A safety assurance and emergency response system and method applied to a ship
By constructing a security architecture of intelligent domain controllers and hull domain controllers, the problems of independent and decentralized ship safety systems and reliance on manual emergency response have been solved, realizing unified management and efficient collaborative response of the entire ship's safety information and improving emergency response capabilities.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- SHANGHAI MERCHANT SHIP DESIGN & RES INST
- Filing Date
- 2025-10-31
- Publication Date
- 2026-08-04
AI Technical Summary
Existing ship safety systems are independent and decentralized, lacking information sharing and collaborative linkage. Emergency response relies on manual operation, and information from emerging intelligent systems cannot be effectively integrated into the overall safety situation awareness and emergency decision-making process.
Construct a security architecture for intelligent domain controllers and hull domain controllers to achieve unified access, intelligent analysis, centralized decision-making, and collaborative response to all types of safety information on the ship. Emergency plans are generated by intelligent domain controllers and executed by hull domain controllers.
It has improved the overall safety level and emergency response capabilities of the ship, and achieved unified management and efficient collaborative response of all types of safety systems on board.
Smart Images

Figure CN121106630B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of ship safety technology, and in particular to a safety assurance and emergency response system and method for ships. Background Technology
[0002] With the continuous improvement of ship intelligence and autonomy, more and more advanced intelligent systems are being integrated on board, such as autonomous navigation systems, intelligent energy efficiency management systems, and equipment health management systems. These systems generate massive amounts of valuable data, but also bring new safety risks and challenges. Traditional ship safety systems (such as fire fighting, stability, lifesaving, and power safety monitoring) are usually designed independently and separately, lacking effective information sharing and collaborative linkage between systems. Emergency response mainly relies on manual operation by crew members based on limited information and procedures, and the response speed and decision-making accuracy need to be improved.
[0003] Therefore, how to effectively integrate information from emerging intelligent systems into the overall security situation awareness and emergency decision-making process, and reliably link them with traditional security execution equipment, is an urgent problem to be solved. Summary of the Invention
[0004] To address the aforementioned technical problems, this application provides a safety assurance and emergency response system and method for ships.
[0005] In a first aspect, embodiments of this application provide a safety assurance and emergency response system for ships, the system including an intelligent domain controller and a hull domain controller, the intelligent domain controller and the hull domain controller being electrically connected; wherein:
[0006] The intelligent domain controller is used to generate at least one first emergency plan for ship equipment based on first ship equipment data associated with the intelligent domain controller and / or second ship equipment data associated with the hull domain controller.
[0007] The hull domain controller is used to control the corresponding equipment on the ship based on at least one ship equipment first emergency plan.
[0008] Secondly, embodiments of this application provide a method for ship safety assurance and emergency response, applied to a ship safety assurance and emergency response system as described in the first aspect; the method includes:
[0009] Based on the first ship equipment data associated with the intelligent domain controller and / or the second ship equipment data associated with the hull domain controller in the system, at least one ship equipment first emergency plan is generated.
[0010] Control the corresponding equipment on the ship based on at least one ship equipment first emergency plan.
[0011] Thirdly, this application also provides an electronic device, comprising:
[0012] One or more processors;
[0013] Memory, used to store one or more programs.
[0014] When the one or more programs are executed by the one or more processors, the one or more processors implement the safety assurance and emergency response methods for ships as described in the second aspect above.
[0015] Fourthly, this application also provides a storage medium storing a computer program thereon, which, when executed by a processor, implements the safety assurance and emergency response methods for ships as described in the second aspect above.
[0016] Fifthly, this application also provides a computer program product, including a computer program that, when executed by a processor, implements the safety assurance and emergency response methods for ships as described in the second aspect above.
[0017] This application proposes a safety assurance and emergency response system and method for ships. The system includes an intelligent domain controller and a hull domain controller, electrically connected. The intelligent domain controller generates at least one first emergency plan for ship equipment based on first ship equipment data associated with it and / or second ship equipment data associated with it. The hull domain controller controls the corresponding equipment on the ship based on the at least one first emergency plan. This system provides a ship-wide safety system architecture and its operating mode for intelligent ship safety assurance and emergency response, enabling unified access, intelligent analysis, centralized decision-making, collaborative response, and reliable execution of all types of safety-related information (including emerging intelligent systems and traditional safety systems) across the ship, thereby improving the overall safety level and emergency response capabilities of the vessel. Attached Figure Description
[0018] Figure 1 This is a schematic diagram of the architecture of a ship safety assurance and emergency response system provided in an embodiment of this application;
[0019] Figure 2 A schematic diagram of the architecture of the intelligent domain controller provided in the embodiments of this application;
[0020] Figure 3 A schematic diagram of the architecture of the ship domain controller provided in the embodiments of this application;
[0021] Figure 4This is one of the flowcharts illustrating a method for ensuring the safety and emergency response of ships, provided in an embodiment of this application.
[0022] Figure 5 The second schematic diagram of a method for ensuring the safety and emergency response of ships provided in this application embodiment;
[0023] Figure 6 The third flowchart illustrating a method for ensuring ship safety and emergency response, provided as an embodiment of this application;
[0024] Figure 7 The fourth flowchart illustrating a method for ensuring ship safety and emergency response, provided as an embodiment of this application;
[0025] Figure 8 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation
[0026] The present application will now be described in further detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative of the application and not intended to limit it. Furthermore, it should be noted that, for ease of description, the accompanying drawings show only the parts relevant to the present application, not the entire structure.
