Instant Messaging and Social Network Operating System Based on Ship Digital Certificates

Through instant communication and social network operation systems based on ship digital certificates, the existing maritime communication system cannot meet the problem that the demand for sharply increased data exchange is solved, and efficient and secure information transmission of maritime navigation is achieved.

CN116506387BActive Publication Date: 2025-06-27WUHAN UNIV OF TECH
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202310384391.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-04-11
Publication Date
2025-06-27
Estimated Expiration
2043-04-11

AI Technical Summary

Technical Problem

The existing maritime communication systems cannot meet the sharply increasing data exchange needs, resulting in information loss or malicious tampering, and cannot ensure the safe navigation of ships and improve the efficiency of communication between ships.

Method used

It adopts an instant communication and social network operation system based on ship digital certificates, verifies the identity of the entity through digital certificates, realizes instant communication between ship-ship and ship-shore, and provides event reporting and notification services.

Benefits of technology

It improves the communication efficiency and security of maritime navigation, ensures the rapid, safe and flexible information transmission, and meets the diverse needs of users.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116506387B_ABST
    Figure CN116506387B_ABST
Patent Text Reader

Abstract

The present invention discloses an instant messaging and social network operation system based on ship digital certificates, which includes an operation platform, as well as a port terminal, a maritime supervision agency terminal, a shipping company terminal and a ship terminal that are connected to the operation platform through a communication network; the physical terminals and the operation platform apply for digital certificates from the maritime certificate authorization center and obtain private keys that match them, and the digital certificates are bound to the above-mentioned physical terminals; the physical terminals and the operation platform confirm each other's identities through the digital certificates; the physical terminals apply to the operation platform for and obtain a unique account by virtue of the digital certificates issued by the maritime certificate authorization center; the operation platform provides a variety of services to ensure the safety of ship navigation. The present invention binds the entity and the digital certificate, improving the communication efficiency and safety of maritime navigation.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of ship instant communication, and particularly to an instant communication and social network operation system based on ship digital certificates. Background Art

[0002] With the increasingly close economic ties among countries around the world, goods flow between countries. Due to the characteristics of low cost and large freight volume of maritime transportation, shipping has become the main way for goods to move between countries. The number of ships sailing at sea is increasing continuously, and the data exchange between ship-ship, ship-shore, and shore-ship shows an explosive growth. The link load of the existing AIS communication system has exceeded the standard proposed by the International Association of Marine Aids to Navigation and Lighthouse Authorities, and there are a large number of phenomena of information loss or malicious tampering, that is, the existing maritime communication system can no longer meet the current rapidly increasing data exchange requirements.

[0003] Therefore, there is an urgent need for a maritime communication system with faster and safer information transmission, more flexible information formats, and richer transmission content to ensure the safe navigation of ships, improve the efficiency of communication between ships, and meet the diverse needs of users. Summary of the Invention

[0004] The main purpose of the present invention is to provide an instant communication and social network operation system based on ship digital certificates to improve the communication efficiency and safety of maritime navigation.

[0005] The technical solution adopted by the present invention is: an instant communication and social network operation system based on ship digital certificates. The system includes an operation platform and four types of users. The users include ports, maritime supervision agencies, shipping companies, and ships. Each type of user entity has a unique entity terminal connected to the operation platform through a communication network, which is called a port terminal, a maritime supervision agency terminal, a shipping company terminal, and a ship terminal; the number of ship terminals is more than 1;

[0006] The entity terminals of the four types of users and the operation platform apply for digital certificates from the maritime certificate authorization center and obtain the corresponding private keys, and the digital certificates are bound to the above entity terminals; the identity of each other is confirmed between the entity terminals and the operation platform through the digital certificates; the four types of users need to trust the operation platform and submit their own digital certificates to the platform for identity verification before joining the operation platform. The entities and the operation platform that pass the verification obtain the digital certificates of each other; the entity terminals of the four types of users apply for and obtain a unique account from the operation platform by virtue of the digital certificates issued by the maritime certificate authorization center;

[0007] Each entity terminal uses a heartbeat mechanism to send heartbeat information to the operation platform at fixed intervals, and the operation platform judges the status of the entity terminal through the heartbeat information;

[0008] The entity terminal realizes instant communication between ship-ship and ship-shore through the operation platform. The instant communication methods are divided into point-to-point instant communication and group instant communication;

[0009] The operation platform mentioned above includes a server and a database. Among them, the server is used to conduct identity verification on each entity terminal based on its digital certificate, monitor the status of the entity terminal, provide the navigation dynamic information of other ships for each ship terminal, forward data between entity terminals, manage the trusted list and group list, including operations such as searching, adding, and deleting trusted parties and groups, report and announce water events, dynamically push navigable environment information, update and push electronic chart information, and update and push events related to navigation safety; the database is used to store the basic setting information, digital certificate, trusted party information, user group information, user static data exchange information, and configuration file information of the entity terminal.

[0010] According to the above solution, each entity terminal uses a heartbeat mechanism to send heartbeat information to the operation platform at fixed intervals. The operation platform judges the status of the entity terminal through the heartbeat information. Specifically:

[0011] The entity terminal sends a heartbeat packet to the operation platform at fixed intervals and signs the heartbeat packet with its own private key. After receiving the heartbeat packet, the server returns a heartbeat response to the entity terminal; the heartbeat information is used to verify the online status of the entity terminal and provide the basic information of the logged-in user for the server;

[0012] The heartbeat packet of ship terminal X contains the following information: IMO number IMO of the ship corresponding to ship terminal X X 、MMSI number MMSI X 、Real-time position information LOC X 、Speed over ground SOG X 、Course over ground COG X 、True course TC X And the timestamp TS of the message sending time point, where LOC X =(Lat X ,Long X ) is the longitude and latitude of the corresponding ship;

[0013] The representation form of the heartbeat packet sent by ship terminal X to the operation platform is as follows:

[0014] IMO X |MMSI X |LOC X |SOG X |COG X |TC X |TS|SIG X_Pri [Hash(IMO X |MMSIX |LOC X |SOG X |COG X |TC X |TS)], where SIG X_Pri [ ] means that the ship terminal X uses its own private key to sign the content in [ ], and Hash() means that the content in ( ) is hashed using the hashing algorithm;

[0015] The heartbeat packets of the entity terminals of the three types of users, namely the maritime supervision agency terminal, the shipping company terminal, and the port terminal, contain the following information: If the entity terminal Y is one of the above three types of entity terminals, NAME Y is the name of the headquarters, LOC Y is the location information of the headquarters, TS is the timestamp of the message sending time point, where LOC Y =(Lat Y , Long Y ) is the latitude and longitude of the entity terminal Y;

[0016] The representation form of the heartbeat packet sent by the entity terminal Y to the operation platform is as follows:

[0017] NAME Y |LOC Y |TS|SIG Y_Pri [Hash(NAME Y |LOC Y |TS)], where SIG Y_Pri [ ] means that the entity terminal Y uses its own private key to sign the content in [ ], and Hash() means that the content in ( ) is hashed using the hashing algorithm.

[0018] According to the above solution, the communication network is one or a combination of satellite communication and operator mobile network communication.

[0019] According to the above solution, the account of each entity terminal includes a digital certificate, a login account, and a user password; where the user password is set by the user himself / herself as the password for the user to log in to the operation platform, and is independent of the public key of the digital certificate obtained by the user and the matching private key; the user logs in to the operation platform through a secure Web service to complete the application for an account, the exchange of digital certificates, and the registration of other platform-related information.

[0020] According to the above solution, the operation platform provides location-based services. After each entity terminal accesses the operation platform, it periodically provides its own real-time location information to the operation platform. The operation platform will push the electronic nautical chart of the water area where it is located to the entity terminal, bind the identity information and geographical location information of each user, and display them on the electronic nautical chart;

[0021] Each ship terminal declares to the operation platform whether it is willing to disclose its identity information and geographical location information to other entity terminals; the maritime supervision agency terminal, the shipping company terminal, and the port terminal must disclose their identity information and geographical location information to other entity terminals.

