Risk of Information Theft on Inmarsat C

Dr. Ir. F. J. Sluiman
Wednesday, March 31, 2010

Dr. Ir. Sluiman, of eXpert ICT, is a naval reserve officer assigned to the Naval Cooperation and Guidance for Shipping (NCAGS) organization of the Netherlands. All analyses and views expressed in this article are those of the author.

Communication between ship and shore is essential for the efficient operation and management of ships. The wireless systems to communicate from and to ships, however, are not always secure and the confidentiality of the communication may be invaded. Owners, operators, managers of vessels and shipmasters should be aware of this risk when using a communication system. Information theft by competitors may erode competitive advantages and could damage relationships with customers, information theft by pirates and terrorists may lead to attacks on ships.

The degree in which the security of a wireless communication system can be trusted depends on the complexity of the computations needed to decode messages intercepted from this system. Technology, however, is constantly advancing and complexity may vanish as computer power increases. Hence, security of wireless communication systems should be a continuous concern.

Presently, several Internet sites are offering Inmarsat C decoding software with the ability to fully reconstruct all Inmarsat C messages send to ships by a land earth station (LES). This is disturbing as Inmarsat C, launched in 1991 to provide low-cost data communication and GMDSS services, counts an estimated 125,000 maritime terminals.

To examine the seriousness of this threat, the most promising Inmarsat C decoding software was purchased and tested on an ordinary personal computer connected to L-Band radio receiving equipment. Tuning in on LES Burum the test showed that the decoder met its specifications: the software flawlessly decoded the Inmarsat C frames, assembled the messages, and logged them. This effectively means that maritime criminals with no more than a basic knowledge of radio technology and computers will be able to read all Inmarsat C messages send from a LES after an investment of €2500 on equipment and decoding software.

So the threat is real, but does it mean that Inmarsat C cannot be used anymore for data communication? No, it continues to be a very reliable system, be it that sensitive data needs to be encrypted. Fortunately there are some good free products available to do this. One of these products is the 7-Zip utility which can be downloaded at www.7-zip.org. This utility supports file compression with 256-bit AES encryption and is very easy to use. It decreases the amount of data to be sent and is applicable where confidential transfer of cryptographic keys between ship and shore is possible (by another communication system or by some physical means).

When confidential transfer of cryptographic keys is not possible, the GNU Privacy Guard tool downloadable at www.gnupg.org might be considered. This free tool is somewhat less intuitive to use and works with ElGamal encryption, which has the disadvantage that the size of the original data will be expanded with a factor of two. It is as such only recommended for confidential cryptographic key transfer of products like 7-Zip.

Whatever cryptographic product is decided upon, care should be taken to use sufficiently large randomly chosen cryptographic keys and to regularly change them. All these measures significantly decrease the risk of information theft on Inmarsat C, making it secure again.
 

Maritime Reporter June 2014 Digital Edition
FREE Maritime Reporter Subscription
Latest Maritime News    rss feeds

Maritime Security

Crew of USCG Cutter Thetis to Return today

The crew of the Coast Guard Cutter Thetis, a 270-foot medium endurance cutter based out of Key West, Florida, is scheduled to return to homeport Tuesday at 11:45 a.

UN Throws the Book at North Korea Ship Operator

A U.N. Security Council committee on Monday blacklisted the operator of a North Korean ship, which was seized near the Panama Canal last year for smuggling Soviet-era arms,

Tripoli Airport Ablaze, Rockets Leave Libya in Chaos

Diplomats flee Libyan chaos; Politicians appeal for international intervention. Clashes in Tripoli, Benghazi kill around 160 over two weeks, while Libyan capital face fuel, power shortages.

Communication

LiveCom Selects iDirect Evolution to Enable Global Expansion

iDirect Asia Pte Ltd today announced that LiveCom Limited (“LiveCom”), a Hong Kong based ISP, has selected Evolution as the platform to help enterprise and government

Seafarers Beware – Social Media Ahead

Videotel, part of KVH Industries, Inc., has launched a new program, Social Media at Sea, addressing the unique dangers of inappropriate use of social media by shipboard

General Dynamics Launches Morgan County NextGen-911

General Dynamics Information Technology, a business unit of General Dynamics, has implemented a NextGen-911 emergency service solution for Morgan County, Ohio.

 
 
Maritime Careers / Shipboard Positions Maritime Security Navigation Pipelines Pod Propulsion Port Authority Ship Electronics Ship Repair Shipbuilding / Vessel Construction Sonar
rss | archive | history | articles | privacy | terms and conditions | contributors | top maritime news | about us | copyright | maritime magazines
maritime security news | shipbuilding news | maritime industry | shipping news | maritime reporting | workboats news | ship design | maritime business

Time taken: 0.1008 sec (10 req/sec)