Maritime Vessel Security Context Management for Disconnection Handling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Maritime communication systems face challenges such as authentication and authorization storms due to disconnections between vessels, limited satellite network speed, and non-compliance with national jurisdictions, leading to inefficiencies and security vulnerabilities.
Innovation Solution
A method involving a management server that predicts future vessel locations to anticipate disconnections, obtains security information before disconnections occur, and performs authorization processes upon reconnection, using blockchain for identity proof and machine learning for location prediction, reducing signaling overhead and enhancing security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If maritime vessels use traditional authentication and authorization processes upon reconnection, then security is maintained, but authentication and authorization storms occur causing network overload and delays
Solution Approach 1:
The system performs authentication and authorization actions in advance before disconnection occurs. The network device stores security context information (including authentication credentials and authorization data) locally before the vessel disconnects. When reconnection happens, the pre-stored security context is directly applied without requiring full authentication cycles, thus preventing authentication storms while maintaining security.
2Reliability
If maritime vessels maintain continuous connection to terrestrial networks, then communication reliability is improved, but vessels cannot take advantage of other maritime vessels in close proximity for more cost effective communication
Solution Approach 1:
The system dynamically switches between different communication modes based on real-time conditions. Vessels can transition between direct terrestrial network connection, relay through other maritime vessels, or satellite connection. The network device tracks vessel locations and connection states, automatically selecting the optimal communication path. This dynamic adaptability allows vessels to use cost-effective maritime-to-maritime communication when appropriate while maintaining reliable terrestrial connection when needed.
3Area of stationary object
If satellite networks are used for maritime communication when out of range of terrestrial networks, then coverage is improved, but high speed service like file transfer or video cannot be provided
Solution Approach 1:
The system uses other maritime vessels as intermediary relay nodes. When a vessel is in satellite-only mode, it can establish data transfer paths through intermediate vessels that have better connection quality to the terrestrial network. The intermediary vessels forward data packets, effectively creating a multi-hop communication path that combines satellite coverage with terrestrial network speed advantages.
4Reliability
If maritime vessels perform standard authentication processes upon reconnection, then security compliance is maintained, but signaling overhead increases causing delays
Solution Approach 1:
The system extracts and stores only the essential security context information (authentication credentials and authorization data) locally in the network device before disconnection. When reconnection occurs, only this extracted minimal security context needs to be validated rather than performing complete authentication sequences. This extraction approach maintains security compliance by preserving critical security data while eliminating time-consuming authentication steps.
Data Source
AI summary
A management server predicts future locations of a plurality of maritime vessels based on historical status information of the plurality of maritime vessels. The plurality of maritime vessels include a first maritime vessel and a second maritime vessel. The first maritime vessel is communicatively connected to a terrestrial network via the second maritime vessel. The management server determines whether a disconnection between the first and second maritime vessels is to occur, based on the predicted future locations of the first and second maritime vessels. In response to determining that the disconnection is to occur, the management server obtains, from the first maritime vessel, security related information of the first maritime vessel before the disconnection occurs. When the first maritime vessel reconnects to the terrestrial network, the management server performs a first authorization process for the first maritime vessel based on the obtained security related information of the first maritime vessel.


