Ship network system

By setting up firewalls and backup firewalls in the main control unit and sub-control unit of the ship network system, the problems of network attack spread and recovery in traditional ship network systems are solved, and higher network security and navigation security are achieved.

CN120201053APending Publication Date: 2025-06-24JIANGNAN SHIPYARD (GRP) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510361785.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-26
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

Traditional ship network systems lack effective network security protection measures, making it difficult to prevent network attacks from spreading horizontally from one sub-control unit to other sub-control units, and lacking a rapid recovery mechanism, which leads to threatening ship operation efficiency and security.

Method used

A ship network system is designed, including a general control unit and multiple sub-control units. The general control firewall and backup firewall are set up in the general control unit. The sub-control firewall and backup firewall are set up in the sub-control unit. Through these firewalls, network attack data is monitored and intercepted in real time, preventing horizontal spread, and automatically recovering in the event of a failure.

Benefits of technology

It effectively prevents the network attack behavior outside the ship network system from entering the system, and prevents the network attack behavior from spreading horizontally between the sub-control units, narrows the attack surface of the ship network system, and ensures navigation safety.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120201053A_ABST
    Figure CN120201053A_ABST
Patent Text Reader

Abstract

The invention provides a ship network system. The ship network system comprises a master control unit, a plurality of sub-control units and a firewall. Wherein a general control switch and an external communication module are arranged in the general control unit, and the general control switch realizes bidirectional network signal transmission with an external network of the ship network system through the external communication module. Each sub-control unit is provided with a sub-control switch and one or more computer systems connected to the sub-control switch, and each computer system comprises a plurality of electronic devices. The sub-control switch of each sub-control unit is connected to the master control switch. And the general control firewall is integrated in the general control switch and is used for monitoring network data entering and exiting the general control unit in real time, so that normal data can pass through the general control firewall, and attack data cannot pass through the general control firewall. According to the technical scheme, external network attack behaviors can be effectively prevented from entering the system, and internal network attack behaviors are prevented from transversely diffusing, so that the navigation safety of the ship is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of ship communication, and more particularly, to a ship network system. Background Art

[0002] With the rapid development of information technology, modern ships are widely equipped with computer-based systems (CBS), whose functions cover key areas of ships such as ship control, navigation steering, propulsion control, safety monitoring, and information management. Each computer system is interconnected through a ship network system to achieve efficient data transmission and automated control, greatly improving the operation efficiency and safety of ships. With the continuous improvement of the degree of ship networking, network security issues have become increasingly prominent. During actual operation, the ship network system faces various network attack threats, such as hacker attacks, malware intrusion, data leakage, etc. If the key systems or devices of the ship are subjected to network attacks, it may lead to serious consequences such as out-of-control ship operation, endangering the safety of crew members and ships and causing economic losses.

[0003] However, in traditional ship network systems, there is usually a lack of effective network security protection measures, or only simple network isolation from the external network is achieved for some important devices using firewalls, etc. With the increasing complexity and diversification of network attack means, these simple network security protection measures are no longer sufficient to meet the requirements. Limited by conditions, it is usually difficult to achieve strict physical isolation between different subsystems or devices of traditional ship network systems. Therefore, when a local part of the ship network system is under a network attack, the attack range is likely to spread to other parts of the system, resulting in greater losses. In addition, traditional ship network systems lack effective backup and recovery mechanisms and do not have the ability to quickly recover when subjected to external network attacks or failures. Therefore, once a key part of the ship network system is damaged, it is very likely that the ship will be unable to operate normally for a long time or even be completely damaged, causing huge economic losses. Summary of the Invention

[0004] The purpose of the embodiments of this application is to provide a ship network system, which can effectively prevent network attack behaviors outside the ship network system from entering the system, and at the same time, when the ship network system is under a network attack internally, prevent the network attack behaviors from spreading horizontally from the currently located sub-control unit to other sub-control units, thereby effectively reducing the attack surface of the ship network system and ensuring the navigation safety of the ship to the greatest extent.

[0005] The present application provides a ship network system, including a master control unit, multiple sub-control units and a firewall. A master control switch and an external communication module are provided in the master control unit, and the master control switch realizes two-way network signal transmission with the external network of the ship network system through the external communication module. Each sub-control unit is provided with a sub-control switch and one or more computer systems connected to the sub-control switch, and each computer system includes multiple electronic devices. The sub-control switches of each sub-control unit are respectively connected to the master control switch. The master control firewall is integrated in the master control switch, and is used to monitor the network data entering and leaving the master control unit in real time, so that normal data can pass through the master control firewall, while preventing attack data from passing through the master control firewall.

