System and method for secured sharing of CAD models for secured manufacturing as a service
The storage device with immutable modules and secure data transfer method addresses the challenges of unauthorized access and data integrity in 3D CAD data transfer, ensuring secure and controlled printing operations.
Patent Information
- Application Number
- PCT/IB2025/056881
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-09-13
- Filing Date
- 2025-07-08
- Publication Date
- 2026-01-15
AI Technical Summary
Existing solutions fail to provide a comprehensive and secure method for transferring 3D CAD data, ensuring data integrity, user control over access, and preventing unauthorized access or hacking, particularly in the context of additive manufacturing and contract manufacturing scenarios.
A storage device with immutable storage modules and a core module, combined with a computer-implemented method, ensures secure data transfer by using unique serial numbers and secret keys for encryption, allowing controlled access and secure printing operations, followed by automatic deletion of residual data.
Ensures secure, controlled, and traceable transfer of 3D CAD data, reducing the risk of data leaks and unauthorized access, while providing user control over production and ensuring compliance with regulatory standards.
Smart Images

Figure 00000016_0000 
Figure 00000016_0001 
Figure 00000017_0000
Abstract
Description
[0001] SYSTEM AND METHOD FOR SECURED SHARING OF CAD MODELS FOR SECURED MANUFACTURING AS A SERVICE
[0002] TECHNICAL FIELD
[0003] The present invention relates to a storage device for the secure transfer of data from a server to a manufacturing device and a corresponding computer implemented method for transferring information data to said storage device. Also, the present invention relates to a computing device executing the method and to a program product comprising instructions to cause a computing device to execute the steps of said method.
[0004] BACKGROUND
[0005] Transferring files between a trading partner and a customer can always involve at least some level of risk, especially for transferring files containing sensitive data. When dealing with additive manufacturing, or 3D printing, this issue becomes more important. As matter of fact, 3D printing is continuing to evolve and becoming more commonplace in the business world, so it leads to potential for cybersecurity risks.
[0006] Additive manufacturing poses several unique risks that could have negative consequences for manufacturing companies. Some of the common cybersecurity threats associated with additive manufacturing include a deliberate insertion of defects, which could cause the printed products to fail or malfunction. Another problem can be the intellectual property theft. Hackers can easily reverse engineer a product by scanning it and then recreate it using additive manufacturing. This is a huge issue for companies that have spent years and money developing their products and building up their brand.
[0007] Another serious concern involves data breaches. If a manufacturer’s design files are stolen or leaked, its competitors could gain an advantage. Additionally, the thieves could sell the designs on the black market or use them to produce and sell counterfeit products.
[0008] Additionally, for a quick market / segment entry, original equipment manufacturer may opt for contract manufacturing with a third party vendor. Furthermore, during projects, components details need to be shared with the partners for system integration and final assembly. Also, in the context of transferable digital assets, customers demand the finished product or the completed components of the manufacturer.
[0009] Solutions to some problems or concerns are known from prior art.
[0010] WO201 7 / 073830 A1 discloses a system and method for protecting 3D printing content by encrypting 3D printing files at the client side using a public key, transmitting the encrypted files to a printing company, and decrypting them at the printing company using a private key, with key management handled by a dedicated server. The system allows for secure transmission and usage restriction of 3D printing files, ensuring that only authorized devices can access and use the files, and can enforce limits such as the number of prints or time of use.
[0011] US2020 / 0326683 A1 describes a secure 3D printing system where encrypted printing instructions are stored on the printer, and cryptographic keys unique to each printer and object are delivered by a server during the print phase, with keys provided in parts and only at specific times or after certain conditions are met. This system enhances security by partitioning print instructions, requiring multiple keys, and using authorization factors such as time, whitelist, payment, or tasks to control access, thereby preventing unauthorized use or copying of 3D print content.
