ELEVATOR ELECTRONICS UNIT AND ASSOCIATED ELEVATOR SYSTEM, METHOD FOR AUTONOMOUS SAFETY TESTING OF AN ELEVATOR ELECTRONICS UNIT

DE502023003663D1Active Publication Date: 2026-04-30ZIEHL ABEGG AG
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
ZIEHL ABEGG AG
Filing Date
2023-10-13
Publication Date
2026-04-30

AI Technical Summary

Technical Problem

Existing elevator systems face increased complexity and maintenance challenges due to the distribution of safety functions, time-critical motor control operations, and cybersecurity across different electronic components, leading to high installation and software update efforts.

Method used

A compact elevator electronics unit with a central processing unit that directly controls the power output stage, integrating motor control and safety functions, eliminating the need for separate processors and reducing complexity by generating motor control signals directly.

Benefits of technology

This approach simplifies maintenance, reduces installation effort, enhances safety, and facilitates software updates by consolidating critical functions within a single unit, improving operational efficiency and security.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The invention relates to an elevator electronics unit designed and configured to control elevator operation, i.e., the travel operation of an elevator system. The elevator electronics unit can comprise the following components, preferably housed in a common casing: a power output stage capable of supplying an elevator motor of the elevator system with an AC output voltage (particularly three-phase); and (at least) a processor. The invention also relates to an elevator system comprising such an elevator electronics unit.

[0002] Furthermore, the invention relates to a method for safely updating such an elevator electronics unit and / or an elevator system according to the invention, as well as a further method for a subsequent and autonomous safety check of an elevator electronics unit or elevator system according to the invention, wherein "subsequent" can be understood here as meaning that the safety check is carried out autonomously after a software update has been performed by the elevator electronics unit.

[0003] Frequency converters with power output stages for operating elevator motors, with or without gearboxes, have long been used in elevator systems and are often implemented in a single-processor solution. This means that one processor can receive complex digital control commands and translate them into corresponding, primarily analog, control signals for controlling the power output stage. Some available frequency converters are specifically adapted for use in elevator systems, both in terms of certain interfaces and their respective designs.

[0004] However, elevator control functions are usually implemented by or separated from several electronic systems.

[0005] For example, CN 109 230 921 A discloses a freight elevator for a wind turbine tower. In this system, a processor of the freight elevator controls an elevator motor via a communication module designed as a separate unit and a separate frequency converter, with the processor, the communication module, and the frequency converter all housed in a common enclosure.

[0006] CN 109 951 096 A, in turn, describes a classic approach for elevator control, in which a frequency converter is controlled via an "inverter drive device 8", which in turn separately The system is designed by an "operation control device 9", which is an elevator control unit that, for example, receives external calls. The "inverter drive device 8" receives control commands from the "operation control device 9" and, after appropriate conversion, forwards them as control signals to the frequency converter.

[0007] Furthermore, decentralized control concepts are also known, for example from EP 0 663 366 A1, based on so-called "distributed processing units (DPU)".

[0008] Tasks of control electronics or electronic elevator control devices, which are often designed separately from the frequency converter, can include, for example: querying a safety circuit, detecting a door zone, evaluating internal and external calls, determining the car position, responding to control commands from the car roof, the pit, or the return control unit, as well as controlling special operating modes such as a fire service elevator. In recent years, additional features have included communication with a remote control or monitoring system, a building management system, or, for example, operation with a cloud database.

[0009] One problem with these established approaches is that elevator safety functions, time-critical motor control operations, and cybersecurity functions (i.e., functions that protect the elevator system from network attacks) are distributed across entirely different electronic components. As a result, the complexity of such elevator systems increases, along with the effort required for installation, maintenance, and the recurring need for software updates to the entire system, for example, to add new functions or adapt existing ones.

[0010] Combinations of an electronic elevator control device and a motor frequency converter, integrated into a single unit, are now also known. However, such existing elevator electronics units are usually surrounded by numerous additional devices. Consequently, the installation and effort required for safe operation of the respective elevator system, potentially with remote monitoring, remain very high.

[0011] Against this background, the invention aims to provide an electronic elevator control device that can be designed as a compact elevator electronics unit, the components of which can be housed in a common enclosure, and which helps to overcome the aforementioned disadvantages.

[0012] To solve the problem, an elevator electronics unit according to claim 1 is proposed. In particular, to solve the problem in an elevator electronics unit of the type mentioned above, it is proposed that the processor be designed as a central processing unit and consequently be configured to directly control the power output stage by means of motor control signals within the framework of motor control. This allows the central processing unit, mediated via the power output stage, to control and regulate the elevator motor. In particular, this enables the central processing unit to specify the elevator operation. Furthermore, the central processing unit is designed and configured to perform basic functions of elevator operation, namely responding to external, especially digital, calls from external transmitters by generating and outputting the corresponding motor control signals based on a respective travel curve for elevator operation.

[0013] By outputting the motor control signals, the central processor directly controls the power output stage. For example, the central processor can move an elevator car to a specific elevator stop (the car's stopping position), thus deliberately approaching such a stop with the elevator car (the elevator stop corresponds to the external call to which the central processor responds).

[0014] A travel curve can be understood as a temporal profile of the elevator car's speed, where the profile indicates the progression or change in the car's speed over time. Such a profile can include acceleration and deceleration ramps, as well as areas where a constant travel speed is maintained, or, for example, areas of very low travel speed, such as when correcting the car's position at the end of a braking process, i.e., shortly before reaching a final stopping position. The central processor can calculate the travel curve section by section (i.e., specify only the respective points of the travel curve step by step) and derive corresponding updated motor control signals from the travel curve at regular intervals of, for example, 5 ms.The actual travel path of the elevator car can also be captured by sensors and documented by the central processor, for example, in the form of automatically generated log files. The travel path can also take into account specific conditions at the endpoints of the elevator journey, such as a shortened shaft head at the top or the engagement of a folding skirt at the bottom. All such points can be considered by the central processor when defining the travel path in order to specify a suitable speed profile.

[0015] In contrast, previous solutions involved an external elevator control system defining the travel curve and typically generating a digital control command at regular intervals, which was transmitted to a frequency converter, for example, via CANopen communication. In the intervals between these commands, the frequency converter often controlled the motor itself. The frequency converter has its own processor / intelligence for this purpose, which generates corresponding control signals from the digital input commands to drive the frequency converter's power output stage and thus, if necessary, fill in any gaps in the timing.

[0016] In previously known approaches, a processor often forwards complex control commands, such as specifying a frequency and the amplitude of the output AC voltage (which the power output stage is to deliver to the elevator motor), to a second instance (e.g., a separate processor of a frequency converter). Only then does this second instance translate these commands into corresponding control signals with which the power output stage can be directly controlled. In contrast, the invention proposes that the central processor directly generates suitable control signals, such as an analog signal or a pulse-width modulation (PWM) signal, and outputs them to the power output stage without any intermediate instance.The power output stage therefore preferably has no intelligence of its own; however, it can, for example, include a hardware circuit that converts an analog signal or a PWM signal sent by the central processor into an analog control signal for controlling the individual transistors / power switches of an inverter circuit of the power output stage.

[0017] The motor control signals are thus output by the central processor as analog signals and / or in the form of at least one PWM signal. Using these motor control signals, the central processor can control individual power switches of the power output stage (either directly or indirectly, for example, via the aforementioned hardware circuit). This allows the central processor to adjust the output AC voltage accordingly, resulting in a desired speed and / or torque of the elevator motor. In other words, the central processor, together with the power output stage, can implement a frequency converter.

[0018] For the purpose of operating the elevator, the central processor can also preferably be configured to (self-)determine the respective travel path, taking into account a (respective) received external call and the evaluation of at least one piece of information regarding the current position of an elevator car in the elevator system. In this case, the central processor automatically generates the necessary motor control signals based on the travel path it has determined.

[0019] Information that allows conclusions to be drawn about the current cabin position can be retrieved by the central processor itself, for example, by directly or indirectly reading a sensor in the elevator system. This could therefore be, in particular, reliably determined information regarding the current position of the elevator cabin within the elevator shaft.

[0020] The central processing unit can also obtain the information, for example, from an instance of the elevator system that continuously creates and updates a virtual representation of the elevator. Such an instance can be implemented, in particular, as a so-called shaft copying system. This virtual representation / shaft copying system can be implemented based on sensors, especially magnetic sensors in the shaft, and / or relative encoder systems and / or an absolute encoder system of the elevator system. In this case, the information regarding the current position of the elevator car will be more of an estimate of the car's current position.

