Method for enhancing security of time-of-day message

By encapsulating authentication and integrity verification information on the time synchronization node side, the problem of easy counterfeiting of TOD messages is solved, achieving efficient security and reliable time synchronization.

WO2025260779A1PCT designated stage Publication Date: 2025-12-26ZTE CORP
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/076061
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-06-17
Filing Date
2025-02-06
Publication Date
2025-12-26

AI Technical Summary

Technical Problem

Existing technologies lack security design for TOD messages, making time synchronization nodes easy to be counterfeited, resulting in high overall security risks. Furthermore, the hardware processing capabilities are insufficient to quickly handle complex network protocols.

Method used

The TOD message is modified on the first synchronization node side, encapsulating authentication and integrity verification information, and then verified on the second synchronization node. Only some fields are calculated to enhance security and verification speed.

Benefits of technology

It improves the security and verification speed of TOD messages, reduces the complexity of hardware processing, and enhances the security of message transmission and the reliability of clock synchronization.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025076061_26122025_PF_FP_ABST
    Figure CN2025076061_26122025_PF_FP_ABST
Patent Text Reader

Abstract

Provided is a method for enhancing the security of a time-of-day (TOD) message. The method is applied to a first time synchronization node. The method comprises: receiving a first TOD message, and acquiring preset authentication information and integrity verification information; adding the authentication information and the integrity verification information into the first TOD message, so as to generate a second TOD message; and sending the second TOD message to a second time synchronization node.
Need to check novelty before this filing date? Find Prior Art

Description

Method for enhancing security of time information message

[0001] Cross-reference to Related Applications

[0002] The present disclosure is based on and claims priority from Chinese patent application 2024107800177 filed on June 17, 2024, the disclosure of which is incorporated herein in its entirety by reference. TECHNICAL FIELD

[0003] Embodiments of the present disclosure relate to the field of communication, in particular to a method for enhancing security of time information message. BACKGROUND

[0004] One Pulse per Second (1PPS) signal refers to a precise and synchronous timing signal transmitted from a time synchronization satellite such as Global Positioning System (GPS) or Beidou to a ground receiving device. The signal generates one pulse per second, which is used to synchronize the clock of the ground receiving device. Time of Day (TOD) data refers to time and date data transmitted by the time synchronization satellite, which transmits the current time and date information to the ground device through the signal. The 1PPS+TOD technology realizes high-precision time synchronization and device time calibration by receiving the 1PPS signal and TOD data sent by the GPS satellite, and has a wide range of application fields such as communication, network, etc.

[0005] At present, different operators and manufacturers have their own TOD data interfaces between different network interfaces. These interfaces have successfully supported large-scale commercial wireless base stations, however, the TOD message design in the existing network is early, without any related security design and consideration, and the time synchronization node used to transmit the TOD message is easy to be imitated, with high overall security risk. SUMMARY

[0006] Embodiments of the present disclosure provide a method for enhancing security of time information message, to at least solve the problem that the TOD message design in the network is early without any related security design and consideration in the related art, the time synchronization node used to transmit the TOD message is easy to be imitated, with high overall security risk, etc.

[0007] According to an embodiment of the present disclosure, a method for enhancing security of time information message is provided, applied to a first time synchronization node, the method comprising:

[0008] receive a first time information TOD message, obtain preset authentication information and integrity check information, add the authentication information and the integrity check information to the first TOD message to generate a second TOD message, and send the second TOD message to a second time synchronization node.

[0009] According to another embodiment of the present disclosure, a method for enhancing security of a time information message is provided, and is applied to a second time synchronization node. The method comprises the following steps.

[0010] receiving a second time information TOD message sent by a first time synchronization node, parsing the second TOD message to obtain authentication information, integrity check information and time information in the second TOD message, performing integrity check on the second TOD message according to the authentication information, the integrity check information and the time information, and performing time synchronization according to a check result.

[0011] According to still another embodiment of the present disclosure, a computer readable storage medium is further provided, and the computer readable storage medium stores a computer program. The computer program is configured to execute the steps in any of the above method embodiments when running.

[0012] According to still another embodiment of the present disclosure, an electronic device is further provided, which comprises a memory and a processor. The memory stores a computer program, and the processor is configured to execute the computer program to perform the steps in any of the above method embodiments.

[0013] According to still another embodiment of the present disclosure, a computer program product is further provided, which comprises a computer program. The computer program is executed by a processor to implement the steps in any of the above method embodiments. BRIEF DESCRIPTION OF DRAWINGS

[0014] FIG. 1 is a hardware structure block diagram of a mobile terminal of a method for enhancing security of a time information message according to an embodiment of the present disclosure;

[0015] FIG. 2 is a time synchronization networking architecture diagram according to an embodiment of the present disclosure;

[0016] FIG. 3 is a flowchart of a method for enhancing security of a time information message according to an embodiment of the present disclosure;

[0017] FIG. 4 is a format diagram of a TOD message according to an embodiment of the present disclosure;

[0018] FIG. 5 is a format diagram of a TOD message according to an embodiment of the present disclosure;

[0019] FIG. 6 is a calculation process diagram of integrity check information according to an embodiment of the present disclosure;

[0020] FIG. 7 is a key sharing diagram according to an embodiment of the present disclosure;

[0021] FIG. 8 is a schematic diagram of a calculation process of integrity check information according to another embodiment of the present disclosure;

[0022] FIG. 9 is a flowchart of a method for enhancing security of time information message according to another embodiment of the present disclosure. DETAILED DESCRIPTION

[0023] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the accompanying drawings and in conjunction with embodiments.

