A trusted time source device, and implementation method and application thereof

By integrating a trusted time source device with multiple identification and encryption modules, the problems of unreliable signals and easy counterfeiting of traditional time source devices are solved, trusted transmission and monitoring of full-link time information are achieved, and the security and stability of time services in key areas are ensured.

CN120639508BActive Publication Date: 2025-10-10SICHUAN TAIFU GROUND BEIDOU TECH CO LTD

Patent Information

Application Number
CN202511101133.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-08-07
Publication Date
2025-10-10
Estimated Expiration
2045-08-07

AI Technical Summary

Technical Problem

Traditional time source devices have problems such as the lack of authenticity verification of time signals, easy misuse of device identities, lack of time output monitoring mechanism, easy tampering of plain text output of time signals, and unreliability caused by a single signal source, which affects the security and reliability of key areas.

Method used

By integrating satellite signal identification modules, optical fiber signal identification modules, device identity identification modules, fault monitoring and service suspension modules, and time information encryption modules, combined with the network management system, full-link trusted identification, encrypted transmission, and fault monitoring of time signals can be achieved, and satellite and ground-based signal sources can be dynamically switched to ensure the security and reliability of time information.

Benefits of technology

It realizes the authenticity of time signals, the uniqueness of device identities, the security of transmission processes and the reliability of systems, avoids time tampering and device counterfeiting, ensures the credibility and stability of time services in key areas, and improves the security and reliability of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120639508B_ABST
    Figure CN120639508B_ABST
Patent Text Reader

Abstract

The application belongs to the technical field of trusted time, and specifically discloses a trusted time source device, an implementation method and application thereof. The trusted time source device comprises a network management system and a time source device integrated with satellite signal identification, optical fiber signal identification, device identity identification, fault monitoring and service suspension, time information encryption, time ground-sky mutual backup module. Through multi-module cooperation and network management system whole-process management and control, the time signal authenticity identification, device identity authentication, encrypted transmission, fault monitoring and ground-sky mutual backup switching are realized. The implementation method of the trusted time source comprises time signal identification, identity authentication solidification and other steps. The trusted time source device provided by the application is applied to the fields of data right, finance, power, block chain and the like, solves the five defects of no authenticity identification of traditional time source signal, easy device counterfeiting and the like, improves the credibility and stability of time service, and has important technical value and wide application prospect.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of trusted time technology, and in particular relates to a trusted time source device and an implementation method and application thereof. Background Art

[0002] In today's rapidly evolving information technology landscape, the value of time, as one of the three key elements of data, is becoming increasingly crucial across various fields. From the high-speed data transmission of 5G communications and the precise analysis of big data processing, to the real-time decision-making of autonomous driving technology and the efficient operation of the low-altitude economy, to the construction of trusted data spaces and the precise management of data ownership, the trustworthiness of time is paramount throughout. The rapid development of these fields relies heavily on secure and reliable time information. Without trustworthy time, the credibility of the data is also questioned.

[0003] As a globally recognized technology that cannot be tampered with, the core of timestamp technology lies in the tamper-proof nature of the timestamp itself. However, if the time source used for timestamp is untrustworthy, that is, the time can be tampered with, then the timestamp will lose its value. Traditional time source devices (such as Figure 1 As shown in the figure, time information is obtained from satellite time sources, NTP time sources, PTP time sources, and other clock sources and then directly used in the time terminal. Although this technical implementation solution is mature, simple, and convenient, it has the following drawbacks:

[0004] First, the authenticity of the time source signal is not verified: Traditional time source devices lack the ability to verify the authenticity of time signals, and the received time information may be tampered with or forged. For example, attackers could create fake Beidou signals for deception, threatening the authenticity and integrity of time information, potentially causing systemic errors and misleading decision-making, with serious negative impacts on normal social operations and public safety.

[0005] Second, the time receiving device is replaceable. Traditional time source devices are typically configured with a serial number to identify the device at the factory through network management software. This method is easily misused by other devices, posing the risk of illegal replacement. If the time source device can be arbitrarily replaced without the user's knowledge, it will threaten the security and reliability of the user's time, making the time information generated by the data unreliable, significantly reducing the value of the data, and even misleading decision-making, leading to serious consequences.

