Elevator service management system and elevator service program management method
The elevator service management system addresses fraudulent service use in remote management systems by using a centralized management center to manage and distribute service programs based on contract and execution type, ensuring authorized and legitimate service execution.
Patent Information
- Application Number
- JP2022147419
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-09-15
- Publication Date
- 2025-12-16
- Estimated Expiration
- 2042-09-15
AI Technical Summary
Existing elevator remote management systems are vulnerable to fraudulent manipulation of service settings, allowing unauthorized or incorrect use of elevator services.
An elevator service management system that includes a management center connected to controllers, utilizing a contract information database, program database, and update management unit to generate specialized downloaders based on contract and execution type information, ensuring authentic and authorized service program distribution.
Prevents fraudulent or incorrect use of elevator services by ensuring authorized and legitimate execution of service programs.
Smart Images

Figure 0007787045000001 
Figure 0007787045000002 
Figure 0007787045000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to an elevator service management system and an elevator service program management method, and is suitable for use in an elevator service management system and an elevator service program management method that manage programs for services (elevator services) provided by an elevator system. [Background technology]
[0002] Conventionally, elevator systems have been configured with multiple types of controllers, each equipped with various control and service functions as programs, allowing users to select the services they wish to provide by enabling or disabling the programs.
[0003] For example, Patent Document 1 discloses a remote elevator management system that "includes a remote management device that is connected to the elevator control panel and remotely manages the elevator based on remote management information corresponding to the elevator, and a control system that manages the remote management information." [Prior art documents] [Patent documents]
[0004] [Patent Document 1] International Publication No. 2022 / 064604 Summary of the Invention [Problem to be solved by the invention]
[0005] However, in the elevator remote management system described in the above-mentioned Patent Document 1, as stated in paragraph
[0019] of Patent Document 1, "Only when a single remote management process is started, setting information relating to the process, which indicates whether the process is enabled or disabled, is stored in the control panel 9 as a remote management parameter, and the remote management program is executed according to whether the setting information is enabled or disabled," which poses a problem in that if the setting of enabled or disabled for the setting information is manipulated fraudulently, services that should not be available may be used or may be used incorrectly.
[0006] The present invention has been made in consideration of the above points, and aims to propose an elevator service management system and an elevator service program management method that can prevent unauthorized or incorrect use of elevator services by managing programs stored in the elevator system controller. [Means for solving the problem]
[0007] In order to solve this problem, the present invention provides an elevator service management system that manages services provided from an elevator system based on a contract, comprising: an elevator system having at least one controller that controls the operation of the elevator; and a management center that is communicatively connected to the controller and manages processing programs executed by the controller to provide the services, wherein the management center has a contract information database that holds equipment and facility information that indicates the configuration of the elevator system's devices and facilities, contract type information that indicates the contract type of the service, and execution type information that indicates the execution type of the processing program of the service; a program database that holds processing programs of the service corresponding to each of the execution types; and an update management unit that manages distribution of the processing programs held in the program database to the controller based on information in the contract information database, wherein the update management unit generates a downloader specialized for the controller that downloads the processing program based on the contract type information of the service and the execution type information of the processing program, and provides the downloader to the controller.
[0008] In order to solve the above problem, the present invention provides a program management method for elevator services by an elevator service management system that manages services provided from an elevator system based on a contract, the elevator service management system comprising: an elevator system having at least one controller that controls the operation of the elevator; and a management center that is communicatively connected to the controller and manages processing programs executed by the controller to provide the services, the management center comprising: a contract information database that holds equipment and facility information indicating the configuration of devices and facilities of the elevator system, contract form information that indicates the contract form of the service, and execution form information that indicates the execution form of the processing programs of the service; a program database that holds processing programs of the service corresponding to each of the execution forms; and an update management unit that manages distribution of the processing programs held in the program database to the controller based on information in the contract information database, the update management unit generating a downloader specialized for the controller that downloads the processing program based on the contract form information of the service and the execution form information of the processing program, and providing the downloader to the controller. [Effects of the Invention]
[0009] According to the present invention, fraudulent or incorrect use of elevator services can be prevented. [Brief explanation of the drawings]
[0010] [Figure 1] 1 is a diagram showing an example of the overall configuration of an elevator service management system 1 according to a first embodiment of the present invention. [Figure 2] FIG. 2 is a diagram illustrating an example of the hardware configuration of a controller 20. [Figure 3] 1 is a diagram showing an example of the internal configuration of an elevator service management system 1. FIG. [Figure 4]10 is a diagram showing an example of the data structure of contract type information 103. FIG. [Figure 5] 10 is a diagram showing an example of the data structure of execution mode information 106. FIG. [Figure 6] FIG. 2 is a diagram showing an example of the data structure of authenticity verification means 110. [Figure 7] 10 is a diagram showing an example of the data structure of program information 120. FIG. [Figure 8] 10 is a flowchart illustrating an example of a processing procedure for downloader generation processing. [Figure 9] FIG. 10 is a diagram showing an example of the binary format of the downloader 84. [Figure 10] 10 is a flowchart illustrating an example of a processing procedure for downloading a service program. [Figure 11] FIG. 2 is a diagram showing an example of the data configuration of reply data 210. [Figure 12] FIG. 10 is a diagram showing an example of the internal configuration of the elevator controller 6 after the download process of the service program is completed. [Figure 13] 10 is a flowchart illustrating an example of a processing procedure for authenticity verification processing when a program is started. [Figure 14] 10 is a flowchart illustrating an example of a processing procedure for fraud detection processing. [Figure 15] 10 is a flowchart illustrating an example of a processing procedure for a downloader update process. [Figure 16] 10 is a flowchart illustrating an example of a processing procedure for processing when a contract type is changed. [Figure 17] 10 is a flowchart illustrating an example of a processing procedure for a service deletion process. [Figure 18] FIG. 10 is a diagram showing an example of the internal configuration of a management center 2A in an elevator service management system 1A according to a second embodiment. [Figure 19] 3A and 3B are diagrams illustrating examples of data configurations of service information 301 and execution configuration information 306. [Figure 20] FIG. 10 is a diagram showing an example of a display of a web page for selecting a service or an execution configuration of a service program. [Figure 21]FIG. 21 is a diagram showing an example of a transition screen from the WEB page of FIG. 20. [Figure 22] FIG. 10 is a diagram illustrating an example of a display of a web page for updating a service. [Figure 23] FIG. 23 is a diagram showing an example of a transition screen from the WEB page of FIG. 22. [Figure 24] FIG. 10 is a diagram showing an example of a display of a web page for facility selection. [Figure 25] FIG. 25 is a diagram showing an example of a transition screen from the WEB page of FIG. 24. [Figure 26] FIG. 10 is a diagram (part 1) showing an example of how a web page is displayed in a series of steps for service approval. [Figure 27] FIG. 2 shows an example of how a web page is displayed in the service approval process (part 2). [Figure 28] FIG. 3 shows an example of how a web page is displayed in the service approval process (part 3). [Figure 29] FIG. 4 shows an example of how a web page is displayed in the service approval process. [Figure 30] 10 is a flowchart illustrating an example of a processing procedure for service approval processing. [Figure 31] FIG. 10 is a diagram showing an example of the overall configuration of an elevator service management system 1B according to a third embodiment. [Figure 32] FIG. 10 is a diagram illustrating an example of the internal configuration of a group management controller 5 in a third embodiment. [Figure 33] FIG. 11 is a diagram illustrating an example of the internal configuration of a virtual machine 62 according to the third embodiment. [Figure 34] FIG. 10 is a diagram showing an example of the overall configuration of an elevator service management system 1C according to a fourth embodiment. [Figure 35] FIG. 10 is a diagram illustrating an example of the internal configuration of an elevator controller 6 according to a fourth embodiment. [Figure 36] FIG. 13 is a diagram illustrating an example of the internal configuration of an edge controller 51 according to a fourth embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0011] Hereinafter, embodiments of the present invention will be described in detail with reference to the drawings.
[0012] Note that the following description and drawings are examples for explaining the present invention, and have been omitted or simplified as appropriate for clarity of explanation. Furthermore, not all of the combinations of features described in the embodiments are necessarily essential to the solution of the invention. The present invention is not limited to the embodiments, and all application examples consistent with the concept of the present invention are included in the technical scope of the present invention. Those skilled in the art can make various additions and modifications to the present invention within the scope of the present invention. The present invention can also be implemented in various other forms. Unless otherwise specified, each component may be plural or singular.
[0013] In the following explanation, various types of information may be described using expressions such as "table," "list," "queue," etc., but the various types of information may also be expressed using data structures other than these. To indicate that it is not dependent on the data structure, "XX table," "XX list," etc. may be referred to as "XX information." When describing the content of each piece of information, expressions such as "identification information," "identifier," "name," "ID," "number," etc. are used, but these are interchangeable.
[0014] In addition, in the following explanation, when describing elements of the same type without distinguishing between them, reference signs or common numbers in reference signs will be used, and when describing elements of the same type with distinction between them, the reference signs of those elements will be used or an ID assigned to those elements will be used instead of the reference signs.
[0015] Furthermore, although the following description may describe processing performed by executing a program, the program is executed by at least one processor (e.g., a CPU) to perform a predetermined process using storage resources (e.g., memory) and / or interface devices (e.g., communication ports) as appropriate, and therefore the processor may be the subject of the processing. Similarly, the subject of the processing performed by executing a program may be a controller, device, system, computer, node, storage system, storage device, server, management computer, client, or host having a processor. The subject of the processing performed by executing a program (e.g., a processor) may include a hardware circuit that performs part or all of the processing. For example, the subject of the processing performed by executing a program may include a hardware circuit that performs encryption and decryption, or compression and decompression. The processor operates as a functional unit that realizes a predetermined function by operating in accordance with the program. Apparatuses and systems including a processor are apparatuses and systems that include these functional units.
[0016] A program may be installed on a device such as a computer from a program source. The program source may be, for example, a program distribution server or a non-transitory storage medium readable by a computer. When the program source is a program distribution server, the program distribution server includes a processor (e.g., a CPU) and a non-transitory storage resource, and the storage resource may further store a distribution program and a program to be distributed. Then, the processor of the program distribution server may execute the distribution program, thereby distributing the program to be distributed to other computers. Also, in the following description, two or more programs may be realized as one program, and one program may be realized as two or more programs.
[0017] (1) First embodiment (1-1) Overall structure Fig. 1 is a diagram showing an example of the overall configuration of an elevator service management system 1 according to a first embodiment of the present invention. For the sake of simplicity, Fig. 1 shows the internal configuration of only one elevator 16 in detail.
[0018] The elevator service management system 1 according to this embodiment is a system that manages programs for services (service programs) provided by an elevator system that includes one or more elevators 16. Therefore, the elevator service management system 1 is an elevator system, or a system that includes an elevator system and certain components.
[0019] An elevator system including one or more elevators 16 is connected to, for example, a remotely installed control center 2 in order to manage, monitor, and maintain each of the elevators 16. That is, the elevator service management system 1 (elevator system) includes one or more elevators 16 and the control center 2 connected to the elevators 16 via a communication path 3. Below, a more detailed configuration of the elevator service management system 1 will be described with reference to FIG. 1.