[0024] It should be noted that the terms "first", "second", and the like in the specification and claims of the present disclosure and the above-described drawings are used to distinguish similar objects, and do not necessarily have to describe a specific order or sequence.

[0025] The traditional clock synchronization mechanism is involved in the early stage, and no security-related design and consideration is made. The time synchronization node for transmitting TOD message is easily imitated, and the TOD message is limited to low-rate transmission and has limited resource processing capability, and cannot handle too complex network protocols.

[0026] The current related solution usually uses asymmetric algorithm in hardware to encrypt the entire TOD message, but the entire message needs to be calculated for decryption, the management of public and private key pairs is complex, and the hardware processing capability is not strong enough, resulting in slow encryption and decryption and long time consumption.

[0027] Based on the above-mentioned technical problems, the present disclosure proposes a method for enhancing security of time information message, and the technical concept is to modify the TOD message on the first time synchronization node side, encapsulate the authentication information and integrity check information, and only need to calculate part of the fields in the TOD message when checking at the second time synchronization node. The method not only enhances the security of the TOD message but also improves the checking speed, and the scheme is simple and has good hardware compatibility.

[0028] The method embodiments provided in the embodiments of the present disclosure can be executed in a mobile terminal, a computer terminal or similar computing device. Taking the case of running on a mobile terminal, FIG. 1 is a hardware structure block diagram of a mobile terminal of a method for enhancing security of time information packets according to an embodiment of the present disclosure. As shown in FIG. 1, the mobile terminal can include one or more (only one is shown in FIG. 1) processors 102 (the processor 102 can include, but is not limited to, a processing device such as a microprocessor MCU or a programmable logic device FPGA) and a memory 104 for storing data, wherein the mobile terminal can further include a transmission device 106 for communication function and an input and output device 108. Those skilled in the art can understand that the structure shown in FIG. 1 is only schematic, which does not limit the structure of the mobile terminal. For example, the mobile terminal can further include more or less components than those shown in FIG. 1, or have a different configuration from that shown in FIG. 1.

[0029] The memory 104 can be used to store computer programs, for example, software programs of application software and modules, such as the computer program corresponding to the method for enhancing security of time information packets in the embodiments of the present disclosure. The processor 102 executes various functional applications and data processing by running the computer programs stored in the memory 104, that is, implements the above-mentioned method. The memory 104 can include a high-speed random access memory, and can further include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some examples, the memory 104 can further include a memory remotely arranged with respect to the processor 102, which can be connected to the mobile terminal through a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0030] The transmission device 106 is used to receive or send data via a network. Specific examples of the above-mentioned network can include a wireless network provided by a communication provider of the mobile terminal. In one example, the transmission device 106 includes a network adapter (Network Interface Controller, NIC), which can be connected to other network devices through a base station so as to communicate with the Internet. In one example, the transmission device 106 can be a radio frequency (Radio Frequency, RF) module, which is used to communicate with the Internet in a wireless manner.

[0031] FIG. 2 is a time synchronization networking architecture diagram according to an embodiment of the present disclosure, and the embodiment of the present disclosure can run on the networking architecture shown in FIG. 2. As shown in FIG. 2, the networking architecture includes a first time synchronization node and a second time synchronization node. The first time synchronization node can be used to provide a reference signal of precise time for subordinate network synchronization, and can be a device or system capable of providing a reference signal of precise time, such as an atomic clock, a time synchronization satellite, or a network time server with high precision synchronization. The second time synchronization node can be used to obtain the reference signal of precise time provided by the first time synchronization node, and synchronize time at the local end. The second time synchronization node can be a network time server, a base station, or a user terminal provided by a network time protocol.

[0032] In time synchronization, the second time synchronization node can receive a TOD message from the first time synchronization node, and synchronize the received signal with the local time through a preset synchronization mechanism to ensure that the two times are consistent.

[0033] It should be noted that in a multi-level networking device, the first time synchronization node and the second time synchronization node are only described from the logical function of time synchronization relationship. The current node can be a second time synchronization node to the upper node, but a first time synchronization node to the lower node. That is, the physical node in the networking can be a second time synchronization node or a first time synchronization node, and one physical node can correspond to two or more logical nodes.

[0034] The method for enhancing the security of time information messages according to the embodiment of the present disclosure can be applied to time synchronization satellites and ground receiving networks, for example, high-precision time synchronization interfaces between communication devices such as base stations.

[0035] The method for enhancing the security of time information messages according to the embodiment of the present disclosure can be applied to the transmission process of TOD messages between the clock time server and the clock synchronization node in the ground network, to ensure that the clock time server is reliable and the TOD message is not tampered with during transmission.

[0036] In the embodiment, a method for enhancing the security of time information messages running on the above mobile terminal or networking architecture is provided, and is applied to the first time synchronization node. FIG. 3 is a flowchart of the method for enhancing the security of time information messages according to an embodiment of the present disclosure. As shown in FIG. 3, the flow includes the following steps:

[0037] In step S301, a first time information TOD message is received, and preset authentication information and integrity verification are obtained.

[0038] As an example, the first time synchronization node can receive a first TOD message sent by a previous node of the first time synchronization node. The previous node of the first time synchronization node can also be an atomic clock, a time synchronization satellite, or a high-precision network time server, and the like.

