A network time synchronization system and method

By employing a physical layer security architecture and system infrastructure model, the trade-off between security and accuracy in network time synchronization protocols is resolved, enabling secure transmission and authentication of network time synchronization messages, thereby improving both the security and accuracy of network time synchronization.

CN118041594BActive Publication Date: 2026-01-20Chinese People's Liberation Army Cyberspace Force Information Engineering University
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202410035474.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-01-10
Publication Date
2026-01-20
Estimated Expiration
2044-01-10

AI Technical Summary

Technical Problem

Existing network time synchronization protocols struggle to strike a reasonable balance between security and time synchronization accuracy. They have limitations in resisting forwarding attacks, timestamps are easily tampered with, authentication mechanisms are computationally complex and unsuitable for broadcast/multicast scenarios, and there is a lack of authentication mechanisms suitable for network time synchronization.

Method used

Employing a physical layer security architecture and system infrastructure model, the system achieves channel coding, modulation, transmission, and demodulation of signals through a secure coding modulator, a channel simulation subsystem, and secure switching equipment. It also incorporates artificial channel influence for legitimacy judgment and routing control, and designs dedicated link communication frames to achieve secure transmission of secret information bits and physical layer authentication.

Benefits of technology

It achieves secure transmission of network time synchronization messages and physical layer authentication, reduces processing latency and computational complexity, is compatible with existing security mechanisms, and improves the security and accuracy of network time synchronization.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118041594B_ABST
    Figure CN118041594B_ABST
Patent Text Reader

Abstract

The application provides a network time synchronization system and method, and belongs to the technical field of network security. The system comprises a sending end and a plurality of receiving ends. Each receiving end is provided with a physical link between the sending end. The sending end is connected with a secure coding modulator. Each receiving end is connected with a secure demodulation decoder. The secure coding modulator and each secure demodulation decoder are provided with a secure transmission auxiliary device. The secure transmission auxiliary device comprises a first end channel simulation subsystem connected with the secure coding modulator, a second end channel simulation subsystem connected with the secure demodulation decoder, a plurality of channel simulation subsystems and a plurality of secure exchange devices located between the first end channel simulation subsystem and the second end channel simulation subsystem. A special communication link is arranged between the secure transmission auxiliary devices. The application realizes the secure transmission of secret information bits in the network time synchronization message, physical layer identity authentication, physical layer routing control and other functions.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network security, and in particular to a network time synchronization system and method. BACKGROUND

[0002] Network time reference is one of the main forms of modern time reference, and is widely used in systems that rely on a unified time reference support and are in a basic form of distribution and networking. Network time synchronization is a key link in the establishment and maintenance of network time reference. Time synchronization refers to the state in which the clock faces of all clocks in the system are consistent. Network time synchronization technology uses a private or public network as a medium, and through the exchange of messages between the reference clock and the clock to be synchronized, the clocks of each computer and device connected to the synchronization network are synchronized to a common reference time. Since the network environment is insecure and unreliable, and not all time and frequency terminals that exchange time synchronization messages are trustworthy, network time synchronization has become the most vulnerable link in the establishment and maintenance of network time reference.

[0003] Typical network time synchronization protocols include the Network Time Protocol (NTP) and the Precision Time Protocol (PTP, IEEE 1588). The NTP protocol is designed for large, dynamic, and variable delay packet switching networks, and the message exchange is based on the connectionless UDP protocol. The PTP protocol is designed for infrastructure networks, and the network construction process requires the use of special hardware to achieve a well-controlled packet switching network. The protocol breaks through the limitations of the time synchronization accuracy of the NTP protocol and can provide high-precision time synchronization services for precision instruments and equipment, industrial automation, and military applications. Both NTP / PTP protocols are constantly evolving and improving, and security issues have become a focus of attention and promotion by the protocol working group in recent years. The latest development of the NTP security protocol is the Network Time Security (NTS) protocol (RFC 8915) released in 2020, and the latest PTP security standardization achievement is Appendix P of the upgraded version of IEEE 1588v2.1 released in 2019. According to the above standardization achievements, the existing security mechanisms can provide basic security functions such as identity authentication, data integrity protection, and replay attack suppression, but still have the following significant defects:

[0004] (1) The current security mechanism mainly relies on encryption technology, which has significant limitations in resisting forwarding attacks such as delay attacks.

[0005] (2) Considering the impact of encryption and decryption processing delay and its uncertainty on time synchronization performance, the timestamps in the time synchronization messages are publicly transmitted in the network and are vulnerable to tampering attacks.

[0006] (3) Network time synchronization has its particularity. In designing security policy and algorithm, time synchronization and synchronization security problem must be considered together, that is, time synchronization precision must be considered while ensuring synchronization security, such as meeting the basic requirements of low processing delay, low operation complexity and not depending on time synchronization. The current mechanism has not achieved a reasonable compromise between security performance and time synchronization precision.

