Elevator control method, mobile terminal, storage medium, and computer program product

CN122809291APending Publication Date: 2026-09-25ZKTECO CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202611122508.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-07-27
Publication Date
2026-09-25

AI Technical Summary

Technical Problem

[0005]基于此,本申请的目的旨在至少能解决上述的技术缺陷之一,特别是现有技术中无法精准地确定用户的呼梯权限的技术缺陷,本申请提供了一种电梯控制方法、移动终端、存储介质和计算机程序产品

Benefits of technology

[0051]本申请提供的电梯控制方法、移动终端、存储介质和计算机程序产品,通过门禁控制系统根据对象标识和设备标识动态确定目标呼梯安全等级,并分别向移动终端和电梯梯控系统发送等级更新指令与权限同步指令,实现了门禁验证结果对呼梯权限的实时驱动,解决了传统梯控系统中安全等级静态配置、无法根据人员实际验证地点和身份动态调整,导致无法精准地确定用户的呼梯权限的技术问题,门禁控制系统作为决策中枢,将验证事件与安全等级绑定,使得人员的呼梯权限与其当前所在门禁点及身份严格匹配,杜绝了越权呼梯,实现了一验证一等级一呼梯的精准安全控制。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122809291A_ABST
    Figure CN122809291A_ABST
Patent Text Reader

Abstract

The application provides an elevator control method, a mobile terminal, a storage medium and a computer program product. The method comprises: in response to a target object performing a verification operation on an access control device, obtaining an object identifier of the target object and a device identifier of the access control device when the verification is passed; determining a target call elevator security level according to the object identifier and the device identifier; generating a level update instruction and a permission synchronization instruction based on the target call elevator security level; sending the level update instruction to a mobile terminal, and sending the permission synchronization instruction to an elevator control system. The method can accurately determine the call elevator permission of a user and accurately perform elevator scheduling.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of elevator technology, and in particular to an elevator control method, a mobile terminal, a storage medium, and a computer program product. Background Technology

[0002] In smart buildings, the coordinated control of access control systems and elevator control systems is a key aspect of achieving safe management of personnel entry and exit.

[0003] Currently, elevator call security levels are typically configured statically, meaning a fixed call level is pre-set for each access control device or individual's identity. Once verified, the user is granted call access at this fixed level. However, this static configuration leads to a disconnect between the security level of call access and the actual access control verification context. This can result in situations where a user with a low-security access control verification grants call access to a higher-security floor, or a user with a high-security access control verification fails to upgrade their call access to the appropriate level in a timely manner, creating security vulnerabilities.

[0004] Therefore, existing technologies have the technical problem of being unable to accurately determine a user's elevator calling permissions. Summary of the Invention

[0005] Based on this, the purpose of this application is to at least solve one of the above-mentioned technical defects, especially the technical defect in the prior art that cannot accurately determine the user's elevator call permissions. This application provides an elevator control method, a mobile terminal, a storage medium, and a computer program product.

[0006] In a first aspect, this application provides an elevator control method applied to an access control system, the method comprising:

[0007] In response to the verification operation of the target object on the access control device, when the verification is successful, the object identifier of the target object and the device identifier of the access control device are obtained;

[0008] Determine the target elevator call safety level based on the object identifier and equipment identifier;

[0009] Based on the target elevator call security level, generate level update instructions and permission synchronization instructions;

[0010] Send a level update command to the mobile terminal, and send a permission synchronization command to the elevator control system;

[0011] Among them, the level update instruction is used to update the elevator call safety level stored locally on the mobile terminal to the target elevator call safety level, so that the mobile terminal can generate an elevator call request carrying the target elevator call safety level; the permission synchronization instruction is used to instruct the elevator control system to generate and execute an elevator dispatching scheme that matches the target elevator call safety level when it receives an elevator call request.

[0012] In one exemplary embodiment, determining the target elevator call safety level based on the object identifier and the device identifier includes:

[0013] Based on the object identifier, determine the permission level to which the target object belongs, and determine the highest security level allowed for that permission level;

[0014] Based on the device identifier, the device security level of the access control device is determined from the preset access control device and security level mapping table;

[0015] The target call elevator safety level is determined based on the highest safety level and the equipment safety level.

[0016] In one exemplary embodiment, based on the target elevator call security level, a level update instruction and a permission synchronization instruction are generated, including:

[0017] The target elevator call security level is encapsulated according to the preset communication protocol to obtain the initial level update instruction and the initial permission synchronization instruction.

[0018] The headers of the initial level update command and the initial permission synchronization command are corrected to obtain the level update command and permission synchronization command.

[0019] In an exemplary embodiment, the headers of the initial level update instruction and the initial permission synchronization instruction are corrected to obtain the level update instruction and permission synchronization instruction, including:

[0020] The message headers of the initial level update command and the initial permission synchronization command are parsed to extract the first core field information and the second core field information;

[0021] The first core field information and the second core field information are compared with the preset protocol template respectively;

[0022] If there is at least one target field that is inconsistent with the protocol template, then each target field is corrected according to the correction method defined in the protocol template, and based on each corrected target field, the corresponding initial level update instruction and / or initial permission synchronization instruction are updated to obtain the level update instruction and / or permission synchronization instruction.

[0023] If the target field does not exist, the initial level update instruction and the initial permission synchronization instruction will be used as the level update instruction and permission synchronization instruction, respectively.

[0024] In an exemplary embodiment, the permission synchronization instruction includes an object authentication instruction and an available floor acquisition instruction; sending the permission synchronization instruction to the elevator control system includes:

[0025] Send object authentication commands and available floor acquisition commands to the elevator control system;

[0026] The object authentication command is used to provide the elevator control system with the object identifier of the target object; the available floor acquisition command is used to instruct the elevator control system to determine the list of accessible floors of the target object based on the object identifier and the target call safety level.

[0027] In one exemplary embodiment, the method further includes:

[0028] Monitor whether the elevator control system returns a confirmation response to the authorization synchronization command;

[0029] If no confirmation response is received, the permission synchronization command will be resent according to the preset resentment policy until a confirmation response is received or the maximum number of resentments is reached.

[0030] The confirmation response is sent by the elevator control system after successfully receiving the authorization synchronization command.

[0031] Secondly, this application provides an elevator control method applied to an elevator control system, the method comprising:

[0032] Receives permission synchronization instructions sent by the access control system; the permission synchronization instructions are generated by the access control system in response to the verification operation of the target object on the access control device.

[0033] It receives elevator call requests sent by mobile terminals, generates elevator dispatching plans based on the target elevator call security level and permission synchronization instructions carried in the call requests, and executes them.

