Military watercraft with sensors
16 claims: 12 independent, 4 dependent
- 1Militärisches Wasserfahrzeug (100), beinhaltend:- mehrere Fahrzeugkomponenten (104-110), die jeweils einen oder mehrere Sensoren (112-120) beinhalten, wobei zumindest einige der Fahrzeugkomponenten zu einem Waffensystem (102), einer Antriebseinheit (104) und einem Navigationssystem (106) gehören, wobei die Sensoren zur Erfassung von Messwerten ausgebildet sind, wobei die Messwerte Betriebszustände der Fahrzeugkomponente, die den die Messwerte erfassenden Sensor beinhaltet, und Zustände des Wasserfahrzeugs oder seiner Umgebung angeben;- eine Datenbank (122), wobei in der Datenbank eine Historie von Messwerten der Sensoren in Verbindung mit einem Zeitstempel persistent und geschützt gespeichert sind;- ein elektronisches Automatisierungssystem (124), wobei das Automatisierungssystem ausgebildet ist zur automatischen und/oder semi-automatischen Steuerung von zumindest einer der Fahrzeugkomponenten in Echtzeit in Abhängigkeit von den Messwerten und/oder in Abhängigkeit von einer Nutzereingabe eines Nutzers, die in Antwort auf eine Ausgabe der Messwerte über eine Benutzerschnittstelle erfolgt;und - mehrere Analysemodule (260-268), die jeweils dazu ausgebildet sind, eine Analyse von zumindest einem Teil der in der Datenbank (122) gespeicherten Messwerte auszuführen, wobei die mehreren Analysemodule in mehreren unterschiedlichen Containern (212-230) und damit isoliert voneinander ausgeführt werden.
- 2Das militärische Wasserfahrzeug nach Anspruch 1, wobei das Wasserfahrzeug umfasst:- mehrere zu einem Rechnerverbund (126) miteinander vernetzte Computer (202-208), die im Verbund als Host so zusammenarbeiten, dass zumindest eine Instanz der Datenbank bereitgestellt wird;und - eine Containerverwaltungssoftware, wobei die Containerverwaltungssoftware konfiguriert ist zur automatisierten Bereitstellung, Skalierung und Verwaltung mehrerer Container (212-230) auf den mehreren Computern auf eine Weise, dass die Computer jeweils als Hostsystem für ein oder mehrere Container dienen, wobei die Container voneinander isoliert sind.
- 3Das militärische Wasserfahrzeug nach einem der vorigen Ansprüche, - wobei das Automatisierungssystem (124) einerseits und die ein oder mehreren Analysemodule (260-268) andererseits voneinander operativ entkoppelt sind;und/oder - wobei sowohl das Automatisierungssystem als auch die ein oder mehreren Analysemodule dazu ausgebildet sind, ihre jeweiligen Steuerungs- oder Analyse-Funktionen ohne Nutzung einer Internetverbindung auszuführen.
- 4Das militärische Wasserfahrzeug nach Anspruch 3, wobei die operative Entkopplung realisiert ist durch:- asynchrone Arbeitsweise von Automatisierungssystem einerseits und den ein oder mehreren Analysemodulen (260-268) andererseits;und/oder - asynchroner Schreib- oder Lesezugriff auf die Datenbank (122) durch das Automatisierungssystem oder durch einen operativ mit dem Automatisierungssystem verbundenen Dienst (288) einerseits und durch die ein oder mehreren Analysemodule (260-268) andererseits;und/oder - Instanziierung des Automatisierungssystems einerseits und der ein oder mehreren Analysemodule (260-268) andererseits auf unterschiedlichen Computern (202-208;290).
- 5Das militärische Wasserfahrzeug nach einem der vorigen Ansprüche, wobei in jedem der Container (212-230) maximal eine Instanz von maximal einem Analysemodul (260-268) ausgeführt wird.
- 6Das militärische Wasserfahrzeug nach einem der vorigen Ansprüche in dessen Rückbezug auf Anspruch 2, wobei die Containerverwaltungssoftware (256) dazu konfiguriert ist, die Erzeugung von Containern (212-230) und die Instanziierung und das Beenden von Analysemodulen (260-268) so zu orchestrieren, dass:- bei Ausfall oder Unerreichbarkeit eines der Computer (202-208) automatisch auf einem anderen der Computer die Container und die Analysemodule gestartet werden, die durch den Ausfall oder die Unerreichbarkeit des einen Computers nicht mehr vorhanden oder erreichbar sind;und/oder - bei Überschreiten einer maximalen Zahl der aktuell auf den Computern laufenden Instanzen eines der Analysemodule automatisch eine dieser Instanzen zu beenden und/oder einen der Container, der eine Instanz dieses Analysemoduls beinhaltet, zu löschen;und/oder - bei Überschreiten einer vordefinierten maximalen Rechenlast eines der Computer automatisch zumindest einen auf diesem Computer gehosteten Container samt der darin laufende Analysemodulinstanz auf einen anderen der Computer zu migrieren;und/oder - bei Unterschreiten einer vordefinierten minimalen Rechenlast eines der Computer automatisch zumindest einen auf einem anderen der Computer gehosteten Container samt der darin laufende Analysemodulinstanz auf diesen Computer zu migrieren;und/oder - bei Überschreiten einer vordefinierten maximalen Rechenlast eines der Computer automatisch zumindest einen auf diesem Computer gehosteten Container samt der darin laufende Analysemodulinstanz zu identifizieren, eine Kopie dieses identifizierten Containers samt darin laufenden Analysemodul auf mindestens einem weiteren der Computer zu instanziieren;und Analysen unter Einbeziehung zumindest der Analysemodulinstanz in dem identifizierten Container und der weiteren instanziierten Analysemodulinstanz parallel auszuführen;und/oder - bei Unterschreiten einer vordefinierten minimalen Rechenlast eines der Computer automatisch zumindest einen auf einem anderen Computer gehosteten Container samt der darin laufende Analysemodulinstanz zu identifizieren eine Kopie dieses identifizierten Containers samt darin laufenden Analysemodul auf diesen einen Computer zu instanziieren;und Analysen unter Einbeziehung zumindest der Analysemodulinstanz in dem identifizierten Container und der weiteren instanziierten Analysemodulinstanz parallel auszuführen.
- 7Das militärische Wasserfahrzeug nach einem der vorigen Ansprüche, wobei zumindest einigen der Analysemodule jeweils ein Teil der Daten der Datenbank spezifisch zugewiesen ist, wobei die Teile der Daten auf eine Weise geschützt gespeichert sind, dass nur dasjenige Analysemodul auf diese lesend und/oder schreibend zugreifen kann, welches diesem Teil der Daten zugewiesen ist.
- 8Das militärische Wasserfahrzeug nach einem der vorigen Ansprüche, wobei mehrere (260, 262, 264;306, 314) der Analysemodule (260-268) jeweils einer (108;110) der Fahrzeugkomponenten spezifisch zugewiesen sind und dazu konfiguriert sind, zumindest die Messwerte, die von den ein oder mehreren Sensoren dieser einen Fahrzeugkomponente, der sie zugewiesen sind, erfasst werden, direkt oder indirekt über die Datenbank zu empfangen, zu analysieren und das Ergebnis der Analyse auszugeben.
- 9Das militärische Wasserfahrzeug nach Anspruch 8, wobei zumindest eines der mehreren Analysemodule, die einer der Fahrzeugkomponenten zugewiesen ist, dazu ausgebildet ist, eine Analyse durchzuführen, welche beinhaltet:- eine Erkennung aktueller oder künftiger kritischer Zustände der einen Fahrzeugkomponente;und/oder - eine Vorhersage der Zeit des Eintretens eines kritischen Zustands der einen Fahrzeugkomponente;und/oder - dem automatischen Identifizieren von ein oder mehreren Umgebungs-Parametern und/oder Fahrzeugkomponenten-Parametern, die ursächlich für einen kritischen Zustand der einen Fahrzeugkomponente sind;und/oder - eine Berechnung einer Handlungsempfehlung an einen Menschen in Bezug auf die eine Fahrzeugkomponente;und/oder - eine Berechnung eines Steuerbefehls an die eine Fahrzeugkomponente zur automatischen Durchführung des Steuerbefehls.
- 10Das militärische Wasserfahrzeug nach einem der vorigen Ansprüche, - wobei die Sensoren von zumindest einer der Fahrzeugkomponenten zumindest einen kryptographischen Verschlüsselungsschlüssel (324, 322, 330, 328, 326, 332) beinhalten, - wobei eines der Analysemodule der zumindest einen Fahrzeugkomponente zugeordnet ist und einen zu diesem kryptographischen Verschlüsselungsschlüssel korrespondierenden Entschlüsselungsschlüssel (334, 336, 338, 340, 342, 344) beinhaltet;- wobei die Sensoren der zumindest einen Fahrzeugkomponente dazu ausgebildet sind, zumindest einige der von ihnen erfassten Messwerte in verschlüsselter Form in der Datenbank zu speichern und/oder direkt an das der zumindest einen Fahrzeugkomponente zugewiesene Analysemodul zu übermitteln;- wobei das zumindest eine Analysemodul dazu konfiguriert ist, die zumindest einigen Messwerte mit dem Entschlüsselungsschlüssel zu entschlüsseln und die entschlüsselten Daten zu analysieren.
- 11Das militärische Wasserfahrzeug nach einem der vorigen Ansprüche, - wobei die Sensoren von zumindest einer der Fahrzeugkomponenten einen Signierschlüssel beinhalten;- wobei eines der Analysemodule der zumindest einen Fahrzeugkomponente zugeordnet ist und einen zu diesem Signierschlüssel korrespondierenden Signaturprüfschlüssel beinhaltet;- wobei die Sensoren der zumindest einen Fahrzeugkomponente dazu ausgebildet sind, zumindest einige der von ihnen erfassten Messwerte mit dem Signierschlüssel zu signieren und diese in signierter Form in der Datenbank zu speichern und/oder direkt an das der zumindest einen Fahrzeugkomponente zugewiesene Analysemodul zu übermitteln;- wobei das zumindest eine Analysemodul dazu konfiguriert ist, die zumindest einigen Messwerte mit dem Signaturprüfschlüssel zu prüfen und die signierten Daten nur dann zu analysieren, wenn die Signaturprüfung ergibt, dass die Signatur valide ist.
- 12Das militärische Wasserfahrzeug nach einem der vorigen Ansprüche , wobei zumindest eines der Analysemodule dazu ausgebildet ist, eine Analyse (z.B. Korrelationsanalyse, NN-basierte Vorhersage, regelbasierte Vorhersage, etc.) auf den Messwerten mehrerer unterschiedlicher Sensoren von mehreren unterschiedlichen Fahrzeugkomponenten durchzuführen, wobei die Analyse beinhaltet:- eine Erkennung aktueller oder künftiger kritischer Zustände von einer Fahrzeugkomponente;und/oder - eine Vorhersage der Zeit des Eintretens eines kritischen Zustands einer Fahrzeugkomponente;und/oder - dem automatischen Identifizieren von ein oder mehreren Umgebungs-Parametern und/oder Fahrzeugkomponenten-Parametern, die ursächlich für einen kritischen Zustand einer der Fahrzeugkomponenten sind;und/oder - eine Berechnung einer Handlungsempfehlung an einen Menschen;und/oder - eine Berechnung eines Steuerbefehls an eine der Fahrzeugkomponenten zur automatischen Durchführung des Steuerbefehls.
- 13Militärisches Wasserfahrzeug nach einem der vorigen Ansprüche, - wobei eine der Fahrzeugkomponenten eine Ruderanlage mit einer Steuereinheit, ein oder mehreren steuerbordseitigen und ein oder mehreren backbordseitigen Rudern beinhaltet, wobei die Steuereinheit dazu ausgebildet ist, die Lage und Bewegung der steuerbordseitigen und backbordseitigen Ruder durch senden von Steuerbefehlen an die steuerbordseitigen Ruder einerseits und an die backbordseitigen Ruder andererseits zu koordinieren, insbesondere zu synchronisieren, - wobei die Ruderanlage mehrere Sensoren beinhaltet, die zur Erfassung von Ruderanlage-Parameterwerten ausgebildet sind, wobei die Ruderanlage-Parameter zwei oder mehr der folgenden Messparameterwerte umfassen:aktuelle Lage der Ruder, Schwingungen der Ruder, Bewuchs der Ruder, Schwingungen von Komponenten der Ruderanlage, Schaltungszustände der Ruderanlage;- wobei ein oder mehrere der Fahrzeugkomponenten mehrere Sensoren beinhalten, die zur Erfassung von Umgebungs-Parameterwerten ausgebildet sind, wobei die Umgebungs-Parameter zwei oder mehr der folgenden Messparameterwerte umfassen: Wassertiefe, Seegang, Schiffsgeschwindigkeit;- wobei eines der Analysemodule ein Analysemodul für die verbesserte Steuerung der Ruderanlage ist und dazu ausgebildet ist, die Ruderanlage-Parameterwerte, die Umgebungs-Parameterwerte sowie Zeitdauern zwischen n einem Senden der Steuerbefehle von der Steuereinheit an die jeweiligen Ruder bis zur Umsetzung der Steuerbefehle zu analysieren, um Korrelationen zwischen den Zeitdauern, den Ruderanlage-Parameterwerten, und den Umgebungs-Parameterwerten zu erkennen und/oder um die Koordination der Ruder der Ruderanlage zu verbessern.
