Ship cyber security maturity management system and method

A cloud-based platform for managing cybersecurity maturity of ships addresses the challenge of identifying and rectifying security issues during shipbuilding, ensuring compliance with international standards and reducing delays and costs by providing continuous tracking and visualization of cybersecurity levels.

WO2025263820A1PCT designated stage Publication Date: 2025-12-26HANWHA OCEAN CO LTD (KR) +1
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/KR2025/006093
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-06-18
Filing Date
2025-05-07
Publication Date
2025-12-26

AI Technical Summary

Technical Problem

Existing methods struggle to effectively manage and assess the cybersecurity maturity of ships during the shipbuilding process, particularly during sea trials, leading to potential security issues that can cause delays and increased costs, as they are difficult to identify and rectify at later stages.

Method used

A cloud-based platform and method for managing cybersecurity maturity of ships, integrating a platform operation server, shipyard terminal, device development terminal, and ship owner terminal, to track and analyze security information, vulnerability, and test results throughout the design, construction, and commissioning stages, providing a visual representation of cybersecurity levels over time.

Benefits of technology

Enables continuous tracking and management of cybersecurity maturity, allowing compliance with international standards and timely identification of security vulnerabilities, reducing delays and costs by addressing security issues proactively.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2025006093_26122025_PF_FP_ABST
    Figure KR2025006093_26122025_PF_FP_ABST
Patent Text Reader

Abstract

A ship cyber security maturity management system is disclosed. The ship cyber security maturity management system provides, through the cloud, the cyber security maturity of a ship over time during the design, construction and test run stages of the ship.
Need to check novelty before this filing date? Find Prior Art

Description

Cybersecurity Maturity Management System and Method for Ships

[0001] The present invention relates to a system and method for managing the maturity of cybersecurity of a ship.

[0002] A smart ship is a next-generation digital ship based on information and communication technology (ICT), which combines cutting-edge information technologies such as the Autonomous Navigation System (ANS), the Automatic Identification System (AIS), and the Integrated Maritime Information Technology (IMIT) with shipbuilding technology. It includes autonomous ships and unmanned ships.

[0003] Smart ships are capable of autonomous navigation and can be controlled from outside the ship via remote access. Land-based base stations can use remote access programs to access the ship's satellite communication services (e.g., VSAT), receive information from the ship, and remotely control the ship. Land-based base stations can be categorized as shipping companies, ship equipment engineers, etc.

[0004] Meanwhile, the International Association of Classification Societies (IACS) has announced Unified Requirements (UR) E26 and E27 for the cyber resilience of ships, mandating the application of UR E26 to new ships contracted for construction after January 2024, and UR E27 after July 2024. UR E26 requires equipment identification, protection, attack detection, response, recovery, and risk management for cyber resilience throughout the entire life cycle of a ship, including design, construction, commissioning, and operation.

[0005] Accordingly, the role of cyber resilience in shipyards is increasingly demanded, particularly considering the entire life cycle of a ship, from the basic design stage, the first step in the shipbuilding process, to the actual shipbuilding and sea trials. In particular, the international classification society DNV emphasizes security throughout the shipbuilding process.

[0006] Onshore security risk assessments, such as vulnerability checks and simulated hacking, are difficult to conduct during the sea trials or launching stages, when equipment is being installed on a ship. Furthermore, if security issues are not promptly identified during the sea trials or launching stages, resolving them can be costly and time-consuming, leading to significant increases in ship prices and delays in ship delivery. Delays in ship delivery, a key export item for South Korea, can harm not only the company itself but also the nation's credibility as a shipbuilding and maritime powerhouse.

[0007] The present invention seeks to provide a cloud-based service platform that measures, evaluates, and manages the cybersecurity maturity of a ship during the shipbuilding period, which typically takes more than one year.

[0008] According to one aspect of the present invention for achieving the above object, a ship cybersecurity maturity management system is provided that provides the cybersecurity maturity of the ship over time through the cloud during the design, construction, and commissioning stages of the ship.

