Elevator Component Code Updates with Staged Installation Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Software updates for embedded devices in passenger conveyance systems like elevators can cause service disruptions and customer dissatisfaction if not managed efficiently.

Innovation Solution

A system and method involving a component management system (CMS), an elevator system controller (ESC), and a gateway that manage code updates through preliminary and secondary installations, utilizing a controller area network and wide area network to minimize disruptions and ensure cybersecurity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If software updates are performed manually or ad-hoc on elevator components, then updates can be applied quickly, but service disruptions occur and customer satisfaction decreases

Engineering Contradiction:
Improveupdate speedVSAvoidservice continuity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary actions by first installing updated code on a virtual system or subset of components before full deployment. The gateway receives updated code, installs it on a virtual system first, verifies functionality, and only then proceeds to install on actual components, preventing service disruptions through advance testing.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The update process is segmented into multiple phases: receiving updated code, installing on virtual system, verifying functionality, installing on subset of components, and full deployment. This segmentation allows controlled rollout and minimizes disruption by updating components incrementally rather than all at once.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If multiple updates are performed to satisfy customer requirements, then customer satisfaction may improve, but service disruptions increase

Engineering Contradiction:
Improvecustomer satisfactionVSAvoidservice disruption time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system incorporates feedback mechanisms where the gateway verifies updated code functionality on the virtual system before full deployment. Customer satisfaction is achieved through reliable updates while minimizing disruptions by using feedback-driven verification to ensure updates work correctly before widespread implementation.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

Multiple customer-requested updates can be prepared in advance on the virtual system and queued for deployment. The gateway manages multiple update installations sequentially on subsets of components, allowing customer requirements to be met without causing repeated service disruptions through careful coordination.

Inventive Principle:
Principle #10Preliminary action

3Loss of time

If code updates are installed on all components simultaneously, then update completion is fast, but system reliability decreases due to potential widespread failures

Engineering Contradiction:
Improveupdate deployment timeVSAvoidsystem stability
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

The system segments the component base into subsets and updates them in waves rather than simultaneously. The gateway installs updated code on one subset of components at a time, allowing isolation of potential failures and maintaining system stability while still achieving relatively quick overall deployment through parallel processing of subsets.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The gateway performs partial updates by installing code on subsets of components rather than all components at once. This partial action approach balances deployment speed with reliability by updating enough components to make progress while limiting the risk of widespread failures.

Inventive Principle:
Principle #16Partial or excessive action

4Ease of operation

If manual update processes are used, then flexibility in handling different scenarios is maintained, but automation level and efficiency decrease

Engineering Contradiction:
ImproveflexibilityVSAvoidupdate automation
Core Design Contradiction:
Ease of operationVSExtent of automation

Solution Approach 1:

The gateway performs self-service by automatically receiving updated code, installing it on virtual systems, verifying functionality, and deploying to components without requiring manual intervention for each step. This maintains operational flexibility while achieving high automation, as the system autonomously handles the update process based on predefined protocols.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP4674798A1Elevator system and method for updating code on elevator components in a building
Publication Date: 2026.01.07 OTIS ELEVATOR CO
  • EP4674798A1 patent drawingFigure 1
  • EP4674798A1 patent drawingFigure 2
  • EP4674798A1 patent drawingFigure 3

AI summary

An elevator system for installing updated code on elevator components in a building, the system having: a component management system (CMS); an elevator system controller (ESC) in the building, operationally coupled to the components; a gateway that communicates with the ESC and the components over a first network and with the CMS over a second network, wherein the gateway is configured to: receive a first signal from the CMS that includes a notification of the updated code for the components; receive a second signal from the ESC that includes instructions for a preliminary installation of the updated code, and thereafter execute the preliminary installation; and receive a third signal from the ESC that includes instructions for a secondary installation of the updated code on the components, and thereafter execute the secondary installation.