Hardware-level intrinsically secure time synchronization devices and trusted collaboration methods
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-03-26
- Publication Date
- 2026-08-11
AI Technical Summary
现有技术中的电力系统硬件级内生安全的时间同步装置,硬件架构多基于单一CPU核心处理器,仅对卫星接收模块、本地高稳晶振及各类时间码输出接口进行功能性集成,未从硬件底层构建安全防护体系,致使装置在安全性、可靠性、信源保障及输出可信性方面存在根本性缺陷,难以适配智能电网的发展需求
本申请通过硬件架构的创新设计,从物理层面解决了现有技术中硬件级内生安全的时间同步装置的安全性不足、抗扰能力弱、信源单一、输出不可验证等核心问题,实现了时间同步技术从功能实现到内生安全的跨越,相比现有技术具备以下显著有益效果:
Smart Images

Figure CN122546592A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of power system time synchronization technology, specifically to a hardware-level intrinsically secure time synchronization device and a trusted collaborative method. Background Technology
[0002] As smart grids rapidly evolve towards ultra-high voltage levels, wide-area interconnection, and high automation, power systems face stringent requirements for the accuracy, reliability, and security of time synchronization. High-precision, hardware-level intrinsically secure time synchronization devices have become core infrastructure supporting stable grid operation, accurate fault location, and automated control. Existing hardware-level intrinsically secure time synchronization devices for power systems are mostly based on a single CPU core processor, functionally integrating only satellite receiving modules, local high-stability crystal oscillators, and various time code output interfaces. They lack a robust security protection system built at the hardware level, resulting in fundamental deficiencies in security, reliability, source assurance, and output credibility, making them ill-suited to the development needs of smart grids.
[0003] In terms of security, the core time processing software shares the same hardware computing environment with a complex general-purpose operating system and network service stack, lacking any physical or logical hard isolation barriers. Once the operating system is compromised by a network attack, the core timestamp generation and processing processes within the same security domain are easily maliciously tampered with, creating serious systemic security risks. In terms of system reliability, the device has a simple hardware structure, with each device operating independently. It lacks dedicated horizontal secure communication interfaces and collaborative processing units with hardware encryption capabilities, making it impossible to achieve state consensus and collective intelligent anti-interference at the hardware level. This makes it difficult to cope with strong regional deception or interference targeting the time source. In terms of signal source reliability, the hardware design relies excessively on satellite signals and lacks an integrated dedicated hardware channel and efficient arbitration switching mechanism for accessing terrestrial wired backup signal sources such as PTP and NTP. This poses a single point of failure risk, and time synchronization can easily be interrupted when external signal sources are abnormal. In terms of output credibility, the generation and output process of the time signal is entirely implemented by software, lacking the ability of a hardware-level secure cryptographic module to digitally sign critical time information. Downstream power equipment cannot verify the authenticity and integrity of the received signal, and the credibility of the time transmission link cannot be guaranteed. Summary of the Invention
[0004] The technical problem to be solved by this invention is to overcome the shortcomings of the prior art and provide a hardware-level intrinsically secure time synchronization device and a trusted collaborative method.
[0005] The present invention is achieved through the following technical solution: a hardware-level intrinsically secure time synchronization device, comprising a multi-source time input module, a secure password module, a crystal oscillator and discipline module, a time output module and a cooperative communication module electrically connected to the main control module; The main control module is divided into a secure world and a normal world that are physically and logically isolated at the hardware level. The secure world is used to run time processing tasks and store local time references. The secure world directly controls and communicates with the security cryptography module, crystal oscillator and discipline module. The ordinary world runs a general operating system, which is used to interact with the multi-source time input module, the cooperative communication module, and the time output module for data interaction and data preprocessing. Controlled data interaction is achieved between the ordinary world and the secure world through secure monitoring calls.
[0006] The multi-source time input module includes multiple independent receiving units, each equipped with an independent signal processing circuit and physical interface, and the output of each receiving unit is connected to the corresponding input interface of the main control module.
[0007] The multi-source time input module includes at least a multi-mode satellite receiver and a terrestrial wired time interface, wherein the multi-mode satellite receiver is used to receive and analyze signals. The terrestrial wired time interface includes at least one or more of the following: a PTP slave clock port, an IRIG-B code input interface, and an NTP client interface.
[0008] The collaborative communication module includes a network controller and a corresponding physical port. The collaborative communication module integrates a hardware encryption engine for encrypting, decrypting, and authenticating the time status information exchanged between devices.
[0009] The secure cryptographic module includes an independent hardware security chip, and the secure cryptographic module is directly connected to the secure world of the main control module. The hardware security chip is used to securely store and manage private keys for asymmetric cryptography algorithms, and to digitally sign timestamp information from the secure world.
[0010] The crystal oscillator and discipline module includes a temperature-controlled crystal oscillator and a digital phase-locked loop (PLL) chip. The PLL chip receives frequency calibration commands sent by the main control module and dynamically adjusts the output phase and frequency to keep the local clock phase and frequency synchronized with the external reference source. When all external signal sources are lost, the system enters hold mode through the temperature-controlled crystal oscillator.