[0027] The following section introduces the relevant knowledge involved in this application.
[0028] With the continuous improvement of ship intelligence and autonomy, more and more advanced intelligent systems are being integrated on board, such as autonomous navigation systems, intelligent energy efficiency management systems, and equipment health management systems. These systems generate massive amounts of valuable data, but also bring new safety risks and challenges. Traditional ship safety systems (such as fire protection, stability, lifesaving, and power safety monitoring) are usually designed independently and separately, lacking effective information sharing and collaborative linkage between systems. Emergency response mainly relies on manual operation by crew members based on limited information and procedures, and the response speed and decision-making accuracy need to be improved. In addition, how to effectively integrate the information of emerging intelligent systems into the overall safety situation awareness and emergency decision-making process, and reliably link them with traditional safety execution equipment, is a key technical challenge currently facing the field of intelligent ship safety. Existing technologies lack a top-level safety architecture that can achieve unified management, intelligent decision-making, and efficient collaboration.
[0029] In other words, the relevant technology has the following drawbacks:
[0030] 1. Independence and Decentralization: Existing ship safety systems are typically designed independently and decentralizedly, lacking effective information sharing and coordination among subsystems (such as fire protection, watertight doors, and emergency power supplies). In emergencies, the response speed and decision-making accuracy of each system are often limited, making it impossible to form a unified and comprehensive safety control posture.
[0031] 2. Information silos and decision lag: In traditional systems, there is a lack of unified interfaces and coordination mechanisms between intelligent subsystems (such as autonomous navigation systems and intelligent energy efficiency management systems) and traditional safety systems (such as watertight doors and fire protection systems), resulting in information silos. The system's response often relies on manual operation by crew members based on limited experience and procedures, lacking intelligent decision support, and resulting in insufficient response time and decision accuracy.
[0032] 3. Emergency response relies on manual intervention: Current emergency responses primarily depend on crew members operating manually based on limited information, experience, and standard operating procedures. Because crew members may face incomplete information or decision-making delays in emergency situations, traditional emergency response plans are often inefficient and imprecise.
[0033] 4. Emerging intelligent systems lack security guarantees: Information from emerging intelligent systems cannot be effectively integrated into the overall security situation awareness and emergency decision-making process, and cannot be reliably linked with traditional security execution equipment.
[0034] In summary, the embodiments of this application aim to solve the above-mentioned problems in the related technologies, construct a top-level security architecture with unified management, intelligent decision-making, and efficient collaboration, and provide an intelligent ship safety assurance and emergency response system architecture and its working mode. This enables unified access, intelligent analysis, centralized decision-making, collaborative response, and reliable execution of all types of safety-related information on the entire ship (including emerging intelligent systems and traditional safety systems), thereby improving the overall safety level and emergency response capabilities of the ship.
[0035] Figure 1 This is a schematic diagram of the architecture of a ship safety assurance and emergency response system provided in an embodiment of this application. See also... Figure 1 As shown, the safety and emergency response system applied to ships includes an Intelligent Domain Controller (IDC) and a Vessel Domain Controller (VDC), with the IDC and VDC electrically connected; wherein:
[0036] In some embodiments, the intelligent domain controller acts as the "brain" of the system, responsible for aggregating and processing information from various intelligent subsystems of the ship, performing situational awareness, risk assessment, intelligent decision-making, and generating contingency plans (such as emergency response instructions).
[0037] Intelligent domain controllers are responsible for assessing resource availability and environmental conditions during emergency response, in order to optimize emergency response strategies and ensure the effectiveness of command execution in emergency situations.
[0038] In practical applications, intelligent domain controllers are mounted on high-performance computing platforms.
[0039] In some embodiments, the hull domain controller acts as the "cerebellum" and "limbs" of the system, responsible for receiving and executing emergency plans from the intelligent domain controller, and directly controlling and monitoring the ship's traditional safety execution systems and equipment (such as fire protection systems, watertight door systems, emergency power systems, and some power system safety-related equipment).
[0040] The ship's domain controller also collects status information from traditional systems and can receive local direct commands or alarm signals. The domain controller also handles human-machine interaction (e.g., via the bridge or control room console), receiving operator confirmations or overriding commands.
[0041] In practical applications, the hull domain controller also includes data logging functionality (black box). The hull domain controller can be deployed on a high real-time platform.
[0042] In some embodiments, the intelligent domain controller is configured to generate at least one first emergency plan for ship equipment based on first ship equipment data associated with the intelligent domain controller and / or second ship equipment data associated with the hull domain controller.
[0043] In practical applications, the primary ship equipment data associated with the intelligent domain controller comes from emerging intelligent subsystems. These intelligent subsystems can be collectively referred to as the System Abstraction Layer (PSAL), and include, but are not limited to, digital base stations, communication network security systems, autonomous navigation systems, autonomous berthing and unberthing systems, remote control systems, equipment health management systems, and intelligent cargo management systems. These constitute the main information sources for the intelligent domain controller.
[0044] The second set of ship equipment data associated with the hull domain controller comes from ship equipment data from traditional safety subsystems. Traditional safety subsystems include, but are not limited to, pumps, valves, sensors, circuit breakers, fire alarm systems, electrical safety management systems, flooding detection systems, and communication and conduction systems. These are the primary information sources for the hull domain controller.
[0045] The hull domain controller is used to control the corresponding equipment on the ship based on at least one ship equipment first emergency plan.
