Intelligent elevator based on ai monitoring system
Patent Information
- Application Number
- CN202611044559.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-14
- Publication Date
- 2026-08-18
AI Technical Summary
[0008]为解决现有升降机在平台停层、机械锁止承载、安全门状态核验及运行许可过程中存在的检测信号与实际物理状态对应不足、各阶段数据缺乏连续关联以及许可条件失效后仍可能触发后续动作的问题,本申请提供基于AI监测系统的智能升降机
通过停层证据构建模块、承载转移确认模块、门锁耦合验证模块和安全许可闭锁模块形成连续的安全控制链,将平台停层、机械锁止承载、安全门状态核验及平台运行恢复关联至同一停层周期,减少各安全装置独立判断时因数据不同步、状态失配或历史许可被错误调用而产生的控制风险。
Smart Images

Figure CN122585785A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of elevator safety control technology, and more specifically, to an intelligent elevator based on an AI monitoring system. Background Technology
[0002] Lifts are widely used in factories, warehouses, construction sites, and production areas to transport personnel, materials, or equipment between different heights. A typical lift includes a platform, drive mechanism, hydraulic system, mechanical locking mechanism, floor safety doors, and controller. Once the platform reaches the target floor, the controller, based on signals from the height detection device, leveling switch, or limit switch, controls the platform to decelerate and stop. The hydraulic system maintains the platform's position, and then the mechanical locking mechanism extends to provide auxiliary support for the platform.
[0003] To prevent the safety doors from opening before the platform has come to a complete stop, existing elevators typically include a door closing switch, a mechanical door lock switch, and an electrical interlock circuit. When the platform reaches the set position, the mechanical locking mechanism outputs a signal indicating it is in position, and the safety door meets the set conditions, the controller allows the safety door to unlock. After the safety door closes and locks again, the controller retracts the mechanical locking mechanism and resumes platform operation. With the development of sensors, image acquisition devices, and control systems, some elevators can also collect information such as platform position, operating speed, hydraulic pressure, and door lock status to help determine the equipment's operating status.
[0004] However, in existing elevators, height signals, image signals, drive status, and leveling signals are typically generated separately by different detection devices, resulting in variations in acquisition cycles, transmission delays, and measurement errors. Controllers often rely on a single signal or a simple combination of multiple instantaneous signals to determine whether the platform has reached a stop, making it difficult to verify the sequence of actions from approaching the floor, entering the leveling area, decelerating, and reaching a stable stop. When the position detection signal deviates, the switch actuates prematurely, or various data are out of sync, a stop confirmation may be generated before the platform has stabilized.
[0005] Whether the mechanical locking mechanism has extended to its full position does not directly reflect whether it has made contact with the load-bearing part and is actually bearing the platform load. Existing control methods mostly rely on position switches or travel signals to determine whether the mechanical locking is complete, lacking continuous verification of the correspondence between platform displacement, changes in hydraulic support, and changes in mechanical locking force. Therefore, it is difficult to identify states such as not making contact when in position, insufficient load bearing, uneven force distribution, and continued platform sinking.
[0006] Meanwhile, the locking signal output by the mechanical door lock switch only indicates that the switch contacts have reached the set state; it cannot fully prove that the bolt has completed the predetermined mechanical action and formed a reliable lock. Switch sticking, bolt jamming, false feedback, and changes in door position can all cause inconsistencies between the electrical signal and the actual physical state. If the controller directly generates unlocking or operation permission based on the final switch signal, it is difficult to confirm whether there is a true causal relationship between the control command, mechanical action, and electrical feedback.
[0007] Therefore, how to continuously verify the correlation between floor stopping, load-bearing capacity, door locks, and operation recovery processes, and promptly revoke subsequent permits and maintain corresponding safety constraints when state mismatch occurs, has become a technical problem that needs to be solved in the safety control of intelligent elevators. Summary of the Invention
[0008] To address the problems of insufficient correspondence between detection signals and actual physical states, lack of continuous correlation between data at different stages, and the potential for subsequent actions to be triggered even after the expiration of permit conditions in existing elevators during platform stopping, mechanical lock load control, safety door status verification, and operation permitting processes, this application provides an intelligent elevator based on an AI monitoring system. This elevator progressively monitors and verifies the stopping process, load transfer process, mechanical lock action response, and safety permit execution process, ensuring that each control stage has clear preconditions, timing relationships, and mismatch handling criteria. This improves the reliability of platform stopping confirmation, mechanical lock load control confirmation, and safety door control, and reduces the risk of accidental locking, release, and start-up under abnormal conditions.
[0009] This application proposes an intelligent elevator based on an AI monitoring system, including: The suspension evidence construction module performs standardized processing and consistency verification on multi-source data during the suspension process, and encapsulates the verified data into time-series evidence units; it calls the time-series evidence units according to the suspension action dependency relationship to construct the current suspension action evidence chain, determines the platform's static candidate state and suspension benchmark data, and obtains the suspension evidence data package; The load transfer confirmation module generates a mechanical locking permission command based on the stop floor evidence data packet, and controls the mechanical locking mechanism to extend; according to the actual extension stroke, platform micro-displacement, hydraulic support force and mechanical support force, it sequentially confirms the extension, contact and load-bearing states, determines the reliable confirmation result of mechanical locking, and obtains the load transfer confirmation data packet. The door lock coupling verification module generates a door lock verification permission command based on the bearer transfer confirmation data packet, applies a restricted verification pulse to the mechanical door lock and obtains the door lock verification response data; and determines the door lock coupling state, door lock coupling confirmation result and door lock anomaly type according to the door lock causal response relationship to obtain the door lock coupling verification data packet. The security permission interlocking module constructs a hierarchical security permission instruction tree based on the stop-floor evidence data packet, the bearer transfer confirmation data packet, and the door lock coupling verification data packet, and generates a state-bound permission credential; it identifies permission mismatches during the permission execution process, revokes the corresponding state-bound permission credential and its subsequent permission credentials, determines the security rollback node, and executes the interlocking control instruction.
[0010] Furthermore, the multi-source data of the stopping process is standardized and its consistency is verified, including: The multi-source data of the stopping process is filtered based on the collection time, the effective duration of the evidence, and the evidence synchronization time difference threshold. The multi-source data of the stopping process includes the current stopping cycle identifier, the target stopping floor, the platform height data, the platform running speed data, the driving mechanism running status, the hydraulic system pressure data, the mechanical locking mechanism position data, the floor safety door locking status data, and the stopping area image. The platform image deviation value is obtained from the image of the stopping area, and the platform coding deviation value is obtained from the platform height data and the stopping reference height. The absolute value of the difference between the two is calculated to obtain the dual-source deviation value. When the dual-source deviation value is not greater than the dual-source deviation threshold and the two are in the same direction, the deviation value with the larger absolute value is determined as the stopping deviation confirmation value, and the verified data is encapsulated into a time-series evidence unit. When the dual-source deviation value is greater than the dual-source deviation threshold or the two are in different directions, the positional evidence inconsistency is written into the abnormal node set.
[0011] Furthermore, the step of constructing the current stop-level action evidence chain by invoking the temporal evidence unit based on the stop-level action dependency includes: The following nodes are set sequentially: approaching the target floor node, entering the leveling allowable zone node, platform deceleration node, and platform static stability node. When the current node is completed and the corresponding time sequence evidence unit satisfies the state conditions and synchronization conditions of the next node, the next node is completed and written into the current stop layer action evidence chain; when the current node is completed but the maximum conversion time exceeds the time limit and the next node is not completed, the action timeout is written into the abnormal node set. When the platform is stationary and stable, and the set of abnormal nodes is empty, the platform is determined to be stationary candidate state. The stationary reference height value, stationary reference pressure value, and initial position value of the locking mechanism are calculated. The current stop cycle identifier, the current stop action evidence chain, the set of abnormal nodes, the platform stationary candidate state, the stationary reference height value, the stationary reference pressure value, and the initial position value of the locking mechanism are encapsulated into a stop evidence data package.
[0012] Further, the extended state and the contact state are confirmed sequentially, including: When the platform is in a static candidate state and the abnormal node set is empty, a mechanical locking permission command is generated; the actual extension stroke is determined based on the current mechanical locking mechanism position data and the initial position value of the locking mechanism; the platform micro-displacement is determined based on the current platform height data and the static reference height value; and the extension state and contact state are determined sequentially by combining the locking mechanism force data; a mechanical load-bearing state ternary set including the extension state, contact state, and load-bearing state is established.
[0013] Further, confirming the bearer status and obtaining the bearer transfer confirmation data packet includes: Based on the current hydraulic system pressure data and the locking mechanism force data, determine the current hydraulic support force and the current mechanical support force respectively, and calculate the mechanical load ratio, hydraulic remaining support ratio, support force balance deviation value and platform sinking trend. Based on the mechanical load ratio, support force balance deviation, platform micro-displacement, and platform subsidence trend within the load transfer evaluation window, update the load status in the mechanical load status triplet and determine the locking anomaly type; when the load status is stable and the locking anomaly type is no anomaly, generate a reliable mechanical locking confirmation result. The current stop cycle identifier, mechanical load status triplet, mechanical locking reliability confirmation result, mechanical load ratio, hydraulic remaining support ratio, platform sinking trend, and locking anomaly type are encapsulated into a load transfer confirmation data packet.
[0014] Furthermore, a restricted verification pulse is applied to the mechanical door lock and door lock verification response data is acquired, including: When the mechanical locking reliability confirmation result is "confirmed as passed", the platform sinking trend is "not present", and the locking anomaly type is "no anomaly", a door lock verification permission command is generated; the verification retraction target depth is determined based on the initial bolt embedding depth, the safety retention embedding threshold, and the mechanical door lock switch action depth, and the bolt retraction and reset are controlled sequentially; door lock verification response data is acquired synchronously, including bolt position data, door lock drive current data, mechanical door lock switch signal, floor security door closing switch signal, and floor security door area image, and a door lock controlled response sequence is formed according to the acquisition time.
[0015] Furthermore, based on the causal response relationship of the door lock, the door lock coupling state, the door lock coupling confirmation result, and the door lock anomaly type are determined, including: Map the controlled response sequence of the door lock to the causal response diagram of the door lock. Based on the completion sequence and response time limit of the lock tongue retraction, drive load response, switch release, lock tongue reset, switch locking and door stability nodes, determine the retraction response state, switch release state, reset response state and door constraint state, and form a door lock coupling state quadruple. The door lock anomaly type is determined based on the incomplete nodes and mismatch relationships. When all states in the door lock coupling state quadruple are passed and the door lock anomaly type is no anomaly, the door lock coupling confirmation result is recorded as confirmed as passed; otherwise, it is recorded as confirmed as failed. The current stop cycle identifier, the door lock coupling state quadruple, the door lock coupling confirmation result, and the door lock anomaly type are encapsulated into a door lock coupling verification data packet.
[0016] Furthermore, a hierarchical security permission instruction tree is constructed and state-bound permission credentials are generated, including: Verify the current stop cycle identifier in the stop evidence data packet, bearer transfer confirmation data packet, and door lock coupling verification data packet, and set the stop cycle root node when the current stop cycle identifier is consistent; Based on the action dependency relationship, the floor stop stability condition node, mechanical load condition node, door lock coupling condition node, and floor safety door unlocking permission node are sequentially connected to form the door opening service branch; the door lock verification condition node, door lock holding condition node, hydraulic reload permission node, hydraulic reload condition node, mechanical lock release permission node, mechanical lock retraction condition node, and platform drive permission node are sequentially connected to form the operation recovery branch, forming a hierarchical safety permission instruction tree in which each node except the floor stop cycle root node has a unique parent node; The licensing conditions are divided into licensing triggering conditions and licensing retention conditions. When both the corresponding licensing triggering conditions and licensing retention conditions are met, a status-bound licensing certificate is generated. The status-bound licensing certificate includes the current stop cycle identifier, licensing type, certificate generation time, certificate expiration time, license triggering condition set, license retention condition set, and licensing certificate status.
[0017] Furthermore, identifying license mismatches during the license enforcement process includes: Before binding the license credential to the call state, re-verify the current pause cycle identifier, license trigger conditions, license retention conditions, credential expiration time, and license credential status; During the floor security door unlocking phase, an unlocking command response chain is established, including an unlocking command node, a door lock release node, and a security door opening node. During the mechanical lock retraction phase, a lock release command response chain is established, including a retraction command node, a lock unloading node, and a lock retraction node. When the permission retention condition changes from passed to failed, or when any of the following occurs in the instruction response chain: node order is reversed, node is missing, or response times out, a permission mismatch is determined, and the corresponding condition node or response node is determined as the mismatch initiation node.
