Elevator system and elevator control method

The elevator system uses controllers with packet inspection and control units to identify and manage unauthorized devices, addressing the limitations of conventional systems by eliminating the need for dedicated hardware, thus enhancing security and flexibility.

JP7839121B2Active Publication Date: 2026-04-01HITACHI LTD
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2023-03-20
Publication Date
2026-04-01

AI Technical Summary

Technical Problem

Conventional elevator systems require dedicated switching hubs and monitoring devices to identify unauthorized controllers, limiting their application to systems connected to these components, and cannot be applied to systems without them.

Method used

An elevator system with multiple controllers that perform packet inspection and identification of unauthorized controllers using task switching determination, packet analysis, and operation control units, without the need for a switching hub or dedicated monitoring device.

Benefits of technology

Enables identification and control of unauthorized controllers using only normal controllers, eliminating the need for additional hardware and expanding applicability to systems without switching hubs or gateways.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007839121000001
    Figure 0007839121000001
  • Figure 0007839121000002
    Figure 0007839121000002
  • Figure 0007839121000003
    Figure 0007839121000003
Patent Text Reader

Abstract

To provide an elevator system capable of identifying an unauthorized controller 20 and controlling operation only with a normal controller 20 without provided with a switching hub or a dedicated monitoring device.SOLUTION: In an elevator system having a plurality of controllers 20 that controls elevators 15, each one of the controllers 20 has a task switching determination unit 32 that determines, depending on a control state of the one controller 20, whether to perform packet inspection of packets sent to other ones of the controllers 20; a packet analysis unit 38 that performs packet inspection to identify a fraudulent controller 20; and an operation control unit 50 that changes control of the elevator 15 depending on the identified status of the fraudulent controller 20.SELECTED DRAWING: Figure 3
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an elevator system and an elevator control method.

Background Art

[0002] An elevator system is a system configured by connecting a plurality of controllers to each other via a communication path. If the controller is replaced with another controller or device, unexpected communication data may flow, which may interfere with the operation of the elevator system.

[0003] As methods for dealing with unauthorized connection of devices to such a communication path, for example, there are Patent Document 1 and Patent Document 2.

[0004] Patent Document 1 describes a technique for blocking unauthorized devices using a switching hub. The abstract of Patent Document 1 states that "each device detects an unauthorized device and transmits a control command for the switching hub to which the unauthorized device is directly connected from each device. The switching hub that receives the control command electronically controls its own connection port to which the unauthorized device is connected or the path information table of the switching hub based on the content of the control command, and blocks the network connection of the unauthorized device."

[0005] In addition, Patent Document 2 describes a technique in which a dedicated monitoring device is connected to a communication path and a gateway is separately prohibited from routing unauthorized data. The abstract of Patent Document 2 states that "in a vehicle network, an in-vehicle control device 50 for monitoring is provided to detect unauthorized data through monitoring of the communication format of data defined for operating the communication protocol used in the same vehicle network. When the in-vehicle control device 50 for monitoring detects unauthorized data different from the defined communication format, it performs a process of transmitting warning information to each of the in-vehicle control devices 11 to 13, 21 to 23, and 31 to 33, and also performs a process of prohibiting the routing of unauthorized data by the gateways 41 and 42." [Prior art documents] [Patent Documents]

[0006] [Patent Document 1] Japanese Patent Publication No. 2015-035724 [Patent Document 2] Japanese Patent Publication No. 2013-131907 [Overview of the project] [Problems that the invention aims to solve]

[0007] However, these conventional technologies have the drawback of requiring a dedicated switching hub and monitoring device in addition to the controller. Furthermore, the communication path topology (network configuration) is limited to connections with switching hubs and gateways. Therefore, they cannot be applied to systems that do not connect to switching hubs or gateways.

[0008] The problem that this invention aims to solve is to provide an elevator system and elevator control method that can identify unauthorized controllers and control operation using only normal controllers, without the need for a switching hub or dedicated monitoring equipment. [Means for solving the problem]

[0009] To solve the above-mentioned problems, the present invention provides an elevator system having a plurality of controllers for controlling an elevator, wherein each controller includes: a task switching determination unit that determines whether to perform packet inspection of packets sent to other controllers according to the control state of the controller; a packet analysis unit that performs the packet inspection and identifies an unauthorized controller; and an operation control unit that changes the control of the elevator according to the identification status of the unauthorized controller.

[0010] Furthermore, the elevator control method of the present invention is an elevator control method that uses a plurality of controllers to control an elevator, characterized in that the controller performs packet inspection of packets sent to other controllers according to the control state of the controller to identify an unauthorized controller, and changes the control of the elevator according to the identification status of the unauthorized controller. [Effects of the Invention]

[0011] According to the elevator system and elevator control method of the present invention, it is possible to identify an unauthorized controller and control operation using only normal controllers without installing a switching hub or dedicated monitoring device.

