Time synchronization timing system and method based on unidirectional isolation
By combining multi-source time acquisition and unidirectional isolation modules with optical transmission and national cryptographic algorithms, an end-to-end trusted chain is constructed, solving the security and efficiency problems of time synchronization in classified networks and achieving high-precision and high-availability time synchronization.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-01-27
- Publication Date
- 2026-03-31
AI Technical Summary
Traditional time synchronization schemes suffer from security and synchronization efficiency issues in classified networks. Existing wireless optical one-way time synchronization systems are vulnerable and have limited resistance to replay attacks, making it difficult to provide a unified, reliable, and high-precision trusted and secure standard time synchronization source.
By employing a multi-source time acquisition module, a one-way isolation module, a secure timekeeping processing module, and a trusted time distribution module, combined with optical one-way transmission, national cryptographic algorithms, and SM2 digital signatures, an end-to-end trusted chain is constructed to achieve hardware-level optical fiber one-way transmission and dynamic key management.
While ensuring microsecond-level accuracy, it significantly improves the availability and maintainability of the system, providing a time synchronization infrastructure with extremely high security, high accuracy and high availability for high-security environments.
Smart Images

Figure CN121770664A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the fields of information security and time synchronization technology, specifically a time synchronization system and method based on one-way isolation. Background Technology
[0002] In the field of time synchronization technology, time synchronization systems ensure the orderly operation of nodes and the consistency of log data in a distributed system by aligning local device clocks with authoritative standard time sources. The basic principle is to use a high-precision clock source as a reference, transmit time information through wired or wireless channels, and use specific protocols such as NTP or PTP for synchronization. However, in high-risk scenarios such as classified networks and industrial control, traditional time synchronization solutions face severe challenges. For example, while satellite time synchronization offers high accuracy, it is susceptible to signal interference and spoofing attacks; network time synchronization relies on protocol stacks and is vulnerable to penetration; and while purely physically isolated portable clock synchronization solutions offer excellent security, they are inefficient due to the need for manual handling and struggle to achieve real-time synchronization.
[0003] Meanwhile, due to the sensitivity of the information carried, classified networks employ complete physical isolation security measures from satellite (or internet) communications. While this ensures the security of the internal network, it also prevents them from utilizing public time synchronization resources. Classified networks often consist of heterogeneous devices such as various operating systems, servers, firewalls, and intrusion detection systems. In the event of a security incident, investigators must extract logs from each system for correlation analysis. If the times of these systems are not calibrated and differ, it will significantly increase the complexity of log analysis, affecting the accuracy and efficiency of security incident tracing, and may even lead to erroneous conclusions.
[0004] Existing technologies for secure time synchronization innovatively combine wireless time synchronization with unidirectional optical transmission based on wireless optical time synchronization systems. By utilizing the physical characteristics of optical signals to block reverse data flow, they meet information security isolation requirements. However, their core reliance on external wireless signals as the sole time source makes them inherently vulnerable. These signals are susceptible to environmental or malicious interference, and their encryption mechanism uses timestamp-based symmetric keys, resulting in a relatively static key generation method and limited ability to resist replay attacks. Therefore, there is an urgent need to develop a dedicated time synchronization system with independent controllability and security protection functions to provide a unified, reliable, and high-precision trusted secure standard time synchronization source for classified networks. Summary of the Invention
[0005] The purpose of this invention is to provide a time synchronization system and method based on one-way isolation, addressing the aforementioned problems.
[0006] The technical solution adopted in this invention is as follows: a time synchronization and timing system based on one-way isolation, comprising a multi-source time acquisition module, a one-way isolation module, a secure timekeeping processing module, and a trusted time distribution module;
[0007] The multi-source time acquisition module is located on a non-classified external network terminal. It is used to receive multi-source time signal data, verify the integrity of the signal data, and then forward it to the one-way isolation module.
[0008] The one-way isolation module is used to receive time data sent by the multi-source time acquisition module, perform encryption, encoding, modulation and decryption of the time data, and forward it to the secure timekeeping processing module;
[0009] The secure timekeeping processing module is located on the classified intranet and is used to receive decrypted time data sent by the one-way isolation module, perform secondary verification on the time data, and provide the verified secure timekeeping signal to the trusted time distribution module.