[0018] Furthermore, the safe rollback node is determined and the interlocking control command is executed, including: Starting from the mismatch initiation node, trace back along the path of the unique parent node of the hierarchical security permission instruction tree to the root node of the stop cycle, and read the status of each preceding node in order of distance from the mismatch initiation node. The first preceding node whose status is still "passed" and which meets the conditions for maintaining the current permit stage is identified as the safe rollback node. If the preceding node is not found, the root node of the stop cycle is identified as the safe rollback node. The status binding license credential of the licensed node corresponding to the mismatch initiating node and its subsequent licensed nodes is updated to "revoked". Based on the position of the security rollback node in the hierarchical security license instruction tree, the lockout control instruction pre-associated with the security rollback node is executed.
[0019] The intelligent elevator based on an AI monitoring system proposed in this application has the following technical effects and advantages: By forming a continuous safety control chain through the floor stop evidence construction module, load transfer confirmation module, door lock coupling verification module, and safety permission locking module, the platform floor stop, mechanical lock load, safety door status verification, and platform operation recovery are associated with the same floor stop cycle, reducing the control risks caused by data asynchrony, status mismatch, or incorrect recall of historical permissions when each safety device makes independent judgments.
[0020] The stop-floor evidence construction module performs timeliness, synchronization, and consistency checks on platform height, operating speed, drive mechanism operating status, hydraulic system pressure, mechanical locking mechanism position, safety door locking status, and images of the stop-floor area. It then determines the stop-floor deviation confirmation value using image position evidence and height position evidence. A stop-floor action evidence chain is constructed according to the sequence of actions: approaching the target floor, entering the permitted leveling zone, platform deceleration, and platform stabilization. This ensures that the platform's stationary state simultaneously provides evidence of position, speed, drive status, and action sequence, reducing erroneous stop confirmations caused by false triggering of a single detection signal.
[0021] The load transfer confirmation module combines the actual extension stroke of the mechanical locking mechanism, the force on the locking mechanism, the micro-displacement of the platform, the hydraulic support force, and the mechanical support force to sequentially confirm the extension state, contact state, and load-bearing state. It then generates a reliable mechanical locking confirmation result based on the mechanical load ratio, the support force balance deviation, and the platform's sinking trend. This allows for the differentiation between situations where the mechanical locking mechanism is in position but not in contact, insufficient load-bearing, support mismatch, uneven force distribution, and continuous platform sinking, avoiding the misjudgment that the mechanical locking mechanism has actually taken on load based solely on the position signal.
[0022] After the mechanical locking mechanism is stably loaded, the door lock coupling verification module applies a restricted verification pulse to the mechanical door lock to maintain a safe embedding depth, and acquires the timing response of the bolt position, drive current, door lock switch signal, security door closing signal, and area image. By verifying the causal sequence between bolt retraction, drive load change, switch release, bolt reset, switch locking, and door stability, it can identify door lock switch sticking, bolt jamming, false locking signals, and door constraint instability, thereby improving the reliability of the correspondence between the physical actions and electrical feedback of the door lock.
[0023] The security permission interlocking module constructs a hierarchical security permission instruction tree based on the stop-floor evidence data packet, bearer transfer confirmation data packet, and door lock coupling verification data packet. It sets the security door unlocking, hydraulic reloading, mechanical lock release, and platform drive as permission stages with sequential dependencies. The status binding permission credential is associated with the current stop-floor cycle, permission triggering conditions, permission retention conditions, and validity period, preventing expired states, expired credentials, and data from different stop-floor cycles from triggering control actions.
[0024] When the permission holding conditions are no longer met, or when there is an abnormal order, missing response, or timeout in the instruction response, the safety permission interlocking module can revoke the corresponding permission and subsequent permissions, determine the safety backoff node along the hierarchical safety permission instruction tree, and execute interlocking controls such as prohibiting safety door unlocking, prohibiting platform drive, mechanical locking, or hydraulic support to prevent the safety door from opening prematurely, mechanical locking from retracting under load, and the platform from losing support.
[0025] In summary, this application enables continuous verification and graded interlocking of floor stops, load-bearing capacity, door locks, and operating permits, reducing the risk of malfunctions caused by inconsistencies between detection signals and actual physical conditions. Attached Figure Description
[0026] Figure 1 This is a schematic diagram of the intelligent elevator structure based on the AI monitoring system according to an embodiment of this application; Figure 2 This is a flowchart illustrating the continuous safety verification and permission interlocking process of an intelligent elevator based on an AI monitoring system, as described in this application. Figure 3 This is a schematic diagram of graded security permission and mismatch interlocking in an embodiment of this application. Detailed Implementation
[0027] The technical solutions in the embodiments of this application will be described in detail, clearly and completely below with reference to the accompanying drawings.
[0028] Example 1: like Figure 1As shown, this embodiment discloses an intelligent elevator based on an AI monitoring system, including a floor stop evidence construction module, a load transfer confirmation module, a door lock coupling verification module, and a security permission locking module. Each module realizes data transmission through wired connection, wireless connection, or a combination of wired and wireless connection.
[0029] The platform pausing evidence construction module standardizes and verifies the consistency of multi-source data during the pausing process, encapsulating the verified data into temporal evidence units. Based on the pausing action dependencies, it invokes these temporal evidence units to construct the current pausing action evidence chain, determining the platform's candidate static state and pausing baseline data, thus obtaining the pausing evidence data package. The pausing baseline data includes static baseline height values, static baseline pressure values, and the initial position values of the locking mechanism.
[0030] It should be noted that the artificial intelligence monitoring system referred to in this embodiment includes an image acquisition device, a floor image recognition model, a door lock image recognition model, a platform status detection device, and an elevator controller. It is used to generate floor, load-bearing, and door lock status verification results based on the image recognition results and platform height, speed, hydraulic pressure, mechanical lock position, mechanical lock force, and door lock switch signals.
[0031] In this embodiment, the stopping evidence construction module is used to continuously monitor the process of the platform approaching the target stopping floor, entering the leveling area, decelerating, and reaching a stationary state. The position monitoring results, speed monitoring results, drive mechanism operating status, hydraulic system pressure status, mechanical locking mechanism position status, and floor safety door locking status during the same stopping process are constructed into a stopping action evidence chain according to a preset action sequence, and the platform stationary candidate state and corresponding stopping benchmark data are output to the load transfer confirmation module.
[0032] In this embodiment, the floor safety door refers to the fence door installed at the entrance and exit of each floor to isolate the elevator shaft from the floor work area. When the elevator controller receives the target floor stopping command, it generates a current floor stopping cycle identifier to associate with the data of this floor stopping process. From the time the target floor stopping command is received until the time the platform reaches a static and stable node, the floor stopping evidence construction stage is constituted.
[0033] The input to the stop evidence construction module is multi-source data of the stop process, specifically including the current stop cycle identifier, target stop floor, platform height data, platform running speed data, drive mechanism running status, hydraulic system pressure data, mechanical locking mechanism position data, floor safety door locking status data, and stop area image.
[0034] The target floor is determined by the elevator controller based on floor commands received from the operation panel, and is represented by floor numbers that correspond one-to-one with each floor. The elevator controller pre-stores a floor reference height mapping table, which includes a floor number field and a floor reference height field. The floor reference height is the platform height value when the platform's bearing surface is flush with the corresponding floor's working surface, and is measured and written into the floor reference height mapping table during the equipment installation and commissioning phase.
[0035] Platform height data is collected by a height detection device to indicate the vertical position of the platform's bearing surface within the lifting channel, measured in millimeters. Platform operating speed data is calculated by the lifting controller based on platform height data from adjacent collection times. Specifically, it is calculated by dividing the difference between the platform height value at the later collection time and the platform height value at the previous collection time by the time interval between the two collection times, measured in millimeters per second.
[0036] The elevator controller determines the target movement direction based on the reference height of the target floor and the current platform height, and records the platform's speed along the target movement direction as the target direction speed value. A positive target direction speed value indicates that the platform is moving towards the target floor; a negative target direction speed value indicates that the platform is moving away from the target floor. Considering the measurement fluctuations of the height detection device, when the target direction speed value is less than the negative of the corresponding value of the speed measurement error, it is determined that the platform has moved in the opposite direction.
[0037] The operating status of the drive mechanism is determined by the elevator controller based on the current operating control commands and feedback signals from the drive mechanism. This includes drive operation status, deceleration control status, and stop-and-hold status. Drive operation status indicates that the drive mechanism is driving the platform in the target direction of motion; deceleration control status indicates that the elevator controller has output a deceleration command, and the drive mechanism is reducing the platform's operating speed according to a preset deceleration method; stop-and-hold status indicates that the elevator controller has stopped outputting operating commands, and the drive mechanism is maintaining the platform's current position.
[0038] Hydraulic system pressure data is collected by a pressure detection device installed in the hydraulic circuit of the bearing platform, indicating the oil pressure in the hydraulic circuit at the current acquisition time, measured in megapascals (MPA). Mechanical locking mechanism position data is collected by a position detection device installed at the drive end of the mechanical locking mechanism, indicating the extension distance of the mechanical locking mechanism relative to its fully retracted position, measured in millimeters (mm).
[0039] The retraction judgment range of the mechanical locking mechanism is preset based on the installation position and position detection error of the mechanical locking mechanism. When the position data of the mechanical locking mechanism is within the retraction judgment range, the mechanical locking mechanism is recorded as being in the retracted state; when the position data of the mechanical locking mechanism exceeds the retraction judgment range, the mechanical locking mechanism is recorded as being in the non-retracted state.
[0040] The floor safety door locking status data is provided jointly by the door closing switch and the mechanical door lock switch. When the door closing switch outputs a closed signal and the mechanical door lock switch outputs a locked signal, the floor safety door is recorded as being in the locked state; when neither switch outputs the corresponding signal, the floor safety door is recorded as being in the unlocked state.
[0041] The image of the stopping area is acquired by an image acquisition device installed at the entrance / exit of the target stopping floor. The field of view of the image acquisition device covers the edge of the platform bearing surface near the floor entrance / exit and the reference edge of the floor working surface. After the image acquisition device is installed, its acquisition position and imaging direction remain unchanged.
[0042] During the equipment installation and commissioning phase, a vertical deviation calibration mapping table is established based on the pixel positions of the platform bearing surface edge, the reference edge edge of the floor working surface, and the corresponding platform height data when the platform is at multiple known height positions. The vertical deviation calibration mapping table includes a directed pixel deviation field and an actual height deviation field, used to convert the edge position difference in the image into the actual vertical deviation between the platform bearing surface and the floor working surface.
[0043] The image of the parking area is input into the parking area image recognition model. The parking area image recognition model is a region recognition model trained based on labeled images. Its input is the parking area image, and its output is the platform bearing surface area, the floor working surface area, and the image recognition confidence value.
[0044] The floor image recognition model extracts the continuous boundary near the floor working surface from the platform bearing surface area and determines the median of the vertical pixel coordinates of the continuous boundary as the edge coordinates of the platform bearing surface; it also extracts the continuous boundary near the elevator channel from the floor working surface area and determines the median of the vertical pixel coordinates of the continuous boundary as the reference edge coordinates of the floor working surface.
[0045] The image recognition confidence threshold is used to determine whether the model output can be used for floor location determination. The image recognition confidence threshold is determined based on the edge recognition error of the model verification image, ensuring that the edge recognition error of the verification image reaching this confidence threshold does not exceed the floor location allowable deviation threshold. The floor location allowable deviation threshold is determined based on the allowable vertical deviation between the platform bearing surface and the floor working surface specified in the equipment design documents.
[0046] When the image recognition confidence value is not lower than the image recognition confidence threshold, the difference between the reference edge coordinates of the floor working surface and the edge coordinates of the platform bearing surface is calculated to obtain the directed pixel deviation value. Then, the directed pixel deviation value is matched against a vertical deviation calibration mapping table to obtain the platform image deviation value. A positive platform image deviation value indicates that the platform bearing surface is higher than the floor working surface; a negative platform image deviation value indicates that the platform bearing surface is lower than the floor working surface.
[0047] When the image recognition confidence value is lower than the image recognition confidence threshold, the image of the current stop layer area does not participate in the action node completion judgment, and the action node that is currently performing the completion judgment remains in an incomplete state.
[0048] The landing evidence construction module reads the corresponding landing reference height from the floor reference height mapping table based on the target landing floor, calculates the difference between the current platform height and the landing reference height, and obtains the platform coding deviation value. A positive platform coding deviation value indicates that the platform bearing surface is higher than the reference position of the target landing floor; a negative platform coding deviation value indicates that the platform bearing surface is lower than the reference position of the target landing floor.