[0046] The above system provides a ship-wide safety system architecture and its working method for intelligent ship safety assurance and emergency response. It enables unified access, intelligent analysis, centralized decision-making, collaborative response, and reliable execution of all types of safety-related information (including emerging intelligent systems and traditional safety systems) on the ship, thereby improving the overall safety level and emergency response capabilities of the ship.
[0047] Figure 2 This is a schematic diagram of the architecture of the intelligent domain controller provided in an embodiment of this application. See also... Figure 2 As shown, the intelligent domain controller includes: an intelligent system interface module, a data fusion module, a situational awareness module, a risk assessment module, a decision engine module, an emergency response planning module, and a first-security communication module; wherein:
[0048] The intelligent system interface module is used to receive first ship equipment data sent by at least one first ship equipment and send the first ship equipment data to the data fusion module.
[0049] In some embodiments, the intelligent system interface module provides a standardized interface for various heterogeneous intelligent subsystems accessing the intelligent domain controller. The intelligent system interface module can shield the communication protocols and data format differences of the underlying systems, decoupling the security system from the intelligent system, and facilitating the addition or replacement of intelligent subsystems (both can evolve and be replaced independently).
[0050] In practical applications, a standard API (e.g., based on the publish / subscribe model DDS, or the request / response model such as RESTful API) and a unified data model (e.g., defining security-related data structures using JSON, XML, or specific binary formats) can be defined. PSAL internally contains adapters or drivers that convert device data from different intelligent subsystems (using their respective protocols via physical interfaces such as Ethernet, CAN, and serial ports) into a standardized format.
[0051] The first security communication module is used to receive the second ship equipment data sent by the ship domain controller and send the second ship equipment data to the data fusion module.
[0052] In some embodiments, the first secure communication module is responsible for establishing and maintaining a secure and reliable communication connection with the ship's domain controller. This includes implementing encrypted data transmission, authentication, and integrity verification.
[0053] The data fusion module is used to fuse the equipment data of the first ship and / or the equipment data of the second ship to obtain fused data, and then send the fused data to the situational awareness module.
[0054] In some embodiments, the data fusion module collects standardized data (first ship equipment data) from the intelligent system interface module and / or status information (second ship equipment data) from the ship domain controller; then it performs data cleaning, time synchronization, validity verification, and multi-source data fusion (e.g., combining navigation status, equipment health prediction, and environmental perception information) to form fused data.
[0055] The situational awareness module is used to determine the current risk type of a vessel based on fused data.
[0056] In some embodiments, the situational awareness module is used to make a comprehensive judgment on the overall safety status of the ship (situational awareness) and determine the current risk type of the ship, such as collision risk, fire risk, stability risk, equipment failure risk, etc.
[0057] The risk assessment module is used to assess risks based on risk types and obtain the risk level corresponding to the risk type; the risk type and / or risk level are then sent to the decision engine module.
[0058] In some embodiments, the risk assessment module comprehensively evaluates the security risk level corresponding to the current risk type based on the situational awareness results (risk type), by comparing them with preset security thresholds, rules, AI / ML-based risk prediction models, and multi-factor comprehensive security risk assessment models based on large models.
[0059] The decision engine module is used to determine at least one risk management strategy based on risk type and / or risk level; and to send at least one risk management strategy to the emergency response planning module.
[0060] An emergency response planning module is used to determine at least one primary emergency plan for ship equipment based on at least one risk management strategy; to send at least one primary emergency plan for ship equipment to a second security communication module in the ship domain controller; the second security communication module is used to send at least one primary emergency plan for ship equipment to a human-machine interface in the ship domain controller; and the human-machine interface is used to display at least one primary emergency plan for ship equipment on a display device.
[0061] In some embodiments, the decision engine module receives risk assessment results (risk type and / or risk level). Internally, it contains a configurable and updatable rule base that stores classification society regulations, shipowner / management company emergency plans, ship-specific safety operating procedures, etc.
[0062] The emergency response planning module automatically generates one or more structured emergency plans (including specific action steps, resources / equipment to be mobilized, and expected goals) based on risk type, risk level, and rule base.
[0063] In some embodiments, it may be necessary to optimize the contingency plan based on current resource availability (feedback from the ship's domain controller) and environmental conditions.
[0064] Figure 3 This is a schematic diagram of the architecture of a ship hull domain controller provided in an embodiment of this application. See also... Figure 3 As shown, the ship's domain controller includes: a second security communication module, a command parsing and distribution module, a device driver and interface module, and a human-machine interface; wherein:
[0065] The second security communication module is used to receive at least one first emergency plan for ship equipment sent by the intelligent domain controller, and to send at least one first emergency plan for ship equipment to the human-machine interface.
[0066] In some embodiments, the second secure communication module is used to communicate securely with the intelligent domain controller, receive instructions, and provide status feedback.
[0067] The human-machine interface module is used to display the first emergency plan for at least one piece of ship equipment on the display interface. In some embodiments, the human-machine interface may be located on the bridge, in the control room or other necessary locations, and is used to display the system status, alarm information, and emergency plans to be confirmed to the crew, and to receive instructions from the crew (confirmation, rejection, manual bypass).
[0068] The human-machine interface module presents system status, early warning information, and generated emergency plans to the operator in a clear and intuitive manner (such as graphics, lists, and text). It processes operator confirmation, rejection, or modification instructions. It also manages unauthorized access permissions and operation logs.