[0006] In an implementable solution, a sub-control firewall is integrated into some or all sub-control switches to monitor the network data entering and leaving the sub-control unit in real time, so that normal data can pass through the sub-control firewall, while preventing attack data from passing through the sub-control firewall.

[0007] In an implementable solution, all electronic devices in each sub-control unit are connected together to form a sub-control unit subnet, and each sub-control unit subnet is respectively set with a separate static IP address, port number and network communication protocol.

[0008] In an implementable solution, part of the computer system in the sub-control unit forms one or more sub-control sub-units, and the sub-control sub-units are connected to the sub-control switch of the sub-control unit to which they belong through a hub.

[0009] In an implementable solution, the sub-control unit includes a navigation system unit, a cabin control unit, a living LAN unit, an office LAN unit and a video monitoring unit.

[0010] In an implementable solution, a backup master control firewall is integrated in the master control switch. When in use, when the master control firewall works normally, the backup master control firewall is in an inactive state. When the master control firewall fails to work normally, the backup master control firewall is enabled.

[0011] In an implementable solution, a backup sub-control firewall is integrated in the sub-control switch. When in use, when the sub-control firewall works normally, the backup sub-control firewall is in an inactive state. When the sub-control firewall fails to work normally, the backup sub-control firewall is enabled.

[0012] In one implementable scheme, the computer system only enables functions that are compatible with pre-set tasks to be performed, and shuts down or removes other functions; the computer system only enables ports, communication protocols, and service items that are compatible with its own enabled functions, and shuts down or removes ports, communication protocols, and service items that are incompatible with or irrelevant to its own enabled functions.

[0013] In an implementable solution, the ship network system adopts a four-layer network model, and the network levels of the ship network system include a transport layer, a network layer, a data link layer, and a physical layer.

[0014] In an implementable solution, the master firewall and the slave firewalls have functions of controlled shutdown, reset, rollback, and restart, and can automatically resume normal operation after a network interruption or network failure occurs in the ship network system.

[0015] Compared with the prior art, the beneficial effects of this application at least include:

[0016] This application provides a ship network system. The entire system is divided into a master control unit and multiple slave control units connected to the master control unit, and a firewall is set in the master control unit, thereby effectively preventing network attack behaviors outside the ship network system from entering the system. Since each slave control unit is connected to the master control unit, when some electronic devices in the ship network system are under network attacks, the design of this application can prevent the network attack behaviors from spreading horizontally from the current slave control unit to other slave control units, and control the losses caused by network attacks to the minimum, that is, effectively reduce the attack surface of the ship network system, enable other slave control units to operate normally, and thus ensure the navigation safety of the ship to the greatest extent. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] In order to more clearly illustrate the technical solutions of the embodiments of this application, the drawings required to be used in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of this application, and therefore should not be regarded as limiting the scope. For those of ordinary skill in the art, other related drawings can be obtained based on these drawings without creative efforts.

[0018] Figure 1 FIG. 1 is a schematic diagram of the basic structure of the ship network system shown according to the embodiments of this application;

[0019] Figure 2 FIG. 2 is a schematic diagram of the basic structure of the master control unit;

[0020] Figure 3 FIG. 3 is a schematic diagram of the basic structure of the slave control unit. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0021] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions in the embodiments of this application will be clearly and completely described below with reference to the drawings in the embodiments of this application. Obviously, the described embodiments are some, but not all, of the embodiments of this application. Usually, the components of the embodiments of this application described and shown in the drawings here can be arranged and designed in various different configurations.

[0022] Accordingly, the following detailed description of the embodiments of the present application provided in the accompanying drawings is not intended to limit the scope of the claimed present application, but merely represents selected embodiments of the present application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present application without creative efforts shall fall within the scope of protection of the present application.

