Connecting device for escalator and control method
By designing dual physical security links and distributed security nodes, and combining hidden Markov models and dynamic authentication mechanisms, the reliability and information security issues of escalator safety monitoring systems are solved, enabling rapid fault location and predictive maintenance, and meeting high security integrity requirements.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- RMO (SUZHOU) SYST TECH CO LTD
- Filing Date
- 2026-01-30
- Publication Date
- 2026-05-01
AI Technical Summary
Existing escalator safety monitoring systems suffer from drawbacks such as poor cost-effectiveness, low maintainability, lack of state awareness and predictability, and insufficient flexibility in hard-wiring solutions, while bus-based solutions struggle to meet high reliability and safety integrity requirements and pose information security risks.
The system employs a dual physical security link design, including link A and link B, which are deployed in parallel. It combines distributed security nodes and a main controller, and uses electronic security circuits, microprocessor units, bus communication interfaces, and diagnostic buses to achieve synchronous control and fault diagnosis of the security links. It utilizes a hidden Markov model for predictive maintenance and employs a dual-ring communication network and dynamic authentication mechanism to ensure system security.
It enables the identification of risk trends before a failure occurs, rapid fault location, and ensures that the system reliably enters a safe state under any single point of failure, thereby reducing operation and maintenance costs, enhancing system resilience and information security, and meeting high security and integrity requirements.
Smart Images

Figure CN121948255A_ABST
Abstract
Description
A connecting device and control method for escalators Technical Field
[0001] This invention belongs to the field of elevator technology, specifically, it relates to a connecting device and control method for escalators. Background Technology
[0002] The safe operation of escalators relies on a monitoring network consisting of a series of safety switches distributed throughout the escalator path (such as step chain break switches, handrail belt entrance switches, emergency stop buttons, comb plate switches, etc.). The status of these switches must be reliably and in real time monitored, and the escalator must be stopped safely immediately upon activation of any switch.
[0003] 1. Traditional Parallel Connection Scheme and its Inherent Defects: The current industry mainstream still adopts the traditional "hard-wired parallel connection" scheme, which connects all safety switch contacts in series or parallel via independent cables directly to the central control cabinet located in the computer room or at the end of the truss. This scheme has the following significant drawbacks: Poor economy and engineering: The large number of long-distance independent signal cables leads to high material costs; the bulky cable bundles make installation, wiring, wiring, and testing extremely cumbersome, resulting in high labor costs; and the control cabinet is bulky due to the need to accommodate a large number of terminals.
[0004] Extremely low maintainability: When the safety circuit is disconnected, maintenance personnel can only perform manual, segment-by-segment line troubleshooting, which makes fault location difficult, results in a long mean time to repair (MTTR), and seriously affects equipment availability.
[0005] Lack of state awareness and predictability: The system can only provide Boolean states of "on / off", and cannot detect gradual fault information such as aging of switch contacts, increased contact resistance, and decreased cable insulation. It cannot achieve predictive maintenance, and hidden dangers may accumulate until a sudden failure occurs.
[0006] Insufficient flexibility and standardization: Different projects or subsequent additions of security features require changes to hardware wiring, making it difficult to achieve standardized product design and rapid configuration.
[0007] 2. Limitations and Security Challenges of Existing Bus-Based Solutions: To address the aforementioned issues, the industry has begun exploring communication solutions based on fieldbus or industrial Ethernet to digitize and transmit safety switch signals. However, escalator safety systems have mandatory legal and standard requirements (such as GB 16899, EN 115-1) for fail-safe, high reliability, and deterministic real-time response. Existing bus-based solutions face fundamental challenges in meeting these requirements: Insufficient safety integrity: Pure communication protocols struggle to achieve the same level of safety (SIL2 / SIL3) "forced disconnection" capability as hardwired systems. In the event of communication interruption, node power failure, or software malfunction, the system may not reliably enter a safe state (i.e., the risk of "fault masking").
[0008] Weak diagnostic capabilities: Most solutions only achieve status transmission and do not utilize bus capabilities to perform in-depth diagnosis of the physical layer health status of switches, cables, etc., and the problem of fault location has not been fundamentally solved.
[0009] Information security risk exposure: Networked access introduces a potential network attack surface. Attacks such as malicious node access, communication hijacking, and injection of false commands may deceive the control system, making it unable to shut down when a real danger occurs, posing a serious security risk.
[0010] Rigid architecture: Simply replacing parallel lines with communication lines fails to achieve organic decoupling and deep integration of security, diagnostic and communication functions at the system architecture level, resulting in insufficient resilience of the system when dealing with complex faults and advanced threats. Summary of the Invention
[0011] In view of the shortcomings of the prior art, the purpose of this invention is to provide a connecting device and control method for escalators.