[0039] As an example, the authentication information can include at least one of the following information: identity information of the first time synchronization node, an authentication mode, an authentication algorithm, a key identifier, and the like.

[0040] As an example, the integrity check information includes information used to check the time information in the TOD message. For example, the integrity check information can include a check value calculated based on the authentication information.

[0041] For example, FIG. 4 is a format diagram of a TOD message according to an embodiment of the present disclosure. As shown in FIG. 4, the TOD message sent by the present disclosure can include a frame header 1, a frame header 2, a newly added authentication control payload, a message type, a message ID, a message length field, a payload field, a newly added integrity check payload, and the like.

[0042] The authentication control payload can encapsulate identity information, an authentication mode, an authentication algorithm, a key identifier (optional), and other control information (optional), and the like. The integrity check payload can encapsulate check description (optional), check data, and the like.

[0043] It should be noted that a person skilled in the art can selectively encapsulate the key identifier and other control information in the newly added authentication control payload according to actual needs, and can selectively encapsulate the check description information in the newly added integrity check payload according to actual needs.

[0044] In an exemplary embodiment, the first TOD message carries time information; the authentication information includes identity information of the first time synchronization node, an authentication mode, and an authentication algorithm, and the integrity check information is obtained by:

[0045] According to the identity information of the first time synchronization node, the authentication mode, the authentication algorithm, and the time information, integrity calculation is performed to obtain the integrity check information.

[0046] As an example, the first TOD message before modification can carry time information, and the second TOD message is a modification based on the first TOD message. The second TOD message also carries time information.

[0047] As an example, when the first time synchronization node sends the TOD message in the network, the identity information of the first time synchronization node can be added in the authentication control load according to the modified TOD message format, and the identity information of the first time synchronization node can be managed and allocated by a unified device management system.

[0048] As an example, the identity information encapsulated in the authentication control load can include at least one of the following: a unique identifier of the current network device, a base station ID, and the like. The unique identifier of the current network device can be an electronic serial number (ESN) of a rack, a frame, a slot, a single board, or the like of the device.

[0049] As an example, the first time synchronization node can select an authentication method and an authentication algorithm corresponding to the identity information according to network planning, and can write the identity information, the authentication method, and the authentication algorithm of the first time synchronization node into fields corresponding to the authentication control load, respectively.

[0050] As an example, the authentication method can include no authentication or other authentication methods for the identity information (such as shared secret key, digital signature, and the like). The authentication algorithm corresponding to the identity information can be selected from a pre-set list of authentication algorithms.

[0051] As an example, the integrity check load is used for integrity protection of information that needs to be protected in the TOD message load that needs to be protected, such as the identity information of the first time synchronization node and the time information. The integrity check information encapsulated in the integrity check load protects the identity information of the first time synchronization node and the time information from being tampered with during transmission. The integrity check information can be a fixed-length message code calculated by an integrity algorithm.

[0052] As an example, the integrity check information can be calculated based on the field content of the TOD message that needs to be protected, such as the identity information of the first time synchronization node and the time information (which can include time and time status), and the calculated integrity check information can be filled into the integrity check load and encapsulated into a new TOD message for sending.

[0053] For example, FIG. 5 is a schematic diagram of a TOD message format according to an embodiment of the present disclosure. As shown in FIG. 5, the TOD message includes a frame header 1, a frame header 2, an authentication control load (Authorization, Auth), a message type, a message ID, a message length field, a payload field, a message authentication code (Hash-based Message Authentication Code, HMAC) / digital signature load Sign, a frame check sequence (FCS), and the like.

[0054] The gray message payload is a new security payload, including an authentication control payload and a message authentication code HMAC / digital signature payload Sign. The authentication control payload header (Authentication Header) can include a version number (Version number, Ver) (e.g., the Ver field occupies 2 bits in length), an authentication mode Mode (e.g., Mode takes a value of 1 or Mode takes a value of 2), a reserved field Reserved (e.g., the Reserved field occupies 4 bits in length), and the like. The authentication mode can include no authentication, HMAC authentication, digital signature authentication, and the like.

[0055] For the HMAC authentication mode (e.g., Mode = 1), the field value of the authentication algorithm Algorithms can represent different HMAC algorithms, for example, SM3 (Algorithm takes a value of 0), SHA2-128 (Algorithm takes a value of 1), SHA2-256 (Algorithm takes a value of 2), and the like. The HMAC payload length is related to the HMAC algorithm, and the specific value can be agreed by both parties, and the default value can be 16 Bytes.

[0056] For the digital signature mode (e.g., Mode = 2), the field value of the authentication algorithm can represent different signature algorithms, for example, SM2 (Algorithm takes a value of 0) (Hash algorithm is SM3), RSA-2048 (Algorithm takes a value of 1) (Hash algorithm is SHA2-256), ECDSA (Algorithm takes a value of 2) (Hash algorithm is SHA2-256), and the like. The digital signature payload length is related to the Hash algorithm, and the specific value can be agreed by both parties, and the default value can be 128 Bytes.

[0057] FIG. 6 is a schematic diagram of a calculation process of integrity check information according to an embodiment of the present disclosure. As shown in FIG. 6, the identity information of the first time synchronization node, the authentication information, and the time information can be calculated to obtain a message digest according to the algorithm configured in the authentication control payload, and the message digest is encrypted by adding the private key of the first time synchronization node to obtain the integrity check information. Thus, the security of the TOD message based on the digital signature mode is enhanced.

