Ship network communication architecture and security management method of ship network communication
Patent Information
- Application Number
- CN202611275126.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-08-21
- Publication Date
- 2026-09-29
AI Technical Summary
[0004]一方面,所有设备共用一个通信网络易造成数据拥堵,动力等关键系统指令易因干扰延迟,影响船舶响应甚至引发安全隐患;另一方面,不同功能模块间设备协议兼容性差,如电机控制器与电池管理系统协议各异,导致设备间数据交互困难,难以协同工作;在第三方面,现有船舶通信架构的故障隔离与处理能力弱,某一设备故障易波及整个网络,干扰自动驾驶等系统决策,且缺乏有效优先级管理,紧急数据难优先传输,进一步降低了船舶通信的可靠性与安全性
[0017]通过对传统的船舶通信网络架构进行优化,采用具有多功能域划分和物理隔离的网络架构,使得各个功能域能够进行单独的通信,同时通过中央网关进行统一的功能域之间的通讯协调,从而大大优化了通信稳定性和可靠性;同时在通信过程中,采用基于场景化的加密策略,保障了通信的安全性,满足了企业实际需求。
Smart Images

Figure CN122845327A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of ship communication technology, specifically to a ship network communication architecture and a method for the security management of ship network communication. Background Technology
[0002] With the rapid development of new energy ship technology, ship network systems are becoming increasingly complex, integrating multiple functional modules such as power control, automatic driving, and intelligent diagnosis. The data interaction requirements between various devices are becoming more and more complex, placing extremely high demands on communication security and reliability.
[0003] In traditional ship communication architectures, due to the large number of electronic and electrical devices, numerous devices share the same network to facilitate cable installation and use. However, in practical applications, technicians have discovered that traditional ship communication architectures suffer from at least the following technical problems:
[0004] On the one hand, sharing a single communication network with all equipment can easily lead to data congestion, and commands from critical systems such as power systems can be delayed due to interference, affecting ship response and even causing safety hazards. On the other hand, poor compatibility of equipment protocols between different functional modules, such as the different protocols of the motor controller and the battery management system, makes data interaction between devices difficult and hinders collaborative work. Thirdly, the existing ship communication architecture has weak fault isolation and processing capabilities. A failure in one device can easily affect the entire network, interfering with the decision-making of systems such as autopilot, and the lack of effective priority management makes it difficult to prioritize the transmission of emergency data, further reducing the reliability and security of ship communication. Summary of the Invention
[0005] To overcome the aforementioned technical problems in the prior art, this invention provides a ship network communication architecture and a security management method for ship network communication. By improving the architecture of the existing ship communication network, multiple functional domains are physically isolated to optimize communication. At the same time, a scenario-based encryption mechanism is adopted to improve the reliability and accuracy of data transmission.
[0006] To achieve the above objectives, embodiments of the present invention provide a ship network communication architecture, which includes multiple functional domains, each configured on a different physical medium, and each functional domain electrically connected to a central gateway via a CAN bus. The multiple functional domains include a power domain, a central control domain, an autopilot domain, an environmental immunity domain, an energy security domain, and an emergency management domain. The power domain includes a first CANFD, which is electrically connected to multiple ship power components. The central control domain includes a second CANFD, which is electrically connected to multiple ship control components. The autopilot domain includes a first Ethernet, which is electrically connected to multiple ship navigation components. The environmental immunity domain includes a third CANFD, which is electrically connected to multiple environmental monitoring sensors. The energy security domain includes a fourth CANFD, which is electrically connected to multiple battery safety protection components. The emergency management domain includes a fifth CANFD, which is electrically connected to multiple ship emergency response devices.
[0007] Preferably, the plurality of functional domains further includes a diagnostic domain; the diagnostic domain includes a second Ethernet, which is electrically connected to the ship diagnostic instrument, and the ship diagnostic instrument and the central gateway perform security authentication operations through the second Ethernet, and execute corresponding communication connections according to the security authentication results.
[0008] On the other hand, embodiments of the present invention also provide a security management method for ship network communication, applied to a ship network communication architecture according to embodiments of the present invention, the ship network communication architecture including a central gateway and multiple functional domains, the method comprising: acquiring ship operation data from the multiple functional domains; determining dynamic weights based on the ship operation data through the central gateway; determining a CRC checksum for communication, and determining multi-factor contribution values based on the ship operation data; generating a final checksum based on the dynamic weights, the CRC checksum, and the multi-factor contribution values; generating a communication message based on the final checksum and data to be transmitted; and sending the communication message.
