When a ship takes oil from a terminal, its safety function ends at the hull. Gas bunkering is different. The ship-shore link (SSL) required by IGF Code 8.5.7 binds the ESD systems of two vessels into a single safety function, and the vapour-return line binds their tank pressures into a single fluid system. The trust boundary of this system sits not at the hull but at the coupling face spanning two ships.

IACS UR E26 and E27 are written with the ship as their unit. The bunkering link cuts across that unit. This article refuses to blur that into "remote access" and instead models it as directional authority.

Part I — Engineering

1. Why This System Exists

One physical fact meets one normative sentence.

LNG is a liquid at roughly -162 °C at atmospheric pressure, so pushing it into a receiving tank displaces an equal volume of vapour. What sets LNG apart from any other liquid transfer is that the act of transfer itself generates additional vapour — flashing as it cools hoses and pipework to cryogenic temperature, flash gas across the pressure drop through manifolds and valves, boil-off from heat ingress. The vapour to be handled exceeds the liquid delivered.

There are three destinations for it: vent to atmosphere, accumulate in the tank, or return to the supplying vessel. The first is closed by rule.

IGF Code 8.5.2 — "The bunkering system shall be so arranged that no gas is discharged to the atmosphere during filling of storage tanks." (IMO Res. MSC.391(95)) Verified

The second collapses into the first: accumulated vapour climbs toward the relief setting, and the moment the relief valve lifts, that is a discharge to atmosphere. The vapour-return line is not an accessory. It is the only means by which 8.5.2 is physically satisfied.

Transfer LNG liquid into receiving vessel tank
        |
        +--> Displaced vapour (volume displacement)
        +--> Cooldown flash + manifold flash + heat-ingress boil-off (additional generation)
        |
        v
   Where does the vapour go?
        |
  +-----+---------------------------+
  |                                 |
Vent to atmosphere            Accumulate in tank
  |                                 |
IGF 8.5.2 prohibits          Pressure rises -> relief valve lifts
  |                                 |
  +---------> same outcome <--------+
                    |
                    v
     A return path to the supplying vessel is mandatory
                    |
                    v
        VAPOUR-RETURN LINE  (+ two tank pressures now form one coupled system)
Operational context diagram of ship-to-ship LNG bunkering: the supplying vessel with its pumps, metering skid, control station and ESD valves on the left; the receiving vessel with its fuel tank, overfill system and unverified ESD logic on the right; and between them a dashed hull boundary crossed by an LNG liquid line running to the receiving vessel, a vapour-return line running back to the supplying vessel, and a bidirectional ESD link required by IGF 8.5.7.
Figure 1. Liquid crosses one way, vapour the other, and the ESD link crosses in both — the only mandatory path by which a safety function leaves the hull.

A second constraint sits on top. The counterparty is another ship, and two vessels move independently; beyond a limit that motion parts the transfer system. So the system needs a device that separates the hose without release — the Emergency Release System (ERS) and its core, the Emergency Release Coupling (ERC). ISO 20519 specifies that the ERS consists of an ERC including interlocked isolating valves to minimise loss of LNG or natural gas when it operates. Verified

And if two vessels each press their own ESD independently there is no coordination: one stops its pumps while the other closes its valves, and cryogenic liquid is trapped in pipework and expands. Hence:

IGF Code 8.5.7 — "A ship-shore link (SSL) or an equivalent means for automatic and manual ESD communication to the bunkering source shall be fitted." Verified

That single sentence is the centre of this article, because it is the only mandatory path by which a safety function leaves the hull.

Regulatory history — why one operation sits under two regimes

The IGF Code was adopted as Res. MSC.391(95) on 11 June 2015 and entered into force with SOLAS Ch. II-1 Part G on 1 January 2017. Verified But it governs the ship receiving the fuel. A bunkering vessel carrying LNG as cargo falls under the IGC Code, and the transfer system itself — arms, hoses, ERS, couplings, ESD link — was fully specified by neither. That gap is why ISO 20519 exists; it scopes itself to bunkering transfer systems for LNG-fuelled vessels not covered by the IGC Code. Verified (Scope confirmed from the ISO catalogue and published extracts; clause numbers unverified, so this article does not cite ISO 20519 at clause level.)

A single bunkering operation straddles two normative systems — the regulatory shape of this system's trust boundary.

2. What the System Does

F1 — Liquid transfer. Move an agreed quantity of LNG at an agreed rate into the receiving vessel's fuel tank. Pumps or compressors provide the motive force; the path is the manifold, the hose, and a lined-up set of valves.

F2 — Vapour management. Take back displaced and newly generated vapour and route it to the supplying vessel's cargo tank or to reliquefaction or gas-combustion plant. If this fails, F1 is immediately constrained — if vapour has nowhere to go, liquid has nowhere to enter.

F3 — Custody transfer. Measure the delivered quantity and fix it as a commercial document. ISO 20519 obliges the provider to issue a bunker delivery note and, where a flowmeter is used, to state whether it conforms to ISO 21903. Verified This output does not return to the physical world — it leaves as a signed document.

F4 — Coordinated emergency shutdown and release. ESD-1 is the controlled emergency stop (pumps stopped, ESD valves closed); ESD-2 is automatic operation of the ERS — physical separation. Typical

F4 differs in kind. F1 to F3 make the operation happen; F4 stops it. And F4 alone is shared with a ship we do not own. ISO 20519 requires the two ESD systems to be interconnected so that coordinated operation of both ESD and ERS is assured Typical — meaning the state of one system determines the action of the other.

3. Core Functions and Operating Modes

Attack surface and human gating differ mode by mode.

M1 — Connection and purging. IGF 8.4.1 requires bunkering connections to be of dry-disconnect type, fitted with an additional dry break-away coupling or self-sealing quick release, and of a standard type. Verified 8.5.1 then requires the lines to be purged with inert gas. This is where the ESD link is connected and tested in both directions. Human density is highest.