[0021] In particular, to obtain information regarding the current cabin position, the central processor can evaluate at least one safety circuit of the elevator system. Such a safety circuit can provide relevant "safety-related information" regarding the cabin position. The safety circuit can be a link in a complex safety chain that ensures the safe operation of the elevator system. The elevator operation can be designed such that the elevator cabin can only move if the entire safety chain is in a state permissible for operation. Accordingly, the central processor can be configured to query the instantaneous state of the safety chain in order to take this state into account when determining the travel path.

[0022] The aforementioned safety chain of the elevator system can be implemented, for example, as a series circuit of several safety elements ("Door closed?", "Cables taut?", "Speed ​​OK?", etc.). Each element (which can be implemented with a separate safety circuit) must be in a specific state so that the safety chain as a whole is in the permissible state in which safe operation of the elevator car is possible / permitted. Such a safety chain can, for example, monitor the correct closing and opening of the car doors and only permit opening of the doors when the car is in a safe state. Furthermore, the safety chain can be designed so that an interruption of the safety chain stops the operation of the elevator system. The safety chain is therefore preferentially superior to the central processor, i.e.,The central processor can only operate the elevator as long as the safety chain is not interrupted.

[0023] The central processor can also be configured to bypass a specific link in the safety chain when certain conditions are met. For example, if the elevator is to approach a stopping position with "early opening doors," the central processor can detect the elevator car entering a door zone, for instance, by reading zone magnets located in the door zone within the elevator shaft. If the central processor detects the elevator car entering a (predefined) door zone, it can selectively bypass a link in the safety chain (e.g., "door closed") (so-called "door bypassing") and thus allow the doors to open before the elevator car has reached its final stopping position ("early door opening").The central processor can therefore be configured to control a safety chain of the elevator system, depending on at least one received sensor signal (e.g., "elevator car within door zone"), which ensures the safe operation of the elevator.

[0024] Since the central processor receives and processes the typically digital external calls and can also communicate with other devices in the elevator system, for example to determine the current cabin position, it combines digital communication within the elevator system with the generation of the (often analog) motor control signals in a single processing unit. This fusion of the digital and analog worlds in the central processor significantly reduces complexity and thus simplifies maintenance and updates of the entire system.

[0025] The central processing unit (CPU) can be implemented, for example, as a microcomputer or microprocessor and / or on a mainboard of the elevator electronics unit. The CPU must have sufficient performance, in particular sufficient processing speed, to execute necessary time-critical motor control functions.

[0026] The central processor has an analog signal output (for generating an analog motor control signal) and / or a PWM unit (for generating a PWM motor control signal), which is / are directly connected to the power output stage to directly control the power output stage with the corresponding motor control signal. This implements direct motor control by the central processor. The central processor can therefore be configured, in particular, to perform a digital-to-analog conversion to generate analog motor control signals from digital data / commands (e.g., derived from the vehicle's operating curve), with which the power output stage can be directly controlled.

[0027] The design according to the invention makes it possible to use the central processor to control the operation of the elevator car and simultaneously control and regulate the elevator motor. The central processor is equipped with such a high operational speed that it can perform time-critical motor control functions.

[0028] Communication between the central processor and the power output stage can also be bidirectional, for example, so that the power output stage can send a fault message to the central processor. The central processor can also be configured to acquire sensor data from the elevator motor (such as the current angular position of the rotor). The central processor can then take such sensor data and / or fault messages into account when generating the motor control signals.

[0029] The elevator control architecture according to the invention can therefore provide that the central processor is configured for this purpose: (i) to respond to incoming external calls by generating and outputting corresponding motor control signals; (ii) to evaluate / take into account at least one piece of information regarding the current cabin position (= position of the elevator cabin), in particular to evaluate / read a safety circuit (preferably continuously); and (iii) to specify / calculate a respective travel curve based on a (momentary) received external call and on the basis of at least one piece of information regarding the current cabin position, in particular on the basis of an evaluation of at least one safety circuit;

[0030] Furthermore, it may also be intended, for example, that the central processing unit is configured for this purpose: (iv) to effect door control (door opening & door closing), for example by directly or indirectly controlling a door drive of the elevator car (this door control may also include the execution of a so-called "door bridging" by the central processor, by which the central processor bridges a link of a safety chain); and / or (v) to monitor an instantaneous state of a safety chain of the elevator system, preferably continuously.

[0031] The elevator system, in which the elevator electronics unit (which can be understood as an electronic elevator control device) is used, can, for example, comprise (in a manner known per se) an elevator car, suspension system, possibly a counterweight, and a drive unit (e.g., with traction sheave and) with an elevator motor (either with or without a gearbox). The elevator electronics unit can be designed as a compact structural unit; it can also take over the control and regulation of the drive unit, for example, by controlling a motor power output stage (especially as part of the aforementioned power output stage) of the drive unit, as already explained in detail.

[0032] Particularly safety-relevant functions of the elevator system, especially individual links in the aforementioned safety chain, can be implemented by means of a (respective) hardware circuit.

[0033] To perform all essential control and regulation functions, the central processor can be equipped with a serial interface, digital input and output ports, and relay outputs to provide control currents for activating relays. The central processor can also include an error memory to document error messages generated during elevator operation, as well as a memory for recording statistical data, such as data on completed trips, particularly the travel paths (which can be documented / logged by the central processor = recorder function), and / or other operating parameters that can be detected by sensors during elevator operation.

[0034] The elevator electronics unit may also include safety circuits, particularly in the form of non-modifiable hardware circuits, which the central processing unit can access (send and / or receive). The respective safety circuit may, in turn, be connected to external field devices, such as a position transmitter or other sensor or actuator.

[0035] All of the central functions described above can be executed by the central processor without requiring (error-prone) communication with another processor. This architecture of the elevator electronics unit according to the invention offers significant advantages with regard to safety during elevator operation, as well as with regard to simplifying maintenance and servicing, and with regard to the adaptability of the elevator electronics unit and thus of the elevator system it controls.

[0036] A housing containing the elevator electronics unit may be characterized, among other things, by the inclusion of a central power supply, which provides electrical voltage to at least one internal power supply unit of the elevator electronics unit. This internal power supply unit can provide a suitable operating voltage for operating components of the elevator electronics unit, for example, a specific DC voltage for the central processor and / or one of the auxiliary processors. Different internal DC voltage levels may be required, as certain sensors powered by the elevator electronics unit may require different voltage levels than the central processor.

[0037] The elevator electronics unit can be further developed as follows: The central processor can be configured to implement motor control of the elevator motor, including time-critical operations that must be executed in less than 1 ms. Furthermore, the central processor can be configured to implement travel control of the elevator system. This travel control can include less time-critical operations that can be executed in more than 1 ms, and / or non-time-critical operations that must be executed within 10 ms. The central processor is preferably configured to execute the motor control and travel control functions simultaneously.For this purpose, it is preferable if the central processor is configured to prioritize the motor control, and in particular the aforementioned time-critical operations, over the vehicle control, and in particular the aforementioned non-time-critical operations. This processing can be sequential and / or using a time-division multiplexing (TDM) method. The central processor can also be configured to interrupt vehicle control operations, especially those that are non-time-critical (if necessary to execute a time-critical operation immediately following the interruption).

[0038] The central processing unit (CPU) can have one or more processor cores. In a multi-core architecture, i.e., the use of at least two processor cores in the CPU, one core can be configured, for example, to perform time-critical engine control operations, and another core can be configured to perform vehicle control or non-time-critical operations. Furthermore, the CPU can also be designed so that, for example, one of the at least two processor cores can pause (i.e., temporarily refrain from performing operations). In all these cases, it is preferred that at least one of the cores can perform time-critical operations in real time.

[0039] Real-time relevant signals, in this context, are those that must be processed within a defined maximum response time; this maximum response time can, however, be in the range of several hundred milliseconds. Real-time relevant signals can therefore include both time-critical (< 1 ms) and time-non-critical (> 10 ms) signals.

[0040] The central processing unit (CPU) can, for example, have a system of intelligent interrupts, allowing time-critical and non-time-critical operations to be processed sequentially and / or using time division multiplexing (TDM), preferably one after the other and ordered according to their priority. Quasi-parallel (using one processor core) or truly parallel (on at least two processor cores) execution of both functions (motor control and the regulation and monitoring of driving operations) by a single CPU is thus possible because the CPU can prioritize between these two functions, executing time-critical operations before non-time-critical ones. This can be achieved, for example, through appropriate interrupt prioritization and / or by using two processor cores.A characteristic feature when using only one processor core is that the central processor executes both functions serially one after the other, but at such short intervals that quasi-parallel execution of both functions by one and the same central processor is possible.

[0041] For this purpose, a program for monitoring the operation of the elevator system (more precisely, the operation of the elevator car) and a program for motor control can be stored in the central processor's memory. Both of these programs can be configured via digital software updates, as will be explained in more detail later; that is, these programs can be stored in a (particularly respective) overwritable (internal or external) memory.