[0020] The management center 2 is connected to a communication controller 4 via a communication path 3. The internal configuration of the management center 2 will be described later with reference to Fig. 3 etc. The communication path 3 may be a closed circuit network such as a dedicated line, or a public line such as the Internet.
[0021] The communication controller 4 is a controller that has a function of mediating communication to realize data transmission and reception, remote operation, and remote maintenance between the management center 2 and the elevators 16. The communication controller 4 is connected to the group management controller 5 via a communication path 18.
[0022] The group management controller 5 is a controller for collectively controlling a plurality of elevators 16 as an elevator group 19, thereby improving the operation efficiency of the elevators 16. The group management controller 5 is connected to a plurality of elevator controllers 6 via a communication path 17. Note that instead of or in addition to the group management controller 5, a management terminal 70, which is a terminal for managing the elevator system, may be configured to be connected to the management center 2 and the elevators 16 via a communication path 18.
[0023] The elevator controller 6 controls the main motor 7 and the movement of the rope 10 connecting the car 8 and the counterweight 9, thereby causing the car 8 to move up and down and stop, thereby providing users with up and down movement services. The elevator controller 6 is connected to one car controller 11 and multiple floor controllers 12 corresponding to the number of floors in the building in which it is installed, via communication path 13. Note that an elevator system configuration without the group controller 5 is also possible, in which case the communication controller 4 is connected to the elevator controller 6 or communication path 17.
[0024] The car controller 11 monitors the status of the car buttons 14 (specifically, for example, the destination floor button and the door open / close button) installed inside the car 8, and notifies the elevator controller 6 of the status change based on the on / off status of the button as an operation and instruction from the user.
[0025] The floor controller 12 monitors the state of the up / down call buttons 15 installed on each floor, for example, and notifies the elevator controller 6 of state changes as operations and instructions by users on each floor.
[0026] In addition, the elevator system of the elevator service management system 1 may also be configured such that the cloud system 60 is connected to the communication controller 4 via the communication path 3. In addition, in this elevator system, additional controllers may be added (added on) to enhance the processing performance and functionality of the various control controllers (communication controller 4, group management controller 5, elevator controller 6, car controller 11, and floor controller 12). Hereinafter, such added controllers will be referred to as edge controllers 51, 52, and 53. FIG. 1 shows edge controller 51 connected to communication path 13, edge controller 52 connected to communication path 17, and edge controller 53 connected to communication path 18. Installing one or more of these edge controllers facilitates enhancing the processing performance and functionality of the elevator system.
[0027] As described above, the elevator system of the elevator service management system 1 is a hierarchical distributed system composed of multiple controllers. Hereinafter, these controllers (communication controller 4, group management controller 5, elevator controller 6, car controller 11, floor controller 12, and edge controllers 51 to 53) will be collectively referred to as "controllers 20." Furthermore, a virtual machine 62 (see FIG. 33) running on a cloud system 60 may also be considered to have a configuration similar to that of the controller 20 in that it can execute service programs. In the elevator service management system 1, the number and combination of multiple controllers 20 can be configured as desired according to customer requests; therefore, the elevator system of the elevator service management system 1 can also be said to be a custom-made system.
[0028] (1-2) Hardware configuration Fig. 2 is a diagram showing an example of the hardware configuration of the controller 20. The controller 20 is a computer, and as shown in Fig. 2, includes a processor 22, a ROM (Read Only Memory) 23, a RAM (Random Access Memory) 24, and an interface (IF) that handles input / output and communication. These components are connected to each other by a system bus 21.
[0029] Specifically, the processor 22 is, for example, an MCU (Micro Controller Unit) or an MPU (Micro Processor Unit), and may also be a CPU (Central Processing Unit) or the like, which is a higher-level concept thereof.
[0030] In the controller 20, the processor 22, the ROM 23, and the RAM 24 constitute a processing unit. Specifically, the ROM 23 is a non-volatile memory that stores binary data (firmware 80) of various programs that implement the control and service processing according to this embodiment. The processor 22 either reads the programs from the ROM 23 and executes them, or reads the programs from the ROM 23 and loads them into the RAM 24 before executing them. The RAM 24 is a volatile memory in which variables, parameters, etc. that are generated during the execution of the programs by the processor 22 are temporarily written, and these variables, parameters, etc. are read and written by the processor 22 as appropriate.
[0031] The ROM 23 may have an area where access is restricted and an area where access is not restricted. If the ROM 23 has these areas, the ROM 23 stores, for example, an individual identifier 85 in the former area and stores the firmware 80 in the latter area (see FIG. 3, which will be described later).
[0032] The interface 25 is a communication interface that enables data transmission and reception between devices such as the controllers 20. Specifically, the interface 25 is, for example, a multi-drop serial communication device such as a GPIO (General Purpose Input / Output) or RS-485, and enables data transmission and reception by wired or wireless communication via a LAN (Local Area Network) or a WAN (Wide Area Network), which are wired communication paths that provide multiple topologies such as Ethernet (registered trademark), or a RAN (Radio Area Network), which is a wireless communication path.
[0033] (1-3) Firmware 80 update management Fig. 3 is a diagram showing an example of the internal configuration of the elevator service management system 1. Focusing on the firmware 80 installed in the controller 20, Fig. 3 shows in detail the internal configuration of the management center 2 that manages updates to the firmware 80. Note that in Fig. 3, an elevator controller 6 is used as an example of the controller 20, but this is not limiting and may be replaced with another controller.
[0034] (1-3-1) Configuration of the controller 20 As shown in Fig. 3, the firmware 80 at the time of shipment is composed of at least a standard control program 81 related to the operation control of the elevator 16 by the elevator controller 6, and a downloader 83. In addition, as described in the explanation of Fig. 2, the ROM 23 stores an individual identifier 85, which is information for identifying the controller 20.
[0035] The standard control program 81 is a program that controls the state of the elevator system by controlling the operation of the elevator 16. Specifically, for example, standard control is performed under normal circumstances, but control can be made to a safe state when an abnormality such as fraud occurs. The content of the safe state control can be set in various ways depending on the abnormality that has occurred, but for example, it can be set to move the car 8 to the nearest floor and open the door.
[0036] The downloader 83 is a program that downloads a service program (a program for service processing that provides elevator services) for shipment (initial use). When the downloader 83 is started for the first time, it notifies the management center 2 of an individual identifier 85. Because the individual identifier 85 is important information, it is notified after undergoing measures such as encryption. The management center 2 generates a new downloader program, downloader 84, based on the contract information corresponding to the individual identifier 85 and transmits it to the controller 20. Then, upon receiving the new downloader 84, the downloader 83 replaces itself with the new downloader 84.
[0037] (1-3-2) Configuration of Management Center 2 3, the management center 2 includes a contract information database (DB) 100, an authenticity verification means database (DB) 110, a program database (DB) 120, a generation information database (DB) 130, and a management center control unit 140. The contract information DB 100, the authenticity verification means DB 110, the program DB 120, and the generation information DB 130 are all storage means such as databases that store information (data), and the management center control unit 140 is control means that provides various functions by a processor executing a program.
[0038] (1-3-2-1) Contract Information DB 100 The contract information DB 100 manages information related to the contract for each customer, and more specifically, manages equipment facility information 101 of the elevator system, contract form information 103, and execution form information 106. In the following description, this information managed by the contract information DB 100 may be collectively referred to as contract information 100.
[0039] The equipment and facility information 101 is information about the equipment and facilities that make up the elevator system. Specifically, the equipment and facility information 101 is information indicating, for example, the presence or absence, number, or connection form of each component, and may include an individual identifier 85 of each component.
[0040] Contract type information 103 is information about the type of contract for each customer, and is information about the type of service provided under the contract. FIG. 4 is a diagram showing an example of the data structure of contract type information 103. As shown in FIG. 4, contract type information 103 includes a service ID 104 indicating an identifier for the service process provided and a contract type 105 indicating the type of contract. Contract type 105 includes three types: "subscription," "purchase," and "cancellation." "Subscription" is a contract type that imposes a predetermined limit on the time or number of times the service can be used. "Purchase" is a contract type that allows the service to be used permanently in principle. "Cancellation" is a contract type that means the service is canceled, and the service program for the service must be deleted or replaced. "Subscription" is further divided into two types: "renewal (maintaining execution type)" and "change of execution type (controller, edge controller, cloud)." "Purchase" is further divided into two types: changing the subscription contract service to purchase by "contract change" at the time of renewal, and purchasing it as a "new" service.
[0041] The execution mode information 106 is information relating to the execution mode of the service processing for providing the service. FIG. 5 is a diagram showing an example of the data configuration of the execution mode information 106. As shown in FIG. 5, the execution mode information 106 has an execution type 107 and a program ID 108 indicating the identifier of the program executed in the service processing. More specifically, the program ID 108 is the identifier of the program executed in the remote system or the control controller in the service processing. Specifically, the execution type 107 has three types: local execution in the controller 20; remote execution in the edge controllers 51, 52, and 53; and remote execution in the cloud system 60.
[0042] (1-3-2-2) Authenticity confirmation means DB110 The authenticity verification means DB 110 manages information relating to means for verifying the authenticity of the program (firmware 80), and more specifically, manages a digest value method 111 for verifying the authenticity of the firmware 80 and an encryption method 113 for the firmware 80. In the following description, this information managed by the authenticity verification means DB 110 may be collectively referred to as the authenticity verification means 110.
[0043] FIG. 6 is a diagram showing an example of the data configuration of the authenticity verification means 110. As shown in FIG. 6, the authenticity verification means 110 manages the digest value method 111 and the encryption method 113 by combining a verification means ID 115 for distinguishing the verification means and programs for authenticity verification processes (A-type verification process 116, B-type verification process 117, and C-type verification process 118) corresponding to each type of processor 22 (e.g., CPU A, CPU B, and CPU C) used in the elevator system. Specific examples of the digest value method 111 include a hash value and a MAC (Message Authentication Code), and a specific example of the encryption method 113 includes an AES (Advanced Encryption Standard). It is preferable that the authenticity verification means 110 use an individual identifier 85 specific to the controller 20, but this is not limited thereto.
[0044] (1-3-2-3) Program DB120 The program DB 120 is information for managing a program (firmware 80) for each service process that provides a service. In the following description, the information managed by the program DB 120 may be collectively referred to as program information 120.
[0045] Fig. 7 is a diagram showing an example of the data configuration of the program information 120. As shown in Fig. 7, the program information 120 requires that firmware 80 corresponding to the type of processor 22 (e.g., CPU A, CPU B, CPU C) installed in the controller 20 be prepared. Furthermore, when the elevator system is connected to a cloud system 60, it is also necessary to prepare a program corresponding to the type of cloud system 60.
[0046] 7 shows an example in which program information 120 manages, for one service process, service programs corresponding to three types of processors 22 (CPU A, CPU B, CPU C) and three types of cloud systems 60 (cloud X, cloud Y, cloud Z). Cloud X, cloud Y, and cloud Z are environments in which virtual machines corresponding to controller 20 operate. Each service program managed by program information 120 is assigned a program ID 108 of execution form information 106 shown in FIG. 5.
