Network Device Time Synchronization Protection Against Unauthorized Grandmaster Changes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication networks in vehicles, particularly those using Ethernet technologies, are vulnerable to unauthorized changes in time synchronization, which can lead to safety-critical disruptions and potential accidents due to the lack of effective protection mechanisms against attacks on the grandmaster clock.

Innovation Solution

A method and network device that monitor and verify time synchronization messages to prevent unauthorized changes by isolating potential new grandmaster clocks and creating virtual time domains to ensure the integrity of the base time domain, allowing only trusted clocks to be adopted, thereby maintaining the reliability of time synchronization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the network uses standard PTP time synchronization protocol, then time synchronization is achieved across all network devices, but the system becomes vulnerable to unauthorized changes and attacks on the grandmaster clock

Engineering Contradiction:
Improvetime synchronization reliabilityVSAvoidvulnerability to unauthorized changes
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the time domain into multiple virtual time domains (first virtual time domain and second virtual time domain) within a single network device. This allows the device to maintain multiple potential grandmaster clocks in isolation, preventing unauthorized changes in one domain from affecting the entire system. The segmentation creates isolated evaluation environments for different clock sources.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The network device acts as an intermediary between potential grandmaster clocks and the rest of the network. It receives time synchronization messages from multiple sources, evaluates them in isolated virtual time domains, and selectively forwards only authorized clocks to other network devices. This intermediary role filters out unauthorized changes before they can propagate through the network.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If the network accepts new grandmaster clocks dynamically, then adaptability and flexibility are improved, but security against unauthorized changes deteriorates

Engineering Contradiction:
Improveclock switching flexibilityVSAvoidprotection against attacks
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The network device performs preliminary evaluation of potential grandmaster clocks by creating virtual time domains before integrating them into the main time synchronization system. Each potential clock is tested and validated in an isolated virtual environment first, ensuring security checks are completed before the clock is accepted by the broader network. This preliminary action prevents unauthorized clocks from directly joining the main system.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system dynamically creates and manages multiple virtual time domains that can be activated or deactivated based on the evaluation of potential grandmaster clocks. The network device can switch between different virtual time domains depending on which clock source is determined to be authorized and reliable, providing both adaptability and security through dynamic reconfiguration.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11973581B2Method for protecting the time synchronization in a network against unauthorized changes
Publication Date: 2024.04.30 CONTINENTAL AUTOMOTIVE TECHNOLOGIES GMBH
  • US11973581B2 patent drawing
  • US11973581B2 patent drawing

AI summary

The time synchronization of a network is protected against unauthorized changes to the grandmaster clock of a base time domain by monitoring the physical communication interfaces of a network device for arrival of messages relating to time synchronization. If the messages relating to time synchronization apply to the initially set-up and synchronized base time domain, a check is performed to determine whether the messages relating to time synchronization announce a new grandmaster clock having better clock parameters than those of the present grandmaster clock. If so, a virtual base time domain is started by the network device. If the verification reveals that the proposed new grandmaster clock is trustworthy or valid, the network device discontinues the virtual time domain, updates its stored information concerning the grandmaster clock and, from this time onward, sends messages relating to time synchronization that are based on the new clock parameters to the network.