops subsequent operations, does not initiate standby listening mode, but instead responds to the query instruction according to the normal process, sending back the elevator's current communication link status information to the remote monitoring center.

[0034] Step 30: Based on the standby listening mode, continuously capture the downlink command frame header features from the remote monitoring center to obtain the remote end communication activity indication signal, and trigger the local communication module to generate response payload information based on the remote end communication activity indication signal.

[0035] Optionally, after the local communication module enters standby monitoring mode, the elevator management device controls the local communication module to initiate continuous capture of downlink command frame header features. The entire capture process is monitored by the elevator management device to ensure the accuracy and continuity of the capture. The downlink command frame header feature refers to a unique identifier included in all downlink commands (including query commands, control commands, etc.) sent by the remote monitoring center to the elevator management device. This identifier is composed of fixed-length binary data (preset to 8 bits, adjustable according to communication security requirements). Each remote monitoring center's downlink command frame header feature is unique and will not repeat with the feature codes of other unrelated signals. The elevator management device pre-stores this unique frame header feature for comparison and identification during capture.

[0036] Furthermore, the local communication module's capture operation adopts a "continuous scanning + real-time comparison" method, the specific process of which is as follows: 1. The local communication module continuously scans all external signals received by its receiving port at a preset scanning frequency (set to 100 times / second, adjustable according to communication link bandwidth) to capture all detectable signal features; 2. The elevator management device compares each signal feature captured by the local communication module with the pre-stored downlink command frame header features of the remote monitoring center in real time. The comparison is performed bit by bit to ensure the accuracy of the comparison results; 3. If a captured signal feature is completely consistent with the pre-stored downlink command frame header features, it is determined that the downlink command frame header features of the remote monitoring center have been captured; if the captured signal feature is inconsistent with the preset frame header features, it is determined that it has not been captured, and the local communication module continues to scan and capture until a frame header feature that meets the requirements is captured, or the elevator management device issues a command to stop capturing.

[0037] During the capture process, if the local communication module fails to capture a signal feature consistent with the preset frame header feature within the preset capture time (the preset capture time is set to 30 seconds, which can be adjusted according to actual needs), the elevator management device controls the local communication module to stop the capture operation, restart the standby listening mode, and attempt to capture again; if a frame header feature that meets the requirements is captured within the preset capture time, the current scanning capture operation is immediately stopped, and the elevator management device generates a remote communication activity indication signal.

[0038] Among them, the remote communication activity indication signal refers to the signal generated by the elevator management device after confirming that the local communication module has captured the downlink command frame header features of the remote monitoring center. This signal is used to identify that the communication status of the remote monitoring center is active. This signal is only used to trigger the local communication module to generate response payload information and is not transmitted externally. The generation of the signal follows the principle of "generating if the frame header features are captured, and not generating if they are not captured". After being generated, it is immediately transmitted to the local communication module.

[0039] In one embodiment, for example, after step 20 has successfully started the standby listening mode of the local communication module, the elevator management device controls the local communication module to start the continuous capture operation of the downlink command frame header feature. The preset scanning frequency is 100 times / second, the preset capture duration is 30 seconds, and the downlink command frame header feature of the remote monitoring center pre-stored by the elevator management device is a fixed 8-bit binary feature code.

[0040] The local communication module continuously scans all external signals received by the receiving port at a frequency of 100 times per second. Each time a signal feature is detected, the elevator management device compares it bit-by-bit with a preset frame header feature. At the 12th second of the capture time, the local communication module detects a signal feature. The elevator management device compares this signal feature with the preset frame header feature, confirms a perfect match, and determines that a downlink command frame header feature from the remote monitoring center has been captured. It then controls the local communication module to stop scanning and capture, generates a remote communication activity indication signal, and transmits this signal to the local communication module.

[0041] In another embodiment, for example, after step 20 activates the standby monitoring mode of the local communication module, the elevator management device controls the local communication module to continuously capture downlink command frame header features at a scanning frequency of 100 times / second, with a preset capture duration of 30 seconds. Within the 30-second capture duration, the local communication module scans multiple external signal features, but after comparing these signal features with the preset frame header features, the elevator management device determines that they are all inconsistent, and no matching frame header features are captured. At this point, the elevator management device controls the local communication module to stop the current capture operation, restart the standby monitoring mode, and begin continuous capture of downlink command frame header features again until a matching frame header feature is captured.

[0042] Furthermore, based on the generated remote communication activity indication signal, the elevator management device triggers the local communication module to generate response payload information. That is, after the remote communication activity indication signal is generated, the elevator management device sends a response generation trigger command to the local communication module. After receiving the command, the local communication module automatically generates response payload information according to the preset response rules. The content of the response payload information meets the reception requirements of the remote monitoring center, as described in steps 301 to 304.

[0043] Step 40: Based on the preset communication channel, the response payload information is transmitted back to the remote monitoring center to complete the implicit reconstruction of the two-way communication link.

[0044] Optionally, the elevator management device confirms that the local communication module has successfully generated the response payload information and performs an integrity check on the response payload information to ensure that the response payload information is complete and error-free. The response payload information refers to the response data generated by the local communication module according to preset response rules after receiving the communication activity indication signal from the remote end. This data is used to respond to the downlink commands from the remote monitoring center. It contains key information such as the elevator's current communication status and operating status, and the data format conforms to the preset communication protocol to ensure that the remote monitoring center can parse it correctly. The integrity check involves the elevator management device verifying each data item of the response payload information one by one, confirming that all required data items exist and that the data content is normal (e.g., no garbled characters, no missing characters). Only after the verification is successful can subsequent data transmission operations proceed. If the verification fails, the elevator management device controls the local communication module to regenerate the response payload information until the verification is successful.

[0045] Furthermore, the elevator management device controls the local communication module to switch its operating mode from standby monitoring mode to temporary communication mode. Temporary communication mode refers to a temporary operating mode where the local communication module resumes active data transmission while maintaining high-sensitivity reception, used only for responding to payload information feedback. The power consumption in this mode is between the normal operating mode and the standby monitoring mode. After the feedback is completed, it automatically switches back to standby monitoring mode. If the downlink command frame header characteristics from the remote monitoring center are subsequently captured again, a rapid response can be initiated. The switching process is controlled entirely by the elevator management device, with a switching time not exceeding 1 millisecond, ensuring timely feedback of the response payload information.

[0046] Furthermore, the elevator management device controls the local communication module to transmit response load information back to the remote monitoring center through a preset communication channel.

[0047] The preset communication channel refers to a dedicated communication channel pre-agreed between the elevator management device and the remote monitoring center for data transmission and command interaction. This channel is characterized by stability, security, and low latency. The channel type can be selected according to the actual application scenario (such as 4G communication channel, 5G communication channel, wired Ethernet channel, etc.). The elevator management device pre-stores the parameters of this communication channel (such as channel address, transmission rate, etc.) to ensure accurate location of the remote monitoring center during feedback.

[0048] During the data transmission process, the elevator management device monitors the transmission status in real time. The transmission status includes "transmitting data", "transmission successful", and "transmission failed". If a transmission failure is detected (e.g., transmission is terminated due to signal interruption), the elevator management device controls the local communication module to retry the transmission. The preset number of retry attempts is 3, with an interval of 2 seconds between each retry. If all 3 retry attempts fail, the transmission stops, and the local communication module switches back to standby listening mode to continue capturing the downlink command frame header characteristics of the remote monitoring center. If a successful transmission is detected, it confirms that the response payload information has been successfully transmitted to the remote monitoring center.

[0049] Furthermore, once the response payload information is successfully transmitted back to the remote monitoring center, the implicit reconstruction of the bidirectional communication link is completed. This implicit reconstruction means that bidirectional communication between the remote monitoring center and the elevator management device is achieved solely through the elevator management device transmitting response payload information back to the remote monitoring center, without requiring a dedicated link reconstruction command between them. The reconstructed bidirectional communication link can then normally receive downlink commands from the remote monitoring center and transmit uplink data from the elevator management device until the elevator communication function returns to normal or a potential communication failure occurs again.

[0050] In one embodiment, for example, after the local communication module has successfully generated response payload information in step 30, the elevator management device first performs an integrity check on the response payload information, verifying each data item in the response payload information, such as elevator communication status and operating status, to confirm that all required data items exist, the data content is free of garbled characters and missing data, and the check is successful. Subsequently, the elevator management device controls the local communication module to switch from standby monitoring mode to temporary communication mode, with a switching time of 0.8 milliseconds. After the switch is completed, the local communication module resumes its active data transmission function.