M2 — Cooldown. A small liquid flow chills the system to cryogenic temperature — the phase with the highest vapour generation per unit time. Transfer rate is low while vapour-handling demand is maximum: a counterintuitive combination, and the design point of F2.

M3 — Bulk transfer. In the steady phase automatic loops carry the most weight and the operator is closer to a monitor. Topping off changes the character again — judgement returns to the human, and measurement accuracy directly governs the outcome.

M4 — Completion and disconnection. Under 8.5.4 residual fuel is drained; under 8.5.5 pipework is inerted and gas-freed, and must be gas-free when not engaged in bunkering unless the consequences of not doing so have been evaluated and approved. Verified

M-ESD — Abnormal mode. ESD-1 can be initiated from any mode, by operator action or sensor input — ISO 20519 requires both. Typical IGF 15.5.3 requires gas detected in ducting around bunkering lines to produce alarm and emergency shutdown at the bunkering control location. Verified That path has no human approval gate.

M1 Connect & purge  -> [max human density]   Manifold connection, IG purge, two-way ESD link test
M2 Cooldown         -> [max vapour load]     Low flow / high vapour — the design point for F2
M3 Bulk transfer    -> [max automation]      Ramp-up -> steady -> topping off (judgement returns to human)
M4 Complete & part  -> [max procedure]       Drain (8.5.4) -> gas-free (8.5.5) -> disconnect -> BDN

                        |
                        v  (enterable from any mode)
M-ESD:   ESD-1 (controlled stop: pumps stopped + ESD valves closed)
             |
             v  (on deterioration)
         ESD-2 (automatic ERS operation = physical separation, irreversible)

4. How the System Works

The outcome — "N tonnes transferred safely" — is not the product of any single executable. It exists only when four things hold at once.

(a) Differential pressure management. Liquid flows because of a pressure difference between the two tanks, maintained only while the vapour-return path is open. Block the return and receiving pressure rises, differential falls, transfer rate drops. The performance of F1 is subordinate to the health of F2.

(b) Valve line-up. IGF 8.5.3 requires a manual stop valve and a remotely operated shutdown valve in series near the connection point of every bunkering line, the remote valve operable from the bunkering control location or other safe location. Verified 8.5.6 requires isolation where crossover piping exists.

(c) Metering. The measured value is both the source of a commercial document and an input to the topping-off decision — one value feeding two different outcomes.

(d) ESD coordination across two ships. Even with the first three sound, the safety function does not exist unless both vessels can stop together.

Part II — Composition

5. What the System Is Made Of

Six component rows map to six typologies. Read it by typology rather than by part name: each row's cyber character comes from the typology doctrine, not from the name of the part.

Table 1 — Typology composition

Typology Equipment class Component in this system Count Purdue CBS (E26) Evidence
TYP-C05Reciprocating / screw compressor — cargo controlGas-transfer pumps / compressors1L0 physical processReview (open)INFERRED
TYP-A10Mechanical power-transmission elementBunkering manifold and couplings1L0 physical processNTYPICAL
TYP-A01Piping, ducting and fittingsVapour-return line1L0 physical processNTYPICAL
TYP-B02Process transmitter / sensor — cargoCustody-transfer metering skid1L1 sensingY — list separatelyINFERRED
TYP-A04Shutoff / isolation valveESD and emergency-release valves1L0 physical processNTYPICAL
TYP-B08HMI / operator console — cargoBunkering control station1L2 supervisoryY — list separatelyTYPICAL
  • Pumps and compressors (TYP-C05) — the only machine that moves fluid by itself. A final element, not a controller.
  • Manifold and couplings (TYP-A10) — where two ships physically meet. No logic. Rule basis IGF 8.4.1.
  • Vapour-return line (TYP-A01) — a passive conduit carrying matter, not data, that nonetheless couples the tank pressures of two ships into one system.
  • Metering skid (TYP-B02) — observes only, yet its observation flows to both a commercial document and an operating decision.
  • ESD and emergency-release valves (TYP-A04) — command nothing, yet cut the fluid directly. The widest authority-to-effect asymmetry here.
  • Bunkering control station (TYP-B08) — where the human stands, and the control point IGF 15.5.1 normatively requires.

6. Typology Profiles — why component count is not a measure of cyber relevance

Only two of the six rows are CBS. The metering skid (B02) and the control station (B08) are "Y — list separately"; the compressor (C05) is "Review", meaning undecided; manifold, vapour-return line and ESD valves are "N".

Programmable. IACS UR E26 Rev.1 §2 defines a CBS as "a programmable electronic device, or interoperable set of programmable electronic devices", and §1.3.2 a) scopes in OT that uses data to control or monitor physical processes. Pipe handles no data. Neither does a valve body — no logic, no setpoint, no state machine; pilot pressure arrives and it opens, is cut and it closes.

Network interface. For the compressor family the workbook records network_interface as "Likely". Whether its link to the IAS and console is a hardwired contact, Modbus RTU, or an Ethernet fieldbus is not established — and statements resting on a "Likely" value cannot exceed INFERRED.

Purdue level runs L0 (compressor, manifold, piping, valves) → L1 (metering skid) → L2 (control station), with most of the physical bulk at L0. Consequence of loss is mostly "Operational", and a severity value alone never raises a physical-effect code. Supply boundary — the metering skid and compressor package are likely delivered with their own control cubicles, the subject of section 7.

Most of what is visible here — manifold, hose, vapour-return line, valve bodies — is not a cyber object. The cyber objects are the measurement and control paths laid on top of them, two rows out of six. Populate an asset inventory "largest first" and you go exactly backwards.