- 14Militärisches Wasserfahrzeug nach einem der vorigen Ansprüche, - wobei eine der Fahrzeugkomponenten zumindest einen Sensor zur Erfassung von Schwingungen, insbesondere Vibrationen, dieser einen Fahrzeugkomponente beinhaltet, wobei die eine Fahrzeugkomponente insbesondere eine Radaranlage und/oder die Antriebseinheit ist, - wobei eines der Analysemodule dazu ausgebildet ist, die Schwingungen der einen Fahrzeugkomponente zu analysieren, um den aktuellen und oder künftigen Zustand einer anderen der Fahrzeugkomponenten zu berechnen, wobei die andere Fahrzeugkomponente insbesondere eine Ruderanlage ist;und/oder - wobei eines der Analysemodule dazu ausgebildet ist, die Schwingungen der einen Fahrzeugkomponente zu analysieren, um eine Steuerung der anderen der Fahrzeugkomponenten zu verbessern, wobei die andere Fahrzeugkomponente insbesondere eine Ruderanlage ist.
- 15Das militärische Wasserfahrzeug nach Anspruch 2 oder einem der Ansprüche 1-14 in dessen Rückbezug auf Anspruch 2, wobei die Daten der Datenbank verteilt in verschiedenen Containern verschiedener Rechner gespeichert sind, wobei die Containerverwaltungssoftware dazu konfiguriert ist, die Erzeugung von Containern und die Speicherung, Replikation und Löschung der Daten in den Containern so zu orchestrieren, dass:- im Normalbetrieb die Daten der Datenbank in redundanter Weise so in den mehreren Computern verteilt gespeichert werden, sodass diese bei Ausfall von einem oder mehreren der Computer aus den in den übrigen Computern gespeicherten Daten rekonstruierbar sind;und/oder - bei Ausfall eines der Computer automatisch ein anderer der Computer, auf welchem eine Kopie derjenigen Teile der Daten, die in dem ausgefallenen Computer gespeichert waren, identifiziert wird, und die auf diesem anderen Computer enthaltenen Daten den Analysemodulen und der Automatisierungssystem bereitgestellt werden;und/oder - bei Ausfall eines der Computer automatisch Neuverteilung zumindest eines Teils der in mehreren Containern redundant und verteilt gespeicherten Daten derart, dass der bisherige Grad der Redundanz der Daten der Datenbank wiederhergestellt wird;und/oder - bei Überschreiten eines vordefinierten maximalen Speicherbedarfs in einem der Computer automatisch zumindest Teile der auf diesem Computer gespeicherten Daten der Datenbank auf einen anderen der Computer zu migrieren oder zu kopieren;und/oder - bei Unterschreiten einer vordefinierten minimalen Rechenlast eines der Computer automatisch zumindest einen der auf diesem einen Computer gehosteten Container zu löschen.
- 16System (150) umfassend:- mindestens zwei militärische Wasserfahrzeuge (100, 130, 132) gemäß einem der vorigen Ansprüche;- ein Computersystem (134) mit: ∘ einer Schnittstelle (136) zum sicheren Import des Inhalts der Datenbanken der mindestens zwei Wasserfahrzeuge;∘ eine Flottenanalysesoftware (138), wobei die Flottenanalysesoftware dazu ausgebildet ist, die Messwerte der Datenbanken der mindestens zwei Wasserfahrzeugen zu analysieren, wobei die Flottenanalysesoftware dazu konfiguriert ist, automatisch zu erkennen, ob die Messwerte unterschiedlicher Wasserfahrzuge von Fahrzeugkomponenten gleichen Typs erfasst wurden, wobei die Analyse umfasst: ▪ eine Erkennung desjenigen der Wasserfahrzeuge, dessen Gesamtheit an Fahrzeugkomponenten im besten oder schlechtesten Zustand ist im Hinblick auf zumindest ein technisches Bewertungskriterium;und/oder ▪ eine Erkennung kritischer Zustände von einer Fahrzeugkomponente in einem oder mehreren der Wasserfahrzeuge;und/oder ▪ eine Vorhersage der Zeit des Eintretens eines kritischen Zustands einer Fahrzeugkomponente in einem oder mehreren der Wasserfahrzeuge;und/oder ▪ dem automatischen Identifizieren von ein oder mehreren Umgebungs-Parametern und/oder Fahrzeugkomponenten-Parametern, die ursächlich für einen kritischen Zustand einer der Fahrzeugkomponenten in einem oder mehreren der Wasserfahrzeuge sind.
Independent claims16
188 paragraphs, as filed
Area
0001The invention relates to a military watercraft, in particular a military watercraft with sensors for recording measured values.
background
0002Military watercraft are often highly complex systems designed for specific missions and comprise a multitude of components, sometimes from different manufacturers. Compared to civilian watercraft, military watercraft are often characterized by a relatively small production run, high complexity, a large number of components, and a high need to protect vehicle-related data. The composition of vehicle components is therefore often very heterogeneous, and given the large number and integration density of components and manufacturers, it is not always possible to comprehensively test the interaction of the individual components for every conceivable application scenario. In addition, there is a tendency among vehicle component manufacturers to keep measurement data collected by internal sensors secret in order to prevent third parties from using this knowledge to replicate or "hack" the vehicle component.
0003These circumstances therefore represent significant technical obstacles to the integration of vehicle components for military watercraft.
0004The German patent application<patcit id="pcit0001" dnum="DE102008025803A1"><text>DE 102008025803 A1</text></patcit> This describes a marine internal combustion engine with a control device for controlling and/or regulating the operation of the marine internal combustion engine. Based on the ship's position, the control device determines target operating parameters for the marine internal combustion engine.
0005The German patent application<patcit id="pcit0002" dnum="DE102011086355A1"><text>DE 102011 086355 A1</text></patcit> Describes a weapon system for object defense, particularly for use on merchant ships, comprising: at least one gun, a firing mechanism, a sensor system for acquiring data, especially environmental and/or target data, and an authorization system. The authorization system is configured to enable or disable the firing mechanism depending on the receipt of a release signal.
0006The German patent application<patcit id="pcit0003" dnum="DE3150895A1"><text>DE 31 50 895 A1</text></patcit> This describes a warship with systems connected via electronic control devices. The warship, with its controlling and controlled systems, is equipped with electronic control units that generate control signals for the controlled systems from raw information received from the assigned controlling system. The electronic control units have a correction stage for each assigned controlled system to modify the generated control signals depending on a bedding error of the respective controlled system and/or the controlling system acting on the control unit. Further memory is provided for the bedding error values depending on the horizontal angular position of the controlled system and/or the controlling system.
0007The US patent application<patcit id="pcit0004" dnum="US20080120620A1"><text>US 2008 / 0 120 620 A1</text></patcit> describes the use of an "open software architecture" for the Navy fleet.
0008The US patent application<patcit id="pcit0005" dnum="US20180304969A1"><text>US2018/0304969A1</text></patcit> describes a ship with a propeller mounted on a rotating shaft and a method for converting the power of a rotating shaft into thrust to propel the ship across the water. The procedure includes obtaining measurement data that are descriptive of the shaft power, estimating two excess shaft powers caused by fouling of the propeller and by fouling of the ship's hull, and issuing a recommendation for propeller cleaning and/or hull cleaning depending on the estimated excess shaft powers.
0009The US patent application<patcit id="pcit0006" dnum="US20190176945A1"><text>US2019/0176945A1</text></patcit> describes a movement control system for a ship in a way that optimally balances performance and noise emission.
0010The US patent application<patcit id="pcit0007" dnum="US20060058929A1"><text>US 2006 / 0 058 929 A1</text></patcit> describes a method for verifying a ship's control system in which the control system, in its operating state, receives sensor signals from sensors and sends control signals to actuators in response to maintain a desired position, speed, course, or other.
0011The US patent application<patcit id="pcit0008" dnum="US20180356826A1"><text>US 2018 / 0 356 826 A1</text></patcit> describes a system and procedure to facilitate decision-making on a watercraft. The procedure includes: collecting environmental data of the environment in which the watercraft is located; generating a variety of digital models, each modeling an impact of the environment on a corresponding capability of the watercraft; using the environmental data and the digital models, modeling an impact of the environment on the capabilities of the watercraft and creating a risk assessment for a selected action.
0012The publication<nplcit id="ncit0001" npl-type="s" url="https://www.mlit.go.jp/common/001039009.pdf"><text>ANDO, Hideyuki: Smart ship application platform project (SSAP Project). In: Sea Japan 2014, Environmental Technology Seminar, 11. April 2014, 11 S. URL: https://www.mlit.go.jp/common/001039009.pdf [abgerufen am 2020-07-20</text></nplcit>] describes application services in the context of a "Smart Ship" to achieve optimal ship operation with regard to safety and energy efficiency.
0013The<patcit id="pcit0009" dnum="WO2019243932A1"><text>WO 2019/243932 A1</text></patcit> This concerns a method for detecting wear on a ship's propeller, whereby the motor driving the propeller is briefly decoupled in order to then record time-dependent measurements of the propeller's rotational speed. These measurements are compared with those of an intact propeller.
0014The documents<patcit id="pcit0010" dnum="DE102008057123A1"><text>DE 10 2008 057123 A1</text></patcit>, <patcit id="pcit0011" dnum="KR20070040188A"><text>KR 2007 0040188 A</text></patcit>, <patcit id="pcit0012" dnum="KR20170043213A"><text>KR 2017 0043213 A</text></patcit>, <patcit id="pcit0013" dnum="US2009271054A1"><text>US 2009/271054 A1</text></patcit> and<patcit id="pcit0014" dnum="US2008147257A1"><text>US 2008/147257 A1</text></patcit> are further state of the art.
Summary
0015The invention is based on the objective of providing an improved military watercraft.
0016The problems underlying the invention are each solved by the features of the independent claims. Embodiments of the invention are specified in the dependent claims. The embodiments listed below can be freely combined with one another, provided they are not mutually exclusive.
0017In one aspect, the invention concerns a military watercraft.
0018The military watercraft comprises several components, each containing one or more sensors. At least some of these components belong to a weapon system, a propulsion unit, and a navigation system. The sensors are designed to acquire measured values, which indicate the operating states of the component containing the sensor and/or the state of the watercraft or its environment.
0019The military watercraft also includes a database. This database persistently and securely stores a history of sensor readings along with a timestamp.
0020The military watercraft incorporates an electronic automation system. This system is designed for the automatic and/or semi-automatic control of at least one of the vehicle's components in real time, based on measured values and/or user input, which is provided via a user interface in response to the output of measured values.
0021This can be advantageous because a watercraft equipped in this way uses the measurement data acquired by the sensors in two ways: firstly, the measurement data is used to directly or indirectly influence the automation system and thus its control over individual vehicle components. For example, the acquired measurement values can be directly forwarded as input to the automation system. Additionally or alternatively, the measured values, or at least some of them, can be displayed to a user, enabling them to decide how the automation system should be operated based on these measurements. One primary use of the currently valid measurement data is therefore to influence the control of the watercraft components in real time. Secondly, the measurement data is also stored in a database. This is done in such a way that the temporal progression of the generation of the measurement data (the "history" of the measured values) can be derived from the database, e.g. by means of the timestamps (preferably UTC or location-independent and unique), which each indicate the time of recording of a measured value. Storing the measurement data persistently in a database allows for the automatic creation of a database over time, through whose analysis complex dependencies and interactions of several vehicle components or their states (engine temperature, turbine speed, rudder vibration) can be discovered, taking into account environmental parameters (temperature, humidity, pressure, depth, geographical position). For example, the database content can be used as a training dataset to train a machine learning algorithm. As a result, hidden, non-obvious, or technically indirect relationships and interactions can be identified, essentially in a way that is unique to each vehicle. This is particularly relevant in the military sector, where production volumes are low and many custom designs are required.
0022The measured values are stored securely in the database, which means that they are protected from unauthorized access by means of security measures, e.g. by encryption or preventing anonymous access by granting access rights.
0023Thus, it is possible, in principle, to digitally record all measured values generated on a watercraft, which may come from various vehicle components and from different manufacturers, and to use them both for real-time control of the vehicle and for subsequent analysis of a history of digital measured values recorded by the sensors (whether available in the automation system or not) of a watercraft. The operators of the watercraft therefore have the opportunity to gain valuable knowledge about an individual watercraft based on the history stored in the database and optionally using their own analysis tools, even if the data comes from a complex, heterogeneous environment of vehicle components and sensors from different manufacturers. Since the measured values from various sensors of different vehicle components were stored in a single database, they are accessible to a wide variety of multivariate analyses, such as those used in the context of big data. The timestamp, which, for example, Being configured as a UTC timestamp allows the various measured values to be uniquely related to each other and optionally also to the times at which control commands were sent to vehicle components or sub-components.
0024Embodiments of the invention thus enable a uniform use and analysis of all digital data that arises or can be captured by the increasingly complex platforms, systems and installations on board a military watercraft, thereby enabling seamless integration, installation, commissioning and long-term operation of the vehicle and its components.
0025Embodiments of the invention can be particularly helpful in the military sector, since users' detailed knowledge of individual vehicle components is often limited or cannot be reliably accessed under military stress. Vehicles and components tend to become increasingly complex, while crew sizes decrease (down to zero, which corresponds to completely autonomous vehicle control). Collecting and storing the sensor data in the database can compensate for these disadvantages.
