Trusted timestamping device
By employing a multi-signal reception and verification mechanism, the problem of untrustworthiness of traditional timestamp devices is solved, enabling the widespread application of trusted timestamps, improving the credibility and compliance of timestamps, and supporting trusted timestamp services in multiple fields.
Patent Information
- Application Number
- CN202511247351.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-03
- Publication Date
- 2025-11-28
- Estimated Expiration
- 2045-09-03
AI Technical Summary
Traditional timestamp devices rely on untrusted network and satellite times, making them vulnerable to attacks and tampering, which undermines the credibility of timestamps and makes them difficult to widely apply in critical fields.
The system employs a trusted satellite time signal receiving module, a trusted fiber optic time signal receiving module, a trusted NTP time signal receiving module, and a trusted time signal selection module. Through signal identification and encryption verification, the system ensures the reliability of the received time signal. Combined with a trusted time stamp verification module, the system achieves the reliability and compliance of the timestamp.
To ensure the credibility of the time used for stamping, enhance the application value and legal acceptance rate of timestamps, reduce the risk of disputes, strengthen cross-industry compatibility, and support a trusted time infrastructure for the digital economy and judicial evidence preservation.
Smart Images

Figure CN120751384B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of trusted time technology, and particularly to a trusted time stamp device. BACKGROUND
[0002] In critical fields such as medical, judicial, financial, etc., the authenticity, integrity and legal effect of electronic data are highly dependent on the authentication of "time dimension", that is, the trusted proof of "when the data is generated / modified". The traditional time stamp device realizes this authentication function by stamping time on electronic data, and the workflow is as follows: receiving satellite or network time from external time source, which is used to stamp time on target data, and the stamping result is returned to the user and stored locally, and a typical application scheme is shown in Figure 1
[0003] The traditional time stamp device mainly relies on network time based on network time protocol (NTP) or satellite time based on satellite navigation system (such as GPS / Beidou), but their credibility is seriously flawed. In terms of network time, NTP cannot ensure time credibility, and it is not confirmed whether the source of NTP time is credible, and NTP protocol uses clear text transmission of time information, lacks encryption authentication mechanism, and is vulnerable to man-in-the-middle attack (MITM) and delay injection attack, such as attackers can fake time data by tampering with NTP service response. In terms of satellite time, although satellite time service provides high time accuracy, but they are vulnerable to signal spoofing and interference and other security risks. According to the data of ION GNSS+2021 conference, the success probability of commercial GPS receiver suffering from spoofing is as high as 80%, and Beidou system receiver also faces similar threats. Once the time reference loses credibility, the time stamp will directly lose the public trust of time evidence, and eventually completely lose the legal effect as time evidence. As an internationally recognized tamper-proof technology, time stamp technology has been applied in many fields, but its value is limited by the untrustworthy time used for stamping. This core defect not only restricts the application boundary of the technology, but also may cause data credibility disputes and even legal risks, making it difficult to fully release the inherent advantages and core value of time stamp technology.
[0004] The untrustworthy time used for stamping by traditional time stamp device is specifically reflected in:
[0005] 1. Untrustworthy network time used for stamping: In the traditional time stamp device using network time source as time reference, the source of NTP server is complex and unknown, and there are a large number of unauthorized time sources. These time sources not only have questionable legitimacy, but also can be changed at will. In addition, since NTP protocol uses clear text transmission in the transmission process, time information is vulnerable to malicious attacks and tampering before reaching the time stamp device, thereby affecting the credibility of the time stamp.
[0006] 2. The problem of counterfeit deception of satellite time signals: traditional time stamp devices lack the ability to identify the authenticity of time signals, leading to the possibility of receiving tampered or counterfeit time information. This problem requires a method to verify the authenticity and integrity of time signals to prevent malicious attackers from creating false signals to impersonate real signals.
[0007] 3. The credibility defect of optical fiber time signal: the traditional time stamp device on the current market has obvious short board in the reception of optical fiber time signal: most devices do not have the ability to receive optical fiber time signal, and a few devices with receiving function also have prominent credibility hidden danger, both lack of identity verification mechanism of optical fiber time source, and cannot distinguish whether the signal comes from legal time node, and do not implement encryption verification on the transmitted time code stream, which makes it difficult to find the tampered signal. This directly leads to the doubt of the authenticity of the received optical fiber time signal, which cannot be used as a credible time reference.
