Trusted timestamp device

By ensuring the credibility of the time signal of the timestamp device through multiple security mechanisms, the problem of traditional timestamp devices being vulnerable to attacks is solved, the credibility and compliance of the timestamp are achieved, and its application value and legal effectiveness in key areas are enhanced.

CN120751384AActive Publication Date: 2025-10-03TIANFU HIGH-PRECISION TRUSTED TIME (SICHUAN) TECHNOLOGY CO LTD
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
CN202511247351.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-03
Publication Date
2025-10-03
Estimated Expiration
2045-09-03

AI Technical Summary

Technical Problem

Traditional timestamp devices rely on unreliable network time and satellite time, which are vulnerable to attacks and tampering, causing the timestamp to lose credibility and cannot be widely used in key areas.

Method used

It uses a trusted satellite time signal receiving module, a trusted fiber optic time signal receiving module, a trusted NTP time signal receiving module and a trusted time signal selection module to ensure the credibility of the time signal through multiple security mechanisms. Combined with a trusted time stamp verification module, it achieves the credibility and compliance of the time stamp.

Benefits of technology

Ensure the credibility of the time used for stamping, improve the application value and legal acceptance rate of timestamps, reduce disputes and risks, enhance cross-industry compatibility, and support the trusted time infrastructure of digital economy and judicial evidence storage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120751384A_ABST
    Figure CN120751384A_ABST
Patent Text Reader

Abstract

The invention discloses a credible timestamp device, which relates to the technical field of credible time, and comprises a credible satellite time signal receiving module used for identifying and receiving time signals provided by a satellite navigation system, and resisting and filtering forged or tampered satellite signals through a signal identification mechanism to obtain credible satellite time signals; the credible optical fiber time signal receiving module is used for identifying and receiving a credible optical fiber time signal from a ground-based time service system to obtain a credible optical fiber time signal; the credible NTP time signal receiving module is used for synchronizing credible NTP reference time from a credible time system in an NTS protocol two-way identity verification and encryption mode to obtain a credible NTP time signal; the credible time signal selection module is used for selecting credible satellite time signals, optical fiber time signals and NTP time signals according to priorities; the trusted time stamping verification module is used for stamping and verifying the timestamp; according to the invention, the time for stamping can be ensured to be credible.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of trusted time technology, and in particular to a trusted time stamp device. Background Art

[0002] In key areas such as medicine, justice, and finance, the authenticity, integrity, and legal validity of electronic data are highly dependent on the "time dimension" authentication, that is, the credibility of "when the data was generated / modified". Traditional time stamping devices achieve this authentication function by adding a timestamp to electronic data. The workflow is as follows: receiving satellite or network time from an external time source, using it to timestamp the target data, and returning the stamped result to the user and storing it locally. Typical application scenarios include Figure 1 shown.

[0003] Traditional timestamp devices primarily rely on network time based on the Network Time Protocol (NTP) or satellite time based on satellite navigation systems (such as GPS / Beidou), but both suffer from serious reliability flaws. Regarding network time, NTP cannot guarantee time reliability and does not verify the authenticity of the NTP time source. Furthermore, the NTP protocol transmits time information in plain text and lacks encryption and authentication mechanisms, making it vulnerable to man-in-the-middle (MITM) and delay injection attacks. For example, attackers can falsify time data by tampering with NTP service responses. Regarding satellite time, while satellite time services offer high time accuracy, they are susceptible to security risks such as signal spoofing and interference. According to data from the ION GNSS+ 2021 conference, commercial GPS receivers have an 80% success rate for spoofing, and Beidou system receivers face similar threats. Once the time base loses its credibility, the timestamp loses its credibility as time evidence, ultimately completely losing its legal validity as time evidence. Timestamp technology, as an internationally recognized tamper-proof technology, has been applied in many fields. However, its value is limited by the unreliability of the time used to stamp the data. This core flaw not only restricts the application boundaries of the technology, but may also cause disputes over data credibility and even lead to legal risks, making it difficult to fully unleash the inherent advantages and core value of timestamp technology.

