Method for carrying out a time synchronization of a control unit of an iot-device, computer program product, and computer readable medium
The method for IoT-devices ensures secure and cost-effective time synchronization by verifying a time signal's digital signature to restore valid system time, addressing invalid certificate issues post-reset or reboot.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-10-01
- Publication Date
- 2026-04-09
AI Technical Summary
Existing IoT-devices face challenges in maintaining valid system time after a reset or reboot, leading to invalid certificates and preventing access for maintenance due to system time being significantly far in the past, which long-lived certificates are excluded by cybersecurity best-practices.
A method involving a control unit that monitors a data channel from a mobile device for a time signal with a digital signature, verifies a signing key, and adjusts the system time using a verifying key to restore validity, ensuring secure time synchronization.
Enables secure and cost-effective reestablishment of valid system time, allowing maintenance access without compromising cybersecurity, even in network disconnection or power loss scenarios.
Smart Images

Figure EP2025078211_09042026_PF_FP_ABST
Abstract
Description
[0001] Method for carrying out a time synchronization of a control unit of an loT-device, control unit, computer program product, and computer readable medium
[0002] The technology described herein generally relates to a method for operating an IoT(Intemet-of-Things)-device. More particularly, the technology relates to a method for carrying out a time synchronization of a control unit of an loT-device. The technology described herein further relates to the control unit for the loT-device, to a computer program product for carrying out the time synchronization of the control unit by using the method, and a computer readable medium on which the computer program product is stored.
[0003] Many modem loT-devices rely on digital certificates to perform authentication of users or services. Different certificates format exists, but their core functionality is comer stoned in the following pieces of information: a unique identification (ID) of the certificate and of the certificate issuer; a time interval where certificate is considered valid; and a digital signature, e.g., based on asymmetric cryptography, to ensure integrity of the certificate itself. When these conditions hold, the certificate can be used as source of trust for all information contained in the certificate itself, especially a user or service identification and legitimacy of its requests.
[0004] Focusing on the time interval property, a typical loT-device may maintain its own system time aligned with a tme time by combining different methods: synchronization against an external and / or remote trusted time source over a network, e.g., based on NTP / NTPs protocols; and synchronization against an internal and / or local trusted time source, e.g., based on a Real-Time Clock (RTC), which can maintain a valid time even on adverse conditions, such as e.g., a network disconnection, or a power loss, wherein in this case an alternative internal power source, e.g., a battery, may be necessary in order to address the main power loss use case. By these two methods, each device can establish whether its current time is valid or not.
[0005] A problem arises in case of all available methods failing and the system time of the loT- device not being valid, in particular when the system time is significantly far in the past, e.g., Unix epoch, or the beginning of the century, as it is sometimes the case after a reset or reboot of the loT-device. Under this scenario, if the condition persists until a repair intervention, any certificate installed on the loT-device and / or provided by the user or a service interacting with the loT-device is likely to be considered invalid by the loT- device itself, because the system time of the loT-device is erroneously outside the validity interval. The invalid state of the certificate may result in the impossibility to allow access for maintenance and repair intervention over a default network channel used by the loT- device under normal conditions. This problem may be solved by allowing long-lived or permanently valid general-purpose certificates, but this approach is excluded in the most cases by cyber security best-practices due to the high risk associated therewith.
[0006] Accordingly, there may be a need for an alternative approach for carrying out a time synchronization of a control unit of the loT-device.
[0007] Such need may be met with the subject-matter of the independent claims. Advantageous embodiments are defined in the dependent claims as well as in the following specification and the associated figures.
[0008] According to a first aspect of the technology described herein, a method for carrying out a time synchronization of a control unit of an loT-device is described. The method comprises: monitoring a data channel between the loT-device and a mobile device with respect to an incoming time signal, by the control unit; receiving the time signal from the mobile device via the data channel, by the control unit, wherein a time stamp being representative of a current time from a first external trusted time source and a digital signature based on a signing key are encoded within the time signal; verifying the signing key by a verifying key stored within a memory of the control unit; and adjusting a system time of the control unit such that it corresponds to the current time of the time stamp, when the verification was successful.