[0011] The time output module includes multiple timecode generators and physical interfaces. The trigger source and time information of the timecode generators come directly from the secure time calculated by the secure world of the main control module. Before outputting the time signal, the time output module sends key time information to the security password module for digital signature, forming a verifiable time signal output with a digital signature.
[0012] A trusted collaboration method based on a hardware-level intrinsically secure time synchronization device, applied to the aforementioned hardware-level intrinsically secure time synchronization device, includes the following steps: S1. Perform secure boot and establish a root of trust. After the hardware-level intrinsically secure time synchronization device is powered on, the digital signatures of the trusted operating system and time application in the executable environment of the main control module are verified step by step through the boot code to establish a hardware root of trust. S2. Acquire multi-source time signals and perform preprocessing; Receive external time signals through the multi-source time input module, enter the normal world of the main control module for preliminary analysis, decoding and data packaging, and obtain raw time data; S3. Perform time processing on the preprocessed data within the safe world. Use a time fusion algorithm to perform quality assessment, bias calculation and weighted fusion on the multi-channel preprocessed data to obtain the optimal global safe time. S4. Generate and output a trusted time. When the time needs to be output externally, SecureWorld sends the current global secure timestamp to the secure cryptographic module for digital signature. The time data packet with the digital signature is output through the time output module.
[0013] S2 includes the following sub-steps: S2-1. Verify the validity of the data, remove abnormal data from each source, and retain valid time data; S2-2, Unify the time reference, and convert the time data of each signal source into the UTC reference; S2-3. Extract feature quantities: extract the time deviation fluctuation rate, link transmission delay, continuous effective duration of the source, signal-to-noise ratio of satellite source and / or packet loss rate of ground source for each source, which are used as quantitative indicators for source quality assessment.
[0014] S3 includes the following sub-steps: S3-1, Multi-source signal quality assessment and weight calculation: Quantitatively score each signal source and calculate the fusion weight of a single signal source based on the scoring results; S3-2, Calculate the time offset of multiple signal sources; S3-3. Based on robust Kalman filtering, the time deviation of multiple information sources is fused and estimated. The local reference time is corrected by the fused deviation value to obtain the global safe time.
[0015] Compared with the prior art, the beneficial effects of the present invention are: This application, through innovative hardware architecture design, solves the core problems of existing hardware-level intrinsically secure time synchronization devices at the physical level, such as insufficient security, weak anti-interference capability, single information source, and unverifiable output. It achieves a leap from functional implementation to intrinsic security in time synchronization technology, and has the following significant advantages compared to existing technologies: This application constructs a hardware-level intrinsic security system to fundamentally avoid the risk of tampering. The main control module is divided at the hardware level into a physically and logically completely isolated secure world and a normal world. Core time fusion, consensus logic operations, and local time base storage are all completed in the hardware-protected secure world. The secure world directly controls the secure cryptographic module and the crystal oscillator and discipline module, while the normal world only handles non-core data analysis and peripheral interaction tasks. Furthermore, the two worlds only achieve controlled data interaction through secure monitoring calls. This design physically isolates the core time processing from the general operating system and network service stack, fundamentally avoiding the risk of malicious software tampering with the core time mechanism and laying the foundation for the device's intrinsic security.
[0016] This application achieves multi-source heterogeneous signal source redundancy, improving signal source reliability. The hardware-level intrinsically secure time synchronization device of this application features a multi-source time input module containing multiple independent receiving units, each equipped with dedicated signal processing circuits and physical interfaces. It also integrates a multi-mode satellite receiver and various terrestrial wired time interfaces, achieving heterogeneous redundant access to satellite and terrestrial wired signal sources. This ensures the diversity of signal sources at the hardware level, solves the single-point failure problem of existing devices that overly rely on satellite signals, and significantly improves the stability and continuity of the time reference source.
[0017] This application achieves swarm intelligence anti-interference, improving system-level reliability. The hardware-level intrinsically secure time synchronization device is equipped with a cooperative communication module that integrates a hardware encryption engine. It can realize online-speed encryption, decryption, and authentication of time status information between devices at the hardware level. Multiple devices can form a trusted time cluster through this dedicated cooperative channel. With the help of distributed consensus logic, it can complete the verification and voting of time information of multiple nodes. It can actively identify and eliminate abnormal nodes that are deceived or malfunction, realizing a leap from single-point protection to swarm intelligence anti-interference, effectively resisting strong regional deception or interference targeting the time source, and ensuring the reliability of time synchronization over a wide area of the power grid.
