Secure 3D printing
Abstract
A computer-implemented method for controlling reproduction of an item represented by a digital asset stored in a trusted computing environment using a reproduction device in an untrusted computing environment, in which a succession of data segments is transmitted from the trusted computing environment to the untrusted computing environment, the succession of data segments comprising segments of reproduction data, each of which includes at least one instruction for controlling the reproduction device to reproduce a portion of the item, and at least one segment of obfuscation data which has a structure identical the reproduction data but is incapable of controlling the reproduction device to reproduce a portion of the item, the method comprising: a) determining whether the next segment of data in the succession should be a segment of reproduction data or a segment of obfuscation data; b) where the next segment of data should be a segment of reproduction data, selecting and extracting an unprocessed segment of data from the digital asset to form the next segment of data; c) where the next segment of data should be a segment of obfuscation data, providing a segment of obfuscation data to form the next segment of data; d) generating a unique encryption key and encrypting the next segment of data using the unique encryption key; e) transmitting the encrypted next segment of data from the trusted computing environment; f) decrypting the encrypted next segment of data received at the untrusted computing environment; g) attempting to control the reproduction device using the decrypted data segment such that where the next segment of data is reproduction data, the reproduction device reproduces the portion of the item at the untrusted computing environment in accordance with the instructions included with the data segment, and where the next segment of data is obfuscation data, the reproduction device is unresponsive; and h) iterating steps (a) to (g) until the entire digital asset, or a desired portion of it, has been processed.
Claims
exact text as granted — not AI-modified1 . A computer-implemented method for controlling reproduction of an item represented by a digital asset stored in a trusted computing environment using a reproduction device in an untrusted computing environment, in which a succession of data segments is transmitted from the trusted computing environment to the untrusted computing environment, the succession of data segments comprising segments of reproduction data, each of which includes at least one instruction for controlling the reproduction device to reproduce a portion of the item, and at least one segment of obfuscation data which has a structure identical the reproduction data but is incapable of controlling the reproduction device to reproduce a portion of the item, the method comprising:
a) determining whether the next segment of data in the succession should be a segment of reproduction data or a segment of obfuscation data; b) where the next segment of data should be a segment of reproduction data, selecting and extracting an unprocessed segment of data from the digital asset to form the next segment of data; c) where the next segment of data should be a segment of obfuscation data, providing a segment of obfuscation data to form the next segment of data; d) generating a unique encryption key and encrypting the next segment of data using the unique encryption key; e) transmitting the encrypted next segment of data from the trusted computing environment; f) decrypting the encrypted next segment of data received at the untrusted computing environment; g) attempting to control the reproduction device using the decrypted data segment such that where the next segment of data is reproduction data, the reproduction device reproduces the portion of the item at the untrusted computing environment in accordance with the instructions included with the data segment, and where the next segment of data is obfuscation data, the reproduction device is unresponsive; and h) iterating steps (a) to (g) until the entire digital asset, or a desired portion of it, has been processed.
2 . A computer-implemented method according to claim 1 , wherein the reproduction device is a 3D printer.
3 . A computer-implemented method according to claim 1 , wherein the digital asset is a file containing 2D data instructions in a numerical control programming language such as G-code, PNG, SVG or any intermediary form.
4 . A computer-implemented method according to claim 1 , wherein step (c) comprises providing the obfuscation data by extracting the obfuscation data from a pre-populated database.
5 . A computer-implemented method according to claim 1 , wherein step (c) comprises providing the obfuscation data by generating the obfuscation data in accordance with a set of rules.
6 . A computer-implemented method according to claim 1 , wherein step (g) includes verifying completion of the reproduction of the portion of the item without error.
7 . A computer-implemented method according to claim 1 , wherein the data decrypted in step (f) are stored in protected memory at the untrusted computing environment.
8 . A computer-implemented method according to claim 7 , wherein the data stored in protected memory are erased after step (g) has been completed.
9 . A computer-implemented method according to claim 1 , wherein step (e) comprises transmitting the encrypted segment of data from the trusted computing environment directly to the untrusted computing environment, the encrypted data received at the untrusted computing environment in step (f) being the encrypted extracted segment of data.
10 . A computer-implemented method according to claim 1 , wherein step (e) comprises transmitting the encrypted segment of data from the trusted computing environment to a stream management server for onward transmission by the stream management server to the untrusted computing environment.
11 . A computer-implemented method according to claim 10 , wherein the unique encryption key is generated by the stream management server and transmitted to a digital asset storage server on which the digital asset is stored in the trusted computing environment.
12 . A computer-implemented method according to claim 1 , wherein the next segment of reproduction data selected in step (a) is contiguous with already-processed segments of data in the digital asset, when iterating steps (a) to (g).
13 . A computer-implemented method according to claim 1 , wherein the location of the segment of reproduction data selected in step (a) and the location of the next segment of reproduction data selected in step (a) within the digital asset are random, when iterating steps (a) to (g).
14 . A computer-implemented method according to any of the preceding claims, further comprising translating a source data structure in a first format into the digital asset.
15 . A computer-implemented method according to any of the preceding claims, wherein the method is initiated by selection and/or purchase of the item from an online source.
16 . A computer-implemented method according to any of the preceding claims, wherein firmware is provided on the reproduction device, such that the data segment is decrypted at the reproduction device.
17 - 18 . (canceled)
19 . A computer-implemented method for controlling access to an item represented by a digital asset stored in a trusted computing environment to enable the item to be reproduced by a reproduction device in an untrusted computing environment, in which a succession of data segments is transmitted from the trusted computing environment to the untrusted computing environment, the succession of data segments comprising segments of reproduction data, each of which includes at least one instruction for controlling the reproduction device to reproduce a portion of the item, and at least one segment of obfuscation data which has a structure identical to the reproduction data but is incapable of controlling the reproduction device to reproduce a portion of the item, the method comprising:
a) determining whether the next segment of data in the succession should be a segment of reproduction data or a segment of obfuscation data; b) where the next segment of data should be a segment of reproduction data, selecting and extracting an unprocessed segment of data from the digital asset to form the next segment of data; c) where the next segment should be a segment of obfuscation data, providing a segment of obfuscation data to form the next segment of data; d) encrypting the next segment of data using a unique encryption key; e) transmitting the encrypted next segment of data from the trusted computing environment; and f) iterating steps (a) to (e) until the entire digital asset, or a desired portion of it, has been processed.
20 - 29 . (canceled)
30 . A computer-implemented method for reproducing an item represented by a digital asset stored in a trusted computing environment using a reproduction device in an untrusted computing environment, in which a succession of data segments is transmitted from the trusted computing environment to the untrusted computing environment, the succession of data segments comprising segments of reproduction data, each of which includes at least one instruction for controlling the reproduction device to reproduce a portion of the item, and at least one segment of obfuscation data which has a structure identical to the reproduction data but is incapable of controlling the reproduction device to reproduce a portion of the item, the method comprising:
a) receiving an encrypted segment of reproduction data having been extracted from the digital asset or obfuscation data; b) decrypting the encrypted segment of data received at the untrusted computing environment; c) attempting to control the reproduction device using the decrypted data segment such that where the segment of data is reproduction data, the reproduction device reproduces the portion of the item at the untrusted computing environment in accordance with the instructions included with the data segment, and where the data segment is obfuscation data, the reproduction device is unresponsive; and d) iterating steps (a) to (c) until the entire digital asset, or a desired portion of it, has been reproduced.
31 - 49 . (canceled)Join the waitlist — get patent alerts
Track US2021224361A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.