Clock synchronization protection method and device, electronic equipment and storage medium
By determining the stage status and protection level during the clock synchronization process, and using multi-level and multi-level dynamic security protection measures, the problem of poor clock synchronization stability in the existing technology is solved, and effective response to illegal traffic and link oscillations is achieved.
Patent Information
- Application Number
- CN202510191876.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-20
- Publication Date
- 2025-05-27
AI Technical Summary
The clock synchronization method in the prior art is difficult to cope with the impact of illegal traffic attacks and link oscillations on clock oscillations, resulting in poor clock synchronization stability.
By determining the stage status and corresponding protection levels of the clock synchronization process, the clock synchronization process is protected according to multi-level and multi-level dynamic security protection measures, and illegal traffic, burst traffic and link changes are identified and dealt with.
Effectively protect the stability of clock synchronization, prevent illegal traffic attacks and link oscillations from negative impacts on clock synchronization, and ensure the accuracy and reliability of clock synchronization.
Smart Images

Figure CN120050762A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the fields of network technology and security technology. Specifically, it relates to a method, device, electronic device, and storage medium for protecting clock synchronization. Background Technique
[0002] The clock synchronization method of the networking clock module mainly uses PTP (Precision Time Protocol) and SyncE (Synchronization Ethernet) in cooperation. Among them, frequency synchronization is the basis, and time synchronization is carried out on the basis of frequency synchronization to ensure nanosecond-level high-precision clock synchronization for the networking under frequency synchronization and phase synchronization.
[0003] However, in the actual deployment process, the clock synchronization methods in the related technologies are difficult to cope with the impacts of illegal traffic attacks and link oscillations on clock oscillations, and there are technical problems such as poor clock synchronization stability.
[0004] In view of the above problems, no effective solution has been proposed yet. Summary of the Invention
[0005] Embodiments of this application provide a method, device, electronic device, and storage medium for protecting clock synchronization, so as to at least solve the technical problem of poor clock synchronization stability caused by the fact that the clock synchronization methods in the related technologies are difficult to cope with the impacts of illegal traffic attacks and link oscillations on clock oscillations.
[0006] According to one aspect of the embodiments of this application, a method for protecting clock synchronization is provided, including: determining the stage state corresponding to the clock synchronization process, where the stage state is used to represent the link stage in which the clock synchronization process is located; determining the protection level corresponding to the stage state, and setting the clock synchronization process according to the protection level, where the protection level is used to represent the strictness of protecting clock synchronization; and performing clock synchronization protection on the clock synchronization process according to the protection strategy corresponding to the protection level.
[0007] Optionally, the method further includes: when the stage state represents that the clock synchronization process is in the clock synchronization stage, setting the protection level corresponding to the clock synchronization process to the first level. Wherein, when the protection level is set to the first level, it is necessary to verify the messages transmitted between clock devices according to the first verification parameter, and screen out the messages that fail the verification. The first verification parameter includes: domain information, port number information, and message type information.
[0008] Optionally, the message includes: a synchronization message, a delay request message, and a delay response message; the clock device includes: a first clock device as the master device and a second clock device as the slave device; in the clock synchronization phase, the first clock device is configured to send a synchronization message to the second clock device and record a first timestamp of sending the synchronization message; the second clock device is configured to receive the synchronization message and record a second timestamp of receiving the synchronization message; and send a delay request message to the first clock device and record a third timestamp of sending the delay request message; the first clock device is further configured to receive the delay request message and record a fourth timestamp of receiving the delay request message, and return a delay response message to the second clock device; the second clock device is further configured to, when receiving the delay response message, determine a clock deviation based on the first timestamp, the second timestamp, the third timestamp, and the fourth timestamp, and adjust its own clock according to the clock deviation to achieve clock synchronization.
[0009] Optionally, the method further includes: when the phase state indicates that the clock synchronization process is in the master-slave election phase, setting the protection level corresponding to the clock synchronization process to the second level, where the master-slave election phase is used to determine the master device and the slave device in the clock device, and when the protection level is set to the second level, it is necessary to verify the messages transmitted between the clock devices according to the second verification parameter and filter out the messages that fail the verification, and the second verification parameter includes: a clock identifier, and the message includes at least one of the following: an announcement message; and / or, when the phase state indicates that the clock synchronization process is in the pre-configuration phase, setting the protection level corresponding to the clock synchronization process to the third level, where when the protection level is set to the third level, all messages with the Ethernet type field being a preset value are allowed to be transmitted.
[0010] Optionally, the method further includes: monitoring the traffic load of the port during the clock synchronization process; when the protection level is set to the fourth level, adjusting the protection level by comparing the traffic load with a preset load threshold, where when the traffic load is less than the preset load threshold, updating the protection level from the fourth level to the second level, and when the traffic load is greater than the preset load threshold, updating the protection level from the fourth level to the first level.