[0034] In an exemplary embodiment, the permission synchronization instruction includes an object authentication instruction and an available floor acquisition instruction; based on the target elevator call security level and permission synchronization instruction carried in the elevator call request, the elevator dispatching scheme is generated as follows:

[0035] Based on the object authentication instructions, determine the object identifier of the target object;

[0036] In response to an available floor acquisition command, the list of accessible floors for the target object is determined based on the object identifier and the target elevator call safety level carried in the elevator call request;

[0037] An elevator dispatching plan is generated based on the target elevator call safety level, object identifier, and list of accessible floors.

[0038] Thirdly, this application provides an elevator control method applied to a mobile terminal, the method comprising:

[0039] Receives a level update command sent by the access control system; the level update command is generated by the access control system in response to the verification operation of the target object on the access control device.

[0040] Update the locally stored elevator call safety level to the target elevator call safety level in the level update command;

[0041] In response to the elevator call operation of the target object, an elevator call request is generated based on the target elevator call safety level;

[0042] Send an elevator call request to the elevator control system so that the elevator control system can generate and execute an elevator scheduling plan.

[0043] Fourthly, this application provides a mobile terminal for performing the method of claim 9, the mobile terminal comprising:

[0044] The communication unit is used to receive the access control system's level update command.

[0045] The security encryption unit is used to obtain the level update instruction from the communication unit and store the target elevator security level carried by the level update instruction;

[0046] The protocol processing unit is used to generate an elevator call request based on the target elevator call safety level using a preset elevator call protocol;

[0047] The communication unit is also used to send elevator call requests to the elevator control system.

[0048] Fifthly, this application provides a computer-readable storage medium having a computer program stored thereon, wherein the steps of the method are implemented when the computer program is executed by a processor.

[0049] Sixthly, this application provides a computer program product, including a computer program that, when executed by a processor, implements the steps of the above-described method.

[0050] As can be seen from the above technical solutions, the embodiments of this application have the following advantages:

[0051] The elevator control method, mobile terminal, storage medium, and computer program product provided in this application dynamically determine the target elevator call security level based on object and device identifiers through an access control system. It then sends level update instructions and permission synchronization instructions to the mobile terminal and elevator control system respectively, achieving real-time driving of elevator call permissions based on access verification results. This solves the technical problem in traditional elevator control systems where static security level configuration and the inability to dynamically adjust based on the actual verification location and identity of personnel lead to inaccurate determination of user elevator call permissions. The access control system, acting as the decision-making center, binds verification events to security levels, ensuring that personnel's elevator call permissions strictly match their current access point and identity, preventing unauthorized elevator calls and achieving precise security control of one verification, one level, and one elevator call. Attached Figure Description

[0052] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0053] Figure 1 A system architecture diagram of the elevator control system provided in the embodiments of this application;

[0054] Figure 2 A flowchart illustrating an elevator control method provided in an embodiment of this application;

[0055] Figure 3 A flowchart illustrating another elevator control method provided in an embodiment of this application;

[0056] Figure 4 A flowchart illustrating yet another elevator control method provided in this application embodiment;

[0057] Figure 5 This is a schematic diagram of the structure of an elevator control device provided in an embodiment of this application;

[0058] Figure 6 This is a schematic diagram of another elevator control device provided in an embodiment of this application;

[0059] Figure 7 This is a schematic diagram of the structure of another elevator control device provided in the embodiments of this application;

[0060] Figure 8 This is a schematic diagram of the internal structure of a computer device provided in an embodiment of this application. Detailed Implementation

[0061] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0062] The technical solution of this application relies on the elevator control system, such as Figure 1As shown, the elevator control system includes three physical device nodes: an access control system 102, an elevator control system 104, and a mobile terminal 106. The access control system 102 serves as the decision-making center, used to collect access verification events in real time and dynamically calculate the target elevator call security level. The elevator control system 104 serves as the execution terminal, used to receive elevator call requests and allocate the car and floor. The mobile terminal 106 serves as the user interaction carrier, used to store the target elevator call security level and generate elevator call requests.

[0063] In one exemplary embodiment, Figure 2 This is a flowchart illustrating an elevator control method provided in an embodiment of this application, as shown below. Figure 2 As shown, an elevator control method is provided, which can be applied to... Figure 1 The access control system 102 in the example is used for illustration, including the following steps S202 to S208. Among them:

[0064] Step S202: In response to the verification operation of the target object on the access control device, when the verification is successful, obtain the object identifier of the target object and the device identifier of the access control device.

[0065] The access control system refers to an automated control platform responsible for collecting access verification events, matching personnel permissions, and calculating the elevator call security level.

[0066] The target group refers to the personnel who are verified through the access control equipment.

[0067] Access control equipment refers to verification terminals deployed at entrances and exits, including card readers, facial recognition terminals, or fingerprint recognition terminals.

[0068] Verification refers to the act of a target person proving their identity by means of swiping a card, facial recognition, or fingerprint recognition.

[0069] Among them, the object identifier is information that uniquely identifies the target object, such as employee number or personnel ID.

[0070] Among them, the device identifier is the information that uniquely identifies the access control device, such as the device number or location ID.

[0071] Optionally, the access control system monitors verification events in real time through the access control device. When a target object performs a verification operation on the access control device and the verification is successful, the access control system extracts the object identifier (e.g., personnel ID) and device identifier (e.g., access point ID) from the verification event.

[0072] Step S204: Determine the target elevator safety level based on the object identifier and the equipment identifier.

[0073] The target elevator call security level refers to the level of authority calculated for this verification event that determines the floors that the elevator can reach. It is usually divided into Level-1 (normal security level) and Level-2 (high security level).

[0074] Optionally, the access control system calculates the target elevator security level to be granted in this verification based on preset permission matching rules, combining the personnel permissions corresponding to the object identifier and the access control point attributes corresponding to the device identifier.

[0075] Step S206: Based on the target elevator call security level, generate a level update instruction and a permission synchronization instruction.

[0076] Among them, the level update command is a command issued by the access control system to the mobile terminal, which is used to update the elevator call security level stored locally on the mobile terminal.

[0077] Among them, the permission synchronization instruction is a command issued by the access control system to the elevator control system to notify the target object of the elevator system of its current security level and related permissions.

[0078] Optionally, the access control system encapsulates the target security level into a level update command and an access control synchronization command according to a predetermined communication protocol, and performs necessary format standardization processing on the commands to ensure that the commands can be correctly parsed by the mobile terminal and the elevator control system.

[0079] Step S208: Send a level update command to the mobile terminal and a permission synchronization command to the elevator control system.

[0080] Among them, the mobile terminal refers to the smartphone OBU device that integrates the ELCS-SP elevator call protocol.