[0007] (4) In terms of resisting time source spoofing attack, the current asymmetric key-based identity authentication mechanism generally has problems of high operation complexity, large processing delay and the like, which has a great influence on time synchronization precision, and some schemes depend on accurate time synchronization, which is not suitable for direct application in network time synchronization system. The symmetric key-based identity authentication mechanism has time source identity authentication function in unicast scenario, but can only realize group identity authentication in broadcast / multicast scenario, and even does not have identity authentication function. Therefore, there is no identity authentication mechanism completely applicable to network time synchronization at present. SUMMARY

[0008] Therefore, the embodiments of the present application provide a network time synchronization system and method, aiming at the inherent limitations of the existing network time synchronization security standardization results based on cryptography technology, a basic security architecture and system infrastructure model are proposed from a new angle, i.e., the angle of physical layer security.

[0009] In a first aspect, the embodiments of the present application provide a network time synchronization system, comprising a sending end and a plurality of receiving ends in communication connection with the sending end, a physical link being arranged between each receiving end and the sending end, each physical link comprising a plurality of sub-links, the sending end being connected with a secure coding modulator, each receiving end being connected with a secure demodulation decoder, a secure transmission auxiliary device being arranged on the physical link between the secure coding modulator and each secure demodulation decoder, the secure transmission auxiliary device comprising a first end channel simulation subsystem connected with the secure coding modulator, a second end channel simulation subsystem connected with the secure demodulation decoder, a plurality of channel simulation subsystems and a plurality of secure exchange devices located between the first end channel simulation subsystem and the second end channel simulation subsystem, and a dedicated communication link being arranged between each secure transmission auxiliary device.

[0010] The secure coding modulator is configured to perform channel coding and modulation on the original time synchronization message sent by the sending end to obtain a coded and modulated signal.

[0011] The first end channel simulation subsystem is configured to extract routing information of the original time synchronization message from the encoded modulated signal, generate a special link communication frame, and transmit the encoded modulated signal with the artificial channel influence to the next channel simulation subsystem through a network link according to the routing information.

[0012] The channel simulation subsystem is configured to determine the legitimacy of the received encoded modulated signal, apply the artificial channel influence to the encoded modulated signal that passes the legitimacy determination, and transmit the encoded modulated signal with the artificial channel influence to the next channel simulation subsystem through the network link according to the routing information.

[0013] The security exchange device is configured to check whether the received encoded modulated signal matches the special link communication frame, and if so, equalize the sum of the artificial channel influences applied to the encoded modulated signal by the first end channel simulation subsystem and the channel simulation subsystem on the sub-link according to the routing information, transmit the equalized encoded modulated signal to the first channel simulation subsystem of the next sub-link through the network link, and transmit the updated special link communication frame to the first channel simulation subsystem of the next sub-link through the special link.

[0014] The second end channel simulation subsystem is configured to check whether the encoded modulated signal transmitted by the channel simulation subsystem matches the special link communication frame, and if so, equalize the sum of the artificial channel influences applied to the encoded modulated signal by the channel simulation subsystem on the sub-link according to the routing information, and transmit the equalized encoded modulated signal to the security demodulator.

[0015] The security demodulator is configured to demodulate, decode, and securely determine the received encoded modulated signal and then transmit it to the receiving end.

[0016] According to a specific implementation of an embodiment of the present application, the special link communication frame sequentially contains an identification code of the sending end, an identification code of the receiving end, and a plurality of sub-frames, each of which corresponds to a sub-link. The identification code of the sending end is arranged in a first field of the special link communication frame, and the identification code of the receiving end is arranged in a second field of the special link communication frame.

[0017] According to a specific implementation manner of the embodiment of the present application, each of the subframes comprises four fields, the first field of each of the subframes is used to carry a sublink identification code corresponding to the subframe, the second field of each of the subframes is used to carry a sending device identification code, the sending device being the security exchange device, the channel simulation subsystem, the first-end channel simulation subsystem, the third field of each of the subframes is used to carry a destination device identification code, the destination device being the security exchange device, the channel simulation subsystem, the second-end channel simulation subsystem, and the fourth field of each of the subframes is used to carry an identification code of the first-end channel simulation subsystem, the channel simulation subsystem, and the second-end channel simulation subsystem and a passing sequence of the original time synchronization message on the sublink.

[0018] According to a specific implementation manner of the embodiment of the present application, the encoding manner of the security encoding modulator comprises Polar encoding, and the modulation manner of the security encoding modulator comprises OFDM-IM modulation.

[0019] According to a specific implementation manner of the embodiment of the present application, the manner of applying artificial channel influence comprises applying artificial noise and frequency selective fading to a signal.

[0020] According to a specific implementation manner of the embodiment of the present application, the security criterion of the security decision is a bit error rate of a security test sequence, and the security test sequence is a sequence known by both the sending device and the receiving device and added in the process of channel encoding and modulation of the original time synchronization message.

[0021] In a second aspect, the embodiment of the present application further provides a network time synchronization method, which adopts the network time synchronization system according to any of the embodiments of the first aspect, and the method comprises the following steps.

[0022] The sending device sends an original time synchronization message.