[0022] Denote the first user group terminal UserTypeI as the ship terminal that has passed the review of the operation platform and is willing to disclose its location and identity. If the ship terminal X belongs to the first user group terminal UserTypeI, the dynamic information representation form of the ship terminal X is as follows:

[0023] IMO X |MMSI X |LOC X |SOG X |COG X |TC X |, where IMO X represents the IMO number of the corresponding ship, MMSI X represents the MMSI number of the corresponding ship, LOC X =(Lat X , Long X ) represents the latitude and longitude of the corresponding ship, SOG X represents the speed over ground of the corresponding ship, COG X represents the course over ground of the corresponding ship, TC X represents the true heading of the bow of the corresponding ship; this information will be displayed on the electronic nautical chart and updated in real time to all logged-in entity terminals;

[0024] Denote the second user group terminal UserTypeⅡ as the ship terminal that has passed the review of the operation platform and is not willing to disclose its location and identity. If the ship terminal X belongs to the second user group terminal UserTypeⅡ, its dynamic information representation form is as follows:

[0025] AM X |LOC X |SOG X |COG X |TC X |, where AM X represents the anonymous identifier of the corresponding ship, LOC X =(Lat X , Long X ) represents the latitude and longitude of the corresponding ship, SOG X represents the speed over ground of the corresponding ship, COG X represents the course over ground of the corresponding ship, TC XIndicates the true heading of the bow of the corresponding ship; this information will be displayed on the electronic chart and updated in real time to all logged-in entity terminals;

[0026] Denote the terminal of the third user group UserTypeⅢ as the terminals of maritime regulatory agencies, shipping companies, and ports that have passed the review of the operation platform. All terminals of the third user group UserTypeⅢ need to disclose their identity information and geographical location information to other entity terminals. If entity terminal X belongs to the terminal of the third user group UserTypeⅢ, its static information representation is as follows:

[0027] NAME X |LOC X |, where NAME X Indicates the headquarters name of the corresponding entity, and LOC X =(Lat X , Long X ) indicates the static location information of the headquarters of the corresponding entity; this information will be displayed on the electronic chart and updated regularly to all logged-in entity terminals.

[0028] According to the above scheme, the system also includes a trust relationship establishment module between entity terminals, which is used for entity terminals to apply for trust with each other by digital certificates and maintain a mutual trust relationship after mutual confirmation. Specifically:

[0029] Entity terminal A applies for trust to entity terminal B, signs the trust application package with its own private key, and then forwards it to entity terminal B through the server of the operation platform;

[0030] Entity terminal B receives the trust application package and verifies the authenticity of the identity of entity terminal A by virtue of the digital certificate of entity terminal A; if entity terminal B confirms to establish a trust relationship with entity terminal A, it returns a trust response package to entity terminal B, grants trust to entity terminal A, signs the trust response package with the private key of entity terminal B and forwards it to entity terminal A through the server of the operation platform, thus establishing a trust relationship between the two;

[0031] Two entity terminals that have established a trust relationship with each other establish data exchange through the forwarding of the operation platform. The data exchange includes text information and file transfer, and real-time audio and video are established under the condition that the network communication quality permits; regardless of whether it belongs to the terminal of the first user group UserTypeI, each other can see the dynamic location, heading, and identity information of the other on the electronic chart;

[0032] The representation form of the trust application package sent by entity terminal A to entity terminal B is as follows:

[0033] Cert A |TrustApply|TS|SIGA _ Pri [Hash(Cert A |TrustApply|TS)], where Cert A represents the digital certificate of entity terminal A, TrustApply represents the application trust identifier, TS represents the timestamp of the message sending time point, and SIG A _ Pri [] indicates that entity terminal A uses its own private key to sign the content in [], and Hash() indicates that the content in () is hashed using the hash algorithm;

[0034] The trust response packet returned by entity terminal B to entity terminal A is represented as follows:

[0035] Cert B |TrustGrant|TS|SIG B _ Pri [Hash(Cert B |TrustGrant|TS)], where Cert B represents the digital certificate of entity terminal B, TrustGrant represents the granted trust identifier, TS represents the timestamp of the message sending time point, and SIG B _ Pri [] indicates that entity terminal B uses its own private key to sign the content in [], and Hash() indicates that the content in () is hashed using the hash algorithm;

[0036] According to the above solution, the peer-to-peer instant messaging includes an encryption mode and a non-encryption mode; among them,

[0037] 1) Encryption mode peer-to-peer instant messaging:

[0038] Each instant messaging entity terminal logs in to the server through the registered user ID and password. The information sender uses its own private key to sign the sent information, uses the public key of the information receiver terminal to encrypt the sent information, generates a ciphertext packet and sends it to the server. The ciphertext packet is forwarded to the information receiver terminal by the server. After the receiver terminal decrypts it, it obtains the plaintext of the message, completing the peer-to-peer instant messaging process;

[0039] The ciphertext packet sent from the information sender terminal to the information receiver terminal is represented as follows:

[0040] ENC Rec _ Pub [message|TS|SIG Send _ Pri[Hash(message|TS)], where message represents the transmitted information, ENC Rec _ Pub [] means encrypting the content in [] using the public key of the information recipient's terminal, SIG Send _ Pri [] means signing the content in [] using the private key of the information sender's terminal, Hash() means hashing the content in () using the hash algorithm, and TS represents the timestamp at the time point of message sending; the symmetric key can also be negotiated in the above way to speed up the calculation speed of encryption and decryption;

[0041] 2) Peer-to-peer instant messaging in non-encrypted mode:

[0042] Each entity terminal for instant messaging logs in to the server through the registered user ID and password. The information sender terminal signs the sent information using its own private key, generates a message packet and sends it to the server. The message packet is forwarded by the server to the information recipient terminal to complete the peer-to-peer instant messaging process;

[0043] The message packet sent by the information sender terminal to the information recipient terminal is represented as follows:

[0044] message|TS|SIG Send _ Pri [Hash(message|TS)], where message represents the transmitted information, SIG Send _ Pri [] means signing the content in [] using the private key of the information sender's terminal, Hash() means hashing the content in () using the hash algorithm, and TS represents the timestamp at the time point of message sending.

[0045] According to the above scheme, the group instant messaging includes the processes of creating a group, joining a group, and transmitting information within the group; among them,

[0046] ① Creating a group: Each entity terminal for instant messaging logs in to the server through the registered user ID and password. Entity terminal A sends a group creation request to the operation platform and signs the group creation request using its own private key; after receiving the request, the operation platform returns a response message to entity terminal A and grants a group, and then signs the response message using its own private key to complete the creation of the group, where entity terminal A is the creator of the group;

[0047] The group creation request sent by entity terminal A to the operation platform is represented as follows:

[0048] GroupApply|TS|SIG A _Pri [Hash(GroupApply|TS)], where GroupApply represents the message identifier for the application to create a group request, and SIG A _ Pri [] means signing the content in [] using the private key of entity terminal A, Hash() means hashing the content in () using a hashing algorithm, and TS represents the timestamp at the time point of message sending;

[0049] The response information returned by the operation platform to entity terminal A is represented as follows:

[0050] GroupGrant|GroupID|TS|SIG P _ Pri [Hash(GroupGrant|GroupID|TS)], where GroupGrant represents the message identifier for the operation platform to grant a group, GroupID represents the group account granted by the operation platform, and SIG P _ Pri [] means signing the content in [] using the private key of the operation platform, Hash() means hashing the content in () using a hashing algorithm, and TS represents the timestamp at the time point of message sending;

[0051] ② Joining a group: After the group is created, there are two ways to join the group, namely, being invited into the group by a group member and joining the group by searching for the group ID;

