Trusted time transfer apparatus and method
By establishing device identity through a trusted time transfer device, employing two-way certificate verification and encrypted transmission mechanisms, the problems of easily replaceable time transfer devices and unreliable signals are solved, enabling trusted transmission and traceability of time signals and providing a reliable time benchmark for the digital economy.
Patent Information
- Application Number
- CN202511406158.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-29
- Publication Date
- 2026-01-27
- Estimated Expiration
- 2045-09-29
AI Technical Summary
Existing time transmission devices are easily replaced, lack identity authentication mechanisms and encrypted output functions, cannot ensure the reliable transmission of time signals, and cannot achieve traceability and proof, thus affecting the development of the digital economy.
A trusted time transfer device is adopted, including a network management system and a trusted time transfer device. Through device identity solidification, two-way certificate verification, encrypted transmission and traceability verification mechanisms, the trusted transmission and traceability of time signals are ensured.
It achieves the immutability, controllable transmission, and traceability of time signals, ensuring the reliability and accuracy of time signals and providing a reliable time benchmark for the digital economy.
Smart Images

Figure CN120896664B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of trusted time transfer technology, and in particular to a trusted time transfer device and method. Background Technology
[0002] Time sources are categorized into two types: ordinary time sources and trusted time sources. Ordinary time sources (such as satellite signal receivers and NTP time servers) do not verify the reliability of the time signal source, and their equipment can be arbitrarily replaced. Trusted time sources, on the other hand, undergo rigorous verification of the time signal source's reliability. They are not only strictly protected against replacement, but their output time signal must also be encrypted and possess traceability and verifiability. However, even if the time signal output by a trusted time source is reliable, if the time transmission device is untrustworthy, it cannot be guaranteed that the reliable time signal will be accurately transmitted to the next-level time transmission device or end user.
[0003] In traditional time application systems, a single time source (such as GPS / BeiDou satellite signal, NTP network time, or fiber optic time signal) is typically selected and forwarded to the user via communication transmission equipment, NTP relay equipment, or fiber optic time transmission equipment. However, the rapid development of the digital economy places higher demands on time; it's not just about "using time," but also about "using reliable time," as the reliability of time directly determines the value of data. Since time is one of the three essential elements of data, if the time used to constitute data is unreliable, the overall reliability of the data will be questioned. Existing time sources and transmission equipment cannot ensure that the time used by users is reliable, which seriously hinders the development of the digital economy. Current time transmission devices in time systems have not solved the problem of reliable time transmission, and their implementation technologies and solutions have many shortcomings, which are discussed in detail below:
[0004] 1. Fiber Optic Time Transfer System: A fiber optic time transfer system uses optical fiber as the medium and a proprietary protocol to transmit high-precision time signals. For example... Figure 1 As shown, the time signal originates from the fiber optic time source, undergoes signal detection, delay compensation, and amplification processing by the time transmission equipment, and is finally transmitted to the time-using terminal using the same proprietary protocol, forming a complete fiber optic time transmission link. However, this system has a serious security vulnerability in terms of the security of the time transmission device. Specifically, if the time transmission device is illegally replaced, the system cannot detect it in time. Attackers can easily implant optical switches at the device's access node, bypassing the device to directly transmit the time signal. This means that if the time transmission device is tampered with, the entire time system will lose its ability to trace and prove the time signal. In short, the existing time transmission device can only perform basic relay and networking tasks and cannot ensure the reliability of the time signal during transmission.
[0005] 2. Network time transfer system: such as Figure 2As shown, network time transmission based on the NTP protocol is achieved through a "source-relay-terminal" link. The time signal emitted by the NTP time source first reaches the relay device, which dynamically calculates and compensates for network latency and clock skew, and then transmits the calibrated time signal to the end user via the NTP protocol. However, the time relay device in this process is also at risk of being illegally replaced. Due to the public and plaintext transmission characteristics of the NTP protocol, attackers can easily intercept and tamper with the time signal, causing the time to lose accuracy during transmission. In addition, once the relay device is replaced, the entire time system will lose the ability to trace and verify the time signal, making the reliability of the time relay unreliable. Therefore, although the time transmission device completes the tasks of signal relay and networking, it has obvious defects in ensuring the reliable transmission of time signals.
