Certificate-Based Time Synchronization for Industrial Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Industrial plants face challenges in secure time synchronization due to the vulnerability of existing time synchronization protocols like NTP, which lack integrity protection and require elaborate key management for secure implementation.

Innovation Solution

A system and method for secure time synchronization in industrial plants using a certificate management system, where a registration authority checks and authenticates synchronization requests, allowing plant components to synchronize their system times based on a secure certificate management protocol, eliminating the need for additional keys and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If NTP protocol is used for time synchronization, then time synchronization can be implemented in packet-based networks, but the messages lack integrity protection making them vulnerable to manipulation

Engineering Contradiction:
Improvetime synchronization capabilityVSAvoidintegrity protection
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a registration authority as an intermediary that issues certificates to time sources. These certificates serve as mediators that provide integrity protection to NTP messages without requiring modification of the NTP protocol itself, thus resolving the contradiction between maintaining NTP compatibility and ensuring message integrity

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent separates the time synchronization function from the security verification function. The NTP protocol handles time synchronization while the certificate-based authentication system handles integrity protection independently, allowing both functions to operate optimally without compromising each other

Inventive Principle:
Principle #1Segmentation

2Reliability

If Secure NTP with cryptographic hash functions is used, then time stamps are transferred securely, but symmetrical keys must be exchanged and securely stored in advance which is highly elaborate

Engineering Contradiction:
ImprovesecurityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The registration authority acts as a trusted intermediary that manages the distribution of public keys and certificates to all time sources and clients. This eliminates the need for direct key exchange between pairs of devices, significantly reducing the complexity of key management in large-scale industrial plants

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Instead of managing unique symmetrical keys between every pair of communication subscribers, the system uses public key certificates that can be widely distributed and copied. Each device obtains a certificate from the registration authority that can be used by any other device to verify time synchronization messages, eliminating the need for elaborate key exchange protocols

Inventive Principle:
Principle #26Copying

3Reliability

If certificates are used for secure communication between components, then security is improved, but system time synchronization becomes necessary for certificate checking which creates additional security vulnerabilities

Engineering Contradiction:
Improvecommunication securityVSAvoidsynchronization system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the time synchronization request process with the existing certificate-based authentication process. The registration authority, which already verifies certificates for secure communication, also performs time synchronization, combining two functions into one unified system that reduces overall complexity

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The registration authority is designed to perform multiple functions: it issues certificates for secure communication and simultaneously provides time synchronization services. This multi-functional approach eliminates the need for separate time synchronization infrastructure, reducing system complexity while maintaining security

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11677741B2Method and system for secure time synchronization
Publication Date: 2023.06.13 SIEMENS AG
  • US11677741B2 patent drawing
  • US11677741B2 patent drawing
  • US11677741B2 patent drawing

AI summary

System and method for secure time synchronization in an industrial facility, wherein a synchronization request of a facility component is transmitted to a registration service of a certificate management of the facility and the synchronization request is examined by the registration service, where the synchronization request includes a signature of the requesting facility component, and where depending on an outcome of the examination, a synchronization response is then transmitted to the requesting facility component a system time of the facility component is matched to a system time of the registration service based on the synchronization response.