Method and controller of an elevator configured for establishing a secure data communication with a mobile device

The method of generating unique key pairs for elevator systems ensures secure data communication with mobile devices by encrypting and decrypting data with specific keys, addressing vulnerabilities and ensuring authorization, thus enhancing security and cost-effectiveness.

WO2025172200A1PCT designated stage Publication Date: 2025-08-21INVENTIO AG
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2025/053361
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-02-12
Filing Date
2025-02-10
Publication Date
2025-08-21

AI Technical Summary

Technical Problem

Existing elevator systems face challenges in establishing secure data communication with external mobile devices due to vulnerabilities in key management and potential cyberattacks, necessitating a secure and cost-effective solution.

Method used

A method involving the generation of unique key pairs for each communication partner, where data transmission is encrypted with respective public keys and decrypted with corresponding private keys, ensuring each participant is uniquely identified and authorized, with key pairs being canceled upon device exit from the detection area.

Benefits of technology

This approach provides high-security data communication by uniquely identifying and authorizing participants, preventing unauthorized access and manipulation, while maintaining simplicity and low cost.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2025053361_21082025_PF_FP_ABST
    Figure EP2025053361_21082025_PF_FP_ABST
Patent Text Reader

Abstract

The present invention relates to a method for establishing a secure data communication between a controller (5) of an elevator system (1) and at least of one mobile device (3). The controller (5) detects the mobile device (3) when this mobile device (3) enters a wireless detection area (4) of the controller (5). The controller (5) and the mobile device (3) communicate initially with each other to establish the secure data communication (2) between them within the detection area (4), wherein the controller (5) generates a first key pair (KP1) consisting of a first public key (PUK1) and a first private key (PRK1) and communicates the first public key (PUK1) to the mobile device (3). In response, the mobile device (3) generates a second key pair (KP2) consisting of a second public key (PUK2) and a second private key (PRK2) and communicating the second public key (PUK2) to the controller (5). The secure data communication (2) is established in this manner that data to be transmitted from the controller (5) to the mobile device (3) is encrypted with the second public key (PUK2), wherein data to be transmitted from the mobile device (3) to the controller (5) is encrypted with the first public key (PUK1).
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Method and controller of an elevator configured for establishing a secure data communication with a mobile device

[0002] The present invention relates to a method for establishing a secure data communication between a controller of an elevator system and at least of one mobile device.

[0003] Furthermore, the present invention relates to a controller of an elevator system, wherein the controller is configured for executing or controlling such method. The present invention relates also to a computer program product configured for executing or controlling such method as well as to a computer readable medium comprising such computer program product stored thereon.

[0004] Passenger transport systems such as elevators, moving walkways or escalators are used to transport people within buildings or structures between various floors (corridors) in the multi-story building. A passenger transport system has various stationary and displaceable components that are usually controlled and / or coordinated by a controller of the passenger transport system. A controller of an elevator system, for example, a main controller, may control a drive machine to move an elevator car to certain floors in response to call requests given by passengers. Furthermore, the elevator system typically comprises a landing operation panel (LOP) located outside of the elevator car and a car operating panel (COP) located inside of the elevator car, which is for registering a destination floor or calling other functions. By using such a COP or LOP, passenger may enter requests to, for example, instruct an elevator car to pick him / her up at a floor where he / she is currently located and then drive him / her to a desired destination floor.

[0005] In recent years, there has been more and more performance of wireless communication between elevator controllers within an elevator. Similarly, it is also considered to perform wireless communication between the elevator system with external devices or networks. Mobile devices such as smartphones can provide quicker and easier elevator operation through convenient features. For example, a smartphone displays the assigned elevator and its current status and also alerts passengers to assist smooth boarding when an elevator car is approaching. Operating an elevator via a smartphone allows passengers to reduce touching a controller like a COP or LOP of the elevator. A mobile device can also be a wheelchair or other assistive mobility equipment. However, controllers of an elevator must meet high safety requirements as it must be ensured that such a controller always controls the operation of the elevator system in a manner that passengers and / or the elevator system are not endangered. It must also be ensured that the controller itself cannot be manipulated without authorization and that data transmitted to and from the controller for operating the elevator system should be protected against hacking and cyberattacks.

