Master Clock Security via Authorized List Filtering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Precision Time Protocol (PTP) and Network Time Protocol (NTP) lack effective security mechanisms to prevent rogue clocks from being selected as master clocks, which can lead to communication failures and network issues due to the lack of regulation and authorization of candidate master clocks.
Innovation Solution
Implementing a system that maintains an authorized clock list, monitors network activity, and removes suspicious clocks from the list to ensure only authorized clocks can be selected as master clocks, using unique clock IDs or fingerprints to prevent tampering and rogue clock interference.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If PTP protocol allows any clock to broadcast announcement messages and be selected as master clock, then network flexibility and ease of operation are improved, but network security and reliability deteriorate due to rogue clock attacks
Solution Approach 1:
The system performs preliminary authorization of candidate master clocks by maintaining an authorized clock list before master clock selection occurs. Clock IDs are pre-approved and stored in this list, so when master clock selection is needed, only authorized clocks can be selected. This preliminary action prevents rogue clocks from being selected while maintaining the ease of operation of the PTP protocol.
Solution Approach 2:
The patent introduces an intermediary authorized clock list that mediates between the PTP protocol's master clock selection process and security requirements. This intermediary structure filters candidate clocks by checking their IDs against the authorized list, allowing the system to maintain operational simplicity while blocking unauthorized clocks from becoming master clocks.
2Reliability
If the system monitors network activity and removes suspicious clocks from the authorized clock list, then network security is improved, but device complexity and processing requirements increase
Solution Approach 1:
The system implements self-service security monitoring where the network monitor continuously observes network activity and automatically identifies suspicious clocks. When suspicious activity is detected, the system automatically removes the clock ID from the authorized clock list without requiring manual intervention. This self-service approach enhances security while minimizing the complexity of manual security management.
Solution Approach 2:
The patent implements feedback mechanisms where the network monitor continuously monitors network activity and provides feedback about suspicious clocks. This feedback loop allows the system to dynamically update the authorized clock list by removing suspicious clock IDs, creating a responsive security system that adapts to threats while maintaining manageable complexity through automated processes.
Data Source
AI summary
Embodiments describe monitoring network activity and behavior of authorized clocks to identify suspicious activity, and in response, removing a clock for an authorized clock list. In one embodiment, a network monitor detects changes in profiles corresponding to the authorized clocks such as a disconnecting from a port, changing a network location, unexpected changes in the clock signal, changes to the clock ID or MAC address, and the like. If the network monitor deems these changes suspicious, it removes the clock from the authorized clock list. When the current master clock fails, the PTP endpoints select a new master clock only if that clock is included in the authorized clock list. In this manner, the network monitor can constantly update the authorized clock list to ensure it contains only clocks that have not been tampered with or replaced with rogue clocks.