0026According to embodiments of the invention, the watercraft comprises several (at least two) computers networked together to form a computer cluster, which cooperate as a host in such a way that at least one instance of the database is provided. It is also possible that some or all of the database data is stored redundantly on the multiple computer systems, e.g. by creating multiple instances of the database, including some or all of the database data, on the multiple computers.
0027According to embodiments, the watercraft comprises container management software configured for the automated provisioning, scaling, and management ("orchestration") of at least one container on at least one of the computers in such a way that this at least one computer serves as a host system for the at least one container, wherein the at least one container separates programs running inside this container from programs running outside this container. isolated. Preferably, the container management software orchestrates multiple containers on one or more computers.
0028According to embodiments of the invention, the watercraft comprises several computers networked together to form a computer network and container management software. The container management software is configured to automatically deploy, scale, and manage ("orchestrate") multiple (at least two) containers across multiple computers in such a way that each computer serves as a host system for one or more containers, with the containers (of the same host computer system as well as different host computer systems) isolated from each other.
0029This can be advantageous because integrating multiple computers into a computer network and using container management software to orchestrate multiple containers hosted on the computers can result in a system and the provision of the database and/or individual analysis modules that is highly performant and also very fault-tolerant. For example, the containers can be orchestrated to provide the database, or parts of the database, and/or one or more analysis modules multiple times, enabling parallel access to identical copies of the data or analysis modules. With regard to the database, this increases the speed of read and write access to the measurement data stored in the database and improves fault tolerance. With regard to the redundantly provided analysis modules according to some embodiments, this also increases the availability (possibly parallel execution of the same type of analysis) and reliability of the corresponding analysis modules. Both are of high importance in the context of a military watercraft, because a failure of the database and/or software programs instantiated in the containers can lead to critical data loss, data inconsistencies, or the failure of forecasting and warning functions based on currently stored or previously stored measurement data. Furthermore, the use of containers and container management software to orchestrate the containers allows for easy scaling of the system, e.g., if a significantly larger amount of (measurement) data needs to be stored and/or analyzed over time, and/or if the number of software programs to be instantiated on the computer network increases over time.
0030Using containers to deploy and isolate software applications ensures the separation and management of resources used on a computer. Containers allow an application to be instantiated on different computers and environments (for example, different computers on a network, but also on different types of computers such as development, QA, and production). Furthermore, updates are simplified.
0031According to embodiments, each container is access-restricted in such a way that it can only access a specific memory area of main memory assigned to it alone, as well as native applications (e.g., native databases).
0032In some embodiments, only the analysis modules are hosted within containers, while the database is run as a native database on one of the computers. Such embodiments of the invention can have the advantage that access to the data stored in the database can be facilitated by the analysis modules instantiated in the containers.
0033According to other embodiments, at least some of the containers are configured such that a virtual network exists between some of the containers, allowing the analysis modules instantiated in one container to access the contents of a database instantiated within a container networked with that container. Such embodiments can have the advantage that a user, e.g., The container management software allows for very precise and granular control over which analysis modules within which containers can access the contents of other containers. For example, it is possible for a first container to hold a primary database with the measured values from sensors S1, S12, and S37, and a second container to hold a secondary database with the measured values from sensors S17 and S35. Sensors S1, S12, and S37 come from manufacturer H1, while the readings from sensors S17 and S35 come from manufacturer H2. It is now possible to configure the computer network or containers so that the analysis software A1 from manufacturer H1 runs in a third container, which is selectively allowed to access the first database in the first container, but not the data from the sensors of manufacturer H2 in the second container. Similarly, the configuration can include the analysis software A2 from manufacturer H2 running in a fourth container, which may selectively access the second database in the second container, but not the data from the sensors of manufacturer H1 in the first container.
0034According to embodiments of the invention, the computers can be servers, i.e., computers that provide one or more programs or functions (e.g., analysis modules, databases, etc.) to external entities (e.g., other servers, analysis modules instantiated on other servers, users, etc.). Server computers are often characterized by above-average computing capacities and/or above-average amounts of available main memory.
0035According to the invention, the military watercraft further comprises several analysis modules, each of which is designed to perform an analysis of at least some of the measured values stored in the database.
0036In some embodiments, the automation system and the one or more analysis modules are operationally decoupled from each other. Additionally or alternatively, the one or more analysis modules are configured to perform their respective analysis functions without using an internet connection. According to embodiments, both the automation system and the one or more analysis modules are designed to perform their respective control or analysis functions without using an internet connection.
0037For example, the analysis modules are designed to analyze the history of measured values stored in the database and, based on this analysis, to calculate predictions regarding the current and/or future condition of the watercraft or its components and/or to determine a technically or tactically appropriate course of action. In particular, according to certain embodiments, recommendations for action are first calculated, which are then implemented manually, semi-automatically, or fully automatically.
0038Preferably, at least some of the analysis modules are designed to evaluate the measured values from two or more sensors of two or more different vehicle components and optionally also one or more environmental parameters (air pressure, water temperature, depth, geographical position of the vehicle, flow rate of the surrounding water, etc.). This has the advantage that interactions between vehicle components and/or environmental parameters can also be detected through retrospective analysis of the history of these measurement parameters and used to predict future states and actions.
0039Executing the control and/or analysis function without using an internet connection can be advantageous, as an internet connection is often not reliably available on the high seas and, even when it is available, is sometimes switched off in the military sector for some systems to increase the security of the system and reduce the probability of detection.
0040The analysis is performed on the database data, and the analysis modules are operationally separate from the automation system. This means that the automation system is not affected by operations for reading and processing the measurement data by the analysis modules. This is advantageous because the automation system is a real-time system, and the operational separation protects it from having its reaction speed and/or responsiveness affected by the execution of the analysis modules. In a military context, it is crucial that the automation system can react immediately and in real time to current events, e.g., to automatically initiate the correct steps in combat situations to turn, brake, accelerate, and/or implement defensive or aggressive measures.
0041According to embodiments of the invention, the operational decoupling is realized through an asynchronous operation of the automation system on the one hand and the one or more analysis modules on the other.
0042For example, operational decoupling can involve programming the automation system and the analysis modules to operate independently of each other, meaning that at no point does the automation system require data and/or wait for data provided by the analysis module.
0043Additionally or alternatively, operational decoupling can be implemented in the form of asynchronous read or write access to the database by the automation system or by a service operationally connected to the automation system on the one hand, and by the one or more analysis modules on the other. For example, operational decoupling can involve the automation system receiving current measurement data directly from the sensors via a first communication channel without writing the measurement data to the database before or during data transmission via the first channel. This means the automation system receives the current measurement data from the sensors directly and immediately after they are acquired, thus avoiding the delay that can occur when writing measurement data to a data storage device. Asynchronously, the measurement data is written to the database to maintain the history of the measurement parameters. The data channel through which this writing process takes place can also be referred to as a second communication channel and may, for example, be configured as a multitude of database connections established by the sensors with regard to the database. The use of the first communication channel and one or more second communication channels means that even if bottlenecks or delays occur when writing the measurement data to the database, this does not lead to a delay in forwarding the measurement data to the automation system, since the data transmission of the measurement data to the automation system is temporally and operationally decoupled from the storage of the measurement data in the database. In another embodiment, the watercraft includes a service through which the automation system reads data from the database and/or writes data generated by the automation system to the database. In this case, the read and/or write access of this service is operationally decoupled from the read/write accesses by the analysis modules.
0044Additionally or alternatively, operational decoupling can be achieved by instantiating the automation system on the one hand and the one or more analysis modules on the other hand on different computers. For example, asynchronous operation can be implemented by hosting the automation system on one or more primary computers and the database and the analysis modules on one or more secondary computers. Alternatively, it is also possible to assign different CPU and/or memory resources of a distributed computer network to the automation system on the one hand and the database and the analysis modules on the other, so that it is impossible for the automation system to compete with the analysis modules for resources.
0045All these measures can be advantageous because they ensure that the automation system, or its real-time capability, is not impaired by the storage and analysis of historical measurement data. According to the invention, the watercraft comprises several analysis modules housed in separate containers, thus isolating them from one another.
0046This can be advantageous, as it improves the reliability, maintainability and performance of the analysis procedures performed by the analysis modules. For example, powerful programs exist for managing containers on multiple computers, which make it possible to redundantly create multiple instances of an analysis module within several different containers, so that certain analyses can be performed in parallel on different subsets of the database data and thus particularly quickly. Furthermore, creating multiple instances of the same analysis module ensures that even if one computer in the computer network fails or becomes unreachable, it is possible to immediately switch to another existing instance of the same analysis module running on a different computer, and/or that this other instance can be created in a new container on the other computer within a short time. Furthermore, it is possible to quickly and flexibly increase or decrease the number and distribution of instances generated by one or more analysis modules, depending on the specific situation.
0047For example, in a safety-critical military operation, it is of secondary importance whether an analysis module, which predicts the next routine service appointment for the vessel based on the distance traveled, has sufficient CPU and memory capacity available for its work, or even whether this module is instantiated at all. However, it can be, for example, During a critical turning maneuver, it is of utmost importance that another analysis module, which can correctly calculate whether material stress limits are exceeded or the stability of the ship is at risk based on various material and flow-related measurements at the rudder, turbine and other vehicle components, has all the necessary CPU and memory resources available to perform its calculations correctly and quickly.
0048According to embodiments of the invention, at most one instance of at most one of the analysis modules is executed in each of the containers.
0049This can be advantageous because it ensures that each instance of an analysis module runs in its own container. This enables highly granular orchestration of the analysis modules at the level of individual instances using the container management program.
0050The fact that the individual analysis modules are operationally isolated from each other thanks to their design in separate containers is particularly advantageous in the context of a military watercraft: for example, the analysis modules can come from different manufacturers of vehicle components. For example, a first analysis module can be provided by the manufacturer of a turbine and be designed to analyze measured values relating to the rotational speed, temperature and vibration behavior of a turbine from the same manufacturer equipped with sensors for rotational speed, temperature and vibration state of the turbine. The analysis can serve various purposes: for example, to determine whether critical system conditions have been reached that would void the manufacturer's warranty and/or necessitate an inspection or overhaul of the turbine. The analysis can also be used to investigate how the individual measured values depend on each other, i.e., whether the turbine exhibits different vibration patterns within different speed ranges. A second analysis module can, for example, be provided by the engine manufacturer and be designed to analyze measured values relating to the current engine temperature, the engine's current energy consumption, or other engine-related measurements. This analysis can also serve various purposes, such as... The analysis can be used to determine whether a critical engine condition has been reached or exceeded, which could void the manufacturer's warranty and/or necessitate an inspection or overhaul of the engine. It can also be used to investigate how the individual measurements depend on each other, for example, whether the engine exhibits different vibration patterns and/or performance curves within different temperature ranges. Both the turbine manufacturer and the engine manufacturer, as well as ultimately the operator of the vessel itself, benefit from the fact that the analysis modules of the various manufacturers are separate, because this prevents third-party software programs from intentionally or unintentionally interacting with a specific analysis module and causing it to crash or malfunction. Especially in the military sector, there is a constant risk that supposedly trustworthy software may actually contain malware designed to disrupt the operation of vehicles or vehicle components and/or to unlawfully obtain information regarding the functionality of the vehicle components. Certain individuals or organizations may have an interest in learning how a particular vehicle component works and/or in causing a vehicle component to operate unreliably or faultily, thereby temporarily or permanently disabling, for example, important long-term functions of the watercraft. According to embodiments of the invention, this can be prevented by executing the individual analysis modules in isolation from each other within their own container.
0051Furthermore, running exactly one instance of an analysis module per container facilitates the orchestration of the containers, for example for the purpose of load balancing, upscaling or downscaling, since the resource consumption of a container is largely identical or strongly correlated with the resource consumption of the analysis module instantiated in that container.
0052According to embodiments of the invention, the container management software is configured to orchestrate the creation of containers, the instantiation and termination of the analysis modules (within these containers) such that one or more of the following effects occur:<ul id="ul0001" list-style="dash"><li>In the event of a failure or unavailability of one of the computers, the containers and analysis modules that are no longer present or accessible due to the failure or unavailability of the first computer are automatically started on another computer; this increases the robustness of the analysis functionality of a watercraft against failures of individual computers; Especially in military situations, it must be anticipated that in combat situations components of the vessel, such as individual computers and/or network connections within a computer cluster, may be destroyed or damaged, or at least fail temporarily; therefore, the ability of the container management software to create a new instance of the failed analysis module in such situations is particularly advantageous; and/or</li><li>If the maximum number of instances of one of the analysis modules currently running on the computers is exceeded, one of these instances should be automatically terminated and/or one of the containers containing an instance of this analysis module should be deleted or moved to another computer; this can be advantageous because it ensures that unused CPU and memory resources are automatically released when they are no longer needed for analytical activities; The faster these free resources can be made available to vital systems in an emergency, the "maximum number" can be, for example, a number specified manually or automatically in a configuration of the container management software. "Maximum" means that exceeding this value is considered undesirable and induces a specific sequence or action, preferably aimed at reducing the number of instances; and/or</li><li>If a predefined maximum computing load is exceeded on one of the computers, at least one container hosted on that computer, along with the analysis module instance running within it, should be automatically migrated to another of the computers; the container management software can therefore perform load-balancing functions; and/or</li><li>If the computing load of one of the computers falls below a predefined minimum threshold, at least one container hosted on another computer, along with the analysis module instance running within it, should be automatically migrated to that computer; the container management software can therefore perform load-balancing functions; in some implementations, this one computer can be deactivated or put into sleep mode to save energy; and/or</li><li>When a predefined maximum computing load is exceeded on one of the computers, at least one container hosted on that computer, along with the analysis module instance running within it, should be automatically identified (e.g. to instantiate a copy of the identified container (including the analysis module running within it) on at least one other computer (a container with the highest CPU/memory consumption or a container containing an instance of a specific analysis module); and to perform analyses in parallel, using at least the analysis module instance in the identified container and the other instantiated analysis module instance. The container management software can therefore perform upscaling functions; and/or</li><li>If the computing load of one of the computers falls below a predefined minimum level, at least one container hosted on another computer, including the analysis module instance running within it, should be automatically identified (e.g., to instantiate a copy of the identified container (with the highest CPU/memory consumption), including the analysis module running within it, on this single computer; and to perform analyses in parallel, using at least the analysis module instance in the identified container and the additional instantiated analysis module instance; the container management software can therefore perform load balancing functions; and/or</li><li>If the computing load of one of the computers falls below a predefined minimum level, at least one of the containers hosted on that computer should be automatically deleted; the container management software can therefore perform downscaling functions.</li></ul>
0053This can be advantageous because it allows for better distribution of CPU and memory resource consumption across the computers in the cluster, resulting in improved response times. Furthermore, it enables demand-based scaling of containers and the analysis modules instantiated within them.