[0018] This application establishes an end-to-end trusted time traceability chain to ensure output credibility. The hardware-level intrinsically secure time synchronization device uses an independent hardware security chip as a secure cryptographic module to perform hardware-level digital signatures on timestamps generated in a secure environment. Before outputting time signals such as PTP, IRIG-B, and 1PPS, the time output module signs key time information to form a verifiable signal consisting of time and signature. Downstream power equipment can verify the signature using a pre-set public key, effectively verifying the authenticity and integrity of the time signal. This establishes an end-to-end trusted time traceability chain, solving the problem of unreliable time transmission links in existing technologies. Attached Figure Description
[0019] Figure 1 This is a schematic diagram of the hardware-level intrinsically secure time synchronization device architecture; Figure 2 This is a schematic diagram of the data flow of a hardware-level intrinsically secure time synchronization device; Figure 3 This is a schematic diagram of the main control module's hardware partitioning; Figure 4 This is a schematic diagram of the PCB layout for Example 3; Figure 5 This is a schematic diagram of a multi-device network cluster; Figure 6 This is a flowchart for reliable time output verification. Detailed Implementation
[0020] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, and not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of the present invention.
[0021] Example 1 Reference Figures 1-3 The hardware structure of the hardware-level intrinsically secure time synchronization device proposed in this embodiment includes a main control module, a multi-source time input module, a secure cryptographic module, a high-stability crystal oscillator and discipline module, a time output module, and a cooperative communication module; wherein the main control module is electrically connected to each of the remaining modules, and each module is usually installed in a housing.
[0022] Furthermore, the main control module is the core computing unit, employing a multi-core system-on-a-chip (SoC) that supports a trusted hardware execution environment. Combined with... Figure 3 This system-on-a-chip is strictly divided into two physically and logically isolated regions at the hardware level—the secure world and the ordinary world.
[0023] The secure world is a hardware-protected, independent computing environment that exclusively uses a specific CPU core, on-chip RAM, and a secure bus. It is dedicated to running the most critical and sensitive tasks and storing and maintaining a high-precision local time base. This area cannot be directly accessed by code in the ordinary world, ensuring the confidentiality and integrity of the time core.
[0024] In the ordinary world, general-purpose operating systems (such as Linux and HarmonyOS) are used to handle non-core tasks, such as network protocol stacks, system management, human-computer interaction interfaces, and receiving raw data from multi-source time input modules through drivers.
[0025] The secure world communicates directly with the secure cryptographic module via the chip's internal secure peripheral bus (such as ARM's AXI bus) and directly controls the crystal oscillator and the digital phase-locked loop in the discipline module. The ordinary world, on the other hand, manages data interaction with the multi-source time input module, cooperative communication module, and time output module through general-purpose peripheral interfaces (such as PCIe, USB, and general-purpose GPIO). This connection method achieves separation of critical and non-critical operations in the physical path.
[0026] A multi-source time input module is physically a collection of multiple independent receiving units, designed to ensure heterogeneity and redundancy of signal sources at the hardware level. It includes at least a multi-mode satellite receiver and a terrestrial wired time interface. The multi-mode satellite receiver can simultaneously receive and interpret signals from satellite navigation systems such as BeiDou and GPS. The terrestrial wired time interface includes, but is not limited to, a PTP slave clock port, an IRIG-B code input interface, and even an NTP client interface.
[0027] Each receiving unit of the multi-source time input module has its own independent signal processing circuit and physical interface on the circuit board. Its output (usually UART, SPI, or Ethernet) is connected to the corresponding input interface in the normal world of the main control module. The raw data is preprocessed in the normal world and then transmitted to the secure world for final processing through a secure internal communication mechanism (such as monitoring calls in TrustZone).
[0028] The collaborative communication module is a dedicated hardware channel for realizing "swarm intelligence." Physically, it includes a network controller (such as an Ethernet MAC+PHY chip) and corresponding physical ports (RJ45 or SFP optical ports). Its core feature lies in its integrated hardware encryption engine (such as a coprocessor supporting AES-GCM), which can encrypt / decrypt and authenticate communication data at line speed, ensuring that the time status information exchanged between devices cannot be eavesdropped on or tampered with during transmission.
[0029] The secure cryptographic module employs a dedicated hardware security chip (SE), which connects directly to the secure world of the main control module via a serial bus such as SPI or I2C. This chip is responsible for the secure storage and management of private keys for core asymmetric cryptographic algorithms (such as the Chinese national standard SM2 and RSA), and digitally signs timestamp information from the secure world. This hardware-level signature is the cornerstone of building a "trusted time chain."
[0030] The crystal oscillator and discipline module consists of a high-stability oven-controlled crystal oscillator (OCXO) and a digital phase-locked loop (DPLL) chip. The OCXO provides a high-quality local frequency reference. The DPLL chip receives frequency calibration commands (digital control words) from the main control module's secure world and dynamically adjusts its output phase and frequency to keep the local clock phase and frequency synchronized with a preferred external reference source (such as a satellite). When all external signal sources are lost, the device relies on the high stability of the OCXO to enter a high-precision hold mode.
[0031] The time output module includes various timecode generators and physical interfaces, such as the PTP master clock protocol stack and port, the IRIG-B code generator, and the pulse generation circuit (1PPS). The trigger source and time information of these generators come directly from the secure time calculated by the main control module's secure world. Before output, key time information (such as the precise timestamp in the PTP message) is sent to the secure cryptographic module for signing, ultimately forming a verifiable signal output of "time + signature".
