Military watercraft with sensors

EP4685044A3Pending Publication Date: 2026-03-11TKMS GMBH +1
View PDF 10 Cites 0 Cited by

Patent Information

Authority / Receiving Office
EP · EP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2021-01-11
Publication Date
2026-03-11

AI Technical Summary

Technical Problem

Military watercraft face challenges in integrating complex, heterogeneous components due to limited testing of interactions, data protection concerns, and reluctance of manufacturers to share measurement data, hindering comprehensive data utilization and analysis.

Method used

A military watercraft system with sensors that record and securely store measurement data in a database, using a computer cluster and container management software for orchestration, enabling real-time control and retrospective analysis while ensuring data access is restricted to trusted analysis modules.

Benefits of technology

Facilitates seamless integration and analysis of diverse components, supports real-time monitoring and retrospective insights, and ensures data security by allowing only authorized modules to access sensitive information, enhancing operational reliability and fault tolerance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure IMGAF001_ABST
    Figure IMGAF001_ABST
Patent Text Reader

Abstract

The invention relates to a military watercraft (100) comprising: - several vehicle components (104-110), each comprising one or more sensors (112-120), wherein at least some of the vehicle components belong to a weapon system (102), a propulsion unit (104) and a navigation system (106), wherein the sensors are configured to acquire measured values, the measured values ​​indicating operating states of the vehicle component containing the sensor acquiring the measured values ​​and / or states of the watercraft or its environment; - a database (122), wherein a history of measured values ​​from the sensors, in conjunction with a timestamp, is persistently and securely stored in the database;and - an electronic automation system (124), wherein the automation system is configured for the automatic and / or semi-automatic control of at least one of the vehicle components in real time depending on the measured values ​​and / or depending on a user input from a user in response to an output of the measured values ​​via a user interface.
Need to check novelty before this filing date? Find Prior Art

Description

Area

[0001] The invention relates to a military watercraft, in particular a military watercraft with sensors for recording measured values. background

[0002] Military watercraft are often highly complex systems designed for specific missions and comprise a multitude of components, sometimes from different manufacturers. Compared to civilian watercraft, military watercraft are often characterized by a relatively small production run, high complexity, a large number of components, and a high need for data protection. The composition of the components is therefore often very heterogeneous, and given the sheer number and integration density of components and manufacturers, it is not always possible to comprehensively test the interaction of the individual components for every conceivable operational scenario.In addition, there is a tendency among vehicle component manufacturers to keep measurement data collected by internal sensors secret in order to prevent third parties from using this knowledge to replicate or "hack" the vehicle component.

[0003] These circumstances therefore represent significant technical obstacles to the integration of vehicle components for military watercraft.

[0004] German patent application DE 102008025803 A1 describes a marine internal combustion engine with a control device for controlling and / or regulating the operation of the marine internal combustion engine. The control device determines target operating parameters for the marine internal combustion engine based on the ship's position.

[0005] German patent application DE 102011 086355 A1 describes a weapon system for object defense, in particular for use on merchant ships, comprising: at least one gun, a firing mechanism, a sensor system for acquiring data, in particular environmental and / or target data, and an authorization system. The authorization system is configured to enable or disable the firing mechanism depending on the receipt of a release signal.

[0006] German patent application DE 31 50 895 A 1 describes a warship with systems connected via electronic control units. The warship, with its controlling and controlled systems, is equipped with electronic control units that generate control signals for the respective controlled systems from raw information received from the assigned controlling system. For each assigned controlled system, the electronic control units have a correction stage for modifying the generated control signals depending on a bedding error of the respective controlled system and / or the controlling system acting on the control unit. Furthermore, memory is provided for storing the bedding error values ​​as a function of the horizontal angular position of the controlled system and / or the controlling system.

[0007] US patent application US 2008 / 0120620A1 describes the use of an "open software architecture" for the Navy fleet.

[0008] US patent application US2018 / 0304969A1 describes a ship with a propeller mounted on a rotating shaft and a method for converting the power of a rotating shaft into thrust to propel the ship across the water. The method includes obtaining measurements descriptive of the shaft power, estimating two excess shaft powers caused by fouling of the propeller and by fouling of the ship's hull, and issuing a recommendation for propeller cleaning and / or hull cleaning based on the estimated excess shaft powers.

[0009] US patent application US2019 / 0176945A1 describes a motion control system for a ship in a way that optimally balances performance and noise emission.

[0010] US patent application US 2006 / 0058929A1 describes a method for verifying a ship's control system in which the control system, in its operating state, receives sensor signals from sensors and, in response, sends control signals to actuators to maintain a desired position, speed, course, or other.

[0011] US patent application US 2018 / 0356826A1 describes a system and method for facilitating decision-making on a watercraft. The method includes: acquiring environmental data of the environment in which the watercraft is located; generating a variety of digital models, each modeling an impact of the environment on a corresponding capability of the watercraft; using the environmental data and the digital models, modeling an impact of the environment on the capabilities of the watercraft and creating a risk assessment for a selected action.

[0012] The publication ANDO, Hideyuki: Smart ship application platform project (SSAP Project). In: Sea Japan 2014, Environmental Technology Seminar, April 11, 2014, 11 pp. URL: https: / / www.mlit.go.jp / common / 001039009.pdf [accessed on 2020-07-20] describes application services in the context of a "smart ship" to achieve optimal ship operation with regard to safety and energy efficiency. Summary

[0013] The invention is based on the objective of providing an improved military watercraft.

[0014] The problems underlying the invention are each solved by the features of the independent claims. Embodiments of the invention are specified in the dependent claims. The embodiments listed below can be freely combined with one another, provided they are not mutually exclusive.

[0015] In one aspect, the invention concerns a military watercraft.

[0016] The military watercraft comprises several components, each containing one or more sensors. At least some of these components belong to a weapon system, a propulsion unit, and a navigation system. The sensors are designed to acquire measured values, which indicate the operating states of the component containing the sensor and / or the state of the watercraft or its environment.

[0017] The military watercraft also contains a database. This database persistently and securely stores a history of sensor readings along with a timestamp.

[0018] The military watercraft incorporates an electronic automation system. This system is designed for the automatic and / or semi-automatic control of at least one of the vehicle's components in real time, based on measured values ​​and / or user input, which is provided via a user interface in response to the output of measured values.

[0019] This can be advantageous because a vessel equipped in this way utilizes the sensor-acquired measurement data in two ways: firstly, the data is used to directly or indirectly influence the automation system and thus its control over individual vessel components. For example, the acquired measurements can be directly forwarded as input to the automation system. Additionally or alternatively, the measurements, or at least some of them, can be displayed to a user, enabling them to decide how to operate the automation system based on these measurements. Thus, the first use of the currently valid measurement data is to influence the control of the vessel components in real time. Secondly, the measurement data is also stored in a database.This is achieved by making the temporal progression of the measurement data generation (the "history" of the measured values) retrievable from the database, for example, using timestamps (preferably UTC or location-independent and unique) that indicate the time of each measurement. Storing the measurement data persistently in a database allows for the automatic creation of a database over time. Analyzing this database can reveal complex dependencies and interactions between multiple vehicle components and their states (engine temperature, turbine speed, rudder vibration), taking environmental parameters (temperature, humidity, pressure, depth, geographical position) into account. For instance, the database content can be used as a training dataset to train a machine learning algorithm.As a result, hidden, non-obvious or technically indirectly recognizable relationships and interactions can be identified, in principle in a way that is individual for each vehicle, which is particularly relevant in the military sector with small production numbers and many custom-made vehicles.

[0020] The measured values ​​are stored securely in the database, which means that they are protected from unauthorized access by means of security measures, e.g. by encryption or preventing anonymous access by granting access rights.

[0021] This makes it possible, in principle, to digitally record all measured values ​​generated on a vessel, which may originate from various vessel components and manufacturers. This data can then be used both for real-time vessel monitoring and for retrospective analysis of the history of digital measurements recorded by the vessel's sensors (regardless of whether they are integrated into the automation system). Vessel operators can thus gain valuable insights into their individual vessels based on the history stored in the database and, optionally, using their own analysis tools, even if the data originates from a complex, heterogeneous environment of vessel components and sensors from different manufacturers.Since the measured values ​​from various sensors of different vehicle components are stored in a single database, they are accessible to a wide variety of multivariate analyses, such as those used in the context of big data. The timestamp, which can be a UTC timestamp, for example, allows the different measured values ​​to be uniquely related to each other and, optionally, also to the times at which control commands were sent to vehicle components or sub-components.

[0022] Embodiments of the invention thus enable a uniform use and analysis of all digital data that arises or can be captured by the increasingly complex platforms, systems and installations on board a military watercraft, thereby enabling seamless integration, installation, commissioning and long-term operation of the vehicle and its components.

[0023] Embodiments of the invention can be particularly helpful in the military sector, since users' detailed knowledge of individual vehicle components is often limited or cannot be reliably accessed under military stress. Vehicles and components are becoming increasingly complex, while crew sizes are decreasing (down to zero, which corresponds to fully autonomous vehicle control). Acquiring and storing sensor data in a database can compensate for these disadvantages.

[0024] According to embodiments of the invention, the watercraft comprises several (at least two) computers networked together to form a computer cluster, which cooperate as a host in such a way that at least one instance of the database is provided. It is also possible that some or all of the database data is stored redundantly on the multiple computer systems, e.g., by creating multiple instances of the database, including some or all of the database data, on the multiple computers.

[0025] According to embodiments, the watercraft includes container management software configured for the automated provisioning, scaling, and management ("orchestration") of at least one container on at least one computer in such a way that this at least one computer serves as the host system for the at least one container, wherein the at least one container isolates programs running inside this container from programs running outside this container. Preferably, the container management software orchestrates multiple containers on one or more computers.

[0026] According to embodiments of the invention, the watercraft comprises several computers networked together to form a computer cluster and container management software. The container management software is configured for the automated provisioning, scaling, and management ("orchestration") of several (at least two) containers on the multiple computers in such a way that each computer serves as a host system for one or more containers, with the containers (of the same host computer system as well as of different host computer systems) being isolated from each other.

[0027] This can be advantageous because integrating multiple computers into a network and using container management software to orchestrate multiple containers hosted on those computers can result in a highly performant and fault-tolerant system and the provisioning of the database and / or individual analysis modules. For example, the containers can be orchestrated to provide the database, parts of the database, and / or one or more analysis modules multiple times, enabling parallel access to identical copies of the data or analysis modules. With regard to the database, this increases the speed of read and write access to the measurement data stored in the database and improves fault tolerance. With regard to the analysis modules, which are redundantly provided according to some implementations, this also increases availability (if applicable).Parallel execution of the same type of analysis) and the fault tolerance of the corresponding analysis modules. Both are of paramount importance in the context of a military watercraft, because a failure of the database and / or software programs instantiated in the containers can lead to critical data loss, data inconsistencies, or the failure of forecasting and warning functions based on currently stored or historically stored measurement data. Furthermore, the use of containers and container management software for container orchestration enables easy system scaling, for example, if a significantly larger amount of (measurement) data needs to be stored and / or analyzed over time, and / or if the number of software programs to be instantiated on the computer network increases over time.

[0028] Using containers to deploy and isolate software applications ensures the separation and management of resources used on a computer. Containers allow an application to be instantiated on different computers and environments (for example, different computers on a network, but also on different types of computers such as development, QA, and production). Furthermore, updates are simplified.

[0029] According to embodiments, each container is access-restricted in such a way that it can only access a specific memory area of ​​main memory assigned to it alone, as well as native applications (e.g., native databases).

[0030] In some embodiments, only the analysis modules are hosted within containers, while the database is run as a native database on one of the computers. Such embodiments of the invention can have the advantage that access to the data stored in the database can be facilitated by the analysis modules instantiated in the containers.

