Method and system for full offline maritime compliance environment audit based on shipboard trusted gateway
Patent Information
- Application Number
- CN202611132965.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-29
- Publication Date
- 2026-09-29
AI Technical Summary
[0004]由于现有的离线管理系统缺乏对物理硬件根源及运行环境连续性的感知能力,单纯依赖软件层的业务日志对账极易被底层黑客手段绕过,无法提供具备绝对法律效力的海事合规审计证据
防克隆与防篡改效果显著:通过硬件信任根和环境指纹度量,将系统运行环境与特定的物理硬件、地理位置和时空状态强绑定,使得环境克隆攻击和底层日志篡改在技术上变得不可行。
Smart Images

Figure CN122845267A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the fields of distributed system security, edge computing, and maritime information technology, specifically to a fully offline maritime compliance environment auditing method and system based on a shipborne trusted gateway. Background Technology
[0002] In maritime compliance audits of ocean-going vessels (such as RightShip RISQ 3.2 audits), data anti-counterfeiting in a fully offline state is a core challenge. Existing offline anti-cheating solutions mostly focus on implementing identity credential derivation, anti-proxy facial recognition, and business-level chained log reconciliation at the software application layer. However, these solutions all rely on the blind spot of "assuming the local operating system and physical hardware environment are secure and trustworthy." In actual maritime scenarios, crew members often employ the following low-level technical means to commit systematic cheating: Environment cloning attack: The local training / examination system is packaged and mirrored, and copied to a high-computing device or virtualized operating environment (virtual machine) on land for centralized question-taking and exam-taking on behalf of others.
[0003] Underlying log tampering: Using underlying debugging tools to modify the business logs in the operating system's memory, and then reporting forged "compliant" reconciliation records to the cloud when connected to the network.
[0004] Because existing offline management systems lack the ability to perceive the continuity of physical hardware and operating environment, relying solely on software-layer business log reconciliation is easily bypassed by low-level hacking techniques, failing to provide maritime compliance audit evidence with absolute legal validity. Therefore, how to combine the unique physical and temporal elements of ocean-going vessels to build an unforgeable environment-level compliance audit mechanism from the hardware level is a technical barrier that urgently needs to be addressed in the current maritime digital transformation. Summary of the Invention
[0005] To address the technical problems existing in the prior art, this invention provides a method and system for continuously measuring the physical environment of the terminal, generating a spatiotemporal topological fingerprint, and implementing consistency auditing and reconciliation on the land end in the absence of network or in an extremely weak network environment on ocean-going vessels.
[0006] The technical solution of the present invention to solve the above-mentioned technical problems is as follows: On the one hand, this invention provides a fully offline maritime compliance environment auditing method based on a shipborne trusted gateway, comprising the following steps: Step S1: Activate the hardware trusted module built into the shipborne trusted gateway; Step S2: The hardware trusted module collects heterogeneous parameters of the underlying physical environment in each preset collection cycle, and fuses them to generate a compliant environment state topology fingerprint corresponding to that cycle. Step S3: Using the non-derivative asymmetric private key inside the hardware trusted module, combined with a monotonically increasing hardware counter, perform hardware-level digital signature on each environmental state topology fingerprint to generate a corresponding environmental time signature stamp, and accumulate them to form an environmental time signature stamp queue. Step S4: Locally solidify and store the environmental time stamp queue; Step S5: When the shipborne trusted gateway establishes a network connection with the shore-based server, it asynchronously and incrementally reports the locally stored environmental time signature queue to the shore-based server. Step S6: The shore-based server decrypts each environmental time stamp in the environmental time stamp queue, retrieves the same period's maritime official AIS navigation trajectory data, and executes the spatiotemporal resonance comparison algorithm; the spatiotemporal resonance comparison algorithm includes: calculating the distance residual of each sampling point, and comparing the internal kernel temperature and voltage drift curve of the shipborne trusted gateway with preset semiconductor physical characteristics; Step S7: If the comparison results meet the preset consistency conditions, the physical operating environment is determined to be real, and a compliance audit ledger is generated; otherwise, it is determined that an attack has been carried out and an early warning is issued.