[0052] Any member within the group can invite members in their trusted list to join the group. Entity terminal A finds entity terminal B that it wants to invite into the group through the search function and sends an invitation request to join the group to entity terminal B. Entity terminal A signs the invitation information using its own private key and forwards it through the server to send the invitation request to entity terminal B. If entity terminal B confirms to join the group, it sends a response message to entity terminal A and signs it using its own private key, thus joining the group;

[0053] The invitation information sent by entity terminal A to entity terminal B to join the group is represented as follows:

[0054] InviteGroup|GroupID|TS|SIG A _ Pri [Hash(InviteGroup|GroupID|TS)], where InviteGroup represents the invitation identifier to join the group, GroupID represents the group ID, TS represents the timestamp at the time point of message sending, and SIG A _ Pri[] indicates that the content in [] is signed using the private key of entity terminal A, and Hash() indicates that the content in () is hashed using a hashing algorithm;

[0055] The response message returned by entity terminal B to entity terminal A is expressed as follows:

[0056] JoinGroup|TS|SIG B _ Pri [Hash(JoinGroup|TS)], where JoinGroup represents the confirmation of the group joining identifier, TS represents the timestamp of the message sending time point, and SIG B _ Pri [] indicates that the content in [] is signed using the private key of entity terminal B, and Hash() indicates that the content in () is hashed using a hashing algorithm;

[0057] All entity terminals approved by the operation platform can join the group by searching for the group ID; after entity terminal C, which has been reviewed by the operation platform, finds the group it wants to join through the group ID, it sends a group joining request to the group creator terminal, signs it with its own private key, and forwards it to the group creator terminal through the server; the group creator terminal verifies the authenticity of its identity based on the digital certificate of entity terminal C. If it agrees to entity terminal C to join the group, it returns a response packet to entity terminal C, and entity terminal C can then join the group;

[0058] The group joining request message sent by entity terminal C to the group creator terminal is expressed as follows:

[0059] Cert C |GroupID|TS|SIG C _ Pri [Hash(Cer C |GroupID|TS)], where Cert C represents the digital certificate of entity terminal C, GroupID represents the group ID, TS represents the timestamp of the message sending time point, and SIG C _ Pri [] indicates that entity terminal C signs the content in [] using its own private key, and Hash() indicates that the content in () is hashed using a hashing algorithm;

[0060] The response packet returned by the group creator terminal to entity terminal C is expressed in the following form:

[0061] AgreeGroup|GroupID|TS|SIG GO _ Pri[Hash(AgreeGroup|GroupID|TS)], where AgreeGroup represents the identifier for agreeing to join the group, GroupID represents the group ID, TS represents the timestamp of the message sending time point, SIG GO _ Pri [] means using the private key of the group creator's terminal to sign the content in [], and Hash() means using the hashing algorithm to perform hashing on the content in ();

[0062] When a user joins or exits the group, the operation platform updates the group member list for each entity terminal in the group and signs it with its own private key; The information for updating the group member list sent by the operation platform to each member terminal in the group is expressed as follows:

[0063] MemberList|TS|SIG P _ Pri [Hash(MemberList|TS)], where MemberList represents the group member list, SIG P _ Pri [] means using the private key of the operation platform to sign the content in [], Hash() means using the hashing algorithm to perform hashing on the content in (), and TS represents the timestamp of the message sending time point;

[0064] ③ Information transmission within the group: After joining the group, each member terminal within the group can communicate within the group. The information sent by the member terminal within the group uses the private key of the sender terminal to sign the sent information, generates a group message packet and sends it to the server, and the group message packet is forwarded by the server to other recipient terminals within the group to complete the group instant messaging process;

[0065] The form of the group message packet sent by the information sender terminal to the operation platform is as follows:

[0066] message|TS|SIG Send _ Pri [Hash(message|TS)], where message represents the transmitted information, SIG Send _ Pri [] means using the private key of the information sender terminal to sign the content in [], Hash() means using the hashing algorithm to perform hashing on the content in (), and TS represents the timestamp of the message sending time point.

[0067] According to the above solution, the reporting and notification of the said events specifically include:

[0068] The operation platform is provided with an event reporting port for reporting to the operation platform when the ship encounters extreme weather suddenly during navigation, when the ship itself has a maritime accident, when the ship observes that other ships have maritime accidents, and any event that may affect the safe navigation of the ship. The report is accompanied by the user's signature;

[0069] The operation platform is provided with a certain event approval mechanism for verifying the authenticity of the report. If it passes the verification, it will be pushed to other entity terminals, and the publisher of the information will be attached. The platform can establish certain exemption clauses to avoid disputes caused by the authenticity of user reports;

[0070] According to the above solution, the operation platform is provided with a value-added service module, which is ordered by the entity terminal according to its own needs; the value-added service module includes news push, advertisement push, etc.

[0071] The beneficial effects of the present invention are: binding the entity with the digital certificate, verifying the legality of the entity's identity and the authenticity of the information source through the asymmetric encryption and hash algorithms adopted by the digital certificate; the approved entity terminals can conduct point-to-point and group instant messaging, and the information format is flexible and the transmission speed is fast; in addition, the operation platform provides reporting and notification services for water events, providing an important guarantee for maritime navigation safety. Brief Description of the Drawings

[0072] The present invention will be further described below in conjunction with the drawings and embodiments. In the drawings:

[0073] Figure 1 is a schematic structural diagram of an embodiment of the present invention.

[0074] In the figure: 1 - operation platform, 2 - port, 3 - maritime supervision agency, 4 - shipping company, 5 - ship. Detailed Embodiment

[0075] In order to make the purpose, technical solution and advantages of the present invention clearer, the present invention will be further described in detail below in conjunction with the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0076] As Figure 1As shown in the figure, the instant messaging and social network operation system based on ship digital certificates of the present invention is provided with an operation platform 1 and four types of users. The users include ports 2, maritime supervision agencies 3, shipping companies 4, and ships 5. Among them, the operation platform 1 includes a database module and a server module. Each type of user includes multiple entities. Taking ship users as an example, there are n ships 5 (entities) in the figure, namely ship 5-1, ship 5-2... ship 5-n. The operation platform 1 is generally deployed as a shore-based service, and each entity terminal can maintain a network connection with the operation platform through a certain communication means (such as satellite communication, operator mobile network communication, but not limited to this).

[0077] The entity terminals of the four types of users and the operation platform apply for digital certificates from the Maritime Certificate Authority (MCA) and obtain the matching private keys. The digital certificates are bound to the above-mentioned entity terminals; the digital certificates contain the following information: ① the identity information of the certificate owner ② the public key of the certificate owner ③ the serial number of the certificate ④ the valid time of the certificate ⑤ the name of the institution issuing the certificate and the digital signature of the institution. The four types of entity terminals and the operation platform confirm each other's identities through digital certificates; the four types of users need to trust the operation platform. Before joining the operation platform, they submit their own digital certificates to the platform for identity verification. The entities and the operation platform that pass the verification obtain each other's digital certificates; the entity terminals of the four types of users apply for and obtain a unique account from the operation platform by virtue of the digital certificates issued by the Maritime Certificate Authority.

[0078] The account of each entity terminal includes a digital certificate, a login account, and a user password; among them, the user password is set by the user himself / herself and is used as the password for the user to log in to the operation platform, which is independent of the public key of the digital certificate obtained by the user and the matching private key; the user logs in to the operation platform through a secure Web service (such as the SSL protocol) to complete the application for the account, the exchange of digital certificates, and the registration of other platform-related information.

[0079] Each entity terminal sends heartbeat information to the operation platform at fixed intervals using the heartbeat mechanism. The operation platform judges the status of the entity terminal through the heartbeat information. Specifically, each entity terminal sends a heartbeat packet to the operation platform at fixed intervals based on the heartbeat mechanism and signs the heartbeat packet using the entity's own private key. After the server receives the heartbeat packet, it returns a heartbeat response to the social network terminal. The heartbeat information is used to verify the online status of the social network terminal and provide the basic information of the logged-in user to the server.