[0058] In an exemplary embodiment, the first TOD message carries time information, and the authentication information includes first time synchronization node identity information, an authentication mode, an authentication algorithm, and a secret key identifier. The integrity check information is obtained by:

[0059] According to the first time synchronization node identity information, the authentication mode, the authentication algorithm, the key identifier, and the time information, integrity calculation is performed to obtain the integrity check information.

[0060] As an example, the authentication information can further include a key identifier, which can be used to identify the shared key information between the two parties in a shared key scenario.

[0061] As an example, the first time synchronization node can select the authentication mode and the authentication algorithm corresponding to the identity information according to network planning, or can pre-import a key set corresponding to the identity information, which can include a key identifier, and can write the identity information, the authentication mode, the authentication algorithm, and the key identifier of the first time synchronization node into the fields corresponding to the authentication control payload, respectively.

[0062] As an example, the integrity check payload can be used to protect the information in the TOD message payload that needs to be protected, such as the identity information of the first time synchronization node, the time information, and the shared key information, so that these information cannot be tampered with during transmission. The integrity check information can be a fixed-length message code calculated by an integrity algorithm.

[0063] As an example, the integrity check information can be calculated according to the field content of the TOD message that needs to be protected, such as the identity information of the first time synchronization node, the time information, and the shared key information, and the calculated integrity check information can be filled into the integrity check payload and encapsulated into a new TOD message for transmission.

[0064] In an exemplary embodiment, before adding the authentication information and the integrity check information to the first TOD message, the method further includes:

[0065] Synchronizing a preset key set to the second time synchronization node; wherein the key set includes the key identifier and the key corresponding to the key identifier.

[0066] As an example, the authentication algorithm of the TOD message, the identity information of the first time synchronization node or the second time synchronization node, and the key set or the user digital certificate / public key corresponding to the identity information can be pre-configured on the first time synchronization node. The key set can be one or more key queues, each key queue in the multiple key queues has a unique key identifier, and the corresponding key can be found according to the key identifier. The digital certificate can be an authentication certificate based on standard public and private key authentication. The corresponding key information also needs to be synchronized and imported on the second time synchronization node.

[0067] For example, FIG. 7 is a schematic diagram of key sharing according to an embodiment of the present disclosure. As shown in FIG. 7, the first time synchronization node and the second time synchronization node can be pre-configured with the same shared key list (i.e., key set), which can include keys and key identifiers (e.g., numbers) corresponding to the keys. The first time synchronization node and the second time synchronization node can obtain the corresponding keys from the locally stored key set by the key identifiers. The first time synchronization node can only transmit the key identifiers when sending the TOD message, and the second time synchronization node can obtain the corresponding keys by the identifiers when calculating the integrity check payload.

[0068] For example, FIG. 8 is a schematic diagram of a calculation process of integrity check information according to another embodiment of the present disclosure. As shown in FIG. 8, the message digest can be calculated according to the identity information, authentication information, time information, key information of the first time synchronization node, and the integrity check algorithm configured in the authentication control payload. Thus, the security of the TOD message based on the shared key mode is enhanced.

[0069] In step S302, the authentication information and the integrity check information are added to the first TOD message to generate a second TOD message.

[0070] For example, the first time synchronization node in the embodiment of the present disclosure can modify the TOD message before sending the TOD message, and encapsulate the authentication information and the integrity check information in some fields in the TOD message. When the second time synchronization node checks, only part of the fields in the TOD message need to be calculated, which not only enhances the security of the TOD time message but also improves the checking speed, and the scheme is simple and has good hardware compatibility.

[0071] In an exemplary embodiment, the adding of the authentication information and the integrity check information to the first TOD message to generate a second TOD message includes:

[0072] adding an authentication control payload and an integrity check payload in the first TOD message;

[0073] adding the authentication information to the authentication control payload and adding the integrity check information to the integrity check payload to generate a second TOD message.

[0074] In the embodiment of the present disclosure, when the first TOD message sent by the previous node of the first time synchronization node is received, the authentication control payload and the integrity check payload can be added in the first TOD message, the authentication information can be added to the authentication control payload, and the integrity check information can be added to the integrity check payload to obtain the encapsulated second TOD message. By adding the authentication control payload and the integrity check payload in the TOD message, the security of the TOD message is increased.

[0075] As an example, the first time synchronization node adds corresponding authentication control load and integrity check load in the first TOD message according to the preset configuration algorithm and the like, adds authentication information to the authentication control load, adds integrity check information to the integrity check load, obtains a new encapsulated TOD message, and sends the same.

[0076] As an example, the field position of the authentication control load and the message integrity check load in the message can be customized according to actual needs. For example, the authentication control load can be arranged at the front end of the TOD message to facilitate extraction by the receiving end, and the integrity check load can be arranged at the tail end of the TOD message to facilitate verification calculation after processing the TOD message by the receiving end.

[0077] In step S303, the second TOD message is sent to the second time synchronization node.

[0078] For example, the second TOD message can be sent to the second time synchronization node to enable the second time synchronization node to complete verification and perform clock synchronization.

[0079] In the embodiments of the present disclosure, the first time information TOD message sent by the previous node of the first time synchronization node is received, authentication information and integrity check information are added to the first TOD message to generate a second TOD message, and the second TOD message is sent to the second time synchronization node. By adding message authentication information and integrity check information to the existing TOD message, the problem that the TOD message in the network is designed earlier in the related art and has no any related security design and consideration, and the time synchronization node used to deliver the TOD message is easily imitated and the overall security risk is high is solved, the integrity of the clock message transmission is protected, the time information in the message transmission process is avoided from being tampered, and the security of message delivery between the first time synchronization node and the second time synchronization node is enhanced.