[0009] Preferably, determining the dynamic weights based on the ship operation data includes: determining initial weights, which include environmental interference weights, equipment health weights, dynamic parameter weights, and link quality weights; determining the ship navigation mode based on the ship operation data, adjusting the environmental interference weights based on the ship navigation mode to generate adjusted environmental weights; determining the ship operation status based on the ship operation data, adjusting the equipment health weights based on the ship operation status to generate adjusted health weights; determining the ship motion state based on the ship operation data, adjusting the dynamic parameter weights based on the ship motion state to generate adjusted parameter weights; determining the link quality based on the ship operation data, adjusting the link quality weights based on the link quality to generate adjusted link weights; and performing normalization processing on the adjusted environmental weights, the adjusted health weights, the adjusted parameter weights, and the adjusted link weights to generate dynamic weights.
[0010] Preferably, the ship operation data includes real-time ship speed, propulsion motor speed, remaining battery power, engine room ambient temperature, positioning latitude and longitude, battery health, motor health, radar health, gateway health, packet loss rate, network latency, bit error rate, electromagnetic interference intensity, salt spray concentration, and wind speed. The step of determining multi-factor contribution values based on the ship operation data includes: dynamically determining operating condition coefficients based on the ship operation data; determining dynamic operation contribution values based on the operating condition coefficients, real-time ship speed, propulsion motor speed, remaining battery power, engine room ambient temperature, and positioning latitude and longitude; determining equipment health contribution values based on the operating condition coefficients, battery health, motor health, radar health, and gateway health; determining link quality contribution values based on the operating condition coefficients, packet loss rate, network latency, and bit error rate; and determining environmental interference contribution values based on the operating condition coefficients, electromagnetic interference intensity, salt spray concentration, and wind speed.
[0011] Preferably, the step of dynamically determining the operating condition coefficient based on the ship's operating data includes: determining a power coefficient based on the ship's real-time speed; determining an energy coefficient based on the remaining battery power and the engine room ambient temperature; determining a positioning coefficient based on the positioning latitude and longitude; determining an equipment health coefficient based on the battery health, motor health, radar health, and gateway health; determining a link quality coefficient based on the packet loss rate and network latency; determining an environmental interference coefficient based on the electromagnetic interference intensity, salt spray concentration, and wind speed; and generating an operating condition coefficient based on the power coefficient, energy coefficient, positioning coefficient, equipment health coefficient, link quality coefficient, and environmental interference coefficient.
[0012] Preferably, the step of generating a communication message based on the final checksum and the data to be transmitted includes: obtaining the parameter acquisition time and the link identifier; generating an initial CAN message based on the data to be transmitted; processing the initial CAN message based on the final checksum to generate a processed message; and processing the processed message based on the parameter acquisition time and the link identifier to generate a communication message.
[0013] Preferably, the method further includes: obtaining the verification feedback from the receiving node for the communication message; if the verification feedback is N data retransmissions, performing the corresponding data retransmission operation, where N is a positive integer; if the verification feedback is a device malfunction, cutting off network communication with the receiving node and establishing a connection with the receiving node using a backup network device.
[0014] Preferably, the plurality of functional domains includes a diagnostic domain, which is electrically connected to a diagnostic instrument. The method further includes: performing an authentication operation before the diagnostic domain communicates with the central gateway; if the authentication operation is successful, obtaining a first key sent by the diagnostic instrument, the first key being generated based on the ship's operating data; the central gateway generating a second key and a random challenge code based on the first key; the central gateway encrypting the random challenge code based on the second key, generating and sending an encrypted challenge code; the diagnostic instrument decrypting the encrypted challenge code based on the first key, generating and sending decryption information; and the central gateway analyzing the decryption information to generate a security authentication result.
[0015] Preferably, the step of performing the identity authentication operation includes: determining preset identity screening data, wherein the preset identity screening data is non-sensitive data; responding to the identity authentication request initiated by the diagnostic instrument; verifying the identity authentication request based on the preset identity screening data, and generating an identity verification result.
[0016] The present invention has at least the following technical effects through the technical solution provided by the present invention:
[0017] By optimizing the traditional ship communication network architecture and adopting a network architecture with multi-functional domain division and physical isolation, each functional domain can communicate independently, while a central gateway coordinates communication between functional domains, thereby greatly optimizing communication stability and reliability. At the same time, a scenario-based encryption strategy is adopted during communication to ensure communication security and meet the actual needs of enterprises.
[0018] Other features and advantages of the embodiments of the present invention will be described in detail in the following detailed description section. Attached Figure Description
[0019] The accompanying drawings are provided to further illustrate embodiments of the present invention and form part of the specification. They are used together with the following detailed description to explain the embodiments of the present invention, but do not constitute a limitation thereof. In the drawings:
[0020] Figure 1 This is a schematic diagram of the ship network communication architecture provided in an embodiment of the present invention;
[0021] Figure 2 This is a flowchart illustrating the specific implementation of the security management method for ship network communication provided in this embodiment of the invention. Detailed Implementation
[0022] The specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings. It should be understood that the specific embodiments described herein are for illustration and explanation only and are not intended to limit the scope of the present invention.