[0012] In all the above scenarios, data, information, and the CAD models are to be shared between manufacturer and customer. Therefore, control and security of these elements become the highest priority for the companies that want to provide information data on the 3D printing of their products. Further, the encryption of the digitally transferable assets or the Digital Twin is an additional aspect to be taken into account.
[0013] In this context, the main technical challenges are the lack of trust between the designer / product owner and the manufacturer due to data security, copyright violation, breach of design data, as well as the lack of control over number / volume of production in a contract manufacturing scenario. Also, in varying demography of the world, local manufacturing needs change quickly and many approvals from government, OEMs and product development teams across the globe adhering to standards and regulations are required. Another important issue is the lack of secured transfer which has limited and restricted usage of 3D CAD data which remains in the usable format once the manufacturing process is completed. Nowadays, the majority of the 3D CAD file exchange occur over email and cloud storage with password protected exchange. But still the 3D CAD data is in the useable format after the manufacturing process is completed. Few of the manufacturer / 3D printing service provider came up with web portals for uploading 3D CAD data and getting the price / quotation. But largely they are in the control of Web portal owners. In addition, most of these Trust & understanding are taken care by signing a Non-Disclosure Agreement and Memorandum of Understanding documents. However, in certain conditions and local jurisdictions these documents are ignored.
[0014] Several solutions are present in prior art facing these problems. For example, business models are known for secured decentralized manufacturing through digitally transferable asset. In particular, distributed manufacturing platforms are used with network-based file exchange, rapid printing based on user instructions and modem connected-logistics. Also, secured communication and data protocol for distributed additive manufacturing are known using HASH key generation, biometric authentication, blockchain and ledger keeping. In particular, ledger keeping, licensing and security encryption can be used for digital rights, licensing, storing 3D CAD data fragment wise, physically unclonable function (PUF) to a product, and generate a non- fungible token (NFT).
[0015] However, all the known solutions fail to address the following problems: i. The user does not have the details and status about the 3D CAD data once manufacturing is completed; ii. Accessibility of 3D CAD data or manufacturing data with or without encryption still have a chance of hacking; iii. Lack of original source for the 3D CAD data since only transferable neutral file is used in the file exchange; iv. The presence of details about the original author, different stages of product lifecycle and the person who accessed the data / machine mac IDs; v. No physical password for a specific 3D CAD data file for manufacturing. vi. Lack of a complete altogether solution package which includes a distribution platform, slicing core for 3D CAD models, payment gateway, an encryption based secured data transfer module and a hardware that triggers decryption and printing and removal of data after the operational cycle has been completed. Examples of the present disclosure seek to address or at least alleviate the above problems.
[0016] SUMMARY
[0017] In a first aspect, there is provided a storage device for the secure transfer of data from a server to a manufacturing device, in particular a 3D printing device, the storage device comprising: a core module including a central processing unit and a main memory; a first immutable storage module accessible by the core module; a second immutable storage module accessible by the core module; and a secondary storage module in communication with the core module, the secondary storage module including a plurality of logical partitions, wherein at least one partition comprises instructions to control the functions of the manufacturing device.
[0018] In a second aspect there is provided a computer-implemented method for transferring information data to the storage device according to the first aspect, the method comprising: requesting a serial key from the storage device coupled to a computing device via a user interface; receiving the requested serial key from the storage device to the computing device; sending a verification request of the serial key to a server external to the computing device; receiving information data from the server; and transferring the information data to the storage device once said information data are successfully validated by the computing device.
[0019] In a third aspect there is provided a computing device executing the computer- implemented method according to the second aspect.
[0020] In a fourth aspect there is provided a computer program comprising instructions which, when the program is executed by a computing device, cause the computing device to carry out the computer-implemented method according to the second aspect. Other aspects and features are defined in the appended claims.
