Penetration testing method and device based on ship national marine electronic association protocol, and method and device for controlling connection of computer-based systems in ship
By employing penetration testing methods and equipment based on the shipborne NMEA protocol, the lack of cybersecurity assessment for ships was addressed, enabling rapid testing of ship networks and protection against remote attacks, thus ensuring legitimate access.
Patent Information
- Application Number
- CN202480036382.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-06-07
- Filing Date
- 2024-05-31
- Publication Date
- 2025-12-26
AI Technical Summary
Existing technologies lack penetration testing methods for ships, making it impossible to effectively assess ship cybersecurity and prevent malicious access to shipboard control systems.
The penetration testing method and equipment based on the shipborne NMEA protocol are used to confirm network communication through packet capture and analysis, select appropriate attack methods, generate and transmit attack data, analyze test results, and verify the legitimacy of CBS through beacon and GPS information to control access.
It enables simple and rapid penetration testing of ship networks, prevents remote network attacks, and ensures that only authorized terminals and systems can access critical systems.
Smart Images

Figure CN121220007A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present invention relates to a shipboard National Marine Electronics Association (NMEA) protocol-based penetration testing method and apparatus that can perform NMEA protocol penetration testing on a ship taking into account different characteristics of the ship, and a method and apparatus for controlling access by a computer-based system (CBS) in a ship that can authenticate a plurality of shipboard devices using a wireless communication function (e.g., Bluetooth, global positioning system (GPS), or wireless fidelity (Wi-Fi)) of the CBS connected to a shipboard control system (e.g., a navigation control system, a communication control system, a propulsion control system). BACKGROUND
[0002] With the convergence of information and communication technology (ICT) with the shipbuilding and marine industries, network risks to ships have also increased. In response, international organizations have issued cyber security requirements, among which the international association of classification societies (IACS) has particularly strongly requested cyber security testing. However, no specific method for performing these tests has been provided.
[0003] A penetration test is a simulated cyber attack used to assess the security of a system. On land, the targets of penetration testing are ICT systems (e.g., network-based systems, information systems, and mobile devices) and operational technology (OT) systems (e.g., smart factories). In the automotive industry, a controller area network (CAN) is a special automotive communication protocol, and there is a specific CAN protocol penetration testing method.
[0004] However, there is currently no penetration test method designed specifically for ships. To perform a penetration test on a ship, the unique network environment of a ship needs to be considered. Therefore, land-based penetration testing methods have limitations because they do not reflect the specific characteristics of a ship.
[0005] A shipboard computer-based system (CBS) is defined as a computer-based system used / installed on a ship.
[0006] Generally, the CBS includes terminals (e.g., mobile devices, tablet computers, notebook computers, and desktop computers) used by the captain and crew on the ship and navigation and communication systems (e.g., an electronic chart display and information system and an integrated navigation system) provided to the ship.
[0007] If both the inputted identifier (ID) and password are verified in a predefined authenticator database, the CBS authenticates the user as authorized.
[0008] However, if the ID and password are leaked through hacking, malware, or other means, there is no way to prevent malicious access to the shipboard control systems (e.g., a navigation control system, a communication control system, and a propulsion control system).
[0009] Related art is disclosed in Korean Patent Registration No. 10-0694248 (March 27, 2007) and Korean Patent Registration No. 10-2328275 (November 17, 2021). SUMMARY
[0010] TECHNICAL PROBLEM
[0011] An aspect of the present disclosure is to provide a shipboard National Marine Electronics Association (NMEA) protocol-based penetration testing method and apparatus that can perform an NMEA protocol penetration test on a ship, thereby enabling a simple and fast penetration test on a shipboard network based on an NMEA protocol.
[0012] An aspect of the present disclosure is to provide a method and apparatus for controlling access by a CBS in a ship that can prevent cyber attacks from remote locations by identifying critical systems (e.g., systems for operation and navigation management) that should only be accessed by authorized crew terminals and systems in the ship.
