Machine Tool NC Data Encryption for Secure External Execution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems for transferring machining data to numerically controlled machine tools lack robust security measures and efficient encryption methods, leading to potential unauthorized access and manipulation of machining data.

Innovation Solution

A method and system that utilize asymmetric encryption with public keys to securely transfer machining data, specifying encryption parameters, authentication requirements, and execution specifications to ensure secure and controlled machining operations on machine tools.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If machining data is transferred to external machine tools without encryption, then data transfer efficiency is improved, but security and protection of know-how deteriorates

Engineering Contradiction:
Improvedata transfer efficiencyVSAvoidsecurity of machining data
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies preliminary action by encrypting the machining data before transmission to the machine tool. The encryption is performed in advance on the sending side (external control device) using asymmetric encryption, so that the data is already secured before leaving the controlled environment. This allows efficient transfer without real-time encryption overhead while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses asymmetric encryption as an intermediary mechanism between the sending and receiving systems. The public key acts as a mediator that allows secure transmission without requiring the private key holder to be present during transmission. The machine tool's control system can verify and process the encrypted data without exposing sensitive information.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If asymmetric encryption is implemented for data transfer, then security is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity of machining dataVSAvoidencryption system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the cryptographic key management complexity from the machine tool control system and places it entirely on the external control device. The machine tool only needs to store its own public key and process encrypted data, while all key generation, management, and decryption operations are performed externally. This extraction reduces the complexity burden on the machine tool system.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The external control device performs self-service by generating and managing its own private key and the corresponding public key pair. The system automatically handles key storage, encryption, and decryption operations without requiring manual intervention or complex key management infrastructure at the machine tool side. The machine tool simply uses its predetermined public key for encryption.

Inventive Principle:
Principle #25Self-service

3Reliability

If encryption parameters and authentication requirements are specified, then data protection is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvedata protectionVSAvoidoperational simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies preliminary action by pre-configuring authentication requirements and encryption parameters before data transmission begins. The external control device is set up in advance with the necessary cryptographic keys and authentication credentials, and the machine tool is pre-configured with its public key. This preliminary setup eliminates the need for complex real-time authentication negotiations during operation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses parameter changes by allowing the encryption parameters and authentication requirements to be dynamically specified and adjusted in the execution data. Different levels of security can be applied to different data sets by changing the encryption parameters, and authentication requirements can be modified without changing the underlying system architecture. This makes the system adaptable while maintaining operational simplicity.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3844576B1Method and system for protecting execution data and/or processing data of a machine tool
Publication Date: 2026.03.25 DMG MORI DIGITAL GMBH
  • EP3844576B1 patent drawingFigure 1
  • EP3844576B1 patent drawingFigure 2A~2C
  • EP3844576B1 patent drawingFigure 3

AI summary

The present invention relates to a method and a system for providing processing data to a numerically controlled machine tool (100), comprising: providing processing data (S301) to a data processing device (300), wherein the processing data comprise numeric control data, in particular one or more NC programs, on the basis of which a processing of a workpiece on the numerically controlled machine tool (100) can be carried out; specifying encryption specifications (S302) on the data processing device (300), which indicate specifications for encrypting the processing data and/or the execution data; specifying authentication specifications (S303) on the data processing device (300), which indicate specifications for the authentication of the numerical machine tool and/or of an operator of the machine tool; specifying execution specifications (S304) on the data processing device (300), which indicate specifications for the machining of the workpiece on the numerically controlled machine tool; generating execution data (S305) on the basis of the specified execution specifications, wherein the execution data comprises the processing data; and encrypting the execution data (S306) on the basis of the encryption specifications; providing or transmitting (S307) the generated execution data to a control device (200,300) of the numerically controlled machine tool (100).