A method for secure maritime information transmission based on the VDES system
By classifying maritime information transmission and designing a unique identity authentication and key distribution process, the problem of information transmission security in the VDES system is solved, and the secure transmission of maritime information is realized.
Patent Information
- Application Number
- CN202211644444.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-20
- Publication Date
- 2025-08-01
- Estimated Expiration
- 2042-12-20
AI Technical Summary
After the existing AIS system is upgraded to VDES, information transmission is still open, resulting in the inability to guarantee information security.
Classify maritime information transmission, and design unique identity authentication and key distribution processes for each category, including point-to-point communication between ordinary ships and special ships, and point-to-point communication between special ships to ensure the security of information transmission.
It realizes the secure transmission of maritime information, solves the problem that secret keys and data are easily intercepted in the same channel transmission, and realizes the effect of on-demand encryption.
Smart Images

Figure CN116017450B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of maritime communication, and more particularly, to a method for secure transmission of maritime information based on the VDES system. Background Art
[0002] With the continuous increase in the number of ships and the emergence of ultra-large integrated service ports, the load of the AIS system is constantly increasing and gradually unable to meet the needs of maritime communication. The International Maritime Organization is promoting the upgrade of AIS to VDES. VDES is based on a complete inheritance of AIS, with the addition of special application messages ASM and very high frequency data interaction VDE channels. The network communication rate has also increased from 9.6 kbps of the AIS channel to 19.2 kbps of ASM and 307.2 kbps of VDE. Although the communication rate of the ASM and VDE channels has been greatly improved, the information transmission still continues the open mode of the AIS system, and the security of information transmission cannot be guaranteed. Summary of the Invention
[0003] In view of the above technical problems, a method for secure transmission of maritime information based on the VDES system is provided. The present invention first classifies the secure information transmission, and then separately designs the identity authentication and key distribution processes for each category, which not only solves the problem that the key and data are easily intercepted when transmitted through the same channel, but also solves the problem of data encryption on demand, and realizes the secure transmission of maritime information.
[0004] The technical means adopted by the present invention are as follows:
[0005] A method for secure transmission of maritime information based on the VDES system, comprising:
[0006] Classifying the secure information transmission, namely point-to-point communication between ordinary ship A and special ship B initiated by ordinary ship A, point-to-point communication between special ship B and ordinary ship A initiated by special ship B, and point-to-point communication between special ship B and special ship C;
[0007] According to the category of point-to-point communication between ordinary ship A and special ship B initiated by ordinary ship A, separately design the identity authentication and key distribution processes;
[0008] According to the category of point-to-point communication between special ship B and ordinary ship A initiated by special ship B, separately design the identity authentication and key distribution processes;
[0009] According to the category of point-to-point communication between special ship B and special ship C, separately design the identity authentication and key distribution processes.
[0010] Further, the separately designing the identity authentication and key distribution processes according to the category of point-to-point communication between ordinary ship A and special ship B initiated by ordinary ship A includes:
[0011] Before communication, ordinary ship A generates a public and private key pair for ordinary ship A using the ship's own MMSI code, and broadcasts the generated public key to surrounding ships regularly or irregularly through the AIS channel or the ASM channel;
[0012] After receiving the broadcast information on the AIS channel or the ASM channel, special ship B parses the received information and checks for the presence of a public key. After collecting the public keys broadcast by surrounding ships, it establishes its own ship identity authentication list and dynamically maintains the authentication list;
[0013] Ordinary ship A sends a communication request to special ship B on the VDE channel. After special ship B agrees to the communication request, it queries its own ship identity authentication list and performs one-way identity authentication on ordinary ship A;
[0014] After successful authentication, special ship B generates a public and private key pair using its own MMSI code, and sends the public key to the ordinary ship A that requested communication through the AIS channel or the ASM channel, and starts point-to-point communication;
[0015] During point-to-point communication, ordinary ship A decrypts the received data using its own private key, encrypts the data to be sent using the public key of special ship B, special ship B decrypts the received data using its own private key, and encrypts the data to be sent using the public key of ordinary ship A;
[0016] After the information transmission is completed, ordinary ship A and special ship B respectively end the communication process of this secure information.