[0013] TECHNICAL SOLUTION
[0014] According to an aspect of the present application, a penetration test method based on a shipboard NMEA protocol includes a network connection step in which a penetration test device is connected to a shipboard control network among a ship network, a confirmation step in which a confirmation unit of the penetration test device confirms whether the network connected in the network connection step is used for NMEA communication by extracting a format and a feature of an NMEA sentence structure through packet capturing and packet analysis, an attack method selection step in which an attack method selection unit of the penetration test device selects an attack method when it is confirmed in the confirmation step that the network is used for NMEA communication, an attack data generation step in which attack data is generated based on the attack method selected in the attack method selection step, an attack data storage step in which the attack data generated in the attack data generation step and network packets during an attack are stored, an attack data transmission step in which the attack data and the network packets stored in the attack data storage step are transmitted to the ship network, and an attack data analysis step in which the attack data transmitted in the attack data transmission step is analyzed.
[0015] Further, the attack method selected in the attack method selection step can include one selected from a fake NMEA data transmission, a replay attack, and a denial-of-service attack.
[0016] Further, the attack method selected in the attack method selection step can be updated with a new attack technique.
[0017] Further, the attack data analysis step can include analyzing the number and transmission time of the transmitted NMEA attack data, and acquiring a test result.
[0018] According to another aspect of the present application, a shipboard NMEA protocol-based penetration testing device configured to perform a penetration test by connecting to a shipboard control network, and includes: a confirmation unit configured to confirm whether a network is used for NMEA communication by extracting a format and a feature of an NMEA sentence structure through packet capturing and packet analysis; an attack method selection unit configured to select an attack method when it is confirmed that the network is used for NMEA communication; an attack data generation unit configured to generate attack data based on the attack method selected by the attack method selection unit; an attack data storage unit configured to store the attack data generated by the attack data generation unit and network packets during an attack; an attack data transmission unit configured to transmit the attack data and the network packets stored in the attack data storage unit to a shipboard network; and an attack data analysis unit configured to analyze the attack data transmitted from the attack data transmission unit.
[0019] Further, the attack method selected by the attack method selection unit can include one selected from among a pseudo-NMEA data transmission, a replay attack, and a denial of service attack.
[0020] Further, the attack method selected by the attack method selection unit can be updated with a new attack technique.
[0021] Further, the attack data analysis unit can analyze the number of transmitted NMEA attack data and a transmission time, and can acquire a test result.
[0022] According to still another aspect of the present application, an apparatus for controlling access by a CBS in a ship includes: a computer-based system (CBS) configured to log into a shipborne control system, such as a navigation control system, a communication control system, and a propulsion control system, via a communication unit after authentication of an ID and a password; a beacon transmitter configured to transmit location information of the CBS upon logging in or starting the CBS; a beacon management server unit configured to receive the location information from the beacon transmitter and to confirm whether device information of the CBS matches information registered in a beacon management server; a location confirmation unit configured to receive global positioning system (GPS) information from the CBS when the CBS is located in a blind spot having no available beacon information during confirmation by the beacon management server unit; a navigation information confirmation unit configured to compare the GPS information received by the location confirmation unit with an Automatic Identification System (AIS) database; and an authentication unit configured to exercise control so that the CBS is connected to internal systems of the ship when the device information of the CBS is confirmed by the beacon management server unit to match the registered information or when the GPS information of the CBS is confirmed by the navigation information confirmation unit to match the AIS database.
[0023] Further, upon receiving a beacon message indicating that the CBS is placed in the ship or upon determining that the location information of the CBS matches a navigation route, the authentication unit can exercise control so that the CBS is connected to the internal systems of the ship.