[0023] In this invention, the terms "system" and "network" are used interchangeably. "Multiple" refers to two or more; therefore, in this invention, "multiple" can also be understood as "at least two." "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, or B alone. Additionally, the character " / ", unless otherwise specified, generally indicates that the preceding and following related objects have an "or" relationship. Furthermore, it should be understood that in the description of this invention, terms such as "first" and "second" are used only for descriptive purposes and should not be construed as indicating or implying relative importance or order.
[0024] In traditional ship communication architectures, devices operate on the same network without clear domain division, making data transmission prone to congestion. For example, critical commands from the power system may experience delays due to interference during transmission, affecting not only the ship's response speed but also potentially posing safety hazards. Furthermore, devices from different vendors often have incompatible protocols; for instance, motor controllers and battery management systems use different protocols, making data exchange between devices extremely difficult and hindering collaborative operation. Additionally, traditional architectures have weak fault isolation and handling capabilities; a failure in one device can easily impact the entire network, interfering with decision-making in systems such as autopilot.
[0025] Please see Figure 1This invention provides a ship network communication architecture, which includes multiple functional domains, each configured on a different physical medium, and each functional domain electrically connected to a central gateway via a CAN bus. The multiple functional domains include a power domain, a central control domain, an autopilot domain, an environmental immunity domain, an energy security domain, and an emergency management domain. The power domain includes a first CANFD, which is electrically connected to multiple ship power components. The central control domain includes a second CANFD, which is electrically connected to multiple ship control components. The autopilot domain includes a first Ethernet, which is electrically connected to multiple ship navigation components. The environmental immunity domain includes a third CANFD, which is electrically connected to multiple environmental monitoring sensors. The energy security domain includes a fourth CANFD, which is electrically connected to multiple battery safety protection components. The emergency management domain includes a fifth CANFD, which is electrically connected to multiple ship emergency response devices.
[0026] In one possible embodiment, the ship's network system is first meticulously divided into several functional domains: power domain, central control domain, autopilot domain, environmental disturbance immunity domain, energy security domain, and emergency management domain. These domains are then configured on different physical media, such as using different circuit boards or placing the corresponding circuit boards in different physical spaces within the ship for electrical isolation. The power domain includes a first CANFD, which connects to ship power components such as motor controllers, battery management systems, ship controllers, remote controls, chargers, and transformers / rectifiers. It is primarily responsible for energy management and power output control of the ship's power system and is the core power source system collection for ship operation. The central control domain includes a second CANFD, which connects to ship control components such as instrument systems, entertainment systems, light and wiper control systems, pilot monitoring systems, keyless start systems, and shipboard networking terminals. It primarily handles information display, entertainment interaction, pilot status monitoring, and ship-to-external network connectivity within the ship's cockpit. The autonomous driving domain includes a first Ethernet network, which connects to ship navigation components such as millimeter-wave radar, ultrasonic radar, panoramic imaging systems, high-definition cameras, autopilot controllers, and lidar. This network is used for environmental perception, decision-making, and control related to ship autopilot, providing support for autonomous navigation. The environmental immunity domain includes a third CANFD network, which connects to environmental monitoring sensors such as electromagnetic interference monitors, salt spray concentration sensors, temperature and humidity sensors, and communication link quality monitoring modules. This network monitors the ship's operating environment and communication link status in real time, and then outputs anti-interference strategies such as signal enhancement and equipment shielding. The energy safety domain includes a fourth CANFD network, which connects to battery safety protection components such as battery thermal management modules, charging safety monitors, electrolyte leak detectors, and fire control systems. This network monitors the energy system status, provides fire / leakage warnings, and implements emergency response measures to ensure energy system safety. The emergency management domain includes a fifth CANFD network, which connects to ship emergency response devices such as emergency power controllers, emergency braking modules, distress signal transmitters, and crew emergency communication terminals. This network is responsible for emergency response and ensuring personnel safety when the ship encounters sudden failures such as power outages or fires.
[0027] The aforementioned first, second, third, fourth, and fifth CANFDs, along with the first Ethernet, are connected to the central gateway for communication. For example, using the ship's central gateway as the communication hub, multiple CAN buses connect it to each functional domain, thus establishing communication connections between all functional domains and enabling data interaction and collaborative control between different domains. During communication, a ship operating condition adaptive verification algorithm is employed. The basic verification part uses the XOR result of traditional CRC checksum and byte sum checksum as the basic verification value.
[0028] In practical applications, ships often use simple fault indications. However, with the continuous development of technology, people have higher and higher requirements for ship intelligence, and need to have the ability to perform intelligent diagnosis of ships at any time. However, this diagnosis involves sensitive data and sensitive operations of the ship's control system. Therefore, if communication is carried out directly, it may bring risks to the safe control of the ship.
[0029] In this embodiment of the invention, the plurality of functional domains further includes a diagnostic domain; the diagnostic domain includes a second Ethernet, which is electrically connected to the ship diagnostic instrument, and the ship diagnostic instrument and the central gateway perform a security authentication operation through the second Ethernet, and execute the corresponding communication connection according to the security authentication result.