[0007] Furthermore, in step S2, the hardware trusted module collects the heterogeneous parameters of the underlying physical environment at a fixed period.
[0008] Furthermore, in step S2, the heterogeneous parameters of the underlying physical environment include: real-time voltage and temperature drift fingerprint of the gateway kernel, topological fingerprint of the MAC address of active terminals in the local area network, physical GPS latitude and longitude data of the ship, and integrity hash of the currently running courseware storage sector.
[0009] Furthermore, in step S3, the count value of the hardware counter is temporarily stored in a memory register protected by hardware shielding. After the system interaction ends or at preset time intervals, the count value in the memory register is batch-written to the non-volatile storage of the hardware trusted module.
[0010] Furthermore, in step S3, the lifetime index of the non-volatile storage inside the hardware trusted module is monitored in real time. If the lifetime index reaches a preset threshold, the system automatically switches to the backup hardware trusted module via a hardware pin to continue the signature operation.
[0011] Furthermore, the distance residual The calculation formula is: , in, The latitude and longitude coordinates deciphered from the environmental time stamp. These are the ship coordinates from the official AIS data at the same time.
[0012] Furthermore, the preset consistency condition in step S7 is: the residual of sampling points above a preset proportion threshold within the offline navigation cycle. The temperature and voltage drift curves of the internal core of the shipborne trusted gateway are less than the preset threshold σ, and conform to the preset semiconductor physical characteristics.
[0013] On the other hand, the present invention also provides a fully offline maritime compliance environment auditing system based on a shipborne trusted gateway, comprising: a shipborne trusted gateway deployed on an ocean-going vessel and a shore-based server; the shipborne trusted gateway is equipped with a hardware trusted module; The hardware trusted module is configured to: collect heterogeneous parameters of the underlying physical environment in each preset collection cycle, and fuse them to generate a compliant environment state topology fingerprint corresponding to that cycle; use the non-derivative asymmetric private key inside the hardware trusted module, combined with a monotonically increasing hardware counter, to perform hardware-level digital signature on each environment state topology fingerprint, generate a corresponding environment time signature stamp, and accumulate them to form an environment time signature stamp queue; store the environment time signature stamp queue locally; when the shipborne trusted gateway establishes a network connection with the shore-based server, asynchronously and incrementally report the locally stored environment time signature stamp queue to the shore-based server; The shore-based server is configured to: decrypt each environmental time stamp in the environmental time stamp queue, retrieve the same period's maritime official AIS navigation trajectory data, and execute a spatiotemporal resonance comparison algorithm; the spatiotemporal resonance comparison algorithm includes: calculating the distance residual of each sampling point, and comparing the internal kernel temperature and voltage drift curve of the shipborne trusted gateway with preset semiconductor physical characteristics; if the comparison result meets the preset consistency conditions, the physical operating environment is determined to be real, and a compliance audit ledger is generated; otherwise, it is determined that an attack has been suffered and an early warning is issued.
[0014] Furthermore, the shipborne trusted gateway also includes a counter management unit, which is configured to: temporarily store the count value of the hardware counter in a memory register protected by hardware shielding, and batch write the count value in the memory register to the non-volatile storage of the hardware trusted module at the end of system interaction or at every preset time period.
[0015] Furthermore, the shipborne trusted gateway is equipped with at least two hardware trusted modules, serving as a primary hardware trusted module and a backup hardware trusted module, respectively. When the primary hardware trusted module detects that the lifetime index of its internal non-volatile storage has reached a preset threshold, it automatically switches to the backup hardware trusted module via a hardware pin to continue working.
[0016] The beneficial effects of this invention are: Significant anti-cloning and anti-tampering effects: By using hardware root of trust and environmental fingerprint measurement, the system operating environment is strongly bound to specific physical hardware, geographical location and spatiotemporal state, making environmental cloning attacks and underlying log tampering technically impossible.