[0024] According to still another aspect of the present application, a method for controlling access by a CBS in a ship includes: a login step in which a computer-based system (CBS) logs into a shipborne control system, such as a navigation control system, a communication control system, and a propulsion control system, via a communication unit after authentication of an ID and a password; a position information transmission step in which a beacon transmitter transmits position information of the CBS after the CBS is logged in or activated in the login step; a comparison determination step in which it is determined whether device information of the CBS matches information registered in a beacon management server after the position information is received from the beacon transmitter; a navigation information confirmation step in which the CBS transmits GPS information of the CBS to a position confirmation unit when the CBS is located in a blind spot having no available beacon information in the comparison determination step, and a navigation information confirmation unit compares the GPS information received by the position confirmation unit with an AIS database; and an authentication step in which an authentication unit performs control so that the CBS is connected to internal systems of the ship when it is confirmed in the comparison determination step that the device information of the CBS matches the registered information, or when it is confirmed in the navigation information confirmation step that the GPS information of the CBS matches the AIS database.
[0025] Further, in the authentication step, after receiving a beacon message indicating that the CBS is placed in the ship, or after it is determined that the position information of the CBS matches a navigation route, the authentication unit can perform control so that the CBS is connected to the internal systems of the ship.
[0026] Advantageous Effects
[0027] Embodiments of the present application provide a shipborne NMEA protocol-based penetration testing method and apparatus that can perform NMEA protocol penetration testing on a ship, thereby enabling simple and fast penetration testing of a ship network based on an NMEA protocol.
[0028] Embodiments of the present application provide a method and apparatus for controlling access by a CBS in a ship that can prevent network attacks from remote locations by identifying critical systems (e.g., systems for operation and navigation management) that should only be accessed by authorized crew terminals and systems in the ship. BRIEF DESCRIPTION OF DRAWINGS
[0029] Figure 1 is a block diagram illustrating a classification of a network in which a shipborne NMEA protocol-based penetration testing apparatus according to the present application is used.
[0030] Figure 2 is a flowchart of a shipborne NMEA protocol-based penetration testing method according to the present application.
[0031] Figure 3 is a block diagram of an apparatus for controlling access by a CBS in a marine vessel according to an embodiment of the present application.
[0032] Figure 4 is a flowchart of a method for controlling access by a CBS in a marine vessel according to an embodiment of the present application. DETAILED DESCRIPTION
[0033] The above and other aspects, features and advantages of the present application will become apparent from the following detailed description of the embodiments taken in conjunction with the accompanying drawings.
[0034] The terms used in the present description are for the purpose of describing particular embodiments only and are not intended to be limiting. As used herein, the use of the term "comprises" and / or "comprising", or "includes" and / or "including" when used in this specification and / or claims, means that the stated features, integers, steps, operations, elements, components and / or groups thereof are present, but not excluding the presence or addition of one or more other features, integers, steps, operations, elements, components and / or groups thereof. In addition, the use of the singular is intended to include the plural, unless the context clearly indicates otherwise.
[0035] Hereinafter, exemplary embodiments of the present application will be described in detail with reference to the accompanying drawings. It should be understood that the exemplary embodiments are presented for the purpose of fully disclosing the present application and making a thorough understanding of the present application to those skilled in the art, and the present application is not limited to the following embodiments but can be embodied in various ways by those skilled in the art.
[0036] Referring to Figure 1 According to the present application, a penetration testing apparatus (20) based on a shipboard NMEA (National Marine Electronics Association) protocol can be connected to a marine network (10), wherein the shipboard network (10) can include an administrative network (11), a shipboard control network (12), an instrumentation network (13), and a dedicated connection (14).
[0037] Here, the penetration testing apparatus (20) can be connected to the shipboard control network (12) to confirm whether the network on the marine vessel is used for NMEA communication.
[0038] The NMEA protocol (often abbreviated as NMEA) is a set of standards for transmitting information such as time, position, and orientation.
[0039] The NMEA protocol is developed by the National Marine Electronics Association of the United States, and is commonly used to relay data from devices such as gyrocompasses, global positioning systems (GPS), compasses, and inertial navigation systems (INS).