[0051] The elevator management device invokes pre-stored preset communication channel parameters (here, a 4G communication channel is selected, and the channel parameters have been pre-configured) to control the local communication module to transmit response payload information back to the remote monitoring center through this 4G communication channel, while simultaneously monitoring the transmission status in real time. During the transmission process, the communication signal is stable, and the elevator management device monitors the transmission status to change from "transmitting back" to "transmission successful," confirming that the response payload information has been successfully transmitted to the remote monitoring center. At this point, without the remote monitoring center sending a dedicated link reconstruction command, the bidirectional communication link between the elevator management device and the remote monitoring center is implicitly reconstructed. The reconstructed link can normally receive downlink commands from the remote monitoring center and can also normally transmit elevator uplink data. The local communication module then automatically switches back to standby listening mode, completing this step and thus completing the implicit reconstruction process of the entire bidirectional communication link.

[0052] In another embodiment, for example, after the local communication module generates the response payload information in step 30, the elevator management device performs an integrity check on it and finds that the elevator operating status data item is missing from the response payload information, resulting in a failed check. At this time, the elevator management device controls the local communication module to regenerate the response payload information, and performs another integrity check, which passes. Subsequently, the local communication module is controlled to switch to temporary communication mode and transmit the response payload information back through a preset 4G communication channel. During the first transmission, due to the interruption of the 4G signal at the site, the elevator management device monitors the transmission failure. According to the preset rules, after an interval of 2 seconds, the local communication module is controlled to retransmit the information. During the second transmission, the 4G signal returns to normal, and the transmission is monitored to be successful, confirming that the response payload information has been successfully transmitted, thus completing the implicit reconstruction of the two-way communication link.

[0053] The embodiments of the present invention achieve reliable recovery of elevator communication interruptions without relying on active reconnection or using a heartbeat mechanism, thereby improving the timeliness of fault reporting and system robustness.

[0054] Optionally, the processes of steps 101 to 104 include: Step 101: Based on the timestamp information of the elevator control unit missing the expected response event during continuous operation contained in the operation continuity anomaly signal, determine the timing characteristics of the elevator local control logic execution interruption.

[0055] Optionally, the timestamp information of the elevator control unit missing expected response events during continuous operation is extracted from the operation continuity anomaly signal. Expected response events refer to corresponding operational events that will inevitably occur after a certain preceding event, according to a preset operating logic, during normal continuous elevator operation. That is, there is a fixed logical relationship between the preceding event and the expected response event. For example, after an "elevator deceleration event" occurs, the expected response event is an "elevator stopping event," and after an "elevator stopping event" occurs, the expected response event is an "elevator door opening event." The types of expected response events correspond one-to-one with the logical sequence of events during normal elevator operation and are pre-stored in the elevator management device.

[0056] A missing expected response event refers to a situation where, after the elevator management device detects a preceding event in the sequence of operating events, it fails to detect the corresponding expected response event within the preset expected response time range, thus determining that the expected response event is missing. Timestamp information refers to the specific time point at which the elevator control unit detects the occurrence of the preceding event, as well as the time point corresponding to the preset expected response event's expected time range. The time accuracy is down to the millisecond level. This timestamp information is collected in real time by the elevator control unit and synchronized to the elevator management device, and is ultimately included in the operational continuity anomaly signal.

[0057] Furthermore, time-series analysis is performed on the extracted timestamp information of missing expected response events to determine the timing characteristics of elevator local control logic execution interruptions. Elevator local control logic refers to the built-in logic rules of the elevator control unit used to control the continuous operation of the elevator, covering the control logic for all operational actions such as elevator start-up, acceleration, constant speed, deceleration, stopping, and door opening / closing. Local control logic execution interruption refers to the situation where, during the execution of the elevator local control logic, some factor causes the logic execution process to stagnate and fail to proceed normally, thus preventing the expected response event from occurring on time. Timing characteristics refer to quantifiable time-related features such as the specific time regularity, time interval, and duration of local control logic execution interruptions, used to accurately identify the occurrence state and pattern of local control logic execution interruptions.

[0058] The specific process for determining the timing characteristics is as follows: 1. The elevator management device extracts the timestamp of the preceding event corresponding to the missing expected response event, which serves as the start timestamp of the local control logic execution interruption; 2. The elevator management device calculates the preset time range of the expected response event corresponding to the preceding event, and determines the latest timestamp at which the expected response event should end, which serves as the estimated end timestamp of the local control logic execution interruption; 3. The time difference between the start timestamp and the estimated end timestamp is calculated as the estimated duration of the local control logic execution interruption; 4. If no corresponding expected response event is detected after the estimated end timestamp, and no other normal operation events occur in the elevator, the estimated end timestamp is updated, and the duration is recalculated until the next normal operation event is detected or the elevator stops running; 5. The elevator management device summarizes the start timestamps, estimated end timestamps, and estimated durations of all local control logic execution interruptions to form a complete timing characteristic. This timing characteristic uniquely corresponds to the local control logic execution interruption situation included in this operation continuity anomaly, providing accurate timing basis for the synchronization comparison of subsequent steps.

[0059] The preset time range of the expected response event is consistent with the normal time interval range of different combinations of running events to ensure the consistency and accuracy of the timing analysis. For example, the preset time range of the "elevator deceleration event" (preceding event) and the "elevator stopping event" (expected response event) is 4 to 6 milliseconds. If the timestamp of the elevator deceleration event is 100 milliseconds, then the latest timestamp at which the expected response event should end is 106 milliseconds. If the elevator stopping event is not detected after 106 milliseconds, it is determined that the expected response event is missing. The start timestamp of the local control logic execution interruption is 100 milliseconds, the estimated end timestamp is 106 milliseconds, and the estimated duration is 6 milliseconds. If the elevator stopping event is not detected after 106 milliseconds, the estimated end timestamp is updated every 1 millisecond, and the duration is recalculated.

[0060] Step 102: Based on the timing characteristics and the level stability information in the elevator main power supply status signal that represents the continuous and effective main power supply, perform a synchronous comparison to determine whether there is a target scenario where the local control logic is interrupted but the main power supply is in a normal power supply state, and obtain the synchronous comparison result.

[0061] Optionally, the elevator main power supply status signal is used to extract level stability information that indicates the continuous effectiveness of the main power supply. The elevator main power supply status signal refers to the signal collected in real time to identify the operating status of the elevator main power supply. This signal contains two types of status information: level stability information indicating the continuous effectiveness of the main power supply and level abnormality information indicating abnormal main power supply (power outage, voltage instability). Level stability information refers to the information that the output voltage of the elevator main power supply remains within a preset rated voltage range (the rated voltage of the elevator main power supply is preset according to the elevator model, for example, 380V AC voltage, the preset rated voltage range is 370V to 390V), with voltage fluctuations not exceeding 5%, and this stable state is maintained continuously. This information is collected in real time by the voltage detection module of the elevator main power supply and synchronously transmitted to the elevator management device. It includes key data such as the start time of voltage stability, duration, and voltage fluctuation value. The time accuracy is consistent with the timestamp information in step 101 (millisecond level) to ensure the accuracy of synchronous comparison.

[0062] Furthermore, the core of synchronous comparison is to accurately align the time information in the timing features with the time information in the level stability information, and determine whether there is overlap between the two in the time dimension, thereby determining whether a target scenario exists. The target scenario refers to a scenario where the elevator's local control logic execution is interrupted (the interruption state identified by the timing features) and the elevator's main power supply is normally powered (the stable state identified by the level stability information) occur simultaneously. Identifying this scenario is crucial to ruling out local control logic interruptions caused by abnormal main power supply, thus eliminating interference from non-communication factors for subsequent determination of potential communication function failures.

[0063] The specific process of synchronous comparison is as follows: 1. The elevator management device aligns the start timestamp and estimated end timestamp of each local control logic execution interruption in the timing characteristics with the voltage stabilization start time and voltage stabilization duration in the level stability information to ensure that the time accuracy of the two is consistent (both accurate to the millisecond level); 2. It checks whether the duration of each local control logic execution interruption (from the start timestamp to the estimated end timestamp) overlaps with the duration of voltage stabilization (from the voltage stabilization start time to the voltage stabilization start time + voltage stabilization duration); 3. If there is an overlap, and the overlap duration accounts for a certain proportion of the duration of the local control logic execution interruption... If the percentage of local control logic execution interruption is not less than 80%, it is determined that the elevator main power supply was in normal power supply state when the local control logic execution interruption occurred, i.e., the target scenario exists; 4. If there is no overlapping part, or the overlapping time percentage is less than 80%, it is determined that the elevator main power supply was not in normal power supply state when the local control logic execution interruption occurred, i.e., the target scenario does not exist; 5. The elevator management device summarizes all judgment results to form a synchronous comparison result. The synchronous comparison result only includes two cases: "target scenario exists" and "target scenario does not exist". If there is at least one local control logic execution interruption that meets the above judgment conditions, the synchronous comparison result is "target scenario exists"; otherwise, it is "target scenario does not exist".

[0064] It should be noted that the criterion of an overlap duration of no less than 80% is based on the actual test results of the stability of the elevator's main power supply. It can be adaptively adjusted according to the actual operating conditions of the elevator and the performance of the main power supply. The core purpose is to eliminate misjudgments caused by short-term voltage fluctuations and ensure the accuracy of the target scenario judgment.

