> ## Content Index
> Fetch the complete content index at: https://julius-shin.ghost.io/llms.txt
> Use this file to discover other available public pages before exploring further.

# [System Study_005] Gas Bunkering: A Safety Function Across Two Hulls
- URL: https://julius-shin.ghost.io/gas-bunkering-cargo-transfer-vapour-return/
- Published: 2026-09-09T12:55:00.000Z
- Updated: 2026-09-10T17:38:40.000Z
- Description: The ESD link and vapour-return line of an LNG bunkering vessel bind two ships into one safety function. An engineering and authority analysis of SYS-215.
- Author: Julius Shin
- Tags: Engineering Intelligence, Maritime Cybersecurity, LNG Bunkering, IACS UR E26, OT Security, SYS-215

When a ship takes oil from a terminal, its safety function ends at the hull. Gas bunkering is different. The ship-shore link (SSL) required by IGF Code 8.5.7 **binds the ESD systems of two vessels into a single safety function**, and the vapour-return line binds their tank pressures into a single fluid system. The trust boundary of this system sits not at the hull but at **the coupling face spanning two ships.**

IACS UR E26 and E27 are written with the ship as their unit. The bunkering link cuts across that unit. This article refuses to blur that into "remote access" and instead models it as directional authority.

Key point

IGF Code 8.5.7 makes the ship-shore ESD link mandatory, and the vapour-return line of 8.5.2 is the only way the no-venting requirement can be physically met. Together they place part of one ship's safety function inside another ship — a vessel whose ESD logic, software versions and operators are outside our configuration control. **The trust boundary is the coupling face, not the hull.**

Part I — Engineering

## 1\. Why This System Exists

One physical fact meets one normative sentence.

LNG is a liquid at roughly -162 °C at atmospheric pressure, so pushing it into a receiving tank displaces an equal volume of vapour. What sets LNG apart from any other liquid transfer is that **the act of transfer itself generates additional vapour** — flashing as it cools hoses and pipework to cryogenic temperature, flash gas across the pressure drop through manifolds and valves, boil-off from heat ingress. The vapour to be handled exceeds the liquid delivered.

There are three destinations for it: vent to atmosphere, accumulate in the tank, or return to the supplying vessel. The first is closed by rule.

> **IGF Code 8.5.2** — "The bunkering system shall be so arranged that no gas is discharged to the atmosphere during filling of storage tanks." (IMO Res. MSC.391(95)) Verified

The second collapses into the first: accumulated vapour climbs toward the relief setting, and the moment the relief valve lifts, that is a discharge to atmosphere. **The vapour-return line is not an accessory. It is the only means by which 8.5.2 is physically satisfied.**

Transfer LNG liquid into receiving vessel tank
        |
        +--> Displaced vapour (volume displacement)
        +--> Cooldown flash + manifold flash + heat-ingress boil-off (additional generation)
        |
        v
   Where does the vapour go?
        |
  +-----+---------------------------+
  |                                 |
Vent to atmosphere            Accumulate in tank
  |                                 |
IGF 8.5.2 prohibits          Pressure rises -> relief valve lifts
  |                                 |
  +---------> same outcome <--------+
                    |
                    v
     A return path to the supplying vessel is mandatory
                    |
                    v
        VAPOUR-RETURN LINE  (+ two tank pressures now form one coupled system)

![Operational context diagram of ship-to-ship LNG bunkering: the supplying vessel with its pumps, metering skid, control station and ESD valves on the left; the receiving vessel with its fuel tank, overfill system and unverified ESD logic on the right; and between them a dashed hull boundary crossed by an LNG liquid line running to the receiving vessel, a vapour-return line running back to the supplying vessel, and a bidirectional ESD link required by IGF 8.5.7.](https://github.com/MaritimeCyber/General/blob/main/Asset/img/ei/gas-bunkering-cargo-transfer-vapour-return/context-v2.jpg?raw=true) 

Figure 1\. Liquid crosses one way, vapour the other, and the ESD link crosses in both — the only mandatory path by which a safety function leaves the hull.

A second constraint sits on top. The counterparty is **another ship**, and two vessels move independently; beyond a limit that motion parts the transfer system. So the system needs a device that separates the hose without release — the Emergency Release System (ERS) and its core, the Emergency Release Coupling (ERC). ISO 20519 specifies that the ERS consists of **an ERC including interlocked isolating valves** to minimise loss of LNG or natural gas when it operates. Verified

And if two vessels each press their own ESD independently there is no coordination: one stops its pumps while the other closes its valves, and cryogenic liquid is trapped in pipework and expands. Hence:

> **IGF Code 8.5.7** — "A ship-shore link (SSL) or an equivalent means for automatic and manual ESD communication to the bunkering source shall be fitted." Verified

**That single sentence is the centre of this article,** because it is the only mandatory path by which a safety function leaves the hull.

### Regulatory history — why one operation sits under two regimes

The IGF Code was adopted as Res. MSC.391(95) on 11 June 2015 and entered into force with SOLAS Ch. II-1 Part G on 1 January 2017\. Verified But it governs **the ship receiving the fuel.** A bunkering vessel carrying LNG as cargo falls under the IGC Code, and the transfer system itself — arms, hoses, ERS, couplings, ESD link — was fully specified by neither. That gap is why ISO 20519 exists; it scopes itself to bunkering transfer systems for LNG-fuelled vessels **not covered by the IGC Code**. Verified (Scope confirmed from the ISO catalogue and published extracts; clause numbers unverified, so this article does not cite ISO 20519 at clause level.)

**A single bunkering operation straddles two normative systems** — the regulatory shape of this system's trust boundary.

## 2\. What the System Does

**F1 — Liquid transfer.** Move an agreed quantity of LNG at an agreed rate into the receiving vessel's fuel tank. Pumps or compressors provide the motive force; the path is the manifold, the hose, and a lined-up set of valves.

**F2 — Vapour management.** Take back displaced and newly generated vapour and route it to the supplying vessel's cargo tank or to reliquefaction or gas-combustion plant. If this fails, F1 is immediately constrained — if vapour has nowhere to go, liquid has nowhere to enter.

**F3 — Custody transfer.** Measure the delivered quantity and fix it as a commercial document. ISO 20519 obliges the provider to issue a bunker delivery note and, where a flowmeter is used, to state whether it conforms to ISO 21903\. Verified This output does not return to the physical world — it leaves as a signed document.

**F4 — Coordinated emergency shutdown and release.** **ESD-1** is the controlled emergency stop (pumps stopped, ESD valves closed); **ESD-2** is automatic operation of the ERS — physical separation. Typical

F4 differs in kind. F1 to F3 **make the operation happen**; F4 **stops it**. And F4 alone is **shared with a ship we do not own.** ISO 20519 requires the two ESD systems to be interconnected so that coordinated operation of both ESD and ERS is assured Typical — meaning the state of one system determines the action of the other.

