Method and system for wired / wireless cyber security patch for ship

A wireless cybersecurity patching system for ships addresses inefficiencies in remote updates by using a system integration server, patch distribution, and backup update server to ensure continuous updates based on ship status and location, supporting smart and autonomous navigation systems.

WO2025143898A1PCT designated stage expired Publication Date: 2025-07-03HANWHA OCEAN CO LTD (KR) +1
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/KR2024/021324
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-28
Filing Date
2024-12-27
Publication Date
2025-07-03

AI Technical Summary

Technical Problem

Existing patching methods for ship cybersecurity are inefficient and difficult to perform remotely due to the nature of ships, especially when using satellites, and do not account for the ship's operating status and location.

Method used

A wireless cybersecurity patching system that includes a system integration server, patch distribution server, and patch update server, which enables remote updates via VSAT, LTE, and Port LAN connections, with a backup update server to handle communication interruptions, ensuring continuous updates based on ship status and location.

Benefits of technology

Enables remote, continuous cybersecurity patch updates without engineer intervention, supporting smart ships and autonomous navigation systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2024021324_03072025_PF_FP_ABST
    Figure KR2024021324_03072025_PF_FP_ABST
Patent Text Reader

Abstract

The present invention relates to a method and device for a wired / wireless cyber security patch for a ship. As the need for the establishment of a method for updating a CBS patch for a ship and a device therefor arises, the present invention proposes the method and system for a wired / wireless cyber security patch for a ship, capable of performing a patch update in accordance with IACS UR E26 requirements.
Need to check novelty before this filing date? Find Prior Art

Description

Method and system for wireless and wired cybersecurity patching of ships

[0001] The present invention relates to a method and device for and for a wireless cybersecurity patch for a ship. As the need for a CBS patch update method and device for ships has arisen, the present invention relates to a method and system for and for a wireless cybersecurity patch for a ship capable of performing patch updates in accordance with IACS UR E26 requirements.

[0002] As the International Maritime Organization (IMO) and classification society rules become more stringent, cybersecurity onboard ships is becoming increasingly important. Among these cybersecurity regulations, security patches and software updates for computer-based systems (e.g., servers and computers) onboard ships are particularly important. Patching methods for this can be broadly categorized into using a Patch Management System (PMS) or manual patching using USB drives. However, the nature of ships makes it difficult to use satellites for patching.

[0003] As a related prior art document, Republic of Korea Patent Publication No. 10-2023-0045769 (April 5, 2023) is published.

[0004] The purpose of the present invention is to provide a wireless cybersecurity patching method and system for a ship that can perform remote patch updates without the presence of engineers in the future by establishing a wireless patch update method.

[0005] In addition, another object of the present invention is to provide a method and system for and for wirelessly patching a ship's cybersecurity, which can perform cybersecurity patches on a ship equipped with ship cybersecurity for a smart ship and autonomous navigation system, and can continuously update cybersecurity patches according to the ship's operating status and ship location.

[0006] In order to achieve the above object, a ship cybersecurity patch system according to one aspect of the present invention comprises a ship cybersecurity patch update system, wherein, when there is a CBS to be patched among multiple CBSs of a ship, a system integration server receives patches from a supplier server of each CBS and integrates the patches; a patch distribution server authenticates and encrypts patches received from the system integration server and distributes the encrypted patches; and a patch update server provided on the ship, authenticates and decrypts patches received from the patch distribution server, and performs patch updates by checking hashes, timestamps, and patch versions; and the patch update server is characterized in that it continuously performs cybersecurity patch updates according to the ship's operating status and ship location.

[0007] In addition, in a ship cybersecurity patch system according to one aspect of the present invention, the patch distribution server is characterized in that it distributes the patch by connecting to one of VSAT, LTE, and Port LAN communication methods according to the ship's operating status and ship location.

[0008] In addition, in a ship cybersecurity patch system according to one aspect of the present invention, the patch update server further comprises a backup update server; and in the event that a communication connection is interrupted while performing a patch update through the patch update server, the patch status before the interruption is saved through the backup update server, and the update is performed from the point of interruption after the communication connection is resumed.

[0009] In addition, a method for patching a ship cybersecurity according to another aspect of the present invention includes a method for updating a ship cybersecurity patch, comprising: a patch reception step in which, when there is a CBS to be patched for a plurality of CBSs of a ship, a system integration server receives and integrates patches for the corresponding CBSs from a supplier server of each CBS; a patch distribution step in which the patch received through the patch reception step is authenticated and encrypted, and the encrypted patch is distributed from a patch distribution server; and a patch update step in which the patch distributed through the patch distribution step is received from the patch update server of the ship, the received patch is authenticated and decrypted, and a hash, a timestamp, and a patch version are verified to perform a patch update; and the patch update step is characterized in that the cybersecurity patch update is continuously performed according to the ship's operating status and ship location.

[0010] In addition, in a ship cybersecurity patch method according to another aspect of the present invention, the patch distribution step is characterized in that the patch is distributed by connecting to one of VSAT, LTE, and Port LAN communication methods depending on the ship's operating status and ship location.