[0012] Other issues, configurations, and effects not mentioned above will be clarified by the following description of the embodiments. [Brief explanation of the drawing]

[0013] [Figure 1] Overall schematic diagram of the elevator system in Example 1. [Figure 2] Hardware basic configuration diagram of the controller in Example 1. [Figure 3] Functional block diagram of the controller in Example 1. [Figure 4] A diagram illustrating the controller table in Example 1. [Figure 5] A flowchart illustrating the operation of the task switching decision unit in Example 1. [Figure 6] A diagram illustrating the switchability table for Example 1. [Figure 7] A diagram illustrating the packet structure of Example 1. [Figure 8] A flowchart illustrating the operation of the packet analysis unit in Example 1. [Figure 9] A flowchart illustrating the operation of the fraudulent node collection unit in Example 1. [Figure 10] Operation control flow in the elevator system of Example 2 when the floor controller is malfunctioning. [Figure 11] Operation control flow when there is unauthorized communication of the floor controller in the elevator system of Example 3. [Figure 12] Operation control flow when the car controller in the elevator system of Example 4 is unauthorized. [Figure 13] Operation control flow when there is unauthorized communication of the car controller in the elevator system of Example 5. [Figure 14] Operation control flow when there is unauthorized communication of the in-car operation panel controller in the elevator system of Example 6.

Mode for Carrying Out the Invention

[0014] Hereinafter, embodiments of the present invention will be described with reference to the drawings. In each figure and each embodiment, the same or similar components are denoted by the same reference numerals, and redundant descriptions are omitted.

Embodiment

[0015] FIG. 1 is an overall schematic diagram of the elevator system of Example 1.

[0016] In this embodiment, for the sake of simplicity of explanation, details of one of the plurality of elevators 15 are illustrated in detail, and the other elevators 15 are illustrated in a simplified manner. In this embodiment, as an elevator system, a configuration that is connected to, for example, a center 1 installed at a remote location in order to perform management, monitoring, maintenance, etc. of the elevator 15 will be described as an example.

[0017] The center 1 is connected to the communication controller 3 via a communication network 2 such as a closed-circuit network like a dedicated line regardless of wireless or wired, or a public line like the Internet. The communication controller 3 is a controller that is responsible for data communication between the center 1 and the elevator 15. This communication is used for management of operation data, remote operation, and remote maintenance.

[0018] The communication controller 3 is connected via a communication path 17 to a group control controller 4 that efficiently controls multiple elevators 15. The group control controller 4 manages and operates the multiple elevators 15 as an elevator group 18. For example, it performs control that improves overall operational efficiency by scheduling the direction of operation and stopping floors of the elevators 15 based on the number of calls and passenger numbers for each floor.

[0019] The elevator controller 5 controls the movement of the rope 9 connecting the elevator car 7 and the counterweight 8 that balances the car 7 by controlling the motor 6, thereby moving the car 7 up and down and stopping it, providing passengers with the service of vertical movement within a building. The elevator controller 5 is connected to the group control controller 4 via a communication channel 16. The elevator controller 5 is also connected to one car controller 10 and floor controllers 11 installed on each floor via a communication channel 12.

[0020] The car controller 10 monitors the operation status of the control panel 13, which consists of destination floor buttons and door open / close buttons installed inside the car 7, via the in-car control panel controller 19, and transmits this status to the elevator controller 5. The in-car control panel controller 19 monitors the operation status of the control panel 13 inside the car 7 by passengers and transmits this status to the car controller 10. The car controller 10 may also perform the functions of the in-car control panel controller 19.

[0021] The floor controller 11 monitors the operation status of the up and down buttons 14 installed on each floor by passengers on each floor and transmits this status to the elevator controller 5.

[0022] In addition, a management terminal 80 may be provided for managing the entire elevator system locally within the building.

[0023] The network configuration using the communication channels shown in this embodiment is just one example and is not limited to this; it can be applied to other network configurations as well.

[0024] Figure 2 is a basic hardware configuration diagram of the controller in Example 1.

[0025] In this embodiment, each controller constituting the elevator system, specifically the communication controller 3, group control controller 4, elevator controller 5, car controller 10, floor controller 11, and in-car operation panel controller 19, will be collectively referred to as controller 20.

[0026] The controller 20 is, for example, a processing unit such as a microcontroller, and has a hardware configuration that includes an MPU (Micro Processing Unit) 22, ROM (Read Only Memory) 23, RAM (Random Access Memory) 24, a communication IF (Interface) 25, a storage device 26, and a bus 21 that connects these components.

[0027] The MPU22, ROM23, and RAM24 constitute the processing unit. Program code for each functional unit described in Figure 3 is stored in ROM23. The MPU22 reads the program code from ROM23, loads it into RAM24, and executes the program. Alternatively, the program code may be read directly from ROM23 and executed as is. ROM23 may also have a secure area that can only be accessed by special procedures and means. Data such as variables and parameters generated during processing by the MPU22 are temporarily written to RAM24, and this data is read from the MPU22 as appropriate depending on the processing.