[0017] Furthermore, for the category of point-to-point communication initiated by special ship B with ordinary ship A, an identity authentication and key distribution process is designed separately, including:
[0018] Before communication, special ship B sends an addressing message to ordinary ship A through the AIS channel or the ASM channel, and confirms the identity of ordinary ship A through the received response message;
[0019] Special ship B generates a public and private key pair using its own MMSI code, and sends the public key to ordinary ship A through the AIS channel or the ASM channel;
[0020] Ordinary ship A generates a public and private key pair using its own MMSI code, and sends the public key to special ship B through the AIS channel or the ASM channel;
[0021] Special ship B authenticates the identity of ordinary ship A through its own ship identity authentication list, and starts point-to-point communication after successful authentication;
[0022] During point-to-point communication, the special ship B uses its own private key to decrypt the received data and uses the public key of the ordinary ship A to encrypt the sent data. The ordinary ship A uses its own private key to decrypt the received data and uses the public key of the special ship B to encrypt the sent data.
[0023] After the information transmission is completed, the special ship B and the ordinary ship A respectively end the communication process of the safety information.
[0024] Furthermore, based on the point-to-point communication between special ship B and special ship C, a separate identity authentication and key distribution process is designed, including:
[0025] Before communication, special ship B sends an addressing message to special ship C via the AIS channel or ASM channel, and confirms its identity through the reply message of special ship C;
[0026] The special ship C sends an addressing message to the special ship B via the AIS channel or the ASM channel, and confirms its identity through the response message of the special ship B.
[0027] Special ship B uses its own MMSI code to generate a public key and private key pair, and sends the public key to special ship C via the AIS channel or ASM channel;
[0028] Special ship C generates a public key and private key pair using its own MMSI code, and sends the public key to special ship B via the AIS channel or ASM channel;
[0029] Special ship B and special ship C authenticate each other's identity using their own identity authentication lists, and then begin point-to-point communication.
[0030] In point-to-point communication, special ship B uses its own private key to decrypt the received data and uses the public key of special ship C to encrypt the sent data. Special ship C uses its own private key to decrypt the received data and uses the public key of special ship B to encrypt the sent data.
[0031] After the information transmission is completed, special ship B and special ship C respectively end the communication process of this safety information.
[0032] Compared with the prior art, the present invention has the following advantages:
[0033] The VDES system-based method for secure maritime information transmission provided by the present invention first classifies secure information transmission and then designs an identity authentication and key distribution process for each category. This not only solves the problem of keys and data being easily intercepted when transmitted on the same channel, but also solves the problem of data encryption on demand, thereby realizing secure transmission of maritime information.
[0034] Based on the above reasons, the present invention can be widely promoted in the fields of maritime communication and the like. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0036] Figure 1 It is a flowchart of the method of the present invention.
[0037] Figure 2 It is a flowchart of the point-to-point communication initiated by the ordinary ship A of the present invention with the special ship B.
[0038] Figure 3 It is a flowchart of the point-to-point communication initiated by the special ship B of the present invention with the ordinary ship A.
[0039] Figure 4 It is a flowchart of the point-to-point communication between the special ship B and the special ship C of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0040] It should be noted that, without conflict, the embodiments in the present invention and the features in the embodiments can be combined with each other. The following will refer to the drawings and combine the embodiments to detail the present invention.
[0041] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. The following description of at least one exemplary embodiment is actually only illustrative and in no way limits the present invention and its application or use. Based on the embodiments in the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.