[0006] Third, there is a lack of a time output monitoring mechanism: when a traditional time source device experiences an anomaly or malfunction, it will still normally output inaccurate and unreliable time information to the outside world. Users or downstream systems cannot detect this through the device's own mechanism and may use the erroneous time information for key operations or decision-making, causing serious interference with the normal operation of key areas and threatening social stability and security.

[0007] Fourth, the time signal is output in plain text: Traditional time source devices do not encrypt the output time information, but directly output it in plain text, which is susceptible to malicious tampering. Users cannot distinguish whether the signal has been tampered with. Using the incorrect time signal for critical applications can cause system operation chaos, lead to serious security issues, and threaten system safety and reliability.

[0008] Fifth, the single source of time signal: traditional time source devices mainly rely on a single satellite signal source. Satellite signals are easily affected by factors such as no coverage areas, external environmental interference or transmission delays, resulting in the time source device being unable to receive signals normally, unable to provide accurate time services or even losing time synchronization functions. It lacks flexibility and reliability in complex environments, affecting its availability in application scenarios.

[0009] In summary, due to the above defects of traditional time source devices, there is an urgent need to improve and perfect the credibility of the time input signal, identity uniqueness, time transmission credibility, time output monitoring mechanism and single time source of the time source device to ensure that the time information output to the time-using terminal is safe and reliable.

[0010] In view of this, this invention is proposed. Summary of the Invention

[0011] The purpose of the present invention is to overcome the shortcomings of the above-mentioned prior art and provide a trusted time source device and its implementation method and application, which are mainly used to solve the five major defects of traditional time source devices (the time source signal is not authenticated, which makes the received time information easy to be tampered with and forged; the time receiving device can be illegally replaced, and the identity is easy to be misused by relying solely on the serial number identification; there is a lack of time output monitoring mechanism, and unreliable time information is still output when the device is abnormal; the time signal is output in plain text and is easy to be maliciously tampered with during transmission; the time signal has a single source and is greatly affected by environmental factors, making it difficult to provide stable time services in complex scenarios). The present invention ensures that the time information output to the time-using terminal is secure and trustworthy by constructing a trusted time service system from the time signal input end to the output end, providing a reliable trust foundation for time-dependent application scenarios such as timestamp evidence storage, blockchain consensus, and data rights confirmation.

[0012] The purpose of the present invention is to solve the problem through the following technical solutions:

[0013] In a first aspect, the present invention provides a trusted time source apparatus, comprising a network management system and a time source device;

[0014] The time source device integrates the following modules:

[0015] Satellite signal identification module, used to receive and identify the authenticity of satellite time signals;

[0016] An optical fiber signal discrimination module is configured to receive and discriminate the authenticity of the ground optical fiber time signal;

[0017] A device identity discrimination module is integrated with a hardware-level security chip or a physically unclonable chip, and stores a device unique identity digital certificate that is issued by a time device digital authentication center and is tamper-proof;

[0018] A fault monitoring and service suspension module is configured to monitor the device operating state, the time signal quality and the time deviation in real time, and to block the time output when the device operating state, the time signal quality or the time deviation is abnormal;

[0019] A time information encryption module is configured to encrypt the output time signal by using an asymmetric encryption algorithm or a national encryption algorithm;

[0020] A time satellite-ground backup module is configured to dynamically switch the input channels of the satellite time signal and the ground time signal;

[0021] The network management system is configured to apply for a device identity digital certificate from the time device digital authentication center, to solidify the certificate to the device identity discrimination module and to verify the legality of the device identity, to monitor the time source device operating state and alarm information in real time, to stop the time signal output when the device fails, and to restore the time signal output after the fault is repaired and is approved.

[0022] Further, the satellite signal discrimination module extracts the signal carrier phase noise waveform by using the built-in physical fingerprint extraction algorithm PHY-Fingerprint V2.3, dynamically matches the pre-stored satellite feature library, analyzes the navigation text digital signature to verify the authenticity of the signal source, and fuses the signals of the GPS / Beidou / Galileo systems to perform multi-system cross comparison and identification of spoofing attacks.

[0023] Further, the optical fiber signal discrimination module is a quantum key distribution device of the QKD-Box 5000 model, and a quantum random number seed is implanted in the IEEE 1588v2 protocol stack to realize anti-middleman attack discrimination.