[0042] The advantages of this approach include the fact that the processor's software is easier to maintain compared to maintaining two separate processors. Furthermore, the solution is more cost-effective because one processor can be eliminated, and there are no longer any failure-prone contacts or lines, as communication between the two processors is no longer necessary. Additionally, the update process is simplified when using only one central processor, as is the error analysis of the entire system, due to the elimination of the communication between two processors that was previously required.

[0043] The elevator electronics unit can be used particularly advantageously if it includes at least one additional processor configured to perform at least one additional function. This additional function can thus modularly expand the functionality of the central processor. For example, the at least one additional processor can be plugged into a mainboard on which the central processor is implemented. This allows an additional function to be added very easily by simply plugging in the additional processor, and thus, in particular, retrofitted.

[0044] At least one additional processor can communicate with the central processing unit (CPU), for example, via a serial interface, particularly in the form of a bus system for data transmission. Alternatively or additionally, a so-called dual-ported RAM can be used to enable communication / data exchange between the additional processor and the CPU. Depending on its configuration, such a dual-ported RAM can be written to and read from by both processors, allowing, for example, the additional processor to read information stored in the dual-ported RAM by the CPU, and vice versa.

[0045] The respective additional processor can thus be viewed as a modular peripheral device of the central processor, through which the central processor gains access to and / or implements additional functions. Using such an additional processor, for example, a so-called STO (Safe Torque Off) function (which ensures that unintentional energization of the drive can be reliably prevented) or a brake control function can be implemented, enabling the safe control and operation of a mechanical brake in the elevator system. This approach is particularly suitable, for instance, when an electromechanical brake is to be controlled by a PWM signal, which PWM signal the associated additional processor can then generate.In this system, the actual (especially digital) braking command can be transmitted from the central processor to the auxiliary processor. The central processor can then deduce from the respective driving profile when braking should be applied and when the brake should be released. It should be noted that such electromechanical brakes typically release when energized and engage when the energizer / PWM signal is removed. Therefore, if the central processor wants to brake, it will instruct the auxiliary processor to discontinue energizing the brake.

[0046] Preferably, the central processor can implement an electronic braking circuit (particularly using an electrical braking resistor) with which braking energy can be electrically dissipated in a controlled manner. For this purpose, the central processor must control the motor / drive unit of the elevator system, which is precisely its function. To this end, the central processor can, for example, control an IGBT or another suitable power switch in a hardware circuit to engage an electrical braking resistor. Such an electronic braking circuit, implemented with the aid of the central processor, can serve, in particular, to prevent overvoltages, for example, in an intermediate circuit of the power output stage.

[0047] Key functions that can be implemented using the central processing unit may also include: a fire service elevator operation (this operating mode of the elevator system can, for example, enable firefighters to quickly move the elevator car in the event of a fire and / or prevent the elevator car from stopping in the event of a fire on floors where smoke detectors have detected heavy smoke, in order to protect the firefighters); an emergency power and / or evacuation operation (e.g., for carrying out an emergency power evacuation of passengers, especially when using a gearless drive unit); an emergency release function for freeing persons trapped in the elevator car, in particular where the emergency release function may include communication with an (external) remote control of the elevator system, for example from a service center; or group control of several elevator cars of the elevator system.

[0048] For all such central functions performed by the central processing unit, the central processing unit can of course also make use of an additional processor, i.e., instruct the respective additional processor accordingly by means of signals and / or digital commands, for example to establish a remote connection or to actually execute the respective additional function.

[0049] If the elevator system comprises two or more cabins that travel in two or more shafts but are electronically connected to form a single system, a group control system as described above can, for example, determine which cabin is moved by the elevator electronics unit to respond to an incoming external call. Alternatively, two separate elevator electronics units according to the invention can be implemented within the elevator system, which are then electronically networked and configured to coordinate with each other regarding the processing of incoming external calls.In other words, the central processor of an elevator electronics unit according to the invention can be configured to communicate with at least one further central processor of another elevator electronics unit, in particular to process incoming external calls in a coordinated manner, namely by generating and outputting corresponding motor control signals to move one of at least two elevator cabins of the elevator system.

[0050] Other possible additional functions that can be handled by an additional processor are: an evaluation of additional call systems for receiving further external calls; a gateway keeper function, for example to establish electronic contact with a building management system or an external computer network / cloud; a brake monitoring function with which the correct operation (in particular correct release and / or correct engagement) of a mechanical brake, especially a mechanical motor brake, of the elevator system can be monitored (this brake monitoring function, which the additional processor implements, can be based on the evaluation of sensor signals, in particular from micro and / or contact switches, and / or on an electrical current and / or voltage measurement); a brake wear monitoring function with which wear on a mechanical brake of the elevator system can be determined or at least estimated;A brake control function (enables correct release and application of the brake at appropriate times during the driving curve; for this purpose, the additional processor can, for example, control a brake operating circuit) allows such a brake to be selectively opened / released and closed. It should also be mentioned here that if the safety chain is interrupted, this interruption will de-energize the respective brake, so that the vehicle cabin comes to a safe stop.

[0051] The respective additional function will generally not be included in the scope of functions covered by the central processing unit (CPU). An additional processor can therefore execute instructions within the scope of the respective additional function decentrally to the CPU and / or simultaneously with it. Naturally, an additional processor can also be configured to execute / take over several such additional functions.

[0052] Another key function, preferably performed by the central processor, is, as mentioned, enabling electrodynamic braking of the elevator car or the recuperation of kinetic braking energy. For this purpose, the central processor can, for example, control a regenerative braking unit (particularly as a pre-stage of the power output stage). This allows kinetic braking energy to be recuperated as electrical power during the regenerative operation of the elevator motor and fed back into an external power grid. The control can be implemented, in particular, via an additional processor. If, however, this function is not to be implemented, the additional processor that controls the regenerative braking unit can be omitted. In this case, the additional processor supplements functionality that is, however, controlled by the central processor.

[0053] Another important additional function, which can be added with the help of an additional processor, is to enable communication between the central processing unit (CPU) and the internet, because the CPU should not have direct internet access for security reasons. At least one additional processor can thus act as a gatekeeper, providing the CPU with secure internet access, similar to a router.

[0054] By modularly adding or retrofitting at least one additional processor, the functionality of the elevator electronics unit can be easily adapted to customer requirements, thus significantly expanding its range of applications. A particular advantage is that all functions relevant to the elevator's passenger safety can be executed by the central processor, allowing the initial safety test to be limited to the elevator electronics unit without any additional processors. In a second step, the safety of the entire system, consisting of the central and additional processors, can then be verified.

[0055] At least one additional processor can be operated with, or be capable of operating with, or comprise such software, standardized, hardware-independent, programmable software, in particular with a standardized, hardware-independent operating system such as Linux.

[0056] As a technical alternative, it is also possible for the at least one additional processor to communicate with the central processing unit (CPU) using interrupts, particularly bidirectionally. In this case, a separate operating system for the additional processor is unnecessary. For efficient communication in such a configuration, it is advantageous if the at least one additional processor is configured to trigger at least one central interrupt of the CPU, thereby triggering (if required) a central interrupt service routine of the CPU associated with that central interrupt.Furthermore, alternatively or additionally (depending on the function the additional processor is to perform), the central processor can be configured to trigger a peripheral interrupt of the at least one additional processor in order to trigger an interrupt service routine of the at least one additional processor associated with this peripheral interrupt (if required). The transmission of a peripheral interrupt from the central processor to the additional processor can, for example, indicate a specific (especially time-controlled) event to the additional processor, such as the vehicle car moving flush into a stopping position or a specific operating state of the elevator system. In response to the peripheral interrupt, the additional processor can then trigger a corresponding, appropriate action, thereby enabling, for example, suitable convenience functions (visualizations and / or the playback of an audio file, etc.).upon reaching a specific stopping position) or to indicate a temporary special operation of the elevator system to persons.

[0057] Conversely, interrupts triggered by an auxiliary processor can initiate specific actions of the central processor. However, it is preferable for the central processor to be configured so that such external central interrupts, originating from an auxiliary processor, cannot interrupt time-critical operations, particularly motor control, that the central processor is currently executing. In other words, these external central interrupts can / should be deprioritized compared to internal interrupts generated by the central processor itself.

[0058] To facilitate the customization of an add-on processor for the customer, a table can be provided, for example, listing which peripheral interrupts correspond to which events. Based on such a table, the customer can then adapt the respective peripheral interrupt routine to their requirements in order to implement a specific customer-specific function with the add-on processor. However, modification of the central processing unit (CPU) is not necessary for this, which demonstrates the advantage of this concept.

