802.1x authentication method for ship network access control
By installing a socket proxy on CBSs to perform 802.1x authentication, the method addresses security vulnerabilities and management inefficiencies, enhancing network security and operational efficiency in ship networks.
Patent Information
- Application Number
- PCT/KR2025/022132
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-12-18
- Filing Date
- 2025-12-18
- Publication Date
- 2026-06-25
AI Technical Summary
Existing ship network access control methods are vulnerable to security breaches due to password leakage and MAC address tampering, and CBSs that do not support 802.1x cannot implement port-based authentication without manufacturer changes.
Install a socket acting as a proxy for 802.1x on the network interface of CBSs to perform port-based authentication without installing an agent, enabling strong authentication through various mechanisms.
Enhances network security and management efficiency by configuring a secure ship network environment even on CBSs that do not support 802.1x, providing strong authentication and efficient access control.
Smart Images

Figure KR2025022132_25062026_PF_FP_ABST
Abstract
Description
802.1X Authentication Method for Ship Network Access Control
[0001] The present invention relates to an 802.1x authentication method for ship network access control that enhances network security of a ship by providing strong authentication through support for various authentication mechanisms, and increases management and operational efficiency.
[0002] In ship networks, it is common to control access using fixed passwords.
[0003] This method is vulnerable to security breaches, and issues regarding access permission may arise due to password leakage.
[0004] In addition, while some networks use MAC addresses to control access to specific devices, MAC addresses can be easily tampered with and may not be efficient in terms of management and maintenance.
[0005] The 802.1x protocol, which is used as a wired and wireless authentication method, allows only terminals authenticated by the L2 switch to connect to the network through port-based authentication.
[0006] However, while L2 switch-based Port-based authentication has the advantage of preventing unauthenticated CBSs from accessing the ship network, for 802.1x implementation, the CBS must install an agent that supports the 802.1x authentication method or support the 802.1x protocol itself.
[0007] Therefore, the method of installing an agent on a CBS is impossible without changing the CBS manufacturer, and there is a problem that this method cannot be applied to CBSs that do not support 802.1x.
[0008] A related prior art is Korean registered patent 10-2463051 (2022.11.03.).
[0009] The objective of the present invention is to provide an 802.1x authentication method for ship network access control that can configure a secure ship network environment by installing a socket acting as a proxy for 802.1x on the network interface of the CBS without installing an agent on the CBS and by performing port-based 802.1x even on a CBS that does not support 802.1x.
[0010] An 802.1x authentication method for ship network access control according to the present invention for achieving the above technical objective comprises, in an authentication method for ship network access control, a Computer Based System (CBS), an authenticator, and an authentication server, wherein a socket acting as an agent for 802.1x is installed and provided on the network interface of the CBS, and wherein the CBS (Computer Based System) intending to access the ship network transmits a connection request to the socket; a step of receiving the connection request at the socket and transmitting the connection request to the authenticator; a step in which the authenticator transmits an ID request to the socket in response to the connection request; a CBS ID transmission step in which the socket transmits a CBS ID to the authenticator in response to the ID request; a step in which the authenticator receives the CBS ID and transmits the CBS ID to the authenticator server; a step in which the authenticator server receives the CBS ID and transmits a password request to the authenticator; a step in which the authenticator receives the password request and transmits it to the socket; a step in which the socket transmits a password response to the password request to the authenticator; a step in which the authenticator transmits the password response to the authentication server; and a password verification step in which the authentication server verifies the password in response to the password response. The authentication server is characterized by allowing access to the CBS vessel network only when the password is verified in the password verification step.
[0011] In addition, the 802.1x authentication method for ship network access control according to the present invention is characterized by being able to perform authentication by performing port-based 802.1x even if the CBS does not support 802.1x.
[0012] According to the present invention, even if a CBS does not support 802.1x, it is possible to configure a secure ship network environment by performing port-based 802.1x without installing an agent on the CBS and installing a socket that acts as a proxy for 802.1x on the network interface of the CBS.