[0024] Further, the hardware-level security chip or the physically unclonable chip in the device identity discrimination module generates a 128-bit unique device serial number by using the silicon chip process deviation, and synchronizes the key with the time device digital authentication center by using the national encryption SM9 algorithm.

[0025] Further, the fault monitoring and service suspension module compares the deviation of the internal double time source and the external time source in real time, stops the time output immediately and triggers the network management alarm when the deviation exceeds the set threshold or the device fails, and the normal time signal output can be restored only after the recovery approval process of the network management system.

[0026] Furthermore, the time information encryption module adopts a two-way digital certificate authentication mechanism at the time transceiver end, and the algorithm for encrypting the output time signal includes SM4, RSA or ECC.

[0027] Furthermore, the time-ground-space mutual backup module realizes automatic switching of the satellite time signal and the ground-based time signal input channels through a hardware circuit switch, and the switching conditions include signal loss, quality degradation or transmission delay exceeding the limit.

[0028] In a second aspect, the present invention further provides a method for implementing a trusted time source based on the above-mentioned trusted time source device, comprising the following steps:

[0029] Step 1: Time signal authenticity verification: The satellite signal verification module and the optical fiber signal verification module simultaneously receive and verify the authenticity of satellite and ground-based time signals;

[0030] Step 2: Device identity authentication and fixation: The network management system applies for the device's unique identity digital certificate from the time device digital authentication center and fixes it to the device identity authentication module;

[0031] Step 3, Fault Monitoring and Service Suspension: The fault monitoring and service suspension module monitors the device status in real time. In case of an abnormality, the time signal output is blocked, and the restoration of the time signal output requires approval from the network management system.

[0032] Step 4: Time encryption transmission: The time signal is encrypted by the time information encryption module, and the sending and receiving ends use two-way certificate authentication;

[0033] Step 5: Switching between the ground and the satellite time signal: When the satellite time signal is abnormal, the ground-based time signal module automatically switches to the ground-based time signal; or when the ground-based time signal is abnormal, the ground-based time signal module automatically switches to the satellite time signal.

[0034] Furthermore, in step 1, the satellite signal identification module is implemented by extracting the carrier phase noise fingerprint and matching it with the pre-stored satellite feature library;

[0035] The optical fiber signal identification module is implemented by implanting random number seeds through a quantum key distribution device.

[0036] In a third aspect, the present invention further provides an application based on the above-mentioned trusted time source device, wherein the trusted time source device is applied to the following scenarios:

[0037] Trusted time-based evidence storage and data ownership confirmation of electronic data preservation and ownership confirmation systems;

[0038] Trusted timestamp storage and evidence preservation for the health care system;

[0039] Trusted time synchronization services for low-altitude economical high-precision navigation and positioning systems such as drones;

[0040] Trusted time storage and settlement of financial transaction systems;

[0041] Trusted time-synchronized phasor measurement and fault location in power systems;

[0042] Trusted time consensus mechanism and smart contract execution of blockchain network;

[0043] Trusted time channel synchronization and trusted access for 6G communication networks.

[0044] Compared with the prior art, the present invention has the following beneficial effects:

[0045] 1. Strengthening the authenticity identification of time signal sources: The present invention uses the physical fingerprint extraction algorithm built into the satellite signal identification module, combined with multi-satellite system cross-validation, to accurately identify spoofing attacks. At the same time, the fiber optic signal identification module uses quantum key distribution technology to achieve anti-man-in-the-middle attack identification, eliminating false signal interference at the source, ensuring the authenticity and reliability of the time signal source, and filling the technical gap in the lack of signal authenticity identification in traditional time source devices.

[0046] 2. Improve device identity authentication security: This invention uses the silicon process deviation of hardware-level security chips or PUF physically unclonable chips to generate a unique device serial number. Combined with the national secret SM9 algorithm and two-way authentication by an authoritative certification center, compared with traditional serial number identification methods, it eliminates the risk of device identity counterfeiting at the hardware level. When the device is replaced, it triggers an automatic alarm and is forced to go offline, ensuring the uniqueness of the device identity and its safety.