[0006] Accordingly, there may be a need for establishing a secure data communication between an elevator and a plurality of external devices, especially mobile devices. On the one hand, it can provide better data communication security. On the other hand, it can be implemented simply and at low cost.

[0007] Such needs may be met with the subject-matter of the independent claims. Advantageous embodiments are defined in the dependent claims as well as in the following specification.

[0008] According to a first aspect of the present invention, a method is provided to establish a secure data communication between a controller of an elevator system and at least one mobile device, particularly, an external mobile device that is not a part of the elevator system. The method may include following steps:

[0009] - the controller detects the mobile device when this mobile device enters a wireless detection area of the controller,

[0010] - the controller and the mobile device initially communicate with each other to establish the secure data communication between them within the detection area, wherein the controller generates a first key pair (KPI) consisting of a first public key (PUK1) and a first private key (PRK1) and communicates the first public key (PUK1) to the mobile device, and this KPI is a randomly generated key pair,

[0011] - the mobile device generates a second key pair (KP2) consisting of a second public key (PUK2) and a second private key (PRK2) and communicates the second public key (PUK2) to the controller,

[0012] - the secure data communication is established in this manner that data to be transmitted from the controller to the mobile device is encrypted with the second public key (PUK2), wherein data to be transmitted from the mobile device to the controller is encrypted with the first public key (PUK1). The controller above can be a main controller, sub-controller and / or an operation panel, such as LOP / COP of the elevator system. The mobile device can be a portable terminal such as a mobile telephone of a passenger or a service technician, wherein the mobile device is able to communicate wirelessly with the controller of the elevator via a wireless area network, especially a Bluetooth Low Energy (BLE) or a Wireless Local Area Network (WLAN) so that an initiate communication between the controller and the mobile device can be performed for establishing a secure data communication between them.

[0013] Conventionally, encryption may be used for establishing a secure data communication. However, implementing such encryption may either require a complex management of encryption keys or may be vulnerable to security losses due to, for example, loss of or publication of encryption keys, which normally is either fixed or changes only periodically. The method according to a first aspect of the present invention can realize a high level of communication security for an elevator, wherein every unit (controller or device) has its own unique key, so that data communicated between two different units can be encrypted and decrypted with two different keys. That is to say, the data encrypted with an encryption key can only be successfully decrypted with a decryption key that corresponds one-to-one with the encryption key. Moreover, in order to increase the security of data communication, for each unit, other units may only know the encryption key, while the decryption key is reserved only for itself. Therefore, each participant in a data communication is uniquely identified and authorised by its key pair. In particular, the controller and the respective mobile device decrypt data encrypted with the first public key (PUK1) only with the first private key (PRK1).

[0014] Since more than one mobile device may enter the detection area of the controller at different time moments, the controller may generate different KPI for each mobile device. Alternatively, the controller may also generate the same KPI for two or more mobile devices when they sequentially enter the detection area, for example, within half or one minute.

[0015] According to an embodiment in respect of the first aspect of the invention, when the mobile device has left the detection area for a predetermined time period, for example, one minute or more than five minutes, the controller cancels the KPI. Correspondingly, the PUK2 is temporarily stored in the controller until the controller cancels the KPI. According to an embodiment in respect of the first aspect of the invention, when the mobile device has left the detection area for a predetermined time period, the mobile device cancels the KP2 and the PUK1.

[0016] According to a further embodiment in respect of the first aspect of the invention, data encrypted with the public key (PUK1, PUK2) of a key pair (KPI, KP2) is only decrypted with the corresponding private key (PRK1, PRK2) of this key pair (KPI, KP2). For instance, the controller decrypts and reads data encrypted with the PUK1 only with the PRK1. And the mobile device decrypts and reads data encrypted with the PUK2 only with the PRK2.