[0081] The elevator control system refers to the dispatching system that interfaces with the elevator controller, and is responsible for receiving elevator call requests and allocating cars and floors.

[0082] Optionally, the access control system sends the level update command to the target object's mobile terminal via a wireless network, while simultaneously sending the permission synchronization command to the elevator control system via a wired network.

[0083] In a real-world application scenario, if the high-rise R&D floors in a chip factory are set to a high security level (Level-2), while the lobby access control is at a normal security level (Level-1), after an R&D engineer verifies their identity at the high-rise server room access control, their mobile terminal's local security level automatically updates to Level-2, granting them only access to the high-rise R&D floors. If they verify their identity at the lobby access control, they only gain Level-1 access and cannot access the high-rise floors. Visitors have no elevator call permission regardless of whether they verify their identity at any access control. This scenario fully demonstrates the precise control of "one verification, one level, one elevator call."

[0084] The aforementioned elevator control method dynamically determines the target elevator call security level based on object and equipment identifiers through the access control system. It then sends level update instructions and permission synchronization instructions to the mobile terminal and the elevator control system, respectively. This achieves real-time driving of elevator call permissions based on access verification results. It solves the technical problem in traditional elevator control systems where static security level configuration cannot be dynamically adjusted according to the actual verification location and identity of the personnel, resulting in the inability to accurately determine the user's elevator call permissions. As the decision-making center, the access control system binds verification events with security levels, ensuring that the personnel's elevator call permissions are strictly matched with their current access point and identity, preventing unauthorized elevator calls, and achieving precise security control of one verification, one level, and one elevator call.

[0085] In one exemplary embodiment, determining the target elevator call security level based on the object identifier and the device identifier includes: determining the permission level to which the target object belongs based on the object identifier, and determining the highest security level allowed for the permission level; determining the device security level of the access control device from a preset access control device and security level mapping table based on the device identifier; and determining the target elevator call security level based on the highest security level and the device security level.

[0086] In this context, the permission level refers to the level of classification based on the target object's role or function in the organization, such as ordinary employee, administrator, visitor, etc.

[0087] The highest security level refers to the maximum elevator call security level that personnel at this access level can obtain.

[0088] The access control device and security level mapping table is a pre-configured data table that records the basic security level corresponding to each access control device.

[0089] The equipment security level refers to the fixed security level corresponding to the access control equipment. For example, the lobby access control is Level-1, and the high-rise computer room access control is Level-2.

[0090] In this embodiment, the target elevator call security level is the smaller of the highest security level and the equipment security level (i.e., the most stringent value) to ensure that the permissions do not exceed the limits.

[0091] Optionally, the access control system queries the personnel permission database based on the object identifier to obtain the permission level of the target object (e.g., R&D engineer), and then obtains the highest security level allowed for that permission level (e.g., Level-2). Simultaneously, the access control system looks up the corresponding device security level (e.g., Level-2) for the access control device from a pre-configured access control device-security level mapping table based on the device identifier. The access control system compares these two security levels and selects the lower level (smaller value or more stringent restrictions) as the target elevator call security level. For example, if the highest security level is Level-2 and the device security level is also Level-2, then the target level is Level-2; if the highest security level is Level-1 but the device security level is Level-2, then the target level is Level-1.

[0092] In this embodiment, the target security level is calculated by combining the highest security level determined by the permission level and the device security level determined by the access control device, forming a dual constraint mechanism. This solves the problem of overly broad or narrow permissions caused by judging elevator call permissions solely based on access control devices or personnel permissions. The dual constraint ensures that even if a person has high-level permissions, they can only obtain low-level elevator call permissions if verified at a low-security access control point. Conversely, low-level personnel cannot obtain high-level permissions through high-security access control. This mechanism achieves refined matching of permissions and further improves the accuracy of elevator call permission determination.

[0093] In an exemplary embodiment, based on the target elevator call security level, a level update instruction and an access control synchronization instruction are generated, including: encapsulating the target elevator call security level according to a preset communication protocol to obtain an initial level update instruction and an initial access control synchronization instruction; and correcting the message headers of the initial level update instruction and the initial access control synchronization instruction to obtain the level update instruction and the access control synchronization instruction.

[0094] Among them, the preset communication protocol refers to the elevator call protocol, which specifies the message format, field definition and communication rules of the command.

[0095] The initial level update command refers to the original command encapsulated according to the basic protocol format but without header correction, and the initial permission synchronization command is similar.

[0096] Among them, message header correction refers to the process of standardizing and correcting key fields in the instruction message header to ensure that the instruction complies with the protocol requirements of the target elevator control system.

[0097] Among them, the level update instruction and the permission synchronization instruction refer to the final instructions that can be used for actual issuance after being corrected.

[0098] Optionally, the access control system first fills the target elevator call security level into the payload field of the instruction according to a fixed format of a preset communication protocol, and generates a standard message header to obtain the initial level update instruction and the initial permission synchronization instruction. Then, the access control system performs calibration operations on the message headers of the two instructions respectively, ensuring that each field in the message header conforms to the specification format required by the target elevator control system. After calibration, the formal level update instruction and permission synchronization instruction are obtained.

[0099] In this embodiment, by introducing a message header correction step during the instruction generation stage, the problem of non-standard instruction formats and communication failures caused by differences in protocols among different elevator manufacturers is solved. The correction mechanism ensures that the issued instructions fully comply with the protocol requirements of the target elevator control system, thereby improving the compatibility of instructions and the success rate of communication, and providing reliable communication guarantee for accurately determining and executing elevator call permissions.

[0100] In an exemplary embodiment, correcting the headers of the initial level update instruction and the initial permission synchronization instruction to obtain the level update instruction and the permission synchronization instruction includes: parsing the headers of the initial level update instruction and the initial permission synchronization instruction to extract the first core field information and the second core field information; comparing the first core field information and the second core field information with a preset protocol template respectively; if there is at least one target field that is inconsistent with the protocol template, then correcting each target field according to the correction method defined in the protocol template, and updating the corresponding initial level update instruction and / or initial permission synchronization instruction based on each corrected target field to obtain the level update instruction and / or permission synchronization instruction; if there is no target field, then using the initial level update instruction and the initial permission synchronization instruction as the level update instruction and the permission synchronization instruction respectively.

[0101] Among them, the core field information refers to the key fields in the message header used for protocol matching, including version number, data length, CRC32 checksum, and vendor identifier.

[0102] The preset protocol template refers to a data template that is pre-configured for a specific elevator provider and describes the rules for taking values ​​in standard message header fields.