[0047] More specifically, the program information 120 in FIG. 7 manages, as firmware 121 for controller, a service program 122 for service processing that corresponds to the firmware 80 locally executed by the controller 20.
[0048] 7 manages, as edge controller firmware 123, a service program 125 for service processing executed by the edge controllers 51, 52, and 53. The service program 125 is managed in combination with client firmware 124 executed by the controller 20 to use the program remotely.
[0049] 7 manages a service program 128 for service processing executed in the cloud system 60 as firmware 126 for the cloud system. This service program 128 is also managed in combination with client firmware 127 executed in the controller 20 to use the program remotely.
[0050] (1-3-2-4) Generation information DB130 The generation information DB 130 manages information about downloaders generated by the management center control unit 140, specifically, contract information 131, authenticity information 133, and program configuration information 135. Conventional downloaders are generally general-purpose programs specialized for downloading binary data, and their configurations have not changed significantly. Therefore, the operation and communication content of the downloader may be analyzed. In contrast, this embodiment generates a downloader specialized for each customer based on a combination of various information, such as device configuration information, contract type (subscription or purchase), and service processing execution type, thereby making such analysis difficult. Furthermore, even if a downloader is analyzed and the service processing (i.e., the service program) is illegally copied, it is possible to make long-term unauthorized use difficult.
[0051] (1-3-2-5) Management center control unit 140 3, the management center control unit 140 is configured to include an update management unit 141, an execution format selection unit 143, a program selection unit 145, a downloader generation unit 147, and a downloader distribution unit 149. The functions of each unit of the management center control unit 140 are realized by a processor in the computer of the management center 2 reading and executing a predetermined program.
[0052] The update management unit 141 is a processing unit that is responsible for overall control in the management center control unit 140, and in addition to controlling the operation of other processing units, it manages the contract information 100, authenticity verification means 110, program information 120, and generation information 130, and further manages the update status of each.
[0053] The execution mode selection unit 143 selects an appropriate execution mode based on the contract information 100.
[0054] The program selection unit 145 selects from the program information 120 a combination of programs (firmware) that corresponds to the execution mode selected by the execution mode selection unit 143.
[0055] The downloader generation unit 147 generates a downloader for appropriately downloading the firmware selected by the program selection unit 145 .
[0056] The downloader distribution unit 149 distributes the downloader generated by the downloader generation unit 147 to the target controller 20 (for example, the elevator controller 6).
[0057] (1-4) Creating a downloader The following describes a downloader generation process in which the management center control unit 140 generates a downloader 84 specialized for each controller 20 based on the contract information 100.
[0058] 8 is a flowchart showing an example of the procedure for downloader generation processing, and FIG. 9 is a diagram showing an example of the binary format of the downloader 84.
[0059] 8, first, the update management unit 141 of the management center control unit 140 acquires the device and facility information 101, contract type information 103, and execution type information 106 of the target customer from the contract information 100 (step S100). Through this process, the update management unit 141 can acquire a combination of a service ID 104 and a contract type 105 for the contract of the target customer. Thereafter, the processes from steps S102 to S110 are executed by selecting one service ID 104 from the acquired combinations.
[0060] Next, the execution mode selection unit 143 identifies what devices are available for providing the service corresponding to the selected service ID 104, based on the device facility information 101 and the execution mode information 106 acquired in step S100 (step S102). Specifically, the execution mode selection unit 143 identifies the controller 20, the edge controllers 51, 52, and 53, or the cloud system 60 as available devices.
[0061] Next, the program selection unit 145 selects a program corresponding to the controller 20, the edge controllers 51, 52, 53, or the cloud system 60 from the program information 120 based on the identification result of step S102 (step S104). Through this process, the program selection unit 145 can acquire the program ID 108 corresponding to the service ID 104.
[0062] Next, the downloader generation unit 147 selects any digest value method 111 or encryption method 113 from the authenticity verification means 110 (step S106). This process enables the downloader generation unit 147 to acquire the program ID 108 of the program for the authenticity verification process (the A-type verification process 116, the B-type verification process 117, and the C-type verification process 118 shown in FIG. 6). Note that, as an example of a method for selecting an authenticity verification means in step S106, a selection method based on random number generation using the operation status of the elevator system as a seed is assumed, but the present embodiment is not limited to this selection method.
[0063] Next, the downloader generation unit 147 checks whether the authenticity verification means (program for authenticity verification processing) selected in step S106 exists in a temporary authenticity verification program list that lists programs for authenticity verification processing (step S108).
[0064] In step S108, if the authenticity verification means (program for authenticity verification processing) selected in step S106 does not exist in the temporary authenticity verification program list ("New" in step S106), the downloader generation unit 147 adds the program to the authenticity verification program list (step S110) and proceeds to step S112. On the other hand, in step S108, if the authenticity verification means (program for authenticity verification processing) selected in step S106 does exist in the temporary authenticity verification program list ("Existing" in step S106), the downloader generation unit 147 proceeds to step S112 without executing the processing of step S110.
[0065] In step S112, the management center control unit 140 (for example, the update management unit 141) checks whether or not there are any unprocessed service IDs 104 that have not been processed in steps S102 to S110 for the service IDs 104 that have been combined with the contract type 105 in step S100. If there are any unprocessed service IDs 104 remaining ("Yes" in step S112), the process returns to step S102, where one of the unprocessed service IDs 104 is selected and the process is repeated.
[0066] On the other hand, if there are no unprocessed service IDs 104 remaining in step S112 ("NO" in step S112), the downloader generation unit 147 converts the service ID 104 into a service number (service No.) 202 (step S114). The service No. 202 is a new number specific to the individual identifier 85 (a new number for each individual identifier 85). By providing the service No. 202, it becomes possible to make it difficult to guess the unique service ID 104 in the elevator system.
[0067] Next, the downloader generation unit 147 executes authenticity confirmation processing using the authenticity confirmation means 110 on the combination of the converted service No. 202, and temporarily stores the execution result as authenticity confirmation information (combination authentic) 204 (step S116).
[0068] Finally, the downloader generation unit 147 generates the downloader 84 by linking the service list 201, the authenticity confirmation information 204, the authenticity confirmation processing list 205, and the communication processing program 207 that communicates this information (step S118).
[0069] Here, the service list 201 is a list having, as elements, at least one combination of the service No. 202 converted in step S114 and an authenticity number (authenticity No.) 203 indicating the order of the program for authenticity verification processing on the temporary authenticity verification program list generated in step S108. The authenticity verification processing list 205 is a list of programs for authenticity verification processing (authenticity verification processing programs 206) corresponding to the temporary authenticity verification program list. Furthermore, the communication processing program 207 is a program generated according to a combination of the device indicated in the device information 101 and the communication path forming the route to the device. Figure 9 shows an example of the binary format of the downloader 84 generated as described above.
[0070] By configuring the downloader 84 as described above, the management center control unit 140 can generate a downloader specialized for the contract information 100. Such a downloader 84 assigns a different authenticity confirmation means 110 to each service process, and further applies the authenticity confirmation means 110 to combinations of service processes as well, thereby utilizing the authenticity confirmation means 110 multiple times, making it difficult to execute an illegal copy of the downloader 84 on another controller or to illegally copy part of the service process (program) and run it on another controller.
[0071] 9, in this embodiment, the downloader 84 preferably has a data format specialized for the individual identifier 85 of the controller 20. Specifically, for example, a method can be envisioned in which the downloader 84 is encrypted using the individual identifier 85. In this case, the encryption and decryption processing programs are stored in an area of the ROM 23 that is access-restricted, just like the individual identifier 85.
[0072] Furthermore, in this embodiment, the management center 2 (management center control unit 140) can further enhance the effectiveness of preventing unauthorized copying and use of the program by appropriately regenerating a new downloader 84. Specific timings for regeneration include, for example, when the contract type is changed, when the execution type is changed, or periodically.
[0073] Also, although FIG. 9 shows the downloader 84 for updating, the downloader 83 before updating may also have a similar binary format.
[0074] (1-5) Downloading the service program Fig. 10 is a flowchart showing an example of the processing procedure for downloading a service program. Hereinafter, with reference to Fig. 10, a process will be described in which the controller 20, after updating its own downloader 83 with the downloader 84 generated by the process of Fig. 8, uses the downloader 84 to download a service program based on the contract information 100 from the management center 2.
[0075] According to FIG. 10, first, the controller 20 transmits a plurality of service numbers 202 to the management center 2 based on the service list 201 of the downloader 84 (step S200).
[0076] When the management center 2 receives the service number 202 sent by the controller 20 in step S200 (step S250), it converts the received service number 202 into a service ID 104 and selects a program corresponding to the converted service ID 104 from the program DB 120 (step S252). Note that the processing of the management center 2 shown in Fig. 10 is mainly executed by the management center control unit 140, and this is also common to the processing of the management center 2 in other flowcharts described later.
[0077] Next, the management center 2 extracts a portion of the contract type information 103 corresponding to the above service ID 104 to generate contract conditions 211 (step S254). In Fig. 11 etc. described later, the contract conditions 211 are abbreviated to conditions 211. The contract conditions 211 generated in step S254 are data indicating the service No. 202, subscription or purchase information, contract period, etc.
[0078] Next, the management center 2 executes a predetermined process on the program selected in step S252 using the authenticity verification means 110 corresponding to the service No. 202, and generates processed data 213 (step S256).
[0079] Next, the management center 2 checks whether or not there is an unprocessed service No. 202 among the service No. 202 received in step S250 (step S258). If there is an unprocessed service No. 202 remaining ("Yes" in step S258), the management center 2 returns to step S252.
[0080] In step S258, if all service Nos. 202 have been processed ("No" in step S258), the management center 2 combines the contract conditions 211 generated in step S254 with the processed data 213 generated in step S256 to generate reply data 210 (step S260).
[0081] 11 is a diagram showing an example of the data configuration of the reply data 210. As shown in FIG. 11, the reply data 210 is configured to include one or more combinations of contract conditions 211 and corresponding processed data 213.
[0082] Then, the management center 2 transmits the reply data 210 generated in step S260 to the controller 20 (step S262). As described above, the reply data 210 includes processed data 213 obtained by performing the authenticity verification process by the authenticity verification means 110 on the program corresponding to the service ID 104.
[0083] The structure of the program corresponding to the service ID 104 when it is communicated may differ depending on the result of the selection of the authenticity verification means method when generating the downloader 84 (see step S106 in FIG. 8). For example, if the digest value method 111 is a HASH function, the data to be transmitted will be binary data that combines the program body and the digest value of the program. Also, if the encryption method 113 is an arbitrary encryption algorithm, the data to be transmitted will be binary data that encrypts the program.
[0084] When the controller 20 receives the reply data 210 from the management center 2 (step S202), the controller 20 divides the received reply data 210 into contract conditions 211 and processed data 213 (step S204).
[0085] Next, the controller 20 extracts the service number 202 from the received contract conditions 211, and executes processing for the combination by the authenticity confirmation means 110 (step S206). Then, the controller 20 compares the execution result of step S206 with the authenticity confirmation information 204 of the corresponding combination (step S208).
[0086] If the execution result of step S206 does not match the authenticity verification information 204 in step S208, the controller 20 determines that fraud has occurred ("Fraud" in step S208) and transitions the elevator system to a safe state using the standard control program 81 (step S222).