[0032] Example 2 Reference Figures 1-3 Based on Example 1, the trusted collaboration method for a hardware-level intrinsically secure time synchronization device is as follows: S1. Perform a secure boot and establish a root of trust. The hardware security chip (SE) of the secure cryptographic module or the system-on-a-chip ROM contains boot code. After the hardware-level intrinsically secure time synchronization device is powered on, the boot code verifies the digital signatures of the trusted operating system (such as OP-TEE) and the core time application within the main control module's Executable Environment (TEE) level by level, ensuring a trusted state from the software bottom layer and establishing a hardware root of trust.
[0033] S2. Acquire multi-source time signals and perform preprocessing. The units of the multi-source time input module work in parallel to receive external time signals. The acquired external time signals (such as NMEA statements and PTP messages) are first sent to the normal world, where the corresponding driver performs preliminary parsing, decoding, and data packaging preprocessing to obtain the raw time data.
[0034] Furthermore, the ordinary world preprocesses the data from each source of the multi-source time input module and then transmits it to the secure world via security monitoring. The secure world first performs secondary verification and feature extraction on the single-source data to provide a basis for subsequent quality assessment. S2 includes the following sub-steps: S2-1. Verify data validity; remove abnormal data from each signal source (such as satellite signal loss rate > 30%, sudden changes in PTP message delay, IRIG-B code point errors, etc.), and retain only valid time data with complete timestamps and stable transmission links. ( For source numbering, For discrete time steps, ).
[0035] S2-2, Unified Time Standard: Convert the time data from all sources to UTC (Coordinated Universal Time) standard to eliminate differences in time systems between different sources (such as the conversion between satellite ephemeris time and PTP local clock time).
[0036] S2-3. Feature Extraction: Extract the core features of each signal source, including time skew volatility. Link transmission delay Continuous effective duration of the information source Satellite source signal-to-noise ratio Ground source packet loss rate , as a quantitative indicator for assessing the quality of information sources.
[0037] S3. Perform core time processing on the preprocessed data within the secure world. The preprocessed data is transmitted from the normal world to the secure world via security monitoring. Within the secure world, a time fusion algorithm is run to assess the quality of each information source, calculate biases, and perform weighted fusion to obtain the optimal global secure time.
[0038] The time fusion algorithm operating within the secure world of this invention is primarily designed for the characteristics of multi-source heterogeneous time information sources in power systems (satellite BeiDou / GPS, ground-based PTP, IRIG-B, NTP, etc.). It performs source quality assessment, deviation calculation, and weighted fusion, ultimately outputting a highly reliable and accurate global secure time. This algorithm is adapted to the high real-time and high anti-interference requirements of power systems for time synchronization, and all calculations are performed within the secure world (TEE) of the main control module, preventing tampering of core operations and ensuring the security of the calculation results.
[0039] The time fusion algorithm includes the following steps: S3-1. Multi-source signal quality assessment and weight calculation: This application uses the analytic hierarchy process (AHP) combined with dynamic thresholds to construct a signal quality assessment model, quantitatively scores each signal source, and calculates the fusion weight of a single signal source based on the scoring results. The core principle is: the higher the quality score, the greater the fusion weight; the weight of abnormal sources approaches 0 to achieve soft isolation.
[0040] S3-1 includes the following sub-steps: S3-1-1. Setting Quality Assessment Indicators and Quantitative Scoring; This embodiment sets four core assessment indicators, each weighted according to the power system time synchronization priority (signal-to-noise ratio as the core for satellite sources, and packet loss rate / transmission delay as the core for ground sources), and sets dynamic thresholds to achieve quantitative scoring (scoring range). (1 represents the optimal quality), and specific indicators are shown in Table 1.
[0041] Table 1. Reference Table of Evaluation Indicators
[0042] S3-1-2. Calculate the overall quality score of a single source; Calculate the weighted sum of the four indicator scores of a single source to obtain the overall quality score. The calculation formula is as follows: ; in, For each indicator, a fixed weight is assigned. .
[0043] S3-1-3, Calculate the dynamic fusion weight. Normalize the overall quality score of all valid sources to obtain the weight of a single source at the [missing value]. Step fusion weights At the same time, a weight threshold limit is added ( If the value is lower than 0, it is set to 0 to achieve soft isolation of abnormal sources. The calculation formula is: , where n is the number of valid information sources.
[0044] The constraints are: ,like ,but And renormalize the weights of the remaining information sources.
[0045] S3-2. Calculate the time deviation of multiple signal sources. Using the local high-stability crystal oscillator reference time of the Secure World as a reference, calculate the time deviation of each effective signal source. Simultaneously, compensation for link transmission delay is considered to eliminate the impact of the transmission link on time deviation. The calculation formula is: ; in, The reference time of the local crystal oscillator in the safe world (the time of the first crystal oscillator) step); Indicates the first Link transmission delay compensation value of the source (collected in real time during preprocessing in the normal world, and verified twice in the secure world). Indicates the first The actual time deviation of the source signal after time delay compensation. A positive deviation indicates that the source time is faster than the local reference, and a negative deviation indicates that the source time is slower than the local reference.