[0059] In both cases—whether using a proprietary operating system in the add-on processor or communicating via interrupts—an "open platform for third parties" can be created. This allows them to easily implement their own control functions, operating options, visualizations (e.g., on a display unit in the elevator car), voice announcements, or other additional functions, particularly comfort features, using an add-on processor. For example, if the visualization of an elevator's user interface needs to be customized to customer requirements, it is sufficient to make the corresponding changes in the add-on processor. For this purpose, the elevator electronics unit can also have an adaptation interface, allowing the add-on processor to be reprogrammed (especially by a customer on-site).In all these cases, the central processor can transmit unchanged instructions to the auxiliary processor for displaying specific information; the auxiliary processor will then visualize this information on the display unit according to customer requirements and / or convert it into a corresponding function / output. Therefore, for example, an operator interface of the elevator system does not necessarily need to communicate bidirectionally with the central processor; bidirectional communication between the central and auxiliary processors, particularly via interrupts, is usually sufficient.

[0060] Alternatively, depending on the application, the additional processor (like the central processing unit) can also be operated using hardware-dependent, especially proprietary, software. While this may have disadvantages for third parties, it leads to greater security for the overall system.

[0061] The at least one additional processor can transmit information to the central processing unit (CPU); however, it is preferred that the respective additional processor cannot control the CPU. This prevents the additional processor from interfering with safety-relevant operations that the CPU must execute reliably. Conversely, it can be provided that the CPU can control the at least one additional processor. For example, the CPU can thus adjust the execution sequence of an instruction by the respective additional processor and / or put the respective additional processor into or wake it from a sleep or hibernation state.

[0062] The elevator electronics unit can include further components: for example, an electronic call interface through which the central processor can receive and evaluate external calls. Furthermore, at least one electronic safety interface through which the central processor can receive and evaluate signals from at least one safety circuit. Depending on its design, the central processor can also control the safety circuit via such an interface, for example, to enable bypassing the safety circuit (as previously explained with reference to the safety chain). And finally, at least one electronic internal communication interface through which the central processor can communicate with at least one additional processor, in particular via another additional processor and / or bidirectionally.It is preferred if the security interface and / or the internal communication interface are each implemented using a BUS system.

[0063] The central processor can thus receive external driving commands via the call interface and translate them into corresponding control commands, actuator control commands (e.g. to open the elevator car door), and / or motor control signals (to control the power output stage).

[0064] Via the safety interface, the central processor can query safety-relevant information from external field devices, in particular sensors and actuators of the elevator system, and / or transmit actuator control commands to such a field device, and / or read a safety circuit, and / or act on the aforementioned safety chain, in particular by bridging a link in the safety chain.

[0065] The central processor can communicate with at least one additional processor via the internal communication interface, thereby receiving central software updates and / or releasing peripheral software updates, as will be explained in more detail later.

[0066] In this context, a bus is understood to be a system for data transmission between multiple participants via a shared transmission path: If data transmission is taking place between two participants, the other participants must remain silent at the same time, as they would otherwise cause interference. Speaking time is distributed according to a (time or signal) schedule known to all participants. Listening, however, is not restricted.

[0067] A preferred embodiment provides that the central processor is configured to collect and document operating parameters during the operation of the elevator system, particularly during automated test runs with the elevator car. Such operating parameters could include, for example: Current consumption of elevator system components, in particular the current consumption of the drive unit and / or a door drive; measured harmonics on current and / or voltage signals, in particular rotary encoder signals; temperatures or temperature profiles over time, in particular within the elevator electronics unit and / or in the power output stage and / or within the elevator motor; slippage of load-bearing elements such as ropes (this can be determined from the rotational speed of the drive unit and the cabin position); error messages; actual travel paths traversed; sensor data from elevator system sensors; states of the safety chain; statistical data, in particular regarding aborted elevator journeys; monitoring data on certain device parameters, e.g.to verify the plausibility of the operation of a fan in the elevator electronics unit; deviations in power demand / current consumption determined during defined test runs; measured or determined holding torques and / or deceleration values ​​of a mechanical motor brake of the elevator system, whereby such parameters can also be recorded by the central processor, particularly through autonomously executed safe test runs; or data regarding the load status of the elevator car (from such data the central processor can implement appropriate responses in case of a fault, for example a warning output inside the elevator car and / or a temporary blocking of elevator operation if a permissible load is exceeded).

[0068] For the purpose of accurately documenting such data / operating parameters, the central processor may, in particular, be equipped with a real-time clock. To collect operating parameters, the central processor may also utilize one of the aforementioned auxiliary processors, for example, if the latter implements a brake monitoring function, which the central processor can then access to collect / document brake parameters.

[0069] The central processor can also be configured to autonomously (i.e., without a human operator) conduct safe test drives without passengers (for example, at night) to collect such operating parameters. For instance, the central processor can safely measure the drive unit's step response by introducing changes in motor speed during such a test drive and recording the drive unit's step response. Such test drives can also be designed as verification drives to check / record specific wear or operating parameters that are not accessible without safety risks during normal passenger-driven journeys.

[0070] Furthermore, the central processor can be configured, for example, to estimate and / or sensor-based measurement of operating temperatures of elevator system components, which are important for evaluating power consumption. For instance, the central processor can use a real-time clock to estimate the cooling of the drive unit over time. Such sensor-based or estimated operating temperatures can then be taken into account when performing test runs and measuring power consumption.

[0071] By collecting such operating parameters, the central processor can also determine at least one wear parameter and / or estimate the remaining service life of at least one elevator component based on these collected parameters. In other words, the central processor can continuously monitor the elevator's condition and / or its wear and tear and, based on such determinations / estimates, initiate maintenance of the elevator and / or the replacement of a component, for example, by sending a corresponding digital message (e.g., a push notification via the internet), for which the central processor can utilize an additional processor.The operating parameters and / or determined wear parameters or remaining service lives stored by the central processor can of course also be retrieved externally, especially via the Internet, whereby one of the additional processors can then forward a retrieval request received via the Internet to the central processor.

[0072] Another desirable functionality that the central processor can implement is the ability to autonomously optimize the operation of the elevator system. For example, based on measured current consumption by a component of the elevator system (especially the drive unit and / or a door drive), the central processor can adjust the control of that component, particularly to enable less wear and tear or improved component performance.For example, safe test runs (which can be considered "reference runs") without passengers in the elevator car (i.e., unloaded) can be carried out within specific timeframes, preferably at night, automatically controlled by the central processor. The central processor can be configured to automatically optimize at least one control parameter using such test runs, particularly taking into account the current temperature of the power output stage and / or the elevator motor. Such control parameters can be, in particular, parameters for current control and / or speed control of the drive unit / elevator motor. The central processor can therefore adjust a current controller and / or a speed controller during optimization.

[0073] Furthermore, the central processor can use autonomous monitoring of the elevator system's operation to record specific user behavior and optimize the elevator's operation based on this monitoring. Such optimization could, for example, result in the central processor autonomously moving the elevator car to specific floors at certain times of day.

[0074] For example, if the central processor detects excessive (electromechanical) load on the drive unit, such as when the temperature of the power output stage and / or the elevator motor exceeds an upper limit ("power output stage and / or motor too hot"), it can extend the door closing time and / or the door opening time (both of which can be summarized as "door movement time"). In this way, the central processor can intelligently provide the drive unit with longer cooling phases during periods of high load (namely, when the elevator car is still stationary because the doors close more slowly / later), without these extended cooling phases being directly noticeable to the user.If, however, the load on the drive unit decreases again, the central processor can, in response to this, for example in response to a drop in the temperature of the power output stage and / or the motor, extend the door closing time and / or the door opening time again in order to accelerate the travel operation (more precisely: the starting after entering the cabin and / or the door opening when a stopping position is reached and / or a travel speed of the elevator cabin).

[0075] The central processing unit (CPU) can also be configured to perform a security check of peripheral software updates obtained from an external source (such as a USB storage device or via a network connection) before installing them on at least one additional processor. Such a peripheral software update can, for example, update and / or customize an additional function performed by the additional processor, particularly according to customer requirements. For this security check, it is preferable that the peripheral software update can only be installed after prior approval by the CPU.

[0076] When verifying and releasing the peripheral software update, it is preferred that the central processing unit (CPU) verifies at least one release condition. For this purpose, the CPU can contact an external instance, particularly via an auxiliary processor, and / or request confirmation from an operator (e.g., by pressing a button on the elevator electronics unit). The verification can also include separate authentication of the peripheral software update, preferably using (very secure) two-factor authentication.