[0087] On the other hand, if the execution result of step S206 matches the authenticity confirmation information 204 in step S208, the controller 20 determines that it is normal ("Normal" in step S208), and executes the authenticity confirmation process for the processed data 213 linked to each of the contract conditions 211 that were the basis for comparison using the authenticity confirmation process program indicated by the corresponding authenticity No. 203 (step S210).The controller 20 then checks the execution result of the authenticity confirmation process in step S210 (step S212).
[0088] If the authenticity verification process does not end normally in step S212, the controller 20 determines that fraud has occurred ("Fraud" in step S212), and causes the standard control program 81 to transition the elevator system to a safe state (step S222).
[0089] On the other hand, if the authenticity verification process is completed successfully in step S212, the controller 20 determines that the program is normal ("Normal" in step S212), and checks which contract type (e.g., subscription or purchase) the program corresponds to by referring to the corresponding contract conditions 211 for the program for which the authenticity verification process was performed (step S214).
[0090] If the contract type is "subscription" in step S214 ("Subscription" in step S214), the controller 20 stores the program after the above-mentioned authenticity confirmation process as a subscription service program 222 in RAM 24 together with the above-mentioned contract conditions 211 (step S216). On the other hand, if the contract type is "purchase" in step S214 ("Purchase" in step S214), the controller 20 stores the program after the above-mentioned authenticity confirmation process as a purchase service program 220 in ROM 23 together with the above-mentioned contract conditions 211 (step S218). In the drawings and the following description, the purchase service program 220 may be referred to as a purchase service 220, and the subscription service program 222 may be referred to as a subscription service 222.
[0091] After steps S216 and S218, the controller 20 checks whether there is any processed data 213 for which the processing of steps S210 to S218 has not been completed (step S220), and if there is any corresponding processed data 213 ("YES" in step S220), the controller 20 returns to step S210 and repeats the processing. If there is no corresponding processed data 213 ("NO" in step S220), the controller 20 ends the download processing of the service program.
[0092] Fig. 12 is a diagram showing an example of the internal configuration of the elevator controller 6 after the download process of the service program is completed. As shown in Fig. 12, after the download process of the service program is completed, in the elevator controller 6, the ROM 23 stores the standard control program 81, the individual identifier 85, a new downloader 84 specialized for the controller 20, a buy-back service 220 which is a service program that has been bought, and condition data (conditions 211) associated with the buy-back service 220. In addition, the RAM 24 stores the subscription service 222 which is a service program currently being subscribed to, and the condition data (conditions 211) associated with the subscription service 222.
[0093] As described above, in the elevator service management system 1, service programs are downloaded using a downloader 84 specialized for the elevator controller 6, thereby preventing unauthorized rollback of firmware caused by unauthorized use of the old downloader 83 installed at the time of shipment.
[0094] (1-6) Service program verification process when starting a program Fig. 13 is a flowchart showing an example of the processing procedure for authenticity verification processing at program startup. The processing shown in Fig. 13 is a processing for determining whether there is any fraud related to the service program by executing the authenticity verification processing etc. at program startup, and transitioning the elevator system to a safe state if fraud is determined. Note that the processing shown in Fig. 13 is not limited to when the program is started, such as when the elevator system starts operating, but may also be executed, for example, when a predetermined long time has elapsed since the elevator system started operating. Furthermore, the processing of Fig. 13 will be described below using the pre-update downloader 83 in the controller 20, but the processing of Fig. 13 can also be executed by the post-update downloader 84.
[0095] According to FIG. 13, first, in the controller 20, the downloader 83 checks the contract conditions 211 stored in the ROM 23, the contract conditions 211 stored in the RAM 24, and the service list 201 held within the downloader 83 (step S300), and determines whether the respective service numbers 202 match (step S302).
[0096] If the service No. 202 does not match in step S302 ("Mismatch" in step S302), the downloader 83 determines that fraud has occurred and causes the elevator system to transition to a safe state using the standard control program 81 (step S318). On the other hand, if the service No. 202 matches in step S302 ("Match" in step S302), the downloader 83 executes the authenticity confirmation means 110 for the service No. 202 included in the contract conditions 211 stored in ROM 23 and the service No. 202 included in the contract conditions 211 stored in RAM 24 in accordance with the order of the service No. 202 saved in the service list 201 (step S304).
[0097] Next, the downloader 83 compares the execution result of step S304 with the combination authenticity confirmation information 204 (step S306). If the comparison result in step S306 is a mismatch ("Mismatch" in step S306), the downloader 83 determines that fraud has occurred and causes the standard control program 81 to transition the elevator system to a safe state (step S318).
[0098] On the other hand, if the comparison result in step S306 is a match ("Match" in step S306), the downloader 83 selects, for the program on ROM 23 and the program on RAM 24 corresponding to the service No. 202 in the service list 201, the authenticity confirmation processing program 206 in the authenticity confirmation processing list 205 corresponding to the authenticity No. 203 assigned to each of them shown in the service list 201 (step S308).The downloader 83 then executes the authenticity confirmation processing program 206 selected in step S308 (step S310) and checks the execution result (step S312).
[0099] If the execution result in step S312 is abnormal ("Failure" in step S312), the downloader 83 determines that fraud has occurred, and causes the standard control program 81 to transition the elevator system to a safe state (step S318).
[0100] On the other hand, if the execution result is normal in step S312 ("Success" in step S312), the downloader 83 checks whether any of the service Nos. 202 registered in the service list 201 has not yet undergone authenticity verification (step S314). If there is an unexecuted service No. 202 ("Yes" in step S314), the process returns to step S308 and repeats the process for the corresponding service No. 202. On the other hand, if the authenticity verification has been performed for all service Nos. 202 ("No" in step S314), the downloader 83 starts the standard control program 81 by normal control (step S316) and ends the process.
[0101] As described above, in the elevator service management system 1, by performing the authenticity confirmation process when a program is started, it is possible to prevent execution of some service processes (such as the service program 122) by illegal copying.
[0102] (1-7) Processing when fraud is detected Fig. 14 is a flowchart showing an example of a processing procedure for processing when fraud is detected. In the processing shown in Fig. 13, when fraud in a service program is detected, the controller 20 (downloader 83) takes action to transition the elevator system to a safe state, but in the processing shown in Fig. 14, as another method of dealing with when fraud in a service program is detected, fraud information is sent to the management center 2. Note that the processing in Fig. 13 and the processing in Fig. 14 may be executed in combination. Furthermore, the processing in Fig. 14 will be described below using the downloader 83 in the controller 20 before it is updated, but the processing in Fig. 14 can also be executed by the downloader 84 after it is updated.
[0103] According to FIG. 14, first, in the controller 20, the downloader 83 checks the contract conditions 211 stored in the ROM 23, the contract conditions 211 stored in the RAM 24, and the service list 201 held within the downloader 83 (step S400), and determines whether the respective service numbers 202 match (step S402).
[0104] If the service number 202 does not match in step S402 ("Mismatch" in step S402), the downloader 83 determines that fraud has occurred, generates fraud information of "Service mismatch" including information on the service number 202 for which the mismatch has been confirmed (step S404), and transmits the generated fraud information to the management center 2 (step S406).
[0105] When the controller 20 (downloader 83) transmits the fraudulent information to the management center 2 in step S406, it is desirable to encrypt the fraudulent information using, for example, the individual identifier 85 of the controller 20 before transmitting it. After the processing of step S406, the controller 20 ends the processing, and the management center 2 that receives the fraudulent information executes the processing from step S450 onwards, which will be described later.
[0106] On the other hand, if the service No. 202 matches in step S402 ("Match" in step S402), the downloader 83 executes the authenticity verification means 110 for the service No. 202 included in the contract conditions 211 stored in ROM 23 and the service No. 202 included in the contract conditions 211 stored in RAM 24 in accordance with the order of the service No. 202 stored in the service list 201 (step S408).
[0107] Next, the downloader 83 compares the execution result of step S408 with the combination authenticity confirmation information 204 (step S410). If the comparison result in step S410 is a mismatch ("Mismatch" in step S410), the downloader 83 determines that fraud has occurred, generates fraud information of "Mismatched combination" including information indicating the mismatched combination (step S412), and transmits the generated fraud information to the management center 2 (step S406).
[0108] On the other hand, if the comparison result in step S410 is a match ("Match" in step S410), the downloader 83 selects, for the program on ROM 23 and the program on RAM 24 corresponding to the service No. 202 in the service list 201, the authenticity confirmation processing program 206 in the authenticity confirmation processing list 205 corresponding to the authenticity No. 203 assigned to each of them shown in the service list 201 (step S414).The downloader 83 then executes the authenticity confirmation processing program 206 selected in step S412 (step S416) and checks the execution result (step S418).
[0109] If the execution result in step S418 is abnormal ("Abnormal" in step S418), the downloader 83 determines that fraud has occurred, generates fraud information "Authenticity verification failed" including service No. 202 whose authenticity verification failed (step S420), and sends the generated fraud information to the management center 2 (step S406).
[0110] On the other hand, if the execution result is normal in step S418 ("Normal" in step S418), the downloader 83 checks whether any of the service Nos. 202 registered in the service list 201 has not yet undergone authenticity verification (step S422). If there is an unexecuted service No. 202 ("Yes" in step S422), the process returns to step S414 and repeats the process for the corresponding service No. 202. On the other hand, if the authenticity verification has been performed for all service Nos. 202 ("No" in step S422), the downloader 83 starts the standard control program 81 under normal control (step S424) and ends the process.
[0111] When the unauthorized information is transmitted from the controller 20 in step S406, the management center 2 (management center control unit 140) receives the unauthorized information (step S450). If the received unauthorized information is encrypted, the management center 2 decrypts it and interprets the unauthorized information (step S452).
[0112] Specifically, if the fraudulent information is "service mismatch," it means that the total number of services being used is inappropriate (the number of services is too few or too many). If the fraudulent information is "combination mismatch," it means that the number of services being used is appropriate (the same), but the content of the services is inappropriate (the content of the services is different, or the order of the registered services is different). If the fraudulent information is "authenticity verification failed," it means that the program (service program) in RAM 24 or ROM 23 corresponding to the service in question is different from the genuine product, or the authenticity verification means is different from the genuine product (i.e., downloader 83 is not genuine).
[0113] The management center 2 then records the result of interpreting the fraudulent information in the contract information DB 100 (step S454), and ends the process.
[0114] By performing the fraud detection process as described above, the elevator service management system 1 can not only detect and understand fraudulent situations related to the service programs stored in the ROM 23 and RAM 24 of the controller 20, but also identify the individual identifier 85 related to the fraud. Therefore, the management center 2 can also identify the specific controller 20 in which fraud was detected, based on the interpretation result of the fraudulent information recorded in the contract information 100 and the device facility information 101 of the contract information 100.
[0115] (1-8) Downloader update process 15 is a flowchart showing an example of the processing procedure for downloader update processing. When the contract information 100 is changed, the elevator service management system 1 executes downloader update processing to update the downloader of the controller 20 from the previous downloader 83 to the downloader 84 corresponding to the changed contract information 100.
[0116] According to FIG. 15, first, the management center 2 (hereinafter, may be read as the management center control unit 140) detects a change in the contract information managed in the contract information DB 100 as the contract information is updated (step S500).
