Elevator Component Code Updates with Staged Installation Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Software updates for embedded devices in passenger conveyance systems like elevators can cause service disruptions and customer dissatisfaction if not managed efficiently.
Innovation Solution
A system and method involving a component management system (CMS), an elevator system controller (ESC), and a gateway that manage code updates through preliminary and secondary installations, utilizing a controller area network and wide area network to minimize disruptions and ensure cybersecurity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If software updates are performed manually or ad-hoc on elevator components, then updates can be applied quickly, but service disruptions occur and customer satisfaction decreases
Solution Approach 1:
The system performs preliminary actions by first installing updated code on a virtual system or subset of components before full deployment. The gateway receives updated code, installs it on a virtual system first, verifies functionality, and only then proceeds to install on actual components, preventing service disruptions through advance testing.
Solution Approach 2:
The update process is segmented into multiple phases: receiving updated code, installing on virtual system, verifying functionality, installing on subset of components, and full deployment. This segmentation allows controlled rollout and minimizes disruption by updating components incrementally rather than all at once.
2Adaptability or versatility
If multiple updates are performed to satisfy customer requirements, then customer satisfaction may improve, but service disruptions increase
Solution Approach 1:
The system incorporates feedback mechanisms where the gateway verifies updated code functionality on the virtual system before full deployment. Customer satisfaction is achieved through reliable updates while minimizing disruptions by using feedback-driven verification to ensure updates work correctly before widespread implementation.
Solution Approach 2:
Multiple customer-requested updates can be prepared in advance on the virtual system and queued for deployment. The gateway manages multiple update installations sequentially on subsets of components, allowing customer requirements to be met without causing repeated service disruptions through careful coordination.
3Loss of time
If code updates are installed on all components simultaneously, then update completion is fast, but system reliability decreases due to potential widespread failures
Solution Approach 1:
The system segments the component base into subsets and updates them in waves rather than simultaneously. The gateway installs updated code on one subset of components at a time, allowing isolation of potential failures and maintaining system stability while still achieving relatively quick overall deployment through parallel processing of subsets.
Solution Approach 2:
The gateway performs partial updates by installing code on subsets of components rather than all components at once. This partial action approach balances deployment speed with reliability by updating enough components to make progress while limiting the risk of widespread failures.
4Ease of operation
If manual update processes are used, then flexibility in handling different scenarios is maintained, but automation level and efficiency decrease
Solution Approach 1:
The gateway performs self-service by automatically receiving updated code, installing it on virtual systems, verifying functionality, and deploying to components without requiring manual intervention for each step. This maintains operational flexibility while achieving high automation, as the system autonomously handles the update process based on predefined protocols.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
An elevator system for installing updated code on elevator components in a building, the system having: a component management system (CMS); an elevator system controller (ESC) in the building, operationally coupled to the components; a gateway that communicates with the ESC and the components over a first network and with the CMS over a second network, wherein the gateway is configured to: receive a first signal from the CMS that includes a notification of the updated code for the components; receive a second signal from the ESC that includes instructions for a preliminary installation of the updated code, and thereafter execute the preliminary installation; and receive a third signal from the ESC that includes instructions for a secondary installation of the updated code on the components, and thereafter execute the secondary installation.