Ship Network Packet Classification via User Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security systems in ship networks face inefficiencies due to redundant checks and limited resources, necessitating improved cybersecurity solutions that provide differentiated security services based on user classifications and packet sensitivity.

Innovation Solution

A user authentication-based packet classification method and apparatus that utilizes open standard protocols for authorization, including a processor to receive and process authorization and access token requests, reference a user class management table for differentiated security services, and apply priority queue processing to optimize packet handling.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If comprehensive security services are provided to all network packets, then security coverage is improved, but system resource consumption increases and operational efficiency decreases

Engineering Contradiction:
Improvesecurity coverageVSAvoidoperational efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments network packets into different categories based on user authentication results and packet characteristics. By dividing the security processing into different queues (high-priority and low-priority) and applying different security service levels to different segments, the system achieves both comprehensive security coverage and improved operational efficiency through differentiated processing

Inventive Principle:
Principle #1Segmentation

2Reliability

If all packets undergo identical security checks, then security consistency is improved, but resource waste increases due to redundant checks

Engineering Contradiction:
Improvesecurity consistencyVSAvoidresource waste
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent implements local quality by providing different security service levels to different packets based on their characteristics and user authentication results. High-priority packets receive comprehensive security checks while low-priority packets receive streamlined processing, eliminating redundant checks for packets that don't require full security validation

Inventive Principle:
Principle #3Local quality

3Reliability

If security gateway processes all packets with full authentication, then security level is improved, but processing speed decreases

Engineering Contradiction:
Improvesecurity levelVSAvoidprocessing speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent performs preliminary user authentication and packet classification before full security processing. By pre-categorizing packets into priority queues based on initial authentication results and packet characteristics, the system prepares the processing structure in advance, enabling faster subsequent processing while maintaining security levels

Inventive Principle:
Principle #10Preliminary action

4Productivity

If differentiated security services are implemented, then operational efficiency is improved, but system complexity increases

Engineering Contradiction:
Improveoperational efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements dynamic packet classification and priority queue assignment based on real-time user authentication results and packet characteristics. The system dynamically adjusts security service levels and processing priorities rather than using static rules, improving operational efficiency while managing complexity through adaptive rather than rigid differentiation

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20240163278A1Method and apparatus for classifying packets based on user authentication for differential security service in ship networks
Publication Date: 2024.05.16 PENTA SECURITY SYST INC
  • US20240163278A1 patent drawing
  • US20240163278A1 patent drawing
  • US20240163278A1 patent drawing

AI summary

Disclosed is a user authentication-based packet classification method and apparatus for providing differentiated security services in a ship network. A user authentication-based packet classification method includes receiving an authorization code request message from a user terminal including a client, authenticating and authorizing a user of the client based on the authorization code request message, transmitting an authorization code response message to the user terminal in response to the authorization code request message, receiving an access token request message from the user terminal based on the authorization code response message, and transmitting an access token response message including an access token to the user terminal in response to the access token request message.