[0017] Audit evidence has legal effect: Hardware private key digital signatures and monotonic counters based on hardware trusted modules provide non-repudiation and temporal integrity that traditional software logs cannot match, making the generated audit evidence have absolute judicial and industry compliance effect.
[0018] Adaptable to extreme network environments: Local measurement and signing in a fully offline state, as well as the asynchronous incremental upload mechanism after networking, perfectly solve the data collection and transmission problems in ocean voyages in environments without or with weak networks.
[0019] Reduced manual review costs: The automated spatiotemporal resonance reconciliation and compliance adjudication of shore-based servers replace traditional manual spot checks and post-audits, greatly improving audit efficiency and accuracy. Attached Figure Description
[0020] Figure 1 This invention provides a schematic diagram of a fully offline maritime compliance environment auditing method based on a shipborne trusted gateway, as an embodiment of the present invention. Detailed Implementation
[0021] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0022] In the description of this application, the term "for example" is used to mean "used as an example, illustration, or description." Any embodiment described as "for example" in this application is not necessarily to be construed as being more preferred or advantageous than other embodiments. The following description is provided to enable any person skilled in the art to make and use the invention. Details are set forth in the following description for purposes of explanation. It should be understood that those skilled in the art will recognize that the invention can be made without using these specific details. In other instances, well-known structures and processes will not be described in detail to avoid obscuring the description of the invention with unnecessary detail. Therefore, the invention is not intended to be limited to the embodiments shown, but is consistent with the broadest scope of the principles and features disclosed in this application.
[0023] like Figure 1As shown, this embodiment of the invention provides a fully offline maritime compliance environment auditing method based on a shipborne trusted gateway. This method is executed collaboratively by the shipborne trusted gateway and a shore-based server. The shipborne trusted gateway is deployed on an ocean-going vessel and integrates a hardware trusted module. In this embodiment, the hardware trusted module uses a TPM2.0 security chip that conforms to the Trusted Computing Cryptographic Support Platform specification. This security chip has an independent encryption processor, a non-exportable asymmetric private key storage area, a monotonically increasing hardware counter, and a hardware-protected NVRAM storage area.
[0024] The specific steps are as follows: Step S1, Offline Activation: In a fully offline state, the crew activates the hardware trusted module built into the shipboard trusted gateway. During startup, the hardware trusted module first performs a self-test to verify its firmware integrity and NVRAM status. Simultaneously, the hardware trusted module loads the metrics kernel, which is responsible for scheduling and executing subsequent periodic data collection tasks.
[0025] Step S2, Continuous Measurement: The trusted hardware module collects heterogeneous parameters of the underlying physical environment in real time during each acquisition cycle (set to 5 minutes in this embodiment). These heterogeneous parameters of the underlying physical environment include the following four items: Gateway kernel real-time voltage and temperature drift fingerprint: The CPU core voltage and temperature values are collected by the onboard ADC sensor, forming a small fluctuation curve that changes over time. This curve has the inherent physical characteristics of semiconductor devices and is difficult to be simulated by a virtual machine.
[0026] MAC address topology fingerprint of active terminals in the local area network: Scan the list of MAC addresses of all active devices in the current local area network and their connection order to form a network topology snapshot.
[0027] Ship physical GPS latitude and longitude data: The ship's precise latitude and longitude coordinates are obtained through the ship's onboard GPS module.
[0028] Integrity hash of the currently running courseware storage sector: Perform a hash calculation on the storage partition where the running courseware file is located to ensure that the courseware content has not been tampered with.
[0029] The hardware trusted module concatenates the above four heterogeneous parameters according to a predetermined format and uses the SHA-256 hash algorithm to generate the compliance environment state topology fingerprint EF for that period. EF is a 256-bit binary string that uniquely represents the ship's physical environment and hardware state at the current moment.
[0030] Step S3, Fingerprint Strong Signature: Using the non-derivative asymmetric private key (ECC P-256 private key) within the hardware trusted module, combined with a monotonically increasing hardware counter, a hardware-level digital signature is performed on the environmental state topology fingerprint EF for each cycle, generating a corresponding environmental time signature stamp. Specifically, the signature data structure is Signature = Sign(PrivKey, EF || Counter), where Counter is the current value of the hardware counter. The signature result for each cycle forms an independent time signature stamp, and multiple time signature stamps are accumulated in chronological order to form an environmental time signature stamp queue.