[0065] Step 103: If the existence of a target scenario is determined based on the synchronous comparison results, the door operator drive system is judged to be in a controlled response state based on the physical feedback pulse sequence of the door operator's actual door opening and closing actions in the corresponding time period in the door operator action signal, and the execution verification result is obtained.

[0066] Optionally, the synchronization comparison result is judged. If the synchronization comparison result is "no target scenario exists", the elevator management device will not perform the subsequent operations of this step, and will directly determine that the interruption of local control logic execution is caused by abnormal main power supply and is unrelated to the communication function. The subsequent judgment of potential failure of communication function will not be performed. If the synchronization comparison result is "target scenario exists", the subsequent execution verification operation of this step will be started to further rule out the possibility that the interruption of local control logic execution is caused by abnormal door machine drive system.

[0067] Furthermore, the elevator management device extracts the physical feedback pulse sequence within the time period corresponding to the target scene from the door operator action signal.

[0068] Among them, the door operator action signal refers to the signal collected in real time to identify the action status of the elevator door operator. This signal is collected by the physical feedback module of the door operator and transmitted to the elevator management device, containing all physical feedback information of the actual door opening and closing actions performed by the door operator; the corresponding time period refers to the duration of the local control logic execution interruption in the synchronous comparison results (i.e., from the start timestamp of the local control logic execution interruption to the estimated end timestamp), ensuring that the extracted physical feedback pulse sequence completely corresponds to the time of the target scenario; the physical feedback pulse sequence refers to the continuous pulse signal generated by the physical feedback module (such as limit switch, encoder) of the door operator to identify the actual action of the door operator when the door operator performs the door opening and closing action. The frequency, amplitude, and number of pulses of this pulse sequence correspond one-to-one with the actual action status of the door operator. For example, when the door operator is open, the frequency of the pulse sequence is 10 Hz to 15 Hz; when the door operator is closed, the frequency of the pulse sequence is 8 Hz to 12 Hz; when the door operator is stationary, no pulse signal is generated. Each pulse in the pulse sequence corresponds to a small displacement of the door operator, which can accurately reflect the actual action of the door operator.

[0069] Furthermore, the extracted physical feedback pulse sequence is analyzed to determine whether the door operator drive system is in a controlled response state. The door operator drive system refers to the system used to drive the elevator door operator to perform opening and closing actions, including components such as the door operator controller, door operator motor, and physical feedback module. The controlled response state of this system means that the door operator drive system can normally receive control commands sent by the elevator control unit, accurately execute the corresponding opening and closing actions according to the control commands, and can feed back the actual action status to the elevator management device through the physical feedback module. The core of determining the controlled response state is to verify whether the door operator drive system can normally respond to control commands, eliminating the possibility of missing expected response events or interruption of local control logic execution due to door operator drive system failure, further narrowing down the possible causes of local control logic execution interruption.

[0070] The specific judgment process is as follows: 1. Extract the door opening and closing control commands sent by the elevator control unit to the door operator drive system within the corresponding time period of the target scenario (these commands are pre-stored in the elevator management device and correspond to the time period when the local control logic execution is interrupted); 2. Analyze the preset pulse sequence corresponding to the door opening and closing control command (the preset pulse sequence refers to the physical feedback pulse sequence that the door operator drive system should generate when it normally responds to the control command, including preset frequency, preset amplitude, and preset number of pulses, which corresponds to the preset door opening and closing action of the door operator); 3. Compare the extracted actual physical feedback pulse sequence with the preset pulse sequence. Yes, the comparison includes pulse frequency, pulse amplitude, and number of pulses; 4. If the deviation between the actual physical feedback pulse sequence and the preset pulse sequence is within the preset deviation range (preset deviation range: frequency deviation not exceeding 1 Hz, amplitude deviation not exceeding 10%, and pulse number deviation not exceeding 2), then the door operator drive system is determined to be able to respond to control commands normally and is in a controlled response state; 5. If the deviation between the actual physical feedback pulse sequence and the preset pulse sequence exceeds the preset deviation range, or if the actual physical feedback pulse sequence is not extracted, then the door operator drive system is determined to be unable to respond to control commands normally and is not in a controlled response state.

[0071] Furthermore, based on the above judgment results, the elevator management device generates an execution verification result, which includes "in a controlled response state" and "not in a controlled response state".

[0072] Step 104: If the execution verification result determines that the system is in a controlled response state, then the potential failure judgment result of the communication function is determined based on the feature fragment of the missing remote communication heartbeat packet return in the continuous operation abnormal signal.

[0073] Optionally, the execution verification result is judged. If the execution verification result is "not in a controlled response state", the elevator management device determines that the interruption of the local control logic execution is caused by the abnormality of the door machine drive system and is unrelated to the communication function. Therefore, it is determined that there is no potential failure of the communication function, and the judgment result "no potential failure" is output, ending the judgment process. If the execution verification result is "in a controlled response state", the possibility of the interruption of the local control logic execution caused by the abnormality of the door machine drive system is ruled out. At this time, the reason for the interruption of the local control logic execution may only be related to the abnormality of the communication function, and the subsequent judgment operation is initiated.

[0074] Furthermore, the elevator management device extracts the characteristic fragment of missing remote communication heartbeat packet feedback contained in the continuous operation anomaly signal. The remote communication heartbeat packet refers to a detection data packet sent by the local communication module to the remote monitoring center at a preset period to indicate that the communication link between the elevator management device and the remote monitoring center is normal. The preset period is set to 10 to 30 seconds (adjustable according to actual communication needs). This data packet only contains communication link detection information and does not contain elevator operation data. The characteristic fragment of missing remote communication heartbeat packet feedback refers to a segment in the continuous operation anomaly signal where the corresponding time period does not contain the identification information of successful remote communication heartbeat packet feedback, and this time period overlaps with the time period of local control logic execution interruption. This characteristic fragment is the core feature indicating a possible abnormality in the communication function.

[0075] Furthermore, the elevator management device determines the potential failure judgment result of the communication function based on the extracted feature fragments of the missing remote communication heartbeat packet feedback, as detailed in steps 1041 to 1044.

[0076] The embodiments of the present invention rely only on the elevator's existing operating event sequence, main power status signal, and door operator action signal, without the need for additional hardware equipment or continuous operation of active reconnection and heartbeat mechanisms. This improves the timeliness of elevator communication interruption recovery and the robustness of the elevator monitoring system, ensuring that potential failures in elevator communication functions can be quickly identified and handled in a timely manner, thus guaranteeing the safety of elevator operation and the continuity of monitoring.

[0077] Optionally, the process of steps 1041 to 1044 includes: Step 1041: Based on the characteristic segment of missing remote communication heartbeat packet feedback in the continuous operation anomaly signal, determine the communication silence phenomenon where the elevator local communication module fails to send a regular status report to the remote monitoring center. The communication silence phenomenon indicates whether there is an abnormality in the data output capability of the local communication link.

[0078] Optionally, the missing feature segment of the remote communication heartbeat packet return refers to the absence of the identification information for successful remote communication heartbeat packet return within the corresponding time period in the continuous operation abnormal signal, and this time period overlaps with the time period of local control logic execution interruption. This feature segment is the core feature indicating that the communication function may be abnormal. The remote communication heartbeat packet refers to the detection data packet sent by the local communication module to the remote monitoring center at a preset period to indicate that the communication link between the elevator management device and the remote monitoring center is normal. The preset period is set to 10 to 30 seconds (which can be adjusted according to actual communication needs). This data packet only contains communication link detection information and does not contain elevator operation data. The identification information for successful remote communication heartbeat packet return refers to the exclusive information fed back by the remote monitoring center to the elevator management device after receiving the remote communication heartbeat packet to indicate successful reception. This identification information is unique and can be accurately identified by the elevator management device. The absence of this identification information indicates that the remote communication heartbeat packet return is missing within the corresponding time period.

[0079] Optionally, the elevator management device determines the communication silence phenomenon based on the aforementioned characteristic segments and the normal operating mechanism of the local communication module. The normal status report refers to a report sent by the elevator management device to the remote monitoring center via the local communication module at preset intervals, containing key information such as elevator operating status, local control logic execution status, and door operator action status. The preset interval is consistent with the preset period of the remote communication heartbeat packet, i.e., 10 to 30 seconds. The normal status report and the remote communication heartbeat packet are sent synchronously, constituting the core content of the data output from the local communication module to the remote monitoring center. The communication silence phenomenon refers to the situation where the elevator's local communication module does not send any normal status report to the remote monitoring center within the preset normal status report sending interval, and does not provide feedback on the successful return of the remote communication heartbeat packet. This phenomenon is a direct manifestation of an abnormal data output status of the local communication module and does not include the status of the local communication module receiving remote commands; it only defines the data transmission status.