[0049] The dual-source deviation threshold is used to limit the allowable measurement difference between the platform image deviation value and the platform coding deviation value. The dual-source deviation threshold is obtained by adding the maximum measurement error of the height detection device, the maximum error of the image position conversion, and the platform displacement within the maximum allowable acquisition time difference.
[0050] The stop-floor evidence construction module calculates the absolute value of the difference between the platform image deviation value and the platform coding deviation value to obtain the dual-source deviation value. When the dual-source deviation value is not greater than the dual-source deviation threshold, and the platform image deviation value and the platform coding deviation value are in the same direction, the two types of location evidence are considered consistent. When either the platform image deviation value or the platform coding deviation value is close to zero, and the absolute value of that deviation value is not greater than the dual-source deviation threshold, the consistency of the location evidence is not negated based on the positive or negative direction of that deviation value. In cases where the two types of location evidence are consistent, the absolute values of the platform image deviation value and the platform coding deviation value are compared. The deviation value with the larger absolute value is determined as the stop-floor deviation confirmation value, and its positive or negative direction is retained. The stop-floor deviation confirmation value is used for subsequent determinations of whether the platform has entered the area approaching the target floor, whether it has entered the leveling area, and whether the stationary position condition is met.
[0051] It should be noted that the zero-point determination threshold is used to limit the range in which the deviation value can be considered zero, and it is determined based on the greater of the maximum measurement error of the height detection device and the image position conversion error. When the absolute value of the deviation value is not greater than the zero-point determination threshold, the deviation value is recorded as zero.
[0052] When the dual-source deviation value is greater than the dual-source deviation threshold, or when the two types of deviation values are opposite in direction and neither is close to zero, the inconsistent position evidence is written into the abnormal node set, and no stop deviation confirmation value is generated in the current control cycle.
[0053] The elevator controller reads various monitoring data according to a preset sampling and update cycle. The sampling and update cycle is the time interval used by the elevator controller to continuously perform one data reading, status calculation, and node status update. The sampling and update cycle is determined based on the rated sampling cycle of each detection device and the single-cycle processing time of the elevator controller. The value is not greater than the minimum value of the rated sampling cycle of each detection device, and is not less than the time required for the elevator controller to complete one data reading, status calculation, and node update.
[0054] When the time difference between the acquisition time of the monitoring data and the current control time does not exceed the evidence validity period, and the monitoring data is within the measurement range of the corresponding detection device, the evidence validity mark of the monitoring data is recorded as valid. The evidence validity period is used to limit the time range within which the monitoring data can participate in the judgment of the current action node, and is determined according to the sampling period, allowable transmission delay, and control period of the corresponding monitoring data.
[0055] For image recognition results, the image recognition confidence value must be no less than the image recognition confidence threshold in order to effectively identify and record the image location evidence as valid.
[0056] The evidence synchronization time difference threshold is used to limit the maximum allowable time difference between different monitoring data participating in the judgment of the same action node. The evidence synchronization time difference threshold is obtained by adding the maximum sampling period, the maximum allowable transmission delay, and a sampling update period among the various types of data participating in the node's judgment.
[0057] The stop-floor evidence construction module encapsulates monitoring data that is valid and meets the evidence synchronization requirements into time-series evidence units. Each time-series evidence unit includes the current stop-floor cycle identifier, evidence type, evidence value, acquisition time, evidence validity identifier, and associated action node.
[0058] Evidence types include platform location evidence, image location evidence, platform speed evidence, drive status evidence, hydraulic pressure evidence, locking mechanism location evidence, and floor safety door locking evidence. Associated action nodes are used to record the action nodes involved in completing the judgment for this time-series evidence unit.
[0059] The stop-floor evidence construction module builds a stop-floor action dependency graph. This graph is a directed graph, consisting of nodes connected in the order of actions: approaching the target floor, entering the permitted leveling zone, platform deceleration, and platform stationary stability. Each action node is predicated on the completion of the previous action node, and the required evidence type and maximum conversion time for completing that node are configured.
[0060] The maximum transition time is used to limit the maximum time allowed for the next action node to complete after the previous action node has finished. It is determined based on the results of the platform's floor-stop debugging under no-load and rated load conditions. If the next action node still fails to meet the completion conditions after the corresponding maximum transition time has elapsed after the previous action node has completed, the action timeout will be written into the abnormal node set.
[0061] The reason for using a stop-and-go action dependency graph is that the platform's approach to the target floor, entry into the leveling area, deceleration, and reaching a stationary state have a definite sequential dependency. By restricting the completion order of action nodes through directed node connections, individual signals generated by subsequent actions cannot be used as a basis for determining whether the platform has entered the subsequent state before the preceding action node has been completed.
[0062] The approach zone distance threshold is used to determine whether the platform has entered the stop control area of the target floor. It is determined based on the maximum braking distance of the platform when it is running at rated speed under no-load and rated load conditions, the position measurement error, and the platform movement distance within the control cycle.
[0063] The conditions for reaching the target floor node are as follows: the floor safety door is locked; the mechanical locking mechanism is retracted; the platform moves toward the target floor; the absolute value of the floor deviation confirmation value is not greater than the proximity zone distance threshold; and the temporal evidence units involved in the judgment meet the evidence synchronization requirements.
[0064] When the above conditions are met simultaneously, the evidence of the floor safety door being locked, the location of the locking mechanism, the platform location, the image location, and the platform speed are written into the node approaching the target floor, and the completion time of the node approaching the target floor is recorded.
[0065] The leveling area distance threshold is used to determine whether the platform has entered the low-speed positioning area. Specifically: during the equipment commissioning phase, the platform is made to run at low speed and perform emergency braking under no-load and rated load conditions, respectively. The maximum displacement from the issuance of the braking command to the complete stop of the platform is recorded, and the larger displacement value between the two conditions is taken as the maximum braking distance. The floor stop allowable deviation threshold is read from the equipment design documents. The maximum measurement error is read according to the calibration results of the height detection device. The maximum braking distance, floor stop allowable deviation threshold, and position measurement error are added together to obtain the leveling area distance threshold.
[0066] The conditions for entering the leveling zone node are as follows: the target floor node has been completed; the absolute value of the floor deviation confirmation value is not greater than the leveling zone distance threshold; the platform has not moved in the opposite direction; the mechanical locking mechanism remains in the retracted state; and the time-series evidence units involved in the judgment meet the evidence synchronization requirements.
[0067] When the above conditions are met simultaneously, the platform location evidence, image location evidence, platform speed evidence, and locking mechanism location evidence are written into the entry into the leveling permission zone node, and the completion time of the entry into the leveling permission zone node is recorded.
[0068] The stop-level evidence construction module divides the deceleration evaluation window into a front window and a back window in chronological order, and calculates the arithmetic mean of the absolute values of the target direction velocity within each window. The deceleration evaluation window is used to determine whether the platform forms a continuous deceleration trend after the drive mechanism enters the deceleration control state. Its duration is determined based on the response time and control cycle of the drive mechanism from receiving the deceleration command to the platform's running speed starting to decrease.
[0069] The conditions for the platform deceleration node to be completed are as follows: the entry into the leveling allowable zone node has been completed; the drive mechanism is in deceleration control mode; the arithmetic mean of the absolute values of the target direction velocity values in the later window is less than the corresponding arithmetic mean in the earlier window; no reverse movement of the platform is detected in the deceleration evaluation window; the absolute value of the stop deviation confirmation value decreases over time; and the timing evidence units involved in the judgment meet the evidence synchronization requirements.
[0070] When the above conditions are met simultaneously, the driving state evidence, platform speed evidence, platform position evidence, and image position evidence are written into the platform deceleration node, and the completion time of the platform deceleration node is recorded.
[0071] The static state threshold set includes static speed threshold, position fluctuation threshold, and pressure fluctuation threshold. The static speed threshold limits the permissible residual velocity after the platform stops; the position fluctuation threshold limits the range of height variation after the platform stops; and the pressure fluctuation threshold limits the range of hydraulic system pressure variation after the platform stops. The static state threshold set is determined based on equipment design parameters and the results of platform stop tests under no-load and rated load conditions. The static speed threshold is no greater than the maximum residual velocity of the platform in the stopped state specified in the equipment design documents; the position fluctuation threshold is no greater than the permissible change in engagement position of the mechanical locking mechanism; and the pressure fluctuation threshold is determined based on the range of hydraulic pressure variation when the platform stops and the mechanical locking mechanism has not yet extended.
[0072] The stability evaluation window is used to limit the time during which the static state conditions need to be met continuously. Its duration is determined based on the duration of inertial movement after the platform stops, the hydraulic pressure stabilization time, and the control cycle.
[0073] The conditions for completing the platform's static stabilization node are as follows: the platform deceleration node has been completed; the drive mechanism is in a stopped and held state; the absolute value of the platform's running speed within the stability evaluation window is not greater than the static speed threshold; the difference between the maximum and minimum values of the platform height data within the stability evaluation window is not greater than the position fluctuation threshold; the difference between the maximum and minimum values of the platform image deviation values within the stability evaluation window is not greater than the position fluctuation threshold; the difference between the maximum and minimum values of the hydraulic system pressure data within the stability evaluation window is not greater than the pressure fluctuation threshold; the absolute value of the floor stop deviation confirmation value within the stability evaluation window is not greater than the floor stop allowable deviation threshold; the mechanical locking mechanism remains in the retracted state; and the temporal evidence units participating in the judgment meet the evidence synchronization requirements.
[0074] When the above conditions are met continuously throughout the stability evaluation window, the platform position evidence, image position evidence, platform speed evidence, drive state evidence, hydraulic pressure evidence, and locking mechanism position evidence are written into the platform static stability node, and the completion time of the platform static stability node is recorded.
[0075] The pause layer evidence construction module arranges completed action nodes and their corresponding temporal evidence units sequentially according to the completion time of each action node, forming the current pause layer action evidence chain. Each action node in the current pause layer action evidence chain records the node name, node completion time, preceding node, temporal evidence units involved in the judgment, and node judgment result.
[0076] The abnormal node set is used to record inconsistencies in location evidence and action timeouts. When the abnormal node set is empty, and the current stopping action evidence chain sequentially records the approaching target floor node, the entry into the leveling permitted zone node, the platform deceleration node, and the platform stationary and stable node, and the node judgment result of the platform stationary and stable node is completed, the platform stationary candidate state is recorded as valid; when there are inconsistencies in location evidence or action timeouts in the abnormal node set, or when the above action nodes are not sequentially completed in the current stopping action evidence chain, the platform stationary candidate state is recorded as invalid.
[0077] After the platform reaches a static candidate state, the arithmetic mean of all platform height data within the stability evaluation window is calculated to obtain the static reference height value; the arithmetic mean of all hydraulic system pressure data within the stability evaluation window is calculated to obtain the static reference pressure value; and the position data of the mechanical locking mechanism at the completion of the platform's static stability node is read to obtain the initial position value of the locking mechanism. The static reference height value is used by the subsequent load transfer confirmation module to calculate the platform's micro-displacement during the mechanical locking process; the static reference pressure value is used to calculate the hydraulic pressure change during the mechanical locking process; and the initial position value of the locking mechanism is used to calculate the actual extension stroke of the mechanical locking mechanism.
[0078] The stop evidence construction module encapsulates the current stop cycle identifier, target stop floor, current stop action evidence chain, abnormal node set, platform static candidate state, static reference height value, static reference pressure value, and initial position value of locking mechanism into a stop evidence data packet, and sends the stop evidence data packet to the bearer transfer confirmation module.
[0079] Through the above processing, the stopping evidence construction module does not directly confirm that the platform has stopped based on a single leveling switch, a single height detection result, or a single frame image recognition result. Instead, it verifies the consistency of numerical values and directions of coded position evidence and image position evidence, and constructs a stopping action evidence chain according to the action sequence of approaching the target floor, entering the leveling area, performing deceleration, and reaching a stationary state. This provides input data with a unified time reference and clear physical meaning for subsequent mechanical locking load confirmation.
[0080] The load transfer confirmation module generates a mechanical locking permission command based on the stop evidence data packet, and controls the mechanical locking mechanism to extend. Based on the actual extension stroke, platform micro-displacement, hydraulic support force and mechanical support force, it sequentially confirms the extension, contact and load-bearing states, determines the reliable confirmation result of mechanical locking, and obtains the load transfer confirmation data packet.
[0081] In this embodiment, the load transfer confirmation module is used to control the mechanical locking mechanism to sequentially enter the extended state, contact state, and load-bearing state from the retracted state after the platform is in a static candidate state. By observing the corresponding changes between the platform displacement, hydraulic support force, and the force on the mechanical locking mechanism, the module confirms whether the platform load has been transferred from the hydraulic system to the mechanical locking mechanism, thus avoiding the conclusion that the mechanical locking mechanism has taken on load based solely on the position signal of the mechanical locking mechanism.