[0077] Two-factor authentication, in this context, can mean that the central processor verifies the legitimacy of updates and additionally obtains confirmation from an operator (who then interacts with the elevator electronics unit on-site). One of the factors could be biometric or hardware-based identification. This ensures the update's legitimacy is reliably verified, and the auxiliary processor can then be updated accordingly. The central processor can thus initiate the actual update process of the auxiliary processor. Both factors of such two-factor authentication can also be obtained via the internet (preferably through an encrypted connection), which can provide sufficient security, for example, for authorizing the installation of a peripheral software update.

[0078] If the central processor, as proposed by the invention, performs all essential safety functions for the operation of the elevator system, it can further be ensured that safety functions cannot be modified by updating the software of at least one additional processor. Therefore, third parties can safely specify or initiate such peripheral software updates. Verifying peripheral software updates can, for example, enhance cybersecurity because it can limit the circle of third parties who can perform or initiate peripheral software updates. According to the invention, peripheral software updates are intended solely to enable the adaptation of certain (comfort) applications. Thus, if the additional processor is reprogrammed by a third party, a conflict with safety-relevant functions of the elevator cannot occur due to the architecture of the elevator electronics unit according to the invention.

[0079] The at least one additional processor can include at least one additional processor configured to perform a security check of a central software update, which is obtained, for example, from an external source (such as a USB storage device or via a network connection). The central software update can / should be installed on the central processor to update it. Such a central software update can therefore be used, in particular, to update and / or adapt a safety-relevant function of the central processor for the operation of the elevator system, such as the aforementioned motor control and / or the previously mentioned operating control. Here, too, for security reasons, it is preferable if the central software update can only be installed on the central processor after it has been approved by the additional processor.

[0080] As with peripheral software updates, it is also preferable for such a central software update if the aforementioned additional processor, in order to release this central software update, contacts an external instance, particularly via another additional processor, and requests confirmation from an operator (e.g., by pressing a button on the elevator electronics unit). This verification / release can therefore include authentication of the central software update, preferably by means of (very secure) two-factor authentication.Since the central software update, as mentioned, can affect safety-relevant functions of the elevator system, it is preferable if at least one of the two factors of the two-factor authentication is not obtained via an external instance, but can only be entered by manually operating a control element (for example, a mechanical button or a virtual button on a touch display) on the elevator system, preferably on the elevator electronics unit (for example, by an on-site service technician). This significantly improves security during the installation of the central software update. In particular, it makes it considerably more difficult to install a corrupted central software update on the central processor via a purely cyberattack, because the control element cannot be manipulated remotely.

[0081] Naturally, the central processor can bring the elevator system to a safe operating state before installing a central software update or a peripheral software update. For example, installing a central software update is prohibited if the central processor is currently performing a ride in the elevator car.

[0082] In the presented approach for the secure installation of a central software update, the additional processor monitors the safety and permissibility of the software update to be installed on the central processor. It is particularly advantageous if the additional processor grants this approval only if at least one further approval condition is met. This approval condition can, in particular, relate to parameters that were recorded and stored during the operation of the elevator system before the central software update was installed. Such recording and storage can be performed, for example, by the central processor itself or by the at least one additional processor.

[0083] The central software update can, for example, be obtained securely via an additional processor that establishes a connection to the internet or another external source (router).

[0084] As mentioned above, a release condition verified by the additional processor could be, for example, a certain minimum number of error-free trips completed by the elevator system within a specific timeframe. Another possible release condition is approval via a separate remote connection, such as by contacting a secure server. The security of this remote connection can be ensured through common technologies like separate authentication, preferably two-factor authentication, and / or encryption (e.g., via a VPN connection). Using these and similar approaches, the central processor can be configured to perform a security check of the central software update to be installed and / or to verify its permissibility via an external instance (such as the aforementioned secure server).

[0085] The additional processor that checks the permissibility of the update of the central processor can either i) be implemented using hardware-independent programmable software or ii) using hardware-dependent, in particular proprietary, software, the design of which therefore depends on the hardware used.

[0086] The at least one additional processor or the central processor can also be configured to perform a downstream security check, i.e., after a central software update is installed on the central processor and / or after a peripheral software update is installed on one of the additional processors. Such a downstream security check can further enhance the operational security of the elevator system with regard to cybersecurity. For this purpose, it is particularly advantageous if the additional processor regularly verifies the validity of the software used by the central processor for its operation.

[0087] Furthermore, it is also possible for the elevator electronics unit to initiate safe test runs (of the elevator car) without passengers. These test runs allow the elevator electronics unit to record operating parameters that can then be considered during the subsequent safety check. This means that the subsequent safety check can include a review of operating parameters collected during such safe test runs initiated by the elevator electronics unit. Such autonomous test runs are only possible because the central processor of the elevator electronics unit, by evaluating information regarding the elevator car's position (and preferably also reading at least one safety circuit) and specifying the travel path, is able to perform such test runs safely and, above all, autonomously.For this purpose, it is preferable if the central processor is configured to check, by reading at least one sensor, whether there are people in the elevator car before carrying out an autonomous test run.

[0088] To further increase the safety of persons, it may also be provided that the elevator electronics unit blocks the operation of the elevator system with persons on board as soon as the aforementioned subsequent safety check reveals / detects a faulty operation of the elevator system or an error in the central software update.

[0089] For example, the elevator electronics unit, in particular the at least one auxiliary processor or the central processor, may be designed to perform safe test runs without passengers in the cabin, for example, at night. It is already common practice in the prior art to conduct, for example, learning runs or test runs to verify the correct functionality of the elevator brakes. The presence of passengers in the cabin can be reliably detected by measuring the cabin's weight. During such test runs, electrical currents or other sensor signals can also be recorded as operating parameters, allowing conclusions to be drawn about the elevator's correct operation.

[0090] If, despite prior safety checks, a faulty update is installed on the central processor, which makes the operation of the elevator unsafe or leads to operational errors, this problem can be detected by carrying out the safe test runs and the operation of the elevator with people can then be blocked by the elevator electronics unit.

[0091] In the case of malicious malware that could reach the central processing unit (CPU) via an update, it's conceivable that the malware might only become active after a certain period of time, meaning the malicious update wouldn't be detected during initial test runs. To prevent this, it can be implemented that the elevator electronics unit automatically performs these safe test runs without passengers at regular intervals, such as daily or weekly. This ensures continuous, automated, and subsequent security checks, which are particularly effective in detecting malicious CPU updates.

[0092] To increase energy efficiency, the power output stage of the elevator electronics unit (together with the central processor) can be designed as an active front-end (AFE) converter. For this purpose, the power output stage can, in particular, include a controlled mains rectifier, which can be implemented, for example, by means of a feed-in and regenerative unit. In such a case, the central processor can be configured to control the AFE converter so that, when the elevator motor is operating in regenerative mode, kinetic braking power can be electrically fed back into an external grid using the AFE converter. In such configurations, the central processor can thus be considered part of the AFE converter.

[0093] The elevator system can therefore be designed to feed electrical power generated in the elevator motor during deceleration, specifically during generator and / or short-circuit operation, back into the grid. In other words, a braking resistor may be unnecessary in such a case. The elevator electronics unit, more precisely the central processor, can control and regulate this electrical regeneration of kinetic braking energy from the elevator system. The central processor can utilize an additional processor for this purpose, controlling it accordingly. The resulting AFE frequency converter, possibly with a regulated mains rectifier, can have active power switches on its input side, for example, in the form of IGCTs (integrated gate-commutated thyristor) or IGBTs (insulated gate bipolar transistor).While this requires more complex control systems, it opens up the possibility of energy recuperation into the grid when the mass of the elevator car (plus any counterweight) driven by the elevator motor needs to be braked during operation. For this purpose, the elevator electronics unit can also include an electrical regenerative braking unit that performs the function of electrically feeding back braking energy. Furthermore, designing the power output stage, including the central processor, as an AFE (Automatic Functional Efficiency) unit enables rapid switching between motor and generator operation of the elevator motor / drive unit.

[0094] For example, if a magnetically excited synchronous motor is used as an elevator motor, it can generate a speed-dependent braking torque that occurs as soon as the motor windings are electrically short-circuited. Such a short-circuit function can be controlled by the central processor; that is, the elevator system, in particular the elevator electronics unit, can include an electronic short-circuit circuit for this purpose, which can be controlled by the central processor. With such a short-circuit circuit, the motor windings of the elevator motor can thus be short-circuited as needed and / or the entire frequency converter can be de-energized.The central processor can use short-circuiting not only for the purpose of recuperating braking energy, but also, for example, in emergency operation to allow the elevator car (especially when using a gearless drive unit) to move safely and passively in the shaft via the electromagnetic braking torque generated by the short circuit. In this case, the elevator car moves only due to its own weight (and any additional load) and is slowed down by the electromagnetic braking torque; however, controlled regenerative operation may not occur.