[0009] According to a second aspect of the technology described herein, a control unit for the loT-device is described. The control unit comprises: a memory for storing the verifying key and at least one timestamp, e.g., the timestamp mentioned above; and a processor communicatively coupled with the memory and being configured to carry out the method as described above and in the following based on the stored verifying key and timestamp. According to a third aspect of the technology described herein, a computer program product is described. The computer program product comprises computer readable instructions which, upon being executed by the processor of the control unit of the loT- device, instruct the control unit to control the loT-device in accordance with the method as described above and in the following. Such computer program product may be stored on a computer readable medium from which the instructions of the program product may be read.
[0010] According to a fourth aspect of the technology described herein, the computer readable medium is proposed, the computer readable medium comprising stored thereon the computer program product. Such computer readable medium may be for example a volatile or non-volatile data memory. For example, the computer readable medium may be a flash memory, a DVD, a CD, a ROM, a RAM, an EPROM or similar devices. Alternatively, the computer readable medium may be part of another computer or server or of a data cloud from which the computer program product may be downloaded for example via a network such as the Internet.
[0011] Ideas underlying embodiments of the technology described herein may be interpreted as being based, inter alia, on the following observations and recognitions.
[0012] Vividly spoken, a method to reestablish a valid current time under the scenario described in the introduction above is provided herewith. The method is based on the following elements: one or more verifying keys installed on the loT device, wherein the verifying keys can be used by the control unit of the loT-device to authenticate incoming requests and / or signals with respect to time synchronization; the mobile device of the user being able to create data sets, e.g., binary blobs, containing at least one digitally signed time stamp and optionally one or more unique identifiers (IDs) of corresponding certificates, wherein the digital signature is created on a counterpart of the verifying key, e.g., as a signing key; and a data channel, e.g., a unidirectional data channel, being available from the mobile device to the loT-device, to transfer the digitally signed data sets.
[0013] This solution can cover a comer case where digital certificates, while still valid in general, cannot be trusted by a single loT-device due to the lack of a valid system time of the loT-device. Also, it can provide a method to reestablish a valid system time in a secure manner in order to avoid any compromission of the cybersecurity chain of trust.
[0014] The use of certificates is going to be more and more adopted to support trustable digital identities of devices, users and services. Full time network availability and continuous monitoring and re-placement of parts, e.g., such as an empty battery, can be costly to maintain, and even impossible to guarantee in some specific business cases, e.g., in case of third-party maintenance. However, the solution presented herein provides a cost- effective method to address these problems.
[0015] The signing key and the verifying key mate to each other, e.g., such as a private key and a public key. The signing key may be the private key, for example. The signing key may be stored on the mobile device. The mobile device may use the signing key when generating the time signal. The verifying key may be the public key, for example. The verifying key and optionally one or more further verifying keys may be stored within the memory of the control unit. The data contained within the time signal may be encoded within the time signal as data set, e.g., as data blob, in particular as a binary blob.
[0016] Verifying the signing key successfully may be seen as a successful authentication of the source of the time signal as being a trustful source of information. When the verification failed, the time signal may be ignored and / or the system time may not be adjusted.
[0017] The data channel may be a “lightweight” data channel. Such a lightweight data channel may be used for transferring a small amount of data only, e.g., for transferring the time signal only. Alternatively or additionally, the lightweight data channel may be used for a short time only, e.g., only for transferring the time signal. So, the data channel may be opened, in other words activated, by the mobile device, may be used for transferring the time signal, and may be closed, in other words deactivated, directly after transferring the time signal.
