Remote fault detection for elevators, escalators and automatic doors

ES2904558T5Active Publication Date: 2026-07-13KONE OYJ

Patent Information

Authority / Receiving Office
ES · ES
Patent Type
Patents
Current Assignee / Owner
KONE OYJ
Filing Date
2017-06-14
Publication Date
2026-07-13

AI Technical Summary

Technical Problem

Existing methods for addressing faults in elevators, escalators, and automatic doors require on-site technician intervention, leading to increased costs and time, especially when passengers are trapped, which is inefficient and inconvenient.

Method used

A method and device for remote fault suppression that allows faults to be cleared remotely by activating a rescue operation function (RDF) switch, determining fault type suitability for remote suppression, and initiating suppression instructions from a service center via connectivity monitoring.

Benefits of technology

Reduces the time and cost of fault resolution by enabling remote fault suppression, minimizing passenger confinement and technician calls.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000009_0000
    Figure 00000009_0000
  • Figure 00000010_0000
    Figure 00000010_0000
  • Figure 00000011_0000
    Figure 00000011_0000
Patent Text Reader

Abstract

A procedure for controlling a device, such as an elevator, an escalator, or automatic doors, comprising the procedure the detection (S1) of an appliance malfunction characterized by A fault is recorded in a fault memory or fault register, and the procedure also includes the reception (S2) of a remote fault suppression instruction, the suppression (S3) of one or more faults from the fault memory or fault register, and the exit from a fault state of a controller (11) of the device related to the detected fault, and the introduction (S4) of an operating mode to control the device.
Need to check novelty before this filing date? Find Prior Art