An honest note on doctrine assignment

The manifold and couplings are assigned to TYP-A10, whose cached doctrine is written about gearbox, clutch and shafting — grounded in clutch engagement sequencing, IACS UR M68 shaft dimensioning and SOLAS II-1 Reg. 47.2 bearing monitoring. None of those grounds apply to a bunkering manifold. Exactly one structural property is inherited: a passive mechanical element with no authority of its own (outbound A0) whose state is not changed by command (P0). This article takes only that property and substitutes IGF Code 8.4.1 as the rule basis; the assignment itself is raised in section 18.

7. Where the Supply Boundary Falls

The supply boundary here is two-layered, and the second layer is what makes this system distinctive.

First layer — the vendor package boundary. The metering skid and compressor package likely arrive with their own control cubicles, and at that line ownership, privilege and above all the update path change hands. For the compressor package, programmable is "Likely": if the local panel is a PLC, an A7 executable-update path opens to the vendor service tool and its effect persists after the interaction ends; if it is a relay panel, that path does not exist at all and inbound collapses to A3/A4. The cyber character of the same system is decided by a single supply decision, independently of where any firewall sits.

Second layer — the hull boundary, where the bunkering link crosses. Beyond the vendor boundary sits a supplier we can control by contract; beyond the hull boundary sits a different ship on every operation — whose ESD logic we do not manage, whose software versions we do not know, whose patch history we cannot see. Yet IGF 8.5.7 requires connection and ISO 20519 requires coordination.

Approval, survey and test regimes — the legitimate window for inbound authority

The rules define when someone may lawfully touch this system: the formal window for inbound authority and, in cyber terms, the scheduled moment at which change occurs.

  • IGF 16.7.3.6 — ESD valves in liquefied gas piping shall close fully and smoothly within 30 seconds, and the closing time shall be verifiable and reproducible. Verified 30 seconds is a ceiling, not a design target — practice selects times of the order of a few seconds, with pressure surge review setting the lower bound Typical, and it is that selected value that belongs under configuration control.
  • IGF 16.7.3.7 — closing time of the valves required by 8.5.8 and 15.4.2.2 shall not exceed 3600 × U / BR seconds, where U is ullage volume at the actuation level (m³) and BR is the maximum bunkering rate agreed between ship and facility (m³/h). Verified
  • IGF 16.7.3.5 — piping, valves and fittings handling fuel or vapour shall be tested under normal operating conditions no later than at the first bunkering operation. Verified

Read 16.7.3.7 again. A safety parameter — permitted valve closing time — is a function of BR, a commercially agreed transfer rate. Raise BR and the permitted closing time shrinks. BR is negotiated afresh for each operation and U depends on level-gauging configuration: both are objects of A3 CONFIGURE.

8. Architecture Patterns

The actual topology is UNKNOWN. But the variable that divides architectures here is not the generic standalone/online/control-integrated axis — it is the physical medium of the ESD link, which decides whether one bit or a data stream crosses between two ships.

Industry technical literature describes three families: pneumatic, electric and fibre optic. Typical A pneumatic link is a single hose joining the two ESD systems — each side monitors hose pressure to detect the other's ESD initiation and vents through a solenoid when its own ESD occurs. Logically one bit, unauthenticated, fail-safe in direction: loss of pressure is a trip. A fibre-optic digital link, per trade-press commentary, was developed in 2006 and widely adopted for FSRU and FSU jetty connections; once connected, the two systems automatically share LNG tank process data as well as telecoms, CCTV and other services. Typical (Single trade source.)

Pattern A — Hardwired / pneumatic. Hardwired contacts inboard, pneumatic hose across; one bit crosses. The narrowest attack surface, where realistic threats reduce to physical access.

Pattern B — Serial-integrated. Package panels reach the IAS and console over Modbus RTU while the ESD link stays pneumatic. Inboard attack surface widens — Modbus RTU has neither sender authentication nor message integrity — while the hull boundary stays narrow at one bit.

Pattern C — Fibre-optic digital link. The link carries process data, telecoms and CCTV. The operational benefit is real: each side sees the other's tank state and trims the transfer rate. But the two ships' networks become logically adjacent, the trust boundary becomes the link's protocol boundary, and E26 §4.2.1.1 — only explicitly permitted traffic crosses a zone boundary — has to be implemented against another vessel, a case the clause, written for inboard zones, does not answer.

Axis A. Pneumatic B. Serial-integrated C. Fibre optic
What crosses the hull boundary1 bit (pressure present/absent)1 bit (pressure present/absent)Process data stream + ancillary services
Link authenticationNone (physical connection is the authentication)NoneProtocol-dependent — to be confirmed
Link failure directionDepressurise = trip (fail-safe)Depressurise = trip (fail-safe)Design-dependent — an E27 SR 3.6 matter
Inboard attack surfaceMinimal (hardwired)Adds Modbus RTU segmentModbus RTU + link gateway
Attack surface beyond the hullLimited to physical accessLimited to physical accessLogical adjacency appears
E26 zone designLink is not a conduitLink is not a conduitLink is a conduit — must be drawn

Part III — Authority and Physical Effect

9. What Information and Commands Flow Through It

Split what flows into information and command and two things appear. Information vastly outweighs command; and almost everything that crosses the hull boundary is information, translated into command on the far side.

Information. Tank pressure, temperature and level on both sides; vapour-return line pressure; transfer rate and totalised quantity; valve position feedback; compressor state; alarm and trip contacts; gas detector readings; ESD link state. Most moves on 4-20 mA and hardwired contacts, some on HART and Modbus RTU.

Command. Pump and compressor start/stop, valve open/close, capacity adjustment, ESD-1 trip, ERS release. The list is short and most of it originates at the bunkering control station.

A third category deserves separate standing: configuration — meter range, span and units; strapping tables; alarm limits; ESD valve closing-time parameters; the agreed rate BR. These do not flow at run time; they are placed before the operation. Because they do not flow, they are watched less.