[0018] According to an embodiment, the method comprises, before monitoring the data channel, comprising recognizing that the system time of the control unit is not valid, by the control unit. For example, when the loT-device is started, the control unit may start by using a default system time of the loT-device and may try to synchronize the default time with current time, but the synchronization fails. Then, the control unit knows and therefore recognizes that the current system time is not correct and therefore not valid. The default time may lie far in the past. Optionally, the data channel may only be monitored in case of the control unit recognizing that the system time of the control unit is not valid.
[0019] According to an embodiment, the data channel is a unidirectional data channel from the mobile device to the loT-device. This may contribute to a high cyber security, because the overall data transfer between the mobile device and the loT-device is strongly limited. For example, the data channel may be an IrDA, BLE, or NFC channel.
[0020] According to an embodiment, after adjusting the system time of the control unit comprising using the adjusted system time for checking a validity of a certificate, wherein the validity of the certificate is timely limited. This may enable to authenticate the source of the certificate and thereby to use any information protected by the certificate.
[0021] According to an embodiment, a unique identification of the certificate is encoded within the time signal; and the unique identification is used for checking the validity of the certificate. This enables that the validity of the single certificate only may be checked by the adjusted system time and no other certificates. This may contribute to a high security of the loT-device and / or the mobile device.
[0022] According to an embodiment, a further synchronization of the loT-device is enabled after verifying the signing key. The further synchronization may refer to a more precise time synchronisation, as described below, or to other data of the loT-device to be synchronized with an external data source. The further synchronization may be a full or complete synchronization. That the synchronization is full or complete may mean that all other data of the loT-device to be synchronized are synchronized with the corresponding external data source. The further synchronization may be carried out via the above-mentioned data channel. Alternatively, another data channel may be used for the further synchronization. This other data channel may be a component of a public network which may be based on NTP / NTPs protocols. The external data source may be a trusted data source, e.g., an external trusted time source. According to an embodiment, the method comprises after adjusting the system time: opening a communication channel from the loT-device to a second external trusted time source, wherein the communication channel is protected by a short-lived certificate; using the timestamp encoded in the time signal to trust this short-lived certificate only; and enabling a communication with the second external trusted time source over this communication channel only. In contrast to the above data channel, the communication channel may be a normal and / or bidirectional communication channel using standard communication protocols such as NTP or NTPs, for example. In particular, the communication channel may not be a lightweight communication channel as described above. The communication channel may be an additional channel with respect to the data channel. Alternatively, the data channel may be altered and in particular expanded such that it can be used as the communication channel. The second external trusted time source may be the same external trusted time source as the first external trusted time source or another external trusted time source. The second external trusted time source may be a timeserver, for example a public time server and / or a full-featured timeserver, e.g., based on NTPs. The timeserver may comprise a RTC.
[0023] According to an embodiment, the current time provided by the timestamp is a coarse time, the communication channel is used for requesting and receiving another timestamp from the second external trusted time source, and a further current time encoded within the further timestamp is a more precise time than the coarse time, and the system time of the control unit is adjusted again, wherein this time it is adjusted such that it corresponds to the more precise time of the further time stamp. A coarse time in the meaning of the present description is always less precise than a precise time. The coarse time in the meaning of the present description may refer to 24 hours, i.e., one day, or more, for example several days, weeks, months, a year, or more than a year, for example. The more precise time may refer to durations shorter than 24 hours, e.g., 1 hour, several minutes, seconds, or microseconds. The 24 hours threshold for the definition of coarse and precise time is based on the RFC 5280: Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile (rfc-editor.org), and 24 hours is the typical time-granularity for certificate expiration. According to an embodiment, the method comprises before receiving the time signal comprising: receiving the timestamp from the first external trusted time source, by the mobile device, generating the time signal depending on the received time stamp and the signing key, by the mobile device, wherein the signing key is stored on a memory of the mobile device; and sending the time signal via the data channel to the loT-device. All steps of the method described above may be carried out by the control unit of the loT- device. In contrast, the new steps of the present embodiment, i.e., receiving the time stamp, generating the time signal and sending the time signal to the loT-device may be carried out by the mobile device. So, the loT-device and the mobile device may represent an loT-system. Thus, the method including all steps mentioned above and including the additional steps of this embodiment may be carried out by the loT-system.