0054In some embodiments, at least some of the analysis modules are specifically assigned a portion of the database data. These data portions are stored in a protected manner such that only the analysis module assigned to that portion of the data can access it for reading and/or writing.
0055For example, the allocation can be such that an analysis module developed by a specific company that has also manufactured a vehicle component or has a contractual relationship with the manufacturers has access to measurement data that is captured and stored by sensors of that vehicle component, but not to the measurement data of sensors of other vehicle components.
0056According to another example, the allocation is such that an analysis module developed by a specific company that also manufactures several vehicle components or has a contractual relationship with the manufacturers of these components has access to the measurement data acquired and stored by sensors of these multiple vehicle components. The analysis module does not have access to the measurement data of sensors from other vehicle components.
0057According to another example, the assignment is carried out in such a way that an analysis module developed by a specific company that has also manufactured one or more vehicle components or has a contractual relationship with the manufacturers of these one or more vehicle components has access to the measurement data that was recorded and stored by the sensors of these one or more vehicle components and additionally has access to measurement data. which were stored in the database as generally accessible (for every analysis module of the watercraft).
0058The analysis modules of watercraft according to embodiments of the invention can be the measurement data of the database according to any combination of the examples described here.
0059The various forms of specific assignment of measurement data and analysis modules can be advantageous, as vehicle component manufacturers can thereby ensure that only analysis modules trusted by that manufacturer have access to the measurement data generated by the sensors of that vehicle component. The installation of sensors of various types on and/or in vehicle components of a military watercraft by the manufacturer of the respective component has the advantage that important condition parameters of the vehicle component, such as temperature, vibration behavior, load parameters, environmental parameters, etc., are made available. This measurement data is relevant for the manufacturer of the vehicle components, for example for testing, development, and repair purposes, and for determining warranty claims. However, the measurement data is also relevant for the operator of the watercraft (for a better understanding of how the vehicle component works and/or for a better understanding of the interactions of the vehicle component with other components or environmental parameters).
0060For the manufacturer of a vehicle component and/or the operator of the vehicle, the problem arises that disclosing all measured values may reveal information about the operation and internal component states, which should remain internal to the company, for example to make it more difficult for competitors to replicate the product and/or to prevent attackers from specifically manipulating the vehicle component. A manufacturer of vehicle components therefore has no inherent interest in having the measurement data relating to this vehicle component disclosed. This currently prevents the integration of sensor data into various vehicle components, which is a disadvantage for the operator of military watercraft from a safety perspective, because many technically relevant effects, such as the specific behavior of a rudder, a turbine, or another complex component of the watercraft, only result from the complex interaction of several vehicle components. which can each have different internal states.
0061The described IT architecture, according to which individual analysis modules are assigned specific parts of the measurement data in the database in such a way that the modules can selectively access only the parts explicitly assigned to them, but not generally all measurement data stored in the database, can be advantageous, since on the basis of this IT architecture the operator of the military watercraft can identify the supplier or Manufacturers of the respective vehicle components (including their sensors) can be assured that the measurement data acquired by the sensors is only accessible to specific analysis modules that have been deemed trustworthy and accepted by both parties. This creates an IT architecture that enables manufacturers of military vehicle components to securely provide sensitive measurement data only to specific analysis modules. The risk that a competitor or attacker might use the measurement data to replicate or attack a vehicle component can therefore be ruled out.
0062The operator of the military watercraft benefits from the fact that, according to embodiments of the invention, the measurement data of a large number of vehicle components are only made available to selected, trusted analysis modules: Manufacturers of vehicle components in the military sector have so far tended to record measurement data from sensors of the vehicle components they produce internally, and to analyze it only by vehicle component-internal computing units, without disclosing the measurement data externally or even storing it for a longer period of time. Thanks to the IT architecture of watercraft according to embodiments of the invention, manufacturers of vehicle components can now do without the component-internal computing units for the secret analysis of the measurement data, since although the measurement data of several sensors and vehicle components are stored centrally in a database, not every analysis module can access this data arbitrarily.
0063While some currently available automation systems for military watercraft also offer access to sensor data from multiple sensors, this only includes the current actual values of individual systems, which do not contain historical profiles and trends of measured values over a longer period that are either not practically usable or only of limited use. Due to the real-time requirements of such automation systems, it had previously been avoided to burden the scarce resources of the automation system of watercraft with computationally intensive analyses of extensive historical data sets. However, thanks to the distributed storage of the analysis modules in several containers in a computer network that is separate from the automation system, it is possible, according to embodiments of the invention, to perform and provide even complex analyses, partly in real time, without impairing the real-time capability of the automation system. The problem that manufacturers of vehicle components with integrated sensors are unwilling or unable to disclose the measured values they collect, for various reasons, has been overcome by an IT architecture that ensures only selected analysis modules with the appropriate permissions can access the data. This has created an IT architecture that is particularly advantageous in the context of the specific requirements of military watercraft.
0064According to embodiments of the invention, several of the analysis modules are each specifically assigned to one of the vehicle components and are configured to receive, analyze, and output the result of the analysis, at least the measured values that are recorded by the one or more sensors of that one vehicle component to which they are assigned, directly or indirectly (via the database). Indirect reception via the database means that the measured values acquired by the sensors are first written to the database, and then, in a second step, the analysis module accesses the measured values stored in the database. This indirect reception via the database has the advantage that the analysis modules do not need an interface to receive measurement data from a specific sensor.
0065According to one embodiment, the one or more sensors have write access to the database and are configured to store the measured values in a suitable format within the database. For example, the sensors can have a network interface and be configured to continuously write the acquired measured values to the database.
0066According to other embodiments, the sensors are configured to first store the measured values they acquire in a local volatile or non-volatile data memory within the sensor. Another component of the watercraft (e.g., the automation system, one of the analysis modules, or other software) reads the locally stored measurement data and writes it to the database, so that the analysis modules can then access the measured values via the database.
0067According to embodiments of the invention, at least one of the several analysis modules assigned to one of the vehicle components is configured to perform an analysis which includes:<ul id="ul0002" list-style="dash"><li>a detection of current or future critical conditions of a vehicle component; and/or</li><li>a prediction of the time of occurrence of a critical condition of a vehicle component; and/or</li><li>the automatic identification of one or more environmental parameters and/or vehicle component parameters that are the cause of a critical condition of one vehicle component; and/or</li><li>a calculation of a recommended course of action for a person with regard to a vehicle component; and/or</li><li>a calculation of a control command to a vehicle component for the automatic execution of the control command.</li></ul>
0068This can be advantageous because the one or more analysis modules can be used not only to retrospectively identify individual correlations and relationships, but also, based on the history of measurement data from multiple sensors stored in the database, to predict technically and/or tactically critical situations in or on the watercraft, as well as to predict instructions for action and control commands that can help to to avoid or mitigate the critical situation. The analysis modules can thus take over functions that were previously performed exclusively by the automation system. While the automation system is typically inflexible, as it typically integrates measured values from a predefined number of sensors of a predefined set of vehicle components, the use of analysis modules in addition to the automation system is advantageous, since the analysis modules are instantiated within an IT architecture according to embodiments of the invention. which is highly available, robust and easily scalable based on container virtualization and automatic container orchestration, and which securely protects the measurement data of the vehicle components from access by unauthorized third parties.
0069According to embodiments of the invention, the sensors of at least one of the vehicle components include at least one cryptographic encryption key. One of the analysis modules is assigned to the at least one vehicle component and includes a decryption key corresponding to this cryptographic encryption key. The two "corresponding" keys of the sensor and the analysis module can be a secret, "symmetric" cryptographic key that is used for both encrypting and decrypting the measured values. Alternatively, the two corresponding keys can be an asymmetric cryptographic key pair, where the key managed and stored by the sensor is a public cryptographic key (encryption key) and the key managed and securely stored by the analysis module is a private cryptographic key (decryption key). The sensors of at least one vehicle component are designed to store at least some of the measured values they record in encrypted form in the database and/or to transmit them directly to the analysis module assigned to the at least one vehicle component.
0070At least one analysis module is configured to decrypt at least some of the measured values using the decryption key and to analyze the decrypted data.
0071According to embodiments of the invention, all sensors mounted in or on the same vehicle component have the same public encryption key. According to other embodiments of the invention, all sensors of at least one of the vehicle components of the vehicle have their own public key, which differs from the public key of the other sensors of that vehicle component.
0072This can be advantageous because the use of encryption methods offers a particularly high level of security, ensuring that the measurement data from sensors of a specific vehicle component can only be read and interpreted by authorized analysis modules.
0073According to embodiments of the invention, the sensors of at least one of the vehicle components include a signing key. The signing key preferably belongs to a Public Key Infrastructure (PKI) of a manufacturer of this vehicle component. One of the analysis modules is assigned to the at least one vehicle component and includes a signature verification key corresponding to this signing key. The sensors of at least one vehicle component are designed to sign at least some of the measured values they record with the signing key and to store these in signed form in the database and/or to transmit them directly to the analysis module assigned to the at least one vehicle component. At least one analysis module is configured to check at least some of the measured values with the signature verification key and to analyze the signed data only if the signature verification shows that the signature is valid.
0074This can be advantageous because it protects the operator of the watercraft from an attack on the stability and integrity of the military watercraft caused by a manipulated vehicle component and/or manipulated sensors generating false analyses and forecasts. In particular, when these analyses and forecasts are automatically translated into corresponding control commands, there is a risk that such manipulation will damage the watercraft in the short or long term or render it unusable. For example, a specific analysis module can typically be used to predict the future course for the next 5 km based on GPS position data, the current turbine rotation speed, and the current rudder angle. A tampered rudder angle sensor can provide incorrect angle data, leading to an inaccurate calculation of the vessel's course. This can lead to the ship being on a different course than predicted and running aground or colliding with rocks. This risk can be mitigated by having the sensors sign the measurement data they generate, with the signature pointing to a trusted entity, such as a specific manufacturer. By checking the signature of the measurement data before using it, the analysis module can rule out the possibility that manipulated sensors and/or manipulated vehicle components pose a threat to the vehicle and crew.
0075According to embodiments of the invention, one or more of the analysis modules are each configured to output their analysis results to a user and/or to the analysis system and/or to store them in the database.
0076For example, the results can be displayed on a screen, printed out using a printer, and/or output via speakers. Additionally or alternatively, the results can be output to a software or hardware component, such as the automation system.
0077This can be advantageous because the results can integrate data from a large number of sensors, a large number of vehicle components and/or environmental parameters, taking into account not only current measurements but also the history of measurements. Since the analysis modules are implemented as individual, isolated software modules, their number and composition can be easily adapted to the potentially changing composition of vehicle components over the vehicle's lifetime. The analysis results from these modules thus provide a source of system diagnostics and control commands, which complement the functions of the automation system in a particularly flexible manner. Depending on the type of analysis result and its implementation, the results can be recommendations for action given to the user, requiring manual execution by the user. Alternatively, the recommendations can be executed automatically by the vehicle components, requiring only manual confirmation from the user. It can also involve control commands that are sent directly from the analysis modules to the automation system without involving the user, causing it to automatically perform the action specified in the commands, e.g. opening an exhaust flap, correcting the angles of a rudder, etc.
0078According to embodiments of the invention, at least one of the analysis modules is configured to perform an analysis (e.g., correlation analysis, machine learning (ML)-based prediction, rule-based prediction, etc.) on the measured values of several (at least two) different sensors from several different vehicle components. The analysis includes:<ul id="ul0003" list-style="dash"><li>a detection of current or future critical conditions of a vehicle component; and/or</li><li>a prediction of the time of occurrence of a critical condition of a vehicle component; and/or</li><li>the automatic identification of one or more environmental parameters and/or vehicle component parameters that are the cause of a critical condition of one of the vehicle components; and/or</li><li>a calculation of a recommended course of action for a person; and/or</li><li>a calculation of a control command to one of the vehicle components for the automatic execution of the control command.</li></ul>
0079This can be advantageous because ML-based methods and various other forms of correlation analysis are particularly suitable for recognizing complex, cross-component, linear as well as non-linear dependencies and interactions from historical measured values of several different parameters and for calculating predictions about current and future system states based on these recognized dependencies.
0080According to embodiments of the invention, the database data is distributed across multiple computers and/or stored redundantly.