[0103] In practical applications, the preset protocol templates support dynamic loading and switching. The corresponding template (e.g., Elevator A template, Elevator B template, etc.) can be selected according to the type of elevator provider being connected, thereby achieving adaptive adaptation of this method to different elevator manufacturer protocols.

[0104] The target field refers to the field whose value is found to be inconsistent with the protocol template after comparison.

[0105] The correction method refers to the specific operational method of correcting inconsistent fields to the standard values ​​of the protocol template, such as changing the version number to 2.0 or recalculating the length.

[0106] Optionally, the access control system parses the headers of the initial level update command and the initial permission synchronization command, extracting their respective core field information. Then, it compares this field information with a pre-loaded preset protocol template (e.g., an elevator protocol template from a provider). If a field is found to be inconsistent (e.g., version number 1.0, while the template requires 2.0), this field is marked as a target field. For all target fields, the access control system corrects them using a correction method (e.g., changing the version number field value to 2.0, recalculating and replacing the data length, regenerating and replacing the CRC32 checksum, and completing the provider identifier). After correction, the corresponding fields in the original command are replaced with the corrected fields to generate the level update command or permission synchronization command. If no target fields are found, the original command does not need to be modified and is directly issued as the official command.

[0107] In this embodiment, through refined processing of field-by-field parsing, comparison, and correction, the automatic identification and repair of abnormal message headers are achieved. This solves the problem of communication handshake failure and command execution failure caused by occasional errors in message format or differences in manufacturer versions in traditional methods. The automatic correction mechanism can adapt to protocol variants of different elevator manufacturers without manual intervention, which significantly improves the stability of the connection between the access control system and the elevator control system and the success rate of command issuance, thereby ensuring the reliability of the communication link for accurate transmission of elevator call permissions.

[0108] In an exemplary embodiment, the permission synchronization instruction includes an object authentication instruction and an available floor acquisition instruction; sending the permission synchronization instruction to the elevator control system includes: sending the object authentication instruction and the available floor acquisition instruction to the elevator control system; the object authentication instruction is used to provide the elevator control system with the object identifier of the target object; the available floor acquisition instruction is used to instruct the elevator control system to determine the list of accessible floors of the target object based on the object identifier and the target call security level.

[0109] Among them, the object authentication instruction is an instruction in the elevator call-specific protocol (such as the ELCS-SP protocol) used to register or authenticate the identity of the target object with the elevator control system. This instruction carries the object identifier of the target object.

[0110] The available floor acquisition instruction is used to request the elevator control system to return a list of floor numbers where the target object can stop, based on the currently granted safety level.

[0111] The reachable floor list refers to the set of floors that the elevator control system is allowed to call based on the target's call safety level (e.g., high safety levels only allow calling the high-level R&D floors).

[0112] Optionally, when generating the access control system's authorization synchronization command, it splits it into two sub-commands: an object authentication command and an available floor acquisition command. The access control system first sends the object authentication command to the elevator control system, notifying it of the target object's object identifier (e.g., R&D 001), enabling the system to complete the authentication and registration of the person. Subsequently, the access control system sends the available floor acquisition command, requesting the elevator control system to calculate and return a list of accessible floors for the person based on the just-synchronized target call security level. Upon receiving this command, the elevator control system generates a floor list, for example, [15, 16, 17], according to its internally configured security level and floor mapping relationship, and returns it via a response message.

[0113] In this embodiment, by refining the permission synchronization instruction into two sub-steps—object authentication instruction and available floor acquisition instruction—the elevator control system achieves prior authentication and subsequent authorization of the target object. This solves the problem that directly issuing security levels may cause the elevator control system to be unable to associate personnel identities. The authentication instruction enables the elevator control system to establish a binding relationship between personnel identification and security level, while the available floor acquisition instruction ensures that the elevator can calculate the reachable floors in real time based on the level, thereby enabling accurate scheduling when an elevator call request arrives, and avoiding permission misjudgments due to incomplete information.

[0114] In one exemplary embodiment, the method further includes: monitoring whether the elevator control system returns a confirmation response to the permission synchronization command; if no confirmation response is received, retransmitting the permission synchronization command according to a preset retransmission strategy until a confirmation response is received or the maximum number of retransmissions is reached; wherein, the confirmation response is sent by the elevator control system after successfully receiving the permission synchronization command.

[0115] The confirmation response refers to the confirmation signal returned by the elevator control system after receiving the instruction, indicating that the instruction has been correctly received and processed.

[0116] The preset retransmission policy refers to the rules for automatically retransmitting commands when there is no response to communication, including the maximum number of retransmissions (e.g., 3 times) and the retransmission interval (e.g., 1 second).

[0117] The maximum number of retransmissions refers to the maximum number of times the system can attempt to send a message. If this number is exceeded, the communication is considered to have failed and an alarm is triggered.

[0118] Optionally, after sending the access control system to the elevator control system with the permission synchronization command, a response timer (with a timeout period set to 3 seconds) is started. If a handshake response (e.g., an ACK signal) is received from the elevator control system within the timeout period, the synchronization is confirmed to be successful; if no response is received within the timeout period, the access control system automatically resends the command according to a preset retransmission strategy, and waits for a response again after each retransmission.

[0119] In practical applications, the retransmission interval is set to 1 second, with a maximum of 3 retransmissions. If no response is received after 3 retransmissions, the access control system determines that the communication link is abnormal, records the failure log, and triggers an alarm (e.g., displaying an alarm message in the management backend or sending an SMS notification to maintenance personnel). Simultaneously, it automatically switches to the backup communication link to retry synchronization until communication is restored or manual intervention is required. If a response is received at any point during the retransmission process, retransmission stops and synchronization is considered successful.

[0120] In this embodiment, by introducing a handshake response monitoring and automatic retransmission mechanism, the problem of instruction loss and permission synchronization failure caused by instantaneous network fluctuations or busy elevator control system is solved. This mechanism ensures the communication reliability between the access control system and the elevator control system, so that the permission synchronization instruction can be delivered with high reliability. This ensures that the elevator call request of the mobile terminal can be correctly identified and processed. Finally, even in a weak network environment, the elevator call permission judgment can be accurately executed, avoiding permission failure caused by instruction loss.

[0121] In an exemplary embodiment, the method further includes: generating a linkage log; the linkage log includes fields such as a unique log identifier (log_id), a person ID (person_id), an access control device ID (door_id), a security level before the change (old_level), a security level after the change (new_level), an elevator number (elevator_no), a car number (car_no), an operation timestamp (timestamp), and an execution status (status).

[0122] The linkage log is used to retrieve data by personnel, time, elevator number, and other criteria, and supports export, so as to achieve full-link traceability and compliance auditing of "person-point-level-elevator".

