METHOD AND SYSTEM FOR PROTECTING EXECUTION AND / OR PROCESSING DATA OF A MACHINE TOOL
Patent Information
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2019-08-27
- Publication Date
- 2026-04-09
AI Technical Summary
Existing systems for transferring machining data to numerically controlled machine tools lack robust security measures and efficient encryption methods, leading to potential unauthorized access and manipulation of machining data.
A method and system that utilize asymmetric encryption with public keys to securely transfer machining data, specifying encryption parameters, authentication requirements, and execution specifications to ensure secure and controlled machining operations on machine tools.
Ensures secure, efficient, and controlled transfer of machining data, protecting know-how while allowing secure execution on external machine tools, with end-to-end encryption and data integrity verification.
Description
[0001] The present invention relates to a method, a system and a computer program product for providing machining data on a numerically controlled machine tool. background
[0002] In the prior art, numerically controlled machine tools, e.g. milling machines, lathes, grinding machines, milling / turning machines and machining centers, are known which are designed to machine workpieces clamped to clamping devices of the machine tool with one or more tools.
[0003] This is usually done, at least partially, using machining programs, so-called NC programs (NC for Numerical Control, or CNC for Computerized Numerical Control), which are executed on the machine tool's control unit. The NC programs typically specify machining commands, machining steps, and / or machining paths, which are processed by the control unit. This allows the machine control to control actuators of the machine tool, such as axis drives (e.g., spindle drives and feed axis drives) or other drive systems (e.g., electrical, hydraulic, and / or pneumatic systems), based on the executed machining program.
[0004] Controllable components, units, or systems of a machine tool can include one or more work spindles and one or, more commonly, several feed axes, such as linear feed axes, rotary axes, or swivel axes, for controlling the relative movement of the tool to the workpiece. Other controllable components, units, or systems of a machine tool can include: a workpiece pallet changer, a chip conveying system, a tool changing system with one or more tool changers, possibly in combination with one or more tool magazines, a coolant supply or circulation system, automatically opening and closing doors or flaps, etc.
[0005] Nowadays, control systems for machine tools include, in addition to the well-known NC control integrated into the machine tool (e.g. CNC machine controls from Siemens, Heidenhain, Fanuc, and other machine control providers) and connected PLC controls, further extended control and operating functions, which are typically implemented on the machine tool's control panel.
[0006] Such control panels for numerically controlled machine tools typically include a graphical user interface with one or more screens, possibly even a touchscreen with touch control or touch operating functions, and input units such as switches, control wheels and buttons, or possibly a keyboard or other input devices known from computer controls, through which an operator can access the control and operating functions of the machine tool.
[0007] WO 2015 / 014390 A1 concerns a control and operating system for a numerically controlled machine tool, in which the machine control is equipped with such extended functionality. On the one hand, the control and operating system comprises the machine control functions of the integrated NC control, and on the other hand, the control and operating system comprises a higher-level data processing system that executes the graphical user interface and makes it available to the operator at the control panel, and that executes or makes executable a number of control and operating programs that extend the setup, operation, and control functions of the machine tool.
[0008] Furthermore, the higher-level data processing system on the machine tool provides the functionality to read, display, and further process sensor data from the machine tool and to transfer it to externally connected data processing facilities, such as computer and / or server facilities, e.g., via a connected data network.
[0009] Furthermore, it is also possible to transmit data such as setup data, tool data, workpiece data, machining data, machining programs or installation data for further installable control and / or operating programs from such externally connected data processing facilities, such as computer and / or server facilities, to the control unit of the machine tool.
[0010] This allows for predefined machining data for one or more workpieces to be specified by a client and transmitted directly, via a network, to the control unit of a contractor's machine tool, enabling the machining of the workpiece(s) directly on the machine tool. For this purpose, data from ERP (Enterprise Resource Planning) systems and / or data processing from CAD / CAM systems (CAD for Computer-Aided Design, CAM for Computer-Aided Manufacturing) can be provided and read into the control data processing unit, either on an upstream computer or directly at the machine tool.
[0011] The data can be loaded or read into the machine tool for processing or execution by the machine tool operator. This has the advantage of enabling fast and efficient data transfer to the machine tool, allowing for the direct and rapid execution of the specified machining operations. The execution is visible to the operator via the graphical user interface; in particular, the NC code to be executed and its execution are visible, and the operator has the ability to intervene in the machining process at the machine control.
[0012] EP 3 232 604 A1 discloses a method in which an encryption key pair is generated for an industrial controller, wherein the encryption key pair comprises a public key and a private key. The private key is stored in a secure storage system of the industrial controller. The contents of the control program are then encrypted with the public key to generate encrypted control content. The encrypted control content is then provided to the industrial controller, and the industrial controller is configured to decrypt the encrypted control content using the private key and execute the control program content.