[0023] The security encoding modulator is used to perform channel encoding and modulation on the original time synchronization message, to obtain an encoded and modulated signal.

[0024] The first-end channel simulation subsystem is used to extract routing information of the original time synchronization message transmitted to the receiving device from the encoded and modulated signal, to generate a dedicated link communication frame, to transmit the encoded and modulated signal to which artificial channel influence has been applied to the next channel simulation subsystem through a network link according to the routing information, and to transmit the dedicated link communication frame to the next channel simulation subsystem through the dedicated link.

[0025] The legality of the received coded modulation signal is judged by the channel simulation subsystem, the artificial channel influence is applied to the coded modulation signal which passes the legality judgment, the coded modulation signal to which the artificial channel influence is applied is transmitted to the next channel simulation subsystem through the network link according to the routing information, and the updated special link communication frame is transmitted to the next channel simulation subsystem through the special link;

[0026] The received coded modulation signal and the special link communication frame are checked by the security exchange device, if matched, the sum of the artificial channel influence applied to the coded modulation signal by the first end channel simulation subsystem and the channel simulation subsystem on the sub-link is equalized according to the routing information, the equalized coded modulation signal is transmitted to the first channel simulation subsystem of the next sub-link through the network link, and the updated special link communication frame is transmitted to the first channel simulation subsystem of the next sub-link through the special link;

[0027] The coded modulation signal transmitted by the channel simulation subsystem and the special link communication frame are checked by the second end channel simulation subsystem, if matched, the sum of the artificial channel influence applied to the coded modulation signal by the channel simulation subsystem on the sub-link is equalized according to the routing information, and the equalized coded modulation signal is sent to the security demodulator and decoder;

[0028] The coded modulation signal arriving is demodulated, decoded and security judged by the security demodulator and decoder;

[0029] The original time synchronization message recovered by demodulation and decoding and which passes the security judgment is sent to the receiving end, and the original time synchronization message recovered by demodulation and decoding and which does not pass the security judgment is discarded, and the receiving end is informed that an illegal message is received.

[0030] According to a specific implementation manner of the embodiment of the application, the method further comprises:

[0031] In the channel simulation subsystem, the coded modulation signal which does not pass the legality judgment is directly transmitted to the exchange device at the end of the current sub-link through the network link and the special link respectively, and if the current sub-link is the last sub-link, the coded modulation signal is directly transmitted to the second end channel simulation subsystem.

[0032] According to a specific implementation manner of the embodiment of the application, the method further comprises:

[0033] If the channel simulation subsystem only receives the dedicated link communication frame within a first preset time limit, the transmission of the dedicated link communication frame is terminated; if the channel simulation subsystem only receives the coded modulation signal, the coded modulation signal is not subjected to the artificial channel influence and is directly sent to the next channel simulation subsystem of the sub-link.

[0034] According to a specific implementation manner of the embodiment of the application, the method further comprises:

[0035] In the security exchange device, if the received coded modulation signal does not match the dedicated link communication frame, the coded modulation signal or the dedicated link communication frame that matches is waited for;

[0036] If the waiting exceeds a second preset time limit, the transmission of the coded modulation signal or the dedicated link communication frame is terminated.

[0037] Advantageous effects

[0038] The network time synchronization system and method in the embodiment of the application provide a general security architecture and system infrastructure model serving the design of network time synchronization physical layer security strategy and algorithm. The system fully considers the typical working mode of NTP / PTP and the network transmission characteristics, adopts the overall idea of combination of coding, modulation and link transmission quality control, and realizes the secure transmission of secret information bits in the network time synchronization message, physical layer identity authentication, physical layer routing control and other functions. The security architecture and system infrastructure model are beneficial to the system integration of physical layer security strategy and algorithm, beneficial to the design of unified upper interface, realize the compatibility with the existing security mechanism, and can further design the cross-layer security mechanism. BRIEF DESCRIPTION OF DRAWINGS

[0039] In order to more clearly illustrate the technical solutions of the embodiments of the application, the following will briefly introduce the drawings needed to be used in the embodiments. Obviously, the drawings in the following description are only some embodiments of the application, and for those skilled in the art, other drawings can also be obtained without creative labor on the basis of these drawings.

[0040] Figure 1 It is an architecture diagram of the network time synchronization system according to an embodiment of the application.

[0041] Figure 2 It is a structural schematic diagram of the dedicated link communication frame according to an embodiment of the application. DETAILED DESCRIPTION

[0042] The embodiments of the application will be described in detail below with reference to the drawings.

[0043] Following, the embodiments of the present application are described through specific examples, and other advantages and effects of the present application can be easily understood by those skilled in the art from the disclosure. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. The present application can also be implemented or applied through other different specific embodiments, and various modifications or changes can be made to the details in the specification based on different views and applications without departing from the spirit of the present application. It should be noted that the following embodiments and features in the embodiments can be combined with each other without conflict. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the present application.