[0021] Examples of the disclosure may provide a way to transfer information data regarding the 3D printing of a product in a secure manner, thereby guaranteeing all the information details to the user regarding the product. For this purpose, a dedicated storage device is provided for transferring data from the platform to the 3D printer, executing the print operation and deleting the residual data. Also, the examples of the disclosure may provide a method and a system for controlling a large number of production in a contract manufacturing scenario. Specifically, a platform (i.e. a website / desktop application) is provided acting as an e-commerce website that enables the purchase of print instances of 3D CAD models.
[0022] It is noted that CAD model or it’s respective G-code file is a digital design model of an object that is then replicated physically via different manufacturing devices. One such device is a 3D printer. A 3D printer reads printing instruction generated from its respective CAD model then creates a physical sample of the same from the provided material. Some CAD models are proprietary assets of an individual / organization, the public disclosure of which causes the interested party certain loss. Therefore, it needs to be handled carefully with limited exposure (almost none) from non-interested parties. The present storage device 1 and the corresponding data transfer method 100 remove this risk constraint by providing secured means for commercially distributing assets necessary for replicating products via 3D printers over the internet.
[0023] BRIEF DESCRIPTION OF DRAWINGS
[0024] Examples of the disclosure will now be described by way of example only with reference to the accompanying drawings, in which like references refer to like parts, and in which:
[0025] Figure 1 is a schematic representation of the storage device for transferring files according to an example;
[0026] Figure 2 is a high-level schema and access controls of the storage device according to an example;
[0027] Figure 3 is an Input / Output control flow of the storage device according to an example; Figure 4 is a flow chart of an algorithm for adding a new printer according to an example;
[0028] Figure 5A is a flow chart of an algorithm for creating a customized configuration file according to an example;
[0029] Figure 5B is a flow chart of an algorithm of a transfer of information data to a printer according to an example; and
[0030] Figure 6 is a flow diagram of a method for transferring information data to the storage device according to an example.
[0031] DETAILED DESCRIPTION OF PREFERRED EMBODIMENTS
[0032] A storage device for secure transfer of data from a server to a 3D printer and a computer-implemented method for transferring information to the storage device are disclosed. In the following description, a number of specific details are presented in order to provide a thorough understanding of the examples of the disclosure. It will be apparent however to a person skilled in the art that these specific details need not be employed in order to practice the examples of the disclosure. Conversely, specific details known to the person skilled in the art are omitted for the purposes of clarity in presenting the examples.
[0033] Figure 1 schematically illustrates the storage device 1 used for transferring data between a server 2 and a manufacturing device 3. The manufacturing device 3 can be for example a 3D printer but can also be any other type of device using a 3D model created by a CAD software. The storage device 1 is configured to receive information data from a server or platform 2 through a coupling of the storage device 1 to a computing device connected to a network shared by the server 2. The storage device 1 is furthermore configured to store the received information data and to transfer said data to the manufacturing device 3. This can be done using one or more dedicated input / output interface 13 provided in the storage device 1 to couple the storage device 1 with an external device.
[0034] The storage device 1 comprises a core module 6 for the main management of the different internal components of the storage device 1. The core module 6 includes a central processing unit (CPU) 7 and a main memory 8. The storage device 1 also includes a first immutable storage module 4 and a second immutable storage module 5, both accessible by, and in communication with, the core module 6. Additionally, the storage device 1 comprises a secondary storage module 9 in communication with the core module 6. This secondary storage module 9 includes a plurality of logical partitions. At least one of these logical partitions comprises instructions to control the functions of the manufacturing device 3.
[0035] Accordingly, the storage device 1 can be used to transfer in a secure way information data from a server 2 to the manufacturing device 3 (3D printer) by a simple coupling process.
[0036] With reference to figures 2 and 3, the high level schema as well as the I / O control flows of the storage device 1 are illustrated in detail.
[0037] In one example, the first immutable storage module 4 comprises the storage device firmware 18. It is noted that the first immutable storage module 4 is a separate memory only accessible by the core module 6.
