Remote Vessel Control Using One-Way Ethernet Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Remote control of vessels, such as maritime and other vehicles, is highly susceptible to cyberattacks due to external access through computer networks, with conventional software-based protection systems becoming increasingly penetrable, posing significant risks and operational disruptions.

Innovation Solution

Implementing a one-way Ethernet cable communication system between a switch and a remote control computing device on the vessel, which prevents hacker-driven feedback signals and malware from accessing onboard command and control systems, combined with encryption using dynamically generated keys based on vessel data to enhance security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If remote control of vessels is implemented via computer networks, then operational control and monitoring capabilities are improved, but vulnerability to cyberattacks and malware infiltration increases

Engineering Contradiction:
Improveremote control capabilityVSAvoidcyberattack susceptibility
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

A one-way Ethernet cable is introduced as an intermediary component between the remote control computing device and the vessel's internal network. This cable allows control signals to flow from the remote device to the vessel while blocking any reverse communication, thereby enabling remote control functionality while preventing malware and feedback signals from infiltrating the vessel's command and control systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The communication architecture is segmented into separate unidirectional pathways. Control signals are transmitted through a dedicated one-way Ethernet cable that physically isolates the remote control device from the vessel's internal network, creating distinct communication zones that prevent cross-contamination of malicious software while maintaining operational control.

Inventive Principle:
Principle #1Segmentation

2Loss of information

If traditional two-way communication systems are used for remote control, then bidirectional data exchange and feedback are improved, but security against port sniffing and feedback signal interception deteriorates

Engineering Contradiction:
Improvefeedback signal transmissionVSAvoidport sniffing vulnerability
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The traditional two-way communication model is inverted to a one-way communication model. Instead of allowing bidirectional data flow between the remote control device and the vessel's network, the system uses a one-way Ethernet cable that permits only outbound control signals while completely blocking inbound feedback signals, thereby eliminating port sniffing vulnerabilities while maintaining essential control functionality.

Inventive Principle:
Principle #13The other way round (Inversion)

3Reliability

If software-based encryption protection is implemented, then data security is improved, but penetrability to sophisticated attackers deteriorates

Engineering Contradiction:
Improvedata protection capabilityVSAvoidencryption breaking risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The one-way Ethernet cable serves as a physical intermediary that complements software-based encryption. While encryption protects data at the software level, the one-way cable provides hardware-level protection by physically blocking attack vectors such as port sniffing and feedback signal interception, creating a layered security approach that is significantly more resistant to sophisticated attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements preemptive security measures by using a one-way Ethernet cable that inherently blocks malicious feedback signals and port sniffing attempts before they can reach the vessel's command and control systems. This physical barrier provides beforehand protection that supplements software encryption and prevents attackers from even attempting to breach encryption algorithms.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Data Source

PatentUS11316834B2System and associated methods for remote control of vessels
Publication Date: 2022.04.26 C INNOVATION LLC
  • US11316834B2 patent drawing
  • US11316834B2 patent drawing
  • US11316834B2 patent drawing

AI summary

A machine and process for remotely controlling a vessel. The system may include a land-based computing system configured to communicate control signals via a communications system that communicates the control signals to the vessel and a controller network on the vessel configured to control at least certain functions of the vessel. The controller network may further be configured to receive the control signals from the land-based computing system. The controller may include a switch including an input port and multiple output ports. A remote control computing device may be configured to control the vessel via at least one other computing device. A one-way Ethernet cable may be communicatively coupled between one of the output ports of the switch and the remote control computing device. The control signals may be received by the switch being communicated to the remote control computing device via the one-way Ethernet cable.