[0023] As Figures 1-3 shown, the present application provides a ship network system, including a master control unit, a plurality of slave control units, and a firewall. Among them, a master control switch and an external communication module are provided in the master control unit, and the master control switch realizes bidirectional network signal transmission with the external network of the ship network system through the external communication module. A slave control switch and one or more computer systems connected to the slave control switch are respectively provided in each slave control unit, and each computer system includes a plurality of electronic devices. The slave control switches of each slave control unit are respectively connected to the master control switch. The master control firewall is integrated in the master control switch and is used to monitor the network data entering and leaving the master control unit in real time, enabling normal data to pass through the master control firewall while preventing attack data from passing through the master control firewall.

[0024] In a ship, a dedicated computer-based system (CBS) is usually set up to control a specific subsystem or achieve a specific function. Multiple computer-based systems with similar functions or that can cooperate with each other can jointly form a sub-control unit. Usually, each sub-control unit is located at different physical positions and there is no direct network connection between them. Specifically, the sub-control units of a ship can include a navigation system unit, an engine room control unit, a living local area network unit, an office local area network unit, and a video surveillance unit. Among them, the navigation system unit is used for the navigation control and management of the ship, including but not limited to the control of the ship's course and speed, as well as route planning, etc.; the engine room control unit is mainly used to monitor and manage various equipment and systems in the ship's engine room, such as the main propulsion system, the side thruster system, the power station management system, the valve remote control system, the cooling water system, the fuel system, the lubricating oil system, the ballast system, the engine room ventilation system, etc.; the living local area network unit is used to provide network services related to life for the people on board, such as Internet access, internal communication, daily entertainment, etc., to meet the network needs of crew members and passengers in terms of life; the office local area network unit is used to provide office network support for the management and operation of the ship, including the daily management of the ship, document processing, data transmission, communication, etc., to ensure that the operation and management work of the ship can be carried out efficiently and orderly; the video surveillance unit is used to conduct real-time video surveillance on various key areas of the ship, including the cab, the engine room, the deck, the cargo hold, etc. The surveillance videos can be transmitted to the monitoring center or authorized terminal devices through the network to achieve all-round monitoring of the ship. In addition, other sub-control units can also be set up for the ship as needed, such as setting up a lighting system unit to achieve intelligent monitoring of the ship's lighting system, or setting up a garbage disposal unit to manage the garbage disposal process of the ship, etc. There is no excessive restriction here.

[0025] Specifically, the external communication module can include one or more of 4G communication devices, 5G communication devices, and VSAT satellite communication devices. There is no excessive restriction here. Among them, 4G communication devices / 5G communication devices are mainly used for the data transmission requirements between the ship and the shore base in the offshore area, with relatively fast transmission rates and good stability; VSAT satellite communication devices are not restricted by geographical location and can provide communication services globally, and can well meet the communication needs of the ship during ocean voyages. And in special situations such as extreme weather, marine disasters, and shipwrecks, VSAT satellite communication devices can also be used as an emergency communication means.

[0026] When the ship is sailing, if a cyber-attack comes from outside the ship's network system, for example, the corresponding attack data enters the ship's network system through the external communication module, attempting to steal data from the electronic devices carried on the ship or control the ship, the master firewall will intercept the attack data at this time, making it unable to enter each sub-control unit through the master switch, thereby preventing the electronic devices carried on the ship from being attacked. If the cyber-attack comes from within the ship's network system, for example, there are malicious programs or viruses lurking in some of the electronic devices carried on the ship, or some crew members or passengers launch a cyber-attack during the voyage, and the cyber-attack attempt spreads to other computer systems through the ship's network system, then when the corresponding attack data reaches the master switch, the master firewall will intercept the attack data to prevent it from further spreading to other sub-control units.

[0027] In summary, the present application provides a ship network system. The entire system can be divided into a master control unit and multiple sub-control units connected to the master control unit, and a firewall is set in the master control unit, thereby effectively preventing cyber-attack behaviors outside the ship network system from entering the system. Moreover, since each sub-control unit is connected to the master control unit, when some electronic devices within the ship network system are under cyber-attack, the design of the present application can prevent the cyber-attack behavior from horizontally spreading from the current sub-control unit to other sub-control units, thereby restricting the cyber-attack behavior to the sub-control unit where the attacked electronic device is located, that is, effectively reducing the attack surface of the ship network system and controlling the losses caused by cyber-attacks to the minimum, ensuring the navigation safety of the ship.