[0082] The bearer transfer confirmation module receives the stoppage evidence data packet output by the stoppage evidence construction module. The current stoppage cycle identifier is used to associate the data collected by this module with the data in the stoppage evidence construction phase to the same stoppage process.
[0083] The load transfer confirmation module reads the platform stationary candidate state and the abnormal node set from the stop floor evidence data packet. When the platform stationary candidate state is valid and the abnormal node set is empty, a mechanical locking permission command is generated; when the platform stationary candidate state is invalid or the abnormal node set is not empty, no mechanical locking permission command is generated, and the floor safety door remains locked.
[0084] After generating the mechanical locking permission command, the elevator controller sends an extension control command to the drive device of the mechanical locking mechanism, and obtains the current platform height data, current hydraulic system pressure data, current mechanical locking mechanism position data, and locking mechanism force data according to the aforementioned sampling update cycle.
[0085] The current platform height data is collected by the aforementioned height detection device, and the measurement caliber is the same as the platform height data in the stop evidence construction module. The current hydraulic system pressure data is collected by the aforementioned pressure detection device, and the measurement caliber is the same as the hydraulic system pressure data in the stop evidence construction module. The current mechanical locking mechanism position data is collected by the aforementioned position detection device, indicating the current extension distance of the mechanical locking mechanism relative to the fully retracted position.
[0086] The force data of the locking mechanism is collected by a force detection device installed between the load-bearing part of the mechanical locking mechanism and the fixed support. This data represents the platform load currently borne by the mechanical locking mechanism, and the unit of measurement is Newtons. When the mechanical locking mechanism has multiple load-bearing points, a force detection device is installed at each load-bearing point, and the force data of the locking mechanism corresponding to each load-bearing point is acquired separately.
[0087] The load transfer confirmation module calculates the actual extension stroke of the mechanical locking mechanism. Specifically, it calculates the difference between the current position data of the mechanical locking mechanism and its initial position value, and uses this difference as the actual extension stroke. The actual extension stroke is used to determine whether the mechanical locking mechanism has completed its extension and whether the locking component has entered the engagement area corresponding to the fixed support.
[0088] The locking extension target range is used to define the travel range of the mechanical locking mechanism when it completes its extension. It is set based on the structural travel required for the mechanical locking component to move from the fully retracted position to the engagement area of the fixed support, the installation position error, and the measurement error of the position detection device. When the actual extension travel is within the locking extension target range, the extension state of the mechanical locking mechanism is recorded as complete; when the actual extension travel has not yet entered the locking extension target range, the extension state of the mechanical locking mechanism is recorded as in progress.
[0089] The load transfer confirmation module calculates the platform's micro-displacement. Specifically, it calculates the difference between the current platform height data and the static reference height value, and uses this difference as the platform's micro-displacement. A positive micro-displacement indicates that the platform has moved upwards relative to its position when the platform's static stability node was completed; a negative micro-displacement indicates that the platform has moved downwards relative to its position when the platform's static stability node was completed.
[0090] The contact displacement threshold is used to limit the permissible platform position change during the contact between the mechanical locking mechanism and the fixed support. It is determined based on the engagement gap of the mechanical locking mechanism, the permissible static displacement of the platform structure, and the measurement error of the height detection device. When the absolute value of the platform's micro-displacement is not greater than the contact displacement threshold, the mechanical locking contact state judgment is allowed to continue; when the absolute value of the platform's micro-displacement is greater than the contact displacement threshold, the mechanical locking mechanism is stopped from extending further, and the locking contact offset is recorded as a locking anomaly type.
[0091] The contact force threshold is used to distinguish between the free-travel resistance of the mechanical locking mechanism and the force generated after the locking component contacts the fixed support. The contact force threshold is determined based on the maximum driving resistance of the mechanical locking mechanism before contacting the fixed support, the measurement error of the force detection device, and the force test results when the mechanical locking component begins to contact the fixed support.
[0092] When the extension state of the mechanical locking mechanism is complete, the force data of the locking mechanism is not less than the contact force threshold, and the absolute value of the platform's micro-displacement is not greater than the contact displacement threshold, the contact state of the mechanical locking mechanism is recorded as complete. When the actual extension stroke has entered the locking extension target range, but the force data of the locking mechanism is less than the contact force threshold, the contact state of the mechanical locking mechanism is recorded as incomplete, and the "not in contact when in position" is written into the locking anomaly type.
[0093] When the mechanical locking mechanism has multiple load-bearing points, it is determined whether the force data of the locking mechanism at each load-bearing point has reached the contact force threshold. When all load-bearing points have reached the contact force threshold, the contact state of the mechanical locking mechanism is recorded as complete; if any load-bearing point has not reached the contact force threshold, the contact state of the mechanical locking mechanism is recorded as incomplete.
[0094] Once the mechanical locking mechanism has completed its contact state, the load transfer confirmation module enters the load transfer evaluation phase. During the load transfer evaluation phase, the mechanical locking mechanism is kept within the target locking extension range, and current hydraulic system pressure data, current platform height data, and locking mechanism force data are continuously acquired.
[0095] The effective working area of a hydraulic cylinder is determined by its structural parameters and pre-stored in the lift controller. When the hydraulic system has multiple hydraulic cylinders sharing a common platform, the sum of the effective working areas of each cylinder is calculated to obtain the total effective working area of the hydraulic system.
[0096] The load transfer confirmation module calculates the static reference hydraulic support force. Specifically, it multiplies the static reference pressure value by the total effective hydraulic working area and converts it into a force value according to the conversion relationship between pressure units and area units, thus obtaining the support force provided by the hydraulic system when the platform's static stability node is completed.
[0097] The load transfer confirmation module uses the same method to multiply the current hydraulic system pressure data by the total effective working area of the hydraulic system to obtain the current hydraulic support force. The current hydraulic support force represents the platform load currently borne by the hydraulic system during the load transfer evaluation phase. When multiple hydraulic cylinders share the same hydraulic circuit, the sum of the effective working areas of each hydraulic cylinder is multiplied by the current hydraulic system pressure data; when each hydraulic cylinder has an independent pressure circuit, the product of the pressure of each hydraulic cylinder and its effective working area is calculated separately, and the products are added together to obtain the current hydraulic support force.
[0098] When the mechanical locking mechanism has one load point, the force data of the locking mechanism corresponding to that load point is determined as the current mechanical support force. When the mechanical locking mechanism has multiple load points, the force data of the locking mechanism corresponding to each load point are added together to obtain the current mechanical support force.
[0099] The load transfer confirmation module adds the current hydraulic support force to the current mechanical support force to obtain the current combined support force, and calculates the absolute difference between the current combined support force and the static reference hydraulic support force to obtain the support force balance deviation value.
[0100] The support force balance deviation threshold is used to limit the allowable deviation of the current synthetic support force relative to the static reference hydraulic support force during the load transfer process. It is determined based on the measurement error of the pressure detection device, the measurement error of the force detection device, and the load fluctuation range of the platform in a static state.
[0101] When the support force balance deviation value is not greater than the support force balance deviation threshold, it is determined that the change between the hydraulic support force and the mechanical support force can correspond to the original load of the platform; when the support force balance deviation value is greater than the support force balance deviation threshold, it is determined that there is a lack of support force during the load transfer process, and the load support mismatch is written into the locking anomaly type.
[0102] The load transfer confirmation module calculates the mechanical load ratio. Specifically, it divides the current mechanical support force by the current combined support force to obtain the mechanical load ratio. The mechanical load ratio represents the proportion of the current platform load borne by the mechanical locking mechanism.
[0103] The mechanical load-bearing ratio threshold is used to limit the proportion of platform load that the mechanical locking mechanism must bear before the floor security door enters the subsequent verification stage. The mechanical load-bearing ratio threshold is set based on the rated load-bearing capacity of the mechanical locking mechanism, the allowable support ratio of the hydraulic system, and the load-bearing safety requirements when the equipment is stopped at the floor.
[0104] The load transfer evaluation window is used to define the time required for the mechanical load ratio, support force balance deviation, and platform micro-displacement to continuously meet the load confirmation conditions. The duration of the load transfer evaluation window is determined based on the maximum response time required for the mechanical locking mechanism to stabilize under force from contact with the fixed bearing seat, the stabilization time of hydraulic system pressure changes, and the sampling update cycle.
[0105] Within the load transfer evaluation window, the load transfer confirmation module continuously calculates the mechanical load ratio, the support force balance deviation value, and the platform micro-displacement. When the mechanical load ratio is not less than the mechanical load ratio threshold, the support force balance deviation value is not greater than the support force balance deviation threshold, and the absolute value of the platform micro-displacement is not greater than the contact displacement threshold, the load state of the mechanical locking mechanism is recorded as stable load.
[0106] When the mechanical load ratio does not reach the mechanical load ratio threshold, the load state of the mechanical locking mechanism is recorded as insufficient load. When the support force balance deviation exceeds the support force balance deviation threshold, the load state of the mechanical locking mechanism is recorded as support mismatch. When the absolute value of the platform's micro-displacement exceeds the contact displacement threshold, the load state of the mechanical locking mechanism is recorded as load instability.
[0107] When the mechanical locking mechanism has multiple load-bearing points, the load transfer confirmation module calculates the locking force difference. Specifically, it reads the force data of the locking mechanism corresponding to all load-bearing points and calculates the difference between the maximum and minimum force values to obtain the locking force difference.
[0108] The locking force difference threshold is used to limit the allowable force differences between multiple load-bearing points. It is determined based on the structural load-bearing capacity of each load-bearing point, installation height error, and measurement error of the force detection device. When the locking force difference is not greater than the locking force difference threshold, the force at each load-bearing point is deemed to meet the consistency requirement. When the locking force difference is greater than the locking force difference threshold, the uneven locking force is recorded as a locking anomaly, and the load state of the mechanical locking mechanism is not recorded as a stable load.
[0109] The load transfer confirmation module calculates the platform subsidence based on the platform height data. Specifically, it calculates the difference between the static reference height value and the current platform height data. When the difference is greater than zero, the difference is recorded as the platform subsidence; when the difference is not greater than zero, the platform subsidence is recorded as zero.
[0110] Within the load transfer evaluation window, the platform subsidence is arranged according to the acquisition time. When the platform subsidence at any subsequent acquisition time is greater than the platform subsidence at its immediately preceding acquisition time, and the platform subsidence at the end of the evaluation window is greater than the subsidence trend threshold, the platform subsidence trend is recorded as existing; otherwise, the platform subsidence trend is recorded as not existing.
[0111] The sinking trend threshold is determined based on the platform structure's allowable static displacement, the measurement error of the height detection device, and the allowable change in the engagement position of the mechanical locking mechanism, and shall not exceed the aforementioned contact displacement threshold. When a platform sinking trend exists, the load state of the mechanical locking mechanism is not recorded as stable load, and the continuous sinking of the platform is written into the locking anomaly type.
[0112] The load transfer confirmation module constructs a mechanical load state ternary set. The mechanical load state ternary set includes the extended state, the contact state, and the load-bearing state, which is used to record the continuous state of the mechanical locking mechanism from the time it is in position to the time it actually bears the platform load.
[0113] When the extension state is complete, the contact state is complete, the load-bearing state is stable, and the platform sinking trend is non-existent, a mechanical locking reliability confirmation result is generated. This mechanical locking reliability confirmation result indicates that the mechanical locking mechanism has entered the preset engagement position, formed contact with the fixed support, and continuously bears a specified proportion of the platform load.
[0114] The load transfer confirmation module calculates the remaining hydraulic support ratio. Specifically, it divides the current hydraulic support force by the current combined support force to obtain the remaining hydraulic support ratio. This ratio is used to subsequently determine whether the hydraulic system still retains a preset support force during the load-bearing period of the mechanical locking mechanism.
[0115] The load transfer confirmation module encapsulates the current stop cycle identifier, mechanical load status triplet, mechanical lock reliability confirmation result, mechanical load ratio, hydraulic remaining support ratio, platform sinking trend and lock anomaly type into a load transfer confirmation data packet, and sends the load transfer confirmation data packet to the door lock coupling verification module.
[0116] Through the above processing, this module does not directly assume that the mechanical locking mechanism has been loaded when it enters the target range of the locking extension. Instead, it combines the force on the mechanical locking mechanism, the hydraulic support force, the support force balance deviation, and the micro-displacement of the platform to confirm the extension state, contact state, and load-bearing state of the mechanical locking mechanism step by step. This distinguishes between incomplete contact, insufficient load-bearing, support mismatch, uneven force, and continuous platform sinking, and provides a basis for the load-bearing state for subsequent verification of the status of the floor safety doors.