[0080] In the embodiments of the present disclosure, a method for enhancing the security of time information messages running on the mobile terminal or the networking architecture is also provided, and is applied to the second time synchronization node. FIG. 9 is a flowchart of the method for enhancing the security of time information messages according to another embodiment of the present disclosure. As shown in FIG. 9, the flowchart includes the following steps:

[0081] In step S901, the second time information TOD message sent by the first time synchronization node is received, and the second TOD message is parsed to obtain authentication information, integrity check information, and time information in the second TOD message.

[0082] Exemplarily, the second time synchronization node can receive the second TOD message sent by the first time synchronization node, and can parse the second TOD message to obtain authentication information, integrity check information and time information in the second TOD message.

[0083] In an exemplary embodiment, the second TOD message comprises an authentication control payload and an integrity check payload, and the parsing of the second TOD message to obtain authentication information and integrity check information in the second TOD message comprises:

[0084] the authentication information is obtained from the authentication control payload, and the integrity check information is obtained from the integrity check payload.

[0085] As an example, after receiving the second TOD message, the second time synchronization node can parse the corresponding authentication control payload and integrity check payload from the second TOD message.

[0086] As an example, after receiving the second TOD message, the second time synchronization node can extract authentication information in the authentication control payload in the second TOD message, wherein the authentication information can comprise identity information of the first time synchronization node, an authentication mode, an authentication algorithm, etc.

[0087] As an example, after receiving the second TOD message, the second time synchronization node can extract integrity check information in the integrity check payload in the second TOD message.

[0088] Step S902, performing integrity check on the second TOD message according to the authentication information, the integrity check information and the time information, and performing time synchronization according to a check result.

[0089] Exemplarily, the second time synchronization node can perform integrity check on the second TOD message according to the parsed authentication information, integrity check information and time information, and perform time synchronization according to a check result.

[0090] In an exemplary embodiment, the performing time synchronization according to the check result comprises:

[0091] determining that the check result is a check success, and performing time synchronization according to the time information.

[0092] Exemplarily, the second time synchronization node can perform time synchronization according to the parsed time information in a case where the check result is a check success.

[0093] In an exemplary embodiment, the authentication information comprises identity information of the first time synchronization node, and the performing time synchronization according to the time information comprises:

[0094] comparing the first time synchronization node identity information with identity information in a preset identity information list;

[0095] determining that the first time synchronization node identity information matches identity information in the identity information list, and performing time synchronization according to the time information.

[0096] Exemplarily, the authentication information can include first time synchronization node identity information, and the second time synchronization node can compare the first time synchronization node identity information with identity information in a preset identity information list, and can perform time synchronization according to the time information in a case where the first time synchronization node identity information matches identity information in the identity information list.

[0097] As an example, the device management system can previously import a list of identity information of trusted first time synchronization nodes into the second time synchronization node, and can compare whether the first time synchronization node identity information in the TOD message is within the range of the imported identity information list after completing authentication and integrity verification of the TOD message. If yes, the time can be synchronized, otherwise, the TOD message can be discarded and recorded, and the recording result can be reported to the management node.

[0098] As an example, the first time synchronization node identity information carried by the TOD message can be compared with identity information in a preset identity information list. If the first time synchronization node identity information carried by the TOD message matches identity information in the identity information list, the second time synchronization node can receive the TOD message and synchronize the clock; otherwise, error information is recorded and reported to the management system.

[0099] In an exemplary embodiment, the authentication information further includes an authentication mode and an authentication algorithm, and the integrity verification of the second TOD message according to the authentication information, the integrity verification information and the time information includes:

[0100] calculating integrity verification information according to the first time synchronization node identity information, the authentication mode, the authentication algorithm and the time information;

[0101] performing integrity verification of the second TOD message according to the calculated integrity verification information and the integrity verification information obtained from the second TOD message.

[0102] Exemplarily, the authentication information can further include an authentication manner and an authentication algorithm, and the second time synchronization node can calculate integrity check information according to the first time synchronization node identity information, the authentication manner, the authentication algorithm and the time information, and perform integrity check on the second TOD message according to the calculated integrity check information and the integrity check information parsed from the second TOD message.

[0103] As an example, the second time synchronization node can obtain the authentication manner, the authentication algorithm, the first time synchronization node identity information and the time information to be protected carried in the authentication control payload of the current TOD message, calculate the integrity check information through the algorithm carried in the authentication control payload, and compare the calculated integrity check information with the integrity check information carried in the integrity check payload of the current TOD message. If the calculated integrity check information is consistent with the integrity check information carried in the integrity check payload of the current TOD message, it can be considered that the first time synchronization node identity is trusted and the TOD message transmission process is not tampered.

[0104] For example, as shown in FIG. 6, the second time synchronization node can decrypt the integrity check payload according to the first time synchronization node public key saved locally to obtain the corresponding message digest; the second time synchronization node calculates the message digest of the received TOD message according to the same authentication algorithm as the first time synchronization node, and can compare the message digest decrypted by the public key with the calculated message digest. If the message digest decrypted by the public key is consistent with the calculated message digest, it can be considered that the first time synchronization node sending the TOD message is trusted and the message transmission process is not tampered, so that the security of the TOD message based on the signature manner is enhanced.