[0011] Optionally, the method further includes: when the phase state indicates that the clock synchronization process is in the master-backup link switching phase, setting the protection level corresponding to the clock synchronization process to the fifth level, where the master-backup link switching phase is used to indicate that the user plans to switch the clock synchronization link from the master link to the backup link, and when the protection level is set to the fifth level, discarding all the messages being transmitted during the clock synchronization process; synchronizing the frequencies of the backup link and the master link, and after the frequency synchronization passes a preset duration, updating the protection level to the first level and performing time synchronization.
[0012] Optionally, the method further includes: recording the number of oscillations of the link by monitoring the status of the port participating in the clock synchronization process; when the number of oscillations exceeds a preset number threshold, setting the protection level corresponding to the clock synchronization process to the fifth level and maintaining it for a preset duration; after the preset duration, updating the protection level to the first level and re-performing clock synchronization.
[0013] According to another aspect of the embodiments of the present application, there is also provided a protection device for clock synchronization, including: a status determination module, configured to determine the stage status corresponding to the clock synchronization process, where the stage status is used to represent the link stage in which the clock synchronization process is located; a level update module, configured to determine the protection level corresponding to the stage status and set the clock synchronization process according to the protection level, where the protection level is used to represent the strictness of protecting the clock synchronization; a synchronization protection module, configured to protect the clock synchronization process according to the protection strategy corresponding to the protection level.
[0014] According to yet another aspect of the embodiments of the present application, there is also provided an electronic device, including: a memory and a processor, where the processor is configured to run a program stored in the memory, and when the program runs, it executes the protection method for clock synchronization.
[0015] According to still another aspect of the embodiments of the present application, there is also provided a non-volatile storage medium, where the non-volatile storage medium includes a stored computer program, and the device where the non-volatile storage medium is located executes the protection method for clock synchronization by running the computer program.
[0016] According to still another aspect of the embodiments of the present application, there is also provided a computer program product, including a computer program, and when the computer program is executed by a processor, it implements the steps of the protection method for clock synchronization.
[0017] In the embodiments of the present application, by determining the stage status corresponding to the clock synchronization process, where the stage status is used to represent the link stage in which the clock synchronization process is located; determining the protection level corresponding to the stage status and setting the clock synchronization process according to the protection level, where the protection level is used to represent the strictness of protecting the clock synchronization; and protecting the clock synchronization process according to the protection strategy corresponding to the protection level, through multi-level and multi-hierarchy dynamic security protection measures, illegal traffic, burst traffic, link changes and other conditions are identified, achieving the purpose of protecting the stability of clock synchronization, and further solving the technical problem of poor clock synchronization stability caused by the fact that the clock synchronization method in the related art is difficult to cope with the impact of illegal traffic attacks and link oscillations on clock oscillations. Description of the Drawings
[0018] The accompanying drawings described herein are used to provide a further understanding of the present application, and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application, and do not constitute an improper limitation of the present application. In the drawings:
[0019] Figure 1 is a schematic diagram provided according to an embodiment of the present application for characterizing that the clock synchronization protection scheme in the related art cannot dynamically respond to complex network traffic attacks;
[0020] Figure 2 is a schematic diagram provided according to an embodiment of the present application for characterizing that the clock synchronization protection scheme in the related art cannot dynamically respond to changes in the synchronization link;
[0021] Figure 3 is a hardware structure block diagram of a computer terminal (or electronic device) for implementing a method for protecting clock synchronization provided according to an embodiment of the present application;
[0022] Figure 4 is a schematic diagram of a method flow for protecting clock synchronization provided according to an embodiment of the present application;
[0023] Figure 5 is a schematic diagram of a multi-level and multi-grade dynamic protection division and anti-attack example provided according to an embodiment of the present application;
[0024] Figure 6 is a schematic diagram of a protection example for clock switching related scenarios provided according to an embodiment of the present application;
[0025] Figure 7 is a schematic diagram of the structure of a protection device for clock synchronization provided according to an embodiment of the present application. Detailed implementation manners
[0026] In order to enable those skilled in the art to better understand the solution of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.
[0027] It should be noted that the terms "first", "second", etc. in the description, claims and the above-mentioned drawings of this application are used to distinguish similar objects, and do not necessarily have to be used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so that the embodiments of this application described here can be implemented in an order other than those illustrated or described here. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device comprising a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0028] To facilitate better understanding of the embodiments of this application by those skilled in the art, some technical terms or glossaries related to the embodiments of this application are explained as follows:
[0029] PTP (Precision Time Protocol): By establishing a master-slave relationship, it realizes frequency synchronization and time synchronization between network communication devices.
[0030] SyncE (Synchronization Ethernet): A technology that uses the Ethernet link code stream to recover the clock.
[0031] ESMC (Ethernet Synchronization Messaging Channel): Used to transmit the clock quality level.
[0032] In actual clock network applications, illegal traffic, burst traffic, etc. will affect the synchronization security of the clock at all levels. In addition, when the clock link changes, such as in the case of sending link oscillation, link switching, etc., if not protected, it will also affect the stability of the clock.