[0012] To achieve the aforementioned objectives, the technical solution adopted by this invention includes: a connection device for escalators, comprising dual physical safety links, distributed safety nodes, and a main controller. The dual physical safety links consist of two completely independent and electrically isolated physical safety links laid in parallel along the entire escalator line, specifically link A and link B. These two links are the final and unavoidable physical channels for the system to execute a safe shutdown. The distributed safety node includes an electronic safety circuit, an electronic safety circuit L, a microprocessor unit, a bus communication interface, a diagnostic access switch, a diagnostic bus, and a safety relay unit containing two pairs of normally open, forced-guided (mechanically linked) contacts K_A and K_B, connected in series in physical safety links A and B respectively. The states of these two pairs of contacts are completely synchronized. The electronic safety circuit L controls the on / off state of K_A and K_B. Its excitation circuit is designed as follows: positive power supply, local safety switch physical contact S_phys, coil L, and negative power supply. This circuit is a simple, direct, hardwired circuit with no possibility of electronic bypass, ensuring that disconnecting S_phys directly de-energizes coil L, thus physically breaking the two safety links. The microprocessor unit (MCU) is responsible for logic control and communication. The bus communication interface has two independent physical ports, Port A and Port B, used to build a dual-loop communication network. The diagnostic access switch Sw_diag is an electronic switch (such as an optocoupler relay) controlled by the MCU. One end connects to the high-potential terminal of the electronic safety circuit L (i.e., after S_phys), and the other end connects to an independent diagnostic bus D+. This switch is off by default. The diagnostic bus connects to an independent diagnostic bus running throughout the entire circuit. This bus consists of a pair of lightweight wires (D+ and D-), with D- typically connected to common ground. The diagnostic bus is used only for fault diagnosis and verification and does not participate in the on / off control of the safety link. The main controller includes a main communication interface and a safety link status detection unit (SLDMU). The SLDMU includes a physical link on / off detection circuit, a diagnostic excitation and measurement circuit, and a safety decision unit. The main communication interface is used to access the dual-ring communication network. The SLDMU includes: a physical link on / off detection circuit that directly detects the voltage / current of link A and link B to determine their conduction status; a programmable diagnostic excitation and measurement circuit that includes a precision constant current source and a high-precision voltage sampling and demodulation circuit. This circuit can be switched to the diagnostic bus to inject test signals into the diagnostic loop composed of multiple node coils and measure the response; and a high-performance processor that runs safety logic, diagnostic algorithms, communication protocols, and safety models. The network topology includes: a communication network that adopts a dual-fiber unidirectional ring topology based on the Ethernet Ring Protection System (ERPS) protocol. Link A of all nodes is connected in series to form the main ring, and link B is connected in series to form the backup ring.Data is transmitted unidirectionally in the main ring. In the event of a main ring failure, the system switches to the backup ring within 50ms. The diagnostic bus uses a linear bus topology. The D+ and D- terminals of all nodes are connected in parallel to a security link status detection unit. The output of this unit controls a set of independent electronic safety circuits. Each fuse relay is connected in series in the power supply circuit (power+) of the corresponding distributed security node block. The fuse circuit is directly driven by the safety fuse output unit. An additional safety fuse output unit is added to the main controller. This unit is controlled by an independent, safety-certified security circuit or electronically programmable safety controller. Its inputs are the fuse command from the main controller's safety decision unit and the main controller's health status from the watchdog circuit of the monitoring chip.
[0013] An escalator control method employing an escalator connection device system includes: Phase 1, System Secure Startup and Network Construction: Step S1: Pre-authentication and Physical Layer Activation: After the main controller powers on, it broadcasts a wake-up frame containing a pre-shared installation code from its two ports. Upon receiving the frame, a legitimate secure node module verifies the installation code and replies with a simple online response frame through the port that received the frame. At this point, only a minimal link-layer connection is established. Step S2: Secure Topology Discovery and Strong Authentication: Based on the online response frame, the main controller initially perceives the correspondence between nodes and ports. Subsequently, the main controller initiates a challenge-response authentication based on the Elliptic Curve Digital Signature Algorithm (ECDSA) for each perceived node. The node signs the challenge using its unique private key. After successful authentication, the main controller sends a neighbor probe command. Each node reports its physical link neighbor information (such as link pulses) detected from Port A and Port B. The main controller integrates all information and draws a complete and reliable physical topology map of the dual-ring network. Step S3: Secure session establishment and operation state startup: The main controller performs an elliptic curve Diffie-Hellman (ECDH) key exchange with each successfully authenticated node to negotiate a unique session symmetric key K_sess. Based on the topology map, the main controller configures the communication routes (primary port, backup port) for each node. All nodes begin to periodically (e.g., every 10ms) send a secure status frame encrypted with K_sess through their primary port. The frame includes at least: node ID, the current state (True / False) of the security switch S_phys, a high-precision timestamp, and a sequence number. The main controller starts continuous monitoring of the physical secure links A and B, and the system enters normal operation.
[0014] Phase Two: Normal Operation and Continuous Health Monitoring, Safety Monitoring Principles: All health monitoring and predictive maintenance functions in this phase are based on the premise of not interfering with, relying on, or replacing the basic safety decisions of physical safety links and real-time communication status. They are parallel and enhanced safety and maintenance functions. The on / off status of the physical safety link is always the sole and ultimate basis for allowing escalator operation. Specifically, this includes: Step M1, Normal Learning: When the escalator is running normally and all safety switches are closed, the main controller's SLDMU can periodically (e.g., every minute) switch to diagnostic mode. The SLDMU broadcasts instructions to all nodes through the diagnostic buses D+ and D-, requiring them to close Sw_diag. A diode D_iso (cathode connected to the coil end, anode connected to Sw_diag) is connected in series between the high-potential terminal of the electronic safety circuit L and the connection point of the diagnostic access switch Sw_diag. Simultaneously, a bias resistor R_bias (e.g., 10kΩ) with a large resistance is added between the positive terminal of the power supply and the high potential terminal of circuit L. At this time, the electronic safety circuits L of all nodes are connected to the diagnostic bus through their Sw_diag, forming a diagnostic loop of all electronic safety circuits. Each electronic safety circuit L can be equivalent to a series connection of an inductor L_coil and a resistor R_coil. The SLDMU injects a small multi-frequency test current into this loop and measures its total impedance spectrum Z_total(f). Since all L_coil and R_coil are known, this measurement is mainly used to establish the impedance baseline of the entire loop and to deduce an average contact resistance. This baseline is used to monitor overall aging. Step M2, Fault Triggering and Precise Location: When the physical safety link A or B is disconnected (caused by the action of a safety switch or a line break), or when a communication message indicates that a switch has been activated, the system triggers the fault diagnosis mode to locate the open circuit fault: a. The SLDMU commands all nodes to close Sw_diag through the communication bus.