[0044] It should be noted that the various aspects of the embodiments described below are within the scope of the appended claims. It should be apparent that the aspects described herein can be embodied in a wide variety of forms and that any specific structure and / or function described herein is merely illustrative. Based on the teachings herein one skilled in the art should appreciate that an aspect described herein can be implemented independently of any other aspects and that an aspect can be implemented both as any number of software, firmware, and / or hardware structures.

[0045] It should also be noted that the figures provided in the following embodiments are only schematically illustrating the basic concepts of the present application, and only the components related to the present application are shown in the figures, not drawn according to the number, shape and size of the components in actual implementation, and the shape, number and proportion of each component in actual implementation can be arbitrarily changed, and the layout of the components can be more complex.

[0046] In addition, in the following description, specific details are provided to facilitate a thorough understanding of examples. However, one skilled in the art will understand that the described aspects can be practiced without these specific details.

[0047] In a first aspect, embodiments of the present application provide a network time synchronization system, which is described below with reference to Figure 1 and Figure 2 in detail.

[0048] In one embodiment, with reference to Figure 1The network time synchronization system comprises a sending end and a plurality of receiving ends in communication connection with the sending end, each of the receiving ends is provided with a physical link with the sending end, each physical link comprises a plurality of sub-links, the sending end is connected with a secure coding modulator, each of the receiving ends is connected with a secure demodulation decoder, a secure transmission auxiliary device is arranged on the physical link between the secure coding modulator and each of the secure demodulation decoders, the secure transmission auxiliary device comprises a first end channel simulation subsystem connected with the secure coding modulator, a second end channel simulation subsystem connected with the secure demodulation decoder, a plurality of channel simulation subsystems and a plurality of secure exchange devices between the first end channel simulation subsystem and the second end channel simulation subsystem, and a dedicated communication link between each of the secure transmission auxiliary devices;

[0049] The secure coding modulator is used for channel coding and modulation of an original time synchronization message sent by the sending end to obtain a coded modulation signal.

[0050] The first end channel simulation subsystem is used for extracting routing information of the original time synchronization message transmitted to the receiving end from the coded modulation signal to generate a dedicated link communication frame, transmitting the coded modulation signal with an artificial channel influence applied thereto to the next channel simulation subsystem through a network link according to the routing information, and transmitting the dedicated link communication frame to the next channel simulation subsystem through the dedicated link.

[0051] The channel simulation subsystem is used for judging the legitimacy of the received coded modulation signal, applying the artificial channel influence to the coded modulation signal with the legitimate judgment passed, transmitting the coded modulation signal with the artificial channel influence applied thereto to the next channel simulation subsystem through the network link according to the routing information, and transmitting the updated dedicated link communication frame to the next channel simulation subsystem through the dedicated link.

[0052] The secure exchange device is used for checking whether the received coded modulation signal matches the dedicated link communication frame, if matched, equalizing the sum of the artificial channel influence applied to the coded modulation signal by the first end channel simulation subsystem (only involving the first sub-link) and the channel simulation subsystem on the sub-link according to the routing information, transmitting the equalized coded modulation signal to the first channel simulation subsystem of the next sub-link through the network link, and transmitting the updated dedicated link communication frame to the first channel simulation subsystem of the next sub-link through the dedicated link.

[0053] The second end channel simulation subsystem is configured to check whether the encoded modulated signal transmitted by the channel simulation subsystem matches the dedicated link communication frame, and if so, to equalize the sum of the artificial channel effects exerted on the encoded modulated signal by the channel simulation subsystem on the sub-link according to the routing information, and to transmit the equalized encoded modulated signal to the secure demodulator.

[0054] The secure demodulator is configured to demodulate, decode and securely determine the received encoded modulated signal and transmit the same to the receiving end.

[0055] Specifically, the network time synchronization system in the embodiment is based on the typical working mode of the NTP / PTP protocol, and the physical link of the message transmission can be divided into two forms: unicast (one-to-one) and broadcast (one-to-many). Without loss of generality, the network time synchronization system is designed based on the broadcast scenario, and unicast is regarded as a special form of broadcast. In the broadcast scenario, the sending end sends time synchronization messages to N receiving ends, and the message transmission route is determined in advance. The specific determination method can refer to patent application No. 202211665095.X. In the actual network environment, the physical link from the sending end to each receiving end is composed of multiple sub-links. In this application, a sub-link refers to the physical link between the sending end and the secure switching device, the secure switching device and the secure switching device, and the secure switching device and the receiving end. In the system proposed in this application, a plurality of channel simulation subsystems are arranged on each sub-link, and the channel simulation subsystems closest to the sending end and the receiving end (i.e., the first and last channel simulation subsystems of the message transmission link) are referred to as end channel simulation subsystems (including the first end channel simulation subsystem and the second end channel simulation subsystem). Each time-frequency terminal (sending end or receiving end) in the system is configured with a set of secure encoding modulator and secure demodulator.

