Maritime Vessel Security Context Management for Disconnection Handling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Maritime communication systems face challenges such as authentication and authorization storms due to disconnections between vessels, limited satellite network speed, and non-compliance with national jurisdictions, leading to inefficiencies and security vulnerabilities.

Innovation Solution

A method involving a management server that predicts future vessel locations to anticipate disconnections, obtains security information before disconnections occur, and performs authorization processes upon reconnection, using blockchain for identity proof and machine learning for location prediction, reducing signaling overhead and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If maritime vessels use traditional authentication and authorization processes upon reconnection, then security is maintained, but authentication and authorization storms occur causing network overload and delays

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs authentication and authorization actions in advance before disconnection occurs. The network device stores security context information (including authentication credentials and authorization data) locally before the vessel disconnects. When reconnection happens, the pre-stored security context is directly applied without requiring full authentication cycles, thus preventing authentication storms while maintaining security.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If maritime vessels maintain continuous connection to terrestrial networks, then communication reliability is improved, but vessels cannot take advantage of other maritime vessels in close proximity for more cost effective communication

Engineering Contradiction:
Improvecommunication reliabilityVSAvoidcommunication flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system dynamically switches between different communication modes based on real-time conditions. Vessels can transition between direct terrestrial network connection, relay through other maritime vessels, or satellite connection. The network device tracks vessel locations and connection states, automatically selecting the optimal communication path. This dynamic adaptability allows vessels to use cost-effective maritime-to-maritime communication when appropriate while maintaining reliable terrestrial connection when needed.

Inventive Principle:
Principle #15Dynamics

3Area of stationary object

If satellite networks are used for maritime communication when out of range of terrestrial networks, then coverage is improved, but high speed service like file transfer or video cannot be provided

Engineering Contradiction:
Improvecoverage areaVSAvoiddata transmission speed
Core Design Contradiction:
Area of stationary objectVSSpeed

Solution Approach 1:

The system uses other maritime vessels as intermediary relay nodes. When a vessel is in satellite-only mode, it can establish data transfer paths through intermediate vessels that have better connection quality to the terrestrial network. The intermediary vessels forward data packets, effectively creating a multi-hop communication path that combines satellite coverage with terrestrial network speed advantages.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If maritime vessels perform standard authentication processes upon reconnection, then security compliance is maintained, but signaling overhead increases causing delays

Engineering Contradiction:
Improvesecurity complianceVSAvoidreconnection time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system extracts and stores only the essential security context information (authentication credentials and authorization data) locally in the network device before disconnection. When reconnection occurs, only this extracted minimal security context needs to be validated rather than performing complete authentication sequences. This extraction approach maintains security compliance by preserving critical security data while eliminating time-consuming authentication steps.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS20230345242A1Methods and apparatuses for security in maritime communication
Publication Date: 2023.10.26 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US20230345242A1 patent drawing
  • US20230345242A1 patent drawing
  • US20230345242A1 patent drawing

AI summary

A management server predicts future locations of a plurality of maritime vessels based on historical status information of the plurality of maritime vessels. The plurality of maritime vessels include a first maritime vessel and a second maritime vessel. The first maritime vessel is communicatively connected to a terrestrial network via the second maritime vessel. The management server determines whether a disconnection between the first and second maritime vessels is to occur, based on the predicted future locations of the first and second maritime vessels. In response to determining that the disconnection is to occur, the management server obtains, from the first maritime vessel, security related information of the first maritime vessel before the disconnection occurs. When the first maritime vessel reconnects to the terrestrial network, the management server performs a first authorization process for the first maritime vessel based on the obtained security related information of the first maritime vessel.