[0004] The time used by traditional time stamping devices is unreliable in the following aspects:

[0005] 1. Unreliable network time used for stamping: Traditional timestamping devices that use a network time source as their time base rely on complex and unidentified NTP servers. This includes numerous unauthorized time sources whose legitimacy is questionable and can be easily replaced. Furthermore, because the NTP protocol uses plain text for transmission, time information is susceptible to malicious attacks and tampering before reaching the timestamping device, compromising the reliability of the timestamp.

[0006] 2. Satellite time signal forgery and spoofing: Traditional time stamping devices lack the ability to verify the authenticity of time signals, potentially leading to the reception of tampered or forged time information. This requires a method to verify the authenticity and integrity of time signals to prevent malicious attackers from creating false signals that impersonate authentic ones.

[0007] 3. Fiber-optic timing signal reliability flaws: Traditional timestamp devices currently on the market have significant shortcomings in receiving fiber-optic timing signals. The vast majority lack the ability to receive fiber-optic timing signals, and those that do have significant reliability risks. They lack mechanisms to verify the identity of fiber-optic time sources, making it impossible to verify whether the signal originates from a legitimate timing node. Furthermore, they lack encryption and verification of the transmitted time code stream, making it difficult to detect signal tampering. This directly raises doubts about the authenticity of the received fiber-optic time signal, making it unreliable as a reliable time reference.

[0008] In summary, the core problem of traditional timestamping devices lies in the unreliability of the time used to stamp, which directly leads to the loss of credibility of timestamping as time evidence, making it difficult for it to be widely accepted in judicial and commercial environments. Therefore, technological innovation is urgently needed to fully realize the potential of timestamping technology, ensure that it can truly fulfill the role of time evidence, and achieve widespread application in various fields such as the digital economy and judicial system. Summary of the Invention

[0009] In order to solve the problems existing in the prior art, the purpose of the present invention is to provide a reliable time stamping device, which can ensure that the time used for stamping is reliable.

[0010] To achieve the above-mentioned purpose, the technical solution adopted by the present invention is: a trusted time stamp device, comprising: a trusted satellite time signal receiving module, a trusted optical fiber time signal receiving module, a trusted NTP time signal receiving module, a trusted time signal selection module and a trusted time stamp verification module, wherein:

[0011] Trusted satellite time signal receiving module, used to identify and receive time signals from satellite navigation systems, and to resist and filter out forged or tampered satellite signals through signal authentication mechanisms, thereby obtaining trustworthy satellite time signals;

[0012] A trusted optical fiber time signal receiving module is used to identify and receive a trusted optical fiber time signal from a ground-based timing system to obtain a trusted optical fiber time signal;

[0013] Trusted NTP time signal receiving module, used to synchronize the trusted NTP reference time from the trusted time system using the NTS protocol two-way authentication and encryption method to obtain a trusted NTP time signal;

[0014] Trusted time signal selection module, used to select trusted satellite time signals, optical fiber time signals and NTP time signals according to priority;

[0015] The trusted time stamp verification module is used to implement time stamping and verification.

[0016] As a further improvement of the present invention, the satellite navigation system includes a GPS navigation system, a Beidou navigation system or a Galileo navigation system.

[0017] As a further improvement of the present invention, the trusted satellite time signal receiving module captures the carrier phase signal of GPS / Beidou / Galileo from the satellite navigation system, first uses the physical fingerprint extraction algorithm to extract the noise waveform characteristics and generate a feature vector; then compares the feature vector with the pre-stored satellite fingerprint template library, and calculates the similarity entropy value based on the dynamic time warping algorithm to verify the authenticity of the physical identity; then analyzes the navigation message of the signal that has passed the physical authentication, and uses the preset public key to verify the digital signature to confirm the credibility of the logical source; finally, calculates the time deviation of multiple systems, uses the weighted median to output the global trusted time, and automatically isolates the attack signal in the event of an abnormality, and finally builds an end-to-end trust chain from physical layer feature extraction, protocol layer signature verification to system layer consensus.