[0013] German patent DE 101 25 383 A1 demonstrates that asymmetric keys are used to protect control programs against unauthorized analysis and use during transmission over public networks. After the control program is created in the supplier's engineering system, it is encrypted in a post-processor and exported to a public web server. The customer uploads the encrypted program to their persistent data storage, imports it into their engineering system, and can edit it there to configure the control system. Only after editing are the encrypted program components decrypted in a pre-processor and forwarded to the compiler.
[0014] DE 11 2012 006329 T5 discloses a programmable logic controller comprising a device which stores data on it, an authentication information storage unit which stores authentication information on it, an authentication function unit which performs user authentication based on the authentication information, and an encryption filter which has a multitude of encryption patterns, one of which is preset by a user for encryption processing.When an external device requests that data be written to the device, the authentication functional unit performs user authentication. If user authentication is successful, the encryption filter performs encryption processing on the data to be written to the device using the encryption pattern pre-set by the user, so that the data is written to the device. If user authentication fails, the encryption filter performs encryption processing on the data to be written to the device using one of the encryption patterns that differs from the encryption pattern pre-set by the user, so that the data is written to the device.
[0015] Based on the prior art described above, it is an object of the present invention to propose a method and a system for providing machining data to a numerically controlled machine tool, which further develops and improves the possibilities and functionalities of transferring machining data from external data processing systems to a machine tool control and the execution of the machining data on the machine tool. Summary
[0016] To solve the aforementioned problems, a method for providing machining data to a numerically controlled machine tool, a system, and a computer program product comprising the features of the respective independent claim are presented. Dependent claims relate to advantageous preferred embodiments. The following explains aspects and embodiments that are helpful for understanding the invention.
[0017] According to one aspect, a method for providing machining data to a numerically controlled machine tool can be provided, comprising: providing machining data to a data processing device, wherein the machining data preferably comprises numerical control data, in particular preferably one or more NC programs, on the basis of which machining of a workpiece on the numerically controlled machine tool can be carried out; specifying execution specifications to the data processing device, which preferably specify specifications for machining the workpiece on the numerically controlled machine tool; generating execution data based on the specified execution specifications, wherein the execution data preferably comprises the machining data and / or preferably specifies the execution specifications;and / or the provision and / or transmission of the generated execution data to a control unit of the numerically controlled machine tool.
[0018] Preferably, the method further comprises specifying encryption parameters at the data processing device, the parameters for encrypting the machining data and / or the execution data, and encrypting the machining data and / or the execution data based on the encryption parameters. The execution data can be encrypted and / or provided and / or transmitted to the control device(s) of the numerically controlled machine tool together with encrypted machining data.
[0019] The encryption of the processing data and / or the execution data is preferably carried out using a public key assigned to the numerically controlled machine tool in an asymmetric encryption method.
[0020] The encryption specifications preferably indicate whether the processing data and / or the execution data are to be encrypted, or which sections of the processing data and / or the execution data are to be encrypted.
[0021] The encryption specifications preferably specify an encryption strength to be used.
[0022] The encryption specifications and / or the execution specifications preferably specify a permitted period within which the encrypted processing data and / or execution data can be decrypted.
[0023] The encryption specifications and / or the execution specifications preferably specify a maximum number of allowed decryptions of the encrypted processing data and / or execution data and / or a maximum number of executions of the processing data.
[0024] The encryption specifications and / or the execution specifications preferably indicate whether the encrypted processing data and / or execution data can only be decrypted directly when applied in an NC code execution system of the control unit of the numerically controlled machine tool.
[0025] The encryption specifications and / or the execution specifications preferably indicate whether the processing data and / or execution data can be viewed and / or edited on a graphical user interface of the control unit of the numerically controlled machine tool.
[0026] The encryption specifications and / or the execution specifications preferably indicate whether the control unit of the numerically controlled machine tool sends a message to the data processing unit before and / or after machining the workpiece based on the machining data.
[0027] The encryption specifications and / or the execution specifications preferably indicate whether the control unit of the numerically controlled machine tool sends machining report data to the data processing unit after machining the workpiece based on the machining data.
[0028] The encryption specifications and / or the execution specifications preferably indicate whether the processing report data should be encrypted before being transferred to the data processing facility.
[0029] The encryption specifications and / or the execution specifications preferably indicate whether the control unit of the numerically controlled machine tool sends an authorization request to the data processing unit before decrypting the encrypted machining data and / or execution data, in order to release the decryption by the data processing unit after successful authorization verification.
[0030] Preferably, the method further comprises obtaining a public key or other key data associated with the machine tool from an external server, wherein the machining data and / or execution data are preferably encrypted using the public key or key data obtained from the server.
