Elevator connection device verification system and elevator connection device verification method
The elevator connection device checking system verifies external devices by using a main controller to select a sub-controller, encrypt identification information, and compare source information, addressing the cost and complexity issues of existing systems while ensuring compliance with elevator system standards.
Patent Information
- Application Number
- JP2022024381
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-02-21
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2042-02-21
AI Technical Summary
The existing systems for verifying elevator connection devices require additional devices and communication paths, increasing implementation costs and complexity.
An elevator connection device checking system that uses a main controller to select a sub-controller, encrypt identification information, and compare source information to determine if an external device conforms to elevator system standards without adding new devices or communication paths.
Enables effective verification of external devices connected to the elevator system without increasing costs or complexity, ensuring compliance with elevator system standards.
Smart Images

Figure 0007675672000001 
Figure 0007675672000002 
Figure 0007675672000003
Abstract
Description
[Technical field]
[0001] The present invention relates to an elevator-connected device confirmation system and an elevator-connected device confirmation method. [Background technology]
[0002] In an elevator system, multiple controllers are connected via various communication paths. Various devices can be connected to the communication paths, but if a device that is not intended to be connected to the elevator system, i.e., a non-standard device that does not comply with the elevator system standards, is connected to the communication path, the operation of the elevator system may be impaired.
[0003] One of the typical devices connected to an elevator system is a service tool used for maintenance work, etc. If the service tool connected to the elevator system is not a genuine device that complies with the elevator standards, it may cause problems not only with the maintenance work using the service tool, but also with the operation of the entire elevator system.
[0004] By using a service tool authentication information management system that checks whether a service tool is a genuine device, it is possible to detect when a non-genuine device is connected to an elevator system. For example, Patent Document 1 discloses a service tool authentication information management system including a storage medium operable to store a plurality of instructions, and at least one processor configured to send an authentication information request to a network server and execute the instructions to access an equipment control device with the service tool. [Prior art documents] [Patent documents]
[0005] [Patent Document 1] JP 2019-23868 A Summary of the Invention [Problem to be solved by the invention]
[0006] However, in order to introduce the service tool authentication information management system described in Patent Document 1, it is necessary to newly install a device control device for monitoring and / or controlling device components, a network server for managing authentication information, and a communication path connecting the device control device and the network server, which increases the introduction cost.
[0007] The present invention has been made in consideration of the above-mentioned circumstances, and an object of the present invention is to make it possible to confirm whether an external device connected to an elevator system is a genuine device without adding a new device or communication path. [Means for solving the problem]
[0008] An elevator-connected device confirmation system according to one aspect of the present invention is an elevator-connected device confirmation system that confirms an external device connected to an elevator system including a plurality of controllers. A main controller, which is one of the plurality of controllers, includes a selection unit that selects one of the plurality of controllers as a sub-controller, an encryption unit that generates encrypted information by encrypting information including at least identification information of the sub-controller with an encryption key obtained from the external device, a transmission unit that transmits the encrypted information to the external device, and a determination unit that compares source information of a packet transmitted from the controller identified by the external device as the source with information of the sub-controller selected by the selection unit based on the identification information of the sub-controller obtained by decrypting the encrypted information by the external device, and determines that the external device is an unauthorized device that does not comply with the standards of the elevator system if the two pieces of information do not match.
[0009] An elevator-connected device confirmation method according to one aspect of the present invention is an elevator-connected device confirmation method by an elevator-connected device confirmation system that confirms an external device connected to an elevator system including a plurality of controllers. The elevator-connected device confirmation method according to one aspect of the present invention includes the steps of: a main controller, which is one of the plurality of controllers, selecting one of the plurality of controllers as a sub-controller; the main controller generating encrypted information by encrypting information including at least identification information of the sub-controller with an encryption key obtained from an external device; the main controller transmitting the encrypted information to the external device; and the main controller comparing, based on the identification information of the sub-controller obtained by decrypting the encrypted information by the external device, source information of a packet transmitted from the controller identified by the external device with information of the selected sub-controller, and determining that the external device is an unauthorized device that does not comply with the elevator system standard if the two pieces of information do not match. Effect of the Invention
[0010] According to at least one aspect of the present invention, it is possible to confirm whether an external device connected to an elevator system is a genuine device without adding a new device or communication path. Problems, configurations and effects other than those described above will become apparent from the following description of the embodiments. [Brief description of the drawings]
[0011] [Figure 1] 1 is a diagram showing a schematic configuration example of an elevator system according to an embodiment of the present invention; [Diagram 2] FIG. 2 is a block diagram showing an example of the configuration of a control system of a node, a main controller, and a sub-controller according to an embodiment of the present invention. [Diagram 3] FIG. 2 is a block diagram showing an example of the hardware configuration of each device constituting the elevator system according to one embodiment of the present invention. [Figure 4]10 is a flowchart showing an example of a procedure for elevator-connected device confirmation processing by the elevator system according to one embodiment of the present invention. [Diagram 5] 11 is a flowchart showing an example of a procedure of an initial communication process and a primary communication process in an elevator-connected device confirmation process by an elevator system according to one embodiment of the present invention. [Figure 6] FIG. 4 is a diagram illustrating an example of the configuration of an initial packet according to an embodiment of the present invention. [Figure 7] FIG. 2 is a diagram illustrating an example of the configuration of a primary packet according to an embodiment of the present invention. [Figure 8] 11 is a flowchart showing an example of a procedure of a secondary communication process and a tertiary communication process in an elevator-connected device confirmation process by an elevator system according to an embodiment of the present invention. [Figure 9] FIG. 13 is a diagram illustrating an example of a configuration of a secondary packet according to an embodiment of the present invention. [Figure 10] FIG. 13 is a diagram illustrating an example of the configuration of a tertiary packet according to an embodiment of the present invention. [Figure 11] 10 is a flowchart showing an example of a procedure of a determination process in an elevator-connected device confirmation process by the elevator system according to one embodiment of the present invention. [Figure 12] 11 is a flowchart showing the steps of a processing example (1) in a main controller when an added node is determined to be an unauthorized device in accordance with an embodiment of the present invention. [Figure 13] 13 is a flowchart showing a procedure of a processing example (2) in the main controller when it is determined that the added node is an unauthorized device in one embodiment of the present invention. [Figure 14] 11 is a flowchart showing an example of a procedure for generating temporary data and determining a sub-controller (1) according to an embodiment of the present invention. [Figure 15] 13 is a flowchart showing an example of a procedure for generating temporary data and determining a sub-controller (2) according to an embodiment of the present invention. [Figure 16]13 is a flowchart showing an example of a procedure for generating temporary data and determining a sub-controller (3) according to an embodiment of the present invention. [Figure 17] 13 is a flowchart showing an example of a procedure for generating temporary data and determining a sub-controller (4) according to an embodiment of the present invention. [Figure 18] 13 is a flowchart showing an example of a procedure for generating temporary data and determining a sub-controller (5) according to an embodiment of the present invention. [Figure 19] 13 is a flowchart showing an example of a procedure for generating temporary data and determining a sub-controller (6) according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0012] Hereinafter, examples of modes for carrying out the present invention (hereinafter referred to as "embodiments") will be described with reference to the accompanying drawings. The present invention is not limited to the embodiments, and various numerical values in the embodiments are merely examples. In addition, in this specification and drawings, the same components or components having substantially the same functions are given the same reference numerals, and duplicated explanations will be omitted.