[0069] The human-machine interface module is also used to send at least one first emergency plan for ship equipment to the instruction parsing and distribution module upon receiving a first instruction from the user; the first instruction is used to instruct the execution of at least one first emergency plan for ship equipment.
[0070] The instruction parsing and distribution module is used to send the first emergency plan of at least one ship equipment to the equipment driver and interface module.
[0071] In some embodiments, the instruction parsing and distribution module is used to parse standardized emergency response instructions (i.e., the first emergency plan, such as "start area A fire pump" or "close the watertight door of compartment B") and over-control instructions from the intelligent domain controller and the human-machine interface. These logical instructions are then distributed to the corresponding device driver and interface modules.
[0072] The device driver and interface module is used to control the corresponding equipment on the ship based on at least one ship equipment first emergency plan.
[0073] In some embodiments, the device driver and interface module includes a hardware interface and software driver for connecting to specific physical devices or fieldbuses (such as CAN, Modbus RTU / TCP, NMEA 0183 / 2000, Ethernet / IP, digital I / O, analog I / O, etc.). It is responsible for the actual signal transmission and data acquisition.
[0074] In practical applications, the second ship equipment data associated with the hull domain controller comes from the ship equipment data of the traditional safety subsystems. These traditional safety subsystems can be collectively referred to as the System / Equipment Abstraction Layer (SDAL). SDAL provides a unified control and monitoring interface for the various traditional safety execution systems / equipment controlled by the hull domain controller, shielding the interface differences of the underlying hardware (such as different bus types, control protocols, and data points). For example, SDAL defines a standard control object model (including state attributes and control methods) for each type of equipment (such as pumps, valves, sensors, and circuit breakers). SDAL converts standardized instructions (such as "on") from device drivers and interface modules into commands that specific devices can understand (such as writing a specific value to a Modbus address or closing a relay).
[0075] See Figure 2 and Figure 3 As shown, in some embodiments, the intelligent domain controller further includes a risk warning module; the risk assessment module in the intelligent domain controller is also used to send the risk type and / or risk level to the risk warning module.
[0076] The risk warning module is used to generate warning information when the risk level exceeds a preset threshold; and to send the warning information to the first security communication module in the intelligent domain controller; the first security communication module is also used to send the warning information to the human-machine interface in the ship domain controller; the human-machine interface is used to display the warning information on the display interface.
[0077] See Figure 3 As shown, in some embodiments, the hull domain controller further includes a status acquisition and feedback module; the device driver and interface module in the hull domain controller is also used to acquire status information of associated ship equipment; send the status information to the status acquisition and feedback module; the status acquisition and feedback module is used to send the status information to the human-machine interface in the hull domain controller; the human-machine interface is used to display the status information on the display interface.
[0078] In some embodiments, the status acquisition and feedback module can periodically or event-drivenly acquire status information (such as running / stopping, on / off, pressure, temperature, flow rate, voltage, current, fault codes, etc.) of the connected devices. This status information is then formatted and fed back to the human-machine interface, and simultaneously fed back to the intelligent domain controller via a second secure communication interface.
[0079] See Figure 3 As shown, in some embodiments, the ship domain controller further includes a local security logic and rapid response module. This module is used to generate at least one second emergency plan for ship equipment in the event of a target event, and to send the at least one second emergency plan to the human-machine interface in the ship domain controller.
[0080] The target event includes at least one of the following:
[0081] 1. The connection between the hull domain controller and the intelligent domain controller is interrupted, and the device associated with the hull domain controller malfunctions.
[0082] 2. Preset events that require the local security logic and rapid response module to generate a second emergency plan.
[0083] The human-computer interaction interface is used to display the second emergency plan for the missing ship equipment on the display screen.
[0084] The human-machine interface module is also used to send at least one second emergency plan for ship equipment to the device driver and interface module in the ship domain controller when a second instruction is received from the user; the second instruction is used to instruct the execution of at least one second emergency plan for ship equipment.
[0085] The device driver and interface module is used to control the corresponding equipment on the ship based on at least one second emergency plan for ship equipment.
[0086] In practical applications, local security logic and fast response modules are used to implement basic, time-critical security logic that needs to be executed even when communication with the smart domain controller is interrupted. For example, a local smoke sensor can directly trigger an audible and visual alarm for the local area; or, upon receiving a signal that the smart domain controller has lost connection, it can automatically execute a preset safety procedure (such as shutting down certain ventilation systems) and receive local over-control commands.
[0087] In some embodiments, the hull domain controller also includes a data logging module (black box). The data logging module securely and tamper-proofly records critical data as required (such as some requirements for VDRs - navigation data recorders) and as needed by the system.
[0088] In practical applications, the data logging module records at least the following: instructions received from the intelligent domain controller, control commands sent to devices, status feedback from critical devices, important data from local sensors, system alarm events, unauthorized operations, communication status with the intelligent domain controller, and system self-diagnostic information. The data logging module uses reliable storage media and possesses data protection and recovery capabilities.
[0089] In some embodiments, to ensure the reliability and continuous operation capability of the safety assurance and emergency response systems applied to ships in the event of failure, the embodiments of this application employ a multi-level redundancy design:
[0090] 1. Intelligent Domain Controller (IDC) Redundancy: A dual-machine hot standby configuration is adopted, with the primary and standby intelligent domain controllers synchronizing their states in real time. This ensures that the standby intelligent domain controller can seamlessly take over in the event of a primary intelligent domain controller failure, minimizing system downtime. Furthermore, the redundant system supports an intelligent failover mechanism; upon detecting a primary intelligent domain controller failure, the standby intelligent domain controller can automatically take over within milliseconds, ensuring stable system operation.