[0028] The storage device 26 is composed of a non-volatile storage medium and stores various types of data. Furthermore, program code executed by the MPU 22 may be stored in the storage device 26 instead of the ROM 23.

[0029] Communication channels using IF25 can include, for example, multidrop serial communication such as RS-485, wired communication channels that provide multiple topologies (connection configurations) such as LAN (Local Area Network) and WAN (Wide Area Network) such as Ethernet®, and wireless communication such as RAN (Radio Area Network). In the case of wireless communication, for example, short-range wireless communication such as Wi-Fi® and long-range wireless communication such as mobile communication networks can be used.

[0030] By using this hardware configuration for the controller 20, it becomes possible to run a real-time operating system (RTOS) that provides the execution of elevator control applications and the basic processing of hardware operations.

[0031] Figure 3 is a functional block diagram of the controller in Example 1.

[0032] The controller 20 in this embodiment includes a control state confirmation unit 30, a task switching determination unit 32, a packet reception switching unit 34, a communication unit 36, a packet analysis unit 38, a fraudulent node collection unit 40, a storage unit 48, and an operation control unit 50. Each of these functional units can be realized by executing program code that implements each functional unit using a processing unit, as explained in Figure 2. The data stored in the storage unit 48 is stored in the storage device 26 or RAM 24.

[0033] The elevator system of this embodiment has multiple controllers 20 that control the elevator 15. In the elevator control method of this embodiment, a controller 20 performs packet inspection of packets sent to other controllers 20 according to the control state of the controller 20 to identify an unauthorized controller 20, and changes the control of the elevator 15 according to the identification of the unauthorized controller 20. As an example of changing the control of the elevator 15, for example, a controller 20 excludes the unauthorized controller 20 and controls the elevator 15. As a result, each controller 20 of the multiple controllers 20 can perform packet inspection when it is possible according to its own control state, so that an unauthorized controller can be identified and operation control can be performed with only normal controllers without the need for a switching hub or dedicated monitoring device.

[0034] The following describes the details of each functional part of the controller 20 that can achieve this.

[0035] The control status confirmation unit 30 checks the control status of the controller 20. An example of the control status is, for example, in the case of the elevator controller 5, whether the motor 6 is controlling the car 7 to move or whether the car 7 is stopped. Other examples of the control status are, for example, in the case of the car controller 10 and the in-car operation panel controller 19, the status of the operation panel 13, for example, in the case of the floor controller 11, the status of the up and down buttons 14, for example, in the case of the group control controller 4, the assignment status in response to passenger calls, etc. The control status confirmed by the control status confirmation unit 30 is transmitted to the task switching determination unit 32.

[0036] The task switching determination unit 32 determines whether to perform packet inspection on packets sent to other controllers 20, depending on the control state of the controller 20. More specifically, the task switching determination unit 32 determines whether to switch between normal control processing, which controls the elevator 15, and packet inspection processing, which performs packet inspection, depending on the control state of the controller 20. Details of this determination will be described later. The determination result from the task switching determination unit 32 is transmitted to the packet reception switching unit 34 and the packet analysis unit 38.

[0037] The packet reception switching unit 34 switches the communication mode setting of the communication unit 36 ​​according to the determination result of the task switching determination unit 32. The task switching determination unit 32 may also perform the functions of the packet reception switching unit 34.

[0038] The communication unit 36 ​​transmits and receives packets. When the task switching determination unit 32 determines that normal control processing should be performed, the communication unit 36 ​​is set to a normal communication mode in which packets destined for destinations other than its own controller 20 are discarded. When the task switching determination unit 32 determines that packet inspection processing should be performed, the communication unit 36 ​​is set to a communication mode in which all communication packets are captured, a so-called promiscuous communication mode. To return from packet inspection processing to normal control processing, the packet reception switching unit 34 simply switches the setting back to the normal communication mode. Packets received by the communication unit 36 ​​are sent to the packet analysis unit 38.

[0039] The packet analysis unit 38 analyzes the received packets. If the task switching determination unit 32 determines that normal control processing should be performed, the packet analysis unit 38 performs normal packet analysis and transmits the analysis results, including commands, to the operation control unit 50. If the task switching determination unit 32 determines that packet inspection processing should be performed, the packet analysis unit 38 performs packet inspection to identify the invalid controller 20. Based on the identification of the invalid controller 20, the packet analysis unit 38 updates the list of invalid controllers 20 stored in the storage unit 48. Details of the packet inspection performed by the packet analysis unit 38 will be described later.

[0040] The storage unit 48 stores, for example, a list of unauthorized transmitting nodes 44 and a list of unauthorized receiving nodes 46 as lists of unauthorized controllers 20. The unauthorized transmitting node list 44 is a list of transmitting nodes that the packet analysis unit 38 has determined to be involved in unauthorized activities, and the unauthorized receiving node list 46 is a list of receiving nodes that the packet analysis unit 38 has determined to be involved in unauthorized activities. A controller 20 corresponding to a node listed in at least one of the unauthorized transmitting node list 44 and the unauthorized receiving node list 46 is an unauthorized controller 20.