## 3\. Core Functions and Operating Modes

**Attack surface and human gating differ mode by mode.**

**M1 — Connection and purging.** IGF 8.4.1 requires bunkering connections to be of **dry-disconnect type**, fitted with an additional **dry break-away coupling or self-sealing quick release**, and of a **standard type**. Verified 8.5.1 then requires the lines to be purged with inert gas. This is where the ESD link is connected and **tested in both directions.** Human density is highest.

**M2 — Cooldown.** A small liquid flow chills the system to cryogenic temperature — **the phase with the highest vapour generation per unit time.** Transfer rate is low while vapour-handling demand is maximum: a counterintuitive combination, and the design point of F2.

**M3 — Bulk transfer.** In the steady phase automatic loops carry the most weight and the operator is closer to a monitor. **Topping off changes the character again** — judgement returns to the human, and measurement accuracy directly governs the outcome.

**M4 — Completion and disconnection.** Under 8.5.4 residual fuel is drained; under 8.5.5 pipework is inerted and gas-freed, and must be gas-free when not engaged in bunkering unless the consequences of not doing so have been evaluated and approved. Verified

**M-ESD — Abnormal mode.** ESD-1 can be initiated from any mode, by operator action or sensor input — ISO 20519 requires **both.** Typical IGF 15.5.3 requires gas detected in ducting around bunkering lines to produce alarm **and emergency shutdown** at the bunkering control location. Verified That path has no human approval gate.

M1 Connect & purge  -> [max human density]   Manifold connection, IG purge, two-way ESD link test
M2 Cooldown         -> [max vapour load]     Low flow / high vapour — the design point for F2
M3 Bulk transfer    -> [max automation]      Ramp-up -> steady -> topping off (judgement returns to human)
M4 Complete & part  -> [max procedure]       Drain (8.5.4) -> gas-free (8.5.5) -> disconnect -> BDN

                        |
                        v  (enterable from any mode)
M-ESD:   ESD-1 (controlled stop: pumps stopped + ESD valves closed)
             |
             v  (on deterioration)
         ESD-2 (automatic ERS operation = physical separation, irreversible)

## 4\. How the System Works

The outcome — "N tonnes transferred safely" — is not the product of any single executable. It exists only when four things hold at once.

**(a) Differential pressure management.** Liquid flows because of a pressure difference between the two tanks, maintained only while the vapour-return path is open. Block the return and receiving pressure rises, differential falls, transfer rate drops. **The performance of F1 is subordinate to the health of F2.**

**(b) Valve line-up.** IGF 8.5.3 requires **a manual stop valve and a remotely operated shutdown valve in series** near the connection point of every bunkering line, the remote valve operable from the bunkering control location or other safe location. Verified 8.5.6 requires isolation where crossover piping exists.

**(c) Metering.** The measured value is both the source of a commercial document and **an input to the topping-off decision** — one value feeding two different outcomes.

**(d) ESD coordination across two ships.** Even with the first three sound, the safety function does not exist unless both vessels can stop together.

ENGINEERING NOTE — the thing to be protected is not one executable.

Narrow the object of protection to "the software in the bunkering control station" and you lose (a) and (d). (a) is a hydrodynamic state created by two ships' tank pressures; (d) is coupled to logic on a vessel whose configuration we do not manage. What must be protected is **the whole judgement chain running from pressure through metering and line-up to coordinated shutdown** — and the fourth link of that chain lies outside our class certificate.

Part II — Composition

## 5\. What the System Is Made Of

Six component rows map to six typologies. Read it by typology rather than by part name: each row's cyber character comes from the typology doctrine, not from the name of the part.

**Table 1 — Typology composition**

| Typology | Equipment class                                  | Component in this system         | Count | Purdue              | CBS (E26)           | Evidence |
| -------- | ------------------------------------------------ | -------------------------------- | ----- | ------------------- | ------------------- | -------- |
| TYP-C05  | Reciprocating / screw compressor — cargo control | Gas-transfer pumps / compressors | 1     | L0 physical process | Review (open)       | INFERRED |
| TYP-A10  | Mechanical power-transmission element            | Bunkering manifold and couplings | 1     | L0 physical process | N                   | TYPICAL  |
| TYP-A01  | Piping, ducting and fittings                     | Vapour-return line               | 1     | L0 physical process | N                   | TYPICAL  |
| TYP-B02  | Process transmitter / sensor — cargo             | Custody-transfer metering skid   | 1     | L1 sensing          | Y — list separately | INFERRED |
| TYP-A04  | Shutoff / isolation valve                        | ESD and emergency-release valves | 1     | L0 physical process | N                   | TYPICAL  |
| TYP-B08  | HMI / operator console — cargo                   | Bunkering control station        | 1     | L2 supervisory      | Y — list separately | TYPICAL  |

- **Pumps and compressors (TYP-C05)** — the only machine that moves fluid by itself. A final element, not a controller.
- **Manifold and couplings (TYP-A10)** — where two ships physically meet. No logic. Rule basis IGF 8.4.1.
- **Vapour-return line (TYP-A01)** — a passive conduit carrying matter, not data, that nonetheless **couples the tank pressures of two ships into one system.**
- **Metering skid (TYP-B02)** — observes only, yet its observation flows to both a commercial document and an operating decision.
- **ESD and emergency-release valves (TYP-A04)** — command nothing, yet cut the fluid directly. The widest authority-to-effect asymmetry here.
- **Bunkering control station (TYP-B08)** — where the human stands, and the control point IGF 15.5.1 normatively requires.

## 6\. Typology Profiles — why component count is not a measure of cyber relevance

**Only two of the six rows are CBS.** The metering skid (B02) and the control station (B08) are "Y — list separately"; the compressor (C05) is "Review", meaning **undecided**; manifold, vapour-return line and ESD valves are "N".

**Programmable.** IACS UR E26 Rev.1 §2 defines a CBS as "a programmable electronic device, or interoperable set of programmable electronic devices", and §1.3.2 a) scopes in OT that **uses data** to control or monitor physical processes. Pipe handles no data. Neither does a valve body — no logic, no setpoint, no state machine; pilot pressure arrives and it opens, is cut and it closes.

**Network interface.** For the compressor family the workbook records network\_interface as "Likely". Whether its link to the IAS and console is a hardwired contact, Modbus RTU, or an Ethernet fieldbus is **not established** — and statements resting on a "Likely" value cannot exceed INFERRED.

**Purdue level** runs L0 (compressor, manifold, piping, valves) → L1 (metering skid) → L2 (control station), with **most of the physical bulk at L0.** **Consequence of loss** is mostly "Operational", and a severity value alone never raises a physical-effect code. **Supply boundary** — the metering skid and compressor package are likely delivered with their own control cubicles, the subject of section 7.