[0040] The penetration testing apparatus (20) based on the shipboard NMEA protocol is configured to be connected to a shipboard control network to perform a penetration test, and can include a confirmation unit (21) configured to confirm whether the connected network is used for NMEA communication by extracting a format and a feature of an NMEA sentence structure through packet capturing and packet analysis, an attack method selection unit (22) configured to select an attack method after the connected network is confirmed to be used for NMEA communication by the confirmation unit (21), an attack data generation unit (23) configured to generate attack data based on the attack method selected by the attack method selection unit (22), an attack data storage unit (24) configured to store the attack data generated by the attack data generation unit (23) and network packets during an attack, an attack data transmission unit (25) configured to transmit the attack data and the network packets stored in the attack data storage unit (24) to the shipboard network, and an attack data analysis unit (26) configured to analyze the attack data transmitted from the attack data transmission unit (25).
[0041] Further, in the penetration testing apparatus (20), the attack method selected by the attack method selection unit (22) can include one selected from among pseudo-NMEA data transmission, a replay attack, and a denial-of-service attack.
[0042] Further, in the penetration testing apparatus (20), the attack method selected by the attack method selection unit (22) can be updated with a new attack technique.
[0043] As such, various penetration tests can be performed by the attack method selection unit (22) by selecting an attack method desired by a user or by updating attack method data with a new attack technique.
[0044] Further, the attack data analysis unit (26) of the penetration testing apparatus (20) can analyze the number and transmission time of the transmitted NMEA attack data, and can acquire a result of the penetration test.
[0045] As such, the penetration testing apparatus (20) according to the present application enables simple and fast penetration testing of a shipboard network based on an NMEA protocol.
[0046] According to another aspect of the present application, a penetration testing method based on a shipboard NMEA protocol includes a network connection step (S10) in which a penetration testing device (20) is connected to a shipboard control network (12) through NMEA communication, and a confirmation step (S20) in which a confirmation unit (21) of the penetration testing device confirms whether the connected shipboard network is used for NMEA communication by extracting a format and a feature of an NMEA sentence structure through packet capturing and packet analysis.
[0047] When it is confirmed in the confirmation step (S20) that the connected shipboard network is not used for NMEA communication, the penetration testing is terminated.
[0048] When it is confirmed in the confirmation step (S20) that the connected shipboard network is used for NMEA communication, the flow proceeds to an attack method selection step (S31) in which an attack method selection unit (22) of the penetration testing device (20) selects an attack method. Then, the flow proceeds to an attack data generation step (S32) in which an attack data generation unit (23) of the penetration testing device generates attack data based on the attack method selected in the attack method selection step (S31). Then, the flow proceeds to an attack data storage step (S33) in which an attack data storage unit (24) stores the attack data generated in the attack data generation step (S32). Then, the flow proceeds to an attack data transmission step (S34) in which an attack data transmission unit (25) transmits the attack data stored in the attack data storage step (S33) to the shipboard network. Finally, the flow proceeds to an attack data analysis step (S35) in which an attack data analysis unit (26) analyzes the attack data transmitted in the attack data transmission step (S34).
[0049] In the penetration testing method based on the shipboard NMEA protocol, the attack method selected in the attack method selection step (S31) can include one selected from among pseudo NMEA data transmission, a replay attack, and a denial of service attack.
[0050] In the penetration testing method based on the shipboard NMEA protocol, the attack method selected in the attack method selection step (S31) can be updated with a new attack technique.
[0051] In the penetration testing method based on the shipboard NMEA protocol, the attack data analysis step (S35) can include analyzing the number and transmission time of the transmitted NMEA attack data, and obtaining a result of the penetration testing.
[0052] In this way, the penetration testing method based on the NMEA protocol of the ship enables a simple and fast penetration test of the ship network based on the NMEA protocol.
[0053] Figure 3 is a block diagram of an apparatus for controlling access by a CBS in a ship according to an embodiment of the present invention, and Figure 4 is a flowchart of a method for controlling access by a CBS in a ship according to an embodiment of the present invention.
[0054] Referring to Figure 3 and Figure 4 , the apparatus for controlling access by a CBS in a ship relates to an authentication apparatus and method for controlling access by a CBS in a ship using device information of the CBS in addition to an ID and a password.