[0031] Preferably, the method further includes specifying authentication requirements at the data processing device, which specify the requirements for the authentication of the numerical machine tool and / or an operator of the machine tool, wherein the execution data preferably further specifies the authentication requirements.
[0032] The design specifications preferably specify a permissible machine tool type or a permissible machine tool.
[0033] The execution specifications preferably specify the required machine equipment of the machine tool, one or more required tools, and / or workpiece data.
[0034] According to another aspect, a system for providing machining data to a numerically controlled machine tool is proposed, comprising a data processing device configured to perform a procedure according to one or more of the above aspects.
[0035] According to another aspect, a computer program product is proposed, comprising instructions which, when the program is executed by a computer, cause it to perform the procedure according to one or more of the above aspects.
[0036] According to a further aspect, a method for providing machining data to a numerically controlled machine tool is proposed, comprising: receiving execution data generated according to a method according to one or more of the above aspects at the control device of the numerically controlled machine tool, processing the execution data on the basis of the execution specifications included in the execution data, optionally with decoding the execution data and / or the machining data included in the execution data, and / or executing the machining data, in particular including controlling the machining of the workpiece on the numerically controlled machine tool on the basis of the machining data.
[0037] According to another aspect, a control device for a numerically controlled machine tool is proposed, wherein the control device is configured to perform the above method, in combination with one or more of the above aspects.
[0038] According to another aspect, a computer program product is proposed, comprising instructions which, when the program is executed by a control device of a numerically controlled machine tool, cause it to execute the aforementioned method, in combination with one or more of the aforementioned aspects.
[0039] Further aspects and their advantages, as well as advantages and more specific implementation possibilities of the aspects and features described above, are described in the following descriptions and explanations of the attached figures, which are in no way to be understood as restrictive. Brief description of the characters
[0040] Fig. 1 Figure 1 shows an exemplary schematic representation of a data processing device for providing machining data to a numerically controlled machine tool according to an embodiment of the invention. Fig. 2 Figure 1 shows an exemplary schematic representation of a system for providing machining data to a numerically controlled machine tool according to an embodiment of the invention. Fig. 3 Figure 1 shows an exemplary schematic representation of a flowchart of a method for providing machining data on a numerically controlled machine tool according to an embodiment of the invention. Fig. 4 Figure 1 shows an exemplary schematic representation of a flowchart of a method for processing provided machining data on a numerically controlled machine tool according to an embodiment of the invention. Fig. 5Figure 1 shows an exemplary schematic representation of a flowchart of a method for providing encryption certificates according to an embodiment of the invention. Detailed description of the figures and preferred embodiments
[0041] Examples and embodiments of the present invention are described in detail below with reference to the accompanying figures. Identical or similar elements in the figures may be designated with the same reference numerals, but sometimes they may be designated with different reference numerals.
[0042] It should be emphasized that the present invention is in no way limited or restricted to the embodiments and features described below, but also includes modifications of the embodiments, in particular those which are encompassed by modifications of the features of the described examples or by combining one or more of the features of the described examples within the scope of protection of the independent claims.
[0043] Fig. 1 Figure 1 shows an exemplary schematic representation of a data processing device 300 for providing machining data to a numerically controlled machine tool 100 according to an embodiment of the invention.
[0044] The data processing device 300 (e.g., a data processing device arranged in an operator panel of the machine tool or a data processing device coupled to the operator panel of the machine tool) is connected to a controller 200 of the machine tool 100 and optionally also to an external data processing device 500 and, via a communication network 600, to a server 400, which, for example, is connected via another communication network 700 (e.g., the Internet) to another server 400 and another external data processing device 500. The data processing device 300, together with the controller 200, forms the control unit of the machine tool 100.
[0045] The machine tool 100 includes, for example, a plurality of actuators 110 of the machine tool 100 that can be controlled by the control 200 and a plurality of sensors 120 for outputting sensor signals relating to a machine state of the machine tool 100 to the control 200.
[0046] The actuators 110 can, for example, include drives for controllable linear and rotary axes (swivel and / or rotary axes) for controlled relative movement between tool and workpiece, as well as drives for tool-carrying work spindles (e.g., on milling machines) or workpiece-carrying work spindles (e.g., on lathes). Furthermore, the actuators 110 can be electronically, hydraulically, and / or pneumatically controlled valves, pumps, or other supply devices for internal or external coolant or compressed air. Conveyor systems, pallet changers, workpiece changers, tool magazines, and other machine tool accessories can also be controlled via drives or circuits or corresponding actuators.
[0047] The sensors 120 can be, for example, sensors that can be assigned to the respective assemblies or components of the machine tool, e.g., the axes, the drives, axis bearings, the spindles, spindle bearings, a tool magazine, a tool changer, a pallet or workpiece changer, an internal or external coolant supply device, a chip conveying device, and / or a hydraulic and / or pneumatic control.
