Reliable time synchronization device and method

By using trusted time synchronization devices and methods, the reliability and security issues of traditional time synchronization systems have been solved, and the reliability and controllability of the time synchronization subject, messages, links and environment have been achieved, supporting the commercial operation and high reliability assurance of time services.

CN122293445APending Publication Date: 2026-06-26SICHUAN TAIFU GROUND BEIDOU TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
SICHUAN TAIFU GROUND BEIDOU TECH CO LTD
Filing Date
2026-06-01
Publication Date
2026-06-26

AI Technical Summary

Technical Problem

Traditional time synchronization systems suffer from systemic defects in terms of reliability, security, and manageability and controllability. These defects include untrustworthy time synchronization entities, untrustworthy time synchronization messages, untrustworthy time synchronization chains, untrustworthy time synchronization environments, and a lack of time synchronization measurement mechanisms. As a result, they are unable to meet the high security, verifiability, measurability, and operability requirements of time elements in the digital economy era.

Method used

By employing trusted time synchronization devices, a trusted time management platform, and a trusted time synchronization client, a new trusted time synchronization system is constructed that achieves two-way strong identity verification of the time synchronization subject, end-to-end encryption and integrity protection of the time synchronization message, tamper-proof auditing of the entire time synchronization lifecycle, secure operation of the core time synchronization algorithm in a trusted environment, and accurate measurement and policy control of time synchronization service usage behavior. This system is highly secure, verifiable, traceable, and operable.

Benefits of technology

Eliminate false time synchronization and illegal time use, prevent the theft and tampering of time synchronization messages, achieve reliable traceability and auditing of the entire time synchronization chain, ensure the purity and reliability of the time synchronization environment, and realize the industrial operation and commercial closed loop of time services.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122293445A_ABST
    Figure CN122293445A_ABST
Patent Text Reader

Abstract

This invention discloses a trusted time synchronization device and method, relating to the field of trusted time synchronization technology, including a trusted time management platform and a trusted time synchronization client. The trusted time management platform is used to complete platform identity authentication, service activation, time synchronization message and service management, real-time control of the time synchronization client, and time synchronization billing and evidence storage management. The trusted time synchronization client, based on dedicated hardware and a trusted execution environment, completes certificate application, login management, status reporting, time synchronization and metering management to achieve trusted time synchronization and accurate metering. This invention constructs a new trusted time synchronization system that is highly secure, verifiable, traceable, and operable, meeting the high reliability and commercial operation requirements of critical infrastructure for time benchmarks in the digital economy era.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of reliable time synchronization technology, and in particular to a reliable time synchronization device and method. Background Technology

[0002] In the digital economy era, time has transcended the realm of basic physical quantities, becoming a core digital credential for data ownership verification, anti-counterfeiting traceability, and accountability. Currently, the time accuracy requirements for equipment and business systems in key sectors such as government affairs, power, finance, and 5G have leaped to the nanosecond and even picosecond levels. Simultaneously, the demands for two-way verification of time identity, full-process monitoring of time synchronization, tamper-proof time data, traceable time usage, and billable management are becoming increasingly urgent. Currently, mainstream time synchronization technologies can be categorized according to signal carrier and implementation mechanism into network time synchronization, satellite time synchronization, ground-based time synchronization, and local timekeeping. Their technical principles, core characteristics, and typical application scenarios are as follows:

[0003] (1) Network time synchronization methods based on NTP protocol: Time synchronization methods based on NTP protocol are as follows Figure 1 As shown, relying on a public NTP time source via the internet or a private network, the time-consuming terminal periodically obtains plaintext time information using the NTP protocol through the operating system's built-in time synchronization service and calibrates the operating system's time. Business systems directly use this operating system time as the reference, with time synchronization accuracy typically ranging from milliseconds to seconds. This method meets the basic time synchronization needs of devices such as computers, servers, and smart terminals, and is suitable for scenarios where high time accuracy is not required, such as daily life and government office work.

[0004] (2) PTP-based network time synchronization method: Based on the IEEE 1588 standard, the master and slave clocks synchronize by exchanging timestamps, accurately measuring network path delay and bidirectional clock deviation to achieve high-precision correction of the slave clock. With the cooperation of dedicated network cards and switches supporting the PTP protocol, the synchronization accuracy can reach the nanosecond level, which is significantly better than the NTP protocol time synchronization method. This method is sensitive to factors such as network jitter and link asymmetry, and is mainly suitable for scenarios with strict time synchronization requirements, such as 5G base station air interface synchronization, differential protection of smart substations, and high-frequency financial transactions.

[0005] (3) Time synchronization method based on satellite navigation system: Using satellite navigation systems such as Beidou and GPS as time references, the time-using end receives satellite broadcast signals through a dedicated time synchronization antenna to obtain satellite time, and the synchronization accuracy can reach the microsecond to nanosecond level. This technology has the characteristics of global coverage, high synchronization accuracy and convenient deployment, and is widely used in infrastructure fields such as communication base stations, power dispatching, financial transactions, aerospace, and land surveying.