[0018] As a further improvement of the present invention, the trusted optical fiber time signal receiving module first performs a two-way handshake with the hardware security module preset in the timing center to exchange a one-time ECDH session key; only devices carrying valid certificates are allowed to continue communicating, blocking illegal injection; then, the received 1PPS+TOD frame is decrypted using the session key for AES-GCM, and the MAC is verified; if the MAC match fails, it is regarded as tampering, immediately discarded and an alarm is issued; then, the phase difference between the local clock and the rising edge of the 1PPS is measured through a time-to-digital converter, and a Kalman filter is used to dynamically estimate the drift and adjust the local OCXO in real time.

[0019] As a further improvement of the present invention, the trusted NTP time signal receiving module first establishes a tunnel with a trusted NTP server. The server presents a certificate for verification of validity period, chain trust and CRL / OCSP status, and returns the certificate to complete two-way verification, thereby blocking the forgery of NTP time sources. Subsequently, HKDF is used to derive an AES-GCM session key, NTSCookie and HMAC-SHA256 verification are added to the NTP message, and the timestamp field is encrypted and attached with an authentication tag. The receiving end decrypts and verifies in real time. If an abnormality occurs, an alarm is immediately issued and the reception of NTP time signals is stopped.

[0020] As a further improvement of the present invention, when multiple time signals are available at the same time, the trusted time signal selection module selects a trusted time signal according to the optical fiber time signal, NTP time signal and satellite time signal from high to low priority as the time used for stamping; when a single time signal is available, it is directly used as the time used for stamping.

[0021] The trusted timestamp device proposed in this invention ensures the authenticity of the time used for stamping. This feature not only gives timestamps the core function of "time notarization" but also opens up the possibility of application in multiple fields: in the field of data ownership, it becomes the core basis for the temporal definition of intellectual property rights; in blockchain technology, it strengthens the trusted anchor point of the on-chain time dimension; in big data management, it provides a solid guarantee for the authority of time series data; and especially in judicial evidence storage scenarios, it can ensure the credibility of electronic evidence and the legality of judicial recognition. Its widespread application will promote the upgrading of timestamp technology from tool-level application to infrastructure-level foundation, providing key technical support for the digital economic governance and the construction of a trusted data ecosystem in modern society.

[0022] The beneficial effects of the present invention are:

[0023] 1. Enhancing the Application Value of Stamped Data: This invention establishes a multi-layered security system through a trusted satellite / fiber / NTP time signal reception mechanism, addressing the unreliable time used by traditional stamping devices. This trusted time reception mechanism ensures the authenticity of stamped time, thereby safeguarding the application value, credibility, and acceptance rate of stamped data in scenarios such as judicial evidence storage and financial transactions. It provides highly reliable timestamping services for data ownership confirmation, blockchain smart contracts, and cross-border electronic evidence.

[0024] 2. Reducing disputes and risks associated with using time as electronic evidence: This invention leverages technologies such as log evidence storage and cryptographic hashing to fully record the entire process of trusted time, from time source identity confirmation and encrypted time transmission to timestamp generation, time stamping, and evidence backup. This enhances the self-evident power of timestamps in dispute resolution, thereby reducing potential risks.

[0025] 3. Improving the Continuous Service Capability of Trusted Timestamp Devices: This invention utilizes a multi-time source mechanism—trusted satellite / fiber / NTP time signals originate from satellite navigation systems, ground-based timing systems, and trusted time systems, respectively. These signals are authenticated and received by a dedicated time signal receiving module. These multiple trusted time input sources are cross-verified and automatically switched when anomalies occur, preventing service interruptions caused by failure of a single time source. This significantly improves the continuity and risk mitigation of timestamp services.

[0026] 4. Enhanced cross-industry compatibility of timestamping devices: Currently, the vast majority of timestamping devices on the market lack access to fiber-optic time signals, and some do not fully comply with national cryptographic industry standards, limiting their application in government and financial sectors, where compliance is critical. In contrast, the trusted timestamping device of this invention not only reliably receives fiber-optic time signals but also strictly adheres to GM / T 0033 "Time Stamp Interface Specification" and GM / T 0028 "Technical Requirements for Cryptographic Module Security," ensuring compatibility with cryptographic systems in government, finance, and other fields. This design significantly reduces the adaptation cost for cross-industry applications and meets the timestamping service requirements of high-compliance scenarios.

