IDS Inspection Delay Compensation for TSN Synchronization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Time-synchronized networks face challenges in maintaining precise synchronization due to the introduction of latency caused by intrusion detection systems (IDS) that inspect and correct protocol messages, leading to unpredictable delays and potential desynchronization of nodes and applications.

Innovation Solution

Implementing techniques to account for inspection delays by measuring and adjusting the inference time associated with security measures within the IDS, such as adding the inspection time to a correction field in protocol messages or reporting it out-of-band, to ensure accurate synchronization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If intrusion detection systems inspect and correct protocol messages to enhance security, then security against attacks is improved, but synchronization precision deteriorates due to inspection delays

Engineering Contradiction:
ImprovesecurityVSAvoidsynchronization precision
Core Design Contradiction:
ReliabilityVSManufacturing precision

Solution Approach 1:

The system performs preliminary actions by measuring the inspection delay before the synchronization message reaches the destination node. The IDS records the time it takes to inspect the message and communicates this delay information to the destination node, allowing the node to compensate for the delay in advance when calculating synchronization timing.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback by communicating the inspection delay information from the IDS back to the destination node. This feedback loop allows the destination node to adjust its timing calculations based on the actual delay introduced by security inspection, ensuring accurate synchronization despite the security measures in place.

Inventive Principle:
Principle #23Feedback

2Reliability

If intrusion detection systems are deployed to detect security attacks, then security monitoring is improved, but message delivery time increases due to inspection processes

Engineering Contradiction:
Improvesecurity monitoringVSAvoidmessage delivery time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system uses an intermediary approach by introducing a delay measurement message that travels through the IDS along with the synchronization message. This intermediary mechanism allows the system to measure and account for the inspection delay without requiring the IDS to slow down its inspection process, as the delay is measured and compensated rather than eliminated.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Difficulty of detecting and measuring

If protocol messages are inspected for security attacks, then detection capability is improved, but synchronization accuracy deteriorates due to unpredictable delays

Engineering Contradiction:
Improvedetection capabilityVSAvoidsynchronization accuracy
Core Design Contradiction:
Difficulty of detecting and measuringVSMeasurement precision

Solution Approach 1:

The system performs preliminary measurement of the inspection delay by having the IDS record the time it takes to inspect each message. This preliminary action allows the destination node to know exactly how much time was spent on security inspection, enabling it to compensate for this delay when calculating synchronization timing, thus maintaining synchronization accuracy despite the inspection process.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20240223585A1Transparent sanitization for synchronization messages in time sensitive networking
Publication Date: 2024.07.04 INTEL CORP
  • US20240223585A1 patent drawing
  • US20240223585A1 patent drawing
  • US20240223585A1 patent drawing

AI summary

Techniques include receiving a message with time information at an ingress queue for an ingress interface of an intrusion detection system (IDS), the IDS to monitor a network node of a time-synchronized network (TSN), generating an entrance timestamp for the message, the entrance timestamp to comprise a time value representing when the message is received at the ingress queue of the ingress interface of the IDS, inspecting the message for indications of a security attack by the IDS, generating an exit timestamp for the message, the exit timestamp to comprise a time value representing when the message is received at an egress queue of an egress interface of the IDS, and generating an inspection time interval associated with the IDS, the inspection time interval to represent a time interval between the entrance timestamp and the exit timestamp for the message while transiting the IDS. Other embodiments are described and claimed.