[0006] In summary, existing time relay systems based on fiber optics and the NTP protocol suffer from several common problems: time relay devices are easily replaced, yet corresponding replacement monitoring mechanisms are lacking; there are no means of time signal identification and transmission management, nor are there any time signal encryption output functions; and the traceability and verification of the time used cannot be achieved. These problems collectively drive the demand for innovative trusted time relay devices. Such devices need to not only perform relay networking functions but also solve the trustworthiness problem of time relay, collaborating with trusted time sources to form a trusted time system, thereby enabling trusted time to effectively serve the development of the digital economy. Summary of the Invention
[0007] To address the problems existing in the prior art, the purpose of this invention is to provide a reliable time transmission device and method. This invention only receives reliable time signals output from the previous stage, and at the same time ensures that it cannot be replaced through a strict control mechanism. In terms of signal processing, the signal is transmitted after time delay compensation, amplification, and encryption, while realizing the controllability of real-time time detection and time delay compensation. In addition, this invention also has a time relay function and provides a feasible path for the traceability verification and reliability proof of time signals.
[0008] To achieve the above objectives, the technical solution adopted by the present invention is: a trusted time transmission device, comprising a network management system and a trusted time transmission device; the network management system is used for device identity solidification and authentication and real-time monitoring of device operating status; the trusted time transmission device, based on a trusted time signal receiving relay module, a device identity authentication pre-solidification mechanism, a two-way certificate verification and transmission encryption mechanism, a device fault stop signal transmission mechanism, and a time signal tracing and verification mechanism, transmits the trusted time signal after real-time measurement, delay compensation, and signal amplification processing.
[0009] As a further improvement to the invention, it also includes an authoritative digital certification center for time devices, used for the application, issuance, and revocation of certificates.
[0010] The present invention also provides a trusted time transfer method, implemented using the trusted time transfer device described above, the method comprising the following steps:
[0011] Step 1, Reliable Time Signal Reception Relay: Receive reliable time signals from a reliable time source through the reliable time signal reception relay module;
[0012] Step 2, Identification of Time Transfer Device: The network management system applies for a digital certificate for the time transfer device from an authoritative digital certificate authentication center. The digital certificate authentication center tests, authenticates, and issues digital certificates to trusted time transfer devices. Then, the network management system embeds the digital certificate into the trusted time transfer device.
[0013] Step 3, Fault Monitoring and Stop Transmission Control: The network management system monitors the signal status, communication status, and operating status of the time transmission device in real time. When the device fails, it immediately stops the time signal output. At the same time, before time output, it checks the duration of continuous normal operation of the device. If the time output reaches the user-set reliable time output standard, it outputs normally and records the reliable time output log.
[0014] Step 4, Time Signal Encryption and Secure Transmission: The output time signal is encrypted using an open-source asymmetric encryption algorithm or a domestic encryption algorithm before being output. The time receiver and sender use a two-way digital certificate authentication mechanism to ensure the secure and reliable transmission and reception of time information and prevent the time signal from being tampered with during transmission.
[0015] Step 5, Time Signal Tracing and Verification: Record the received time signal information, time source device information, time transmission device information, encrypted time signal output information, and time terminal information throughout the entire process for reliable time signal tracing and verification.
[0016] As a further improvement to the present invention, step 1 is specifically as follows:
[0017] The trusted time signal receiving relay module obtains a trusted time signal from a trusted time source using a proprietary protocol, measures the signal strength, frequency, and phase, then calculates and dynamically compensates for the time delay caused by the transmission link and device processing. The compensated time signal enters the amplification stage to enhance the signal strength, and finally uses an encryption algorithm to securely encrypt the processed time signal before transmitting the encrypted trusted time signal to the downstream system.
