期刊文献+

IHO S-63数据保护方案潜在风险 被引量:1

Potential Risks of IHO S-63 Data Protection Scheme
下载PDF
导出
摘要 针对IHO 2012年4月颁布的S-63电子海图数据保护方案及其策略结构与工作流程,从3个方面分析该方案的潜在风险,即:设备制造商开发的软件可能跳过S-63标准规定的数字签名验证环节;数据服务商提供的海图许可文件的权威性无法保证;设备制造商可解密出符合S-57标准的电子海图数据,从而非授权传播。这些潜在风险直接威胁到海图数据的完整性和权威性,会给导航安全带来极大的隐患。对此,提出相应的风险控制方案改进建议并给出改进后的实现流程。试验结果证明,改进方案可行,为完善S-63数据保护方案提供了科学参考。 In April 2012 IHO published new version of S-63 data protection scheme. Potential risks are discovered through analyzing the strategy structure and the operating procedures of the scheme : No. 1, the equipment manufacturers may deve- lop systems which ignore the digital signature authentication specified in the S-63. No. 2, there is no mechanism to prevent unauthorized information from data suppliers. No. 3, S-63 data can be decoded and transformed into S-57 data, which e- quipment manufacturers may make unauthorized delivery of. These problems threaten the integrity and authority of ENC da- ta, hence, the navigation safety. An improved process flow is suggested. Tests show that the improved process flow is feasi- ble. This study can stimulate improvement of the S-63 Data Protection Scheme.
出处 《中国航海》 CSCD 北大核心 2015年第1期4-8,共5页 Navigation of China
基金 国家高技术研究发展计划("八六三"计划)子课题(2009AA045003) 国家自然科学基金(51309041) 中央高校基本科研业务费(3132013015)
关键词 船舶工程 S-63 电子海图 数据保护方案 潜在风险 S-63 ship engineering S-63 Electronic Navigational Chart Data Protection Scheme potential risk
  • 相关文献

参考文献9

  • 1International Hydrographic Bureau. IHO S-63 Edition 1.1.1 : Data Protection Scheme [ EB/OL]. (2012-04- 12) [2013-12-12].
  • 2DPSWG. IHO S-63 Edition 1. 1. 1: OEM Agreement [ EB/OL]. (2012-04-18) [2013-12-12]. http ://www. iho. int/svrl/.
  • 3DPSWG. IHO S-63 Edition 1.1.1 : Data Server Agree-merit [ EB/OL]. (2012-04-18) [2013-12-12]. http ://www. iho. int/svrl/.
  • 4SCHNEIER B. Blowfish Eneryption Algorithm, Fast Software Eneryption[ C ]. Cambridge Security Workshop Proceedings, 1993.
  • 5International Hydrographic Bureau. IHO S-57 Edition 3.1 :IHO Transfer Standard for Digital Hydrographic Da- ta [ EB/OL]. (2000-11-01) [2000-11-013. http ://www. iho. int/svrl/.
  • 6National Institute of Standard and Technology. NIST FIPS PUB 180-1, Secure Hash Standard [ S ]. Washing- ton DC : Department of Commerce, NIST, 1995.
  • 7National Institute of Standards and Technology. NIST FIPS PUB 186, Digital Signature Standard [ S ]. Wash- ington DC: Department of Commerce, NIST, 1994.
  • 8International Hydrographic Bureau. IHO S-63 Edition 1.1.1 : S-63 SA Certificate [ EB/OL]. (2012-04-12) [ 2013-t2-123. http ://www. iho. int/svrl/.
  • 9张勇,莫红飞,刘扬.IHO S63数据保护策略在电子海图系统中的应用[J].信息网络安全,2011(11):42-45. 被引量:3

二级参考文献9

  • 1IEC61174-2008,海上导航和无线电通信设备和系统一电子海图显示和信息系统一操作和性能需求,测试方法和要求的测试结果[S].
  • 2中国海事局.国内航行船舶船载电子海图系统(ECS)功能、性能和测试要求(暂行)[EB/OL].http://wwwmoc.gov.cn/zizhan/zhishujigc,u/haishiju/guanlipindao/guanfiwenjian/201002/P02(H(1f)224356441569227pdf.2010-02-09/2011-10-13.
  • 3International Hydrographic Bureau. IHO S-63 Edition 1.1: Data Protection Scheme[EB/OL], http://www.iho.shom.fr/, 2003/2(111-10-13.
  • 4B. Schneier. Fast Software Encryption[M]. Cambridge Security Workshop Proceedings (December 1993), Springer-Verlag, 1994. 191-204.
  • 5FIPS Pub 186. Digital Signature Standard (DSS)[EB/OL]. http://www. itl.nist.gov/div897/pubs/fip 186.htm, 1994-03-19/2011-10-13.
  • 6M.Thompson, A. Essiari, S. Mudumbai. ACM Transactions on Infomation and System Security (TISSEC)[J]. Certificate-based Authorization Policy in a PKI Environment. Volume 6, Issue 4, November 2003, 566-588.
  • 7Secure Hash Standard (SHA)(FIPS Pub 180-1)[EB/OLI. http://www. itl.nist.gov/div897/!oubs/fip 180-1 .htm, 1995-04-17/2011 - 10-26.
  • 8ISO/IEC 13239:2002, CRC32 checksum algorithm. Information technology -- Telecommunications and information exchange between systems -- High-level data link control (HDLC) procedures[S].
  • 9S57 edition 3.1, Transfer Standard for Digital Hydrographic Data[S].

共引文献2

同被引文献30

引证文献1

二级引证文献15

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部