The brake, the safety chain and the controller
The fail-safe brake, the series safety chain and its two kinds of failure (Tutorial 3.3), fault finding by bracketing, and how lift controllers went from relays to microcontrollers.
35 min
On this page
Lift safety is not an extra layer on top of the drive. It is built so that any failure, a power cut, a broken wire, a crashed program, stops the car. This lesson follows course section 3.3 and Tutorial 3.3.
The fail-safe brake
Lift codes (EN 81-20/50 in Europe, ASME A17.1 in North America) require a brake that holds by default and needs energy to open: spring-applied, electrically released.
- Power off: engaged. Springs press the friction pads against the disc or drum. The brake torque must hold 125 % of rated load: .
- Power on: released. A coil pulls the armature plate away from the springs and frees the shaft.
The brake opens only after the drive has proved its torque (lesson 4). Brake coils usually run on DC at 110 to 200 V, often with two levels: a high pick voltage snaps the brake open, then a lower hold voltage (by PWM) keeps it open without overheating the coil.
The brake coil is wired through the safety chain. If any safety contact opens, the coil loses power and the springs stop the car mechanically, whatever the drive or the software is doing. When the mains fails in a hospital lift between floors, the springs clamp within milliseconds: a hard but safe stop. A technician can then lift the brake by hand and let the car drift slowly to the nearest floor.
The safety chain
The safety chain is a hardwired series circuit of normally closed contacts: a Boolean AND. Every condition must be true for the lift to run, and any single open contact breaks the circuit. It runs at a raised control voltage (110 V or 48 V) for noise immunity and feeds the main safety relay K1: chain closed, K1 energised, power allowed to the drive and the brake; chain open, K1 drops out and both are cut.
Its main contacts:
- the pit stop switch, a latching button that protects anyone working under the car;
- the overspeed governor, which opens the chain at about 115 % of rated speed and, at a higher overspeed, trips the mechanical safety gear on the rails;
- the final limit switches, beyond the top and bottom floors, against over-travel;
- the door interlocks: the car door contact and the locks of every landing door, all in series.
The chain's reliability is the product of its contacts', : more contacts mean more nuisance trips, but a stop is the safe outcome. A dangerous failure, failing to stop when needed, would need a contact to weld shut or be bypassed.
Tutorial 3.3: two faults
The Tutorial 3.3 chain: 110 V AC, then S1 (pit stop), S2 (overspeed governor), S3 (car door), S4 (landing door locks), then K1.
- Fault A, open circuit. Vibration loosens a wire on S2 while the car travels. Current stops in everything downstream; the K1 coil drops out; its power contacts cut the drive and its auxiliary contact cuts the brake coil. The brake clamps and the car makes an emergency stop. This is a safe failure: the system fails into the stopped state it was designed for.
- Fault B, bypass. A technician left a jumper across the car door contact S3. The contact's state no longer matters: if the door is forced open while the car runs, S3 opens but current flows through the jumper, K1 stays in, and the car keeps moving with its door open. This is a dangerous failure. Fault A stops the car; Fault B silently removes the very protection S3 exists for, and a plain series chain cannot tell a jumper from a healthy closed contact. That is why modern safety relays use dual-channel or pulse-monitored inputs.
- Finding a fault. Test points sit after each contact: TP1 between S1 and S2, TP2 between S2 and S3, and so on. V proves that the supply reaches S2, so S1 is healthy. V proves that it does not come out of S2. The fault is in the one element between them: S2, the overspeed governor contact.
Predict first
A chain has 16 contacts and one is open. Measuring from one end, point by point, can take 16 readings. How many readings does half-splitting need at most?
From relays to microcontrollers
Lift control went through three generations:
| Relay logic (to the late 1970s) | PLC (1980s) | Microcontroller (today) | |
|---|---|---|---|
| Logic | hardwired contacts | software (ladder) | embedded firmware |
| Size | a room | a rack | one board |
| Changing it | rewiring | reprogramming | reprogramming |
| Field wiring | one pair per device | I/O cards | serial bus (CAN, RS-485) |
| Drive interface | contactor steps | analogue reference | digital bus, direct to floor |
| Dispatching | fixed, per car | basic group control | group and destination algorithms |
A modern group controller gives each new hall call to the car with the lowest cost:
The weights change with the traffic pattern: morning up-peak, evening down-peak, lunchtime. In the course's example, a 1920s building's room-sized relay controller is replaced by a board the size of a shoebox. Two spare pairs in the old travelling cable carry a CAN bus, and the new dispatching moves 20 % more passengers with the same motors and car speeds.
FoundationStart here if this is new to you
A safety chain is like a string of old Christmas lights wired one after another: if one bulb breaks, they all go out. That is annoying for lights but perfect for safety: any problem stops the lift. A jumper is like replacing a broken bulb with a piece of wire: the lights come back on, but that bulb no longer tells you anything.
ExplorerGo deeper: derivations and open questions
Reliability against safety. With 20 contacts each 99.9 % reliable over a year, what is the chance of at least one nuisance stop? What does a second, redundant channel do to nuisance stops, and to dangerous failures?
Pulse testing. A safety relay can send short test pulses down the chain and check that each contact interrupts them when it opens. Why does this detect a jumper that a DC chain cannot?