[0041] The operation control unit 50 performs operation control of the elevator 15. Here, the operation control unit 50 modifies the control of the elevator 15 according to the identification status of the unauthorized controller 20. Specifically, the operation control unit 50 retrieves the unauthorized transmission node list 44 and the unauthorized reception node list 46, which are lists of unauthorized controllers 20 stored in the memory unit 48, and modifies the operation control of the elevator 15 according to the combination of the unauthorized controller 20 and the content of the control process. A specific example of operation control by the operation control unit 50 will be described later.

[0042] The fraudulent node collection unit 40 generates a list of legitimate controllers 20 based on the list of fraudulent controllers 20 it owns, which is stored in the memory unit 48. It then collects a list of fraudulent controllers 20 owned by other legitimate controllers 20 that are present in the list of legitimate controllers 20, and updates its own list of fraudulent controllers 20. Details of the processing in the fraudulent node collection unit 40 will be described later.

[0043] Figure 4 is a diagram illustrating the controller table of Example 1.

[0044] Controller 20 maintains a controller table 60 that manages its components. Controller table 60 is a table that describes the standard configuration of controller 20. Controller table 60 is set during installation. Controller table 60 holds the controller type 62 of controller 20 and the node number 64 of controller 20. Controller table 60 is stored, for example, in the secure storage area of ​​the ROM 23 mentioned above.

[0045] Figure 5 is a flowchart illustrating the operation of the task switching decision unit in Example 1. Figure 6 is a diagram illustrating the switchability table in Example 1.

[0046] S10 is a control state acquisition step, in which the controller 20's control state is checked by the control state confirmation unit 30. The control state is checked, for example, according to the control cycle.

[0047] S20 is a task switching decision step, in which the controller 20, using the task switching decision unit 32, determines whether to perform packet inspection according to the control state. It determines whether a task switch from normal control processing to packet inspection processing is possible. For example, the switching feasibility table 100 shown in Figure 6 is used to determine whether a task switch is possible. The switching feasibility table 100 is a table that pre-defines the correspondence between the control state 102 and the task switching feasibility 104. Figure 6 is an example of the switching feasibility table 100 for the elevator controller 5, where the task switching feasibility 104 is set to ○ (possible) when the control state 102 is stopped or constant speed, and to × (impossible) when the control state 102 is accelerating or decelerating. For example, it is sufficient to set the task switch to packet inspection processing to be possible when the processing load on the controller 20 is light, such as when the utilization rate of the MPU 22 is below a predetermined value. Other controllers 20 other than the elevator controller 5 also maintain such a switching feasibility table 100 according to their operation and control content.

[0048] If the S20 decision indicates that switching is not possible, the process moves to S30 and continues with normal control processing.

[0049] If S20 determines that a switch is possible, the process moves to S40, where the task switching determination unit 32 registers the packet inspection task with the aforementioned RTOS.

[0050] The registered analysis tasks are executed as needed by the RTOS scheduler running on controller 20.

[0051] In S50, the packet reception switching unit 34 checks whether a packet inspection task is registered. If no task is registered, the process terminates. If a task is registered, the process moves to S60.

[0052] S60 is a communication mode switching step, in which the packet reception switching unit 34 switches the communication mode to the aforementioned indiscriminate communication mode.

[0053] S70 is a packet inspection step, and the packet analysis unit 38 performs the packet inspection. Once the packet inspection is complete, the registration of the packet inspection task is removed.

[0054] Once packet inspection is complete or interrupted, the process moves to step S80, where the packet reception switching unit 34 switches the communication mode to the normal communication mode. In this way, by determining whether to perform packet inspection depending on the control state of the controller 20, the processing load on the controller 20 can be reduced.

[0055] Figure 7 is a diagram illustrating the packet configuration of Example 1.

[0056] The packet 70 in this embodiment is composed of, for example, a magic number 71 indicating the packet's identity, a transmitting node number 72, a receiving node number 73, a data size 74, a command number 75, command parameters and other data 76, and check data 77 such as a checksum to detect communication data corruption. Here, the invalid data are the transmitting node number 72, the receiving node number 73, and the command number 75. In the elevator system, the number and role of the legitimate controllers 20 are predetermined in the controller table 60 described in Figure 4.

[0057] Figure 8 is a flowchart illustrating the operation of the packet analysis unit in Example 1.

[0058] The packet analysis unit 38 performs packet inspection to detect malicious communication. Specifically, in packet inspection, the packet analysis unit 38 identifies a malicious controller 20 by checking whether the transmitting node or receiving node exists in the controller table 60 which describes the configuration of a legitimate controller, and whether the command is a legitimate command.