[0047] 3. Realize trusted traceability of full-link time signals: The satellite and optical fiber signal identification module of the present invention deeply verifies the source of the time signal. Combined with the network management system's record of the status of the equipment throughout its life cycle, it can completely trace the transmission link of the time signal from the source to the terminal, solving the technical problem that traditional technologies cannot verify the authenticity and source of the signal, and providing a reliable time basis for applications such as medical data evidence storage and judicial data evidence storage and data rights confirmation.

[0048] 4. Enhanced fault protection and redundancy guarantee capabilities: The fault monitoring and shutdown module of the present invention monitors the equipment operating status and time deviation in real time. If the threshold is exceeded, it automatically blocks the output of the wrong time and issues an alarm, thus avoiding the propagation of the wrong time caused by the traditional device running with a fault. In addition, the time ground-to-space mutual backup module automatically switches the main and backup signal sources (generally the satellite time signal is the main one and the ground-based time signal is the backup one) through the hardware circuit, and combines the weighted algorithm to evaluate the signal credibility, thus ensuring the continuity of time service in complex environments and significantly improving the reliability and stability of the system.

[0049] 5. Ensure the security of time signal transmission: The time information encryption module of the present invention adopts an asymmetric encryption algorithm or a national secret algorithm, combined with a two-way digital certificate authentication mechanism. Compared with traditional plaintext transmission, it effectively prevents the time signal from being maliciously tampered with during transmission, ensuring the confidentiality and integrity of time data.

[0050] In summary, the full-link trusted time service system constructed by this invention achieves a breakthrough in traditional time source devices through multi-dimensional technological innovation. In terms of social value, it strengthens the timing security of critical national infrastructure such as electricity, communications, and national defense, preventing systemic risks caused by time tampering. It provides judicially reliable time evidence for blockchain-based evidence storage and electronic contract signing, accelerating the marketization of data elements. In life-critical scenarios such as autonomous driving and medical equipment, it provides zero-interruption time services to protect public life and property. In terms of economic benefits, it can avoid hundreds of billions of yuan in settlement errors annually in the financial sector and reduce the risk of power outages by tens of billions of yuan for the power system. As the core foundation of emerging industries such as 6G communications and the Industrial Internet, its highly reliable time will foster a trillion-yuan digital economy ecosystem, including intelligent connected vehicles and metaverse interactions. With "time source trust" as its core, this invention addresses five key pain points of traditional time sources from a fundamental technical perspective, providing a quantifiable and highly reliable trust foundation for key areas of the digital economy. BRIEF DESCRIPTION OF THE DRAWINGS

[0051] The accompanying drawings are incorporated in and constitute a part of this specification and, together with the description, serve to explain the principles of the invention.

[0052] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0053] Figure 1 This is a block diagram of a traditional time source device;

[0054] Figure 2 This is a block diagram of a trusted time source device according to the present invention;

[0055] Figure 3 This is a block diagram of a trusted authentication mechanism for time signals in a trusted time source device of the present invention;

[0056] Figure 4 This is a block diagram of the device identity authentication and fixation mechanism in the trusted time source device of the present invention;

[0057] Figure 5 This is a block diagram of the fault monitoring and service suspension mechanism in the trusted time source device of the present invention;

[0058] Figure 6 A block diagram of the bidirectional certificate verification and encryption output mechanism in the trusted time source device of the present invention;

[0059] Figure 7 This is a block diagram of the multi-source earth-ground mutual backup mechanism in the trusted time source device of the present invention.

[0060] in:

[0061] 1 is the network management system;

[0062] Reference numeral 2 denotes a time source device; reference numeral 21 denotes a satellite signal identification module; reference numeral 22 denotes an optical fiber signal identification module; reference numeral 23 denotes an equipment identity identification module; reference numeral 24 denotes a fault monitoring and shutdown module; reference numeral 25 denotes a time information encryption module; reference numeral 26 denotes a time space-ground mutual backup module. DETAILED DESCRIPTION

[0063] Exemplary embodiments will be described in detail herein, examples of which are illustrated in the accompanying drawings. In the following description, when referring to the drawings, identical numerals in different figures represent identical or similar elements unless otherwise indicated. The embodiments described in the following exemplary embodiments are not intended to represent all possible embodiments consistent with the present invention. Rather, they are merely examples of arrangements consistent with certain aspects of the present invention as detailed in the appended claims.