[0006] (4) Time synchronization method based on ground-based time synchronization system: The ground-based time synchronization system distributes the national standard time signal to regional nodes through ground-based fixed transmission media such as long waves and optical fibers, and can achieve time synchronization at the level of up to 100 picoseconds. This technology has the characteristics of stable transmission, strong resistance to electromagnetic interference, and controllable physical link, and mainly serves cutting-edge scientific research and strategic fields such as quantum communication, 6G research and development and large scientific facilities.

[0007] (5) Local clock-based timing method: Using a dedicated local clock source such as a high-stability crystal oscillator or atomic clock, it can maintain high-precision timekeeping for a long time in the event of interruption of the timing signal, thanks to its excellent frequency stability and low drift characteristics. It is usually used as an emergency backup clock or disaster recovery timekeeping unit for core nodes.

[0008] (6) Other time synchronization methods: In view of the limitations of single-source time synchronization, a multi-source time synchronization architecture is adopted, which integrates space-based and ground-based time synchronization, complements satellite and network time synchronization, and coordinates NTP and PTP. Relying on redundant backup and intelligent source selection strategy, a comprehensive time synchronization system with elastic disaster recovery and self-healing capabilities is constructed, which is widely used in key infrastructure such as new power systems, financial core transaction networks and government cloud platforms.

[0009] While traditional time synchronization systems have met basic time synchronization requirements, they still have systemic shortcomings in terms of reliability, security, manageability, controllability, and commercial operation. These shortcomings are mainly manifested in the following five dimensions:

[0010] ① Untrustworthy time synchronization entities: The lack of strong authentication and two-way verification mechanisms between the time source and the time-using terminal makes time synchronization signals from satellites, fiber optics, and NTP / PTP easily forged, intercepted, and abused. The lack of verification of the legitimacy of both the time source and the time-using terminal easily leads to the risk of false time synchronization and unauthorized access by time-using terminals.

[0011] ② Unreliable time messages: Time messages lack end-to-end encryption and integrity verification during transmission, parsing, and forwarding, making them vulnerable to man-in-the-middle attacks or malicious tampering. The receiving end struggles to detect data anomalies, and once time information is contaminated, it will directly cause clock disruptions, cascading failures, and even systemic paralysis in the business system.

[0012] ③ The time synchronization chain is unreliable: Key aspects such as time generation, transmission, calibration, use, policy changes, and anomaly handling lack tamper-proof audit mechanisms, failing to form a continuous and verifiable chain of evidence. The time used is untraceable, unverifiable, and unauditable, making it difficult to support the needs of high-reliability scenarios such as anti-counterfeiting traceability, judicial evidence collection, compliance supervision, and liability determination.

[0013] ④ Untrusted time synchronization environment: Existing time synchronization software is mostly deployed on general operating systems and hardware platforms, lacking trusted execution or security isolation mechanisms. It is susceptible to malicious code penetration, vulnerability exploitation or underlying tampering, which may lead to risks such as contamination of the time synchronization algorithm logic and tampering of the time base.

[0014] ⑤ Lack of time synchronization and measurement mechanism makes it difficult to achieve closed-loop commercial operation: Traditional time synchronization is mostly provided in a rough manner as a public resource, lacking fine-grained monitoring and measurement of usage behaviors such as the frequency, traffic, and duration of time service calls.

[0015] Furthermore, trusted time technology has developed rapidly in recent years, with numerous patents granted for different aspects of the time trust chain: Patent CN120639508B, "A Trusted Time Source Device and Its Implementation Method and Application," focuses on ensuring the security and physical anti-tampering capabilities of time generation from the source; Patent CN120896664B, "A Trusted Time Transmission Device and Method," aims to achieve encrypted encapsulation, integrity verification, and replay protection of time data in the transmission link; and Patent CN120751384B, "A Trusted Timestamp Device," and CN112395620B, "A Trusted Timestamp Implementation Method Based on Trusted Time," focus on the cryptographic binding, evidence verification, and judicial validity protection of trusted timestamps and business events. Although these patents have achieved significant breakthroughs in the sources, transmission, and stamping applications of time, the lack of a trusted time synchronization device makes the trusted time trust chain prone to security breaches when used in terminal deployments.

[0016] In summary, traditional time synchronization systems prioritize availability over reliability, exhibiting systemic deficiencies in areas such as identity authentication, time security, operational isolation, audit traceability, and service measurement. Trusted time technologies suffer from weak security protection at the "last mile" of the time trust chain, particularly at the time-using terminal. These deficiencies make it difficult to meet the strategic requirements of the digital economy era for high security, verifiability, measurability, and operability of time elements. Summary of the Invention

[0017] To address the systemic deficiencies in the reliability, security, and manageability of existing time synchronization technologies, this invention aims to provide a trusted time synchronization device and method. This method enables two-way strong identity verification of the time synchronization subject, end-to-end encryption and integrity protection of the time synchronization messages, tamper-proof auditing throughout the entire time synchronization lifecycle, secure operation of the core time synchronization algorithm in a trusted environment, and precise measurement and policy control of time synchronization service usage behavior. This will build a new trusted time synchronization system that is highly secure, verifiable, traceable, and operable, meeting the high reliability and commercial operation requirements of critical infrastructure for time benchmarks in the digital economy era.