[0046] right Perform anti-differential treatment: if A preset threshold (50ns for power scenarios) is used to identify sudden abnormal deviations, and the weight of the information source is adjusted accordingly. Forced to 0 to avoid abnormal deviations interfering with the fusion results.
[0047] S3-3: Weighted fusion calculation based on robust Kalman filtering; This application, based on weight calculation and bias calculation, uses robust Kalman filtering instead of traditional Kalman filtering to fuse and estimate the time bias of multiple information sources, effectively suppressing the influence of outliers (sudden abnormal data). Finally, the local reference time is corrected by the fusion bias value to obtain the global safe time. .
[0048] S3-3 includes the following sub-steps: S3-3-1. System state modeling: Using the deviation of the local reference time as the system state quantity, construct the discrete-time system state equation and observation equation to meet the computational requirements of Kalman filtering.
[0049] The state equation is expressed as follows: ; in, This refers to system state variables (the deviation of the local reference time from the ideal UTC). Here is the state transition matrix. The system process noise (introduced by crystal oscillator drift, variance) Set as the crystal drift coefficient; for power applications, use an OCXO crystal oscillator. .
[0050] The expression for the observation equation is: ; in, This is the observation vector (the actual time deviation of each signal source). For the observation matrix, Observation noise (introduced by source accuracy, variance) Negatively correlated with source quality score ).
[0051] S3-3-2. Perform robust Kalman filtering. To address the sensitivity of traditional Kalman filtering to outliers, the M-estimation method is introduced to weight the filter residuals, reducing the weight of outliers and thus achieving robustness. The core steps include: One-step prediction: ; Prediction mean square error ; Residual calculation: ; Robust weight adjustment: Calculate robust weights based on the residual magnitude. The larger the residual, the smaller the robustness weight (using Huber weight function to adapt to sudden anomalies in power scenarios). Filter gain ; in, This is the observation noise variance matrix after robust weighting correction; Status Update: ; Update mean squared error: .
[0052] S3-3-3, Generate a global safe time. Obtain the optimal deviation estimate of the local reference time through robust Kalman filtering. By combining the source-weighted average deviation to perform a double correction on the local reference time, the final result is obtained. global safe time of step Its expression is as follows: ; in, The weighted average time bias of multiple information sources is used to further correct the filter estimate and improve the accuracy of the global security time.
[0053] Global safe time output by time fusion algorithm Provides core references directly for crystal oscillators and discipline modules: Secure World based on The deviation from the actual output time of the local crystal oscillator generates a frequency control word, which is sent to the digital phase-locked loop (DPLL) chip to dynamically adjust the output phase and frequency of the oven-controlled crystal oscillator (OCXO) so that the local hardware clock is synchronized with the global safe time, thus realizing closed-loop control of "fusion computing-clock discipline".
[0054] Furthermore, this embodiment uses a 1PPS (1 second pulse) / 10MHz clock for global security time as a reference, and samples the phase / time deviation of the local OCXO output clock in real time. Specific operations include: Setting the sampling period: To adapt to the drift characteristics of the OCXO, this embodiment sets the sampling period. (With the same step size as the time fusion algorithm), bias data is collected once every 1ms; The deviations are calculated, including time deviation and phase deviation. Specifically, the time deviation... ( Sampling step size (in nanoseconds). Indicates the local OCXO output time; converts the time offset to the phase offset. (OCXO output frequency is) ,cycle The calculation formula is as follows: (Unit: rad); Phase deviation Quantization to digital quantities (such as 16-bit / 32-bit binary) is expressed by the following formula: =r ;in The phase quantization bit depth of the DPLL chip (commonly used) ), To ensure the accuracy of the digital circuit's calculations, rounding is performed to the nearest integer.
[0055] Direct sampling introduces noise (such as electromagnetic interference and sampling jitter), requiring proportional-integral-derivative (PID) filtering to smooth the deviation and output a stable frequency adjustment to meet the low jitter requirements of power scenarios. The core formula for PID filtering is: ; In the formula, Represents the proportionality coefficient (taken in the power scenario). (Rapid response to large deviations) Indicates the integral coefficient (taken in the power scenario). (Eliminate static deviation) Represents the differential coefficients (taken in the power scenario). (to suppress deviation mutations); Indicates the first The frequency adjustment amount (unit: Hz) represents the offset value of the OCXO output frequency that needs to be corrected. This embodiment includes filtering constraints, setting... Threshold (e.g.) (To adapt to the drift range of a 10MHz OCXO), avoiding sudden changes in the control word that could cause the crystal oscillator to lose lock.
