研究生: 胡若家
Jo-Chia Hu
論文名稱: AIS 階層式的船舶識別和認證框架
Hierarchical Vessel Identification and Authentication Framework for AIS
指導教授: 黃政嘉
Jheng-Jia Huang
口試委員: 林志學
學位類別: 碩士
系所名稱: 管理學院 - 資訊管理系
Department of Information Management
論文出版年: 2024
畢業學年度: 112
語文別: 英文
論文頁數: 109
中文關鍵詞: 階層式架構AIS匿名化超平面群認證
外文關鍵詞: Hierarchical framework, AIS, Anonymization, Hyperplane group authentication
相關次數: 點閱:161下載:0
  • 為了更好地管理海上交通,大多數管理組織機構使用船舶交通管理系統(VTS)。在這些系統中,有一種船舶自動識別系統(AIS)用於船對船通訊,主要使用 AIS 收發機將船舶自身的訊息廣播到附近的 AIS 收發機。由於此訊息是以明文方式廣播的,攻擊者可以輕易地篡改或進行其他攻擊。由於海洋環境的限制,船舶的計算資源有限,因此有必要盡可能降低計算成本,但同時也必須考慮船對船認證在安全性方面的重要性。因此,本論文提出了一種結合對稱加密和非對稱加密的階層式認證和通訊配對協議框架,並透過這個階層式框架建立了一個安全的認證機制。我們提出匿名化航行船舶的身份,以保護其真實身份(例如 MMSI)不被攻擊者竊取。此外,我們提出了一種新的超平面認證方法,可以快速認證群內成員,以實現對其他船舶合法性的有效快速驗證。

    To better manage maritime traffic, most management organization agencies use vessel traffic management systems (VTS). Among these, there is an Automatic Identification System (AIS) for vessel-to-vessel communication, which mainly uses AIS transceivers to broadcast their own vessel information to nearby AIS transceivers. Since the information is broadcast in plaintext, attackers can easily tamper with it or perform other attacks. Due to the constraints of the maritime environment, vessels have limited computational resources, so it is necessary to reduce their computing costs as much as possible, but at the same time, the importance of vessel-to-vessel authentication in terms of safety must also be considered. Therefore, this paper proposes a hierarchical framework of authentication and communication pairing protocol that combines symmetric encryption and asymmetric encryption and establishes a secure authentication mechanism through this hierarchical framework. We propose to anonymize the identity of the sailing vessels to protect their real identities (e.g. MMSI) from being stolen by attackers. Additionally, we propose a new hyperplane authentication method that can quickly authenticate members within a group to achieve effective and rapid verification of the legitimacy of the other vessel.

    Recommendation Letter i Approval Letter ii 論文摘要 iii Abstract iv Acknowledgements v Contents vi List of Figures ix List of Tables xi 1 Introduction 1 1.1 Background and Motivation 1 2 Preliminaries 8 2.1 HyperPlane 9 2.2 Hash chain 10 2.3 Elliptic Curve Digital Signature Algorithm 11 2.4 Elliptic Curve Diffie-Hellman key exchange 12 2.5 Security Definitions 13 3 Related Works 25 3.1 Aziz et al.'s scheme 25 3.2 Jegadeesan et al.'s scheme 29 3.3 Chen et al.'s scheme 32 4 Proposed Scheme 36 4.1 System model 36 4.2 System Initialization 40 4.2.1 Port Initialization 40 4.2.2 Vessel Initialization 41 4.2.3 Vessel Application 42 4.2.4 Vessel Departure 47 4.3 Authentication 50 4.3.1 Vessels Authentication 51 4.3.2 Vessel Authentication with Port 52 4.4 Vessels Communication 56 5 Security Proof 59 5.1 Security Proof 59 5.2 Security Analysis 86 5.2.1 Man-in-the-Middle Attack (MITM) 86 5.2.2 Replay Attack 86 5.2.3 Impersonation Attack 87 5.2.4 Repudiation Attack 87 5.2.5 Data Tampering Attack 88 5.2.6 Insider Attack 88 5.2.7 Unlinkability and Anonymity 89 6 Performance 90 6.1 Security Comparison 91 6.2 Computation Comparison 92 6.3 Communication Overhead 98 7 Conclusions and Future Work 104 7.1 Future Work 105 References 106