[0123] In one exemplary embodiment, when the target elevator call security level is high security level (Level-2), it is activated only after the target object passes verification at a preset high security access point. If no elevator call operation is performed within a preset time window or the target object leaves the high security area without re-verification, the high security level is automatically revoked, and the elevator call security level stored locally on the mobile terminal is restored to the normal security level (Level-1). This mechanism achieves a dynamic closed loop for high security permissions, avoiding permission residue.

[0124] In one exemplary embodiment, Figure 3 This is a flowchart illustrating an elevator control method provided in an embodiment of this application, as shown below. Figure 3 As shown, an elevator control method is provided, which can be applied to... Figure 1 Taking the elevator control system 104 as an example, the explanation includes the following steps S302 to S304. Wherein:

[0125] Step S302: Receive the access control system's permission synchronization instruction; the permission synchronization instruction is generated by the access control system in response to the verification operation of the target object on the access control device.

[0126] The elevator control system refers to the dispatching system that interfaces with the elevator controller and is responsible for receiving elevator call requests and allocating cars and floors.

[0127] Among them, the permission synchronization instruction refers to the command issued by the access control system to notify the target object of the elevator control system of its current security level and related permission information.

[0128] Optionally, the elevator control system first receives the permission synchronization instruction sent by the access control system, and accordingly caches or updates the relevant permission information of the target object locally.

[0129] Step S304: Receive the elevator call request sent by the mobile terminal, generate an elevator dispatching plan and execute it based on the target elevator call security level and permission synchronization instruction carried in the elevator call request.

[0130] Among them, the elevator call request refers to the command generated by the mobile terminal based on the locally updated target elevator call security level to request elevator service.

[0131] The elevator dispatching scheme refers to the allocation result generated by the elevator control system based on the safety level in the call request and the pre-synchronized permission information, combined with the current elevator operating status. This includes specifying the target car and the floors that are allowed to stop.

[0132] Optionally, when a mobile terminal initiates an elevator call request, the elevator control system extracts information such as the target elevator call security level and object identifier from the request. The elevator control system compares and verifies this security level with previously synchronized permission information. If they match, the system generates an optimal elevator scheduling plan based on the security level, pre-configured floor permission mapping relationships, and the current operating status of each elevator car, such as its location and load. The elevator control system then sends this plan to the elevator controller for execution and simultaneously feeds back the allocation results (such as the car number) to the mobile terminal.

[0133] In this embodiment, the elevator control system simultaneously receives the permission synchronization command and the elevator call request, and associates and verifies the two to ensure that only personnel who have passed the access control verification and obtained the corresponding security level can obtain the correct elevator dispatch. This solves the problem that the security level reported by the mobile terminal may be tampered with. As the execution end, the elevator control system performs secondary confirmation of the permission, thereby realizing the accurate execution of the elevator call permission and preventing unauthorized elevator call behavior.

[0134] In one exemplary embodiment, the permission synchronization instruction includes an object authentication instruction and an available floor acquisition instruction; generating an elevator dispatching scheme based on the target elevator call security level carried in the elevator call request and the permission synchronization instruction includes: determining the object identifier of the target object based on the object authentication instruction; in response to the available floor acquisition instruction, determining the list of accessible floors of the target object based on the object identifier and the target elevator call security level carried in the elevator call request; and generating an elevator dispatching scheme based on the target elevator call security level, the object identifier, and the list of accessible floors.

[0135] Among them, the object authentication instruction provides a unique identifier for the target object in the elevator control system.

[0136] Among them, the available floor acquisition command enables the elevator control system to pre-calculate all floor numbers that the target object can stop at under a given safety level based on the object identifier of the target object.

[0137] The reachable floor list is a set of floors maintained internally by the elevator control system and linked to the safety level.

[0138] Optionally, upon receiving the permission synchronization command, the elevator control system parses the object identifier (e.g., personnel ID = R&D 001) from the object authentication command and stores it in the local session cache. Simultaneously, based on the target security level carried in the available floor retrieval command, the elevator control system queries its internal configuration table (e.g., Level-2 corresponding floors [15,16,17]) to obtain the list of reachable floors. When a subsequent elevator call request is received from a mobile terminal, the elevator control system extracts the target elevator call security level and object identifier from the request and matches them with the information in the local cache for verification. After successful verification, the system combines the reachable floor list with the current elevator operating status (e.g., the current floor, direction of travel, and congestion level of each car) to calculate the optimal elevator scheduling scheme: for example, in the Level-2 scenario, only calls to higher floors are allowed, and dedicated cars are assigned.

[0139] In this embodiment, by pre-storing object identifiers and accessible floor lists in the elevator control system and performing matching verification upon receiving an elevator call request, dual protection of pre-locking and post-verification of permissions is achieved. This solves the security vulnerabilities that may be caused by mobile terminals or tampered elevator call requests. The elevator control system does not rely on the permissions declared in the elevator call request, but rather on the authoritative information stored internally and synchronized by the access control system, thereby ensuring the absolute accuracy and non-repudiation of elevator call permission determination.

[0140] In one exemplary embodiment, Figure 4 This is a flowchart illustrating an elevator control method provided in an embodiment of this application, as shown below. Figure 4 As shown, an elevator control method is provided, which can be applied to... Figure 1 Taking mobile terminal 106 as an example, the explanation includes the following steps S402 to S408. Wherein:

[0141] Step S402: Receive the level update instruction sent by the access control system; the level update instruction is generated by the access control system in response to the verification operation of the target object in the access control device.

[0142] Among them, the mobile terminal can refer to a smartphone OBU device that integrates the ELCS-SP elevator call protocol and a security encryption module.

[0143] Optionally, the mobile terminal receives the access control system's level update instruction via a wireless network.

[0144] Step S404: Update the locally stored elevator call safety level to the target elevator call safety level in the level update instruction.

[0145] The elevator call security level stored locally refers to the level value representing the current user's elevator call permissions, which is encrypted and stored within the mobile terminal.

[0146] Optionally, the mobile terminal parses the instruction and extracts the target elevator call security level (e.g., Level-2). Then, the mobile terminal calls the local secure storage interface to update the original elevator call security level (e.g., Level-1) to the target elevator call security level.

[0147] Step S406: In response to the elevator call operation of the target object, generate an elevator call request based on the target elevator call safety level.

[0148] The elevator call operation refers to the action of the target person selecting the target floor or clicking the elevator call button on the mobile terminal APP interface.

[0149] Among them, the elevator call request is a command message constructed by the mobile terminal according to the current local security level and conforming to the ELCS-SP protocol.