[0055] As shown in Figure 3 , the apparatus for controlling access by a CBS in a ship can include a communication unit (100), a beacon transmitter (140), a beacon management server (150), a location confirmation unit (160), a navigation information confirmation unit (170), an authentication unit (180), and an automatic identification system (AIS) database (200).
[0056] Here, the beacon management server (150) can refer to a database registered in the beacon management server.
[0057] Further, the CBS (computer-based system) can refer to a computer-based system logged into a shipboard control system (e.g., a navigation control system, a communication control system, and a propulsion control system) via the communication unit (100) after authentication of an ID and a password.
[0058] The communication unit (100) can include a Bluetooth module (110), a GPS module (120), and a wireless fidelity (Wi-Fi) module (130).
[0059] The beacon transmitter (140) can transmit location information of the CBS after logging in or starting the CBS, and the beacon management server (150) can receive the location information from the beacon transmitter (140) and can confirm whether the device information of the CBS matches the registered device information.
[0060] Further, when the CBS is located in a blind spot that does not have available beacon information during the confirmation by the beacon management server (150), the CBS transmits its GPS information to the location confirmation unit (160), and the navigation information confirmation unit (170) compares the GPS information received by the location confirmation unit (160) with the AIS database (200).
[0061] When the device information of the CBS is confirmed by the beacon management server (150) to match the registered device information, or when the GPS information of the CBS is confirmed to match the AIS database (200), the authentication unit (180) performs control so that the CBS is connected to the internal system of the ship. With the authentication unit (180), the device according to the present application controls access by the CBS in the ship.
[0062] That is, when the position of the CBS cannot be confirmed through the information comparison by the beacon management server (150), the navigation information confirmation unit (170) can confirm the position of the CBS through the comparison between the GPS information and the AIS database.
[0063] Further, upon receiving the beacon message indicating that the CBS is placed in the ship, or upon determining that the position information of the CBS matches the navigation route, the authentication unit (180) can also perform control so that the CBS is connected to the internal system of the ship.
[0064] In this way, the device according to the present application can prevent cyber attacks from remote locations by identifying critical systems (e.g., systems for operation and navigation management) that should only be accessed by authorized crew terminals and systems in the ship.
[0065] According to still another aspect of the present application, a method for controlling access by a CBS in a ship can include a login step (S110), a position information transmission step (S120), a comparison determination step (S130), a navigation information confirmation step (S140), and an authentication step (S150).
[0066] More specifically, the method for controlling access by a CBS in a ship according to the present application can include a login step (S110) in which a CBS (Computer Based System) logs into a shipboard control system, such as a navigation control system, a communication control system, and a propulsion control system, via a communication unit after authentication of an ID and a password; a position information transmission step (S120) in which, after the CBS is logged in or activated in the login step (S110), a beacon transmitter transmits position information of the CBS; a comparison determination step (S130) in which, after receiving the position information transmitted from the beacon transmitter in the position information transmission step (S120), it is determined whether device information of the CBS matches information registered in a beacon management server; a navigation information confirmation step (S140) in which, when the CBS is located in a blind spot having no available beacon information in the comparison determination step (S130), the CBS transmits its GPS information to a position confirmation unit, and a navigation information confirmation unit compares the GPS information received by the position confirmation unit with an AIS database; and an authentication step (S150) in which, when the device information of the CBS matches the information registered in the beacon management server in the comparison determination step (S130), or when the GPS information of the CBS matches the AIS database in the navigation information confirmation step (S140), an authentication unit exercises control so that the CBS is connected to internal systems of the ship.
[0067] Further, in the authentication step (S150), after receiving a beacon message indicating that the CBS is placed in the ship, or after determining that the position information of the CBS matches a navigation route, the authentication unit exercises control so that the CBS is connected to internal systems of the ship.
[0068] As such, the method according to the present application can prevent cyber attacks from remote locations by identifying critical systems (e.g., systems for operation and navigation management) that should only be accessed by authorized crew terminals and systems in the ship.