[0013] <Outline of elevator system configuration> First, a configuration of an elevator system 100 (an example of an elevator-connected device confirmation system) according to an embodiment of the present invention will be described with reference to Fig. 1. Fig. 1 is a diagram showing a schematic configuration example of the elevator system 100.
[0014] As shown in FIG. 1, the elevator system 100 includes a center device 1, a communication controller 3, a group controller 4, an elevator 15, a maintenance terminal 19, and a management terminal 20.
[0015] The center device 1 is installed in a location remote from the building in which the elevator 15 is installed, and is a device that manages, monitors, and maintains the elevator 15 connected via a network 2. The network 2 is configured, for example, as a closed circuit network such as a dedicated line, or a public line such as the Internet.
[0016] The maintenance terminal 19 is a portable terminal carried by a maintenance worker (not shown) of the elevator 15, and is connected to the network 2. Based on operations by the maintenance worker, the maintenance terminal 19 acquires operation data when the elevator 15 breaks down, and displays the details of work inspections, etc., on the screen.
[0017] The control terminal 20 is a device that monitors and operates the operation of the elevator 15, and is configured as a general-purpose PC (Personal Computer) or a dedicated device. The control terminal 20 is installed, for example, in a control room (not shown) of a building in which the elevator 15 is installed, and is connected to a communication path 17.
[0018] The communication controller 3 is a controller that controls data transmission and reception between the center device 1 and the elevator 15, and communications for executing remote operation and remote maintenance by the maintenance terminal 19, and is connected to the network 2 and a communication path 17.
[0019] The group management controller 4 is a controller that collectively manages and operates a group of elevators 15 as an elevator group 18, and is connected to communication paths 17 and 16. The elevator groups 18 are established, for example, in units of the installation location or purpose of the elevators 15, the building in which the elevators 15 are installed, etc.
[0020] The elevator controller 5 is provided in each of the multiple elevators 15, is a controller that controls the operation of the elevators 15, and is connected to the communication path 16 and the communication path 12. The elevator controller 5, for example, controls a motor 6 that is the main engine of the elevator 15, and operates the movement of a rope 9 that connects a car 7 and a counterweight 8, thereby moving the car 7 up and down or stopping it, thereby providing users with the service of moving up and down.
[0021] Although only one car 7 is shown in FIG. 1, each of the elevators 15 is provided with one or more cars.
[0022] The elevator controller 5 is connected to the group controller 4 via a communication path 16, and is connected to the car controller 10 and the floor controller 11 via a communication path 12. Although only one floor controller 11 is shown in Fig. 1, in reality, a plurality of floor controllers are provided corresponding to the number of floors in the building.
[0023] The car controller 10 monitors the operation status by a user (not shown) of the destination floor buttons and door opening / closing buttons 13 installed in the car 7, and transmits the acquired operation content to the elevator controller 5 as a change in the operation status.
[0024] The floor controller 11 monitors, for example, the operation status by users on each floor of the up and down buttons 14 installed on each floor (not shown), and transmits the acquired operation content to the elevator controller 5 as a change in the operation status.
[0025] The node 30 newly connected to the elevator system 100 may be, for example, a maintenance terminal for performing maintenance and inspection of the elevator system 100, a sensor or camera for providing new data to the elevator system 100, an edge controller for providing new processing or functions, a communication controller for connecting to another system or network (not shown), etc. The new data may be, for example, a measured value of the number of people in the car 7 or on a floor, and the new processing or functions may be, for example, a result of a people flow prediction using AI (Artificial Intelligence), i.e., an inference result of how many passengers are likely to use the elevator 15. Note that the node 30 is not limited to a device that provides such information, processing, or functions.
[0026] The newly added node 30 may be connected to one or more of the communication paths 12, 16, and 17. Note that the network configuration using the communication paths shown in Fig. 1 is merely an example, and the network configuration of the present invention is not limited to the example shown in Fig. 1. Furthermore, the equipment configuration of the elevator system of the present invention is not limited to the example shown in Fig. 1.
[0027] In this embodiment, any one of the communication controller 3, the group controller 4, the elevator controller 5, the car controller 10, the floor controller 11, the maintenance terminal 19, and the management terminal 20 is set as the main controller 50 or the sub-controller 60 (see FIG. 2 for all of them). If the elevator system includes a controller other than these, that controller can also be set as the main controller 50 or the sub-controller 60.
[0028] The main controller 50 is a controller that executes authentication processing for the newly added node 30. The sub-controller 60 is a controller that configures a communication path for packets for authentication of the node 30, and is selected by the main controller 50. The selection of the sub-controller 60 by the main controller 50 is performed based on processed information of the operation information of the elevator 15 (such as a random number using a value indicated in the operation information as a seed). The method of selection of the sub-controller 60 by the main controller 50 will be described later.
[0029] <Control system configuration of node, main controller, and sub-controller> Next, the configuration of the control system of the node 30, the main controller 50, and the sub-controller 60 will be described with reference to Fig. 2. Fig. 2 is a block diagram showing an example of the configuration of the control system of the node 30, the main controller 50, and the sub-controller 60. The node 30, the main controller 50, and the sub-controller 60 are communicatively connected to each other via a communication path Nt, which is any one of the communication path 12, the communication path 16, and the communication path 17.
[0030] [node] A node 30 to be newly connected to the elevator system 100 (see FIG. 1 ) has a public key 31 and a private key N32 that is paired with the public key 31. The node 30 also has a decryption unit 33, a packet generation unit 34, and a communication unit 35.
[0031] The decryption unit 33 decrypts the encrypted data, which is contained in the primary packet P2 (see Figure 7) sent from the main controller 50 and was encrypted using the public key 31, and outputs the information obtained by decryption to the packet generation unit 34.
[0032] When node 30 is connected to any of the communication paths of elevator system 100, packet generation unit 34 generates initial packet P1 (see FIG. 6) including public key 31 and identification information of its own node, and outputs the initial packet P1 to communication unit 35. In addition, packet generation unit 34 generates secondary packet P3 (see FIG. 9) using information input from decryption unit 33, and outputs the secondary packet P3 to communication unit 35.
[0033] The communication unit 35 performs the process of transmitting the initial packet P1 generated by the packet generation unit 34 to the main controller 50, the process of receiving the primary packet P2 transmitted from the main controller 50 and outputting it to the decoding unit 33, and the process of transmitting the secondary packet P3 generated by the packet generation unit 34 to the sub-controller 60.
[0034] [Main Controller] The main controller 50 has a private key M53. The private key M53 (an example of a second private key) is a shared key held only by the main controller 50. The main controller 50 also has a temporary data generating unit 51, a communication path selecting unit 52, an encryption unit 54, a packet generating unit 55, a communication unit 56, an address determining unit 57, a decrypting unit 58, and a discrimination unit 59.
[0035] The temporary data generating unit 51 (an example of a temporary information generating unit) generates temporary data (an example of temporary information) using operation information of the elevator 15 (see FIG. 1) acquired via the communication path Nt. The temporary data is processed information of the operation data (an example of operation information), and may be, for example, a random number value using the position (car position) of the car 7, which is the operation data, as a seed, or a hash value obtained by inputting the car position into a predetermined hash function. Note that the temporary data may be the operation data itself (data before processing).
[0036] The communication path selection unit 52 (an example of a selection unit) selects a sub-controller 60 that constitutes a communication path for packets for authentication of the node 30 (primary packet P2, secondary packet P3, tertiary packet P4 (see FIG. 10)) based on operation information of the elevator 15 acquired via the communication path Nt. For example, the communication path selection unit 52 can refer to call information, which is operation data, and select the floor controller 11 (see FIG. 1) of a floor where no call has been registered (where no call has been generated) as the sub-controller 60. An example of the selection of the sub-controller 60 by the communication path selection unit 52 will be described later with reference to FIGS. 14 to 19.