[0048] The control system 200 comprises, for example, a control device 210 with an NC controller 211 and a programmable logic controller 212 (also called PLC). The control system 200 is connected to the machine tool 100, in particular to be able to output control signals to the actuators 110 of the machine tool and to read sensor signals from the sensors 120 of the machine tool 100.
[0049] The data processing device 300 comprises a control-side data interface 310 (control interface) for data and signal connection with the controller 200 and an external data interface 340 (universal interface) for data connection with the external data processing device 500 or the communication network 600 for network connection with the server 400.
[0050] Furthermore, the data processing device 300 includes a CPU-comprising data processing unit 320 for processing data and for executing applications and editing programs, and a data storage device 330 for storing program or application data, editing data, configuration data and sensor data (e.g. memory, RAM, hard disk and / or a flash memory).
[0051] Furthermore, the data processing device 300 includes, for example, a human-machine interface 350 (also called HMI for "Human-Machine Interface"), which enables an operator of the machine tool 100 to control, monitor, and / or operate the machine tool 100. The human-machine interface 350 includes, for example, a graphical user interface (GUI) that can be displayed on a monitor or touchscreen.
[0052] The data processing device 300 can be configured, for example, to read, process and execute NC data of a machining program, in particular by executing the NC program and carrying out commands specified in the NC program, transmitting commands specified in the NC program to the NC control 211 and / or the PLC control 212 for execution, or transmitting corresponding control commands or signals to the NC control 211 and / or the PLC control 212 based on the commands specified in the NC program.
[0053] Fig. 2 Figure 1 shows an exemplary schematic representation of a system for providing machining data to a numerically controlled machine tool according to an embodiment of the invention.
[0054] The system comprises, for example, three areas A, B, and C. In area A, the system includes, for example, a server 400, which is connected via an, for example, internal communication network 600 of area A to a plurality of data processing units 500 of area A. One of the data processing units 500 of area A is, for example, equipped with a machining data application 501, which, when executed on the data processing unit 500, is configured to process machining data for provision to a machine tool 100.
[0055] Area A can, for example, be assigned to a client who wants to outsource the machining of workpieces on machine tools to external contractors.
[0056] The server 400 of area A is, for example, still connected to an external communication network 700, particularly preferably for transmitting processing orders to contractors, e.g. via the Internet or a comparable external communication network with a limited number of participants.
[0057] In area B, the system includes, for example, another server 400, which is also connected to the external communication network 700. The server 400 in area B stores, for example, encryption key data K1, K2, and K3 (e.g., keys for use in asymmetric encryption methods, such as public keys and / or private keys) and, for example, machine data M2 and M3, which specify machine information for a correspondingly associated machine tool, such as properties, configuration, equipment, type, and / or functionalities of the associated machine tool.
[0058] Area B, containing server 400 of area 400, can be assigned to a machine manufacturer or a central service provider. Server 400 of area 400 can, for example, centrally provide data to system participants for supplying machining data to machine tools.
[0059] For example, encryption key data K2 can be assigned to machine data M2, and encryption key data K3 can be assigned to machine data M3. Encryption key data K1 can be assigned to server 400 of area A.
[0060] In area C, the system includes, for example, another server 400, which is also connected, for example, to the external communication network 700. The server 400 of area C is also, for example, connected to an internal communication network 600 of area C, to which, for example, a data processing unit 500 of area C is connected.
[0061] Furthermore, for example, machine tools 100 are connected to the internal communication network 600 of area C via their respective control systems 200 and the associated data processing facilities 300.
[0062] Area C can, for example, be assigned to a contractor who wants to accept and execute orders from the client of area A for the processing of workpieces on machine tools.
[0063] For example, the data processing device 500 of section C includes a machine tool simulation application 502, which is configured to simulate the machining of the workpiece on the machine tool by executing it on the data processing device 500 and based on machine data relating to a machine tool and machining data relating to the machining of a workpiece on the machine tool, in particular to perform a collision check during the machining process simulated on the machine tool. A corresponding machine tool simulation application 502 is known, for example, from DE 10 2006 043 390 A1.
[0064] Fig. 3 Figure 1 shows an exemplary schematic representation of a flowchart of a method for providing machining data on a numerically controlled machine tool according to an embodiment of the invention.
[0065] The procedure can preferably be implemented on a data processing facility 500 of area A in Fig. 2 be performed.
[0066] In step S301, machining data is provided that specifies or dictates the machining of one or more workpieces on a machine tool.
[0067] For example, the machining data can include NC data, which may comprise one or more NC programs. The NC program(s) preferably specify machining commands, machining steps, and / or machining paths, which are processed by the control unit in such a way that, based on the executed machining program, the machine tool's control unit can control actuators of the machine tool, such as axis drives (e.g., spindle drives and feed axis drives) or other drive systems of the machine tool.