[0069] The above-described embodiments of the present application can be implemented in the form of program instructions that can be executed by various computer components and recorded in computer-readable recording media. The computer-readable recording media can include program instructions, data files, data structures, etc. alone or in combination. The program instructions recorded on the computer-readable recording media can be specifically designed and constructed for the present application, or can be known and available to those skilled in the computer software field. Examples of the computer-readable media include hardware devices specifically configured to store and execute program instructions, including magnetic media such as hard disks, floppy disks, and magnetic tapes; optical recording media such as compact discs (CD-ROM) and digital versatile discs (DVDs); magneto-optical media such as floptical disks; read-only memories (ROMs); random access memories (RAMs); and flash memories. Examples of the program instructions include not only machine language codes made by compilers, but also high-level language codes that can be executed by using an interpreter, etc. on a computer. The hardware devices can be configured to operate as one or more software modules in order to perform operations according to the present application, or vice versa.
[0070] Although some embodiments have been described herein, it should be understood that these embodiments are merely provided for the purpose of illustration, and should not be construed as limiting the present application in any way, and various modifications and changes can be made by those skilled in the art without departing from the spirit and scope of the present application. Accordingly, the appended claims and their equivalents are intended to cover such changes or modifications as fall within the scope and spirit of the present application.
[0071] BRIEF DESCRIPTION OF DRAWINGS
[0072] 10: network
[0073] 11: administrative network
[0074] 12: shipboard control network
[0075] 13: instrument network
[0076] 14: dedicated connection
[0077] 20: penetration testing device
[0078] 21: confirmation unit
[0079] 22: attack method selection unit
[0080] 23: attack data generation unit
[0081] 24: attack data storage unit
[0082] 25: attack data transmission unit
[0083] 26: attack data analysis unit
[0084] 100: communication unit
[0085] 110: Bluetooth module
[0086] 120: global positioning system (GPS) module
[0087] 130: Wi-Fi module
[0088] 140: beacon transmitter
[0089] 150: beacon management server
[0090] 160: position confirmation unit
[0091] 170: navigation information confirmation unit
[0092] 180: authentication unit
[0093] 200: automatic identification system (AIS)
Claims
1. A shipboard Link 11 protocol-based penetration testing method, comprising: a network connection step in which a penetration testing device connects to a ship control network among ship networks; a confirmation step in which a confirmation unit of the penetration testing device confirms whether the network connected in the network connection step is used for Link 11 communication by extracting a format and a feature of a Link 11 sentence structure through packet capturing and packet analysis; an attack method selection step in which an attack method selection unit of the penetration testing device selects an attack method when it is confirmed in the confirmation step that the network is used for Link 11 communication; an attack data generation step in which attack data is generated based on the attack method selected in the attack method selection step; an attack data storage step in which the attack data generated in the attack data generation step and network packets during an attack are stored; an attack data transmission step in which the attack data and the network packets stored in the attack data storage step are transmitted to the ship networks; and an attack data analysis step in which the attack data transmitted in the attack data transmission step is analyzed.
2. The shipboard Link 11 protocol-based penetration testing method according to claim 1, wherein the attack method selected in the attack method selection step includes one selected from among pseudo Link 11 data transmission, a replay attack, and a denial of service attack.
3. The shipboard Link 11 protocol-based penetration testing method according to claim 2, wherein the attack method selected in the attack method selection step is updated with a new attack technique. the number of transmitted Link 11 attack data and transmission time are analyzed; and 4. The shipboard National Oceanic and Electronic Association agreement based penetration testing method of claim 1, wherein the attack data analysis step comprises: a test result is obtained.