[0018] As a further improvement of the present invention, step 2 is specifically as follows:
[0019] A hardware-level security chip or a PUF (Physically Unclonable Array) chip is integrated on the main circuit board of the time transfer device. Leveraging process variations naturally occurring during silicon wafer manufacturing, a unique and uncopyable device serial number is generated, serving as the physical fingerprint of the device's identity. The network management system generates a key pair for the device, associating and binding the device serial number with the device's public key, device information, and affiliated unit information. Based on this, it applies for a digital certificate for the device's identity from an authoritative time device digital certification center. The certification center verifies the application materials, the authenticity of the applicant unit, the authenticity of the device's identity, and the device's trustworthiness requirements. After successful verification, it digitally signs the affiliated unit information, the device's public key, the device's identity information, and the certificate's validity period using its own private key, generating a digital certificate. The certificate is then returned to the device manager, who embeds it into the device using the network management system for identity verification and encryption in subsequent time signal transmission.
[0020] As a further improvement of the present invention, in step 2, the digital certificate can only be read and not modified.
[0021] As a further improvement of the present invention, step 2 further includes:
[0022] During the operation of the time transmission device, the network management system checks the device's offline status at preset time intervals. If an abnormality is detected, the network management system immediately forces the device to stop time output and generates a communication interruption alarm. After on-site inspection by the equipment management personnel and approval according to the device time output approval process in the network management system, time output is restored. At the same time, the network management system comprehensively analyzes and judges the situation of network interruptions or abnormal fluctuations by considering factors such as the number of interruptions, duration, and operating status of devices on the same network, so as to avoid the transmission of time signals being affected by network fluctuations.
[0023] As a further improvement to the present invention, step 3 is specifically as follows:
[0024] Based on the multi-dimensional abnormal characteristics of equipment operation status, signal quality, and time deviation, a graded judgment rule is established: (1) In terms of equipment operation status, the voltage, temperature and logs of the core hardware are monitored. If any parameter fails to meet the standard for multiple consecutive sampling cycles, it is judged as a hardware or system failure; (2) In terms of time signal quality, the signal-to-noise ratio of satellite signal, the fluctuation of optical power of fiber optic signal, and whether the signature verification is passed are monitored. If the signal characteristics exceed the limit for multiple consecutive cycles or the signature verification fails, it is judged as an abnormal signal source or tampering; (3) In terms of time deviation, the fault threshold and warning threshold are set with reference to other local time sources and other reliable standard time sources. If the deviation continues for a preset time within the warning range, or a single jump is greater than the preset time normal interference, it is judged as a time reference drift fault; When any dimension of equipment operation status, time signal quality, or time deviation is abnormal, it is judged as an equipment fault, and the stop time output mechanism is immediately triggered to block the erroneous time output and automatically report the alarm to the network management system.
[0025] As a further improvement to the present invention, step 5 is specifically as follows:
[0026] Time source X encrypts the original time data with its private key and signs it with the public key of time transmission device Y to generate the first hash segment, then sends the data to time transmission device Y. Time transmission device Y verifies the signature with its own private key and then decrypts the data with the public key of time source X. Next, time transmission device Y adds delay compensation to the decrypted data, encrypts the time data with its own private key, signs it with the time-using terminal Z to generate the second hash segment, and then sends the data to the time-using terminal Z. The network management system extracts the device entity information from the digital certificates of devices X, Y, and Z, and writes it along with the two segments of time data into the time transmission chain log. Any node anomaly can be reverse-verified by verifying the signature and hash, realizing the tracing of the time signal path and the identity verification of the device nodes it passes through.
[0027] This invention addresses the issue of replaceability in existing mainstream time transfer devices by constructing a reliable time transfer device. This device must ensure its immutability while simultaneously providing reliable time traceability and verification capabilities, fulfilling both relay networking functions. Specifically, it solves the following technical problems:
[0028] 1. The problem of arbitrary replacement of time transfer devices: Due to the lack of device authentication mechanisms and physical layer security protection, fiber optic time transfer allows attackers to replace time transfer devices by implanting optical switches. Network time transfer, because the IP address of the NTP time source can be arbitrarily spoofed and lacks an identity binding mechanism, allows attackers to easily impersonate or replace legitimate intermediate time transmission devices. Both types of systems create serious security blind spots because they cannot detect the replacement of time transfer devices in real time.