[0059] In S100, the packet analysis unit 38 checks whether the transmitting node number 72 of the received packet exists in the controller table 60. If it does not exist, it determines that it is invalid and proceeds to S101. In S101, the packet analysis unit 38 records the transmitting node number 72 in the invalid transmitting node list 44 of the storage unit 48. After that, it proceeds to S102. In S100, if it exists, it determines that it is legitimate and proceeds to flow A.

[0060] In S102, the packet analysis unit 38 checks whether the receiving node number 73 exists in the controller table 60. If it does not exist, it determines that it is invalid and proceeds to S103. In S103, the packet analysis unit 38 records the receiving node number 73 in the invalid receiving node list 46 of the storage unit 48. After that, it proceeds to S104. If it exists in S102, it determines that it is legitimate and proceeds to S104.

[0061] In S104, the packet analysis unit 38 checks whether command number 75 is a predetermined legitimate command. If it is not a legitimate command, it determines it is invalid and proceeds to S105. In S105, the packet analysis unit 38 records the sending node number 72 in the invalid sending node list 44 of the storage unit 48. Also, in S106, as a candidate for an invalid controller 20, it temporarily records the receiving node number 73 as an invalid candidate node in the invalid candidate list (not shown) of the storage unit 48. After that, the flow ends. In S104, if it is a legitimate command, it determines it is legitimate and terminates the flow.

[0062] Flow A is a flow that determines whether receiving node number 73, which was recorded in the fraud candidate list in S106, is fraudulent or legitimate. This can be determined by checking the response of the response packet. Note that in the next communication cycle after being recorded in the fraud candidate list, the sending node and receiving node are swapped in the response packet to this packet.

[0063] In S107, the packet analysis unit 38 checks whether the sending node number 72 of the response packet (the same as the receiving node number 73 in the previous cycle) is recorded as a suspected malicious node in the suspected malicious node list. If there is no record, flow A is terminated. If there is a record, the process moves to S108.

[0064] In S108, the packet analysis unit 38 checks the response of the response packet. If it responds with "abnormal" to communication containing an invalid command, it determines that the source of this response packet is the legitimate controller 20, and the packet analysis unit 38 removes the sending node number 72 of the response packet (the same as the receiving node number 73 from the previous cycle) from the list of invalid candidates. After that, flow A ends and the process moves to S102. In S108, if it responds with "normal" to invalid communication, it determines that the source of this response packet is the invalid controller 20, and the packet analysis unit 38 records the sending node number 72 (the same as the receiving node number 73 from the previous cycle) in the invalid sending node list 44 or invalid receiving node list 46 of the storage unit 48. Furthermore, the packet analysis unit 38 may also remove the sending node number 72 of the response packet (the same as the receiving node number 73 from the previous cycle) from the list of invalid candidates. After that, flow A ends and the process moves to S102.

[0065] In this way, by verifying at least the transmitting node number 72, the receiving node number 73, and the command number 75, it becomes possible to detect the addition of an unauthorized controller 20 to the elevator system, or the replacement of an unauthorized controller 20 using an unauthorized command number 75, and thereby identify the unauthorized controller 20.

[0066] Figure 9 is a flowchart illustrating the operation of the fraudulent node collection unit in Example 1.

[0067] As mentioned above, the controller 20 switches to the packet inspection processing task depending on its control state, so the timing of receiving malicious communications also differs. Therefore, by exchanging analysis results for malicious communications that could not be received by each controller 20 individually, the accuracy of the analysis results can be improved.

[0068] To this end, the fraudulent node collection unit 40 generates a list of legitimate controllers 20 based on the list of fraudulent controllers 20 it owns stored in the memory unit 48, collects a list of fraudulent controllers 20 owned by other legitimate controllers 20 from the list of legitimate controllers 20 that are present in the list of legitimate controllers 20, and updates its own list of fraudulent controllers 20.

[0069] In S200, the fraudulent node collection unit 40 generates a list of legitimate controllers 20 (legitimate list) based on the list of fraudulent controllers 20 it owns (fraudulent list) stored in the memory unit 48. For example, the list of legitimate controllers 20 can be generated by excluding the fraudulent controllers 20 recorded in the list of fraudulent controllers 20 (fraudulent transmitting node list 44, fraudulent receiving node list 46) from the controller table 60 in Figure 4.

[0070] In S201, the fraudulent node collection unit 40 checks whether the node is present in the generated legitimate list. If the node is present, the process moves to S202. If the node is not present, the process moves to S206.

[0071] In S202, the fraudulent node collection unit 40 sends a fraudulent list transmission request to other legitimate controllers 20 that are present in the legitimate list, in order to collect the fraudulent lists held by those other legitimate controllers 20. If there are multiple legitimate controllers 20 in the legitimate list, it is desirable to send a fraudulent list transmission request to all legitimate controllers 20 present in the legitimate list.