[0038] In one example, the second immutable storage module 5 comprises at least a serial number 16 and a secret key 17 of the storage device 1 . This module 5 is a separate protected memory, wherein the serial number 16 and the secret key 17 are stored by the manufacturer of the storage device 1. It is noted that the serial number 16 for every storage device 1 is unique and it is stored in a database. Depending on the cryptographic algorithm used in cryptography engine for encryption and decryption, one or more secret keys 17 are stored (also by manufacturer) to decrypt the encrypted data. These secret keys 17 also have required counterpart keys which are securely stored in an external database and are used to encrypt the data. As shown in figure 3, the data stored in the second immutable storage module 5 cannot be modified and can only be read, the secret key 17 in the second immutable storage module 5 can be read by software application through I / O interface 13 and the firmware partition 10 can read both serial number 16 and serial key 17.
[0039] According to an example, the secondary storage module 9 is a separate memory with controlled I / O access. The plurality of logical partitions in the secondary storage module 9 includes at least a firmware partition 10, a license partition 11 , and an auxiliary storage partition 12. In particular, the firmware partition 10 can comprise the firmware of the manufacturing device 3. This is a partition with custom 3D printer firmware that has additional modules to handle security, licenses, exceptions and logging along with cryptography engine. It is noted that the firmware is used to boot the 3D printer 3. Algorithm for cryptography engine can be pre-set externally based on the stored secret keys 17.
[0040] The license partition 11 is another secure logical partition to store encrypted license files. The I / O access of this partition is defined in figure 3. Only firmware stored in firmware partition 10 has read access to the encrypted licenses and software application has write access to write the encrypted licenses to the partition through I / O interface 13.
[0041] The auxiliary storage partition 12 is configured to store information data to be transferred to the manufacturing device 3. Compared to the firmware partition 10 and license partition 11 , the auxiliary storage partition 12 is a logical partition with a very large storage space. As a matter of fact, this storage partition 12 is used to store large data like files used for 3D printing (example: G-codes) and logs. The I / O access of this partition is defined in figure 3. Both firmware in firmware partition 10 and software application through I / O interface 13 have read & write access to auxiliary partition. Software application needs read access to read the log files & write access to write the large data files (ex: G-codes) used for 3D printing. Firmware partition 10 needs read access to read data files for 3D printing and write access to write all the logs generated during 3D printed process.
[0042] According to an example, the storage device 1 is a modified flash memory device, for example a USB storage stick that can easily be plugged into a corresponding USB port of the manufacturing device 3 or of any external computing device.
[0043] The present storage device 1 , combined with a workflow of platform 2, facilitates the distribution of data, in particular of 3D models, to a 3D printer 3 in a secure mode.
[0044] The workflow (data transfer process) starts with a user interacting with the server 2 to perform typical ecommerce operations like creating an account, browsing through products (CAD models in this case), cart functionality, adding printer configuration (default configuration is used otherwise), managing printer configuration, creating quotation (dynamically rendered and pdf format), placing order, making payment via available payment gateway methods (initially UPI) and after purchase, accessing the purchased instance via a special page (suppose user inventory, a section from where the use can access all his new / unused print in-stances). With reference to figure 4, the process 200 for adding printer configuration is illustrated in a flow chart. The user adds details about the printer specification. These details along with boiler plate configuration of, for example, a fused deposition modelling (FDM) printer are used to create a customized configuration file. Also using these configurations, a Marlin firmware specific to the user’s configuration can be generated. This firmware is used to facilitate various functionalities in the progressive iterations of this method.
[0045] As shown in figure 5A, the authenticated user can add a product or multiple products of same or different type to the cart from the available catalogue displayed in the software application. Based on the preset printer settings for each product added to cart, a quotation would be generated with total price to be paid. The user can then make the payment using available payment gateway methods and after purchase is verified, print licenses will be generated and allocated to the user. User inventory would contain print license and products purchased.