[0008] In summary, the core problem of traditional time stamp device is that the untrustworthy time used for stamping directly leads to the loss of credibility of time stamp as time evidence, making it difficult to be widely accepted in judicial and commercial environment. Therefore, it is urgent to innovate technology to fully realize the technical potential of time stamp, and ensure that it can effectively play the role of time evidence and achieve wide application in digital economy and justice and other fields. SUMMARY
[0009] To solve the problems in the prior art, the purpose of the present application is to provide a credible time stamp device, which can ensure that the time used for stamping is credible.
[0010] To achieve the above-mentioned purpose, the technical scheme adopted by the present application is as follows: a credible time stamp device, comprising: a credible satellite time signal receiving module, a credible optical fiber time signal receiving module, a credible NTP time signal receiving module, a credible time signal selection module and a credible time stamp verification module, wherein:
[0011] The credible satellite time signal receiving module is used for identifying and receiving the time signal provided by the satellite navigation system, and resisting and filtering out the counterfeit or tampered satellite signal through the signal identification mechanism, to obtain the credible satellite time signal;
[0012] The credible optical fiber time signal receiving module is used for identifying and receiving the credible optical fiber time signal from the ground-based time system, to obtain the credible optical fiber time signal;
[0013] The credible NTP time signal receiving module is used for synchronizing the credible NTP reference time from the credible time system in the form of NTS protocol bidirectional identity authentication and encryption, to obtain the credible NTP time signal;
[0014] A trusted time signal selection module is configured to select a trusted satellite time signal, a fiber time signal and an NTP time signal according to priorities.
[0015] A trusted time stamp verification module is configured to implement stamping and verification of time stamps.
[0016] As a further improvement of the application, the satellite navigation system comprises a GPS navigation system, a Beidou navigation system or a Galileo navigation system.
[0017] As a further improvement of the application, the trusted satellite time signal receiving module captures a carrier phase signal from GPS / Beidou / Galileo of the satellite navigation system, first extracts noise waveform features and generates a feature vector by using a physical fingerprint extraction algorithm; then compares the feature vector with a pre-stored satellite fingerprint template library, calculates a similarity entropy value based on a dynamic time warping algorithm to verify the authenticity of the physical identity; then analyzes navigation messages for the signal that passes the physical authentication, checks a digital signature by using a pre-set public key to confirm the trustworthiness of the logical source; finally, calculates a time deviation of multiple systems, adopts a weighted median to output a global trusted time, automatically isolates attack signals in an abnormal state, and finally achieves consensus from physical layer feature extraction, protocol layer signature verification to system layer, thereby constructing an end-to-end trust chain.
[0018] As a further improvement of the application, the trusted fiber time signal receiving module first performs a bidirectional handshake with a hardware security module pre-set by a time service center, exchanges a one-time ECDH session key; only a device carrying a valid certificate is allowed to continue communication, and illegal injection is blocked; then, the received 1PPS+TOD frame is decrypted by using the session key for AES-GCM, and a MAC is checked; if the MAC fails to match, it is regarded as tampering, and is discarded and alarmed immediately; then, a phase difference between a local clock and a rising edge of the 1PPS is measured by using a time-to-digital converter, and a Kalman filter is used to dynamically estimate drift and adjust the local OCXO in real time.
[0019] As a further improvement of the application, the trusted NTP time signal receiving module first establishes a tunnel with a trusted NTP server, the server presents a certificate for checking a validity period, a chain trust and a CRL / OCSP state, and returns the certificate to complete bidirectional verification, and blocks a fake NTP time source; subsequently, an AES-GCM session key is derived by using an HKDF, an NTP packet adds an NTSCookie and an HMAC-SHA256 check, a time stamp field is encrypted and an authentication tag is attached; a receiving end decrypts and verifies in real time, and if an exception occurs, an alarm is given and the receiving of the NTP time signal is stopped.
[0020] As a further improvement of the application, when multiple time signals are available at the same time, the trusted time signal selection module selects the trusted time signal from high to low priority as the time used for stamping according to the optical fiber time signal, the NTP time signal and the satellite time signal; when a single time signal is available, it is directly used as the time used for stamping.
[0021] The trusted time stamp device provided by the application can ensure that the time used for stamping is trusted, which not only makes the time stamp truly have the core function of "time notarization", but also provides the possibility for application in multiple fields: in the field of data right, it becomes the core basis for time definition of intellectual property rights; in the blockchain technology, it strengthens the trusted anchor point of the time dimension on the chain; in big data management, it provides a solid guarantee for the authority of time series data; especially in the judicial evidence scene, it can ensure the acceptance rate and judicial recognition of electronic evidence. Its wide application will promote the time stamp technology from tool-level application to infrastructure-level base, and provide key technical support for the digital economic governance and construction of a trusted data ecosystem in modern society.