[0037] The encryption unit 54 encrypts the identification information (hereinafter also referred to as "sub-information") of the sub-controller 60 selected by the communication path selection unit 52 and the temporary data generated by the temporary data generation unit 51 using the public key 31 obtained from the node 30, and generates encrypted temporary data (see Figure 7).
[0038] The packet generation unit 55 generates a primary packet P2 (see FIG. 7) including the encrypted temporary data generated by the encryption unit 54, and outputs the primary packet P2 to the communication unit 56. An example of the configuration of the primary packet P2 will be described in detail later with reference to FIG. 7.
[0039] The communication unit 56 (an example of a transmitting unit) performs the following processes: receiving an initial packet P1 (see Figure 6) transmitted from the node 30; transmitting a primary packet P2 (see Figure 7) generated by the packet generating unit 55 to the node 30; and receiving a secondary packet P3 transmitted from the sub-controller 60 and outputting it to the address determining unit 57.
[0040] The address determination unit 57 determines whether or not the node 30 is a legitimate device that complies with the standards of the elevator system 100 by referring to the identification information of the node 30 included in the initial packet P1 transmitted from the node 30. Then, the address determination unit 57 outputs the determination result to the decryption unit 58.
[0041] The decryption unit 58 uses the private key M53 to decrypt the encrypted temporary data included in the secondary packet P3 (see FIG. 9) transmitted from the sub-controller 60. Then, the decryption unit 58 outputs the temporary data obtained by decryption to the discrimination unit 59.
[0042] The discrimination unit 59 compares the information in the tertiary packet P4 decoded by the decoding unit 58 with the information held by the main controller 50 to determine whether or not the node 30 is a legitimate device that complies with the standards of the elevator system 100. That is, the discrimination unit 59 performs an authentication (discrimination) process for the node 30. Furthermore, when the discrimination unit 59 determines that the node 30 is an illegitimate device, it performs a process of notifying other controllers of that effect and an instruction to stop the car 7 of the elevator 15 in operation at the nearest floor, etc.
[0043] The process of discriminating node 30 by discrimination unit 59 will be described in detail with reference to FIG. 11 described later, and the process by discrimination unit 59 when it is determined that node 30 is an unauthorized device will be described in detail with reference to FIG. 12 and FIG. 13 described later.
[0044] [Sub-controller] The sub-controller 60 has a communication unit 61 and a packet forwarding unit 62. The communication unit 61 performs a process of receiving a secondary packet P3 transmitted from the node 30 and outputting it to the packet forwarding unit 62, and a process of transmitting a tertiary packet P4 (see FIG. 10) generated by the packet forwarding unit 62 to the main controller 50.
[0045] The packet forwarding unit 62 extracts the encrypted temporary data from the secondary packet P3 transmitted from the node 30, generates a tertiary packet P4 (see Figure 10) containing the encrypted temporary data and its own (sub-controller 60) identification information, and outputs the tertiary packet P4 to the communication unit 61.
[0046] <Example of computer hardware configuration> Next, the configuration (hardware configuration) of the control system of each device (communication controller 3, group management controller 4, elevator controller 5, car controller 10, floor controller 11, maintenance terminal 19, and management terminal 20) that constitutes the elevator system 100 shown in FIG. 1 will be described with reference to FIG. 3.
[0047] Fig. 3 is a block diagram showing an example of the hardware configuration of each device constituting the elevator system 100. A calculator 200 shown in Fig. 3 is hardware used as a so-called computer.
[0048] The computer 200 includes a central processing unit (CPU) 201, a read only memory (ROM) 202, a random access memory (RAM) 203, a non-volatile storage 204, and a communication interface (I / F) 205, all of which are connected to a bus B.
[0049] The CPU 201 reads out program code of software for implementing each function according to this embodiment from the ROM 202, expands it in the RAM 203, and executes it. Alternatively, the CPU 201 may directly read out the program code from the ROM 202 and execute it as is. Note that the computer 200 may include a processing device such as an MPU (Micro-Processing Unit) instead of the CPU 201.
[0050] In the RAM 203, variables, parameters, etc. generated during the arithmetic processing by the CPU 201 are temporarily written.
[0051] Each function of the decryption unit 33, packet generation unit 34 of the node 30, the temporary data generation unit 51, communication path selection unit 52, encryption unit 54, packet generation unit 55, address determination unit 57, decryption unit 58, discrimination unit 59, and packet forwarding unit 62 of the sub-controller 60 is realized by the CPU 201 reading out from the ROM 202 and executing a program for realizing each of these functions.
[0052] The non-volatile storage 204 may be, for example, a hard disk drive (HDD), a solid state drive (SSD), a flexible disk, an optical disk, a magneto-optical disk, a CD-ROM, a CD-R, a non-volatile memory card, etc. In addition to an operating system (OS) and various parameters, programs for operating the computer 200, etc. are recorded in the non-volatile storage 204. The programs may be stored in the ROM 202.
[0053] The program is stored in the form of a computer-readable program code, and the CPU 201 sequentially executes operations according to the program code. In other words, the ROM 202 or the non-volatile storage 204 is used as an example of a computer-readable non-transitory recording medium that stores a program executed by a computer.
[0054] In addition, operation data of the elevator 15 generated in each controller or obtained from another controller via the communication path Nt (see FIG. 2) is also written to the non-volatile storage 204. The operation data of the elevator 15 includes, for example, position information of the car 7, car speed information, load information of the car 7, information on the number of people moving (transported) by the car 7, information on the number of trips of the elevator 15, information on the destination floor of the elevator 15, information on the number of stops of the elevator 15 on each floor, etc.
[0055] The communication I / F 205 is configured with a communication device that controls communication between other devices. The network for which the communication I / F 205 controls communication includes, for example, a multi-drop serial communication such as RS-485, and a communication path that provides multiple topologies such as Ethernet (registered trademark). The communication path that provides multiple topologies includes a wired communication path such as a Local Area Network (LAN) or a Wide Area Network (WAN), and a wireless communication path such as a Radio Area Network (RAN).
[0056] For example, the network in which the communication I / F 205 performs communication control includes wireless networks such as Wi-Fi (registered trademark) and wireless networks in wireless communication infrastructure. The functions of the communication unit 35 of the node 30, the communication unit 56 of the main controller 50, and the communication unit 61 of the sub-controller 60 are realized by the communication I / F 205.
[0057] <Outline of elevator connection device confirmation process> Next, an overview of the elevator-connected-device confirmation process performed by the elevator system 100 will be described with reference to Fig. 4. Fig. 4 is a flowchart showing an example of the procedure of the elevator-connected-device confirmation process performed by the elevator system 100.
[0058] First, the node 30 (see FIG. 2) executes an initial communication process to generate an initial packet P1, and transmits the generated initial packet P1 to the main controller 50 (step S1). Next, the main controller 50 executes a primary communication process based on the information included in the received initial packet P1 to generate a primary packet P2, and transmits the generated primary packet P2 to the node 30 (step S2). Next, the node 30 executes a secondary communication process using the information included in the received primary packet P2 to generate a secondary packet P3, and transmits the generated secondary packet P3 to the sub-controller 60 (step S3).
[0059] Next, the sub-controller 60 executes a tertiary communication process based on the information included in the received secondary packet P3 to generate a tertiary packet P4, and transmits the generated tertiary packet P4 to the main controller 50 (step S4). Next, the main controller 50 executes a determination process based on the information included in the received tertiary packet P4 (step S5).