[0072] In S203, the malicious node collection unit 40 receives the malicious list that was sent in response to the malicious list transmission request.

[0073] In S204, the malicious node collection unit 40 checks for any discrepancies between its own list of malicious nodes and the received list of malicious nodes. If there is a discrepancy, it proceeds to S205. If there is no discrepancy, it proceeds to S206. If multiple lists of malicious nodes are received, it is sufficient to proceed to S205 if there is a discrepancy in at least one list of malicious nodes, and to S206 if there are no discrepancies in any of the lists of malicious nodes.

[0074] In S205, since there is a mismatch, the rogue node collection unit 40 updates the rogue list in the storage unit 48. Specifically, it adds the missing node to the rogue list in the storage unit 48. If its own controller 20 is recorded as a rogue node in the transmitted rogue list, the node that sent this rogue list is determined to be a rogue node and is added to the rogue transmitting node list 44 in the storage unit 48. After updating the rogue list, the process ends.

[0075] In S206, since there are no discrepancies, the accuracy of the fraudulent list is judged to be high, and the fraudulent node collection unit 40 reports the fraudulent list to center 1.

[0076] As described above, by sharing the list of fraudulent nodes stored in the memory unit 48 only among the controllers 20 that each controller has determined to be legitimate, the accuracy of analyzing fraudulent nodes can be improved throughout the entire elevator system. [Examples]

[0077] Examples 2 and later describe specific examples of how the control of the elevator 15 is changed in the elevator system of Example 1 according to the identification of the unauthorized controller 20.

[0078] Figure 10 shows the operation control flow when the floor controller in the elevator system of Example 2 is malfunctioning.

[0079] In Embodiment 2, if the floor controller 11 is found to be faulty, the operation control unit 50 cancels the call from the faulty floor controller 11 and controls the floor where the faulty floor controller 11 is installed as a non-stopping floor.

[0080] In S300, the operation control unit 50 of the elevator controller 5 checks whether the floor controller 11 is legitimate. Specifically, it checks whether the floor controller 11 is registered in the invalid list of the storage unit 48. If it is not registered, it is a legitimate floor controller 11, and the process is completed successfully.

[0081] If it is registered, it is an invalid floor controller 11, so in S302, the operation control unit 50 cancels the floor call registration command from the invalid floor controller 11.

[0082] In S304, the operation control unit 50 of the elevator controller 5 checks whether the floor where the unauthorized floor controller 11 is installed is registered as a stop floor. If it is not registered as a stop floor, the process moves to S308. In S308, the operation control unit 50 of the elevator controller 5 sets the floor in question as a non-stop floor and terminates the process. As a result, the elevator is controlled not to stop on that floor thereafter. If the floor is registered as a stop floor in S304, the process moves to S306. In S306, since there is a passenger in the car 7 who wants to get off on that floor, the operation control unit 50 of the elevator controller 5 executes operation control to stop on that floor. After that, the process moves to S308 to register the floor in question as a non-stop floor.

[0083] As explained above, when an unauthorized floor controller 11 is detected, the up / down call registration command transmitted from that floor controller 11 in conjunction with the up / down buttons 14 is potentially unauthorized and will be canceled. At the same time, the floor in question will be made a non-stopping floor and will not be used. By eliminating the unauthorized floor controller 11, it is possible to reduce the impact of the unauthorized floor controller 11 on elevator operation control thereafter. [Examples]

[0084] Figure 11 shows the operation control flow in the elevator system of Example 3 when there is unauthorized communication from the floor controller.

[0085] In Embodiment 3, the operation control unit 50 stops the train at the nearest floor if the frequency of unauthorized communication from the floor controller 11 exceeds a predetermined value, and also controls the floor where the unauthorized floor controller 11 is installed as a non-stopping floor. Here, the frequency of unauthorized communication exceeding a predetermined value refers to, for example, exceeding a predetermined number of occurrences within a predetermined time.

[0086] In S400, the operation control unit 50 of the elevator controller 5 measures the number of unauthorized communications.

[0087] In S402, the operation control unit 50 of the elevator controller 5 checks the frequency of unauthorized communications. For example, it checks whether the number of unauthorized communications within a predetermined time exceeds a predetermined number. If the frequency is low, the processing flow ends. If the frequency exceeds a predetermined value, the process moves to S404.

[0088] In S404, the operation control unit 50 of the elevator controller 5 performs an operation to stop at the nearest floor. However, this operation may be omitted if it is not necessary to stop at the nearest floor.

[0089] In S406, the operation control unit 50 of the elevator controller 5 sets the floor where the unauthorized floor controller 11 is installed as a non-stopping floor.

[0090] Through the control described above, it is possible to eliminate unauthorized floor controllers 11 and reduce the impact of unauthorized floor controllers 11 on elevator operation control thereafter. [Examples]

[0091] Figure 12 shows the operation control flow when the car controller in the elevator system of Example 4 is malfunctioning.