[0024] The mobile device, in particular the user of the mobile device, may request for the timestamp from the first external trusted time source, because the user recognizes that something goes wrong with the loT-device. For example, the user may recognize that the loT-device was not able to synchronize itself at its system start. For example, the mobile device may receive information being representative of the loT-device not working properly and may provide the user with the corresponding information such that the user can trigger receiving the time stamp. Alternatively, the mobile device may start the method automatically, when recognizing that the loT-device does not work properly.
[0025] Embodiments of the method described herein may be implemented in hardware, software or a combination thereof. Particularly, a computer program product may comprise computer readable instructions which instruct a computer processor to execute or control the method steps. The computer processor may be for example the data processor of the elevator use monitoring system. The computer program may be provided in any computer readable language.
[0026] It shall be noted that possible features and advantages of embodiments of the technology described herein are described herein partly with respect to a method for monitoring use and / or passengers in an elevator space and partly with respect to an elevator use monitoring system being configured for implementing such method. One skilled in the art will recognize that the features may be suitably transferred from one embodiment to another and features may be modified, adapted, combined and / or replaced, etc. in order to come to further embodiments of the technology described herein.
[0027] In the following, advantageous embodiments of the technology described herein will be described with reference to the enclosed drawings. However, neither the drawings nor the description shall be interpreted as limiting the technology described herein.
[0028] Fig. 1 shows an loT-system in a first state, according to an embodiment of the technology described herein.
[0029] Fig. 2 shows the loT-system of figure 1 in a second state, according to an embodiment of the technology described herein.
[0030] Fig. 3 shows a flow-diagram of a method for carrying out a time synchronization of a control unit of the loT-device of figures 1 and 2.
[0031] The figures are only schematic and not to scale. Same reference signs refer to same or similar features.
[0032] Fig. 1 shows an loT-system 20 in a first state, according to an embodiment of the technology described herein. The loT-system 20 has an loT-device 22 and a mobile device 24 of a user 28. The loT-device 22 may be or may comprise a sensor, an actuator, a motor, a generator, etc. In addition, the loT-device 22 has a control unit 30. The control unit 30 comprises a memory 32 for storing one or more verifying keys 36 and at least one timestamp, and a processor 34 communicatively coupled with the memory 32 and being configured to carry out the method as described below with respect to figure 3, based on the stored verifying key 36 and timestamp.
[0033] The user 28 may be a service personal for checking, maintaining or repairing the loT- device 22, for example. The mobile device 24 may be a smartphone, tablet computer, or laptop, for example. The mobile device 24 may be configured for communicating with a first external trusted time source 26. The first external trusted time source 26 may be a timeserver, for example a public time server and / or a full-featured timeserver, e.g., based on NTPs. The timeserver may comprise a Real-Time Clock (RTC). At least one signing key 38 is stored within the mobile device 24. The signing key 38 and the verifying key 36 mate to each other, e.g., such as a private key and a public key. For example, the signing key 38 may be the private key. The mobile device 24 can use the signing key 38 when generating a time signal TS for the loT-device 22. In this example, the verifying key 36 may be the public key. The verifying key 36 and optionally one or more further verifying keys (not shown) may be stored within the memory 32 of the control unit 30. The data contained within the time signal TS may be encoded within the time signal TS as data set, e.g., as data blob, in particular as a binary blob.
