GB/T 44909-2024Additive manufacturing-Technical requirements for product data protection of cloud service platform (English PDF)
增材制造 云服务平台产品数据保护技术要求
Open the GB/T 44909-2024 preview as PDF
This is a limited preview
Buy now to download the full PDF (17 pages)
Issued by
SAMR; SAC
Level / Type
National · Recommended
Issue date
November 28, 2024
Implementation date
November 28, 2024
Scope
GB/T 44909-2024 is the English-translated version of 增材制造 云服务平台产品数据保护技术要求.
GB/T 44909-2024 deals with the data a customer hands over when it orders a printed part through an additive manufacturing cloud platform, and above all with the three-dimensional model file, which is the whole product in a form that can be copied without limit. The document first sorts the product data into six types, from the basic listing and the ownership record through the model itself, the manufacturing parameters, the transaction details and the design brief, then grades each item at one of three protection levels, the top level reserved for material that must not leak at all. Clause 6 follows the data through five stages, collection, storage, presentation, transfer and deletion, and attaches requirements to each: collection limited to what the service actually needs, encryption and access control in storage, encrypted or simplified models when a buyer views a part on screen, secure transmission to the printing supplier under a written agreement, and deletion that leaves nothing recoverable. Clause 7 sets out what a test plan for these protections has to contain, and clause 8 divides the duties between the party supplying a model, the party receiving it for printing, and the platform in the middle. It is written for the operators of such platforms and for the designers and print bureaux trading on them.
Document preview — GB/T 44909-2024
National Standard of the People's Republic of China
- ICS
- 25.030
- Classification
- J 07
Issued by: State Administration for Market Regulation; Standardization Administration of the PRC
Contents
- 1 Scope1
- 2 Normative references1
- 3 Terms and definitions1
- 4 Types of product data information1
- 5 Protection levels of product data information2
- 6 Protection requirements for product data information3
- 6.1 General3
- 6.2 Collection stage3
- 6.3 Storage stage3
- 6.4 Presentation stage3
- 6.5 Transfer stage4
- 6.6 Deletion stage4
- 7 Verification methods4
- 8 Responsibilities and obligations of the different parties4
- 8.1 Responsibilities and obligations of the provider of product data information4
- 8.2 Responsibilities and obligations of the receiver of product data information4
- 8.3 Responsibilities and obligations of the cloud service platform5
- Bibliography6
1 Scope
This document specifies the types of product data information, the protection levels, the protection requirements and the responsibilities and obligations of the different parties for an additive manufacturing cloud service platform, and describes the corresponding verification methods.
This document applies to the protection of product data by an additive manufacturing cloud service platform in the course of providing services.
2 Normative references
The contents of the following documents constitute indispensable provisions of this document through normative reference in the text. For dated references, only the version corresponding to that date applies; for undated references, the latest version, including all amendments, applies.
GB/T 35351 Additive manufacturing - Terminology; GB/T 37461 Additive manufacturing - Specification for cloud service platform mode; GB/T 39403 Security protection management requirements for cloud manufacturing service platforms.
3 Terms and definitions
The terms and definitions given in GB/T 35351 and GB/T 37461 and the following apply to this document.
3.1 additive manufacturing cloud service platform, AMCSP: a platform based on additive manufacturing and cloud service technology that provides additive manufacturing goods and related services such as design, payment, transaction and delivery. Source: GB/T 37461-2019, 3.5.
3.2 product data information: the information relating to a product that is involved when the AMCSP provides additive manufacturing goods and services.
3.3 provider of 3D design model: the party that owns a three-dimensional model or has been lawfully authorized by its owner and that provides the three-dimensional model to the AMCSP. Note: this mainly includes consumers and designers.
3.4 receiver of 3D design model: the party that receives three-dimensional model data from the AMCSP for additive manufacturing purposes. Note: this normally means the additive manufacturing production service provider.
4 Types of product data information
The additive manufacturing cloud service platform, called the cloud service platform below, has four basic service modes: manufacturing, online design and manufacturing, commissioned design and manufacturing, and online purchase. The product data information of the cloud service platform falls into six types: basic product information, product ownership information, product three-dimensional model information, product manufacturing information, product transaction information and product design requirement information.
Basic product information includes but is not limited to: a) the product name; b) the trade mark and/or brand; c) the product category, which may be classified by use, by material and so on; d) the product description, for example information of every kind such as text, images, audio and video.
Product ownership information includes but is not limited to: a) the provider of the three-dimensional model, who can produce proof of copyright or of lawful authorization; b) the name of the shop, if any.
Product three-dimensional model information includes but is not limited to: a) the shape of the product; b) the dimensions of the product; c) the model file, for example a geometry file or a slice file.
