Method and system for wired / wireless network security patching for a ship
By integrating servers, deployment servers, and update servers into a wireless patching solution, the challenge of remote patching for ships has been solved, enabling continuous cybersecurity patching updates in intelligent ships and autonomous navigation systems, meeting IACS UR E26 requirements.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- HANWHA OCEAN CO LTD (KR)
- Filing Date
- 2024-12-27
- Publication Date
- 2026-07-24
AI Technical Summary
Existing technologies make it difficult to implement remote, on-site engineer-free cybersecurity patch updates on ships, especially in smart ships and autonomous navigation systems, and patch updates are difficult to continuously adapt to ship operating conditions and location.
The system employs a system integration server, a patch deployment server, and a patch update server. Patches are received, encrypted, verified, and updated via wireless communication (such as VSAT, LTE, 5G, and port LAN). Combined with hash, timestamp, and patch version verification, the security and continuity of patch updates are ensured.
It enables remote cybersecurity patch updates without on-site engineer intervention, and continuous updates based on ship operating conditions and location, ensuring the cybersecurity of smart ships and autonomous navigation systems.
Smart Images

Figure CN122460041A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to a method and system for security patching of wired and wireless networks for ships, and more particularly to a method and system for security patching of wired and wireless networks for ships that can perform patch updates according to IACS UR E26 requirements, in order to meet the need for establishing a CBS patch update method and apparatus for ships. Background Technology
[0002] With the increasing stringency of regulations from the International Maritime Organization (IMO) and classification societies, there is a growing need for robust shipboard cybersecurity. Among these regulations, security patches and software updates for shipboard computer-based systems (e.g., servers or computers) are particularly important. Patching methods typically fall into two categories: those based on a Patch Management System (PMS) and those using manual methods employing Universal Serial Bus (USB) drives or similar devices. However, given the operational nature of ships, applying patches via satellite has always been challenging.
[0003] The relevant technology was disclosed in Korean Patent Publication No. 10-2023-0045769 (published on April 5, 2023). Summary of the Invention
[0004] Technical issues
[0005] One aspect of the present invention is to provide a method and system for patching cybersecurity for ships, which enables remote patching without the intervention of on-site engineers by establishing a wireless patching update scheme.
[0006] Another aspect of the present invention is to provide a method and system for security patching of wired and wireless networks for ships, the method and system enabling the application of cybersecurity patches to ships equipped with cybersecurity measures for smart ships and autonomous navigation systems, while allowing continuous patch updates based on ship operating conditions and location.
[0007] Technical solutions
[0008] According to one aspect of the present invention, a ship network security patching system includes: a system integration server configured to receive patches from a corresponding CBS provider server and integrate patches received for the target CBS when a target CBS to be patched is identified among a plurality of computer-based systems (CBS) on the ship; a patch deployment server configured to authenticate and encrypt the patches received from the system integration server and deploy the encrypted patches; and a patch update server installed on the ship and configured to authenticate and decrypt the patches received from the patch deployment server and verify the patches based on a hash, a timestamp, and a patch version to apply patch updates, wherein the patch update server continuously applies network security patch updates based on the ship's operating conditions and location.
[0009] The patch deployment server can deploy patches by connecting via any of the following communication methods, depending on the ship's operating conditions and location: Very Small Aperture Terminal (VSAT), Long Term Evolution (LTE), and local area network (LAN).
[0010] The patch update server may also include a backup update server; and if the communication connection is interrupted during a patch update performed through the patch update server, the patch update server may save the patch state before the interruption through the backup update server, and resume the patch update from the point of interruption once the communication connection is re-established.
[0011] According to another aspect of the present invention, a method for patching ship network security includes: a patch receiving step, in which, upon identifying a target CBS to be patched among multiple CBSs on the ship, a system integration server receives patches from the corresponding CBS provider server and integrates the patches received for the target CBS; a patch distribution step, in which a patch deployment server authenticates and encrypts the patches received in the patch receiving step and deploys the encrypted patches; and a patch update step, in which a patch update server on the ship receives the patches deployed in the patch distribution step, authenticates and decrypts the received patches, and verifies the patches based on hashes, timestamps, and patch versions to apply patch updates, wherein in the patch update step, network security patch updates are continuously applied based on ship operating conditions and location.
[0012] In the patch distribution step, patches can be deployed via any communication method selected from VSAT, LTE, and port LAN, depending on the ship's operating conditions and location.
[0013] In the patch update step, the patch update server may also include a backup update server; and if the communication connection is interrupted during the patch update performed through the patch update server, the patch update server can save the patch state before the interruption through the backup update server, and resume the patch update from the point of interruption once the communication connection is re-established.
[0014] Beneficial effects
[0015] Embodiments of the present invention provide a method and system for patching ship network security, which enables remote patch updates without the intervention of on-site engineers by establishing a wireless patch update scheme.
