Trusted Fabrication Endpoint for Signed Manufacturing Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Digital manufacturing (DM) systems face cybersecurity vulnerabilities due to untrusted equipment and lack of secure traceability, leading to risks in intellectual property protection, quality control, and industrial espionage, especially in sensitive environments like aerospace and defense.

Innovation Solution

A digital manufacturing trusted endpoint (DMTE) is introduced, comprising a secure controller for network connectivity and an untrusted controller for local communication, which verifies digitally signed data before manufacturing items, ensuring data privacy and integrity through electrical isolation and strong cryptography, thus extending trust from DM data sources to DM equipment with minimal trust requirements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If DM machines are connected to networks for ease of operation, then network connectivity and convenience are improved, but cybersecurity vulnerabilities and attack surface increase

Engineering Contradiction:
Improvenetwork connectivityVSAvoidcybersecurity vulnerabilities
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system segments the DM machine into trusted and untrusted components. The trusted controller runs certified security software and manages cryptographic operations, while the untrusted controller handles user interface and local communication. This segmentation allows network connectivity through the untrusted controller while the trusted controller maintains security boundaries, resolving the contradiction between ease of operation and cybersecurity vulnerabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The trusted controller acts as an intermediary between the network and the fabrication process. It verifies digitally signed data from authorized sources before executing manufacturing instructions, thereby mediating between network connectivity benefits and cybersecurity risks. The intermediary validates all incoming data through cryptographic verification, preventing unauthorized access while maintaining operational convenience.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If DM machines are air-gapped for security, then cybersecurity protection is improved, but operational convenience and productivity deteriorate

Engineering Contradiction:
Improvecybersecurity protectionVSAvoidoperational convenience
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The system replaces physical air-gap isolation with cryptographic verification mechanisms. Instead of relying on physical separation to ensure security, the trusted controller verifies digitally signed data using public key infrastructure. This substitution maintains cybersecurity protection equivalent to air-gapping while enabling network connectivity and remote operation, thereby improving productivity without sacrificing security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system changes the security parameter from physical isolation (air-gap) to cryptographic verification. By transitioning from a mechanical/physical security model to a digital/cryptographic security model, the system achieves the same security objectives while enabling networked operation and remote access, thus resolving the contradiction between cybersecurity protection and operational convenience.

Inventive Principle:
Principle #35Parameter changes

3Manufacturing precision

If digital data elements are used for manufacturing control, then manufacturing precision is improved, but traceability and authenticity verification become more difficult

Engineering Contradiction:
Improvedimensional controlVSAvoidtraceability
Core Design Contradiction:
Manufacturing precisionVSReliability

Solution Approach 1:

The system implements feedback through cryptographic verification of digitally signed data. The trusted controller continuously verifies the authenticity and integrity of manufacturing instructions against authorized sources before execution. This feedback mechanism ensures that precise digital control data maintains its authenticity throughout the manufacturing process, resolving the contradiction between manufacturing precision and traceability verification.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11516017B2Endpoint and protocol for trusted digital manufacturing
Publication Date: 2022.11.29 AURA TECHNOLOGIES LLC
  • US11516017B2 patent drawing
  • US11516017B2 patent drawing
  • US11516017B2 patent drawing

AI summary

An endpoint for trusted fabrication, the endpoint including at least one secure controller configured for connection to a wide area network; and at least one untrusted controller configured for local communication, wherein the endpoint is configured for connection to a fabricator and further configured to receive digitally-signed data specifying at least one item for manufacture; verify the digitally-signed data; and direct the fabricator to manufacture the at least one item after verifying the digitally signed data. A method for trusted on-demand manufacturing, the method including receiving, at an endpoint connected to a fabricator, digitally signed data describing at least one item for manufacture; verifying, at the endpoint, the digitally signed data; and manufacturing the at least one item using the digitally signed data after verifying the digitally signed data, wherein the endpoint comprises at least one secure controller and at least one untrusted controller.