[0029] 2. Lack of Time Signal Authenticity Verification: Current fiber optic and network time transmission systems do not verify the authenticity of time signals. This allows time transmission devices to potentially receive and propagate tampered or false time information, leading to time synchronization errors in downstream devices or end users. To address this issue, a mechanism is urgently needed to ensure the authenticity and integrity of time signals, guaranteeing the accuracy and reliability of the time information received by the receiving end and preventing chain reactions and serious consequences caused by time errors.
[0030] 3. The lack of a time transmission monitoring mechanism: Under the existing time transmission technology framework, when deviations or errors occur during time transmission, users and downstream time-using systems cannot detect these problems through the mechanisms of the time-using terminals themselves. This necessitates the establishment of a real-time monitoring and verification mechanism to continuously monitor and verify the time output, thereby ensuring the reliability and accuracy of the time information.
[0031] 4. The problem of untraceability and unprovability of time signals: In existing time transmission technologies, the transmission system does not have tamper-proof operation logs and event records. Once an anomaly occurs, it is impossible to restore the complete path of signal transmission or accurately locate potential attack points, which seriously restricts the traceability and provability of time signals.
[0032] The core of this invention lies in solving the fundamental defect of the lack of reliability in existing time transmission devices, laying the foundation for building a comprehensive reliable time system, and making it a reality that reliable time plays a key role in promoting the development of the digital economy.
[0033] The beneficial effects of this invention are:
[0034] 1. Time transfer device anti-replacement: The trusted time transfer device uses a device identity authentication and solidification mechanism to generate a unique "physical fingerprint" using a hardware-level security chip or a PUF physically unclonable chip. Combined with the application, issuance and solidification of digital certificates, as well as real-time monitoring by the network management system, it prevents the device from being replaced or impersonated, ensuring the legitimacy and trustworthiness of the device identity and solving the security risks of traditional devices being easily replaced.
[0035] 2. Trusted Time Signal Relay: The trusted time transmission device obtains a trusted time signal through a proprietary protocol. After precise parameter measurement, dynamic delay compensation, and signal amplification and enhancement, it is securely encrypted using encryption algorithms (such as SM4 and asymmetric RSA) and then outputted stably. This not only solves the problems of signal interference, difficulty in controlling delay, and insecure transmission in traditional technologies, but also builds an end-to-end trusted link to ensure the reliability and accuracy of the signal from reception to output. This provides a more reliable time reference for downstream systems and helps trusted time systems to be used efficiently in scenarios such as the digital economy.
[0036] 3. Anti-tampering of time signal transmission: The two-way certificate verification and encrypted output mechanism of the trusted time transmission device dynamically encrypts time information through national cryptographic algorithms, asymmetric encryption algorithms, etc. At the same time, the sending and receiving ends exchange verification digital certificates to establish two-way trust, ensuring the integrity and confidentiality of time data during transmission and avoiding the risk of signal tampering.
[0037] 4. Controllable Time Signal Transmission: The reliable time transmission device's equipment failure-stopping time transmission mechanism monitors the device's operating status, signal quality, and time deviation from multiple dimensions, establishes hierarchical judgment rules, and immediately stops time output and issues an alarm once an anomaly occurs. This effectively blocks the transmission of erroneous time, ensures the accuracy and stability of time output, and reduces the chain reaction problems caused by time errors.
[0038] 5. Time signal traceability proof: The traceability and proof mechanism of the trusted time transmission device constructs a three-segment non-repudiable evidence chain of "source-transmission-use", records relevant information throughout the entire life cycle of the time signal, and enables any abnormality at any node to be traced back in reverse. It realizes the traceability of the path of the time signal and the identity proof of the device nodes it passes through, providing a strong ex-post audit and proof basis for the credibility of time information.