[Supplying vessel]                Hull boundary            [Receiving vessel]
                                        |
Bunkering console --ESD trip--> solenoid +-- pneumatic hose --+--> pressure switch --> their ESD logic
                                        |     (1 bit)         |                          |
Metering skid --flow/total--> console    |                     |                          v
                                        |                     |        their pumps stop + valves close
Vapour-return line ============ matter ==+=====================+==== receiving tank vapour space
                                        |
                                (pattern C only)
Console / gateway <--process data, CCTV, telecoms--+--fibre--+--> their systems
                                        |

On a pneumatic link the information crossing the boundary is one bit, translated inside the other ship into "stop pumps" and "close valves". On a fibre link that bit is joined by a continuous process-data stream, bidirectional in principle.

The vapour-return line hands across matter, not data — and its effect is stronger than an information channel, because our pressure manipulation changes their tank pressure directly. No protocol, no authentication, and physically the strongest coupling of all.

10. What Authority Does Each Connection Carry

Table 2 — Authority matrix. Source × destination. YES / NO / UNKNOWN / COND (conditional).

Source → Destination Observe (A1) Provide info (A2) Configure (A3) Command (A4) Control (A5) Admin (A6) Update exec (A7)
Bunkering console → cargo controllerYESYESYESYESNONONO
Bunkering console → ESD valves (via solenoid cabinet)YESYESNOYESYESNONO
Bunkering console → compressor packageYESYESYESYESNONONO
Metering skid → bunkering consoleYESYESNONONONONO
Metering skid → BDN / commercial recordNOYESNONONONONO
ESD valve → console (position feedback)NOYESNONONONONO
Compressor → console (state, alarms)NOYESNONONONONO
Manifold and couplings → anythingNONONONONONONO
Vapour-return line → anythingNONONONONONONO
Our ESD link → their ESD logicNOYESNOCONDNONONO
Their ESD logic → our ESD systemNOYESNOCONDNONONO
Vendor service laptop → metering skidYESYESYESYESNOCONDCOND
Vendor service laptop → bunkering consoleYESYESYESYESNOYESYES
Vendor service tool → compressor panelYESYESCONDCONDNOCONDCOND
IAS / cargo network → bunkering consoleYESYESYESNONONONO

The authority of the link — this system's own item

Pneumatic link. What we send is one item of A2 PROVIDE_INFORMATION — "we have tripped". We do not command their pumps; their ESD logic receives that information and commands its own. Yet as a consequence our action changes the physical state of their vessel. The cell is A2 directly and conditionally A4 via their logic — a propagation path taken up in section 13.

Fibre-optic link. A2 is unchanged, but a continuous process-data channel opens alongside it. If bidirectional, an inbound face exists — traffic arriving at our gateway from their vessel — and what that traffic is and how it is validated is unconfirmed. Unknown

Where inbound matters more

(1) The metering skid's HART and gauging configuration path (A3, conditionally A7). A HART Command 35-class range, span or unit change alters the interpretation of the measured quantity. Diverge from the strapping table and you manufacture a plausible but wrong quantity — it looks like a level, so nothing on screen is abnormal. Inferred

(2) The bunkering control station's vendor service laptop (A3, A6, A7). HMI-class items are programmable throughout, so executable code and sequence logic are replaceable. Metering algorithms and conversion tables are software configuration and fall under the inventory obligation of E26 Rev.1 §4.1.1.3.2. Typical A7 differs in kind because its effect persists after the interaction ends.

(3) The compressor package service tool (conditional A3/A6/A7). With programmable recorded as "Likely", the very existence of this path is unconfirmed. Inferred For this family the cache names the anti-surge setpoint (A3) as the most consequential inbound point: surge control modulates a valve on a preset flow-to-pressure ratio, so shift that one ratio and the machine is driven into surge without a single command being issued. This is where A3 outweighing A4 holds physically for rotating machinery.

11. Can the System Affect the Physical Process

Table 3 — Authority-effect matrix

Interaction Authority (out / in) Physical effect Human gate Security significance
Console → compressor start/stop/capacityout A4/A3 · in A2P4 (the compressor itself)EXECUTIONMain path for starting and stopping transfer
Console → ESD valve open/closeout A4/A5 · in A2P4 + P5EXECUTIONCuts the fluid directly. Final element of a safety function
Metering skid → console / BDNout A1/A2 · in A3 (+A7?)P1 (+P3 via overfill logic)EXECUTION / partly NONEThe quiet-wrong failure. Two outcomes, commercial and operational
Gas detection → automatic ESD (IGF 15.5.3)out A2 · in —P3 → P5NONEAutomatic path with no human gate
Vapour-return line (matter path)A0 / A0P0 (no path via a CBS)NONENo cyber path; risk migrates to adjacent instrumentation
Manifold and couplingsA0 / A0P0NONENo logic. Rule basis IGF 8.4.1
ESD link (pneumatic)out A2 · in A2P4 (inside their hull)EXECUTION or NONEOne bit moves another ship's physical process
ESD link (fibre optic)out A2 · in A2 + UnknownP4 (inside their hull)SameContinuous channel widens the inbound face
Vendor laptop → consolein A3/A6/A7P3 (via console)REVIEW (procedural)Persistent effect. Configuration-controlled

P5 attaches to subsets, never to a whole family. Three have grounds. (a) ESD valves — commanded and not closing, emergency isolation as a safety function does not exist. (b) The ERC — a final element that is, unusually, an item whose spurious operation is itself the accident. (c) The independent overfill and high-level system — IBC Code 15.19.6 and 15.19.7 define an overfill-prevention safety function and 15.19.5 requires independence from the gauging system; forge or suppress the switch value on that independent path and the safety function itself is defeated. Verified for the clauses, Inferred for their implementation here.

Conversely the vapour-return line is P0 — which does not mean "not dangerous" but "not captured on this axis." The consequence of a ruptured cryogenic line is enormous, yet it cannot be reached through a control system. The risk does not disappear; it is counted at adjacent typologies, the pressure transmitters and valve actuators attached to the line. The cleanest available example of physical effect ≠ severity.