[0022] The application has the following beneficial effects:
[0023] 1. Improve the application value of stamped data: the application builds a multiple security system through a satellite / optical fiber / NTP trusted time signal receiving mechanism to solve the defect that the time used for stamping by traditional devices is not trusted. The trusted time receiving mechanism ensures that the time used for stamping is trusted, thereby guaranteeing the application value, credibility and acceptance rate of stamped data in the scene of judicial evidence, financial transactions and the like, and providing high-trusted time stamp services for the fields of data right, blockchain smart contract, cross-border electronic evidence and the like.
[0024] 2. Reduce the controversy and risk of time as electronic evidence: the application relies on log evidence, encryption hash and the like to record the whole process of trusted time from time source identity confirmation, time encryption transmission, to time stamp generation, time stamping and evidence backup, thereby enhancing the self-evident ability of time stamp in dispute resolution and reducing potential risks.
[0025] 3. Improve the continuous service ability of the trusted time stamp device: the application adopts a multiple time source mechanism, i.e., trusted satellite / optical fiber / NTP time signals respectively from a satellite navigation system, a ground-based time system and a trusted time system, which are identified and received by a special time signal receiving module. The multiple trusted time input sources are mutually checked and automatically switched in an abnormal state, thereby avoiding the service stop phenomenon caused by failure of a single time source and significantly improving the continuity and risk resistance of time stamp service.
[0026] 4. Enhance the cross-industry compatibility of the time stamp device: Most of the time stamp devices on the market do not have the access capability of the optical fiber time signal, and some devices do not fully comply with the national cryptography industry standard, thereby limiting the application in the government and financial field scenarios with higher compliance requirements. In contrast, the trusted time stamp device of the present application not only can receive the optical fiber time signal, but also strictly complies with GM / T 0033 "Time stamp interface specification" and GM / T 0028 "Security technology requirements for cryptographic modules", ensuring its compatibility with the cryptography system in the government, finance and other fields. This design greatly reduces the adaptation cost of cross-industry applications and meets the time stamp service needs of high-compliance scenarios.
[0027] The above effects are due to the satellite / optical fiber / NTP time receiving module design, trusted time signal selection mechanism and other technical features, which achieve a technical breakthrough in time stamp reliability and provide key support for the construction of digital economy trusted time infrastructure. BRIEF DESCRIPTION OF DRAWINGS
[0028] Figure 1 A schematic diagram of a typical application scheme of a traditional time stamp device;
[0029] Figure 2 A structural schematic diagram of a trusted time stamp device in an embodiment of the present application;
[0030] Figure 3 A schematic diagram of a trusted satellite time signal receiving mechanism in an embodiment of the present application;
[0031] Figure 4 A schematic diagram of a trusted optical fiber time signal receiving mechanism in an embodiment of the present application;
[0032] Figure 5 A schematic diagram of a trusted NTP time signal receiving mechanism in an embodiment of the present application. DETAILED DESCRIPTION
[0033] The embodiments of the present application will be described in detail below with reference to the accompanying drawings.
[0034] Embodiment:
[0035] As shown in the figure, a trusted time stamp device can receive satellite time signals, trusted optical fiber time signals and trusted NTP time signals, and then pass through a signal optimization mechanism to ensure the time used for stamping is trusted, which specifically includes: Figure 2
[0036] 1. Trusted satellite time signal receiving module: The satellite signal discrimination module of the trusted timestamp device is specially designed to identify and receive time signals provided by satellite navigation systems (such as GPS, Beidou, and Galileo). This module effectively resists and filters out counterfeit or tampered satellite signals through signal discrimination mechanisms, ensuring the credibility of the received time information.
[0037] 2. Trusted fiber time signal receiving module: The trusted fiber time signal receiving module of the trusted timestamp device discriminates and receives trusted fiber time signals from national time center ground-based time systems, ensuring the credibility of the time source and avoiding "contamination of time used for stamping".
[0038] 3. Trusted NTP time signal receiving module: The trusted NTP time signal receiving module of the trusted timestamp device synchronizes trusted NTP reference time from a trusted time system in a bidirectional authentication and encrypted manner using NTS protocol, ensuring the credibility and integrity of the received NTP time.
[0039] 4. Trusted time signal selection module: The trusted time signal selection module of the trusted timestamp device implements priority selection of satellite time signals, fiber time signals, and NTP time signals.
[0040] 5. Trusted time stamp verification module. The trusted time stamp verification module of the trusted timestamp device implements the functions of time stamping and verification required by the national cryptographic industry standards GM / T 0033 "Time Stamp Interface Specification" and GM / T 0028 "Security Technical Requirements for Cryptographic Modules".