[0028] In one embodiment, a sub-control firewall can be integrated in some or all of the sub-control switches to monitor the network data entering and leaving the sub-control unit in real time, enabling normal data to pass through the sub-control firewall while preventing attack data from passing through. The sub-control firewall and the master firewall jointly provide multiple layers of security protection for the ship network system. For example, when the sub-control firewall fails to intercept the attack data generated inside the sub-control unit, the attack data will still be intercepted by the master firewall when it enters the master control unit; when the master firewall fails to effectively intercept the attack data from the outside, the attack data will be intercepted by the sub-control firewall before entering the sub-control unit; similarly, when the master firewall fails to effectively intercept the attack data from a certain sub-control unit, the attack data will be intercepted by the corresponding sub-control firewall before entering other sub-control units. Therefore, setting up the sub-control firewall can more effectively prevent the spread of cyber-attack behaviors between the master control unit and each sub-control unit, improving the security of the entire ship network system.

[0029] Preferably, the master control firewall and the sub-control firewall have functions of controlled shutdown, reset, rollback, and restart, and can automatically resume normal operation after a network interruption or network failure occurs in the ship network system. Among them, the controlled shutdown function allows the computer system connected to the firewall to submit / roll back pending transactions, terminate processes, close connections, etc., so that the computer system is in a safe, consistent, and known state; the reset function can guide the computer system to complete the process of shutting down, clearing the memory, and resetting each electronic device to its initial state; the rollback function can make the computer system return to the previous configuration and / or state to restore the integrity and consistency of the system; the restart function can make the computer system start from a read-only source and reload a new image of all software and data, and the restart time should be adapted to the expected service of the computer system.

[0030] In an actual ship, a firewall can also be separately set for some computer systems with a relatively high safety protection level, and the corresponding computer system software backup can be set. When the ship network system is under a network attack, if the network attack problem cannot be alleviated through the various functions of the firewall (controlled shutdown function, reset function, rollback function, and restart function), or the ship network system has been partially damaged or even failed, the relevant software can be restored through the computer system software backup. Specifically, computer systems related to navigation safety (such as computer systems for controlling equipment such as radars and steering gears) need to be backed up in advance so that when a failure occurs in the ship network system, the crew can quickly resume the normal operation of the ship network system through the computer system software backup.

[0031] In the master control firewall, sub-control firewall, and the firewalls separately set up for some computer systems, industrial standard antivirus and anti-malware can be configured. Additionally, the operating system can be kept up-to-date by timely updates, and antivirus and anti-malware can be installed, maintained, and regularly updated in the operating system. For computer systems where antivirus and anti-malware cannot be installed, protective measures can be taken through operating procedures, physical safeguards, or vendor-defined methods. The information stored in each computer system should only be accessible to authorized personnel, programs, and devices according to their respective responsibilities or expected functional requirements. For example, a password is required to access a computer system related to video surveillance, and if further modification of the parameters in the system is needed, an additional password from a person with higher privileges is required. In addition, ship visitors should be restricted from accessing each sub-control unit of the ship. If there is a temporary connection requirement (such as printing documents), an independent computer isolated from the ship's network system should be used (these computers can be connected to a dedicated network for visitors). In addition, a usage policy for removable media can be formulated. Specifically, it can be stipulated that files be scanned before being uploaded to or downloaded from the ship's network system, and digital signatures and / or watermarks can be used to check for malware and / or verify the legitimacy of the software in the removable media.

[0032] During the operation of the ship's network system, it can be monitored in real time all day long. Specifically, the ship's network system can be monitored from the following aspects: monitoring and protecting against excessive traffic, monitoring network connections, monitoring and recording device management activities, and monitoring or protecting against unauthorized access of electronic devices. For example, if the information received by the VSAT satellite communication system shows a significant increase in magnitude compared to normal, or if the living local area network unit for entertainment suddenly requests access to the office local area network unit, or there are situations such as network connection interruptions and unauthorized device access, all these abnormal situations will be monitored and recorded.

[0033] In addition to integrating firewalls in the master control switch and sub-control switches, network data can also be inspected and screened through other means. For example, a boundary firewall, an intermediate isolation station, etc. can be further set up outside each sub-control switch to strictly inspect the incoming and outgoing network data to ensure that only the network data that is clearly allowed to pass can be released.

