Certificate-Validated Time Acquisition Across Heterogeneous Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In heterogeneous networks, computing devices may lose secure system time due to power loss or lack of security resources, leading to inaccurate time settings and inefficient time request routing, with potential compromise from unsecured time servers.
Innovation Solution
A method involving a network interface controller (NIC) that sorts neighbor lists based on security and cost metrics to efficiently select a trusted time server, validates certificates, and ensures secure time acquisition by using a minimum trusted time mechanism.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If computing devices use heterogeneous network with varying security abilities, then network adaptability is improved, but time security reliability deteriorates
Solution Approach 1:
The patent introduces a time server as an intermediary component that provides secure time services to heterogeneous computing devices. The time server acts as a mediator between devices with varying security capabilities, ensuring that all devices can obtain secure time information regardless of their individual security abilities. This resolves the contradiction by centralizing time security management while maintaining network heterogeneity.
Solution Approach 2:
The patent implements preliminary actions by pre-establishing trust relationships and security contexts before time synchronization occurs. Devices perform preliminary certificate validation and security capability assessment before obtaining time services, ensuring that secure time acquisition is prepared in advance for all heterogeneous devices, thereby maintaining both adaptability and reliability.
2Use of energy by moving object
If devices lose power without secure time retention, then energy efficiency is improved, but time accuracy deteriorates
Solution Approach 1:
The patent enables devices to self-synchronize their time by automatically contacting the time server when powered on or after power loss. The devices perform self-service time acquisition without requiring manual intervention or persistent power consumption, achieving both energy efficiency and time accuracy by leveraging the time server's continuous availability.
Solution Approach 2:
The patent applies partial action by implementing time synchronization only when necessary (upon power restoration or time loss detection), rather than maintaining continuous synchronization. This allows devices to maintain time accuracy during operation while minimizing energy consumption during power loss periods, resolving the contradiction between energy efficiency and time accuracy.
3Device complexity
If unsecured time servers are used, then network simplicity is improved, but time security deteriorates
Solution Approach 1:
The patent applies local quality by implementing security measures selectively at the time server level rather than requiring security at all device levels. The time server maintains centralized security controls while allowing heterogeneous devices to access services with varying local security capabilities. This resolves the contradiction by concentrating security complexity where it is most effective while preserving network simplicity at individual device levels.
4Reliability
If comprehensive certificate validation is performed, then time security is improved, but processing time deteriorates
Solution Approach 1:
The patent implements preliminary certificate validation by pre-establishing trust anchors and security contexts before time synchronization requests are processed. The time server and devices perform preliminary security setup in advance, allowing faster time acquisition operations subsequent to the preliminary actions, thus resolving the contradiction between comprehensive validation and processing time.
Data Source
AI summary
A method of securely providing a trusted time to a first device may include receiving at a network interface controller (NIC) a neighbor list comprising a plurality of entries for a corresponding plurality of neighbor devices wherein each of the plurality of entries includes a unique device identity of a time server which the plurality of neighbor devices has reached, and an inception time of a time server certificate corresponding to the unique device identity. The method may further include sorting the plurality of entries within the neighbor list to obtain a sorted neighbor list and sending a time request to a first neighbor device of the plurality of neighbor devices based at least in part on the sorted neighbor list.