[0080] Optionally, the communication silence phenomenon indicates whether there is an abnormality in the data output capability of the local communication link. Here, the local communication link refers to the link between the local communication module and the remote monitoring center for data transmission, including the sending port of the local communication module, the transmission channel, and the receiving port of the remote monitoring center. Abnormal data output capability means that the local communication module cannot normally send regular status reports, remote communication heartbeat packets, or other data to the remote monitoring center, or that the sent data cannot be received by the remote monitoring center and receive a successful feedback status. If a communication silence phenomenon exists, it indicates that the local communication link is highly likely to have an abnormal data output capability; if no communication silence phenomenon exists, it indicates that the data output capability of the local communication link is normal, and the possibility of an abnormality at the sending end of the local communication module can be ruled out.

[0081] It should be noted that the determination of communication silence requires "two or more consecutive preset periods". That is, the elevator management device detects that no regular status report has been sent or no successful remote communication heartbeat packet has been received within two or more consecutive preset periods (such as 20 seconds to 60 seconds) before it is determined that there is a communication silence. This avoids misjudgment caused by a single signal interference and ensures the accuracy of the determination result.

[0082] Step 1042: If it is determined that there is an abnormality in the data output capability of the local communication link based on the communication silence phenomenon, then the local communication module can perform normal communication tasks under the condition of guaranteed power supply based on the continuously effective power supply status information in the elevator main power supply status signal, and obtain the functional abnormality indication information.

[0083] Optionally, the abnormal situation of local communication link data output capability corresponding to the communication silence phenomenon is confirmed. That is, if step 1041 determines that there is no communication silence phenomenon, that is, the local communication link data output capability is normal, the elevator management device determines that there is no potential failure of communication function, outputs the judgment result of "no potential failure", and ends the judgment process.

[0084] If step 1041 determines that there is a communication silence phenomenon, that is, the local communication link has an abnormal data output capability, then the subsequent judgment operation of this step is initiated to rule out the possibility that the local communication module cannot perform normal communication tasks due to abnormal power supply.

[0085] Furthermore, the elevator management device extracts continuously valid power supply status information from the elevator main power supply status signal. This continuously valid power supply status information refers to the elevator main power supply output voltage consistently remaining within a preset rated voltage range (the rated voltage of the elevator main power supply is preset according to the elevator model; for example, for 380V AC voltage, the preset rated voltage range is 370V to 390V), with voltage fluctuations not exceeding 5%, and maintaining this stable state continuously. This information is collected in real-time by the elevator main power supply voltage detection module and synchronously transmitted to the elevator management device. It includes key data such as the start time of voltage stability, duration, and voltage fluctuation values. The time accuracy is consistent with the judgment period for the communication silence phenomenon in step 1041 (millisecond level), ensuring the accuracy of the judgment.

[0086] Power supply guarantee conditions refer to the ability of the local communication module to obtain a continuous and effective power supply, with the power supply voltage and current meeting the rated operating requirements of the local communication module, ensuring that the local communication module can start normally and execute communication tasks. This condition is directly represented by continuous and effective power supply status information.

[0087] Furthermore, based on continuously valid power supply status information, the elevator management device determines whether the local communication module can perform routine communication tasks under the condition of guaranteed power supply. Routine communication tasks refer to the tasks of the local communication module sending routine status reports and remote communication heartbeat packets to the remote monitoring center at preset intervals, and receiving downlink commands from the remote monitoring center and providing feedback confirmation. The core of these tasks is the local communication module's data transmission and command reception feedback functions. The specific determination process is as follows: 1. The elevator management device confirms whether the time period corresponding to the continuously valid power supply status information completely overlaps with the time period corresponding to the communication silence phenomenon. If the overlap duration accounts for no less than 90% of the duration of the communication silence phenomenon, it is determined that the local communication module has the power supply guarantee conditions during the communication silence phenomenon. 2. If the power supply guarantee conditions are confirmed, the elevator management device further checks the working status of the local communication module to see if the local communication module is in a normal start-up state and whether the sending port is in a fault-free state (such as no port blockage, port damage, etc.). 3. If the local communication module is in a normal start-up state and the sending port is fault-free, but the communication silence phenomenon still exists, that is, the regular communication task is not performed, it is determined that the local communication module failed to perform the regular communication task under the condition of power supply guarantee. 4. If the local communication module is not in a normal start-up state or the sending port is faulty, it is determined that the failure to perform the regular communication task is due to a hardware failure other than power supply guarantee. 5. If the overlap duration between the time period corresponding to the continuously valid power supply status information and the time period corresponding to the communication silence phenomenon is less than 90%, it is determined that the communication silence phenomenon is caused by an abnormal power supply, and the local communication module is unable to perform the regular communication task due to insufficient power supply.

[0088] Furthermore, based on the above judgment results, the elevator management device generates functional abnormality indication information. This information indicates whether the local communication module can perform routine communication tasks under conditions of guaranteed power supply. This information includes only two scenarios: one, "guaranteed power supply but unable to perform routine communication tasks," and two, "unreliable power supply or hardware failure causing failure to perform routine communication tasks." This information provides the core basis for subsequent judgments, accurately distinguishing between power supply issues, hardware failures, and remote communication channel abnormalities.

[0089] Step 1043: If it is determined that the normal communication task could not be performed based on the functional abnormality indication information, then the communication between the elevator control function and the local actuator is normal based on the closed-loop feedback information of the door operator's response to the local control command displayed in the door operator action signal, and the communication status information is obtained.

[0090] Optionally, if the function abnormality indication information is "no power supply guarantee or hardware failure causing failure to perform routine communication tasks", the elevator management device determines that the communication function abnormality is caused by a power supply abnormality or a hardware failure of the local communication module itself, and is unrelated to the remote communication channel. Therefore, it determines that there is no potential failure of the communication function (or determines it to be a clear local fault), outputs the corresponding judgment result, and ends the judgment process. If the function abnormality indication information is "power supply guarantee is available but routine communication tasks cannot be performed", the subsequent judgment operations of this step are initiated to further eliminate the possibility that the communication abnormality between the elevator control function and the local actuator causes the routine communication tasks to be unable to be performed, thus narrowing the scope of the communication abnormality.

[0091] Furthermore, the elevator management device extracts the door operator's action signal and displays the closed-loop feedback information of the door operator's response to the local control command. The local control command refers to the instruction sent by the elevator management device (or elevator control unit) to the local actuator to control the local actuator to perform the corresponding action; here, it specifically refers to the door opening and closing control command sent by the door operator drive system. The closed-loop feedback information refers to the feedback information corresponding to the door operator's physical feedback module collecting and feeding back the actual action status of the door operator (such as door fully open, door fully closed, action abnormality, etc.) to the elevator management device after the door operator drive system receives the local control command and drives the door operator to perform the corresponding door opening and closing action. This forms a closed-loop link of "command sending—action execution—status feedback," and the information completely includes the command reception identifier, action execution process information, and action completion status information, accurately representing the door operator's response to the local control command.

[0092] Furthermore, based on the extracted closed-loop feedback information, the elevator management device determines whether the communication between the elevator control function and the local actuator is normal. Here, the elevator control function refers to the function of the elevator management device (or elevator control unit) in sending control commands to the local actuator, receiving feedback information from the local actuator, and controlling the normal operation of the local actuator; the local actuator refers to the component controlled by the elevator management device (or elevator control unit) and performing specific operating actions, specifically the door operator drive system and the door operator; the communication between the elevator control function and the local actuator refers to the internal communication link between them used to transmit control commands and feedback information. This link is independent of the remote communication channel between the local communication module and the remote monitoring center, and its communication status is not affected by the remote communication channel.

[0093] Optionally, the determination process in this embodiment of the invention is as follows: 1. The elevator management device extracts the instruction reception identifier from the closed-loop feedback information to confirm whether the door operator drive system has successfully received the local control instruction. If the instruction reception identifier exists, it is determined that the instruction was successfully sent and the door operator drive system has successfully received the instruction. 2. Extract the action execution process information from the closed-loop feedback information to confirm whether the door operator has executed the corresponding door opening and closing actions according to the requirements of the local control command. If the action execution process information is consistent with the requirements of the local control command (e.g., the command requires the door to open, and the feedback information shows that the door is open normally), then the action execution is judged to be normal. 3. Extract the action completion status information from the closed-loop feedback information to confirm whether the door operator has completed the actions required by the local control command (e.g., the door is open in place, the door is closed in place). If the action completion status information shows that the action is completed and there are no abnormalities, then the status feedback is judged to be normal. 4. If the instruction is sent successfully, the action is executed normally, and the status feedback is normal, that is, the closed-loop feedback information is complete and meets expectations, then it is determined that the communication between the elevator control function and the local actuator is normal; 5. If the instruction reception identifier is missing in the closed-loop feedback information, the action execution process information is inconsistent with the instruction requirements, or the action completion status information is displayed abnormally, then it is determined that the communication between the elevator control function and the local actuator is abnormal.