**Most of what is visible here — manifold, hose, vapour-return line, valve bodies — is not a cyber object.** The cyber objects are **the measurement and control paths laid on top of them**, two rows out of six. Populate an asset inventory "largest first" and you go exactly backwards.

KEY DISTINCTION — bulk and relevance are different axes.

The vapour-return line is the longest physical element here and the consequences of its failure are large. Yet the object of the asset inventory under E26 §4.1.1.3 is not the line but the transmitter attached to it. Conversely the metering skid is physically small and is a separately listed CBS. **The criterion is not size but whether the item uses data to control or monitor a physical process.**

### An honest note on doctrine assignment

The manifold and couplings are assigned to **TYP-A10**, whose cached doctrine is written about **gearbox, clutch and shafting** — grounded in clutch engagement sequencing, IACS UR M68 shaft dimensioning and SOLAS II-1 Reg. 47.2 bearing monitoring. **None of those grounds apply to a bunkering manifold.** Exactly one structural property is inherited: **a passive mechanical element with no authority of its own (outbound A0) whose state is not changed by command (P0).** This article takes only that property and substitutes **IGF Code 8.4.1** as the rule basis; the assignment itself is raised in section 18.

## 7\. Where the Supply Boundary Falls

The supply boundary here is **two-layered**, and the second layer is what makes this system distinctive.

**First layer — the vendor package boundary.** The metering skid and compressor package likely arrive with their own control cubicles, and at that line ownership, privilege and above all **the update path** change hands. For the compressor package, programmable is "Likely": if the local panel is a PLC, an **A7 executable-update path opens to the vendor service tool and its effect persists after the interaction ends**; if it is a relay panel, that path does not exist at all and inbound collapses to A3/A4\. The cyber character of the same system is decided by a single supply decision, independently of where any firewall sits.

**Second layer — the hull boundary,** where the bunkering link crosses. Beyond the vendor boundary sits a supplier we can control by contract; beyond the hull boundary sits **a different ship on every operation** — whose ESD logic we do not manage, whose software versions we do not know, whose patch history we cannot see. Yet IGF 8.5.7 requires connection and ISO 20519 requires coordination.

### Approval, survey and test regimes — the legitimate window for inbound authority

The rules define when someone may lawfully touch this system: the formal window for inbound authority and, in cyber terms, **the scheduled moment at which change occurs.**

- **IGF 16.7.3.6** — ESD valves in liquefied gas piping shall close fully and smoothly **within 30 seconds**, and **the closing time shall be verifiable and reproducible.** Verified 30 seconds is **a ceiling, not a design target** — practice selects times of the order of a few seconds, with pressure surge review setting the lower bound Typical, and it is that selected value that belongs under configuration control.
- **IGF 16.7.3.7** — closing time of the valves required by 8.5.8 and 15.4.2.2 shall not exceed **3600 × U / BR seconds**, where U is ullage volume at the actuation level (m³) and BR is **the maximum bunkering rate agreed between ship and facility** (m³/h). Verified
- **IGF 16.7.3.5** — piping, valves and fittings handling fuel or vapour shall be tested under normal operating conditions **no later than at the first bunkering operation.** Verified

Read 16.7.3.7 again. **A safety parameter — permitted valve closing time — is a function of BR, a commercially agreed transfer rate.** Raise BR and the permitted closing time shrinks. BR is negotiated afresh for each operation and U depends on level-gauging configuration: **both are objects of A3 CONFIGURE.**

## 8\. Architecture Patterns

The actual topology is UNKNOWN. But the variable that divides architectures here is not the generic standalone/online/control-integrated axis — it is **the physical medium of the ESD link**, which decides whether one bit or a data stream crosses between two ships.

Industry technical literature describes three families: pneumatic, electric and fibre optic. Typical A **pneumatic link** is a single hose joining the two ESD systems — each side monitors hose pressure to detect the other's ESD initiation and vents through a solenoid when its own ESD occurs. Logically **one bit, unauthenticated, fail-safe in direction: loss of pressure is a trip.** A **fibre-optic digital link**, per trade-press commentary, was developed in 2006 and widely adopted for FSRU and FSU jetty connections; once connected, the two systems automatically share **LNG tank process data as well as telecoms, CCTV and other services.** Typical (Single trade source.)

**Pattern A — Hardwired / pneumatic.** Hardwired contacts inboard, pneumatic hose across; one bit crosses. The narrowest attack surface, where realistic threats reduce to physical access.

**Pattern B — Serial-integrated.** Package panels reach the IAS and console over Modbus RTU while the ESD link stays pneumatic. **Inboard** attack surface widens — Modbus RTU has neither sender authentication nor message integrity — while **the hull boundary stays narrow at one bit.**

**Pattern C — Fibre-optic digital link.** The link carries process data, telecoms and CCTV. The operational benefit is real: each side sees the other's tank state and trims the transfer rate. But **the two ships' networks become logically adjacent**, the trust boundary becomes the link's protocol boundary, and E26 §4.2.1.1 — only explicitly permitted traffic crosses a zone boundary — has to be implemented **against another vessel**, a case the clause, written for inboard zones, does not answer.

| Axis                           | A. Pneumatic                                     | B. Serial-integrated            | C. Fibre optic                           |
| ------------------------------ | ------------------------------------------------ | ------------------------------- | ---------------------------------------- |
| What crosses the hull boundary | 1 bit (pressure present/absent)                  | 1 bit (pressure present/absent) | Process data stream + ancillary services |
| Link authentication            | None (physical connection is the authentication) | None                            | Protocol-dependent — to be confirmed     |
| Link failure direction         | Depressurise = trip (fail-safe)                  | Depressurise = trip (fail-safe) | Design-dependent — an E27 SR 3.6 matter  |
| Inboard attack surface         | Minimal (hardwired)                              | Adds Modbus RTU segment         | Modbus RTU + link gateway                |
| Attack surface beyond the hull | Limited to physical access                       | Limited to physical access      | **Logical adjacency appears**            |
| E26 zone design                | Link is not a conduit                            | Link is not a conduit           | **Link is a conduit — must be drawn**    |

TYPICAL ARCHITECTURE — disclaimer.

These three patterns are a **conceptual model** built from link media described in industry technical literature, not the actual configuration of any vessel. Which pattern any instance of SYS-215 follows is unconfirmed; how to find out is in the question list in section 18\. Nothing here designates any vendor or product.

Part III — Authority and Physical Effect

## 9\. What Information and Commands Flow Through It

Split what flows into information and command and two things appear. Information vastly outweighs command; and **almost everything that crosses the hull boundary is information, translated into command on the far side.**

**Information.** Tank pressure, temperature and level on both sides; vapour-return line pressure; transfer rate and totalised quantity; valve position feedback; compressor state; alarm and trip contacts; gas detector readings; ESD link state. Most moves on 4-20 mA and hardwired contacts, some on HART and Modbus RTU.