[0018] To achieve the above objectives, the technical solution adopted by the present invention is: a trusted time synchronization device, comprising a trusted time management platform and a trusted time synchronization client; the trusted time management platform is used to complete platform identity authentication, service activation, time synchronization message and service management, real-time control of the time synchronization client, and time synchronization billing and evidence storage management; the trusted time synchronization client, based on dedicated hardware and a trusted execution environment, completes certificate application, login management, status reporting, time synchronization and metering management of the trusted time synchronization client, so as to achieve trusted time synchronization and accurate metering.

[0019] As a further improvement of the present invention, it also includes a National Time Management and Certificate Center, which is used to verify whether the trusted time management platform can carry out trusted time synchronization business, issue root identity digital certificates to the management platform, supervise the management platform to issue sub-identity digital certificates to the time synchronization client, and provide the national authoritative standard time to the trusted time synchronization device in a two-way signature encryption method.

[0020] As a further improvement of the present invention, it also includes a National Data Management and Evidence Storage Center, which is used to synchronously store and manage the time synchronization data generated by the trusted time synchronization device, the time synchronization process log, the operating status of the management platform and the time synchronization client, and whether the time used by the customer to apply for verification is a trusted time, so as to prevent the time synchronization and evidence storage from being forged by the same entity.

[0021] The present invention also provides a reliable time synchronization method, implemented using the reliable time synchronization device described above, the method comprising the following steps:

[0022] S1. Building a Hardware and Trusted Execution Environment: The trusted time synchronization client uses a tamper-proof, one-time programmable, and physically isolated anti-copying security chip as a carrier to securely burn the time synchronization control program and digital certificate into the chip's secure area, simultaneously building a trusted execution environment with hardware-level security isolation and strict access control.

[0023] S2. Trusted Identity Authentication of Time Provider: The trusted time synchronization device uses a hierarchical digital certificate system to perform two-way identity verification between the trusted time management platform and the trusted time synchronization client; among them, the root certificate of the trusted time management platform is issued by the National Time Management and Certificate Center, which issues sub-certificates to each trusted time synchronization client accordingly.

[0024] S3. Time synchronization message two-way authentication and encryption: The trusted time management platform establishes a two-way digital certificate authentication channel with the National Time Management and Certificate Center, and uses domestic or open source asymmetric encryption algorithms to sign and encrypt the reference time information before sending it out; after receiving it, the time synchronization client uses the pre-set certificate to perform decryption and two-way signature verification.

[0025] S4. Trusted Metering and Billing Management of Time Synchronization Services: After users complete real-name registration and subscribe to a service package on the Trusted Time Management Platform, the built-in secure metering module of the Trusted Time Synchronization Client can statistically analyze the consumption indicators of time synchronization call frequency, service duration, and accuracy level in real time. The metering data is encrypted and reported after being cryptographically signed. Based on this, the Trusted Time Management Platform generates an unalterable billing statement, realizing refined management and closed-loop commercial operation of the time synchronization service.

[0026] S5. Time synchronization end-to-end trusted traceability and evidence storage: The trusted time management platform monitors and dynamically evaluates the identity of each node device, communication link status and device operation indicators in real time in the time synchronization path, and immediately stops the time synchronization service if an anomaly is detected; at the same time, the platform encrypts and packages all process data of time synchronization routing nodes, link topology, trust score and accuracy evaluation, and synchronizes them to the National Data Management and Evidence Storage Center for authoritative evidence storage in a two-way identity authentication and encryption manner, so as to realize the auditability, traceability and judicial proof of time synchronization.

[0027] As a further improvement of the present invention, in S1, at the hardware level, the trusted timing client integrates a national-level security chip with physical non-cloning and one-time programmable characteristics. It utilizes the physical process deviations naturally formed in the silicon wafer manufacturing process to generate a unique, uncopyable, and tamper-proof terminal identity serial number. At the same time, it is equipped with a tamper-proof physical protection structure that triggers a self-destruct mechanism when subjected to physical detection or violent disassembly. At the operational level, a trusted execution environment independent of the main operating system is built based on the domestically produced ARM TrustZone technology. Through hardware-level security isolation and strict access control, the core timing logic, timestamp calculation, and certificate verification highly sensitive services are enclosed and run in a secure isolation environment.

[0028] As a further improvement of the present invention, S2 specifically includes two stages: platform qualification certification and user service activation. Specifically: In the platform certification stage, the trusted time operator submits application materials to the National Time Management and Certificate Center. After review and approval, it obtains authorization for time use and traceability, official certification of the trusted time management platform, and a platform identity digital certificate. In the time service activation stage, the user initiates a service application to the trusted time management platform according to the trusted time service activation specifications. The trusted time management platform completes the initial review of the materials, associates and binds the terminal identity serial number, terminal information, and the information of the entity to which the terminal belongs, and submits it to the National Time Management and Certificate Center for final review. The management center verifies the authenticity of the materials submitted by the platform, the authenticity of the terminal entity, the authenticity of the terminal device identity, and the trustworthiness requirements of the terminal device. After verification, the management center authorizes the platform to allocate a dedicated account to the terminal, bind a service package, issue hardware with an embedded identity digital certificate, and configure the trusted time service policy. Customers can securely access and use the trusted time service by logging into the management platform and obtaining an authorization access token.

