DriveLab
Account

The brake, the safety chain and the controller

The fail-safe brake, the series safety chain and its two kinds of failure (Tutorial 3.3), fault finding by bracketing, and how lift controllers went from relays to microcontrollers.

35 min

Show me

Lift safety is not an extra layer on top of the drive. It is built so that any failure, a power cut, a broken wire, a crashed program, stops the car. This lesson follows course section 3.3 and Tutorial 3.3.

The fail-safe brake

Lift codes (EN 81-20/50 in Europe, ASME A17.1 in North America) require a brake that holds by default and needs energy to open: spring-applied, electrically released.

  • Power off: engaged. Springs press the friction pads against the disc or drum. The brake torque must hold 125 % of rated load: Tbrake≥1.25 Tunbalanced,maxT_\text{brake} \ge 1.25\, T_\text{unbalanced,max}.
  • Power on: released. A coil pulls the armature plate away from the springs and frees the shaft.

The brake opens only after the drive has proved its torque (lesson 4). Brake coils usually run on DC at 110 to 200 V, often with two levels: a high pick voltage snaps the brake open, then a lower hold voltage (by PWM) keeps it open without overheating the coil.

The brake coil is wired through the safety chain. If any safety contact opens, the coil loses power and the springs stop the car mechanically, whatever the drive or the software is doing. When the mains fails in a hospital lift between floors, the springs clamp within milliseconds: a hard but safe stop. A technician can then lift the brake by hand and let the car drift slowly to the nearest floor.

The safety chain

The safety chain is a hardwired series circuit of normally closed contacts: a Boolean AND. Every condition must be true for the lift to run, and any single open contact breaks the circuit. It runs at a raised control voltage (110 V or 48 V) for noise immunity and feeds the main safety relay K1: chain closed, K1 energised, power allowed to the drive and the brake; chain open, K1 drops out and both are cut.

Its main contacts:

  1. the pit stop switch, a latching button that protects anyone working under the car;
  2. the overspeed governor, which opens the chain at about 115 % of rated speed and, at a higher overspeed, trips the mechanical safety gear on the rails;
  3. the final limit switches, beyond the top and bottom floors, against over-travel;
  4. the door interlocks: the car door contact and the locks of every landing door, all in series.

The chain's reliability is the product of its contacts', Rsystem=∏RiR_\text{system} = \prod R_i: more contacts mean more nuisance trips, but a stop is the safe outcome. A dangerous failure, failing to stop when needed, would need a contact to weld shut or be bypassed.

Try it: the safety-chain troubleshooter
110 VS1TP1S2TP2S3TP3S4TP4K1NK1 energised: drive and brake have power

Click a test point in the diagram to measure it.

ContactConditionWiring fault
S1 · pit stop switch
S2 · overspeed governor
S3 · car door contact
S4 · hoistway door locks

Running: every safe condition holds.

Multimeter
–
Safety relay K1
energised

Tutorial 3.3: two faults

The Tutorial 3.3 chain: 110 V AC, then S1 (pit stop), S2 (overspeed governor), S3 (car door), S4 (landing door locks), then K1.

  • Fault A, open circuit. Vibration loosens a wire on S2 while the car travels. Current stops in everything downstream; the K1 coil drops out; its power contacts cut the drive and its auxiliary contact cuts the brake coil. The brake clamps and the car makes an emergency stop. This is a safe failure: the system fails into the stopped state it was designed for.
  • Fault B, bypass. A technician left a jumper across the car door contact S3. The contact's state no longer matters: if the door is forced open while the car runs, S3 opens but current flows through the jumper, K1 stays in, and the car keeps moving with its door open. This is a dangerous failure. Fault A stops the car; Fault B silently removes the very protection S3 exists for, and a plain series chain cannot tell a jumper from a healthy closed contact. That is why modern safety relays use dual-channel or pulse-monitored inputs.
  • Finding a fault. Test points sit after each contact: TP1 between S1 and S2, TP2 between S2 and S3, and so on. VTP1=110V_\text{TP1} = 110 V proves that the supply reaches S2, so S1 is healthy. VTP2=0V_\text{TP2} = 0 V proves that it does not come out of S2. The fault is in the one element between them: S2, the overspeed governor contact.

Predict first

A chain has 16 contacts and one is open. Measuring from one end, point by point, can take 16 readings. How many readings does half-splitting need at most?

From relays to microcontrollers

Lift control went through three generations:

Relay logic (to the late 1970s)PLC (1980s)Microcontroller (today)
Logichardwired contactssoftware (ladder)embedded firmware
Sizea rooma rackone board
Changing itrewiringreprogrammingreprogramming
Field wiringone pair per deviceI/O cardsserial bus (CAN, RS-485)
Drive interfacecontactor stepsanalogue referencedigital bus, direct to floor
Dispatchingfixed, per carbasic group controlgroup and destination algorithms

A modern group controller gives each new hall call to the car with the lowest cost:

Jcar=α Twait+β Ttravel+γ Eenergy(3.7)J_\text{car} = \alpha\, T_\text{wait} + \beta\, T_\text{travel} + \gamma\, E_\text{energy} \tag{3.7}

The weights change with the traffic pattern: morning up-peak, evening down-peak, lunchtime. In the course's example, a 1920s building's room-sized relay controller is replaced by a board the size of a shoebox. Two spare pairs in the old travelling cable carry a CAN bus, and the new dispatching moves 20 % more passengers with the same motors and car speeds.

FoundationStart here if this is new to you

A safety chain is like a string of old Christmas lights wired one after another: if one bulb breaks, they all go out. That is annoying for lights but perfect for safety: any problem stops the lift. A jumper is like replacing a broken bulb with a piece of wire: the lights come back on, but that bulb no longer tells you anything.

ExplorerGo deeper: derivations and open questions

Reliability against safety. With 20 contacts each 99.9 % reliable over a year, what is the chance of at least one nuisance stop? What does a second, redundant channel do to nuisance stops, and to dangerous failures?

Pulse testing. A safety relay can send short test pulses down the chain and check that each contact interrupts them when it opens. Why does this detect a jumper that a DC chain cannot?