12. Human Gate — where the person stands in the architecture

The human's position here is fixed by rule, not by custom.

IGF Code 15.5.1 — bunkering control shall be possible from a safe location remote from the bunkering station, from which tank pressure, temperature and level can be monitored and the remote valves of 8.5.3 and 11.5.7 operated. Overfill alarm and automatic shutdown shall also be indicated at that location. Verified

That clause places the human at EXECUTION — actor, not observer. Compressors do not start themselves; valve line-up is commanded by a person; so are the decisions to begin transfer and to stop at topping off. But paths with no human gate coexist inside the same system, and blurring them destroys the analysis.

[Gated path — EXECUTION]
Operator judgement -> console action -> controller -> solenoid -> valve/pump -> fluid
   ^ A person initiates every step. IGF 15.5.1 requires this position by rule.

[Ungated path — NONE]
Gas detector (in duct) -> safety logic -> emergency shutdown            (IGF 15.5.3)
Independent 95/98 % level switch -> overfill logic -> sequential pump & valve shutdown  (IBC 15.19.7 class)
ESD link loss of pressure -> our ESD logic -> pumps stop + valves close
   ^ The person is informed of the result, not asked to approve it. That is the design intent.

[A person in our chain whom we do not manage]
Their operator -> their console -> their ESD -> link -> our system
   ^ Inside our safety chain, but not in our SMS and not in our training records.

The third block is this system's own problem. The absence of a gate on the automatic paths is correct design — require human approval for gas detection and it is not a safety function. The problem is not the missing gate but the gate that sits outside our jurisdiction: the coordinated operation ISO 20519 requires presupposes the training and qualification of the other vessel's operators. Typical

SIMOPS compounds this. Where passenger embarkation, stores or cargo work proceed simultaneously, the operator is asked to hold situational awareness of several operations at once. Typical The assumption that the human is the gate holds only while that human's attention is whole — a gap no cyber control closes, and for an attacker seeking to bypass the gate, the cheapest condition available.

Test regimes also fix the human's place. IGF 16.7.3.5 requires testing under normal operating conditions no later than the first bunkering, and 16.7.3.6 requires closing time to be verifiable and reproducible. Verified The rules order a person to confirm that this value is right — which from a cyber standpoint is an unexpected control: a closing-time reproducibility test is also a detection mechanism for A3 configuration tampering.

13. Authority Escalation and Propagation

Three paths enter at low authority and acquire higher authority downstream.

Path 1 — indirect propagation through a person (metering). The metering skid holds only A1/A2 and commands nothing. But its value is the input to the topping-off decision.

Metering skid re-ranged (A3, inbound)
      |
      v
Totalised quantity reads low   [nothing abnormal on screen — a "plausible but wrong" value]
      |
      v
Operator: "we are short of the target" -> continue transfer (A4, legitimately issued by a person)
      |
      v
Receiving tank level rises -> reaches the independent overfill system (ungated automatic path)
      |
      v
Overfill trip — or, if the independent system is also compromised, physical overfill
      |
      v
P3 -> P5 (via the safety function)     Consequence: transfer halted + commercial dispute; at worst, a release

The attacker never acquired A4. They took one A3 and let the operator issue the command. The control "a human is the gate" works only while what the human sees is true.

Path 2 — propagation across the link. An ESD trip at our console stops their pumps and closes their valves, and the reverse holds too. What crosses is one bit at grade A2, and that one bit is amplified to A4/A5 inside their hull.

Our console (A4 outbound, inside our system)
   |
   v
Our solenoid -> link pressure released   [crossing the boundary: A2, one bit]
   |
   ==== hull boundary ====   <- where our configuration management ends
   |
   v
Their pressure switch -> their ESD logic (logic we have not verified)
   |
   v
Their pumps stop + their ESD valves close   [A4/A5 — amplified inside their hull]
   |
   v
P4 (physical process of the other vessel)

This chain is normal operation — it is what IGF 8.5.7 requires. But the chain of normal operation is also the shape of an attack chain, and we cannot verify its middle link. On a pneumatic link the problem is small; on a fibre link, process data flows continuously across the same boundary and the problem grows.

Path 3 — promotion of a commercial parameter into a safety parameter (BR). BR is a commercial value negotiated for each operation, and under IGF 16.7.3.7 it determines the permitted closing time of a safety valve. Raise BR and the allowance shrinks; U in turn depends on level-gauging configuration. Both are objects of A3 CONFIGURE.

Commercial negotiation (BR agreed) ---+
                                      |
Level gauging configuration (U) ------+--> closing-time requirement = 3600 x U / BR
                                      |            |
                                      |            v
                                      |    ESD valve closing time set & verified (16.7.3.6: <= 30 s, reproducible)
                                      |            |
                                      +------------+--> if the requirement is looser than actual valve response,
                                                        an ESD-1 will not prevent surge or overfill

The escalation here is not technical. It happens at the negotiating table. Agree a high BR without re-verifying valve closing time and safety margin disappears silently. An attacker using this path would not need to enter the system at all — and equally, no network control blocks it.

Part IV — Uncertainty and Security

14. Trust Boundaries and Dependencies

Four trust boundaries, differing in kind.