[0095] The central processor can also be configured to process time-critical and / or real-time relevant signals and / or to generate time-critical and / or real-time relevant engine control commands when executing engine control.

[0096] To solve the aforementioned problem, a method for the safe updating of an elevator electronics unit or elevator system according to the invention is also proposed. The elevator electronics unit is configured according to one of the claims relating to an elevator electronics unit. The method provides that the update is performed by installing a central software update onto a processor, wherein this processor is the central processor of the elevator electronics unit described above. Furthermore, it is provided that the security of the central software update is first checked by an additional processor (which can, in particular, be an additional processor of the aforementioned elevator electronics unit) before the update is installed, and the update is released by this additional processor depending on the test result.It is preferred that the additional processor (for the purpose of release) checks at least one release condition, whereby the additional processor can access an external instance, such as an external secure server, for this purpose. The central software update can be obtained from an external source, for example, from a USB storage device or via a network connection.

[0097] It is particularly advantageous if at least one release condition checked by the additional processor concerns a parameter that was recorded and stored during the elevator's operation, before the central software update was installed. As already mentioned, this can be done by the central processor or by the additional processor.

[0098] Finally, to further improve the safety of an elevator system, another method is proposed which enables a safety check of an elevator electronics unit or elevator system according to the invention following a software update. This method can be used, in particular, as a supplement to or alternative to the methods described above to increase safety. In this second method, the safety check is triggered by installing a central software update on the central processor of the elevator electronics unit, and the permissibility of software used by the central processor for its operation is checked at regular intervals. This safety check can preferably be carried out automatically by the central processor or by an additional processor of the elevator electronics unit (i.e., in particular without external triggering).

[0099] This procedure may also include conducting safe test runs without passengers (preferably automated) of the elevator system for safety verification purposes, recording operating parameters that will be considered in the subsequent safety check. Such operating parameters allow conclusions to be drawn about the correct functioning of the elevator system / elevator electronics unit and thus about the permissibility and safety of the central software update performed.

[0100] The invention will now be described in more detail with reference to exemplary embodiments, but is not limited to these. Further embodiments of the invention can be derived from the following description of a preferred embodiment in conjunction with the general description, the claims, and the drawings. In the following description of various preferred embodiments of the invention, elements that are functionally identical are assigned the same reference numerals even if they differ in design or shape.

[0101] It shows: Fig. 1 a schematic view of a first elevator electronics unit according to the invention with a central processor, Fig. 2 a schematic view of a second elevator electronics unit according to the invention, Fig. 3 a schematic view of a third elevator electronics unit according to the invention, Fig. 4 a schematic view of a fourth elevator electronics unit according to the invention, Fig. 5 a schematic view of a fifth elevator electronics unit according to the invention, Fig. 6 illustrates a safe update process of an additional processor, Fig. 7 illustrates a safe update process of the central processor, i.e., a software update is applied to the central processor, and finally Fig. 8 details of the direct communication between the central processor and the power output stage of an elevator electronics unit according to the invention.

[0102] Figure 1Figure 1 shows an elevator electronics unit 1 according to the invention, which is designed and can be used to control an elevator motor 3 of a complex elevator system 28. For this purpose, the elevator electronics unit 1 comprises a processor 11, which implements a control CPU that communicates with external senders 27, for example, an elevator user who makes an input via an operating interface. The control CPU 11, which is designed as a central processing unit 4, thus receives external calls and, in response, generates a suitable control signal for the elevator motor 3 in order to approach a specific elevator stop with an elevator car 20 of the elevator system 28 that corresponds to the received call.

[0103] The central processor 4 thus implements a motor frequency converter CPU that generates motor control signals 42 and transmits them to a power output stage 2 as part of the elevator electronics unit 1 (black block arrow). The central processor 4 and the power output stage 2 therefore form a frequency converter 39. Based on the motor control signals 42, the power output stage 2 generates a suitable AC output voltage 38 in a known manner to operate the elevator motor 3 and to move the elevator car 20, suspended by means of suspension elements 15, accordingly in the hoistway. In doing so, the central processor 4 reads a hoistway position sensor or other field devices 24 as needed, which are relevant for the safe operation of the elevator 22. In this way, the central processor 4 can reliably control the operation of the elevator system 28.

[0104] The central processor 4 of the elevator electronics unit 1 of the Figure 1The central processor 4 can not only communicate directly with the power output stage 2 to implement motor control 37, but also read a safety circuit 23 via an electronic safety interface 7, which in turn queries information from safety-relevant field devices 24 or other sensors 25. The central processor 4 thus takes over basic functions of elevator operation, such as approaching a desired elevator stop, since the central processor 4 reacts to incoming (i.e., external) digital calls from external transmitters 27 by generating corresponding motor control signals 42 and transmitting them directly to the power output stage 2.

[0105] Within the framework of motor control 37, the central processor 4 directly controls the power output stage 2 by means of the motor control signals 42 and thus, mediated by the power output stage 2, controls the elevator motor 3 according to the received call. For this purpose, the central processor 4 generates a respective travel curve based on the incoming external call and taking into account at least one piece of information regarding the current position of the elevator car 20, and derives the corresponding motor control signals 42 from this travel curve. The central processor 4 generates the travel curve in segments, so that updated motor control signals 42 are output from the central processor 4 to the power output stage 2 at regular intervals.

[0106] As the Figure 8As illustrated, the central processor 4 can have at least one analog signal output 43 and / or at least one PWM unit 44, each of which is / are directly connected to the power output stage 2 in order to transmit analog signals and / or PWM signals 40 as motor control signals 42 directly to the power output stage 2. It can be seen in Figure 8 but also that the power output stage 2 can include a hardware circuit 45, for example to convert a PWM signal 40 into corresponding analog control signals for controlling power switches of an inverter circuit 46 of the power output stage 2.

[0107] In Figure 1It can also be seen that the elevator electronics unit 1 has several electronic call interfaces 6, via which the central processor 4 can communicate digitally with external transmitters 27. In this way, the central processor 4 can, for example, receive external calls from the elevator shaft, from a display, or from an operator interface of the elevator 22. As illustrated, the central processor 4 can also, for example, access an external network node 29 in this way, which in turn may itself include its own CPU.

[0108] The central processor 4 also controls the door drive of the elevator car 20. In this process, the central processor 4 detects, through communication with zone magnets located in the elevator shaft, when the car 20 enters a door zone. In this case, the central processor 4 bypasses a link in the elevator system's safety chain. By thus controlling the safety chain, the central processor 4 enables the doors to open early (by activating the door drive) even before the car has reached a safe final stopping position within the door zone.

[0109] Characteristic of the in Figure 1The presented architecture of the elevator electronics unit 1 according to the invention is thus that the central processor 4, within the framework of the motor control 37, controls the power output stage 2 in order to control and regulate the elevator motor 3 and thus define the elevator operation, and that furthermore the central processor 4 performs basic functions of the elevator operation, namely responding to external calls, defining a travel curve for the elevator operation and evaluating the aforementioned safety circuit 23. Within the framework of the motor control 37, the central processor 4 implements time-critical operations that must be executed in less than 1 ms.

[0110] At the same time, the central processor 4 also handles the operation control of the elevator system 28, which includes numerous non-time-critical operations that can be processed at a lower speed. This is possible because the central processor 4 has a system of intelligent interrupts, allowing time-critical and non-time-critical operations to be processed sequentially, one after the other, and in order of priority.

[0111] Figure 2 shows another possible embodiment of an elevator electronics unit 1 according to the invention, which, however, in comparison to the Figure 1 , includes an additional processor 5a. This additional processor 5a performs an additional function and thus expands the functionality of the central processor 4 modularly, because the additional function can be easily added or omitted by adding / removing the additional processor.

[0112] In the example shown, the Figure 2 The central processor 4 communicates via the auxiliary processor 5a with a feed-in and feed-back unit 13, through which the power output stage 2 can draw power from the power grid 12 or feed power back into it. Such feed-back can occur, for example, when the elevator motor 3 is operated in generator mode and used to brake the elevator car 20, in which case the resulting kinetic braking energy is converted into electrical power, which flows back into the power grid 12 via unit 13. Thus, the central processor 4, with the aid of the auxiliary processor 5a, implements an electrodynamic braking function or an energy recuperation function.

[0113] In the example of the Figure 3 The elevator electronics unit 1 is otherwise analogous to that of the Figure 2 or Figure 1The system is designed with an additional auxiliary processor 5b, whereby the central processor 4 communicates with the two auxiliary processors 5a and 5b via respective internal communication interfaces 8, which are implemented by means of a bus system 10. As can be seen in the Figure 3 Upon detection, an additional electronic call interface 6c is created by means of the additional processor 5b, via which the central processor 4 can communicate with further peripheral devices 26, mediated by the additional processor 5b. The additional processor 5b is operated by means of hardware-independent software, namely a Linux operating system.