[0030] Specifically, diagnostic domains are configured in multiple functional domains. These diagnostic domains include a second Ethernet network, electrically connected to the diagnostic instrument, specifically for fault diagnosis and safety verification of various ship systems, ensuring reliable operation. During implementation, the ship's diagnostic instrument and central gateway must first undergo security authentication via the second Ethernet network. Only after successful security authentication can subsequent communication connections be established.
[0031] In this embodiment of the invention, by improving the configuration of the existing ship control system and adopting an interactive communication method for different functional domains, the data between different functional domains do not interfere with each other, avoiding congestion caused by mixed transmission of different types of data, and greatly reducing the transmission delay of critical system commands; the dedicated bus and protocol adaptation design improves device compatibility and greatly increases the success rate of data interaction; at the same time, domain division realizes fault isolation, and the failure of a device in a certain domain only affects the function of that domain and will not affect the entire network, effectively improving the stability of ship operation.
[0032] The following describes a security management method implemented based on the ship network communication architecture according to an embodiment of the present invention. Existing ship network communication methods often rely on a single CRC checksum, without considering the ship's operating conditions and multi-dimensional parameters, resulting in insufficient data transmission accuracy. Furthermore, existing communication methods lack a dynamic weight adjustment mechanism, making it impossible to adapt the checksum strategy to the navigation status, which easily leads to checksum misjudgments and affects communication reliability.
[0033] On the other hand, please see Figure 2 This invention provides a security management method for ship network communication, applied to a ship network communication architecture according to an embodiment of the invention. The ship network communication architecture includes a central gateway and multiple functional domains. The method includes:
[0034] S10) Obtain ship operation data from the multiple functional domains;
[0035] S20) The central gateway determines the dynamic weights based on the ship operation data;
[0036] S30) Determine the CRC check value for communication and determine the multi-factor contribution value based on the ship operation data;
[0037] S40) Generate the final verification value based on the dynamic weight, the CRC check value, and the multi-factor contribution value;
[0038] S50) Generate a communication message based on the final verification value and the data to be transmitted;
[0039] S60) Send the communication message.
[0040] In one possible implementation, ship operation data is first acquired from multiple functional domains, such as dynamic parameters (speed, motor speed, etc.), equipment health parameters (battery health, motor health, etc.), link quality parameters (packet loss rate, latency, etc.), and environmental interference parameters (electromagnetic interference intensity, salt spray concentration, etc.). Then, the corresponding dynamic weights are determined through a central gateway.
[0041] In traditional communication processes, a fixed weight method is often used. However, in complex marine environments, data may be affected by various interferences, resulting in poor data transmission accuracy and communication quality, which cannot meet the requirements for real-time and high-stability communication.
[0042] In this embodiment of the invention, determining the dynamic weights based on the ship operation data includes: determining initial weights, which include environmental interference weights, equipment health weights, dynamic parameter weights, and link quality weights; determining the ship navigation mode based on the ship operation data, adjusting the environmental interference weights based on the ship navigation mode to generate adjusted environmental weights; determining the ship operation status based on the ship operation data, adjusting the equipment health weights based on the ship operation status to generate adjusted health weights; determining the ship motion state based on the ship operation data, adjusting the dynamic parameter weights based on the ship motion state to generate adjusted parameter weights; determining the link quality based on the ship operation data, adjusting the link quality weights based on the link quality to generate adjusted link weights; and performing normalization processing on the adjusted environmental weights, the adjusted health weights, the adjusted parameter weights, and the adjusted link weights to generate dynamic weights.
[0043] In one possible implementation, initial weights are first determined, including, for example, environmental interference weights, equipment health weights, dynamic parameter weights, and link quality weights, each with an initial weighting of 25%. Then, each weight is optimized and adjusted based on actual ship operation data. Specifically, the ship's navigation mode is determined based on the ship's operation data; for example, when the ship's navigation mode is ocean voyage, the environmental interference weight is increased by 20%. The ship's operating status is determined based on the ship's operation data; for example, when the ship's operating status is port berth, the equipment health weight is increased by 20%. Based on the same principle, the dynamic parameter weights and link quality weights are adjusted. Finally, normalization processing is performed on all adjusted weights to generate dynamic weights.
[0044] In this embodiment of the invention, by improving the traditional weight allocation method, the weight allocation is combined with the specific scenarios of ship operation. When the ship is docked in port, the focus is on the health status of the equipment, and when it is sailing in coastal waters, the focus is on ensuring the accuracy of dynamic parameter transmission. This makes the weight dynamically adaptable to different sailing scenarios, the verification strategy more targeted, greatly improves the scenario adaptability of data transmission, and further reduces the risk of verification misjudgment.