[0042] It should be noted that the terms used here are only for describing the specific embodiments and are not intended to limit the exemplary embodiments according to the present invention. As used here, unless the context clearly indicates otherwise, the singular form is also intended to include the plural form. In addition, it should be understood that when the terms "comprise" and / or "include" are used in this specification, they indicate the presence of features, steps, operations, devices, components, and / or combinations thereof.
[0043] Unless otherwise specifically stated, the relative arrangements, numerical expressions, and numerical values of the components and steps set forth in these embodiments do not limit the scope of the present invention. At the same time, it should be clear that, for the sake of convenience in description, the dimensions of the various parts shown in the drawings are not drawn in actual proportional relationships. Technologies, methods, and devices known to those of ordinary skill in the relevant art may not be discussed in detail, but where appropriate, the said technologies, methods, and devices should be regarded as part of the authorization specification. In all the examples shown and discussed here, any specific values should be construed as merely exemplary and not as a limitation. Therefore, other examples of the exemplary embodiments may have different values. It should be noted that: like reference numerals and letters denote like items in the following drawings, and thus, once an item is defined in one drawing, it does not need to be further discussed in subsequent drawings.
[0044] In the description of the present invention, it should be understood that the orientation or positional relationships indicated by orientation words such as "front, rear, upper, lower, left, right", "lateral, vertical, perpendicular, horizontal", and "top, bottom", etc. are generally based on the orientation or positional relationships shown in the drawings. It is only for the convenience of describing the present invention and simplifying the description. Without contrary statements, these orientation words do not indicate and imply that the devices or elements referred to must have a specific orientation or be constructed and operated in a specific orientation. Therefore, they should not be construed as limiting the protection scope of the present invention: the orientation words "inside, outside" refer to the inside and outside relative to the contour of each component itself.
[0045] For the convenience of description, spatial relative terms such as "above...", "over...", "on the upper surface of...", "upper...", etc. can be used here to describe the spatial positional relationships of one device or feature with other devices or features as shown in the drawings. It should be understood that the spatial relative terms are intended to include different orientations in use or operation in addition to the orientations described in the drawings of the devices. For example, if the device in the drawing is inverted, the device described as "above other devices or structures" or "over other devices or structures" will then be positioned as "below other devices or structures" or "under other devices or structures". Thus, the exemplary term "above..." can include both the orientations of "above..." and "below...". The device can also be positioned in other different ways (rotated 90 degrees or in other orientations), and corresponding interpretations should be made for the spatial relative descriptions used here.
[0046] In addition, it should be noted that the use of words such as "first", "second", etc. to limit components is only for the convenience of differentiating the corresponding components. Without additional statements, the above words have no special meanings. Therefore, they should not be construed as limiting the protection scope of the present invention.
[0047] Such as Figure 1As shown in the figure, the present invention provides a method for secure maritime information transmission based on the VDES system, including:
[0048] S1. Classify the secure information transmission, namely, point-to-point communication initiated by ordinary ship A with special ship B, point-to-point communication initiated by special ship B with ordinary ship A, and point-to-point communication between special ship B and special ship C;
[0049] S2. According to the category of point-to-point communication initiated by ordinary ship A with special ship B, separately design the identity authentication and key distribution processes;
[0050] S3. According to the category of point-to-point communication initiated by special ship B with ordinary ship A, separately design the identity authentication and key distribution processes;
[0051] S4. According to the category of point-to-point communication between special ship B and special ship C, separately design the identity authentication and key distribution processes.