[0041] The trusted timestamp device of the present embodiment receives signals from three types of different time sources: trusted satellite time signals provided by satellite navigation systems, trusted fiber time signals provided by ground-based time systems, and trusted NTP time signals provided by a trusted time system. These signals are received, processed, and analyzed by respective receiving modules to ensure the accuracy and credibility of the time information. Then, the trusted time signal selection module selects the trusted time signal. Next, the trusted time stamping and verification module of the device further applies time information, such as electronic data trusted time stamping, etc. The entire device aims to provide a high-credibility time stamping service suitable for application scenarios that require trusted time stamping and verification.
[0042] The trusted timestamp device, which receives trusted satellite time signals, trusted time fiber signals, and trusted NTP time signals, and selects the received trusted time signals, includes the following parts:
[0043] 1. Trusted satellite time signal receiving mechanism;
[0044] 2. Trusted fiber time signal receiving mechanism;
[0045] 3. Trusted NTP time signal receiving mechanism;
[0046] 4. Trusted time signal selection mechanism;
[0047] 5. Trusted time stamp verification mechanism.
[0048] As shown in Figure 3 , the trusted satellite time signal receiving mechanism captures the carrier phase signals of GPS / Beidou / Galileo from the satellite navigation system through the trusted satellite time signal receiving module. First, the physical fingerprint extraction algorithm is used to extract the noise waveform features and generate a 128-dimensional feature vector. Then, it is compared with the pre-stored 32 satellite fingerprint template library, and the similarity entropy value (threshold ≤0.15) is calculated based on the dynamic time warping algorithm to verify the physical identity authenticity. Then, the navigation message of the physically authenticated signal is parsed, and the digital signature (RSA-3072 / SM2) is verified by the pre-set public key to confirm the logical source credibility. Finally, the multi-system time deviation (threshold ±50ns) is calculated, the weighted median (weight 4:3:3) is used to output the global trusted time, and the attack signal is automatically isolated in abnormality. Finally, from the physical layer feature extraction, protocol layer signature verification to system layer consensus, an end-to-end trust chain is constructed.
[0049] As shown in Figure 4 , the trusted optical fiber time signal receiving mechanism receives the optical fiber time signal from the ground-based time service system through the identity authentication, credibility verification and precision calibration functions of the trusted optical fiber time signal receiving module. First, after the optical fiber module is powered on, it performs a two-way TLS1.3 handshake with the pre-set hardware security module (HSM) of the national time service center, and exchanges a one-time ECDH session key. Only devices carrying valid certificates are allowed to continue communication, blocking illegal injection. Then, the received 1PPS+TOD frame is decrypted using the session key AES-GCM, and the 256-bit MAC is verified. If the MAC fails to match, it is considered tampered with and discarded immediately. Next, the phase difference between the local clock and the rising edge of 1PPS is measured by the TDC (time-to-digital converter) built-in FPGA, and the Kalman filter is used to dynamically estimate the drift and adjust the local OCXO in real time. The calibration residual is kept within ±5ns to ensure that the output time reference is long-term stable and cannot be disturbed or deceived.
[0050] As shown in Figure 5As shown, the trusted NTP time signal receiving mechanism realizes bidirectional identity authentication and end-to-end encryption through the trusted NTP time signal receiving module using the NTS protocol. First, the device establishes a TLS 1.3 tunnel with the trusted NTP server, the server presents an X.509 certificate for the device to check the validity period, chain trust and CRL / OCSP status, and the device also returns the certificate to complete bidirectional verification and block fake NTP time sources. Subsequently, both parties use HKDF to derive an AES-GCM session key, the NTP message adds an NTS cookie and an HMAC-SHA256 check, and the timestamp field is encrypted and attached with an authentication tag; the receiving end decrypts and verifies in real time, and if there is an exception, it immediately alarms and stops receiving the NTP time signal, thereby ensuring that the time source is real and the transmission link is tamper-proof.
[0051] The trusted time signal selection mechanism realizes real-time receiving, analysis and intelligent selection of satellite, optical fiber and NTP multi-channel signals through the trusted time signal selection module: for the case where multiple time signals are available at the same time, the trusted time signal is selected as the time used for stamping from high to low priority according to the optical fiber time signal, the NTP time signal and the satellite time signal; for the case where a single time signal is available, it is directly used as the time used for stamping.
[0052] The trusted time stamping and verification mechanism supports the stamping, verification and log recording functions required by the second level of GM / T 0033 "Time Stamp Interface Specification" and GM / T 0028 "Cryptographic Module Security Technical Requirements".