+-------------------------------------------------------------------+
|  Supplying vessel (our ship)                                      |
|                                                                   |
|   +----------------------------+  B1: vendor package boundary     |
|   | Metering skid (own cubicle)|  - ownership & update path shift |
|   | Compressor package (?)     |  - inbound A3/A6/A7 (conditional)|
|   +----------------------------+  - controllable by contract      |
|                |                                                  |
|   +----------------------------+  B2: physical zone boundary      |
|   | Bunkering control station  |  - the door is the authentication|
|   +----------------------------+  - outsiders enter during work   |
|                |                                                  |
|   +----------------------------+  B4: commercial data boundary    |
|   | Metering -> BDN -> shore   |  - a standing path off the ship  |
|   +----------------------------+  - motive is commercial          |
|                |                                                  |
+================|==================================================+
   B3: hull      |  <=== unique to this system. The counterparty changes every operation
+================|==================================================+
|  Receiving vessel (a ship whose configuration we do not manage)   |
|   Their ESD logic / their tanks / their operators / their software|
+-------------------------------------------------------------------+

B1 — vendor package boundary. Two items can sit in the same drawn zone while configuration responsibility rests with different organisations. ⚠ The cache warns of a common trap: the control cubicle can be absorbed into its parent package and appear in no component row at all. This system's BOM has six rows and no independent cubicle row, so the cubicle may already be invisible in the drawing and the inventory.

B2 — physical zone boundary. The control station is an HMI needing immediate operation, so it is among the device classes most easily granted the identification and authentication exemption of E26 Rev.1 §4.2.4.4.1 — an exemption conditioned on physical access control. But during bunkering that space sees counterparty personnel, surveyors and supervisors coming and going. If a door rather than an account is the boundary, its substance is the visitor control of §4.2.4.3.2 — the control that loosens first under schedule pressure. Typical E27 Rev.1 §4.1 Table 1 item 12 (SR 2.5, session lock) collides with this head-on: an operating requirement not to leave the console and an inactivity lock are not compatible, and the compromise is often undocumented.

B3 — hull boundary, the one unique to this system. What separates it from the other three is that the counterparty changes every operation. A vendor is a contracting party whose configuration can be asked about; the other ship was a different ship yesterday. Here the regulatory duality of section 1 returns as a trust problem: we are under the IGC Code and they are under the IGF Code, and one safety function bridges two normative systems. E26 and E27 are written with the ship as the unit, and §4.2.1.1 requires traffic crossing a zone boundary to be limited to what is explicitly permitted — but that clause presumes inboard zones. How to apply it to a conduit spanning two ships, it does not say: less a defect of the rules than a shape they have not yet addressed, and the honest tag is Unknown.

B4 — commercial data boundary. The measured quantity becomes a BDN and leaves the ship Verified, possibly under E26 §1.3.2 b) on communication interfaces from in-scope CBSs to other systems — a standing path out of the cargo control zone for commercial reasons. Its distinctive feature is motive: the incentive to distort a measured quantity may be commercial gain rather than an accident, and that incentive does not exist in machinery-space typologies.

15. What Happens When the System Fails

Engineering failure comes before cyber failure, and knowing these chains puts section 16 on evidence rather than assumption.

(a) Unplanned separation of the ERC. The two principal failures identified for flexible cryogenic transfer hoses are unplanned disconnection of the breakaway coupling and damage or rupture of the hose itself. Typical

ERC operates early (malfunction or spurious signal)
   |
   v
Physical separation during transfer — by design, "without spillage"
   |
   v  in practice, however:
possible release of residual cryogenic liquid + immediate loss of transfer + long re-connection
   |
   v
Consequence: failed operation, deck personnel exposure, hours to resume

Malfunction of the safety function is itself the accident. The received wisdom that a safety function is safe even when it operates spuriously does not hold here. ESD-1 is reversible; ESD-2 is an irreversible physical event. That asymmetry bears on target selection in section 16.

(b) Blockage or insufficient capacity of the vapour-return path.

Vapour-return line blocked / compressor capacity short / valves mis-lined
   |
   v
Receiving tank vapour-space pressure rises   (fastest during M2 cooldown)
   |
   v
Differential falls -> transfer rate drops  (the first symptom is a performance problem, not a safety one)
   |
   v
If pressure keeps rising -> receiving tank relief valve lifts
   |
   v
Natural gas discharged to atmosphere = the state IGF 8.5.2 prohibits.
The relief valve worked correctly; the system failed normatively.

The two release scenarios that cannot be dismissed during bunkering are LNG hose leakage and natural gas release through the receiving vessel's fuel tank relief valve — and that chain is precisely where the second ends. Typical

(c) Quiet metering drift. The cache's sentence applies verbatim: the most dangerous failure is not the screen going dark but the screen being quietly wrong. Antenna or stilling-well fouling weakens the radar return so level jumps or locks to the wrong surface; after re-ranging, divergence from the strapping table leaves level plausible while the converted quantity is systematically off. Inferred With no symptom, detection depends on periodic verification.

(d) Failures of the ESD valve family. Wear or debris produces passing at the fully closed position while the console still reads "shut". A burnt-out solenoid coil leaves that valve unable to be operated remotely. Limit-switch misalignment produces disagreement between actual position and console indication, so a pump is started against a wrong line-up. Typical The last matters most: a physical failure whose consequence has the same shape as a cyber attack.

The most dangerous failure class here is not the one that stops the system but the one that shows it falsely. A stoppage is visible immediately; a falsehood only after the outcome.

16. Attack Surface and Credible Threat Scenarios

Surface What it is here Note
Local / physicalBunkering control station, solenoid cabinet, field wiring and junction boxesOutsider presence during operations is a constant
Removable mediaConsole and metering-skid updates, vendor laptops (E26 §4.2.4.3.4)At modification or changed terminal requirements
Connected OTIAS and cargo control network, Modbus RTU segmentsNo authentication, no message integrity
Ship-to-ship interfaceESD link, vapour-return lineUnique to this system. Re-established every operation
VendorMetering, compressor and console service access (E26 §4.2.6.3.2)Inbound A3/A6/A7
Supply chainPackage software configuration, cubicle delivery stateThe B1 boundary

Generic threat lists are not the subject. The three below are derived from the structure of this system and each is carried to the end of its chain.