[0017] According to another embodiment in respect of the first aspect of the invention, the KPI is generated if the controller has identified and authorized the mobile device that is allowed to communicate with the controller. In other words, the controller generates a random KPI that will be used for authentication and authorization of the mobile device.

[0018] In summary, a pair of keys (KP) with a public key (PUK) which may be distributed to communication partners, while a private key (PRK) is to be kept secret in the unit in which the PRK is generated. Therein, the PUK of a recipient may be used by a communication partner to encrypt data before sending them to the recipient. Then the PRK can be used by the recipient to decrypt the received data, which is encrypted with the PUK.

[0019] Using such encryption, each participant on a network is uniquely identified and authorised by its key pair. Therefore, it is crucial that the secret key of a certain authorised member of the network is never revealed. If a secret key is compromised, it is then virtually possible to impersonate an authorised member of the network to perform unauthorised access to and manipulations of the other members.

[0020] According to a second aspect of the invention, a controller of an elevator system is provided, wherein the controller is capable of

[0021] - detecting a mobile device when this mobile device enters a wireless detection area of the controller, - communicating initially with the mobile device to establish the secure data communication between them within the detection area, wherein the controller generates a first key pair (KPI) including a first public key (PUK1) and a first private key (PRK1) and communicates the first public key (PUK1) to the mobile device,

[0022] - receiving a second public key (PUK2) generated by the mobile device,

[0023] - establishing the secure data communication in this manner that data to be transmitted from the controller to the mobile device is encrypted with the second public key (PUK2), wherein data received by the controller is encrypted with the first public key (PUK1).

[0024] According to an embodiment in respect of the second aspect of the invention, the controller may cancel the KPI when the controller hast detected the mobile device has been out of the detection area for a predetermined time period.

[0025] According to an embodiment in respect of the second aspect of the invention, the controller is able to store the PUK2 temporarily until the controller cancels the KPI.

[0026] According to an embodiment in respect of the second aspect of the invention, the controller decrypts data encrypted with the PUK1 only with the PRK1.

[0027] According to a further embodiment in respect of the second aspect of the invention, the controller may encrypt data with the PUK2 of the mobile device which is to receive this encrypted data.

[0028] According to a further embodiment in respect of the second aspect of the invention, if the controller has identified and authorized the mobile device that is allowed to communicate with the controller, the controller can generate the KP 1.

[0029] According to a third aspect of the invention, a computer program product is proposed. The computer program product comprises computer readable instructions which, when performed by a controller according to an embodiment of the second aspect of the invention, instruct the controller to executing or controlling the method according to an embodiment of the first aspect of the invention. The computer program product may be programmed in any computer language. According to a fourth aspect of the invention, a computer readable medium is proposed, the computer readable medium comprising a computer program product according to an embodiment of the third aspect of the invention stored thereon. The computer readable medium can be a flash memory, a CD, a DVD, a ROM, a PROM, an EPROM, etc. Alternatively, the computer program product may be stored on another computer or server or in a data cloud and may be downloaded for example via a network such as the Internet.

[0030] It shall be noted that possible features and advantages of embodiments of the invention are described herein partly with respect to a method for establishing a secure data communication between a controller of an elevator system and partly with respect to a controller being configured for implementing such a method. One skilled in the art will recognize that the features may be suitably transferred from one embodiment to another, and features may be modified, adapted, combined and / or replaced, etc. in order to come to further embodiments of the invention.

[0031] In the following, advantageous embodiments of the invention will be described with reference to the enclosed drawings. However, neither the drawings nor the description shall be interpreted as limiting the invention.

[0032] Fig. 1 shows an elevator system comprising a controller, according to an embodiment of the present invention,

[0033] Fig. 2 shows a flowchart for visualising a establishing a secure data communication according to an embodiment of the present invention,

[0034] Fig. 3 shows a flowchart for visualising a data transmission via the established secure data communication according to an embodiment of the present invention.