[0009] The above-mentioned ship cybersecurity maturity management system may include a platform operation server that compares and analyzes one or more of the security information of the ship, the security vulnerability information of the equipment mounted on the ship, and the cybersecurity test information of the equipment mounted on the ship; and a platform that receives the comparative analysis results from the platform operation server and provides the cybersecurity level of the ship according to changes over time during the design, construction, and commissioning stages of the ship.

[0010] The above ship cybersecurity maturity management system may further include a shipyard terminal that transmits one or more of the ship name, ship owner, classification, onboard equipment, and security status information of the ship from the shipyard to the platform operation server.

[0011] The above ship cybersecurity maturity management system may further include a PLM server that transmits BOM information of equipment mounted on the ship to the platform operation server.

[0012] The above ship cybersecurity maturity management system may further include a device development terminal that transmits information about devices installed on the ship from the device development company to the platform operation server.

[0013] The above ship cybersecurity maturity management system may further include a ship owner terminal that allows the ship owner to access the platform through the platform operation server.

[0014] The above platform may include a BOM data linkage unit that manages BOM data in conjunction with a PLM server.

[0015] The above platform may include a vessel information processing unit that processes and analyzes information related to the vessel and provides the results.

[0016] The above platform may include a material information processing unit that processes and analyzes information related to material loaded on the ship and provides the results.

[0017] The platform may include a cybersecurity maturity provider that analyzes and provides results of one or more of the following: the ship's cybersecurity plan; the ship's current cybersecurity maturity; the ship's past cybersecurity maturity trend; and the ship's future cybersecurity maturity.

[0018] According to another aspect of the present invention for achieving the above object, a method for managing cybersecurity maturity for a ship is provided, which provides the cybersecurity maturity of the ship at one or more of the contract stage, basic design stage, detailed design stage, CS-FAT stage, CS-SAT stage, land trial stage, and sea trial stage of the ship.

[0019] The above-described ship cybersecurity maturity management method may include a step of inputting new ship information into a platform operation server via a shipyard terminal; a step of the platform operation server receiving BOM information of equipment from a PLM server via a BOM data linkage unit; and a step of analyzing security construction standards based on the input new ship information by a ship information processing unit.

[0020] The above-mentioned ship cybersecurity maturity management method may include a step in which a platform operation server requests a device development company to input test results; a step in which the device development company performs a cybersecurity test; a step in which the device development company inputs the cybersecurity test results into the platform operation server via a device development terminal; and a step in which the platform operation server receives the device cybersecurity test results from the device development company.

[0021] The above method for managing cybersecurity maturity for ships may include a step of determining whether there is a change in security vulnerability information of equipment, and if there is a change in the equipment security vulnerability information, the security vulnerability information is linked and processed on a platform and stored in a recording device, the security vulnerability information recorded in the cybersecurity maturity provision unit is updated and displayed, and a shipyard terminal and a shipowner terminal can receive updated security status information through the cyber maturity provision unit.

[0022] In the event of a change in the above shipbuilding process, it is possible to check whether there is a change in the security vulnerability information of the equipment, and if there is a change in the security vulnerability information of the equipment, the security vulnerability information can be updated and provided to the shipyard and ship owner.

[0023] According to the present invention, by enabling the cybersecurity maturity of a ship to be managed through a cloud-based platform, data can be concentrated and accessibility of management entities can be increased.

[0024] According to the present invention, by providing the cybersecurity maturity of a ship over time during the design, construction, and commissioning stages of the ship, it is possible to comply with the ship's cybersecurity design standards and respond to smart ship security requirements based on international regulations.

[0025] FIG. 1 schematically illustrates a ship cybersecurity maturity management system according to a preferred embodiment of the present invention.

[0026] FIG. 2 schematically illustrates a platform of a ship cybersecurity maturity management system according to a preferred embodiment of the present invention.

[0027] FIG. 3 illustrates an example screen of a ship cybersecurity maturity management system according to a preferred embodiment of the present invention.

