NC Machine Tool Execution Data Encryption and Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for numerically controlled machine tools lack efficient methods for securely and reliably transferring processing data from external data processing facilities to machine tools, particularly in ensuring data integrity and compliance with execution specifications.

Innovation Solution

A method and system for providing processing data to numerically controlled machine tools that involves generating execution data based on specified execution specifications, encrypting it using asymmetric encryption with a public key associated with the machine tool, and transmitting it securely, while also managing authentication and authorization to ensure only authorized machines and operators can access and execute the data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If processing data is transmitted from external data processing facilities to machine tools over a network, then data transfer efficiency and speed are improved, but data security and integrity are compromised

Engineering Contradiction:
Improvedata transfer efficiencyVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies preliminary action by generating execution data with embedded encryption specifications and authentication data before transmission. The data is prepared with security measures pre-integrated, including encryption keys and authorization information, so that secure transmission occurs automatically without compromising speed or efficiency during the actual data transfer process

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary mechanism in the form of encrypted execution data that acts as a mediator between the external data processing facility and the machine tool. This intermediary contains embedded authentication and authorization information that enables secure communication over the network without requiring direct trust between the transmitting and receiving systems

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If encryption and authentication mechanisms are implemented for data transfer, then data security is improved, but system complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple security functions into a single integrated execution data structure. Encryption specifications, authentication data, authorization information, and execution instructions are combined into one unified data package that is transmitted as a single entity, reducing the number of separate security mechanisms needed and simplifying the overall system architecture

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The execution data structure is designed to be self-sufficient, containing all necessary authentication, authorization, and encryption information within itself. The machine tool can independently verify and process the encrypted data without requiring external authentication servers or complex security infrastructure, thereby reducing system complexity

Inventive Principle:
Principle #25Self-service

3Loss of information

If execution data is encrypted with public keys, then intellectual property protection is improved, but processing overhead increases

Engineering Contradiction:
Improveintellectual property protectionVSAvoidprocessing overhead
Core Design Contradiction:
Loss of informationVSUse of energy by moving object

Solution Approach 1:

The patent applies local quality by selectively encrypting only the critical execution data containing intellectual property, rather than encrypting all data transmitted to the machine tool. The encryption is applied locally to specific data elements that require protection, while other non-sensitive data can be transmitted in plaintext, thereby reducing overall processing overhead while maintaining IP protection

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12124238B2Method and system for protecting execution data and/or processing data of a machine tool
Publication Date: 2024.10.22 DMG MORI SOFTWARE SOLUTIONS GMBH
  • US12124238B2 patent drawing
  • US12124238B2 patent drawing
  • US12124238B2 patent drawing

AI summary

The present invention relates to a method and a system for providing processing data to a numerically controlled machine tool (100), comprising: providing processing data (S301) to a data processing device (300), wherein the processing data comprises numeric control data, in particular one or more NC programs, on the basis of which a processing of a workpiece on the numerically controlled machine tool (100) can be carried out; specifying encryption specifications (S302) on the data processing device (300), which indicate specifications for encrypting the processing data and/or the execution data; specifying authentication specifications (S303) on the data processing device (300), which indicate specifications for authentication of the numerical machine tool and/or of an operator of the machine tool; specifying execution specifications (S304) on the data processing device (300), which indicate specifications for the machining of the workpiece on the numerically controlled machine tool; generating execution data (S305) on the basis of the specified execution specifications, wherein the execution data comprises the processing data; and encrypting the execution data (S306) on the basis of the encryption specifications; providing or transmitting (S307) the generated execution data to a control device (200, 300) of the numerically controlled machine tool (100).