[0033] Among them, illegal traffic attack means that the attacker consumes the computing and bandwidth resources of the clock synchronization device by sending a large number of invalid requests, making the clock synchronization protocol unable to process legitimate time synchronization requests normally, thus affecting the stability and accuracy of the clock; in addition, illegal traffic attack can also cause the clock server or client to receive incorrect time information by sending a large number of forged time synchronization requests or responses, resulting in clock offset, and this offset will gradually accumulate, ultimately leading to the failure of time synchronization in the entire network.
[0034] Link oscillation refers to the rapid change of the frequency of the clock signal in a short period of time. The resulting frequency fluctuation will cause the instability of the clock signal, affect the locking of the clock frequency and cause more serious synchronization problems. In addition, clock oscillation will cause phase error, that is, the phase of the clock signal changes irregularly in a short period of time. Phase error will further aggravate clock offset and affect the accuracy of time synchronization.
[0035] Specifically, in the related art, protection against illegal network traffic attacks is generally performed by pre-configuring and issuing hardware entries for preventing illegal network attack traffic, such as Figure 1 As shown, however, the protection provided by pre-configuration cannot provide effective protection, because illegal traffic attacks are not static, and it is impossible to dynamically identify illegal traffic for dynamic protection. In addition, since the protection strategies in related technologies are relatively simple, most of them are to verify a single field in the PTP message: clockid. If an attacker constructs a legitimate clockid message to bypass the protection, it will cause a serious attack on the networking equipment.
[0036] On the other hand, the related technologies cannot effectively handle link oscillations and cannot cope with frequent link oscillations. At the same time, for link switching, the related technologies detect link changes and then make corresponding switches, such as Figure 2 As shown in the figure, in the scenario where the clock link changes, after the link switching occurs, the clock frequency and time synchronization are immediately switched to another link. This switching method will also cause the jitter of the clock after the link switching to be too large, which cannot meet the stability requirements.
[0037] In order to solve the above problems, relevant solutions are provided in the embodiments of the present application. Through multi-level and multi-level dynamic security protection measures, illegal network traffic attacks and frequent changes in clock synchronization links are identified, and corresponding protection strategies are implemented in a targeted manner, ultimately protecting the stability of clock synchronization. The following is a detailed description.
[0038] According to an embodiment of the present application, a method embodiment of clock synchronization protection is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0039] The method embodiments provided in the embodiments of the present application can be executed in a mobile terminal, a computer terminal or a similar computing device. Figure 3 The hardware structure block diagram of a computer terminal (or electronic device) for implementing a clock synchronization protection method is shown. Figure 3As shown, the computer terminal 30 (or electronic device) may include one or more processors 302 (illustrated as 302a, 302b, ……, 302n in the figure) (the processor 302 may include, but is not limited to, a processing device such as a microprocessor MCU or a programmable logic device FPGA), a memory 304 for storing data, and a transmission device 306 for communication functions. In addition, it may further include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of the BUS bus), a network interface, a power supply, and / or a camera. Those of ordinary skill in the art can understand that Figure 3 the structure shown is only schematic and does not limit the structure of the above-mentioned electronic device. For example, the computer terminal 30 may further include more or fewer components than those Figure 3 shown in, or have a different configuration from that Figure 3 shown.
[0040] It should be noted that the above one or more processors 302 and / or other data processing circuits are generally referred to as "data processing circuits" herein. The data processing circuit may be embodied in software, hardware, firmware, or any combination thereof, in whole or in part. In addition, the data processing circuit may be a single independent processing module, or be incorporated in whole or in part into any one of the other elements in the computer terminal 30 (or electronic device). As involved in the embodiments of the present application, the data processing circuit is a processor control (such as the selection of a variable resistor terminal path connected to an interface).
[0041] The memory 304 may be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the clock synchronization protection method in the embodiments of the present application. The processor 302 executes various functional applications and data processing by running the software programs and modules stored in the memory 304, that is, implements the above-mentioned clock synchronization protection method. The memory 304 may include a high-speed random access memory, and may further include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some instances, the memory 304 may further include a memory remotely set relative to the processor 302, and these remote memories may be connected to the computer terminal 30 through a network. Examples of the above network include, but are not limited to, the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.
[0042] The transmission device 306 is used to receive or send data via a network. Specific examples of the above-mentioned network may include a wireless network provided by a communication provider of the computer terminal 30. In one example, the transmission device 306 includes a network adapter (Network Interface Controller, NIC), which can be connected to other network devices through a base station so as to communicate with the Internet. In one example, the transmission device 306 can be a Radio Frequency (RF) module, which is used to communicate with the Internet wirelessly.
[0043] The display can be, for example, a touch-screen liquid crystal display (LCD), which enables the user to interact with the user interface of the computer terminal 30 (or electronic device).
[0044] Under the above operating environment, an embodiment of the present application provides a method for protecting clock synchronization. Figure 4 It is a schematic diagram of a method flow for protecting clock synchronization provided by an embodiment of the present application, as Figure 4 shown. The method includes the following steps:
[0045] Step S402, determining the stage state corresponding to the clock synchronization process, where the stage state is used to represent the link stage in which the clock synchronization process is located;
[0046] Step S404, determining the protection level corresponding to the stage state, and setting the clock synchronization process according to the protection level, where the protection level is used to represent the strictness of protecting the clock synchronization;
[0047] Step S406, protecting the clock synchronization of the clock synchronization process according to the protection strategy corresponding to the protection level. Through the above steps, through multi-level and multi-tier dynamic security protection measures, illegal traffic, burst traffic, link changes and other conditions are identified, and the purpose of protecting the stability of clock synchronization is achieved. Furthermore, the technical problem of poor clock synchronization stability caused by the difficulty of the clock synchronization method in the related art in coping with the impact of illegal traffic attacks and link oscillations on clock oscillations is solved.