[0028] Figure 4 schematically illustrates a method for managing cybersecurity maturity for a ship according to a preferred embodiment of the present invention.

[0029] The configuration and operation of a preferred embodiment of the present invention are described in detail with reference to the attached drawings. The present invention can be applied in various fields of ship control and security management. Furthermore, the following embodiments may be modified in various other forms, and the scope of the present invention is not limited to the following embodiments.

[0030]

[0031] FIG. 1 schematically illustrates a ship cybersecurity maturity management system according to a preferred embodiment of the present invention.

[0032] Referring to FIG. 1, the ship cybersecurity maturity management system of the present invention includes a platform (200) and a platform operation server (150), and may include one or more of a shipyard terminal (110), a material development terminal (120), a ship owner terminal (130), and a PLM server (140).

[0033] A shipyard (yard) that builds ships can access a platform (200) through a communication network (N) and a platform operation server (150) using a shipyard terminal (110). The platform operation server (150) can receive information about the new ship's name, ship owner, classification, onboard equipment, security status, etc. from the shipyard.

[0034] The platform operation server (150) can receive BOM information of equipment installed on a ship from the PLM server (140). A BOM (Bill of Materials) is a parts list that organizes all parts required for manufacturing a product, and can be composed of a PN (Parts Number) that describes item information and a PS (Part Structure) that describes the sub-structure of the item information. By linking information or deliverables required for product development to the BOM item information and entering them, product design information can be managed. PLM (Product Lifecycle Management) is a system that digitalizes and manages BOMs. In the case of the present invention, parts required for ship manufacturing at a shipyard can be managed by PLM.

[0035] A shipboard equipment development company developing shipboard equipment can access the platform (200) via a communication network (N) and a platform operation server (150) using a shipboard equipment development terminal (120). The platform operation server (150) can receive cybersecurity test results, such as CS-FAT and CS-SAT, of shipboard equipment from the shipboard equipment development company.

[0036] Cybersecurity testing refers to cybersecurity testing of equipment performed by equipment developers before and after loading equipment onto a ship, and may include CS (CyberSecurity)-FAT (Factory Acceptance Test), a cybersecurity test performed at the development site before loading equipment onto a ship, and CS (CyberSecurity)-SAT (Site Acceptance Test), a test to verify that the security functions of the system are fully operational after loading onto a ship.

[0037] The platform operation server (150) can compare and analyze the ship's security information, security vulnerability information of equipment mounted on the ship, CS-FAT results, CS-SAT results, etc., and provide the ship's cybersecurity level according to changes over time during the ship's design, construction, and test operation stages through the platform (200).

[0038] A ship owner, which is a company that owns a ship, can access the platform (200) via a communication network (N) and a platform operation server (150) using a ship owner terminal (130). Through the platform (200), the ship owner can check the ship's cybersecurity level over time during the ship's design, construction, and commissioning stages.

[0039]

[0040] FIG. 2 schematically illustrates a platform of a ship cybersecurity maturity management system according to a preferred embodiment of the present invention.

[0041] Referring to FIG. 2, the platform (200) may include one or more of a BOM data linkage unit (210), a ship information processing unit (220), a material information processing unit (230), a cybersecurity maturity provision unit (240), and a platform management unit (250).

[0042] The BOM data linkage unit (210) can manage BOM data in conjunction with the PLM server (140).

[0043] The ship information processing unit (220) can process and analyze information related to the ship, such as ship security construction standards, and provide the results.

[0044] The equipment information processing unit (230) can process and analyze information related to equipment installed on a ship, such as CS-FAT results and CS-SAT results of the equipment, received from the equipment development company, and provide the results.

[0045] The cybersecurity maturity provision unit (240) can analyze the cybersecurity plan of a ship under construction, the current cybersecurity maturity and past trends, and the predicted future cybersecurity maturity based on these, and provide the results.

[0046] The platform management unit (250) can comprehensively manage matters necessary for platform operation, such as definition and management of interfaces, data linkage management, and access authority management.

