285
International Maritime Organization (IMO) and
national maritime authorities.
Finally, pAIS was designed to work with NMEA
0183 formatted messages. Conceptually, there is no
reason why it could not be extended to protect NMEA
2000 binary messages.
8 SUMMARY AND CONCLUSION
This paper has described pAIS, proof-of-concept
software that adds bit integrity, timestamp integrity,
and sender authentication to NMEA 0183 AIS
messages. The scheme is designed to be simple,
backward compatible, and able to co-exist with non-
pAIS implementations.
This prototype software was developed for
research applications to demonstrate that such a
scheme was viable and feasible. AIS is increasing in
importance as new applications get attached to the
system; autonomous ocean-going and near-coastal
vessels are merely the latest in a long line of mission-
critical uses for AIS. Every new use of AIS adds to the
reasons that the industry has to find ways to better
secure the system.
Another lesson from this research had nothing to
do with technology and everything to do with policy.
Backward compatibility was an essential goal of the
project so that introduction of protected AIS did not
break a working network. But adding security as an
additional layer to an existing system will ultimately
do little good because bad actors will continue to
operate in the non-secure mode and others will accept
their messages. Without a strong policy that requires
use of secure methods, add-on security will not
achieve the goal of a secure AIS network.
REFERENCES
[1] Balduzzi, M., Pasta, A., & Wilhoit, K. (2014). A security
evaluation of AIS automated identification system. In
Proceeding the 30th Annual Computer Security Applications
Conference (ACSAC '14), pp. 436-445. New Orleans,
Louisiana, December 8-12, 2014.
[2] Balduzzi, M., Wilhoit, K., & Pasta, A. (2014, December).
A Security Evaluation of AIS. Trend Micro Research
Paper. Retrieved from https://www.trendmicro.com/
cloud-content/us/pdfs/security-intelligence/white-
papers/wp-a-security-evaluation-of-ais.pdf
[3] Cutlip, K. (2017, March 31). AIS for Safety and Tracking:
A Brief History. Global Fishing Watch Web site. Retrieved
from https://globalfishingwatch.org/data/ais-for-safety-
and-tracking-a-brief-history/
[4] Ferguson, N., Schneier, B., & Kohno, T. (2010).
Cryptography Engineering: Design Principles and
Practical Applications. New York: John Wiley & Sons.
[5] Goudossis, A., & Katsikas, S.K. (2019, June). Towards a
secure automatic identification system (AIS). Journal of
Marine Science and Technology, 24(2), 410-423.
https://doi.org/10.1007/s00773-018-0561-3
[6] Goudossis, A., Kostis, T., & Nikitakos, N. (2012).
Automatic identification system stated requirements for
naval transponder security assurance. In A. Goudossis,
T. Kostis, & N. Nikitakos (Eds.), Proceedings of the 2nd
International Conference on Applications of
Mathematics and Informatics in Military Sciences
(AMIMS), Vari, Greece.
[7] Hall, J., Lee, J., Benin, J., Armstrong, C., & Owen, H.
(2015). IEEE 1609 Influenced Automatic Identification
System (AIS). In Proceedings of 2015 IEEE 81st
Vehicular Technology Conference (VTC Spring),
Glasgow, May 11-14, 2015, pp. 1-5.
https://doi.org/10.1109 /VTCSpring.2015.7145867
[8] International Association of Marine Aids to Navigation
and Lighthouse Authorities (IALA). (2016, June). An
Overview of AIS (Edition 2). IALA Guideline 1082.
Retrieved from https://www.navcen.uscg.gov/pdf/
IALA_Guideline_1082_An_Overview_of_AIS.pdf
[9] International Maritime Organization (IMO). (2002, July
1). International Convention for the Safety of Life at Sea
(SOLAS), Chapter V (Safety of Navigation), Regulation
19 (Carriage requirements for shipborne navigational
systems and equipment). Retrieved from
https://mcanet.mcga.gov.uk /public/c4/solas/index.html
[10] International Telecommunication Union (ITU). (2014,
February). Technical characteristics for an automatic
identification system using time division multiple access in
the VHF maritime mobile frequency band. ITU-R
Recommendation M.1371-5. M Series: Mobile,
radiodetermination, amateur and related satellite
services. Retrieved from https://www.itu.int/
dms_pubrec/itu-r/rec/m/R-REC-M.1371-5-201402-I!!PDF-
E.pdf
[11] International Telecommunication Union (ITU). (2015,
March). Assignment and use of identities in the maritime
mobile service. ITU-R Recommendation M.585-7. M
Series: Mobile, radiodetermination, amateur and related
satellite services. Retrieved from
https://www.itu.int/dms_pubrec/itu-r/rec/m/R-REC-
M.585-7-201503-I!!PDF-E.pdf
[12] Kessler, G.C. (2019, October 14). AIS Research Using a
Raspberry Pi. Retrieved from
https://www.garykessler.net/library/ais_pi.html
[13] Kessler, G.C., Craiger, J.P., & Haass, J. (2018,
September). A Taxonomy Framework for Maritime
Cybersecurity: A Demonstration Using the Automatic
Identification System. TransNav, The International
Journal on Marine Navigation and Safety of Sea
Transportation, 12(3), 429-437.
https://doi.org/10.12716/1001.12.03.01
[14] National Marine Electronics Association (NMEA).
(2019). NMEA 0183 Interface Standard. Retrieved from
https://www.nmea.org/content/STANDARDS/NMEA_0
183_Standard
[15] National Marine Electronics Association (NMEA).
(2019). NMEA 2000® Interface Standard. Retrieved from
https://www.nmea.org/content/STANDARDS/
NMEA_2000
[16] National Marine Electronics Association (NMEA).
(2019). OneNet Standard for IP Networking of Marine
Electronic Devices. Retrieved from
https://www.nmea.org/content/STANDARDS/OneNet
[17] Oh, S.H., Seo, D., & Lee, B. (2015). S3 (secure ship-to-
ship) information sharing scheme using ship
authentication in the e-navigation. International Journal
of Security and its Applications, 9(2),97–110.
[18] Trend Micro Warns Of Vulnerabilities In Global Vessel
Tracking Systems. (2017, February 3). Firstpost Web site.
Retrieved from https://www.firstpost.com/business/
biztech/business-tech/security/trend-micro-warns-of-
vulnerabilities-in-global-vessel-tracking-systems-
1895547.html
[19] U.S. Coast Guard (USCG). (2014, June 4). Encrypted
Automatic Identification System (EAIS) Interface Design
Description (IDD). Command, Control, and
Communications Engineering Center (C3Cen).Retrieved
from https://epic.org/foia/dhs/uscg/nais/EPIC-15-05-29-
USCG-FOIA-20151030-Production-2.pdf
[20] U.S. Coast Guard (USCG). (2019, August 14). AIS
Requirements. USCG Navigation Center Web site.