[0117] The door lock coupling verification module generates a door lock verification permission command based on the bearer transfer confirmation data packet, applies a restricted verification pulse to the mechanical door lock and obtains the door lock verification response data; it determines the door lock coupling state, door lock coupling confirmation result and door lock anomaly type according to the door lock causal response relationship, and obtains the door lock coupling verification data packet.
[0118] In this embodiment, the door lock coupling verification module applies a restricted verification pulse to the mechanical door lock drive device of the floor security door after the mechanical locking mechanism completes the platform load confirmation. It acquires the timing response of the bolt position, drive load, door lock electrical signals, and door position as a result of the verification pulse, and confirms whether the physical actions and electrical feedback of the mechanical door lock correspond to each other based on the causal sequence of the responses. This module actively triggers changes in the door lock state and verifies the response process to identify mechanical door lock switch sticking, bolt jamming, false locking signals, and door position offset.
[0119] The door lock coupling verification module receives the load transfer confirmation data packet output by the load transfer confirmation module. The load transfer confirmation data packet includes the current stop cycle identifier, mechanical load status triplet, mechanical locking reliability confirmation result, mechanical load ratio, hydraulic remaining support ratio, platform sinking trend, and locking anomaly type.
[0120] The current stop cycle identifier is used to associate the door lock coupling verification process with the stop evidence data and load transfer confirmation data during the same stop process. The mechanical load status triplet includes the extended state, contact state, and load-bearing state. The mechanical locking reliability confirmation result is used to indicate whether the mechanical locking mechanism has borne the platform load. The platform sinking trend is used to indicate whether the platform continues to descend after the mechanical locking mechanism bears the load. The locking anomaly type is used to indicate the anomaly category identified during the load transfer confirmation phase; if no anomaly is identified, it is recorded as no anomaly.
[0121] When the extension state, contact state, and load-bearing state in the mechanical load-bearing state triplet are all complete, the mechanical locking reliability confirmation result is "confirmed and passed," the platform sinking trend is "not present," and the locking anomaly type is "no anomaly," the door lock coupling verification module generates a door lock verification permission command. If any condition is not met, no door lock verification permission command is generated, the floor safety door remains locked, and all states in the door lock coupling state quadruplet are recorded as "unverified," the door lock coupling confirmation result is recorded as "confirmed and passed," and the failure to meet the precondition is written into the door lock anomaly type.
[0122] After generating the door lock verification permission command, the door lock coupling verification module applies a restricted verification pulse to the mechanical door lock and synchronously acquires the door lock verification response data according to the aforementioned sampling update cycle. The door lock verification response data refers to the set of mechanical action response, drive load response, electrical signal response, and floor security door constraint response generated by the mechanical door lock under the action of the restricted verification pulse, including latch position data, door lock drive current data, mechanical door lock switch signal, floor security door closing switch signal, and floor security door area image.
[0123] The data includes: latch position data (indicating the distance the latch extends relative to its fully retracted position); door lock drive current data (indicating the workload of the mechanical door lock drive device during latch retraction and reset); mechanical door lock switch signal (indicating the change in locking state when the latch passes the mechanical door lock switch position); floor security door closing switch signal (indicating whether the floor security door remains in the closed detection position during the execution of the restricted verification pulse); and floor security door area image (indicating the latch embedment depth and the actual width of the door gap). The door lock coupling verification module correlates the above data according to the acquisition time to form door lock verification response data during the execution of the restricted verification pulse.
[0124] The floor safety door closing switch signal is output by the door closing switch located at the door's closed position, indicating whether the door has reached the preset closed position. The mechanical door lock switch signal is output by the mechanical door lock switch located inside the mechanical door lock, indicating whether the bolt has passed the locking action position of the mechanical door lock switch. Bolt position data is collected by a position detection device located at the bolt drive end, measured as the distance the bolt extends relative to the fully retracted position, in millimeters. Door lock drive current data is collected by a current detection device located in the power supply circuit of the mechanical door lock drive device, measured as the operating current of the mechanical door lock drive device at the current collection moment, in amperes. Door lock drive current data is used to distinguish between normal bolt movement and bolt obstruction.
[0125] The floor security door area image is acquired by an image acquisition device installed at the entrance / exit of the target floor. The field of view of the image acquisition device covers the door edge, door frame edge, bolt tip, and keyhole entrance. The floor security door area image is input into a door lock image recognition model. The door lock image recognition model is a region recognition model trained based on labeled images. Its input is the floor security door area image, and its output includes the coordinates of the door edge, door frame edge, bolt tip, keyhole entrance, and door lock image recognition confidence value. The door edge and door frame edge coordinates are used to calculate the actual width of the door gap, and the bolt tip and keyhole entrance coordinates are used to calculate the bolt embedding depth in the image.
[0126] The door lock image recognition confidence threshold is determined based on the recognition error of the door gap width and the recognition error of the latch position corresponding to the model verification image. When the door lock image recognition confidence value is not lower than the door lock image recognition confidence threshold, the door lock image recognition result participates in the door lock coupling verification; when the door lock image recognition confidence value is lower than the door lock image recognition confidence threshold, insufficient image evidence is written into the door lock anomaly type, and the door lock coupling confirmation result is recorded as confirmation failed.
[0127] During the equipment installation and commissioning phase, a door lock size calibration mapping table is established based on the image coordinates and actual dimensions of the door in different known closed positions and the latch in different known embedded positions. This table is used to convert the pixel distance between the door edge and the door frame edge into the actual width of the door gap, and the pixel distance between the front end of the latch and the keyhole entrance into the image latch embedding depth.
[0128] The door lock coupling verification module calculates the initial bolt embedding depth. Specifically, it subtracts the empty travel required for the bolt to move from the fully retracted position to the keyhole entrance position from the bolt position data to obtain the position bolt embedding depth; it obtains the image bolt embedding depth based on the door lock image recognition results and the door lock size calibration mapping table; and it compares the absolute values of the two, determining the smaller value as the initial bolt embedding depth.
[0129] The safety retention embedding threshold is used to limit the minimum embedding depth that the bolt must remain in the keyhole during the door lock verification process. It is determined based on the minimum load-bearing embedding depth specified in the mechanical door lock structural design, the bolt position detection error, and the image position conversion error.
[0130] The mechanical door lock switch action depth is used to indicate the bolt insertion depth when the mechanical door lock switch changes from a locking signal to an unlocking signal. It is determined during the equipment installation and commissioning phase by controlling the bolt to continuously retract and recording the bolt position when the mechanical door lock switch signal changes.
[0131] The arithmetic mean of the safety retention embedding threshold and the mechanical door lock switch action depth is determined as the verification retraction target depth. When the difference between the mechanical door lock switch action depth and the safety retention embedding threshold is not greater than the sum of the lock tongue position detection error and the image position conversion error, the restricted verification pulse is not executed, and the insufficient safety embedding margin is written into the door lock anomaly type.
[0132] The door lock coupling verification module generates a restricted verification pulse. The restricted verification pulse includes a retraction control phase and a reset control phase. The retraction control phase is used to control the bolt to move from the initial locking position to the verification retraction target depth; the reset control phase is used to control the bolt to return from the verification retraction target depth to the initial locking position.
[0133] The retraction control amount of the restricted verification pulse is determined based on the difference between the initial bolt embedding depth and the verification retraction target depth. The door lock coupling verification module continuously reads the bolt position data during the retraction process. When the bolt embedding depth reaches the verification retraction target depth, the retraction control is terminated, thus ensuring that the bolt always maintains an embedding depth greater than the safety retention embedding threshold during the verification process.
[0134] The door lock coupling verification module encapsulates the verification stage, control command and door lock verification response data corresponding to each acquisition moment into a door lock response unit, and arranges each door lock response unit according to the acquisition moment to form a door lock controlled response sequence.
[0135] The door lock coupling verification module constructs a door lock causal response graph. The door lock causal response graph is a directed graph, including retraction pulse nodes, bolt retraction nodes, drive load response nodes, door lock switch release nodes, reset pulse nodes, bolt reset nodes, door lock switch locking nodes, and door stability nodes.
[0136] The retraction pulse node points to the latch retraction node, indicating that the retraction control command should decrease the latch position before the latch position decreases; the latch retraction node points to the drive load response node and the door lock switch release node, indicating that a change in drive current should occur after the latch actually moves, and an unlocked signal should be generated when the latch passes the mechanical door lock switch action depth; the reset pulse node points to the latch reset node, and the latch reset node points to the door lock switch locking node, indicating that the mechanical door lock switch can only restore the locking signal after the latch reaches the locking position again; the door stability node is used to limit the difference between the maximum and minimum values of the actual door gap width during the execution of the restricted verification pulse to not be greater than the door gap fluctuation threshold, and the floor safety door closing switch signal remains closed.
[0137] The reason for using a cause-effect diagram for door locks is that the actual operation of a mechanical door lock forms a physical chain in which control commands, bolt displacement, drive load, and electrical switch signals respond sequentially. Simply comparing the state at the end of the verification cannot distinguish between switch signal sticking and bolt mechanical jamming. The cause-effect diagram for door locks restricts the order and timing of each response, so that different faults correspond to different missing nodes and mismatched edges.
[0138] The door lock response time difference threshold is used to limit the maximum time allowed for each response node to complete after the restricted verification pulse is output. It is determined based on the response time of the mechanical door lock drive device, the bolt movement time, the mechanical door lock opening and closing action delay, and the sampling update cycle. The door gap fluctuation threshold is used to limit the allowable displacement change of the door body relative to the door frame during the execution of the restricted verification pulse. It is determined based on the structural gap of the floor security door, image measurement error, and the allowable displacement of the door body in the closed state.
[0139] The drive current response range is used to define the range of changes in the lock drive current during normal bolt retraction and reset. It is determined based on the drive current data of the mechanical lock during the installation and commissioning phase when it is running smoothly without jamming. The current change ranges during the bolt retraction and reset processes are recorded separately to form the retraction current response range and the reset current response range.
[0140] The door lock coupling verification module maps the door lock response units in the controlled response sequence to the door lock causal response graph. After the constrained verification pulse is output, when the latch position data changes along the retraction direction within the door lock response time difference threshold, and the door lock drive current data is within the retraction current response range, the latch retraction node and drive load response node are completed.
[0141] When the bolt insertion depth drops below the mechanical lock switch action depth, and the mechanical lock switch signal is converted into an unlocked signal within the lock response time difference threshold, the lock switch release node is completed.
[0142] After the reset control phase begins, the bolt position data changes along the extension direction within the door lock response time difference threshold, and the door lock drive current data is within the reset current response range, thus completing the bolt reset node. Once the bolt embedding depth returns to the range corresponding to the initial bolt embedding depth, the door lock switch signal is converted to a locking signal within the door lock response time difference threshold, thus completing the door lock switch locking node.
[0143] During the execution of the restricted verification pulse, the door stability node is completed when the difference between the maximum and minimum values of the actual width of the door gap is not greater than the door gap fluctuation threshold, and the floor safety door closing switch signal remains closed.
[0144] When the bolt position retracts, but the mechanical door lock switch signal remains locked after the bolt has passed the depth of the mechanical door lock switch action, the door lock switch sticking is written into the door lock abnormality type.
[0145] When the mechanical door lock switch signal changes to the unlocked state, but the bolt position data and the bolt embedment depth in the image do not change accordingly, a false door lock signal is written into the door lock anomaly type.
[0146] When the retraction control command is output, if the door lock drive current exceeds the upper limit of the retraction current response range, and the change in the bolt position is less than the retraction position response threshold, the bolt retraction jamming will be written as a door lock abnormality type. The retraction position response threshold is determined based on the measurement error of the position detection device.
[0147] When the reset control command is output, if the door lock drive current exceeds the upper limit of the reset current response range and the bolt fails to return to the initial locking position within the door lock response time difference threshold, the bolt reset jamming will be written into the door lock abnormality type.
[0148] When the actual width change of the door gap exceeds the door gap fluctuation threshold during the execution of the restricted verification pulse, or when the floor safety door closing switch signal changes from closed to open, the door constraint instability is written into the door lock abnormality type.
[0149] The door lock coupling verification module constructs a door lock coupling state quadruple. The door lock coupling state quadruple includes a retraction response state, a switch release state, a reset response state, and a door constraint state, which are used to represent the complete response process of the mechanical door lock under the action of a constrained verification pulse.