[0029] As a further improvement of the present invention, S3 is specifically as follows:

[0030] Real-time monitoring is implemented across key nodes in the entire time chain, including the time source, management platform, and time synchronization client. Data on device operating status, signal transmission quality, and key indicators of time reliability and accuracy are dynamically collected. Upon detecting an anomaly, the trusted time management platform immediately stops the time synchronization service and automatically triggers an alarm. The service is restored after administrators complete troubleshooting and compliance procedures. Based on this, the National Time Management and Certificate Center, relying on a standardized trusted encryption and authentication system, uses national cryptographic standards or open-source algorithms. It first performs asymmetric encryption on the national authoritative time signal using the trusted time management platform's public key, then signs it with its own private key before distributing it to the management platform. After the platform completes legitimate verification and data decryption, it asymmetrically encrypts the obtained time using the public keys of each trusted time synchronization client, signs it with the management platform's private key, and broadcasts it uniformly to the trusted time synchronization clients. The trusted time synchronization clients complete certificate verification and time synchronization within a trusted execution environment.

[0031] As a further improvement of the present invention, S4 is specifically as follows:

[0032] In addition to providing accurate time synchronization services, the trusted time synchronization client automatically collects service call frequency and core network traffic consumption data through its built-in real-time metering module, and synchronizes the collected information to the trusted time management platform in real time. After receiving the data, the trusted time management platform performs real-time billing and settlement according to the user's subscribed service package and established tariff standards. At the same time, it assigns an authoritative and trusted timestamp to each time synchronization interaction data and simultaneously completes local and national data management and evidence storage. Furthermore, the user submits verification and evidence storage data to the national data management and evidence storage center in real time, retrieves authoritative evidence storage data and compares it with the data to be verified, and the evidence storage center issues a legally valid third-party authoritative verification and evidence storage report.

[0033] As a further improvement to the present invention, it also includes:

[0034] The time source encrypts the original time data with its private key, signs it with the public key of the management platform to generate the first hash, and sends it to the trusted time management platform. The trusted time management platform verifies the signature, decrypts the data, and compensates for the delay. Then, it encrypts the data with its own private key, signs it with the public key of the trusted time synchronization client to generate the second hash, and sends it to the time-using terminal. At the same time, the trusted time management platform synchronously writes the subject information of the third-party digital certificate and the two time synchronization data into the time synchronization chain log and the evidence storage center database. If any abnormality occurs in any link, the signature, hash and evidence storage records are reverse-verified to achieve full traceability and verification of the identity and path of the time synchronization node.

[0035] The beneficial effects of this invention are:

[0036] 1. Eliminate false time synchronization and illegal time use: The trusted time synchronization device uses a two-way digital certificate authentication mechanism, along with a certificate system and dynamic session key negotiation technology, to completely solve the problems of traditional time synchronization entities lacking two-way verification and signals being easily forged and intercepted, thus fundamentally eliminating the access of false time synchronization sources and illegal time-using terminals.

[0037] 2. Preventing theft and tampering of time synchronization messages: The trusted time synchronization device adopts end-to-end encryption and digital signature technology to ensure that the time synchronization data cannot be eavesdropped, tampered with or forged throughout the entire link of transmission and parsing, effectively resisting man-in-the-middle attacks and time synchronization data contamination, and avoiding clock disorder or cascading failures in business systems.

[0038] 3. Trusted traceability and auditing of the entire time synchronization chain: The trusted time synchronization device forms a continuous and non-repudiable evidence chain based on key time synchronization node logs, anti-tampering logs of time synchronization data, and authoritative verification separation technology for time synchronization process evidence storage. This provides technical support for highly reliable scenarios such as anti-counterfeiting traceability, judicial evidence collection, compliance supervision, and liability determination.

[0039] 4. Dedicated hardware ensures the time synchronization environment is free from contamination: The trusted time synchronization device isolates the core time synchronization process through a hardware-level trusted execution environment, separating it from the general operating system, blocking the risk of malicious code infiltration and underlying tampering, and ensuring the purity and reliability of the time synchronization execution environment.

[0040] 5. Time can be industrialized and commercialized: The trusted time synchronization device introduces a service metering and billing module to realize precise metering and strategic control according to dimensions such as accuracy, frequency and duration, transforming time synchronization from a "public resource" into a "quantifiable service", providing a key technological closed loop for the intensive utilization and industrial development of the national high-precision time infrastructure (especially the ground-based time synchronization system).