[0045] After determining the dynamic weights, the CRC checksum of the communication is determined, and further multi-factor contribution values are determined. In this embodiment of the invention, the ship operation data includes the ship's real-time speed, propulsion motor speed, remaining battery power, engine room ambient temperature, positioning latitude and longitude, battery health, motor health, radar health, gateway health, packet loss rate, network latency, bit error rate, electromagnetic interference intensity, salt spray concentration, and wind speed. Determining the multi-factor contribution values based on the ship operation data includes: dynamically determining the operating condition coefficient based on the ship operation data; determining the dynamic operation contribution value based on the operating condition coefficient, the ship's real-time speed, the propulsion motor speed, the remaining battery power, the engine room ambient temperature, and the positioning latitude and longitude; determining the equipment health contribution value based on the operating condition coefficient, the battery health, the motor health, the radar health, and the gateway health; determining the link quality contribution value based on the operating condition coefficient, the packet loss rate, the network latency, and the bit error rate; and determining the environmental interference contribution value based on the operating condition coefficient, the electromagnetic interference intensity, the salt spray concentration, and the wind speed.
[0046] In one possible implementation, operating condition coefficients are first dynamically determined based on ship operation data. These operating condition coefficients include, but are not limited to, power correlation coefficient α, energy and environment coefficient β, positioning coefficient γ, equipment health coefficient ζ, link quality coefficient η, and environmental interference coefficient θ.
[0047] In this embodiment of the invention, the step of dynamically determining the operating condition coefficient based on the ship's operating data includes: determining a power coefficient based on the ship's real-time speed; determining an energy coefficient based on the remaining battery power and the engine room ambient temperature; determining a positioning coefficient based on the positioning latitude and longitude; determining a device health coefficient based on the battery health, motor health, radar health, and gateway health; determining a link quality coefficient based on the packet loss rate and network latency; determining an environmental interference coefficient based on the electromagnetic interference intensity, salt spray concentration, and wind speed; and generating an operating condition coefficient based on the power coefficient, energy coefficient, positioning coefficient, device health coefficient, link quality coefficient, and environmental interference coefficient.
[0048] In one possible implementation, corresponding operating condition coefficients are determined based on different ship operating data. Specifically, the power coefficient is determined based on the ship's real-time speed; for example, when the speed is ≥20 km / h, α=2 is set, otherwise α=1. The energy coefficient is determined based on the remaining battery charge and engine room ambient temperature; for example, when SOC <30% or engine room temperature T >50℃, β=2 is set, otherwise β=1. The positioning coefficient is determined based on the positioning latitude and longitude; for example, when the ship is docked in port, γ=2 is set, otherwise γ=1. A comprehensive determination is made based on battery health, motor health, radar health, and gateway health (e.g., using a weighted average). Methods) Equipment health coefficients: For example, when the core equipment health is <50%, set ζ=4; when it is 50%-70%, set ζ=3; when it is 70%-90%, set ζ=2; and when it is ≥90%, set ζ=1. Link quality coefficients are determined based on packet loss rate and network latency: For example, when the packet loss rate is ≥5% or the latency is ≥100ms, set η=4; when it is 3%-5% or 50-100ms, set η=3; when it is 1%-3% or 20-50ms, set η=2; otherwise, set η=1. Environmental interference coefficients are determined based on electromagnetic interference intensity, salt spray concentration, and wind speed: For example, when electromagnetic interference is ≥10V / m or salt spray concentration is ≥50mg / m³. 3 Or, when the wind speed is ≥20m / s, set θ=4, 5-10V / m or 30-50mg / m 3 Alternatively, set θ=3 when the speed is 12-20 m / s, otherwise set θ=1.
[0049] After determining the operating condition coefficients, the following are further determined: the ship's dynamic contribution value, for example, represented as: Dyn_Value=α×(V+N / 10)+β×(SOC%+T / 10)+γ×(Lon'+Lat'); the equipment health contribution value, for example, represented as: Health_Value=ζ×(H_bat+H_mot+H_rad+H_gw); the link quality contribution value, for example, represented as: Link_Value=η×(1000-L_loss+100-L_delay×10+1000000-L_error) / 1000; and the environmental interference contribution value, for example, represented as: Env_Value=θ×(20-E_emc+100-E_salt+30-E_wind) (the parameter is taken as 0 when it exceeds the upper limit). Where V is the ship's real-time speed, N is the propulsion motor speed, SOC% is the remaining battery charge, T is the engine room ambient temperature, Lon' is the decimal part of longitude × 100 (e.g., 123.456° is taken as 45), Lat' is the decimal part of latitude × 100 (e.g., 30.123° is taken as 12), H_bat is the battery health, H_mot is the motor health, H_rad is the radar health, H_gw is the gateway health, L_loss is the packet loss rate, L_delay is the network latency, L_error is the bit error rate, E_emc is the electromagnetic interference intensity, E_salt is the salt spray concentration, and E_wind is the wind speed.