[0031] To protect the physical lifetime of the NVRAM of the monotonic counter inside the hardware trusted module (the NVRAM write lifetime of a typical TPM2.0 chip is approximately 100,000 cycles), this embodiment employs a hardware-software hybrid counter architecture: During each 5-minute signature operation, the monotonic counter's count value is first temporarily stored in a hardware-shielded memory register and is not directly written to NVRAM. This memory register is implemented by the TPM's internal SRAM, is lost upon power failure, but is powered by the gateway's backup battery during fully offline periods.
[0032] The accumulated count value in the memory register is only written to the NVRAM of the hardware trusted module in batches after the system interaction ends (such as exam submission or practical operation completion) or every 24 hours (whichever comes first). In this way, the NVRAM write frequency is reduced from once every 5 minutes to once a day or once at the end of each interaction, which greatly extends the life of the NVRAM.
[0033] To further ensure reliability during long-term voyages, this embodiment incorporates two TPM2.0 security chips on the shipboard trusted gateway hardware board, serving as the primary and backup trusted hardware modules, respectively. Before each signature operation, the primary trusted hardware module monitors the lifespan metrics of its internal NVRAM (such as write / erase cycles and remaining lifespan percentage). When the lifespan metrics reach a preset threshold (e.g., remaining lifespan below 10%), the primary trusted hardware module outputs a switching signal via a GPIO pin, automatically switching the signature task to the backup trusted hardware module. Upon activation, the backup trusted hardware module immediately takes over all measurement, signing, and storage functions, ensuring uninterrupted auditing processes.
[0034] Step S4, Local Solidification: The environmental time stamp queue is solidified and stored in a non-volatile storage medium (such as an eMMC flash memory chip) of the shipborne trusted gateway. Storage is performed using an append-only method, with each stamp accompanied by a timestamp index for easy subsequent incremental uploads and retrieval.
[0035] Step S5, Asynchronous Stream Reconciliation: When the shipborne trusted gateway establishes a network connection with the shore-based server (e.g., when the ship enters a near-shore 4G coverage area or obtains idle bandwidth via a satellite link), the gateway automatically and asynchronously incrementally reports the locally stored environmental time stamp queue to the shore-based server. The reporting uses a breakpoint resume mechanism, uploading only the stamps added since the last synchronization to reduce bandwidth consumption.
[0036] Step S6, Spatiotemporal Resonance Verification: The shore-based server decrypts each environmental time stamp in the environmental time stamp queue, extracts the GPS latitude and longitude data and kernel temperature and voltage drift curve data, retrieves the same-period maritime official AIS navigation trajectory data, and executes the spatiotemporal resonance comparison algorithm. This algorithm includes two parallel sub-steps: Sub-step A: Distance residual calculation. For each sampling point, calculate the Euclidean distance residual between its GPS coordinates and AIS coordinates: , in, The latitude and longitude coordinates deciphered from the environmental time stamp. These are the ship coordinates from the official AIS data at the same time. Time alignment uses a linear interpolation method to match the timestamps in the AIS data with the stamp timestamps.
[0037] Sub-step B: Temperature and voltage drift curve comparison. The shore-based server pre-stores a semiconductor physical characteristic model (i.e., a baseline curve showing the core temperature and voltage changes with time and load) of the trusted module of this hardware model under a real physical environment. The decrypted temperature and voltage drift curve is compared with the baseline curve to calculate similarity, and a dynamic time warping algorithm is used to measure the degree of agreement between the two curves. If the degree of agreement is higher than a preset threshold (e.g., 95%), the physical environment is considered real.