[0068] For example, the machining data at the data processing unit 500 can be automatically generated using a CAD / CAM application, e.g. based on 2D and / or 3D design data relating to a finished part, or also by manual programming or manual adjustment of an automatically generated machining program.
[0069] The processing data can still be generated or adapted based on data from an ERP system.
[0070] In step S302, encryption specifications are defined at the data processing unit 500 of area A.
[0071] The encryption settings can specify whether the processing data is to be encrypted in whole or in part, and whether the execution data to be transmitted to the machine tool is to be encrypted in whole or in part. The operator of the 500 data processing unit can, for example, specify whether and which data or data components are to be encrypted. Furthermore, the encryption settings can specify a desired or required encryption strength.
[0072] Furthermore, the encryption specifications can also specify the encryption method to be used, e.g., whether symmetric or asymmetric encryption is to be applied, or which specific encryption method is to be used. For example, for asymmetric encryption methods, it is possible to specify a public-key / private-key encryption method, in which the data to be sent is encrypted with a publicly available public key of the recipient, so that the recipient can decrypt the received encrypted data with a private key available only to the recipient. It is also possible to use an encryption method based on a Diffie-Hellman key exchange.
[0073] The encryption specifications can further specify whether the NC code of the machining program is decryptable on the graphical user interface of the control panel, so that the NC program is partially or fully visible to the operator of the machine tool on the graphical user interface, or whether it is to be kept hidden, so that the decryption of the NC code is only carried out by the NC code execution system directly when the machining program is executed, but the NC program is not visible to the operator of the machine tool on the graphical user interface.
[0074] The encryption specifications can also specify whether a decrypted NC code or decrypted machining data at the data processing unit 300 of the machine tool should only be made available to the operator of the machine tool as a "read-only" display, so that the NC code or the machining data cannot be edited or adapted at the control panel of the machine tool.
[0075] The encryption settings can further specify the period within which the processing and / or execution data can be decrypted. This can restrict the possibility of executing the processing to a permitted period or production period, during which manufacturing by processing the workpiece is allowed.
[0076] In addition to the NC program or NC code of the machining data, the following data can be encrypted as needed: images and / or 3D models, e.g., with regard to a specified clamping situation of tool and / or workpiece, raw part information (e.g., images, 3D models, geometry information, material information, and / or size information), data on the tools used or tool data, data on specified zero points, CAD data of the finished part to be manufactured (e.g., images and / or 3D models), and / or other graphics, sketches, 2D drawings, 3D models, texts, or documents.
[0077] In an optional step S303, authentication specifications are defined at the data processing unit 500 of area A.
[0078] The authentication specifications can indicate a designated recipient and whether and how the designated recipient is to be authenticated. The authentication data specifying the designated recipient can include recipient-identifying ID data, which, for example, identifies a contractor, a machine tool, or a group of machine tools (e.g., among those available at the contractor) (e.g., by a type specification and / or machine tool number).
[0079] The operator of the 500 data processing unit can thus specify whether and which data should only be extractable by authenticated users, and who or what should be considered an authenticated user (authorized recipient). The operator can specify a client / user as the authorized recipient, thereby stipulating that only machine tools belonging to the authenticated client / user are permitted to process the data. Furthermore, the operator can specify or define particular machine tools or groups of machine tools as authorized recipients, for example, depending on the type and configuration of the machine tool.
[0080] The authentication specifications may further stipulate whether the recipient's authorization must be verified by authentication for the first time or again before decrypting the processing data and / or before processing begins, or even whether authentication data must be sent to server 400 of area A before decrypting the processing data and / or before processing begins, so that the authentication check is or can be carried out on server 400 of area A before decryption and / or processing begins, and server 400 of area A sends the final release before decryption of the processing data and / or processing begins.
[0081] In step S304, execution specifications are defined at the data processing unit 500 of area A.
[0082] The execution specifications can indicate one or more machine tools or machine types that are intended to or capable of machining the workpiece. The execution data can further specify which equipment or features are required for a particular machine type to perform the machining of the workpiece. The execution data can also specify which tool(s) are required to perform the machining of the workpiece.
[0083] The execution specifications may also specify a permitted production period, in which the production of a finished part by machining a workpiece based on the machining data is permitted, and / or a permitted production number, i.e., how many finished parts can be produced or how many workpieces can be machined based on the machining data.
[0084] The execution specifications may further stipulate whether the decryption of the processing data, or the start and / or end of the processing of the workpiece, is to be reported to the server 400 of area A, so that the server 400 of area A can monitor or supervise the processing operations on external machine tools and track the progress.