[0105] In an exemplary embodiment, the authentication information further includes an authentication manner, an authentication algorithm and a key identifier, and the integrity check on the second TOD message according to the authentication information, the integrity check information and the time information includes:

[0106] According to the key identifier, a key corresponding to the key identifier is obtained from a preset key set;

[0107] According to the key, the first time synchronization node identity information, the authentication manner, the authentication algorithm and the time information, integrity check information is calculated;

[0108] According to the calculated integrity check information and the integrity check information parsed from the second TOD message, integrity check is performed on the second TOD message.

[0109] Exemplarily, the authentication information can further include a key identifier. The second time synchronization node can obtain, according to the key identifier, a key corresponding to the key identifier from a preset key set, can calculate integrity check information according to the key, the first time synchronization node identity information, the authentication mode, the authentication algorithm and the time information, and can perform integrity check on the second TOD message according to the calculated integrity check information and the integrity check information obtained from the second TOD message.

[0110] As an example, the second time synchronization node can obtain the authentication mode, the authentication algorithm, the first time synchronization node identity information, the key identifier and the time information to be protected carried in the authentication control payload of the current TOD message, calculate the integrity check information through the algorithm carried in the authentication control payload, and compare the calculated integrity check information with the integrity check information carried in the integrity check payload of the current TOD message. If the calculated integrity check information is consistent with the integrity check information carried in the integrity check payload of the current TOD message, it can be considered that the first time synchronization node identity is trusted and the TOD message transmission process is not tampered.

[0111] For example, as shown in FIG. 8, after receiving the TOD message, the second time synchronization node can obtain the integrity check information carried in the integrity check payload of the TOD message, can obtain the key saved at the second time synchronization node end according to the key identifier carried in the TOD message, can calculate the integrity check information (i.e. message digest) of the TOD message according to the same authentication algorithm as the first time synchronization node, can compare the integrity check information carried in the integrity check payload with the calculated integrity check information of the TOD message, and if the integrity check information carried in the integrity check payload is consistent with the calculated integrity check information of the TOD message, it can be considered that the TOD message is sent by a trusted first time synchronization node and the TOD message is not tampered in the transmission process, and the TOD security enhancement based on the shared key mode.

[0112] In an exemplary embodiment, before receiving the second time information TOD message sent by the first time synchronization node, the method further includes:

[0113] synchronizing the preset key set to the first time synchronization node; wherein the key set includes the key identifier and the key corresponding to the key identifier.

[0114] As an example, the second time synchronization node can pre-receive and synchronize the authentication algorithm of the TOD message sent by the first time synchronization node, the first time synchronization node identity information, and import the corresponding key information, which can be a key set or a user digital certificate / public key. The key set can be one or more key queues, and each group of keys in the multiple key queues has a unique key identifier. The second time synchronization node can search for the corresponding key according to the key identifier. The corresponding key information also needs to be synchronized and imported on the second time synchronization node. The digital certificate can be an authentication certificate based on standard public-private key pair authentication.

[0115] As an example, the second time synchronization node can determine whether to extract the key identifier according to the local configuration. If it is determined to extract the key identifier, the key identifier can be obtained from the pre-configured key set, and then the integrity check information of the received TOD message can be calculated according to the authentication information and the integrity check algorithm in the authentication control load. The calculated integrity check information can be compared with the integrity check information carried in the integrity check load. If the calculated integrity check information is consistent with the integrity check information carried in the integrity check load, it can be concluded that the TOD message is sent by a trusted time service node and the TOD message has not been tampered with illegally in the transmission process, and the time can be synchronized. Otherwise, error information can be recorded and reported to the management system.

[0116] In the embodiments of the present disclosure, the second time synchronization node receives the second TOD message sent by the first time synchronization node, and analyzes the second TOD message to obtain the authentication information, the integrity check information, and the time information in the second TOD message. The second TOD message is subjected to integrity check according to the authentication information, the integrity check information, and the time information, and the time is synchronized according to the check result. Thus, the security problem in the transmission process of the traditional TOD message is solved, the reliability of the clock source is protected, the anti-fraud capability is increased, the integrity of the clock message transmission is protected, the time information in the transmission process of the message is avoided to be tampered with, and the security of the clock synchronization is enhanced.

[0117] The authentication process of the TOD message in the embodiments of the present disclosure is further described below through two examples:

[0118] Example 1:

[0119] Authentication based on pre-shared key mode:

[0120] 1. The authentication method and authentication algorithm (such as HMAC authentication-SM3 algorithm) of the TOD message, the first time synchronization node identity information (such as configuring the first time synchronization node identity information as the master control board ESN and gNB ID corresponding to the device), and the imported corresponding key set (such as importing 8 different keys) can be pre-configured on the first time synchronization node and the second time synchronization node.

[0121] 2. The first time synchronization node can select the third key according to the pre-configured authentication algorithm field, that is, the corresponding key identifier keyID=3, and obtain the third key from the local configuration key set, fill in the corresponding random salt value (salt), select the HMAC authentication method, and the authentication algorithm HMAC=Hash(message type|message ID|payload field|identity|Key|Salt), wherein the Hash algorithm can be SM3 algorithm, and “|” is a connection symbol; integrity calculation is performed according to the first time synchronization node identity information, the HMAC authentication method, the SM3 algorithm, the key identifier keyID=3, and the like, a message digest is obtained, the message digest is filled into the integrity check payload, the authentication information is filled into the authentication control payload, and the TOD message is sent to the second time synchronization node.