[0091] 2. Redundancy of hull domain controller (VDC): Hull domain controllers for critical areas or functions can be configured with dual-machine redundancy.
[0092] 3. Network Redundancy: Physically independent dual-channel redundant networks (e.g., two Ethernet cables running on different paths) are used between the intelligent domain controller and the ship's domain controller, and between the ship's domain controller and critical equipment. Redundancy-supporting protocols (such as PRP / HSR) or link aggregation are used.
[0093] 4. Power redundancy: Both the intelligent domain controller and the ship's domain controller are powered by the ship's main power supply and emergency power supply (through UPS or DC system) simultaneously, and have power monitoring and automatic switching capabilities.
[0094] 5. Fault Detection and Recovery (FDIR): The system has built-in heartbeat detection, status monitoring, and self-diagnostic programs, which can promptly detect hardware failures, software anomalies, or communication interruptions and trigger corresponding switching logic or alarms.
[0095] 6. Network security: The system architecture was designed with network security protection in mind, including the following points (1) and (6):
[0096] (1) Secure communication: Encryption (such as TLS / DTLS), message authentication (MAC), and two-way authentication mechanisms are used between the intelligent domain controller and the ship's domain controller, as well as between the intelligent domain controller / ship's domain controller and external interfaces, to ensure the confidentiality and integrity of data during communication. In addition, the system design also includes protection mechanisms against common network attacks, such as DDoS attacks and MITM attacks, to ensure the safety of the ship in complex network environments.
[0097] (2) Network isolation: Safety-critical networks are strictly physically or logically isolated from other ship information networks (such as crew entertainment networks and office networks) (through firewalls and gateways).
[0098] (3) Access control: Implement strict identity authentication and permission management for HMI and system configuration interfaces.
[0099] (4) System hardening: Harden the operating system and applications of the intelligent domain controller / hull domain controller, close unnecessary services and ports, and patch vulnerabilities in a timely manner.
[0100] (5) Security audit: The black box of the hull domain controller and the log system of the intelligent domain controller record all important security events and operations, which facilitates post-event auditing.
[0101] (6) Secure Boot: The intelligent domain controller / hull domain controller adopts a secure boot mechanism to ensure that the loaded firmware and software have not been tampered with.
[0102] Figure 4 This is one of the flowcharts illustrating a method for ensuring safety and responding to emergencies on ships, provided as an embodiment of this application. See also... Figure 4 As shown, this method is applied to, for example Figures 1-3 The safety and emergency response system applied to ships shown includes the following steps S401 to S402:
[0103] Step S401: Based on the first ship equipment data associated with the intelligent domain controller and / or the second ship equipment data associated with the hull domain controller in the system, generate at least one first emergency plan for ship equipment.
[0104] Step S402: Control the corresponding equipment on the ship based on at least one ship equipment first emergency plan.
[0105] The above method provides a ship-wide safety response approach for intelligent ship safety assurance and emergency response, enabling unified access, intelligent analysis, centralized decision-making, collaborative response, and reliable execution of all types of safety-related information (including emerging intelligent systems and traditional safety systems) across the ship, thereby improving the overall safety level and emergency response capabilities of the vessel.
[0106] Figure 5 This is the second flowchart illustrating a method for ship safety assurance and emergency response provided in this application. See also... Figure 5 As shown, this method is applied to, for example Figures 1-3 The safety and emergency response system applied to ships shown includes the following steps S501 to S512:
[0107] Step S501: The intelligent system interface module of the intelligent domain controller receives first ship equipment data sent by at least one first ship equipment, and sends the first ship equipment data to the data fusion module.
[0108] Step S502: The first security communication module of the intelligent domain controller receives the second ship equipment data sent by the ship domain controller and sends the second ship equipment data to the data fusion module of the intelligent domain controller.
[0109] Step S503: The data fusion module of the intelligent domain controller performs fusion processing on the first ship equipment data and / or the second ship equipment data to obtain fused data, and sends the fused data to the situational awareness module of the intelligent domain controller.
[0110] Step S504: The situational awareness module of the intelligent domain controller determines the current risk type of the ship based on the fused data.
[0111] Step S505: The risk assessment module of the intelligent domain controller assesses the risk type and obtains the risk level corresponding to the risk type; the risk type and / or risk level are sent to the decision engine module of the intelligent domain controller.
[0112] Step S506: The decision engine module of the intelligent domain controller determines at least one risk handling strategy based on the risk type and / or risk level; and sends the at least one risk handling strategy to the emergency response planning module of the intelligent domain controller.
[0113] Step S507: The emergency response planning module of the intelligent domain controller determines at least one first emergency plan for ship equipment based on at least one risk handling strategy; sends at least one first emergency plan for ship equipment to the second security communication module in the ship domain controller; the second security communication module is used to send at least one first emergency plan for ship equipment to the human-machine interface in the ship domain controller; the human-machine interface is used to display at least one first emergency plan for ship equipment on the display device.
[0114] Step S508: The second security communication module of the ship domain controller receives at least one first emergency plan for ship equipment sent by the intelligent domain controller, and sends at least one first emergency plan for ship equipment to the human-machine interface.
[0115] Step S509: The human-machine interface module of the ship domain controller displays the first emergency plan of at least one ship equipment on the display interface.