[0150] When both the latch retraction node and the drive load response node are completed, the retraction response status is recorded as passed; otherwise, it is recorded as failed. When the door lock switch release node is completed, the switch release status is recorded as passed; otherwise, it is recorded as failed. When both the latch reset node and the door lock switch locking node are completed, the reset response status is recorded as passed; otherwise, it is recorded as failed. When the door body stabilization node is completed, the door body constraint status is recorded as passed; otherwise, it is recorded as failed.
[0151] When all four states in the door lock coupling state quadruple are passed, the door lock anomaly type is no anomaly, the embedding depth after the lock tongue is reset is not less than the lower limit of the initial lock tongue embedding depth, and the mechanical locking reliability confirmation result is still passed, the door lock coupling confirmation result is recorded as passed; if any condition is not met, the door lock coupling confirmation result is recorded as failed.
[0152] The lower limit of the initial latch embedment depth is determined based on the initial latch embedment depth, latch position detection error, and door lock image measurement error. It is used to limit the range of the latch position that must be restored to before verification after the latch has completed reset.
[0153] When the door lock coupling confirmation result is "confirmed and the door lock anomaly type is 'no anomaly'", the door lock coupling verification data packet is sent to the security permission interlocking module. The security permission interlocking module then generates a floor security door unlocking permission based on the door lock coupling confirmation result and the current security control conditions.
[0154] The door lock coupling verification module encapsulates the current stop cycle identifier, the door lock coupling state quadruple, the door lock coupling confirmation result, and the door lock anomaly type into a door lock coupling verification data packet, and sends the door lock coupling verification data packet to the security permission interlocking module. The node completion results of the door lock controlled response sequence and the door lock causal response graph are used as process data for generating the door lock coupling state quadruple, the door lock coupling confirmation result, and the door lock anomaly type, and are stored in the verification record corresponding to the current stop cycle.
[0155] Through the above processing, this module does not statically compare the bolt position and the mechanical door lock switch signal at a certain moment. Instead, under the condition that the platform is stably supported by the mechanical locking mechanism, it actively applies a restricted verification pulse without removing the mechanical obstruction, and verifies the causal response relationship between the control command, bolt displacement, drive load, door lock switch signal and door position, thereby distinguishing door lock switch adhesion, bolt jamming, false door lock signal and door constraint instability.
[0156] The security permission interlocking module constructs a hierarchical security permission instruction tree based on the stop-floor evidence data packet, the bearer transfer confirmation data packet, and the door lock coupling verification data packet, and generates a state-bound permission credential; it identifies permission mismatches during the permission execution process, revokes the corresponding state-bound permission credential and its subsequent permission credentials, determines the security rollback node, and executes the interlocking control instruction.
[0157] In this embodiment, the security permission interlocking module is used to read the floor stop evidence data packet, the bearer transfer confirmation data packet, and the door lock coupling verification data packet. Based on the action dependencies between platform floor stop stability, mechanical lock bearing, mechanical door lock coupling verification, security door relocking, hydraulic reload, and mechanical lock retraction, a hierarchical security permission instruction tree is constructed, and floor security door unlocking permission, hydraulic reload permission, mechanical lock release permission, and platform drive permission are generated sequentially.
[0158] It should be noted that, Figure 2 This is a flowchart illustrating the continuous safety verification and permission interlocking process of an intelligent elevator based on an AI monitoring system, as described in this application embodiment.
[0159] The licenses generated by this module are represented by state-bound license credentials. These credentials are bound to the current stop cycle, the corresponding license conditions, and the license's validity period. If the data upon which the license was generated does not belong to the same stop cycle, the license retention conditions expire during license execution, or the actual response to the control command does not conform to the preset response sequence, this module revokes the current license credential and its subsequent license credentials, and generates a latching control command based on the still valid security conditions.
[0160] The safety permission interlocking module reads the current stop cycle identifier, current stop action evidence chain, abnormal node set, platform static candidate state, static reference height value, static reference pressure value and initial position value of the locking mechanism from the stop evidence data packet.
[0161] This module reads the current stop cycle identifier, mechanical load status triplet, mechanical locking reliability confirmation result, platform sinking trend, and locking anomaly type from the load transfer confirmation data packet. This module also reads the current stop cycle identifier, door lock coupling status quadruplet, door lock coupling confirmation result, and door lock anomaly type from the door lock coupling verification data packet.
[0162] The current pause cycle identifier in the three data packets is used to determine whether the three data packets originate from the same pause process. When the three current pause cycle identifiers are the same, the three data packets are associated with the current pause cycle; when any current pause cycle identifier is different from the others, no security permission is generated, and the permission mismatch type is recorded as cycle association mismatch.
[0163] The license mismatch type is used to record the mismatch categories identified during license generation or execution. Its values include no mismatch, periodic associated mismatch, instruction sequence mismatch, instruction response timeout, load holding mismatch, hydraulic reload mismatch, and mechanical lock release mismatch. If no mismatch is identified, the license mismatch type is recorded as no mismatch.
[0164] When three current pause cycle identifiers are identical, this module sets the pause cycle root node and writes the current pause cycle identifier into the pause cycle root node. The pause cycle root node is used to associate the condition node, permission node, permission credential, and instruction response chain generated within the current pause cycle.
[0165] This module generates a stop-floor stability condition node, a mechanical load condition node, and a door lock coupling condition node based on three data packets.
[0166] When the platform is in a static candidate state, the abnormal node set is empty, and the platform is in a static stable state in the current stopping action evidence chain, the stopping stability condition node is recorded as passed; otherwise, the stopping stability condition node is recorded as failed.
[0167] When the extension state is complete, the contact state is complete, the load-bearing state is stable load-bearing in the mechanical load-bearing state triplet, the mechanical locking reliability confirmation result is confirmed as passed, the platform sinking trend is non-existent, and the locking anomaly type is no anomaly, the mechanical load-bearing condition node is recorded as passed; otherwise, the mechanical load-bearing condition node is recorded as failed.
[0168] If the retraction response state, switch release state, reset response state, and door constraint state in the door lock coupling state quadruple are all passed, the door lock coupling confirmation result is confirmed as passed, and the door lock exception type is no exception, then the door lock coupling condition node is recorded as passed; otherwise, the door lock coupling condition node is recorded as failed.
[0169] Starting with the root node of the platform's stop cycle, the system sequentially connects the stop stability condition node, mechanical load condition node, door lock coupling condition node, and floor safety door unlocking permission node to form an opening service branch. This branch controls the unlocking of mechanical door locks and the opening of floor safety doors after the platform stops at a floor.
[0170] This module sequentially sets up a door lock verification condition node, a hydraulic reload condition node, a mechanical lock retraction condition node, and a platform drive permission node after the door opening service branch, forming the operation recovery branch. The operation recovery branch is used to control the relocking of the floor security door, the transfer of platform load to the hydraulic system, the retraction of the mechanical lock mechanism, and the restoration of the platform drive.
[0171] The door opening service branch and the operation recovery branch together constitute a hierarchical security permission instruction tree. Each node in the hierarchical security permission instruction tree has a unique parent node, enabling this module to perform mismatch backtracking along the path of the node's parent node.
[0172] In this embodiment, licensing conditions are divided into licensing triggering conditions and licensing retention conditions according to their role in the control process. The licensing triggering condition is used to determine whether to generate and invoke the corresponding state-bound licensing credential. When the corresponding control instruction completes according to the preset instruction response chain, the node state corresponding to the licensing triggering condition is updated to "consumed." "Consumed" indicates that the condition has completed its triggering function for the current licensing stage and will no longer record licensing mismatch due to expected state changes caused by control instructions.
[0173] License maintenance conditions are used to restrict the security state that must remain in effect during the license execution period. This module continuously verifies the license maintenance conditions according to the sampling update cycle until the end of the corresponding license phase. When a license maintenance condition changes from passed to failed, the current license credential and its subsequent license credentials are revoked.
[0174] For floor security door unlocking permission, the floor stability condition node and the door lock coupling condition node serve as the permission triggering condition, and the mechanical load condition node serves as the permission holding condition.
[0175] For mechanical lock release permission, the lock verification condition node serves as the permission trigger condition, and the hydraulic reload condition node and lock holding condition serve as the permission holding conditions.
[0176] For platform-driven licenses, the door lock verification condition node, hydraulic reload condition node, mechanical lock retraction condition node, and door lock holding condition serve as license triggering conditions. After the platform-driven license is executed, the status of the nodes corresponding to the above license triggering conditions is updated to consumed.
[0177] The status-bound license credential includes the current pause cycle identifier, license type, credential generation time, credential expiration time, license trigger condition set, license retention condition set, and license credential status.
[0178] The license type is used to indicate the control action that the state-bound license credential is allowed to perform. Its values include floor security door unlocking, hydraulic reload, mechanical lock release, and platform drive.
[0179] The license validity window is used to limit the time range from the generation of the state-bound license credential to the date when it is allowed to be invoked. The license validity window corresponding to different license types is determined based on the control command transmission time, the maximum startup response time of the corresponding actuator, and the sampling update cycle.
[0180] The expiration time of a credential is obtained by adding the credential generation time to the duration of the corresponding license validity window. License credential status includes pending execution, executed, revoked, and timed out.
[0181] When all the license triggering conditions for the license node are met and all the license retention conditions are met, a state-bound license credential is generated, and the license credential status is recorded as pending execution.
[0182] Before the controller invokes the status binding license credential, this module rereads the current stop cycle identifier, license trigger condition, and license retention condition. If the current stop cycle identifier has not changed, the license trigger condition and license retention condition are both met, the current time has not exceeded the credential expiration time, and the license credential status is pending execution, the controller is allowed to execute the corresponding control instruction, and the license credential status is updated to executed.
[0183] If the current time exceeds the certificate's expiration time and the license certificate has not yet been executed, the license certificate status will be updated to "Timeout". If the current pause cycle identifier changes, or if either the license trigger condition or the license retention condition is not met, the license certificate status will be updated to "Revoked".
[0184] Only one license credential is retained in the pending execution state during each licensing phase. After the state-bound license credential for the next licensing phase is generated, the corresponding license credential for the previous licensing phase remains in the executed state and is no longer used as the current pending execution license credential.
[0185] This module sets the current permission stage, indicating the current position reached by the hierarchical security permission instruction tree. The current permission stage includes the floor stop permission verification stage, door opening service stage, door lock verification stage, hydraulic reload stage, mechanical lock retraction stage, and operation recovery stage.
[0186] After the three data packets are associated, the current permission stage is recorded as the stop-layer permission verification stage.
[0187] When the floor stability condition node, mechanical load condition node, and door lock coupling condition node are all passed, this module generates a floor security door unlocking permit. The permit triggering condition set for the floor security door unlocking permit includes the floor stability condition node and the door lock coupling condition node, and the permit holding condition set includes the mechanical load condition node.
[0188] After the controller invokes the floor security door unlocking authorization credential, it sends an unlocking control command to the mechanical door lock drive device. This module uses the moment the unlocking control command is sent as the start time of the unlocking response, and synchronously acquires the mechanical door lock switch signal, the floor security door closing switch signal, the current platform height data, the current hydraulic system pressure data, the current mechanical locking mechanism position data, and the locking mechanism force data according to the sampling update cycle.
[0189] The data acquisition entities and status parameters for mechanical door lock switch signals and floor safety door closing switch signals are the same as those in the door lock coupling verification module. The data acquisition entities and measurement parameters for current platform height data, current hydraulic system pressure data, current mechanical locking mechanism position data, and locking mechanism force data are the same as those in the load transfer confirmation module.
[0190] This module establishes an unlock command response chain based on the unlock control command and its corresponding signal changes. The unlock command response chain includes an unlock command node, a door lock release node, and a security door opening node.
[0191] When sending the unlock control command, record the unlock command node as completed.
[0192] The unlock response time limit is used to limit the maximum time for the mechanical door lock switch signal to respond to the unlock control command. It is determined based on the maximum release time of the mechanical door lock drive device, the signal conversion time of the mechanical door lock switch, and the sampling update cycle.
[0193] When the mechanical door lock switch signal changes from the locked state to the unlocked state within the unlock response time limit, the door lock release node is recorded as complete.
[0194] The door opening response time limit is used to limit the maximum time that the floor safety door leaves the closed detection position after the mechanical door lock is released. It is determined based on the maximum response time and sampling update cycle of the floor safety door from the release of the mechanical door lock to the door leaving the closed detection position.
[0195] After the door lock release node is completed, when the floor safety door closing switch signal changes from the closed state to the open state within the door opening response time limit, the safety door opening node is recorded as completed.
[0196] When the floor safety door closing switch signal changes from closed to open before the mechanical door lock switch signal, it indicates that the door has left the closing detection position before the mechanical door lock is released. The permissible mismatch type is recorded as instruction sequence mismatch, and the safety door opening node is determined as the mismatch start node.