5. A shipboard Link 11 protocol-based penetration testing device configured to perform a penetration test by connecting to a ship control network, the device comprising: a confirmation unit configured to confirm whether the network is used for Link 11 communication by extracting a format and a feature of a Link 11 sentence structure through packet capturing and packet analysis; an attack method selection unit configured to select an attack method when it is confirmed that the network is used for Link 11 communication; an attack data generation unit configured to generate attack data based on the attack method selected by the attack method selection unit; an attack data storage unit configured to store the attack data generated by the attack data generation unit and network packets during an attack; an attack data transmission unit configured to transmit the attack data and the network packets stored in the attack data storage unit to ship networks; and an attack data analysis unit configured to analyze the attack data transmitted in the attack data transmission step. An attack data analysis unit configured to analyze the attack data transmitted from the attack data transmission unit.
6. The shipboard National Oceanographic Electronics Association protocol based penetration testing device of claim 5, wherein the attack method selected by the attack method selection unit includes one selected from a pseudo National Oceanographic Electronics Association data transmission, a replay attack, and a denial of service attack.
7. The National Oceanographic Electronics Association protocol based penetration testing device of claim 6, wherein the attack method selected by the attack method selection unit is updated with new attack techniques.
8. The shipboard National Oceanographic Electronics Association protocol based penetration testing device of claim 5, wherein the attack data analysis unit analyzes the number and transmission time of the transmitted National Oceanographic Electronics Association attack data and acquires a test result.
9. An apparatus for controlling access by a computer-based system in a ship, comprising: a computer-based system (CBS) configured to log in to a shipboard control system, such as a navigation control system, a communication control system, and a propulsion control system, via a communication unit after authentication of an identifier and a password; a beacon transmitter configured to transmit position information of the computer-based system after the computer-based system is logged in or started; a beacon management server unit configured to receive the position information from the beacon transmitter and confirm whether device information of the computer-based system matches information registered in a beacon management server; a position confirmation unit configured to receive global positioning system information from the computer-based system when the computer-based system is located in a blind spot having no available beacon information during the confirmation by the beacon management server unit; a navigation information confirmation unit configured to compare the global positioning system information received by the position confirmation unit with an automatic identification system database; and an authentication unit configured to perform control so that the computer-based system is connected to internal systems of the ship when the device information of the computer-based system is confirmed by the beacon management server unit to match the registered information or when the global positioning system information of the computer-based system is confirmed by the navigation information confirmation unit to match the automatic identification system database.
10. The apparatus of claim 9, wherein the authentication unit performs control so that the computer-based system is connected to the internal systems of the ship upon receipt of a beacon message indicating that the computer-based system is placed in the ship or upon determination that the position information of the computer-based system matches a navigation route.
11. A method for controlling access by a computer-based system in a ship, comprising: a login step in which a computer-based system (CBS) logs in to a shipboard control system, such as a navigation control system, a communication control system, and a propulsion control system, via a communication unit after authentication of an identifier and a password; a position information transmission step in which, after the computer-based system is logged in or activated in the login step, a beacon transmitter transmits position information of the computer-based system; a comparison determination step in which, after the position information is received from the beacon transmitter, it is determined whether device information of the computer-based system matches information registered in a beacon management server; a navigation information confirmation step in which, when the computer-based system is located in a blind spot having no available beacon information in the comparison determination step, the computer-based system transmits global positioning system information of the computer-based system to a position confirmation unit, and a navigation information confirmation unit compares the global positioning system information received by the position confirmation unit with an automatic identification system database; and an authentication step in which, when it is confirmed in the comparison determination step that the device information of the computer-based system matches the registered information, or when it is confirmed in the navigation information confirmation step that the global positioning system information of the computer-based system matches the automatic identification system database, an authentication unit exercises control so that the computer-based system is connected to an internal system of the ship.
12. The method according to claim 11, wherein in the authentication step, after a beacon message indicating that the computer-based system is placed in the ship is received, or after it is determined that the position information of the computer-based system matches a navigation route, the authentication unit exercises control so that the computer-based system is connected to the internal system of the ship.
Citation Information
Patent Citations
Apparatus for testing security policies in network security system and its method
KR100694248B1
Bridge system for unmanned vessel and control method thereof
KR102328275B1