0081This can be advantageous because it increases reliability if one of the computers fails or becomes unreachable. Furthermore, redundant storage allows parallel access to copies of the same data, thus speeding up queries.
0082According to embodiments of the invention, the database data is distributed across different containers on different computers (i.e., the containers are instantiated on different computers, and some computers may even have multiple containers instantiated). The container management software is configured to orchestrate the creation of containers and the storage, replication, and deletion of data within the containers such that:<ul id="ul0004" list-style="dash"><li>Under normal operating conditions, the database data is stored redundantly across multiple computers in such a way that, in the event of a failure of one or more computers, it can be reconstructed from the data stored on the remaining computers; and/or</li><li>In the event of a computer failure, another computer is automatically selected, on which a copy of those parts of the data that were stored on the failed computer is identified, and the data contained on this other computer is made available to the analysis modules and the automation system (e.g., by starting this other computer, granting access to the partial data, etc.); and/or</li><li>In the event of a computer failure, at least a portion of the data, which is stored redundantly and distributed across multiple containers, is automatically redistributed in such a way that the previous level of data redundancy in the database is restored; and/or</li><li>If a predefined maximum storage requirement is exceeded in one of the computers, at least parts of the database data stored on that computer should be automatically migrated or copied to another computer; for this purpose, load balancing functions such as those already included in the Kubernetes software can be used.</li></ul>
0083This can be advantageous for reasons similar to the redundant instantiation of analysis modules on multiple computers. In particular, availability and fault tolerance are increased, and access times are reduced through parallel access.
0084According to embodiments of the invention, at least some of the computers in the computer network are each contained in their own security container, which is fireproof and/or pressure wave resistant and/or waterproof.
0085For example, the security container can consist of a single-walled or, preferably, a multi-walled body. The body can be made of steel, for example, and be equipped with a door with its own locking mechanism or lock. Preferably, the security container is watertight and/or pressure wave resistant. For example, the enclosure can include cable entry points on the back and integrated cooling to prevent both water and/or pressure ingress and overheating. While "containers" are software or runtime environments for programs instantiated on a computer, security containers are physical containers that can hold one or more computers.
0086This can be advantageous because the computers, and therefore also the analysis programs and containers, are protected from damage in the event of a leak or detonation (pressure wave, fire).
0087According to embodiments of the invention, the computers of the computer network comprise one or more first computers and one or more second computers. The first computers and the second computers are housed in different spatial areas of the watercraft, the different spatial areas being different rooms, different decks, different chambers separated by watertight lock gates, starboard and port sides of the watercraft, or bow and stern sides of the watercraft.
0088This can be advantageous because it increases the reliability of the vessel and the analysis modules: if certain areas of the ship are damaged due to a detonation or accident, not all analysis modules will be affected. Instead, the container management software can be located on the containers.
0089In a further aspect, the invention relates to a system comprising at least two military watercraft according to one of the embodiments or examples described herein and a computer system. The computer system includes an interface for the secure import of the contents of the databases of the at least two watercraft. The computer system also includes fleet analysis software. The fleet analysis software is designed to analyze the measurement data from the databases of at least two vessels. The software is configured to automatically detect whether the measurements from different vessels were taken from components of the same type. The analysis includes:<ul id="ul0005" list-style="dash"><li>Identification of the watercraft whose totality of components is in the best or worst condition with regard to at least one technical assessment criterion (e.g., tank level, availability of energy resources, time until next maintenance, indicator of reliability, indicator of the watercraft's suitability for a specific operational scenario); and/or</li><li>a detection of critical conditions of a vehicle component in one or more of the watercraft; For example, by analyzing historical measurement data in the databases of several watercraft, it can be recognized that in a few watercraft, a combination of rudder angle and turbine speed, which was unproblematic in the majority of watercraft, caused an unstable condition of the watercraft, requiring manual intervention, so these few vessels should be brought in for inspection; Certain vibration patterns can indicate that a vehicle component of a particular watercraft is suffering from material fatigue or is negatively affected by vibrations and movements of adjacent components, making an inspection advisable for this component as well; and/or</li><li>a prediction of the time of occurrence of a critical condition of a vehicle component in one or more of the watercraft; For example, the timing of each vessel's next inspection date, considering the material fatigue derived from vibration data and/or the usual maintenance intervals, could be used to determine whether the vessel with the latest predicted inspection date is the most suitable for current, extended use; and/or</li><li>the automatic identification of one or more environmental parameters and/or vehicle component parameters that are the cause of a critical condition of one of the vehicle components in one or more of the watercraft; For example, fleet analysis software can detect that only those ships operating in waters with a water temperature below 6°C experienced problems triggering movement in a specific component. This strongly suggests that material contraction at low temperatures was the cause of the problems and that the component is unsuitable for use in low temperatures. Analyzing multiple vessels may provide further insights. This enables the detection of causes that would not have been, or probably would not have been, detected without evaluating data from multiple vehicles.</li></ul>
0090Fleet analysis software can be a single, complex application program or a combination of several individual analysis programs that can perform various types of analysis on the history of measurements recorded by sensors of multiple watercraft over a period of several hours, days, weeks, months or years.
0091According to some implementation systems, the computer system hosting the fleet analysis software also includes a decryption key and/or signature verification key, with these keys being provided by the manufacturer(s) of the vehicle components or the watercraft, if the manufacturers release these keys to the customer, i.e., the operator of the watercraft.
0092In this context, a "military watercraft" refers to a watercraft designed and equipped for use by armed forces to fulfill their missions. Vehicles for military purposes often have specific modifications, such as reinforced hulls or floors for mine protection, camouflage paint, and weapons and/or defense systems. Watercraft are vehicles designed for movement on or in water. In particular, it can be a wind-powered or engine-powered watercraft, e.g., sailing ships, hovercraft, hydrofoils, submarines, frigates, aircraft carriers, supply ships, etc. For example, some frigates may be trained or equipped for maritime surveillance, anti-submarine warfare, combating surface vessels, and defending against air attacks on their own ship or squadron. Supply ships are trained to support naval task forces, which can be composed of various ships and boats depending on the mission. The primary logistical task of a supply ship is to provide fuel, consumables, provisions, and ammunition. A supply ship may also be equipped with a weapons system, for example, to defend against enemy attacks.
0093In this context, a "vehicle component" refers to a part of the watercraft that, as a whole, fulfills at least one specific function. A vehicle component can be a single part, i.e., an individual component of a technical complex, or a system of several components that together fulfill this function. Typically, all components of a particular vehicle component are installed as a unit in a vehicle. For example, a rudder system, a radar system, a weapon system, an engine unit, a control unit, etc. can each represent a vehicle component.
0094A "sensor", also called detector, (measurement or measuring) transducer or (measuring) probe, is a technical component that can qualitatively or quantitatively detect certain physical or chemical properties (physical, e.g., heat quantity, temperature, humidity, pressure, sound field quantities, brightness, acceleration, or chemical, e.g., pH value, ionic strength, electrochemical potential) and/or the material composition of its environment. These quantities are detected using physical or chemical effects and converted into a processable electrical signal. This processable electrical signal can include, in particular, data that can be processed electronically and represents the quantity. The electrical signal that can be processed further does not necessarily have to be generated in the detector itself, but can also be generated from the detector's output signal by electronics connected to the detector.
0095Here, a "weapon system" refers to (often complex) technical defense equipment, particularly large military equipment. A component of the weapon system is the actual weapon. For example, a warship may carry weapons in the form of anti-aircraft missiles within a weapon system designed as a close-in defense system. In particular, a weapon system can be a combination of individual technical elements that interact with each other and, through this combination, achieve an improved weapon effect or even make it possible in the first place.
0096For example, the Common Remotely Operated Weapon Station (CROWS) is a weapon system. Another example of a weapon system is a gun mounted on a self-propelled gun carriage or on a ship's deck. Depending on the design, the vessel's engine power is used both for propelling the vessel and for aiming the gun, or the weapon system includes its own independent engine for aiming the gun. An anti-aircraft missile system is another example of a weapon system. The various components, such as sensors (e.g., a radar system), control center, and launch system of the anti-aircraft missile system, can collect various measurement data that are processed for monitoring, status control, and correct alignment of the radar system and/or the missiles.
0097In this context, a "drive unit" refers to the structural unit that uses energy conversion to move a machine, such as a ship's turbine. This is often a motor with a potentially necessary gearbox. The drive unit can include a rotary drive or a linear drive. It can derive its energy from fossil fuels (especially oil, natural gas, and coal), nuclear energy (nuclear fission), battery power, and other energy sources.
0098In this context, a "navigation system" is understood to be a technical system that uses position determination (satellite, radio, GSM or inert or autonomous system) and geoinformation (topological, road, air or sea charts) to guide the user to a chosen location or along a route, taking desired criteria into account.
0099A "measured value" here refers to the value of a quantity measured by a sensor. Examples of measured values include temperature in °C, position in the form of GPS coordinates, rotational speed in revolutions per minute, etc. "Measured values" are also referred to as "measurement data".
0100Here, a "database" refers to a data structure for the structured storage of data. A database can be a directory tree or a file. Preferably, a database is a data structure managed by a database management system (DBMS). A database management system (DBMS) is an electronic data management system designed to efficiently, consistently, and permanently store large amounts of data and to provide required subsets in various, needs-based formats for users and application programs. A database system provides a database language for querying and managing the data. The database can be a relational database. The structure of the data is defined by a database model.
0101In this context, a "history of measured values" refers to a data set that specifies the temporal progression of several measured values.
0102A "timestamp" is understood here to be a data value that specifies a particular point in time, e.g., the date and time when a specific measurement was recorded. Timestamps are preferably given in or relative to Coordinated Universal Time (UTC). This can prevent potential misunderstandings due to globally differing time zones.
0103The term "persistently stored" here refers to the storage of data on a non-volatile storage medium.
0104The term "protected storage" here refers to data storage that technically ensures that only a specific selection of users and/or applications that can prove they are authorized to access the protected data can write to and/or read from it. For example, protection can consist of storing the data in an access-protected area and/or storing the data in encrypted form so that it can only be read by a program that possesses a suitable decryption key.
0105A "real-time capable" system, such as a real-time automation system, is a system designed to perform a task in "real time." This means that the system is capable of continuously fulfilling this task within a predefined maximum duration. Typically, this means that the hardware and/or software system in question is subject to a "real-time constraint," for example, from event to system response. Real-time programs must guarantee a response within specific timeframes, often referred to as "deadlines." Real-time responses are often understood in terms of milliseconds, and sometimes microseconds or seconds. A system not specified as operating in real time generally cannot guarantee a response within a timeframe, although typical or expected response times may be provided.
0106In this context, a "host" or "host computer" refers to a computer that, alone or in interaction with one or more other computers, provides a specific software program (guest software program), thus making it available to other programs and/or users. The guest program can be a database, an application program, a service, or other programs and program modules.
0107Here, a "container" refers to a runtime environment for software programs that includes and provides all the system components required for executing these programs and isolates the software programs running within the container from programs outside the container. A container can be a virtual machine created and managed by a hypervisor (a program for managing virtual machines). Preferably, a container is a runtime environment that can be managed using a container virtualization program. Containers according to these embodiments typically require fewer resources than virtual machines because they do not start their own operating system and instead run within the context of the host operating system. Nevertheless, the containers are isolated from each other and from the host system, although not as tightly as with virtualization.
0108For example, the free software "Docker" can be used to define containers and isolate applications from each other using container virtualization. Docker simplifies application deployment because containers, which contain all necessary packages, can be easily transported and installed as files. Docker packages the application and all system components required for its execution into a single file, the so-called "container." Docker containers ensure that applications run reliably after being moved from one environment to another. This not only simplifies the deployment of complex applications across different computers, but also enables a more flexible application infrastructure that is easier to modify, extend, and scale.
0109Container virtualization is a method for running multiple instances of an operating system (as so-called "guests") in isolation from each other on a host system. Unlike virtualization using a hypervisor based on multiple virtual machines, container virtualization has some limitations regarding the types of guests it can run, but it is considered particularly resource-efficient. Container virtualization is based on several principles, which are implemented differently in individual container virtualization software products. However, one core principle is always similar: multiple containers share a kernel and isolate at least some of the operating system resources used from each other.
0110For example, the open-source program Kubernetes can be used as a container management program. Kubernetes is container orchestration software that enables the simple and efficient orchestration of applications across multiple hosts. Kubernetes facilitates simplified or even fully automated deployment, operation, maintenance, and scaling of container-based applications. Groups of hosts running containers are grouped into clusters of physical or virtual machines and managed as a unit. Kubernetes defines a Container Runtime Interface (CRI) that container platforms must implement to be orchestrated by Kubernetes. These implementations are also known as "shims." This makes Kubernetes platform-agnostic: alongside or... Instead of Docker, other platforms with appropriate shims, such as CRI-O or KataContainers, can also be used.
0111In this context, "container management software" refers to software configured for the automated deployment, scaling, and management ("orchestration") of multiple (at least two) containers on multiple computers in such a way that each computer serves as a host system for one or more containers, with the containers (of the same host computer system as well as different host computer systems) being isolated from each other. For complex vehicles, this can involve several hundred containers. Kubernetes, for example, can be used as container management software.