[0085] In step S305, the execution data is generated at data processing unit 500 of area A based on the predefined execution specifications and the provided processing data, as well as on the predefined encryption specifications and, optionally, the optionally specified authentication specifications. The generated execution data includes the processing data and further information that specifies the predefined execution specifications, predefined encryption specifications, and, optionally, any predefined authentication specifications.
[0086] Since encryption of the execution data is planned, depending on the entered encryption specifications, the encryption of the generated execution data is carried out in step S306 based on the entered encryption specifications.
[0087] An encryption key assigned to the designated recipient can be used here. For example, a public key assigned to the designated recipient can be used to encrypt the generated execution data.
[0088] If the encryption key or public key assigned to the designated recipient is not available, it can be obtained from server 400 (certificate server) of area B and / or from server 400 of area C of the designated recipient.
[0089] For example, it is possible that a designated recipient, a machine tool belonging to the designated recipient, a group of machine tools belonging to the designated recipient, one or more data processing units 300 belonging to the designated recipient, and / or the server 400 of area C belonging to the designated recipient is assigned a respective encryption key or public key. This can also be obtained using the authentication data underlying the authentication specifications.
[0090] If the encryption key or public key assigned to the designated recipient is available, or after obtaining the encryption key or public key, this encryption key or public key is used in step S306 to encrypt the execution data and / or the processing data.
[0091] In step S307, the relevant data, i.e., the generated execution data with processing data, the encrypted execution data comprising the processing data and / or the execution data with encrypted processing data, are provided and / or transferred via the 700 network to area C (e.g. via email or TCP / IP).
[0092] For example, the execution data generated (and possibly encrypted) on data processing unit 500 of area A can be transferred to server 400 of area A. The execution data can then be made available for download on server 400 of area A by one of the other servers 400 (pull procedure), so that the execution data can be downloaded directly or indirectly from server 400 of area A via server 400 of area B. Alternatively, the execution data can also be transferred to server 400 of area C (or even server 400 of area B) using a push procedure.
[0093] The execution data can continue to be made available on the internal network 600 of area C, for example, to be retrieved by data processing unit 500 or data processing units 300 of area C. Alternatively, server 400 of area C can send the execution data directly to the designated machine tool 100 or to the upstream data processing unit 300 of area C and / or to data processing unit 500 of area C (push method).
[0094] Alternatively, the execution data can be transmitted via email to the target data processing device or machine, or to the email account of an operator or user of the target machine tool or the contractor. Furthermore, the execution data can be transferred manually, e.g., via the exchange of USB storage media.
[0095] Fig. 4Figure 1 shows an exemplary schematic representation of a flowchart of a method for processing provided machining data on a numerically controlled machine tool according to an embodiment of the invention.
[0096] In step S401, the execution data is transferred to the data processing unit 300 of the target machine tool 100 (according to Fig. 1 ) provided or received.
[0097] Step S402 checks whether a private key or encryption key is present on the storage medium 330 (at least if it is determined that the execution data is partially or fully encrypted). This step can be omitted if the data is not encrypted, i.e., if the execution data is received unencrypted. If no private key or encryption key is present and the execution data is received encrypted, the execution data cannot be decrypted, and the process is aborted / terminated.
[0098] If a private key or encryption key is present on the storage medium 330 (step S402 results in YES), then the execution data is decrypted in step S403.
[0099] After decrypting the execution data, the machining data contained within it can be extracted. The machining data may already be unencrypted after decryption of the execution data, or it may still be encrypted (e.g., if the machining data or the contained NC code may only be decrypted during execution on the NC code execution system).
[0100] Furthermore, after decrypting the execution data, the authentication conditions or authentication specifications optionally contained in the execution data can be extracted. Based on the extracted authentication conditions, it can be determined in step S404 whether authentication of the machine tool and / or the operator at the machine tool is required.
[0101] If step S404 determines that authentication of the machine tool and / or the operator at the machine tool is required (step S404 results in YES), step S405 will be used to authenticate the receiver (i.e., the machine tool and / or the operator at the machine tool).
[0102] Step S406 determines whether authentication was successful according to the authentication specifications of the execution data. If authentication was unsuccessful (step S406 returns NO), processing is rejected and the procedure is aborted / terminated.
[0103] In step S407, for example, after successful authentication or if no authentication is necessary (step S404 results in NO), step S407 is executed, in which the execution specifications of the execution data are checked.
[0104] The specifications can be used to verify whether the machine tool, or the machine tool type, and / or the machine tool's equipment or features meet the specifications. Furthermore, it can be verified whether the raw parts and / or tools available for the machine tool meet the specifications.
[0105] Furthermore, it can be checked whether the current time is within the permitted production period in which the production of a finished part by processing a workpiece based on the processing data is permitted, and / or whether the permitted production number has not yet been exceeded if the processing data has already been used to process other workpieces, which can be recorded by a counter at the data storage device 300.