[0116] In step S510, upon receiving a first instruction from the user, the human-machine interface module of the ship domain controller sends at least one first emergency plan for ship equipment to the instruction parsing and distribution module; the first instruction is used to indicate the execution of at least one first emergency plan for ship equipment.
[0117] Step S511: The instruction parsing and distribution module of the ship domain controller sends the first emergency plan of at least one ship equipment to the equipment driver and interface module.
[0118] Step S512: The backup driver and interface module of the ship domain controller controls the corresponding equipment in the ship based on at least one ship equipment first emergency plan.
[0119] Figure 6 This is the third flowchart illustrating a method for ship safety assurance and emergency response provided in this application. See also... Figure 6 As shown, this method is applied to, for example Figures 1-3 The safety and emergency response system applied to ships shown includes the following steps S601 to S602:
[0120] Step S601: The device driver and interface module of the ship domain controller obtains the status information of the associated ship equipment and sends the status information to the status acquisition and feedback module.
[0121] Step S602: The status acquisition and feedback module of the hull domain controller sends the status information to the human-machine interface in the hull domain controller; the human-machine interface is used to display the status information on the display screen.
[0122] Figure 7 This is the fourth flowchart illustrating a method for ship safety assurance and emergency response provided in this application. See also... Figure 7 As shown, this method is applied to, for example Figures 1-3 The safety and emergency response system applied to ships shown includes the following steps S701 to S704:
[0123] Step S701: When the target event is triggered, the local security logic and fast response module of the ship domain controller generates at least one second emergency plan for ship equipment; and sends at least one second emergency plan for ship equipment to the human-machine interface in the ship domain controller.
[0124] Step S702: The human-machine interface of the ship's domain controller displays at least one second emergency plan for ship equipment on the display screen.
[0125] Step S703: Upon receiving a second instruction from the user, the human-machine interface of the hull domain controller sends at least one second emergency plan for ship equipment to the device driver and interface module of the hull domain controller; the second instruction is used to instruct the execution of at least one second emergency plan for ship equipment.
[0126] Step S704: The device driver and interface module of the ship domain controller controls the corresponding equipment in the ship based on at least one second emergency plan for ship equipment.
[0127] The following section uses fire emergency response as an example to further illustrate the safety assurance and emergency response methods applied to ships:
[0128] Step 1: A smart fire detector (belonging to the intelligent subsystem) or a traditional smoke detector (belonging to the traditional safety equipment, connected to the ship's domain controller) in a certain compartment detects signs of fire.
[0129] Step 2: If it is an intelligent detector, the information is transmitted to the PSAL of the IDC through its interface, and after standardization, it is sent to the data fusion module.
[0130] If it is a traditional probe, the signal is sent directly to the ship's domain controller. The status acquisition module of the ship's domain controller obtains the information and reports it to the intelligent domain controller through secure communication (at the same time, local logic may have triggered a local alarm).
[0131] Step 3: The data fusion module of the intelligent domain controller confirms the fire information (possibly in conjunction with other sensor information, such as temperature and video), and the situational awareness module determines the location and initial severity of the fire.
[0132] Step 4: The risk assessment module assesses the fire risk level and triggers a high-level fire alarm.
[0133] Step 5: The decision engine generates an emergency response plan based on the rule base (such as SOLAS fire protection requirements and ship fire extinguishing plans), such as: starting the fire pump in the area, shutting off ventilation, closing fire doors, releasing extinguishing agents (if any), issuing a ship-wide alarm, and notifying relevant personnel.
[0134] Step 6: The decision engine, based on a rule base (such as SOLAS fire protection requirements and ship fire extinguishing plans), combines AI / ML models to perform comprehensive analysis and generate an emergency response plan. This plan not only considers preset regulatory requirements but also dynamically adjusts the response plan based on actual risk assessments (such as fire severity and equipment availability).
[0135] For example, actions include: starting the area's fire pumps, shutting off ventilation, closing fire doors, releasing extinguishing agents (if any), issuing a ship-wide alarm, and notifying relevant personnel. This decision-making process also automatically considers the ship's current condition and environmental circumstances to optimize resource allocation.
[0136] Step 7: The emergency plan is presented to the crew in the bridge / control room through the human-machine interface module.
[0137] Step 8: The crew confirms the plan within the specified time. (Alternatively, depending on preset rules and the urgency of the risk, the smart domain controller may be configured to skip this step in certain situations or execute it automatically after the timeout). If the crew rejects or modifies the plan, the new instructions are executed or a new plan is devised.
[0138] Step 9: The intelligent domain controller sends the confirmed (or automatically executed) command to the hull domain controller via secure communication. The command is standardized, such as "ExecuteFireResponsePlan(Zone_A)".
[0139] Step 10: The instruction parsing module of the ship's domain controller parses the instructions and controls the corresponding equipment to perform actions (starting the fire pump, closing the air damper, closing the fire door, etc.) through SDAL and device driver control.
[0140] Step 11: The status acquisition module of the ship hull domain controller continuously monitors the status of the controlled equipment (such as whether the pump has started successfully, whether the valve is closed properly, and whether the pressure has been established), and feeds back the status information to the intelligent domain controller.
[0141] Step 12: The intelligent domain controller receives feedback information, updates situational awareness, evaluates the response effect, and may adjust subsequent actions as needed.
[0142] Step 13: The black box module of the ship's domain controller records key commands, actions, statuses, and alarm information throughout the entire process.