[0031] According to other embodiments, at least some of the containers are configured such that a virtual network exists between some of the containers, allowing the analysis modules instantiated in one container to access the contents of a database instantiated within a container networked with that container. Such embodiments can offer the advantage that a user, for example via container management software, can define very precisely and with fine granularity which analysis modules within which containers can access the contents of other containers. For example, a first container might contain a first database with the measured values ​​from sensors S1, S12, and S37, and a second container a second database with the measured values ​​from sensors S17 and S35. Sensors S1, S12, and S37 come from manufacturer H1, while the measured values ​​from sensors S17 and S35 come from manufacturer H2.It is now possible to configure the computer network or containers so that the analysis software A1 from manufacturer H1 runs in a third container, which is selectively allowed to access the first database in the first container, but not the data from the sensors of manufacturer H2 in the second container. Similarly, the configuration can include the analysis software A2 from manufacturer H2 running in a fourth container, which is selectively allowed to access the second database in the second container, but not the data from the sensors of manufacturer H1 in the first container.

[0032] According to embodiments of the invention, the computers can be servers, i.e., computers that provide one or more programs or functions (e.g., analysis modules, databases, etc.) to external entities (e.g., other servers, analysis modules instantiated on other servers, users, etc.). Server computers are often characterized by above-average computing capacities and / or above-average amounts of available main memory.

[0033] According to the invention, the military watercraft further comprises one or more analysis modules, each of which is designed to perform an analysis of at least some of the measured values ​​stored in the database.

[0034] In some embodiments, the automation system and the one or more analysis modules are operationally decoupled from each other. Additionally or alternatively, the one or more analysis modules are configured to perform their respective analysis functions without using an internet connection. In other embodiments, both the automation system and the one or more analysis modules are configured to perform their respective control or analysis functions without using an internet connection.

[0035] For example, the analysis modules are designed to analyze the history of measured values ​​stored in the database and, based on this analysis, to calculate predictions regarding the current and / or future condition of the watercraft or its components and / or to determine a technically or tactically appropriate course of action. In particular, according to certain embodiments, recommendations for action are first calculated, which are then implemented manually, semi-automatically, or fully automatically.

[0036] Preferably, at least some of the analysis modules are designed to evaluate the measured values ​​from two or more sensors of two or more different vehicle components and, optionally, one or more environmental parameters (air pressure, water temperature, depth, geographical position of the vehicle, current strength of the surrounding water, etc.). This has the advantage that interactions existing between the vehicle components and / or environmental parameters can be identified through retrospective analysis of the history of these measurement parameters and used to predict future states and actions.

[0037] Executing the control and / or analysis function without using an internet connection can be advantageous, as an internet connection is often not reliably available on the high seas and, even when it is available, is sometimes switched off in the military sector for some systems to increase the security of the system and reduce the probability of detection.

[0038] The analysis is performed on the database data, and the analysis modules are operationally separate from the automation system. This means that the automation system is not affected by operations performed by the analysis modules to read and process the measurement data. This is advantageous because the automation system is a real-time system, and this operational separation protects it from having its reaction speed and / or responsiveness affected by the execution of the analysis modules. In a military context, it is crucial that the automation system can react immediately and in real time to current conditions, for example, to automatically initiate the correct steps in combat situations to turn, brake, accelerate, and / or implement defensive or aggressive measures for the vessel.

[0039] According to embodiments of the invention, the operational decoupling is realized through an asynchronous operation of the automation system on the one hand and the one or more analysis modules on the other.

[0040] For example, operational decoupling can involve programming the automation system and the analysis modules to operate independently of each other, meaning that at no point does the automation system require data and / or wait for data provided by the analysis module.

[0041] Additionally or alternatively, operational decoupling can be implemented in the form of asynchronous read or write access to the database by the automation system or a service operationally connected to the automation system on the one hand, and by one or more analysis modules on the other. For example, operational decoupling can involve the automation system receiving current measurement data directly from the sensors via a primary communication channel without writing the measurement data to the database before or during data transmission. This means the automation system receives the current sensor measurement data directly and immediately after acquisition from the respective sensors, thus avoiding the delays that can occur when writing measurement data to a data storage device.Asynchronously, the measurement data is written to the database to update the history of the measurement parameters. The data channel over which this writing process takes place can also be referred to as a second communication channel and could, for example, be configured as a multitude of database connections established by the sensors to the database. The use of the first communication channel and one or more secondary communication channels means that even if bottlenecks or delays occur when writing the measurement data to the database, this does not lead to a delay in forwarding the measurement data to the automation system, since the data transmission to the automation system is temporally and operationally decoupled from the storage of the measurement data in the database.In another embodiment, the watercraft includes a service through which the automation system reads data from the database and / or writes data generated by the automation system to the database. In this case, the read and / or write access of this service is operationally decoupled from the read / write accesses by the analysis modules.

[0042] Additionally or alternatively, operational decoupling can be achieved by instantiating the automation system on the one hand and the one or more analysis modules on the other hand on different computers. For example, asynchronous operation can be implemented by hosting the automation system on one or more primary computers and the database and the analysis modules on one or more secondary computers. Alternatively, it is also possible to allocate different CPU and / or memory resources of a distributed computer network to the automation system on the one hand and the database and the analysis modules on the other, thus preventing the automation system from competing with the analysis modules for resources.

[0043] All these measures can be advantageous because they ensure that the automation system or the real-time capability of the automation system is not affected by the storage and analysis of the history of measurement data.

[0044] According to embodiments of the invention, the watercraft comprises several analysis modules which are implemented in several different containers and thus isolated from one another.

[0045] This can be advantageous because it improves the reliability, maintainability, and performance of the analysis procedures executed by the analysis modules. For example, powerful programs exist for managing containers across multiple computers. These programs allow for the redundant creation of multiple instances of an analysis module within several different containers. This enables certain analyses to be executed in parallel on different subsets of the database data, resulting in particularly fast performance. Furthermore, creating multiple instances of the same analysis module ensures that even if one computer in the network fails or becomes unreachable, it is possible to immediately switch to another existing instance of the same analysis module running on a different computer, and / or that this other instance can be created in a new container on the other computer within a short time.Furthermore, it is possible to quickly and flexibly increase or decrease the number and distribution of instances generated by one or more analysis modules, depending on the specific situation.

[0046] For example, in a safety-critical military operation, it is of secondary importance whether an analysis module, which predicts the next routine service appointment for the vessel based on the distance traveled, has sufficient CPU and memory capacity available for its work, or even whether this module is instantiated at all. However, it can be of paramount importance, for instance during a critical turning maneuver, that another analysis module, which uses various material and flow-related measurements at the rudder, turbine, and other vessel components to correctly calculate whether material stress limits are being exceeded or the vessel's stability is at risk, has all the necessary CPU and memory resources available to perform its calculations accurately and quickly.

[0047] According to embodiments of the invention, at most one instance of at most one of the analysis modules is executed in each of the containers.

[0048] This can be advantageous because it ensures that each instance of an analysis module runs in its own container. This enables highly granular orchestration of the analysis modules at the level of individual instances using the container management program.

[0049] The fact that the individual analysis modules are operationally isolated from one another thanks to their separate containers is particularly advantageous in the context of a military watercraft: for example, the analysis modules can originate from different manufacturers of vehicle components. Thus, for instance, a first analysis module could be provided by the turbine manufacturer and be designed to analyze measured values ​​relating to the rotational speed, temperature, and vibration behavior of a turbine from the same manufacturer, equipped with sensors for these parameters. The analysis can serve various purposes: for example, to determine whether critical system conditions have been reached that would void the manufacturer's warranty and / or necessitate an inspection or overhaul of the turbine.The analysis can also be used to investigate how the individual measurements depend on each other, for example, whether the turbine exhibits different vibration patterns within different speed ranges. A second analysis module can be provided by the engine manufacturer and designed to analyze measurements related to the current engine temperature, the engine's current energy consumption, or other engine-related parameters. This analysis can also serve various purposes, such as determining whether a critical engine condition has been reached or exceeded, which could void the manufacturer's warranty and / or necessitate an inspection or overhaul of the engine.The analysis can also be used to investigate how the individual measured values ​​depend on each other, for example, whether the engine exhibits different vibration patterns and / or performance curves within different temperature ranges. Both the turbine manufacturer and the engine manufacturer, as well as ultimately the operator of the vessel itself, benefit from the fact that the analysis modules of the various manufacturers are separate. This prevents third-party software programs from intentionally or unintentionally interacting with a specific analysis module and causing it to crash or malfunction. Especially in the military sector, there is a constant risk that supposedly trustworthy software actually contains malware designed to disrupt the operation of vehicles or other equipment.Interfering with vehicle components and / or unauthorized access to information regarding the functionality of vehicle components. Certain individuals or organizations might have an interest in learning how a particular vehicle component operates and / or causing a vehicle component to operate unreliably or faultily, thereby, for example, temporarily or permanently disabling important functions of the watercraft. According to embodiments of the invention, this can be prevented by integrating the individual analysis modules into separate containers.

[0050] Furthermore, running exactly one instance of an analysis module per container facilitates the orchestration of the containers, for example for the purpose of load balancing, upscaling or downscaling, since the resource consumption of a container is largely identical or strongly correlated with the resource consumption of the analysis module instantiated in that container.

[0051] According to embodiments of the invention, the container management software is configured to orchestrate the creation of containers, the instantiation and termination of the analysis modules (within these containers) such that one or more of the following effects occur: In the event of a failure or unavailability of one of the computers, the containers and analysis modules that are no longer available or accessible due to the failure or unavailability of the first computer are automatically started on another computer; this increases the robustness of the analysis functionality of a watercraft against the failure of individual computers; particularly in the military sector, it must be expected that in combat situations components of the watercraft, such as individual computers and / or network connections within a computer network, may be destroyed or damaged, or at least fail temporarily; the ability of the container management software to create a new instance of the failed analysis module in such situations is therefore particularly advantageous;and / or, if a maximum number of instances of one of the analysis modules currently running on the computers is exceeded, automatically terminate one of these instances and / or delete or move one of the containers containing an instance of this analysis module to another computer; this can be advantageous because it ensures that unused CPU and memory resources are automatically released when they are no longer needed for analytical tasks; the faster these freed resources can be made available to critical systems in an emergency; the "maximum number" can, for example, be a number specified manually or automatically in a configuration of the container management software. "Maximum" means that exceeding this value is considered undesirable and induces a specific sequence or action, preferably one designed to reduce the number of instances;and / or, if a predefined maximum workload of one of the computers is exceeded, automatically migrate at least one container hosted on that computer, along with the analysis module instance running within it, to another of the computers; the container management software can therefore perform load-balancing functions; and / or, if a predefined minimum workload of one of the computers is not reached, automatically migrate at least one container hosted on another of the computers, along with the analysis module instance running within it, to that computer; the container management software can therefore perform load-balancing functions; in some embodiments, this one computer can be deactivated or put into sleep mode to save energy;and / or, if a predefined maximum computational load is exceeded on one of the computers, automatically identify at least one container hosted on that computer, including the analysis module instance running within it (e.g., the container with the highest CPU / memory consumption or a container containing an instance of a specific analysis module), instantiate a copy of this identified container, including the analysis module running within it, on at least one other computer; and execute analyses in parallel, using at least the analysis module instance in the identified container and the other instantiated analysis module instance; the container management software can therefore perform upscaling functions;and / or, if the compute load of one of the computers falls below a predefined minimum, automatically identify at least one container hosted on another computer, including the analysis module instance running within it (e.g., the container with the highest CPU / memory consumption), instantiate a copy of this identified container, including the analysis module running within it, on that one computer; and execute analyses in parallel, using at least the analysis module instance in the identified container and the other instantiated analysis module instance; the container management software can therefore perform load balancing functions; and / or, if the compute load of one of the computers falls below a predefined minimum, automatically delete at least one of the containers hosted on that one computer; the container management software can therefore perform downscaling functions.

[0052] This can be advantageous because it allows for better distribution of CPU and memory resource consumption across the computers in the cluster, resulting in improved response times. Furthermore, it enables demand-based scaling of containers and the analysis modules instantiated within them.

[0053] In some embodiments, at least some of the analysis modules are specifically assigned a portion of the database data. These data portions are stored in a protected manner such that only the analysis module assigned to that portion of the data can access it for reading and / or writing.