[0117] Next, the management center 2 generates a new downloader 84 related to the update by the downloader generation process shown in Fig. 8 (step S502). Then, the management center 2 encrypts the generated downloader 84 as described in the explanation of Fig. 8.
[0118] Next, the management center 2 transmits the downloader 84 encrypted in step S504 as an update event to the controller 20 related to the update (step S506). Thereafter, the management center 2 waits for the progress of processing in the controller 20 to which the downloader 84 was transmitted, and when the service number 202 is transmitted from the controller 20 (corresponding to step S200 in FIG. 10), the management center 2 transmits this (corresponding to step S250 in FIG. 10).
[0119] Meanwhile, the controller 20 involved in the update receives the encrypted downloader 84 transmitted from the management center 2 in step S506 (step S550) and decrypts it (step S552). The decryption process is executed by using a boot loader or the like that is provided in advance with encryption / decryption processing utilizing the individual identifier 85, for example.
[0120] Next, the controller 20 overwrites the downloader 83 stored in the ROM 23 with the decrypted new downloader 84 (step S554).
[0121] Then, the controller 20 executes the new downloader 84 based on the operation status of the elevator system (step S556). Specifically, for example, when the entire elevator system is in a safe state, the controller 20 executes the downloader 84. Alternatively, the controller 20 executes the downloader 84 when the elevator system is restarted after a regular inspection. By executing the new downloader 84 related to the update of the contract information in this way, the download process of the service program is started as described in Fig. 10, and the controller 20 transmits a plurality of service Nos. 202 to the management center 2 based on the service list 201 of the downloader 84 (step S200).
[0122] By executing the downloader update process as described above, the elevator service management system 1 can quickly replace the existing downloader 83 with the latest downloader 84 corresponding to the update of the contract information when a change occurs in the management information (contract information) of the contract information DB100.
[0123] (1-9) Processing when changing contract type 16 is a flowchart showing an example of the processing procedure for contract type change processing. When the elevator service management system 1 is using a service through local execution under the contract type of "subscription" and the contract status is changed to "purchase," the elevator service management system 1 executes the contract type change processing shown in FIG.
[0124] According to FIG. 16, first, the management center 2 (hereinafter, may be read as the management center control unit 140) detects a change in the contract information managed in the contract information DB 100 in accordance with a change in the contract type (step S600).
[0125] Next, the management center 2 modifies the conditions 211 for the service whose contract type has been changed from subscription to purchase (step S602), and then encrypts the modified conditions 211 (step S604).
[0126] Next, the management center 2 transmits the condition 211 encrypted in step S604 as a change event to the controller 20 related to the change (step S606). After that, the management center 2 waits until the result of the modification of the condition 211 is transmitted from the controller 20 in step S662, which will be described later.
[0127] On the other hand, the controller 20 involved in the change receives the encrypted condition 211 sent from the management center 2 in step S606 (step S650), and decrypts it (step S652).
[0128] Next, in the controller 20, the downloader 83 (or the downloader 84) searches for a service corresponding to the condition 211 decrypted in step S652 (step S654), and checks the search result (step S656).
[0129] If a corresponding service is found in step S656 (YES in step S656), the downloader 83 modifies the conditions 211 stored in the RAM 24 based on the search results (step S658).
[0130] Then, the downloader 83 moves the conditions 211 modified in step S658 and the subscription service 222 (see FIG. 12) stored in RAM 24 corresponding to the conditions 211 to ROM 23 (step S660). One example of the movement process in step S660 is to temporarily stop the subscription service 222 and move the subscription service 222 stored in RAM 24 to ROM 23. Furthermore, the downloader 83 may clear the area of RAM 24 after the movement to zero. Furthermore, the downloader 83 may write a return command to the entry point of the area cleared to zero.
[0131] Thereafter, the downloader 83 transmits the result of the transfer process carried out in step S660 to the management center 2 as the result of correcting the condition 211 (step S662).
[0132] On the other hand, if a corresponding service cannot be found in step S656 ("NO" in step S656), the downloader 83 transmits to the management center 2 a result of correcting the condition 211 that a corresponding service does not exist (step S662).
[0133] Then, upon receiving the results of the correction of the condition 211 transmitted in step S662, the management center 2 receives the results of the correction (step S608) and checks the contents of the results of the correction (step S610).
[0134] If the correction result in step S610 indicates that there is no service that changes the contract type from "subscription" to "purchase" ("None" in step S610), the management center 2 determines that fraud has occurred, records information indicating the nature of the fraud in the contract information DB100 (step S612), and abnormally terminates the processing.
[0135] On the other hand, if the correction result in step S610 indicates the result of the program migration process in step S660 ("Yes" in step S610), the management center 2 determines that the change in contract type for the service from "subscription" to "purchase" has been successfully executed, and terminates the process normally.
[0136] As a variant of the processing when the contract type is changed, if there are multiple services under contract with the "subscription" contract type and the contract type for some of the services is changed from "subscription" to "purchase," the management center 2 may generate a dedicated downloader specialized for the remaining combinations of "subscription" service programs, excluding the subscription service 222 moved from RAM 24 to ROM 23 by the processing of step S660 by the controller 20, and send it to the controller 20.
[0137] By executing the contract type change process as described above, the elevator service management system 1 can detect fraudulent service processing when the contract type is changed from "subscription" to "purchase." When the service contract type is changed from "purchase" to "subscription," the program transfer process in step S660 can be changed to move the corresponding program from ROM 23 to RAM 24, and the contract type change process similar to that shown in Fig. 16 can be executed, and as a result, the elevator service management system 1 can detect fraudulent service processing when the contract type is changed.
[0138] (1-10) Processing when service is cancelled Fig. 17 is a flowchart showing an example of a processing procedure for service cancellation processing. When a service is canceled due to a change in the contract status, such as cancellation of a service subscription or deletion of a purchased service, the elevator service management system 1 executes the service cancellation processing shown in Fig. 17.
[0139] 17, first, the management center 2 (hereinafter, may be read as the management center control unit 140) registers the cancellation of the service contract in the contract information DB 100 (step S700). Specifically, the management center 2 modifies the conditions 211 of the corresponding service to a deleted state. The management center 2 also assigns an instruction (deletion work instruction) to the conditions 211 as to whether to immediately execute the deletion work or to postpone it. Then, the management center 2 encrypts the conditions 211 that have been modified to a deleted state (step S702).
[0140] Next, the management center 2 transmits the condition 211 encrypted in step S702 to the controller 20 related to the deletion as a deletion event (step S704). After that, the management center 2 waits until an instruction result is transmitted from the controller 20 in step S766, which will be described later.
[0141] On the other hand, the controller 20 involved in the deletion receives the encrypted condition 211 sent from the management center 2 in step S704 (step S750), and decrypts it (step S752).
[0142] Next, in the controller 20, the downloader 83 (or the downloader 84) searches for a service corresponding to the condition 211 decrypted in step S752 (step S754), and checks the search result (step S756).
[0143] If a corresponding service is found in step S756 (YES in step S756), the downloader 83 refers to the deletion work instruction given to the above condition 211 (step S758) and checks the instruction content (step S760).
[0144] If the deletion work instruction is for immediate execution ("IMMEDIATE" in step S760), the downloader 83 stops the target service and modifies the service program of the target service stored in ROM 23 or RAM 24 (step S762). If the deletion work instruction is for pending ("PEND" in step S760), the downloader 83 modifies the condition 211 of the target service stored in ROM 23 or RAM 24 to the deleted state (step S764).
[0145] After the processing of step S762 and step S764, the downloader 83 transmits the processing result of step S762 or step S764 to the management center 2 as an instruction result indicating that the deletion work instruction has been processed normally (step S766).
[0146] If a corresponding service cannot be found in step S756 ("No" in step S756), the deletion instruction for the service program of the service in question cannot be executed, and therefore the downloader 83 sends an instruction result indicating an abnormality to the management center 2 in step S766.
[0147] Then, upon receiving the instruction result transmitted in step S766, the management center 2 receives the instruction result (step S706) and checks the content of the instruction result (step S708).
[0148] If the instruction result is abnormal in step S708 ("abnormal" in step S708), the management center 2 determines that fraud has occurred, records information indicating the nature of the fraud in the contract information DB 100 (step S710), and abnormally terminates the process.
[0149] On the other hand, if the instruction result is normal in step S708 ("normal" in step S708), the management center 2 ends the process normally without performing the process in step S710.
[0150] By executing the service cancellation process as described above, the elevator service management system 1 can prevent unauthorized use of the service process when the service is cancelled.
[0151] As described above, according to the elevator service management system 1 of this embodiment, it is possible to prevent fraudulent or incorrect use of the service by updating (which may include adding, changing, and deleting) the program that provides the service depending on the equipment configuration of the controller 20 etc. in the elevator system, the type of service contract, or the system configuration.
[0152] (2) Second embodiment An elevator service management system 1A according to a second embodiment of the present invention has, in addition to the functions of the elevator service management system 1 according to the first embodiment, a function of displaying services (service processes) that the elevator system can provide and accepting various operations related to contracts, etc. In the elevator service management system 1A according to this embodiment, a description of the configuration common to the elevator service management system 1 will be omitted.
[0153] (2-1) Internal configuration of management center 2A Fig. 18 is a diagram showing an example of the internal configuration of a control center 2A in an elevator service management system 1A according to the second embodiment. The control center 2A is a component corresponding to the control center 2 in the first embodiment, and differs from the control center 2 shown in Fig. 3 in that it includes a service information database (DB) 300 and a control center control unit 340. Although not shown in Fig. 18, like the control center 2, the control center 2A may also include components such as an authenticity verification means DB 110 and generated information 130. Furthermore, the control center control unit 340 may be configured to further include each unit of the control center control unit 140 shown in Fig. 3.
[0154] The service information DB 300 manages information about services that can be provided by the elevator system. Specifically, the service information DB 300 manages service information 301 that holds basic information about each service, and execution configuration information 306 that holds information about the execution configuration required to provide the service.
[0155] Fig. 19 is a diagram showing an example of the data structure of service information 301 and execution configuration information 306. In the case of Fig. 19, service information 301 is configured to include service ID 302 indicating the identifier of the service, service name 303 indicating the name of the service, service description 304 indicating an explanation of the service, and contract type 305 indicating the form of service provision. Note that the data structure of service information 301 is not limited to the example of Fig. 19 as long as it includes at least contract type 305.
[0156] 19, the execution configuration information 306 is configured to include a configuration ID 307 indicating an identifier assigned to each execution configuration, a configuration description 308 indicating a description of the execution configuration, facilities 309 indicating facilities required to provide the service, and network information 310 indicating communication paths and routes connecting the plurality of facilities 309. Note that the data configuration of the execution configuration information 306 is not limited to the example of FIG. 19 as long as it includes at least facilities 309.
[0157] As shown in FIG. 19, in the service information DB 300, each piece of service information 301 is associated with one or more pieces of execution configuration information 306 relating to the execution configuration of the corresponding service, thereby managing information required to provide each service.