[0048] The following further introduces the method for protecting clock synchronization in steps S402 to S406 of the embodiment of the present application.
[0049] In the embodiment of the present application, a multi-level classification mechanism is designed to classify messages and set different protection levels, so as to judge the importance and security according to different fields of the messages. Specifically, in this embodiment, the protection levels include but are not limited to:
[0050] 1) First level (STRICT): At this level, the message needs to be verified according to the port_id (port number), domain, and message_type (message type) fields. This is the strictest level for messages. Only messages that meet these strict conditions will be used for clock synchronization to ensure the accuracy and reliability of clock synchronization.
[0051] 2) Second level (MID): At this level, the message needs to be verified according to the clock_id (clock identifier) field. Such messages have a strong correlation with clock synchronization but are not the strictest requirements. They may be messages from some known and relatively reliable clock sources.
[0052] 3) Third level (LOOSE): At this level, the message is only verified according to the Ethernet_type (Ethernet type) field. The requirements for messages in the phase state corresponding to this level are relatively low. They may be some basic and common network messages, which have a relatively small direct impact on clock synchronization.
[0053] 4) Fourth level (FLEX): At this level, it is possible to dynamically learn according to the traffic and update the current protection level to the second level MID or the first level STRICT. This is an adaptive mechanism that can dynamically classify messages into the medium or strict level according to the actual traffic situation, so as to flexibly respond to different network environments and traffic characteristics.
[0054] 5) Fifth level (CRITICAL): At this level, no fields are used to judge or verify the message, but all messages are directly discarded without clock synchronization to prevent some unknown and potentially dangerous messages from interfering with or damaging clock synchronization.
[0055] The embodiments of the present application can adjust the protection level and strategy corresponding to clock synchronization in real time according to the actual situation during the clock synchronization process (such as different phase states). Figure 5 It is a schematic diagram of a multi-level and multi-grade dynamic protection division and anti-attack example provided by the embodiments of the present application, as Figure 5 shown below for specific introduction.
[0056] First, in the pre-configuration stage of clock synchronization, the embodiments of the present application default the protection level in this stage state to the third level LOOSE, as follows.
[0057] In some embodiments of the present application, the method further includes the following steps: when the phase state indicates that the clock synchronization process is in the pre-configuration phase, set the protection level corresponding to the clock synchronization process to the third level, wherein when the protection level is set to the third level, all packets with the Ethernet type field being a preset value are allowed to be transmitted.
[0058] Specifically, the pre-configuration phase is the initial phase of the clock synchronization process, and the clock synchronization device is in an initial and not fully activated state. In this phase, some basic configurations and preparations need to be carried out to enter the subsequent master-slave election and time synchronization phases. Therefore, in this phase, the protection policy is relatively loose, the inspection and filtering of packets are relatively less, and more packets are allowed to pass. For example, all packets with the Ethernet type field being a preset value (such as 0x8847) can be allowed to be transmitted.
[0059] This loose mode helps to ensure that in the initial phase, various necessary packets can be received, including those that may be used for subsequent master-slave election and time synchronization, thus providing the necessary data support for the normal operation of the subsequent phases.
[0060] After the clock synchronization process enters the master-slave election phase (i.e., when the phase state indicates that the clock synchronization process is in the master-slave election phase), update the protection level to the second level MID, specifically as follows.
[0061] In some embodiments of the present application, the method further includes the following steps: when the phase state indicates that the clock synchronization process is in the master-slave election phase, set the protection level corresponding to the clock synchronization process to the second level, wherein the master-slave election phase is used to determine the master device and the slave device among the clock devices. When the protection level is set to the second level, it is necessary to verify the packets transmitted between the clock devices according to the second verification parameter, and filter out the packets that fail the verification. The second verification parameter includes: clock identifier, and the packet includes at least one of the following: announcement packet;
[0062] Specifically, in this phase, the master and slave clock devices conduct master-slave election by mutually sending announce packets (announcement packets) to determine the master device (master) and the slave device (slave). In this embodiment, the protection level corresponding to this phase state is set to the second level MID, and mainly verifies the main parameter clock id (clock identifier, which is a unique identifier used by the device to identify its own clock) that affects the election, ensuring that only the packets that conform to the clock id verification rule participate in the election, avoiding interference from illegal devices in the election process, and thus ensuring the reliability of the election process.
[0063] After the clock synchronization process enters the clock synchronization phase (i.e., when the phase state indicates that the clock synchronization process is in the clock synchronization phase), update the protection level to the first level STRICT, as follows.