[0150] Optionally, when the target object performs an elevator call operation on the mobile terminal (e.g., clicks the elevator call button), the mobile terminal reads the currently stored security level, constructs an elevator call request message according to the ELCS-SP protocol, and fills in the security level as one of the request parameters.

[0151] Step S408: Send an elevator call request to the elevator control system so that the elevator control system can generate and execute an elevator scheduling plan.

[0152] Optionally, the mobile terminal sends the elevator call request to the elevator control system. Upon receiving the request, the elevator control system generates and executes a scheduling plan based on the target elevator call safety level and other synchronous information. Ultimately, the mobile terminal receives feedback on the car allocation result.

[0153] In the aforementioned elevator control method, the mobile terminal acts as a bridge between the access control system and the elevator control system. It passively updates its local security level based on security level update commands and actively carries this level when calling the elevator. This solves the problem of traditional mobile phone elevator calling, where the security level is stored on the server or is fixed, preventing dynamic adaptation. The mobile terminal's local security level is entirely driven by the access control system through verification events, avoiding the possibility of users modifying permissions themselves. Furthermore, because the security level is stored locally on the terminal, elevator calling operations do not require accessing the server every time, resulting in faster response times. It also allows users to continue using acquired permissions (within their validity period) even offline, thereby improving the user's elevator calling experience and the reliability of precise permission control.

[0154] It is understood that the elevator control system of this application can be divided into five logical functional modules: an access control module (i.e., the ACS access control module), a protocol adaptation module (i.e., the ELCS-SP protocol adaptation module), a terminal interaction module (i.e., the OBU interaction module), a log storage module, and a permission configuration module. Among them:

[0155] The access control module (i.e., the ACS access control module) is deployed in the access control system 102. This module is the core function of the access control system 102 and is responsible for collecting verification events of access control devices, matching personnel permission groups, and calculating the target elevator call security level.

[0156] The protocol adaptation module (i.e., the ELCS-SP protocol adaptation module) is deployed in the access control system 102. As a built-in communication protocol processing unit of the access control system 102, this module is responsible for constructing ELCS-SP commands, correcting message headers, and monitoring communication status. It works in conjunction with the access control module to complete the standardized conversion of commands within the access control system 102.

[0157] The terminal interaction module (i.e., the OBU interaction module) is deployed on the access control system 102 and the mobile terminal 106. It is divided into a sending end and a receiving end. The sending end is deployed on the access control system 102 and is responsible for sending level update instructions to the mobile terminal 106 and sending permission synchronization instructions to the elevator control system 104. The receiving end is deployed on the mobile terminal 106 and is responsible for receiving level update instructions, updating the local security level, generating and sending elevator call requests.

[0158] The log storage module is deployed in the access control system 102 (or an independent log server). This module usually serves as the background storage unit of the access control system 102, recording event logs such as access control verification, security level changes, and elevator calls. In terms of deployment, it can be the built-in database of the access control system 102 or an independent log server, but functionally it falls under the management scope of the access control system 102.

[0159] The permission configuration module is deployed on the access control system 102 (backend management terminal). This module is the management configuration sub-module of the access control system 102. It provides a backend interface with a preset "Access Control Device-Security Level Mapping Table" and personnel permission groups. The operation and maintenance personnel configure permission policies through this module, and the configuration results are available for the access control module to call.

[0160] The five functional modules mentioned above, with the access control system 102 as the core and the mobile terminal 106 as the terminal node, jointly drive the elevator control system 104 to complete precise elevator call permission control. Practical application shows that after adopting this method, the mobile terminal elevator call response success rate has increased from approximately 60% in existing technologies to over 99%; the time for abnormal elevator calls and fault location has been shortened from hours to minutes; system deployment requires no modification to elevator hardware, reducing costs by over 80%; and personnel no longer require manual authorization or special cards, improving work efficiency by over 60%.

[0161] In one exemplary embodiment, a mobile terminal is provided for performing the method described in the previous embodiment. The mobile terminal includes a communication unit, a security encryption unit, and a protocol processing unit.

[0162] Among them, the mobile terminal refers to the smartphone OBU (Off-Board Unit) device that integrates a dedicated elevator call protocol and a security encryption module. Unlike ordinary mobile phones, it natively supports the ELCS-SP protocol and has secure storage capabilities.

[0163] The communication unit is a hardware and software module in the mobile terminal responsible for wireless or wired data transmission and reception with the access control system and elevator control system.

[0164] Among them, the level update command is a command generated by the access control system in response to the verification operation of the target object on the access control device, used to update the local elevator call security level of the mobile terminal.

[0165] Among them, the security encryption unit is a hardware or software encryption module inside the mobile terminal used to securely store sensitive data (such as elevator security level) and prevent tampering.

[0166] The target elevator call security level refers to the level of authority determined by the verification event that determines the floors that the elevator can reach. It is usually divided into normal security level (Level-1) and high security level (Level-2).

[0167] Among them, the preset elevator call protocol refers to the ELCS-SP (Elevator Control System – Smart Phone) dedicated protocol, which defines the message format, encryption method and communication rules for call requests between the mobile terminal and the elevator control system.

[0168] Among them, the elevator call request is a command message constructed by the mobile terminal based on the current local security level to request elevator service.

[0169] The elevator control system refers to the dispatching system that interfaces with the elevator controller, and is responsible for receiving elevator call requests and allocating cars and floors.

[0170] Optionally, the mobile terminal's communication unit listens for level update commands from the access control system in real time via a wireless network. Upon receiving a command, the communication unit transmits the raw data to the security encryption unit. The security encryption unit first verifies the legality and integrity of the command, then parses out the target elevator call security level and writes it to its internal tamper-proof storage area (e.g., a Secure Element (SE) or Trusted Execution Environment (TEE), while overwriting the original local security level. When a user initiates an elevator call operation through the mobile terminal's APP interface (e.g., clicking the "Call Elevator" button), the protocol processing unit reads the currently stored target elevator call security level from the security encryption unit and constructs a call request message according to the preset elevator call protocol (ELCS-SP 2.0). This message includes user identification, target security level, timestamp, and checksum information. The protocol processing unit delivers the constructed call request to the communication unit, which then sends it to the elevator control system. Upon receiving the request, the elevator control system generates and executes a scheduling plan based on the security level and other synchronization information, ultimately returning the car allocation result to the mobile terminal's communication unit.