Product manufacturing information includes but is not limited to: a) the raw material; b) the manufacturing process and/or equipment, including the type, the parameters and so on; c) the requirements on the appearance of the product, including colour, surface treatment method and surface roughness; d) the requirements on the performance of the product, including mechanical properties and machining accuracy.
Product transaction information includes but is not limited to: a) the price quoted for the product; b) the quantity purchased; c) the transaction amount; d) the delivery time; e) the delivery address and method.
Product design requirement information includes but is not limited to: a) the description of the functions of the product; b) the requirements on the dimensions of the product; c) the requirements on the appearance of the product, that is colour, surface treatment method and so on; d) the performance of the product, that is mechanical properties, accuracy and so on; e) the time by which the design is to be completed; f) the mode of delivery; g) the price quoted for the design.
5 Protection levels of product data information
According to how important the product data information is, it is divided into three protection levels: level I is the strictest protection level, used for the protection of core data information, and information at this level cannot be disclosed; level II is a strict protection level, used for the protection of important data information, and the party entitled to the information at this level chooses for itself whether to make it public; level III is the ordinary protection level, used for the protection of general data information, and information at this level is normally made public.
The recommended protection levels of the product data information are given in Table 1. Basic product information, that is the product name, the trade mark and/or brand, the product category and the product description, is level III. Within product ownership information, the name of the shop and similar items are level III while the provider of the three-dimensional model is level II. Within product three-dimensional model information, the shape and the dimensions of the product are level III while the model file is level I. Within product manufacturing information, the raw material, the manufacturing process and/or equipment as regards the type, the requirements on the appearance of the product and the requirements on its performance are level III, while the manufacturing process and/or equipment as regards the parameters is level II. Within product transaction information, the price quoted for the product is level III while the quantity purchased, the transaction amount and similar items are level II. Product design requirement information, that is the description of the functions of the product, the requirements on its dimensions, the requirements on its appearance, its performance, the time by which the design is to be completed, the mode of delivery and the price quoted for the design, is level II.
6.1 General
The processing of product data information can be divided into five stages, collection, storage, presentation, transfer and deletion: a) the collection stage means the extraction, recording and labelling by the cloud service platform of the three-dimensional models and other product data information uploaded by the provider of the three-dimensional model; b) the storage stage means the storage operations carried out by the cloud service platform on the product data information it has collected; c) the presentation stage means the display on the platform of the product data information it has collected; d) the transfer stage means the sending by the cloud service platform of the product data information it has collected to the additive manufacturing production service provider or another receiver of the three-dimensional model; e) the deletion stage means the deletion by the cloud service platform of the product data information it has collected.
Different product data information protection strategies shall be used according to the protection level of the type of product data information concerned and according to the stage.
6.2 Collection stage
The infrastructure of the cloud service platform shall comply with the security requirements of GB/T 39403, and the cloud service provider should have passed classified protection certification.
At the product data information collection stage the cloud service platform shall follow the principles of lawfulness, legitimacy and necessity, and shall not collect information that has no direct or reasonable connection with the services it provides, or that goes beyond the period to which the subject of the sensitive data and information has expressly consented.
6.3 Storage stage
The cloud service platform shall take security measures for the storage of product data information, so as to prevent the unlawful spreading and the theft of the information.
For sensitive product data information at level I and level II, security measures such as encryption, secure storage, access control and security auditing shall be used, and the storage period agreed with the subject of the sensitive data information shall not be exceeded.
6.4 Presentation stage
When a consumer selects on the cloud service platform the goods that suit its needs, the platform should provide an online function for browsing the appearance of the three-dimensional model of the product, helping the consumer to examine the details of the product from different viewpoints.
For level I product data information, the calls, the transmission and the presentation between the server side and the client side shall use product data protection techniques such as, but not limited to, model encryption and browsing of a simplified model, so as to ensure the security of the three-dimensional models and of other sensitive product data information.
For level II product data information, the party entitled to the data information chooses for itself whether to make it public. For level III product data information, information at this level is normally made public.
6.5 Transfer stage
When the cloud service platform transmits data to a receiver of the three-dimensional model, it shall take security measures as required and shall agree them in writing.
Level I product data information shall receive particular protection: when the cloud service platform, or the consumer, and the receiver of the three-dimensional model transmit product data information they should use a secure connection and secure transmission techniques such as encryption, blockchain and the sending of a stream of slice data, so as to guarantee the security of the three-dimensional models and of other sensitive product data information.
When the receiver of the three-dimensional model stores the data, it shall likewise take security measures as required and agree them in writing.