S1 — Suppression of the vapour-return pressure signal (Connected OT)

Stage Content
Entry interactionModbus RTU segment of the cargo control network, or the pressure transmitter signal path
Initial authorityA2 (access to an information path)
MechanismHold the vapour-return and receiving vapour-space pressure indications inside the normal band. Symptomatically identical to a blocked impulse line
Authority gainedNone — information is distorted without acquiring authority
Affected interactionOperator's rate judgement, compressor capacity loop, high-pressure alarm
Physical effectP3 → rising receiving tank pressure goes undetected
ConsequenceEnters the chain of 15(b) — relief valve discharge, reaching the state IGF 8.5.2 prohibits

The precondition is that pressure indication is single-path. If an independent vapour-space pressure monitor exists on a separate system, the scenario does not hold. Whether that independence exists here is unconfirmed. Unknown

S2 — Defeat of the ESD link itself (ship-to-ship interface)

Stage Content
Entry interactionThe bunkering link. Whether this holds at all depends on the pattern
Initial authorityPatterns A/B: physical access only. Pattern C: access to the link protocol
MechanismIn pattern C, hold the ESD status field of link traffic at "normal", or delay trip propagation
Authority gainedThe negation of A2 — the ability not to send information
Affected interactionESD coordination between two ships
Physical effectOur side stops while theirs keeps transferring — trapped liquid expansion in pipework, or the reverse
ConsequenceFailure of coordinated shutdown; at worst, system rupture and cryogenic release

An honest distinction. On a pneumatic link (patterns A and B) the scenario is hard to construct. Depressurisation is a trip, and depressurisation follows from merely cutting the hose — the direction is fail-safe. To suppress a trip an attacker must hold the link physically and supply pressure, which is not a logical attack. On a fibre-optic link (pattern C), status is a data field, and a data field can be held. Whether that link's failure behaviour implements the deterministic output required by E27 Rev.1 §4.1 Table 1 item 20 (SR 3.6) is unconfirmed. Unknown

That distinction is itself one of this article's conclusions. The choice of link medium determines whether this threat exists. Choose pneumatic and the scenario disappears — not a security control added, but a threat eliminated by design.

S3 — Re-ranging the metering skid (vendor / removable media)

Stage Content
Entry interactionVendor service laptop or HART handheld. Cargo-area junction boxes are physically accessible and unauthenticated
Initial authorityA3 CONFIGURE (range, span, units, or strapping interpretation)
MechanismA HART Command 35-class range change. Nothing abnormal on screen
Authority gainedNone — the command is issued by the operator
Affected interactionTopping-off judgement, rate decisions, BDN quantity
Physical effectP1 → P3 (on reaching overfill logic)
ConsequenceCommercial dispute plus overfill risk. The chain of path 1 in section 13, exactly

What separates this from the other two is motive. S1 and S2 aim at an accident; S3 can aim at money. An attack aimed at money aims at not being discovered, so it avoids the accident — meaning it persists and repeats. Inferred

17. Security Architecture and Standards

Controls are derived from the threats; standards mapping comes afterwards.

From S1 (signal suppression).

  • Maintain at least one monitoring path independent of the control path for vapour-space and vapour-return pressure — separate power, separate cable route, separate marshalling, the property IBC Code 15.19.5 requires of the overfill system.
  • E27 Rev.1 §4.1 Table 1 item 20 (SR 3.6) — outputs placed in a predetermined state when normal operation is not maintained. Loss of pressure indication must not degrade into "holding at normal".
  • E26 Rev.1 §4.2.1.1 — restrict boundary crossing of the zone containing Modbus RTU segments to explicitly permitted traffic.

From S2 (link defeat).

  • Treat the link medium as a design decision. A pneumatic link structurally removes threat S2; if fibre optic is adopted, document explicitly whether its benefit exceeds the cost of logical adjacency.
  • Draw the bunkering link on the zones and conduits diagram, explicitly, as a conduit. This is this article's central recommendation. The link is often absent from the drawing because it is not an inboard system — but under E26 §4.2.1.1 it is unmistakably a path crossing a zone boundary, and what is not drawn is not controlled.
  • E26 Rev.1 §4.4.4.1/§4.4.4.3 — minimal risk condition on a cyber incident. Here it is unambiguous: stop the transfer and close the valves. What must be defined separately is whether that stop is coordinated while the link is impaired.
  • E27 Rev.1 §4.1 Table 1 item 20 (SR 3.6) — design the link's failure behaviour as fail-to-trip.

From S3 (re-ranging).

  • Register the metering configuration (range, span, units, strapping table) as a configuration-controlled item and compare values before and after each operation. The inventory E26 Rev.1 §4.1.1.1 and §4.1.1.3.2 require includes metering algorithms and conversion tables.
  • E26 Rev.1 §4.2.4.3.4 — removable media policy, with malware scanning and signature verification before use.
  • E26 Rev.1 §4.2.6.3.2 — control of vendor remote diagnostic and maintenance access. Do not blur vendor access into "remote access"; state which authority enters in which direction.
  • E26 Rev.1 §4.2.1.3 — navigation and communication systems shall not share a zone with cargo systems.

Controls the rules themselves already provide.

  • The manual stop valve in series with a remote shutdown valve of IGF 8.5.3 lets a person cut the fluid locally even if the remote circuit is wholly compromised — functionally the last manual fallback, of the same character as the local backup control requirement of E26 §4.4.2. Verified
  • The closing-time reproducibility requirement of IGF 16.7.3.6 is a detection mechanism for A3 configuration tampering, and the operational test at first bunkering of 16.7.3.5 establishes a commissioning-time configuration baseline. Verified
  • Manage BR and U as per-operation configuration items: while the closing-time requirement is a function of BR, changing BR is changing a safety parameter.

A caution. The E26 and E27 clauses mapped above are written with the ship as the unit, so requirements for a conduit spanning two ships cannot be read directly out of them. The recommendations above are an extension of the clauses' intent, and this article does not claim the rules require them.

18. Open Questions, Takeaways and References

Open questions

The typologies are 6/6 established, but items remain unresolved at instance level.