[0060] <Details of elevator connection device confirmation process> Next, the elevator-connected device confirmation process by the elevator system 100 will be described in detail with reference to Fig. 5, Fig. 8, and Fig. 11. Fig. 5 is a flowchart showing an example of the procedure of an initial communication process and a first communication process in the elevator-connected device confirmation process by the elevator system 100. Fig. 8 is a flowchart showing an example of the procedure of a second communication process and a third communication process in the elevator-connected device confirmation process by the elevator system 100. Fig. 11 is a flowchart showing an example of the procedure of a determination process in the elevator-connected device confirmation process by the elevator system 100.
[0061] [Initial communication processing and primary communication processing] First, the initial communication process and the primary communication process in the elevator-connected device confirmation process will be described with reference to Fig. 5. First, the communication unit 35 of the node 30 (see Fig. 2) judges whether or not it is connected to the communication path Nt (see Fig. 2) of the elevator system 100 (step SA1). If it is judged in step SA1 that it is not connected to the communication path Nt (if the judgment in step SA1 is NO), the communication unit 35 repeats the judgment in step SA1.
[0062] On the other hand, if it is determined in step SA1 that the communication path Nt has been connected (YES in step SA1), the packet generator 34 generates an initial packet P1 including public key information and transmits it to the main controller 50 (step SA2). The processes of steps SA1 and SA2 correspond to the initial communication process of step S1 in FIG.
[0063] [Initial packet configuration] The configuration of the initial packet P1 will now be described with reference to Fig. 6. Fig. 6 is a diagram showing an example of the configuration of the initial packet P1.
[0064] As shown in FIG. 6, the initial packet P1 has a source information field F1, a destination information field F2, a public key information field F3, a node identification information field F4, and a check data field F5.
[0065] The source information field F1 stores information (source information) about itself (node 30) that is the source of the initial packet P1. The destination information field F2 stores information (destination information) about the main controller 50 that is the destination of the initial packet P1.
[0066] For example, the source information is a device ID when communication conforms to RS-485. Also, when communication is performed using Ethernet (registered trademark), the source information is a device's MAC (Media Access Control) address or IP (Internet Protocol) address. The destination information may be configured with the same information as the source information, but in a network where packets are transmitted by broadcast communication, the destination information stores a broadcast address.
[0067] The public key information field F3 stores the public key 31 (see FIG. 2). The node identification information field F4 stores identification information (node identification information) of the own node (node 30). The node identification information includes, for example, the model and serial number of the node 30. The check data field F5 stores an error detection code such as a checksum.
[0068] Although it is assumed that the initial packet P1 is composed of plain text and is transmitted by unencrypted communication, the packets may be encrypted and may be transmitted by encrypted communication. Similarly, the primary packet P2 to the tertiary packet P4 themselves may be encrypted and may be transmitted by encrypted communication.
[0069] If the node 30 is a node that intends to perform fraudulent acts, it may perform a DoS (Denial of Services) attack after connecting to the communication path Nt. Therefore, if the number of transmissions of the initial packet P1 transmitted from the node 30 is excessive (above a predetermined threshold number), the node 30 may be immediately determined to be a fraudulent node at that point in time.
[0070] Returning to Fig. 5, the explanation will be continued. The main controller 50 receives the initial packet P1 transmitted from the node 30 in step SA2 (step SB1). Next, the communication path selection unit 52 (see Fig. 2) of the main controller 50 selects a specific controller as the sub-controller 60 based on the operation data of the elevator 15 (step SB2).
[0071] For example, the communication path selection unit 52 can obtain call information as operation data and select the controller with the fewest call registrations as the sub-controller 60.
[0072] In this embodiment, the main controller 50 performs the selection process of the sub-controller 60 with the reception of the initial packet P1 as a trigger, but the present invention is not limited to this. The selection process may be performed at a certain period set in the main controller 50 or when a certain condition is met, such as when the number of trips of the elevator 15 reaches a certain threshold number of trips. Alternatively, the selection process may be performed at random time units. By performing such a process, it is possible to make it more difficult for a third party to detect the execution of the authentication process of the node 30.
[0073] Next, the temporary data generating unit 51 of the main controller 50 generates temporary data using the operation data (step SB3). For example, the temporary data generating unit 51 generates random numbers using operation data such as car positions as seeds, or hash values obtained by inputting the operation data into a predetermined hash function, and sets these as temporary data.
[0074] Next, the encryption unit 54 of the main controller 50 encrypts the temporary data generated in step SB3 using the private key M53 to generate encrypted temporary data (step SB4). Next, the packet generation unit 55 of the main controller 50 encrypts the encrypted temporary data generated in step SB4 and the information (sub-information) of the sub-controller 60 selected in step SB2 using the public key included in the initial packet P1 received in step SB1 to generate encrypted data (an example of encrypted information) (step SB5).
[0075] Next, the packet generation unit 55 of the main controller 50 generates a primary packet P2 including the encrypted data generated in step SB5 and information about itself (the main controller 50) (step SB6). Then, the communication unit 56 transmits the primary packet P2 to the node 30 (step SB7). The processes of steps SB1 to SB7 correspond to the primary communication process of step S2 in FIG. 4.
[0076] 5, the main controller 50 generates temporary data after selecting the sub-controller 60, but the present invention is not limited to this. The main controller 50 may select the sub-controller 60 after generating the temporary data.
[0077] [Primary packet composition] Here, the configuration of the primary packet P2 will be described with reference to Fig. 7. Fig. 7 is a diagram showing an example of the configuration of the primary packet P2.
[0078] As shown in FIG. 7, the primary packet P2 has a source information field F21, a destination information field F22, an encrypted data field F23, and a check data field F24.
[0079] The source information field F21 stores information (source information) about itself (the main controller 50) that is the source of the primary packet P2. The destination information field F22 stores information (destination information) about the node 30 that is the destination of the primary packet P2.
[0080] The encrypted data field F23 stores encrypted data generated by the encryption unit 54 of the main controller 50. The encrypted data is composed of identification information (sub-information) of the sub-controller 60 and encrypted temporary data. The check data field F24 stores an error detection code such as a checksum.
[0081] [Secondary and tertiary communication processing] Next, the secondary communication process and the tertiary communication process in the elevator connected device confirmation process will be described with reference to Fig. 8. First, the communication unit 35 of the node 30 (see Fig. 2) receives the primary packet P2 transmitted from the main controller 50 (step SA3). Next, the decryption unit 33 of the node 30 decrypts the encrypted data included in the primary packet P2 received in step SA3 using the private key N32 corresponding to the public key 31 (step SA4).
[0082] Next, the packet generator 34 of the node 30 extracts the encrypted temporary data from the encrypted data decrypted in step SA4 and stores it in the secondary packet P3 (step SA5). Next, the packet generator 34 sets the sub-information (identification information of the sub-controller 60) included in the encrypted data decrypted in step SA4 in the destination information field F32 (see FIG. 9) of the secondary packet P3 (step SA6).
[0083] Next, the communication unit 35 of the node 30 transmits the secondary packet P3 to the sub-controller 60 (step SA7). The processes of steps SA1 to SA7 are the secondary communication process of step S3 in Fig. 4, and after the process of step SA7, all processes (initial communication process and secondary communication process) by the node 30 are terminated.
[0084] [Secondary packet configuration] Here, the configuration of the secondary packet P3 will be described with reference to Fig. 9. Fig. 9 is a diagram showing an example of the configuration of the secondary packet P3.