[0027] The above effects are due to technical features such as the satellite / optical fiber / NTP time receiving module design and the trusted time signal selection mechanism, which achieve a technological breakthrough in timestamp credibility and provide key support for the construction of trusted time infrastructure for the digital economy. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] Figure 1 A schematic diagram of a typical application scenario of a traditional time stamping device;

[0029] Figure 2 This is a schematic diagram of the structure of a trusted timestamp device according to an embodiment of the present invention;

[0030] Figure 3 Schematic diagram of a trusted satellite time signal receiving mechanism according to an embodiment of the present invention;

[0031] Figure 4 Schematic diagram of a trusted optical fiber time signal receiving mechanism according to an embodiment of the present invention;

[0032] Figure 5 Schematic diagram of a trusted NTP time signal receiving mechanism in an embodiment of the present invention. DETAILED DESCRIPTION

[0033] The embodiments of the present invention are described in detail below with reference to the accompanying drawings.

[0034] Example:

[0035] like Figure 2 As shown, a trusted timestamp device can receive satellite time signals, trusted fiber time signals, and trusted NTP time signals, and then use a signal optimization mechanism to ensure that the time used for stamping is reliable. Specifically, it includes:

[0036] 1. Trusted Satellite Time Signal Receiving Module: The trusted timestamping device's satellite signal identification module is specifically designed to identify and receive time signals from satellite navigation systems (such as GPS, BeiDou, and Galileo). This module effectively protects against and filters out forged or tampered satellite signals through its signal identification mechanism, ensuring the credibility of the received time information.

[0037] 2. Trusted Fiber Optic Time Signal Receiving Module: The trusted fiber optic time signal receiving module of the trusted timestamping device identifies and receives the trusted fiber optic time signal from the ground-based timing system of the National Time Service Center, ensuring the trustworthiness of the time source and preventing "contamination of the time used for stamping."

[0038] 3. Trusted NTP time signal receiving module: The trusted NTP time signal receiving module of the trusted timestamp device synchronizes the trusted NTP reference time from the trusted time system using the NTS protocol bidirectional authentication and encryption to ensure the credibility and integrity of the received NTP time.

[0039] 4. Trusted time signal selection module: The trusted time signal selection module of the trusted time stamp device realizes the priority selection of satellite time signal, optical fiber time signal and NTP time signal.

[0040] 5. Trusted time stamp verification module. The trusted time stamp verification module of the trusted time stamp device implements the time stamping and verification functions required by the national cryptography industry standards GM / T 0033 "Time Stamp Interface Specification" and GM / T 0028 "Security Technical Requirements for Cryptography Modules."

[0041] The trusted timestamp device of this embodiment receives signals from three different time sources: a trusted satellite time signal provided by a satellite navigation system, a trusted fiber optic time signal provided by a ground-based timing system, and a trusted NTP time signal provided by a trusted time system. These signals are received, processed, and analyzed by their respective receiving modules to ensure the accuracy and reliability of the time information. Then, the trusted time signal selection module selects the trusted time signal. Next, the trusted time stamping and verification module of the device further applies the time information, such as a trusted time stamping of electronic data. The entire device is designed to provide a highly reliable time stamping service, suitable for application scenarios that require trusted time stamping and verification.

[0042] The trusted timestamp device is implemented by receiving trusted satellite time signals, trusted time fiber signals, and trusted NTP time signals, and selecting the received trusted time signals. It includes the following parts:

[0043] 1. Trusted satellite time signal reception mechanism;

[0044] 2. Trusted fiber optic time signal receiving mechanism;

[0045] 3. Trusted NTP time signal receiving mechanism;

[0046] 4. Trusted time signal selection mechanism;

[0047] 5. Trusted time stamp verification mechanism.