[0011] In addition, a method for patching a ship cybersecurity according to another aspect of the present invention is characterized in that, in the patch update step, the patch update server further comprises a backup update server; and, in the event that a communication connection is interrupted while performing a patch update through the patch update server, the patch status before the interruption is saved through the backup update server, and the update is performed from the point of interruption after the communication connection is resumed.

[0012] According to the present invention, by establishing a wireless patch update method, it is possible to perform patch updates remotely without requiring engineers in the future.

[0013] In addition, according to the present invention, cybersecurity of a ship is possible with ship cybersecurity applied for a smart ship and autonomous navigation system, and has the effect of continuously performing cybersecurity patch updates according to the ship's operating status and ship location.

[0014] FIG. 1 is a drawing showing a cybersecurity wired / wireless patch system for a ship according to the present invention.

[0015] Figure 2 is a flowchart showing a method for wired and wireless cybersecurity patching of a ship according to the present invention.

[0016] The purpose and technical configuration of the present invention and the resulting operation and effects will be more clearly understood through a detailed description based on the drawings attached to the specification of the present invention.

[0017] The terminology used herein is merely used to describe specific embodiments and is not intended to limit the present invention. For example, terms such as "consist of" or "include" used herein should not necessarily be construed to include all of the various components or various steps described in the invention, but should be construed to mean that some of the components or some steps may not be included, or that additional components or steps may be included. Furthermore, the singular expression "a" or "an" as used herein includes the plural expression unless the context clearly dictates otherwise.

[0018] Hereinafter, the present invention will be described in detail by describing preferred embodiments thereof with reference to the attached drawings. The embodiments described below are provided to facilitate the technical concept of the present invention for those skilled in the art to understand, and should not be construed as limiting the present invention. It should be understood that the embodiments of the present invention will have various applications to those skilled in the art.

[0019] With reference to FIGS. 1 and 2, a method and system for wirelessly patching a ship's cybersecurity according to the present invention will be examined.

[0020] A ship cybersecurity wired / wireless patch system according to one aspect of the present invention establishes a CBS patch update method and system for ships in accordance with IACS UR E26 requirements.

[0021] A ship cybersecurity patch update system according to the present invention may include a system integration server (100) that receives patches for a plurality of CBSs (Computer Based Systems) of a ship from a supplier server (10) of each CBS when there is a CBS to be patched, a patch distribution server (200) that authenticates and encrypts the patches received from the system integration server (100) and distributes the encrypted patches by differentiating the communication connection method according to the ship's operating status and ship location, and a patch update server (450) that is provided on a ship (400) and authenticates and decrypts the patches received from the patch distribution server (200) and performs a patch update by checking a hash, a time stamp, and a patch version.

[0022] The patch update server (450) is characterized by continuously performing cybersecurity patch updates according to the ship's operating status and ship location.

[0023] That is, due to the nature of the ship, patch updates can be applied via wireless communication while sailing or at anchor.

[0024] For example, while at sea, a VSAT (very small aperture terminal) can be used to update to 5G or LTE (long term evolution) while at anchor.

[0025] Accordingly, the patch distribution server (300) is characterized in that it distributes patches by connecting to a communication unit (300) using one of VSAT, LTE, and Port LAN (local area network) connection methods depending on the ship's operating status and ship location.

[0026] Additionally, it is characterized by being able to perform patching while maintaining security even when other ships receive patch data by distributing encrypted patches through a key management system.

[0027] More specifically, when there is a CBS to be patched for multiple CBSs of a ship, the system integration server (100) receives the patch for the CBS from the supplier server (11 to 13) of each CBS.

[0028] Next, the patch distribution server (200) authenticates the patch received from the system integration server (100) through a firewall (210) and encrypts it through a key management system (230), and can distribute the encrypted patch by differentiating the communication connection method according to the ship's operating status and ship location.

[0029] That is, depending on the ship's operating status and ship location, the patch can be distributed through one of the communication units (300) among VSAT, LTE, and Port LAN (local area network).

[0030] The patch received from the ship (400) is authenticated through a firewall (410), decrypted through a key management system (430), hash and timestamp are checked, the patch version is checked at the patch update server (450), and a patch update is performed for the OT (Operational Technology) system of each ship CBS.

[0031] In addition, the patch update server (450) may further include a backup update server (460), and in the event that a communication connection is interrupted while performing a patch update through the patch update server (450), the patch status before the interruption may be saved through the backup update server (460), and the update may be performed from the point of interruption after the communication connection is resumed.

[0032] At this time, patch updates can be continuously performed based on the ship's operating status and ship location.

[0033] In addition, referring to FIG. 2, the method for patching a ship cybersecurity according to the present invention may include a patch reception step (S100) in which, when there is a CBS to be patched for multiple CBSs of a ship, a system integration server receives a patch for the corresponding CBS from a supplier server of each CBS, a patch distribution step (S200) in which the patch received through the patch reception step (S100) is authenticated and encrypted, and the encrypted patch is distributed from the patch distribution server by differentiating the communication connection method according to the ship's operating status and ship location, and a patch update step (S300) in which the patch distributed through the patch distribution step (S200) is received from the ship's patch update server, authenticates and decrypts the received patch, and verifies the hash, time stamp, and patch version to perform a patch update.