[0094] Furthermore, based on the above judgment results, the elevator management device generates communication status information. This communication status information refers to information used to identify the communication status between the elevator control function and the local actuator. This information includes only two possibilities: either "communication between the elevator control function and the local actuator is normal," or "communication between the elevator control function and the local actuator is abnormal."

[0095] Step 1044: If the communication anomaly is presumed to be limited to the remote communication channel based on the communication status information, then the potential failure judgment result of the communication function is determined based on the fact that the remote instruction parsing success flag was not detected in multiple consecutive cycles in the operation continuity anomaly signal.

[0096] Optionally, if the communication status information is "communication abnormal between elevator control function and local actuator," the elevator management device determines that the inability to execute regular communication tasks is due to an internal communication abnormality, unrelated to the remote communication channel. Therefore, it determines that the communication function has no potential failure (or determines it is an internal communication fault), outputs the corresponding determination result, and ends the determination process. If the communication status information is "communication normal between elevator control function and local actuator," then, based on the determination results of the aforementioned steps (abnormal data output capability of the local communication link, sufficient power supply, and no obvious hardware fault in the local communication module), it is presumed that the communication abnormality is limited to the remote communication channel. The remote communication channel refers to the channel between the local communication module and the remote monitoring center used for remote data transmission and command interaction, independent of the elevator's internal communication link. Its abnormality mainly manifests as data transmission obstruction and command reception failure.

[0097] Furthermore, the elevator management device extracts information related to remote command parsing from the continuous abnormal operation signals and checks for the presence of a remote command parsing success flag. This flag indicates that the command parsing is complete and executable, generated after the local communication module receives and successfully parses a downlink command from the remote monitoring center. This flag is unique and can be accurately detected by the elevator management device. If the flag is detected, it means the local communication module can normally receive and parse remote commands, and the remote communication channel is normal. If the flag is not detected, it means the local communication module did not receive the remote command, or received the command but failed to parse it, and the remote communication channel may be abnormal. "Several consecutive cycles" refers to the preset cycle (e.g., 30 to 90 seconds) of three or more consecutive remote communication heartbeat packets. This cycle setting is consistent with the preset cycle of the remote communication heartbeat packets to ensure the accuracy of the detection results and avoid misjudgments due to the loss of a single command.

[0098] Furthermore, based on the above detection results, the elevator management device determines the potential failure judgment result of the communication function according to the preset upper-level logic, specifically as in steps 10441 to 10444.

[0099] The embodiments of the present invention rely solely on the various signals and data already present in the elevator itself, without the need for additional hardware equipment or the continuous operation of active reconnection and heartbeat mechanisms. This enables reliable recovery of elevator communication interruptions, improves the timeliness of fault reporting and the robustness of the elevator monitoring system, ensures that elevator communication link anomalies can be accurately identified and handled in a timely manner, and ensures the continuity and reliability of elevator operation monitoring.

[0100] Optionally, the process of steps 10441 to 10444 includes: Step 10441: Based on the fact that the remote command parsing success flag was not detected in multiple consecutive cycles in the continuous operation anomaly signal, determine whether there are any abnormal signs on the receiving side of the remote communication receiving path, such as data parsing failure or no valid frame capture, and obtain the bidirectional function judgment result.

[0101] Optionally, the elevator management device extracts detection information related to the remote command parsing success flag from the continuous operation anomaly signal, focusing on confirming the specific situation where this flag is not detected within multiple consecutive cycles. The remote command parsing success flag refers to the flag information generated after the local communication module receives a downlink command sent by the remote monitoring center, parses the command, and successfully parses it. This flag is unique and can be accurately detected by the elevator management device. Multiple consecutive cycles refer to the preset cycle (e.g., 30 to 90 seconds) of three or more consecutive remote communication heartbeat packets. This cycle setting is consistent with the preset cycle of the remote communication heartbeat packets to ensure the accuracy of the detection results and avoid misjudgments caused by the loss of a single command.

[0102] The "No successful remote command parsing" flag indicates that within the aforementioned consecutive cycles, the elevator management device did not capture any flag information corresponding to this unique identifier in the continuous operation abnormality signal.

[0103] Furthermore, based on the aforementioned situation where no flag was detected, the elevator management device focuses on analyzing the working status of the remote communication receiving path to determine whether there are any abnormal signs on the receiving side. The remote communication receiving path refers to the complete path within the local communication module used to receive downlink commands sent by the remote monitoring center and to parse and process these commands. It includes components such as the local communication module's receiving port, command parsing unit, and signal conversion unit, and is the core receiving link for bidirectional remote communication interaction. Abnormal signs on the receiving side refer to abnormal behavior where the remote communication receiving path cannot normally complete command reception and parsing. Specifically, there are two types: data parsing failure and no valid frame capture. These two types can exist individually or simultaneously.

[0104] Valid frame capture means that the receiving port of the remote communication receiving path does not capture any downlink command data frames from the remote monitoring center within several consecutive cycles, i.e., the receiving port is in a state of no signal input. Here, the data frame refers to the complete data unit containing downlink commands sent by the remote monitoring center, which has a preset frame structure and can be recognized by the receiving port of the local communication module. Data parsing failure means that the receiving port of the remote communication receiving path captures downlink command data frames from the remote monitoring center, but the command parsing unit of the local communication module cannot parse the data frame normally, cannot extract the valid downlink command content, and therefore cannot generate a remote command parsing success flag. The manifestations of parsing failure include, but are not limited to, data frame format disorder, data frame missing key fields, and data frame verification failure.

[0105] Furthermore, by combining the transmitting-side operating status of the local communication module (which can be obtained from the characteristic segments of missing remote communication heartbeat packets in the continuous operation anomaly signal), the bidirectional transmitting and receiving function of the local communication module is comprehensively judged to obtain the bidirectional transmitting and receiving function judgment result. Here, bidirectional transmitting and receiving function refers to the local communication module's simultaneous ability to send data (regular status reports, remote communication heartbeat packets) to the remote monitoring center and to receive and parse downlink commands from the remote monitoring center.

[0106] Optionally, the judgment process is as follows: 1. If there are only signs of abnormality on the receiving side (data parsing failure or no valid frame capture), but the sending side function is normal (data can be sent normally, but no return flag is received), then it is determined that the receiving side function is abnormal and the sending side function is normal; 2. If there are signs of abnormality on the receiving side, and the sending side function is also abnormal (unable to send data normally, manifested as communication silence), then it is determined that both the receiving and sending functions are abnormal; 3. If there are no signs of abnormality on the receiving side (valid data frames can be captured and parsed successfully, but the absence of flag bit detection is an occasional occurrence), then it is determined that both the receiving and sending functions are normal.

[0107] Furthermore, a bidirectional function judgment result is generated based on the above comprehensive judgment results. This bidirectional function judgment result refers to information used to identify abnormalities in the bidirectional function of the local communication module. This information includes only three situations: first, "abnormal receiving side function, normal sending side function"; second, "abnormal bidirectional function"; and third, "normal bidirectional function". This result provides the core basis for isolation judgment in subsequent steps, accurately distinguishing the differences between receiving side, sending side, and bidirectional abnormalities.

[0108] Step 10442: If the bidirectional function of the local communication module is determined to be abnormal based on the bidirectional function judgment result, the isolation judgment result caused by the failure of the elevator body control is obtained based on the comprehensive status information that the elevator main power supply status signal and the door operator action signal jointly indicate that the elevator body control is operating normally.

[0109] Optionally, if the bidirectional function judgment result is "receiving side function is abnormal, sending side function is normal" or "both bidirectional functions are normal", the elevator management device will not perform the subsequent operations of this step, and will directly enter step 10443 to analyze the abnormal communication link based on the corresponding judgment result; if the bidirectional function judgment result is "both bidirectional functions are abnormal", the subsequent isolation judgment operation of this step will be initiated. The core purpose is to eliminate the possibility that the local communication module's bidirectional function is abnormal due to the failure of the elevator body control, and to achieve effective isolation between communication abnormality and body control abnormality.

[0110] Furthermore, the elevator main power supply status signal and door operator action signal are extracted, and their status information is integrated to generate comprehensive status information indicating that the elevator body control is operating normally.

[0111] Among them, the comprehensive status information refers to the information generated by the elevator management device after integrating and verifying the continuous effective power supply information in the elevator main power status signal and the closed-loop feedback information in the door operator action signal. This information is used to comprehensively characterize the control and operation status of the elevator body. The generation of this information follows the principle that "if both are normal, the comprehensive status is normal; if either is abnormal, the comprehensive status is abnormal."