[0064] In some embodiments of the present application, the method further includes: when the phase state indicates that the clock synchronization process is in the clock synchronization phase, setting the protection level corresponding to the clock synchronization process to the first level. Wherein, when the protection level is set to the first level, it is necessary to verify the messages transmitted between clock devices according to the first verification parameters, and filter out the messages that fail the verification. The first verification parameters include: domain information, port number information, and message type information.
[0065] Specifically, in this phase, the master device and the slave device perform time synchronization operations through a series of message interactions (synchronization message sync, delay request message delay-req, delay response message delay-resp). The specific message interaction process is as follows.
[0066] In some embodiments of the present application, the messages include: synchronization messages, delay request messages, and delay response messages; the clock devices include: a first clock device as the master device and a second clock device as the slave device; in the clock synchronization phase, the first clock device is used to send a synchronization message to the second clock device and record the first timestamp of sending the synchronization message; the second clock device is used to receive the synchronization message and record the second timestamp of receiving the synchronization message; and send a delay request message to the first clock device and record the third timestamp of sending the delay request message; the first clock device is further used to receive the delay request message and record the fourth timestamp of receiving the delay request message, and return a delay response message to the second clock device; the second clock device is further used to determine the clock deviation according to the first timestamp, the second timestamp, the third timestamp, and the fourth timestamp when receiving the delay response message, and adjust its own clock according to the clock deviation to achieve clock synchronization.
[0067] Specifically, the time synchronization phase is the core part of the clock synchronization process. Its main goal is to ensure precise time synchronization between the master device and the slave device. The specific process of the time synchronization phase is as follows: First, the master device (Device A) sends a sync message (synchronization message), which carries a first timestamp T1. This first timestamp T1 represents the local time of Device A when it sends the sync message. The slave device (Device B) receives the sync message and records the second timestamp T2 when it receives the message. This second timestamp T2 represents the local time of Device B when it receives the sync message. Then, Device B (slave) sends a delay-req message (delay request message) and records the third timestamp T3 when it sends the delay-req message. This third timestamp represents the local timestamp T3 of Device B when it sends the delay-req message. Device A (master) receives the delay-req message sent by Device B, records the received fourth timestamp T4, and sends a delay-resp message (delay response message) to Device B. This fourth timestamp T4 represents the local time of Device A when it receives the delay-req message. After receiving the delay-resp message, Device B (slave) calculates its own clock deviation based on these timestamps T1, T2, T3, and T4, and adjusts its own clock accordingly to achieve time synchronization.
[0068] In this embodiment, the protection level corresponding to the state of this phase is set to the first level STRICT. During the entire time synchronization phase, the integrity and accuracy of the messages are strictly monitored to ensure that only the messages that fully meet the requirements are used for time synchronization, thereby ensuring the reliability of the synchronization result. Specifically, the fields that need to be verified include the domain, port_id, and message_type that affect time synchronization. Among them, the domain is used to identify different clock domains to ensure that the synchronization operation is carried out within the same clock domain; the port_id is used to identify the ports of the device to ensure that the message comes from the correct port; the message_type is used to identify the type of the message to ensure that the format and content of the message meet the requirements.
[0069] After the stable synchronization phase is carried out through the clock synchronization phase, the protection level can be set to the fourth level FLEX. Under the fourth level, the port traffic load can be monitored through traffic awareness, and the protection level can be dynamically adjusted according to the traffic conditions. The specific steps are as follows.
[0070] In some embodiments of the present application, the method further includes the following steps: monitoring the traffic load of the port during the clock synchronization process; when the protection level is set to the fourth level, adjusting the protection level by comparing the traffic load with a preset load threshold, wherein when the traffic load is less than the preset load threshold, updating the protection level from the fourth level to the second level, and when the traffic load is greater than the preset load threshold, updating the protection level from the fourth level to the first level.
[0071] Specifically, after the clock synchronization is stable, the protection level can be set to the fourth level FLEX. In this level, the traffic load of all ports participating in the master-slave election and clock synchronization will be continuously monitored, and the protection level will be flexibly updated according to the traffic load to effectively cope with traffic attacks and protection. For example, if the port traffic load is less than 50%, the protection level will be updated from the fourth level FLEX to the second level MID, that is, in the case of small traffic, the verification requirements for packets can be appropriately relaxed to improve the synchronization efficiency; if the traffic load is greater than 50%, the protection level will be updated from the fourth level FLEX to the first level STRICT, that is, when the traffic is large, in order to ensure the accuracy and security of synchronization, packets need to be strictly verified. By flexibly adjusting the FLEX mode, traffic attacks and protection can be effectively coped with, and the stability of the clock synchronization process can be ensured.
[0072] The embodiments of the present application gradually realize the stability and security of clock synchronization through four stages: pre-configuration, master-slave election, time synchronization, and synchronization stability (traffic monitoring) during the entire clock synchronization process. The protection level is flexibly adjusted according to the actual situation in different stages to ensure that clock synchronization can proceed normally and stably in a complex network environment and traffic changes.