[0041] In summary, this invention powerfully promotes the leap of trusted time synchronization technology from "basic public availability" to "highly trusted and operable", providing a solid and verifiable time reference guarantee for the construction of Digital China and critical information infrastructure. Attached Figure Description

[0042] Figure 1 This is a schematic diagram of an existing time synchronization method based on the NTP protocol;

[0043] Figure 2 This is a structural block diagram of the trusted timing device in an embodiment of the present invention;

[0044] Figure 3 This is a schematic diagram of the time synchronization platform authentication and service activation mechanism in an embodiment of the present invention;

[0045] Figure 4 This is a schematic diagram of the authorization message encryption and service control mechanism in an embodiment of the present invention;

[0046] Figure 5 This is a schematic diagram of the time-based trusted billing and authoritative evidence storage mechanism in an embodiment of the present invention;

[0047] Figure 6 This is a schematic diagram of the time synchronization full-chain trusted traceability and proof mechanism in an embodiment of the present invention. Detailed Implementation

[0048] The embodiments of the present invention will now be described in detail with reference to the accompanying drawings.

[0049] Example

[0050] like Figure 2 As shown, a trusted time synchronization device includes a trusted time management platform and a trusted time synchronization client. The trusted time management platform is used to complete platform identity authentication, service activation, time synchronization message and service management, real-time control of the time synchronization client, and time synchronization billing and evidence storage management. The trusted time synchronization client, based on dedicated hardware and a trusted execution environment, completes certificate application, login management, status reporting, and time synchronization and metering management to achieve trusted time synchronization and accurate metering. Furthermore, the National Time Management and Certificate Center is used to verify whether the trusted time management platform can conduct trusted time synchronization business, issue root identity digital certificates to the management platform, supervise the management platform to issue sub-identity digital certificates to the time synchronization client, and provide the national authoritative standard time to the trusted time synchronization device using a two-way signature encryption method. The National Data Management and Evidence Storage Center is used to store and manage in real time the time synchronization data generated by the trusted time synchronization device, time synchronization process logs, the operating status of the management platform and the time synchronization client, and whether the time used for customer verification is trusted time, preventing time synchronization and evidence storage from being forged by the same entity.

[0051] This embodiment also provides a trusted time synchronization method, which integrates core mechanisms such as time synchronization subject identity authentication, two-way authentication and encryption of time synchronization messages, end-to-end trusted traceability and evidence storage, dedicated hardware trusted execution environment, and trusted metering and billing management of time synchronization services to achieve end-to-end trusted assurance of time synchronization subject identity, time synchronization data, time synchronization link, time synchronization environment, hardware carrier, and service management; the method includes the following steps:

[0052] 1. Dedicated Hardware and Trusted Execution Environment Construction. The trusted time synchronization client uses a dedicated security chip that is tamper-proof, programmable at one time, and physically isolated to prevent copying. The time synchronization control program and digital certificate are securely burned into the chip's secure area. The core time synchronization logic runs in isolation within the chip's built-in trusted execution environment, preventing external malicious code injection and memory theft, and ensuring the hardware-level trustworthiness of the time synchronization runtime environment.

[0053] 2. Trusted Identity Authentication of Time Providers. The trusted time synchronization device employs a hierarchical digital certificate system to conduct two-way identity verification between the trusted time management platform and the trusted time synchronization clients. The root certificate of the trusted time management platform is issued by a nationally authorized time management and certificate center; based on this certificate, the platform issues sub-certificates to each trusted time synchronization client. This certificate chain verification mechanism ensures the authoritative legitimacy and unforgeability of the time synchronization entity's identity.

[0054] 3. Two-way authentication and encryption of time authorization messages. The trusted time management platform establishes a two-way digital certificate authentication channel with the National Time Management and Certificate Center, and uses domestic or open-source asymmetric encryption algorithms to sign and encrypt the reference time information before sending it out; after receiving it, the time authorization client uses a pre-set certificate to perform decryption and two-way signature verification to ensure the confidentiality, integrity and non-repudiation of the time authorization messages during transmission.

[0055] 4. Trusted Metering and Billing Management of Time Synchronization Services. After users complete real-name registration and subscribe to a service package on the trusted time management platform, the system uses the built-in secure metering module in the client to statistically analyze consumption indicators such as time synchronization call frequency, service duration, and accuracy level in real time. The metering data is encrypted and reported after being cryptographically signed, and the platform generates an immutable billing statement based on this, realizing refined management and closed-loop commercial operation of the time synchronization service.

[0056] 5. Trusted Traceability and Evidence Storage for the Entire Time Synchronization Link. The trusted time management platform monitors and dynamically evaluates the identity of each node device, communication link status, and device operation indicators in real time along the time synchronization path. Upon detecting an anomaly, the time synchronization service is immediately terminated. Simultaneously, the platform encrypts and packages all process data, including time synchronization routing nodes, link topology, trustworthiness scores, and accuracy assessments, and synchronizes it to the National Data Management and Evidence Storage Center for cryptographic security storage using two-way authentication and encryption. This ensures the time synchronization process is auditable, traceable, and legally certifiable.