[0085] As shown in FIG. 9, the secondary packet P3 has a source information field F31, a destination information field F32, a main controller identification information field F33, an encrypted temporary data field F34, and a check data field F35.
[0086] The source information field F31 stores information (source information) about itself (node 30) that is the source of the secondary packet P3. The destination information field F32 stores information (destination information) about the sub-controller 60 that is the destination of the secondary packet P3.
[0087] The main controller identification information field F33 stores identification information of the main controller 50. The identification information of the main controller 50 is used by the sub-controller 60 that receives the secondary packet P3 as information on the destination of the generated tertiary packet P4. The encrypted temporary data field F34 stores encrypted temporary data extracted from the primary packet P2. The check data field F35 stores an error detection code such as a checksum.
[0088] Returning to Fig. 8, the explanation will be continued. The communication unit 61 of the sub-controller 60 (see Fig. 2) receives the secondary packet P3 transmitted from the node 30 in step SA5 (step SC1). Next, the packet forwarding unit 62 of the sub-controller 60 generates a tertiary packet P4 including the encrypted temporary data and source information contained in the secondary packet P3 received in step SC1 (step SC2). Next, the communication unit 61 of the sub-controller 60 transmits the tertiary packet P4 to the main controller 50 (step SC3). The processing of steps SC1 to SC3 is the tertiary communication processing of step S4 in Fig. 4, and after the processing of step SC3, the processing by the sub-controller 60 ends.
[0089] [Tertiary packet configuration] Here, the configuration of the tertiary packet P4 will be described with reference to Fig. 10. Fig. 10 is a diagram showing an example of the configuration of the tertiary packet P4.
[0090] As shown in FIG. 10, the tertiary packet P4 has a source information field F41, a destination information field F42, an encrypted temporary data field F43, and a check data field F44.
[0091] The source information field F41 stores information (source information) about itself (the sub-controller 60) which is the source of the tertiary packet P4. The destination information field F42 stores information (destination information) about the main controller 50 which is the destination of the tertiary packet P4. The encrypted temporary data field F43 stores encrypted temporary data extracted from the secondary packet P3. The check data field F44 stores an error detection code such as a checksum.
[0092] [Discrimination process] Next, the determination process in the elevator connected device confirmation process will be described with reference to Fig. 11. First, the determination unit 59 of the main controller 50 (see Fig. 2) determines whether or not the tertiary packet P4 has been received from the sub-controller 60 within a predetermined threshold time (step SB8). The determination whether or not it is within the threshold time is based on the elapsed time since the main controller 50 transmitted the primary packet P2 to the node 30 in step SB7 of Fig. 5.
[0093] If the node 30 is not a legitimate device, the node 30 cannot correctly execute the secondary communication process. That is, the node 30 cannot decrypt the encrypted data included in the primary packet P2 transmitted from the main controller 50, and cannot obtain the information of the sub-controller 60 included in the encrypted data. In addition, the node 30, which is an unauthorized device, cannot obtain the encrypted temporary data included in the encrypted data.
[0094] Therefore, the node 30 of the unauthorized device cannot execute a secondary communication process of generating a secondary packet P3, the destination of which is the sub-controller 60 and including encrypted temporary data, based on the primary packet P2 transmitted from the main controller 50, and transmitting the secondary packet P3 to the sub-controller 60. Therefore, the sub-controller 60 also cannot execute a tertiary communication process of generating a tertiary packet P4 based on the secondary packet P3 received from the node 30 and transmitting the tertiary packet P4 to the main controller 50.
[0095] That is, if the node 30 is an unauthorized device, the main controller 50 will not receive the tertiary packet P4 from the sub-controller 60 within a predetermined threshold time after transmitting the primary packet P2 to the node 30. Therefore, if the main controller 50 fails to receive the tertiary packet P4 within a predetermined threshold time after transmitting the primary packet P2 to the node 30, it can be determined that the node 30 is an unauthorized device.
[0096] If it is determined in step SB8 that the tertiary packet P4 has not been received from the sub-controller 60 within the threshold time (if step SB8 is determined to be NO), the determination unit 59 of the main controller 50 determines that the added node 30 is a node that does not conform to the standard, that is, a node of an unauthorized device (step SB9). After processing in step SB9, the main controller 50 ends the determination process.
[0097] On the other hand, if it is determined in step SB8 that the tertiary packet P4 has been received from the sub-controller 60 within the predetermined threshold time (if the determination in step SB8 is YES), the discrimination unit 59 determines whether or not the source information included in the tertiary packet P4 matches the information of the sub-controller 60 selected in step SB2 of Fig. 5 (step SB10). If it is determined in step SB10 that the two pieces of information do not match (if the determination in step SB10 is NO), the discrimination unit 59 performs the process of step SB9. That is, it determines that the added node 30 is an unauthorized device.
[0098] On the other hand, if it is determined in step SB10 that the two pieces of information match (if the determination in step SB10 is YES), the discrimination unit 59 decrypts the encrypted temporary data contained in the tertiary packet P4 received from the sub-controller 60 using the private key M53 (see FIG. 2) (step SB11).
[0099] Next, the discrimination unit 59 judges whether or not the temporary data included in the decrypted encrypted data matches the temporary data generated in step SB3 of Fig. 5 (step SB12). If it is judged in step SB12 that the two pieces of data do not match (if the judgment in step SB12 is NO), the process of step SB9 is performed. That is, it is judged that the added node 30 is an unauthorized device.
[0100] On the other hand, if it is determined in step SB12 that the two pieces of data match (YES in step SB12), the discrimination unit 59 determines that the added node is a node that complies with the standard, that is, a legitimate device (step SB13). The processes in steps SB8 to SB13 are the discrimination process in step S5 in Fig. 4, and after the process in step SB9 or step SB13, all the processes (primary communication process and discrimination process) by the main controller 50 are terminated.
[0101] [Processing when non-genuine device is detected] Next, the processing in the main controller 50 when it is determined that the added node 30 is an unauthorized device will be described with reference to Fig. 12 and Fig. 13. Fig. 12 is a flowchart showing the procedure of a processing example (1) in the main controller 50 when it is determined that the added node 30 is an unauthorized device. Fig. 13 is a flowchart showing the procedure of a processing example (2) in the main controller 50 when it is determined that the added node 30 is an unauthorized device.
[0102] First, a process example (1) will be described with reference to Fig. 12. First, when the determination unit 59 (see Fig. 2) of the main controller 50 determines that the node 30 is not a genuine device, that is, that the node 30 is an unauthorized device, the determination unit 59 stores information about the node 30 determined to be an unauthorized device (hereinafter also referred to as an unauthorized node 30) as unauthorized information (step S11). The unauthorized information includes at least information about the unauthorized node 30 (identification information, etc.), and is composed of, for example, a device ID, a serial number, a MAC address, an IP address, etc.
[0103] Next, the discrimination unit 59 of the main controller 50 notifies the other controllers of the fraud information stored in step S11 via the communication unit 56 (step S12). For example, when a plurality of devices are connected in a multi-drop configuration on the communication path Nt (see FIG. 2), the notification is made to all the controllers connected to the communication path Nt by serial communication.
[0104] Furthermore, when communication is performed on the communication path Nt based on a standard such as Ethernet (registered trademark), notification of the fraudulent information is sent to all controllers connected to the communication path Nt via broadcast communication. Each controller that receives the fraudulent information can perform processing such as refusing communication with the node 30 based on the information of the node 30 included in the received fraudulent information.