[0054] For example, the allocation can be such that an analysis module developed by a specific company that has also manufactured a vehicle component or has a contractual relationship with the manufacturers has access to measurement data that is captured and stored by sensors of that vehicle component, but not to the measurement data of sensors of other vehicle components.

[0055] According to another example, the allocation is such that an analysis module developed by a specific company that also manufactures several vehicle components or has a contractual relationship with the manufacturers of these components has access to the measurement data acquired and stored by sensors of these multiple vehicle components. The analysis module does not have access to the measurement data of sensors from other vehicle components.

[0056] According to another example, the allocation is carried out in such a way that an analysis module developed by a specific company that has also manufactured one or more vehicle components or has a contractual relationship with the manufacturers of these one or more vehicle components has access to the measurement data that was recorded and stored by the sensors of these one or more vehicle components and additionally has access to measurement data that was stored in the database as generally (for every analysis module of the watercraft) freely accessible.

[0057] The analysis modules of watercraft according to embodiments of the invention can be the measurement data of the database according to any combination of the examples described here.

[0058] The various forms of specific assignment of measurement data and analysis modules can be advantageous because vehicle component manufacturers can ensure that only analysis modules they trust have access to the measurement data generated by the sensors of that vehicle component. The installation of various types of sensors on and / or in vehicle components of a military watercraft by the respective component manufacturer has the advantage of making important condition parameters of the vehicle component, such as temperature, vibration behavior, load parameters, environmental parameters, etc., available. This measurement data is relevant for the vehicle component manufacturer, for example, for testing, development, and repair purposes, and for determining warranty claims.However, the measurement data are also relevant for the operator of the watercraft (for a better understanding of how the vehicle component works and / or for a better understanding of interactions between the vehicle component and other components or environmental parameters).

[0059] For the manufacturer of a vehicle component and / or the vehicle operator, the problem arises that disclosing all measurement data could potentially reveal information about the component's operation and internal states, which should remain confidential, for example, to make it more difficult for competitors to replicate the product and / or to prevent attackers from deliberately manipulating the vehicle component. Therefore, a manufacturer of vehicle components generally has no interest in having the measurement data relating to that vehicle component disclosed.This currently prevents the integration of sensor measurement data into various vehicle components, which is a disadvantage for the operator of military watercraft from a safety perspective, because many technically relevant effects, such as a specific behavior of a rudder, a turbine or another complex component of the watercraft, only result from the complex interaction of several vehicle components, each of which can have different internal states.

[0060] The described IT architecture, in which specific parts of the database's measurement data are assigned to individual analysis modules in such a way that the modules can selectively access only the parts explicitly assigned to them, and not all measurement data stored in the database, can be advantageous. This is because, based on this IT architecture, the operator of the military watercraft can assure the suppliers or manufacturers of the respective vehicle components (including their sensors) that the measurement data recorded by the sensors is only accessible to specific analysis modules that have been deemed trustworthy and accepted by both parties. Thus, an IT architecture is created that enables manufacturers of military vehicle components to securely provide sensitive measurement data only to specific analysis modules.The risk that a competitor or attacker might use the measurement data to replicate or attack a vehicle component can therefore be ruled out.

[0061] The operator of the military watercraft benefits from the fact that, according to embodiments of the invention, the measurement data of a large number of vehicle components are only made available to selected, trusted analysis modules: Manufacturers of vehicle components in the military sector have so far tended to record measurement data from sensors of the vehicle components produced by these manufacturers only internally and to analyze it only by computing units internal to the vehicle components, without disclosing the measurement data externally or even storing it for a longer period of time.Thanks to the IT architecture of watercraft according to embodiments of the invention, manufacturers of vehicle components can now do without the component-internal computing units for the secret analysis of the measurement data, since although the measurement data of several sensors and vehicle components are stored centrally in a database, not every analysis module can access this data arbitrarily.

[0062] While some currently available automation systems for military watercraft also offer access to sensor data from multiple sensors, this access is limited to the current actual values ​​of individual systems. Historical profiles and trends of measured values ​​over extended periods are either unusable or of limited practical use. Due to the real-time requirements of such automation systems, it has been avoided to date to burden the limited resources of the watercraft automation system with computationally intensive analyses of extensive historical datasets. However, thanks to the distributed storage of analysis modules in multiple containers within a computer network independent of the automation system, embodiments of the invention make it possible to perform and provide even complex analyses, some in real time, without impairing the real-time capability of the automation system.The problem that manufacturers of vehicle components with integrated sensors are unwilling or unable to disclose the measured values ​​they collect, for various reasons, has been overcome by an IT architecture that ensures only selected analysis modules with the appropriate permissions can access the data. This has created an IT architecture that is particularly advantageous in the context of the specific requirements of military watercraft.

[0063] According to embodiments of the invention, several of the analysis modules are each specifically assigned to one of the vehicle components and are configured to receive, analyze, and output the results of the analysis, at least the measured values ​​acquired by the one or more sensors of the vehicle component to which they are assigned, either directly or indirectly (via the database). Indirect reception via the database means that the measured values ​​acquired by the sensors are first written to the database, and then, in a second step, the analysis module accesses the measured values ​​stored in the database. This indirect reception via the database has the advantage that the analysis modules do not need to have an interface to receive measurement data from a specific sensor.

[0064] According to one embodiment, the one or more sensors have write access to the database and are configured to store the measured values ​​in a suitable format within the database. For example, the sensors can have a network interface and be configured to continuously write the acquired measured values ​​to the database.

[0065] According to other embodiments, the sensors are configured to first store the measured values ​​they acquire in a local volatile or non-volatile data memory within the sensor. Another component of the watercraft (e.g., the automation system, one of the analysis modules, or other software) reads the locally stored measurement data and writes it to the database, so that the analysis modules can then access the measured values ​​via the database.

[0066] According to embodiments of the invention, at least one of the several analysis modules assigned to one of the vehicle components is configured to perform an analysis which includes: a detection of current or future critical states of a vehicle component; and / or a prediction of the time of occurrence of a critical state of a vehicle component; and / or the automatic identification of one or more environmental parameters and / or vehicle component parameters that are the cause of a critical state of a vehicle component; and / or a calculation of a recommendation for action to a person with regard to the vehicle component; and / or a calculation of a control command to the vehicle component for the automatic execution of the control command.

[0067] This can be advantageous because the one or more analysis modules can be used not only to retrospectively identify individual correlations and relationships, but also, based on the database-stored history of measurement data from multiple sensors, to predict technically and / or tactically critical situations in or on the vessel, as well as to predict instructions and control commands that can help to avoid or mitigate the critical situation. The analysis modules can thus take over functions that were previously performed exclusively by the automation system.While the automation system is typically inflexible, as it typically integrates measured values ​​from a predefined number of sensors of a predefined set of vehicle components, the use of analysis modules in addition to the automation system is advantageous because, according to embodiments of the invention, the analysis modules are instantiated within an IT architecture that is highly available, robust and easily scalable based on container virtualization and automatic container orchestration, and which securely protects the measurement data of the vehicle components from access by unauthorized third parties.

[0068] According to embodiments of the invention, the sensors of at least one of the vehicle components contain at least one cryptographic encryption key. One of the analysis modules is assigned to the at least one vehicle component and contains a decryption key corresponding to this cryptographic encryption key. The two "corresponding" keys of the sensor and the analysis module can be a secret, "symmetric" cryptographic key that is used for both encrypting and decrypting the measured values.Alternatively, the two corresponding keys can be an asymmetric cryptographic key pair, where the key managed and stored by the sensor is a public cryptographic key (encryption key) and the key managed and securely stored by the analysis module is a private cryptographic key (decryption key). The sensors of the at least one vehicle component are configured to store at least some of the measured values ​​they acquire in encrypted form in the database and / or to transmit them directly to the analysis module assigned to the at least one vehicle component.

[0069] At least one analysis module is configured to decrypt at least some of the measured values ​​using the decryption key and to analyze the decrypted data.

[0070] According to embodiments of the invention, all sensors mounted in or on the same vehicle component have the same public encryption key. According to other embodiments of the invention, all sensors of at least one of the vehicle components of the vehicle have their own public key, which differs from the public key of the other sensors of that vehicle component.

[0071] This can be advantageous because the use of encryption methods offers a particularly high level of security, ensuring that the measurement data from sensors of a specific vehicle component can only be read and interpreted by authorized analysis modules.

[0072] According to embodiments of the invention, the sensors of at least one of the vehicle components include a signing key. The signing key preferably belongs to a Public Key Infrastructure (PKI) of a manufacturer of this vehicle component. One of the analysis modules is assigned to the at least one vehicle component and includes a signature verification key corresponding to this signing key. The sensors of the at least one vehicle component are configured to sign at least some of the measured values ​​they acquire with the signing key and to store these values ​​in signed form in the database and / or transmit them directly to the analysis module assigned to the at least one vehicle component. The at least one analysis module is configured to verify the at least some measured values ​​with the signature verification key and to analyze the signed data only if the signature verification shows that the signature is valid.

[0073] This can be advantageous because it protects the vessel operator from attacks on the stability and integrity of the military vessel caused by a manipulated component and / or sensor generating false analyses and predictions. In particular, if these analyses and predictions are automatically translated into corresponding control commands, there is a risk that such manipulation could damage the vessel in the short or long term, or render it unusable. For example, a specific analysis module might normally be used to predict the future course for the next 5 km based on GPS position data, the current turbine rotation speed, and the current rudder angle. A manipulated rudder angle sensor could provide false angle data, leading to an incorrect calculation of the vessel's course.This can lead to the vessel being on a different course than predicted, causing it to run aground or collide with rocks. This risk can be mitigated by having the sensors sign the measurement data they generate, with the signature pointing to a trusted entity, such as a specific manufacturer. By having the analysis module verify the signature of the measurement data before using it, it can be ensured that manipulated sensors and / or vehicle components do not pose a threat to the vessel and crew.

[0074] According to embodiments of the invention, one or more of the analysis modules are each configured to output their analysis results to a user and / or to the analysis system and / or to store them in the database.

[0075] For example, the results can be displayed on a screen, printed out using a printer, and / or output via speakers. Additionally or alternatively, the results can be output to a software or hardware component, such as the automation system.

[0076] This can be advantageous because the results integrate data from a multitude of sensors across a wide range of vehicle components and / or environmental parameters, taking into account not only current measurements but also historical data. Since the analysis modules are implemented as individual, isolated software modules, their number and composition can be easily adapted to potentially changing vehicle component compositions over the vehicle's lifetime. The analysis results from these modules thus provide a source of system diagnostics and control commands, flexibly complementing the automation system's functions. Depending on the type of analysis result and its implementation, the results can provide user recommendations for action, which must then be carried out manually.These can also be recommendations for action that can be executed automatically by the vehicle components, requiring only manual confirmation from the user. Alternatively, they can be control commands that are sent directly from the analysis modules to the automation system without user intervention, causing it to automatically perform the action specified in the commands, such as opening an exhaust flap, correcting the angle of a rudder, etc.

[0077] According to embodiments of the invention, at least one of the analysis modules is configured to perform an analysis (e.g., correlation analysis, machine learning (ML)-based prediction, rule-based prediction, etc.) on the measured values ​​of several (at least two) different sensors from several different vehicle components. The analysis includes: a detection of current or future critical states of a vehicle component; and / or a prediction of the time of occurrence of a critical state of a vehicle component; and / or the automatic identification of one or more environmental parameters and / or vehicle component parameters that are the cause of a critical state of one of the vehicle components; and / or a calculation of an action recommendation to a human; and / or a calculation of a control command to one of the vehicle components for the automatic execution of the control command.

[0078] This can be advantageous because ML-based methods and various other forms of correlation analysis are particularly suitable for recognizing complex, cross-component, linear as well as non-linear dependencies and interactions from historical measured values ​​of several different parameters and for calculating predictions about current and future system states based on these recognized dependencies.

[0079] According to embodiments of the invention, the database data is distributed across multiple computers and / or stored redundantly.

[0080] This can be advantageous because it increases reliability if one of the computers fails or becomes unreachable. Furthermore, redundant storage allows parallel access to copies of the same data, thus speeding up queries.