[0057] The trusted time synchronization method of this embodiment will be further described below:

[0058] The trusted time synchronization device is implemented based on the mechanism of "platform trustworthiness - execution environment trustworthiness - time trustworthiness - billing trustworthiness - evidence storage trustworthiness - time synchronization chain trustworthiness". Specifically, it includes: dedicated hardware and trusted execution environment mechanism, time synchronization platform authentication and service activation mechanism, time synchronization message encryption and service control mechanism, time synchronization trusted billing and authoritative evidence storage mechanism, and time synchronization full chain trusted traceability and proof mechanism.

[0059] First, the trusted time synchronization client adopts a proactive defense architecture that deeply integrates dedicated hardware and a trusted execution environment, achieving a comprehensive security protection system from the physical layer to the runtime layer. At the hardware level, the client integrates a national-level security chip with physically unclonable and one-time programmable characteristics. Utilizing inherent physical process deviations in silicon wafer manufacturing, it generates a unique, uncopyable, and tamper-proof terminal identity serial number. Simultaneously, it is equipped with an anti-tampering physical protection structure that triggers a self-destruct mechanism upon physical detection or forced disassembly, eliminating the risks of device forgery, data copying, and hardware cloning from a physical structure perspective. At the runtime layer, a trusted execution environment independent of the main operating system is built based on domestically developed ARM TrustZone technology. Through hardware-level security isolation and strict access control, highly sensitive services such as core time synchronization logic, timestamp calculations, and certificate verification are enclosed and run within this secure isolation environment. This ensures that the security of the time synchronization service no longer depends on the external operating system state, thus achieving comprehensive intrinsic security from the physical layer to the runtime logic.

[0060] Secondly, such as Figure 3 As shown, the time synchronization platform certification and service activation mechanism includes two stages: platform qualification certification and user service activation. In the platform certification stage, the trusted time operator submits application materials to the National Time Management and Certificate Center. After review and approval, it obtains national authoritative authorization for time use and traceability, official certification of the trusted time management platform, and a platform identity digital certificate, ensuring the compliance and authority of the platform's identity. In the time synchronization service activation stage, users initiate service applications to the trusted platform according to the trusted time service activation specifications. The platform completes the initial review of the materials, associates and binds the terminal identity serial number, terminal information, and the information of the entity to which the terminal belongs, and submits it to the National Time Management and Certificate Center for final review. The management center verifies the authenticity of the materials submitted by the platform, the authenticity of the terminal entity, the authenticity of the terminal device identity, and the trustworthiness requirements of the terminal device. After verification, the management center authorizes the platform to assign a dedicated account to the terminal, bind a service package, issue dedicated hardware with embedded identity digital certificates, and configure trusted time service policies on the management platform. Customers can securely access and use the trusted time service by logging into the management platform and obtaining an authorized access token. This mechanism relies on the verification and authorization of national authoritative institutions to ensure the credibility of the platform's identity, and combines dedicated hardware and digital certificate technology to achieve strong authentication of user identity, thus building a security control system with trusted identities for both the platform and the user.

[0061] Again, such as Figure 4As shown, the time synchronization message encryption and service control mechanism implements real-time monitoring of key nodes across the entire chain, including the time source, management platform, and time synchronization clients, dynamically collecting key indicator data such as device operating status, signal transmission quality, and time reliability and accuracy. Once an anomaly is detected, the platform immediately stops the time synchronization service and automatically triggers an alarm. The service can only be restored after administrators have completed troubleshooting and compliance procedures. Based on this, the National Time Management and Certificate Center, relying on a standardized trusted encryption authentication system, uses national cryptographic algorithms or open-source algorithms. It first performs asymmetric encryption on the national authoritative time signal using the public key of the trusted time management platform, and then signs it with its own private key before distributing it to the management platform. After the platform completes legitimate signature verification and data decryption, it asymmetrically encrypts the obtained time original using the public keys of each trusted time synchronization client, signs it with the management platform's private key, and broadcasts it uniformly to trusted clients. The clients complete certificate verification and time synchronization in a trusted execution environment. This mechanism achieves multi-layered encryption protection, multi-level signature verification, and full-chain closed-loop verification throughout the entire process, comprehensively ensuring that the time used by the terminal originates from an untampered national authoritative time source.

[0062] Next, as Figure 5 As shown, the trusted billing and authoritative evidence storage mechanism for time synchronization relies on the collaboration of a trusted time synchronization client, a trusted time management platform, and the National Data Management and Evidence Storage Center to construct a trusted closed loop for the entire billing and evidence storage process, encompassing metering, billing, evidence storage, and verification. The time synchronization client, while providing accurate time synchronization services, automatically collects core consumption data such as service call frequency and network traffic through its built-in real-time metering module, and synchronizes the collected information to the trusted time management platform in real time. After receiving the data, the platform performs real-time billing and settlement according to the user's subscribed service package and established pricing standards. Simultaneously, it assigns an authoritative and trusted timestamp to each time synchronization interaction data, and simultaneously completes evidence storage both locally and with authoritative regulatory agencies, ensuring that the original interaction data is tamper-proof and fully traceable. Users can submit verification applications to the National Data Management and Evidence Storage Center at any time to retrieve authoritative evidence storage data for comparison and verification with the data to be verified, and receive a legally credible third-party authoritative evidence storage report. This mechanism comprehensively covers all aspects of time synchronization service metering and statistics, intelligent billing, dual evidence storage, and authoritative verification, truly achieving a trusted, controllable, and closed-loop operation throughout the entire time synchronization business process.