Description

Remote fault detection for elevators, escalators and automatic doors Field of invention The present invention relates to an apparatus, a procedure and a computer program product for executing a remotely activated rescue operation in an elevator, an escalator and automatic doors (e.g., automatic building doors) in the event of a breakdown. Related background technique The subsequent description of the prior art and examples may include insights, discoveries, concepts, or disclosures, or associations, together with disclosures not known in the relevant prior art, and with respect to at least some examples of embodiments of the present invention but provided by the invention. Some of these contributions of the invention may be specifically highlighted in the following lines, while other configurations of the invention of the type indicated will become evident in relation to the context. Some examples in this disclosure relate to elevators. An elevator may stop due to a breakdown or malfunction between floors, trapping passengers inside the car. Some breakdowns require a shutdown sequence and / or activation of the Rescue Drive Function (RDF), that is, intervention by a service technician. More specifically, in some cases, when the elevator control software detects a malfunction, the elevator stops immediately. If the car is moving between floors with passengers inside, they could become trapped. Rescue is only possible when a maintenance technician receives a notification, accesses the installation, and restarts the elevator's power supply or activates service mode to restore normal operation. For example, when an elevator malfunction occurs, this malfunction can be classified and indicated by a fault code. Based on this fault code, rescue measures can be specified. Thus, for example, if such a rescue measure includes operations such as "shutdown," "shutdown and restart," "manual restart for machine room inspection," "machine room inspection maneuver," or "inspection maneuver," a technician receives the notification, accesses the installation, and either restarts the power cycle (i.e., switches the power supply on and off) of the elevator or activates service mode with an RDF switch to free any trapped passengers. If the elevator remains malfunctioning, the necessary corrective actions are taken to eliminate the cause of the malfunction. Therefore, a technician needs to access the installation and perform a procedure to fix the fault / malfunction. For example, the technician may perform a power cycle refresh (also referred to as "off-on") by manually disconnecting the power supply to the control system to reset the system or by activating an RDF (rescue maneuver feature) switch in the engine room or on the cab ceiling. Figure 5 shows a simplified system state machine. That is, after a successful "power-on sequence" state (ST51) ("true") is executed, a normal operating state ("normal operating mode") (ST42) is entered. If a fault is detected during this state, a "faulty" state (ST53) is entered. The fault can be resolved by a technician activating the RDF switch, and the system can then re-enter the "normal operating mode" state. Alternatively, the technician can fix the fault by performing a power cycle. In this case, the system will re-enter the power-on sequence, and after successful power-on, the "normal operating mode" state is re-entered. Another alternative is that the fault may be resolved by other locally detected issues that are manually addressed by the technician at the installation site.The "normal operating mode" state can then be restored. Thus, the described procedure involves costs and time, during which passengers are trapped inside the cabin. Similar problems can also occur with escalators or automatic doors. US patent 2007 / 261924 A1 discloses a control method for an apparatus that is an elevator, escalator, or automatic door as described in the preamble of claim 1, and a control device provided for said apparatus as described in the preamble of claim 8. In particular, it describes a remote control of an elevator, in which an evaluation is made as to whether a control action to be executed is selected based on image information and / or elevator status data, and an assessment is made as to whether the control action involves a risk of injury.If there is no risk of injury, then the control action is initiated from the remote terminal. US patent 7350626 B2 discloses a Power-On Reset (POR) for an elevator controller, which can be activated internally or by remotely operated power relays that interrupt power to the controllers. This POR can be instructed by maintenance personnel at a remote station via transmission, or by a remote elevator monitor, or alternatively, by an elevator controller using its own elevator diagnostics, which identify the elevator malfunction that a POR can resolve. US patent 20157251875 A1 discloses a procedure for resetting a safety system in an elevator installation. As described in the abstract, the elevator safety system is only reset in response to a reset request, when the safety system's verification of the reset request is deemed valid. Summary of the invention Thus, it is an object of the present invention to overcome these drawbacks and provide a procedure and a device for controlling an elevator, escalator, or automatic doors, by which the costs and time required to fix a breakdown / malfunction of the elevator, escalator, or automatic doors can be reduced. According to a first aspect of the present invention, this object is achieved by means of a procedure for controlling an apparatus that is an elevator, an escalator or automatic doors according to claim 1. According to a second aspect of the present invention, the required object is achieved by means of a control device for controlling an apparatus that is an elevator, an escalator, or automatic doors according to claim 8. The first and second aspects can be modified as follows: It can be determined, after receiving the remote fault suppression instruction, whether the detected fault allows remote suppression of the controller fault, and one or more controller faults can be suppressed only when the detected fault allows remote suppression of the fault. Appliance malfunctions can be classified into different types of malfunctions, and it can be determined, based on the type of malfunction detected, whether the detected malfunction allows for remote suppression of the malfunction. The remote fault suppression instruction can be received from a service center by means of a connectivity / remote monitoring device. The remote fault suppression instruction can be initiated by a person or by a software algorithm. Similarly, the suppression of one or more faults can be carried out by activating a rescue maneuver function (RDF) switch on the controller. The elimination of one or more faults may include the elimination of all faults or the elimination of faults that prevent the appliance from returning to a predetermined operating mode. According to a third aspect of the present invention, a system is provided comprising a control device according to the second aspect and / or any of its modifications and a service center configured to send the remote fault suppression instruction to the control device by means of a remote connectivity / monitoring device. According to a fourth aspect of the present invention, a software product is provided comprising a code medium for executing a procedure according to the first aspects referred to above and / or any of the modifications thereof described above when executing a processing medium or module. The software product can be incorporated into a computer-readable medium, and / or the software product can be directly loaded into the internal memory of the computer and / or transmitted over a network by means of at least one procedure involving upload, download, and push. Brief description of the drawings These and other objects, features, details, and advantages will become clearer from the subsequent detailed description of embodiments of the present invention, which should be considered in conjunction with the accompanying drawings, in which: Figure 1 shows an elevator control apparatus according to some embodiments of the present invention, Figure 2 shows a procedure for controlling an elevator according to one embodiment of the present invention. Figure 3 shows a more detailed procedure for controlling an elevator according to one embodiment of the