[0039] In summary, this invention constructs an end-to-end closed-loop trusted transmission system for time signals, realizing non-repudiation, immutability, and full traceability throughout the entire lifecycle of time-transmitted signals. It provides a truly reliable time reference for critical infrastructure and the development of the digital economy, effectively solving many security and reliability issues existing in current time transmission technologies. Attached Figure Description
[0040] Figure 1 A schematic diagram of an optical fiber time transfer system;
[0041] Figure 2 A schematic diagram of a network time transfer system;
[0042] Figure 3 This is a schematic diagram of a trusted time transfer device in an embodiment of the present invention;
[0043] Figure 4 This is a schematic diagram of the reliable time signal reception relay mechanism in an embodiment of the present invention;
[0044] Figure 5 This is a schematic diagram of the device identity authentication and solidification mechanism in an embodiment of the present invention;
[0045] Figure 6 This is a schematic diagram of the equipment failure stop time propagation mechanism in an embodiment of the present invention;
[0046] Figure 7 This is a schematic diagram of the two-way certificate verification and encrypted output mechanism in an embodiment of the present invention;
[0047] Figure 8 This is a schematic diagram of the time signal tracing and verification mechanism in an embodiment of the present invention. Detailed Implementation
[0048] The embodiments of the present invention will now be described in detail with reference to the accompanying drawings.
[0049] Example:
[0050] like Figure 3As shown, a trusted time transfer device includes a network management system and a trusted time transfer device. The network management system is used for device identity solidification and authentication, as well as real-time monitoring of device operating status, ensuring the legitimacy of device identity and the stability of device operation. The trusted time transfer device, based on a trusted time signal receiving relay module, a device identity authentication pre-solidification mechanism, a two-way certificate verification and transmission encryption mechanism, a device fault stop signal transmission mechanism, and a time signal traceability and verification mechanism, transmits the trusted time signal after real-time measurement, delay compensation, and signal amplification. Furthermore, an authoritative time device digital certification center is responsible for the application, issuance, and revocation of certificates, further enhancing the trustworthiness of the trusted time transfer device.
[0051] This embodiment ensures reliable time information output from reception to output by establishing mechanisms such as trusted time signal reception relay, anti-tampering measures for time transmission equipment, real-time monitoring of time signal transmission, encrypted transmission of time signals, and traceability and verification of time signals. It also proposes a trusted time transmission method, including the following steps:
[0052] 1. Reliable Time Signal Reception Relay: The time transmission device receives a reliable time signal from a reliable time source through a reliable time signal reception relay mechanism, and then relays the time signal after real-time measurement, time delay compensation, and signal amplification.
[0053] 2. Authentication of Time Transfer Device: The network management system applies for a digital certificate for the time transfer device from the national authoritative digital certificate authentication center for time devices. The authentication center tests, authenticates, and issues a digital certificate for the device. The network management system then embeds the certificate into the device. The certificate can only be read and cannot be modified to prevent the device from being replaced or impersonated, thus ensuring the credibility of the device's identity.
[0054] 3. Fault Monitoring and Time Transmission Stop Control: The network management system monitors the signal status, communication status, and operational status of the time transmission equipment in real time. If the equipment malfunctions, it immediately stops the time signal output. Simultaneously, before outputting time, the equipment checks its continuous normal operating time; only outputting time normally if it meets the user-defined reliable time output standard, and a reliable time output log is recorded for subsequent reliability auditing.
[0055] 4. Encryption and secure transmission of time signals: The output time signals are encrypted using open-source asymmetric encryption algorithms or domestic encryption algorithms before being output. The time receiver and sender use a two-way digital certificate authentication mechanism to ensure the secure and reliable transmission and reception of time information and prevent the time signals from being tampered with during transmission.
[0056] 5. Time signal traceability and verification: The received time signal information, time source device information, time transmission device information, encrypted time signal output information, and time terminal information are recorded throughout the entire process for reliable traceability and verification of the time signal.
[0057] The trusted time transfer method in this embodiment will be further explained below:
[0058] The trusted time transmission method is based on the mechanism of "time signal reception relay - trusted identity of transmission device - encrypted transmission of time data - fault monitoring to stop transmission - time traceability and proof". Specifically, it includes: trusted time signal reception relay mechanism, device identity authentication and solidification mechanism, device fault to stop time transmission mechanism, two-way certificate verification and transmission encryption mechanism, and time signal traceability and proof mechanism.