[0197] When the mechanical door lock switch signal fails to switch to the unlocked state within the unlock response time limit, the permitted mismatch type is recorded as command response timeout, and the door lock release node is determined as the mismatch start node.
[0198] When the door lock release node has been completed, but the floor safety door closing switch signal has not been converted to the open state within the door opening response time limit, the permitted mismatch type is recorded as instruction response timeout, and the safety door opening node is determined as the mismatch start node.
[0199] After the unlock command response chain is completed in sequence, the floor stabilization condition node and the door lock coupling condition node will be updated to consumed, and the current permission stage will be recorded as the door opening service stage.
[0200] During the door opening service phase, this module continuously verifies the mechanical load-bearing conditions. These conditions include that the current mechanical locking mechanism position data remains within the lock extension target range, the mechanical load ratio is not lower than the service maintenance ratio threshold, and the platform height deviation is not greater than the service maintenance displacement threshold.
[0201] Platform height deviation is the absolute value of the difference between the current platform height data and the static reference height value, used to represent the amount of change in the platform's position relative to the stationary position of the floor during the opening of the floor safety door.
[0202] This module, following the calculation criteria in the load transfer confirmation module, multiplies the current hydraulic system pressure data by the total effective hydraulic working area to obtain the current hydraulic support force; it adds the force data of the locking mechanism corresponding to each load point to obtain the current mechanical support force; and it divides the current mechanical support force by the sum of the current hydraulic support force and the current mechanical support force to obtain the mechanical load ratio.
[0203] The service retention ratio threshold limits the proportion of platform load that the mechanical locking mechanism must continuously bear during the door opening service phase. It is determined based on the rated load capacity of the mechanical locking mechanism, the allowable support ratio of the hydraulic system, and the platform load requirements during the opening of the floor safety door. The service retention displacement threshold limits the permissible displacement of the platform relative to the static reference height during the door opening service phase. It is determined based on the permissible displacement of the platform at each floor, the engagement clearance of the mechanical locking mechanism, and the measurement error of the height detection device.
[0204] During the door opening service phase, when the current mechanical locking mechanism position data leaves the locking extension target range, the mechanical load ratio is lower than the service maintenance ratio threshold, or the platform height deviation is greater than the service maintenance displacement threshold, the mechanical load condition node is recorded as failed, the permitted mismatch type is recorded as load maintenance mismatch, and the mechanical load condition node is determined as the mismatch start node.
[0205] When the floor safety door closes again, the floor safety door closing switch signal changes from the open state to the closed state. This module sets a door closing stability window to limit the duration for which the floor safety door needs to remain closed. The door closing stability window is determined based on the maximum time required for the floor safety door to complete closing, the maximum time required for the mechanical door lock to complete locking, and the sampling update cycle.
[0206] When the floor safety door closing switch signal remains closed within the door closing stability window, the current permitted phase is recorded as the door lock verification phase, and a door lock verification request is sent to the door lock coupling verification module. The door lock verification request instructs the door lock coupling verification module to apply the restricted verification pulse again after the floor safety door is closed again, and to generate a new door lock coupling verification data packet according to the door lock causal response relationship.
[0207] This module receives the door lock coupling verification data packet generated after receiving the door lock verification request. When the current stop cycle identifier in this data packet is the same as the current stop cycle identifier in the stop cycle root node, the data packet is identified as a reset door lock coupling verification data packet. When all four states of the door lock coupling status quadruple in the reset door lock coupling verification data packet are passed, the door lock coupling confirmation result is confirmed as passed, and the door lock exception type is no exception, the door lock verification condition node is recorded as passed; otherwise, the door lock verification condition node is recorded as failed, and no hydraulic reload permit is generated.
[0208] The door lock holding condition indicates that the floor security door must remain closed and locked before the mechanical lock release and platform drive permission generation. When the floor security door close switch signal indicates closed and the mechanical door lock switch signal indicates locked, the door lock holding condition is recorded as passed; if either signal is not met, the door lock holding condition is recorded as failed.
[0209] When the door lock verification condition node passes and the door lock holding condition passes, this module generates a hydraulic reload permit and records the current permit stage as the hydraulic reload stage.
[0210] The target pressure range for reload is used to define the pressure range that the hydraulic system needs to reach after the platform load is transferred back to the hydraulic system. The target pressure range for reload is determined based on the static reference pressure value, the measurement error of the pressure detection device, and the pressure fluctuation range when the platform is stationary.
[0211] The maximum pressure increment per cycle is used to limit the maximum allowable increase in hydraulic system pressure within a sampling update cycle, and is determined based on the allowable pressure rise rate of the hydraulic system and the sampling update cycle.
[0212] After the controller invokes the hydraulic reload permission certificate, it reads the current hydraulic system pressure data according to the sampling update cycle, calculates the pressure difference between the lower limit of the reload target pressure range and the current hydraulic system pressure data, and determines the smaller value between the pressure difference and the maximum pressure increment in a single cycle as the pressure adjustment amount for the current cycle.
[0213] When the current hydraulic system pressure is below the lower limit of the reload target pressure range, and the platform height deviation is no greater than the service hold displacement threshold, the controller increases the hydraulic system pressure according to the current cycle pressure adjustment. When the current hydraulic system pressure enters the reload target pressure range, the controller stops increasing the hydraulic system pressure and enters the reload evaluation window. The reload evaluation window is used to limit the time during which the hydraulic system support state must continuously meet the reload conditions; its duration is determined based on the pressure stabilization time after the hydraulic system is pressurized, the platform structure response time, and the sampling update cycle.
[0214] This module calculates the current hydraulic support force based on the current hydraulic system pressure data and the current mechanical support force based on the locking mechanism force data, according to the calculation criteria in the load transfer confirmation module. The current hydraulic support force and the current mechanical support force are then added together to obtain the current combined support force.
[0215] This module divides the current hydraulic support force by the current combined support force to obtain the hydraulic reload ratio. The hydraulic reload ratio represents the proportion of the platform's current load that is now being borne by the hydraulic system.
[0216] The hydraulic reload ratio threshold is used to limit the proportion of platform load that the hydraulic system needs to bear before the mechanical locking mechanism exits the load-bearing state. It is determined based on the rated support capacity of the hydraulic system, the mechanical load that can be retained when the mechanical locking mechanism exits the engagement area, and the pressure detection error.
[0217] This module calculates the absolute difference between the current synthetic support force and the static reference hydraulic support force to obtain the support force balance deviation value. The calculation method for the static reference hydraulic support force and the support force balance deviation threshold is the same as that of the load transfer confirmation module.
[0218] Within the reload evaluation window, when the hydraulic reload ratio is consistently not lower than the hydraulic reload ratio threshold, the support force balance deviation value is consistently not greater than the support force balance deviation threshold, and the platform height deviation is consistently not greater than the service maintenance displacement threshold, the hydraulic reload condition node is recorded as passed.
[0219] When the platform height deviation exceeds the service maintenance displacement threshold, the support force balance deviation exceeds the support force balance deviation threshold, or the hydraulic reload ratio is still lower than the hydraulic reload ratio threshold at the end of the reload evaluation window, the hydraulic system pressure is stopped from being adjusted further, the hydraulic reload condition node is recorded as failed, the permissible mismatch type is recorded as hydraulic reload mismatch, and the hydraulic reload condition node is determined as the mismatch start node.
[0220] When the hydraulic reload condition node passes and the door lock holding condition passes, this module generates a mechanical lock release permit. The permit triggering condition set for the mechanical lock release permit includes the door lock verification condition node, and the permit holding condition set includes the hydraulic reload condition node and the door lock holding condition.
[0221] After the controller invokes the mechanical lock release authorization certificate, it sends a retraction control command to the drive device of the mechanical lock mechanism and records the current authorization stage as the mechanical lock retraction stage.
[0222] This module simultaneously acquires the current position data of the mechanical locking mechanism, the force data of the locking mechanism, the current platform height data, and the current hydraulic system pressure data, and establishes a locking release command response chain based on the retraction control command and its corresponding state changes.
[0223] The lock release command response chain includes a revocation command node, a lock unloading node, and a lock revocation node.
[0224] When sending a control retraction command, record the retraction command node as completed.
[0225] The release force threshold is used to limit the maximum force that the mechanical locking mechanism can retain before leaving the fixed support. It is determined based on the allowable frictional resistance when the mechanical locking mechanism exits the engagement area, the measurement error of the force detection device, and the structural load-bearing requirements of the mechanical locking components.
[0226] When the force data of the locking mechanism drops below the release force threshold, the locking unloading node is recorded as complete.
[0227] The lock retraction target range is used to define the position range of the mechanical locking mechanism when it completes retraction. It is determined based on the initial position value of the locking mechanism, the measurement error of the position detection device, and the safety clearance between the mechanical locking mechanism and the platform's operating area. The lock retraction response time limit is used to define the maximum time the locking mechanism can remain within the lock retraction target range after unloading. It is determined based on the maximum retraction time of the mechanical locking mechanism, the response time of the drive device, and the sampling update cycle.
[0228] After the locking unloading node is completed, when the current mechanical locking mechanism position data enters the locking retraction target range within the locking retraction response time limit, the locking retraction node is recorded as completed.
[0229] When the locking unloading node has not been completed, but the current position data of the mechanical locking mechanism has already left the locking extension target range, it indicates that the mechanical locking mechanism has begun to exit the engagement area before the force drops to the allowable range. The permissible mismatch type is recorded as mechanical locking release mismatch, and the locking unloading node is determined as the mismatch start node.
[0230] When the force data of the locking mechanism is lower than the release force threshold, but the current position data of the mechanical locking mechanism does not enter the locking retraction target range within the locking retraction response time limit, the permitted mismatch type is recorded as command response timeout, and the locking retraction node is determined as the mismatch start node.
[0231] During the mechanical lock retraction process, this module continuously verifies the hydraulic reload condition and the door lock holding condition. When the hydraulic reload condition changes from pass to fail, or the door lock holding condition changes from pass to fail, the mechanical lock mechanism stops retracting, the permissible mismatch type is recorded as mechanical lock release mismatch, and the corresponding condition node is determined as the mismatch start node.
[0232] When the lock release command response chain is completed sequentially, the hydraulic reload condition remains valid, the door lock holding condition remains valid, and the platform height deviation is not greater than the service holding displacement threshold, the mechanical lock retraction condition node is recorded as valid.
[0233] After the mechanical lock retraction condition node is passed, a platform driver license credential is generated. The license trigger condition set of the platform driver license credential includes the door lock verification condition node, the hydraulic reload condition node, the mechanical lock retraction condition node, and the door lock holding condition. The license holding condition set is empty.
[0234] Before the controller invokes the platform driver license certificate, it reads the floor safety door closing switch signal, mechanical door lock switch signal, current mechanical locking mechanism position data, and current hydraulic system pressure data again.
[0235] The support pressure range before platform operation is used to define the pressure range that the hydraulic system needs to maintain before the platform starts driving. It is determined based on the static reference pressure value, the measurement error of the pressure detection device, and the pressure fluctuation range when the platform starts.
[0236] When the floor safety door closing switch signal indicates that it is closed, the mechanical door lock switch signal indicates that it is locked, the current mechanical locking mechanism position data is within the locking retraction target range, the current hydraulic system pressure data is within the platform operation support pressure range, and the permitted mismatch type is no mismatch, the controller is allowed to execute the platform drive command and record the current permitted stage as the operation recovery stage.
[0237] After the platform-driven command is executed, the status of the nodes corresponding to the door lock verification condition node, hydraulic reload condition node, mechanical lock retraction condition node, and door lock holding condition is updated to consumed.
[0238] This module continuously verifies the license retention conditions and instruction response chain corresponding to the current license credential during each licensing phase. A license mismatch is determined to have occurred when the license retention conditions change from passed to failed, or when any of the following occurs in the instruction response chain: the order of response nodes is reversed, a response node is missing, or a response times out.
[0239] When a license mismatch occurs, the node that fails to meet the license preservation conditions or the node that fails to complete the response in the preset order will be identified as the mismatch initiation node.
[0240] Starting from the mismatch initiation node, this module traces back level by level along the unique parent node path of the hierarchical security permission instruction tree to the root node of the stop cycle, and reads the latest sampled data corresponding to each preceding node in order of distance from the mismatch initiation node.
[0241] If the read status is still "passed" and it is a preceding node that meets the current permission stage's permission retention conditions, then that preceding node is designated as a safe rollback node. If no preceding node meeting the above conditions is found, then the root node of the stop cycle is designated as a safe rollback node.