[0114] In the example of the Figure 4 The second additional processor 5b also takes on the function of a router 18 and thus mediates between the central processor 4 and an external instance 19 such as the Internet or a cloud.

[0115] In the further example of the Figure 5However, a third additional processor 5c is provided, which here takes on the function of such a router 18. With this approach, calls from a remote control 31 or other (e.g., distant) external transmitters 27 can also be received. Using the BUS system 10, the central processor 4 can again access these external information sources 19, 27, 31 via the additional processor 5c, or receive calls from them and convert them into corresponding operations. With this architecture, for example, an evacuation of the elevator 22 can be initiated via a remote control 31 without the central processor 4 needing a direct connection to the internet. To ensure security, authentication queries and the like can be implemented.

[0116] Since the central processor 4 can communicate with numerous components of the elevator system 28, particularly digitally, it can also collect and document operating parameters during the operation of the elevator system 28. This includes, in particular, the documentation of error messages and the actual travel paths completed by the elevator car 20. The central processor 4 also autonomously performs safe test runs at night without passengers in the elevator car 20, measuring the current consumption of the drive unit as well as other operating parameters. From these collected operating parameters, the central processor 4 then determines estimated values ​​for the remaining service life of individual components. If such a remaining service life is too short, the central processor 4 (with the help of the additional processor 5c) can send a push notification via the internet, thus initiating maintenance of the elevator system 28. The push notification can include information about which component needs to be replaced or serviced.If, for example during a night test run, a significant deviation in the current consumption or an impermissible step response of the drive unit is detected by the central processor 4, it can also autonomously adjust the motor control 37 and thus autonomously optimize the operation of the elevator system 38.

[0117] The Figure 6Figure 1 illustrates a method according to the invention by which the central processing unit 4 can release a peripheral software update that is to be installed on one of the additional processors 5 of the elevator electronics unit 1. Such a software update can, for example, be retrieved via the additional processor 5c from an external instance 19, such as a secure server. According to the invention, it is provided that—before the peripheral software update is installed on the respective additional processor 5—the central processing unit 4 first checks the permissibility and security of this update. For this purpose, the central processing unit 4 checks a release condition.For example, two-factor authentication can be used as an authorization condition, whereby the central processing unit 4 accesses the external server 19 via the auxiliary processing unit 5c and, furthermore, requests confirmation by means of an operator prompt 33, which a service technician must enter manually using the input device 35 shown. The central processing unit 4 can thus first verify the permissibility of the update via the external server 19 using a security prompt 34 and, furthermore, ensure via the operator prompt 33 that the software update is actually desired and can be carried out securely at this time because it has been authorized by the service technician.

[0118] The Figure 7In contrast, this illustrates the case where a central software update is to be installed on the central processor 4. This software update can also be obtained, for example, via router 18 from an external instance 19 or, in a familiar manner, from an electronic storage device such as a USB stick, which is inserted into a corresponding interface of the elevator electronics unit 1. In this case as well, the central software update is only installed on the central processor 4 after it has been authorized, but this authorization is carried out by one of the additional processors 5 of the elevator electronics unit 1.The responsible additional processor 5 checks at least one release condition for this purpose. It can be particularly advantageous if this release condition concerns parameters, such as the number of successfully completed trips of the elevator system 28, which were recorded and saved during the operation of the elevator system 28 before the software update was installed. To prevent any impairment of safety-relevant functions of the elevator system 28 by installing the central software update, the additional processor 5 only releases the central software update if two-factor authentication has been successfully performed. One of the two factors of this authentication cannot be entered remotely, but must be entered on-site by a service technician by manually operating a control element of the elevator electronics unit 1.

[0119] Based on the Figure 1, which represents approximately a minimal solution of an elevator unit 1 according to the invention, it can also be easily understood how a subsequent safety check can be carried out with this system, which is only performed after a central software update has been installed on the central processor 4: For this purpose, it can be provided that said installation first triggers the safety check. The central processor 4 can then, for example at regular intervals and / or especially at night, carry out safe test runs without persons in the elevator car 20 with the elevator 22 and thereby collect (i.e., record and store) operating parameters, which can be sensorially recorded, for example, via connected field devices 24.Once a sufficient number of such safe test runs have been carried out, the central processor 4 can then perform the safety check based on these collected operating parameters / data and thus decide whether the operating parameters document the correct functioning of the elevator system 28 and thus whether safe operation of the elevator 22 can be guaranteed even after the central software update has been installed. If, however, the safety check fails, the central processor 4 blocks further operation of the elevator 22, at least as soon as there are people in the elevator car 20.

[0120] In summary, an intelligent elevator electronics unit 1 is proposed with a central processor 4 that implements both direct motor control 37, encompassing time-critical motor control commands, and performs basic elevator operation functions such as responding to external calls, specifying a travel curve, or evaluating a safety circuit 23 of the elevator system 28 in which the elevator electronics unit 1 is used to control an elevator motor 3. The elevator electronics unit 1 also includes the power output stage 2 necessary for operating the elevator motor 3 and can additionally include one or more auxiliary processors 5 with which the functionality of the elevator electronics unit 1 can be modularly expanded.With this architecture, it is particularly possible to safely perform software updates of the central processor 4 and / or an additional processor 5, to carry out a subsequent security check of such a software update, or to autonomously optimize the operation of the elevator system 28 with the help of the central processor 4. Reference symbol list

[0121] 1 Elevator electronics unit / elevator control device 2 Power output stage (generates 38 for operation of 3; part of 39) 3 Elevator motor 4 Central processor (controls 3 indirectly and 2 directly) 5 Auxiliary processor (communicates with 4; can establish a connection between an external network, e.g. the Internet, and 4 if necessary). 6 Electronic call interface 7 Electronic safety interface 8 Electronic internal communication interface 9 Serial interface 10 Bus system 11 Processor (especially designed as a microprocessor or microcomputer) 12 Power grid 13 Input and feedback unit (for drawing power from 12 or feeding power back into 12) 14 Signal path (especially as part of 10) 15 Support element (e.g., steel cables) 16 Electrical connection (especially bidirectional) 17 Housing 18 Router 19 External instance (Internet / Cloud / Server) 20 Elevator car 21 Counterweight 22 Elevator 23 Safety circuit (especially implemented as a hardware circuit) 24 Field device (e.g., .Shaft position sensor) 25 Sensor / actuator 26 Peripheral device (not safety-critical) 27 External transmitter (e.g., elevator user, external calls, from the shaft box / inspection box, from a display or from an operator interface) 28 Elevator system 29 Network node (possibly with its own processor / CPU) 30 Hardware-independent software 31 Remote control (from 22 / 28 mediated by 1) 32 Input stage (AC / DC converter, provides DC voltage for 2) 33 Operator query (= 1st factor) 34 Safety query (= 2nd factor) 35 Input device (operating button, smartphone with app, etc.) 36 Safety check 37 Motor control 38 Output AC voltage (generated by 2 based on 40 / 42) 39 Frequency converter 40 Analog signal or PWM signal 41 Error message 42 Motor control signal 43 Analog signal output 44 PWM unit 45 Hardware circuit (in particular comprising a low-pass filter for filtering a PWM signal) 46 Inverter circuit (with power transistors) 47 Drive unit

Claims

1. Elevator electronic unit (1) for controlling elevator operation of an elevator system (28), comprising the following components, which are preferably housed in a common housing: - a power output stage (2) for supplying an elevator motor (3) of the elevator system (28) with an AC output voltage (38), and - a processor (11), characterized in that - the processor (11) is designed as a central processor (4) and is configured to directly control the power output stage (2) within the framework of a motor control system (37) via motor control signals (42) without any intermediate instance in order to control and regulate the elevator motor (3) via the power output stage (2), - wherein the central processor (4) comprises at least one analog signal output (43) and / or at least one PWM unit (44) for this purpose, which is / are directly connected to the power output stage (2), and - wherein the central processor (4) is further configured to perform basic functions of elevator operation, specifically responding to external calls, in particular digital calls, from external transmitters (27, 31) by generating and outputting the corresponding motor control signals (42) based on a respective travel curve for elevator operation, - in particular in order to travel to a specific elevator stop with an elevator car (20) of the elevator system (28).