[0052] Specifically, as a preferred implementation manner of the present invention, in step S2, according to the category of point-to-point communication initiated by ordinary ship A with special ship B, separately design the identity authentication and key distribution processes, as Figure 2 shown, including:
[0053] S21. Before communication, ordinary ship A generates a public key and a private key pair for ordinary ship A using the MMSI code of the ship itself, and broadcasts the generated public key to surrounding ships regularly or irregularly through the AIS channel or the ASM channel;
[0054] S22. After receiving the broadcast information on the AIS channel or the ASM channel, special ship B parses the received information and searches for whether it contains a public key. After collecting the public keys broadcast by surrounding ships, special ship B establishes its own identity authentication list and dynamically maintains the authentication list;
[0055] S23. Ordinary ship A sends a communication request to special ship B on the VDE channel. After special ship B agrees to the communication request, special ship B queries its own identity authentication list and performs one-way identity authentication on ordinary ship A;
[0056] S24. After the authentication is passed, special ship B generates a public key and a private key pair using its own MMSI code, and sends the public key to the ordinary ship A requesting communication through the AIS channel or the ASM channel, and starts point-to-point communication;
[0057] S25. During point-to-point communication, ordinary ship A decrypts the received data using its own private key, encrypts the sent data using the public key of special ship B, special ship B decrypts the received data using its own private key, and encrypts the sent data using the public key of ordinary ship A;
[0058] After the information transmission is completed, the ordinary ship A and the special ship B respectively end the communication process of this safety information.
[0059] In specific implementation, as a preferred implementation manner of the present invention, in step S3, according to the category of point-to-point communication initiated by the special ship B with the ordinary ship A, an identity authentication and key distribution process is separately designed, such as Figure 3 shown, including:
[0060] S31: Before communication, the special ship B sends an addressing message to the ordinary ship A through the AIS channel or the ASM channel, and authenticates the ordinary ship A through the received response message;
[0061] S32: The special ship B generates a public key and private key pair using its own MMSI code, and sends the public key to the ordinary ship A through the AIS channel or the ASM channel;
[0062] S33: The ordinary ship A generates a public key and private key pair using its own MMSI code, and sends the public key to the special ship B through the AIS channel or the ASM channel;
[0063] S34: The special ship B authenticates the identity of the ordinary ship A through its own identity authentication list. After the authentication is passed, the point-to-point communication starts;
[0064] S35: During point-to-point communication, the special ship B decrypts the received data using its own private key, encrypts the sent data using the public key of the ordinary ship A, the ordinary ship A decrypts the received data using its own private key, and encrypts the sent data using the public key of the special ship B;
[0065] S36: After the information transmission is completed, the special ship B and the ordinary ship A respectively end the communication process of this safety information.
[0066] In specific implementation, as a preferred implementation manner of the present invention, in step S4, according to the category of point-to-point communication between the special ship B and the special ship C, an identity authentication and key distribution process is separately designed, such as Figure 4 shown, including:
[0067] S41: Before communication, the special ship B sends an addressing message to the special ship C through the AIS channel or the ASM channel, and authenticates its identity through the response message of the special ship C;
[0068] S42: The special ship C sends an addressing message to the special ship B through the AIS channel or the ASM channel, and authenticates its identity through the response message of the special ship B.
[0069] S43. Special ship B generates a public and private key pair using its own MMSI code, and sends the public key to special ship C via the AIS channel or the ASM channel;
[0070] S44. Special ship C generates a public and private key pair using its own MMSI code, and sends the public key to special ship B via the AIS channel or the ASM channel;
[0071] S45. Special ship B and special ship C respectively authenticate the identity of the other party through their own identity authentication lists. After successful authentication, point-to-point communication begins;
[0072] S46. During point-to-point communication, special ship B decrypts the received data using its own private key, encrypts the data to be sent using the public key of special ship C, special ship C decrypts the received data using its own private key, and encrypts the data to be sent using the public key of special ship B;
[0073] S47. After the information transmission is completed, special ship B and special ship C respectively end the communication process of this secure information.
[0074] In summary, the above method provided by the present invention not only solves the problem that the secret key and data are easily intercepted when transmitted through the same channel, but also solves the problem of data encryption on demand, realizing the secure transmission of maritime information.
[0075] Finally, it should be noted that: the above embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some or all of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the present invention.
