NC User Administration via Shared Rights Database Setup

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Numerical control systems for machine tools lack simple and user-friendly user administration solutions, particularly in environments where expertise in network administration is scarce, such as small companies or shop floors, leading to difficulties in setting up and maintaining user rights and access.

Innovation Solution

A numerical control system with integrated user administration that includes two software components: one for setting up a database with user rights and creating a configuration file, and another for processing this file to enable secure network access, allowing inexperienced operators to establish a central user administration without requiring network administration knowledge or additional hardware, using a server-client model and LDAP-like functionality.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a dedicated server with LDAP directory is used for user management, then user rights management capability is improved, but device complexity and setup difficulty increase

Engineering Contradiction:
Improveuser rights management capabilityVSAvoidsystem setup complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines the user management server functionality with existing numerical control systems that are already present in the workshop. Instead of introducing a separate dedicated server, the numerical control systems themselves are equipped with server and client software components, merging multiple functions into existing devices.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The numerical control systems perform user management tasks themselves without requiring external dedicated servers. The systems can autonomously establish server-client connections, transfer configuration files, and manage user rights across the network using built-in software components.

Inventive Principle:
Principle #25Self-service

2Reliability

If an LDAP server infrastructure is implemented, then centralized user management is improved, but ease of operation deteriorates due to requiring network administration knowledge

Engineering Contradiction:
Improvecentralized user managementVSAvoidsetup ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system enables operators to perform user management setup themselves using the built-in software components. The first software component guides operators through creating user databases and configuration files without requiring external network administration expertise, making the system self-configurable.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Configuration files serve as intermediaries that encapsulate complex network communication settings. These files simplify the setup process by pre-configuring server-client connection parameters, allowing operators to establish centralized user management through simple file transfers rather than complex network configuration.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If additional hardware for user management is introduced, then user administration capability is improved, but device complexity and cost increase

Engineering Contradiction:
Improveuser administration capabilityVSAvoidhardware requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The numerical control systems are designed to perform multiple functions: they serve as both machining controls and user management servers/clients. This multi-functionality eliminates the need for dedicated hardware servers, as the existing numerical control systems can handle user management tasks through installed software components.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges user management functionality with existing numerical control systems. By combining these functions in single devices, the system avoids adding separate hardware infrastructure, reducing overall system complexity and cost while maintaining centralized user administration capability.

Inventive Principle:
Principle #5Merging (Combining)

4Reliability

If a network administrator is involved in setup, then user management reliability is improved, but loss of time and operational independence worsen

Engineering Contradiction:
Improveuser management setup reliabilityVSAvoidsetup time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables operators to independently perform user management setup without requiring network administrators. The built-in software components provide guided setup procedures that allow workshop personnel to configure user databases, create configuration files, and establish server-client connections autonomously.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The first software component performs preliminary actions by automatically generating configuration files with all necessary network communication settings. This pre-configured information is then transferred to client systems, enabling rapid setup without requiring administrators to manually configure each connection parameter.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3413148B1Numerical control with integrated user administration
Publication Date: 2022.07.27 DR JOHANNES HEIDENHAIN GMBH
  • EP3413148B1 patent drawingFigure 1

AI summary

A numerical control system with integrated user management is disclosed, including a user rights management system. This user management system enables cross-controller administration of at least two controllers (NC-A, NC-B, NC-N) connected via a network (N), where the controller is configured as a server (NC-A) and/or as a client (NC-A, NC-B, NC-N). The rights of all users are stored on the server (NC-A) and can be queried by the clients (NC-A, NC-B, NC-N) via the network (N). A first software component (S1) is installed on the controller, enabling the creation of a database (DB) with user rights and the generation of a configuration file (F) containing all the information necessary for secure access to the database (DB) via the network (N). The first software component (S1) is also configured to copy this configuration file (F) to a transport medium (T).A second software component (S2) is also installed on the controller, which is set up to read the configuration file (F) from the means of transport (T) and to process the configuration file (F) in order to enable access to the database (DB) via the network (N).