Ship Network Security via User Authentication Packet Classification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security systems for ship networks lack efficient differential security services, particularly in controlling access rights and providing tailored security services based on packet security classes, sensitivities, and sources, leading to inefficiencies in redundant checks and limited resource management.
Innovation Solution
The implementation of a method and apparatus for providing differential security services using user authentication-based packet classification and open authorization (OAuth), which enables effective control of system access rights and provision of differential security services by verifying ID tokens and setting session cookies, thereby improving the efficiency of redundant checks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If conventional security systems are used in ship networks, then basic security protection is provided, but differential security services for different user classes cannot be provided and redundant checks occur
Solution Approach 1:
The security system segments users into different classes (first user class and second user class) based on their authentication credentials. First user terminals receive first security services with relaxed security checks, while second user terminals receive second security services with stringent security checks. This segmentation enables differential security services tailored to different user requirements, improving system efficiency by avoiding redundant checks for authenticated users while maintaining high security for unauthenticated users.
2Reliability
If stringent security checks are performed for all users, then high security is maintained, but system efficiency decreases due to redundant checks
Solution Approach 1:
The system applies different security check intensities to different user classes locally. First user terminals (authenticated users) experience relaxed security checks with faster processing, while second user terminals (unauthenticated users) undergo stringent security checks. This local differentiation of security quality ensures high security where needed while improving overall system efficiency by reducing redundant checks for authenticated users.
3Reliability
If multiple security services are provided for all packets, then comprehensive security coverage is achieved, but resource consumption increases
Solution Approach 1:
The system applies partial security services selectively based on user class. First user terminals receive a subset of security services (relaxed checks) while second user terminals receive comprehensive security services (stringent checks). This partial application of security services ensures comprehensive security coverage for unauthenticated users while reducing resource consumption by providing only necessary security services to authenticated users.
Data Source
AI summary
A method of providing differential security services for a ship network by a service provider connected to a client performing the differential security services may comprise: receiving a service request from a user terminal by an authentication performing unit of a service provider including a processor; returning or issuing, by the authentication performing unit, an ID token and an authentication code to the user terminal in response to the service request; receiving, by the client, the ID token and the authentication code from the user terminal; verifying, by the client, validity of the ID token; setting, by the client, a session cookie for the service request when the validity is verified; transmitting, by the client, an access token request including the authentication code to a token issuing unit of the service provider; and receiving, by the client, an access token from the token issuing unit.