[0050] For example, in one specific embodiment, a new energy transport ship is sailing in near-shore waters at a speed of V=22 km / h (α=2), SOC%=45%, T=40℃ (β=1), and is in a non-port area (γ=1); battery health H_bat=85%, motor health H_mot=88%, radar health H_rad=90%, gateway health H_gw=86% (ζ=1); packet loss rate L_loss=2%, delay L_delay=30ms (η=2); electromagnetic interference E_emc=6V / m, salt spray concentration E_salt=35mg / m 3 With wind speed E_wind=15m / s (θ=3), the dynamic contribution value of the new energy transport ship is calculated as 2×(22+N / 10)+1×(45+40 / 10)+1×(Lon'+Lat'), the equipment health contribution value is 349, the link quality contribution value is 2×(1000-20+100-30×10+1000000-L_error) / 1000, and the environmental interference contribution value is 282.
[0051] After generating multi-factor contribution values, a final checksum is generated. For example, the base checksum is first determined by XORing the CRC16 checksum of the communication with the checksum. Then, based on the ship's operating data, the contribution values of four types of multi-factors—dynamic parameters, equipment health, link quality, and environmental interference—are calculated. Combined with dynamic weights, the final checksum is generated, for example, represented as SDFFC_Pro=[Base_Check+W1×Dyn_Value+ W2×Health_Value+W3×Link_Value+W4×Env_Value] mod65535. Finally, the calculated SDFFC_Pro is appended to the end of the CAN message data segment to generate the communication message, which is then sent.
[0052] At the receiving end, after receiving the communication message, it is parsed and calculated. The calculation result is compared with the received check code. If the two match, the message data transmission is determined to be correct and can be received normally. If there is a discrepancy, the message transmission is determined to be incorrect, and the data retransmission mechanism is triggered to ensure the accuracy of data transmission.
[0053] In this embodiment of the invention, by integrating a verification mechanism of multi-dimensional parameters and operating conditions during the transmission of communication information in complex marine environments, the error recognition rate of data transmission is greatly improved; and by dynamically adjusting the weights, the verification strategy is adapted to different navigation scenarios, effectively reducing the false judgment rate of verification.
[0054] In conventional communication messages, only the data to be transmitted and basic checksums are included. There is a lack of parameter acquisition time traceability and link identification information. When data transmission is abnormal, it is impossible to locate the source of the problem, which is not convenient for troubleshooting.
[0055] In this embodiment of the invention, generating a communication message based on the final checksum and the data to be transmitted includes: obtaining parameter acquisition time and link identifier; generating an initial CAN message based on the data to be transmitted; processing the initial CAN message based on the final checksum to generate a processed message; and processing the processed message based on the parameter acquisition time and the link identifier to generate a communication message.
[0056] In one possible implementation, before sending the communication message, the parameter acquisition time and link identifier are further obtained. For example, the link identifier for the power domain CANFD is "CANFD-P", used to distinguish communication links from different domains. Then, based on the initial CAN message generated according to the data to be transmitted, the final checksum value SDFFC_Pro is appended to the end of the initial CAN message data segment to complete the checksum integration and generate the processed message. Finally, the parameter acquisition timestamp and link identifier are added to the extended field of the processed message to form a complete communication message.
[0057] In this embodiment of the invention, by further adding timestamps and link identifiers to the communication messages, the timing of data transmission and the source of data can be traced, which facilitates accurate troubleshooting and reduces troubleshooting time. At the same time, the integration of checksums and core data ensures data integrity, improves the success rate of message transmission, and effectively prevents data tampering or loss.
[0058] In this embodiment of the invention, the method further includes: obtaining the verification feedback of the receiving node for the communication message; if the verification feedback is N data retransmissions, performing the corresponding data retransmission operation, where N is a positive integer; if the verification feedback is a device malfunction, cutting off network communication with the receiving node and establishing a connection with the receiving node using a backup network device.
[0059] Specifically, after receiving a communication message, the receiving node calculates a local checksum and compares it with the message checksum to generate a data difference. If the difference is less than 1%, the data is considered normal, and the data is received and stored. If 1% ≤ difference < 3%, one data retransmission is triggered, and the link status (packet loss rate, latency change) is recorded. If 3% ≤ difference < 5%, three data retransmissions are triggered, and a "link quality warning" is reported to the main gateway. If the difference is ≥ 5%, retransmission is terminated, a "device abnormality" is reported to the main gateway, and the main gateway initiates a switchover of backup devices within the domain (such as switching to backup sensors or backup communication links).
[0060] In this embodiment of the invention, by implementing a graded data retransmission mechanism when communication is abnormal, the waste of resources caused by excessive retransmission can be effectively avoided, and the utilization rate of communication bandwidth can be improved. At the same time, the rapid switching of backup equipment in abnormal situations can control the communication interruption time to within 50ms, ensuring the data continuity of critical ship systems (such as autopilot and power control) and reducing navigation safety risks.
[0061] In practical applications, traditional ship diagnostic domains lack multi-level security authentication mechanisms and rely solely on a single encryption method, making them vulnerable to unauthorized access. Furthermore, directly using all data for authentication exposes core data before authentication, posing security risks and resulting in insufficient security.