[0064] In order to enable those skilled in the art to better understand the technical solutions of the present invention, the present invention is described in further detail below with reference to the accompanying drawings and embodiments.

[0065] See also Figures 2 to 7 The present invention provides a trusted time source device, comprising a network management system 1 and a time source device 2. The network management system 1 is used to ensure the legitimacy of the device identity and the stability of the device operation. Its specific functions include applying for a device identity digital certificate from an authoritative time device digital authentication center; solidifying the certificate into the device identity authentication module 23 in the time source device 2 and verifying the legitimacy of the device identity; monitoring the operating status and alarm information of the time source device 2 in real time; and approving time signal output requests after fault recovery. The time source device 2 integrates a satellite signal authentication module 21, an optical fiber signal authentication module 22, a device identity authentication module 23, a fault monitoring and service suspension module 24, a time information encryption module 25, and a time space-ground mutual backup module 26. Through the collaborative work of the above modules, the time signals from the satellite navigation system and the ground-based timing system are authenticated and processed to ensure the security and reliability of the time information. At the same time, the time device digital authentication center is responsible for the application, issuance, and revocation of certificates, further enhancing the security and reliability of the trusted time source device.

[0066] Specifically, in the embodiment of the present invention, the satellite signal identification module 21 embeds a physical fingerprint extraction algorithm (PHY-Fingerprint V2.3) to extract the signal carrier phase noise waveform, dynamically matches it with a pre-stored satellite feature library containing 32 satellite fingerprint templates, parses the digital signature of the navigation message to verify the authenticity of the signal source, and simultaneously combines GPS / Beidou / Galileo multi-satellite system cross-comparison to identify spoofing attacks, ensuring that the device always receives reliable satellite signals. In addition, the fiber optic signal identification module 22 deploys a quantum key distribution device model QKD-Box 5000, implants a quantum random number seed in the fiber optic PTP protocol stack, and implements anti-man-in-the-middle attack authentication for the IEEE 1588v2 protocol, ensuring that the received fiber optic signal comes from the ground-based timing system, rather than a fake fiber optic signal, to achieve the following: Figure 3 The time signal trust authentication mechanism shown.

[0067] In the embodiment of the present invention, the device identity authentication module 23 integrates a hardware-level security chip or a PUF physical non-clonable chip, and uses silicon process deviation to generate a 128-bit unique device serial number to form an unalterable "time ID card". When the device is connected to the network, it needs to apply for a digital certificate from the time device digital authentication center, complete two-way authentication based on asymmetric encryption technology, and synchronize the key with the digital authentication center through the national secret SM9 algorithm to ensure that the device identity is legal and cannot be counterfeited. Figure 4 As shown in the figure, during device operation, network management system 1 monitors the device's operating status in real time. If the time source is replaced, network management system 1 immediately interrupts communication with the device, issues an alarm, and forces the time source device offline. After the administrator confirms the repair, the device must be restored online according to the time output restoration approval process in network management system 1 to ensure the reliability of the device's output time signal.

[0068] In the embodiment of the present invention, the fault monitoring and service stop module 24 detects the operating status, signal quality and time deviation of the equipment in real time (such as comparison with the atomic clock reference). When a device fault is detected, the time service stop mechanism is immediately triggered to block the output of the wrong time, and the operation and maintenance end is notified through the alarm system; when a time signal abnormality is detected, the time signal input is refused to ensure the credibility of the time signal output. After the time signal is blocked from output, the equipment operation and maintenance management personnel troubleshoot the equipment through the network management system 1 to check for equipment faults, and then initiate a time signal output application through the network management system 1. The management personnel review and confirm whether the time signal of the device can be output according to business needs, such as Figure 5 shown.

[0069] In the embodiment of the present invention, the time information encryption module 25 adopts a national secret algorithm (such as SM4), an asymmetric encryption algorithm (such as RSA, ECC) or quantum encryption technology for dynamic encryption, and adopts a two-way digital certificate verification mechanism at the time sending and receiving end to ensure the integrity and confidentiality of the data. Figure 6 shown.