[0048] like Figure 3 As shown in the figure, the trusted satellite time signal reception mechanism captures the carrier phase signal of GPS / Beidou / Galileo from the satellite navigation system through the trusted satellite time signal reception module. First, the physical fingerprint extraction algorithm is used to extract the noise waveform characteristics and generate a 128-dimensional feature vector. This is then compared with the pre-stored 32-satellite fingerprint template library. The similarity entropy value (threshold ≤ 0.15) is calculated based on the dynamic time warping algorithm to verify the authenticity of the physical identity. The navigation message of the signal that has passed the physical authentication is then analyzed, and the digital signature (RSA-3072 / SM2) is verified using a preset public key to confirm the credibility of the logical source. Finally, the multi-system time deviation is calculated (threshold ±50ns), and the weighted median (weight 4:3:3) is used to output the global trusted time. In the event of an anomaly, the attack signal is automatically isolated. Ultimately, an end-to-end trust chain is established from physical layer feature extraction, protocol layer signature verification, to system layer consensus.

[0049] like Figure 4 As shown, the trusted fiber-optic time signal reception mechanism receives fiber-optic time signals from the ground-based timing system through the identity authentication, authenticity verification, and accuracy calibration functions of the trusted fiber-optic time signal receiving module. First, after powering on, the fiber-optic module performs a two-way TLS 1.3 handshake with the hardware security module (HSM) pre-installed by the National Time Service Center to exchange a one-time ECDH session key. Only devices with valid certificates are allowed to continue communication, preventing unauthorized injection. The received 1PPS+TOD frame is then decrypted using AES-GCM using the session key and the 256-bit MAC is verified. If the MAC fails to match, it is considered tampered, immediately discarded, and an alarm is issued. Next, the FPGA's built-in TDC (time-to-digital converter) measures the phase difference between the local clock and the rising edge of the 1PPS. A Kalman filter is used to dynamically estimate drift and adjust the local OCXO in real time. The calibration residual is maintained within ±5ns, ensuring the long-term stability of the output time reference and immunity to interference or spoofing.

[0050] like Figure 5As shown, the trusted NTP time signal reception mechanism uses the NTS protocol to achieve two-way identity authentication and end-to-end encryption through a trusted NTP time signal reception module. First, the device establishes a TLS 1.3 tunnel with the trusted NTP server. The server presents an X.509 certificate for the device to verify the validity period, chain trust, and CRL / OCSP status. The device also returns the certificate to complete the two-way verification and block the forgery of NTP time sources. Subsequently, both parties use HKDF to derive the AES-GCM session key. The NTP message is added with NTSCookie and HMAC-SHA256 checksum. The timestamp field is encrypted and attached with an authentication tag. The receiving end decrypts and verifies in real time. If an abnormality occurs, an alarm will be immediately issued and the reception of NTP time signals will be stopped, thus ensuring the authenticity of the time source and the tamper-proof transmission link.

[0051] The trusted time signal selection mechanism uses the trusted time signal selection module to receive, parse, process and intelligently select multiple signals such as satellite, optical fiber and NTP in real time: when multiple time signals are available at the same time, the trusted time signal is selected from the highest to the lowest priority among the optical fiber time signal, NTP time signal and satellite time signal as the time used for stamping; when a single time signal is available, it is directly used as the time used for stamping.

[0052] The trusted time stamping and verification mechanism supports the stamping, verification and logging functions required by the second level of GM / T 0033 "Time Stamp Interface Specification" and GM / T 0028 "Technical Requirements for Cryptographic Module Security".

[0053] The trusted timestamping device of this invention utilizes the five aforementioned mechanisms to establish a trusted time stamping technology system. The first four ensure the authenticity of the stamped time by identifying, receiving, and selecting signals from multiple sources, including satellite, optical fiber, and NTP. The fifth mechanism, through its compliance function, adapts to national cryptographic standards, thus meeting the high-trust and high-compliance requirements for time bases in government, finance, and other fields. These mechanisms effectively ensure a highly reliable timestamping service and increase the legal admissibility of electronic evidence.

[0054] The above-described embodiments merely represent specific implementations of the present invention. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present invention. It should be noted that a person skilled in the art would be able to make numerous variations and improvements without departing from the spirit of the present invention, and all such variations and improvements fall within the scope of protection of the present invention.