[0063] Finally, as Figure 6As shown, the time synchronization end-to-end trusted traceability and proof mechanism constructs a three-segment non-repudiable evidence chain across the entire link from the authoritative source to the management platform and the time synchronization client: node identity mutual trust is achieved based on digital certificates; the integrity and tamper-proof nature of transmitted data is ensured by an asymmetric encryption signature mechanism; and finally, a verification report with judicial credibility is issued by the National Data Management and Evidence Preservation Center. Specifically, the time source encrypts the original time data with its private key, signs it with the management platform's public key to generate the first hash segment, and sends it to the management platform; the management platform verifies the signature, decrypts the data, and compensates for delays, then encrypts it again with its own private key, signs it with the time synchronization client's public key to generate a second hash segment, and sends it to the time-using terminal; simultaneously, the trusted time management platform synchronously writes the subject information of the three-party digital certificates and the two segments of time synchronization data into the time synchronization chain log and the evidence preservation center database. If any link experiences an anomaly, the signature, hash, and evidence preservation records can be reverse-checked, achieving full traceability and verifiability of the time synchronization node's identity and path.

[0064] This embodiment constructs an end-to-end trusted time synchronization closed-loop system through the collaborative innovation of five mechanisms: identity authentication, message encryption, end-to-end authoritative evidence storage, trusted hardware environment, and metering and billing. It fundamentally solves the core problems in time synchronization services, such as identity spoofing, data tampering, untrusted links, and lack of supervision. It achieves full-element trusted protection for time synchronization subjects, data, links, environment, hardware, and services, and significantly improves the security, reliability, and commercial availability of the time synchronization system.

[0065] The embodiments described above are merely illustrative of specific implementations of the present invention, and while the descriptions are detailed, they should not be construed as limiting the scope of the present invention. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of the present invention, and these modifications and improvements all fall within the scope of protection of the present invention.

Claims

1. A reliable time synchronization device, characterized in that, It includes a trusted time management platform and a trusted time synchronization client; the trusted time management platform is used to complete platform identity authentication, service activation, time synchronization message and service management, real-time control of the time synchronization client, and time synchronization billing and evidence storage management; the trusted time synchronization client is based on dedicated hardware and a trusted execution environment to complete the certificate application, login management, status reporting, time synchronization and metering management of the trusted time synchronization client, so as to achieve trusted time synchronization and accurate metering.

2. The reliable time synchronization device according to claim 1, characterized in that, It also includes the National Time Management and Certificate Center, which is used to verify whether a trusted time management platform can carry out trusted time synchronization business, issue root identity digital certificates to the management platform, supervise the supervision platform to issue sub-identity digital certificates to the time synchronization client, and provide the national authoritative standard time to the trusted time synchronization device in a two-way signature encryption method.

3. The reliable timing device according to claim 1 or 2, characterized in that, It also includes the National Data Management and Evidence Storage Center, which is used to synchronously store and manage time synchronization data generated by trusted time synchronization devices, time synchronization process logs, the operating status of the management platform and time synchronization client, and whether the time used by the customer to apply for verification is a trusted time, so as to prevent time synchronization and evidence storage from being forged by the same entity.

4. A reliable time synchronization method, characterized in that, Implemented using the trusted timing device as described in claim 3, the method includes the following steps: S1. Building a Hardware and Trusted Execution Environment: The trusted time synchronization client uses a tamper-proof, one-time programmable, and physically isolated anti-copying security chip as a carrier to securely burn the time synchronization control program and digital certificate into the chip's secure area, simultaneously building a trusted execution environment with hardware-level security isolation and strict access control. S2. Trusted Identity Authentication of Time Provider: The trusted time synchronization device uses a hierarchical digital certificate system to perform two-way identity verification between the trusted time management platform and the trusted time synchronization client; among them, the root certificate of the trusted time management platform is issued by the National Time Management and Certificate Center, which issues sub-certificates to each trusted time synchronization client accordingly. S3. Time synchronization message two-way authentication and encryption: The trusted time management platform establishes a two-way digital certificate authentication channel with the National Time Management and Certificate Center, and uses domestic or open source asymmetric encryption algorithms to sign and encrypt the reference time information before sending it out; after receiving it, the time synchronization client uses the pre-set certificate to perform decryption and two-way signature verification. S4. Trusted Metering and Billing Management of Time Synchronization Services: After users complete real-name registration and subscribe to a service package on the Trusted Time Management Platform, the built-in secure metering module of the Trusted Time Synchronization Client can statistically analyze the consumption indicators of time synchronization call frequency, service duration, and accuracy level in real time. The metering data is encrypted and reported after being cryptographically signed. Based on this, the Trusted Time Management Platform generates an unalterable billing statement, realizing refined management and closed-loop commercial operation of the time synchronization service. S5. Time synchronization end-to-end trusted traceability and evidence storage: The trusted time management platform monitors and dynamically evaluates the identity of each node device, communication link status and device operation indicators in real time in the time synchronization path, and immediately stops the time synchronization service if an anomaly is detected; at the same time, the platform encrypts and packages all process data of time synchronization routing nodes, link topology, trust score and accuracy evaluation, and synchronizes them to the National Data Management and Evidence Storage Center for authoritative evidence storage in a two-way identity authentication and encryption manner, so as to realize the auditability, traceability and judicial proof of time synchronization.