[0034] In actual use, a wired connection is usually preferred between the sub-control switch and the master control computer instead of a wireless connection. This is because wireless network signals are vulnerable to interception and have relatively low bandwidth, resulting in poor security. Additionally, on a ship, the terrain is complex and there are numerous devices, which can easily block wireless network signals or cause electromagnetic interference, limiting the signal transmission distance and strength. Therefore, for considerations such as network data security and reliability, each sub-control switch is preferably connected to the master control switch using network cables (such as twisted pair cables, coaxial cables, or optical fibers, without limitation here).

[0035] For cases where there may be an interconnection requirement between some sub-control units, a dedicated firewall can be set up between the sub-control switches of different sub-control units, and a wired connection can be used to connect different sub-control switches, thus maximizing the security of the ship's network system and preventing the spread of network attack behaviors between different sub-control units. For example, a simplex serial communication method can be used to connect different sub-control switches.

[0036] The various electronic devices within a sub-control unit can be connected via wired or wireless means. Specifically, within each sub-control unit, depending on the situation, serial communication connections, multi-core cable connections, and coaxial cable connections can be used to achieve wired connections, or wireless connections can be achieved by integrating a wireless network function into the sub-control switch. For example, the sub-control switch of the living local area network unit can integrate a wireless network function to provide wireless connections for the various electronic devices within that sub-control unit (such as crew members' personal computers and personal mobile phones), enabling crew members or passengers to access the external network. For network security reasons, electronic devices using the wireless network can only communicate on the wireless network. For example, electronic devices such as crew members' mobile phones and computers in the living local area network unit can only access the ship's external network and cannot access the electronic devices in other sub-control units.

[0037] In one embodiment, all electronic devices in each sub-control unit are connected together to form a sub-control unit subnet, and each sub-control unit subnet is set with a separate static IP address, port number and network communication protocol. Assigning a separate static IP address to each sub-control unit subnet helps to ensure the stability and manageability of the entire ship network system, because the static IP address is fixed, which enables the network administrator to more conveniently manage and troubleshoot equipment. For example, a specific IP address range (e.g., 192.168.1.xxx) can be assigned to the navigation system unit subnet, and another range (e.g., 192.168.2.xxx) can be assigned to the cabin control unit subnet. By assigning different port numbers to each subnet, network traffic can be more accurately controlled, improving the safety and efficiency of the entire ship network system. For example, the navigation system unit subnet may use a specific port number to access the ECDIS (Electronic Chart Display and Information System) service, while the cabin control unit subnet may use another set of specific port numbers for power station management. By selecting a suitable network communication protocol for each sub-control unit subnet, efficient communication between devices can be ensured and protocol conflicts can be reduced. For example, the flight system unit subnet may use the TCP / IP protocol to implement data transmission between devices, while the cabin control unit subnet may use the industrial Ethernet protocol to control mechanical equipment.

[0038] In one embodiment, some computer systems in the sub-control unit form one or more sub-control sub-units, and the sub-control sub-units are connected to the sub-control switch of the sub-control unit to which they belong through a hub. For example, for the office LAN unit, since both the engine room and the bridge need to use office computers, and the physical distance between the engine room and the bridge is far, it is impossible to directly connect all the electronic equipment inside the two to the sub-control switch of the office LAN unit. Therefore, each electronic equipment in the engine room can be connected to the sub-control switch of the office LAN unit, and then a separate sub-control sub-unit is set up under the office LAN unit, that is, the bridge office unit, and each electronic equipment in the bridge office unit is connected to a hub, and then the hub is connected to the sub-control switch of the office LAN unit.

[0039] In one embodiment, a backup master control firewall can be integrated into the master control switch. When in use, when the master control firewall is working properly, the backup master control firewall is in an unenabled state. When the master control firewall fails to work properly, the backup master control firewall is enabled. This design can ensure that when the master control firewall is breached or fails, the ship network system can automatically switch to another set of backup master control firewalls, thus guaranteeing the normal operation of the ship network communication. In an emergency, relevant personnel can also manually complete the switching operation to ensure that when a cyber attack affects the normal operation of the master control firewall, the master control switch can still provide the expected service capabilities, enabling the ship to quickly get out of the influence of the cyber attack and resume normal operation as much as possible. Similarly, a backup sub-control firewall can also be integrated into the sub-control switch. When the sub-control firewall is working properly, the backup sub-control firewall is in an unenabled state. When the sub-control firewall fails to work properly, the backup sub-control firewall is enabled.