[0070] In the embodiment of the present invention, the time-space backup module 26 dynamically integrates satellite and ground-based timing signals, and the monitoring program monitors the main time signal input in real time to see if it is normal. Once an abnormality is detected (such as signal loss, quality degradation, or excessive transmission delay), the control program immediately triggers a hardware circuit switch (existing technology, no further description will be given) to close the main time signal input channel and simultaneously open the backup time signal input channel to ensure the continuity of the received time signal input. Figure 7 shown.

[0071] The trusted time source device provided by the present invention forms a closed-loop protection system through mechanisms such as time signal identification, device identity authentication, time encrypted transmission, time monitoring and service suspension, and time-space mutual backup. It can effectively solve the problems of time signal source forgery, device replacement or counterfeiting, lack of control over abnormal time output, plaintext transmission, and single point failure existing in traditional time sources. It is suitable for fields with high requirements for time security and credibility, such as electronic data evidence storage and verification, electronic data ownership confirmation, finance, electricity, and national defense.

[0072] In addition, based on the above-mentioned trusted time source device, the present invention also provides a trusted time source implementation method, which specifically includes the following steps:

[0073] Step 1: Time signal authenticity verification: The satellite signal verification module 21 and the fiber signal verification module 22 simultaneously receive and verify the authenticity of satellite and ground-based time signals. Satellite signal verification extracts carrier phase noise fingerprints and matches them with a pre-stored satellite feature library. It also analyzes the digital signature of navigation messages to verify the authenticity of the signal source, and combines multi-satellite system cross-comparison to identify spoofing attacks. Fiber signal verification uses a quantum key distribution device to implant a random number seed into the fiber PTP protocol stack, achieving IEEE 1588v2 anti-man-in-the-middle attack authentication.

[0074] Step 2: Device identity authentication and fixation: The network management system 1 applies for a unique device identity digital certificate from the Time Device Digital Authentication Center, completes two-way authentication based on asymmetric encryption technology, synchronizes the key with the Time Device Digital Authentication Center using the national secret SM9 algorithm, and finally fixes the authentication information to the device identity authentication module 23;

[0075] Step 3, Fault Monitoring and Service Suspension: The fault monitoring and service suspension module 24 monitors the device's operating status, signal quality, and time deviation (e.g., compared with an atomic clock reference) in real time. When a device fault or time signal anomaly is detected, the time service suspension mechanism is immediately triggered to block the output of the erroneous time and notify the operation and maintenance end through the alarm system. After the fault is rectified, a time signal output request must be initiated through the network management system 1, and the system must be restored online after review and confirmation by the management personnel.

[0076] Step 4: Time encryption transmission: The time information encryption module 25 uses a national secret algorithm (such as SM4), an asymmetric encryption algorithm (such as RSA, ECC) or quantum encryption technology to dynamically encrypt the time signal, and uses a two-way digital certificate verification mechanism at the time sending and receiving end to ensure the integrity and confidentiality of the data;

[0077] Step 5: Switching between the ground and the earth: The ground and the earth backup module 26 monitors the input status of the main time signal in real time. When it detects abnormalities such as signal loss, quality degradation, or excessive transmission delay, it immediately switches to the backup time signal source through the hardware circuit switch to ensure the continuity of the received time signal input.

[0078] Through the above steps, the present invention realizes all-round protection of the time signal source, device identity, transmission process and system reliability, forming a closed-loop trusted time service system.

[0079] The foregoing description is intended only to provide specific embodiments of the present invention, which will enable those skilled in the art to understand and implement the present invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention.

[0080] It should be understood that the present invention is not limited to the above description and that various modifications and changes may be made without departing from the scope thereof. The scope of the present invention is limited only by the appended claims.