[0112] The specific integration and verification process is as follows: 1. The elevator management device confirms whether the elevator main power supply status signal is a continuously valid power supply status information, that is, the output voltage of the elevator main power supply is always kept within the preset rated voltage range, the voltage fluctuation range does not exceed 5%, and there are no abnormalities such as power outages or voltage instability; 2. The elevator management device confirms whether the closed-loop feedback information in the door operator action signal is complete and normal, that is, the door operator can successfully receive local control commands, normally execute the corresponding door opening and closing actions, and provide complete action completion status information, without any abnormal actions or missing feedback; 3. If both of the above two conditions are met, that is, the main power supply is continuously valid and the door operator responds normally to the control commands, then a comprehensive status information of "elevator body control operation is normal" is generated; if either of the above two conditions is not met, that is, the main power supply is abnormal or the door operator response is abnormal, then a comprehensive status information of "elevator body control operation is abnormal" is generated.

[0113] Furthermore, based on the generated comprehensive status information, the elevator management device performs an isolation assessment for elevator body control failures and obtains the isolation assessment result.

[0114] Among them, elevator body control failure refers to the failure state in which the elevator management device (or elevator control unit) cannot execute local control logic normally and cannot control the operation of elevator body components (such as door operators and main power supply) normally; isolation judgment refers to judging whether the abnormal bidirectional function of local communication module is caused by elevator body control failure, so as to isolate communication abnormality from body control abnormality; isolation judgment result refers to the information used to identify whether there is a correlation between the bidirectional abnormality of local communication module and elevator body control failure, specifically divided into two situations: one is "the comprehensive status information indicates that the elevator body control is operating normally, and the bidirectional abnormality of local communication module is unrelated to elevator body control failure", and the other is "the comprehensive status information indicates that the elevator body control is operating abnormally, and the bidirectional abnormality of local communication module is caused by elevator body control failure".

[0115] Step 10443: Based on the isolation judgment result, determine the abnormal communication link between the local communication module itself or between the local communication module and the remote monitoring center.

[0116] Optionally, an abnormal communication link refers to a communication link that prevents normal data interaction (sending, receiving, parsing) between the local communication module and the remote monitoring center. The scope of the abnormality is limited to the local communication module itself or the remote communication channel between the local communication module and the remote monitoring center, and does not include the internal communication link between the elevator's internal control function and the local actuator.

[0117] In the first scenario, if the isolation assessment result is "the comprehensive status information indicates that the elevator body control is operating normally, and the bidirectional abnormality of the local communication module is unrelated to the elevator body control failure," then the elevator management device further considers the characteristic of both bidirectional transmission and reception being abnormal to determine that the abnormal communication link is the local communication module itself or the remote communication channel between the local communication module and the remote monitoring center. The specific judgment logic is as follows: 1. Since the elevator body control is operating normally, interference from the body control failure to the local communication module can be ruled out. At this time, the bidirectional abnormality of the local communication module can only be due to its own fault or the fault of the remote communication channel; 2. If the power supply of the local communication module is normal (confirmed by the continuous effective power supply information of the elevator main power supply) and there is no hardware fault indication (confirmed by the status detection information of the local communication module itself, which is already included in the continuous operation abnormality signal), then the abnormal communication link is determined to be the remote communication channel between the local communication module and the remote monitoring center; 3. If the local communication module has a hardware fault indication (such as port damage, parsing unit failure, etc.), then the abnormal communication link is determined to be the local communication module itself.

[0118] In the second scenario, if the isolation assessment result is "The comprehensive status information indicates that the elevator body control is malfunctioning, and the bidirectional malfunction of the local communication module is caused by the failure of the elevator body control," then the elevator management device determines that the abnormal communication link is the local communication module itself, and that the malfunction is an indirect malfunction caused by the failure of the elevator body control. The specific judgment logic is as follows: 1. The failure of the elevator body control will prevent the elevator management device from sending control commands to the local communication module normally, thus causing the bidirectional transmission and reception functions of the local communication module to malfunction; 2. At this time, the local communication module itself has no hardware failure, and its malfunction is caused by the failure of external control, which is an indirect malfunction. Therefore, the abnormal communication link is determined to be the local communication module itself, and the cause of the malfunction is clearly the failure of the elevator body control.

[0119] Furthermore, if the bidirectional function determination result of step 10441 is "abnormal receiving side function and normal sending side function", the elevator management device directly determines that the abnormal communication link is the receiving path of the local communication module (which is part of the local communication module itself) or the receiving link of the remote communication channel; if the determination result is "both bidirectional functions are normal", then it is determined that there is no abnormal communication link, and the failure to detect the remote command parsing success flag is only due to occasional signal interference.

[0120] Step 10444: Based on the abnormal communication link combined with the timing consistency and logical mutual verification relationship between the abnormal operation signal, the elevator main power supply status signal and the door operator action signal, determine the potential failure judgment result of the communication function.

[0121] Optionally, the elevator management device analyzes the temporal consistency and logical mutual verification relationship among the above three signals. Temporal consistency refers to the matching and consistency of the time information (timestamp, duration) contained in the three signals. Specifically, the abnormal time period corresponding to the abnormal communication link overlaps with the abnormal time period in the continuous operation abnormal signal, the continuous effective time period (or abnormal time period) of the elevator main power supply status signal, and the normal response time period (or abnormal time period) of the door operator action signal. The overlap duration accounts for no less than 90% of the duration of the abnormal communication link, ensuring consistency of each signal in the time dimension and eliminating temporal contradictions. Logical mutual verification refers to the mutual support and corroboration of the status information of the three signals, jointly confirming the abnormality of the abnormal communication link without logical conflicts. Specifically, this is manifested as follows: 1. If the abnormal communication link is a remote communication channel, the continuous abnormal operation signal will show characteristics of missing remote communication heartbeat packet transmission and no detected remote command parsing success flag. The elevator main power status signal will show continuous and effective power supply, and the door operator action signal will respond normally. These three characteristics corroborate each other, indicating that the abnormality exists only in the remote communication channel and is unrelated to the elevator itself. 2. If the abnormal communication link is the local communication module itself and is caused by a failure in the elevator's control system, the continuous abnormal operation signal will show anomalies, the door operator action signal will show anomalies, and the elevator main power status signal may show anomalies. These three characteristics corroborate each other, indicating that the communication abnormality is indirectly caused by a failure in the elevator's control system. 3. If the abnormal communication link is the local communication module itself (without a failure in the elevator's control system), the continuous abnormal operation signal will show anomalies, the elevator main power status signal will show continuous and effective power supply, and the door operator action signal will respond normally. These three characteristics corroborate each other, indicating that the communication abnormality is caused by a hardware failure in the local communication module itself.

[0122] Furthermore, the elevator management device verifies the consistency of timing and the mutual verification of logic. If both are satisfied (consistent timing and no contradiction in logical verification), the potential failure judgment result of the communication function is determined based on the specific scope of the abnormal communication link and the preset judgment rules. If either of the two is not satisfied (contradictory timing or logical conflict), the determination result of the abnormal communication link is rechecked, corrected, and verified again until both are satisfied.

[0123] Furthermore, the elevator management device determines the potential failure judgment result of the communication function based on the verification results. The judgment result only includes two cases: "potential failure exists" and "potential failure does not exist." The specific judgment rules are as follows: 1. If the abnormal communication link is the remote communication channel or the local communication module itself (without elevator body control failure), and the timing is consistent and the logic is mutually verifiable, then the communication function is judged to have a potential failure. This failure is caused by an abnormality in the remote communication channel or a fault in the local communication module itself, and is unrelated to the elevator body control operation; 2. If the abnormal communication link is the local communication module itself, and is caused by a fault in the elevator body control, then the communication function is judged to have no potential failure. This communication abnormality is indirectly caused by a fault in the elevator body control, and the core fault is a fault in the elevator body control, not a potential failure of the communication function itself; 3. If there is no abnormal communication link, or the timing is inconsistent and the logic conflict cannot prove the abnormality, then the communication function is judged to have no potential failure. The failure to detect the remote command parsing success flag is only due to occasional interference.

[0124] The embodiments of the present invention rely solely on the various signals and data already present in the elevator itself, without the need for additional hardware equipment or the continuous operation of active reconnection and heartbeat mechanisms. This enables reliable recovery from elevator communication interruptions, improves the timeliness of fault reporting and the robustness of the elevator monitoring system, ensures that elevator communication link anomalies can be accurately identified and classified, and guarantees the continuity and reliability of elevator operation monitoring.

[0125] Optionally, the processes of steps 301 to 304 include: Step 301: Based on the event that the downlink command frame header features of the remote monitoring center contained in the remote end communication activity indication signal are successfully identified by the local communication module, determine the communication activation information that the remote monitoring center is currently in a valid communication initiation state.

[0126] Optionally, the remote communication activity indication signal is parsed to extract the key event "the downlink command frame header features of the remote monitoring center are successfully identified by the local communication module." This successful identification event must simultaneously meet three core requirements: The local communication module captures external signal characteristics, and the elevator management device compares these characteristics bit by bit with the pre-stored unique frame header characteristics. The comparison results are completely consistent. Based on this successful identification event, the elevator management device determines that the remote monitoring center is currently in a valid communication initiation state (i.e., it has the ability to send downlink commands normally and actively initiates communication interaction), and generates communication activation information. The communication activation information includes three key components: the event timestamp (accurate to milliseconds), the remote monitoring center's frame header characteristic identifier, and the local communication module's identification status, accurately representing the remote monitoring center's valid communication initiation state.