[0092] In Embodiment 4, if the car controller 10 is malfunctioning, the operation control unit 50 determines whether to continue operation or stop operation after arriving at the registered floor, depending on whether or not there is any malfunctioning communication within a predetermined time.

[0093] In S500, the operation control unit 50 of the elevator controller 5 checks whether the car controller 10 is recorded in the unauthorized transmission node list 44 or unauthorized reception node list 46 of the storage unit 48 in order to confirm whether the car controller 10 is a legitimate controller 20. If it is not recorded, it is determined to be legitimate and the process ends. If it is recorded, it is determined to be unauthorized and the process moves to S502.

[0094] In S502, the operation control unit 50 of the elevator controller 5 executes operation control to the registered floor, arrives, and waits. This allows all passengers in the elevator car 7 to disembark.

[0095] In S504, the operation control unit 50 of the elevator controller 5 checks whether the current operation is a restart operation from a standby due to an unauthorized communication during the previous operation (S512, described later).

[0096] If operation is to resume, proceed to S506. In S506, the operation control unit 50 of the elevator controller 5 stops operation.

[0097] If the elevator does not resume operation, proceed to S508. In S508, the operation control unit 50 of the elevator controller 5 waits at the current stopping floor for a predetermined time.

[0098] In S510, the operation control unit 50 of the elevator controller 5 checks whether or not malicious packet communication has occurred during the predetermined waiting time. If malicious packet communication has occurred, the process moves to S506 and stops operation. If no malicious packet communication has occurred, the process moves to S512. In S512, the operation control unit 50 of the elevator controller 5 resumes operation and stores that it is a resumed operation.

[0099] Through the control described above, if an unauthorized car controller 10 is detected, the system will check for the occurrence of unauthorized packets within a predetermined time, and if no unauthorized packets are generated, it will be possible to temporarily resume operation. However, a second resumption of operation is not permitted. The reason for allowing one resumption of operation is that stopping operation after just one instance would reduce operational efficiency, so one resumption of operation is permitted, and operation will be stopped if the unauthorized activity continues. [Examples]

[0100] Figure 13 shows the operation control flow in the elevator system of Example 5 when there is unauthorized communication from the car controller.

[0101] In Embodiment 5, the operation control unit 50 stops operation after stopping at the nearest floor if the frequency of unauthorized communication from the car controller 10 exceeds a predetermined value.

[0102] In S600, the operation control unit 50 of the elevator controller 5 checks whether the car controller 10 is recorded in the unauthorized transmission node list 44 or unauthorized reception node list 46 of the storage unit 48 in order to confirm whether the car controller 10 is a legitimate controller 20. If it is not recorded, it is determined to be legitimate and the process ends. If it is recorded, it is determined to be unauthorized and the process moves to S602.

[0103] In S602, the operation control unit 50 of the elevator controller 5 measures the number of unauthorized communications.

[0104] In S604, the operation control unit 50 of the elevator controller 5 checks the frequency of unauthorized communications. For example, it checks whether the number of unauthorized communications within a predetermined time exceeds a predetermined number. If the frequency is low, the processing flow ends. If the frequency exceeds a predetermined value, the process moves to S606.

[0105] In S606, the operation control unit 50 of the elevator controller 5 performs an operation to stop at the nearest floor. This allows passengers in the elevator car 7 to disembark.

[0106] In S608, the operation control unit 50 of the elevator controller 5 stops operation.

[0107] Through the control described above, it is possible to eliminate the unauthorized car controller 10 and reduce the impact of the unauthorized car controller 10 on subsequent elevator operation control. [Examples]

[0108] Figure 14 shows the operation control flow in the elevator system of Example 6 when there is unauthorized communication from the in-car control panel controller.

[0109] In Embodiment 6, the operation control unit 50 stops operation after stopping at the nearest floor if the frequency of unauthorized communication from the in-car operation panel controller 19 exceeds a predetermined value.

[0110] In S700, the operation control unit 50 of the car controller 10 checks whether the car control panel controller 19 is recorded in the unauthorized transmission node list 44 or unauthorized reception node list 46 of the storage unit 48 to confirm whether the car control panel controller 19 is a legitimate controller 20. If it is not recorded, it is determined to be legitimate and the process ends. If it is recorded, it is determined to be unauthorized and the process moves to S702.

[0111] In S702, the operation control unit 50 of the car controller 10 measures the number of unauthorized communications.

[0112] In S704, the operation control unit 50 of the cage controller 10 checks the frequency of unauthorized communications. For example, it checks whether the number of unauthorized communications within a predetermined time exceeds a predetermined number. If the frequency is low, the processing flow is terminated. If the frequency exceeds a predetermined value, the process moves to S706.

[0113] In S706, the operation control unit 50 of the car controller 10 requests the elevator controller 5 to stop at the nearest floor. After that, the process ends.

[0114] In S708, the operation control unit 50 of the elevator controller 5 receives a request to stop at the nearest floor.