[0073] On the other hand, the embodiments of the present application can also monitor the link change situation in real time (such as master-backup link switching and link frequent oscillation), and make corresponding protection, wherein examples of clock synchronization protection for the master-backup link switching and link frequent oscillation scenarios are Figure 6 as shown below, and specific introduction will be made.
[0074] Master-backup link switching refers to the process of switching from the primary link to the backup link. The processing process in the master-backup link switching scenario is as follows.
[0075] In some embodiments of the present application, the method further includes the following steps: when the phase state characterizing that the clock synchronization process is in the primary / backup link switching phase, set the protection level corresponding to the clock synchronization process to the fifth level, where the primary / backup link switching phase is used to indicate that the user plans to switch the clock synchronization link from the primary link to the backup link. When the protection level is set to the fifth level, discard all the packets being transmitted during the clock synchronization process; synchronize the frequency of the backup link with the primary link, and after the frequency synchronization has passed a preset duration, update the protection level to the first level and perform time synchronization.
[0076] Specifically, assume that the current clock synchronization system is running stably and the protection level is the second level MID. If the user expects to switch from the primary link to the backup link at this time, update the protection level to the fifth level CRITICAL. At the fifth level, all packets do not participate in synchronization to ensure the security of the switching process. First, perform frequency synchronization to ensure that the clock frequency of the backup link is the same as that of the primary link. After a preset duration (for example, five minutes), and the protection level is switched to the first level STRICT, start performing time synchronization to ensure that the clocks of the backup link and the primary link are exactly the same. Finally, under the condition that the clock synchronization system is running stably, complete the successful switching from the primary link to the backup link.
[0077] Frequent link oscillation means that the link state changes frequently within a short period of time, which may lead to a decrease in clock synchronization accuracy or synchronization failure. The processing process in the scenario of frequent link oscillation is as follows.
[0078] In some embodiments of the present application, the method further includes the following steps: by monitoring the status of the ports participating in the clock synchronization process, record the number of oscillations of the link; when the number of oscillations exceeds the preset number threshold, set the protection level corresponding to the clock synchronization process to the fifth level and maintain it for a preset duration; after the preset duration has passed, update the protection level to the first level and re-perform clock synchronization.
[0079] Specifically, by continuously monitoring the status of the clock synchronization protocol and the synchronization accuracy, ensure that problems such as link oscillation can be detected in a timely manner, including but not limited to: checking whether the protocol is running normally, whether there are errors or abnormalities, and measuring whether the synchronization accuracy meets the requirements and whether there are deviations, etc.; in addition, it is also necessary to monitor the status of the ports participating in the clock synchronization, record the frequency of link oscillation, count the number of oscillations of the link, and determine whether the preset number threshold is reached.
[0080] If the number of oscillations exceeds the preset number threshold, update the protection level to the fifth level CRITICAL. At the same time, record the status of the closed port as the alarm mode, and set the port not to participate in clock synchronization within the preset duration (e.g., five minutes), aiming to prevent it from participating in synchronization and further affecting the synchronization accuracy. After the preset duration, restore the port status to the trust mode, update the protection level to the first level STRICT, and perform clock synchronization again.
[0081] Through the above processing flow, the clock synchronization system can ensure the stability and reliability of synchronization in the case of master-slave link switching and frequent link oscillations.
[0082] This application designs a dynamic multi-level and multi-grade protection scheme, establishes a complex security mechanism according to the stage state of protocol synchronization, can effectively resist the attack of illegal traffic, and then protects the stable operation of the clock protocol and clock devices. At the same time, by monitoring the link status and establishing a fault tolerance mechanism for link oscillations, mark the port as the alarm mode during oscillations and do not perform clock synchronization, so as to ensure the stable operation of the network clock synchronization.
[0083] According to the embodiments of the present application, an embodiment of a protection device for clock synchronization is also provided. Figure 7 It is a schematic structural diagram of a protection device for clock synchronization provided according to the embodiments of the present application. As Figure 7 shown, the device includes:
[0084] A status determination module 70, configured to determine the stage state corresponding to the clock synchronization process, where the stage state is used to represent the link stage in which the clock synchronization process is located;
[0085] A level update module 72, configured to determine the protection level corresponding to the stage state and set the clock synchronization process according to the protection level, where the protection level is used to represent the strictness of protecting the clock synchronization;
[0086] A synchronization protection module 74, configured to perform clock synchronization protection on the clock synchronization process according to the protection strategy corresponding to the protection level.
[0087] Optionally, the protection device for clock synchronization is used to: when the stage state represents that the clock synchronization process is in the clock synchronization stage, set the protection level corresponding to the clock synchronization process to the first level. Among them, when the protection level is set to the first level, it is necessary to verify the messages transmitted between clock devices according to the first verification parameter, and screen out the messages that fail the verification. The first verification parameter includes: domain information, port number information, and message type information.