[0080] The heartbeat packet of ship terminal X contains the following information: the IMO number IMO of the ship corresponding to ship terminal X X 、MMSI number MMSI X 、real-time location information LOC X, Ground Speed Over Ground (SOG) X , Course Over Ground (COG) X , True Course (TC) X and the time stamp TS of the message sending time point, where LOC X =(Lat X , Long X ) is the longitude and latitude of the corresponding ship;

[0081] The representation form of the heartbeat packet sent by the ship terminal X to the operation platform is as follows:

[0082] IMO X |MMSI X |LOC X |SOG X |COG X |TC X |TS|SIG X_Pri [Hash(IMO X |MMSI X |LOC X |SOG X |COG X |TC X |TS)], where SIG X_Pri [] means that the ship terminal X uses its own private key to sign the content in [], and Hash() means using the hash algorithm to hash the content in ();

[0083] The heartbeat packets of the three types of entity terminals, namely the maritime supervision agency terminal, the shipping company terminal, and the port terminal, contain the following information: If the entity terminal Y is one of the above three types of entity terminals, NAME Y is the headquarters name, LOC Y is the location information of the headquarters, and TS is the time stamp of the message sending time point, where LOC Y =(Lat Y , Long Y ) is the longitude and latitude of the entity terminal Y.

[0084] The representation form of the heartbeat packet sent by the entity terminal Y to the operation platform is as follows:

[0085] NAME Y |LOC Y |TS|SIG Y_Pri [Hash(NAME Y |LOC Y |TS)], where SIG Y_Pri [] means that the entity terminal Y uses its own private key to sign the content in [], and Hash() means using the hash algorithm to hash the content in ().

[0086] The physical terminal realizes instant communication between ship-ship and ship-shore through the operation platform. The instant communication methods are divided into point-to-point instant communication and group instant communication.

[0087] Point-to-point instant communication includes two methods, namely, encryption mode and non-encryption mode;

[0088] 1) Point-to-point instant communication in encryption mode:

[0089] Each physical terminal for instant communication logs in to the server through the registered user ID and password. The sender terminal uses its own private key to sign the message to be sent, and uses the public key of the receiver terminal to encrypt the message to be sent, generates a ciphertext packet and sends it to the server. The ciphertext packet is forwarded to the receiver terminal through the server. After the receiver terminal decrypts it, it gets the plaintext of the message, completing the process of point-to-point instant communication.

[0090] The representation form of the ciphertext packet sent from the sender terminal to the receiver terminal is as follows:

[0091] ENC Rec _ Pub [message|TS|SIG Send _ Pri [Hash(message|TS)], where message represents the information to be transmitted, ENC Rec _ Pub [] means encrypting the content in [] using the public key of the receiver terminal, SIG Send _ Pri [] means signing the content in [] using the private key of the sender terminal, Hash() means hashing the content in () using the hash algorithm, and TS represents the timestamp of the message sending time point; the symmetric key can also be negotiated in the above way to speed up the encryption and decryption calculation speed.

[0092] 2) Point-to-point instant communication in non-encryption mode:

[0093] Each physical terminal for instant communication logs in to the server through the registered user ID and password. The sender terminal uses its own private key to sign the message to be sent, generates a message packet and sends it to the server. The message packet is forwarded to the receiver terminal through the server, completing the process of point-to-point instant communication.

[0094] The representation form of the message packet sent from the sender terminal to the receiver terminal is as follows:

[0095] message|TS|SIG Send _ Pri [Hash(message|TS)], where message represents the transmitted information, SIG Send _ Pri [] means signing the content in [] using the private key of the information sender's terminal, Hash() means hashing the content in () using the hashing algorithm, and TS represents the timestamp at the time point of message sending.

[0096] Group instant messaging includes the processes of creating a group, joining a group, and information transmission within the group.

[0097] ① Creating a group: Each entity terminal of instant messaging logs in to the server through the registered user ID and password. Entity terminal A sends a group creation request (GroupApply) to the operation platform and signs GroupApply using its own private key. After receiving the request, the operation platform (Platform) returns a response message to entity terminal A and grants a group (GroupGrant), and then signs the response message using its own private key to complete the creation of the group, where entity terminal A is the creator (GroupOwner) of the group.

[0098] The form of the group creation request sent by entity terminal A to the operation platform is as follows:

[0099] GroupApply|TS|SIG A _ Pri [Hash(GroupApply|TS)], where GroupApply represents the message identifier of the request to apply for creating a group, SIG A _ Pri [] means signing the content in [] using the private key of entity terminal A, Hash() means hashing the content in () using the hashing algorithm, and TS represents the timestamp at the time point of message sending.

[0100] The form of the response message returned by the operation platform to entity terminal A is as follows:

[0101] GroupGrant|GroupID|TS|SIG P _ Pri [Hash(GroupGrant|GroupID|TS)], where GroupGrant represents the message identifier of the group granted by the operation platform, GroupID represents the group account granted by the operation platform, SIG P _ Pri[] indicates signing the content in [] using the private key of the operation platform, Hash() indicates hashing the content in () using a hashing algorithm, and TS represents the timestamp of the message sending time point.

[0102] ② Joining a group: After a group is created, there are two ways to join the group, namely, being invited into the group by a group member and joining the group by searching for the group ID (GroupID);

[0103] Any member within the group can invite members in their trusted list to join the group. Entity terminal A finds entity terminal B that it wants to invite into the group through the search function and sends a group invitation request to entity terminal B. Entity terminal A signs the invitation information using its own private key and forwards it through the server to send the invitation request to entity terminal B. If entity terminal B confirms to join the group, it sends a response message to entity terminal A and signs it using its own private key, thus joining the group.

[0104] The group invitation information sent by entity terminal A to entity terminal B is expressed as follows:

[0105] InviteGroup|GroupID|TS|SIG A _ Pri [Hash(InviteGroup|GroupID|TS)], where InviteGroup represents the group invitation identifier, GroupID represents the group ID, TS represents the timestamp of the message sending time point, and SIG A _ Pri [] indicates signing the content in [] using the private key of entity terminal A, Hash() indicates hashing the content in () using a hashing algorithm.

[0106] The response message returned by entity terminal B to entity terminal A is expressed as follows:

[0107] JoinGroup|TS|SIG B _ Pri [Hash(JoinGroup|TS)], where JoinGroup represents the confirmation of joining the group identifier, TS represents the timestamp of the message sending time point, and SIG B _ Pri [] indicates signing the content in [] using the private key of entity terminal B, Hash() indicates hashing the content in () using a hashing algorithm.

[0108] All physical terminals that have passed the review by the operation platform can join a group by searching for the group ID (GroupID). After the physical terminal C that has passed the review by the operation platform finds the group it wants to join through the group ID, it sends a group entry request to the group creator (GroupOwner) terminal, signs it with its own private key, and forwards it to the group creator terminal through the server. The group creator terminal verifies the authenticity of its identity based on the digital certificate of the physical terminal C. If it agrees to the physical terminal C to join the group, it returns a response packet to the physical terminal C, and the physical terminal C can then join the group.

[0109] The group entry request information sent by the physical terminal C to the group creator terminal is expressed as follows:

[0110] Cert C |GroupID|TS|SIG C _ Pri [Hash(Cer C |GroupID|TS)], where Cert C represents the digital certificate of the physical terminal C, GroupID represents the group ID, TS represents the timestamp of the message sending time point, and SIG C _ Pri [] means that the physical terminal C uses its own private key to sign the content in [], and Hash() means using the hash algorithm to hash the content in ().

[0111] The response packet returned by the group creator terminal to the physical terminal C is expressed in the following form:

[0112] AgreeGroup|GroupID|TS|SIG GO _ Pri [Hash(AgreeGroup|GroupID|TS)], where AgreeGroup represents the identifier for agreeing to join the group, TS represents the timestamp of the message sending time point, and SIG GO _ Pri [] means using the private key of the group creator terminal to sign the content in [], and Hash() means using the hash algorithm to hash the content in ().