[0081] According to embodiments of the invention, the database data is distributed across different containers on different computers (i.e., the containers are instantiated on different computers, and some computers may even have multiple containers instantiated). The container management software is configured to orchestrate the creation of containers and the storage, replication, and deletion of data within the containers such that: In normal operation, the database data is stored redundantly across multiple computers so that, in the event of a failure of one or more computers, it can be reconstructed from the data stored on the remaining computers; and / or, in the event of a failure of one of the computers, another computer is automatically identified on which a copy of those parts of the data that were stored on the failed computer is located, and the data contained on this other computer is made available to the analysis modules and the automation system (e.g., by starting this other computer, granting access to the partial data, etc.).); and / or, in the event of a computer failure, automatically redistribute at least some of the data stored redundantly and distributed across multiple containers in such a way that the previous level of database data redundancy is restored; and / or, if a predefined maximum storage requirement is exceeded on one of the computers, automatically migrate or copy at least parts of the database data stored on that computer to another computer; for this purpose, load-balancing functions such as those already included in Kubernetes software can be used.

[0082] This can be advantageous for reasons similar to the redundant instantiation of analysis modules on multiple computers. In particular, availability and fault tolerance are increased, and access times are reduced through parallel access.

[0083] According to embodiments of the invention, at least some of the computers in the computer network are each contained in their own security container, which is fireproof and / or pressure wave resistant and / or waterproof.

[0084] For example, the security container can consist of a single-walled or, preferably, a multi-walled body. The body can be made of steel, for example, and equipped with a door with its own locking mechanism or lock. Preferably, the security container is waterproof and / or pressure wave resistant. For example, the body can include cable entry points at the rear and integrated cooling to prevent both the ingress of water and / or pressure and overheating. While "containers" are software or runtime environments for programs that are instantiated on a computer, security containers are physical containers that can hold one or more computers.

[0085] This can be advantageous because the computers, and therefore also the analysis programs and containers, are protected from damage in the event of a leak or detonation (pressure wave, fire).

[0086] According to embodiments of the invention, the computers of the computer network comprise one or more first computers and one or more second computers. The first computers and the second computers are located in different spatial areas of the watercraft, wherein the different spatial areas are different rooms, different decks, different compartments separated by watertight lock gates, the starboard and port sides of the watercraft, or the bow and stern sides of the watercraft.

[0087] This can be advantageous because it increases the reliability of the vessel and the analysis modules: if certain areas of the ship are damaged due to a detonation or accident, not all analysis modules will be affected. Instead, the container management software can be located on the containers.

[0088] In another aspect, the invention relates to a system comprising at least two military watercraft according to one of the embodiments or examples described herein and a computer system. The computer system includes an interface for the secure import of the contents of the databases of the at least two watercraft. The computer system also includes fleet analysis software. The fleet analysis software is configured to analyze the measured values ​​from the databases of the at least two watercraft. The fleet analysis software is configured to automatically detect whether the measured values ​​from different watercraft were acquired from vehicle components of the same type. The analysis includes: Identifying the vessel whose totality of components is in the best or worst condition with regard to at least one technical evaluation criterion (e.g., tank level, availability of energy resources, time until next maintenance, indicator of reliability, indicator of the vessel's suitability for a specific operational scenario); and / or identifying critical conditions of a component in one or more of the vessels; for example, by analyzing historical measurement data in the databases of several vessels, it may be identified that in a few vessels, a combination of rudder angle and turbine speed, which was unproblematic in the majority of vessels, caused an unstable condition requiring manual intervention, and these few vessels should therefore be brought in for inspection;Certain vibration patterns can indicate that a vehicle component of a particular watercraft is suffering from material fatigue or is negatively affected by vibrations and movements of adjacent components, making an inspection advisable for that component as well; and / or a prediction of the time of occurrence of a critical condition of a vehicle component in one or more of the watercraft; for example, the timing of each watercraft's next scheduled inspection, given the material fatigue deducible from the vibration values ​​and / or the usual maintenance intervals, so that the vessel whose predicted inspection date is furthest in the future can be considered the most suitable for current, extended use;and / or the automatic identification of one or more environmental parameters and / or vehicle component parameters that are the cause of a critical condition of one of the vehicle components in one or more of the vessels; for example, the fleet analysis software may detect that only those vessels that operated in waters with a water temperature below 6 °C had problems initiating movement in a specific component, suggesting that material contraction at low temperatures was the cause of the problems and that the component is not suitable for use at low temperatures. Analyzing multiple vessels may, in some cases, enable further investigation. To uncover causes that would not have been, or probably would not have been, detected without evaluating data from multiple vehicles.

[0089] Fleet analysis software can be a single, complex application program or a combination of several individual analysis programs that can perform various types of analysis on the history of measurements recorded by sensors of multiple watercraft over a period of several hours, days, weeks, months or years.

[0090] According to some implementation systems, the computer system hosting the fleet analysis software also includes a decryption key and / or signature verification key, with these keys being provided by the manufacturer(s) of the vehicle components or the watercraft, if the manufacturers release these keys to the customer, i.e., the operator of the watercraft.

[0091] In this context, a "military watercraft" is understood to be a watercraft trained and equipped for use by armed forces to fulfill their missions. Vessels designed for military purposes often have specific modifications, such as reinforced hulls or floors for mine protection, camouflage paint, and weapons and / or defense systems. Watercraft are vehicles designed for movement on or in water. Specifically, they can be wind-powered or engine-powered, for example, sailing ships, hovercraft, hydrofoils, submarines, frigates, aircraft carriers, supply ships, etc. For instance, some frigates may be trained and equipped for maritime surveillance, anti-submarine warfare, combating surface vessels, and defending against air attacks on their own ship or squadron.Supply ships are trained to support naval task forces, which can be composed of various ships and boats depending on the mission. The primary logistical task of a supply ship is to provide fuel, consumables, provisions, and ammunition. A supply ship may also be equipped with a weapons system, for example, to defend against enemy attacks.

[0092] In this context, a "vehicle component" refers to a part of a watercraft that, as a whole, fulfills at least one specific function. A vehicle component can be a single part, i.e., an individual component of a technical complex, or a system of several components that together fulfill this function. Typically, all components of a particular vehicle component are installed as a unit in a vessel. For example, a rudder system, a radar system, a weapon system, an engine unit, a control unit, etc., can each constitute a vehicle component.

[0093] A "sensor," also known as a detector, (measuring) transducer, or (measuring) probe, is a technical component that can qualitatively or quantitatively detect certain physical or chemical properties (physical properties such as heat quantity, temperature, humidity, pressure, sound field quantities, brightness, acceleration; or chemical properties such as pH value, ionic strength, electrochemical potential) and / or the material composition of its environment. These properties are detected by means of physical or chemical effects and converted into a processable electrical signal. This processable electrical signal can include, in particular, data that can be processed electronically and represents the quantity.The electrical signal that can be processed further does not necessarily have to be generated in the detector itself, but can also be generated from the detector's output signal by electronics connected to the detector.

[0094] In this context, a "weapon system" refers to (often complex) technical defense equipment, particularly large-scale military equipment. A component of the weapon system is the actual weapon. For example, a warship may carry weapons in the form of anti-aircraft missiles within a weapon system designed as a close-in defense system. More specifically, a weapon system can be a network of individual technical elements that interact with each other, achieving or even enabling an enhanced weapon effect through this interaction.

[0095] For example, the Common Remotely Operated Weapon Station (CROWS) is a weapon system. Another example of a weapon system is a gun mounted on a self-propelled gun carriage or on a ship's deck. Depending on the design, the vessel's engine power is used both to propel the vessel and to aim the gun, or the weapon system includes its own independent engine for aiming the gun. An anti-aircraft missile system is another example of a weapon system. The various components of the anti-aircraft missile system, such as sensors (e.g., a radar system), control center, and launcher, can acquire various measurement data that are processed for monitoring, status control, and correct aiming of the radar system and / or the missiles.

[0096] In this context, a "drive unit" refers to the structural unit that uses energy conversion to move a machine, such as a ship's turbine. This is often a motor with a potentially necessary gearbox. The drive unit can include a rotary drive or a linear drive. It can derive its energy from fossil fuels (especially oil, natural gas, and coal), nuclear energy (nuclear fission), battery power, and other energy sources.

[0097] In this context, a "navigation system" is understood to be a technical system that uses position determination (satellite, radio, GSM or inert or autonomous system) and geoinformation (topological, road, air or sea charts) to guide the user to a chosen location or along a route, taking desired criteria into account.

[0098] A "measured value" here refers to the value of a quantity measured by a sensor. Examples of measured values ​​include temperature in °C, position in the form of GPS coordinates, rotational speed in revolutions per minute, etc. "Measured values" are also referred to as "measurement data".

[0099] Here, a "database" refers to a data structure for the structured storage of data. A database can be a directory tree or a file. Preferably, a database is a data structure managed by a database management system (DBMS). A DBMS is an electronic data management system designed to efficiently, consistently, and permanently store large amounts of data and to provide required subsets in various, needs-based formats for users and application programs. A database system provides a database language for querying and managing the data. The database can be a relational database. The structure of the data is defined by a database model.

[0100] In this context, a "history of measured values" refers to a data set that specifies the temporal progression of several measured values.

[0101] A "timestamp" is understood here to be a data value that specifies a particular point in time, e.g., the date and time when a specific measurement was recorded. Timestamps are preferably given in or relative to Coordinated Universal Time (UTC). This can prevent potential misunderstandings due to globally differing time zones.

[0102] The term "persistently stored" here refers to the storage of data on a non-volatile storage medium.

[0103] The term "protected storage" here refers to data storage that technically ensures only a specific selection of users and / or applications, who can prove their authorization, can access the protected data for reading and / or writing. For example, this protection can consist of storing the data in an access-protected area and / or encrypting the data so that it can only be read by a program that possesses a suitable decryption key.

[0104] A "real-time capable" system, such as a real-time automation system, is a system designed to perform a task in "real time." This means the system is capable of continuously performing this task within a predefined maximum duration. Typically, this means the hardware and / or software system is subject to a "real-time constraint," such as the time from event to system response. Real-time programs must guarantee a response within specific timeframes, often referred to as "deadlines." Real-time responses are often understood to be on the order of milliseconds, and sometimes microseconds or seconds. A system not specified as operating in real time generally cannot guarantee a response within a timeframe, although typical or expected response times may be provided.

[0105] In this context, a "host" or "host computer" refers to a computer that, alone or in interaction with one or more other computers, provides a specific software program (guest software program), thus making it available to other programs and / or users. The guest program can be a database, an application program, a service, or other programs and program modules.

[0106] Here, a "container" is understood to be a runtime environment for software programs that includes and provides all the system components required for executing these programs and isolates the software programs running within it from programs outside the container. A container can be a virtual machine created and managed by a hypervisor (a program for managing virtual machines). Preferably, a container is a runtime environment that can be managed using a container virtualization program. Containers according to these embodiments typically require fewer resources than virtual machines because they do not start their own operating system and instead run within the context of the host operating system. Nevertheless, the containers are isolated from each other and from the host system, although not as tightly as with virtualization.

[0107] For example, the free software "Docker" can be used to define containers and isolate applications from each other using container virtualization. Docker simplifies application deployment because containers, which contain all the necessary packages, can be easily transported and installed as files. Docker packages the application and all the system components required to run it into a single file, the so-called "container." Docker containers ensure that the application runs reliably after being moved from one environment to another. This not only simplifies the deployment of complex applications on different computers but also enables a more flexible application infrastructure that is easier to modify, extend, and scale.

[0108] Container virtualization is a method for running multiple instances of an operating system (as so-called "guests") on a host system, isolated from one another. Unlike virtualization using a hypervisor based on multiple virtual machines, container virtualization has some limitations regarding the types of guests it can support, but it is considered particularly resource-efficient. Container virtualization is based on several principles, which are implemented differently in individual container virtualization software products. However, one core principle is always similar: multiple containers share a kernel and isolate at least some of the operating system resources used from each other.

