Hedberg Thomas D, Krima Sylvere, Camelio Jaime A
National Institute of Standards and Technology, Gaithersburg, Maryland 20899.
Engisis LLC, Bethesda, Maryland 20817.
J Comput Inf Sci Eng. 2017 Mar;17(1). doi: 10.1115/1.4034131. Epub 2016 Nov 7.
Exchange and reuse of three-dimensional (3D)-product models are hampered by the absence of trust in product-lifecycle-data quality. The root cause of the missing trust is years of "silo" functions (e.g., engineering, manufacturing, quality assurance) using independent and disconnected processes. Those disconnected processes result in data exchanges that do not contain all of the required information for each downstream lifecycle process, which inhibits the reuse of product data and results in duplicate data. The X.509 standard, maintained by the Telecommunication Standardization Sector of the International Telecommunication Union (ITU-T), was first issued in 1988. Although originally intended as the authentication framework for the X.500 series for electronic directory services, the X.509 framework is used in a wide range of implementations outside the originally intended paradigm. These implementations range from encrypting websites to software-code signing, yet X.509 certificate use has not widely penetrated engineering and product realms. Our approach is not trying to provide security mechanisms, but equally as important, our method aims to provide insight into what is happening with product data to support trusting the data. This paper provides a review of the use of X.509 certificates and proposes a solution for embedding X.509 digital certificates in 3D models for authentication, authorization, and traceability of product data. This paper also describes an application within the Aerospace domain. Finally, the paper draws conclusions and provides recommendations for further research into using X.509 certificates in product lifecycle management (PLM) workflows to enable a product lifecycle of trust.
对产品生命周期数据质量缺乏信任阻碍了三维(3D)产品模型的交换和重用。信任缺失的根本原因是多年来工程、制造、质量保证等“竖井式”职能采用独立且不相关的流程。这些不相关的流程导致数据交换不包含每个下游生命周期流程所需的所有信息,从而抑制了产品数据的重用并导致数据重复。由国际电信联盟电信标准化部门(ITU-T)维护的X.509标准于1988年首次发布。尽管最初旨在作为X.500系列电子目录服务的认证框架,但X.509框架在最初预期范式之外的广泛实现中得到了应用。这些实现范围从加密网站到软件代码签名,然而X.509证书的使用尚未广泛渗透到工程和产品领域。我们的方法并非试图提供安全机制,但同样重要的是,我们的方法旨在深入了解产品数据的情况,以支持对数据的信任。本文回顾了X.509证书的使用情况,并提出了一种在3D模型中嵌入X.509数字证书以实现产品数据认证、授权和可追溯性的解决方案。本文还描述了航空航天领域内的一个应用。最后,本文得出结论并为在产品生命周期管理(PLM)工作流程中进一步研究使用X.509证书以实现可信的产品生命周期提供了建议。