[0158] The management center control unit 340 comprises a related information extraction unit 341, a display generation unit 343, a service extraction unit 345, and a service voting unit 347. The functions of each unit of the management center control unit 340 are realized by a processor in the computer of the management center 2A reading and executing a predetermined program.
[0159] The related information extraction unit 341 reads the service information 301 and the execution configuration information 306 from the service information DB 300, and extracts the contract type 305 (device and configuration) and the like of the execution configuration information 306 linked to the service information 301.
[0160] The display generation unit 343 generates information to be displayed on a display device such as a monitor, specifically, code for a web page, based on the information extracted by the related information extraction unit 341. The information to be displayed on the display device also includes code for accepting operation results such as selections made by the user.
[0161] The management center control unit 340 then uses the code generated by the display generation unit 343 to display, for example, a web page, thereby displaying information to the user about the services (service processing) that the elevator system can provide, and enabling the user to accept predetermined selection operations, etc.
[0162] (2-2)Display configuration Hereinafter, functions that can be provided by the elevator service management system 1A will be described with reference to examples of display screens of web pages that can be output by the management center 2A of this embodiment.
[0163] (2-2-1) Service selection and execution configuration selection Fig. 20 is a diagram showing an example of a web page display for selecting a service or selecting the execution configuration of a service program. Fig. 21 is a diagram showing an example of a transition screen from the web page of Fig. 20. Note that the following explanation is for a case where the service selection screen 350 is displayed as a design equivalent to a window or dialog on a window system of a general-purpose OS (Operating System), but the display method and display design of the screen in this embodiment are not limited to this. The same applies to other display examples described below.
[0164] 20 is a display screen provided to the user for selecting a service to be used or its execution configuration. The service selection screen 350 displays a list of services whose information is held in the service information 301 based on the information extracted from the service information DB 300 by the related information extraction unit 341.
[0165] In the list of services displayed on service selection screen 350, specifically, number 351 corresponds to service ID 302, name 352 corresponds to service name 303, and description 353 corresponds to service description 304. Radio button 354 is a button operated when selecting a target service. OK button 355 is a button operated when finalizing the selection of a service while service selection screen 350 is displayed, and cancel button 356 is a button operated when canceling the selection of a service on service selection screen 350.
[0166] 20, the number 351 and name 352 of each service are underlined, which means that a hyperlink is provided. The hyperlink is linked to a window or dialog box such as the configuration selection screen 360 shown in FIG.
[0167] The configuration selection screen 360 is a display screen provided to the user for selecting an execution configuration for the service selected on the service selection screen 350 (i.e., the service for which the hyperlink was operated). The configuration selection screen 360 displays a list of information for each combination of execution configurations (configuration ID 307) required to provide the selected service, and this display information is composed of information extracted mainly from the execution configuration information 306 by the related information extraction unit 341.
[0168] Specifically, the display configuration of the configuration selection screen 360 is as follows: name 361 corresponds to the service name 303, description 362 corresponds to the configuration description 308, facility 363 corresponds to the facility 309, and network 364 corresponds to the network information 310. Radio button 365 is a button operated when selecting the target execution configuration. OK button 366 is a button operated when finalizing the selection of the execution configuration in the display state of the configuration selection screen 360, and cancel button 367 is a button operated when canceling the selection of the execution configuration on the configuration selection screen 360 (returning to the service selection screen 350, which is the source of the hyperlink).
[0169] For example, when selecting one of configurations X, Y, or Z on the configuration selection screen 360 in Fig. 21, the user presses the corresponding radio button 365, causing that button to be in a selected state (indicated by a black circle in other figures). Thereafter, when the user presses the OK button 366, an event occurs that updates the contract information DB 100.
[0170] As described above, the user can select equipment when selecting the service to be used by displaying the service selection screen 350 and the configuration selection screen 360 based on the information managed in the contract information DB 100. Then, starting from the selection of the service process, the elevator service management system 1A can quickly update the service process, program structure, and execution mode by updating various databases in the management center 2A in response to the maintenance or change of the contract mode or execution mode depending on the status of the buttons.
[0171] (2-2-2) Service updates after starting service Fig. 22 is a diagram showing an example of a web page display for updating a service, and Fig. 23 is a diagram showing an example of a transition screen from the web page of Fig. 22.
[0172] 22 is a screen that displays the contract status of a service after starting to use the service process. The user can select and update the contract status of the service on the service update screen 370, and the elevator service management system 1 updates the status of the elevator system in response to the operation on the service update screen 370.
[0173] Similar to the service selection screen 350 in FIG. 20, the service update screen 370 displays a list of services whose information is held in the service information 301 based on the information extracted from the service information DB 300 by the related information extraction unit 341.
[0174] In the list of services displayed on the service update screen 370 , specifically, the number 371 corresponds to the service ID 302 , the name 372 corresponds to the service name 303 , and the description 373 corresponds to the service description 304 .
[0175] Furthermore, subscription 374 and purchase 375 represent contract types for existing services, continuation 376 and purchase 377 represent contract types for expiring services, and subscription 378 and purchase 379 represent contract types for newly proposed services.
[0176] Specifically, in the case of Figure 22, it is shown that service A is currently contracted as a "subscription" (subscription 374) as an existing (currently in use) service. Continuation of the contract for service B, which is about to expire, has been selected (continuation 376). Service C is proposed as a new service process, and when the user contracts for service C, subscription 378 or purchase 379 is selected depending on the desired contract type. Note that selecting purchase 375 means that the contract type for service A currently in use will be changed from "subscription" to "purchase," and selecting purchase 377 means that the contract for service B, which has expired, will be renewed as a "purchase" contract type.
[0177] The OK button is a button that is operated when confirming the update of a service with the configuration selected on the service update screen 370, and the cancel button 381 is a button that is operated when canceling the update of a service on the service update screen 370.
[0178] In addition, on the service update screen 370, similar to the service selection screen 350 in FIG. 20, hyperlinks are provided to the number 371 and the name 372, and the hyperlinks are linked to windows or dialogs such as the configuration selection screen 390 shown in FIG. 23.
[0179] 23 is a display screen provided to the user for selecting an execution configuration for the service selected on the service update screen 370 (i.e., the service for which the hyperlink was operated). The configuration selection screen 390 displays a list of information for each combination of execution configurations (configuration ID 307) required to provide the service selected on the service update screen 370, and this display information is composed of information extracted mainly from the execution configuration information 306 by the related information extraction unit 341.
[0180] The display configurations of the configuration selection screen 390 (name 391, description 392, equipment 393, network 394, radio button 395, OK button 396, cancel button 397) are the same as the display configurations of the same names on the configuration selection screen 360 of Figure 21, and detailed explanations will be omitted.
[0181] When the user presses the OK button 396 on the configuration selection screen 390, the selection is confirmed and the screen returns to the service update screen 370. When the user presses the OK button 380 on the service update screen 370, an event occurs to update the contract information DB 100.
[0182] As described above, the elevator service management system 1A starts with an update of the contract status by the user, and updates various databases in the management center 2A in response to the maintenance or change of the contract form or execution form of the service (service processing) depending on the status of the buttons on the service update screen 370 and the configuration selection screen 390, thereby enabling the service processing, program structure, and execution form to be quickly updated.
[0183] (2-2-3) Adding services from equipment selection Fig. 24 is a diagram showing an example of a display of a web page for facility selection, and Fig. 25 is a diagram showing an example of a transition screen from the web page of Fig. 24.
[0184] The facility selection screen 400 shown in Fig. 24 is a screen that displays existing facilities of the elevator system. The service addition screen 410 shown in Fig. 25 is a screen that is transitioned to and displayed when a hyperlink on the facility selection screen 400 is selected, and is provided to the user for adding a new service process.
[0185] 24 is a window or dialog box configured with a number 401 corresponding to the configuration ID 307 (see FIG. 19), a facility 402 corresponding to the facility 309 (see FIG. 19), an OK button 403 operated to confirm the facility selection status, and a cancel button 404 operated to cancel the facility selection. On the facility selection screen 400, a hyperlink is provided to the number 401 or the facility 402, and when either of these is selected, a service addition screen 410 related to the selected service is displayed.
[0186] The service addition screen 410 in Figure 25 is a screen having the same display configuration as the service update screen 370 in Figure 22, and specifically, is a window or dialog consisting of a number 411, a name 412, a description 413, a subscription 414, a purchase 415, a continuation 416, a purchase 417, an OK button 418, and a cancel button 419.
[0187] When a hyperlink is selected on the facility selection screen 400 and the initial service addition screen 410 is displayed, the radio buttons for subscription 414, purchase 415, continuation 416, and purchase 417 are displayed in an unselected state. After that, when the user selects the radio button corresponding to the desired service and its contract type and presses the OK button 418, an event occurs that updates the contract information DB 100.
[0188] As described above, by using the equipment selection screen 400 and the service addition screen 410, the user can select a new service contract or renewal from the equipment, and the elevator service management system 1A can create a state in which a new service is added according to these screen operations (radio button selection status), and can also update various databases in the management center 2A.
[0189] (2-2-4) Service Approval Based on Voting on Proposals This section explains service approval, which is a selection and decision made by multiple parties (e.g., elevator owner, manager, or user) regarding whether to continue or stop service use in an elevator system.
[0190] 26 to 29 are diagrams (parts 1 to 4) showing examples of web page displays in a series of steps for service approval. More specifically, Fig. 26 and Fig. 27 are display examples of a service confirmation screen, Fig. 28 is a display example of a service voting screen, and Fig. 29 is a display example of a service proposal screen.
[0191] Below, we will explain the multi-stage service approval process, in which the owner proposes the use of a service, multiple users express their support or opposition to the proposal, these opinions are compiled, and the users' overall opinion of support or opposition or alternative proposals are presented to the owner based on arbitrary criteria, with reference to the screen examples in Figures 26 to 29.
[0192] First, the service confirmation screen 420 illustrated in Fig. 26 is a display screen provided to the proposer (here, the owner or manager of the elevator system). Also, the service confirmation screen 430 illustrated in Fig. 27 is one of the display screens transitioning from the service confirmation screen 420 in Fig. 26, and shows the proposed content of the service contract change. The display configuration of the service confirmation screens 420 and 430 is the same as that of the service update screen 370 and the service addition screen 410 described above.
[0193] The service confirmation screen 420 shown in Fig. 26 displays the current contract status of the service, similar to the service update screen 370 in Fig. 22. That is, in the current contract status shown on the service confirmation screen 420, the contract type for service A is "subscription" (radio button 421), and "continue" is selected for service B, whose contract is expiring (radio button 423).
[0194] In this example, it is assumed that the elevator owner (or manager) proposes a new contract status based on the current contract status and changes the contract type of service B to "purchase." At this time, on service confirmation screen 420, radio button 424 for "purchase" is selected instead of radio button 423 for service B, and the owner presses OK button 427.
[0195] When the OK button 427 is pressed as described above, the selection made by the owner is confirmed, and the service confirmation screen 420 transitions to the service confirmation screen 430 shown in Fig. 27. On the service confirmation screen 430, the "Purchase" radio button 424 for service B is selected.