[0053] The trusted time stamping device of the application builds a trusted time stamping technology system through the above five mechanisms: the first four mechanisms ensure that the time used for stamping is trusted through the identification and selection of satellite, optical fiber and NTP multi-source signals; the fifth mechanism adapts to the national cryptographic standards through compliance functions, and overall meets the high trust and high compliance requirements of time reference in the fields of government affairs and finance. These mechanisms effectively guarantee the high-trust time stamping service and improve the legal acceptance rate of electronic evidence.
[0054] The above-described embodiments only express the specific implementation of the present application, and the description is more specific and detailed, but it cannot be understood as a limitation on the scope of the patent of the present application. It should be noted that for ordinary skilled persons in the art, without departing from the concept of the present application, a number of modifications and improvements can be made, which are within the scope of protection of the present application.
Claims
1. A trusted timestamping apparatus, characterized in that, The application relates to a trusted time signal receiving device. The trusted time signal receiving device comprises a trusted satellite time signal receiving module, a trusted optical fiber time signal receiving module, a trusted NTP time signal receiving module, a trusted time signal selection module and a trusted time stamp verification module, wherein: The trusted satellite time signal receiving module is used for identifying and receiving a time signal provided by a satellite navigation system, resisting and filtering out a fake or tampered satellite signal through a signal discrimination mechanism, and obtaining a trusted satellite time signal; the trusted satellite time signal receiving module captures a carrier phase signal of GPS / Beidou / Galileo from the satellite navigation system, firstly extracts noise waveform features and generates a feature vector by using a physical fingerprint extraction algorithm; then the feature vector is compared with a pre-stored satellite fingerprint template library, a similarity entropy value is calculated based on a dynamic time warping algorithm to verify the physical identity authenticity; then the signal of which the physical authentication is passed is parsed for navigation text, a digital signature is verified by using a preset public key to confirm the logical source credibility; finally, a global trusted time is output by using a weighted median number, attack signals are automatically isolated in an abnormal state, and finally, an end-to-end trust chain is constructed from physical layer feature extraction, protocol layer signature verification to system layer consensus. The trusted optical fiber time signal receiving module is used for identifying and receiving a trusted optical fiber time signal from a ground-based time system, and obtaining a trusted optical fiber time signal; the trusted optical fiber time signal receiving module firstly performs a two-way handshake with a hardware security module preset in a time center, and exchanges an ECDH session key; only a device carrying a valid certificate is allowed to continue communication, and illegal injection is blocked; then, the received 1PPS+TOD frame is decrypted by using the session key for AES-GCM, and a MAC is verified; if the MAC fails to match, it is regarded as tampering, and is discarded and alarmed immediately; then, a Kalman filter is used to dynamically estimate the drift and real-timely adjust a local OCXO by measuring the phase difference between a local clock and a 1PPS rising edge. The trusted NTP time signal receiving module is used for synchronizing a trusted NTP reference time from a trusted time system in a bidirectional identity authentication and encrypted mode through an NTS protocol, and obtaining a trusted NTP time signal; the trusted NTP time signal receiving module firstly establishes a tunnel with a trusted NTP server, the server presents a certificate for checking a validity period, a chain trust and a CRL / OCSP state, and returns the certificate to complete bidirectional verification, and blocks a fake NTP time source; subsequently, an AES-GCM session key is derived by using an HKDF, an NTP packet is added with an NTS cookie and an HMAC-SHA256 verification, a time stamp field is encrypted and is attached with an authentication label; the receiving end is real-timely decrypted and verified, and if an exception occurs, an alarm is given and the receiving of the NTP time signal is stopped; The trusted time signal selection module is used for selecting a trusted satellite time signal, an optical fiber time signal and an NTP time signal according to priorities. The trusted time stamp verification module is used for realizing time stamp stamping and verification.
2. The trusted timestamping device of claim 1, wherein, The satellite navigation system comprises a GPS navigation system, a Beidou navigation system or a Galileo navigation system.
3. The trusted timestamping device of claim 1, wherein, When multiple time signals are available at the same time, the trusted time signal selection module selects the trusted time signal from high to low priority as the time used for stamping according to the fiber time signal, the NTP time signal and the satellite time signal; when a single time signal is available, it is directly used as the time used for stamping.
Citation Information
Patent Citations
NTP protocol enhanced information processing system and method based on national cryptographic algorithm
CN111106928A
Space-time signal isolation protection method and system
CN119475339A
Cited By
Trusted time service device and method
CN122293445A