[0010] The trusted time distribution module is located at the classified intranet end and is used to distribute time signals to various devices on the classified intranet.
[0011] Optionally, the multi-source time acquisition module receives signals from BeiDou satellites and / or NTSC, and has a built-in local atomic clock. The multi-source time acquisition module performs digital signature verification and integrity verification on the time signal data received from BeiDou satellites and / or NTSC.
[0012] Optionally, the multi-source time acquisition module is equipped with a Trusted Cryptography (TCM) submodule, which is used to generate the key required for encryption.
[0013] Optionally, the unidirectional isolation module includes an optical unidirectional transmitting module and an optical unidirectional receiving module;
[0014] The optical one-way transmitting module is located on a non-classified external network terminal, used to receive time data sent by the multi-source time acquisition module, perform encryption, encoding and modulation processing, and transmit it unidirectionally to the optical one-way receiving module;
[0015] The optical one-way receiving module is located on the classified intranet and is used to decrypt the time data sent by the optical one-way transmitting module and transmit it unidirectionally to the secure timekeeping processing module.
[0016] Optionally, the optical one-way transmitting module performs SM2 signature on the time data using the private key in the trusted cryptographic submodule TCM, and the optical one-way receiving module verifies the transmitted time data using the public key in the trusted cryptographic submodule TCM.
[0017] Furthermore, it also includes a security management module, which is located on the classified intranet and is used to receive security events from the optical one-way receiving module, the secure timekeeping processing module, and the trusted time distribution module, and adjust the isolation strategy.
[0018] Optionally, the secure timekeeping processing module receives verified integrity and trusted source time data from the optical one-way receiving module, and performs timekeeping and secondary security processing on this basis. The timekeeping and secondary security processing includes trusted execution environment isolation protection and SM2-based asymmetric key negotiation.
[0019] Optionally, the trusted execution environment isolation protection divides the confidential intranet where the secure timekeeping processing module is located into a secure part and a normal part. The secure part contains the decrypted raw time data received by the secure timekeeping processing module, the timekeeping discipline core algorithm, and the driver and control program. The normal part contains the management interface of the secure timekeeping processing module. When the timekeeping algorithm needs to be executed, the application in the normal part calls the instruction through the predefined security monitor to pass the request and parameters to the secure part. After the secure part finishes processing, it returns the result through the same channel.
[0020] The SM2-based asymmetric key negotiation establishes a secure channel between the secure timekeeping processing module and the time distribution module for synchronous transmission of keys or sensitive instructions. The secure timekeeping processing module has a built-in key that matches the trusted cryptographic submodule TCM, and the secure timekeeping processing module can provide the public key to the trusted time distribution module.
[0021] This application, based on a one-way isolated time synchronization system, also provides a one-way isolated time synchronization method, including the following steps:
[0022] S1. Multi-source time acquisition: The multi-source time acquisition module receives signals from BeiDou satellites, NTSC, and atomic clocks in parallel, and calculates the time deviation of each source to obtain time data;
[0023] S2. One-way transmission encoding: The one-way isolation module encapsulates time data into a fixed format and uses an algorithm to encrypt and generate a dynamic session key;
[0024] S3. Secure reception verification: The secure timekeeping processing module receives the time data sent by the one-way isolation module and verifies the SM3 hash value.
[0025] S4. Timekeeping and Distribution: The trusted time distribution module generates NTP or PTP protocol messages from time data and distributes them to various devices on the confidential intranet.
[0026] Furthermore, in S2, the optical one-way transmitting module located on the non-classified external network end in the one-way isolation module will encapsulate time data in a fixed format, convert it into a 1310nm optical pulse signal, and transmit it unidirectionally to the optical one-way receiving module on the classified internal network end.
[0027] The beneficial effects of the present invention include at least one of the following;
[0028] 1. The time synchronization system based on unidirectional isolation, while inheriting the security features of physical isolation, has undergone multi-dimensional innovation and enhancement. The system adopts a multi-source time acquisition architecture, integrating satellite, network, and local atomic clock signals, and intelligently selects and switches between them through a dynamic confidence algorithm, fundamentally avoiding the risk of single-point failure.