Claims

1. A trusted timestamp device, characterized in that: include: Trusted satellite time signal receiving module, trusted optical fiber time signal receiving module, trusted NTP time signal receiving module, trusted time signal selection module and trusted time stamp verification module, including: Trusted satellite time signal receiving module, used to identify and receive time signals from satellite navigation systems, and to resist and filter out forged or tampered satellite signals through signal authentication mechanisms, thereby obtaining trustworthy satellite time signals; A trusted optical fiber time signal receiving module is used to identify and receive a trusted optical fiber time signal from a ground-based timing system to obtain a trusted optical fiber time signal; Trusted NTP time signal receiving module, used to synchronize the trusted NTP reference time from the trusted time system using the NTS protocol two-way authentication and encryption method to obtain a trusted NTP time signal; Trusted time signal selection module, used to select trusted satellite time signals, optical fiber time signals and NTP time signals according to priority; The trusted time stamp verification module is used to implement time stamping and verification.

2. The trusted timestamp device according to claim 1, wherein: The satellite navigation system includes the GPS navigation system, the Beidou navigation system or the Galileo navigation system.

3. The trusted timestamp device according to claim 2, characterized in that: The trusted satellite time signal receiving module captures the carrier phase signal of GPS / Beidou / Galileo from the satellite navigation system, first uses the physical fingerprint extraction algorithm to extract the noise waveform characteristics and generate a feature vector; then compares the feature vector with the pre-stored satellite fingerprint template library, and calculates the similarity entropy value based on the dynamic time warping algorithm to verify the authenticity of the physical identity; then analyzes the navigation message of the signal that has passed the physical authentication, and uses the preset public key to verify the digital signature to confirm the credibility of the logical source; finally, calculates the time deviation of multiple systems, uses the weighted median to output the global trusted time, and automatically isolates the attack signal in the event of an anomaly. Finally, an end-to-end trust chain is established from physical layer feature extraction, protocol layer signature verification to system layer consensus.

4. The trusted timestamp device according to claim 1, wherein: The trusted fiber optic time signal receiving module first performs a two-way handshake with the hardware security module preset by the timing center to exchange a one-time ECDH session key. Only devices with valid certificates are allowed to continue communicating, blocking illegal injection. Then, the received 1PPS+TOD frame is decrypted using the session key for AES-GCM and the MAC is verified. If the MAC match fails, it is considered tampering, immediately discarded and an alarm is issued; then, the phase difference between the local clock and the rising edge of the 1PPS is measured through a time-to-digital converter, and the Kalman filter is used to dynamically estimate the drift and adjust the local OCXO in real time.

5. The trusted timestamp device according to claim 1, wherein: The trusted NTP time signal receiving module first establishes a tunnel with a trusted NTP server. The server presents a certificate for verification of validity period, chain trust and CRL / OCSP status, and returns the certificate to complete two-way verification, blocking the forgery of NTP time sources. Subsequently, HKDF is used to derive an AES-GCM session key, NTP messages are added with NTSCookie and HMAC-SHA256 verification, and the timestamp field is encrypted and attached with an authentication tag. The receiving end decrypts and verifies in real time. If an abnormality occurs, an alarm is immediately issued and the reception of NTP time signals is stopped.

6. The trusted timestamp device according to claim 1, wherein: When multiple time signals are available at the same time, the trusted time signal selection module selects a trusted time signal according to the priority of the optical fiber time signal, NTP time signal and satellite time signal from high to low as the time used for stamping; when a single time signal is available, it is directly used as the time used for stamping.

Citation Information

Patent Citations

  • Method for authenticating and validating electronic data

    CN103152182A

  • NTP protocol enhanced information processing system and method based on national cryptographic algorithm

    CN111106928A

  • Time synchronization method and system based on multiple network systems and medium

    CN113904747A

  • High-precision time synchronization device and method based on satellite common view and PPP

    CN115801174A

  • Space-time signal isolation protection method and system

    CN119475339A