[0038] Step S7, Compliance Decision Output: If the comparison results meet the preset consistency conditions, the physical operating environment is determined to be authentic, and a compliance audit ledger is generated; otherwise, an attack is determined and an early warning is issued. The preset consistency conditions are: within the offline navigation cycle, the residual distance ΔD of sampling points above a preset percentage threshold (e.g., 98.5%) is less than a preset threshold σ, and the consistency between the core temperature and voltage drift curves and the semiconductor physical characteristics is higher than 95%.
[0039] In this embodiment, the distance residual threshold σ = 0.005 degrees (approximately 550 meters of physical distance in equatorial and mid-latitude sea areas). This value is set based on the maximum reasonable physical displacement spatial residual generated when the ship is sailing at a normal speed (12-20 knots) between the conventional GPS positioning error of civilian ships (approximately 10-15 meters) and the dynamic update delay of the standard shipborne AIS transmitter (ranging from 3 seconds to 3 minutes), as stipulated by the International Maritime Organization (IMO). Calculations show that at a speed of 20 knots and a 3-minute AIS update delay, the maximum displacement is approximately 1.85 kilometers. However, considering the GPS positioning error and the center deviation of the AIS reported position, a conservative threshold of 0.005 degrees (approximately 550 meters) is used to ensure safety while avoiding misjudgments.
[0040] The 98.5% threshold is a statistical convergence result based on the discarding of outlier, dirty data from satellite signals due to multipath effects under high sea states in the open ocean. In laboratory simulation tests, statistical analysis of real navigation data under 100 different sea state conditions revealed that the outlier rate normally does not exceed 1.2%. Therefore, a 1.5% fault tolerance rate (i.e., a 98.5% pass rate) is set to filter environmental noise such as sudden sharp turns by ships and satellite outages due to severe weather. If the outlier rate exceeds 1.5% (i.e., the fit rate is below 98.5%), statistically, it is highly likely to be a spoofed trajectory attack occurring in a virtual machine operating environment.
[0041] By employing this integrated hardware and software environmental dynamic measurement and spatiotemporal resonance reconciliation method, this embodiment completely eliminates technical fraud in the field of maritime compliance from the root of physical trust at the system's underlying level.
[0042] It should be understood that the various forms of processes shown above can be used to rearrange, add, or delete steps. For example, the steps described in this disclosure can be performed in parallel, sequentially, or in a different order, as long as the desired result of the technical solution disclosed in this disclosure can be achieved, and this is not limited herein.
[0043] While embodiments or examples of this disclosure have been described with reference to the accompanying drawings, it should be understood that the methods, systems, and devices described above are merely exemplary embodiments or examples, and the scope of the invention is not limited by these embodiments or examples, but only by the granted claims and their equivalents. Various elements in the embodiments or examples may be omitted or replaced by their equivalents. Furthermore, the steps may be performed in a different order than that described in this disclosure. Further, various elements in the embodiments or examples may be combined in various ways. Importantly, as the technology evolves, many elements described herein can be replaced by equivalents that appear after this disclosure.
Claims
1. A fully offline maritime compliance environment auditing method based on a shipborne trusted gateway, characterized in that, Includes the following steps: Step S1: Activate the hardware trusted module built into the shipborne trusted gateway; Step S2: The hardware trusted module collects heterogeneous parameters of the underlying physical environment in each preset collection cycle, and fuses them to generate a compliant environment state topology fingerprint corresponding to that cycle. Step S3: Using the non-derivative asymmetric private key inside the hardware trusted module, combined with a monotonically increasing hardware counter, perform hardware-level digital signature on each environmental state topology fingerprint to generate a corresponding environmental time signature stamp, and accumulate them to form an environmental time signature stamp queue. Step S4: Locally solidify and store the environmental time stamp queue; Step S5: When the shipborne trusted gateway establishes a network connection with the shore-based server, it asynchronously and incrementally reports the locally stored environmental time signature queue to the shore-based server. Step S6: The shore-based server decrypts each environmental time stamp in the environmental time stamp queue, retrieves the same period's maritime official AIS navigation trajectory data, and executes the spatiotemporal resonance comparison algorithm; the spatiotemporal resonance comparison algorithm includes: calculating the distance residual of each sampling point, and comparing the internal kernel temperature and voltage drift curve of the shipborne trusted gateway with preset semiconductor physical characteristics; Step S7: If the comparison results meet the preset consistency conditions, the physical operating environment is determined to be real, and a compliance audit ledger is generated; otherwise, it is determined that an attack has been carried out and an early warning is issued.