[0029] 2. Regarding the one-way isolation mechanism, not only is hardware-level one-way fiber optic transmission achieved, completely eliminating reverse leakage in electrical circuits, but also the national cryptographic algorithm system and custom one-way protocol are introduced at the data link layer and protocol layer. Combined with PUF dynamic keys and SM2 digital signatures, an end-to-end trusted chain is constructed from time source authentication, transmission encryption to distribution auditing.
[0030] 3. Through fully automated optical transmission and intelligent timekeeping algorithms, the availability and maintainability of the system are significantly improved while ensuring microsecond-level accuracy, providing a time synchronization infrastructure solution with extremely high security, high accuracy and high availability for high-security environments. Attached Figure Description
[0031] Figure 1 This is a schematic diagram of a time synchronization system framework based on unidirectional isolation;
[0032] Figure 2 Here is a flowchart of a time synchronization method based on one-way isolation;
[0033] Figure 3 This is an electronic frame diagram;
[0034] Figure 4 This is an example diagram of a time synchronization system based on one-way isolation.
[0035] Figure 5 This is a schematic diagram of the structure of an electronic device. Detailed Implementation
[0036] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. The components of the embodiments of the present invention described and shown in the accompanying drawings can generally be arranged and designed in various different configurations.
[0037] Therefore, the following detailed description of the embodiments of the invention provided in the accompanying drawings is not intended to limit the scope of the claimed invention, but merely to illustrate selected embodiments of the invention. All other embodiments obtained by those skilled in the art based on the embodiments of the invention without inventive effort are within the scope of protection of the invention.
[0038] It should be noted that, unless otherwise specified, the embodiments and features described in this invention can be combined with each other.
[0039] like Figure 1 As shown, a time synchronization and timing system based on one-way isolation includes a multi-source time acquisition module, a one-way isolation module, a secure timekeeping processing module, and a trusted time distribution module.
[0040] The multi-source time acquisition module is located on a non-classified external network terminal. It is used to receive multi-source time signal data, verify the integrity of the signal data, and then forward it to the one-way isolation module.
[0041] The one-way isolation module is used to receive time data sent by the multi-source time acquisition module, perform encryption, encoding, modulation and decryption of the time data, and forward it to the secure timekeeping processing module;
[0042] The secure timekeeping processing module is located on the classified intranet and is used to receive decrypted time data sent by the one-way isolation module, perform secondary verification on the time data, and provide the verified secure timekeeping signal to the trusted time distribution module.
[0043] The trusted time distribution module is located at the classified intranet end and is used to distribute time signals to various devices on the classified intranet.
[0044] Meanwhile, the multi-source time acquisition module receives signals from BeiDou satellites and / or NTSC. The multi-source time acquisition module has a built-in local atomic clock and performs digital signature verification and integrity check on the time signal data received from BeiDou satellites and / or NTSC.
[0045] The purpose of this design is to innovate and enhance the unidirectional isolation-based time synchronization system in multiple dimensions while inheriting the security features of physical isolation. The system adopts a multi-source time acquisition architecture, integrating satellite, network, and local atomic clock signals, and intelligently selects and switches between them through a dynamic confidence algorithm, fundamentally avoiding the risk of single-point failure.
[0046] Meanwhile, in this embodiment, the multi-source time acquisition module is equipped with a Trusted Cryptography (TCM) submodule, which is used to generate the key required for encryption.
[0047] Furthermore,
[0048] The unidirectional isolation module includes an optical unidirectional transmitting module and an optical unidirectional receiving module;
[0049] The optical one-way transmitting module is located on a non-classified external network terminal, used to receive time data sent by the multi-source time acquisition module, perform encryption, encoding and modulation processing, and transmit it unidirectionally to the optical one-way receiving module;
[0050] The optical one-way receiving module is located on the classified intranet and is used to decrypt the time data sent by the optical one-way transmitting module and transmit it unidirectionally to the secure timekeeping processing module.