[0106] Step S408 determines whether the execution specifications of the execution data are met. If the execution specifications of the execution data are not met (step S408 returns NO), then processing is rejected and the procedure is aborted / terminated.
[0107] If the execution specifications of the execution data are met (step S408 results in YES), the optional step S410 checks whether the encryption specifications and / or the execution specifications of the execution data indicate that the machining data is to be executed covertly, i.e., whether the operator of the machine tool is allowed to view the machining program or the NC code on the graphical user interface or not, and also, if applicable, whether the operator of the machine tool is allowed to edit or modify the machining program or the NC code on the graphical user interface or not.
[0108] If step S410 is YES, indicating that the operator of the machine tool is not permitted to view, edit, or modify the machining program or NC code on the graphical user interface, the machining data will be completely hidden from the operator (step S411) or, if the NC code may be viewed but not edited or modified, displayed only as a read-only version.
[0109] In step S412, the processing data is executed at the data processing unit 300, or the machining of the workpiece at the machine tool 100 is controlled via the execution at the data processing unit 300 via the control unit 200.
[0110] Alternatively, the procedure can be carried out according to Fig. 4first be carried out on the machine tool simulation application 502 of the data processing unit 500 of area C, whereby any permitted production number or permitted production period may be disregarded.
[0111] In this case, step S412 is simulated on the machine tool simulation application 502. Since the contractor cannot potentially view the NC code, it is advantageous for the contractor to first test the machining data specified therein, which may be hidden or encrypted, on a corresponding virtual machine tool in a machining simulation before executing the execution data on a real machine tool. This allows the contractor to test the machining for collisions and any other machining problems.
[0112] Such a simulation of machining using a machine tool simulation application 502 may be limited in that the machining data can only be simulated set by set on the machine tool simulation application 502.
[0113] Preferably, the contractor's or the contractor's and client's machine tools must first be registered on server 400 of area B. Encryption data keys can also be distributed and managed during this process.
[0114] Fig. 5 Figure 1 shows an exemplary schematic representation of a flowchart of a method for providing encryption certificates according to an embodiment of the invention.
[0115] In step S501, a registration request is received on server 400 of area B. Server 400 then generates, as an example, a pair of public keys and a corresponding private key in step S502 and stores the generated key pair in step S503 for managing the public and private keys.
[0116] In step S504, installation data is transmitted to the applicant (e.g., a data processing facility 300 or 500 from one of areas A or C), the installation data being configured to set up an application that performs a procedure according to Fig. 3 and / or after Fig. 4 can execute.
[0117] In step S505, the generated encryption keys or private and public keys are transmitted to the applicant (e.g. a data processing facility 300 or 500 of one of the areas A or C).
[0118] Furthermore, in step S506, the public keys of the registered users are provided so that others can obtain the public keys if necessary in order to encrypt execution data for the application with the owner of the respective public key.
[0119] Storing the public and private keys on server 400 has the advantage that even if participants lose their private keys, any encrypted data can be decrypted, since the keys can be managed centrally by an independent entity.
[0120] Furthermore, it is also possible for participants to generate their own public and private keys and exchange their public keys directly with each other. It is also possible to use a Diffie-Hellman encryption method, in which participants directly perform a Diffie-Hellman key exchange. Additionally, participants or clients can maintain their own electronic address book containing address data, which stores target machines, contractors, and / or assigned IP addresses.
[0121] In further embodiments, the execution data can be additionally provided with verification data before transmission, enabling a check of data integrity. In such embodiments, the data integrity of the available data can be verified before and / or after decryption, and / or before and / or after execution of the execution or processing data, using the verification data. Such verification data can, for example, include one or more hash values that can be calculated from the encrypted and / or unencrypted execution data and / or from the encrypted and / or unencrypted processing data.
[0122] In further embodiments, a processing report can be generated after processing is completed, based on the processing data, and made available to or transmitted to the client's server 400 in area A. Such processing reports can also optionally be encrypted, e.g., with the client's public key (who possesses the corresponding private key for decryption). The client's public key can be obtained from server 400 in area B in the same way as the public key of the machine tool or the contractor.
[0123] In addition to processing information regarding the start and end of processing, such processing reports can also indicate whether any control errors occurred during processing. Furthermore, processing reports can also include information about sensor values recorded during the processing period by the machine tool's sensors (120) or about position measurement results (e.g., from touch probes). This allows clients to conduct an external quality inspection.
[0124] In further embodiments, the processing data on the contractor's side can not only be encrypted, hidden and / or available as a read-only version, but copy protection mechanisms can also be provided so that the processing data cannot be copied.
[0125] In further embodiments, the execution data can be temporarily stored and / or long-term stored on server 400 of area B.