[0109] For example, the open-source program Kubernetes can be used as a container management program. Kubernetes is container orchestration software that enables the simple and efficient orchestration of applications across multiple hosts. Kubernetes facilitates simplified or even fully automated deployment, operation, maintenance, and scaling of container-based applications. Groups of hosts running the containers are grouped into clusters of physical or virtual machines and managed as a unit. Kubernetes defines a Container Runtime Interface (CRI) that container platforms must implement to be orchestrated using Kubernetes. These implementations are also known as "shims." This makes Kubernetes platform-agnostic: in addition to or instead of Docker, other platforms with corresponding shims, such as CRI-O or KataContainers, can also be used.

[0110] In this context, "container management software" refers to software configured for the automated deployment, scaling, and management ("orchestration") of multiple (at least two) containers across multiple computers. Each computer acts as a host system for one or more containers, while the containers (whether on the same host computer system or different host computer systems) remain isolated from one another. In complex environments, this can involve several hundred containers. For example, Kubernetes can be used as container management software.

[0111] In this context, an "analysis module" refers to software designed to process measurement data from one or more sensors using one or more different computational methods in such a way as to generate an answer to an analytical question. The software can be a script, a complex application program, a program library, or a combination of two or more of the aforementioned options. The computational method can be a heuristic, a rule explicitly specified by a programmer, a mathematical and especially statistical algorithm (e.g., a correlation analysis method), or any other explicitly formulated computational procedure. The computational method can also be a method that is only implicitly formulated, for example, in the form of the mathematical model of a machine learning program created during a training process.For example, the model can be specified in the network architecture and the weights of network nodes of a neural network. The analytical question can address various issues, such as the current or predicted future state of a vehicle component (do parameters for vibration, conductivity, elasticity, etc. indicate a critical wear state?), or the question of which measurement parameter values ​​indicate whether a critical system state has been reached or is expected to be reached in the future, the question of the current and future availability of fuel or wear parts, or a question of recommended measures to prevent or mitigate a current or future critical state of the vehicle or a vehicle component.

[0112] In this context, an "encryption key" refers to a cryptographic key designed for encrypting data. With symmetric encryption methods, including all classical cryptography techniques and modern algorithms such as the Data Encryption Standard (DES) and its successor, the Advanced Encryption Standard (AES), both communicating parties use the same (secret) key for both encryption and decryption. Asymmetric encryption methods, such as the RSA cryptosystem, use key pairs consisting of a public key and a private key. The public key is not secret; it is disclosed to at least the party that is to send encrypted data to the holder of the private key.Data is encrypted using a public key. It is crucial that a public key can be uniquely assigned to a specific entity, such as a user or an analysis module. To decrypt the ciphertext, the private key is required. Unlike symmetric encryption methods, where multiple parties share a secret key, in asymmetric encryption methods only one party possesses the private (secret) key. Therefore, it is essential that the private key cannot be derived from the public key.

[0113] In this context, an "automation system" is understood to be a system for the fully or semi-automatic control of a watercraft. Control is achieved by means of predefined rules based on current measured values ​​from one or more sensors, which are converted into control commands by the automation system, and / or based on control commands entered by a user via a user interface. Preferably, the automation system is a real-time capable system. According to embodiments of the invention, the automation system is configured not only to receive current measured values ​​and / or manually entered control commands as input and to control the craft accordingly, but also to receive results of analyses from one or more of the analysis modules, with the automation system interpreting and implementing these results as control commands.

[0114] A "computer cluster," or simply "cluster," refers to a number of networked computers. The cluster can be configured to increase the computing capacity and / or availability of the computers or the services they provide. The computers in a computer cluster (also called "nodes") are often referred to as servers. According to embodiments of the invention, each computer in the cluster hosts one or more containers, the distribution of which across the computers is orchestrated by container management software. Analysis modules or other programs, which may be implemented as services, can be executed within these containers, and their results can be made available to specific vehicle components. Because of this function of providing analysis results, the computers can also be called "servers." Brief description of the drawing

[0115] The following describes embodiments of the invention with reference to the drawing. The drawing shows Fig. 1A A block diagram of a military watercraft with multiple sensor-equipped vehicle components; Fig. 1B A system comprising multiple military watercraft and a computer with fleet analysis software; Fig. 2 A block diagram of a distributed computer system that can be used to store and analyze sensor measurement data; Fig. 3 Several analysis module-specific asymmetric cryptographic key pairs and their use; Fig. 4 Components of a military watercraft with multiple databases and analysis modules.

[0116] Figure 1AFigure 1 illustrates a block diagram of a military watercraft 100 with several sensor-equipped vehicle components. For example, the vehicle components include a propulsion system 104, which contains, for instance, a diesel-powered marine engine with a gearbox coupled to the engine. The propulsion system includes several sensors for measuring various parameters of the engine and the gearbox, including a sensor 112 for the rotational speed of a shaft that is mechanically coupled to the gearbox.

[0117] The vehicle components of the watercraft include a navigation system 106 with a GPS sensor 114 for determining the current position of the vehicle, and a rudder 108 with a position or angle sensor for determining the current angle of the rudder relative to the longitudinal axis of the watercraft. Furthermore, the vehicle incorporates an electronic monitoring unit 110 with several sensors, which includes multiple sensors 118 and 120. The sensors of component 110 automatically and preferably continuously or repeatedly determine vehicle and environmental parameters. These parameters include, for example, air pressure, humidity, air temperature, water temperature, water current, and / or other parameters.

[0118] All or some of the recorded parameters are forwarded to an automation system 124 immediately after their acquisition. The automation system is a fully or semi-automatic system for monitoring and controlling the internal states of the vessel, as well as for controlling the movement or other actions of the vessel or its components. The automation system is a real-time system designed to use the measured values ​​received from the sensors and user input via a user interface to control the vessel accordingly.

[0119] Over time, a large number of measurement data points are generated during the ship's operation. These data points are timestamped to reflect the time they were generated. The measurement data and their timestamps are stored in a database (122), thus creating a history of the parameter values ​​recorded for one or more measurement parameters. The database can be, for example, a relational database such as PostgreSQL or MySQL, or a NoSQL database.

[0120] The database and several analysis modules for analyzing the data are stored and instantiated in a computer system 126. The computer system 126 can be a standalone, monolithic computer system. Preferably, however, it is a computer network comprising several computers connected to form a functional unit. Such a computer network is, for example, advantageous with regard to Figure 2 described in more detail.

[0121] The vessel also incorporates a Weapon System 102, which also includes sensors (not shown). Because the vessel, due to its weapon system, is a significant target for enemy forces and poses a potential danger to its own crew and uninvolved third parties in the event of a malfunction, the reliable operation of the automation system is of paramount importance. "Reliable operation" in this context means that the automation system, as well as the data on which it bases its decisions, must be protected from manipulation by third parties. Example 1: Improved monitoring and control of a rudder system

[0122] For example, the vessel in question could be an overseas vessel equipped with a rudder system, particularly a twin rudder system. The rudder system has a control system designed to monitor and adjust the position of the rudders.

[0123] Such systems are currently only monitored in accordance with SOLAS (International Convention for the Safety of Life at Sea) and thus only in a rudimentary way (collective alarm). For military vessels, the precision of this monitoring is often insufficient: With currently available twin rudder systems, it can happen that the rudders do not react synchronously to rudder position commands. For example, the starboard rudder may reach a rudder position in response to a command faster than a corresponding rudder position command reaches the port rudder. Even if the commands arrive simultaneously, one side of the rudder system may not be able to execute the command as quickly as the other. This asynchronicity impairs the performance of the rudder platform and makes it more difficult to precisely control other system components, such as the weapon system.The causes for asynchronous command transmission and / or implementation could be manifold and interact in complex ways: different sliding properties of the rudder shafts, aging potentiometers in corresponding circuits, different control pressures and much more.

[0124] Embodiments of the invention address this problem as follows: A rudder system is used which includes a plurality of sensors for several different rudder system-specific parameters, referred to here as "rudder system parameters". The rudder system parameters include two or more of the following: pressures of the rudder system's oil circuits, voltages of the rudder system's electrical control system, currents of the rudder system's electrical control system, the position of the rudders, and / or accelerations (especially vibrations) occurring at the rudder shafts. The rudder system sensors are configured to regularly measure a rudder system parameter within relatively short time intervals (e.g., at least once per minute, preferably at least 10 times per second), optionally encrypt and / or sign this measurement, and store it in a database in conjunction with a timestamp.In some embodiments, the sensor's acquisition frequency can also be dynamically adjusted to the conditions, e.g., increasing the measurement frequency when one or more relevant parameters change above a predefined threshold. The timestamp can, for example, indicate the time when a measured value is saved to the database, with this time being very close to the time of data acquisition and therefore representing this time at least approximately. The position data of the rudders are also recorded by sensors as "rudder parameters," enabling the control system to determine whether the rudders have reached the positions they are supposed to assume according to the control commands.

[0125] In addition to these "rudder system parameters," several other sensors inside or outside the rudder system record environmental parameter values, such as the ship's speed, water temperature and / or water depth, and / or the operating states of other vessel components, such as a pump system. If, for example, the ship's speed (measured, for example, in meters of distance traveled per second) is not available, the propulsion power and / or turbine speed can alternatively be used as an indicator of speed.

[0126] These embodiments implicitly capture the time required for a rudder system to execute the given control commands and reach the desired positions under specific environmental conditions and system states. This is because the measurement data, and preferably also the control commands, are time-stamped and stored in the database. By analyzing the history of these measurements and commands using an analysis module, measured values ​​and rudder states can be easily correlated with the times at which the control system sent control commands to the actuator system.

[0127] According to embodiments, an analysis module is provided which, based on the recorded and stored, timestamp-linked measured values ​​of rudder system parameters, environmental parameters, and rudder system control commands, determines the time it takes for a control command to be fully implemented by the rudders affected by the command under the prevailing conditions. The analysis module uses the determined times to adjust the transmission of the control commands and / or the content of the control commands in such a way as to improve the synchronization of the rudders of the rudder system.

[0128] In some embodiments, the analysis module is configured, for example, to detect correlations between measured rudder deployment times and the value ranges of rudder system parameters and environmental parameters. Thus, a large number of factors are considered, not just the current deviation of the rudder position from the target position, to determine if and when a rudder will assume a desired position. Potential asynchronies between the port and starboard rudders can therefore be detected early and reliably, enabling timely responses and rapid, dynamic adjustments to the control commands for individual rudders, in preferred embodiments even in real time. Predicting asynchronies also allows for the forecasting of necessary maintenance work and facilitates its planning.

[0129] The analysis module for improved rudder control can, for example, identify potential causes of asynchronies based on acceleration and vibration data and display this information to the user. However, the analysis considers not only acceleration data (oscillations / vibrations) but also other rudder system parameters and environmental parameters. This can be advantageous because oscillations and vibrations are highly dependent on water depth, rudder position, sea state, fouling, rudder system switching states, and ship speed. Without considering this context, acceleration data alone is often insufficient for precise rudder control or accurate prediction of the next required maintenance date.In contrast, an analysis of the acceleration data in combination with the other rudder system parameters and environmental parameters makes it possible to identify vibration states that can provide information about the current deviation of a rudder actual position from a rudder target position or the current material fatigue state of the rudder system.

[0130] According to one embodiment of the invention, the vehicle components of the watercraft comprise a rudder system with a control unit, one or more starboard rudders, and one or more port rudders. The control unit is configured to coordinate, and in particular synchronize, the position and movement of the starboard and port rudders by sending control commands to the starboard rudders on the one hand and to the port rudders on the other. The rudder system includes several sensors configured to detect rudder system parameter values, wherein the rudder system parameters comprise two or more of the following measured parameter values: current position of the rudders, rudder vibrations, fouling of the rudders (e.g., by means of an optical sensor or a force sensor that measures the force in the direction of the flow), vibrations of components of the rudder system, and switching states of the rudder system.

[0131] One or more of the other vehicle components and / or the steering system also include several sensors designed to detect environmental parameter values, the environmental parameters comprising two or more of the following measurement parameter values: water depth, sea state, ship speed.