**Command.** Pump and compressor start/stop, valve open/close, capacity adjustment, ESD-1 trip, ERS release. The list is short and most of it originates at the bunkering control station.

A third category deserves separate standing: **configuration** — meter range, span and units; strapping tables; alarm limits; ESD valve closing-time parameters; the agreed rate BR. These do not flow at run time; they are placed before the operation. Because they do not flow, they are watched less.

[Supplying vessel]                Hull boundary            [Receiving vessel]
                                        |
Bunkering console --ESD trip--> solenoid +-- pneumatic hose --+--> pressure switch --> their ESD logic
                                        |     (1 bit)         |                          |
Metering skid --flow/total--> console    |                     |                          v
                                        |                     |        their pumps stop + valves close
Vapour-return line ============ matter ==+=====================+==== receiving tank vapour space
                                        |
                                (pattern C only)
Console / gateway <--process data, CCTV, telecoms--+--fibre--+--> their systems
                                        |

On a pneumatic link the information crossing the boundary is **one bit**, translated inside the other ship into "stop pumps" and "close valves". On a fibre link that bit is joined by a continuous process-data stream, bidirectional in principle.

The vapour-return line hands across **matter**, not data — and its effect is stronger than an information channel, because our pressure manipulation changes their tank pressure directly. No protocol, no authentication, and physically the strongest coupling of all.

## 10\. What Authority Does Each Connection Carry

**Table 2 — Authority matrix.** Source × destination. YES / NO / UNKNOWN / COND (conditional).

| Source → Destination                                  | Observe (A1) | Provide info (A2) | Configure (A3) | Command (A4) | Control (A5) | Admin (A6) | Update exec (A7) |
| ----------------------------------------------------- | ------------ | ----------------- | -------------- | ------------ | ------------ | ---------- | ---------------- |
| Bunkering console → cargo controller                  | YES          | YES               | YES            | YES          | NO           | NO         | NO               |
| Bunkering console → ESD valves (via solenoid cabinet) | YES          | YES               | NO             | YES          | YES          | NO         | NO               |
| Bunkering console → compressor package                | YES          | YES               | YES            | YES          | NO           | NO         | NO               |
| Metering skid → bunkering console                     | YES          | YES               | NO             | NO           | NO           | NO         | NO               |
| Metering skid → BDN / commercial record               | NO           | YES               | NO             | NO           | NO           | NO         | NO               |
| ESD valve → console (position feedback)               | NO           | YES               | NO             | NO           | NO           | NO         | NO               |
| Compressor → console (state, alarms)                  | NO           | YES               | NO             | NO           | NO           | NO         | NO               |
| Manifold and couplings → anything                     | NO           | NO                | NO             | NO           | NO           | NO         | NO               |
| Vapour-return line → anything                         | NO           | NO                | NO             | NO           | NO           | NO         | NO               |
| **Our ESD link → their ESD logic**                    | NO           | **YES**           | NO             | **COND**     | NO           | NO         | NO               |
| **Their ESD logic → our ESD system**                  | NO           | **YES**           | NO             | **COND**     | NO           | NO         | NO               |
| Vendor service laptop → metering skid                 | YES          | YES               | **YES**        | YES          | NO           | COND       | **COND**         |
| Vendor service laptop → bunkering console             | YES          | YES               | **YES**        | YES          | NO           | **YES**    | **YES**          |
| Vendor service tool → compressor panel                | YES          | YES               | **COND**       | COND         | NO           | COND       | **COND**         |
| IAS / cargo network → bunkering console               | YES          | YES               | **YES**        | NO           | NO           | NO         | NO               |

KEY DISTINCTION — connectivity is not authority.

An ESD valve has wiring to the console and wiring from it. The cabling is bidirectional; the authority is not symmetric. Console → valve carries A4/A5 (command, control); valve → console **stops at A2.** What the valve emits is one limit-switch contact, and it directs nothing with it. Two directions of the same cable carry authority of different grades.

### The authority of the link — this system's own item

**Pneumatic link.** What we send is one item of **A2 PROVIDE\_INFORMATION** — "we have tripped". We do not command their pumps; their ESD logic receives that information and commands its own. Yet **as a consequence** our action changes the physical state of their vessel. The cell is A2 directly and conditionally A4 via their logic — a propagation path taken up in section 13.

**Fibre-optic link.** A2 is unchanged, but a continuous process-data channel opens alongside it. If bidirectional, an inbound face exists — traffic arriving at our gateway from their vessel — and what that traffic is and how it is validated is **unconfirmed.** Unknown

### Where inbound matters more

**(1) The metering skid's HART and gauging configuration path (A3, conditionally A7).** A HART Command 35-class range, span or unit change alters the interpretation of the measured quantity. Diverge from the strapping table and you manufacture a **plausible but wrong** quantity — it looks like a level, so nothing on screen is abnormal. Inferred

**(2) The bunkering control station's vendor service laptop (A3, A6, A7).** HMI-class items are programmable throughout, so executable code and sequence logic are replaceable. Metering algorithms and conversion tables are software configuration and fall under the inventory obligation of E26 Rev.1 §4.1.1.3.2\. Typical A7 differs in kind because its effect persists after the interaction ends.

**(3) The compressor package service tool (conditional A3/A6/A7).** With programmable recorded as "Likely", **the very existence of this path is unconfirmed.** Inferred For this family the cache names the **anti-surge setpoint (A3)** as the most consequential inbound point: surge control modulates a valve on a preset flow-to-pressure ratio, so **shift that one ratio and the machine is driven into surge without a single command being issued.** This is where A3 outweighing A4 holds physically for rotating machinery.

## 11\. Can the System Affect the Physical Process

**Table 3 — Authority-effect matrix**

| Interaction                                | Authority (out / in)     | Physical effect             | Human gate              | Security significance                                             |
| ------------------------------------------ | ------------------------ | --------------------------- | ----------------------- | ----------------------------------------------------------------- |
| Console → compressor start/stop/capacity   | out A4/A3 · in A2        | P4 (the compressor itself)  | EXECUTION               | Main path for starting and stopping transfer                      |
| Console → ESD valve open/close             | out A4/A5 · in A2        | **P4 + P5**                 | EXECUTION               | Cuts the fluid directly. Final element of a safety function       |
| Metering skid → console / BDN              | out A1/A2 · in A3 (+A7?) | P1 (+P3 via overfill logic) | EXECUTION / partly NONE | The quiet-wrong failure. Two outcomes, commercial and operational |
| Gas detection → automatic ESD (IGF 15.5.3) | out A2 · in —            | P3 → P5                     | **NONE**                | Automatic path with no human gate                                 |
| Vapour-return line (matter path)           | A0 / A0                  | P0 (no path via a CBS)      | NONE                    | No cyber path; risk migrates to adjacent instrumentation          |
| Manifold and couplings                     | A0 / A0                  | P0                          | NONE                    | No logic. Rule basis IGF 8.4.1                                    |
| ESD link (pneumatic)                       | out A2 · in A2           | P4 (inside their hull)      | EXECUTION or NONE       | One bit moves another ship's physical process                     |
| ESD link (fibre optic)                     | out A2 · in A2 + Unknown | P4 (inside their hull)      | Same                    | Continuous channel widens the inbound face                        |
| Vendor laptop → console                    | in A3/A6/A7              | P3 (via console)            | REVIEW (procedural)     | Persistent effect. Configuration-controlled                       |

KEY DISTINCTION — outbound A0 and P4 hold together.