[0126] The present invention advantageously enables the know-how held by the producer of the machining data or the client to be protected, while still allowing machining data to be transmitted efficiently and securely to external contractors for machining on external machine tools at the contractors' premises. Simultaneously, it can be ensured that the machining and execution specifications are adhered to and that the data is protected. The data transmission to the machine tool can advantageously be end-to-end encrypted and protected, thereby ensuring data integrity.
[0127] Examples and embodiments of the present invention, as well as their advantages, have been described in detail above with reference to the accompanying figures. It should be emphasized again that the present invention is in no way limited to the embodiments and their features described above, but also includes modifications of these embodiments, in particular those resulting from modifications of the features of the described examples or from combinations of one or more of the features of the described examples within the scope of the independent claims.
Claims
1. Method for providing machining data to a numerically controlled machine tool, comprising: - providing (S301) machining data to a data processing device, wherein the machining data comprise numerical control data, in particular one or more NC programs, on the basis of which machining of a workpiece is implementable on the numerically controlled machine tool, - specifying encryption specifications (S302) at the data processing device, which specify specifications for the encryption of the machining data and of execution data, wherein the encryption specifications specify a maximum number of permitted decryptions of the encrypted execution data and a maximum number of executions of the machining data, - specifying (S304) execution specifications at the data processing device, which specify specifications for the machining of the workpiece on the numerically controlled machine tool, wherein the execution specifications specify a permitted machine tool type or a permitted machine tool, and / or wherein the execution specifications specify required machine equipment of the machine tool, one or more required tools, and workpiece data, - generating execution data (S305) on the basis of the specified execution specifications, the provided machining data and the specified encryption specifications, wherein the generated execution data comprise the machining data and further specifications which comprise the specified execution data and the specified encryption specifications, - encrypting (S306) the generated execution data on the basis of the encryption specifications, and - providing or transmitting the encrypted execution data (S307) to a / a control device of the numerically controlled machine tool.
2. Method according to Claim 1, characterized in that the encryption of the execution data is carried out by means of a public key assigned to the numerically controlled machine tool in an asymmetric encryption method.
3. Method according to Claim 1 or 2, characterized in that the encryption specifications specify which sections of the machining data are to be encrypted.
4. Method according to one of the preceding claims, characterized in that the encryption specifications specify a permitted time period in which the encrypted machining data and / or execution data is decryptable.
5. Method according to one of the preceding claims, characterized in that the encryption specifications specify whether the encrypted execution data is decryptable only directly when used in an NC code execution system of the control device of the numerically controlled machine tool.
6. Method according to one of the preceding claims, characterized in that the encryption specifications specify whether the machining data is viewable and / or editable on a graphical user interface of the control device of the numerically controlled machine tool.
7. Method according to one of the preceding claims, characterized in that the encryption specifications and / or the execution specifications specify whether the control device of the numerically controlled machine tool sends a message to the data processing device before and / or after machining of the workpiece on the basis of the machining data.
8. Method according to one of the preceding claims, characterized in that the encryption specifications and / or the execution specifications specify whether the control device of the numerically controlled machine tool sends machining report data to the data processing device after machining of the workpiece on the basis of the machining data.
9. Method according to one of the preceding claims, characterized in that the encryption specifications and / or the execution specifications specify whether the control device of the numerically controlled machine tool sends an authorization request to the data processing device before decryption of the encrypted execution data, in order to enable the decryption by the data processing device after an authorization check has been carried out.
10. Method according to one of the preceding claims, characterized by: - obtaining a public key assigned to the machine tool or other key data assigned to the machine tool from an external server (400), wherein the execution data are encrypted on the basis of the public key obtained from the server or the key data obtained from the server.
11. Method according to one of the preceding claims, characterized by: - specifying authentication specifications (S303) at the data processing device, which specify specifications for the authentication of the numerical machine tool and / or of an operator of the machine tool, and wherein the execution data furthermore comprise specifications which specify the authentication specifications.
12. Method according to one of the preceding claims, furthermore comprising: - receiving the encrypted execution data at the control device (200) of the numerically controlled machine tool (100), - decrypting the execution data on the basis of the execution specifications comprised in the execution data, and - executing the machining data, in particular comprising controlling the machining of the workpiece on the numerically controlled machine tool on the basis of the machining data.
13. System for providing machining data on a numerically controlled machine tool (100), the system comprising a controller (200) of the machine tool (100), a data processing device (300, 500), which is connected to the controller (200) of the machine tool (100), and a server (400), which is connected to the controller (200) of the machine tool (100) via a communication network (600, 700), wherein the system is set up to carry out a method according to one of the preceding Claims 1 to 12.
14. Computer program product, comprising instructions which, when the program is executed by a computer, cause the latter to carry out the method according to one of the preceding Claims 1 to 12.