[0056] In specific implementation, the secure encoding modulator: performs channel encoding and modulation on the physical layer information bits of the original time synchronization message sent by the sending end, and the encoding and modulation methods include but are not limited to Polar encoding and OFDM-IM modulation. The OFDM-IM modulation method is described in detail in patent application No. 202211656673.3. The purpose of encoding and modulation is:

[0057] 1) To build a secure transmission link and realize secure and reliable transmission of time synchronization message information bits. This security is based on information theory and is different from the security based on the limited computing power of attackers in cryptography. It is usually characterized by the normalized mutual information between the original information bits and the information bits intercepted by the attacker, as shown in equation (1):

[0058]

[0059] wherein U denotes the original data block, Y e denotes the data block intercepted by the attacker, N denotes the data block length, and I(X;Y) denotes the mutual information between the data block and the data block.

[0060] The encoding and modulation mode adopted by the secure coding modulator must ensure that, for the information bits (referred to as secret information bits in the present application) in the message that need to be protected, the formula (1) tends to zero, thereby ensuring the security of message transmission from the physical layer. For an attacker, it is impossible to obtain any valid information from the intercepted secret information bit data block, and further impossible to implement a timestamp tampering attack. For each legitimate receiving end, by performing a secure judgment on the received time synchronization message, it is possible to effectively identify the message subjected to a forwarding attack (such as a time delay attack).

[0061] 2) Implement physical layer identity authentication. The encoding and modulation mode adopted by the secure coding modulator must further rely on physical layer technology and means to implement source identity authentication of the time synchronization message on the basis of the above-mentioned secure transmission link, thereby enabling each legitimate receiving end to effectively identify the false message subjected to a time source spoofing attack.

[0062] 3) Carry the routing information from the sending end to each legitimate receiving end, and cooperate with the dedicated secure transmission auxiliary device designed in the present application to implement physical layer routing control.

[0063] 4) While implementing physical layer security, it is possible to be compatible with the existing NTP / PTP security mechanism.

[0064] 5) The physical layer technology processing delay is small, and the influence on the precision of time synchronization is low.

[0065] In specific implementation, the end channel simulation subsystem is one of the secure transmission auxiliary devices, and all the secure transmission auxiliary devices and their operating mechanisms cooperate with each other to implement artificial degradation of the signal transmission quality of the illegal message. The artificial degradation assists the above-mentioned secure coding and modulation to implement various security functions.

[0066] In one embodiment, the first end channel simulation subsystem on the sending end side receives the output signal of the secure coding modulator, extracts the routing information of the message to the target receiving end from the output signal, and generates a dedicated link communication frame. The dedicated link communication frame is a dedicated data frame for information interaction between the secure transmission auxiliary devices, and the frame structure is as follows: Figure 2As shown in the figure, each legal receiver corresponds to a special link communication frame, the first two fields of each frame respectively bear the identification code of the sender and the legal receiver, and then are the sub-frames. That is, the special link communication frame sequentially contains the identification code of the sender, the identification code of the receiver and a plurality of sub-frames, each of the sub-frames corresponds to a sub-link, the identification code of the sender is arranged in the first field of the special link communication frame, and the identification code of the receiver is arranged in the second field of the special link communication frame. Each sub-frame corresponds to a sub-link, for example, sub-frame 1 corresponds to the first sub-link, sub-frame 2 corresponds to the second sub-link, and so on.

[0067] In an embodiment, each of the sub-frames includes four fields, the first field of each of the sub-frames is used to bear the sub-link identification code corresponding to the sub-frame, the second field of each of the sub-frames is used to bear the identification code of the sending device, which can be the security exchange device, the channel simulation sub-system, the first-end channel simulation sub-system, the third field of each of the sub-frames is used to bear the identification code of the destination device, which can be the security exchange device, the channel simulation sub-system, the second-end channel simulation sub-system, and the fourth field of each of the sub-frames is used to bear the identification code of the first-end channel simulation sub-system (only related to the first sub-link), the channel simulation sub-system, the second-end channel simulation sub-system (only related to the last sub-link) and the passing sequence which the original time synchronization message needs to pass on the sub-link.

[0068] In an embodiment, the manner of applying artificial channel influence includes applying artificial noise and frequency selective fading to the signal. The specific artificial channel influence applied depends on the technical features of the encoding and modulation technology adopted by the security encoding modulator, and the degradation strategy for the illegal signal.

[0069] In an embodiment, the security demodulation decoder is used to demodulate, decode and make a security decision on the encoded and modulated signal reaching each legal receiver. The security criterion of the security decision is the bit error rate of the security test sequence, which is a sequence added in the process of channel encoding and modulation of the original time synchronization message and known by both the sender and the receiver, and is part of the secret information bits. If the bit error rate of the security test sequence is lower than the security threshold, it is determined as a legal message, and the recovered original time synchronization message is sent to the receiver; if the bit error rate is greater than or equal to the security threshold, it is determined as an illegal message, and is discarded, and the receiver is informed that an illegal message is received.

[0070] It needs to be explained that this application assumes that all the secure transmission auxiliary devices in the network (including the end channel simulation subsystem, the channel simulation subsystem and the secure exchange device) are trusted, and that a dedicated communication link is built between each secure transmission auxiliary device for the transmission of dedicated link communication frames. The entire dedicated communication link of the system constitutes a secure private network, which is shielded from non-secure transmission auxiliary devices.