[0132] One of the analysis modules is an analysis module for improved control of the rudder system and is designed to analyze the rudder system parameter values, the environmental parameter values, and the time periods between sending the control commands from the control unit to the respective rudders and the implementation of the control commands, in order to identify correlations between the time periods, the rudder system parameter values, and the environmental parameter values ​​and / or to improve the coordination of the rudders of the rudder system.

[0133] For example, the analysis module for improved rudder control can be trained to automatically determine that, given the current sea state and marine growth, the command to the starboard rudders must be sent 400 milliseconds earlier than the corresponding control command to the port rudders. The analysis module then sends a corresponding control command to the rudder control unit, causing the control unit to send the command to the starboard rudders only after the aforementioned delay.

[0134] According to embodiments of the invention, the analysis module for improved control of the rudder system is designed to analyze the rudder system parameter values, the environmental parameter values, the time intervals between sending the control commands from the control unit to the respective rudders and the implementation of the control commands, and additionally, condition and / or vibration parameter values ​​acquired by sensors of other vehicle components, in particular the engine and / or the transmission and / or a radar system, in order to identify correlations between the time intervals, the rudder system parameter values, the environmental parameter values, and the condition and / or vibration parameter values ​​of the other vehicle components and / or to improve the coordination of the rudders of the rudder system.

[0135] These characteristics are based on the observation that vehicle components, even those not explicitly linked to the steering system, can influence its behavior and controllability. For example, a radar system could be excited by the frequency generated by a propulsion diesel engine at a certain speed, leading to a negative impact on the steering system.

[0136] For example, the control system can be implemented in the form of logic rules. These rules can be used not only to control the rudder system as described here, but also to control other components of the watercraft. For instance, one of the logic rules might stipulate that an internal combustion engine can only be started if at least one exhaust port is open. This rule is executed every time the engine is started, and depending on the result of the check to see if an exhaust port is open, either such a port is automatically opened or the starting process is aborted – possibly accompanied by a message to the user. Example 2: Improved detection and prediction of consumption and conditions

[0137] Environmental parameters and condition-related parameters of vehicle components are interdependent in a complex way.

[0138] For example, when seawater temperatures are higher, cooling systems that use seawater for cooling operate differently than with cold seawater. Power consumption increases, and the diesel engines used for power generation are subjected to greater stress. This, in turn, affects the maintenance and wear of the components, which are not only subjected to higher stress due to the increased energy required for cooling, but also become less effective at cooling themselves, since the machinery and capsules are typically cooled with seawater just like the engine itself. Therefore, the performance characteristics of seawater-cooled vehicle components are often difficult to compare, and predictions regarding their energy consumption are subject to uncertainties.

[0139] According to embodiments of the invention, one of the analysis modules is configured to calculate the current or future energy consumption and / or the current or future degree of wear of a vehicle component as a function of the temperature of the ambient water used as cooling water.

[0140] This data basis can also be used, for example, to automatically find similar operating modes of the entire watercraft, e.g. operating modes defined by the temperature of the ambient water, in order to take into account the evaluation of measurement data and / or other performance parameters of the entire watercraft in such a way that only comparable operating modes of the vehicle are compared with each other.

[0141] According to one embodiment, the analysis module is configured to use the temperature measured at various times to automatically identify similar operating modes of the entire watercraft, defined by a specific temperature or temperature range of the ambient water. The analysis module is configured to analyze measurement data and / or other performance parameters of the entire watercraft in such a way that only comparable operating modes of the craft are compared, in order to calculate, in particular, future energy consumption, the current maximum possible range, and / or the current or future degree of wear.

[0142] Furthermore, by analyzing performance and condition measurements recorded by sensors of numerous vehicle components and stored in the database, as well as by recording and analyzing the usage profiles of individual vehicle components (which specify, for example, how often which potentially redundant vehicle components are used in which situations and / or how high the utilization of various vehicle components is under different readiness and usage states), both the commissioning and usage phases of various vehicle components can be improved. These insights can enable the automatic or manual optimization of the operating modes of individual vehicle components or the improvement of the technical characteristics of a (new) vehicle component. Example 3: Cross-vehicle analyses

[0143] The acquisition and storage of a large number of measured values ​​over longer periods of time (measurement history) according to embodiments of the invention already offers significant advantages at the application level.

[0144] Further significant advantages arise for systems in which the measurement histories of multiple parameters, recorded from several vessels, are analyzed by fleet analysis software. For example, a data acquisition system and analysis module can be developed, at least for the rudder systems of the vessels, as described in Example 1. The rudder systems of the different vessels can be, but do not necessarily have to be, of the same type (i.e., from the same manufacturer). Even if the rudder systems differ slightly, at least subsystems such as the individual sensors of the rudder system or the control unit can be of the same type or comparable. Often, different manufacturers of certain vessel components use the same parts supplied by a single vendor.

[0145] By importing the databases containing the measurement histories of multiple vessels into a central and highly secure database, for example within the secure infrastructure of a home port, cross-platform analyses can be performed. For instance, at least some of the historical data can be imported into the central database and deleted from the vessel's own database while it is in its home port. This increases data security and reduces the storage requirements of the vessel's database.

[0146] The various data sets can be useful in multiple ways. For example, fleet analysis software can analyze various environmental parameters such as air and water temperature, flow conditions, etc., to determine whether the vehicles or vehicle components were operated under comparable conditions, or to identify vehicles and components that were operated under comparable, i.e., sufficiently similar, conditions. In the next step, the fleet analysis software can then analyze and identify whether vehicle components of a specific type or manufacturer perform better or worse than functionally equivalent vehicle components of a different type or manufacturer with regard to one or more performance parameters. In this way, a problem that has already occurred with one vehicle component can potentially be prevented with another.Furthermore, it is possible to determine across vehicles how a particular vehicle component can be operated better, or should not be operated, in order to avoid certain types of damage.

[0147] The action recommendations calculated by the fleet analysis software can be issued to a user to prompt them to make improvements to specific vehicle components, as well as components of the same or similar type. According to some implementations, individual analysis modules and / or the fleet analysis software can be configured to also calculate and issue tactical recommendations based on the data in the database(s).

[0148] Figure 1BFigure 150 shows a system with several military watercraft 100, 130, and 132. Each of the watercraft can be configured as a watercraft of the embodiments described herein. Preferably, the watercraft all belong to the same or a similar type. However, it is also possible that the watercraft belong to different types. In this case, an evaluation of the sensor data histories for several watercraft can also be advantageous, for example, if the different types of watercraft contain some or more vehicle components of the same type, so that a comparison of the component-related measured values ​​is useful, at least for these vehicle components.

[0149] System 150 also includes a computer system 134, which can be configured as a single computer or a computer network. This computer system includes an interface 136 for the secure import of the contents of the databases of the watercraft 100, 130, and 132. Depending on the implementation variant, interface 136 can be implemented in different ways. For example, it can be a wired interface, such as one based on fiber optic technology, which allows for the rapid transmission of large amounts of data. In some cases, however, it can also be a contactless interface, such as a wireless connection, or a USB interface for importing data from a portable drive via USB. In any case, several technical and / or organizational security measures are in place to ensure that the data cannot be read or manipulated during transmission.For example, the transmission may only take place in encrypted form via an end-to-end encrypted data transmission channel. Alternatively, authentication of the user initiating the data transmission may be required, e.g., via password-based and / or biometric authentication methods. For example, computer system 134 and interface 136 for secure data transmission may be part of the IT infrastructure of a home port, which can be used to import and collectively evaluate the measurement data automatically generated by the vessels during their operations.

[0150] The evaluation of data from multiple vessels is performed by fleet analysis software 138, which is instantiated on computer system 134. The fleet analysis software analyzes the imported measurement data from the vessels' databases. The imported data can be stored and analyzed, for example, in a central relational database on computer system 134. During the analysis, the fleet analysis software automatically recognizes whether the measurement data from different vessels was recorded by vehicle components of the same type. This information can be helpful in ensuring that the correct measurement data is being compared. A temperature sensor on an engine measures the engine temperature, while a temperature sensor on the outside of the vessel below the waterline measures the water temperature. It is important to consider which sensor is responsible for the measurement during the analysis.It is important to determine which vehicle component a parameter value, such as "temperature," originates from, as a comparison is generally only meaningful if the measured values ​​come from sensors and components of the same or similar type. For example, only the temperature values ​​for the "engine" component should be compared. Ideally, the manufacturer should also be included in the analysis. For instance, different manufacturers of the same type of vehicle component (engine) might mount the sensor in slightly different positions or use different sensor types. In this case, considering the different manufacturers or other relevant factors can lead to incorrect analysis results due to a misinterpretation of minor, manufacturer-related measurement deviations.

[0151] During the analysis, the fleet analysis software uses imported measurement data to identify which of the vessels are optimally or worst-performing with regard to at least one specific target criterion. This target criterion is a technical evaluation criterion, such as the vessel with the best energy and wear part reserves, the vessel with the least maintenance backlog, and / or the longest time until the next inspection. Additionally or alternatively, the fleet analysis software detects critical conditions of vehicle components in one or more of the vessels. For example, the software can identify all vessels in which vibration parameters indicate that, within the last six months, a problem has occurred in an engine, such as...Temperatures and / or rotational speeds were measured due to material fatigue or other adverse factors, which must be considered dangerous for the vehicle component and / or the crew.

[0152] In some configurations, the fleet analysis software is designed to predict the point at which a critical condition of a vehicle component will occur in one or more of the watercraft. This could be the point at which energy, oxygen gas, or food supplies run low, when a failure of an essential component due to wear is expected, or similar events.

[0153] In some configurations, the fleet analysis software is also designed to automatically identify one or more environmental parameters and / or vehicle component parameters and their corresponding parameter value ranges that are the cause of a critical condition in one or more of the vehicle components. This is a particularly advantageous aspect, especially in the context of highly complex military watercraft: sometimes vehicle components and parts fail well before their expected, normal service life, without any clear cause being identifiable. It is also sometimes observed that a specific component in a particular watercraft repeatedly fails, while the same component lasts significantly longer in other watercraft of the same type and with the same components.Given the highly complex interplay of various components and environmental factors, it is regularly assumed that the cause of the problem lies in an interaction between the component and its environment, although the specific cause responsible for the component's failure is not precisely known. The mechanical stresses on components depend on a wide variety of factors, such as the vibration behavior of spatially adjacent components, the sea state, wind, and current conditions to which the vessel is exposed during operation, and, not least, manually entered control commands from the crew. In light of this complexity, it is often impossible to identify specific causes of component failure through a detailed inspection of a particular vessel.Only by analyzing a large number of measurements, collected and stored over an extended period by the sensors of numerous watercraft, is it possible to correlate the failure of specific components with the interaction of several other factors, such as a particular operating style, air temperature, salinity, flow conditions, and the use of specific components and vehicle parts from other manufacturers. Fleet diagnostics thus enables improved fault diagnosis based on a broader database, including the detection of faults caused in highly complex, often non-linear ways by the interaction of several specific factors.

[0154] Figure 2Figure 1 shows a block diagram of a distributed computer system 126 that can be used to store and analyze sensor measurement data. The computer system shown here comprises five computers 202, 204, 206, and 208, which are functionally interconnected via a network 280, for example, an intranet, to form a computer cluster. Each computer instantiates several containers 212-230. Each computer has one or more processors 240, 242, 244, and 246, memory 248, 250, 252, and 254, and optionally one or more non-volatile storage devices.

[0155] Each container holds and executes a maximum of one instance of an analysis module. For example, the analysis modules can each be implemented as a so-called microservice.

[0156] Some analysis modules exist only in a single instance. For example, analysis module AM2 runs only as a single instance, 262, within container 214; analysis module AM3 runs only as a single instance, 264, in container 216; and analysis module AM4 runs only as a single instance, 268, in container 222. However, some analysis modules can run in multiple instances within a corresponding number of containers. For example, analysis module AM1 is instantiated as two instances, 260 and 266, in containers 212 and 220, respectively.