[0051] The purpose of this design is to add a one-way protocol design to the protocol layer, a one-way authentication mechanism to the cryptographic layer, and a one-way separation of permissions to the management layer, on the basis of the existing single physical layer.
[0052] In this embodiment, the optical one-way transmitting module performs SM2 signature on the time data using the private key in the Trusted Cryptographic Submodule (TCM), and the optical one-way receiving module verifies the transmitted time data using the public key in the TCM. The secure timekeeping processing module receives the verified integrity and trusted source time data from the optical one-way receiving module and performs timekeeping and secondary security processing on this basis. This timekeeping and secondary security processing includes trusted execution environment isolation protection and SM2-based asymmetric key negotiation. Furthermore, the trusted execution environment isolation protection divides the confidential intranet where the secure timekeeping processing module is located into a secure part and a normal part, wherein the secure part includes the secure timekeeping processing module... The block receives decrypted raw time data, the time-keeping discipline core algorithm, and the driver and control program. The general part includes the management interface of the secure time-keeping processing module. When the time-keeping algorithm needs to be executed, the application in the general part calls the instruction through the predefined security monitor, passing the request and parameters to the secure part. After the secure part finishes processing, it returns the result through the same channel. The SM2-based asymmetric key negotiation establishes a secure channel between the secure time-keeping processing module and the time distribution module for synchronous transmission of keys or sensitive instructions. The secure time-keeping processing module has a built-in key that matches the trusted cryptographic submodule TCM, and the secure time-keeping processing module can provide the public key to the trusted time distribution module.
[0053] like Figure 3 and Figure 4 As shown, this embodiment provides a hardware architecture and specific application scenario of a time synchronization system based on one-way isolation. It includes a one-way isolated secure time synchronization device and a secure time synchronization server set in a classified intranet. In this scenario, the two complete one-way time synchronization through a portable time synchronization clock.
[0054] In the secure time synchronization device section, a standard time source is obtained through BeiDou satellite communication. The device's dedicated synchronization software and discipline algorithm are used to perform high-precision time synchronization and atomic clock discipline on the embedded portable time synchronization clock. Its main functions in the classified network's dedicated time synchronization system are acquiring the standard time source, managing the entire lifecycle of one-way authentication keys, and high-precision atomic clock discipline. It also enables secure timekeeping and operation through the physical transport of the portable time synchronization clock. Furthermore, it is designed based on the domestically developed Loongson 2K2000 CPU. The Beidou antenna provides satellite signal reception for the Beidou timing module; the main function of the Beidou timing module is to acquire a high-precision time source; the 2K main control board reads the time information of the Beidou satellite through the serial port, and also provides a user interface for the device; the LED light board provides various function status indicators for the safety time synchronization instrument, and the current working status of the device can be clearly known through the status of the LED lights, controlled by the 2K main control board; the function key board provides a human-machine input interface for the device; the LCD screen is the user display interface, which can display more detailed and comprehensive related functions and time information; the power module and power filter provide a stable and reliable DC12V (20W) input to power the device.
[0055] The secure time synchronization server is a high-precision, high-concurrency, and multifunctional secure standard time synchronization device that can be deployed in classified network systems as a standard time synchronization source. It supports multiple time synchronization protocols, including NTP, PTP, 1PPS, and PTOD output. The high-precision time source of the time synchronization server is obtained solely from a dedicated portable time synchronization clock for classified networks through one-way isolated secure time synchronization. The secure time synchronization server uses a high-precision atomic clock for secure timekeeping, ensuring high-precision time synchronization of all devices within the classified network, and supports two 10 / 100 / 1000M adaptive Ethernet ports. The time synchronization server has a web interface for management, allowing users to view and configure the device status via the web interface. The secure time synchronization server utilizes a built-in trusted cryptographic module to securely receive one-way isolated time synchronization, maintain secure timekeeping, and synchronize trusted and secure standard time with various devices in the classified intranet using the NTP / PTP protocol. Its 2K main control board can provide standard time to various terminal devices interconnected with the secure time synchronization server via the NTP / PTP protocol, ensuring time synchronization among all devices. The server clock board serves as the reference time source for the secure time synchronization server. The one-way isolation module ensures the one-way nature of the standard time input to the secure time synchronization server, and, in conjunction with a proprietary protocol, protects against external malicious attacks. The LED light board, function key board, and LCD screen are all human-machine interface input / output modules for the secure time synchronization server. The power module and power filter provide a stable and reliable DC12V (30W) input to power the device.