5. The reliable time synchronization method according to claim 4, characterized in that, In S1, at the hardware level, the trusted timing client integrates a national-level security chip with physical non-cloning and one-time programmable characteristics. It utilizes the physical process deviations naturally formed during silicon wafer manufacturing to generate a unique, uncopyable, and tamper-proof terminal identity serial number. At the same time, it is equipped with a tamper-proof physical protection structure that triggers a self-destruct mechanism when subjected to physical detection or violent disassembly. At the operational level, a trusted execution environment independent of the main operating system is built based on domestically produced ARM TrustZone technology. Through hardware-level security isolation and strict access control, the core timing logic, timestamp calculation, and certificate verification highly sensitive services are enclosed and run in a secure isolation environment.

6. The reliable time synchronization method according to claim 4, characterized in that, The S2 process specifically includes two stages: platform qualification certification and user service activation. In the platform certification stage, the trusted time operator submits application materials to the National Time Management and Certificate Center. After approval, it obtains authorization for time use and traceability, official certification from the trusted time management platform, and a digital certificate for platform identity. In the time service activation stage, users submit service applications to the trusted time management platform according to the trusted time service activation specifications. The trusted time management platform completes the initial review of the materials, associates and binds the terminal identity serial number, terminal information, and the information of the entity to which the terminal belongs, and submits the application to the National Time Management and Certificate Center for final review. The management center verifies the authenticity of the materials submitted by the platform, the authenticity of the terminal entity, the authenticity of the terminal device identity, and the trustworthiness requirements of the terminal device. After verification, the management center authorizes the platform to assign a dedicated account to the terminal, bind a service package, issue hardware with an embedded digital certificate, and configure trusted time service policies. Customers can securely access and use the trusted time service by logging into the management platform and obtaining an authorization access token.

7. The reliable time synchronization method according to claim 4, characterized in that, S3 is specifically as follows: Real-time monitoring is implemented for key nodes across the entire time chain, including the time source, management platform, and time synchronization client. Data on key indicators such as device operating status, signal transmission quality, and time reliability and accuracy are dynamically collected. Once an anomaly is detected, the trusted time management platform immediately stops the time synchronization service and automatically triggers an alarm. The time synchronization service is restored after the administrator completes the problem investigation and compliance handling. Based on this, the National Time Management and Certificate Center relies on a standardized trusted encryption and authentication system and uses national cryptographic or open-source algorithms to first perform asymmetric encryption on the national authoritative time signal using the trusted time management platform's public key, and then sends it to the management platform after signing it with its own private key. After the platform completes the legitimate signature verification and data decryption, it uses the public key of each trusted time synchronization client to perform asymmetric encryption and the management platform's private key to sign the obtained original time. The platform then broadcasts and distributes the information to the trusted time synchronization clients. The trusted time synchronization clients complete certificate verification and time synchronization in the trusted execution environment.

8. The reliable time synchronization method according to claim 4, characterized in that, S4 is specifically as follows: In addition to providing accurate time synchronization services, the trusted time synchronization client automatically collects service call frequency and core network traffic consumption data through its built-in real-time metering module, and synchronizes the collected information to the trusted time management platform in real time. After receiving the data, the trusted time management platform conducts real-time billing and settlement according to the user's subscribed service package and established pricing standards. At the same time, it solidifies an authoritative and trusted timestamp for each time synchronization interaction data and simultaneously completes the notarization at the local and national data management and notarization centers. Furthermore, the user submits verification and notarization data to the national data management and notarization center in real time, retrieves authoritative notarized data for comparison and verification with the data to be verified, and the notarization center issues a legally valid third-party authoritative verification and notarization report.

9. The reliable time synchronization method according to claim 4, characterized in that, Also includes: The time source encrypts the original time data with its private key, signs it with the management platform's public key to generate the first hash segment, and sends it to the trusted time management platform. After verifying the signature, decrypting the data, and compensating for the delay, the trusted time management platform encrypts the data with its own private key and signs it with the public key of the trusted time synchronization client to generate a two-part hash, which is then sent to the time-using terminal. At the same time, the trusted time management platform synchronously writes the subject information of the third-party digital certificate and the two-part time synchronization data into the time synchronization chain log and the evidence storage center database. If any abnormality occurs in any link, the signature, hash, and evidence storage records are reverse-verified to achieve full traceability and verification of the identity and path of the time synchronization node.

Citation Information

Patent Citations

  • A method for implementing a trusted timestamp based on trusted time

    CN112395620B

  • A trusted time source device, and implementation method and application thereof

    CN120639508B

  • Trusted timestamping device

    CN120751384B

  • Trusted time transfer apparatus and method

    CN120896664B