[0171] The aforementioned mobile terminal receives level update instructions via the communication unit, securely stores the target elevator call security level using a security encryption unit, generates an elevator call request based on a preset elevator call protocol via the protocol processing unit, and finally sends it to the elevator control system via the communication unit, thus constructing a complete closed loop from instruction reception and secure storage to protocol construction and request transmission. This solves the technical problems of traditional mobile phone elevator call systems, where security levels are stored on the server side or are fixed, making dynamic adaptation impossible, or where ordinary mobile phones lack secure storage capabilities, making permissions easily tampered with, thus hindering the accurate determination of user elevator call permissions. The security encryption unit ensures that the local security level cannot be maliciously modified, and the protocol processing unit guarantees that the elevator call request conforms to the elevator control system's protocol specifications. This enables the mobile terminal to act as a trusted bridge between the access control system and the elevator control system, achieving precise security control of "one verification, one level, one call," while also improving response speed and offline availability.

[0172] It should be noted that the mobile terminal is not an ordinary smartphone, but a dedicated OBU device that natively integrates the ELCS-SP elevator call protocol and has a built-in security encryption module. It can securely store the elevator call security level and directly parse and construct call commands, which is different from ordinary mobile phones.

[0173] It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.

[0174] The elevator control device provided in the embodiments of this application is described below. The elevator control device has the same inventive concept as the elevator control method described above. The solution to the problem provided by the device is similar to the solution described in the above method. Therefore, the specific limitations of one or more elevator control device embodiments provided below can be referred to the limitations of the elevator control method above. The elevator control device described below and the elevator control method described above can be referred to each other, and will not be repeated here.

[0175] In one exemplary embodiment, Figure 5 This is a schematic diagram of the structure of an elevator control device provided in an embodiment of this application, as shown below. Figure 5As shown, the elevator control device, applied to the access control system 102, includes: a verification module 502, a determination module 504, and a sending module 508, wherein:

[0176] The verification module 502 is used to respond to the verification operation of the target object in the access control device. When the verification is successful, it obtains the object identifier of the target object and the device identifier of the access control device.

[0177] The determination module 504 is used to determine the target elevator safety level based on the object identifier and the device identifier;

[0178] The generation module 506 is used to generate level update instructions and permission synchronization instructions based on the target elevator call security level.

[0179] The sending module 508 is used to send a level update instruction to the mobile terminal and an access control system instruction to the elevator control system. The level update instruction is used to update the elevator call security level stored locally on the mobile terminal to the target elevator call security level, so that the mobile terminal generates an elevator call request carrying the target elevator call security level. The access control system instruction is used to instruct the elevator control system to generate and execute an elevator dispatching scheme that matches the target elevator call security level when it receives an elevator call request.

[0180] In an exemplary embodiment, the determining module 504 is specifically used to determine the permission level of the target object based on the object identifier, and determine the highest security level allowed for the permission level; determine the device security level of the access control device from a preset access control device and security level mapping table based on the device identifier; and determine the target elevator call security level based on the highest security level and the device security level.

[0181] In an exemplary embodiment, the generation module 506 is specifically used to encapsulate the target elevator call security level according to a preset communication protocol to obtain an initial level update instruction and an initial permission synchronization instruction; and to correct the message headers of the initial level update instruction and the initial permission synchronization instruction to obtain the level update instruction and the permission synchronization instruction.

[0182] In an exemplary embodiment, the generation module 506 is specifically used to parse the message headers of the initial level update instruction and the initial permission synchronization instruction, extract the first core field information and the second core field information; compare the first core field information and the second core field information with a preset protocol template respectively; if there is at least one target field that is inconsistent with the protocol template, then each target field is corrected according to the correction method defined in the protocol template, and based on each corrected target field, the corresponding initial level update instruction and / or initial permission synchronization instruction is updated to obtain the level update instruction and / or permission synchronization instruction; if there is no target field, then the initial level update instruction and the initial permission synchronization instruction are used as the level update instruction and the permission synchronization instruction respectively.

[0183] In an exemplary embodiment, the permission synchronization instruction includes an object authentication instruction and an available floor acquisition instruction; the sending module 508 is specifically used to send the object authentication instruction and the available floor acquisition instruction to the elevator control system; the object authentication instruction is used to provide the elevator control system with the object identifier of the target object; the available floor acquisition instruction is used to instruct the elevator control system to determine the list of accessible floors of the target object based on the object identifier and the target call security level.

[0184] In one exemplary embodiment, the device further includes: a monitoring module, configured to monitor whether the elevator control system returns a confirmation response to the permission synchronization command; if no confirmation response is received, the permission synchronization command is resent according to a preset retransmission strategy until a confirmation response is received or the maximum number of retransmissions is reached; wherein, the confirmation response is sent by the elevator control system after successfully receiving the permission synchronization command.

[0185] In one exemplary embodiment, Figure 6 This is a schematic diagram of the structure of an elevator control device provided in an embodiment of this application, as shown below. Figure 6 As shown, the elevator control system 104 includes: an authorization synchronization command receiving module 602 and an elevator scheduling scheme execution module 604, wherein:

[0186] The access control synchronization instruction receiving module 602 is used to receive access control synchronization instructions sent by the access control system; the access control system generates the access control instructions in response to the verification operation of the target object in the access control device.

[0187] The elevator dispatching scheme execution module 604 is used to receive elevator call requests sent by mobile terminals, generate elevator dispatching schemes and execute them according to the target elevator call security level and permission synchronization instructions carried in the elevator call request.

[0188] In an exemplary embodiment, the permission synchronization instruction includes an object authentication instruction and an available floor acquisition instruction; the elevator scheduling scheme execution module 604 is specifically used to determine the object identifier of the target object according to the object authentication instruction; in response to the available floor acquisition instruction, determine the list of accessible floors of the target object according to the object identifier and the target elevator call security level carried in the elevator call request; and generate an elevator scheduling scheme according to the target elevator call security level, the object identifier, and the list of accessible floors.

[0189] In one exemplary embodiment, Figure 7 This is a schematic diagram of the structure of an elevator control device provided in an embodiment of this application, as shown below. Figure 7 As shown, applied to mobile terminal 106, the elevator control device includes: a level update instruction receiving module 702, a call safety level update module 704, a call request generation module 706, and a call request sending module 708, wherein:

[0190] The level update instruction receiving module 702 is used to receive level update instructions sent by the access control system; the level update instruction is generated by the access control system in response to the verification operation of the target object in the access control device;

[0191] The elevator call safety level update module 704 is used to update the locally stored elevator call safety level to the target elevator call safety level in the level update instruction;

[0192] The elevator call request generation module 706 generates an elevator call request based on the target elevator call safety level in response to the elevator call operation of the target object.

[0193] The elevator call request sending module 708 is used to send elevator call requests to the elevator control system so that the elevator control system can generate and execute an elevator scheduling plan.

