Encrypted NC Program Execution for Secure Machine Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing numerical control systems for manufacturing machines lack effective protection against unauthorized access to control programs, which can lead to data theft, sabotage, or unintended changes during the manufacturing process.

Innovation Solution

The method involves generating program instructions for manufacturing machines using CAM software integrated within the numerical control facility, encrypting these instructions, and storing them in non-volatile memory, with decryption occurring in the NC kernel for processing, ensuring that only authorized access can read and execute the control programs, thereby preventing unauthorized access and data manipulation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If program instructions are stored in unencrypted form for easy access and execution, then ease of operation is improved, but security against unauthorized access deteriorates

Engineering Contradiction:
Improveaccess to control programsVSAvoidprotection against unauthorized access
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an encryption/decryption intermediary mechanism between the stored program instructions and the numerical control facility. The program instructions are encrypted during storage and only decrypted when executed by the authorized numerical control facility, preventing unauthorized access while maintaining operational ease for legitimate users

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the state parameter of the program instructions from unencrypted to encrypted form during storage. This parameter change ensures that even if unauthorized access occurs, the stolen instructions remain unreadable and unusable, thus protecting against data theft and sabotage

Inventive Principle:
Principle #35Parameter changes

2Reliability

If encryption is implemented for program instructions, then security is improved, but device complexity increases

Engineering Contradiction:
Improveprotection against unauthorized accessVSAvoidencryption and decryption mechanisms
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The numerical control facility is equipped with built-in decryption capability, allowing it to autonomously decrypt the encrypted program instructions during execution without requiring external intervention. This self-service approach minimizes additional system complexity while maintaining security

Inventive Principle:
Principle #25Self-service

3Ease of operation

If program instructions are decrypted for execution, then ease of operation is improved, but vulnerability to manipulation increases

Engineering Contradiction:
Improveexecution of control programsVSAvoidunauthorized manipulation during execution
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary encryption to the program instructions before they are stored or transmitted. This preliminary protective action ensures that even if the instructions are intercepted or accessed during transmission/storage, they remain protected from manipulation and unauthorized use

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20240288848A1Generating and executing encrypted program instructions by means of a digital control device
Publication Date: 2024.08.29 SIEMENS AG
  • US20240288848A1 patent drawing
  • US20240288848A1 patent drawing
  • US20240288848A1 patent drawing

AI summary

A method for operating a digital control device, and a digital control device, for controlling a manufacturing machine for manufacturing a workpiece, are disclosed. In the method, workpiece data are provided on the digital control device, and CAM software is provided on the digital control device. Program instructions for manufacturing the workpiece are generated by the manufacturing machine by the CAM software in accordance with the workpiece data. The program instructions are executed by the digital control device for controlling the manufacturing machine for manufacturing the workpiece. In order to protect the control program for the digital control device against unauthorized access, the generated program instructions are saved in encrypted form in a non-volatile memory of the digital control device and are only decrypted again immediately before the execution in a volatile memory of the NC core of the digital control device.