[0059] First, such as Figure 4 As shown, the trusted time signal receiving relay mechanism obtains a trusted time signal from a trusted time source using a proprietary protocol through a trusted time signal receiving relay module. It accurately measures key parameters such as signal strength, frequency, and phase, and then automatically calculates and dynamically compensates for the time delay caused by the transmission link and device processing. The compensated time signal enters the amplification stage to enhance the signal strength. Finally, it uses encryption algorithms (such as the national standard SM4, asymmetric RSA, etc.) to securely encrypt the processed time signal, and then stably transmits the encrypted trusted time signal to the downstream system, ensuring the reliability and accuracy of the signal from reception to output, and constructing an end-to-end trusted time transmission link.
[0060] Secondly, such as Figure 5 As shown, the device identity authentication and solidification mechanism integrates a hardware-level security chip or a PUF (Physically Unclonable Array) chip on the main circuit board of the time-transfer device. Leveraging process variations naturally occurring during silicon wafer manufacturing, a unique and uncopyable device serial number is generated, serving as the device's "physical fingerprint." The network management system generates a key pair for the device, associating and binding the device serial number with the device's public key, device information, and affiliated organization information. Based on this, it applies for a digital certificate for the device's identity from an authoritative time device digital certification center. The certification center verifies the application materials, the authenticity of the applicant organization, the authenticity of the device's identity, and the device's trustworthiness requirements. After successful verification, it digitally signs the affiliated organization information, device public key, device identity information, certificate validity period, and other data using its own private key, generating a digital certificate containing the aforementioned information and signature. After certificate issuance, it is returned to the device manager, who then embeds it into the device using the network management system for identity verification and encryption in subsequent time signal transmission. Others can verify the validity of the device certificate using the certification center's public key.
[0061] During routine operation, the network management system checks the device's offline status at second-by-second intervals. If an anomaly is detected, the system immediately forces the device to stop time output and generates a communication interruption alarm, preventing the possibility of the device being replaced. Time output can only be restored with a single click after on-site inspection by equipment management personnel and approval according to the device time output approval process in the network management system. Simultaneously, the network management system also incorporates fault tolerance to address network intermittent interruptions or abnormal fluctuations by comprehensively analyzing multiple factors such as the number of interruptions, duration, and operating status of devices on the same network, thus preventing network fluctuations from affecting time signal transmission.
[0062] Again, such as Figure 6 As shown, the equipment failure stop time propagation mechanism combines multi-dimensional abnormal characteristics of equipment operating status, signal quality, and time deviation to establish a graded judgment rule: First, regarding equipment operating status, the voltage (deviation from rated value ±10%), temperature (exceeding -20℃ to 70℃), and logs (containing unauthorized modifications and process crash records) of core hardware (such as security chips, oscillators, and receivers) are monitored. If any parameter fails to meet the standard for three consecutive sampling cycles (1 time / second), it is judged as a hardware or system failure. Second, regarding time signal quality, satellite signals must meet a signal-to-noise ratio ≥45dB; optical fiber signal power fluctuation ≤±2dBm; and RSA / SM2 signature verification must pass. If signal characteristics exceed the limits for five consecutive cycles or signature verification fails, it is judged as an abnormal signal source or tampering. Third, regarding time deviation, using other local time sources and other trusted standard time sources as references, a fault threshold >100ns and a warning threshold of 50ns-100ns are set. If the deviation remains within the warning range for 10 seconds, or if there is normal interference such as a single jump >100ns, it is judged as a time reference drift fault. When equipment operating status, time signal quality, or time deviation exceeds the fault threshold, any of these three factors combined constitutes a equipment fault. This triggers an immediate stop-time output mechanism, blocking erroneous time output and automatically reporting an alarm to the network management system. After the time signal output is blocked, equipment maintenance personnel must troubleshoot the equipment fault and then initiate a time signal output request through the network management system. Management personnel will then review and confirm whether the time signal can be output according to the trusted time output approval process.