[0047]

[0048] FIG. 3 illustrates an example screen of a ship cybersecurity maturity management system according to a preferred embodiment of the present invention.

[0049] Referring to FIG. 3, the ship cybersecurity maturity management system of the present invention can provide the cybersecurity maturity of a ship under construction according to changes in time through a graph in which the horizontal axis represents date and the vertical axis represents the cybersecurity level (%).

[0050] In addition, the ship cybersecurity maturity management system of the present invention can provide the cybersecurity maturity of a ship at one or more of the ship contract stage where a ship owner and a shipbuilder contract to build a ship, the basic design stage where the foundation of the ship is designed, the detailed design stage where detailed parts of the ship are designed, the CS-FAT stage where cybersecurity testing of equipment is performed before loading the equipment on the ship, the CS-SAT stage where cybersecurity testing of equipment is performed after loading the equipment on the ship, the sea trial stage where the ship is tested on land, and the sea trial stage where the ship is tested at sea. Although the cybersecurity maturity cannot be clearly known at the ship contract stage, an estimated value can be provided through analysis.

[0051] Stakeholders in shipbuilding, such as ship owners, can access the cybersecurity maturity provision unit (240) of the platform (200) to check the level of cybersecurity over time during the shipbuilding process and monitor the ship security process based on security specifications.

[0052]

[0053] Figure 4 schematically illustrates a method for managing cybersecurity maturity for a ship according to a preferred embodiment of the present invention.

[0054] Referring to FIG. 4, the ship cybersecurity maturity management method of the present embodiment includes a step (S510) of inputting new ship information into the platform operation server (150) through a shipyard terminal (110), a step (S520) of the platform operation server (150) receiving BOM information of equipment from a PLM server (140) through a BOM data linkage unit (210), a step (S530) of the ship information processing unit (220) analyzing security construction standards according to the input new ship information, a step (S540) of the platform operation server (150) requesting input of test results from an equipment development company, a step (S550) of the equipment development company performing a cybersecurity test, a step (S560) of inputting cybersecurity test results into the platform operation server (150) through an equipment development terminal (120), a step (S570) of the platform operation server (150) receiving cybersecurity test results of equipment from an equipment development company, and a step (S580) of information on security vulnerability information of equipment. It may include one or more of the following steps: a step for determining whether there is a change (S580), a step for linking and processing security vulnerability information to the platform (200) and storing it in a recording device (S590), a step for updating and displaying security vulnerability information recorded in the cybersecurity maturity provision unit (240) (S600), a step for receiving security status information through the cyber maturity provision unit (240) by the shipyard terminal (110) and the shipowner terminal (130) (S610), and a step for determining whether there is a process change (S620).

[0055]

[0056] 1) A step (S510) of inputting new ship information into the platform operation server (150) through a shipyard terminal (110), a step (S520) of receiving BOM information of equipment from the PLM server (140) through a BOM data linkage unit (210) by the platform operation server (150), and a step (S530) of analyzing the security construction standards according to the input new ship information by the ship information processing unit (220).

[0057] A shipyard (Yard) can input information about a new ship's name, ship owner, classification, onboard equipment, and security status into the platform operation server (150) via a shipyard terminal (110) (S510). Furthermore, the platform operation server (150) can receive BOM information on equipment from the PLM server (140) via the BOM data linkage unit (210) (S520). The ship information processing unit (220) can analyze security construction standards based on the input new ship information (S530).

[0058]

[0059] 2) A step in which the platform operation server (150) requests the equipment development company to input test results (S540), a step in which the equipment development company performs a cybersecurity test (S550), a step in which the equipment development company inputs the cybersecurity test results into the platform operation server (150) through the equipment development terminal (120) (S560), and a step in which the platform operation server (150) receives the cybersecurity test results of the equipment from the equipment development company (S570).

[0060] When the platform operation server (150) requests the equipment developer to input test results (S540), the equipment developer can perform cybersecurity tests such as CS-FAT and CS-SAT (S550) and input the results of the performed cybersecurity tests into the platform operation server (150) via the equipment developer terminal (120) (S560). The platform operation server (150) can receive the results of the cybersecurity test of the equipment input by the equipment developer (S570).