[0015] b. The SLDMU attempts to apply a low-voltage DC to the diagnostic loop. If the loop remains open (current is 0), it confirms that the physical link itself is broken or all safety switches are open (very low probability).
[0016] c. The SLDMU commands each node to briefly open its Sw_diag via the communication bus (e.g., open for 100ms and then automatically close), and synchronously monitors the total current I_total(t) of the diagnostic circuit at a high frequency.
[0017] d. Analyze the current change of each node during the Sw_diag opening period: Normal node: When Sw_diag is opened, the node is removed from the diagnostic circuit, and I_total(t) will drop by an expected step value ΔI_normal (corresponding to the removal of the parallel impedance of the node coil and R_bias). Fault node (S_phys disconnected): Since it has already been connected to the circuit through R_bias, the opening action of Sw_diag has a minimal impact on the total impedance of the circuit. I_total(t) hardly changes or the change value ΔI_fault is much smaller than ΔI_normal. By identifying nodes with abnormal ΔI, the fault node in which S_phys is disconnected can be located. This method does not require prior knowledge of whether the circuit is open and can directly distinguish between a line break and a switch disconnection. This step also includes predictive maintenance based on a Hidden Markov Model (HMM): Step P1: Feature extraction: For each safety switch, calculate in real time: action frequency N_act, state jitter F_jitter, action timing difference Δt_ij with associated switches, ambient temperature T, and other feature vectors O_t. Step P2: State assessment: Establish an HMM for critical switches, with hidden states {healthy (H), sub-healthy (S), critical (C)}. Training: Offline: Obtain labeled sequences (O_1:T, S_1:T) from accelerated life tests in the laboratory, and train initial parameters (A, B) using the Baum-Welch algorithm. Online: After a real fault occurs in the field, extract the feature sequence M hours before the fault, label it as S_t = C, and update the model parameters online with a small learning rate. Learning rate: During online updates, use the exponential decay averaging method to update the HMM parameters: B_new = (1 - η) * B_old + η * B_sample, where η is the learning rate (e.g., 0.01), B_sample is the observation probability matrix calculated from the new sample, and B_old is the old observation probability matrix. Step P3: Define the graded response and decouple it from the safety link decision: Warning level (P(S_t = S) > Θ_warn): Send a maintenance alarm to the upper-level management system without affecting the current operation of the escalator. Action level (P(S_t = C) > Θ_action): The main controller issues a high-level risk warning to the upper-level system and suggests speed limiting or planned shutdown. Whether to implement this suggestion is decided by the upper-level management system or the operator. The main controller's own safety decision logic is still based only on the physical link and real-time communication status, and is only enforced in one case: If the predictive model and the communication bus continuously report abnormal switch status (e.g., continuous jitter) at the same time, and the physical link has not been disconnected, the safety decision unit can determine it as an abnormal node communication and behavior, which may trigger the continuous dynamic authentication challenge in stage three (step D2), rather than directly intervening in the operating speed.
[0018] Phase Three: Anomaly Handling and Security Defense: Communication Self-Healing and Reliable Data Transmission: Self-Healing Mechanism: The system operates based on the standard ERPS protocol. When the main ring fiber breaks, adjacent nodes will detect the fault within milliseconds and send a ring network protection protocol frame. All nodes synchronously switch data services to the backup ring path. This process is guaranteed by hardware and underlying protocols, is fast, and requires no application layer intervention. Reliable Data Transmission: Nodes independently send encrypted status frames. The main controller processes the first valid frame arriving at any port and records the sequence number. Lightweight reliable transmission is guaranteed by periodically sending cumulative acknowledgment frames. Nodes can trigger retransmission or path switching alarms if they do not receive an acknowledgment.
[0019] This step also includes continuous dynamic authentication and behavioral anomaly challenges: Step D1: Behavioral Modeling and Anomaly Detection: Establish node communication behavior models (periodic jitter, frame length) and physical behavior models of safety switches (e.g., state change sequence after emergency stop is pressed). Monitor deviations in real time.
[0020] Step D2: Initiating a Non-Destructive Electrical Challenge: Safety Confirmation: Before initiating the challenge, the safety decision unit must confirm that both physical security links A and B are in a conducting state, and that the S_phys state reported by the challenged node X is closed, based on the communication messages. This is a prerequisite for the challenge. Loop Preparation: The SLDMU broadcasts a command via the diagnostic bus, instructing all nodes to close Sw_diag to establish a basic diagnostic loop. Sending the Challenge Command: The main controller sends a secret challenge command to node X via an encrypted channel. The command contains the challenge resistance value R_challenge and the pulse width T_pulse. se, Node Execution: After receiving the instruction, node X controls the switch connected in parallel with the electronic safety circuit L at a specified time point to connect R_challenge, which lasts for T_pulse and then disconnects. When node X is detected to have abnormal behavior (such as overly regular messages), the main controller sends a secret challenge instruction to it through an encrypted channel. After receiving the instruction, node X, under the control of its MCU, momentarily connects a high-precision, known-value challenge resistor R_challenge (e.g., 1kΩ) in parallel across its electronic safety circuit L for a duration of T_pulse (e.g., 20ms). This operation is completed through a switch completely in parallel with the electronic safety circuit L, without ever connecting or bypassing the safety switch S_phys in series. At the same time, the main controller's SLDMU must have pre-commanded all nodes to close Sw_diag via the diagnostic bus and continuously monitor the total impedance Z_monitor(t) of the diagnostic loop at a high sampling rate. Step D3: Verification and Fuse: During the challenge, due to the change in the coil branch resistance of node X, ΔR = R_coil / / R_challenge occurs. - Known variations of R_coil, R_coil: DC resistance of the electronic safety circuit, R_challenge: challenge resistance value, total impedance of the diagnostic loop. Z_monitor(t) should produce a calculable theoretical transient waveform ΔZ_calc(t). The SLDMU captures the actual waveform ΔZ_meas(t) of Z_monitor(t). Verification logic: Trustworthy: If ΔZ_meas(t) and ΔZ_calc(t) are highly matched in time, amplitude, and shape (correlation coefficient > 0.9), it proves that the MCU of node X is functioning normally and responding to the command, and the alarm is cleared. Untrustworthy / Faulty: If the expected transient is not detected, or the transient is severely distorted or time-misaligned, it is determined that the MCU of node X may be hijacked or has a serious fault. Step D4: Security Isolation (Fuse): For nodes determined to be untrustworthy, the main controller immediately cuts off the power supply to the node and its subordinate safety switches through an independent security circuit or electronic programmable safety controller, completely isolating it electrically. At the same time, the highest level alarm is triggered and the security event is recorded.