[0016] Embodiments of the present invention provide a method and system for patching ship cybersecurity, which can apply cybersecurity patches to ships that have deployed cybersecurity measures for intelligent ships and autonomous navigation systems, while allowing continuous patch updates based on ship operating conditions and location. Attached Figure Description
[0017] Figure 1 This is a diagram illustrating a wired and wireless marine network security patching system according to the present invention.
[0018] Figure 2 This is a flowchart illustrating a method for patching wired and wireless marine network security according to the present invention. Best mode
[0019] The above and other aspects, features and advantages of the present invention will become apparent from the following detailed description of the embodiments in conjunction with the accompanying drawings.
[0020] The terminology used herein is for the purpose of illustrating particular embodiments and is not intended to be limiting. The terms “comprises / comprising” and / or “includes / including” as used herein, when used in this specification, designate the presence of stated features, integers, steps, operations, elements, components, and / or groups thereof, but do not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof. Furthermore, unless the context clearly indicates otherwise, the singular forms “a / an” and “the” as used herein are intended to also include the plural forms.
[0021] In the following sections, exemplary embodiments of the invention will be described in detail with reference to the accompanying drawings. It should be understood that the embodiments are provided to fully disclose the invention and to enable those skilled in the art to fully understand it, and that the invention is not limited to the following embodiments but can be practiced in different ways by those skilled in the art.
[0022] Reference Figure 1 and Figure 2 This paper will describe a method and system for patching wireless and wired ship network security according to embodiments of the present invention.
[0023] According to one aspect of the present invention, a wired and wireless marine network security patching system establishes a method and system for CBS patching of ships that conforms to the Unified Requirements (UR) E26 of the International Association of Classification Societies (IACS).
[0024] The ship network security patching system according to the present invention includes: a system integration server (100) configured to receive patches from the corresponding CBS provider server (10) and integrate patches received for the target CBS when a target CBS to be patched is identified among multiple shipborne computer-based systems (CBS) on the ship (400); a patch deployment server (200) configured to authenticate and encrypt patches received from the system integration server (100) and deploy encrypted patches; and a patch update server (450) installed on the ship (400) and configured to authenticate and decrypt patches received from the patch deployment server (200) and verify the patches based on hash, timestamp, and patch version to apply patch updates.
[0025] The patch update server (450) can continuously apply cybersecurity patch updates based on the ship's operating conditions and location.
[0026] In other words, given the nature of ship operations, patch updates can be performed wirelessly while the ship is sailing or berthed.
[0027] For example, patch updates can be applied via Very Small Aperture Terminal (VSAT) while at sea, or via 5G or LTE while berthed.
[0028] Therefore, the patch deployment server (200) can deploy the patch by connecting via any communication unit (300) selected from VSAT, LTE and port local area network (LAN), depending on the ship's operating conditions and location.
[0029] In addition, by deploying encrypted patches via a key management system, the patch deployment server (200) can apply patches while maintaining security even when other vessels receive the patch data.
[0030] More specifically, when a target CBS to be patched is identified among multiple CBSs on the ship, the system integration server (100) receives the patch from the corresponding provider servers 11 to 13.
[0031] Then, the patch deployment server (200) can authenticate the patches received from the system integration server (100) through the firewall (210), encrypt the received patches through the key management system (230), and deploy the encrypted patches by selecting an effective communication method based on the ship's operating conditions and location.
[0032] In other words, the patch deployment server (200) can deploy the patch via any communication unit (300) selected from VSAT, LTE and port local area network (LAN) depending on the ship's operating conditions and location.
[0033] Therefore, the ship network security patching system according to the present invention authenticates the patch received from the ship (400) through the firewall (410), decrypts the patch through the key management system (430), verifies the hash and timestamp of the patch, checks the patch version through the patch update server (450), and applies the patch update to the Operational Technology (OT) system of each CBS on the ship.
[0034] Additionally, the patch update server (450) may also include a backup update server (460). Therefore, if the communication connection is interrupted during a patch update performed via the patch update server (450), the patch update server (450) can save the patch state before the interruption via the backup update server (460) and resume the patch update from the point of interruption once the communication connection is re-established.
[0035] With this configuration, the ship's cybersecurity patching system ensures that cybersecurity patch updates can be continuously applied based on the ship's operating conditions and location.
[0036] Reference Figure 2The ship network security patching method according to the present invention includes: a patch receiving step (S100), in which, when a target CBS to be patched is identified among multiple CBSs on the ship, a system integration server receives a patch from the corresponding CBS provider server and integrates the patches received for the target CBS; a patch distribution step (S200), in which a patch deployment server authenticates and encrypts the patch received in the patch receiving step (S100) and deploys the encrypted patch; and a patch update step (S300), in which a patch update server on the ship receives the patch deployed in the patch distribution step (S200), authenticates and decrypts the received patch, and verifies the patch based on hash, timestamp, and patch version to apply the patch update.
