Client Time Approximation via Secure Server Metadata

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Client computer systems with incorrect system clock times cannot establish secure connections to secure servers, leading to circular dependencies and inefficiencies in communication, which often result in futile connection attempts and increased power consumption.

Innovation Solution

A method that allows client devices to access multiple secure servers to collect time specifications, approximate the current system time, and use this approximation to establish secure connections, thereby breaking the dependency on accurate time for secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a client computer system attempts to establish secure connections with incorrect system clock time, then secure communication cannot be established, but the system continues to make futile connection attempts consuming power

Engineering Contradiction:
Improvesecure connection establishmentVSAvoidpower consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system performs preliminary time approximation by collecting time specifications from multiple secure servers before attempting secure connection. This preliminary action of approximating time breaks the circular dependency and prevents futile connection attempts, thereby reducing power consumption while enabling reliable secure communication.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If a client computer system requires accurate time for secure protocols, then secure communication can be established, but systems with incorrect time cannot access time servers to obtain correct time

Engineering Contradiction:
Improvesecure protocol functionVSAvoidtime synchronization
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system introduces an intermediary time approximation mechanism that mediates between incorrect local time and the requirement for accurate time in secure protocols. By collecting time specifications from multiple secure servers and approximating current time, the system enables secure protocol function without requiring direct access to time servers, thus resolving the circular dependency.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If a client computer system makes multiple connection attempts to secure servers, then it can collect time specifications for time approximation, but repeated attempts increase power consumption

Engineering Contradiction:
Improvetime specification accuracyVSAvoidpower consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The system performs a limited number of connection attempts to collect time specifications from multiple secure servers, which is sufficient for accurate time approximation. By performing this partial action of collecting time data from several servers rather than attempting continuous secure connections, the system achieves measurement precision while minimizing power consumption.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10069839B2Determine approximate current time on a client using secure protocol metadata
Publication Date: 2018.09.04 MICROSOFT TECHNOLOGY LICENSING LLC
  • US10069839B2 patent drawing
  • US10069839B2 patent drawing
  • US10069839B2 patent drawing

AI summary

Establishing secure connections from a computing device to secure servers when the computing device starts with an incorrect system clock time that would ordinarily prohibit connection to the secure servers. A method includes attempting to access a plurality of secure servers. The method further includes, from each of the servers in the plurality of secure servers, receiving one or more certificates from the secure servers and metadata which includes a specification of time. The method further includes preventing secure applications from sending sensitive data to the plurality of secure servers until a system time has been approximated. The method further includes, from the secure specifications of time, approximating a current system time. The method further includes accessing another secure server using the approximated current system time and using the approximated current system time to validate a certificate from the other server.