[0035] Fig. 1 shows an elevator system 1, which comprises at least one controller 5, for example, a main controller, sub-controller and / or a LOP / COP of the elevator system 1. This controller 5 is wireless communicable and has a wireless detection area 4, in which a mobile device 3a such as a portable terminal, mobile telephone of a person (passenger or service technician) or a wheelchair that is also capable of wireless communication can be detected by the controller 5. Consequently, the controller 5 and mobile device 3a communicate intimately with each other at first via a data communication network 6, for example, a wireless area network, especially a Bluetooth Low Energy (BLE) or a Wireless Local Area Network (WLAN), depending on what is available. As a means of short-distance communication, Bluetooth is widely used to connect Bluetooth devices. For this embodiment, preferably, a Bluetooth network 6 can be used for this elevator system 1 to communicate with the controller 5. However, such a communication initiated between the controller 5 and the mobile device 3 is not safe enough, because any mobile device 3 in the detection area 4 of the controller 5 may ask the controller 5 to communicate without any security provisions being in place. No authorization check is made when establishing a communication. It must thus be ensured that data transmission between the controller 5 and the mobile device 3 to operate the elevator system 1 should be protected.

[0036] A flowchart is shown in Fig. 2, in order to establish a secure data communication 2 with the detected mobile device 3, the controller 5 will generate a random first key pair (KPI) which includes a first public key (PUK1) and a first private key (PRK1). The generation of the random KPI can be understood as meaning that the controller has authenticated and authorized the mobile device 3. Advantageously, the KPI is generated only when the controller 5 has authenticated and authorized this mobile device 3 that is allowed to communicate with the controller 5.

[0037] The controller 5 will keep the PRK1 secret and only send the PUK1 to the mobile device 3 through the conventional communication network 6, for example, Bluetooth. In response, the mobile device 3 will generate a second key pair (KP2) including a second public key (PUK2) and a second private key (PRK2). Moreover, via the communication network 6, the mobile device 3 will send the PUK2 to the controller 5, and the controller 5 will save this PUK2.

[0038] Fig. 3 shows a flow chart of data transmission through a secure data communication between the controller 5 and the mobile device 3. This secure data communication 2 between the controller 5 and the mobile device 3 can then be established by encrypting data to be sent from the controller 5 to the mobile device 3 with the PUK2 and encrypting data to be sent from the mobile device 3 to the controller 5 with the PUK1. Accordingly, data encrypted with the PUK1 can only be decrypted in the controller 5 with the PRK1, while data encrypted with the PUK2 can only be decrypted in the mobile device 3a with the PRK2. Since the PRK1 and PRK2 generated in one unit (controller 5 or mobile device 3a) are never published to other units, data which is set to be received by the unit can only be read by that unit. Hence, the data transmission between the controller 5 and the mobile device 3a is secure and safe.

[0039] In case that another mobile device 3b exists in the detection area 4 at the same time, the controller 5 will also send its PUK1 to the mobile device 3b. The mobile device 3b will also generate a third key pair (KP3) including a third public key (PUK3) and a third private key (PRK3), wherein the PRK3 will be kept secret in the mobile device 3b, and only the PUK3 will be sent to the controller 5 and stored there. Therein, the controller 5 is able to encrypt data with the corresponding PUK2 or PUK3 according to which mobile device the data will be sent to.

[0040] When the mobile device 3 has been out of the detection area 4 for more than a predetermined time period, for example, one or five minutes. The controller 5 will cancel the KPI. Accordingly, the PUK2 and the PUK3 are temporarily stored in the controller 5 until the controller 5 cancels the KPI. And when the mobile devices 3a and 3b leave the detection area 4 for a predetermined time period, they cancel the KP2, KP3 and the PUK1 respectively.

[0041] Finally, it should be noted that the term “comprising” does not exclude other elements or steps and the “a” or “an” does not exclude a plurality. Also elements described in association with different embodiments may be combined. It should also be noted that reference signs in the claims should not be construed as limiting the scope of the claims.