[0034] The time signal TS may be transferred from the mobile device 24 to the loT-device 22 via a data channel 40. The data channel 40 may be a unidirectional data channel from the mobile device 24 to the loT-device 22. The data channel 40 may be a “lightweight” data channel. Such a lightweight data channel may be used for transferring a small amount of data only, e.g., for transferring the time signal TS only. Alternatively or additionally, the lightweight data channel may be used for a short duration only, e.g., only for transferring the time signal. The short duration may last from 1 second to 1 minute, e.g., from 10 seconds to 1 minute. So, the data channel 40 may be opened, in other words activated, by the mobile device 24, and may be used for transferring the time signal TS only, and may be closed, in other words deactivated, directly after transferring the time signal TS. For example, the data channel 40 may be an Infrared Data Association (IrDA), a Bluetooth Low Energy (BLE), or Near Field Communication (NFC) channel.
[0035] Fig. 2 shows the loT-system of figure 1 in a second state, according to an embodiment of the technology described herein. In the second state, a communication channel 42 between the loT-device 22 and the mobile device 24 is present. The communication channel 42 may be protected by a short-lived certificate.
[0036] In contrast to the data channel 40, the communication channel 42 may be a normal and / or bidirectional communication channel using standard communication protocols such as NTP or NTPs, for example. In particular, it may be the case that the communication channel 42 is not a lightweight communication channel as described above. The communication channel 42 may be an additional channel with respect to the data channel 40. Alternatively, the data channel 40 may be altered and in particular expanded such that it can be used as the communication channel 42. Alternatively, the data channel 40 may be closed and the communication channel 42 may be opened to achieve the second state shown in figure 2.
[0037] Fig. 3 shows a flow-diagram of a method for carrying out a time synchronization of the control unit 30 of the loT-device 22 of figures 1 and 2. The complete method including all steps mentioned below may be carried out by the loT-system 20, i.e., by the loT- device 22 and the mobile device 24. In contrast, steps S2 to S6, i.e., receiving the time stamp, generating the time signal TS and sending the time signal TS to the loT-device 22, which are characterized by dotted lines, may be carried out by the mobile device 24 only, and all other steps may be carried out by the control unit 30 of the loT-device 24.
[0038] The method may be started by the mobile device 24, in particular by the user 28 of the mobile device 24. For example, the user 28 may recognize that something is wrong with the loT-device 22 and may therefore request for the timestamp from the first external trusted time source 26. For example, the user 28 may recognize that the loT-device 22 was not able to synchronize itself at its system start. For example, the mobile device 22 may have received information being representative of the loT-device 22 not working properly and may provide the user 27 with the corresponding information such that the user 28 can trigger requesting and receiving the time stamp. Alternatively, the mobile device 22 may start the method automatically, when recognizing that the loT-device 22 does not work properly.
[0039] In a step S2, the timestamp from the first external trusted time source 26 may be received by the mobile device 24.
[0040] In a step S4, the time signal TS may be generated by the mobile device 24 depending on the received time stamp and the signing key 38 stored on a memory (not shown) of the mobile device 24.
[0041] In a step S6, the time signal TS may be sent from the mobile device 24 via the data channel 40 to the loT-device 22. In an optional step S8, it may be recognizing that the system time of the control unit 30 is not valid, e.g., by the control unit. For example, when the loT-device 22 is started, the control unit 30 may start by using a default system time of the loT-device 22 and may try to synchronize the default time with current time, but the synchronization fails. The default time may lie far in the past. The synchronization may fail because the loT-device 22 may erroneously render a time interval during which a certificate necessary for the synchronization as not being valid, because of the default time used at the system start. Then, the control unit 30 knows and therefore recognizes that the current system time is not correct and therefore not valid.
[0042] Optionally, step S8, which is the first step carried out by the loT-device 22, may be the first step of the method and / or may be used as a trigger for carrying out the steps of the method, in particular the steps described in the following.
[0043] In a step S10, the data channel 40 between the loT-device 22 and the mobile device 22 may be monitored with respect to the incoming time signal TS, in particular by the control unit 30. Optionally, e.g., in case of the optional step S8 having been carried out, the data channel 40 may only be monitored in case of the control unit 30 recognizing that the system time of the control unit is not valid.