[0061]

[0062] 3) A step for determining whether there is a change in the security vulnerability information of the equipment (S580), a step for linking and processing the security vulnerability information to the platform (200) and storing it in a recording device (S590), a step for updating and displaying the security vulnerability information recorded in the cybersecurity maturity provision unit (240) (S600), a step for receiving security status information through the shipyard terminal (110) and the shipowner terminal (130) through the cyber maturity provision unit (240) (S610).

[0063] Through the cybersecurity test results of the equipment received from the equipment developer (S570), it is possible to determine whether there is a change in the security vulnerability information of the equipment (S580).

[0064] If there is a change in the security vulnerability information of the equipment ('Yes' in S580), the security vulnerability information is linked and processed in the platform (200) and stored in the recording device (S590), and the security vulnerability information recorded in the cybersecurity maturity provision unit (240) can be updated and displayed (S600). The shipyard terminal (110) and the shipowner terminal (130) can receive the updated security status information through the cyber maturity provision unit (240) (S610), and the shipyard and the shipowner can check the updated security status information through the shipyard terminal (110) and the shipowner terminal (130), respectively.

[0065] If there is no change in the security vulnerability information of the equipment ('No' in S580), the shipyard terminal (110) and the shipowner terminal (130) can receive security status information through the cyber maturity provision unit (240) without updating the security vulnerability information (S610), and the shipyard and the shipowner can check the security status information through the shipyard terminal (110) and the shipowner terminal (130), respectively.

[0066]

[0067] 4) Step for determining whether there is a change in the process (S620)

[0068] By determining whether there is a change in the shipbuilding process (S620), if there is a change in the shipbuilding process ('Yes' in S620), new ship information is input into the platform operation server (150) through the shipyard terminal (110) (S510), and the above-described series of steps can be performed again.

[0069] That is, if there is a change in the shipbuilding process ('Yes' in S620), it is possible to check whether there is a change in the security vulnerability information of the equipment, and if there is a change in the security vulnerability information of the equipment, the security vulnerability information can be updated and provided to the shipyard and ship owner.

[0070]

[0071] The present invention can provide a trend in the maturity of cybersecurity of a ship under construction over time by continuously tracking the cybersecurity of the ship during the ship's construction stages, including the ship's design, construction, and test-run stages (i.e., as shown in FIG. 3, it can provide a time-series view of the level of cybersecurity at each point in time based on completed cybersecurity (100%)).

[0072] Since general security vulnerability checks and simulated hacking are difficult to perform during the ship trial run and launch stages due to physical environmental constraints, the present invention identifies security vulnerabilities in equipment installed on a ship in advance from the ship design and construction stages.

[0073] The present invention provides a visual representation of the cybersecurity maturity of a ship under construction, as illustrated in Figure 3, to enable shipowners and others to assess the ship's cybersecurity level over time. This allows shipowners and others to assess not only the current cybersecurity level, but also past and projected cybersecurity levels. According to the present invention, shipowners and others can use the visually presented cybersecurity maturity level to assess the current cybersecurity status, establish action plans accordingly, and manage cybersecurity by reflecting the results of the actions.

[0074] According to the present invention, by enabling the cybersecurity maturity of a ship to be managed through a cloud-based platform, data can be concentrated and accessibility of management entities can be increased.

[0075] According to the present invention, by providing the cybersecurity maturity of a ship over time during the design, construction, and commissioning stages of the ship, it is possible to comply with the ship's cybersecurity design standards and respond to smart ship security requirements based on international regulations.

[0076]

[0077] It is obvious to those skilled in the art that the present invention is not limited to the above embodiments, and that various modifications or variations can be made without departing from the technical spirit of the present invention.

Claims

1. A ship cybersecurity maturity management system that provides the ship's cybersecurity maturity over time through the cloud during the ship's design, construction, and commissioning stages.