[0056] like Figure 2As shown, in this embodiment, a time synchronization method based on a one-way isolated time synchronization system is also provided, including the following steps:
[0057] S1. Multi-source time acquisition: The multi-source time acquisition module receives signals from BeiDou satellites, NTSC, and atomic clocks in parallel, and calculates the time deviation of each source to obtain time data;
[0058] S2. One-way transmission encoding: The one-way isolation module encapsulates time data into a fixed format and uses an algorithm to encrypt and generate a dynamic session key;
[0059] S3. Secure reception verification: The secure timekeeping processing module receives the time data sent by the one-way isolation module and verifies the SM3 hash value.
[0060] S4. Timekeeping and Distribution: The trusted time distribution module generates NTP or PTP protocol messages from time data and distributes them to various devices on the confidential intranet.
[0061] Among them, the optical one-way transmitting module located on the non-classified external network end in the one-way isolation module will encapsulate time data in a fixed format, convert it into a 1310nm optical pulse signal, and transmit it unidirectionally to the optical one-way receiving module on the classified internal network end.
[0062] The purpose of this design is to not only achieve hardware-level unidirectional fiber optic transmission and completely eliminate reverse leakage in electrical circuits at the unidirectional isolation mechanism, but also to introduce national cryptographic algorithms and custom unidirectional protocols at the data link and protocol layers. Combined with PUF dynamic keys and SM2 digital signatures, an end-to-end trusted chain is constructed from time source authentication and transmission encryption to distribution auditing. Furthermore, through fully automated optical transmission and intelligent timekeeping algorithms, the availability and maintainability of the system are significantly improved while ensuring microsecond-level accuracy. This provides a time synchronization infrastructure solution with extremely high security, high accuracy, and high availability for high-security environments.
[0063] In one embodiment of this application, the electronic device further includes a bus and a computer program stored in the memory and executable on the processor, such as a one-way isolated time synchronization program.
[0064] Figure 5 Only an electronic device with memory and processor is shown. Those skilled in the art will understand that the structure shown does not constitute a limitation on the electronic device and may include fewer or more components than shown, or combine certain components, or have different component arrangements.
[0065] Combination Figure 5The memory in the electronic device stores a plurality of computer-readable instructions to implement a one-way isolated time synchronization method, and the processor can execute the plurality of instructions to implement it.
[0066] Specifically, the processor's implementation method for the above instructions can be found in the description of the relevant steps in the corresponding embodiment of the figure, and will not be repeated here.
[0067] Those skilled in the art will understand that the schematic diagram is merely an example of an electronic device and does not constitute a limitation on the electronic device. The electronic device may be a bus-type structure or a star-type structure. The electronic device may also include more or fewer other hardware or software than shown in the diagram, or different component arrangements. For example, the electronic device may also include input / output devices, network access devices, etc.
[0068] It should be noted that electronic devices are merely examples. Other existing or future electronic products that are suitable for this application should also be included within the scope of protection of this application and are incorporated herein by reference.
[0069] The memory includes at least one type of readable storage medium, which can be non-volatile or volatile. The readable storage medium includes flash memory, portable hard drives, multimedia cards, card-type memory (e.g., SD or DX memory), magnetic storage, magnetic disks, optical disks, etc. In some embodiments, the memory can be an internal storage unit of an electronic device, such as a portable hard drive. In other embodiments, the memory can be an external storage device of the electronic device, such as a plug-in portable hard drive, a smart media card (SMC), a secure digital (SD) card, a flash card, etc. The memory can be used not only to store application software and various types of data installed on the electronic device, such as one-way isolated time synchronization code, but also to temporarily store data that has been output or will be output.