present invention. Figure 4 shows a state diagram illustrating different states of a procedure for controlling an elevator according to one embodiment of the present invention, and Fig. 5 illustrates a simplified system state machine for fixing an elevator breakdown / malfunction according to the prior art. Detailed description of implementation methods The following describes embodiments of the present invention. It should be understood, however, that the description is provided by way of example only and that the embodiments described should in no way be considered as limiting the scope of the present invention. It should be emphasized that the following examples and embodiments should be considered illustrative only. Although the descriptive report may refer to "one" or "some" example(s) or embodiment(s) in various locations, this does not necessarily mean that each of these references relates to the same example(s) or embodiment, or that the feature applies only to a single example or embodiment. The unique features of different embodiments may also be combined to provide other embodiments. Likewise, terms such as "comprising" and "including" should be considered as not limiting the embodiments described to only those features mentioned; such examples and embodiments may also contain features, structures, units, modules, etc.that have not been specifically mentioned. The general elements and functions of the elevator systems described, the details of which also depend on the specific type of elevator system, are well known to experts in the field, and therefore a detailed description of them will be omitted from this document. However, it should be noted that various additional devices and functions, besides those described in more detail later, may be considered in elevator systems. Figure 1 shows a schematic diagram illustrating a configuration of a control device 1 in which several embodiments can be implemented. Specifically, the elevator control device comprises a processor or controller 11. The elevator control device may also include a memory 12 in which programs are developed and required data is stored, and input / output units 13 through which control signals can be transmitted to other control units, elevator transmissions, etc., and / or signals from sensors or other control units can be received. The controller 11 shown in Figure 1 can be configured to perform a procedure as illustrated in Figure 2. In stage S1, a fault is detected. For example, in response to this detection, a remote service center may be notified of the fault. In stage S2, a remote fault clearing instruction may be received, for example, from a remote service center. Then, in stage S3, one or more faults in an elevator control unit are cleared, and the control unit exits a fault state. Finally, in stage S4, the operating mode for controlling the elevator is entered (i.e., normal elevator operation). Thus, a remote fault suppression instruction can be received, and one or more faults in the elevator control unit can be suppressed. The system can then exit the fault state and subsequently return to normal operating mode (e.g., the "normal operating mode" state shown in Fig. 5). The control unit from which one or more faults are to be suppressed can be the controller 11 shown in Fig. 1, but it can also be another control unit related to the detected fault. For example, when the fault is caused by a separate motor controller, fault suppression can be performed on only that controller. Therefore, according to embodiments of the present invention, remote fault detection is performed, so that a malfunction of a device, such as an elevator, escalator, or automatic doors, can be quickly repaired. This reduces both the costs and the time required to repair a malfunction. The term "remote fault suppression," as used herein, means that an instruction is sent remotely to a device, and that the device, after receiving the instruction, suppresses the faults (which are recorded in a fault memory or fault register, for example) and exits the fault state. Fault suppression means that one or more faults stored, for example, in a fault memory or fault register of the controller are suppressed. For example, all faults can be suppressed. Furthermore, for example, faults that prevent the device from returning to a predetermined operating mode can be suppressed. The predetermined operating mode can be the normal operating mode described earlier in connection with step S4. In other words, the predetermined operating mode, or normal operating mode, can be a normal service mode. The normal service mode is the operating mode in which the device is when it is started and reaches a fully operational state. That is, the normal service mode can be an operating mode in which passengers can be transported (as in the case of an elevator or escalator) or in which automatic doors can open and close automatically.In other words, the default operating mode may be the operating mode the device was in when the fault caused the controller to enter fault mode. Examples of faults that cause the controller to enter a fault state and that can be addressed by fault suppression include voltage drops or other disturbances in an electrical power supply network. However, the invention is not limited to these examples, and various other types of faults are possible. Furthermore, when a fault is detected in the device, this fault can be stored / recorded in the controller (for example, in the fault memory or fault log). Therefore, in this case, fault suppression can refer to the removal of this specific fault that has been stored / recorded in the controller. Furthermore, according to some embodiments, fault suppression can be performed by remotely activating a rescue function switch (RDF). Activating the RDF suppresses one or more (or all) of the fault signals; that is, it performs a "fault suppression" operation. Specifically, the suppression of one or more (or all) faults can be accomplished by activating a rescue function switch (RDF) located in the controller. For example, when the remote fault suppression instruction is received by the elevator control device 1 shown in Fig. 1, the processor 11 can activate the RDF switch. In this way, remote activation of the RDF is achieved. Fig. 3 shows a modified procedure, in which it is considered that, depending on the type of fault detected, a remote fault suppression instruction cannot be allowed. In particular, the procedure according to Fig. 3 further comprises steps S5 and S6, which are described below. In stage S5, which is performed after receiving the remote fault suppression instruction in stage S2, it is verified whether the detected fault allows for remote suppression. For example, there may be application standards that prohibit remote fault suppression for certain types of faults and require manual intervention by a technician. If this is not the case (YES in stage S5), then stages S3 and S4 follow as described above in connection with Fig. 2. However, when the detected fault does not allow for remote fault suppression (NOT in stage S5), a default fault procedure is then carried out. For example, the elevator may be taken out of service, and a technician must access the installation area and manually repair the elevator fault / malfunction. To decide whether the fault allows for remote fault suppression, faults can be classified into different types of faults (and optionally be indicated by fault codes), and it can be determined, based on the type of fault detected, whether the detected fault allows for remote fault suppression. Likewise, a system according to some embodiments of the present invention comprises a control device as shown in Fig. 1, configured to carry out the procedure shown in Fig. 2, and a service center configured to send a remote fault suppression instruction to the control device by means of a connectivity / remote monitoring device. Therefore, according to embodiments of the present invention, a troubleshooting procedure is applied, in which remote fault suppression is performed via a communications interface. Specifically, the remote fault suppression instruction does not restart the power cycle, but rather instructs the controller to suppress one or more faults (fault signals) and to enter normal operating mode. This remote fault suppression instruction may originate from a service center via a connectivity / remote monitoring device and may be initiated by a person or by a software