[0062] In this embodiment of the invention, the plurality of functional domains includes a diagnostic domain, which is electrically connected to a diagnostic instrument. The method further includes: performing an authentication operation before the diagnostic domain communicates with the central gateway; if the authentication operation is successful, obtaining a first key sent by the diagnostic instrument, the first key being generated based on the ship's operating data; the central gateway generating a second key and a random challenge code based on the first key; the central gateway encrypting the random challenge code based on the second key, generating and sending an encrypted challenge code; the diagnostic instrument decrypting the encrypted challenge code based on the first key, generating and sending decryption information; and the central gateway analyzing the decryption information to generate a security authentication result.
[0063] In one possible implementation, an authentication operation is performed before the diagnostic domain communicates with the central gateway. In this embodiment of the invention, performing the authentication operation includes: determining preset identity screening data, wherein the preset identity screening data is non-sensitive data; responding to an authentication request initiated by the diagnostic instrument; verifying the authentication request based on the preset identity screening data, and generating an authentication result.
[0064] Specifically, a diagnostic instrument on a new energy vessel needs to perform intelligent diagnostic operations. Therefore, it initiates an authentication request. The central gateway, through the low-security UDS27 service, obtains non-sensitive data from the diagnostic instrument, including battery SOC=65.5%, gear=1 (forward), and motor_status=0 (normal operation). This non-sensitive data includes, but is not limited to, battery level, gear position, motor status, charging status, GPS information, and steering angle. The gateway then authenticates the diagnostic instrument and generates an identity verification result. At this point, the diagnostic instrument acquires the vessel's operating data, concatenates parameters such as SOC, gear, and motor_status, and generates a seed using SHA-256. This seed, combined with the master key, generates the first key. The central gateway receives the seed, generates a second key and a random challenge code, encrypts them, and sends them to the diagnostic instrument. The diagnostic instrument decrypts and performs calculations, then returns the result. If the central gateway verifies the request, it allows the diagnostic instrument to read sensitive data such as battery thermal management temperature and fault history, and to modify the motor controller's operating parameters. If authentication fails, the communication request is rejected.
[0065] In this embodiment of the invention, by constructing a four-layer authentication system (multi-dimensional parameter verification + multi-round challenge-response + hardware fingerprint bidirectional binding + dynamic key update), unauthorized access is effectively resisted, greatly improving authentication security; the initial screening of non-sensitive parameters balances convenience and security, and sensitive data is only transmitted after authentication is passed, greatly reducing the risk of leakage of core data; at the same time, through dynamic keys and challenge-response mechanisms, the encryption information is effectively prevented from being cracked, and the communication security of the diagnostic domain is fully guaranteed.
[0066] The optional embodiments of the present invention have been described in detail above with reference to the accompanying drawings. However, the embodiments of the present invention are not limited to the specific details in the above embodiments. Within the scope of the technical concept of the embodiments of the present invention, various simple modifications can be made to the technical solutions of the embodiments of the present invention, and these simple modifications all fall within the protection scope of the embodiments of the present invention.
[0067] It should also be noted that the various specific technical features described in the above embodiments can be combined in any suitable manner without contradiction. To avoid unnecessary repetition, the embodiments of the present invention will not describe the various possible combinations separately.
[0068] Those skilled in the art will understand that all or part of the steps in the methods of the above embodiments can be implemented by a program instructing related hardware. This program is stored in a storage medium and includes several instructions to cause a microcontroller, chip, or processor to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as a USB flash drive, a portable hard drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.
[0069] Furthermore, various different implementations of the present invention can be combined arbitrarily, as long as they do not violate the spirit of the present invention, they should also be regarded as the content disclosed in the present invention.
Claims
1. A ship network communication architecture, characterized in that, The ship network communication architecture includes multiple functional domains, each configured on a different physical medium, and each functional domain is electrically connected to the central gateway via a CAN bus. The multiple functional domains include the power domain, central control domain, autonomous driving domain, environmental disturbance immunity domain, energy security domain, and emergency management domain; The power domain includes a first CANFD, which is electrically connected to multiple ship power components; the central control domain includes a second CANFD, which is electrically connected to multiple ship control components; the autopilot domain includes a first Ethernet, which is electrically connected to multiple ship navigation components; the environmental immunity domain includes a third CANFD, which is electrically connected to multiple environmental monitoring sensors; the energy security domain includes a fourth CANFD, which is electrically connected to multiple battery safety protection components; and the emergency management domain includes a fifth CANFD, which is electrically connected to multiple ship emergency response devices.
2. The ship network communication architecture according to claim 1, characterized in that, The multiple functional domains also include a diagnostic domain; The diagnostic domain includes a second Ethernet, which is electrically connected to the ship diagnostic instrument. The ship diagnostic instrument and the central gateway perform security authentication operations through the second Ethernet and execute corresponding communication connections based on the security authentication results.