[0115] In S710, the operation control unit 50 of the elevator controller 5 performs an operation to stop at the nearest floor. This allows passengers in the car 7 to disembark.

[0116] In S712, the operation control unit 50 of the elevator controller 5 stops operation.

[0117] Through the control described above, it is possible to eliminate the unauthorized in-car control panel controller 19 and reduce the impact of the unauthorized in-car control panel controller 19 on elevator operation control thereafter.

[0118] Although embodiments of the present invention have been described above, the present invention is not limited to the configurations described in the embodiments, and various modifications are possible within the scope of the technical idea of ​​the present invention. Furthermore, some or all of the configurations described in each embodiment may be combined and applied. [Explanation of symbols]

[0119] 1 Center 2. Communication Network 3. Communication Controller 4 Group Management Controller 5. Elevator Controller 6 motors 7 baskets 8 counterweights 9 ropes 10 Basket Controllers 11 Floor Controller Channels 12, 16, and 17 13 Control panel 14 Up and down buttons 15 Elevator 18 Elevator Groups 19. In-car control panel controller 20 controllers 21 Bus 22 MPU 23 ROM 24 RAM 25 Communication IF 26 Storage device 30 Control status confirmation unit 32 Task switching determination unit 34. Packet reception switching unit 36 Communications Department 38 Packet Analysis Unit 40. Fraudulent Node Collection Unit 44 List of Unauthorized Sending Nodes 46 List of unauthorized receiving nodes 48 Memory section 50 Operation Control Unit 60 Controller Table 62 Controller Types 64 node number 70 packets 71 Magic Number 72 Transmitting node number 73 Receiving node number 74 Data size 75 Command number 76 data 77 Check Data 80 Management terminals 100 Switchability Table 102 Control State 104 Task switching capability

Claims

1. In an elevator system having multiple controllers for controlling the elevator, The aforementioned controller, A task switching determination unit determines whether to perform packet inspection of packets sent to other controllers, depending on the control state of the aforementioned controller. A packet analysis unit that performs the aforementioned packet inspection to identify the unauthorized controller, An elevator system characterized by having an operation control unit that changes the control of the elevator according to the identification status of the unauthorized controller.

2. In claim 1, The elevator system is characterized in that the task switching determination unit determines whether to switch between a normal control process for controlling the elevator and a packet inspection process for performing packet inspection, depending on the control state of the controller.

3. In claim 1, The elevator system is characterized in that, in the packet analysis unit, it identifies the invalid controller by checking whether the transmitting node or receiving node exists in a controller table describing the configuration of a legitimate controller, and whether the command is a legitimate command.

4. In claim 1, The elevator system is characterized in that the controller has a fraudulent node collection unit that generates a list of legitimate controllers based on the list of fraudulent controllers it owns, collects a list of fraudulent controllers owned by other legitimate controllers that are present in the list of legitimate controllers, and updates the list of fraudulent controllers it owns.

5. In claim 1, The elevator system is characterized in that, if the floor controller is found to be faulty, the operation control unit cancels the call from the faulty floor controller and controls the floor where the faulty floor controller is installed as a non-stopping floor.

6. In claim 1, The elevator system is characterized in that, when the frequency of unauthorized communication from the floor controller exceeds a predetermined value, the operation control unit performs an operation to stop at the nearest floor and controls the floor where the unauthorized floor controller is installed as a non-stopping floor.

7. In claim 1, The elevator system is characterized in that, if the car controller is malfunctioning, the operation control unit determines whether to continue operation or stop operation after arrival at the registered floor, depending on whether or not there has been any unauthorized communication within a predetermined time.

8. In claim 1, The elevator system is characterized in that, if the frequency of unauthorized communication from the car controller exceeds a predetermined value, the operation control unit stops the elevator after stopping at the nearest floor.

9. In claim 1, The elevator system is characterized in that, if the frequency of unauthorized communication from the in-car control panel controller exceeds a predetermined value, the operation control unit stops the elevator after stopping at the nearest floor.

10. In claim 1, The elevator system is characterized in that the operation control unit eliminates the unauthorized controller and controls the elevator.

11. In an elevator control method that uses multiple controllers to control an elevator, An elevator control method characterized in that the controller performs packet inspection of packets sent to other controllers according to the control state of the controller to identify an unauthorized controller, and changes the control of the elevator according to the identification status of the unauthorized controller.

12. In claim 11, The elevator control method is characterized in that the controller controls the elevator by eliminating the unauthorized controller.

Citation Information

Patent Citations

  • Fraudulent intrusion detecting system

    JP2001350678A

  • Vehicle network monitoring device

    JP2013131907A

  • Network control device

    JP2015035724A

  • Whitelist generator, whitelist evaluator and whitelist generation / evaluator, whitelist generation method, whitelist evaluation method and whitelist generation / evaluation method

    JP2018537009A

  • Unauthorized use prevention method of elevator board

    JP2020193044A