Certificate-Based Time Synchronization for Industrial Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial plants face challenges in secure time synchronization due to the vulnerability of existing time synchronization protocols like NTP, which lack integrity protection and require elaborate key management for secure implementation.
Innovation Solution
A system and method for secure time synchronization in industrial plants using a certificate management system, where a registration authority checks and authenticates synchronization requests, allowing plant components to synchronize their system times based on a secure certificate management protocol, eliminating the need for additional keys and enhancing security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If NTP protocol is used for time synchronization, then time synchronization can be implemented in packet-based networks, but the messages lack integrity protection making them vulnerable to manipulation
Solution Approach 1:
The patent introduces a registration authority as an intermediary that issues certificates to time sources. These certificates serve as mediators that provide integrity protection to NTP messages without requiring modification of the NTP protocol itself, thus resolving the contradiction between maintaining NTP compatibility and ensuring message integrity
Solution Approach 2:
The patent separates the time synchronization function from the security verification function. The NTP protocol handles time synchronization while the certificate-based authentication system handles integrity protection independently, allowing both functions to operate optimally without compromising each other
2Reliability
If Secure NTP with cryptographic hash functions is used, then time stamps are transferred securely, but symmetrical keys must be exchanged and securely stored in advance which is highly elaborate
Solution Approach 1:
The registration authority acts as a trusted intermediary that manages the distribution of public keys and certificates to all time sources and clients. This eliminates the need for direct key exchange between pairs of devices, significantly reducing the complexity of key management in large-scale industrial plants
Solution Approach 2:
Instead of managing unique symmetrical keys between every pair of communication subscribers, the system uses public key certificates that can be widely distributed and copied. Each device obtains a certificate from the registration authority that can be used by any other device to verify time synchronization messages, eliminating the need for elaborate key exchange protocols
3Reliability
If certificates are used for secure communication between components, then security is improved, but system time synchronization becomes necessary for certificate checking which creates additional security vulnerabilities
Solution Approach 1:
The patent merges the time synchronization request process with the existing certificate-based authentication process. The registration authority, which already verifies certificates for secure communication, also performs time synchronization, combining two functions into one unified system that reduces overall complexity
Solution Approach 2:
The registration authority is designed to perform multiple functions: it issues certificates for secure communication and simultaneously provides time synchronization services. This multi-functional approach eliminates the need for separate time synchronization infrastructure, reducing system complexity while maintaining security
Data Source
AI summary
System and method for secure time synchronization in an industrial facility, wherein a synchronization request of a facility component is transmitted to a registration service of a certificate management of the facility and the synchronization request is examined by the registration service, where the synchronization request includes a signature of the requesting facility component, and where depending on an outcome of the examination, a synchronization response is then transmitted to the requesting facility component a system time of the facility component is matched to a system time of the registration service based on the synchronization response.