2. The method according to claim 1, characterized in that, In step S2, the trusted hardware module collects heterogeneous parameters of the underlying physical environment at fixed intervals.
3. The method according to claim 1, characterized in that, In step S2, the heterogeneous parameters of the underlying physical environment include: real-time voltage and temperature drift fingerprint of the gateway kernel, MAC address topology fingerprint of active terminals in the local area network, physical GPS latitude and longitude data of the ship, and integrity hash of the currently running courseware storage sector.
4. The method according to claim 1, characterized in that, In step S3, the count value of the hardware counter is temporarily stored in a memory register protected by hardware shielding. After the system interaction ends or at preset time intervals, the count value in the memory register is written in batches to the non-volatile storage of the hardware trusted module.
5. The method according to claim 4, characterized in that, The lifetime index of the non-volatile memory inside the hardware trusted module is monitored in real time. If the lifetime index reaches a preset threshold, the system automatically switches to the backup hardware trusted module via a hardware pin to continue the signature operation.
6. The method according to claim 1 or 3, characterized in that, The distance residual The calculation formula is: , in, The latitude and longitude coordinates deciphered from the environmental time stamp. These are the ship coordinates from the official AIS data at the same time.
7. The method according to claim 1, characterized in that, The preset consistency condition in step S7 is: the residual of sampling points above a preset proportion threshold within the offline navigation cycle. The temperature and voltage drift curves of the internal core of the shipborne trusted gateway are less than the preset threshold σ, and conform to the preset semiconductor physical characteristics.
8. A fully offline maritime compliance environment auditing system based on a shipborne trusted gateway, characterized in that, include: Shipborne trusted gateway and shore-based server deployed on ocean-going vessels; the shipborne trusted gateway is equipped with a hardware trusted module; The hardware trusted module is configured to: collect heterogeneous parameters of the underlying physical environment in each preset collection cycle, and fuse them to generate a compliant environment state topology fingerprint corresponding to that cycle; use the non-derivative asymmetric private key inside the hardware trusted module, combined with a monotonically increasing hardware counter, to perform hardware-level digital signature on each environment state topology fingerprint, generate a corresponding environment time signature stamp, and accumulate them to form an environment time signature stamp queue; store the environment time signature stamp queue locally; when the shipborne trusted gateway establishes a network connection with the shore-based server, asynchronously and incrementally report the locally stored environment time signature stamp queue to the shore-based server; The shore-based server is configured to: decrypt each environmental time stamp in the environmental time stamp queue, retrieve the same period's maritime official AIS navigation trajectory data, and execute a spatiotemporal resonance comparison algorithm; the spatiotemporal resonance comparison algorithm includes: calculating the distance residual of each sampling point, and comparing the internal kernel temperature and voltage drift curve of the shipborne trusted gateway with preset semiconductor physical characteristics; if the comparison result meets the preset consistency conditions, the physical operating environment is determined to be real, and a compliance audit ledger is generated; otherwise, it is determined that an attack has been suffered and an early warning is issued.
9. The system according to claim 8, characterized in that, The shipborne trusted gateway also includes a counter management unit, which is configured to: temporarily store the count value of the hardware counter in a memory register protected by hardware shielding, and at the end of system interaction or at every preset time period, batch write the count value in the memory register to the non-volatile storage of the hardware trusted module.
10. The system according to claim 8, characterized in that, The shipborne trusted gateway is equipped with at least two hardware trusted modules, serving as the primary hardware trusted module and the backup hardware trusted module, respectively. When the primary hardware trusted module detects that the lifetime index of its internal non-volatile storage has reached a preset threshold, it automatically switches to the backup hardware trusted module via a hardware pin to continue working.