[0021] Compared with existing technologies, the advantages of the present invention include: (1) The connection device and control method for escalators provided by the present invention, with its dual physical safety links and direct control design, can still directly disconnect the safety circuit through a physical switch when any electronic system (including MCU and communication) fails, meeting the highest failure-safety standard; (2) The connection device and control method for escalators provided by the present invention, through an independent diagnostic bus and innovative algorithms, achieves remote, online, non-destructive, and precise positioning of the safety switch contact status and line connection status, reducing on-site troubleshooting time from several hours to minutes; (3) The connection device and control method for escalators provided by the present invention The method, based on the predictive model of HMM, can identify risk trends before a failure occurs, realizing the transformation from post-maintenance to predictive maintenance; (4) The connection device and control method for escalators provided by this invention, based on the predictive model of HMM, ensures uninterrupted data transmission through dual-loop self-healing communication; continuous dynamic authentication + non-destructive electrical challenge mechanism can effectively identify and isolate attacked or faulty nodes, realizing the deep integration of functional safety and information security; (5) The connection device and control method for escalators provided by this invention, the bus-based design greatly reduces the amount of cables and cable trays and installation time; the standardized node module simplifies design and production, and reduces the total life cycle cost. Attached Figure Description
[0022] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0023] Figure 1 is an overall operation flowchart of an escalator connection device and control method according to the present invention; Figure 2 is a safety monitoring and decision-making flowchart of an escalator connection device and control method according to the present invention; Figure 3 is a parallel intelligent monitoring flowchart of an escalator connection device and control method according to the present invention; Figure 4 is a deep diagnosis and fault location flowchart of an escalator connection device and control method according to the present invention; Figure 5 is a graded response flowchart of an escalator connection device and control method according to the present invention. Detailed Implementation
[0024] In view of the shortcomings of the prior art, the inventors of this invention, through long-term research and extensive practice, have proposed the technical solution of this invention. The technical solution, its implementation process, and principles will be further explained below with reference to the accompanying drawings and specific implementation examples in the embodiments of this application.
[0025] It should be noted that the embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain the present invention, and should not be construed as limiting the present invention. The described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, the present invention covers any substitutions, modifications, equivalent methods and solutions made on the spirit, principles and scope of the present invention as defined by the claims. All other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0026] In the description of this application, the terms "first," "second," "third," and similar terms do not indicate any order, quantity, or importance, but are merely used to distinguish different components. Similarly, the terms "one" or "a" do not indicate a quantity limitation, but rather indicate the presence of at least one. Terms such as "include" or "contain" mean that the elements or objects preceding "include" cover the elements or objects listed following "include" or their equivalents, and do not exclude other elements or objects. Terms such as "connected" or "linked" are not limited to physical or mechanical connections, but can include electrical connections, whether direct or indirect.
[0027] In the description of this application, the terms center, up, down, front, back, left, right, vertical, horizontal, top, bottom, inside, outside, etc., indicate the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings. They are used only for the convenience of describing this application and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, they should not be construed as limitations on this application. In addition, when using positional terms such as sides, outer side, top and bottom, etc., it should be understood that they are used only for the convenience of understanding and description, taking into account that the structure may be oriented to other positions.
[0028] In the description of this application, unless otherwise expressly specified and limited, the technical or scientific terms used shall have the ordinary meaning understood by a person with ordinary skills in the art to which this application pertains. Terms such as installation, connection, and linking shall be interpreted broadly, for example, they may refer to fixed connection, detachable connection, mating connection, or integral connection. For a person skilled in the art, the specific meaning of the above terms in this application may be understood according to the specific circumstances.
[0029] The present invention aims to introduce and explain the structural composition of a connecting device and control method for escalators and the cooperation relationship between the various components. Unless otherwise specified, the dimensions, materials and manufacturing processes of the various components in the connecting device and control method for escalators in the present invention can be selected according to specific circumstances, and no special limitations or explanations are made here.
[0030] Furthermore, to provide the public with a better understanding of the present invention, certain specific details are described in detail in the following description of the invention. However, those skilled in the art will fully understand the invention even without these detailed descriptions.