[0113] When a physical terminal joins or exits a group, the operation platform (Platform) updates the group member list (MemberList) for each physical terminal in the group and signs it with its own private key. The information for updating the group member list sent by the operation platform to each member terminal in the group is expressed as follows:

[0114] MemberList|TS|SIG P _Pri [Hash(MemberList|TS)], where MemberList represents the group member list, and SIG P _ Pri [] indicates that the content in [] is signed using the private key of the operating platform, Hash() indicates that the content in () is hashed using a hashing algorithm, and TS represents the timestamp of the message sending time point.

[0115] ③ Information transmission within the group: After joining the group, each member terminal within the group can communicate within the group. The information (message) sent by the member terminal within the group is signed using the private key of the sender (Sender) terminal to generate a group message packet and sent to the server. The group message packet is forwarded by the server to other recipient terminals within the group to complete the group instant messaging process.

[0116] The representation form of the group message packet sent by the information sender terminal to the operating platform is as follows:

[0117] message|TS|SIG Send _ Pri [Hash(message|TS)], where message represents the transmitted information, and SIG Send _ Pri [] indicates that the content in [] is signed using the private key of the information sender terminal, Hash() indicates that the content in () is hashed using a hashing algorithm, and TS represents the timestamp of the message sending time point.

[0118] The described operating platform includes a server and a database; among them, the server is used to conduct identity verification based on the digital certificates of each entity terminal, monitor the status of entity terminals, provide the navigation dynamics information of other ships for each ship, forward data between entity terminals, manage the truster list and group list, including operations such as searching for, adding, and deleting trusters and groups, reporting and notifying water events, dynamically pushing navigable environment information, updating and pushing electronic chart information, and updating and pushing events related to navigation safety; the database is used to store the basic setting information, digital certificates, truster information, user group information, user static data exchange information (such as text, pictures, files, etc.) and configuration file information of entity terminals;

[0119] Each entity terminal logs in to the operating platform through a secure Web service (such as the SSL protocol, but not limited to this) to complete account application, digital certificate exchange, and registration of other platform-related information;

[0120] Preferably, the system further includes a trust relationship establishment module between entity terminals, which is used for entity terminals to apply for trust with each other based on digital certificates and maintain a mutual trust relationship after mutual confirmation. Specifically:

[0121] Entity terminal A applies for trust to entity terminal B, signs the trust application package with its own private key, and then forwards it to entity terminal B through the server of the operation platform;

[0122] Entity terminal B receives the trust application package and verifies the authenticity of the identity of entity terminal A based on the digital certificate of entity terminal A; if entity terminal B confirms to establish a trust relationship with entity terminal A, it returns a trust response package to entity terminal B, grants trust to entity terminal A, signs the trust response package with the private key of entity terminal B and forwards it to entity terminal A through the server of the operation platform, thereby establishing a trust relationship between the two;

[0123] Two entity terminals that have established a trust relationship with each other establish data exchange through the forwarding of the operation platform. The data exchange includes text information and file transfer, and real-time audio and video are established under the condition that the network communication quality permits; regardless of whether they belong to the first user group terminal UserTypeI, they can see each other's dynamic position, course and identity information on the electronic chart;

[0124] The representation form of the trust application package sent by entity terminal A to entity terminal B is as follows:

[0125] Cert A |TrustApply|TS|SIG A _ Pri [Hash(Cert A |TrustApply|TS)], where Cert A represents the digital certificate of entity terminal A, TrustApply represents the trust application identifier, TS represents the timestamp of the message sending time point, and SIG A _ Pri [] represents that entity terminal A signs the content in [] with its own private key, and Hash() represents hashing the content in () using the hash algorithm;

[0126] The representation form of the trust response package returned by entity terminal B to entity terminal A is as follows:

[0127] Cert B |TrustGrant|TS|SIG B _ Pri [Hash(Cert B |TrustGrant|TS)], where Cert BThe digital certificate of entity terminal B, TrustGrant represents the granted trust identifier, TS represents the timestamp of the message sending time point, SIG B _ Pri [] means that entity terminal B uses its own private key to sign the content in [], and Hash() means using the hash algorithm to perform hashing on the content in ();

[0128] The operation platform provides Location Based Services (LBS). After each entity terminal accesses the operation platform, it periodically provides its own real-time location information to the operation platform. The operation platform will push the electronic nautical chart of the water area where it is located to the user, bind the identity information and geographical location information of each user and display them on the electronic nautical chart; under some conditions, the locations and relevant dynamic information of other entities are also displayed on the electronic nautical chart;

[0129] Each ship terminal declares to the operation platform whether it is willing to disclose its identity information and geographical location information to other entity terminals; the maritime supervision agency terminal, the shipping company terminal and the port terminal must disclose their identity information and geographical location information to other entity terminals;

[0130] Record the first user group terminal UserTypeI as the ship terminal that has passed the review of the operation platform and is willing to disclose its location and identity. If the ship terminal X belongs to the UserTypeI type of entity terminal, its dynamic information representation form is as follows:

[0131] IMO X |MMSI X |LOC X |SOG X |COG X |TC X |, where IMO X represents the IMO number of the ship corresponding to ship terminal X, MMSI X represents the MMSI number of the corresponding ship, LOC X =(Lat X ,Long X ) represents the latitude and longitude of the corresponding ship, SOG X represents the speed over ground of the corresponding ship, COG X represents the course over ground of the corresponding ship, TC X represents the true course of the bow of the corresponding ship; this information will be displayed on the electronic nautical chart and updated in real time to all logged-in entity terminals.

[0132] Denote the terminal of the second user group UserTypeⅡ as the ship terminal that has passed the review of the operation platform and is unwilling to disclose its location and identity. If the ship terminal X belongs to the terminal of the second user group UserTypeⅡ, its dynamic information representation is as follows:

[0133] AM X |LOC X |SOG X |COG X |TC X |, where AM X represents the anonymous identifier of the ship terminal X, LOC X =(Lat X , Long X ) represents the longitude and latitude of the ship corresponding to the ship terminal X, SOG X represents the speed over ground of the corresponding ship, COG X represents the course over ground of the corresponding ship, TC X represents the true course of the bow of the corresponding ship; this information will be displayed on the electronic nautical chart and updated in real time to all logged-in entity terminals;

[0134] Denote the terminal of the third user group UserTypeⅢ as the terminal of the maritime supervision agency, ship company, and port terminal that have passed the review of the operation platform. All terminals of the third user group UserTypeⅢ need to disclose their identity information and geographical location information to other entity terminals. If the entity terminal X belongs to the terminal of the third user group UserTypeⅢ, its static information representation is as follows:

[0135] NAME X |LOC X |, where NAME X represents the headquarters name of the entity corresponding to the entity terminal X, LOC X =(Lat X , Long X ) represents the static location information of the corresponding entity headquarters; this information will be displayed on the electronic nautical chart and updated regularly to all logged-in entity terminals;

[0136] The operation platform provides event reporting and notification services, specifically including: The operation platform encourages it to report to the platform. The operation platform has an event reporting port for reporting to the operation platform when the ship encounters extreme weather during navigation, a maritime accident occurs on the ship itself, a maritime accident is observed on other ships by the ship itself, and any event that may affect the safe navigation of the ship. The report is signed by the user;

[0137] The operation platform is equipped with a certain event approval mechanism to verify the authenticity of reports. If the verification is passed, the reports will be pushed to other entity terminals, along with the publishers of the information. The platform can establish certain exemption clauses to avoid disputes arising from the authenticity of user reports;

[0138] Optionally, the operation platform can also set up a value-added service module, which can be subscribed by entity terminals according to their own needs; the value-added service module is used to provide value-added services including news push and advertisement push;

[0139] The following is an example for illustration.