Claims
1. A method for secure maritime information transmission based on the VDES system, characterized in that, Including: Classify the transmission of security information, namely point-to-point communication initiated by ordinary ship A with special ship B, point-to-point communication initiated by special ship B with ordinary ship A, and point-to-point communication between special ship B and special ship C; According to the category of point-to-point communication initiated by ordinary ship A with special ship B, separately design the identity authentication and key distribution processes, including: Before communication, ordinary ship A generates a public key and private key pair using its own MMSI code of the ship, and broadcasts the generated public key to surrounding ships regularly or irregularly through the AIS channel or ASM channel; After special ship B receives the broadcast information on the AIS channel or ASM channel, it parses the received information and searches for the existence of the public key. After collecting the public keys broadcast by surrounding ships, it establishes its own ship identity authentication list and dynamically maintains the authentication list; Ordinary ship A sends a communication request to special ship B on the VDE channel. After special ship B agrees to the communication request, it queries its own ship identity authentication list and conducts one-way identity authentication on ordinary ship A; After the authentication is passed, special ship B generates a public key and private key pair using its own MMSI code of the ship, and sends the public key to ordinary ship A that requests communication through the AIS channel or ASM channel, and starts point-to-point communication; During point-to-point communication, ordinary ship A decrypts the received data using its own private key, encrypts the sent data using the public key of special ship B, special ship B decrypts the received data using its own private key, and encrypts the sent data using the public key of ordinary ship A; After the information transmission is completed, ordinary ship A and special ship B respectively end the communication process of this security information; According to the category of point-to-point communication initiated by special ship B with ordinary ship A, separately design the identity authentication and key distribution processes; According to the category of point-to-point communication between special ship B and special ship C, separately design the identity authentication and key distribution processes.
2. The maritime information security transmission method based on the VDES system according to claim 1, wherein The separately designed identity authentication and key distribution processes according to the category of point-to-point communication initiated by special ship B with ordinary ship A include: Before communication, special ship B sends an addressing message to ordinary ship A through the AIS channel or ASM channel, and confirms the identity of ordinary ship A through the received response message; Special ship B generates a public key and private key pair using its own MMSI code of the ship, and sends the public key to ordinary ship A through the AIS channel or ASM channel; Ordinary ship A generates a public key and private key pair using its own MMSI code of the ship, and sends the public key to special ship B through the AIS channel or ASM channel; Special ship B authenticates the identity of ordinary ship A through its own ship identity authentication list, and starts point-to-point communication after the authentication is passed; During point-to-point communication, special ship B decrypts the received data using its own private key, encrypts the sent data using the public key of ordinary ship A, ordinary ship A decrypts the received data using its own private key, and encrypts the sent data using the public key of special ship B; After the information transmission is completed, special ship B and ordinary ship A respectively end the communication process of this security information.
3. The method for secure maritime information transmission based on the VDES system according to claim 1, wherein According to the category of point-to-point communication between special ship B and special ship C, a separate identity authentication and key distribution process is designed, including: Before communication, special ship B sends an addressing message to special ship C through the AIS channel or the ASM channel, and performs identity confirmation through the response message of special ship C; Special ship C sends an addressing message to special ship B through the AIS channel or the ASM channel, and performs identity confirmation through the response message of special ship B; Special ship B generates a public key and private key pair using its own MMSI code, and sends the public key to special ship C through the AIS channel or the ASM channel; Special ship C generates a public key and private key pair using its own MMSI code, and sends the public key to special ship B through the AIS channel or the ASM channel; Special ship B and special ship C respectively authenticate the identity of the other party through their own identity authentication lists. After successful authentication, point-to-point communication begins; During point-to-point communication, special ship B decrypts the received data using its own private key, encrypts the sent data using the public key of special ship C, special ship C decrypts the received data using its own private key, and encrypts the sent data using the public key of special ship B; After the information transmission is completed, special ship B and special ship C respectively end the communication process of this security information.
Citation Information
Patent Citations
Intelligent ship identity verification and false identity early warning system based on ship digital certificate
CN115037465A