[0031] Example 1 (Refer to Figures 1-5): A connection device for escalators includes: dual physical safety links, distributed safety nodes, and a main controller. The dual physical safety links consist of two completely independent and electrically isolated physical safety links laid in parallel along the entire escalator line, specifically link A and link B. These two links are the final, unavoidable physical channels for the system to execute a safe shutdown. The distributed safety node includes an electronic safety circuit, an electronic safety circuit L, a microprocessor unit, a bus communication interface, a diagnostic access switch, a diagnostic bus, and a safety relay unit containing two pairs of normally open, forced-guided (mechanically linked) contacts K_A and K_B, connected in series in physical safety links A and B respectively. The states of these two pairs of contacts are completely synchronized. The electronic safety circuit L controls the on / off state of K_A and K_B. Its excitation circuit is designed as follows: positive power supply, local safety switch physical contact S_phys, coil L, and negative power supply. This circuit is a simple, direct, hardwired circuit with no possibility of electronic bypass, ensuring that disconnecting S_phys directly de-energizes coil L, thus physically breaking the two safety links. The microprocessor unit (MCU) is responsible for logic control and communication. The bus communication interface has two independent physical ports, Port A and Port B, used to build a dual-loop communication network. The diagnostic access switch Sw_diag is an electronic switch (such as an optocoupler relay) controlled by the MCU. One end connects to the high-potential terminal of the electronic safety circuit L (i.e., after S_phys), and the other end connects to an independent diagnostic bus D+. This switch is off by default. The diagnostic bus connects to an independent diagnostic bus running throughout the entire circuit. This bus consists of a pair of lightweight wires (D+ and D-), with D- typically connected to ground. The diagnostic bus is used only for fault diagnosis and verification and does not participate in the on / off control of the safety link. The main controller includes a main communication interface and a safety link status detection unit (SLDMU). The SLDMU includes a physical link on / off detection circuit, a diagnostic excitation and measurement circuit, and a safety decision unit. The main communication interface is used to access the dual-ring communication network. The SLDMU includes: a physical link on / off detection circuit that directly detects the voltage / current of link A and link B to determine their conduction status; a programmable diagnostic excitation and measurement circuit that includes a precision constant current source and a high-precision voltage sampling and demodulation circuit. This circuit can be switched to the diagnostic bus to inject test signals into the diagnostic loop composed of multiple node coils and measure the response; and a high-performance processor that runs safety logic, diagnostic algorithms, communication protocols, and safety models. The network topology includes: a communication network that adopts a dual-fiber unidirectional ring topology based on the Ethernet Ring Protection System (ERPS) protocol. Link A of all nodes is connected in series to form the main ring, and link B is connected in series to form the backup ring.Data is transmitted unidirectionally in the main ring. In the event of a main ring failure, the system switches to the backup ring within 50ms. The diagnostic bus uses a linear bus topology. The D+ and D- terminals of all nodes are connected in parallel to a security link status detection unit. The output of this unit controls a set of independent, forced-direction safety relays (fuse relays). Each fuse relay is connected in series in the power supply circuit (power+) of the corresponding distributed security node block. The coil of the fuse relay is directly driven by the safety fuse output unit. An additional safety fuse output unit is added to the main controller. This unit is controlled by an independent, safety-certified security circuit or electronically programmable safety controller. Its inputs are the fuse command from the main controller's safety decision unit and the main controller's health status from the watchdog circuit of the monitoring chip.
[0032] An escalator control method employs a system with an escalator connection device, comprising: Phase 1, System Secure Startup and Network Construction: Step S1: Pre-authentication and Physical Layer Activation: After the main controller powers on, it broadcasts a wake-up frame containing a pre-shared installation code from its two ports. Upon receiving the frame, a legitimate secure node module verifies the installation code and replies with a simple online response frame through the port that received the frame. At this point, only a minimal link-layer connection is established. Step S2: Secure Topology Discovery and Strong Identity Authentication: Based on the online response frame, the main controller initially perceives the correspondence between nodes and ports. Subsequently, the main controller initiates a challenge-response authentication based on the Elliptic Curve Digital Signature Algorithm (ECDSA) for each perceived node. The node signs the challenge using its unique private key. After successful authentication, the main controller sends a neighbor probe command. Each node reports its physical link neighbor information (such as link pulses) detected from Port A and Port B. The main controller integrates all information and draws a complete and reliable physical topology map of the dual-ring network. Step S3: Secure session establishment and operation state startup: The main controller performs an elliptic curve Diffie-Hellman (ECDH) key exchange with each successfully authenticated node to negotiate a unique session symmetric key K_sess. Based on the topology map, the main controller configures the communication routes (primary port, backup port) for each node. All nodes begin to periodically (e.g., every 10ms) send a secure status frame encrypted with K_sess through their primary port. The frame includes at least: node ID, the current state (True / False) of the security switch S_phys, a high-precision timestamp, and a sequence number. The main controller starts continuous monitoring of the physical secure links A and B, and the system enters normal operation.
[0033] Phase Two: Normal Operation and Continuous Health Monitoring, Safety Monitoring Principles: All health monitoring and predictive maintenance functions in this phase are based on the premise of not interfering with, relying on, or replacing the basic safety decisions of physical safety links and real-time communication status. They are parallel and enhanced safety and maintenance functions. The on / off status of the physical safety link is always the sole and ultimate basis for allowing escalator operation. Specifically, this includes: Step M1, Normal Learning: When the escalator is running normally and all safety switches are closed, the main controller's SLDMU can periodically (e.g., every minute) switch to diagnostic mode. The SLDMU broadcasts instructions to all nodes through the diagnostic buses D+ and D-, requiring them to close Sw_diag. A diode D_iso (cathode connected to the coil end, anode connected to Sw_diag) is connected in series between the high-potential end of the electronic safety circuit L and the connection point of the diagnostic access switch Sw_diag. Simultaneously, a bias resistor R_bias (e.g., 10kΩ) with a large resistance is added between the positive terminal of the power supply and the high potential terminal of circuit L. At this time, the electronic safety circuits L of all nodes are connected to the diagnostic bus through their Sw_diag, forming a diagnostic loop consisting of all the series circuits. Each circuit L can be equivalent to a series connection of an inductor L_coil and a resistor R_coil. The SLDMU injects a small multi-frequency test current into this loop and measures its total impedance spectrum Z_total(f). Since all L_coil and R_coil are known, this measurement is mainly used to establish the impedance baseline of the entire loop and to deduce an average contact resistance. This baseline is used to monitor overall aging. Step M2, Fault Triggering and Precise Location: When the physical safety link A or B is disconnected (caused by the action of a safety switch or a line break), or when a communication message indicates that a switch has been activated, the system triggers the fault diagnosis mode to locate the open circuit fault: a. The SLDMU commands all nodes to close Sw_diag through the communication bus.