[0056] The frequency control word is the core input of the DPLL chip. Essentially, it's the incremental value of the phase accumulator of the numerically controlled oscillator (NCO), and it needs to adjust the frequency. Converted to binary control words recognizable by the DPLL. Taking a 32-bit DPLL as an example, the OCXO nominal frequency... DPLL system clock (DPLL chip internal reference), frequency control word The calculation formula is: =r ; when (No frequency deviation) (32-bit binary: 0x1999999A); when (OCXO is too slow and needs to be accelerated), K(k)=r ≈429496730+4.294967296≈429496730; When Δf(k) = -0.1Hz (OCXO is too fast and needs to be slowed down), K(k)≈429496730-4.294967296≈429496726.
[0057] Different DPLL chips support different numbers of control words (16 / 24 / 32 bits), and the formula needs to be adjusted according to the chip specifications: K(k)=r ; Where M is the number of bits in the DPLL control word (e.g., 24 bits). =16777216), ensuring the control word is within the chip's valid value range (0~). -1) inside.
[0058] After generating the frequency control word in the secure world, the validity of the control word is first verified (e.g., whether it exceeds the preset range). To prevent damage to the crystal oscillator caused by abnormal control words, the control word is sent to the control register of the DPLL chip via a secure bus (such as an SPI / I2C encrypted channel) to prevent tampering during transmission. After receiving the control word, the DPLL chip generates a reference clock of the corresponding frequency through its internal NCO. The phase / frequency of the reference clock is compared with that of the OCXO output clock to generate an error voltage. The error voltage drives the voltage-controlled terminal (VCXO interface) of the OCXO to adjust the resonant frequency of the crystal oscillator, so that the phase / frequency of the OCXO output clock converges to the global safe time. The above process is repeated every 1ms to continuously adjust the control word so that the deviation between the local hardware clock and the global safe time is stabilized within ±1ns (high precision requirements of power systems).
[0059] The time fusion algorithm iterates in a safe world with a fixed discrete step length (1ms in the power scenario, balancing real-time performance and computational efficiency). Specifically, it includes: collecting effective time data from each source every 1ms to perform quality assessment, weight updates, and bias calculations; executing robust Kalman filtering prediction and update steps to correct the local reference time; and outputting the latest global safe time. It serves two purposes: firstly, it generates frequency control words to tame the local crystal oscillator, and secondly, it provides a core secure time reference for the time output module.
[0060] The secure world securely exchanges its local time state (signed by SE) with other trusted devices in the network through a collaborative communication module (data path: secure world -> ordinary world -> collaborative communication module). After these signatures are received, they are sent back to the secure world via a security monitoring call. Distributed consensus logic within the secure world (such as the BFT algorithm) verifies and votes on the collected time information, identifying and eliminating potentially anomalous nodes (such as spoofed nodes), further enhancing the system's overall anti-interference capability.
[0061] Specifically, trusted devices exchange their local time states via SE signature. The secure world uses a customized PBFT algorithm to complete verification, voting, and consensus, eliminating abnormal nodes and enhancing the system's anti-interference capabilities. Specifically, each device signs its local time state (including core time, auxiliary state, and identity identifier) with SE, packages it into a reporting packet, and sends it to other nodes. The receiver first verifies the validity of the public key; if successful, it sends it to the secure world. A master node is elected according to the rules. The master node encapsulates its own and other nodes' time states, generates a pre-preparation message, and sends it to all slave nodes. Slave nodes verify the signature validity and time rationality of the pre-preparation message; if verification passes, they generate a preparation message, feed it back to all nodes, and retain it locally. Each node collects and verifies the preparation message, counts the number of valid votes for each node, determines trusted / abnormal nodes based on a threshold, generates an confirmation message, and synchronizes it to all nodes. The master node calculates the global consensus time based on the trusted node time states using a weighted average, signs it, and synchronizes it to all nodes. Each node uses the consensus time to correct its local global security time and updates the blacklist of abnormal nodes. Abnormal nodes are temporarily isolated, periodically re-verified, and if the abnormality persists, an alarm is triggered; isolation is lifted after normal operation is restored.
[0062] S4. Generate and output a trusted time. When the time needs to be output externally, SecureWorld sends the current precise secure timestamp to the secure cryptographic module for digital signature. The digitally signed time data packet is then sent to the corresponding generator in the time output module.
[0063] The PTP master port will send Announce and Sync messages carrying signature information; the IRIG-B code will embed the signature information; the rising edge of the 1PPS pulse will be strictly aligned with the secure timestamp of the signature.
[0064] After receiving these signals, downstream devices can use a pre-set public key to verify the signature, thereby confirming the authenticity and integrity of the time signal.
[0065] Based on the above hardware structure and working principle, this application constructs a highly secure hardware-level intrinsically secure time synchronization device with inherent security, cooperative anti-interference, and reliable output at the physical level.
[0066] Example 3 Combination Figure 4 Based on Embodiments 1 and 2, this embodiment adopts an industry-standard 19-inch chassis, with each module integrated on the core printed circuit board (PCB). The circuit board adopts a design with at least 4 layers, with complete ground and power layers to ensure signal integrity.