[0140] Vessel terminal A is a vessel terminal that has passed the review of the operation platform and is willing to disclose its location and identity, that is, the terminal of the first user group UserTypeI. The dynamic information of vessel terminal A is shown on the chart as follows:

[0141] IMO: 9602423|MMSI: 248238000|LOC: (127°3.516′E, 30°41.123′N)|SOG: 9.7kn|COG: 90°|TC: 90°|

[0142] Vessel terminal B is a vessel terminal that has passed the review of the operation platform and is not willing to disclose its location and identity, that is, the terminal of the second user group UserTypeⅡ. The dynamic information of vessel terminal B is shown on the chart as follows:

[0143] AM B |LOC: (128°57.073′E, 29°52.090′N)|SOG: 9.7kn|COG: 90°|TC: 90°|

[0144] The terminal of C Maritime Safety Administration is the terminal of the third user group UserTypeⅢ, and its static information is shown on the chart as follows:

[0145] NAME: C Maritime Safety Administration|LOC: (130°190′E, 33°051′N)|

[0146] Each entity terminal needs to send a heartbeat packet to the operation platform at fixed intervals (such as 5s for vessel entities and 24h for maritime regulatory agencies) based on the heartbeat mechanism, and sign the heartbeat packet with the entity's own private key;

[0147] The representation form of the heartbeat packet sent by vessel terminal A to the operation platform is as follows:

[0148] 9602423|248238000|(127°3.516′E, 30°41.123′N)|9.7kn|90°|90°|2022-11-18 13:53:00|SIGX_Pri [Hash(9602423|248238000|(127°3.516′E, 30°41.123′N)|9.7kn|90|90°|2022-11-18 13:53:00)]

[0149] The heartbeat packet sent by the C Maritime Safety Administration terminal to the operation platform is represented as follows:

[0150] C Maritime Safety Administration|(130°190′E, 33°051′N)|2022-11-01 12:00:00|SIG X_Pri [Hash(C Maritime Safety Administration|(130°190′E, 33°051′N)|2022-11-01 12:00:00)]

[0151] Ship terminal A applies for trust from ship terminal B and conducts point-to-point communication in non-encrypted mode;

[0152] Ship terminal A uses its own private key to sign the trust application packet and forwards it to ship terminal B through the server. The trust application packet sent by ship terminal A to ship terminal B is represented as follows:

[0153] Cert A |TrustApply|2022-11-19 12:51:00|SIG A _ Pri [Hash(Cert A |TrustApply|2022-11-19 12:51:00)]

[0154] Ship terminal B receives the trust application packet and agrees to establish a trust relationship with ship terminal A, and returns a trust response packet to ship terminal A. The trust response packet is signed with the private key of ship terminal B. The trust response packet returned by ship terminal B to ship terminal A is represented as follows:

[0155] Cert B |TrustGrant|2022-11-19 12:51:01|SIG B _ Pri [Hash(Cert B |TrustGrant|2022-11-19 12:51:01)]

[0156] Ship terminal A and ship terminal B can establish data exchange through the forwarding of the operation platform. The data exchange includes text information and file transfer, etc. Real-time audio and video can be established under the condition that the network communication quality permits;

[0157] The ship terminal A sends the encrypted information "xxx" to the ship terminal B. The ship terminal A signs "xxx" with its own private key and encrypts it with the public key of the ship terminal B to generate a ciphertext packet. The ciphertext packet is forwarded to the receiver terminal through the server, and the receiver terminal decrypts it to obtain the plaintext of the message;

[0158] The representation form of the ciphertext packet sent by the ship terminal A to the ship terminal B is as follows:

[0159] ENC B _ Pub [xxx|2022-11-19 12:52:00|SIG A _ Pri [Hash(xxx|2022-11-19 12:52:00)]]

[0160] The ship terminal A wants to create a group and invite the trusted ship terminal B to join the group. First, the ship terminal A sends a group creation request (GroupApply) to the operation platform and signs GroupApply with its own private key. The representation form of the group creation request sent by the ship terminal A to the operation platform is as follows:

[0161] GroupApply|2022-11-19 13:00:00|SIG A _ Pri [Hash(GroupApply|2022-11-19 13:00:00)]

[0162] After receiving the request, the operation platform (Platform) returns a response message to the entity terminal A and grants a group (GroupGrant), and then signs the response message with its own private key to complete the creation of the group. The representation form of the response message returned by the operation platform to the ship terminal A is as follows:

[0163] GroupGrant|00000001|2022-11-19 13:00:01|SIG P _ Pri [Hash(GroupGrant|00000001|2022-11-19 13:00:01)]

[0164] The ship terminal A signs the invitation information with its own private key and forwards it through the server to send the invitation request to the ship terminal B. The invitation information to enter the group sent by the ship terminal A to the ship terminal B is as follows:

[0165] InviteGroup|00000001|2022-11-19 14:00:00|SIGX_Pri [Hash(InviteGroup|00000001|2022-11-19 14:00:00)]

[0166] The ship terminal B confirms to join the group, sends a response message to the entity terminal A and signs it with its own private key, thus joining the group. The response message returned by the ship terminal B to the ship terminal A is as follows:

[0167] JoinGroup|2022-11-19 14:00:01|SIG B _ Pri [Hash(JoinGroup|2022-11-19 14:00:01)]

[0168] When a user joins or exits the group, the operation platform (Platform) updates the group member list (MemberList) for each entity terminal in the group and signs it with its own private key;

[0169] The information of the updated group member list sent by the operation platform to each member terminal in the group is as follows:

[0170] MemberList|2022-11-19 14:00:02|SIG P _ Pri [Hash(MemberList|2022-11-19 14:00:02)]

[0171] The present invention binds entities with digital certificates, and verifies the legality of entity identities and the authenticity of information sources through the asymmetric encryption and hash algorithms adopted by the digital certificates; the audited users can conduct point-to-point and group instant messaging, and can transmit information in an encrypted mode or a non-confidential mode, and the information format is flexible and the transmission speed is fast. In addition, the operation platform provides reporting and notification services for water events, providing an important guarantee for maritime navigation safety;

[0172] It should be understood that for those of ordinary skill in the art, improvements or transformations can be made according to the above description, and all such improvements and transformations should fall within the protection scope of the appended claims of the present invention.