[0088] Optionally, the message includes: a synchronization message, a delay request message, and a delay response message; the clock device includes: a first clock device serving as the master device and a second clock device serving as the slave device; in the clock synchronization phase, the first clock device is configured to send a synchronization message to the second clock device and record a first timestamp when sending the synchronization message; the second clock device is configured to receive the synchronization message and record a second timestamp when receiving the synchronization message; and send a delay request message to the first clock device and record a third timestamp when sending the delay request message; the first clock device is further configured to receive the delay request message and record a fourth timestamp when receiving the delay request message, and return a delay response message to the second clock device; the second clock device is further configured to, when receiving the delay response message, determine a clock deviation based on the first timestamp, the second timestamp, the third timestamp, and the fourth timestamp, and adjust its own clock according to the clock deviation to achieve clock synchronization.
[0089] Optionally, the protection device for clock synchronization is further configured to: when the phase state indicates that the clock synchronization process is in the master-slave election phase, set the protection level corresponding to the clock synchronization process to the second level, where the master-slave election phase is used to determine the master device and the slave device in the clock device. When the protection level is set to the second level, it is necessary to verify the messages transmitted between the clock devices according to the second verification parameter and filter out the messages that fail the verification. The second verification parameter includes: a clock identifier, and the message includes at least one of the following: an announcement message; and / or, when the phase state indicates that the clock synchronization process is in the pre-configuration phase, set the protection level corresponding to the clock synchronization process to the third level, where when the protection level is set to the third level, all messages with the Ethernet type field being a preset value are allowed to be transmitted.
[0090] Optionally, the protection device for clock synchronization is further configured to: monitor the traffic load of the port during the clock synchronization process; when the protection level is set to the fourth level, adjust the protection level by comparing the traffic load with a preset load threshold, where when the traffic load is less than the preset load threshold, update the protection level from the fourth level to the second level, and when the traffic load is greater than the preset load threshold, update the protection level from the fourth level to the first level.
[0091] Optionally, the protection device for clock synchronization is further configured to: when the phase state indicates that the clock synchronization process is in the primary / backup link switching phase, set the protection level corresponding to the clock synchronization process to the fifth level, where the primary / backup link switching phase is used to indicate that the user plans to switch the clock synchronization link from the primary link to the backup link. When the protection level is set to the fifth level, discard all the packets being transmitted during the clock synchronization process; synchronize the frequency of the backup link with that of the primary link, and after the frequency synchronization has passed a preset duration, update the protection level to the first level and perform time synchronization.
[0092] Optionally, the protection device for clock synchronization is further configured to: by monitoring the status of the ports participating in the clock synchronization process, record the number of oscillations of the link; when the number of oscillations exceeds a preset number threshold, set the protection level corresponding to the clock synchronization process to the fifth level and maintain it for a preset duration; after the preset duration has passed, update the protection level to the first level and re-perform clock synchronization.
[0093] It should be noted that each module in the above protection device for clock synchronization can be a program module (for example, a set of program instructions for implementing a specific function), or a hardware module. For the latter, it can be presented in the following forms, but not limited to this: the manifestation form of each of the above modules is a processor, or the functions of each of the above modules are implemented by a processor.
[0094] It should be noted that the protection device for clock synchronization provided in this embodiment can be used to execute Figure 4 the protection method for clock synchronization shown, so the relevant explanations of the above protection method for clock synchronization also apply to the embodiments of the present application and will not be elaborated here.
[0095] The embodiments of the present application further provide a non-volatile storage medium, which includes a stored computer program. The device where the non-volatile storage medium is located executes the following protection method for clock synchronization by running the computer program: determine the phase state corresponding to the clock synchronization process, where the phase state is used to indicate the link stage in which the clock synchronization process is located; determine the protection level corresponding to the phase state, and set the clock synchronization process according to the protection level, where the protection level is used to indicate the strictness of protecting the clock synchronization; perform protection for the clock synchronization process according to the protection strategy corresponding to the protection level.
[0096] The embodiments of the present application further provide a computer program product, including a computer program which, when executed by a processor, implements the steps of the clock synchronization protection method described in the embodiments of the present application: determining the stage state corresponding to the clock synchronization process, where the stage state is used to represent the link stage in which the clock synchronization process is located; determining the protection level corresponding to the stage state, and setting the clock synchronization process according to the protection level, where the protection level is used to represent the strictness of protecting the clock synchronization; and performing clock synchronization protection on the clock synchronization process according to the protection strategy corresponding to the protection level.
[0097] The serial numbers of the embodiments of the present application above are only for description and do not represent the advantages and disadvantages of the embodiments.
[0098] In the above embodiments of the present application, the descriptions of the various embodiments have their own emphases. For the parts not detailed in a certain embodiment, reference may be made to the relevant descriptions of other embodiments.
[0099] In several embodiments provided by the present application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only illustrative. For example, the division of the units can be a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of the units or modules can be in electrical or other forms.
[0100] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0101] In addition, the functional units in the various embodiments of the present application can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated units can be implemented in the form of hardware or in the form of software functional units.
[0102] When the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes: various media that can store program codes, such as USB flash drives, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), mobile hard disks, magnetic disks, or optical discs.
[0103] The above are only the preferred embodiments of this application. It should be noted that for those of ordinary skill in the art of this technology, without departing from the principle of this application, several improvements and refinements can still be made, and these improvements and refinements should also be regarded as the protection scope of this application.
