Ship Network Security via User Authentication Packet Classification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security systems for ship networks lack efficient differential security services, particularly in controlling access rights and providing tailored security services based on packet security classes, sensitivities, and sources, leading to inefficiencies in redundant checks and limited resource management.

Innovation Solution

The implementation of a method and apparatus for providing differential security services using user authentication-based packet classification and open authorization (OAuth), which enables effective control of system access rights and provision of differential security services by verifying ID tokens and setting session cookies, thereby improving the efficiency of redundant checks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If conventional security systems are used in ship networks, then basic security protection is provided, but differential security services for different user classes cannot be provided and redundant checks occur

Engineering Contradiction:
Improvedifferential security servicesVSAvoidsystem efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The security system segments users into different classes (first user class and second user class) based on their authentication credentials. First user terminals receive first security services with relaxed security checks, while second user terminals receive second security services with stringent security checks. This segmentation enables differential security services tailored to different user requirements, improving system efficiency by avoiding redundant checks for authenticated users while maintaining high security for unauthenticated users.

Inventive Principle:
Principle #1Segmentation

2Reliability

If stringent security checks are performed for all users, then high security is maintained, but system efficiency decreases due to redundant checks

Engineering Contradiction:
Improvesecurity levelVSAvoidsystem efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system applies different security check intensities to different user classes locally. First user terminals (authenticated users) experience relaxed security checks with faster processing, while second user terminals (unauthenticated users) undergo stringent security checks. This local differentiation of security quality ensures high security where needed while improving overall system efficiency by reducing redundant checks for authenticated users.

Inventive Principle:
Principle #3Local quality

3Reliability

If multiple security services are provided for all packets, then comprehensive security coverage is achieved, but resource consumption increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system applies partial security services selectively based on user class. First user terminals receive a subset of security services (relaxed checks) while second user terminals receive comprehensive security services (stringent checks). This partial application of security services ensures comprehensive security coverage for unauthenticated users while reducing resource consumption by providing only necessary security services to authenticated users.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20250193010A1Method and apparatus for providing differential security services for ship networks using user authentication-based packet classification
Publication Date: 2025.06.12 PENTA SECURITY SYST INC
  • US20250193010A1 patent drawing
  • US20250193010A1 patent drawing
  • US20250193010A1 patent drawing

AI summary

A method of providing differential security services for a ship network by a service provider connected to a client performing the differential security services may comprise: receiving a service request from a user terminal by an authentication performing unit of a service provider including a processor; returning or issuing, by the authentication performing unit, an ID token and an authentication code to the user terminal in response to the service request; receiving, by the client, the ID token and the authentication code from the user terminal; verifying, by the client, validity of the ID token; setting, by the client, a session cookie for the service request when the validity is verified; transmitting, by the client, an access token request including the authentication code to a token issuing unit of the service provider; and receiving, by the client, an access token from the token issuing unit.