The ESD valve is exactly that place. The valve body **commands nothing** — no logic, no setpoint, no state machine. Outbound authority is A0\. And yet **that valve cuts the flow of cryogenic LNG directly.** Physical effect is P4, and P5 for the subset used as the final element of a safety function. Authority is upstream, at the console and solenoid cabinet; physical contact is downstream, at the valve. **That asymmetry is the starting point for securing this system** — the way to protect the valve is not at the valve. In the cache's own words: when excluding this family from a CBS inventory, what matters is not deleting the valve but **keeping the cabinet that governs it.**

P5 attaches to subsets, never to a whole family. Three have grounds. **(a) ESD valves** — commanded and not closing, emergency isolation as a safety function does not exist. **(b) The ERC** — a final element that is, unusually, an item whose spurious operation is itself the accident. **(c) The independent overfill and high-level system** — IBC Code 15.19.6 and 15.19.7 define an overfill-prevention safety function and 15.19.5 requires independence from the gauging system; forge or suppress the switch value on that independent path and the safety function itself is defeated. Verified for the clauses, Inferred for their implementation here.

Conversely the vapour-return line is P0 — which does not mean "not dangerous" but **"not captured on this axis."** The consequence of a ruptured cryogenic line is enormous, yet it cannot be reached through a control system. The risk does not disappear; it is counted at adjacent typologies, the pressure transmitters and valve actuators attached to the line. **The cleanest available example of physical effect ≠ severity.**

## 12\. Human Gate — where the person stands in the architecture

The human's position here is fixed by rule, not by custom.

> **IGF Code 15.5.1** — bunkering control shall be possible from a safe location remote from the bunkering station, from which tank pressure, temperature and level can be monitored and the remote valves of 8.5.3 and 11.5.7 operated. Overfill alarm and automatic shutdown shall also be indicated at that location. Verified

That clause places the human at **EXECUTION** — actor, not observer. Compressors do not start themselves; valve line-up is commanded by a person; so are the decisions to begin transfer and to stop at topping off. **But paths with no human gate coexist inside the same system,** and blurring them destroys the analysis.

[Gated path — EXECUTION]
Operator judgement -> console action -> controller -> solenoid -> valve/pump -> fluid
   ^ A person initiates every step. IGF 15.5.1 requires this position by rule.

[Ungated path — NONE]
Gas detector (in duct) -> safety logic -> emergency shutdown            (IGF 15.5.3)
Independent 95/98 % level switch -> overfill logic -> sequential pump & valve shutdown  (IBC 15.19.7 class)
ESD link loss of pressure -> our ESD logic -> pumps stop + valves close
   ^ The person is informed of the result, not asked to approve it. That is the design intent.

[A person in our chain whom we do not manage]
Their operator -> their console -> their ESD -> link -> our system
   ^ Inside our safety chain, but not in our SMS and not in our training records.

The third block is this system's own problem. The absence of a gate on the automatic paths is **correct design** — require human approval for gas detection and it is not a safety function. The problem is not the missing gate but the gate that sits **outside our jurisdiction**: the coordinated operation ISO 20519 requires presupposes the training and qualification of the other vessel's operators. Typical

SIMOPS compounds this. Where passenger embarkation, stores or cargo work proceed simultaneously, **the operator is asked to hold situational awareness of several operations at once.** Typical The assumption that the human is the gate holds only while that human's attention is whole — a gap no cyber control closes, and for an attacker seeking to bypass the gate, **the cheapest condition available.**

Test regimes also fix the human's place. IGF 16.7.3.5 requires testing under normal operating conditions no later than the first bunkering, and 16.7.3.6 requires closing time to be **verifiable and reproducible.** Verified The rules order a person to confirm that this value is right — which from a cyber standpoint is an unexpected control: **a closing-time reproducibility test is also a detection mechanism for A3 configuration tampering.**

## 13\. Authority Escalation and Propagation

Three paths enter at low authority and acquire higher authority downstream.

**Path 1 — indirect propagation through a person (metering).** The metering skid holds only A1/A2 and commands nothing. But its value is the input to the topping-off decision.

Metering skid re-ranged (A3, inbound)
      |
      v
Totalised quantity reads low   [nothing abnormal on screen — a "plausible but wrong" value]
      |
      v
Operator: "we are short of the target" -> continue transfer (A4, legitimately issued by a person)
      |
      v
Receiving tank level rises -> reaches the independent overfill system (ungated automatic path)
      |
      v
Overfill trip — or, if the independent system is also compromised, physical overfill
      |
      v
P3 -> P5 (via the safety function)     Consequence: transfer halted + commercial dispute; at worst, a release

**The attacker never acquired A4.** They took one A3 and let the operator issue the command. The control "a human is the gate" works only while what the human sees is true.

**Path 2 — propagation across the link.** An ESD trip at our console stops their pumps and closes their valves, and the reverse holds too. What crosses is one bit at grade A2, and **that one bit is amplified to A4/A5 inside their hull.**

Our console (A4 outbound, inside our system)
   |
   v
Our solenoid -> link pressure released   [crossing the boundary: A2, one bit]
   |
   ==== hull boundary ====   <- where our configuration management ends
   |
   v
Their pressure switch -> their ESD logic (logic we have not verified)
   |
   v
Their pumps stop + their ESD valves close   [A4/A5 — amplified inside their hull]
   |
   v
P4 (physical process of the other vessel)

This chain is normal operation — it is what IGF 8.5.7 requires. But **the chain of normal operation is also the shape of an attack chain**, and we cannot verify its middle link. On a pneumatic link the problem is small; on a fibre link, process data flows continuously across the same boundary and the problem grows.

**Path 3 — promotion of a commercial parameter into a safety parameter (BR).** BR is a **commercial value** negotiated for each operation, and under IGF 16.7.3.7 it determines the permitted closing time of a safety valve. Raise BR and the allowance shrinks; U in turn depends on level-gauging configuration. **Both are objects of A3 CONFIGURE.**

Commercial negotiation (BR agreed) ---+
                                      |
Level gauging configuration (U) ------+--> closing-time requirement = 3600 x U / BR
                                      |            |
                                      |            v
                                      |    ESD valve closing time set & verified (16.7.3.6: <= 30 s, reproducible)
                                      |            |
                                      +------------+--> if the requirement is looser than actual valve response,
                                                        an ESD-1 will not prevent surge or overfill

The escalation here is not technical. **It happens at the negotiating table.** Agree a high BR without re-verifying valve closing time and safety margin disappears silently. An attacker using this path would not need to enter the system at all — and equally, no network control blocks it.