Claims
1. A clock synchronization protection method, characterized in that: include: Determine a phase state corresponding to a clock synchronization process, wherein the phase state is used to characterize a link phase of the clock synchronization process; Determine a protection level corresponding to the stage state, and set the clock synchronization process according to the protection level, wherein the protection level is used to characterize the strictness of protecting the clock synchronization; The clock synchronization process is protected by the protection strategy corresponding to the protection level.
2. The clock synchronization protection method according to claim 1, characterized in that: The method further comprises: When the stage status represents that the clock synchronization process is in the clock synchronization stage, the protection level corresponding to the clock synchronization process is set to the first level, wherein, when the protection level is set to the first level, it is necessary to verify the messages transmitted between the clock devices according to the first verification parameter, and filter out the messages that fail the verification, and the first verification parameter includes: domain information, port number information, and message type information.
3. The clock synchronization protection method according to claim 2, characterized in that: The message includes: a synchronization message, a delay request message, and a delay response message; the clock device includes: a first clock device as a master device and a second clock device as a slave device; in the clock synchronization stage, The first clock device is used to send the synchronization message to the second clock device, and record a first timestamp of sending the synchronization message; The second clock device is used to receive the synchronization message and record a second timestamp of receiving the synchronization message; and send the delay request message to the first clock device and record a third timestamp of sending the delay request message; The first clock device is further used to receive the delay request message, record a fourth timestamp of receiving the delay request message, and return the delay response message to the second clock device; The second clock device is also used to determine the clock deviation based on the first timestamp, the second timestamp, the third timestamp, and the fourth timestamp when receiving the delayed response message, and adjust its own clock based on the clock deviation to achieve clock synchronization.
4. The clock synchronization protection method according to claim 2, characterized in that: The method further comprises: In the case where the stage state represents that the clock synchronization process is in the master-slave election stage, the protection level corresponding to the clock synchronization process is set to the second level, wherein the master-slave election stage is used to determine the master device and the slave device in the clock device, and in the case where the protection level is set to the second level, it is necessary to verify the messages transmitted between the clock devices according to the second verification parameter, and filter out the messages that fail the verification, wherein the second verification parameter includes: a clock identifier, and the message includes at least one of the following: a declaration message; and / or, When the stage status represents that the clock synchronization process is in the preconfiguration stage, the protection level corresponding to the clock synchronization process is set to the third level, wherein when the protection level is set to the third level, all messages with Ethernet type fields as preset values are allowed to be transmitted.
5. The clock synchronization protection method according to claim 4, characterized in that: The method further comprises: Monitoring the traffic load of the port during the clock synchronization process; When the protection level is set to the fourth level, the protection level is adjusted by comparing the size relationship between the traffic load and the preset load threshold, wherein, when the traffic load is less than the preset load threshold, the protection level is updated from the fourth level to the second level, and when the traffic load is greater than the preset load threshold, the protection level is updated from the fourth level to the first level.
6. The clock synchronization protection method according to claim 1, characterized in that: The method further comprises: In the case where the stage state indicates that the clock synchronization process is in the primary-backup link switching stage, the protection level corresponding to the clock synchronization process is set to the fifth level, wherein the primary-backup link switching stage is used to indicate that the user plans to switch the clock synchronization link from the primary link to the backup link, and in the case where the protection level is set to the fifth level, all messages being transmitted in the clock synchronization process are discarded; The backup link is frequency synchronized with the main link, and after the frequency synchronization has been performed for a preset time, the protection level is updated to the first level, and time synchronization is performed.
7. The clock synchronization protection method according to claim 6, characterized in that: The method further comprises: By monitoring the status of the ports involved in the clock synchronization process, the number of times the link oscillates is recorded; When the number of oscillations exceeds a preset number threshold, the protection level corresponding to the clock synchronization process is set to the fifth level and maintained for the preset duration; After the preset time period has passed, the protection level is updated to the first level, and clock synchronization is performed again.
8. A clock synchronization protection device, characterized in that: include: A state determination module, used to determine the phase state corresponding to the clock synchronization process, wherein the phase state is used to characterize the link phase of the clock synchronization process; A level update module, used to determine the protection level corresponding to the stage state, and set the clock synchronization process according to the protection level, wherein the protection level is used to characterize the strictness of protecting the clock synchronization; The synchronization protection module is used to perform clock synchronization protection on the clock synchronization process according to the protection strategy corresponding to the protection level.
9. An electronic device, characterized in that: include: A memory and a processor, wherein the processor is used to run a program stored in the memory, wherein the clock synchronization protection method described in any one of claims 1 to 7 is executed when the program is run.
10. A non-volatile storage medium, characterized in that: The non-volatile storage medium includes a stored computer program, wherein the device where the non-volatile storage medium is located executes the clock synchronization protection method according to any one of claims 1 to 7 by running the computer program.
11. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the clock synchronization protection method described in any one of claims 1 to 7 are implemented.
Citation Information
Cited By
Clock source screening method and equipment based on PTP (Precision Time Protocol) message and storage medium
CN121077714A