[0105] By performing such processing by the main controller 50 and other controllers, any action by the node 30, which is an unauthorized device, can be ignored by the elevator system 100. Therefore, according to this embodiment, even if an unauthorized device is connected to the communication path Nt, it is possible to continue operation of the elevator 15 (see FIG. 1).
[0106] Furthermore, according to this embodiment, when a node 30 that is an unauthorized device is connected, this is immediately detected by the main controller 50, making it possible to prevent malfunctions in the operation, etc. of the elevator system 100 caused by the connection of the node 30 that is an unauthorized device. Also, even if the node 30 is an unauthorized device that has been added for the purpose of committing fraud, processing such as refusing communication with the node 30 is performed, making it possible to prevent fraud from being carried out.
[0107] Next, a processing example (2) will be described with reference to Fig. 13. First, when the discrimination unit 59 of the main controller 50 determines that the node 30 is an unauthorized device, it instructs the corresponding controller to stop the car 7 of the elevator 15 (see Fig. 1) at the nearest floor (step S21).
[0108] For example, when an unauthorized node 30 is connected to the communication path 17 in Fig. 1, the main controller 50 instructs the group management controller 4 to stop the car 7 at the nearest floor, and when an unauthorized node 30 is connected to the communication path 16, the main controller 50 instructs the elevator controller 5 to stop the car 7 at the nearest floor. Also, when an unauthorized node 30 is connected to the communication path 12, the main controller 50 instructs the elevator controller 5 to stop the car 7 at the nearest floor. By performing such processing, the safety of users of the elevator 15 can be ensured even if an unauthorized node 30 is connected.
[0109] Next, the discrimination unit 59 of the main controller 50 notifies the upper controller of the occurrence of fraud via the communication unit 56 (step S22). For example, when the fraudulent node 30 is connected to the communication path 17 in Fig. 1, the main controller 50 notifies the communication controller 3 of the occurrence of fraud, and when the fraudulent node 30 is connected to the communication path 16, the main controller 50 notifies the group management controller 4 of the occurrence of fraud. Also, when the fraudulent node 30 is connected to the communication path 12, the main controller 50 notifies the elevator controller 5 of the occurrence of fraud. The controller that receives the notification of the occurrence of fraud further forwards the notification of the occurrence of fraud to the upper controller, so that the notification of the occurrence of fraud can be made to reach the highest-level center device 1 promptly.
[0110] [Example of temporary data generation and sub-controller determination] Next, with reference to Figs. 14 to 19, an example of temporary data generation by the temporary data generation unit 51 (see Fig. 2) of the main controller 50 and an example of selection of the sub-controller 60 by the communication path selection unit 52 of the main controller 50 will be described.
[0111] Fig. 14 is a flowchart showing an example of temporary data generation and a procedure for a sub-controller 60 determination example (1), Fig. 15 is a flowchart showing an example of temporary data generation and a procedure for a sub-controller 60 determination example (2). Fig. 16 is a flowchart showing an example of temporary data generation and a procedure for a sub-controller 60 determination example (3), Fig. 17 is a flowchart showing an example of temporary data generation and a procedure for a sub-controller 60 determination example (4). Fig. 18 is a flowchart showing an example of temporary data generation and a procedure for a sub-controller 60 determination example (5), and Fig. 19 is a flowchart showing an example of temporary data generation and a procedure for a sub-controller 60 determination example (6).
[0112] [Example (1): Operation data for temporary data = cage position information, Operation data for selection by the sub-controller 60 = call information] First, with reference to FIG. 14, an example of generation of temporary data by the main controller 50 and a determination example (1) of the sub-controller 60 will be described. First, the temporary data generation unit 51 (see FIG. 2) of the main controller 50 acquires position information (car position information) of the car 7 (see FIG. 1) as operation data of the elevator 15 via the communication unit 56 (step S31).
[0113] Next, the temporary data generating unit 51 of the main controller 50 generates temporary data using the car position information acquired in step S31 as an input value (step S32). The temporary data can be generated, for example, by inputting the car position information into a random number generating function, a hash value function, or the like. That is, the temporary data generating unit 51 can obtain, as temporary data, a random number or a hash value using the car position information as an input value.
[0114] Next, the communication path selection unit 52 of the main controller 50 acquires the call information as the operation data (step S33).
[0115] Next, the communication path selection unit 52 selects a predetermined controller as the sub-controller 60 based on the call information acquired in step S33 (step S34). For example, the communication path selection unit 52 can input the call registration information of each car 7 included in the call information to a minimum function and select a controller based on the obtained output value. As a result, the controller with the smallest call registration is selected as the sub-controller 60.
[0116] By performing such processing by the communication path selection unit 52, the car controller 10 that controls the operation of the car 7 with the fewest call registrations, including the car 7 with zero call registrations, is selected as the sub-controller 60. In other words, the car controller 10 with the processing capacity to spare is selected as the sub-controller 60 that configures the packet transmission path. Therefore, it is possible to minimize the impact on the normal operation of the elevator 15 caused by executing the elevator connection device confirmation method according to this embodiment.
[0117] [Example (2): Operation data for temporary data = cage speed information, Operation data for selection by the sub-controller 60 = call information] Next, an example of temporary data generation by the main controller 50 and a determination example (2) of the sub-controller 60 will be described with reference to FIG. First, the temporary data generating unit 51 of the main controller 50 acquires speed information (car speed information) of the car 7 as operation data of the elevator 15 via the communication unit 56 (step S41).
[0118] Next, the temporary data generating unit 51 of the main controller 50 generates temporary data using the car speed information acquired in step S41 as an input value (step S42). The temporary data can be generated, for example, by inputting the car speed information into a random number generating function, a hash value function, or the like. That is, the temporary data generating unit 51 can obtain, as temporary data, a random number or a hash value using the car speed information as an input value.
[0119] Next, the communication path selection unit 52 of the main controller 50 acquires destination floor information of the car 7 as operation data (step S43).
[0120] Next, the communication path selection unit 52 selects a predetermined controller as the sub-controller 60 based on the destination floor information acquired in step S43 (step S44). For example, the communication path selection unit 52 can input the destination floor included in the destination floor information to a minimum value function and select the sub-controller 60 based on the obtained output value. As a result, the controller with the smallest number of destination floors registered is selected as the sub-controller 60.
[0121] By performing such processing by the communication path selection unit 52, the floor controller 11 installed on the floor with the fewest destination floor registrations, including floors with zero destination floor registrations, is selected as the sub-controller 60. In other words, the floor controller 11 with processing capacity is selected as the sub-controller 60 that configures the packet transmission path. Therefore, it is possible to minimize the effect that the implementation of the elevator-connected device confirmation method according to this embodiment has on the normal operation of the elevator 15.
[0122] [Example (3): Operation data for temporary data and operation data for selection by the sub-controller 60 = car load information] Next, an example of temporary data generation by the main controller 50 and a determination example (3) of the sub-controller 60 will be described with reference to FIG. First, the temporary data generating unit 51 of the main controller 50 acquires the load information (car load information) of the car 7 as the operation data of the elevator 15 via the communication unit 56 (step S51).
[0123] Next, the temporary data generating unit 51 of the main controller 50 generates temporary data using the car load information acquired in step S51 as an input value (step S52). The temporary data can be generated, for example, by inputting the car load information into a random number generating function, a hash value function, or the like. That is, the temporary data generating unit 51 can obtain, as the temporary data, a random number or a hash value using the car load information as an input value.