[0157] The number of instances of each analysis module instantiated and / or closed, and on which machine this occurs, is controlled by the container management software 256. Software 256 dynamically orchestrates the instantiation, migration, and closure of containers and their contained analysis modules according to various optimization criteria, which are preferably configurable by a user. Optimization criteria can include, for example, load balancing, upscaling, and downscaling, which ensure that the computational load is evenly distributed across the machines, that some frequently used analysis modules can be executed in parallel in multiple instances, and that fast response times and / or high availability are guaranteed.

[0158] The measurement data acquired by the sensors of the various vehicle components of the watercraft 100 are stored in a database 122. To increase the reliability of the database, its contents are stored redundantly on the various computers 202-208. Various methods for distributed, redundant data storage are known in the prior art, for example, storage using error correction methods with error correction bits. In some embodiments, some of the containers 224-230 can also be used to store parts of the database data.

[0159] The automation system 124 also includes one or more processors 282, working memory 284, and automation software 286. The automation software is configured to dynamically receive currently acquired measurement data from at least some of the sensors and to use this data, possibly together with commands entered by a user, as input in order to derive one or more control commands from this input and to automatically control the behavior of one or more vehicle components 102, 104, 106, 108, 110 based on the control commands.

[0160] The computer system 290 with the automation system 124 is connected to the computer network 126 via a data communication channel 292. In some embodiments, the automation system can send a request to an access service 288 via the data connection 292 in order to read data from the distributed database 122 and use it for calculating control commands. The automation system is operationally decoupled from the analysis modules; that is, it preferably runs on a different computer and, if it uses the measured values ​​stored in the database, accesses the measured values ​​asynchronously to the analysis modules.

[0161] Figure 3 shows several analysis module-specific asymmetric cryptographic key pairs that can be used for the secure transmission and storage of measurement data.

[0162] For example, the propulsion system 104 can be manufactured by a first manufacturer H1. Manufacturer H1 also develops an analysis module AM4, which is designed to analyze measured values ​​acquired by one or more sensors 112 of the propulsion system in order to automatically predict the current and / or future state of the propulsion system 104. Before or during the development of the analysis module AM4, manufacturer H1 generates a first asymmetric cryptographic key pair with a first secret decryption key 344 and a corresponding public encryption key 332. Before delivery of the analysis module AM4 to the operator or manufacturer of the military watercraft 100, the secret cryptographic decryption key 344 is integrated into the analysis module AM4 in such a way that it cannot be read by unauthorized third parties.Furthermore, the speed sensor 112 of the drive system 104 is provided with the public encryption key 332.

[0163] The public keys, all shown here with thick outlines, can be generated specifically for each individual sensor of a vehicle component, along with their corresponding private keys. In other embodiments, however, it is also possible for all sensors of a vehicle component to share the same cryptographic key pair, or rather the public key of that pair, and to use the public key to encrypt the measurement data acquired by each sensor. Generating key pairs individually for each sensor has the advantage of allowing for very fine-grained control of access rights.Generating key pairs individually for each vehicle component and using the same public key for the sensors of the same vehicle component has the advantage of simplified key management, because as a rule, though not always, the measurement data recorded by different sensors of a vehicle have identical or similar requirements for their confidentiality.

[0164] All measured values ​​acquired by sensor 112 for storage in database 122 are encrypted with the public key 332. This means that all other analysis modules AM1, AM2, and AM3 cannot decrypt the data acquired by speed sensor 112 and encrypted with key 332.

[0165] In one embodiment, however, the speed sensor 112 is configured to encrypt copies of the measured values ​​it acquires with a public key 330, which is assigned to an analysis module AM3 of another manufacturer H2, so that this analysis module AM3 can decrypt the copies with its corresponding private cryptographic key 342. For example, contractual trust relationships may exist between manufacturer H1 and manufacturer H2 of the rudder 108, such that the sensor 112 of the drive system encrypts the measured values ​​it acquires not only with the public key 332, but also, in copy, with the public key 330, so that not only analysis module AM4 but also analysis module AM3 can access and decrypt these measured values.

[0166] Similarly, the vehicle component 110, which includes a temperature sensor 120 and a pressure sensor 118, can be manufactured by a third-party manufacturer, H3. Manufacturer H3 also develops the analysis modules AM5 and AM6, which can be instantiated in multiple copies on the computer system 126. Modules AM5 and AM6 both evaluate temperature and pressure data, but with regard to different analytical purposes or questions. Sensor 120 generates its measurement data in the form of two copies, encrypted with different public keys 324 and 322. Sensor 118 also generates its measurement data in the form of two copies, encrypted with public keys 324 and 322. Data encrypted with key 322 can be decrypted and processed by any analysis module that contains the corresponding private key 334.Data encrypted with the key 324 can be decrypted and processed by any analysis module that contains the corresponding private key 336. Each of the multiple instances 306-312 of the AM5 analysis module contains the private key 334. Each of the multiple instances 314-318 of the AM6 analysis module contains the private key 336.

[0167] In the example shown, the rudder 108 contains three sensors of different types, including the angle sensor 114. Each sensor is assigned a public key 326-330, which, together with a corresponding private key 338-342, forms an asymmetric cryptographic key pair. The measured values ​​acquired by the sensors are encrypted in triplicate and stored in the database, each copy using a different public key. Analysis module AM1 can only decrypt data encrypted with public key 326. Analysis module AM2 can only decrypt data encrypted with public key 328. However, analysis module AM3 possesses two private keys, 340 and 342, and can therefore decrypt data encrypted with either public key 328 or public key 330.

[0168] This precise control of access rights is particularly advantageous in the area of ​​military vessels, because often it is only a combination of specific data that is security-critical, not individual data values. For example, GPS position data is always security-critical, as it allows enemy units to launch an attack on the vessel. The vessel's position below the waterline (in the case of a submarine) is generally not critical on its own, provided no other position data is known. The same applies to data such as water temperature or current conditions. However, combining the vessel's underwater position with current and temperature data allows, in some cases, at least an approximate determination of the vessel's current position.

[0169] The use of different encryption keys for different types of measurement data according to embodiments of the invention allows for fine-grained control of access to this measurement data. Analysis modules have only one or a few private keys and can therefore only access and process the measurement data that was acquired by a sensor that used a public key corresponding to these private keys for encryption.

[0170] In some embodiments, a single highly trusted software possesses a copy of all private keys of the analysis modules. For example, the highly trusted software could be another analysis module with extended privileges, developed by the vessel operator. Additionally or alternatively, the fleet analysis software could possess a copy of all private keys of the analysis modules to analyze data from all sensors of all vessels in a fleet.

[0171] Figure 3 This shows the assignment of private decryption keys to the individual analysis modules and the assignment of public encryption keys to the sensors (or the vehicle components containing these sensors). The sensors collect measurement data and encrypt it using their assigned public keys.

[0172] According to embodiments of the invention, further asymmetric cryptographic key pairs are assigned to the sensors and analysis modules, but for the purpose of signature verification (not shown here). In this case, private signing keys are assigned to the individual sensors or to the vehicle components containing these sensors. The sensors or vehicle components use the signing keys to sign the acquired and optionally encrypted measurement data. The individual analysis modules have access to public signature verification keys, each of which forms an asymmetric cryptographic key pair with one of the signing keys. For example, the public signature verification keys can be part of individual analysis modules. The analysis modules are configured to check the validity of the signatures of the measurement data with signature verification keys and to process the measurement data further only if its signature is valid.

[0173] Figure 4 Figure 122 shows some components of a military watercraft with several analysis modules ("AMs") and a database. Here, database 122 is implemented as two separate databases, each containing different parts of the data. Database 122.1 contains measurement data with a normal security level, which is available in whole or in part in unencrypted form. Database 122.2, on the other hand, contains sensitive measurement data, also known as "red data" in the military context, which is preferably encrypted with one or more different cryptographic keys, e.g., according to a key designed for... Figure 3described encryption method. Box 406 represents a variety of different measured values ​​from various sensors of different vehicle components. For example, the measured values ​​can originate from the following vehicle components and subsystems: various internal measurement data (e.g., condition-related measured values ​​of various vehicle components), SBM (damage-related measurement data, e.g., regarding damage after an accident and / or combat deployment), EBM (energy-related measurement data, e.g., condition data of a diesel generator), ONA (own noise analysis), and vibration data. Vibration data, in particular, is important for estimating current and future system states, as this data makes it possible in most cases to identify mechanical operational problems of rotating machinery, especially aging processes in steel structures.

[0174] The output interface 404 can be, for example, a screen, a speaker, or a machine-to-machine interface. For instance, the interface could be a GUI that displays the results of the analysis from each analysis module to the user (424), enabling the user to take appropriate action.

[0175] For example, the analysis module 410 can generate an analysis showing that energy reserves will be depleted in three days if consumption remains constant. This result is displayed on the user's screen, allowing them to take appropriate action, such as heading to a port in time or reducing energy consumption. The analysis module for 112 can predict the expected range of energy reserves by analyzing multiple measurements, such as currently available energy reserves, current conditions, and wind conditions, in combination with user-specified data, such as the chosen route for the next few days.If the calculations show that the currently selected route has insufficient energy reserves, but an alternative route would provide enough, the module can suggest the alternative route. The user simply needs to confirm the alternative route for the vehicle's automation system to automatically steer the vehicle onto it. Some analysis modules can also output their results directly to individual vehicle components. For example, in the event of an energy emergency on the vessel, module 410 can automatically switch off all energy consumers on the vessel that are considered non-essential for its operation, or at least stop supplying energy to these consumers.

[0176] At least some of the vehicle components may have a 402 interface to transmit acquired measurement data directly to one or more of the analysis modules 410-422. This can be particularly useful for measurement data that is important for fast, real-time responses from individual analysis modules, as it avoids delays caused by writing the measurement data to a database. If necessary, the measurement data can also be written to the database in the background or asynchronously.

[0177] The analysis modules shown here are grouped according to application areas, for example, into modules of the energy generation system (EES), the maintenance system, or the "service" system. The service system includes various services, e.g., regarding the recording and / or reporting of various faults in components of the watercraft.

[0178] In some configurations, various external systems have access to the analysis modules and their results, for example via an external interface 408. The interface 408 can be used, for example, to export the data from database 122 in the home port, so that fleet analysis software can evaluate the exported data. Reference symbol list

[0179] 100 Military Watercraft 102 Weapon System 104 Propulsion System 106 Navigation System 108 Rudder System 110 Vehicle Component 112 Speed ​​Sensor 114 GPS Sensor 116 Angle / Position Sensor 118 Pressure Sensor 120 Temperature Sensor 122 Database 124 Automation System 126 Distributed Computing System 130 Military Watercraft 132 Military Watercraft 134 Computer System 136 Import Interface 138 Fleet Analysis Software 140 Screen 202-208 Computer System 212-230 Container 260-268 Analysis Module Instances 260, 266 Instances of Analysis Module AM1 270-278 Parts of Database Data 122 240-246 CPUs 248-254 RAM 256 Container management software 280 Network connection (intranet) 282 CPUs 284 RAM 286 Automation software 288 Database access service 290 Computer system 292 Data connection 302304 Instances of the AM2 analysis module 306-312 Instances of the AM5 analysis module 314-318 Instances of the AM6 analysis module 322-332 Public encryption keys for secure data exchange with specific analysis modules 334-344 Private decryption keys, specific to specific analysis modules 402 Input interface 404 Output interface 406 Measured values ​​408 External interface 410-422 Analysis modules

Claims

1. Military watercraft (100), comprising: - several vehicle components (104-110), each comprising one or more sensors (112-120), wherein at least some of the vehicle components belong to a weapon system (102), a propulsion unit (104), and a navigation system (106), wherein the sensors are configured to acquire measured values, the measured values ​​indicating operating states of the vehicle component containing the sensor acquiring the measured values ​​and / or states of the watercraft or its environment; - a database (122), wherein a history of measured values ​​from the sensors, in conjunction with a timestamp, is persistently and securely stored in the database; and - an electronic automation system (124).wherein the automation system is configured for the automatic and / or semi-automatic control of at least one of the vehicle components in real time, depending on the measured values ​​and / or depending on user input, which is made in response to an output of the measured values ​​via a user interface; - one or more analysis modules (260-268), each configured to perform an analysis of at least a part of the measured values ​​stored in the database (122); - wherein an analysis module is software configured to process measurement data from one or more sensors using one or more different computational methods in such a way as to generate an answer to an analytical question, wherein the computational method is a method which is a mathematical model of a machine learning program created in the course of a training process.