[0127] Step 302: Based on the communication activation information, determine whether the local communication module has the triggering communication conditions to start the response payload information generation process, and obtain the communication activation triggering result.

[0128] Optionally, the communication activation information is checked for completeness and validity: the completeness check verifies that the three key elements of the information are not missing; the validity check confirms that the difference between the event occurrence time and the current time does not exceed a preset 5 seconds, otherwise the information is deemed invalid. After the verification is successful, the current working status of the local communication module is considered to determine whether the conditions for triggering the response payload information generation process are met.

[0129] The triggering condition contains two indispensable elements: First, the local communication module is in standby listening mode, and core components such as the receiving port and parsing unit are functioning normally without hardware failure. Second, the remote monitoring center is in a valid communication initiation state (represented by qualified communication activation information). Ultimately, a communication activation trigger result is generated indicating either "conditions for triggering communication are met" or "conditions for triggering communication are not met." If the conditions are not met, the elevator management device controls the local communication module to continue in standby listening mode, continuously capturing the characteristics of the remote downlink command frame header.

[0130] Step 303: If the triggering communication condition is determined based on the communication activation triggering result, the position code value of the current car in the hoistway is read from the position code storage unit in the elevator control system to obtain the position identification information, and all the types of abnormal events that have not been cleared in the most recent operating cycle and their order of occurrence are read from the fault status register in the elevator control unit to obtain the fault status summary information.

[0131] Optionally, if the condition for triggering communication is determined to be met, the preparatory operation for generating response load information is immediately initiated, and two key pieces of information are read and their integrity is verified simultaneously. First, the position code value of the current car in the hoistway is read from the position code storage unit in the elevator control system (this code value corresponds one-to-one with the actual position of the car, which can accurately identify the floor and offset distance of the car) to generate position identification information; second, all uncleared abnormal event types (such as abnormal door opening and closing, abnormal speed, etc.) and their order of occurrence are read from the fault status register in the elevator control unit in the most recent operating cycle (tracing back to the last restart or within 30 minutes, which can be adjusted as needed) to generate fault status summary information.

[0132] Step 304: Generate response payload information based on location identification information and fault status summary information.

[0133] Optionally, response payload information is generated based on location identification information and fault status summary information, as described in steps 3041 to 3044.

[0134] The embodiments of the present invention ensure the validity and integrity of the generated information by verifying communication activation information, location and fault information, and response payload information. It can accurately report the current car position and recent fault status of the elevator to the remote monitoring center, realize reliable recovery of elevator communication interruption, effectively improve the timeliness of fault reporting and the robustness of the elevator monitoring system, and ensure the continuity of elevator operation monitoring.

[0135] Optionally, the processes of steps 3041 to 3044 include: Step 3041: Based on the preset response load structure, determine the position of the first data field of the location identification information and the position of the second data field of the fault status summary information to obtain the field layout mapping relationship.

[0136] Optionally, the preset response payload structure is a fixed data structure that pre-stores data conforming to the resolution standards of the remote monitoring center. It includes multiple preset data fields and the position parameters and length limits of each field. Based on the preset response payload structure, the elevator management device determines the position of the first data field corresponding to the position identification information and the position of the second data field corresponding to the fault status summary information. The first data field position is specifically used to store car position-related identification data, and the second data field position is specifically used to store elevator fault status-related summary data. The two positions do not overlap, and the field length matches the data volume of the corresponding information, ultimately obtaining a field layout mapping relationship to determine the specific writing positions of the two pieces of information within the preset structure.

[0137] Step 3042: Based on the field layout mapping relationship, write the location identification information into the first data field position specified in the preset response payload structure to obtain the intermediate payload fragment.

[0138] Optionally, the location identification information undergoes format adaptation processing to ensure that its data format is consistent with the format requirements of the first data field in the preset response payload structure. After format adaptation, based on the position of the first data field indicated by the field layout mapping relationship, the location identification information is accurately written into the corresponding position of the preset response payload structure. After writing, a preliminary verification of data integrity is performed to confirm that the location identification information is complete and without misalignment, ultimately obtaining an intermediate payload fragment containing the location identification information.

[0139] Step 3043: Write the fault status summary information into the second data field position specified in the preset response load structure based on the intermediate load fragment to obtain the load body information.

[0140] Optionally, the fault status summary information is first processed for format adaptation to conform to the format requirements of the second data field in the preset response payload structure, ensuring consistency with the data format of the intermediate payload segment. After format adaptation, based on the position of the second data field indicated by the field layout mapping relationship, the fault status summary information is accurately written into the preset position corresponding to the intermediate payload segment. After writing, the integrity of the entire payload segment is verified to confirm that the position identification information and the fault status summary information are complete, without any missing, misaligned, or formatted errors, ultimately yielding the payload body information containing these two key pieces of information.

[0141] Step 3044: Generate response payload information based on payload subject information.

[0142] Optionally, response payload information is generated based on the payload subject information, as described in steps 30441 to 30443.

[0143] The embodiments of the present invention standardize the response payload information, improve the reliability of communication interruption recovery, achieve independent reconnection and heartbeat mechanism, improve the timeliness of fault reporting and the robustness of the elevator monitoring system, and ensure that the remote monitoring center can accurately grasp the elevator operating status through the response payload information.

[0144] Optionally, the processes of steps 30441 to 30443 include: Step 30441: Based on the response payload header format in the preset communication protocol, add a response type identifier and a payload length identifier at the beginning of the payload body information to obtain a structured response data block.

[0145] Optionally, the preset communication protocol is a pre-stored protocol used to standardize the data interaction format and verification standards between the elevator management device and the remote monitoring center, including core content such as the response payload header format and verification algorithm type. Based on the response payload header format specified in the preset communication protocol, a response type identifier and a payload length identifier are added at the beginning of the payload body information to obtain a structured response data block. The response type identifier is a unique identifier used to identify that the response payload is an "elevator status feedback response," which can be quickly identified by the remote monitoring center and distinguished from other types of response data; the payload length identifier is used to identify the total length of the entire structured response data block; the starting position is before the first byte of the payload body information, and adding it does not change the original data and order of the payload body information.

[0146] Step 30442: Calculate the check value of each byte content element in the structured response data block according to the check algorithm type in the preset communication protocol to obtain the response check value of each byte content element.

[0147] Optionally, the verification algorithm type is a fixed algorithm (such as the CRC check algorithm) used to verify the integrity of data transmission and prevent data corruption, pre-adapted to the verification logic of the remote monitoring center. Subsequently, the elevator management device calculates the byte-by-byte check value of the structured response data block obtained in step 30441 according to the verification algorithm type. That is, for each byte content element in the structured response data block, the verification algorithm is substituted sequentially to obtain the response check value corresponding to each byte content element. Among them, the response check value of each byte content element is a unique check identifier for that byte data, corresponding one-to-one with the byte content, which can accurately detect whether the byte is lost, tampered with, or otherwise abnormal during subsequent transmission.

[0148] Step 30443: Add the response check value of each byte content element to the end of the structured response data block to obtain the response payload information.

[0149] Optionally, the response check values ​​of all byte content elements are collected, and the corresponding response check values ​​are sequentially added to the end of the structured response data block according to the order of the byte content elements in the structured response data block to complete the data integration. After integration, the elevator management device performs a final check on the entire data block to confirm that the response type identifier, load length identifier, load body information, and all response check values ​​are complete, without any missing or misaligned elements, and in a consistent format. Finally, the response load information is obtained and transmitted to the local communication module.

[0150] The embodiments of the present invention achieve the standardization, completeness and verifiability of response payload information, effectively reduce the probability of anomalies in the data transmission and parsing process, improve the reliability of communication interruption recovery, realize the absence of active reconnection and heartbeat mechanism, improve the timeliness of fault reporting and the robustness of elevator monitoring system, and ensure that the remote monitoring center can accurately grasp the elevator operating status through response payload information.

[0151] Furthermore, the real-time communication connection device for elevator faults provided by the present invention will be described below. The real-time communication connection device for elevator faults described below can be referred to in correspondence with the real-time communication connection method for elevator faults described above.

[0152] Optional, refer to Figure 2 , Figure 2 This is a structural diagram of the real-time communication connection device for elevator faults provided by the present invention. The real-time communication connection device for elevator faults includes: The communication function monitoring module 210 is used to determine the operation continuity abnormal signal based on the operation event sequence of the elevator control unit during continuous operation, and to determine the potential failure judgment result of the communication function based on the operation continuity abnormal signal combined with the elevator main power status signal and the door operator action signal. The monitoring mode startup module 220 is used to start the standby monitoring mode of the local communication module based on the result of the potential failure of the communication function and without receiving an active query instruction from the remote monitoring center. The remote communication triggering module 230 is used to continuously capture the downlink instruction frame header features from the remote monitoring center based on the standby listening mode, obtain the remote end communication activity indication signal, and trigger the local communication module to generate response payload information based on the remote end communication activity indication signal. The communication restoration module 240 is used to transmit response payload information back to the remote monitoring center based on a preset communication channel, thereby completing the implicit reconstruction of the two-way communication link.