[0194] In one exemplary embodiment, this application also provides a computer-readable storage medium having a computer program stored thereon that, when executed by a processor, implements the steps of any of the elevator control methods described above.

[0195] In one exemplary embodiment, this application also provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps of any of the elevator control methods described above.

[0196] In one exemplary embodiment, this application also provides a computer program product, including a computer program that, when executed by a processor, implements the steps of any of the elevator control methods described in the above embodiments.

[0197] Indicatively, such as Figure 8 As shown, Figure 8 This is a schematic diagram of the internal structure of a computer device 800 provided in an embodiment of this application. The computer device 800 can be provided as a server. (Refer to...) Figure 8 The computer device 800 includes a processing component 802, which further includes one or more processors, and memory resources represented by memory 801 for storing instructions, such as application programs, that can be executed by the processing component 802. The application programs stored in memory 801 may include one or more modules, each corresponding to a set of instructions. Furthermore, the processing component 802 is configured to execute instructions to perform the elevator control method of any of the above embodiments.

[0198] The computer device 800 may also include a power supply component 803 configured to perform power management of the computer device 800, a wired or wireless network interface 804 configured to connect the computer device 800 to a network, and an input / output (I / O) interface 805. The computer device 800 may operate on an operating system stored in memory 801, such as Windows Server™, Mac OS X™, Unix™, Linux™, Free BSD™, or similar.

[0199] Those skilled in the art will understand that Figure 8 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0200] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of the relevant data must comply with relevant regulations.

[0201] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0202] The various embodiments in this specification are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. The various embodiments can be combined as needed, and the same or similar parts can be referred to each other.

[0203] The above description of the disclosed embodiments enables those skilled in the art to make or use this application. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of this application. Therefore, this application is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. An elevator control method, characterized in that, Applied to an access control system, the method includes: In response to the verification operation of the target object on the access control device, when the verification is successful, the object identifier of the target object and the device identifier of the access control device are obtained; The target elevator call safety level is determined based on the object identifier and the device identifier; Based on the target elevator call security level, generate a level update instruction and a permission synchronization instruction; Send the level update instruction to the mobile terminal, and send the permission synchronization instruction to the elevator control system; The level update instruction is used to update the elevator call safety level stored locally on the mobile terminal to the target elevator call safety level, so that the mobile terminal generates an elevator call request carrying the target elevator call safety level; the permission synchronization instruction is used to instruct the elevator control system to generate and execute an elevator scheduling scheme that matches the target elevator call safety level when it receives the elevator call request.

2. The method according to claim 1, characterized in that, Determining the target elevator call safety level based on the object identifier and the device identifier includes: Based on the object identifier, determine the permission level to which the target object belongs, and determine the highest security level allowed for the permission level; Based on the device identifier, the device security level of the access control device is determined from a preset access control device and security level mapping table; The target elevator call safety level is determined based on the highest safety level and the equipment safety level.

3. The method according to claim 1, characterized in that, The process of generating a level update instruction and a permission synchronization instruction based on the target elevator call security level includes: The target elevator call security level is encapsulated according to a preset communication protocol to obtain an initial level update instruction and an initial permission synchronization instruction. The message headers of the initial level update instruction and the initial permission synchronization instruction are corrected to obtain the level update instruction and the permission synchronization instruction.

4. The method according to claim 3, characterized in that, The step of correcting the message headers of the initial level update instruction and the initial permission synchronization instruction to obtain the level update instruction and permission synchronization instruction includes: The message headers of the initial level update instruction and the initial permission synchronization instruction are parsed to extract the first core field information and the second core field information; The first core field information and the second core field information are compared with the preset protocol template respectively; If there is at least one target field that is inconsistent with the protocol template, then each target field is corrected according to the correction method defined in the protocol template, and based on each corrected target field, the corresponding initial level update instruction and / or the initial permission synchronization instruction is updated to obtain the level update instruction and / or permission synchronization instruction. If the target field does not exist, the initial level update instruction and the initial permission synchronization instruction will be used as the level update instruction and permission synchronization instruction, respectively.

5. The method according to claim 1, characterized in that, The permission synchronization instruction includes an object authentication instruction and an available floor acquisition instruction; sending the permission synchronization instruction to the elevator control system includes: Send the object authentication command and the available floor acquisition command to the elevator control system; The object authentication instruction is used to provide the elevator control system with the object identifier of the target object; the available floor acquisition instruction is used to instruct the elevator control system to determine the list of reachable floors of the target object based on the object identifier and the target call security level.

6. The method according to claim 1, characterized in that, The method further includes: Monitor whether the elevator control system returns a confirmation response to the permission synchronization command; If no confirmation response is received, the permission synchronization command will be resent according to the preset resentment strategy until a confirmation response is received or the maximum number of resentments is reached. The confirmation response is sent by the elevator control system after successfully receiving the permission synchronization command.

7. An elevator control method, characterized in that, Applied to elevator control systems, the method includes: Receives a permission synchronization instruction sent by the access control system; the permission synchronization instruction is generated by the access control system in response to the verification operation of the target object on the access control device; The system receives elevator call requests from mobile terminals, generates and executes elevator scheduling schemes based on the target elevator call security level and the permission synchronization instructions carried in the elevator call requests.

8. The method according to claim 7, characterized in that, The permission synchronization instruction includes an object authentication instruction and an available floor acquisition instruction; the step of generating an elevator dispatching scheme based on the target elevator call security level carried in the elevator call request and the permission synchronization instruction includes: The object identifier of the target object is determined according to the object authentication instruction; In response to the available floor acquisition instruction, the list of accessible floors of the target object is determined based on the object identifier and the target elevator call security level carried in the elevator call request; An elevator scheduling plan is generated based on the target elevator call safety level, the object identifier, and the list of reachable floors.

9. An elevator control method, characterized in that, Applied to a mobile terminal, the method includes: Receive a level update instruction sent by the access control system; the level update instruction is generated by the access control system in response to the verification operation of the target object on the access control device; Update the locally stored elevator call safety level to the target elevator call safety level in the level update instruction; In response to the elevator call operation of the target object, an elevator call request is generated based on the target elevator call safety level; The elevator call request is sent to the elevator control system so that the elevator control system can generate and execute an elevator scheduling plan.

10. A mobile terminal, characterized in that, For performing the method as described in claim 9, the mobile terminal includes: A communication unit is used to receive the access control system's level update command. A security encryption unit is used to obtain the level update instruction from the communication unit and store the target elevator call security level carried by the level update instruction; The protocol processing unit is used to generate an elevator call request based on the target elevator call safety level using a preset elevator call protocol; The communication unit is also used to send the elevator call request to the elevator control system.

11. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 9.

12. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 9.