[0040] In one embodiment, the computer system only enables functions that are adapted to the preset tasks to be executed and shuts down or removes other functions. In addition, the computer system only enables ports, communication protocols, and service items that are adapted to the functions already enabled by itself, and shuts down or removes ports, communication protocols, and service items that are not adapted to or irrelevant to the functions already enabled by itself. That is, the computer system in the sub-control unit implements functions according to the "minimum function" principle, only provides the minimum functions required for the normal operation of the ship, and disables or prohibits other unnecessary functions. This design helps to reduce the waste of resources in the ship network system, improve the system operation efficiency, and reduce the security risks caused by unnecessary functions. For example, if a computer system is used for the navigation monitoring task of a ship, it will only enable functions related to the acquisition, processing, and transmission of navigation data, and will not enable functions related to the monitoring of engine room equipment, thus reducing the consumption of system resources and avoiding potential interference and security vulnerabilities.

[0041] In one embodiment, the ship network system adopts a four-layer network model, and the network levels include the transport layer, network layer, data link layer, and physical layer. Among them, the transport layer includes various electronic devices involved in the external communication module, such as converters, antennas, land-based stations, etc.; the network layer includes the master control switch and the master control firewall, which play the roles of forwarding between subnets, supporting dynamic routing, and centralized defense of routing policies and firewall technologies; the data link layer includes each sub-control unit subnet, and each sub-control unit subnet is respectively set with a static IP address, port number, and network communication protocol; the physical layer includes all terminal hardware devices, including the electronic devices of each computer system and hubs, etc.

[0042] The above are only the preferred embodiments of the present application and are not intended to limit the present application. For those skilled in the art, various modifications and variations can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the protection scope of the present application.

Claims

1. A ship network system, characterized in that: include: A master control unit, wherein a master control switch and an external communication module are arranged in the master control unit, and the master control switch realizes two-way network signal transmission with an external network of the ship network system through the external communication module; A plurality of sub-control units, each of which is provided with a sub-control switch and one or more computer systems connected to the sub-control switch, each of which includes a plurality of electronic devices; the sub-control switches of each sub-control unit are connected to the master control switch; The master control firewall is integrated in the master control switch and is used to monitor the network data entering and leaving the master control unit in real time, so that normal data can pass through the master control firewall, while preventing attack data from passing through the master control firewall.

2. The ship network system according to claim 1, characterized in that: A sub-control firewall is integrated in some or all of the sub-control switches to monitor the network data entering and leaving the sub-control unit in real time, so that normal data can pass through the sub-control firewall, while preventing attack data from passing through the sub-control firewall.

3. The ship network system according to claim 1, characterized in that: All electronic devices in each sub-control unit are connected together to form a sub-control unit subnet, and each sub-control unit subnet is respectively set with a separate static IP address, port number and network communication protocol.

4. The ship network system according to claim 1, characterized in that: Part of the computer systems in the sub-control unit form one or more sub-control sub-units, and the sub-control sub-units are connected to the sub-control switch of the sub-control unit to which they belong through a hub.

5. The ship network system according to claim 1, characterized in that: The sub-control units include a navigation system unit, a cabin control unit, a living LAN unit, an office LAN unit and a video monitoring unit.

6. The ship network system according to claim 1, characterized in that: The master control switch integrates a backup master control firewall. When in use, when the master control firewall is working normally, the backup master control firewall is in an inactive state. When the master control firewall cannot work normally, the backup master control firewall is enabled.

7. The ship network system according to claim 2, characterized in that: The sub-control switch integrates a backup sub-control firewall. When in use, when the sub-control firewall is working normally, the backup sub-control firewall is in an inactive state. When the sub-control firewall cannot work normally, the backup sub-control firewall is enabled.

8. The ship network system according to claim 1, characterized in that: The computer system only enables functions that are compatible with the pre-set tasks to be performed, and shuts down or removes other functions; The computer system only enables ports, communication protocols and service items that are compatible with its own enabled functions, and closes or removes ports, communication protocols and service items that are incompatible with or irrelevant to its own enabled functions.

9. The ship network system according to claim 1, characterized in that: The ship network system adopts a four-layer network model, and the network layers of the ship network system include a transport layer, a network layer, a data link layer and a physical layer.

10. The ship network system according to claim 2, characterized in that: The master control firewall and the sub-control firewall have controlled shutdown function, reset function, rollback function and restart function, and can automatically resume normal operation after network interruption or network failure occurs in the ship network system.