[0070] In some embodiments, a processor can be composed of integrated circuits, such as a single packaged integrated circuit or multiple integrated circuits packaged with the same or different functions. This includes combinations of one or more central processing units (CPUs), microprocessors, digital processing chips, graphics processors, and various control chips. The processor is the control unit of an electronic device, connecting various components of the device through various interfaces and lines. It executes programs or modules stored in the memory (e.g., executing unidirectional isolated time synchronization programs) and calls data stored in the memory to perform various functions and process data within the electronic device.
[0071] The processor executes the operating system of the electronic device and various installed applications. The processor executes the applications to implement the steps in the above-described embodiments of the unidirectional isolated time synchronization method, such as the steps shown in the figure.
[0072] For example, the computer program may be divided into one or more modules / units, which are stored in the memory and executed by the processor to complete this application. The one or more modules / units may be a series of computer-readable instruction segments capable of performing a specific function, which describe the execution process of the computer program in an electronic device. For example, the computer program may be divided into a receiving module, a preprocessing module, a projection module, and a determining module.
[0073] The integrated unit implemented as a software functional module described above can be stored in a computer-readable storage medium. This software functional module, stored in a storage medium, includes several instructions to cause a computer device (which may be a personal computer, computer equipment, or network device, etc.) or processor to execute portions of the unidirectional isolated time synchronization method described in the various embodiments of this application.
[0074] When modules / units integrated into an electronic device are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the methods of the above embodiments can also be implemented by a computer program instructing related hardware devices. The computer program can be stored in a computer-readable storage medium, and when executed by a processor, it can implement the steps of the various method embodiments described above.
[0075] This application provides a one-way isolated time synchronization method, which can be applied to one or more electronic devices. An electronic device is a device that can automatically perform numerical calculations and / or information processing according to pre-set or stored instructions. Its hardware includes, but is not limited to, microprocessors, application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), digital signal processors (DSPs), embedded devices, etc.
[0076] The computer program includes computer program code, which may be in the form of source code, object code, executable file, or some intermediate form. The computer-readable medium may include: any entity or device capable of carrying the computer program code, recording media, USB flash drive, portable hard drive, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory, and other memory.
[0077] Furthermore, the computer-readable storage medium may primarily include a stored program area and a stored data area, wherein the stored program area may store the operating system, an application program required for at least one function, etc.; and the stored data area may store data created based on the use of blockchain nodes, etc.
[0078] The bus can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. This bus can be divided into address bus, data bus, control bus, etc. For ease of illustration, only one arrow is used in the diagram, but this does not mean that there is only one bus or one type of bus. The bus is configured to implement the connection and communication between the memory and at least one processor, etc.
[0079] This application also provides a computer-readable storage medium (not shown), which stores computer-readable instructions. These computer-readable instructions are executed by a processor in an electronic device to implement the unidirectional isolated time synchronization method described in any of the above embodiments.
[0080] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of modules is only a logical functional division, and other division methods may be used in actual implementation.
[0081] The modules described as separate components may or may not be physically separate. The components shown as modules may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.
[0082] Furthermore, the functional modules in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or in the form of hardware plus software functional modules.
[0083] Furthermore, it is clear that the word "comprising" does not exclude other units or steps, and the singular does not exclude the plural. Multiple units or devices described in the specification may also be implemented by a single unit or device through software or hardware. Terms such as "first," "second," etc., are used to indicate names and do not indicate any specific order.
[0084] Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing embodiments or make equivalent substitutions for some of the technical features. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. A time synchronization system based on unidirectional isolation, characterized in that, It includes a multi-source time acquisition module, a one-way isolation module, a secure timekeeping processing module, and a trusted time distribution module; The multi-source time acquisition module is located on a non-classified external network terminal. It is used to receive multi-source time signal data, verify the integrity of the signal data, and then forward it to the one-way isolation module. The one-way isolation module is used to receive time data sent by the multi-source time acquisition module, perform encryption, encoding, modulation and decryption of the time data, and forward it to the secure timekeeping processing module; The secure timekeeping processing module is located on the classified intranet and is used to receive decrypted time data sent by the one-way isolation module, perform secondary verification on the time data, and provide the verified secure timekeeping signal to the trusted time distribution module. The trusted time distribution module is located at the classified intranet end and is used to distribute time signals to various devices on the classified intranet.