[0143] This application also provides a computer program product, which includes a computer program that, when executed by a processor, implements the safety assurance and emergency response methods for ships provided in the above embodiments; or the computer program, when executed by a processor, implements the safety assurance and emergency response methods for ships provided in the above embodiments.
[0144] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer program products, which may include one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be an application-specific or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.
[0145] Figure 8 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application, with reference to... Figure 8 , Figure 8 The electronic device 12 shown is merely an example and should not be construed as limiting the functionality and scope of the embodiments of this application. Figure 8 As shown, the electronic device 12 is represented in the form of a general-purpose computing device. The components of the electronic device 12 may include, but are not limited to: one or more processors or processing units 16, system memory 28, and bus 18 connecting different system components (including system memory 28 and processing unit 16).
[0146] Bus 18 represents one or more of several bus architectures, including a memory bus or memory controller, a peripheral bus, a graphics acceleration port, a processor, or a local bus using any of the various bus architectures. For example, these architectures include, but are not limited to, the Industry Standard Architecture (ISA) bus, the Micro Channel Architecture (MAC) bus, the Enhanced ISA bus, the Video Electronics Standards Association (VESA) local bus, and the Peripheral Component Interconnect (PCI) bus.
[0147] Electronic device 12 typically includes a variety of computer system readable media. These media can be any available media that can be accessed by electronic device 12, including volatile and non-volatile media, removable and non-removable media.
[0148] System memory 28 may include computer system readable media in the form of volatile memory, such as random access memory (RAM) 30 and / or cache memory 32. Electronic device 12 may further include other removable / non-removable, volatile / non-volatile computer system storage media. By way of example only, storage system 34 may be used to read and write non-removable, non-volatile magnetic media (… Figure 8 Not shown; usually referred to as a "hard drive"). Although Figure 8 As not shown, a disk drive for reading and writing to a removable non-volatile disk (e.g., a "floppy disk") and an optical disk drive for reading and writing to a removable non-volatile optical disk (e.g., a CD-ROM, DVD-ROM, or other optical media) may be provided. In these cases, each drive may be connected to bus 18 via one or more data media interfaces. Memory 28 may include at least one program product having a set (e.g., at least one) of program modules configured to perform the functions of the embodiments of this application.
[0149] A program / utility 40 having a set (at least one) of program modules 46 may be stored, for example, in memory 28. Such program modules 46 include, but are not limited to, an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include an implementation of a network environment. Program modules 46 typically perform the functions and / or methods described in the embodiments of this application.
[0150] Electronic device 12 can also communicate with one or more external devices 14 (e.g., keyboard, pointing device, display 24, etc.), and with one or more devices that enable a user to interact with electronic device 12, and / or with any device that enables electronic device 12 to communicate with one or more other computing devices (e.g., network card, modem, etc.). This communication can be performed via input / output (I / O) interface 22. Furthermore, electronic device 12 can also communicate with one or more networks (e.g., local area network (LAN), wide area network (WAN), and / or public networks, such as the Internet) via network adapter 20. As shown, network adapter 20 communicates with other modules of electronic device 12 via bus 18. It should be understood that, although... Figure 8 As not shown, other hardware and / or software modules may be used in conjunction with electronic device 12, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.
[0151] The processing unit 16 executes various functional applications and data processing by running programs stored in the system memory 28. For example, it implements the safety assurance and emergency response method for ships provided in the embodiments of the present invention, which includes: generating at least one first emergency plan for ship equipment based on first ship equipment data associated with the intelligent domain controller and / or second ship equipment data associated with the hull domain controller; and controlling the corresponding equipment in the ship based on at least one first emergency plan for ship equipment.
[0152] This invention provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the ship safety assurance and emergency response method provided in all embodiments of this invention, including: generating at least one ship equipment first emergency plan based on first ship equipment data associated with an intelligent domain controller and / or second ship equipment data associated with a hull domain controller; and controlling corresponding equipment in the ship based on the at least one ship equipment first emergency plan. The computer-readable medium can be a computer-readable signal medium or a computer-readable storage medium. For example, a computer-readable storage medium can be, but is not limited to, an electronic device, apparatus, or device that is electrical, magnetic, optical, electromagnetic, infrared, or semiconductor, or any combination thereof. More specific examples of computer-readable storage media (a non-exhaustive list) include: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this document, a computer-readable storage medium can be any tangible medium that contains or stores a program that can be used or combined with an electronic device, apparatus, or device by instructions to execute it.
[0153] Computer-readable signal media may include data signals propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. Computer-readable signal media may also be any computer-readable medium other than computer-readable storage media, capable of sending, propagating, or transmitting programs for use by or in conjunction with an electronic device, apparatus, or device that executes instructions.
[0154] Program code contained on a computer-readable medium may be transmitted using any suitable medium, including but not limited to wireless, wire, optical fiber, RF, etc., or any suitable combination thereof.
[0155] Computer program code for performing the operations of this invention can be written in one or more programming languages or a combination thereof. Programming languages include object-oriented programming languages such as Java, Smalltalk, and C++, as well as conventional procedural programming languages such as C or similar languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0156] Note that the above description is merely a preferred embodiment of the present invention and the technical principles employed. Those skilled in the art will understand that the present invention is not limited to the specific embodiments described herein, and various obvious changes, readjustments, and substitutions can be made without departing from the scope of protection of the present invention. Therefore, although the present invention has been described in detail through the above embodiments, the present invention is not limited to the above embodiments, and may include many other equivalent embodiments without departing from the concept of the present invention, the scope of which is determined by the scope of the appended claims.