[0063] Next, as Figure 7 As shown, the two-way certificate verification and encrypted output mechanism dynamically encrypts the time information generated by the time transmission device using national cryptographic algorithms (such as SM4), asymmetric encryption algorithms (such as RSA, ECC), or quantum encryption technology. It establishes two-way trust at the time transceiver end by exchanging and verifying each other's digital certificates (X.509 format) to ensure the integrity and confidentiality of the data.
[0064] Finally, as Figure 8As shown, the time signal tracing and verification mechanism establishes a three-segment non-repudiable evidence chain of "source-transmission-use" throughout the entire lifecycle of the time signal passing through the trusted time transmission device: Time source X encrypts the original time data with its private key and signs it with the public key of transmission device Y to generate the first hash segment, and then sends the data to transmission device Y; Transmission device Y verifies the signature with its own private key and then decrypts the data with the public key of time source X. Next, device Y adds delay compensation to the decrypted data, encrypts the time data with its own private key, signs it with the time-using terminal Z to generate the second hash segment, and then sends the data to the time-using terminal Z; The network management system extracts the device entity information from the digital certificates of devices X, Y, and Z, and writes it along with the two segments of time data into the time transmission chain log; Any node anomaly can be reverse-verified to verify the signature and hash, realizing the tracing of the time signal path and the identity verification of the device nodes it passes through.
[0065] This embodiment constructs an end-to-end trusted closed loop by "trusted time signal reception relay, identity solidification of transmission equipment, encrypted signature of time data, immediate shutdown upon fault monitoring of transmission equipment, and recording of time transmission process". From source anti-counterfeiting, transmission anti-tampering, transmission controllability, terminal anti-substitution to post-event traceability and proof, it realizes the non-repudiation, immutability and full traceability of time signals throughout their entire life cycle, providing a truly trusted time reference for critical infrastructure.
[0066] The embodiments described above are merely illustrative of specific implementations of the present invention, and while the descriptions are detailed, they should not be construed as limiting the scope of the present invention. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of the present invention, and these modifications and improvements all fall within the scope of protection of the present invention.
Claims
1. A reliable time transfer method, characterized in that, A trusted time transfer device is used, comprising a network management system and a trusted time transfer equipment. The network management system is used for device identity authentication and real-time monitoring of device operating status. The trusted time transfer equipment, based on a trusted time signal receiving relay module, a device identity authentication pre-solidification mechanism, a two-way certificate verification and transmission encryption mechanism, a device fault stop signal transmission mechanism, and a time signal tracing and verification mechanism, transmits the trusted time signal after real-time measurement, delay compensation, and signal amplification. The method includes the following steps: Step 1, Reliable Time Signal Reception Relay: Receive reliable time signals from a reliable time source through the reliable time signal reception relay module; Step 1 is described in detail as follows: The trusted time signal receiving relay module obtains a trusted time signal from a trusted time source using a private protocol, measures the signal strength, frequency, and phase, then calculates and dynamically compensates for the time delay caused by the transmission link and device processing. The compensated time signal enters the amplification stage to enhance the signal strength, and finally uses an encryption algorithm to securely encrypt the processed time signal before transmitting the encrypted trusted time signal to the downstream system. Step 2, Identification of Time Transfer Device: The network management system applies for a digital certificate for the time transfer device from an authoritative digital certificate authentication center. The digital certificate authentication center tests, authenticates, and issues digital certificates to trusted time transfer devices. Then, the network management system embeds the digital certificate into the trusted time transfer device. Step 3, Fault Monitoring and Stop Transmission Control: The network management system monitors the signal status, communication status, and operating status of the time transmission device in real time. When the device fails, it immediately stops the time signal output. At the same time, before time output, it checks the duration of continuous normal operation of the device. If the time output reaches the user-set reliable time output standard, it outputs normally and records the reliable time output log. Step 4, Time Signal Encryption and Secure Transmission: The output time signal is encrypted using an open-source asymmetric encryption algorithm or a domestic encryption algorithm before being output. The time receiver and sender use a two-way digital certificate authentication mechanism to ensure the secure and reliable transmission and reception of time information and prevent the time signal from being tampered with during transmission. Step 5, Time Signal Tracing and Verification: Record the received time signal information, time source device information, time transmission device information, encrypted time signal output information, and time terminal information throughout the entire process for reliable time signal tracing and verification. Step 5 is described in detail below: Time source X encrypts the original time data with its private key and signs it with the public key of time transmission device Y to generate the first hash segment, then sends the data to time transmission device Y. Time transmission device Y verifies the signature with its own private key and then decrypts the data with the public key of time source X. Next, time transmission device Y adds delay compensation to the decrypted data, encrypts the time data with its own private key, signs it with the time-using terminal Z to generate the second hash segment, and then sends the data to the time-using terminal Z. The network management system extracts the device entity information from the digital certificates of devices X, Y, and Z, and writes it along with the two segments of time data into the time transmission chain log. Any node anomaly can be reverse-verified by verifying the signature and hash, realizing the tracing of the time signal path and the identity verification of the device nodes it passes through.