[0034] b. The SLDMU attempts to apply a low-voltage DC to the diagnostic loop. If the loop remains open (current is 0), it confirms that the physical link itself is broken or all safety switches are open (very low probability).
[0035] c. The SLDMU commands each node to briefly open its Sw_diag via the communication bus (e.g., open for 100ms and then automatically close), and synchronously monitors the total current I_total(t) of the diagnostic circuit at a high frequency.
[0036] d. Analyze the current change of each node during the Sw_diag opening period: Normal node: When Sw_diag is opened, the node is removed from the diagnostic loop, and I_total(t) will drop by an expected step value ΔI_normal (corresponding to the removal of the parallel impedance of the node coil and R_bias). Fault node (S_phys disconnected): Since it has already been connected to the loop through R_bias, the opening action of Sw_diag has a minimal impact on the total impedance of the loop, and I_total(t) hardly changes or the change value ΔI_fault is much smaller than ΔI_normal. By identifying nodes with abnormal ΔI, the fault node in which S_phys is disconnected can be located. This method does not require prior knowledge of whether the circuit is open and can directly distinguish between a line break and a switch disconnection. This step also includes predictive maintenance based on a Hidden Markov Model (HMM): Step P1: Feature Extraction: For each safety switch, calculate in real-time: action frequency N_act, state jitter F_jitter, action timing difference Δt_ij with associated switches, ambient temperature T, and other feature vectors O_t. Step P2: State Assessment: Establish an HMM for critical switches, with hidden states {healthy (H), sub-healthy (S), critical (C)}. Training: Offline: Obtain labeled sequences (O_1:T, S_1:T) from accelerated life testing in the laboratory, and train initial parameters (A, B) using the Baum-Welch algorithm. Online: After a real fault occurs in the field, extract the feature sequence from the M hours before the fault, label it as S_t = C, and update the model parameters online with a small learning rate. Learning Rate: During online updates, use the exponential decay averaging method to update the HMM parameters: B_new = (1 - η) * B_old + η * B_sample, where η is the learning rate (e.g., 0.01), B_sample is the observation probability matrix calculated from the new sample, and B_old is the old observation probability matrix. Step P3: Define the graded response and decouple it from the safety link decision: Warning level (P(S_t = S) > Θ_warn): Send a maintenance alarm to the upper-level management system without affecting the current operation of the escalator. Action level (P(S_t = C) > Θ_action): The main controller issues a high-level risk warning to the upper-level system and suggests speed limiting or planned shutdown. Whether to implement this suggestion is decided by the upper-level management system or the operator. The main controller's own safety decision logic is still based only on the physical link and real-time communication status, and is only enforced in one case: If the predictive model and the communication bus continuously report abnormal switch status (e.g., continuous jitter) at the same time, and the physical link has not been disconnected, the safety decision unit can determine it as an abnormal node communication and behavior, which may trigger the continuous dynamic authentication challenge in stage three (step D2), rather than directly intervening in the operating speed.
[0037] Phase Three: Anomaly Handling and Security Defense: Communication Self-Healing and Reliable Data Transmission: Self-Healing Mechanism: The system operates based on the standard ERPS protocol. When the main ring fiber breaks, adjacent nodes will detect the fault within milliseconds and send a ring network protection protocol frame. All nodes synchronously switch data services to the backup ring path. This process is guaranteed by hardware and underlying protocols, is fast, and requires no application layer intervention. Reliable Data Transmission: Nodes independently send encrypted status frames. The main controller processes the first valid frame arriving at any port and records the sequence number. Lightweight reliable transmission is guaranteed by periodically sending cumulative acknowledgment frames. Nodes can trigger retransmission or path switching alarms if they do not receive an acknowledgment.
[0038] This step also includes continuous dynamic authentication and behavioral anomaly challenges: Step D1: Behavioral Modeling and Anomaly Detection: Establish node communication behavior models (periodic jitter, frame length) and physical behavior models of safety switches (e.g., state change sequence after emergency stop is pressed). Monitor deviations in real time.