[0071] In specific implementation, the channel simulation subsystem is one of the secure transmission auxiliary devices, which is used to: receive a message signal (a coded modulated signal) and a corresponding dedicated link communication frame, make a decision on the legitimacy of the arriving signal according to the dedicated link communication frame, the message signal and the time difference between the arrival of the dedicated link communication frame and the message signal, and if it is a normal signal, apply a specific artificial channel impact to the signal, and then send the message signal to the next channel simulation subsystem along the network link according to the routing information, while transmitting the updated dedicated link communication frame to the next channel simulation subsystem through the dedicated link; if it is an abnormal signal, do not apply an artificial channel impact to the message signal, and directly transmit the message signal and the updated dedicated link communication frame to the exchange device at the end of the current sub-link through the network link and the dedicated link respectively (if the current sub-link is the last sub-link, directly transmit them to the end channel simulation subsystem).

[0072] Within a specified time limit, if the channel simulation subsystem only receives the dedicated link communication frame, it terminates the transmission of the dedicated link communication frame; if the channel simulation subsystem only receives the message signal, it does not apply an artificial channel impact to the signal, and transmits it to the next channel simulation subsystem of the sub-link.

[0073] In specific implementation, the secure exchange device is one of the secure transmission auxiliary devices, which is different from ordinary exchange devices. The secure exchange device is used to: receive a message signal and a corresponding dedicated link communication frame, and check whether they match. If they match, balance the total artificial channel impact applied to the signal by all the channel simulation subsystems on the sub-link according to the routing information, and transmit the signal and the updated dedicated link communication frame to the first channel simulation subsystem of the next sub-link through the network link and the dedicated link respectively; if they do not match, wait for a matching message signal or a matching dedicated link communication frame. If the waiting time exceeds a specified time limit, terminate the transmission of the message signal or the dedicated link communication frame.

[0074] The basic working process of the network time synchronization system (physical layer security architecture and system model) designed by the application is as follows: the original time synchronization message broadcast by the sending end is first modulated by a security coding modulator into a message signal carrying all information of the original message, routing information, secret information bit security transmission, and message source identity authentication function. Then the message signal enters the network, is transmitted to the security demodulator of each legal receiving end through the security transmission auxiliary devices such as the end channel simulation subsystem, the channel simulation subsystem, and the security exchange device according to the predetermined routing, and realizes the physical layer routing control and the artificial degradation of the transmission quality of the illegal message signal in the process. The security demodulator makes a security decision on the message signal, and if it is legal, the original time synchronization message is recovered and sent to the legal receiving end; if it is illegal, the message is discarded and the legal receiving end is informed.

[0075] In a second aspect, the embodiments of the application also provide a network time synchronization method, which adopts the network time synchronization system of any of the embodiments of the first aspect, and the method comprises the following steps:

[0076] The sending end sends an original time synchronization message.

[0077] The security coding modulator performs channel coding and modulation on the original time synchronization message to obtain a coded modulation signal.

[0078] The first end channel simulation subsystem extracts the routing information of the original time synchronization message transmitted to the receiving end from the coded modulation signal, generates a dedicated link communication frame, transmits the coded modulation signal to which the artificial channel influence has been applied to the next channel simulation subsystem through the network link according to the routing information, and transmits the dedicated link communication frame to the next channel simulation subsystem through the dedicated link.

[0079] The channel simulation subsystem makes a decision on the legality of the received coded modulation signal, applies the artificial channel influence to the coded modulation signal that passes the legality decision, transmits the coded modulation signal to which the artificial channel influence has been applied to the next channel simulation subsystem through the network link according to the routing information, and transmits the updated dedicated link communication frame to the next channel simulation subsystem through the dedicated link.

[0080] checking, by the security exchange device, whether the received coded modulation signal matches the private link communication frame, if yes, equalizing, by the first end channel emulation subsystem (only involving the first sub-link) and the sum of the artificial channel influence exerted by the channel emulation subsystem on the coded modulation signal, the sum of the artificial channel influence exerted by the channel emulation subsystem on the coded modulation signal according to the routing information, transmitting the equalized coded modulation signal to the first channel emulation subsystem of the next sub-link through the network link, and transmitting the updated private link communication frame to the first channel emulation subsystem of the next sub-link through the private link;

[0081] checking, by the second end channel emulation subsystem, whether the coded modulation signal transmitted by the channel emulation subsystem matches the private link communication frame, if yes, equalizing the sum of the artificial channel influence exerted by the channel emulation subsystem on the coded modulation signal according to the routing information, and sending the equalized coded modulation signal to the security demodulator and decoder;

[0082] demodulating, decoding and security judging, by the security demodulator and decoder, the arrived coded modulation signal;

[0083] sending the demodulated and decoded original time synchronization message, which passes the security judgment, to the receiving end, and discarding the demodulated and decoded original time synchronization message, which fails the security judgment, and informing the receiving end that an illegal message is received.