0112In this context, an "analysis module" refers to software designed to process measurement data from one or more sensors using one or more different computational methods in such a way as to generate an answer to an analytical question. The software can be a script, a complex application program, a program library, or a combination of two or more of the aforementioned options. The computational method can be a heuristic, a rule explicitly specified by a programmer, a mathematical and especially statistical algorithm, e.g., a correlation analysis method, or any other explicitly formulated computational procedure. The computational method can also be a procedure that is only implicitly formulated, e.g., in the form of the mathematical model of a machine learning program created during a training process. For example, the model can be specified in the network architecture and the weights of network nodes of a neural network. The analytical question can address various issues, such as the current or predicted future state of a vehicle component (parameters for vibration, conductivity, elasticity, etc.). indicative of a critical wear condition?), or a question regarding which measurement parameter values indicate a critical system condition has been reached or is expected to be reached in the future, the question about the current and future availability of fuel or wear parts, or a question about a recommended measure to prevent or mitigate a current or future critical condition of the vehicle or a vehicle component.
0113In this context, an "encryption key" is understood to be a cryptographic key that is designed to be used for encrypting data. In symmetric methods, i.e., in all classical methods of cryptography and also in modern algorithms such as the Data Encryption Standard (DES) or its successor, the Advanced Encryption Standard (AES), both communication partners use the same (secret) key for both encryption and decryption. Asymmetric encryption methods, such as the RSA cryptosystem, use key pairs consisting of a public key and a private key. The public key is not secret; it is disclosed to at least the party that is to send encrypted data to the owner of the private key. The public key can then be used to encrypt data. It is important that a public key can be uniquely assigned to a specific entity, such as a user or an analysis module. To decrypt the ciphertext, the private key is required. Unlike symmetric encryption methods, where multiple parties share a secret key, in asymmetric encryption methods only one party possesses the private (secret) key. Therefore, it is fundamental that the private key cannot be derived from the public key.
0114In this context, an "automation system" refers to a system for the fully or semi-automatic control of a watercraft. Control is achieved through predefined rules based on current measurements from one or more sensors, which are translated into control commands by the automation system, and/or based on control commands entered by a user via a user interface. According to the invention, the automation system is a real-time capable automation system. According to embodiments of the invention, the automation system is configured not only to receive current measured values and/or manually entered control commands as input and to control the vehicle accordingly, but also to receive results of analyses from one or more of the analysis modules, wherein the automation system interprets and implements the results as control commands.
0115A "computer cluster," or simply "cluster," refers to a group of networked computers. The cluster can be configured to increase the computing capacity and/or availability of the computers or the services they provide. The computers within a cluster (also called "nodes") are often referred to as servers. According to embodiments of the invention, the computers in the computer network each host one or more containers, the distribution of which across the computers is orchestrated by container management software. Analysis modules or other programs, which may be implemented as services, for example, can be executed within the containers, and whose results can be made available to specific vehicle components. Because of this function of providing analysis results, the computers can also be referred to as "servers".
Brief description of the drawing
0116The following describes embodiments of the invention with reference to the drawing. The drawing shows<dl id="dl0001"><dt>Fig. 1A</dt><dd>a block diagram of a military watercraft with several sensor-equipped vehicle components;</dd><dt>Fig. 1B</dt><dd>a system comprising several military watercraft and a computer with fleet analysis software;</dd><dt>Fig. 2</dt><dd>a block diagram of a distributed computer system that can be used to store and analyze sensor measurement data;</dd><dt>Fig. 3</dt><dd>several analysis module-specific asymmetric cryptographic key pairs and their use;</dd><dt>Fig. 4</dt><dd>Components of a military watercraft with multiple databases and analysis modules.</dd></dl>
0117<figref idref="f0001"><b>Figure 1A</b></figref> Figure 1 illustrates a block diagram of a military watercraft 100 with several sensor-equipped vehicle components. For example, the vehicle components include a propulsion system 104, which includes, for example, a diesel-powered marine engine with a gearbox coupled to the engine. The drive system contains several sensors for measuring various parameters of the motor and gearbox, including a sensor 112 for the rotational speed of a shaft that is mechanically coupled to the gearbox.
0118The vehicle components of the watercraft also include a navigation system 106 with a GPS sensor 114 for determining the current position of the vehicle, as well as a rudder 108 with a position or angle sensor for determining the current angle of the rudder relative to the longitudinal axis of the watercraft. Furthermore, the vehicle incorporates an electronic monitoring unit 110 with several sensors, which includes several sensors 118 and 120. The sensors of component 110 automatically and preferably continuously or repeatedly determine vehicle and environmental parameter values. These parameters include, for example, air pressure, humidity, air temperature, water temperature, water flow rate, and/or other parameters.
0119All or some of the recorded parameters are forwarded to an automation system 124 immediately after their acquisition. The automation system is a fully or semi-automatic system for monitoring and controlling the internal states of the watercraft, as well as for controlling the movement or other actions of the craft or its components. The automation system is a real-time system designed to use the sensor readings and user input via a user interface to control the watercraft accordingly.
0120Over time, a large number of measurement data points are generated during the ship's operation. These data points are timestamped to reflect the time they were generated. The measurement data and their timestamps are stored in a database (122), thus creating a history of the parameter values recorded for one or more measurement parameters. The database is, for example, a relational database such as PostgreSQL or MySQL. about a NoSQL database.
0121The database and several analysis modules for analyzing the data are stored and instantiated in a computer system 126. The computer system 126 can be a standalone, monolithic computer system. Preferably, however, it is a computer network comprising several computers connected to form a functional unit. Such a computer network is, for example, advantageous with regard to<figref idref="f0002">Figure 2</figref> described in more detail.
0122The vessel also incorporates a Weapon System 102, which also includes sensors (not shown). Because the vessel is a significant target for enemy forces due to the weapon system, and because malfunctions pose a potential danger to its own crew as well as uninvolved third parties, the safe operation of the automation system is of paramount importance. "Safe operation" here means that the automation system, as well as the data on which it bases its decisions, must be protected from manipulation by third parties.
Example 1: Improved monitoring and control of a rudder system
0123For example, the vessel in question could be an overseas vessel equipped with a rudder system, particularly a twin rudder system. The rudder system has a control system designed to monitor and adjust the position of the rudders.
0124In current technology, such installations are only monitored in accordance with SOLAS (International Convention for the Safety of Life at Sea) and therefore only in a rudimentary way (collective alarm). For military watercraft, the precision of monitoring is often insufficient: With the currently available twin rudder systems, it can happen that the rudders do not react synchronously to rudder position control commands: For example, the starboard rudder reaches a rudder position in response to the control command faster than a corresponding rudder position control command reaches the port rudder. Even if the commands arrive simultaneously, one side of the rudder system may not be able to execute the command as quickly as the other. This asynchronicity impairs the performance of the rudder platform and makes precise control of other system components, such as the weapon system, more difficult. The causes for asynchronous command transmission and/or implementation could be manifold and interact in complex ways: different sliding properties of the rudder shafts, aging potentiometers in corresponding circuits, different control pressures and much more.
0125Embodiments of the invention address this problem as follows: A rudder system is used which contains a plurality of sensors for several different rudder system-specific parameters, here referred to as "rudder system parameters". The rudder system parameters include two or more of the following: pressures of the rudder system's oil circuits, voltages of the rudder system's electrical control system, currents of the rudder system's electrical control system, the position of the rudders, and/or accelerations (especially vibrations) occurring at the rudder shafts. The rudder system sensors are configured to regularly measure these parameters within relatively short time intervals (e.g., to take a measurement of a rudder system parameter at least once per minute (preferably at least 10 times per second), optionally encrypt and/or sign this measurement, and store it in a database along with a timestamp. In some embodiments, the sensor's recording frequency can also be dynamically adjusted to the conditions, e.g. The measurement frequency increases when one or more relevant parameters change above a predefined threshold. The timestamp can, for example, indicate the time when a measurement is saved to the database, with this time being very close to the time of data acquisition and therefore representing that time at least approximately. The position data of the rudders of the rudder system are also recorded by sensors as "rudder system parameters", so that the control system is able to determine whether the rudders of the rudder system have reached the positions they are supposed to take according to the control commands.
0126In addition to these "rudder system parameters," several other sensors inside or outside the rudder system record environmental parameter values, such as the ship's speed, water temperature and/or water depth, and/or the operating states of other vessel components, such as a pump system. For example, if the ship's speed (measured, e.g., If the speed (in meters traveled per second) is not available, the drive power and/or turbine speed can alternatively be used as an indicator of speed.
0127These embodiments implicitly capture the times a rudder system requires until, under given environmental conditions and a given state of the rudder system, the rudders execute the respective control commands and reach the desired positions, because the measurement data and preferably also the control commands are time-stamped and stored in the database. By analyzing the history of these measurements, or... Commands from an analysis module can thus easily relate measured values and rudder states to the times at which the control system sent control commands to the actuator system.
0128According to embodiments, an analysis module is provided which, based on the recorded and stored in the database and linked with timestamps measured values of rudder system parameters, environmental parameters and rudder system control commands, determines the times until a control command has been fully implemented by the rudders affected by the command under the prevailing conditions. The determined times are used by the analysis module to adjust the sending of the control commands and/or the content of the control commands in such a way as to improve the synchronization of the rudders of the rudder system.
0129In some embodiments, the analysis module is configured, for example, to detect correlations between measured rudder deployment times and the value ranges of rudder system parameters and environmental parameters. Thus, a large number of factors are considered, not just the current deviation of the rudder position from the target position, to determine if and when a rudder will assume a desired position. Potential asynchronies between the port and starboard rudders can be detected early and reliably, allowing for timely responses and rapid, dynamic adjustments to the control commands of individual rudders, ideally in real time. Predicting asynchronies also enables the forecasting of necessary maintenance work and facilitates its planning.
0130The analysis module for improved rudder control can, for example, identify potential causes of asynchronies based on acceleration and vibration data and display this information to the user. However, the analysis considers not only acceleration data (oscillations/vibrations) but also other rudder system parameter values and environmental parameters. This can be advantageous because the vibrations and oscillations that occur depend heavily on water depth, rudder position, sea state, fouling, the rudder system's operating states, and the ship's speed. Without considering this context, acceleration data is often insufficient for precise control of the rudder system or for accurately predicting the date of the next required maintenance. In contrast, an analysis of the acceleration data in combination with the other rudder system parameters and environmental parameters makes it possible to identify vibration states that can provide information about the current deviation of a rudder actual position from a rudder target position or the current material fatigue state of the rudder system.
0131According to one embodiment of the invention, the vehicle components of the watercraft comprise a rudder system with a control unit, one or more starboard and one or more port rudders. The control unit is designed to coordinate, and in particular synchronize, the position and movement of the starboard and port rudders by sending control commands to the starboard rudders on the one hand and to the port rudders on the other. The rudder system includes several sensors designed to detect rudder system parameter values, the rudder system parameters comprising two or more of the following measurement parameter values: current position of the rudders, rudder vibrations, fouling of the rudders (e.g. by means of an optical sensor or with a force sensor that measures the force in the direction of the flow), vibrations of components of the rudder system, switching states of the rudder system.
0132One or more of the other vehicle components and/or the steering system also include several sensors designed to detect environmental parameter values, the environmental parameters comprising two or more of the following measurement parameter values: water depth, sea state, ship speed.
0133One of the analysis modules is an analysis module for improved control of the rudder system and is designed to analyze the rudder system parameter values, the environmental parameter values, and the time durations between sending control commands from the control unit to the respective rudders and the implementation of the control commands, in order to identify correlations between the time durations, the rudder system parameter values, and to recognize the environmental parameter values and/or to improve the coordination of the rudders of the rudder system.
0134For example, the analysis module for improved control of the rudder system can be trained to automatically determine that, given the sea state and fouling, the command to the starboard rudders must be sent 400 milliseconds earlier than the corresponding control command to the port rudders. The analysis module sends a corresponding control command to the control unit of the rudder system, thereby causing the control unit to send the command to the starboard rudders only after the aforementioned delay to the port rudders.
0135According to embodiments of the invention, the analysis module for improved control of the rudder system is designed to analyze the rudder system parameter values, the environmental parameter values, the time intervals between sending control commands from the control unit to the respective rudders and the implementation of the control commands, and additionally, condition and/or vibration parameter values obtained from sensors of other vehicle components. in particular the engine and/or the transmission and/or a radar system, were recorded in order to identify correlations between the time durations, the rudder system parameter values, the environmental parameter values and the condition and/or vibration parameter values of the other vehicle components and/or to improve the coordination of the rudders of the rudder system.
0136These characteristics are based on the observation that vehicle components, even those not explicitly linked to the steering system, can influence its behavior and controllability. For example, a radar system could be excited by the frequency generated by a propulsion diesel engine at a certain speed, leading to a negative impact on the steering system.
0137For example, the control system can be implemented in the form of logic rules. These rules can be used not only to control the rudder system as described here, but also to control other components of the watercraft. For example, one of the logic rules could stipulate that an internal combustion engine can only be started if at least one exhaust passage is open. This rule is executed every time this engine is started, and depending on the result of the check to see if an exhaust path is open, either such an exhaust path is automatically opened or the starting process is aborted - possibly accompanied by a message to the user.
Example 2: Improved detection and prediction of consumption and conditions
0138Environmental parameters and condition-related parameters of vehicle components are interdependent in a complex way.
0139For example, if the seawater temperature is higher, the cooling systems that use seawater for cooling operate differently than with cold seawater. Power consumption increases, and the diesel engines used for power generation are subjected to greater strain. This in turn has an impact on the maintenance and wear of the units, which are not only subjected to greater stress due to higher seawater temperatures because more energy has to be used for cooling, but are also less able to achieve their own cooling, since the machines and capsules are usually cooled with seawater just like the engine itself. The performance characteristics of seawater-cooled vehicle components are therefore often difficult to compare, and predictions regarding their energy consumption are subject to uncertainties.