[0034] The patch update step (S300) is characterized by continuously performing cybersecurity patch updates according to the ship's operating status and ship location.

[0035] In addition, in the ship cybersecurity patch method, the patch distribution step (S200) can distribute the patch by connecting to one of VSAT, LTE, and Port LAN communication methods depending on the ship's operating status and ship location.

[0036] In addition, in the patch update step (S300), the patch update server (450) may further be equipped with a backup update server (460), and in the event that the communication connection is interrupted while performing a patch update through the patch update server (450), the patch status before the interruption may be saved through the backup update server (460), and the update may be performed from the point of interruption after the communication connection is resumed.

[0037] Therefore, according to the present invention, by establishing a wireless patch update method, it is possible to perform patch updates remotely without engineer intervention in the future.

[0038] In addition, according to the present invention, cybersecurity of a ship is possible with ship cybersecurity applied for a smart ship and autonomous navigation system, and has the effect of continuously performing cybersecurity patch updates according to the ship's operating status and ship location.

[0039] The embodiments of the present invention described above may be implemented in the form of program commands that can be executed through various computer components and recorded on a computer-readable recording medium. The computer-readable recording medium may include program commands, data files, data structures, etc., either singly or in combination. The program commands recorded on the computer-readable recording medium may be specially designed and configured for the present invention or may be known and available to those skilled in the art of computer software. Examples of computer-readable recording media include magnetic media such as hard disks, floppy disks, and magnetic tapes, optical recording media such as CD-ROMs and DVDs, magneto-optical media such as floptical disks, and hardware devices specifically configured to store and execute program commands, such as ROMs, RAMs, and flash memories. Examples of program commands include not only machine language codes generated by a compiler, but also high-level language codes that can be executed by a computer using an interpreter, etc. Hardware devices may be changed into one or more software modules to perform processing according to the present invention, and vice versa.

[0040] The embodiments described above are provided to enable those skilled in the art to easily understand the technical concept of the present invention, and should not be construed as limiting the present invention thereby. It will be apparent to those skilled in the art that the embodiments of the present invention can be variously modified and altered without departing from the spirit and scope of the present invention. Accordingly, such modifications or variations should be considered to fall within the scope of the claims of the present invention.

[0041] 10: Provider Server

[0042] 100: System Integration Server

[0043] 200: Patch distribution server

[0044] 300: Communications Department

[0045] 400: Ship

[0046] 450: Patch Update Server

Claims

1. In the ship cybersecurity patch update system, A system integration server that receives patches from the supplier servers of each CBS and integrates them when there is a CBS that is the target of a patch for multiple CBSs of a ship; A patch distribution server that authenticates and encrypts patches received from the above system integration server and distributes encrypted patches; and A patch update server is provided on the ship, and authenticates and decrypts patches received from the patch distribution server, and performs patch updates by checking hash, timestamp, and patch version; A ship cybersecurity patch system, characterized in that the above patch update server continuously performs cybersecurity patch updates according to the ship's operating status and ship location.

2. In claim 1, The above patch distribution server is, A ship cybersecurity patch system characterized by distributing patches by connecting via one of the communication methods among VSAT, LTE, and Port LAN depending on the ship's operating status and ship location.

3. In claim 1, The above patch update server further comprises a backup update server; A ship cybersecurity patch system characterized in that, when a communication connection is interrupted while performing a patch update through the above patch update server, the patch status before the interruption is saved through a backup update server, and the update is performed from the point of interruption after the communication connection is resumed.

4. In terms of ship cybersecurity patch update method, When there is a CBS to be patched for multiple CBSs of a ship, a patch reception step in which the system integration server receives patches for the corresponding CBS from the supplier server of each CBS and integrates them; A patch distribution step for authenticating and encrypting a patch received through the above patch receiving step and distributing the encrypted patch from a patch distribution server; and A patch update step is included, which receives the patch distributed through the above patch distribution step from the patch update server of the ship, authenticates and decrypts the received patch, and performs a patch update by checking the hash, timestamp, and patch version; A method for patching cybersecurity on a ship, characterized in that the above patch update step continuously performs cybersecurity patch updates according to the ship's operating status and ship location.

5. In claim 4, The above patch distribution steps are: A method for patching cybersecurity on a ship, characterized in that the patch is distributed by connecting via one of the communication methods among VSAT, LTE, and Port LAN depending on the ship's operating status and ship location.

6. In claim 4, In the above patch update step, the patch update server further has a backup update server; A method for patching ship cybersecurity, characterized in that, when a communication connection is interrupted while performing a patch update through the above patch update server, the patch status before the interruption is saved through a backup update server, and an update is performed from the point of interruption after the communication connection is resumed.

Citation Information

Patent Citations

  • Server for updating network and method using the same

    KR101622204B1

  • System for remotely monitering ship and supporting optimal operation of ship using multiple communication environment

    KR1020180045440A

  • System and method fo managing driving negotiation targets for minimal risk maneuver

    KR1020250072031A

  • Vessel antivirus or security program update system and method using satellite communication

    KR102323476B1

  • KR20230045769A