[0044] In a step S12, the time signal TS from the mobile device 24 may be received via the data channel 40 by the control unit 30. The time stamp and a digital signature are encoded within the time signal TS. The timestamp is representative of a current time from the first external trusted time source 26. The digital signature is based on the signing key 38 of the mobile device 24. The time signal TS may be generated by the mobile device 24 depending on the timestamp and the signing key 38.
[0045] In a step S 14, the signing key 38 may be verified by one of the verifying keys 36 stored within the memory 32 of the control unit 20.
[0046] In a step S 16, a system time of the control unit 30 may be adjusted such that it corresponds to the current time of the time stamp, when the verification was successful. Verifying the signing key 38 successfully may be seen as a successful authentication of the source of the time signal TS, i.e., the mobile device 24 as being a trustful source of information. When the verification failed, the time signal may be ignored and / or the system time may not be adjusted.
[0047] A possible attack scenario against a vulnerability of the mechanism provided by the steps described in the foregoing may include a violation of the signing key, allowing a rogue user to forge legitimate-like blobs containing an arbitrary timestamp, and / or a compromission of the system time synchronization mechanisms, to activate the monitoring of the data channel 40. In order to prevent such a scenario, the following optional steps may be carried out, for example.
[0048] In an optional step SI 8, the adjusted system time may be used for checking a validity of a certificate, wherein the validity of the certificate is timely limited. The certificate may be the certificate which is necessary for synchronizing the system time in case of a normal operation of the loT-device 22. Optionally, a unique identification (ID) of the certificate may be encoded within the time signal TS. In this case, the ID may be used for checking the validity of the certificate.
[0049] In an optional step S20, a further synchronization of the loT-device 22 may be enabled after verifying the signing key 38. The further synchronization may refer to a more precise time synchronisation, as described below, or to other data of the loT-device 22 to be synchronized with an external data source. The further synchronization may be a full or complete synchronization. The further synchronization may be carried out via the data channel 40. Alternatively, another data channel may be used for the further synchronization, e.g., the communication channel 42. This other data channel may be a component of a public network which may be based on NTP / NTPs protocols. The external data source may be a trusted data source, e.g., an external trusted time source, e.g., the first external trusted time source.
[0050] In an optional step S22, which may be carried out in addition to the step S20 or which may be carried out as a sub-step of the step S20, after adjusting the system time, the communication channel 42 from the loT-device 22 to a second external trusted time source (not shown) may be opened. Preferably, the communication channel 42 is protected by a short-lived certificate. Then, the timestamp encoded in the time signal TS may be used to trust this short-lived certificate only, and a communication with the second external trusted time source over this communication channel 42 only may be enabled. The second external trusted time source may be the same external trusted time source as the first external trusted time source 26 or another external trusted time source. The second external trusted time source may be a timeserver, for example a public time server and / or a full-featured timeserver, e.g., based on NTPs. The timeserver may comprise a Real-Time Clock (RTC).
[0051] Optionally, the current time provided by the timestamp is a coarse time only. In this case, an optional step S24 may be carried out, in which the communication channel 42 is used for requesting and receiving another timestamp from the second external trusted time source, wherein a further current time encoded within the other timestamp is a more precise time than the coarse time provided by the time signal TS. Then, the system time of the control unit 30 may be adjusted again, wherein this time it is adjusted such that it corresponds to the more precise time of the further time stamp. The coarse time in the meaning of the present description is always less precise than the precise time. The coarse time in the meaning of the present description may refer to 24 hours, i.e., one day, or more, for example several days, weeks, months, a year, or more than a year, for example. The more precise time may refer to durations shorter than 24 hours, e.g., 1 hour, several minutes, seconds, or microseconds.