2. The reliable time transfer method according to claim 1, characterized in that, Step 2 is described in detail below: A hardware-level security chip or a PUF (Physically Unclonable Array) chip is integrated on the main circuit board of the time transfer device. Leveraging process variations naturally occurring during silicon wafer manufacturing, a unique and uncopyable device serial number is generated, serving as the physical fingerprint of the device's identity. The network management system generates a key pair for the device, associating and binding the device serial number with the device's public key, device information, and affiliated unit information. Based on this, it applies for a digital certificate for the device's identity from an authoritative time device digital certification center. The certification center verifies the application materials, the authenticity of the applicant unit, the authenticity of the device's identity, and the device's trustworthiness requirements. After successful verification, it digitally signs the affiliated unit information, the device's public key, the device's identity information, and the certificate's validity period using its own private key, generating a digital certificate. The certificate is then returned to the device manager, who embeds it into the device using the network management system for identity verification and encryption in subsequent time signal transmission.
3. The reliable time transfer method according to claim 2, characterized in that, In step 2, the digital certificate is read-only and cannot be modified.
4. The reliable time transfer method according to claim 1, characterized in that, Step 2 also includes: During the operation of the time transmission device, the network management system checks the device's offline status at preset time intervals. If an abnormality is detected, the network management system immediately forces the device to stop time output and generates a communication interruption alarm. After on-site inspection by the equipment management personnel and approval according to the device time output approval process in the network management system, time output is restored. At the same time, the network management system comprehensively analyzes and judges the situation of network interruptions or abnormal fluctuations by considering factors such as the number of interruptions, duration, and operating status of devices on the same network, so as to avoid the transmission of time signals being affected by network fluctuations.
5. The reliable time transfer method according to claim 1, characterized in that, Step 3 is as follows: Based on the multi-dimensional abnormal characteristics of equipment operation status, signal quality, and time deviation, a graded judgment rule is established: (1) In terms of equipment operation status, the voltage, temperature and logs of the core hardware are monitored. If any parameter fails to meet the standard for multiple consecutive sampling cycles, it is judged as a hardware or system failure; (2) In terms of time signal quality, the signal-to-noise ratio of satellite signal, the fluctuation of optical power of fiber optic signal, and whether the signature verification is passed are monitored. If the signal characteristics exceed the limit for multiple consecutive cycles or the signature verification fails, it is judged as an abnormal signal source or tampering; (3) In terms of time deviation, the fault threshold and warning threshold are set with reference to other local time sources and other reliable standard time sources. If the deviation continues for a preset time within the warning range, or a single jump is greater than the preset time normal interference, it is judged as a time reference drift fault; When any dimension of equipment operation status, time signal quality, or time deviation is abnormal, it is judged as an equipment fault, and the stop time output mechanism is immediately triggered to block the erroneous time output and automatically report the alarm to the network management system.
6. The reliable time transfer method according to claim 1, characterized in that, It also includes the authoritative Digital Certification Centre for Time Devices, which is used for the application, issuance, and revocation of certificates.
Citation Information
Patent Citations
Trusted time source device and implementation method and application thereof
CN120639508A
Cited By
Reliable time synchronization device and method
CN122293445A