Claims
1. A safety assurance and emergency response system for ships, characterized in that, The system includes an intelligent domain controller and a hull domain controller, with the intelligent domain controller electrically connected to the hull domain controller. The intelligent domain controller includes: an intelligent system interface module, a data fusion module, a situational awareness module, a risk assessment module, a decision engine module, an emergency response planning module, and a first security communication module. The hull domain controller includes: a second security communication module, a command parsing and distribution module, a device driver and interface module, and a human-machine interface. The intelligent domain controller is used to generate at least one first emergency plan for ship equipment based on first ship equipment data associated with the intelligent domain controller and / or second ship equipment data associated with the hull domain controller. The ship domain controller is used to control the corresponding equipment on the ship based on the at least one ship equipment first emergency plan; wherein... The intelligent system interface module is used to receive first ship equipment data sent by at least one first ship equipment, and send the first ship equipment data to the data fusion module; the first security communication module is used to receive second ship equipment data sent by the hull domain controller, and send the second ship equipment data to the data fusion module; the data fusion module is used to perform fusion processing on the first ship equipment data and / or the second ship equipment data to obtain fused data, and send the fused data to the situation awareness module; the situation awareness module is used to determine the current risk type of the ship based on the fused data; the risk assessment module is used to perform assessment based on the risk type to obtain the risk level corresponding to the risk type; and the... The risk type and / or risk level are sent to the decision engine module; the decision engine module is used to determine at least one risk handling strategy based on the risk type and / or the risk level; and send the at least one risk handling strategy to the emergency response planning module; the emergency response planning module is used to determine at least one first emergency plan for ship equipment based on the at least one risk handling strategy; and send the at least one first emergency plan for ship equipment to a second security communication module in the ship domain controller; the second security communication module is used to send the at least one first emergency plan for ship equipment to a human-machine interface in the ship domain controller; the human-machine interface is used to display the at least one first emergency plan for ship equipment on a display device; The second security communication module is used to receive the first emergency plan for at least one ship equipment sent by the intelligent domain controller, and send the first emergency plan for at least one ship equipment to the human-machine interface; the human-machine interface is used to display the first emergency plan for at least one ship equipment on the display interface; the human-machine interface is also used to send the first emergency plan for at least one ship equipment to the instruction parsing and distribution module upon receiving a first instruction from the user; the first instruction is used to instruct the execution of the first emergency plan for at least one ship equipment; the instruction parsing and distribution module is used to send the first emergency plan for at least one ship equipment to the device driver and interface module; the device driver and interface module is used to control the corresponding equipment in the ship based on the first emergency plan for at least one ship equipment.
2. The system according to claim 1, characterized in that, The intelligent domain controller also includes a risk warning module; The risk assessment module in the intelligent domain controller is also used to send the risk type and / or risk level to the risk warning module; The risk warning module is used to generate warning information when the risk level exceeds a preset threshold; and to send the warning information to the first security communication module in the intelligent domain controller. The first security communication module is further configured to send the warning information to the human-machine interface in the ship domain controller; the human-machine interface is configured to display the warning information on the display interface.
3. The system according to claim 1, characterized in that, The hull domain controller also includes a status acquisition and feedback module; The device driver and interface module in the hull domain controller is also used to acquire the status information of associated ship equipment and send the status information to the status acquisition and feedback module. The status acquisition and feedback module is used to send the status information to the human-machine interface in the ship domain controller; the human-machine interface is used to display the status information on the display interface.
4. The system according to claim 1, characterized in that, The hull domain controller also includes local security logic and a fast response module; The local security logic and rapid response module is used to generate at least one second emergency plan for ship equipment in the event of triggering a target event. The second emergency plan for at least one ship equipment is sent to the human-machine interface in the ship domain controller; the target event includes at least one of the following: the connection between the ship domain controller and the intelligent domain controller is interrupted, and the equipment associated with the ship domain controller malfunctions; an event that requires the local security logic and rapid response module to generate the second emergency plan is preset; The human-computer interaction interface is used to display the second emergency plan for at least one ship equipment on the display interface; The human-machine interface is also used to send the second emergency plan for at least one ship equipment to the device driver and interface module in the ship domain controller when a second instruction is received from the user. The second instruction is used to instruct the determination of the implementation of the second emergency plan for the at least one ship equipment; The device driver and interface module is used to control the corresponding equipment in the ship based on the at least one second emergency plan for ship equipment.
5. A method for ensuring safety and responding to emergencies on ships, characterized in that, The method is applied to a ship safety assurance and emergency response system as described in any one of claims 1-4; the method includes: Based on the first ship equipment data associated with the intelligent domain controller and / or the second ship equipment data associated with the hull domain controller in the system, at least one ship equipment first emergency plan is generated. Based on the first emergency plan for at least one ship equipment, the corresponding equipment in the ship is controlled.
6. An electronic device, characterized in that, include: One or more processors; Memory, used to store one or more programs. When the one or more programs are executed by the one or more processors, the one or more processors implement the safety assurance and emergency response method for ships as described in claim 5.
7. A storage medium having a computer program stored thereon, characterized in that, When executed by the processor, the program implements the safety assurance and emergency response method for ships as described in claim 5.
8. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the safety assurance and emergency response method for ships as described in claim 5.