6.6 Deletion stage
For the product data information used at the collection, storage, presentation and transfer stages, the cloud service platform shall provide an automatic or a manual deletion function. The deletion function provided by the cloud service platform shall be capable of deleting the data completely, so that the deleted product data information cannot be recovered.
When a consumer or a designer asks for deletion by electronic mail, fax, written application or another means, or when the cloud service platform has kept the product data information beyond the time agreed between the two parties, the platform shall delete the product data information completely.
7 Verification methods
The cloud service platform shall draw up the general policy and the strategic measures for the protection of product data information according to the different protection levels and the processing stages of that information, and shall publish or declare the necessary matters.
When quality testing of product data protection is carried out, a test plan shall be prepared first, containing but not limited to the following. a) The test environment, that is the resources needed for the test, including hardware, software and network. b) The test content, which shall cover the corresponding functions of the cloud service platform according to the protection levels and the protection requirements of the product data information, giving the test plan, a description of the test process, and the test results and their assessment. c) The test cases, including their names, numbers, requirements, test steps and data. d) The test methods, including the techniques, means and tools used and the main limitations. e) The test personnel, who shall be familiar with additive manufacturing technology and with cloud service platforms and shall be allocated their tasks sensibly. f) Risk assessment, that is risk analysis and assessment of the testing work in relation to the focus of the tests at each stage.
8 Responsibilities and obligations of the different parties
Responsibilities and obligations of the provider of product data information. The provider of product data information shall be responsible for the compliance of the circulation and use of the three-dimensional model data it provides, and its responsibilities and obligations include but are not limited to: a) it shall ensure that the three-dimensional models it provides do not involve information whose publication or transmission is prohibited by laws or administrative regulations; b) it shall ensure that the three-dimensional models it provides are covered by copyright or lawful authorization and are not copied unlawfully from a third party, and shall guarantee that no content it publishes infringes the intellectual property rights of a third party.
Responsibilities and obligations of the receiver of product data information. The responsibilities and obligations of the receiver of product data information for product data protection include but are not limited to: a) it shall implement the laws, administrative regulations and codes of conduct relating to the protection of personal information and shall of its own accord safeguard the intellectual property rights and lawful interests of the subject of the product information; b) it shall respect the ownership of three-dimensional models held by others, using them only for the specific authorized purpose and not for any other purpose; c) it shall collect, process, keep, transmit and delete the data lawfully for the agreed business purpose, and shall take appropriate protective measures to prevent the data from being used or leaked without authorization.
Responsibilities and obligations of the cloud service platform. The responsibilities and obligations of the cloud service platform for product data protection include but are not limited to: a) it shall implement the laws, administrative regulations and codes of conduct relating to the protection of personal information and shall of its own accord safeguard the intellectual property rights and lawful interests of the subject of the product information; b) it shall draw up a product data protection policy for the platform in accordance with laws and administrative regulations, so as to safeguard the lawful interests of the parties to a transaction; c) it shall set up a product data protection management department responsible for the day-to-day management and implementation of product data protection on the platform; d) it shall draw up a product data protection management system that makes clear the duties and obligations of the platform and of the parties to a transaction, together with the penalties; e) it shall organize publicity and training activities on product data protection; f) it shall strengthen the management of data review and, on finding information whose publication or dissemination is prohibited by laws or administrative regulations, take the necessary measures according to law and report to the competent authorities.
......
This preview omits tables, figures, formulas and parts of the technical clauses. The complete document — 17 pages — is available in the English PDF.
Referenced standards
Normative references
GB/T 35351 Additive manufacturing - Terminology; GB/T 37461 Additive manufacturing - Specification for cloud service platform mode; GB/T 39403 Security protection management requirements for cloud manufacturing service platforms.
How to Buy GB/T 44909-2024
- 1Add to cart. Click the "Buy GB/T 44909-2024" button on this page. You can add more standards before checkout.
- 2Checkout. Enter your email and billing details. Payment is processed securely by Stripe (cards, Apple Pay, Google Pay supported).
- 3Instant delivery (0–9 sec). Delivery is automatic: within seconds of payment you'll receive an email with a secure download link. The link stays valid for 72 hours.
- 4Invoice included. A tax invoice is attached to the confirmation email. Need a custom invoice? Contact us.
Related Standards
GB/T 47310-2026 — Determination of total silicon, aluminium, iron, potassium, sodium, calcium, magnesium, manganese, phosphorus, titanium and sulfur in soil - Monochromatic excitation energy dispersive X-ray fluorescence spectrometry
GB/T 47321-2026 — Specification for the warning data exchange of the national emergency early warning dissemination system
GB/T 47293-2026 — Determination of available mercury in soil
Secure payment via Stripe
Payments accepted
GB/T 44909-2024
$215.00