Part IV — Uncertainty and Security

## 14\. Trust Boundaries and Dependencies

Four trust boundaries, differing in kind.

+-------------------------------------------------------------------+
|  Supplying vessel (our ship)                                      |
|                                                                   |
|   +----------------------------+  B1: vendor package boundary     |
|   | Metering skid (own cubicle)|  - ownership & update path shift |
|   | Compressor package (?)     |  - inbound A3/A6/A7 (conditional)|
|   +----------------------------+  - controllable by contract      |
|                |                                                  |
|   +----------------------------+  B2: physical zone boundary      |
|   | Bunkering control station  |  - the door is the authentication|
|   +----------------------------+  - outsiders enter during work   |
|                |                                                  |
|   +----------------------------+  B4: commercial data boundary    |
|   | Metering -> BDN -> shore   |  - a standing path off the ship  |
|   +----------------------------+  - motive is commercial          |
|                |                                                  |
+================|==================================================+
   B3: hull      |  <=== unique to this system. The counterparty changes every operation
+================|==================================================+
|  Receiving vessel (a ship whose configuration we do not manage)   |
|   Their ESD logic / their tanks / their operators / their software|
+-------------------------------------------------------------------+

**B1 — vendor package boundary.** Two items can sit in the same drawn zone while configuration responsibility rests with different organisations. ⚠ The cache warns of a common trap: **the control cubicle can be absorbed into its parent package and appear in no component row at all.** This system's BOM has six rows and no independent cubicle row, so **the cubicle may already be invisible in the drawing and the inventory.**

**B2 — physical zone boundary.** The control station is an HMI needing immediate operation, so it is among the device classes most easily granted the identification and authentication exemption of E26 Rev.1 §4.2.4.4.1 — an exemption conditioned on **physical access control.** But during bunkering that space sees counterparty personnel, surveyors and supervisors coming and going. If a door rather than an account is the boundary, its substance is the visitor control of §4.2.4.3.2 — the control that loosens first under schedule pressure. Typical E27 Rev.1 §4.1 Table 1 item 12 (SR 2.5, session lock) collides with this head-on: an operating requirement not to leave the console and an inactivity lock are not compatible, and the compromise is often undocumented.

**B3 — hull boundary, the one unique to this system.** What separates it from the other three is that **the counterparty changes every operation.** A vendor is a contracting party whose configuration can be asked about; the other ship was a different ship yesterday. Here the regulatory duality of section 1 returns as a trust problem: **we are under the IGC Code and they are under the IGF Code**, and one safety function bridges two normative systems. E26 and E27 are **written with the ship as the unit**, and §4.2.1.1 requires traffic crossing a zone boundary to be limited to what is explicitly permitted — but that clause **presumes inboard zones.** How to apply it to a conduit spanning two ships, it does not say: less a defect of the rules than **a shape they have not yet addressed**, and the honest tag is Unknown.

**B4 — commercial data boundary.** The measured quantity becomes a BDN and leaves the ship Verified, possibly under E26 §1.3.2 b) on communication interfaces from in-scope CBSs to other systems — a standing path out of the cargo control zone **for commercial reasons.** Its distinctive feature is motive: the incentive to distort a measured quantity may be **commercial gain** rather than an accident, and that incentive does not exist in machinery-space typologies.

## 15\. What Happens When the System Fails

Engineering failure comes before cyber failure, and knowing these chains puts section 16 on evidence rather than assumption.

**(a) Unplanned separation of the ERC.** The two principal failures identified for flexible cryogenic transfer hoses are **unplanned disconnection of the breakaway coupling** and **damage or rupture of the hose itself.** Typical

ERC operates early (malfunction or spurious signal)
   |
   v
Physical separation during transfer — by design, "without spillage"
   |
   v  in practice, however:
possible release of residual cryogenic liquid + immediate loss of transfer + long re-connection
   |
   v
Consequence: failed operation, deck personnel exposure, hours to resume

**Malfunction of the safety function is itself the accident.** The received wisdom that a safety function is safe even when it operates spuriously does not hold here. ESD-1 is reversible; **ESD-2 is an irreversible physical event.** That asymmetry bears on target selection in section 16.

**(b) Blockage or insufficient capacity of the vapour-return path.**

Vapour-return line blocked / compressor capacity short / valves mis-lined
   |
   v
Receiving tank vapour-space pressure rises   (fastest during M2 cooldown)
   |
   v
Differential falls -> transfer rate drops  (the first symptom is a performance problem, not a safety one)
   |
   v
If pressure keeps rising -> receiving tank relief valve lifts
   |
   v
Natural gas discharged to atmosphere = the state IGF 8.5.2 prohibits.
The relief valve worked correctly; the system failed normatively.

The two release scenarios that cannot be dismissed during bunkering are LNG hose leakage and **natural gas release through the receiving vessel's fuel tank relief valve** — and that chain is precisely where the second ends. Typical

**(c) Quiet metering drift.** The cache's sentence applies verbatim: **the most dangerous failure is not the screen going dark but the screen being quietly wrong.** Antenna or stilling-well fouling weakens the radar return so level jumps or locks to the wrong surface; after re-ranging, divergence from the strapping table leaves level plausible while the converted quantity is systematically off. Inferred With no symptom, detection depends on periodic verification.

**(d) Failures of the ESD valve family.** Wear or debris produces passing at the fully closed position while the console still reads "shut". A burnt-out solenoid coil leaves that valve unable to be operated remotely. Limit-switch misalignment produces **disagreement between actual position and console indication**, so a pump is started against a wrong line-up. Typical The last matters most: a physical failure whose **consequence has the same shape as a cyber attack.**

**The most dangerous failure class here is not the one that stops the system but the one that shows it falsely.** A stoppage is visible immediately; a falsehood only after the outcome.

## 16\. Attack Surface and Credible Threat Scenarios

| Surface                    | What it is here                                                              | Note                                                      |
| -------------------------- | ---------------------------------------------------------------------------- | --------------------------------------------------------- |
| Local / physical           | Bunkering control station, solenoid cabinet, field wiring and junction boxes | Outsider presence during operations is a constant         |
| Removable media            | Console and metering-skid updates, vendor laptops (E26 §4.2.4.3.4)           | At modification or changed terminal requirements          |
| Connected OT               | IAS and cargo control network, Modbus RTU segments                           | No authentication, no message integrity                   |
| **Ship-to-ship interface** | ESD link, vapour-return line                                                 | **Unique to this system. Re-established every operation** |
| Vendor                     | Metering, compressor and console service access (E26 §4.2.6.3.2)             | Inbound A3/A6/A7                                          |
| Supply chain               | Package software configuration, cubicle delivery state                       | The B1 boundary                                           |

Generic threat lists are not the subject. The three below are derived from the structure of this system and each is carried to the end of its chain.