2. The military watercraft according to claim 1, wherein the watercraft comprises: - several computers (202-208) interconnected to form a computer cluster (126), which cooperate as a host in the cluster such that at least one instance of the database is provided; and - container management software, wherein the container management software is configured to automatically deploy, scale, and manage multiple containers (212-230) on the multiple computers in such a way that each computer serves as a host system for one or more containers, the containers being isolated from each other.

3. The military watercraft according to one of the preceding claims, further comprising: - wherein the automation system (124) on the one hand and the one or more analysis modules (260-268) on the other hand are operationally decoupled from each other; and / or - wherein both the automation system and the one or more analysis modules are configured to perform their respective control or analysis functions without the use of an internet connection.

4. The military watercraft according to claim 3, wherein the operational decoupling is realized by: - ​​asynchronous operation of the automation system on the one hand and the one or more analysis modules (260-268) on the other hand; and / or - asynchronous write or read access to the database (122) by the automation system or by a service (288) operationally connected to the automation system on the one hand and by the one or more analysis modules (260-268) on the other hand; and / or - instantiation of the automation system on the one hand and the one or more analysis modules (260-268) on the other hand on different computers (202-208; 290).

5. The military watercraft according to one of the preceding claims, wherein the several analysis modules are implemented in several different containers (212-230) and thus isolated from each other.

6. The military watercraft according to any one of claims 2 to 5, wherein each of the containers (212-230) executes a maximum of one instance of a maximum of one analysis module (260-268).

7. The military watercraft according to any one of claims 2 to 6, wherein the container management software (256) is configured to orchestrate the creation of containers (212-230) and the instantiation and termination of analysis modules (260-268) such that: - if one of the computers (202-208) fails or becomes unreachable, the containers and analysis modules that are no longer present or reachable due to the failure or unreachability of the first computer are automatically started on another of the computers; and / or - if a maximum number of instances of one of the analysis modules currently running on the computers is exceeded, one of these instances is automatically terminated and / or one of the containers containing an instance of this analysis module is deleted;and / or - if a predefined maximum compute load of one of the computers is exceeded, automatically migrate at least one container hosted on that computer, including the analysis module instance running within it, to another of the computers; and / or - if a predefined minimum compute load of one of the computers is not reached, automatically migrate at least one container hosted on another of the computers, including the analysis module instance running within it, to that computer; and / or - if a predefined maximum compute load of one of the computers is exceeded, automatically identify at least one container hosted on that computer, including the analysis module instance running within it, and instantiate a copy of this identified container, including the analysis module running within it, on at least one other of the computers;and to execute analyses in parallel, including at least the analysis module instance in the identified container and the other instantiated analysis module instance; and / or – if the computational load of one of the computers falls below a predefined minimum threshold – to automatically identify at least one container hosted on another computer, including the analysis module instance running within it, and to instantiate a copy of this identified container, including the analysis module running within it, on that one computer; and to execute analyses in parallel, including at least the analysis module instance in the identified container and the other instantiated analysis module instance.

8. The military watercraft according to one of the preceding claims, wherein at least some of the analysis modules are specifically assigned a part of the database data, wherein the parts of the data are stored in a protected manner such that only the analysis module assigned to that part of the data can access them for reading and / or writing.

9. The military watercraft according to one of the preceding claims, wherein several (260, 262, 264; 306, 314) of the analysis modules (260-268) are each specifically assigned to one (108; 110) of the vehicle components and are configured to receive, directly or indirectly via the database, at least the measured values ​​acquired by the one or more sensors of that one vehicle component to which they are assigned, to analyze and output the result of the analysis.

10. The military watercraft according to claim 9, wherein at least one of the several analysis modules assigned to one of the vehicle components is configured to perform an analysis which includes: - the detection of current or future critical states of the one vehicle component; and / or - the prediction of the time of occurrence of a critical state of the one vehicle component; and / or - the automatic identification of one or more environmental parameters and / or vehicle component parameters that are the cause of a critical state of the one vehicle component; and / or - the calculation of a recommendation for action to a person with regard to the one vehicle component; and / or - the calculation of a control command to the one vehicle component for the automatic execution of the control command.

11. The military watercraft according to one of the preceding claims, - wherein the sensors of at least one of the vehicle components include at least one cryptographic encryption key (324, 322, 330, 328, 326, 332), - wherein one of the analysis modules is assigned to the at least one vehicle component and includes a decryption key (334, 336, 338, 340, 342, 344) corresponding to this cryptographic encryption key; - wherein the sensors of the at least one vehicle component are configured to store at least some of the measured values ​​they acquire in encrypted form in the database and / or to transmit them directly to the analysis module assigned to the at least one vehicle component; - wherein the at least one analysis module is configured to decrypt the at least some measured values ​​with the decryption key and to analyze the decrypted data.

12. The military watercraft according to one of the preceding claims, - wherein the sensors of at least one of the vehicle components include a signing key; - wherein one of the analysis modules is assigned to the at least one vehicle component and includes a signature verification key corresponding to this signing key; - wherein the sensors of the at least one vehicle component are configured to sign at least some of the measured values ​​they acquire with the signing key and to store these in signed form in the database and / or to transmit them directly to the analysis module assigned to the at least one vehicle component; - wherein the at least one analysis module is configured to check the at least some measured values ​​with the signature verification key and to analyze the signed data only if the signature check shows that the signature is valid.

13. The military watercraft according to any of the preceding claims, wherein one or more of the analysis modules are each configured to output their analysis results to a user and / or to the analysis system (404) and / or to store them in the database.

14. The military watercraft according to any of the preceding claims, wherein at least one of the analysis modules is configured to perform an analysis (e.g., correlation analysis, NN-based prediction, rule-based prediction, etc.) on the measured values ​​of several different sensors of several different vehicle components, wherein the analysis includes: - the detection of current or future critical states of a vehicle component; and / or - the prediction of the time of occurrence of a critical state of a vehicle component; and / or - the automatic identification of one or more environmental parameters and / or vehicle component parameters that are the cause of a critical state of one of the vehicle components; and / or - the calculation of a recommendation for action to a human; and / or - the calculation of a control command to one of the vehicle components for the automatic execution of the control command.

15. The military watercraft according to one of the preceding claims, - wherein one of the vehicle components comprises a rudder system with a control unit, one or more starboard and one or more port rudders, wherein the control unit is configured to coordinate, in particular synchronize, the position and movement of the starboard and port rudders by sending control commands to the starboard rudders on the one hand and to the port rudders on the other, - wherein the rudder system comprises several sensors configured to detect rudder system parameter values, wherein the rudder system parameters comprise two or more of the following measurement parameter values: current position of the rudders, vibrations of the rudders, fouling of the rudders, vibrations of components of the rudder system, switching states of the rudder system;- wherein one or more of the vehicle components include multiple sensors designed to detect environmental parameter values, the environmental parameters comprising two or more of the following measurement parameter values: water depth, sea state, ship speed; - wherein one of the analysis modules is an analysis module for improved steering system control and is designed to analyze the steering system parameter values, the environmental parameter values, and the time intervals between the transmission of control commands from the control unit to the respective rudders and the execution of the control commands, in order to detect correlations between the time intervals, the steering system parameter values, and the environmental parameter values, and / or to improve the coordination of the rudders of the steering system.

16. The military watercraft according to one of the preceding descriptions, - wherein one of the vehicle components includes at least one sensor for detecting vibrations, in particular oscillations, of that one vehicle component, wherein that one vehicle component is in particular a radar system and / or the propulsion unit, - wherein one of the analysis modules is configured to analyze the vibrations of that one vehicle component in order to calculate the current and / or future state of another of the vehicle components, wherein the other vehicle component is in particular a steering system; and / or - wherein one of the analysis modules is configured to analyze the vibrations of that one vehicle component in order to improve the control of the other of the vehicle components, wherein the other vehicle component is in particular a steering system.

17. The military watercraft according to one of the preceding claims, wherein one of the sensors measures the temperature of the water surrounding the watercraft and stores it in the database, wherein one of the analysis modules is configured to calculate the current or future energy consumption and / or the current or future degree of wear of a vehicle component as a function of the temperature of the ambient water used as cooling water.

18. The military watercraft according to claim 17, wherein one analysis module is configured to use the temperature measured at different times to identify similar operating modes of the entire watercraft defined by a specific temperature or temperature range of the ambient water, wherein the analysis module is configured to analyze measurement data and / or other performance parameters of the entire watercraft in such a way that only comparable operating modes of the craft are compared, and in particular to use the comparison results to calculate the future energy consumption, the currently maximum possible range and / or the current or future degree of wear of the watercraft or watercraft components.

19. The military watercraft according to one of the preceding claims, wherein data from the database are distributed and / or redundantly stored in the multiple computers.

20. The military watercraft according to any one of claims 2 to 19, wherein the database data is stored distributed across different containers on different computers, the container management software being configured to orchestrate the creation of containers and the storage, replication, and deletion of the data in the containers such that: - during normal operation, the database data is stored redundantly across the multiple computers in such a way that, in the event of failure of one or more of the computers, it can be reconstructed from the data stored on the remaining computers; and / or - in the event of failure of one of the computers, another computer is automatically identified on which a copy of those parts of the data that were stored on the failed computer is located, and the data contained on this other computer is made available to the analysis modules and the automation system;and / or - in the event of a computer failure, automatically redistribute at least some of the data stored redundantly and distributed across multiple containers in such a way that the previous level of database data redundancy is restored; and / or - if a predefined maximum storage requirement is exceeded on one of the computers, automatically migrate or copy at least parts of the database data stored on that computer to another computer; and / or - if the processing load on one of the computers falls below a predefined minimum, automatically delete at least one of the containers hosted on that computer.

21. The military watercraft according to any one of claims 2 to 20, wherein at least some of the computers of the computer network are each contained in their own safety container which is fireproof and / or pressure wave resistant and / or waterproof.

22. The military watercraft according to any one of claims 2 to 21, wherein the computers of the computer network comprise one or more first computers and one or more second computers, wherein the first computers and the second computers are located in different spatial areas of the watercraft, wherein the different spatial areas are different rooms, different decks, different chambers separated by watertight lock gates, starboard side and port side of the watercraft or bow side and stern side of the watercraft.

23. System (150) comprising: - at least two military watercraft (100, 130, 132) according to any one of the preceding claims; - a computer system (134) comprising: ∘ an interface (136) for securely importing the contents of the databases of the at least two watercraft; ∘ fleet analysis software (138), wherein the fleet analysis software is configured to analyze the measured values ​​of the databases of the at least two watercraft, wherein the fleet analysis software is configured to automatically detect whether the measured values ​​of different watercraft were acquired from vehicle components of the same type, wherein the analysis comprises: ▪ detection of the watercraft whose totality of vehicle components is in the best or worst condition with respect to at least one technical evaluation criterion; and / or ▪ detection of critical conditions of a vehicle component in one or more of the watercraft;and / or ▪ a prediction of the time of occurrence of a critical condition of a vehicle component in one or more of the watercraft; and / or ▪ the automatic identification of one or more environmental parameters and / or vehicle component parameters that are the cause of a critical condition of one of the vehicle components in one or more of the watercraft.;

Citation Information

Patent Citations

  • Marine internal combustion engine

    DE102008025803A1

  • Combat ship or boat has weapons platform mounted in pivoted manner, where ship body is provided for bearing commando bridge, and ballast device is provided for ballast sub-structure of weapons platform

    DE102008057123A1

  • Weapon system for use on commercial vessel, for defending against pirates, has gun, special ammunition, shot release device, control computer unit, sensor unit, weapon mounting unit, authorization unit and safety and support unit

    DE102011086355A1

  • Combat ship with systems connected via electronic control units

    DE3150895A1

  • Remote control system of unmanned patrol vehicle

    KR1020070040188A