[0039] Step D2: Initiating a Non-Destructive Electrical Challenge: Safety Confirmation: Before initiating the challenge, the safety decision unit must confirm that both physical security links A and B are in a conducting state, and that the S_phys state reported by the challenged node X is closed, based on the communication messages. This is a prerequisite for the challenge. Loop Preparation: The SLDMU broadcasts instructions via the diagnostic bus, commanding all nodes to close Sw_diag to establish a basic diagnostic loop. Sending the Challenge Instruction: The main controller sends a secret challenge instruction to node X via an encrypted channel. The instruction contains the challenge resistance value R_challenge and the pulse width T_pulse. Node Execution: After receiving the instruction, node X controls the switch connected in parallel with coil L within its internal circuit at a specified time point, connecting R_challenge, continuing for T_pulse, and then disconnecting. When node X is detected to have abnormal behavior (such as overly regular messages), the main controller sends a secret challenge instruction to it via an encrypted channel. After receiving the instruction, node X, under the control of its MCU, activates its electronic safety circuit L. At both ends, a high-precision, known-value challenge resistor R_challenge (e.g., 1kΩ) is instantaneously connected in parallel for a duration T_pulse (e.g., 20ms). This operation is accomplished through a switch that is completely parallel to circuit L, without ever connecting it in series or bypassing the safety switch S_phys. Simultaneously, the SLDMU of the main controller must have pre-commanded all nodes to close Sw_diag via the diagnostic bus and continuously monitor the total impedance Z_monitor(t) of the diagnostic loop at a high sampling rate. Step D3: Verification and Fuse: During the challenge, due to a known change in the coil branch resistance of node X of ΔR = R_coil / / R_challenge - R_coil, where R_coil is the DC resistance of the electronic safety circuit and R_challenge is the challenge resistance value, the total impedance Z_monitor(t) of the diagnostic loop should produce a calculable theoretical transient waveform ΔZ_calc(t). The SLDMU captures the actual waveform ΔZ_meas(t) of Z_monitor(t). Verification logic: Confidentiality: If ΔZ_meas(t) and ΔZ_calc(t) are highly matched in time, amplitude, and shape (correlation coefficient > 0.05), then the total impedance Z_monitor(t) of the diagnostic loop is considered reliable. If 0.9), it proves that the MCU of node X is functioning normally and has responded to the command, and the alarm is cleared. Untrusted / Faulty: If the expected transient is not detected, or the transient is severely distorted or the timing is out of sync, it is determined that the MCU of node X may have been hijacked or has suffered a serious fault. Step D4: Security Isolation (Fuse): For nodes determined to be untrusted, the main controller immediately cuts off the power supply to the node and its associated safety switches through an independent security circuit or electronic programmable safety controller, completely isolating it electrically. At the same time, the highest level alarm is triggered and the security event is recorded.
[0040] How it works: For example, this method can significantly reduce wiring costs and complexity, and reduce the amount of cable used through bus-based connections.
[0041] This enables precise fault location and predictive maintenance, reducing the difficulty and cost of operation and maintenance.
[0042] The system meets the highest Security Integrity Level (SIL) requirements and can reliably enter a safe state under any single point of failure (including communication failure and node failure).
[0043] Build a robust and adaptive security system that can withstand potential cyberattacks and internal failures.
[0044] It should be understood that the above embodiments are only for illustrating the technical concept and features of the present invention, and are intended to enable those skilled in the art to understand the content of the present invention and implement it accordingly. It should not be considered that the specific implementation of the present invention is limited to these descriptions. For those skilled in the art, several simple deductions or substitutions can be made without departing from the concept of the present invention. All equivalent changes or modifications made in accordance with the spirit and essence of the present invention should be covered within the protection scope of the present invention.
Claims
1. A connecting device for escalators, characterized in that: The system includes dual physical safety links, distributed safety nodes, and a main controller. The dual physical safety links consist of two completely independent and electrically isolated physical safety links laid in parallel along the entire escalator line, designated as Link A and Link B. The distributed safety node includes an electronic safety circuit, an electronic safety circuit L, a microprocessor unit, a bus communication interface, a diagnostic access switch, and a diagnostic bus. The electronic safety circuit comprises two sets of electronic safety circuits, K_A and K_B, whose states are completely synchronized and connected in series in physical safety links A and B, respectively. The electronic safety circuit L controls the on / off state of K_A and K_B. The microprocessor unit is responsible for logic control and communication. The bus communication interface has two independent physical ports, Port A and Port B, used to form a dual-loop communication network. The diagnostic access switch is an electronic switch controlled by the microprocessor unit, with one end connected to the electronic safety circuit L. The high-potential end is connected to an independent diagnostic bus, which is a separate diagnostic bus that runs through the entire line and is used for fault diagnosis and verification. The main controller includes a main communication interface and a security link status detection unit. The security link status detection unit includes a physical link continuity detection circuit, a diagnostic excitation and measurement circuit, and a security decision unit. The physical link continuity detection circuit directly detects the voltage / current of link A and link B to determine their conduction status. The diagnostic excitation and measurement circuit includes a precision constant current source and a high-precision voltage sampling and demodulation circuit. This circuit can be switched to the diagnostic bus to inject test signals into the diagnostic loop composed of multiple electronic safety circuits and measure the response. The security decision unit runs security logic, diagnostic algorithms, communication protocols, and security models.
2. The connecting device for an escalator according to claim 1, characterized in that: It also includes the network topology, including: Communication network: adopts a dual-fiber unidirectional ring topology based on Ethernet ring network protection protocol, with Port A of all distributed security nodes connected in series to form the main ring, and Port B connected in series to form the backup ring. Data is transmitted unidirectionally in the main ring, and switches to the backup ring when the main ring fails.
3. A connecting device for escalators according to any one of claims 1 or 2, characterized in that: It also includes a safety fuse output unit in the main controller, which is controlled by an independent safety circuit or electronic programmable safety controller, and its input is a fuse command from the safety decision unit of the main controller.