[0067] This application allows for the centralized arrangement of power interfaces, DC-DC converters, and filter capacitor banks, which can be installed on the top edge of the board during actual design. This facilitates heat dissipation and reduces power supply noise interference to subsequent circuits.
[0068] Core modules such as the main control module, crystal oscillator and discipline module, and security cryptography module are centrally located on the board. To ensure that critical timing signals are not interfered with, a metal shield is placed over this area and properly connected to the PCB's ground plane to form a complete electromagnetic shielding environment. The OCXO is placed as close as possible to the clock input pin of the main control module SoC, using the shortest possible trace to reduce clock jitter.
[0069] For each external interface (such as satellite receiving antenna interface, Ethernet port (RJ45 or SFP), IRIG-B input / output terminal, etc.), it is installed on the bottom and / or side of the board, and each interface circuit is equipped with ESD (electrostatic discharge) protection device.
[0070] In this embodiment, the main control module uses NXP's i.MX8 QuadMax series multi-core processor. The SoC is based on the ARM Cortex-A series core and incorporates ARM TrustZone technology. This embodiment allocates a dedicated CPU core (specifically, two Cortex-A72 cores, etc.) to the secure world and configures a dedicated secure memory area (isolated via a TZASC controller). Physically, the SPI bus leading to the secure cryptographic module and the control bus leading to the DPLL in the crystal oscillator and discipline module are directly driven by the SoC's internal secure world peripheral controller, ensuring that critical control paths are isolated from the ordinary world.
[0071] In this embodiment, the security cryptography module uses the CCM3310S-H hardware security chip from Guoxin Technology. This chip is connected to the main control module SoC via the SPI bus. The chip select (CS) signal line of this SPI bus is directly controlled by the pins in the SoC's secure world, ensuring from a hardware connection perspective that the ordinary world cannot directly access the SE.
[0072] In this embodiment, the collaborative communication module includes two independent Ethernet interfaces in hardware. One interface is used for conventional network time protocol communication such as PTP and NTP; the other serves as a dedicated collaborative channel, whose physical layer chip (PHY) uses Marvell's 88E1512, which supports hardware timestamps and electrical isolation. The data stream from this dedicated channel, after preprocessing by the protocol stack in the normal world, is then sent to the secure world for consensus calculation via SMC calls.
[0073] In conjunction with Embodiment 2, the process during device operation in this embodiment is as follows: After the device is powered on, the secure boot ROM code of the main control module first verifies the legitimacy of the secure cryptographic module (i.e., the hardware security chip SE), and then verifies the digital signatures of the trusted operating system (such as OP-TEE) and core time applications (such as time fusion algorithms, consensus logic, etc.) within the executable environment of the main control module. This process establishes an immutable hardware trust chain to ensure the trustworthiness of the system's starting point.
[0074] like Figure 2 As shown in the data stream, the multi-source time input module receives BeiDou / GPS satellite signals and ground PTP link signals in parallel. The underlying drivers for these signals run in the normal world, performing preprocessing tasks such as message parsing and decapsulation to extract the raw time information. Subsequently, this data is transmitted to the TEE secure world through a secure monitoring call (this is the controlled and only communication interface between the normal world and the secure world).
[0075] The preprocessed data undergoes core time processing and clock taming worldwide. Specifically, this includes: Time fusion: The time fusion algorithm (such as robust Kalman filter algorithm) is used to perform quality assessment, deviation calculation and optimal fusion of multiple signal sources, and output a highly reliable global safe time.
[0076] Clock discipline: The global safe time is compared with the local time generated by the OCXO, and the difference is used to generate a frequency control word, which is sent directly to the DPLL chip to dynamically adjust the output frequency and phase of the OCXO, thereby achieving precise discipline.
[0077] Distributed consensus: such as Figure 5 As shown, this device periodically exchanges local time state information, signed by the SE, with other nodes in the network through a dedicated collaborative channel. The consensus logic within the TEE (such as a practical Byzantine fault-tolerant algorithm) verifies the collected signature information and makes majority decisions. If a node's time state is found to differ significantly from the consensus result, it is determined that the node may have been deceived or is malfunctioning, and is marked as untrustworthy locally, thus achieving group-level anti-spoofing capability.
[0078] like Figure 6As shown in the process, when a time signal needs to be output, the TEE sends the current precise secure timestamp to the SE. The SE digitally signs the timestamp using its internally stored private key. Subsequently, the TEE sends the data packet containing the timestamp and digital signature to the time output module. Further, the PTP master port generates Announce and Sync messages carrying signature information; the IRIG-B code generator embeds the signature segment into the time code. Finally, these verifiable real time signals are sent to downstream power equipment (such as protection devices and monitoring and control devices) through physical interfaces, completing end-to-end trusted time transmission.
[0079] The above description is merely an optional embodiment of the present invention and does not limit the patent scope of the present invention. Any equivalent structural transformations made using the content of the present invention under the concept of the present invention, or direct / indirect applications in other related technical fields, are included within the patent protection scope of the present invention.