algorithm. Therefore, the risk of passengers being trapped in the elevator is greatly reduced, and likewise, the number of calls to a technician is reduced. The following describes some more detailed embodiments of the present invention. As stated above, according to embodiments of the present invention, a "fault suppression instruction" is used to resolve a fault situation. According to embodiments of the present invention, a simplified state machine is shown in Fig. 4. This state machine is similar to that shown in Fig. 5, with the exception of the additional functionality related to the remote fault suppression instruction, as described below. As described in connection with Fig. 5, after successfully executing a "power-on sequence" state ST41 ("correct"), a normal operating state ("normal operating mode") ST42 is entered. If a fault is detected during this state, a "faulty" state ST43 is entered. The fault can be resolved by a technician activating the RDF switch located in the elevator, allowing the system to return to the "normal operating mode" state. Alternatively, the technician can resolve the fault by performing a power cycle. In this case, the system will restart the power-on sequence, and after successful startup, it will return to "normal operating mode." Alternatively, the fault may be resolved by addressing other local anomalies that are manually managed by the technician at the installation site. In this case, the "normal operating mode" can also be restored. However, according to the present embodiment, the "faulty" state ST43 can be resolved using the remote fault clearing instruction. This remote fault clearing instruction does not trigger the power-on sequence state ST41, but rather the "normal operating mode" state S42, thereby restoring normal operating mode. That is, the remote fault suppression instruction would not perform the "power-on reset" but would instead enter normal operating mode ("normal operating mode"). The other existing reset functionalities (RDF, power cycle) would remain available to a technician without remote connection to the device. This remote fault suppression instruction would originate from a service center via a connectivity / remote monitoring device and would be initiated either by a person or by a software algorithm. Similarly, in some fault situations, existing standards and codes require the presence of a qualified technician in the installation area. In this case, the control system must not accept the remote fault suppression instruction, and as a result, the system would remain in a "Failed" state awaiting manual intervention, as described earlier in connection with Figure 3. Thus, according to embodiments of the present invention, a long confinement of passengers inside the cabin and the call and presence of a technician in the installation area can be avoided, since it is possible to carry out remote fault suppression. Forms of embodiment of the present invention are not limited to the details of the embodiments described above, and various modifications are possible. For example, the elevator control device 1, and in particular the controller 11 shown in Fig. 1, may be arranged separately from a control device that performs overall elevator control, or it may be part of a plurality of control units that generally perform elevator control. Alternatively, controller 1 may be part of a main control device that performs overall elevator control. Figure 4 shows a detailed representation of the elevator control system. However, embodiments of the present invention are not limited to these details. In particular, the flow can be arbitrarily modified. For example, additional procedures can be added to resolve a fault condition, or some of the procedures shown (apart from the remote fault clearance instruction) can be omitted. According to some embodiments such as those described above, an elevator control system is described. However, embodiments of the present invention are not limited to this. For example, the control system can also be applied to an escalator or automatic doors. In this case, the advantage can also be obtained that a technician is not always required to enter the installation area. Furthermore, the time required to resume service of the escalator or automatic doors can be shortened. It should be understood that any of the modifications set out can be applied individually or in combination with the respective aspects and / or forms of implementation to which they refer, unless explicitly stated as mutually exclusive alternatives. Likewise, the elements of the elevator system, in particular the functional elements, control elements (for example, elevator control device 1), or detection elements, as well as the corresponding functions as described herein, and other elements, functions, or applications, may be implemented by software, for example, by a computer program, and / or by hardware. To perform their respective functions, the corresponding devices, elements, or functions may include various means, modules, component units, etc. (not shown) required to control, process, and / or communicate / signal the functionality.Such means, modules, units, and components may include, for example, one or more processors or processor units comprising one or more processing parts for executing instructions and / or programs and / or processing data, storage units or memory or means for storing instructions, programs, and / or data, serving as the processor's work area for the processing part and the like (e.g., ROM, RAM, EEPROM, and the like), input means or interface for entering data or instructions by means of software (e.g., floppy disk, CD-ROM, EEPROM, and the like), a user intervention to provide monitoring and manipulation capabilities to a user (e.g., a display, a keyboard, and the like), another interface or means for establishing links and / or connections under the control of the processor unit or part (e.g., wired or wireless interface means, etc.), and the like.It should be noted that in this descriptive report, the processing parts should not only be considered as representative of physical parts of one or more processors, but can also be considered as a logical division of the processing tasks referred to and executed by one or more processors. For the purposes of the present invention as described herein, it should be noted that - The relevant implementations that are to be materialized as software code or parts thereof and that are executed using a processor or processing function are independent software code and can be specified using any known or future developed programming language, for example, a high-level programming language such as Objective-C, C, C++, C#, Java, Python, Javascript, other programming languages, etc., or a low-level programming language such as machine language or assembly language, - The implementation of realization forms is hardware-independent and can be implemented using any known or future hardware technology or any hybrid thereof, such as a microprocessor or CPU (Central Processing Unit), MOS (Metal Oxide Semiconductor), CMOS (Complementary MOS), BiMOS (Bipolar MOS), BiCMOS (Bipolar CMOS), ECL (Emitter-Chosen Logic) and / or TTL (Transistor-Transistor Logic), - The embodiments can be implemented as individual devices, apparatuses, units, media, or functions, or in a distributed manner; for example, one or more processors or processing functions can be used or shared in the processing, or one or more processing sections or procedural parts can be used and shared in the processing, so that one or more physical processors can be used to implement one or more processing parts dedicated to specific processing, as described. - a device can be implemented by a semiconductor chip, or a set of chips or a module (hardware) that includes such a chip or set of chips; - The implementation forms can also be implemented in the form of any combination of hardware and software, for example, components of an ASIC (Application Specific IC (integrated circuit)), FPGA (Field Programmable Gate Array) or components of CPLD (Complex Programmable Logic Device) or components of DSP (Digital Signal Processor). - the embodiments can also be implemented as a computer program product, including a computer-usable medium incorporating a computer-readable program code, the computer-readable program code being adapted to execute a process as described in embodiments, wherein the computer-usable medium may be a non-transient medium.