[0242] The safety rollback node is used to determine the control state that can be retained after a permission mismatch occurs. This module pre-stores safety rollback rules, which generate interlocking control instructions according to the position of the safety rollback node in the hierarchical safety permission instruction tree.
[0243] When the safety retraction node is the root node of the stop cycle or the stop stability condition node, it generates a floor safety door unlocking prohibition command, a platform drive prohibition command, a mechanical locking action stop command, and a hydraulic support holding command; when the safety retraction node is a mechanical load condition node or a door lock coupling condition node, it generates a floor safety door unlocking prohibition command, a platform drive prohibition command, a mechanical locking holding command, and a hydraulic support holding command.
[0244] When the safety retraction node is a door lock verification condition node or a door lock holding condition node, a platform drive prohibition command, a mechanical lock retraction prohibition command, and a hydraulic support holding command are generated; when the safety retraction node is a hydraulic reload condition node, a platform drive prohibition command, a mechanical lock retraction stop command, and a hydraulic adjustment stop command are generated; when the safety retraction node is a mechanical lock retraction condition node, a platform drive prohibition command, a floor safety door unlocking prohibition command, and a hydraulic support holding command are generated.
[0245] The interlocking control command type is used to record the control restrictions output after permission mismatch. Its values include floor safety door unlocking prohibition, platform drive prohibition, mechanical lock holding, mechanical lock action stop, mechanical lock retraction prohibition, mechanical lock retraction stop, hydraulic support holding, and hydraulic adjustment stop.
[0246] After determining the safe rollback node, this module updates the status binding license credentials of the licensed node corresponding to the mismatch start node and its subsequent licensed nodes to "revoked" and outputs the lockout control command corresponding to the safe rollback node.
[0247] It should be noted that, Figure 3 This is a schematic diagram of graded safety authorization and mismatch interlocking.
[0248] The current stop cycle identifier, current permission stage, current permission credential status, permission mismatch type, security rollback node, and lockout control instruction type are encapsulated into a hierarchical security permission status data packet.
[0249] The current license credential status indicates the execution status of the license credential bound to the current license stage. When the current license stage has not yet generated a state-bound license credential, the current license credential status is recorded as pending generation; after the state-bound license credential is generated, it is recorded as pending execution, executed, revoked, or timed out according to the corresponding license credential status.
[0250] The graded safety permission status data packet is used to record the status of permission generation, permission execution, permission revocation and lockout handling within the current stop cycle, and sends it to the elevator controller, which then executes the lockout control command recorded therein or the control command corresponding to the current permission stage.
[0251] Through the above processing, this module organizes the floor stabilization, mechanical load, door lock coupling verification, door lock review, hydraulic reload, and mechanical lock retraction into a hierarchical safety permission instruction tree with action dependencies. It distinguishes between state changes caused by normal actions and safety condition failures through permission triggering conditions and permission holding conditions. Each state-bound permission credential is subject to the combined constraints of the floor stabilization period, permission conditions, and permission validity window. When a sequence mismatch, response timeout, or load condition failure occurs between the control command and the actual physical response, this module can revoke the permission credential after the mismatch node and revert to the still valid safety condition node, preventing the failed permission from continuing to trigger floor safety door unlocking, mechanical lock release, or platform actuation.
Claims
1. An intelligent elevator based on an AI monitoring system, characterized in that, include: The suspension evidence construction module performs standardized processing and consistency verification on multi-source data during the suspension process, and encapsulates the verified data into time-series evidence units; it calls the time-series evidence units according to the suspension action dependency relationship to construct the current suspension action evidence chain, determines the platform's static candidate state and suspension benchmark data, and obtains the suspension evidence data package; The load transfer confirmation module generates a mechanical locking permission command based on the stop floor evidence data packet, and controls the mechanical locking mechanism to extend. Based on the actual extension stroke, platform micro-displacement, hydraulic support force and mechanical support force, the extension, contact and load-bearing states are confirmed in sequence to determine the reliable confirmation result of mechanical locking and obtain the load transfer confirmation data package. The door lock coupling verification module generates a door lock verification permission command based on the bearer transfer confirmation data packet, applies a restricted verification pulse to the mechanical door lock, and obtains the door lock verification response data. Based on the causal response relationship of the door lock, the door lock coupling state, door lock coupling confirmation result, and door lock anomaly type are determined, and a door lock coupling verification data packet is obtained. The security permission interlocking module constructs a hierarchical security permission instruction tree based on the floor stop evidence data packet, the bearer transfer confirmation data packet, and the door lock coupling verification data packet, and generates a state-bound permission credential. Identify license mismatches during the license execution process, revoke the corresponding state-bound license credential and its subsequent license credentials, determine the safe rollback node, and execute the lockout control command.
2. The intelligent elevator based on an AI monitoring system according to claim 1, characterized in that, The multi-source data of the stopping process is normalized and its consistency is verified, including: The multi-source data of the stopping process is filtered based on the collection time, the effective duration of the evidence, and the evidence synchronization time difference threshold. The multi-source data of the stopping process includes the current stopping cycle identifier, the target stopping floor, the platform height data, the platform running speed data, the driving mechanism running status, the hydraulic system pressure data, the mechanical locking mechanism position data, the floor safety door locking status data, and the stopping area image. The platform image deviation value is obtained from the image of the stopping area, and the platform coding deviation value is obtained from the platform height data and the stopping reference height. The absolute value of the difference between the two is calculated to obtain the dual-source deviation value. When the dual-source deviation value is not greater than the dual-source deviation threshold and the two are in the same direction, the deviation value with the larger absolute value is determined as the stopping deviation confirmation value, and the verified data is encapsulated into a time-series evidence unit. When the dual-source deviation value is greater than the dual-source deviation threshold or the two are in different directions, the positional evidence inconsistency is written into the abnormal node set.
3. The intelligent elevator based on an AI monitoring system according to claim 2, characterized in that, The step of constructing the current stop-level action evidence chain by invoking the temporal evidence unit based on the stop-level action dependency relationship includes: The following nodes are set sequentially: approaching the target floor node, entering the leveling allowable zone node, platform deceleration node, and platform static stability node. When the current node is completed and the corresponding time sequence evidence unit satisfies the state conditions and synchronization conditions of the next node, the next node is completed and written into the current stop layer action evidence chain; when the current node is completed but the maximum conversion time exceeds the time limit and the next node is not completed, the action timeout is written into the abnormal node set. When the platform is stationary and stable, and the set of abnormal nodes is empty, the platform is determined to be stationary candidate state. The stationary reference height value, stationary reference pressure value, and initial position value of the locking mechanism are calculated. The current stop cycle identifier, the current stop action evidence chain, the set of abnormal nodes, the platform stationary candidate state, the stationary reference height value, the stationary reference pressure value, and the initial position value of the locking mechanism are encapsulated into a stop evidence data package.
4. The intelligent elevator based on an AI monitoring system according to claim 1, characterized in that, Confirm the extended and contact states sequentially, including: When the platform is in a static candidate state and the set of abnormal nodes in the stopping evidence data packet is empty, a mechanical locking permission command is generated; the actual extension stroke is determined based on the current mechanical locking mechanism position data and the initial position value of the locking mechanism; the platform micro-displacement is determined based on the current platform height data and the static reference height value; and the extension state and contact state are determined sequentially by combining the locking mechanism force data; a mechanical load-bearing state ternary set including the extension state, contact state, and load-bearing state is established.
5. The intelligent elevator based on an AI monitoring system according to claim 4, characterized in that, Confirm the bearer status and obtain the bearer transfer confirmation data packet, including: Based on the current hydraulic system pressure data and the locking mechanism force data, determine the current hydraulic support force and the current mechanical support force respectively, and calculate the mechanical load ratio, hydraulic remaining support ratio, support force balance deviation value and platform sinking trend. Based on the mechanical load ratio, support force balance deviation, platform micro-displacement, and platform subsidence trend within the load transfer evaluation window, update the load status in the mechanical load status triplet and determine the locking anomaly type; when the load status is stable and the locking anomaly type is no anomaly, record the mechanical locking reliability confirmation result as confirmed and passed. The current stop cycle identifier, mechanical load status triplet, mechanical locking reliability confirmation result, mechanical load ratio, hydraulic remaining support ratio, platform sinking trend, and locking anomaly type are encapsulated into a load transfer confirmation data packet.
6. The intelligent elevator based on an AI monitoring system according to claim 1, characterized in that, Apply a restricted verification pulse to the mechanical door lock and acquire the door lock verification response data, including: When the mechanical locking reliability confirmation result in the carrier transfer confirmation data packet is confirmed as passed, the platform sinking trend is not present, and the locking anomaly type is no anomaly, a door lock verification permission command is generated; the verification retraction target depth is determined based on the initial bolt embedding depth, the safety retention embedding threshold, and the mechanical door lock switch action depth, and the bolt retraction and reset are controlled sequentially; door lock verification response data is acquired synchronously, including bolt position data, door lock drive current data, mechanical door lock switch signal, floor safety door closing switch signal, and floor safety door area image, and a door lock controlled response sequence is formed according to the acquisition time.
7. The intelligent elevator based on an AI monitoring system according to claim 6, characterized in that, Based on the causal response relationship of the door lock, the door lock coupling state, the door lock coupling confirmation result, and the door lock anomaly type are determined, including: Map the controlled response sequence of the door lock to the causal response diagram of the door lock. Based on the completion sequence and response time limit of the lock tongue retraction, drive load response, switch release, lock tongue reset, switch locking and door stability nodes, determine the retraction response state, switch release state, reset response state and door constraint state, and form a door lock coupling state quadruple. The door lock anomaly type is determined based on the incomplete nodes and mismatch relationships. When all states in the door lock coupling state quadruple are passed and the door lock anomaly type is no anomaly, the door lock coupling confirmation result is recorded as confirmed as passed; otherwise, it is recorded as confirmed as failed. The current stop cycle identifier, the door lock coupling state quadruple, the door lock coupling confirmation result, and the door lock anomaly type are encapsulated into a door lock coupling verification data packet.
8. The intelligent elevator based on an AI monitoring system according to claim 1, characterized in that, Construct a hierarchical security permission instruction tree and generate state-bound permission credentials, including: Verify the current stop cycle identifier in the stop evidence data packet, bearer transfer confirmation data packet, and door lock coupling verification data packet, and set the stop cycle root node when the current stop cycle identifier is consistent; Based on the action dependency relationship, the floor stop stability condition node, mechanical load condition node, door lock coupling condition node, and floor safety door unlocking permission node are sequentially connected to form the door opening service branch; the door lock verification condition node, door lock holding condition node, hydraulic reload permission node, hydraulic reload condition node, mechanical lock release permission node, mechanical lock retraction condition node, and platform drive permission node are sequentially connected to form the operation recovery branch, forming a hierarchical safety permission instruction tree in which each node except the floor stop cycle root node has a unique parent node; The licensing conditions are divided into licensing triggering conditions and licensing retention conditions. When both the corresponding licensing triggering conditions and licensing retention conditions are met, a status-bound licensing certificate is generated. The status-bound licensing certificate includes the current stop cycle identifier, licensing type, certificate generation time, certificate expiration time, license triggering condition set, license retention condition set, and licensing certificate status.
9. The intelligent elevator based on an AI monitoring system according to claim 8, characterized in that, Identifying license mismatches during license enforcement includes: Before binding the license credential to the call state, re-verify the current pause cycle identifier, license trigger conditions, license retention conditions, credential expiration time, and license credential status; During the floor security door unlocking phase, an unlocking command response chain is established, including an unlocking command node, a door lock release node, and a security door opening node. During the mechanical lock retraction phase, a lock release command response chain is established, including a retraction command node, a lock unloading node, and a lock retraction node. When the permission retention condition changes from passed to failed, or when any of the following occurs in the instruction response chain: node order is reversed, node is missing, or response times out, a permission mismatch is determined, and the corresponding condition node or response node is determined as the mismatch initiation node.
10. The intelligent elevator based on an AI monitoring system according to claim 9, characterized in that, Determine the safe rollback point and execute the interlock control command, including: Starting from the mismatch initiation node, trace back along the path of the unique parent node of the hierarchical security permission instruction tree to the root node of the stop cycle, and read the status of each preceding node in order of distance from the mismatch initiation node. The first preceding node whose status is still "passed" and which meets the conditions for maintaining the current permit stage is identified as the safe rollback node. If the preceding node is not found, the root node of the stop cycle is identified as the safe rollback node. The status binding license credential of the licensed node corresponding to the mismatch initiating node and its subsequent licensed nodes is updated to "revoked". Based on the position of the security rollback node in the hierarchical security license instruction tree, the lockout control instruction pre-associated with the security rollback node is executed.