Claims

Claims:

1. Method for establishing a secure data communication (2) between a controller (5) of an elevator system (1) and at least one mobile device (3), including:- the controller (5) detecting the mobile device (3) when this mobile device (3) enters a wireless detection area (4) of the controller (5),- the controller (5) and the mobile device (3) communicating initially with each other to establish the secure data communication (2) between them within the detection area (4), wherein the controller (5) generates a first key pair (KPI) consisting of a first public key (PUK1) and a first private key (PRK1) and communicates the first public key (PUK1) to the mobile device (3),- the mobile device (3) generating a second key pair (KP2) consisting of a second public key (PUK2) and a second private key (PRK2) and communicating the second public key (PUK2) to the controller (5),- establishing the secure data communication (2) in this manner that data to be transmitted from the controller (5) to the mobile device (3) is encrypted with the second public key (PUK2), wherein data to be transmitted from the mobile device (3) to the controller (5) is encrypted with the first public key (PUK1).

2. Method according to claim 1, wherein the controller (5) cancels the first key pair (KPI) when the mobile device (3) has been out of the detection area (4) for a predetermined time period.

3. Method according to claim 1 or 2, wherein the second public key (PUK2) is temporarily stored in the controller (5) until the controller (5) cancels the first key pair (KPI).

4. Method according to any of the preceding claims, wherein the mobile device (3) cancels the second key pair (KP2) and the first public key (PUK1) when the mobile device (3) has left the detection area (4) for the predetermined time period.

5. Method according to any of the preceding claims, wherein data encrypted with the public key (PUK1, PUK2) of a key pair (KPI, KP2) is only decrypted with the corresponding private key (PRK1, PRK2) of this key pair (KPI, KP2).

6. Method according to any of the preceding claims, wherein in case of more than one mobile device (3), data is encrypted with the second public key (PUK2) of the mobile device (2) which is to receive this encrypted data.

7. Method according to any of the preceding claims, wherein the first key pair (KPI) is generated if the controller (5) has identified and authorized the mobile device (3) that is allowed to communicate with the controller (5).

8. Controller (5) of an elevator system (1), wherein the controller (5) is capable of- detecting a mobile device (3) when this mobile device (3) enters a wireless detection area (4) of the controller (5),- communicating initially with the mobile device (3) to establish the secure data communication (2) between them within the detection area (4), wherein the controller (5) generates a first key pair (KPI) consisting of a first public key (PUK1) and a first private key (PRK1) and communicates the first public key (PUK1) to the mobile device (3),- receiving a second public key (PUK2) generated by the mobile device (3),- establishing the secure data communication (2) in this manner that data to be transmitted from the controller (5) to the mobile device (3) is encrypted with the second public key (PUK2), wherein data received by the controller (5) is encrypted with the first public key (PUK1).

9. Controller (5) according to claim 8, wherein the controller (5) is capable of cancelling the first key pair (KPI) when the controller (5) hast detected the mobile device (3) has been out of the detection area (4) for a predetermined time period.

10. Controller (5) according to claim 8 or 9, wherein the controller (5) is capable of storing the second public key (PUK2) temporarily until the controller (5) cancels the first key pair (KPI).

11. Controller (5) according to any of claims 8 to 10, wherein the controller (5) is capable of encrypting data with the second public key (PUK2) of the mobile device (2) which is to receive this encrypted data.

12. Controller (5) according to any of claims 8 to 11, wherein the controller (5) is capable of generating the first key pair (KPI) if the controller (5) has identified and authorized the mobile device (3) that is allowed to communicate with the controller (5).

13. Elevator system (1) comprising a controller (5) according to any of claims 8 to 12.

14. Computer program product comprising computer readable instructions which, when performed by a processor of a controller (5) of an elevator system (1), instruct the controller (5) to one of executing and controlling the method according to one of claims 8 to 12.

15. Computer readable medium comprising a computer program product according to claim 14 stored thereon.

Citation Information

Patent Citations

  • Method for operating an elevator system and system for operating an elevator device

    CN115667111A

  • Establishing a protected data communication connection between a controller of a passenger transport system and a mobile device

    US20220086129A1

  • Techniques for authenticating building / room access terminals

    US20220392286A1

  • Method of operating a computer-controlled device for establishing a secure data communication in a distributed control system of a passenger transportation arrangement

    WO2021160542A1