Claims

1. A method for controlling a device, such as an elevator, escalator, or automatic doors, the method comprising detecting (S1) a fault in the device, characterized in that a fault is recorded in a fault memory or fault register, and the method further comprising receiving (S2) a remote fault erasure instruction, erasing (S3) one or more faults from the fault memory or fault register, exiting a fault state from a controller (11) of the device related to the detected fault, and entering (S4) an operating mode for controlling the device. 2.- The method according to claim 1, further comprising determining (S5), after receiving the remote fault erasure instruction, whether the detected fault permits remote fault erasure by the controller (11), and erasing (S3) one or more faults stored by the controller (11) only when the detected fault permits remote fault erasure.

3. The method according to claim 2, wherein the appliance faults are classified into different fault types, and it is determined based on the detected fault type whether the detected fault permits remote fault erasure.

4. The method according to any one of claims 1 to 3, wherein the remote fault erasure instruction is received from a service center by means of a connectivity / remote monitoring device. 5.- The method according to claim 4, wherein the remote fault suppression instruction is initiated by a person or by a software algorithm.

6. The method according to any one of claims 1 to 5, wherein the suppression (S3) of one or more faults is executed by activating a rescue maneuver function (RDF) switch provided in the controller (11).

7. The method according to any one of claims 1 to 6, wherein the suppression (S3) of one or more faults comprises the suppression of all faults or the suppression of faults that prevent the return of the device to a predetermined operating mode. 8.- A control device for controlling an apparatus that is an elevator, an escalator, or automatic doors, comprising a controller (11), wherein the controller (11) is configured to detect a fault in the apparatus, characterized in that a fault is recorded in a fault memory or fault register of the apparatus, and the control device is also configured to receive a remote fault erasure instruction, erase one or more faults from the fault memory or fault register, exit a fault state of a controller of the apparatus related to the detected fault, and enter an operating mode for controlling the apparatus. 9.- The control device according to claim 8, wherein the controller (11) is configured to determine, after receiving the remote fault suppression instruction, whether the detected fault permits remote fault suppression of the controller (11), and to suppress one or more faults of the controller (11) only when the detected fault permits remote fault suppression.

10. The control device according to claim 9, wherein the apparatus faults are classified into different fault types, and it is determined based on the type of fault detected whether the detected fault permits remote fault suppression.

11. The control device according to any one of claims 8 to 10, wherein the controller (11) is configured to suppress one or more faults by activating a rescue maneuver function (RDF) switch arranged in the controller (11). 12.- The control device according to any one of claims 8 to 11, wherein the controller (11) is configured to, after clearing one or more faults, clear all faults or clear faults that prevent the device from returning to a predetermined operating mode.

13. A system comprising a control device according to any one of claims 8 to 12 and a service center configured to send the remote fault-clearing instruction to the control device by means of a connectivity / remote monitoring device.

14. The system according to claim 13, wherein the remote fault-clearing instruction is initiated by a person or by a software algorithm. 15.- A computer program product comprising a code medium for performing a procedure according to any one of claims 1 to 7 when executed on a processing medium or module.