3. A method for security management of ship network communication, characterized in that, Applied to the ship network communication architecture according to claim 1 or 2, the ship network communication architecture including a central gateway and multiple functional domains, the method includes: Ship operation data is acquired from the multiple functional domains; The central gateway determines dynamic weights based on the ship operation data. Determine the CRC checksum value for communication and determine the multi-factor contribution value based on the ship operation data; The final verification value is generated based on the dynamic weight, the CRC check value, and the multi-factor contribution value. A communication message is generated based on the final verification value and the data to be transmitted. Send the communication message.
4. The method according to claim 3, characterized in that, The determination of dynamic weights based on the ship operation data includes: Determine the initial weights, which include environmental interference weights, equipment health weights, dynamic parameter weights, and link quality weights; The ship navigation mode is determined based on the ship operation data, and the environmental interference weights are adjusted based on the ship navigation mode to generate adjusted environmental weights. The ship's operating status is determined based on the ship's operating data, and the health weight of the equipment is adjusted based on the ship's operating status to generate the adjusted health weight. The ship's motion state is determined based on the ship's operating data, and the dynamic parameter weights are adjusted based on the ship's motion state to generate adjusted parameter weights. The link quality is determined based on the ship operation data, and the link quality weight is adjusted based on the link quality to generate the adjusted link weight. Normalization is performed on the adjusted environment weight, the adjusted health weight, the adjusted parameter weight, and the adjusted link weight to generate dynamic weights.
5. The method according to claim 3, characterized in that, The ship operation data includes real-time ship speed, propulsion motor speed, remaining battery power, engine room ambient temperature, positioning latitude and longitude, battery health, motor health, radar health, gateway health, packet loss rate, network latency, bit error rate, electromagnetic interference intensity, salt spray concentration, and wind speed. The determination of multi-factor contribution values based on the ship operation data includes: The operating condition coefficient is dynamically determined based on the aforementioned ship operation data; The dynamic contribution value of operation is determined based on the operating condition coefficient, the real-time speed of the ship, the speed of the propulsion motor, the remaining battery power, the ambient temperature of the engine room, and the positioning latitude and longitude. The device health contribution value is determined based on the operating condition coefficient, the battery health, the motor health, the radar health, and the gateway health. The link quality contribution value is determined based on the operating condition coefficient, the packet loss rate, the network latency, and the bit error rate. The environmental interference contribution value is determined based on the operating condition coefficient, the electromagnetic interference intensity, the salt spray concentration, and the wind speed.
6. The method according to claim 5, characterized in that, The dynamic determination of operating condition coefficients based on the ship's operating data includes: The power coefficient is determined based on the ship's real-time speed. The energy coefficient is determined based on the remaining battery power and the cabin ambient temperature. The positioning coefficient is determined based on the aforementioned latitude and longitude. The device health coefficient is determined based on the battery health, motor health, radar health, and gateway health. The link quality coefficient is determined based on the packet loss rate and the network latency; The environmental interference coefficient is determined based on the electromagnetic interference intensity, the salt spray concentration, and the wind speed. Operating condition coefficients are generated based on the power coefficient, energy coefficient, positioning coefficient, equipment health coefficient, link quality coefficient, and environmental interference coefficient.
7. The method according to claim 3, characterized in that, The step of generating a communication message based on the final verification value and the data to be transmitted includes: Obtain parameter acquisition time and link identifier; An initial CAN message is generated based on the data to be transmitted; Based on the final checksum and the initial CAN message, a processed message is generated. The processed message is processed based on the parameter acquisition time and the link identifier to generate a communication message.
8. The method according to claim 3, characterized in that, The method further includes: Obtain the verification feedback from the receiving node for the communication message; If the verification feedback is N data retransmissions, the corresponding data retransmission operation is executed, where N is a positive integer; If the verification feedback indicates a device malfunction, the network communication with the receiving node is cut off, and a connection with the receiving node is established using a backup network device.
9. The method according to claim 3, characterized in that, The plurality of functional domains includes a diagnostic domain, the diagnostic domain being electrically connected to a diagnostic instrument, and the method further includes: An authentication operation is performed before the diagnostic domain communicates with the central gateway; If the identity authentication operation is successful, the first key sent by the diagnostic instrument is obtained, and the first key is generated based on the ship operation data; The central gateway generates a second key and a random challenge code based on the first key; The central gateway encrypts the random challenge code according to the second key, generates and sends the encrypted challenge code; The diagnostic instrument decrypts the encryption challenge code based on the first key, generates and sends decryption information; The central gateway analyzes the decrypted information and generates a security authentication result.
10. The method according to claim 9, characterized in that, The process of performing identity authentication includes: Determine preset identity screening data, wherein the preset identity screening data is non-sensitive data; In response to the authentication request initiated by the diagnostic instrument; The identity authentication request is verified based on the preset identity screening data, and an identity verification result is generated.