[0046] From the inventory, the user can initiate print, which starts the second segment of the workflow as show shown in the flow chart of figure 6. As soon as the print is triggered, the server 2 performs verification check on the storage device 1 , passing of which, slicing operation is performed on the respective CAD file and then the G-code file is sent to the storage device 1 in encrypted form along the all the other necessary artifacts like (licenses, firmware, etc.). Specifically, figure 6 illustrates the method 100 for transferring information data to the storage device 1. The method 100 first comprises requesting a serial key 17 from the storage device 1 coupled to a computing device via a user interface 15. After that, the method 100 comprises receiving the requested serial key 17 from the storage device 1 to the computing device and sending a verification request of the serial key 17 to a server 2 external to the computing device. The method 100 further comprises receiving information data from the server 2 and transferring the information data to the storage device 1 once said information data are successfully validated by the computing device.
[0047] The method 100 can comprise a step in which the server 2 verifies the serial key 17 received and, upon successful verification by the server 2, the server 2 sends information data to the computing device. In other words, information data from the server 2 can be received upon successful verification of the serial key 17 by the server 2. The server 2 can be a second computing device that is external to, but operationally coupled with, the computing device coupled to the storage device 1 .
[0048] In one example, the method 100 further comprises receiving a unique session ID using user credentials and serial key 17 from the server 2. Optionally, the unique session ID can be received upon successful verification of the serial key 17 by the server. Alternatively, in case the verification of the serial key at the server 2 is failed, the method 100 comprises exiting the computer-implemented method.
[0049] The method 100 can comprise storing the session ID at the storage device 1. Optionally, storing the session ID occurs if the verification of the serial key 17 at the server 2 is successfully completed.
[0050] According to an example, the information data are validated by the computing device using checksum. However, other reliable validation process can also be considered.
[0051] Should the validation of the information data by the computing device fail, the method 100 can comprise maintaining the information data at the computing device, for example by storing said data in a dedicated memory.
[0052] In one example, the information data comprises at least encrypted G-codes.
[0053] After the artifacts has been transferred to the storage device 1 , the storage device 1 is ready for printing. The user then attaches the storage device 1 to the 3D printer 2, upon which the storage device 1 runs a program that performs all necessary operations required to complete the print cycles successfully. The operations include verification of artifacts, decryption of artifacts to access G-code file, feeding the G-code file to the 3D printer 2 and then monitoring.
[0054] When the printing operation is completed, a utility program present in the core module 6 removes all the unnecessary files, generates a log of the operations performed till the end of the workflow. The conclusion of the printing process is illustrate in figure 5B.
[0055] After the artifacts has been transferred to the storage device 1 (i.e. a USB device), the USB device is said to be ready for printing. The user then attaches the USB device to the 3D printer, upon which the USB device runs a program that performs all necessary operations required to complete the print cycles successfully. The operations include verification of artifacts, checking connected 3D printer for compatibility, decryption of artifacts to access G-code file, feeding the G-code files to the 3D printer and monitoring of the whole process. When the printing operation is completed, the utility program removes all the unnecessary files, generates a log of the operations performed till the end of the workflow. Logs would be transferred back to server when user connects the USB device to computer running our software application.
[0056] The combination of the present storage device 1 in a context of an e-commerce platform can be considered as a CPS (Cyber Physical System) implementation which provides a single package solution, using which the instances of digital design files like CAD models can be commercially distributed (partial sharing) in a secured manner. The concern of data leak is overcome by transcribing the G-code of a particular CAD model that needs to be transferred in the server (source) itself and then transferring an encrypted copy of the G-code file from the server 2 to the destination i.e. , the storage device 1 , for example a USB hardware attached to the user’s laptop (user interface 15). The storage device 1 is then connected to the manufacturing device 3, i.e., the 3D printer, and the printing operation is performed along with all the other necessary steps (monitoring print, generating log, deletion of files, etc.).