### S1 — Suppression of the vapour-return pressure signal (Connected OT)

| Stage                | Content                                                                                                                                            |
| -------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------- |
| Entry interaction    | Modbus RTU segment of the cargo control network, or the pressure transmitter signal path                                                           |
| Initial authority    | A2 (access to an information path)                                                                                                                 |
| Mechanism            | Hold the vapour-return and receiving vapour-space pressure indications inside the normal band. Symptomatically identical to a blocked impulse line |
| Authority gained     | None — **information is distorted without acquiring authority**                                                                                    |
| Affected interaction | Operator's rate judgement, compressor capacity loop, high-pressure alarm                                                                           |
| Physical effect      | P3 → rising receiving tank pressure goes undetected                                                                                                |
| Consequence          | Enters the chain of 15(b) — relief valve discharge, reaching the state IGF 8.5.2 prohibits                                                         |

The precondition is that **pressure indication is single-path.** If an independent vapour-space pressure monitor exists on a separate system, the scenario does not hold. Whether that independence exists here is unconfirmed. Unknown

### S2 — Defeat of the ESD link itself (ship-to-ship interface)

| Stage                | Content                                                                                               |
| -------------------- | ----------------------------------------------------------------------------------------------------- |
| Entry interaction    | The bunkering link. **Whether this holds at all depends on the pattern**                              |
| Initial authority    | Patterns A/B: physical access only. Pattern C: access to the link protocol                            |
| Mechanism            | In pattern C, hold the ESD status field of link traffic at "normal", or delay trip propagation        |
| Authority gained     | The negation of A2 — the ability not to send information                                              |
| Affected interaction | ESD coordination between two ships                                                                    |
| Physical effect      | Our side stops while theirs keeps transferring — trapped liquid expansion in pipework, or the reverse |
| Consequence          | Failure of coordinated shutdown; at worst, system rupture and cryogenic release                       |

⚠ **An honest distinction. On a pneumatic link (patterns A and B) the scenario is hard to construct.** Depressurisation is a trip, and depressurisation follows from merely cutting the hose — the direction is **fail-safe.** To suppress a trip an attacker must hold the link physically and supply pressure, which is not a logical attack. On a **fibre-optic link (pattern C), status is a data field**, and a data field can be held. Whether that link's failure behaviour implements the deterministic output required by E27 Rev.1 §4.1 Table 1 item 20 (SR 3.6) is **unconfirmed.** Unknown

That distinction is itself one of this article's conclusions. **The choice of link medium determines whether this threat exists.** Choose pneumatic and the scenario disappears — not a security control added, but **a threat eliminated by design.**

### S3 — Re-ranging the metering skid (vendor / removable media)

| Stage                | Content                                                                                                         |
| -------------------- | --------------------------------------------------------------------------------------------------------------- |
| Entry interaction    | Vendor service laptop or HART handheld. Cargo-area junction boxes are physically accessible and unauthenticated |
| Initial authority    | A3 CONFIGURE (range, span, units, or strapping interpretation)                                                  |
| Mechanism            | A HART Command 35-class range change. Nothing abnormal on screen                                                |
| Authority gained     | None — **the command is issued by the operator**                                                                |
| Affected interaction | Topping-off judgement, rate decisions, BDN quantity                                                             |
| Physical effect      | P1 → P3 (on reaching overfill logic)                                                                            |
| Consequence          | Commercial dispute plus overfill risk. The chain of path 1 in section 13, exactly                               |

What separates this from the other two is **motive.** S1 and S2 aim at an accident; S3 can aim at **money.** An attack aimed at money aims at not being discovered, so it avoids the accident — meaning it **persists and repeats.** Inferred

## 17\. Security Architecture and Standards

Controls are derived from the threats; standards mapping comes afterwards.

**From S1 (signal suppression).**

- Maintain at least one **monitoring path independent of the control path** for vapour-space and vapour-return pressure — **separate power, separate cable route, separate marshalling**, the property IBC Code 15.19.5 requires of the overfill system.
- E27 Rev.1 §4.1 Table 1 item 20 (SR 3.6) — outputs placed in a predetermined state when normal operation is not maintained. Loss of pressure indication must not degrade into "holding at normal".
- E26 Rev.1 §4.2.1.1 — restrict boundary crossing of the zone containing Modbus RTU segments to explicitly permitted traffic.

**From S2 (link defeat).**

- **Treat the link medium as a design decision.** A pneumatic link structurally removes threat S2; if fibre optic is adopted, document explicitly whether its benefit exceeds the cost of logical adjacency.
- **Draw the bunkering link on the zones and conduits diagram, explicitly, as a conduit.** This is this article's central recommendation. The link is often absent from the drawing because it is not an inboard system — but under E26 §4.2.1.1 it is unmistakably a path crossing a zone boundary, and what is not drawn is not controlled.
- E26 Rev.1 §4.4.4.1/§4.4.4.3 — minimal risk condition on a cyber incident. Here it is unambiguous: **stop the transfer and close the valves.** What must be defined separately is **whether that stop is coordinated while the link is impaired.**
- E27 Rev.1 §4.1 Table 1 item 20 (SR 3.6) — design the link's failure behaviour as fail-to-trip.

**From S3 (re-ranging).**

- Register the metering configuration (range, span, units, strapping table) as a **configuration-controlled item** and compare values before and after each operation. The inventory E26 Rev.1 §4.1.1.1 and §4.1.1.3.2 require includes metering algorithms and conversion tables.
- E26 Rev.1 §4.2.4.3.4 — removable media policy, with malware scanning and signature verification before use.
- E26 Rev.1 §4.2.6.3.2 — control of vendor remote diagnostic and maintenance access. Do not blur vendor access into "remote access"; state **which authority enters in which direction.**
- E26 Rev.1 §4.2.1.3 — navigation and communication systems shall not share a zone with cargo systems.

**Controls the rules themselves already provide.**

- The **manual stop valve in series with a remote shutdown valve** of IGF 8.5.3 lets a person cut the fluid locally even if the remote circuit is wholly compromised — functionally **the last manual fallback**, of the same character as the local backup control requirement of E26 §4.4.2\. Verified
- The **closing-time reproducibility** requirement of IGF 16.7.3.6 is a detection mechanism for A3 configuration tampering, and the **operational test at first bunkering** of 16.7.3.5 establishes a commissioning-time configuration baseline. Verified
- Manage **BR and U as per-operation configuration items**: while the closing-time requirement is a function of BR, changing BR is changing a safety parameter.