[0084] According to a specific implementation manner of the embodiment of the application, the method further comprises:

[0085] In the channel emulation subsystem, transmitting the coded modulation signal, which fails the legality judgment, to the exchange device at the end of the current sub-link through the network link and the private link respectively, and if the current sub-link is the last sub-link, transmitting the coded modulation signal to the second end channel emulation subsystem directly.

[0086] According to a specific implementation manner of the embodiment of the application, the method further comprises:

[0087] Within a first preset time limit, if the channel emulation subsystem only receives the private link communication frame, terminating the transmission of the private link communication frame; and if the channel emulation subsystem only receives the coded modulation signal, not exerting the artificial channel influence on the coded modulation signal and directly sending the coded modulation signal to the next channel emulation subsystem of the sub-link.

[0088] According to a specific implementation manner of the embodiment of the application, the method further comprises:

[0089] In the secure exchange device, if the received coded modulation signal does not match the special link communication frame, waiting for the matched coded modulation signal or the matched special link communication frame;

[0090] If the waiting exceeds a second preset time limit, terminating the transmission of the coded modulation signal or the special link communication frame.

[0091] The embodiment provided by the application provides a general secure architecture and system infrastructure model serving network time synchronization physical layer security policy and algorithm design, the model fully considers typical working modes of NTP / PTP and network transmission characteristics, adopts an overall idea of combination of coding, modulation and link transmission quality control, and realizes secure transmission of secret information bits in network time synchronization messages, physical layer identity authentication, physical layer routing control and other functions. The secure architecture and system infrastructure model are beneficial to system integration of physical layer security policy and algorithm, beneficial to design of a unified upper layer interface, realization of compatibility with existing security mechanisms, and further overall design of cross-layer security mechanisms.

[0092] The above merely describes specific embodiments of the application, but the protection scope of the application is not limited thereto, any person skilled in the art can easily think of changes or replacements within the technical range disclosed by the application, which should be covered in the protection scope of the application. Therefore, the protection scope of the application should be subject to the protection scope of the claims.

Claims

1. A network time synchronization system, characterized by, The system comprises a sending terminal and a plurality of receiving terminals connected with the sending terminal, each of the receiving terminals is provided with a physical link with the sending terminal, each of the physical links comprises a plurality of sub-links, the sending terminal is connected with a secure coding modulator, each of the receiving terminals is connected with a secure demodulation decoder, each of the secure coding modulators is provided with a secure transmission auxiliary device on the physical link with each of the secure demodulation decoders, the secure transmission auxiliary device comprises a first end channel simulation subsystem connected with the secure coding modulator, a second end channel simulation subsystem connected with the secure demodulation decoder, a plurality of channel simulation subsystems and a plurality of secure exchange devices between the first end channel simulation subsystem and the second end channel simulation subsystem, and a dedicated communication link between the secure transmission auxiliary devices; The secure coding modulator is used for channel coding and modulation of an original time synchronization message sent by the sending terminal to obtain a coded modulation signal; The first end channel simulation subsystem is used for extracting routing information of the original time synchronization message transmitted to the receiving terminal from the coded modulation signal to generate a dedicated link communication frame, transmitting the coded modulation signal with an artificial channel influence applied thereto to the next channel simulation subsystem through a network link according to the routing information, and transmitting the dedicated link communication frame to the next channel simulation subsystem through the dedicated link; The channel simulation subsystem is used for judging the legitimacy of the received coded modulation signal, applying the artificial channel influence to the coded modulation signal with the legitimate judgment passed, transmitting the coded modulation signal with the artificial channel influence applied thereto to the next channel simulation subsystem through the network link according to the routing information, and transmitting the updated dedicated link communication frame to the next channel simulation subsystem through the dedicated link; The secure exchange device is used for checking whether the received coded modulation signal matches the dedicated link communication frame, if yes, equalizing the sum of the artificial channel influences applied to the coded modulation signal by the first end channel simulation subsystem and the channel simulation subsystem on the sub-link according to the routing information, transmitting the equalized coded modulation signal to the first channel simulation subsystem of the next sub-link through the network link, and transmitting the updated dedicated link communication frame to the first channel simulation subsystem of the next sub-link through the dedicated link; The second end channel simulation subsystem is used for checking whether the coded modulation signal transmitted by the channel simulation subsystem matches the dedicated link communication frame, if yes, equalizing the sum of the artificial channel influences applied to the coded modulation signal by the channel simulation subsystem on the sub-link according to the routing information, and transmitting the equalized coded modulation signal to the secure demodulation decoder; The secure demodulation decoder is used for demodulation, decoding and security judgment of the received coded modulation signal and then transmitting the coded modulation signal to the receiving terminal.

2. The network time synchronization system of claim 1, wherein, The special link communication frame comprises in sequence an identification code of the sending end, an identification code of the receiving end and a plurality of subframes, each of the subframes corresponding to a sublink, the identification code of the sending end being arranged in a first field of the special link communication frame, and the identification code of the receiving end being arranged in a second field of the special link communication frame.