Claims

1. An instant messaging and social network operation system based on ship digital certificates, characterized in that, This system includes an operation platform and four types of users, namely ports, maritime supervision agencies, shipping companies, and ships. Each type of user entity has a unique entity terminal connected to the operation platform through a communication network, which are called port terminals, maritime supervision agency terminals, shipping company terminals, and ship terminals respectively. The number of ship terminals is more than 1. The entity terminals of the four types of users and the operation platform apply for digital certificates from the maritime certificate authorization center and obtain the corresponding private keys. The digital certificates are bound to the above entity terminals. The entity terminals and the operation platform confirm each other's identities through the digital certificates. The four types of users need to trust the operation platform. Before joining the operation platform, they submit their own digital certificates to the platform for identity verification. The entities and the operation platform that pass the verification obtain each other's digital certificates. The entity terminals of the four types of users apply for and obtain a unique account from the operation platform by virtue of the digital certificates issued by the maritime certificate authorization center. Each entity terminal uses the heartbeat mechanism to send heartbeat messages to the operation platform at fixed intervals. The operation platform judges the status of the entity terminal through the heartbeat messages. The entity terminal realizes instant communication between ship-ship and ship-shore through the operation platform. The instant communication methods are divided into point-to-point instant communication and group instant communication. The operation platform mentioned above includes a server and a database. Among them, the server is used for identity verification of each entity terminal based on its digital certificate, monitoring the status of the entity terminal, providing the navigation dynamic information of other ships for each ship terminal, data forwarding between entity terminals, managing the trusted list and group list, including operations such as searching, adding, and deleting trusted parties and groups, reporting and notifying water events, dynamically pushing navigable environment information, updating and pushing electronic chart information, and updating and pushing events related to navigation safety. The database is used to store the basic setting information, digital certificates, trusted party information, user group information, user static data exchange information, and configuration file information of the entity terminals. Each entity terminal mentioned above uses the heartbeat mechanism to send heartbeat messages to the operation platform at fixed intervals. The operation platform judges the status of the entity terminal through the heartbeat messages. Specifically: The entity terminal sends a heartbeat packet to the operation platform at fixed intervals and signs the heartbeat packet with its own private key. After receiving the heartbeat packet, the server returns a heartbeat response to the entity terminal. The heartbeat message is used to verify the online status of the entity terminal and provide the basic information of the logged-in user for the server. The heartbeat packet of the ship terminal X contains the following information: the IMO number of the ship corresponding to the ship terminal X IMO X , MMSI number MMSI X , real-time position information LOC X , speed over ground SOG X , course over ground COG X , true course of the bow TC X and the timestamp of the message sending time point TS , where LOC X = ( Lat X Long X ) is the longitude and latitude of the corresponding ship; The representation form of the heartbeat packet sent by ship terminal X to the operation platform is as follows: IMO X |MMSI X | LOC X | SOG X | COG X | TC X | TS | SIG X_Pri Hash ( IMO X | MMSI X | LOC X | SOG X | COG X | TC X | TS )], where SIG X_Pri [ ] means that the ship terminal X signs the content in [ ] using its own private key. Hash () means that the content in () is hashed using a hashing algorithm.​ The heartbeat packets of the physical terminals of the three types of users, namely, the maritime supervision agency terminal, the shipping company terminal, and the port terminal, contain the following information: If the physical terminal Y is one of the above three types of physical terminals, NAME Y is the name of the headquarters, LOC Y is the location information of the headquarters, TS is the timestamp of the message sending time point, where LOC Y = ( Lat Y Long Y ) is the latitude and longitude of the physical terminal Y; The representation form of the heartbeat packet sent by entity terminal Y to the operation platform is as follows: NAME Y |LOC Y | TS|SIG Y_Pri Hash ( NAME Y |LOC Y |TS )], where SIG Y_Pri [ ] means that the entity terminal Y signs the content in [ ] using its own private key, Hash () means that the content in () is hashed using a hashing algorithm.​ 2. The instant messaging and social network operation system based on ship digital certificates according to claim 1, characterized in that The communication network mentioned above is one or a combination of satellite communication and operator mobile network communication.

3. The instant messaging and social network operation system based on ship digital certificates according to claim 1, wherein The account of each entity terminal described above includes a digital certificate, a login account, and a user password; the user password is set by the user himself / herself as the password for the user to log in to the operation platform, and is independent of the public key of the digital certificate obtained by the user and the matching private key; the user logs in to the operation platform through a secure Web service to complete the application for an account, the exchange of digital certificates, and the registration of other platform-related information.

4. The instant messaging and social network operation system based on ship digital certificates according to claim 1, characterized in that, The operation platform provides location-based services. After each entity terminal accesses the operation platform, it periodically provides its own real-time location information to the operation platform. The operation platform will push the electronic nautical chart of the waters where it is located to the entity terminal, and bind and display the identity information and geographical location information of each user on the electronic nautical chart; Each ship terminal declares to the operation platform whether it is willing to disclose its identity information and geographical location information to other entity terminals; the maritime supervision agency terminal, the shipping company terminal, and the port terminal must disclose their identity information and geographical location information to other entity terminals; Let the first user group terminal UserTypeI be the ship terminal that has passed the review of the operation platform and is willing to disclose its location and identity. If the ship terminal X belongs to the first user group terminal UserTypeI, the dynamic information representation form of the ship terminal X is as follows: IMO X |MMSI X | LOC X |SOG X | COG X | TC X |, where IMO X represents the IMO number of the corresponding ship, MMSI X represents the MMSI number of the corresponding ship, LOC X = ( Lat X Long X ) represents the latitude and longitude of the corresponding ship, SOG X represents the speed over the ground of the corresponding ship, COG X represents the course over the ground of the corresponding ship, TC X represents the true heading of the bow of the corresponding ship; this information will be displayed on the electronic chart and updated in real time to all logged-in entity terminals; Let the second user group terminal UserTypeⅡ be the ship terminal that has passed the review of the operation platform and is not willing to disclose its location and identity. If the ship terminal X belongs to the second user group terminal UserTypeⅡ, its dynamic information representation form is as follows: AM X |LOC X |SOG X | COG X | TC X |, where AM X represents the anonymous identifier of the corresponding ship, LOC X = ( Lat X Long X ) represents the latitude and longitude of the corresponding ship, SOG X represents the speed over ground of the corresponding ship, COG X represents the course over ground of the corresponding ship, TC X represents the true heading of the bow of the corresponding ship; this information will be displayed on the electronic chart and updated in real time to all logged-in entity terminals; Let the third user group terminal UserTypeⅢ be the maritime supervision agency terminal, the shipping company terminal, and the port terminal that have passed the review of the operation platform. All third user group terminals UserTypeⅢ need to disclose their identity information and geographical location information to other entity terminals. If the entity terminal X belongs to the third user group terminal UserTypeⅢ, its static information representation form is as follows: NAME X |LOC X |, where NAME X represents the headquarter name of the corresponding entity, LOC X = ( Lat X Long X ) represents the longitude and latitude of the headquarter of the corresponding entity; this information will be displayed on the electronic nautical chart and updated regularly to all logged-in entity terminals.