[0124] Next, the communication path selection unit 52 of the main controller 50 selects a predetermined controller as a sub-controller 60 based on information on the distribution position of the random number or hash value using the car load information generated in step S52 as an input value (step S53). Specifically, the communication path selection unit 52 divides a numerical range in which the random number or hash value can be generated into the number of sub-controllers 60, and selects a sub-controller 60 depending on which numerical range the actually generated random number or hash value belongs to.
[0125] [Example (4): Operation data for temporary data and operation data for selection by the sub-controller 60 = operation count information] Next, an example of temporary data generation by the main controller 50 and a determination example (4) of the sub-controller 60 will be described with reference to FIG. First, the temporary data generating unit 51 of the main controller 50 acquires information on the number of trips of the elevator 15 as operation data of the elevator 15 via the communication unit 56 (step S61).
[0126] Next, the temporary data generating unit 51 of the main controller 50 generates temporary data using the trip count information acquired in step S61 as an input value (step S62). The temporary data can be generated, for example, by inputting the trip count information into a random number generating function or a hash value function. That is, the temporary data generating unit 51 can obtain, as the temporary data, a random number or a hash value using the trip count information as an input value.
[0127] Next, the communication path selection unit 52 of the main controller 50 selects a predetermined controller as the sub-controller 60 based on the value of the number of trips (step S63). For example, the communication path selection unit 52 can select the elevator controller 5 of the elevator 15 with the smallest number of trips as the sub-controller 60.
[0128] The communication path selection unit 52 may select the elevator controller 5 of the elevator 15 with the median or maximum number of trips as the sub-controller 60. In other words, the value used to select the sub-controller 60 may be any value as long as it allows selection of an arbitrary elevator controller 5.
[0129] [Example (5): Operation data for temporary data and operation data for selection by the sub-controller 60 = information on the number of people moving] Next, with reference to FIG. 18, a description will be given of an example of generation of temporary data by the main controller 50 and a determination example (5) of the sub-controller 60. FIG. First, the temporary data generating unit 51 of the main controller 50 acquires information on the number of people moving (transported) in the elevator 15 as operation data of the elevator 15 via the communication unit 56 (step S71).
[0130] Next, the temporary data generating unit 51 of the main controller 50 generates temporary data using the number of people information acquired in step S71 as an input value (step S72). The temporary data can be generated, for example, by inputting the number of people information into a random number generating function or a hash value function. That is, the temporary data generating unit 51 can obtain, as the temporary data, a random number or a hash value using the number of people information as an input value.
[0131] Next, the communication path selection unit 52 of the main controller 50 selects a predetermined controller as the sub-controller 60 based on the number of people moving (step S73). For example, the communication path selection unit 52 can select the elevator controller 5 of the elevator 15 with the smallest number of people moving as the sub-controller 60. Note that the communication path selection unit 52 may select the elevator controller 5 of the elevator 15 with the median or maximum number of people moving as the sub-controller 60. In other words, the value used to select the sub-controller 60 may be any value as long as it allows the selection of an arbitrary elevator controller 5.
[0132] [Example (6): Operation data for temporary data and operation data for sub-controller 60 selection = elevator stop count information] Next, with reference to FIG. 19, an example of generation of temporary data by the main controller 50 and a determination example (6) of the sub-controller 60 will be described. First, the temporary data generating unit 51 of the main controller 50 acquires information on the number of stops of the car 7 at each floor as operation data of the elevator 15 via the communication unit 56 (step S81).
[0133] Next, the temporary data generating unit 51 of the main controller 50 generates temporary data using the stop count information acquired in step S81 as an input value (step S82). The temporary data can be generated, for example, by inputting the stop count information into a random number generating function, a hash value function, or the like. That is, the temporary data generating unit 51 can obtain, as the temporary data, a random number or a hash value using the stop count information as an input value.
[0134] Next, the communication path selection unit 52 of the main controller 50 selects a predetermined controller as the sub-controller 60 based on the magnitude of the number of stops (step S83). For example, the communication path selection unit 52 can select the floor controller 11 of the floor on which the number of stops of the car 7 is the smallest as the sub-controller 60. Note that the communication path selection unit 52 may select the floor controller 11 of the floor on which the number of stops of the elevator 15 is the median or the largest as the sub-controller 60. In other words, the value used to select the sub-controller 60 may be any value as long as it is a value that allows the selection of an arbitrary floor controller 11.
[0135] It should be noted that the combinations of temporary data and the sub-controller 60 in the above-mentioned examples (1) to (6) are merely examples, and are not limited to these examples of combinations of temporary data and the sub-controller 60. In addition, the temporary data may be generated based on operation data other than the operation data shown in the examples (1) to (6).
[0136] <Various effects> In the above-described embodiment, the main controller 50 of the elevator system 100 includes a communication path selection unit 52, an encryption unit 54, a communication unit 56, and a determination unit 59 (see FIG. 2 for all of them). The communication path selection unit 52 selects one of the multiple controllers as a sub-controller 60. The encryption unit 54 generates encrypted data by encrypting information including at least the identification information of the sub-controller 60 using the public key 31 acquired from the node 30. The communication unit 56 transmits the encrypted data to the node 30. The determination unit 59 compares the source information of the packet transmitted from the controller identified by the node 30 as the source with the information of the sub-controller 60 selected by the communication path selection unit 52, based on the identification information of the sub-controller 60 obtained by decrypting the node 30 encrypted data. Then, the communication path selection unit 52 determines that the node 30 is an unauthorized device that does not comply with the standards of the elevator system 100, if the two pieces of information do not match.
[0137] Therefore, according to this embodiment, it becomes possible to confirm whether or not an external device (node 30) connected to the elevator system 100 is a genuine device by using only the existing configuration without adding a new device or communication path. Therefore, it is possible to save the cost of adding a new mechanism for authenticating the node 30.
[0138] Furthermore, in the above-described embodiment, the main controller 50 selects the sub-controller 60, and thereby a combination of the main controller 50, the sub-controller 60, and the node 30 is dynamically generated. Then, packets (initial packet P1 to tertiary packet P4) are transmitted between these devices, and the node 30 is authenticated. Therefore, according to this embodiment, it is possible to make it difficult for a third party intending to perform a fraudulent act to analyze the authentication method of the node 30.
[0139] In the above-described embodiment, the communication path selection unit 52 of the main controller 50 selects one of the multiple controllers as the sub-controller 60 based on the operation information of the elevator 15 acquired from the elevator system 100 or the processed information of the operation information. That is, in this embodiment, the sub-controller 60 constituting the communication path of various packets used for authenticating the node 30 is determined based on data that changes dynamically from time to time, i.e., the operation data. Therefore, it is possible to reduce the probability that a third party will detect the communication path of the packets for authenticating the node 30.
[0140] In the above-described embodiment, the discrimination unit 59 of the main controller 50 compares the temporary data generated by the temporary data generation unit 51 with the temporary data extracted and decrypted from the tertiary packet P4 transmitted from the sub-controller 60, and if the two pieces of information do not match, it determines that the node 30 is an unauthorized device. In this embodiment, the temporary data is generated using data that changes dynamically from time to time, that is, operation data, or processed data of the operation data. That is, in this embodiment, authentication is not performed using fixed information such as the serial number and MAC address of the node 30. Therefore, according to this embodiment, even if an unauthorized device node that has faked and copied this information is added, it is possible to prevent the node from being erroneously authenticated as an authorized device.