[0122] 3. After receiving the TOD message, the second time synchronization node can parse the corresponding authentication information from the TOD message, and determine that the authentication method of the current TOD message is pre-shared key authentication according to the key identifier in the authentication information.

[0123] 4. The second time synchronization node can obtain the authentication algorithm SM3 and the key identifier keyID=3 in the authentication information, and obtain the corresponding key from the local key set through the third key identifier, and obtain the random salt Salt value in the TOD message.

[0124] 5. The second time synchronization node can use the authentication algorithm SM3 in the authentication information carried by the TOD message to calculate the corresponding HMAC' value, and compare the HMAC' value with the HMAC carried by the message.

[0125] 6. If HMAC' and HAMC are the same, the first time synchronization node identity information ESN and gNB ID can be further compared with the identity information in the pre-configured identity information list to determine whether the ESN and gNB ID are in the identity information list.

[0126] 7、If the first time synchronization node identity information ESN and gNB ID are in the pre-configured identity information list, the second time synchronization node can receive the TOD message and synchronize the clock; if the first time synchronization node identity information ESN and gNB ID are not in the pre-configured identity information list, the TOD message can be discarded and recorded, and the recording result is reported to the current device network management.

[0127] In the present example 1, the same key set can be configured in the first time synchronization node and the second time synchronization node, and only the corresponding key identifier needs to be transmitted in the transmission process, and the deployment process is simple. The method of the present example 1 reduces the risk of sensitive information transmission leakage, and compared with transmitting original key information, the length of the transmission message is also shortened, and it is especially suitable for scenarios where the TOD message bandwidth is insufficient and the processing capacity is not strong.

[0128] Example 2:

[0129] Authentication based on signature mode:

[0130] 1. The authentication mode and authentication algorithm (such as configuring signature authentication: SM2 signature-SM3 hash algorithm) of the TOD message and the first time synchronization node identity information (such as configuring the first time synchronization node identity information as the ESN and gNB ID corresponding to the master board of the device) and other authentication information can be pre-configured on the first time synchronization node and the second time synchronization node, and the corresponding device digital certificate is imported.

[0131] 2. The first time synchronization node can select the authentication mode as signature authentication and the authentication algorithm as hash algorithm according to the pre-configured authentication mode, authentication algorithm and other fields, hash = Hash(message type | message ID | payload domain | identity), wherein the Hash algorithm is SM3 algorithm, and “|” is the connection symbol. The private key stored locally by the time service node is used to encrypt the calculated Hash to obtain the message digest, the authentication information is filled into the authentication control payload, and the encrypted message digest is filled into the corresponding integrity check payload and encapsulated, and the encapsulated TOD message is sent to the second time synchronization node.

[0132] 3. The second time synchronization node receives the TOD message, parses the corresponding authentication information from the message, and determines that the current TOD message authentication mode is signature authentication.

[0133] 4、The second time synchronization node obtains the signature algorithm (SM2 signature-SM3 hash algorithm) in the authentication control load, calculates the corresponding Hash' value using the authentication algorithm (SM3) in the authentication control load, decrypts the signature load carried by the TOD message using the public key information of the first time synchronization node certificate stored locally, obtains the Hash value carried by the received message, and compares Hash' with Hash.

[0134] 5、If Hash' and Hash are the same, the first time synchronization node identity information ESN and the gNB ID can be compared with the identity information in the preconfigured identity information list according to the preconfigured identity information list, and it is determined whether the ESN and the gNB ID are in the identity information list.

[0135] 6、If the first time synchronization node identity information ESN and the gNB ID are in the preconfigured identity information list, the second time synchronization node can receive the TOD message and synchronize the clock; if the first time synchronization node identity information ESN and the gNB ID are not in the preconfigured identity information list, the TOD message can be discarded and recorded, and the recording result is reported to the current device network management.

[0136] In the present example 2, the certificate can be deployed at the first time synchronization node and the second time synchronization node, and the identity credibility of the TOD message and the integrity and anti-repudiation of the TOD message can be effectively enhanced through the signature.

[0137] Through the above description of the embodiments, those skilled in the art can clearly understand that the method according to the above embodiments can be realized by means of software and necessary general hardware platforms, and of course, it can also be realized by hardware, but in many cases, the former is a better embodiment. Based on such understanding, the technical solutions of the present disclosure can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes a plurality of instructions for making a terminal device (which can be a mobile phone, computer, server, or network device, etc.) execute the methods described in various embodiments of the present disclosure.

[0138] The embodiments of the present disclosure also provide a computer readable storage medium, which stores a computer program, wherein the computer program is configured to execute the steps in any of the method embodiments when running.

[0139] In an example embodiment, the computer readable storage medium described above can include, but is not limited to, a U disk, a Read-Only Memory (ROM), a Random Access Memory (RAM), a mobile hard disk, a magnetic disk or an optical disk, and various media that can store computer programs.

[0140] Embodiments of the present disclosure also provide an electronic device including a memory and a processor, the memory storing a computer program, and the processor being configured to execute the computer program to perform the steps in any of the method embodiments described above.

[0141] In an example embodiment, the electronic device described above can further include a transmission device connected to the processor and an input / output device connected to the processor.

[0142] The specific examples in the present embodiment can refer to the examples described in the above embodiments and example implementations, and the present embodiment will not be described here again.

[0143] Embodiments of the present disclosure also provide a computer program product including a computer program, which, when executed by a processor, implements the steps in any of the method embodiments described above.