4. An escalator control method, employing the method described in any one of claims 1-3, characterized in that: The process includes the following steps: Phase 1: Pre-authentication and physical layer activation: The master controller broadcasts a wake-up frame containing a pre-shared installation code from its two physical ports. Upon receiving the frame, a legitimate distributed security node block verifies the installation code and replies with a simple online response frame through the physical port that received the frame. Each distributed security node block reports the physical link neighbor information it detected from link A and link B. The master controller integrates all the information and draws a complete and reliable physical topology map of the dual-ring network. Phase Two, Normal Operation and Continuous Health Monitoring, specifically includes: Step M1: Routine Learning: When the escalator is running normally and all safety switches are closed, the main controller periodically switches the safety link status detection unit to diagnostic mode. Through the diagnostic buses D+ and D-, it broadcasts instructions to all nodes, requiring them to close Sw_diag. A diode D_iso is connected in series between the high-potential terminal of the electronic safety circuit L and the connection point of the diagnostic access switch Sw_diag. Simultaneously, a bias resistor R_bias with a large resistance is added between the positive terminal of the power supply and the high-potential terminal of the coil L. At this time, the electronic safety circuit L of all nodes, through its Sw_diag... Connected to the diagnostic bus, forming a diagnostic loop with all coils connected in series; Step M2: Fault Triggering and Precise Location: When link A or link B is disconnected; Phase 3: Anomaly Handling and Security Defense: Communication Self-Healing and Trusted Data Transmission: Self-Healing Mechanism: When the main ring fiber breaks, the nodes adjacent to the fault point will detect it within milliseconds and send a ring network protection protocol frame. All nodes will synchronously switch data services to the backup ring path. Trusted data transmission: Nodes independently send encrypted status frames. The main controller processes the first valid frame arriving at any port and records the sequence number. It also includes continuous dynamic authentication and behavioral anomaly challenge: Step D1: Behavioral Modeling and Anomaly Detection: Establish a node communication behavior model and a safety switch physical behavior model, and monitor deviations in real time; Step D2: Initiate a Non-Destructive Electrical Challenge: Node Execution: After receiving the instruction, node X controls the switch connected in parallel with coil L inside it at a specified time point, connects to R_challenge, and disconnects after T_pulse; When node X is detected to have a behavioral anomaly, the main controller sends a secret challenge instruction to it through an encrypted channel. After receiving the instruction, node X, under the control of its microprocessor unit, activates its electronic security circuit L At both ends, a high-precision, known-value challenge resistor R_challenge is instantaneously connected in parallel for a duration of T_pulse; Step D3: Verification and Fuse: During the challenge, due to the known change of the coil branch resistance of node X by ΔR = R_coil / / R_challenge - R_coil, where R_coil is the DC resistance of the electronic safety circuit and R_challenge is the challenge resistance value, the total impedance of the diagnostic circuit Z_monitor(t) should generate a calculable theoretical transient waveform ΔZ_calc(t). The SLDMU captures the actual waveform ΔZ_meas(t) of Z_monitor(t) to verify trustworthiness and untrustworthiness / fault; Step D4: Safety Isolation: For nodes determined to be untrustworthy, the main controller immediately cuts off the power supply to the node and its associated safety switches through an independent hardwired safety line, completely isolating it electrically. At the same time, the highest-level alarm is triggered, and the safety event is recorded.
5. The escalator control method according to claim 4, characterized in that: The M2 system triggers fault diagnosis mode to locate open-circuit faults: a. Command all nodes to close Sw_diag via the communication bus; b. Attempt to apply a low-voltage DC to the diagnostic loop. If the loop remains open, it confirms that the physical link itself is broken or all safety switches are open; c. Command each node to briefly open its Sw_diag via the communication bus, and synchronously monitor the total current I_total(t) of the diagnostic loop at high frequency; d. Analyze the current change of each node during the opening of Sw_diag: Normal node: When Sw_diag is opened, the node is removed from the diagnostic loop, and I_total(t) will drop by an expected step value ΔI_normal; Faulty node: S_phys is disconnected: Since it has already been connected to the loop through R_bias, the opening action of Sw_diag has minimal impact on the total impedance of the loop, and I_total(t) hardly changes or the change value ΔI_fault is much smaller than ΔI_normal. By identifying the node with abnormal ΔI, S_phys can be located. A faulty node that is disconnected.
6. The escalator control method according to claim 5, characterized in that: Step M2 further includes predictive maintenance based on a Hidden Markov Model: Step P1: Feature extraction: For each safety switch, calculate in real time: action frequency N_act, state jitter F_jitter, action timing difference Δt_ij with associated switches, ambient temperature T, and feature vector O_t. Step P2: State assessment: Establish an HMM for critical switches, with hidden states {healthy (H), sub-healthy (S), critical (C)}. Training: Offline: Obtain labeled sequences (O_1:T, S_1:T) from accelerated life testing in the laboratory, and train initial parameters (A, B) using the Baum-Welch algorithm. Online: After a real fault occurs in the field, extract the feature sequence M hours before the fault, label it as S_t = C, and update the model parameters online with a small learning rate. Learning rate: During online updates, use the exponential decay averaging method to update the HMM parameters: B_new = (1 - η) * B_old + η * B_sample, where η Let B_sample be the learning rate, B_old be the observation probability matrix calculated from the new sample, and B_old be the old observation probability matrix. Step P3: Define the graded response and decouple it from the safety link decision: Warning level P(S_t = S) > Θ_warn: Send a maintenance alarm to the upper-level management system without affecting the current operation of the escalator. Action level P(S_t = C) > Θ_action: The main controller issues a high-level risk warning to the upper-level system and suggests speed limiting or planned shutdown.
7. The escalator control method according to claim 6, characterized in that: Step D3 verifies trusted and untrusted / fault logic: Trustworthy: If ΔZ_meas(t) and ΔZ_calc(t) are highly matched in time, magnitude and shape, it proves that the MCU of node X is functioning normally and responding to the instruction, and the alarm is cleared; Untrustworthy / Faulty: If the expected transient is not detected, or the transient is severely distorted or the time is misaligned, it is determined that the MCU of node X may be hijacked or has a serious fault.
8. A computer medium having a computer program stored thereon, which, when executed, implements the steps of the method as described in any one of claims 4-6.