2. Elevator electronic unit (1) according to claim 1, - wherein the central processor (4) is configured to predetermine the respective travel curve, taking into account a received external call and evaluation of at least one piece of information relating to a current position of the elevator car (20) of the elevator system (28), - in particular wherein the piece of information is queried by the central processor (4) itself, e.g. by a sensor and / or based on a virtual image of the elevator system (38), or based on an evaluation of a safety circuit (23), and / or - wherein the central processor (4) together with the power output stage (2) implements a frequency converter (39).

3. Elevator electronic unit (1) according to one of the preceding claims, wherein the central processor (4) is configured to implement - the motor control system (37) of the elevator motor (3), which comprises time-critical operations that must be executed in less than 1 ms, and - a travel operation control of the elevator system (28) comprising less time-critical operations, which can be executed in more than 1 ms, or non-time-critical operations, which must be executed within 10 ms, - preferably wherein the central processor (4) is configured to process the motor control system (37), in particular the time-critical operations, with priority over the travel operation control, in particular the non-time-critical operations, preferably sequentially and / or by means of a time multiplex process, and / or - wherein the central processor (4), in particular at least one processor core of the central processor (4), is configured, when executing the motor control system (37), to - process time-critical or real-time relevant signals and / or - generate time-critical or real-time relevant motor control signals (42).

4. Elevator electronic unit (1) according to one of the preceding claims, wherein the elevator electronic unit (1) comprises at least one additional processor (5) which is configured to perform at least one additional function which modularly supplements a functional scope of the central processor (4), preferably wherein the at least one additional processor (5) - is plugged into a mainboard on which the central processor (4) is implemented, and / or - is adapted to communicate with the central processor (4) via a serial interface (9), in particular in the form of a BUS system (10) for data transmission, and / or - is adapted to communicate with the central processor (4) via a dual-ported RAM.

5. Elevator electronic unit (1) according to claim 4, - wherein the at least one additional processor (5) is operated / can be operated with standardized hardware-independent programmable software (30), in particular a standardized hardware-independent operating system such as LINUX, or comprises such software, or - wherein the at least one additional processor (5), in particular without its own operating system, communicates with the central processor (4) on the basis of interrupts, in particular bidirectionally, - preferably wherein the at least one additional processor (5) is configured to trigger a central interrupt of the central processor (4) in order to thus trigger a central interrupt service routine of the central processor associated with this central interrupt, and / or - wherein the central processor (4) is configured to trigger a peripheral interrupt of the at least one additional processor (5) in order to trigger a peripheral interrupt service routine of the at least one additional processor (5) associated with this peripheral interrupt.

6. Elevator electronic unit (1) according to one of the two preceding claims, wherein the at least one additional processor (5) is adapted to transmit information to the central processor (4), but is not adapted to access the central processor (4) in a controlling manner, - preferably while conversely the central processor (4) is configured to access the at least one additional processor (5) in a controlling manner, - in particular in order to adapt a sequence of an instruction execution of the at least one additional processor (4) and / or in order to put the at least one additional processor (4) into a sleep mode or idle state or to wake the at least one additional processor (4) up from such a state.

7. Elevator electronic unit (1) according to one of the preceding claims, wherein the central processor (4) is configured to: - effect door control, e.g. by activating a door drive of the elevator car (20), and / or to - monitor an instantaneous state of a safety chain of the elevator system (28), preferably continuously, and / or to - act in a controlled manner on the safety chain of the elevator system (28) as a function of at least one received sensor signal, - and / or wherein the elevator electronic unit (1) further comprises as further components: - an electronic call interface (6), via which the central processor (4) is adapted receive and evaluate the external calls, and / or - at least one electronic safety interface (7), via which the central processor (4) is adapted to receive and evaluate signals from the at least one safety circuit (23) and / or have a controlling effect on the safety circuit (23), and / or - at least one electronic internal communication interface (8), via which the central processor (4) is adapted to communicate with the at least one additional processor (5), preferably bidirectionally, - preferably wherein the safety interface (7) and / or the internal communication interface (8) are implemented by means of a BUS system (10).

8. Elevator electronic unit (1) according to one of the preceding claims, wherein the central processor (4) is configured to collect operating parameters, such as: - current consumption of components of the elevator system (28), and / or - temperature curves, and / or - error messages, and / or - travel curves actually traveled, and / or - sensor data, during operation of the elevator system (28), in particular by autonomously performed safe test drives without passengers, and documenting the same, and / or for determining - based on collected operating parameters - at least one wear parameter, and / or - an estimate of the remaining service life of at least one component of the elevator system (28), preferably initiating maintenance of the elevator system (28) and / or replacement of a component of the elevator system (28), in particular by means of a push message, on the basis of such determinations / estimates, and / or - to perform autonomous optimization of the travel operation of the elevator system (28), e.g. adjustment of the control of a component of the elevator system (28) based on the power consumption collected during operation.

9. Elevator electronic unit (1) according to one of claims 4 to 8, wherein the central processor (4) is configured to perform a security check of a peripheral software update which is to be obtained from an external source, e.g. a USB memory device or via a network connection, and is to be installed on the at least one additional processor (5), in particular in order to update or adapt an additional function executed by the additional processor (5), - preferably wherein the peripheral software update is only to be installable on the additional processor (5) after it has been released by the central processor (4).

10. Elevator electronic unit (1) according to one of claims 4 to 7, wherein the at least one additional processor (5) comprises a further additional processor (5) which is set up to perform a security check of a central software update which is to be obtained from an external source such as a USB memory device or via a network connection, and is to be installed on the central processor (4), - in particular in order to update and / or adapt a function of the central processor (4) which is relevant to safety for the travel operation of the elevator system, in particular the said motor control and / or travel operation control, - preferably wherein the central software update is only installable on the central processor (4), based on a secure 2-factor authentication, after it has been released by the additional processor (5), - particularly preferably wherein at least one of the two factors of the two-factor authentication can only be entered by manually operating a control element, and / or - wherein the additional processor (5) only grants the release if at least one further release condition is fulfilled, - preferably wherein the release condition relates to parameters that were recorded and stored during travel operation of the elevator system (28) prior to the installation of the central software update, in particular by the central processor (4) or by the at least one additional processor (5).

11. Elevator electronic unit (1) according to one of the preceding claims, wherein the at least one additional processor (5) or the central processor (4) is configured to perform a downstream security check after a central software update has been installed on the central processor (4), - preferably - in that the auxiliary processor (5) checks at regular intervals the permissibility of software used by the central processor (4) for its operation and / or - in that safe test runs are initiated without passengers by the elevator electronic unit (1) in order to record operating parameters that are taken into account in the subsequent security check, - in particular wherein the elevator electronic unit (1) blocks travel of the elevator system with persons as soon as the downstream security check reveals faulty operation or an error in the central software update, and / or - wherein the power output stage (2) comprises part of an active front-end (AFE) converter (39), in particular with a regulated mains rectifier, and the central processor (4) is configured to control the AFE Converter (39) such that, when the elevator motor (3) is operating in a regenerative mode, kinetic braking power is adapted to be fed back electrically into an external network (12) using the AFE Converter (39).

12. Elevator system (28), comprising: - an elevator car (20), - associated support means (15), - a drive unit (47) with elevator motor (3) and - an elevator electronic unit (1) according to one of the preceding claims, with which the elevator motor (3) is controlled or is adapted to be controlled.

13. Method for securely updating an elevator electronic unit (1), which is designed according to one of claims 1 to 11, characterized in that - an update is performed by installing a central software update on the central processor (4) of the elevator electronics unit (1), - the security of the central software update is checked by an additional processor (5) of the elevator electronic unit (1) before the central software update is installed, and the additional processor (5) releases the central software update depending on a result of the check, - preferably wherein the additional processor (5) checks at least one release condition for release, in particular by means of an external instance such as an external secure server, - in particular, wherein the central software update is obtained from an external source, for example from a USB memory device or via a network connection.

14. Method according to one of the preceding claims, wherein the release condition relates to parameters that were recorded and stored during the operation of an elevator system (28) comprising the elevator electronic unit (1) and prior to the installation of the central software update, preferably by the central processor (4) or by the additional processor (5), and / or - wherein verification of the central software update comprises authentication, preferably a two-factor authentication.

15. Method for a downstream autonomous security check of an elevator electronic unit (1) according to one of claims 1 to 11 or an elevator system (28) according to claim 12, characterized in that - the security check is triggered by installing a central software update to the central processor (4) of the elevator electronic unit (1), and - the admissibility of software used by the central processor (4) for operation thereof is checked at regular intervals, - preferably wherein the security check is performed automatically, in particular without external triggering, by a processor (11), in particular the central processor (4) or an additional processor (5) of the elevator electronic unit (1), - wherein, in particular, for the security check, safe test drives without passengers are carried out with the elevator system (28), and operating parameters are recorded in this process which are taken into account in the subsequent security check.