0140According to embodiments of the invention, one of the analysis modules is configured to calculate the current or future energy consumption and/or the current or future degree of wear of a vehicle component as a function of the temperature of the ambient water used as cooling water.
0141This data basis can also be used, for example, to automatically find similar operating modes of the entire watercraft, e.g. operating modes defined by the temperature of the ambient water, in order to take into account the evaluation of measurement data and/or other performance parameters of the entire watercraft in such a way that only comparable operating modes of the vehicle are compared with each other.
0142According to embodiments, one analysis module is configured to use the temperature measured at different times to automatically identify similar operating modes of the entire watercraft, which are defined by a specific temperature or temperature range of the ambient water. The analysis module is configured to analyze measurement data and/or other performance parameters of the entire watercraft in such a way that only comparable operating modes of the vehicle are compared with each other in order to calculate, in particular, the future energy consumption, the currently maximum possible range and/or the current or future degree of wear.
0143Furthermore, by analyzing performance and condition measurements recorded by sensors of a large number of vehicle components and stored in the database, as well as by recording and analyzing the usage profiles of the individual vehicle components (which specify, for example, how often which components are used), it is possible to... By understanding which situations redundant vehicle components are used and/or how high the utilization of different vehicle components is under different readiness and usage conditions, both the commissioning and usage phases of different vehicle components can be improved. These findings can make it possible to automatically or manually optimize the operating modes of individual vehicle components or to improve the technical properties of a (new) vehicle component.
Example 3: Cross-vehicle analyses
0144The acquisition and storage of a large number of measured values over longer periods of time (measurement history) according to embodiments of the invention already offers significant advantages at the application level.
0145Further significant advantages arise for systems in which the measurement histories of several parameters, recorded by multiple vessels, are analyzed by fleet analysis software. For example, a data acquisition system and analysis module can be developed, at least for the rudder systems of the vessels, as described in Example 1. The rudder systems of the different vessels can be, but do not have to be, of the same type (i.e., e.g., (from the same manufacturer). Even if the steering systems differ slightly, at least subsystems such as the individual sensors of the steering system or the control unit can be identical or comparable. Often, different manufacturers of certain vehicle components use the same parts supplied by a single vendor.
0146By importing the databases containing the measurement histories of multiple vessels into a central and highly secure database, e.g., within the secure infrastructure of a home port, cross-platform analyses can be performed. For example, at least some of the historical data can be imported into the central database and deleted from the vessel's own database while it is in its home port. This increases data security and reduces the storage requirements of the watercraft's database.
0147The various data sets can be useful in multiple ways. For example, fleet analysis software can analyze various environmental parameters such as air and water temperature, flow conditions, etc., to determine whether the vehicles or vehicle components were operated under comparable conditions, or to identify vehicles and components that were operated under comparable, i.e., sufficiently similar, conditions. In the next step, the fleet analysis software can then analyze and identify whether vehicle components of a specific type or manufacturer perform better or worse than functionally equivalent vehicle components of a different type or manufacturer with regard to one or more performance parameters. This way, a problem that has already occurred with one vehicle component can potentially be prevented with another. Furthermore, it is possible to determine across vehicles how a particular vehicle component can be operated better, or should not be operated, in order to avoid certain types of damage.
0148The action recommendations calculated by the fleet analysis software can be issued to a user to prompt them to make improvements to specific vehicle components, as well as components of the same or similar type. According to some implementations, individual analysis modules and/or the fleet analysis software can be configured to also calculate and issue tactical recommendations based on the data in the database(s).
0149<figref idref="f0001"><b>Figure 1B</b></figref> Figure 150 shows a system with several military watercraft 100, 130, 132. Each of the watercraft can be configured as a watercraft of the embodiments described herein. Preferably, the watercraft all belong to the same or a similar type of vessel. However, it is also possible that the watercraft belong to different vehicle types; in this case, an evaluation of the sensor data histories for several watercraft can be advantageous, e.g., if the vehicles of different types contain some or more vehicle components of the same type, so that a comparison of the component-related measured values is useful at least for these vehicle components.
0150System 150 also includes a computer system 134, which can be configured, for example, as a single computer or a computer network. The computer system includes an interface 136 for the secure import of the contents of the databases of the watercraft 100, 130, and 132. Depending on the implementation variant, the interface 136 can be implemented differently. For example, it can be a wired interface. Based on fiber optic technology, which allows for the rapid transmission of large amounts of data. In some cases, however, it may also be a contactless interface, e.g., via a wireless connection, or a USB interface for importing data onto a portable drive via USB. In any case, several technical and/or organizational security measures are in place to ensure that the data cannot be read or manipulated during transmission. For example, transmission may only take place in encrypted form via an end-to-end encrypted data transmission channel. Alternatively, authentication of the user initiating the data transmission may be required, e.g. via password-based and/or biometric authentication methods. For example, the computer system 134 and the interface 136 for secure data transmission can be part of the IT infrastructure of a home port, which can be used to import and collectively evaluate the measurement data automatically generated by the vessels during their operations.
0151The evaluation of data from multiple vessels is performed by fleet analysis software 138, which is instantiated on computer system 134. The fleet analysis software analyzes the imported measurement data from the vessels' databases. The imported data can, for example, be stored and analyzed in a central relational database on computer system 134. During the analysis, the fleet analysis software automatically detects whether the measurements from different watercraft were taken from vehicle components of the same type. This information can be helpful in ensuring that the correct measurements are being compared. For example, an engine temperature sensor measures the engine temperature, while a temperature sensor on the outside of the vehicle below the waterline measures the water temperature. It is important to consider which sensor or vehicle component a parameter value, such as "temperature," originates from during the analysis. A comparison is generally only meaningful if the measured values come from sensors and components of the same or similar type; for example, only comparing temperature values for the "engine" component. Ideally, the manufacturer should also be included in the analysis. For example, It is possible that different manufacturers of the same type of vehicle component (engine) mount the sensor in slightly different positions or use different sensor types. In this case, considering the different manufacturers or other relevant circumstances can contribute to incorrect analysis results due to a misinterpretation of minor manufacturer-related measurement deviations.
0152During the analysis, the fleet analysis software uses imported measurement data to identify which of the vessels are optimally or worst equipped with regard to at least one specific target criterion. This target criterion is a technical evaluation criterion such as... The vehicle with the best energy and wear part reserves, the vehicle with the least maintenance backlog, and/or the longest time until the next inspection is due. Additionally or alternatively, the fleet analysis software identifies critical conditions of vehicle components in one or more of the vessels. For example, the fleet analysis software can identify all those vehicles in which vibration parameters indicate that within the last 6 months, temperatures and/or speed values were measured in an engine, e.g. due to material fatigue or other adverse factors, which must be considered dangerous for the vehicle component and/or the crew.
0153In some configurations, the fleet analysis software is designed to predict the point at which a critical condition of a vehicle component will occur in one or more of the watercraft. This could be the point at which energy, oxygen gas, or food supplies run low, when a failure of an essential component due to wear is expected, or similar events.
0154In some embodiments, the fleet analysis software is also designed to automatically identify one or more environmental parameters and/or vehicle component parameters and their corresponding parameter value ranges that are the cause of a critical condition of one of the vehicle components in one or more of the watercraft. This is a particularly advantageous aspect, especially in the context of highly complex military watercraft: sometimes vehicle components and parts are defective well before the expected, normal end of their service life, without any clear cause being identifiable. Sometimes it can also be observed that a particular component in a particular watercraft repeatedly fails, while the same component lasts significantly longer in other watercraft of the same type and with the same components. Given the highly complex interaction of various components and environmental factors, it is regularly assumed that the cause of the problem lies in an interaction of the component with its environment, although it is not known exactly which cause is specifically responsible for the failure of the component. The mechanical stresses on components depend on a wide variety of factors, such as the vibration behavior of spatially adjacent components, the sea state, wind and current conditions to which the vehicle is exposed during its operation, and last but not least, manually entered control commands from the crew. Given this complexity, it is often not possible to identify specific causes for component failure through a thorough inspection of a particular vehicle. Only by analyzing a large number of measurements, recorded and stored over a longer period by the sensors of numerous watercraft, is it possible to correlate the failure of certain components with the interaction of several other factors, such as a specific driving style, a specific air temperature, a specific salinity, This is due to specific flow conditions and the use of certain other components and vehicle parts from other manufacturers. Fleet diagnostics thus enables improved fault diagnosis based on a broader data basis, including the detection of faults that are caused in a highly complex, often non-linear way by the interaction of several specific factors.
0155<figref idref="f0002"><b>Figure 2</b></figref> Figure 126 shows a block diagram of a distributed computer system that can be used to store and analyze sensor measurement data. The computer system shown here comprises five computers (202, 204, 206, 208) that are functionally interconnected via a network (280), for example an intranet, to form a computer cluster, and on each of which several containers (212-230) are instantiated. Each of the computers has one or more 240, 242, 244, 246 processors, 248, 250, 252, 254 RAM, and optionally one or more non-volatile data storage devices.
0156Each container holds and executes a maximum of one instance of an analysis module. For example, the analysis modules can each be implemented as a so-called microservice.
0157Some analysis modules exist only in a single instance. For example, analysis module AM2 runs only as a single instance 262 within container 214, analysis module AM3 only as a single instance 264 in container 216, and analysis module AM4 only as a single instance 268 in container 222. However, some analysis modules can also run in multiple instances within a corresponding number of containers. For example, the analysis module AM1 is instantiated in the form of the two instances 260 and 266 in containers 212 and 220 respectively.
0158The number of instances of each analysis module instantiated and/or closed, and on which machine this occurs, is controlled by the container management software 256. Software 256 dynamically orchestrates the instantiation, migration, and closure of containers and their contained analysis modules according to various optimization criteria, which are preferably configurable by a user. Optimization criteria can include, for example, load balancing, upscaling and downscaling criteria, which ensure that the computing load is evenly distributed among the computers, that some frequently used analysis modules can be executed in parallel in multiple instances, and that a fast response time and/or high reliability is guaranteed.
0159The measurement data recorded by the sensors of the various vehicle components of the watercraft 100 are stored in a database 122. To increase the reliability of the database, the database contents are stored redundantly on the various computers 202-208. Various methods for distributed, redundant data storage are known in the prior art, for example, storage using error correction methods with error correction bits. In some embodiments, some of the containers 224-230 can also be used to store parts of the database data.
0160The automation system 124 also includes one or more processors 282, main memory 284 and automation software 286. The automation software is configured to dynamically receive currently acquired measurement data from at least some of the sensors and to use this, possibly together with commands entered by a user, as input in order to derive one or more control commands from this input and to automatically control the behavior of one or more vehicle components 102, 104, 106, 108, 110 on the basis of the control commands.
0161The computer system 290 with the automation system 124 is connected to the computer network 126 via a data communication channel 292. In some embodiments, the automation system can send a request to an access service 288 via the data connection 292 in order to read data from the distributed database 122 and use it for calculating control commands. The automation system is operationally decoupled from the analysis modules, meaning that it preferably runs on a different computer and, if it uses the measured values stored in the database, accesses the measured values asynchronously to the analysis modules.
0162<figref idref="f0003"><b>Figure 3</b></figref> shows several analysis module-specific asymmetric cryptographic key pairs that can be used for the secure transmission and storage of measurement data.
0163For example, the drive system 104 can be manufactured by a first manufacturer H1. Manufacturer H1 also develops an analysis module AM4, which is designed to analyze measured values acquired by one or more sensors 112 of the drive in order to automatically predict the current and/or future state of the drive system 104. Before or during the development of the AM4 analysis module, the manufacturer H1 generates a first asymmetric cryptographic key pair with a first secret decryption key 344 and a corresponding public encryption key 332. Before the AM4 analysis module is delivered to the operator or manufacturer of the military watercraft 100, the secret cryptographic decryption key 344 is integrated into the AM4 analysis module in such a way that it cannot be read by unauthorized third parties. In addition, the speed sensor 112 of the propulsion system 104 is provided with the public encryption key 332.
0164The public keys, all shown here with thick outlines, can be generated specifically for each individual sensor of a vehicle component, along with their corresponding private keys. In other embodiments, however, it is also possible for all sensors of a vehicle component to use the same cryptographic key pair. Share the public key of this pair and use it to encrypt the measurement data recorded by each sensor. Generating key pairs individually for each sensor offers the advantage of very fine-grained control over access rights. Generating key pairs individually for each vehicle component and using the same public key for the sensors of the same vehicle component has the advantage of simplified key management, because as a rule, though not always, the measurement data recorded by different sensors of a vehicle have identical or similar requirements for their confidentiality.
0165All measured values acquired by sensor 112 for storage in database 122 are encrypted with the public key 332. This means that all other analysis modules AM1, AM2, and AM3 cannot decrypt the data acquired by speed sensor 112 and encrypted with key 332.
0166In one embodiment, however, the speed sensor 112 is configured to encrypt copies of the measured values it acquires with a public key 330, which is assigned to an analysis module AM3 of another manufacturer H2, so that this analysis module AM3 can decrypt the copies with its corresponding private cryptographic key 342. For example, contractual trust relationships can exist between manufacturer H1 and manufacturer H2 of the rudder 108, so that the sensor 112 of the drive system encrypts the measured values it has recorded not only with the public key 332, but also in copy with the public key 330, so that not only analysis module AM4 but also analysis module AM3 can access and decrypt these measured values.