[0141] Furthermore, in the above-described embodiment, the encrypted data encrypted in the main controller 50 using the public key 31 acquired from the node 30 is decrypted in the node 30 using the private key N32 corresponding to the public key 31. In other words, if the node 30 is an unauthorized device, the node 30 does not possess the public key 31, and therefore the main controller 50 cannot generate encrypted data, nor can the node 30 decrypt the encrypted data, and the authentication process cannot proceed further. Therefore, according to this embodiment, even when a node of an unauthorized device is added, the discrimination unit 59 of the main controller 50 can easily determine that the node is an unauthorized device.
[0142] Furthermore, in the above-described embodiment, the encryption unit 54 of the main controller 50 includes temporary data encrypted using the private key M53 (encrypted temporary data) in the encrypted data, and the decryption unit 58 decrypts the encrypted temporary data included in the tertiary packet P4 transmitted from the sub-controller 60 using the private key M53. If the node 30 is an unauthorized device and cannot properly process the primary packet P2 transmitted from the main controller 50, the tertiary packet P4 including the encrypted temporary data is not transmitted from the sub-controller 60 to the main controller 50. In other words, according to this embodiment, even when an unauthorized node is added, the determination unit 59 of the main controller 50 can easily determine that the node is an unauthorized device.
[0143] Furthermore, in the above-described embodiment, the determination unit 59 of the main controller 50 determines that the node 30 is an unauthorized device when the time from when the communication unit 56 transmits the primary packet P2 including encrypted data to the node 30 until when the tertiary packet P4 is received from the sub-controller 60 exceeds a predetermined threshold time. When the node 30 is an unauthorized device, the secondary communication process of transmitting the secondary packet P3 from the node 30 to the sub-controller 60 and the tertiary communication process of transmitting the tertiary packet P4 from the sub-controller 60 to the main controller 50 are not properly executed. As a result, the communication unit 56 of the main controller 50 cannot receive the tertiary packet P4 transmitted from the sub-controller 60 within the predetermined threshold time from when the primary packet P2 is transmitted from the main controller 50 to the node 30.
[0144] Therefore, according to this embodiment, the discrimination unit 59 of the main controller 50 can easily determine whether or not the node 30 is a legitimate device based on the time between when the main controller 50 transmits the primary packet P2 to the node 30 and when it receives the tertiary packet P4.
[0145] Furthermore, the above-described embodiments provide detailed and specific descriptions of the configurations of the devices and systems in order to clearly explain the present invention, and are not necessarily limited to those having all of the configurations described.
[0146] 1 to 3, the control lines or information lines shown by solid lines are those considered necessary for explanation, and not all control lines or information lines in the product are necessarily shown. In reality, it can be considered that almost all components are connected to each other.
[0147] In addition, in this specification, the processing steps describing chronological processing include not only processing that is performed chronologically in the order described, but also processing that is not necessarily performed chronologically but is performed in parallel or individually (for example, parallel processing or processing by objects).
[0148] Furthermore, each component of the elevator system according to the embodiment of the present invention described above may be implemented in any hardware as long as each hardware can transmit and receive information to and from each other via a network. Furthermore, the processing performed by a certain processing unit may be realized by a single piece of hardware, or may be realized by distributed processing using multiple pieces of hardware. [Explanation of symbols]
[0149] 1...center device, 3...communication controller, 4...group management controller, 5...elevator controller, 10...car controller, 11...floor controller, 12...communication path, 15...elevator, 16...communication path, 17...communication path, 19...maintenance terminal, 20...management terminal, 30...node, 31...public key, 33...decryption unit, 34...packet generation unit, 35...communication unit, 50...main controller, 51...temporary data generation unit, 52...communication path selection unit, 54...encryption unit, 55...packet generation unit, 56...communication unit, 57...address determination unit, 58...decryption unit, 59...discrimination unit, 60...subcontroller, 61...communication unit, 62...packet forwarding unit, 100...elevator system, M53...secret key, N32...secret key, P1...initial packet, P2...primary packet, P3...secondary packet, P4...tertiary packet
Claims
1. An elevator connection device confirmation system for confirming an external device connected to an elevator system including a plurality of controllers, A main controller which is one of the plurality of controllers, a selection unit that selects one of the plurality of controllers as a sub-controller; an encryption unit that generates encrypted information by encrypting information including at least the identification information of the sub-controller using an encryption key obtained from the external device; a transmission unit that transmits the encrypted information to the external device; a discrimination unit that compares source information of a packet transmitted from the controller identified by the external device as a source based on identification information of the sub-controller obtained by the external device decrypting the encrypted information with information of the sub-controller selected by the selection unit, and discriminates that the external device is an unauthorized device that does not comply with the standards of the elevator system if the two pieces of information do not match. Elevator connection equipment confirmation system.
2. The selection unit selects one of the plurality of controllers as the sub-controller based on elevator operation information acquired from the elevator system or processed information of the operation information. The elevator connection device confirmation system according to claim 1.
3. The main controller further includes a temporary information generating unit that generates temporary information using elevator operation information acquired from the elevator system or processed information of the operation information, The encryption unit includes the temporary information generated by the temporary information generation unit in the encrypted information, the packet includes the encrypted temporary information; The determination unit compares the temporary information generated by the temporary information generation unit with the temporary information extracted from the packet and decrypted, and if the two pieces of information do not match, determines that the external device is the unauthorized device. The elevator connection device confirmation system according to claim 2.
4. The encryption key is a public key, and the external device decrypts the encrypted information using a private key corresponding to the public key. The elevator connection device confirmation system according to claim 3.
5. the encryption unit includes the temporary information encrypted using a second private key different from the private key in the encrypted information; The packet is encrypted and the temporary information is decrypted by the second secret key. The elevator connection device confirmation system according to claim 4.
6. The elevator operation information used by the selection unit or the determination unit includes at least one of the following: position information of the elevator car, speed information of the car, load information of the car, call information of the elevator, destination floor information of the elevator, number of trips of the elevator, and number of passengers transported by the elevator. The elevator connection device confirmation system according to claim 5.
7. The discrimination unit determines that the external device is the unauthorized device when a time period from when the transmission unit transmits the encrypted information to the external device to when the packet is received exceeds a predetermined threshold time. The elevator connection device confirmation system according to claim 6.
8. When the discrimination unit determines that the external device is an unauthorized device, the discrimination unit notifies each of the controllers that the external device is an unauthorized device. The elevator connection device confirmation system according to any one of claims 1 to 7.
9. When the discrimination unit determines that the external device is the unauthorized device, the discrimination unit instructs a controller that controls the operation of the elevator to stop the elevator car at the nearest floor. The elevator connection device confirmation system according to claim 8.
10. An elevator connected device confirmation method by an elevator connected device confirmation system for confirming external devices connected to an elevator system including a plurality of controllers, comprising: a step of a main controller, which is any one of the plurality of controllers, selecting any one of the plurality of controllers as a sub-controller; a step of generating encrypted information by encrypting information including at least identification information of the sub-controller by the main controller using an encryption key obtained from the external device; the main controller transmitting the encrypted information to the external device; and a procedure in which the main controller compares source information of a packet transmitted from the controller identified by the external device as a source with information on the selected sub-controller based on identification information of the sub-controller obtained by the external device decrypting the encrypted information, and if the two pieces of information do not match, determines that the external device is an unauthorized device that does not comply with the standards of the elevator system. How to check elevator connection devices.
Citation Information
Patent Citations
Maintenance system, maintenance method, and maintenance terminal device of elevator
JP2010228907A
Elevator
JP2013023356A
Unauthorized device detection method, unauthorized device detection server, and unauthorized device detection system
JP2015146175A
Service tool authentication information management
JP2019023868A
Control method, device, and control system
JP2021111921A