[0037] In the patch update step (S300), cybersecurity patch updates are continuously applied based on the ship's operating conditions and location.
[0038] Furthermore, in the patch distribution step (S200), the patch can be deployed by connecting via any communication method selected from VSAT, LTE, and port LAN, depending on the ship's operating status and location.
[0039] Additionally, in the patch update step (S300), the patch update server (450) may also include a backup update server (460). If the communication connection is interrupted during patch update via the patch update server (450), the backup update server (460) can save the patch state before the interruption and resume patch update from the point of interruption once the communication connection is re-established.
[0040] Therefore, according to the present invention, the network security patching method and system can achieve remote patch updates without the intervention of on-site engineers by establishing a wireless patch update scheme.
[0041] Furthermore, according to the present invention, the network security patching method and system can apply network security patches to ships that have deployed network security measures for intelligent ships and autonomous navigation systems, while allowing continuous patch updates based on ship operating conditions and location.
[0042] The embodiments of the present invention described above can be implemented in the form of program instructions that can be executed by various computer components and recorded on a computer-readable recording medium. The computer-readable recording medium may include program instructions, data files, data structures, etc., individually or in combination. The program instructions recorded on the computer-readable recording medium may be specifically designed and constructed for the present invention, or may be known and available to those skilled in the art of computer software. Examples of computer-readable media include hardware devices specifically configured to store and execute program instructions, including: magnetic media, such as hard disks, floppy disks, and magnetic tapes; optical recording media, such as Compact Disc Read-Only Memory (CD-ROM) and Digital Versatile Disc (DVD); magneto-optical media, such as floppy disks; read-only memory (ROM); random access memory (RAM); and flash memory. Examples of program instructions include not only machine language code generated by a compiler, but also high-level language code executable on a computer using an interpreter or the like. The hardware device may be configured to operate as one or more software modules to perform operations according to the present invention, or vice versa.
[0043] Although some embodiments have been described herein, it should be understood that these embodiments are provided for illustrative purposes only and should not be construed as limiting the invention in any way, and various modifications and alterations can be made by those skilled in the art without departing from the spirit and scope of the invention. Therefore, the appended claims and their equivalents are intended to cover such changes or modifications that fall within the scope and spirit of the invention.
[0044] Explanation of icon numbers
[0045] 10: Provider Server
[0046] 100: System Integration Server
[0047] 200: Patch Distribution Server
[0048] 300: Communication Unit
[0049] 400: Ships
[0050] 450: Patch Update Server
Claims
1. A ship network security patching system, comprising: The system integration server is configured to receive patches from the corresponding computer-based system provider server and integrate the patches received for the target computer-based system when a target computer-based system to be patched is identified among multiple computer-based systems on the ship. A patch deployment server is configured to authenticate and encrypt the patches received from the system integration server, and deploy the encrypted patches. as well as A patch update server, installed on the vessel, is configured to authenticate and decrypt patches received from the patch deployment server, and to verify the patches based on hashes, timestamps, and patch versions to apply patch updates. The patch update server continuously applies cybersecurity patch updates based on the ship's operating conditions and location.
2. The ship network security patching system according to claim 1, wherein the patch deployment server deploys the patch by connecting via any communication method selected from Very Small Aperture Terminal, Long Term Evolution, and Port Area Network, based on the ship's operating conditions and location.
3. The ship network security patching system according to claim 1, wherein... The patch update server also includes a backup update server; and If the communication connection is interrupted during the patch update performed through the patch update server, the patch update server saves the patch state before the interruption through the backup update server, and resumes the patch update from the point of interruption once the communication connection is re-established.
4. A method for patching ship cybersecurity, comprising: In the patch receiving step, when a target computer-based system to be patched is identified among multiple computer-based systems on the ship, the system integration server receives patches from the corresponding computer-based system provider server and integrates the patches received for the target computer-based system. In the patch distribution step, the patch deployment server authenticates and encrypts the patch received in the patch receiving step, and deploys the encrypted patch. as well as In the patch update step, the patch update server on the ship receives the patch deployed in the patch distribution step, authenticates and decrypts the received patch, and verifies the patch based on hash, timestamp, and patch version to apply the patch update. In the patch update step, cybersecurity patch updates are continuously applied based on the ship's operating conditions and location.
5. The method for patching ship network security according to claim 4, wherein in the patch distribution step, the patch is deployed by connecting via any one of the following communication methods selected from Very Small Aperture Terminal, Long Term Evolution, and Port Area Network, based on the ship's operating conditions and location.
6. The method for patching ship network security according to claim 4, wherein in the patch update step, the patch update server further includes a backup update server; and If the communication connection is interrupted during the patch update performed through the patch update server, the patch update server saves the patch state before the interruption through the backup update server, and resumes the patch update from the point of interruption once the communication connection is re-established.