Claims

1. A trusted time source device, characterized in that: It includes a network management system (1) and a time source device (2); Wherein, the time source device (2) integrates the following modules: A satellite signal identification module (21) is used to receive and identify the authenticity of satellite time signals; An optical fiber signal identification module (22) for receiving and identifying the authenticity of a ground-based time signal; The device identity authentication module (23) is integrated with a hardware-level security chip or a physically unclonable chip, and stores a tamper-proof device unique identity digital certificate issued by a time device digital authentication center; A fault monitoring and service stop module (24) monitors the equipment operation status, time signal quality and time deviation in real time, and blocks time output when the equipment operation status, time signal quality or time deviation are abnormal; A time information encryption module (25) encrypts the output time signal using an asymmetric encryption algorithm or a national secret algorithm; A time-space mutual backup module (26) dynamically switches the input channels of satellite time signals and ground-based time signals; The network management system (1) is used to apply for a device identity digital certificate from a time device digital authentication center, fix the certificate to a device identity authentication module (23) and verify the legitimacy of the device identity, monitor the operating status and alarm information of the time source device (2) in real time, stop the time signal output when the device fails, and resume the time signal output after the failure is repaired and approved; The satellite signal identification module (21) extracts the signal carrier phase noise waveform through the built-in physical fingerprint extraction algorithm PHY-Fingerprint V2.3, dynamically matches it with the pre-stored satellite feature library, analyzes the digital signature of the navigation message to verify the authenticity of the signal source, and integrates the signals of the GPS / Beidou / Galileo systems to perform multi-system cross-comparison to identify deception attacks; The optical fiber signal identification module (22) deploys a quantum key distribution device of model QKD-Box 5000, and implants a quantum random number seed in the IEEE1588v2 protocol stack to achieve anti-man-in-the-middle attack identification.

2. The trusted time source device according to claim 1, wherein: The hardware-level security chip or the physical unclonable chip in the device identity authentication module (23) generates a 128-bit unique device serial number using silicon process deviation, and synchronizes the key with the time device digital authentication center through the national secret SM9 algorithm.

3. The trusted time source device according to claim 1, wherein: The fault monitoring and service suspension module (24) compares the deviation between the dual time sources inside the device and the external time source in real time. When the deviation exceeds a set threshold or the device fails, the time output is immediately stopped and a network management alarm is triggered. The normal time signal output can only be restored after the recovery approval process of the network management system (1).

4. The trusted time source device according to claim 1, wherein: The time information encryption module (25) adopts a two-way digital certificate authentication mechanism at the time transceiver end, and the algorithm for encrypting the output time signal includes SM4, RSA or ECC.

5. The trusted time source device according to claim 1, wherein: The time-ground-space mutual backup module (26) realizes automatic switching between the satellite time signal and the ground-based time signal input channel through a hardware circuit switch, and the switching conditions include signal loss, quality degradation or transmission delay exceeding the limit.

6. A method for implementing a trusted time source, based on the trusted time source device according to any one of claims 1 to 5, characterized in that: The following steps are involved: Step 1: Time signal authenticity identification: The satellite signal identification module (21) and the optical fiber signal identification module (22) are used to simultaneously receive and identify the authenticity of the satellite and ground-based time signals; Step 2, device identity authentication and solidification: the network management system (1) applies for a device unique identity digital certificate from the time device digital authentication center and solidifies it into the device identity authentication module (23); Step 3, fault monitoring and service suspension: The fault monitoring and service suspension module (24) monitors the device status in real time, blocks the time signal output when an abnormality occurs, and the restoration of the time signal output requires approval from the network management system (1); Step 4, time encryption transmission: encrypt the time signal through the time information encryption module (25), and the sending and receiving ends use two-way certificate authentication; Step 5, ground-to-space backup switching: When the satellite time signal is abnormal, the time ground-to-space backup module (26) automatically switches to the ground-based time signal; or when the ground-based time signal is abnormal, the time ground-to-space backup module (26) automatically switches to the satellite time signal.

7. An application of the trusted time source device according to any one of claims 1 to 5, characterized in that: The trusted time source device is used in the following scenarios: Trusted time-based evidence storage and data ownership confirmation of electronic data preservation and ownership confirmation systems; Trusted timestamp storage and evidence preservation for the health care system; Trusted time synchronization services for low-altitude economical high-precision navigation and positioning systems such as drones; Trusted time storage and settlement of financial transaction systems; Trusted time-synchronized phasor measurement and fault location in power systems; Trusted time consensus mechanism and smart contract execution of blockchain network; Trusted time channel synchronization and trusted access for 6G communication networks.

Citation Information

Patent Citations

  • Credible timestamp implementation method based on credible time

    CN112395620A

  • Data storage verification method and device, equipment and medium

    CN119577725A

Cited By

  • Trusted time service device and method

    CN122293445A