[0013] In addition, according to the present invention, by providing strong authentication through support for various authentication mechanisms, it has the effect of strengthening the network security of a vessel and increasing management and operational efficiency.
[0014] Figure 1 is a diagram showing the configuration of a typical 802.1x authentication mechanism.
[0015] FIG. 2 is a diagram showing a state in which a socket acting as an 802.1x proxy is installed and provided on the network interface of a CBS in an 802.1x authentication method for ship network access control according to the present invention.
[0016] FIG. 3 is a diagram showing the flow of an 802.1x authentication method for ship network access control according to the present invention.
[0017] Detailed information regarding the purpose, technical configuration, and the resulting operation and effects of the present invention will be more clearly understood through the detailed description based on the drawings attached to the specification of the present invention.
[0018] The terms used in this specification are used merely to describe specific embodiments and are not intended to limit the invention. For example, terms such as "composed of" or "comprising" used in this specification should not be interpreted as necessarily including all of the various components or steps described in the invention, but should be interpreted as excluding some of the components or steps, or potentially including additional components or steps. Furthermore, singular expressions used in this specification include plural expressions unless the context clearly indicates otherwise.
[0019] The present invention will be described in detail below by explaining preferred embodiments with reference to the attached drawings. The embodiments described below are provided to enable those skilled in the art to easily understand the technical concept of the present invention, and should not be interpreted as limiting the present invention; it is obvious to those skilled in the art that the embodiments of the present invention can have various applications.
[0020] First, looking at the configuration of the 802.1x authentication mechanism as shown in Fig. 1, 802.1x refers to an authentication structure that enables port-based access control.
[0021] 802.1x has the advantage of being able to utilize all existing and new certification systems and infrastructure as is.
[0022] It can be used in all wired and wireless networks and can provide user authentication for each port based on user authentication.
[0023] In addition, 802.1x can perform authentication at the physical port level within the switch for wired connections and at the combined level between the access point (AP) and the wireless terminal for wireless connections.
[0024] The physical components of 802.1x may consist of an authenticator that controls network access, such as a bridge, switch, or access point, which connects a supervisant attempting to access the network with the supervisant and the authentication server, and an authentication server that verifies the authentication of the authentication request and makes a decision to allow or restrict access.
[0025] In other words, authentication exchange takes place between the authentication requester and the authentication server, and the authenticator acts only as a bridge.
[0026] FIG. 2 is a diagram showing a state in which a socket acting as an 802.1x proxy is installed and provided on the network interface of a CBS in an 802.1x authentication method for ship network access control according to the present invention.
[0027] That is, by providing a socket between the CBS and the authenticator, a socket acting as a proxy for 802.1x is installed on the network interface of the CBS to configure a secure ship network environment by performing port-based 802.1x even if the CBS does not support 802.1x, without installing an agent on the CBS.
[0028] This provides strong authentication through the support of various authentication mechanisms, thereby enhancing the network security of vessels and increasing management and operational efficiency.
[0029] FIG. 3 is a diagram showing the flow of an 802.1x authentication method for ship network access control according to the present invention.
[0030] Referring to FIG. 3, the 802.1x authentication method for ship network access control is composed of a CBS (Computer Based System, 110), an authenticator (130), and an authentication server (140), and a socket (120) acting as an 802.1x agent may be installed and provided on the network interface of the CBS.