0167Similarly, the vehicle component 110, which includes a temperature sensor 120 and a pressure sensor 118, can be manufactured by a third-party manufacturer H3. Manufacturer H3 also develops the analysis modules AM5 and AM6, which can be instantiated in multiple copies on the computer system 126. Modules AM5 and AM6 both evaluate temperature and pressure data, but with regard to different analytical purposes or questions. Sensor 120 generates its measurement data in the form of two copies, encrypted with different public keys 324 and 322. Sensor 118 also generates its measurement data in the form of two copies, encrypted with public keys 324 and 322. Data encrypted with key 322 can be decrypted and processed by any analysis module that contains the corresponding private key 334. Data encrypted with the key 324 can be decrypted and processed by any analysis module that contains the corresponding private key 336. Each of the multiple instances 306-312 of the AM5 analysis module contains the private key 334. Each of the multiple instances 314-318 of the AM6 analysis module contains the private key 336.
0168In the example shown, the rudder 108 incorporates three sensors of different types, including the angle sensor 114. Each sensor is assigned a public key 326-330, which, together with a corresponding private key 338-342, forms an asymmetric cryptographic key pair. The measured values acquired by the sensors are encrypted in triplicate and stored in the database, each copy using a different public key. Analysis module AM1 can only decrypt data encrypted with public key 326. Analysis module AM2 can only decrypt data encrypted with public key 328. However, analysis module AM3 possesses two private keys, 340 and 342, and can therefore decrypt data encrypted with public key 328 or public key 330.
0169This precise control of access rights is particularly advantageous in the area of military vessels, because often it is only a combination of specific data that is security-critical, not individual data values. For example, GPS position data is always security-critical, as it allows enemy units to launch an attack on the vessel. The position of a vessel below the waterline (if it is a submarine) is generally not critical on its own, provided no other positional data is known. The same applies to data such as water temperature or current conditions. However, combining the vessel's underwater position with current and temperature data allows, in some cases, at least an approximate determination of the vessel's current position.
0170The use of different encryption keys for different types of measurement data according to embodiments of the invention allows for fine-grained control of access to this measurement data. Analysis modules have only one or a few private keys and can therefore only access and process measurement data that was captured by a sensor that used a public key corresponding to these private keys for encryption.
0171In some embodiments, a single highly trusted software possesses a copy of all the private keys of the analysis modules. For example, the highly trusted software could be another analysis module with extended privileges, developed by the vehicle operator. Additionally or alternatively, the fleet analysis software can have a copy of all private keys of the analysis modules in order to analyze the data of all sensors of all watercraft in a fleet.
0172<figref idref="f0003">Figure 3</figref> This shows the assignment of private decryption keys to the individual analysis modules and the assignment of public encryption keys to the sensors (or the vehicle components containing these sensors). The sensors collect measurement data and encrypt it using their assigned public keys.
0173According to embodiments of the invention, further asymmetric cryptographic key pairs are assigned to the sensors and analysis modules, but for the purpose of signature verification (not shown here). In this case, private signing keys are assigned to the individual sensors or to the vehicle components containing these sensors. The sensors or vehicle components use the signing keys to sign the acquired and optionally encrypted measurement data. The individual analysis modules have access to public signature verification keys, each of which forms an asymmetric cryptographic key pair with one of the signing keys. For example, the public signature verification keys can be part of individual analysis modules. The analysis modules are configured to check the validity of the measurement data signatures using signature verification keys and to process the measurement data further only if its signature is valid.
0174<figref idref="f0004"><b>Figure</b> 4</figref> This shows, as an example, some components of a military watercraft with several analysis modules ("AMs") and a database 122. Here, database 122 is implemented as two separate databases, each containing different parts of the data. Database 122.1 contains measurement data with a normal security level, which is available in whole or in part in unencrypted form. Database 122.2, on the other hand, contains sensitive measurement data, also referred to as "red data" in the military context, and is preferably encrypted with one or more different cryptographic keys, e.g. according to a [document/code] with regard to<figref idref="f0003">Figure 3</figref> described encryption method. Box 406 represents a variety of different measured values from different sensors of various vehicle components. For example, the measured values can originate from the following vehicle components and subsystems: various internal measurement data (e.g., condition-related measured values of various vehicle components), SBM (damage-related measurement data, e.g., regarding damage after an accident and/or combat deployment), EBM (energy-related measurement data, e.g., Condition data of a diesel engine), ONA (own noise analysis), and vibration data. Vibration data is particularly important for assessing current and future system states, as it allows, in most cases, the identification of mechanical operational problems in rotating machinery, especially aging processes in steel structures.
0175The output interface 404 can be, for example, a screen, a speaker, or a machine-to-machine interface. For instance, the interface could be a GUI that displays the results of the analysis from each analysis module to the user (424), enabling the user to take appropriate action.
0176For example, the analysis module 410 can generate an analysis showing that energy reserves will be depleted in three days if consumption remains constant. This result is displayed to the user on the screen, allowing them to take appropriate measures, such as heading to a port in time or reducing energy consumption. The analysis module for 112 can predict the expected range of energy supplies by analyzing several measured values such as currently available energy reserves, flow conditions, wind conditions in combination with user-specified data such as the chosen route for the next few days. In the event that the calculation shows that the energy reserves are insufficient for the currently selected route, but would be sufficient if an alternative route were chosen, the module can suggest the alternative route, so that the user only needs to confirm the alternative route to cause the vehicle's automation system to automatically steer the vehicle onto the alternative route. Some analysis modules can also output their analysis results directly to individual vehicle components. For example, in the event of an energy emergency on the vessel, module 410 can automatically switch off all energy consumers on the vessel that are considered non-essential for its operation, or stop supplying energy to these consumers.
0177At least some of the vehicle components may have a 402 interface to transmit acquired measurement data directly to one or more of the analysis modules 410-422. This can be particularly useful for measurement data that is important for fast, real-time responses from individual analysis modules, as it avoids delays caused by writing the measurement data to a database. The measurement data can also be processed in the background, if necessary. asynchronously, data is written to the database.
0178The analysis modules shown here are grouped according to application areas, for example, into modules of the energy generation system (EES), the maintenance system, or the "service" system. The service system includes various services, e.g., regarding the recording and/or reporting of various faults in components of the watercraft.
0179In some configurations, various external systems have access to the analysis modules and their results, for example via an external interface 408. The interface 408 can be used, for example, to export the data from database 122 in the home port, so that fleet analysis software can evaluate the exported data.
Reference symbol list
0180<dl id="dl0002" compact="compact"><dt>100</dt><dd>military watercraft</dd><dt>102</dt><dd>weapon system</dd><dt>104</dt><dd>drive system</dd><dt>106</dt><dd>Navigation system</dd><dt>108</dt><dd>Glazing system</dd><dt>110</dt><dd>Vehicle component</dd><dt>112</dt><dd>Speed sensor</dd><dt>114</dt><dd>GPS Sensor</dd><dt>116</dt><dd>Angle/position sensor</dd><dt>118</dt><dd>Pressure sensor</dd><dt>120</dt><dd>temperature sensor</dd><dt>122</dt><dd>database</dd><dt>124</dt><dd>Automation system</dd><dt>126</dt><dd>distributed computer system</dd><dt>130</dt><dd>military watercraft</dd><dt>132</dt><dd>military watercraft</dd><dt>134</dt><dd>computer system</dd><dt>136</dt><dd>Import interface</dd><dt>138</dt><dd>Fleet analysis software</dd><dt>140</dt><dd>Screen</dd><dt>202-208</dt><dd>computer system</dd><dt>212-230</dt><dd>Container</dd><dt>260-268</dt><dd>Analysis module instances</dd><dt>260, 266</dt><dd>Instances of the AM1 analysis module</dd><dt>270-278</dt><dd>Parts of the data from database 122</dd><dt>240-246</dt><dd>CPUs</dd><dt>248-254</dt><dd>RAM</dd><dt>256</dt><dd>Container management software</dd><dt>280</dt><dd>Network connection (Intranet)</dd><dt>282</dt><dd>CPUs</dd><dt>284</dt><dd>RAM</dd><dt>286</dt><dd>Automation software</dd><dt>288</dt><dd>Database access service</dd><dt>290</dt><dd>computer system</dd><dt>292</dt><dd>Data connection</dd><dt>302, 304</dt><dd>Instances of the AM2 analysis module</dd><dt>306-312</dt><dd>Instances of the AM5 analysis module</dd><dt>314-318</dt><dd>Instances of the AM6 analysis module</dd><dt>322-332</dt><dd>Public encryption keys for secure data exchange with specific analysis modules</dd><dt>334-344</dt><dd>Private decryption keys, specific to certain analysis modules</dd><dt>402</dt><dd>Input interface</dd><dt>404</dt><dd>Output interface</dd><dt>406</dt><dd>Measured values</dd><dt>408</dt><dd>external interface</dd><dt>410-422</dt><dd>Analysis module</dd></dl>
4 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| KR20070040188A | Cites | Republic of Korea | Examiner |
| US2008147257A1 | Cites | United States of America | Examiner |
| US2009271054A1 | Cites | United States of America | Examiner |
| KR20170043213A | Cites | Republic of Korea | Examiner |
| DE3150895A1 | Cites | Germany | Examiner |
| WO2019243932A1 | Cites | World Intellectual Property Organization (WIPO) | – |
| DE102008057123A1 | Cites | Germany | – |
| DE3150895A1 | Cites | Germany | – |
| KR20070040188A | Cites | Republic of Korea | – |
| KR20170043213A | Cites | Republic of Korea | – |
| US2008147257A1 | Cites | United States of America | – |
| US2009271054A1 | Cites | United States of America | – |
| US2019176945A1 | Cites | United States of America | – |
40 legal events, as 6 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Renewal fee for the european patent with unitary effect paidU20 | U20 | EP | |
| Definitive protectionFG2A | FG2A | ES | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Request for unitary effect filedU01 | U01 | EP | |
| Unitary effect registeredU07 | U07 | EP | |
| European patents granted designating irelandGrantedLANGUAGE OF EP DOCUMENT: GERMANFG4D | FG4D | IE | |
| Dpma publication of mentioned ep patent grantGrantedR096 | R096 | DE | |
| Designated contracting statesAK | AK | EP | |
| Ip right grantedGrantedST27 STATUS EVENT CODE: U-0-0-F10-F00 (AS PROVIDED BY THE NATIONAL OFFICE)F10 | F10 | CH | |
| European patent grantedGrantedNOT ENGLISHFG4D | FG4D | GB | |
| (expected) grantORIGINAL CODE: 0009210GRAA | GRAA | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: THE PATENT HAS BEEN GRANTEDSTAA | STAA | EP | |
| Grant fee paidORIGINAL CODE: EPIDOSNIGR3GRAS | GRAS | EP | |
| Party data changed (applicant data changed or rights of an application transferred)RAP3 | RAP3 | EP | |
| Party data changed (applicant data changed or rights of an application transferred)RAP3 | RAP3 | EP | |
| Intention to grant announcedINTG | INTG | EP | |
| Despatch of communication of intention to grant a patentORIGINAL CODE: EPIDOSNIGR1GRAP | GRAP | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: GRANT OF PATENT IS INTENDEDSTAA | STAA | EP | |
| First examination report despatched17Q | 17Q | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: EXAMINATION IS IN PROGRESSSTAA | STAA | EP | |
| Request for validation of the european patent (deleted)DAV | DAV | EP | |
| Request for extension of the european patent (deleted)DAX | DAX | EP | |
| Party data changed (applicant data changed or rights of an application transferred)RAP3 | RAP3 | EP | |
| Party data changed (applicant data changed or rights of an application transferred)RAP3 | RAP3 | EP | |
| Request for examination filed17P | 17P | EP | |
| Designated contracting statesAK | AK | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: REQUEST FOR EXAMINATION WAS MADESTAA | STAA | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: THE INTERNATIONAL PUBLICATION HAS BEEN MADESTAA | STAA | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: UNKNOWNSTAA | STAA | EP |
Numbers
- Publication
- 4090586
- Application
- 217005164
Titles3
- German
- MILITÄRISCHES WASSERFAHRZEUG MIT SENSOREN
- English
- MILITARY WATERCRAFT WITH SENSORS
- French
- VÉHICULE NAUTIQUE MILITAIRE ÉQUIPÉ DE CAPTEURS
Classification
- CPC, 8
- B63B79/10
- B63B79/15
- B63B79/30
- B63B79/40
- B63B79/20
- B63B35/00
- B63G1/00
- B63G13/00
- IPC, 7
- B63B79 10
- B63B79 15
- B63B79 20
- B63B79 30
- B63B79 40
- B63G1 00
- B63G13 00
Designated states38
- Contracting states, 38
- Albania
- Austria
- Belgium
- Bulgaria
- Switzerland
- Cyprus
- Czechia
- Germany
- Denmark
- Estonia
- Spain
- Finland
- France
- United Kingdom
- Greece
- Croatia
- Hungary
- Ireland
- Iceland
- Italy
- Liechtenstein
- Lithuania
- Luxembourg
- Latvia
and 14 moreShow fewer
- Monaco
- North Macedonia
- Malta
- Netherlands (Kingdom of the)
- Norway
- Poland
- Portugal
- Romania
- Serbia
- Sweden
- Slovenia
- Slovakia
- San Marino
- Türkiye