[0144] Obviously, those skilled in the art should understand that the modules or steps of the present disclosure described above can be realized by general computing devices, which can be concentrated on a single computing device or distributed on a network composed of multiple computing devices, and they can be realized by program codes executable by computing devices, so that they can be stored in storage devices and executed by computing devices, and in some cases, the steps shown or described can be executed in different order, or they can be manufactured into individual integrated circuit modules, or multiple modules or steps among them can be manufactured into a single integrated circuit module. Thus, the present disclosure is not limited to any specific combination of hardware and software.

[0145] The above only describes example embodiments of the present disclosure and is not intended to limit the present disclosure. For those skilled in the art, the present disclosure can have various modifications and changes. Any modification, equivalent replacement, improvement, etc. within the principles of the present disclosure shall be included in the protection scope of the present disclosure.

Claims

1. A method for enhancing security of a time information message, applied to a first time synchronization node, the method comprising: receiving a first time information (TOD) message, and obtaining preset authentication information and integrity check information; adding the authentication information and the integrity check information to the first TOD message to generate a second TOD message; sending the second TOD message to a second time synchronization node.

2. The method of claim 1, wherein, The adding of the authentication information and the integrity check information to the first TOD message to generate a second TOD message comprises: adding authentication control payload and integrity check payload to the first TOD message; adding the authentication information to the authentication control payload and adding the integrity check information to the integrity check payload to generate a second TOD message.

3. The method according to any one of claims 1-2, wherein, The first TOD message carries time information; the authentication information comprises first time synchronization node identity information, an authentication mode, and an authentication algorithm; and the obtaining of the integrity check information comprises: performing integrity calculation according to the first time synchronization node identity information, the authentication mode, the authentication algorithm, and the time information to obtain the integrity check information.

4. The method according to any one of claims 1-2, wherein, The first TOD message carries time information; the authentication information comprises first time synchronization node identity information, an authentication mode, an authentication algorithm, and a key identifier; and the obtaining of the integrity check information comprises: performing integrity calculation according to the first time synchronization node identity information, the authentication mode, the authentication algorithm, and the key identifier to obtain the integrity check information.

5. The method of claim 4, wherein, Before the adding of the authentication information and the integrity check information to the first TOD message, the method further comprises: synchronizing a preset key set to the second time synchronization node; wherein the key set comprises the key identifier and a key corresponding to the key identifier.

6. A method for enhancing security of a time information message, applied to a second time synchronization node, the method comprising: receiving a second time information (TOD) message sent by a first time synchronization node, and parsing the second TOD message to obtain authentication information, integrity check information, and time information in the second TOD message; performing integrity check on the second TOD message according to the authentication information, the integrity check information, and the time information, and performing time synchronization according to a check result.

7. The method of claim 6, wherein, The second TOD message comprises authentication control payload and integrity check payload; and the parsing of the second TOD message to obtain authentication information and integrity check information in the second TOD message comprises: obtaining the authentication information from the authentication control payload and obtaining the integrity check information from the integrity check payload.

8. The method of claim 6, wherein, The performing of time synchronization according to a check result comprises: determining that the check result is a check success, and performing time synchronization according to the time information.

9. The method of claim 6, wherein, The authentication information comprises first time synchronization node identity information; and the performing of time synchronization according to the time information comprises: comparing the first time synchronization node identity information with identity information in a preset identity information list; determining that the first time synchronization node identity information matches identity information in the identity information list, and performing time synchronization according to the time information.

10. The method of claim 6, wherein, The authentication information further includes an authentication mode and an authentication algorithm, and the integrity check of the second TOD message according to the authentication information, the integrity check information and the time information includes: calculating integrity check information according to the first time synchronization node identity information, the authentication mode, the authentication algorithm and the time information; performing integrity check of the second TOD message according to the calculated integrity check information and the integrity check information parsed from the second TOD message.

11. The method of claim 6, wherein, The authentication information further includes an authentication mode, an authentication algorithm and a key identifier, and the integrity check of the second TOD message according to the authentication information, the integrity check information and the time information includes: obtaining a key corresponding to the key identifier from a preset key set according to the key identifier; calculating integrity check information according to the key, the first time synchronization node identity information, the authentication mode, the authentication algorithm and the time information; performing integrity check of the second TOD message according to the calculated integrity check information and the integrity check information parsed from the second TOD message.

12. The method of claim 11, wherein, Before receiving the second time information TOD message sent by the first time synchronization node, the method further includes: receiving the preset key set synchronized by the first time synchronization node; wherein the key set includes the key identifier and the key corresponding to the key identifier.

13. A computer-readable storage medium having stored therein a computer program, wherein, The computer program is executed by the processor to realize the steps of the method in any one of claims 1 to 5, or to realize the steps of the method in any one of claims 6 to 12. 14.An electronic device comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein the processor executes the computer program to realize the steps of the method in any one of claims 1 to 5, or to realize the steps of the method in any one of claims 6 to 12. 15.A computer program product comprising a computer program, wherein the computer program is executed by a processor to realize the steps of the method in any one of claims 1 to 5, or to realize the steps of the method in any one of claims 6 to 12.

Citation Information

Patent Citations

  • Time synchronization device, equipment and system

    CN103401672A

  • Method, device and system for realizing time synchronization between base station equipment through baseband radio frequency interfaces

    CN107493599A

  • Wireless Fine Time Measurement Authentication

    US20230055972A1

  • Client / server based secure timekeeping system

    US5444780A