[0052] Embodiments of the method described herein may be implemented in hardware, software or a combination thereof. Particularly, one or more computer program products may comprise computer readable instructions which instruct one or more processors 34 to execute or control the method steps. The processor 34 may be for example processor 34 of the control unit 30, at least for carrying out steps S8 to S24. The computer program may be provided in any computer readable language.
[0053] Finally, it should be noted that the term “comprising” does not exclude other elements or steps and the “a” or “an” does not exclude a plurality. Also elements described in association with different embodiments may be combined. It should also be noted that reference signs in the claims should not be construed as limiting the scope of the claims.
Claims
Claims:
1. Method for carrying out a time synchronization of a control unit (30) of an loT- device (22), the method comprising: monitoring a data channel (40) between the loT-device (22) and a mobile device (24) with respect to an incoming time signal (TS), by the control unit (30); receiving the time signal (TS) from the mobile device (24) via the data channel (40), by the control unit (30), wherein a time stamp being representative of a current time from a first external trusted time source (26) and a digital signature based on a signing key (38) are encoded within the time signal (TS); verifying the signing key (38) by a verifying key (36) stored within a memory (32) of the control unit (30); and adjusting a system time of the control unit (30) such that it corresponds to the current time of the time stamp, when the verification was successful.
2. Method of claim 1, before monitoring the data channel (40), comprising: recognizing that the system time of the control unit (30) is not valid, by the control unit (30).
3. Method of one of the preceding claims, wherein the data channel (40) is a unidirectional data channel (40) from the mobile device (24) to the loT-device (22).
4. Method of one of the preceding claims, after adjusting the system time of the control unit (30) comprising: using the adjusted system time for checking a validity of a certificate, wherein the validity of the certificate is timely limited.
5. Method of claim 4, wherein a unique identification of the certificate is encoded within the time signal (TS); and the unique identification is used for checking the validity of the certificate.
6. Method of one of the preceding claims, whereina further synchronization of the loT-device (22) is enabled after verifying the signing key (38).
7. Method of one of the preceding claims, after adjusting the system time comprising: opening a communication channel (42) from the loT-device (22) to a second external trusted time source, wherein the communication channel (42) is protected by a short-lived certificate; using the timestamp encoded in the time signal (TS) to trust this short-lived certificate only; and enabling a communication with the second external trusted time source over this communication channel (42) only.
8. Method of claim 7, wherein the current time provided by the timestamp is a coarse time, the communication channel (42) is used for requesting and receiving another timestamp from the second external trusted time source, and a further current time encoded within the further timestamp is a more precise time than the coarse time, and the system time of the control unit (30) is adjusted again, wherein this time it is adjusted such that it corresponds to the more precise time of the further time stamp.
9. Method of one of the preceding claims, before receiving the time signal (TS) comprising: receiving the timestamp from the first external trusted time source (26), by the mobile device (24), generating the time signal (TS) depending on the received time stamp and the signing key (38), by the mobile device (24), wherein the signing key (38) is stored on a memory (32) of the mobile device (24); and sending the time signal (TS) via the data channel (40) to the loT-device (22).
10. Control unit (30) for an loT-device (22), the control unit (30) comprising: a memory (32) for storing a verifying key (36) and at least one timestamp; and- 16 - a processor (34) communicatively coupled with the memory (32) and being configured to carry out the method in accordance with one of claims 1 to 8 based on the stored verifying key (36) and time stamp.
11. Computer program product, comprising: computer readable instructions which, upon being executed by the processor of the control unit (30) of claim 10, instruct the control unit (30) to control the loT-device (22) in accordance with the method according to one of claims 1 to 8.
12. Computer readable medium, comprising: a computer program product according to claim 11 stored thereon.
Citation Information
Patent Citations
Device side, server side, network system and network connection method
CN113630364B
Network security time synchronization method and device
CN117639997A
System and method for authenticating a network time protocol (NTP)
US9621689B2