Attestation-Based Time Source Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network technologies lack effective methods to authenticate and verify the trustworthiness of time sources, which are crucial for maintaining network security and integrity, as identity authentication of time sources may not be sufficient to prevent compromised time sources from propagating harm throughout the network.

Innovation Solution

The implementation of attestation-based techniques using metadata elements and tokens, such as Proof of Integrity and Secure Unique Device Identification, within time synchronization signals to authenticate and verify the trustworthiness of time sources, ensuring the freshness and authenticity of time synchronization data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If identity authentication of time sources is used, then authentication process is simple, but the time source can still be compromised and propagate harm throughout the network

Engineering Contradiction:
Improveauthentication process simplicityVSAvoidtime source trustworthiness
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies preliminary action by performing trustworthiness evaluation of time sources before using them for time synchronization. The system proactively assesses the trust status of time sources using historical data and operational measurements, and only accepts time synchronization signals from sources that pass this preliminary evaluation, preventing compromised sources from propagating harm throughout the network.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms by continuously monitoring and evaluating the trustworthiness of time sources based on operational data and historical records. The system uses feedback from trustworthiness evaluations to dynamically adjust its acceptance criteria for time synchronization signals, allowing it to respond to changing security conditions and maintain reliable time synchronization even when time sources may be compromised.

Inventive Principle:
Principle #23Feedback

2Reliability

If memory verification checks are performed to validate device trustworthiness, then device security is improved, but the verification process is expensive and time-consuming

Engineering Contradiction:
Improvedevice trustworthiness validationVSAvoidverification time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by performing trustworthiness evaluation of time sources before using them for time synchronization. The system proactively assesses the trust status of time sources using historical data and operational measurements, and only accepts time synchronization signals from sources that pass this preliminary evaluation, preventing compromised sources from propagating harm throughout the network.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces expensive mechanical memory verification checks with alternative trust assessment mechanisms. Instead of performing costly memory validation, the system uses cryptographic signatures, trustworthiness evaluation data, and operational measurements to assess the trust status of time sources, achieving similar security goals with reduced computational overhead and time consumption.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Measurement precision

If historical and operational data are used to quantify likelihood of compromise, then trust assessment accuracy is improved, but data collection and processing complexity increases

Engineering Contradiction:
Improvetrust assessment accuracyVSAvoiddata collection and processing
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies universality by using a multi-functional trustworthiness evaluation framework that handles multiple aspects of trust assessment through a unified system. The same evaluation mechanism processes both historical data and operational measurements, and the system serves multiple functions including time synchronization, security monitoring, and trust assessment, thereby managing data collection and processing complexity through consolidation rather than separation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11245484B2Authenticating time sources using attestation-based methods
Publication Date: 2022.02.08 CISCO TECHNOLOGY INC
  • US11245484B2 patent drawing
  • US11245484B2 patent drawing
  • US11245484B2 patent drawing

AI summary

Systems, methods, and computer-readable media for authenticating time sources using attestation-based techniques include receiving, at a destination device, a time reference signal from a source device, the source and destination devices being network devices. The time reference signal can include a time synchronization signal or a time distribution signal. The destination device can obtain attestation information from one or more fields of the time reference signal and determine whether the source device is authentic and trustworthy based on the attestation information. The destination device can also determine reliability or freshness of the time reference signal based on the attestation information. The time reference signal can be based on a Network Time Protocol (NTP), a Precision Time Protocol (NTP), or other protocol. The attestation information can include Proof of Integrity based a Canary stamp, a hardware fingerprint, a Secure Unique Device Identification (SUDI) of the source device, or an attestation key.