  1. Appropriateness of the TYP-A10 doctrine assignment. Only the structural property (A0/P0) is inherited; clutch sequencing, propulsion control, UR M68 and SOLAS II-1 Reg. 47.2 do not apply. Whether a separate typology is needed is a judgement for the cache owner.
  2. What is the physical medium of the bunkering link? Pneumatic or fibre optic decides the threat conclusions of this article.
  3. Who owns configuration management of the other vessel's ESD system? Part of our safety function lies outside our configuration control, and the rules give no answer.
  4. Is the compressor package local panel a PLC or a relay panel? A PLC settles both the A7 path and CBS status; a relay panel deletes A6 and A7 from inbound.
  5. When will the compressor family's CBS status (E26 "Review") be closed? Unlisted means neither §4.2.1 zone assignment nor E27 §4 capability requirements apply. The unresolved state is itself a management gap.
  6. Which BOM row holds the control cubicles of the metering skid and the console? None of the six is an independent cubicle row.
  7. Is there a vapour-pressure monitoring path independent of the control path? The precondition for S1.
  8. If a fibre-optic link is adopted, is its failure behaviour defined? An E27 SR 3.6 matter.

Twelve questions to ask first on a real project

  1. Is the bunkering ESD link pneumatic, fibre optic, or hardwired cable?
  2. Is that link drawn on the zones and conduits diagram? If not, why not?
  3. Is there a documented list of the data the link carries?
  4. Designed behaviour when the link is severed — trip, hold, or alarm only?
  5. What do we verify about the other vessel's ESD system before connecting?
  6. Design, measured and last-verified values of ESD valve closing time? (16.7.3.6)
  7. Where is BR recorded, and is the closing-time requirement recalculated when it changes? (16.7.3.7)
  8. Are the metering skid's range, span and strapping table registered as configuration items?
  9. Vendor service access: to which device, in which direction, carrying which authority?
  10. Is the compressor package panel a PLC or a relay panel? Does it have an engineering port?
  11. Is there a vapour-space pressure monitor with genuinely separate power and cable routes?
  12. If the §4.2.4.4.1 authentication exemption was applied to this console, what physical control does it rest on?

Engineering takeaways

  • The trust boundary of this system is not the hull. The ESD link of IGF 8.5.7 and the vapour-return line bind two ships into one safety function and one fluid system.
  • Two of six rows are CBS. Manifold, piping and valves are most of the physical bulk and none of the cyber objects.
  • At the ESD valve, outbound A0 and P4/P5 hold together. The way to protect the valve is at the solenoid cabinet and the console.
  • The choice of link medium determines whether a threat exists. Pneumatic structurally removes S2; fibre optic brings operational benefit together with logical adjacency.
  • A commercial parameter, BR, is promoted into a safety parameter. Negotiating BR is a safety configuration change.
  • The most dangerous failure class is not the one that stops the system but the one that shows it falsely.
System (gas bunkering transfer & vapour return)
  -> Function (liquid transfer / vapour management / custody transfer / coordinated shutdown)
  -> Component (6 rows)
  -> Typology (C05, A10, A01, B02, A04, B08)
  -> Interaction (console-valve, console-compressor, metering-console, link-their ESD, vapour-their tank)
  -> Information / Command (much information, little command; configuration is placed, not flowed)
  -> Authority (out A0-A5 / in A0-A7 — inbound carries more weight)
  -> Physical Effect (P0-P5 — A0 and P4 hold in the same place)
  -> Human Gate (EXECUTION + ungated automatic paths + a person outside our jurisdiction)
  -> Dependency (vapour-return health -> transfer performance -> safety margin)
  -> Trust (vendor / physical zone / hull / commercial data)
  -> Failure (early ERC release / vapour blockage / metering drift / valve passing)
  -> Consequence (release, overfill, dispute, failed coordinated stop)
  -> Threat (S1 signal suppression / S2 link defeat / S3 re-ranging)
  -> Security Requirement (independent monitoring / link as conduit / metering under configuration control)
  -> Control (E26 4.2.1.1, 4.2.4.3.4, 4.2.6.3.2 / E27 SR 3.6 / IGF 8.5.3 manual fallback)
  -> Assurance (16.7.3.5 operational test / 16.7.3.6 closing-time reproducibility)
  -> Evidence (verification dates, configuration baseline, link test records)

References

  • IMO Res. MSC.391(95), IGF Code (in force 1 Jan 2017) — §8.4.1, §8.5.1-8.5.8, §15.5.1, §15.5.3, §16.7.3.5-16.7.3.7.
  • IMO IGC Code — the regime governing the supplying (bunkering) vessel.
  • IMO IBC Code §15.19.5-15.19.7 — independence of high-level alarm and overflow control (basis of the cached TYP-B02 doctrine).
  • ISO 20519:2021, Specification for bunkering of liquefied natural gas fuelled vessels (cited at scope level only); ISO 21903 transfer hoses; ISO 21562:2020 mass flowmeters.
  • IACS UR E26 Rev.1 (Nov 2023) — §1.3.2, §2, §4.1.1.1, §4.1.1.3.2, §4.2.1.1, §4.2.1.3, §4.2.4.3.2, §4.2.4.3.4, §4.2.4.4.1, §4.2.6.3.2, §4.4.2, §4.4.4.
  • IACS UR E27 Rev.1 (Sep 2023) — §4.1 Table 1 items 12, 20 (IEC 62443-3-3 SR 2.5, SR 3.6). IACS UR E22 Rev.3 — software functional requirements.
  • SGMF linked-ESD / bunkering safety link recommendations; LNG bunkering HAZID literature (ERC failure modes, release scenarios, SIMOPS); trade-press technical commentary on ESD-1/ESD-2 and link media. Typical
  • blog-pipeline typology cache, SYS-215 brief (6/6 typologies) — doctrine and authority / physical-effect codes for TYP-C05, A10, A01, B02, A04, B08.