2. In claim 1, A platform operation server that compares and analyzes one or more of the security information of the vessel, the security vulnerability information of the equipment mounted on the vessel, and the cybersecurity test information of the equipment mounted on the vessel; and A platform that receives comparative analysis results from the platform operation server and provides the level of cybersecurity of the ship according to changes in time during the design, construction, and commissioning stages of the ship; A cybersecurity maturity management system for ships, including:

3. In claim 2, A ship cybersecurity maturity management system further comprising a shipyard terminal that transmits one or more of the ship name, ship owner, classification, onboard equipment, and security status information of the ship from the shipyard to the platform operation server.

4. In claim 2, A ship cybersecurity maturity management system further comprising a PLM server that transmits BOM information of equipment mounted on the ship to the platform operation server.

5. In claim 2, A ship cybersecurity maturity management system further comprising a terminal for equipment development that transmits information about equipment installed on the ship from the equipment development company to the platform operation server.

6. In claim 2, A ship cybersecurity maturity management system further comprising a ship owner terminal that allows the ship owner to access the platform through the platform operation server.

7. In claim 2, The above platform, A ship cybersecurity maturity management system including a BOM data linkage unit that manages BOM data in conjunction with a PLM server.

8. In claim 2, The above platform, A ship cybersecurity maturity management system including a ship information processing unit that processes and analyzes information related to the ship and provides the results.

9. In claim 2, The above platform, A ship cybersecurity maturity management system including a ship information processing unit that processes and analyzes information related to ship equipment and provides the results.

10. In claim 2, The above platform, Cybersecurity plan for the above vessel; The current cybersecurity maturity of the above vessel; Past trends in the cybersecurity maturity of the above vessels; Future cybersecurity maturity of the above vessel; A ship cybersecurity maturity management system, comprising a cybersecurity maturity provision unit that analyzes one or more of the above and provides the results.

11. A method for managing cybersecurity maturity for a ship, which provides the cybersecurity maturity of the ship at one or more of the contract stage, basic design stage, detailed design stage, CS-FAT stage, CS-SAT stage, land trial stage, and sea trial stage of the ship.

12. In claim 11, Step of entering new ship information into the platform operation server through a shipyard terminal; A step in which the platform operation server receives BOM information of equipment from the PLM server through the BOM data linkage unit; and A step in which the ship information processing unit analyzes the security construction standards based on the new ship information entered; A method for managing cybersecurity maturity for ships, including:

13. In claim 11, The step where the platform operation server requests the equipment development company to input test results; The step where the above equipment development company performs cybersecurity testing; A step in which the above equipment development company inputs the cybersecurity test results into the platform operation server through the equipment development terminal; and A step in which the platform operation server receives the results of a cybersecurity test of the equipment from the equipment development company; A method for managing cybersecurity maturity for ships, including:

14. In claim 11, Includes a step of determining whether there is a change in the security vulnerability information of the equipment, A method for managing ship cybersecurity maturity, wherein when there is a change in equipment security vulnerability information, the platform links and processes the security vulnerability information and stores it in a recording device, updates and displays the security vulnerability information recorded in the cybersecurity maturity provision unit, and a shipyard terminal and a shipowner terminal receive updated security status information through the cyber maturity provision unit.

15. In any one of claims 11 to 14, A method for managing ship cybersecurity maturity, which checks whether there is a change in the security vulnerability information of equipment when there is a change in the above shipbuilding process, and if there is a change in the security vulnerability information of equipment, updates the security vulnerability information and provides it to the shipyard and ship owner.

Citation Information

Patent Citations

  • Block chain account anonymity mechanism application method and system based on ship design and manufacturing

    CN117910987A

  • Method for anode design in ship designing and system thereof

    KR1020130038040A

  • Interfloor noise mats that allow robot cleaners to enter

    KR1020250022350A

  • Cyber risk quantitative evaluation system for autonomous ship and method performing thereof

    KR102578059B1

  • Ship security server and ship security enhancement method thereof

    KR102596396B1