2. The time synchronization system based on unidirectional isolation according to claim 1, characterized in that, The multi-source time acquisition module receives signals from BeiDou satellites and / or NTSC. The multi-source time acquisition module has a built-in local atomic clock and performs digital signature verification and integrity check on the time signal data received from BeiDou satellites and / or NTSC.
3. The time synchronization system based on unidirectional isolation according to claim 1, characterized in that, The multi-source time acquisition module is equipped with a Trusted Cryptography (TCM) submodule, which is used to generate the keys required for encryption.
4. A time synchronization system based on unidirectional isolation according to claim 3, characterized in that, The unidirectional isolation module includes an optical unidirectional transmitting module and an optical unidirectional receiving module; The optical one-way transmitting module is located on a non-classified external network terminal, used to receive time data sent by the multi-source time acquisition module, perform encryption, encoding and modulation processing, and transmit it unidirectionally to the optical one-way receiving module; The optical one-way receiving module is located on the classified intranet and is used to decrypt the time data sent by the optical one-way transmitting module and transmit it unidirectionally to the secure timekeeping processing module.
5. A time synchronization system based on unidirectional isolation according to claim 4, characterized in that, The optical one-way transmitting module performs SM2 signature on the time data using the private key in the Trusted Cryptographic Submodule (TCM), and the optical one-way receiving module verifies the transmitted time data using the public key in the TCM.
6. A time synchronization system based on unidirectional isolation according to claim 3, characterized in that, It also includes a security management module, which is located on the classified intranet and is used to receive security events from the optical one-way receiving module, the secure timekeeping processing module, and the trusted time distribution module, and adjust the isolation strategy.
7. A time synchronization system based on unidirectional isolation according to claim 3, characterized in that, The secure timekeeping processing module receives verified integrity and reliable source time data from the optical one-way receiving module, and performs timekeeping and secondary security processing on this basis. The timekeeping and secondary security processing includes trusted execution environment isolation protection and SM2-based asymmetric key negotiation.
8. A time synchronization system based on unidirectional isolation according to claim 7, characterized in that, The trusted execution environment isolation protection divides the classified intranet where the secure timekeeping processing module is located into a secure part and a normal part. The secure part contains the decrypted raw time data received by the secure timekeeping processing module, the timekeeping discipline core algorithm, and the driver and control program. The normal part contains the management interface of the secure timekeeping processing module. When the timekeeping algorithm needs to be executed, the application in the normal part calls the instruction through the predefined security monitor, and passes the request and parameters to the secure part. After the secure part completes the processing, it returns the result through the same channel. The SM2-based asymmetric key negotiation establishes a secure channel between the secure timekeeping processing module and the time distribution module for synchronous transmission of keys or sensitive instructions. The secure timekeeping processing module has a built-in key that matches the trusted cryptographic submodule TCM, and the secure timekeeping processing module can provide the public key to the trusted time distribution module.
9. A time synchronization method based on one-way isolation, implemented based on a time synchronization system based on one-way isolation as described in any one of claims 1 to 8, characterized in that, Includes the following steps: S1. Multi-source time acquisition: The multi-source time acquisition module receives signals from BeiDou satellites, NTSC, and atomic clocks in parallel, and calculates the time deviation of each source to obtain time data; S2. One-way transmission encoding: The one-way isolation module encapsulates time data into a fixed format and uses an algorithm to encrypt and generate a dynamic session key; S3. Secure reception verification: The secure timekeeping processing module receives the time data sent by the one-way isolation module and verifies the SM3 hash value. S4. Timekeeping and Distribution: The trusted time distribution module generates NTP or PTP protocol messages from time data and distributes them to various devices on the confidential intranet.
10. A time synchronization method based on unidirectional isolation according to claim 9, characterized in that, In step S2, the optical one-way transmitting module located on the non-classified external network end in the one-way isolation module encapsulates time data in a fixed format, converts it into a 1310nm optical pulse signal, and transmits it unidirectionally to the optical one-way receiving module on the classified internal network end.