[0196] Once the owner's selection is finalized, the owner's proposal for the new contract status of the service is displayed on the terminals of multiple users as service voting screen 440, which has the same display configuration as service confirmation screen 430. Note that since it is expected that service voting screen 440 will be displayed on a user's terminal different from service confirmation screens 420 and 430 displayed on the owner's terminal, the display configuration of service voting screen 440 shown in Fig. 28 is given different symbols (radio buttons 441 to 446, OK button 447, cancel button 448) from those of service confirmation screens 420 and 430.
[0197] Next, the user indicates whether he or she approves or disapproves of the proposal for new contract information for the service displayed on the service voting screen 440.
[0198] Specifically, a user who agrees with the proposal from the owner can generate a user approval event by pressing the OK button 447 without changing the selection state of the radio button displayed on the service voting screen 440. The service voting unit 347 of the management center control unit 340 counts the occurrence of these approval events, and when the number of approval events exceeds the majority of the total number of users, for example, it can determine that the proposal has been generally understood (approved) by the users, and generate an event requesting the owner (or manager) of the elevator system to approve the contract change indicated in the proposal.
[0199] On the other hand, if a user is dissatisfied with the proposal from the owner, the user performs an operation to change the selection state of the radio button displayed on the service voting screen 440 to the desired selection state, and then presses the OK button 447. In this case, an event occurs for a service proposal different from the proposal. When the service proposal event occurs, the service voting screen 440 displayed on the user's terminal transitions to a service proposal screen 450 shown in FIG. 29. The service proposal screen 450 is a screen for selecting a new proposal (another service proposal).
[0200] 29, the user wishes to "continue" service B instead of "purchase" as proposed by the owner, and radio button 453 is changed to a selected state. When the user presses confirm button 457 to confirm the changes to service proposal screen 450, a predetermined event (another service proposal event) different from the approval request event described above occurs.
[0201] When this event of another service proposal occurs, the service voting unit 347 acquires information on the radio buttons 441-446 and 451-456 on the service voting screen 440 and the service proposal screen 450, and tally these. At this time, for example, if the occurrence of an event in which "purchase" (selection state of radio button 443) of service B, which was initially proposed by the owner, is selected by less than half of the total number of users, the service voting unit 347 determines that general understanding (approval) of the users has not been obtained, and can generate an event notifying the owner (or manager) of the elevator system of the rejection of the contract change indicated in the initial proposal. Furthermore, if the occurrence of an event in which "continue" of service B is selected by more than half of the total number of users, the service voting unit 347 determines that general understanding (approval) of the above-mentioned another service proposal has been obtained, and can generate an event requesting the owner (or manager) of the elevator system to reconsider the contract change indicated in the initial proposal.
[0202] 30 is a flowchart showing an example of the processing procedure of the service approval processing. The service approval processing is processing for executing the multi-stage service approval described above with reference to FIGS. 26 to 29, and is executed by the management center control unit 340.
[0203] 30, first, the service voting unit 347 performs service confirmation (step S800). In step S800, the service voting unit 347 causes the display generation unit 343 to generate a service confirmation screen 420 and displays it on the terminal of the proposer (for example, the owner or manager of the elevator system).
[0204] Next, if the service confirmation screen 420 displayed in step S800 is operated (the display content is changed to that of service confirmation screen 430), a service change occurs, and so the service voting unit 347 conducts a service vote (step S802). In step S802, the service voting unit 347 causes the display generation unit 343 to generate the service voting screen 440 based on the information confirmed on the service confirmation screen 430, and causes the screen to be displayed on the terminals of the voters (e.g., multiple users).
[0205] Thereafter, the service voting unit 347 determines whether or not voting by the voters has finished (step S804). The determination of the end may be based on, for example, a time limit or the number of people who have voted. If voting has not finished (NO in step S804), step S804 is repeated until it is determined that voting has finished.
[0206] When voting is completed in step S804 (YES in step S804), the service voting unit 347 tallies the voting results based on predetermined conditions (step S806). An example of the predetermined conditions for tallying is as described above in the description of the service voting screen 440 in FIG.
[0207] Then, the service voting unit 347 notifies the proposer of the tally result of step S806 (step S808). When notifying the tally result, the display generation unit 343 may generate a web page or the like with a predetermined display configuration.
[0208] By executing the processing as described above, the elevator service management system 1A can incorporate the opinions of multiple parties and realize approval for changes in service processing, making it possible to select service processing and enter into a service contract.
[0209] In the above explanation, we have detailed a format for implementing service approval by combining the owner's selection (proposal) with votes from multiple users on that selection, but this embodiment is not limited to this combination, and for example, service approval may be implemented by combining the aggregated results of selections (proposals) by multiple users with the owner's approval of the aggregated results.
[0210] (3) Third embodiment The elevator service management system 1B according to the third embodiment of the present invention has, in addition to the functions of the elevator service management system 1 according to the first embodiment (or the elevator service management system 1A according to the second embodiment), a function in which a device (mobile body) capable of autonomous behavior cooperates with the elevator system to provide a new service (hereinafter also referred to as a robot cooperation service).
[0211] Fig. 31 is a diagram showing an example of the overall configuration of an elevator service management system 1B according to the third embodiment. In Fig. 31, among the configurations of the elevator service management system 1B, the same configurations as those of the elevator service management system 1 are denoted by the same reference numerals, and the description thereof will be omitted.
[0212] As shown in Fig. 31, the elevator service management system 1B is configured by connecting a robot 500 to the elevator service management system 1 according to the first embodiment shown in Fig. 1 via a communication path 3. The robot 500 is an example of a device (mobile body) capable of autonomous behavior. Because the robot 500 is an autonomous mobile body, the robot 500 and the communication path 3 are generally connected wirelessly, but this is not limiting.
[0213] The robot 500 is equipped with various sensors, specifically, for example, a Global Navigation Satellite System (GNSS), an acceleration sensor, an image sensor, or a Light Detection and Ranging (LiDAR).
[0214] In the elevator service management system 1B, a virtual machine 62 (see FIG. 33) running on a cloud system 60 performs a service process that calculates and processes robot-related data (specifically, position information, operation information, image information, surrounding environment information, etc.) acquired by various sensors of the robot 500, generates new data, control information, or instructions, and transmits the control information or instructions that are the processing results of the service process to the group management controller 5. The processing by the virtual machine 62 may be performed according to instructions from the management center 2 (management center control unit 140). Based on the received control information or instructions, the group management controller 5 then performs a control calculation to improve the operation efficiency of the elevator group 19 that it manages, and transmits the new control information or instructions obtained by the calculation to the subordinate elevator controllers 6.
[0215] The elevator service management system 1B of this embodiment is configured as a service collaboration system using the cloud system 60 as described above, making it possible to realize a new collaboration service in which a device (mobile body) capable of autonomous behavior collaborates with an elevator system.
[0216] In this embodiment, information about the robot 500 is added to the equipment facility information 101 in the contract information DB 100 of the management center 2. Specifically, the equipment facility information 101 additionally holds information indicating the cloud system 60, the robot 500, and communication path 3 as communication path information between them. The contract form for the robot collaboration service held in the contract form information 103 of the contract information DB 100 is, for example, "subscription." In addition, the execution form information 106 related to the robot collaboration service indicates that the group management controller 5 is the client process and the cloud system 60 is the service process.
[0217] FIG. 32 is a diagram showing an example of the internal configuration of the group management controller 5 in the third embodiment, and FIG. 33 is a diagram showing an example of the internal configuration of the virtual machine 62 in the third embodiment.
[0218] 32, in the group management controller 5, a standard control program 501 for managing the elevator group 19 and an individual identifier 505 assigned to each group management controller 5 are stored in the ROM 23. In addition, the RAM 24 of the group management controller 5 stores contract conditions (conditions 507) corresponding to a robot collaboration service that uses the cloud system 60, and a client program (subscription service 509) for subscribing to the robot collaboration service executed in the cloud system 60.
[0219] 33, in the cloud system 60, the ROM 23 of the virtual machine 62 stores a standard control program 511 for the robot collaboration service and an individual identifier 515 assigned to each virtual machine 62. The RAM 24 of the virtual machine 62 also stores contract conditions (conditions 517) corresponding to the robot collaboration service and a service program (collaboration service 519) for subscribing to the robot collaboration service executed in the cloud system 60.
[0220] In the elevator service management system 1B according to this embodiment, by adopting the above-described system configuration, the management center control unit 140 of the management center 2 can generate downloaders 503, 513 specialized for adding devices capable of autonomous behavior, such as the robot 500, and for adding service processes, in the same manner as in the first embodiment. The downloader 503 is stored in the ROM 23 of the group management controller 5, and the downloader 513 is stored in the ROM 23 of the virtual machine 62. Then, by generating and storing such downloaders 503, 513, it becomes difficult for the elevator service management system 1B to illegally copy and execute processing programs related to the devices and service processes.
[0221] (4) Fourth embodiment An elevator service management system 1C according to a fourth embodiment of the present invention has, in addition to the functions of the elevator service management system 1 according to the first embodiment (or the elevator service management system 1A according to the second embodiment), a function in which a device with an intelligent function (for example, an intelligent sensor) works in conjunction with the elevator system to provide a new service (hereinafter also referred to as a sensor-linked service).
[0222] Fig. 34 is a diagram showing an example of the overall configuration of an elevator service management system 1C according to the fourth embodiment. In Fig. 34, among the configurations of the elevator service management system 1C, the same configurations as those of the elevator service management system 1 are assigned the same reference numerals, and the description thereof will be omitted.
[0223] As shown in Fig. 34, the elevator service management system 1C is configured by connecting an edge controller 51 and a sensor 600 to a communication path 13. The sensor 600 is an intelligent sensor in which a sensor and a signal processing circuit are integrated, such as an image sensor. Note that for simplicity, Fig. 34 shows one sensor 600, but the number of sensors 600 installed is not limited to one. For example, if the sensor 600 is an image sensor, it is expected that multiple sensors 600 will be installed on each floor and inside the car 8.
[0224] The edge controller 51 connected to the sensor 600 via the communication path 13 executes a specific service process (for example, if the sensor 600 is an image sensor, an image analysis service process that performs image analysis) using the information detected or processed by the sensor 600, and transmits the processing results of the image analysis service process (for example, the number of people as the processing results of the image analysis) to the elevator controller 6.
[0225] The elevator service management system 1C of this embodiment is configured to be capable of executing specific service processing such as the image analysis service processing described above, thereby making it possible to realize a new sensor collaboration service in which an additional device (equipment) such as the sensor 600 collaborates with the elevator system.
[0226] In this embodiment, information about the edge controller 51 and the sensor 600 is added to the device facility information 101 in the contract information DB 100 of the management center 2. Specifically, the device facility information 101 additionally holds information indicating the edge controller 51, the sensor 600, and the communication path 13 as communication path information between them. In addition, the contract form for the sensor collaboration service held in the contract form information 103 of the contract information DB 100 is, for example, "purchase." In addition, in the execution form information 106 related to the sensor collaboration service, the elevator controller 6 is set as client processing and the edge controller 51 is set as service processing.
[0227] FIG. 35 is a diagram showing an example of the internal configuration of the elevator controller 6 in the fourth embodiment, and FIG. 36 is a diagram showing an example of the internal configuration of the edge controller 51 in the fourth embodiment.