[0057] By using the present method 100 and by employing the present storage device 1 the following advantages can be achieved:
[0058] - The need for manufacturing unit and logistics are removed;
[0059] - The time restriction associated with manufacturing and delivery is overcome;
[0060] - The overall cost of venture is reduced;
[0061] - Limited instances of important data can be shared by users without loss;
[0062] - Numerous gateways for payment are provided;
[0063] - a CAD model using the live model feature available in the plat-form itself can properly be verified by the user.
[0064] Although a variety of techniques and examples of such techniques have been described herein, these are provided by way of example only and many variations and modifications on such examples will be apparent to the skilled person and fall within the spirit and scope of the present invention, which is defined by the appended claims and their equivalents.
Claims
CLAIMS1 . Storage device (1 ) for the secure transfer of data from a server (2) to a manufacturing device (3), in particular a 3D printing device, the storage device (1 ) comprising: a core module (6) including a central processing unit (7) and a main memory (8); a first immutable storage module (4) accessible by the core module (6); a second immutable storage module (5) accessible by the core module (6); and a secondary storage module (9) in communication with the core module (6), the secondary storage module (9) including a plurality of logical partitions, wherein at least one partition comprises instructions to control the functions of the manufacturing device (3).
2. Storage device (1 ) according to claim 1 , wherein the first immutable storage module (4) comprises the storage device firmware (18).
3. Storage device (1 ) according to any one of claims 1 to 2, wherein the second immutable storage module (5) comprises at least a serial number (16) and a secret key (17) of the storage device (1 ).
4. Storage device (1 ) according to any one of claims 1 to 3, wherein the plurality of logical partitions in the secondary storage module (9) includes at least a firmware partition (10), a license partition (11 ), and an auxiliary storage partition (12).
5. Storage device (1 ) according to claim 4, wherein the firmware partition (10) comprises the firmware of the manufacturing device (3).
6. Storage device (1 ) according to claim 4, wherein the auxiliary storage partition (12) is configured to store information data, in particular G-codes, to be transferred to the manufacturing device (3).
7. Storage device (1 ) according to any one of claims 1 to 6, further comprising at least an input / output interface (13) to couple the storage device (1 ) with an external device.
8. Storage device (1 ) according to any one of claims 1 to 7, wherein the storage device (1) is a modified flash memory device.
9. Computer-implemented method (100) for transferring information data to the storage device (1 ) according to any one of claims 1 to 8, the method comprising: requesting a serial key (17) from the storage device (1 ) coupled to a computing device via a user interface (15); receiving the requested serial key (17) from the storage device (1 ) to the computing device; sending a verification request of the serial key (17) to a server (2) external to the computing device; receiving information data from the server (2); and transferring the information data to the storage device (1) once said information data are successfully validated by the computing device.
10. Computer-implemented method (100) according to claim 9, further comprising: receiving a unique session ID using user credentials and serial key (17) from the server (2), optionally upon successful verification of the serial key (17) by the server; or exiting the computer-implemented method if the verification of the serial key (17) at the server (2) is failed.11 . Computer-implemented method (100) of claim 10, further comprising storing the session ID at the storage device (1 ) preferably if the verification of the serial key (17) at the server (2) is successfully completed.
12. Computer-implemented method (100) according to any one of claims 9 to 11 , wherein the information data are validated by the computing device using checksum.
13. Computer-implemented method (100) according to any one of claims 9 to 12, comprising maintaining the information data at the computing device, if the validation of the information data by the computing device is failed.
14. Computer-implemented method (100) according to any one of claims 9 to 12, wherein the information data comprises at least encrypted G-codes.
15. Computing device executing the computer-implemented method according to any one of the claims 9 to 14.
16. Computer program, comprising instructions which, when the program is executed by a computing device, cause the computing device to carry out the computer- implemented method according to any one of the claims 9 to 14.