Architecture 9 — Maritime & Offshore (Ship/Rig Connectivity)

Reference Architecture Diagram + Narrative (multi-orbit SATCOM + edge safety)

                           ┌─────────────────────────────────────────────┐
                           │                ROLES & ZONES               │
 Capt/Bridge │ OT Eng │ HSE │ Corporate IT │ Crew/Contractors │ Port Ops │
                           └─────────┬─────────┬────────┬────────┬───────┘
                                     │         │        │        │
                                     ▼         ▼        ▼        ▼
            ┌────────────────────────────────────────────────────────────────┐
            │                 VESSEL / RIG EDGE (SEGMENTED)                   │
            │  VRFs/VLANs:  ▸ OT/SCADA/DP  ▸ Corp-IT  ▸ Crew Wi-Fi  ▸ Guest  │
            │  SD-WAN/SD-Branch (ZTP)  |  NAC/NGFW  |  QoS: OT > voice > web │
            │  Edge Compute: telemetry buffer, protocol normalize (OPC/Modbus)│
            └───────────┬───────────────────────────┬────────────────────────┘
                        │                           │
   Dual SATCOM (VSAT): GEO / MEO / LEO beams        │  Near-shore LTE/5G  |  Port microwave
   (dual modems, auto beam/constellation failover)  │  (policy-based prefer at coast/port)
                        ▼                           ▼
                ┌────────────────────────────────────────────────┐
                │           TRANSPORT / SECURITY FABRIC          │
                │  SD-WAN overlays ║ BGP ║ IX/Peering (shore)    │
                │  SASE/SSE POPs: ZTNA | SWG | CASB | FWaaS | DLP│
                │  Geo/data-sovereignty + vendor access gates    │
                └──────────────┬──────────────────┬──────────────┘
                               │                  │
                               ▼                  ▼
   ┌──────────────────────────────────┐   ┌──────────────────────────────────┐
   │  SHORE COLO / DC (sovereign)     │   │     CLOUD ON-RAMPS (DX/ER/GCI)   │
   │  • Fleet Ops  • EAM/ERP          │   │  • Analytics  • Data Lake        │
   │  • HSM/KMS  • PAM  • SIEM/NDR    │   │  • UCaaS/CCaaS • Crew portals    │
   └───────────────┬──────────────────┘   └──────────────┬───────────────────┘
                   │                                     │
                   ▼                                     ▼
      ┌──────────────────────────────┐      ┌─────────────────────────────┐
      │  SAFETY & REGULATORY COMMS   │      │    WELFARE / BUSINESS APPS  │
      │  • GMDSS / DSC / Inmarsat    │      │  • Email/HR • e-learning    │
      │  • MRCC integration          │      │  • Crew Wi-Fi • eDocs       │
      └──────────────────────────────┘      └─────────────────────────────┘

 Observability bus (logs/metrics/traces) ──► NOC/SOC + AIOps + ITSM/CMDB + IMO/ISM audit vault

Narrative (how the fleet stays safe, connected, and compliant)

1) Purpose & posture

  • Objective: Provide mission-safe, always-on communications for ships/rigs—protecting OT/SCADA and bridge systems, enabling crew welfare, and assuring safety services (GMDSS) anywhere on the globe.
  • Posture: Zero-Trust, strict OT/IT/Crew segmentation, and multi-orbit resilience with jurisdiction-aware routing and storage.

2) Edge & underlay (syntax at sea)

  • SD-WAN/SD-Branch at the vessel/rig edge, with deterministic VRFs for OT/SCADA/DP, Corp-IT, Crew, Guest.
  • Dual SATCOM modems bound to GEO/MEO/LEO beams; policy steers flows by class (e.g., OT control before welfare traffic).
  • Near-shore the edge prefers LTE/5G; in-port it prefers microwave. Failover is automatic and stateful.

3) Zero-Trust access fabric (semantics preserved)

  • SASE/SSE POPs enforce ZTNA (user/device/role), SWG/CASB/FWaaS/DLP; vendor sessions are just-in-time through PAM.
  • Geo/data-sovereignty fences pin corporate and crew data to approved shore regions; OT telemetry is signed and rate-limited.

4) Compute destinations (shore + cloud)

  • Shore DC/Colo hosts fleet ops, asset management (EAM/ERP), HSM/KMS, SIEM/NDR, and immutable audit vaults (IMO/ISM evidence).
  • Cloud on-ramps (Direct Connect/ExpressRoute/Interconnect) provide private access to analytics, UCaaS/CCaaS, crew portals, and data lakes.

5) Safety & welfare paths (meaning under stress)

  • Safety plane: GMDSS/DSC has dedicated priority routes independent of crew internet; MRCC links are pre-staged.
  • Welfare plane: Crew Wi-Fi and apps traverse distinct VRFs with bandwidth ceilings and content controls—never lateral to OT.

6) Resilience patterns (grammar that survives weather)

  • Beam/constellation failover: SATCOM switches <60s; near-shore LTE/5G preempts when stronger; port microwave overtakes in harbor.
  • Edge store-and-forward buffers OT telemetry if backhaul is impaired; ordered replay restores historian truth when link returns.

7) Security & compliance (trust with evidence)

  • Identity-centric access (MFA + device posture) for bridge and engineering roles; cert-based identity for PLCs/sensors.
  • NDR watches east-west inside OT VRF; SIEM/SOAR auto-isolates crew VLAN on malware signals; WORM/immutable logs meet IMO/ISM audits.

8) Telemetry & KPIs (pragmatics)

  • AIOps tracks link jitter/packet loss per orbit, MOS for bridge voice, OT latency spikes; auto-ticketing via ITSM/CMDB.
  • Targets: Availability ≥99.9% at sea; failover <60 s; OT jitter <30 ms; MOS ≥3.8; safety signaling success 100% during drills.

9) Minimal BOM (mapped to your matrix)

Dual VSAT (LEO/MEO/GEO), LTE/5G, port microwave; SD-WAN/SD-Branch; SASE/SSE (ZTNA/SWG/CASB/FWaaS/DLP); Edge compute (telemetry buffer); Shore DC (HSM/KMS, PAM, SIEM/NDR, audit vault); Cloud on-ramps; UCaaS/CCaaS; AIOps; ITSM/CMDB; GMDSS stack.