⚠ **A caution.** The E26 and E27 clauses mapped above are **written with the ship as the unit**, so requirements for a conduit spanning two ships cannot be read directly out of them. The recommendations above are **an extension of the clauses' intent**, and this article does not claim the rules require them.

## 18\. Open Questions, Takeaways and References

### Open questions

The typologies are 6/6 established, but items remain unresolved at instance level.

1. **Appropriateness of the TYP-A10 doctrine assignment.** Only the structural property (A0/P0) is inherited; clutch sequencing, propulsion control, UR M68 and SOLAS II-1 Reg. 47.2 do not apply. Whether a separate typology is needed is a judgement for the cache owner.
2. **What is the physical medium of the bunkering link?** Pneumatic or fibre optic decides the threat conclusions of this article.
3. **Who owns configuration management of the other vessel's ESD system?** Part of our safety function lies outside our configuration control, and the rules give no answer.
4. **Is the compressor package local panel a PLC or a relay panel?** A PLC settles both the A7 path and CBS status; a relay panel deletes A6 and A7 from inbound.
5. **When will the compressor family's CBS status (E26 "Review") be closed?** Unlisted means neither §4.2.1 zone assignment nor E27 §4 capability requirements apply. **The unresolved state is itself a management gap.**
6. **Which BOM row holds the control cubicles of the metering skid and the console?** None of the six is an independent cubicle row.
7. **Is there a vapour-pressure monitoring path independent of the control path?** The precondition for S1.
8. **If a fibre-optic link is adopted, is its failure behaviour defined?** An E27 SR 3.6 matter.

### Twelve questions to ask first on a real project

1. Is the bunkering ESD link pneumatic, fibre optic, or hardwired cable?
2. Is that link drawn on the zones and conduits diagram? If not, why not?
3. Is there a documented list of the data the link carries?
4. Designed behaviour when the link is severed — trip, hold, or alarm only?
5. What do we verify about the other vessel's ESD system before connecting?
6. Design, measured and last-verified values of ESD valve closing time? (16.7.3.6)
7. Where is BR recorded, and is the closing-time requirement recalculated when it changes? (16.7.3.7)
8. Are the metering skid's range, span and strapping table registered as configuration items?
9. Vendor service access: to which device, in which direction, carrying which authority?
10. Is the compressor package panel a PLC or a relay panel? Does it have an engineering port?
11. Is there a vapour-space pressure monitor with genuinely separate power and cable routes?
12. If the §4.2.4.4.1 authentication exemption was applied to this console, what physical control does it rest on?

### Engineering takeaways

- **The trust boundary of this system is not the hull.** The ESD link of IGF 8.5.7 and the vapour-return line bind two ships into one safety function and one fluid system.
- **Two of six rows are CBS.** Manifold, piping and valves are most of the physical bulk and none of the cyber objects.
- **At the ESD valve, outbound A0 and P4/P5 hold together.** The way to protect the valve is at the solenoid cabinet and the console.
- **The choice of link medium determines whether a threat exists.** Pneumatic structurally removes S2; fibre optic brings operational benefit together with logical adjacency.
- **A commercial parameter, BR, is promoted into a safety parameter.** Negotiating BR is a safety configuration change.
- **The most dangerous failure class is not the one that stops the system but the one that shows it falsely.**

System (gas bunkering transfer & vapour return)
  -> Function (liquid transfer / vapour management / custody transfer / coordinated shutdown)
  -> Component (6 rows)
  -> Typology (C05, A10, A01, B02, A04, B08)
  -> Interaction (console-valve, console-compressor, metering-console, link-their ESD, vapour-their tank)
  -> Information / Command (much information, little command; configuration is placed, not flowed)
  -> Authority (out A0-A5 / in A0-A7 — inbound carries more weight)
  -> Physical Effect (P0-P5 — A0 and P4 hold in the same place)
  -> Human Gate (EXECUTION + ungated automatic paths + a person outside our jurisdiction)
  -> Dependency (vapour-return health -> transfer performance -> safety margin)
  -> Trust (vendor / physical zone / hull / commercial data)
  -> Failure (early ERC release / vapour blockage / metering drift / valve passing)
  -> Consequence (release, overfill, dispute, failed coordinated stop)
  -> Threat (S1 signal suppression / S2 link defeat / S3 re-ranging)
  -> Security Requirement (independent monitoring / link as conduit / metering under configuration control)
  -> Control (E26 4.2.1.1, 4.2.4.3.4, 4.2.6.3.2 / E27 SR 3.6 / IGF 8.5.3 manual fallback)
  -> Assurance (16.7.3.5 operational test / 16.7.3.6 closing-time reproducibility)
  -> Evidence (verification dates, configuration baseline, link test records)

---

### References

- IMO Res. MSC.391(95), *IGF Code* (in force 1 Jan 2017) — §8.4.1, §8.5.1-8.5.8, §15.5.1, §15.5.3, §16.7.3.5-16.7.3.7.
- IMO *IGC Code* — the regime governing the supplying (bunkering) vessel.
- IMO *IBC Code* §15.19.5-15.19.7 — independence of high-level alarm and overflow control (basis of the cached TYP-B02 doctrine).
- ISO 20519:2021, *Specification for bunkering of liquefied natural gas fuelled vessels* (cited at scope level only); ISO 21903 transfer hoses; ISO 21562:2020 mass flowmeters.
- IACS UR E26 Rev.1 (Nov 2023) — §1.3.2, §2, §4.1.1.1, §4.1.1.3.2, §4.2.1.1, §4.2.1.3, §4.2.4.3.2, §4.2.4.3.4, §4.2.4.4.1, §4.2.6.3.2, §4.4.2, §4.4.4.
- IACS UR E27 Rev.1 (Sep 2023) — §4.1 Table 1 items 12, 20 (IEC 62443-3-3 SR 2.5, SR 3.6). IACS UR E22 Rev.3 — software functional requirements.
- SGMF linked-ESD / bunkering safety link recommendations; LNG bunkering HAZID literature (ERC failure modes, release scenarios, SIMOPS); trade-press technical commentary on ESD-1/ESD-2 and link media. Typical
- blog-pipeline typology cache, SYS-215 brief (6/6 typologies) — doctrine and authority / physical-effect codes for TYP-C05, A10, A01, B02, A04, B08.

Article classification

This is a **typology-based system analysis**, not an audit of a specific vessel or vendor product. Component attributes are typology-inherited values, not vessel or vendor measurements. Authority and Physical Effect codes are **descriptive classifications, not risk scores**. Evidence tags (Verified / Typical / Inferred / Unknown) grade the basis of each statement, and a typology doctrine's grade is the ceiling for statements resting on it. Architecture patterns A, B and C are conceptual models, not the configuration of any instance.