[0031] The method comprises the following steps: transmitting a connection request to a socket from a Computer Based System (CBS) attempting to access a ship network (S110); receiving the connection request from the socket and transmitting the connection request to an authenticator (S120); the authenticator transmitting an ID request to the socket in response to the connection request (S130); transmitting a CBS ID from the socket to the authenticator in response to the ID request (S121); the authenticator receiving the CBS ID and transmitting the CBS ID to an authenticator server (S132); the authenticator server receiving the CBS ID and transmitting a password request to the authenticator (S140); the authenticator receiving the password request and transmitting it to the socket (S133); the socket transmitting a password response to the password request to the authenticator (S124); the authenticator transmitting the password response to an authentication server (S135); and the authentication server verifying the password in response to the password (S146). The authentication server (140) establishes a connection only when the password is verified in the password verification step (S146). It is characterized by allowing CBS to access the ship network by permitting (S137, S128, S119).
[0032] That is, when the password is verified in the password verification step (S146), the authentication server (140) transmits the connection permission to the authenticator (S137), the authenticator transmits it to the socket (S128), and the socket transmits the connection permission to the CBS (S119) to enable the CBS to connect to the ship network.
[0033] Additionally, the authentication server (140) blocks access if the password is not verified in the password verification step (S146).
[0034] Accordingly, according to the present invention, even if a CBS does not support 802.1x, port-based 802.1x is performed without installing an agent on the CBS, and a socket acting as a proxy for 802.1x is installed on the network interface of the CBS, thereby enabling the configuration of a secure ship network environment.
[0035] In addition, according to the present invention, by providing strong authentication through support for various authentication mechanisms, it has the effect of strengthening the network security of a vessel and increasing management and operational efficiency.
[0036] The embodiments according to the present invention described above may be implemented in the form of program instructions that can be executed through various computer components and recorded on a computer-readable recording medium. The computer-readable recording medium may include program instructions, data files, data structures, etc., either individually or in combination. The program instructions recorded on the computer-readable recording medium may be those specifically designed and configured for the present invention or those known and available to those skilled in the art of computer software. Examples of computer-readable recording media include magnetic media such as hard disks, floppy disks, and magnetic tapes; optical recording media such as CD-ROMs and DVDs; magneto-optical media such as floptical disks; and hardware devices specifically configured to store and execute program instructions, such as ROM, RAM, and flash memory. Examples of program instructions include machine code, such as that generated by a compiler, as well as high-level language code that can be executed by a computer using an interpreter, etc. Hardware devices may be modified into one or more software modules to perform processing according to the present invention, and vice versa.
[0037] The embodiments described above are provided to enable those skilled in the art to easily understand the technical concept of the present invention, and should not be interpreted as limiting the present invention. It is obvious to those skilled in the art that the embodiments of the present invention can be modified and varied in various ways without departing from the spirit and scope of the present invention. Accordingly, such modifications or variations should be deemed to fall within the scope of the claims of the present invention.
[0038] 110: CBS (Computer Based System)
[0039] 120: Socket
[0040] 130: Authenticator
[0041] 140: Authentication Server
Claims
1. In an authentication method for ship network access control, It is composed of a CBS (Computer Based System), an authenticator, and an authentication server, wherein a socket acting as an 802.1x proxy is installed and provided on the network interface of the CBS, A step of sending a connection request via a socket from a CBS (Computer Based System) attempting to access the ship network; A step of receiving the above connection request from the socket and transmitting the connection request to the authenticator; The authenticator sends an ID request to the socket in response to the above connection request; A CBS ID transmission step of transmitting a CBS ID from a socket to an authenticator in response to the above ID request; The authenticator receives the CBS ID and transmits the CBS ID to the authenticator server; The authenticator server receives the CBS ID and transmits a password request to the authenticator; The authenticator receives the above password request and transmits it to the socket; The socket transmits a password response to the above password request to the authenticator; The authenticator transmits the above-mentioned password response to the authentication server; and The authentication server includes a password verification step that verifies the password for the above password response; An 802.1x authentication method for ship network access control, wherein the authentication server allows access only when the password is verified in the password verification step, thereby allowing CBS to access the ship network.
2. In Claim 1, An 802.1x authentication method for ship network access control that performs port-based 802.1x authentication even if the CBS does not support 802.1x.