3. The network time synchronization system of claim 2, wherein, Each of the subframes comprises four fields, a first field of each of the subframes being used to carry a sublink identification code corresponding to the subframe, a second field of each of the subframes being used to carry a sending device identification code, the sending device being the security exchange device, the channel simulation subsystem, the first-end channel simulation subsystem, a third field of each of the subframes being used to carry a destination device identification code, the destination device being the security exchange device, the channel simulation subsystem, the second-end channel simulation subsystem, and a fourth field of each of the subframes being used to carry an identification code and a passing sequence of the first-end channel simulation subsystem, the channel simulation subsystem and the second-end channel simulation subsystem which the original time synchronization message needs to pass on the sublink.

4. The network time synchronization system of claim 1, wherein, The encoding mode of the security encoding modulator comprises Polar encoding, and the modulation mode of the security encoding modulator comprises OFDM-IM modulation.

5. The network time synchronization system of claim 1, wherein, The manner of applying the artificial channel influence comprises applying artificial noise and frequency selective fading to the signal.

6. The network time synchronization system of claim 1, wherein, The security criterion of the security decision is a bit error rate of a security test sequence, the security test sequence being a sequence added in the process of channel encoding and modulation of the original time synchronization message and known by both the sending end and the receiving end.

7. A network time synchronization method using the network time synchronization system according to any one of claims 1 to 6, characterized by, The method comprises: The sending end sends an original time synchronization message; The security encoding modulator is used to perform channel encoding and modulation on the original time synchronization message to obtain an encoded modulation signal; The first-end channel simulation subsystem is used to extract routing information of the original time synchronization message transmitted to the receiving end from the encoded modulation signal to generate a special link communication frame, transmit the encoded modulation signal to which the artificial channel influence has been applied to the next channel simulation subsystem through a network link according to the routing information, and transmit the special link communication frame to the next channel simulation subsystem through a special link. The channel simulation subsystem is used to make a decision on the legality of the received encoded modulation signal, apply the artificial channel influence to the encoded modulation signal which passes the decision on the legality, transmit the encoded modulation signal to which the artificial channel influence has been applied to the next channel simulation subsystem through the network link according to the routing information, and transmit the updated special link communication frame to the next channel simulation subsystem through the special link. checking, by the security exchange device, whether the received encoded modulated signal matches the private link communication frame, if yes, equalizing the sum of the artificial channel influence exerted on the encoded modulated signal by the first end channel emulation subsystem and the channel emulation subsystem on the sub-link according to the routing information, transmitting the equalized encoded modulated signal to the first channel emulation subsystem of the next sub-link through the network link, and transmitting the updated private link communication frame to the first channel emulation subsystem of the next sub-link through the private link; checking, by the second end channel emulation subsystem, whether the encoded modulated signal transmitted by the channel emulation subsystem matches the private link communication frame, if yes, equalizing the sum of the artificial channel influence exerted on the encoded modulated signal by the channel emulation subsystem on the sub-link according to the routing information, and sending the equalized encoded modulated signal to the security demodulator and decoder; demodulating, decoding and security judging, by the security demodulator and decoder, the received encoded modulated signal; sending the decoded and demodulated original time synchronization message, which passes the security judgment, to the receiving end, and discarding the decoded and demodulated original time synchronization message, which fails the security judgment, and informing the receiving end that an illegal message is received.

8. The network time synchronization method of claim 7, wherein, The method further comprises: in the channel emulation subsystem, transmitting the encoded modulated signal, which fails the legality judgment, to the exchange device at the end of the current sub-link through the network link and the updated private link communication frame through the private link respectively, and if the current sub-link is the last sub-link, transmitting the encoded modulated signal to the second end channel emulation subsystem directly.

9. The network time synchronization method of claim 7, wherein, The method further comprises: if the channel emulation subsystem only receives the private link communication frame within a first preset time limit, terminating the transmission of the private link communication frame, and if the channel emulation subsystem only receives the encoded modulated signal, not exerting the artificial channel influence on the encoded modulated signal and sending the encoded modulated signal to the next channel emulation subsystem of the sub-link directly.

10. The network time synchronization method of claim 7, wherein, The method further comprises: in the security exchange device, if the received encoded modulated signal does not match the private link communication frame, waiting for the encoded modulated signal or the private link communication frame that matches; if the waiting exceeds a second preset time limit, terminating the transmission of the encoded modulated signal or the private link communication frame. The method further comprises: in the security exchange device, if the received encoded modulated signal does not match the private link communication frame, waiting for the encoded modulated signal or the private link communication frame that matches; if the waiting exceeds a second preset time limit, terminating the transmission of the encoded modulated signal or the private link communication frame.

Citation Information

Patent Citations

  • Method and device for determining secure transmission route of network time synchronization message

    CN115883443A

  • Network Time Synchronization Message Transmission Method and Device Applied to Arbitrary Channel Environments

    CN115967463B

  • Method and apparatus for enabling flo device certification

    CN101444123A

  • Novel method for providing MBMS and carrying out network equipment synchronization in wireless communication

    CN104640194A