5. The instant messaging and social network operation system based on ship digital certificates according to claim 4, characterized in that, This system also includes a trust relationship establishment module between entity terminals, which is used for entity terminals to apply for trust with each other based on digital certificates and maintain a mutual trust relationship after mutual confirmation. Specifically: Entity terminal A applies for trust to entity terminal B, signs the trust application package with its own private key, and then forwards it to entity terminal B through the server of the operation platform; Entity terminal B receives the trust application package and verifies the authenticity of the identity of entity terminal A by virtue of the digital certificate of entity terminal A; if entity terminal B confirms to establish a trust relationship with entity terminal A, it returns a trust response package to entity terminal B and grants trust to entity terminal A. The trust response package is signed with the private key of entity terminal B and forwarded to entity terminal A through the server of the operation platform, thus establishing a trust relationship between the two; Two entity terminals that have established a trust relationship with each other establish data exchange through the forwarding of an operation platform. The data exchange includes text information and file transfer, and real-time audio and video are established under the condition that the network communication quality permits. Regardless of whether they belong to the terminal of the first user group UserTypeI, each other can see the dynamic position, course, and identity information of the other party on the electronic chart. The representation form of the trust application packet sent by entity terminal A to entity terminal B is as follows: Cert A |TrustApply | TS | SIG A _ Pri Hash ( Cert A |TrustApply|TS )], where Cert A represents the digital certificate of entity terminal A, TrustApply represents the application trust identifier, TS represents the timestamp indicating the message sending time point, SIG A _ Pri [ ] means that entity terminal A uses its own private key to sign the content in [ ], Hash () means that the content in () is hashed using the hash algorithm;​ The representation form of the trust response packet returned by entity terminal B to entity terminal A is as follows: Cert B |TrustGrant | TS | SIG B _ Pri Hash ( Cert B | TrustGrant|TS )], where Cert B represents the digital certificate of entity terminal B, TrustGrant represents the granted trust identifier, TS represents the timestamp indicating the message sending time point, SIG B _ Pri [] means that entity terminal B uses its own private key to sign the content in [], Hash () means that the content in () is hashed using the hash algorithm.​ 6. The instant messaging and social network operation system based on ship digital certificates according to claim 1, wherein The described point-to-point instant messaging includes an encryption mode and a non-encryption mode; among them, 1) Encryption mode point-to-point instant messaging: Each entity terminal for instant messaging logs in to the server through the registered user ID and password. The information sender terminal signs the sent information with its own private key and encrypts the sent information with the public key of the information receiver terminal to generate a ciphertext packet and sends it to the server. The ciphertext packet is forwarded to the information receiver terminal by the server. After the receiver terminal decrypts it, it obtains the plaintext of the message, completing the point-to-point instant messaging process. The representation form of the ciphertext packet sent by the information sender terminal to the information receiver terminal is as follows: ENC Rec _ Pub [message| TS | SIG Send _ Pri Hash (message| TS )]], where "message" represents the transmitted information, ENC Rec _ Pub [] means encrypting the content in [] using the public key of the information recipient's terminal, SIG Send _ Pri [] means signing the content in [] using the private key of the information sender's terminal, Hash () means hashing the content in () using a hashing algorithm, TS represents the timestamp at the time point of message sending; it is also possible to negotiate a symmetric key in the above manner to accelerate the calculation speed of encryption and decryption;​ 2) Non-encryption mode point-to-point instant messaging: Each entity terminal for instant messaging logs in to the server through the registered user ID and password. The information sender terminal signs the sent information with its own private key, generates a message packet and sends it to the server. The message packet is forwarded to the information receiver terminal by the server, completing the point-to-point instant messaging process. The representation form of the message packet sent by the information sender terminal to the information receiver terminal is as follows: message| TS|SIG Send _ Pri Hash (message| TS )],where message represents the transmitted information, SIG Send _ Pri [] means signing the content in [] using the private key of the information sender's terminal, Hash () means hashing the content in () using a hash algorithm, TS represents the timestamp at the time point of message sending.​ 7. The instant messaging and social network operation system based on ship digital certificates according to claim 1, characterized in that, The described group instant messaging includes the processes of creating a group, joining a group, and information transmission within the group; among them, ① Creating a group: Each entity terminal for instant messaging logs in to the server through the registered user ID and password. Entity terminal A sends a group creation request to the operation platform and signs the group request with its own private key; after receiving the request, the operation platform returns a response message to entity terminal A and grants the group, and then signs the response message with its own private key to complete the creation of the group, where entity terminal A is the creator of the group. The representation form of the group creation request sent by entity terminal A to the operation platform is as follows: GroupApply | TS|SIG A _ Pri Hash ( GroupApply | TS )], where GroupApply represents the message identifier for the request to create a group, SIG A _ Pri [ ] means signing the content in [ ] using the private key of entity terminal A, Hash ( ) means hashing the content in ( ) using a hashing algorithm, TS represents the timestamp at the time point when the message is sent;​ The representation form of the response message returned by the operation platform to entity terminal A is as follows: GroupGrant | GroupID | TS|SIG P _ Pri Hash ( GroupGrant|GroupID | TS )], where GroupGrant represents the message identifier granted by the operation platform to the group, GroupID represents the group account granted by the operation platform, SIG P _ Pri [] means signing the content in [] using the private key of the operation platform, Hash () means hashing the content in () using the hash algorithm, TS represents the timestamp at the time point of message sending;​ ② Join the group: After the group is created, there are two ways to join the group, namely, being invited into the group by group members and joining the group by searching for the group ID; Any member within the group can invite members in their trusted list to join the group; The entity terminal A finds the entity terminal B that it wants to invite into the group through the search function and sends a group invitation request to the entity terminal B; The entity terminal A signs the invitation information with its own private key and forwards it through the server to send the invitation request to the entity terminal B; If the entity terminal B confirms to join the group, it sends a response message to the entity terminal A and signs it with its own private key, thus joining the group; The group invitation information sent by the entity terminal A to the entity terminal B is expressed as follows: InviteGroup | GroupID | TS|SIG A _ Pri Hash ( InviteGroup | GroupID | TS )], where InviteGroup represents the invitation-to-group identifier, GroupID represents the group ID, TS represents the timestamp of the message sending time point, SIG A _ Pri [ ] means signing the content in [ ] using the private key of entity terminal A, Hash () means hashing the content in () using the hash algorithm;​ The response message returned by the entity terminal B to the entity terminal A is expressed as follows: JoinGroup | TS|SIG B _ Pri Hash ( JoinGroup | TS )], where JoinGroup represents the confirmation of joining the group identifier, TS represents the timestamp of the message sending time point, SIG B _ Pri [] means using the private key of entity terminal B to sign the content in [], Hash () means using the hash algorithm to hash the content in ();​ All entity terminals that have passed the review by the operation platform can join the group by searching for the group ID; After the entity terminal C that has passed the review by the operation platform finds the group it wants to join through the group ID, it sends a group entry request to the group creator terminal and signs it with its own private key, and forwards it to the group creator terminal through the server; The group creator terminal verifies the authenticity of its identity based on the digital certificate of the entity terminal C. If it agrees that the entity terminal C joins the group, it returns a response packet to the entity terminal C, and the user C can then join the group; The group entry request information sent by the entity terminal C to the group creator terminal is expressed as follows: Cert C |GroupID | TS | SIG C _ Pri Hash ( Cer C |GroupID|TS )], where Cert C represents the digital certificate of entity C, GroupID represents the group ID, TS represents the timestamp of the message sending time point, SIG C _ Pri [ ] means that entity terminal C uses its own private key to sign the content in [ ], Hash () means that the content in () is hashed using the hash algorithm;​ The form of the response packet returned by the group creator terminal to the entity terminal C is as follows: AgreeGroup|GroupID|TS | SIG GO _ Pri Hash ( AgreeGroup|GroupID|TS )], where AgreeGroup represents the group join identifier consent, TS represents the timestamp of the message sending time point, SIG GO _ Pri [] means using the private key of the group creator's terminal to sign the content in [], Hash () means using the hash algorithm to hash the content in ();​ When a user joins or exits the group, the operation platform updates the group member list for each entity terminal within the group and signs it with its own private key; The information on updating the group member list sent by the operation platform to each member terminal within the group is expressed as follows: MemberList|TS|SIG P _ Pri Hash ( MemberList|TS )], where MemberList represents the group member list, SIG P _ Pri [] means signing the content in [] with the private key of the operation platform, Hash () means hashing the content in () using the hash algorithm, TS represents the timestamp at the time point of message sending;​ ③ Information transmission within the group: After joining the group, each member terminal within the group can communicate within the group; the information sent by the member terminal within the group uses the private key of the sender terminal to sign the sent information, generates a group message packet and sends it to the server, and the group message packet is forwarded by the server to other recipient terminals within the group to complete the group instant messaging process; The representation form of the group message packet sent by the information sender terminal to the operation platform is as follows: message| TS | SIG Send _ Pri Hash (message|TS), where message represents the transmitted information, SIG Send _ Pri [ ] means signing the content in [ ] using the private key of the information sender's terminal, Hash () means hashing the content in () using a hashing algorithm, TS represents the timestamp at the time point when the message is sent.​ 8. The instant messaging and social network operation system based on ship digital certificates according to claim 1, characterized in that, The reporting and notification of the said events specifically include: The operation platform is provided with an event reporting port for reporting to the operation platform when the ship encounters extreme weather during navigation, a maritime accident occurs to the ship itself, a maritime accident is observed on other ships by the ship itself, and any event that may affect the safe navigation of the ship. The report is signed by the user; The operation platform is provided with a certain event approval mechanism for verifying the authenticity of the report. If it passes the verification, it will be pushed to other entity terminals and the publisher of the information will be attached. The platform can establish certain exemption clauses to avoid disputes arising from the authenticity of user reports.

9. The instant messaging and social network operation system based on ship digital certificates according to claim 1, characterized in that, The said operation platform is provided with a value-added service module, and the entity terminal subscribes according to its own needs; the said value-added service module includes news push and advertisement push.

Citation Information

Patent Citations

  • Instant communication method, server andsxja system

    CN105376136A

  • Ship instant messaging system and method

    CN106130890A

  • Intelligent ship identity verification and false identity early warning system based on ship digital certificate

    CN115037465A