[0228] As shown in Figure 35, in the elevator controller 6, the ROM 23 stores a standard control program 601 for managing the elevator 16, an individual identifier 605 assigned to each elevator controller 6, contract conditions (conditions 607) corresponding to the image analysis service, and a client program (purchase service 609) for using the image analysis service executed by the edge controller 51.
[0229] 36, in the edge controller 51, a standard image processing program for the image analysis service (standard image processing program 612) and an individual identifier 85 assigned to each edge controller 51 are stored in the ROM 23. In addition, the RAM 24 of the edge controller 51 stores contract conditions (conditions 617) corresponding to the image analysis service and a program for purchasing the image analysis service executed by the edge controller 51 (analysis service 619).
[0230] In the elevator service management system 1C according to this embodiment, the system configuration as described above allows the management center control unit 140 of the management center 2 to generate downloaders 603, 613 specialized for adding devices with intelligent functions such as the sensor 600 and for adding service processes, in a manner similar to that of the first embodiment. The downloader 603 is stored in the ROM 23 of the elevator controller 6, and the downloader 613 is stored in the ROM 23 of the edge controller 51. Then, by generating and storing such downloaders 603, 613, it becomes difficult for the elevator service management system 1C to illegally copy and execute processing programs related to the devices and service processes.
[0231] 35, in this example, the client program (purchase service 609) for using the image analysis service is stored as a purchase in the ROM 23 of the elevator controller 6. However, even if the purchase service 609 on the elevator controller 6 side is illegally copied and executed on another elevator controller 6, if the edge controller 51 device itself is changed or the analysis service 619 on the edge controller 51 side is updated, it becomes necessary to update the purchase service 609 on the elevator controller 6 side. Therefore, in the elevator service management system 1C, even if the purchased service program (purchase service 609) is illegally copied on the elevator controller 6 side, a new edge controller 51 or a new analysis service 619 cannot be used, thereby preventing unauthorized or incorrect use of the service.
[0232] As described above, the elevator service management systems 1, 1A to 1C according to each embodiment of the present invention can make it difficult to manipulate the setting information and programs related to service processing by updating (which may include adding, changing, and deleting) the programs that provide the services according to the equipment configuration of the controllers etc. in the elevator system, the contract type of the service, or the system configuration, thereby preventing fraudulent or incorrect use of the service. [Explanation of symbols]
[0233] 1, 1A, 1B, 1C Elevator Service Management System 2,2A Management Center 3, 13, 17, 18 Communication Channels 4 Communication Controller 5 Group Management Controller 6 Elevator Controller 7 motors 8 baskets 9 Counterweight 10 Rope 11. Cage controller 12 Floor Controller 14 Basket button 15 Up / down call button 16 Elevator 19 Elevator Group 20 Controller 21 System Bus 22 processors 23 ROM 24 RAM 25 Interface 51, 52, 53 Edge Controller 60 Cloud System 62 virtual machines 70 Management terminal 80 Firmware 81 Standard Control Program 83,84 Downloader 85 Individual Identifier 100 Contract Information Database (Contract Information) 101 Equipment information 103 Contract type information 104 Service ID 105 Contract Types 106 Execution mode information 107 Execution Type 108 Program ID 110 Authenticity confirmation means database (authenticity confirmation means) 111 Summary Value Method 113 Encryption method 120 Program Database (Program Information) 121 Controller Firmware 122,125,128 Service Programs 123 Edge Controller Firmware 124 Client Firmware 126 Cloud System Firmware 127 Client Firmware 130 Generation Information Database (Generation Information) 131 Contract Information 133 Authenticity information 135 Program Structure Information 140 Management Center Control Unit 141 Update Management Department 143 Execution mode selection section 145 Program Selection Section 147 Downloader Generation Unit 149 Downloader Distribution Department 201 Service List 202 Service Number (Service No.) 203 Authenticity number 204 Authenticity confirmation information (combined authenticity) 205 Authenticity Verification Processing List 206 Authenticity Verification Processing Program (Authenticity Processing) 207 Communication Processing Program (Communication Processing) 210 Reply Data 211 Terms and Conditions (Conditions) 213 Processed Data 220 Buyback Service Program (Buyback Service) 222 Subscription Service Program (Subscription Service) 300 Service Information Database 301 Service Information 302 Service ID 303 Service Name 304 Service Description 305 Contract Form 306 Execution Configuration Information 307 Configuration ID 308 Configuration Description 309 Equipment 310 Network Information 340 Management Center Control Unit 341 Related Information Extraction Unit 343 Display generation section 345 Service Extraction Unit 347 Service Voting Department 350 Service selection screen 360,390 Configuration selection screen 370 Service Update Screen 400 Facility selection screen 410 Add Service Screen 420,430 Service confirmation screen 440 Service Voting Screen 450 Service proposal screen 500 robots 501,511 Standard Control Program 503,513 downloaders 505,515 Individual Identifier 507,517 conditions 509 Subscription Services 519 Collaborative Services 600 sensors 601 Standard Control Program 603,613 downloaders 605.615 Individual identifiers 607,617 conditions 609 Purchase Service 611 Standard Image Processing Program 619 Analysis Service
Claims
1. An elevator service management system that manages services provided by an elevator system based on a contract, an elevator system having at least one controller for controlling operation of the elevator; a management center that is communicatively connected to the controller and that manages a processing program executed by the controller to provide the service; Equipped with The management center a contract information database that holds equipment and facility information indicating the configuration of the equipment and facilities of the elevator system, contract form information indicating the contract form of the service, and execution form information indicating the execution form of the processing program of the service; a program database that stores processing programs for the services corresponding to the respective execution modes; an update management unit that manages distribution of the processing program stored in the program database to the controller based on information in the contract information database; and The update management unit generates a downloader specialized for the controller that downloads the processing program based on the contract type information of the service and the execution type information of the processing program, and provides the downloader to the controller. An elevator service management system.
2. the update management unit generates the downloader including an authenticity verification unit that verifies the authenticity of the processing program to be downloaded; When the controller downloads the processing program from the program database using the downloader provided by the update management unit, the controller verifies the authenticity of the processing program using the authenticity verification means of the downloader, and if the authenticity is confirmed, stores the processing program in its own storage area. The elevator service management system according to claim 1 .
3. The authenticity verification means included in the downloader has a function of verifying the authenticity of the combination of processing programs downloaded by the downloader. The elevator service management system according to claim 2 .
4. When the downloader provided by the update management unit cannot be executed, or when the authenticity of the processing program downloaded using the downloader cannot be confirmed, the controller executes control to transition the elevator to a predetermined safety state according to the operating status of the elevator. The elevator service management system according to claim 2 .
5. The update management unit updates the downloader and the authenticity verification means when the service contract is changed or periodically. The elevator service management system according to claim 2 .
6. When the contract type of the service is changed from a first contract type that has restrictions on the period or number of times of use of the service to a second contract type that has no restrictions on the period or number of times of use of the service, the downloader held by the controller moves the processing program of the service corresponding to the second contract type from a storage area of a volatile memory to a storage area of a non-volatile memory; The update management unit generates a new downloader that is specialized for the combination of processing programs of the service contracted under the first contract type, excluding the moved processing programs. The elevator service management system according to claim 1 .
7. If the above service is cancelled due to a change in contract status, The downloader held by the controller invalidates the processing program of the service to be deleted, and updates the processing programs of other services that are not to be deleted to a program structure that conforms to the latest contract type by using a downloader that conforms to the latest contract type and execution type. The elevator service management system according to claim 2 .
8. The management center a related information extraction unit that extracts devices and facilities related to the service, a contract form for the service, and an execution configuration required to provide the service; a display generation unit that generates display information based on the extraction result by the related information extraction unit and outputs the display information in a manner that allows a selection operation for at least one of a contract type or an execution configuration of the service, The management center updates the contract information of the service based on the result of a selection operation by the user on the display information output by the display generation unit. The elevator service management system according to claim 1 .
9. When at least one of the services is being used in the elevator system, the related information extraction unit extracts the service being used, the contract type of the service, and the execution configuration of a processing program of the service from the device facility information, the contract type information, and the execution type information stored in the contract information database; the display generation unit generates and outputs display information based on the extraction result by the related information extraction unit; The management center updates contract information for services used in the elevator system based on a result of a selection operation by a user on the display information output by the display generation unit. The elevator service management system according to claim 8 .
10. the related information extraction unit extracts available services, contract types of the services, and execution configurations of processing programs of the services from the device facility information, the contract type information, and the execution type information stored in the contract information database; the display generation unit generates and outputs a display screen on which the services available in existing facilities in the elevator system can be selected based on the extraction result by the related information extraction unit; and The management center updates contract information for services used in the elevator system based on a result of a selection operation by a user on the display information output by the display generation unit. The elevator service management system according to claim 8 .
11. the display generation unit generates and outputs first display information representing information related to services available in the elevator system based on the extraction result by the related information extraction unit, and when a selection operation to propose a change in service is performed by a proposer on the first display information, generates and outputs second display information representing the content of the proposal by the proposer based on a result of the selection operation; The management center further includes a service voting unit that tallys up results of selection operations from voters on the second display information output by the display generation unit and determines whether to adopt the proposal content in accordance with predetermined conditions.
11. The elevator service management system according to claim 8, wherein the elevator service management system is a system for managing an elevator.
12. the elevator system is communicatively connected to a cloud system; When a predetermined service linked with the cloud system is provided, a virtual machine running on the cloud system executes a processing program for the service instead of the controller. The elevator service management system according to claim 1 .
13. a mobile object capable of autonomous behavior is connected to the cloud system so as to be able to communicate with the mobile object; Instead of the controller, a virtual machine running on the cloud system executes the processing program using information obtained from the mobile object, thereby providing a specific service in which the elevator system and the mobile object are linked together. The elevator service management system according to claim 12 .
14. The elevator system comprises: an edge controller that is added to enhance the processing performance and functionality of the controller; a device having an intelligent function communicatively connected to the edge controller; The edge controller executes the processing program using information obtained from the device instead of the controller, thereby providing a specific service in which the elevator system and the device cooperate with each other. The elevator service management system according to claim 1 .
15. 1. A method for managing an elevator service program by an elevator service management system that manages services provided by an elevator system based on a contract, comprising: The elevator service management system an elevator system having at least one controller for controlling operation of the elevator; a management center that is communicatively connected to the controller and that manages a processing program executed by the controller to provide the service; and The management center a contract information database that holds equipment and facility information indicating the configuration of the equipment and facilities of the elevator system, contract form information indicating the contract form of the service, and execution form information indicating the execution form of the processing program of the service; a program database that stores processing programs for the services corresponding to the respective execution modes; an update management unit that manages distribution of the processing program stored in the program database to the controller based on information in the contract information database; and The update management unit generates a downloader specialized for the controller that downloads the processing program based on the contract type information of the service and the execution type information of the processing program, and provides the downloader to the controller.
10. A program management method for elevator service, comprising:
Citation Information
Patent Citations
Control device for elevator facility, building facilities repairing method and control method using it, and elevator system
CN1473132A
Remote maintenance device
JP2002175189A
Elevator maintenance contract system, maintenance center, and elevator maintenance contract method and program
JP2003091608A
Elevator system
JP2014172714A
Remote monitoring information management method and remote monitoring system for elevator
JP2019202845A