[0153] The embodiments of the present invention achieve reliable recovery of elevator communication interruptions without relying on active reconnection or using a heartbeat mechanism, thereby improving the timeliness of fault reporting and system robustness.

[0154] Please see Figure 3 , Figure 3 An embodiment diagram of an electronic device provided in accordance with the present invention. For example... Figure 3 As shown, an embodiment of the present invention provides an electronic device 300, including a memory 310, a processor 320, and a computer program 311 stored in the memory 310 and executable on the processor 320. When the processor 320 executes the computer program 311, it implements the processes of steps 10 to 40.

[0155] Please see Figure 4 , Figure 4 An embodiment diagram of a computer-readable storage medium provided in accordance with an embodiment of the present invention is shown. Figure 4 As shown, this embodiment provides a computer-readable storage medium 400 on which a computer program 311 is stored. When the computer program 311 is executed by a processor, it implements the processes of steps 10 to 40.

[0156] On the other hand, the present invention also provides a computer program product, which includes a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer is able to execute the real-time communication connection method for elevator faults provided by the above methods, which includes steps 10 to 40.

[0157] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for real-time communication connection oriented to elevator failure, characterized in that, include: Based on the sequence of operating events of the elevator control unit during continuous operation, an abnormal signal of continuous operation is determined, and based on the abnormal signal of continuous operation combined with the elevator main power status signal and the door operator action signal, the potential failure judgment result of the communication function is determined. Based on the potential failure determination result of the communication function, and without receiving an active query instruction from the remote monitoring center, the standby listening mode of the local communication module is activated. Based on the standby monitoring mode, the downlink command frame header features from the remote monitoring center are continuously captured to obtain the remote end communication activity indication signal, and the local communication module is triggered to generate response payload information based on the remote end communication activity indication signal. The response payload information is transmitted back to the remote monitoring center based on the preset communication channel, thereby completing the implicit reconstruction of the two-way communication link.

2. The real-time communication connection method for elevator failure according to claim 1, characterized by, The steps for determining the potential failure result of the communication function include: Based on the timestamp information of the elevator control unit missing the expected response event during continuous operation contained in the operation continuity anomaly signal, the timing characteristics of the elevator local control logic execution interruption are determined. Based on the timing characteristics and the level stability information representing the continuous and effective power supply of the main power supply in the elevator main power supply status signal, a synchronous comparison is performed to determine whether there is a target scenario where the local control logic is interrupted but the main power supply is in a normal power supply state, and the synchronous comparison result is obtained. If the existence of a target scenario is determined based on the synchronous comparison results, the door operator drive system is judged to be in a controlled response state based on the physical feedback pulse sequence of the door operator's actual door opening and closing actions in the corresponding time period in the door operator action signal, and the execution verification result is obtained. If the execution verification results determine that the system is in a controlled response state, then the potential failure judgment result of the communication function is determined based on the characteristic fragment of the missing remote communication heartbeat packet return in the operation continuity anomaly signal.

3. The real-time communication connection method for elevator faults according to claim 2, characterized in that, The determination of potential communication function failure based on the missing feature segments of remote communication heartbeat packet feedback in the abnormal operation signal includes: Based on the missing feature fragments of remote communication heartbeat packet feedback in the aforementioned abnormal operation signal, it is determined that the elevator local communication module is not sending a regular status report to the remote monitoring center, indicating a communication silence phenomenon; the communication silence phenomenon indicates whether there is an abnormality in the data output capability of the local communication link. If it is determined that there is an abnormal data output capability of the local communication link based on the communication silence phenomenon, then the local communication module can be judged whether it can perform normal communication tasks under the condition of guaranteed power supply based on the continuously effective power supply status information in the elevator main power supply status signal, and functional abnormality indication information is obtained. If it is determined that the normal communication task could not be performed based on the functional abnormality indication information, then the communication between the elevator control function and the local actuator is normal based on the closed-loop feedback information of the door operator's response to the local control command displayed in the door operator action signal, and the communication status information is obtained. If the communication anomaly is presumed to be limited to the remote communication channel based on the communication status information, then the potential failure judgment result of the communication function is determined based on the fact that the remote instruction parsing success flag was not detected in multiple consecutive cycles of the operation continuity anomaly signal.

4. The real-time communication connection method for elevator faults according to claim 3, characterized in that, The determination of the potential failure of the communication function based on the absence of a remote instruction parsing success flag in multiple consecutive cycles of the operational continuity anomaly signal includes: Based on the fact that the remote instruction parsing success flag was not detected in the continuous abnormal signal for multiple consecutive cycles, it is determined whether there are any abnormal signs on the receiving side of the remote communication receiving path, such as data parsing failure or no valid frame capture, and the bidirectional function judgment result is obtained. If the bidirectional function of the local communication module is determined to be abnormal based on the bidirectional function judgment result, the isolation judgment result caused by the failure of the elevator body control is obtained based on the comprehensive status information that the elevator main power supply status signal and the door operator action signal jointly indicate that the elevator body control is operating normally. Based on the isolation determination result, an abnormal communication link is determined between the local communication module itself or between the local communication module and the remote monitoring center. Based on the abnormal communication link and the timing consistency and logical mutual verification relationship between the abnormal operation signal, the elevator main power status signal and the door operator action signal, the potential failure judgment result of the communication function is determined.

5. The real-time communication connection method for elevator faults according to claim 1, characterized in that, The steps for generating the response payload information include: Based on the event that the downlink command frame header features of the remote monitoring center contained in the remote end communication activity indication signal are successfully identified by the local communication module, the communication activation information that the remote monitoring center is currently in a valid communication initiation state is determined. Based on the communication activation information, determine whether the local communication module has the triggering communication conditions to start the response payload information generation process, and obtain the communication activation triggering result; If the triggering conditions for communication are determined based on the communication activation triggering result, the position code value of the current car in the hoistway is read from the position code storage unit in the elevator control system to obtain the position identification information. Then, all the types of abnormal events that have not been cleared in the most recent operating cycle and their order of occurrence are read from the fault status register in the elevator control unit to obtain the fault status summary information. Response payload information is generated based on the location identification information and the fault status summary information.

6. The real-time communication connection method for elevator faults according to claim 5, characterized in that, The generation of response payload information based on the location identification information and the fault status summary information includes: Based on the preset response payload structure, the position of the first data field of the location identification information and the position of the second data field of the fault status summary information are determined to obtain the field layout mapping relationship; Based on the field layout mapping relationship, the location identification information is written into the first data field position specified in the preset response payload structure to obtain an intermediate payload fragment. Based on the intermediate load segment, the fault status summary information is written into the second data field position specified in the preset response load structure to obtain the load body information; The response payload information is generated based on the payload subject information.

7. The real-time communication connection method for elevator faults according to claim 6, characterized in that, The process of generating the response payload information based on the payload subject information includes: Based on the response payload header format in the preset communication protocol, a response type identifier and a payload length identifier are added to the beginning position of the payload body information to obtain a structured response data block. The verification value of each byte content element in the structured response data block is calculated according to the verification algorithm type in the preset communication protocol to obtain the response verification value of each byte content element; The response check value of each byte content element is added to the end of the structured response data block to obtain the response payload information.

8. A real-time communication connection device for elevator faults, characterized in that, The device is applied to the real-time communication connection method for elevator faults as described in any one of claims 1 to 7; the device includes: The communication function monitoring module is used to determine the operation continuity abnormal signal based on the operation event sequence of the elevator control unit during continuous operation, and to determine the potential failure judgment result of the communication function based on the operation continuity abnormal signal combined with the elevator main power status signal and the door operator action signal. The monitoring mode activation module is used to activate the standby monitoring mode of the local communication module based on the potential failure determination result of the communication function and without receiving an active query instruction from the remote monitoring center. The remote communication triggering module is used to continuously capture the downlink instruction frame header features from the remote monitoring center based on the standby listening mode, obtain the remote end communication activity indication signal, and trigger the local communication module to generate response payload information based on the remote end communication activity indication signal. The communication restoration module is used to transmit the response payload information back to the remote monitoring center based on a preset communication channel, thereby completing the implicit reconstruction of the bidirectional communication link.

9. An electronic device, comprising: Memory, used to store computer software programs; A processor for reading and executing the computer software program, characterized in that, when the processor executes the computer software program, it implements the real-time communication connection method for elevator faults as described in any one of claims 1 to 7.

10. A non-transitory computer-readable storage medium, wherein a computer software program is stored therein, characterized in that, When the computer software program is executed by the processor, it implements the real-time communication connection method for elevator faults as described in any one of claims 1 to 7.