Claims
1. A time synchronization apparatus for hardware-level innate security, characterized in that, It includes a multi-source time input module, a security password module, a crystal oscillator and discipline module, a time output module, and a cooperative communication module, all of which are electrically connected to the main control module. The main control module is divided into a secure world and a normal world that are physically and logically isolated at the hardware level. The secure world is used to run time processing tasks and store local time references. The secure world directly controls and communicates with the security cryptography module, crystal oscillator and discipline module. The ordinary world runs a general operating system, which is used to interact with the multi-source time input module, the cooperative communication module, and the time output module for data interaction and data preprocessing. Controlled data interaction is achieved between the ordinary world and the secure world through secure monitoring calls.
2. The hardware-intrinsic security time synchronization apparatus according to claim 1, wherein, The multi-source time input module includes multiple independent receiving units, each equipped with an independent signal processing circuit and physical interface, and the output of each receiving unit is connected to the corresponding input interface of the main control module.
3. The hardware-in-the-loop secure time synchronization apparatus of claim 1, wherein, The multi-source time input module includes at least a multi-mode satellite receiver and a terrestrial wired time interface, wherein the multi-mode satellite receiver is used to receive and analyze signals. The terrestrial wired time interface includes at least one or more of the following: a PTP slave clock port, an IRIG-B code input interface, and an NTP client interface.
4. The hardware-in-the-loop secure time synchronization apparatus of claim 1, wherein, The collaborative communication module includes a network controller and a corresponding physical port. The collaborative communication module integrates a hardware encryption engine for encrypting, decrypting, and authenticating the time status information exchanged between devices.
5. The hardware-in-the-loop secure time synchronization apparatus of claim 1, wherein, The secure cryptographic module includes an independent hardware security chip, and the secure cryptographic module is directly connected to the secure world of the main control module. The hardware security chip is used to securely store and manage private keys for asymmetric cryptography algorithms, and to digitally sign timestamp information from the secure world.
6. The hardware-level intrinsically secure time synchronization device according to claim 1, characterized in that, The crystal oscillator and discipline module includes a temperature-controlled crystal oscillator and a digital phase-locked loop (PLL) chip. The PLL chip receives frequency calibration commands sent by the main control module and dynamically adjusts the output phase and frequency to keep the local clock phase and frequency synchronized with the external reference source. When all external signal sources are lost, the system enters hold mode through the temperature-controlled crystal oscillator.
7. The hardware-level intrinsically secure time synchronization device according to claim 1, characterized in that, The time output module includes multiple timecode generators and physical interfaces. The trigger source and time information of the timecode generators come directly from the secure time calculated by the secure world of the main control module. Before outputting the time signal, the time output module sends key time information to the security password module for digital signature, forming a verifiable time signal output with a digital signature.
8. A trusted collaborative method based on a hardware-level intrinsically secure time synchronization device, characterized in that, A time synchronization device with hardware-level intrinsic security as described in any one of claims 1-7 includes the following steps: S1. Perform secure boot and establish a root of trust. After the hardware-level intrinsically secure time synchronization device is powered on, the digital signatures of the trusted operating system and time application in the executable environment of the main control module are verified step by step through the boot code to establish a hardware root of trust. S2. Acquire multi-source time signals and perform preprocessing; Receive external time signals through the multi-source time input module, enter the normal world of the main control module for preliminary analysis, decoding and data packaging, and obtain raw time data; S3. Perform time processing on the preprocessed data within the safe world. Use a time fusion algorithm to perform quality assessment, bias calculation and weighted fusion on the multi-channel preprocessed data to obtain the optimal global safe time. S4. Generate and output a trusted time. When the time needs to be output externally, SecureWorld sends the current global secure timestamp to the secure cryptographic module for digital signature. The time data packet with the digital signature is output through the time output module.
9. The trusted collaboration method based on a hardware-level intrinsically secure time synchronization device according to claim 8, characterized in that, S2 includes the following sub-steps: S2-1. Verify the validity of the data, remove abnormal data from each source, and retain valid time data; S2-2, Unify the time reference, and convert the time data of each signal source into the UTC reference; S2-3. Extract feature quantities: extract the time deviation fluctuation rate, link transmission delay, continuous effective duration of the source, signal-to-noise ratio of satellite source and / or packet loss rate of ground source for each source, which are used as quantitative indicators for source quality assessment.
10. The trusted collaboration method for a time synchronization device based on hardware-level intrinsic security according to claim 9, characterized in that, S3 includes the following sub-steps: S3-1, Multi-source signal quality assessment and weight calculation: Quantitatively score each signal source and calculate the fusion weight of a single signal source based on the scoring results; S3-2, Calculate the time offset of multiple signal sources; S3-3. Based on robust Kalman filtering, the time deviation of multiple information sources is fused and estimated. The local reference time is corrected by the fused deviation value to obtain the global safe time.