PKI Time Synchronization for Tamper-Resistant Industrial Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial plants face challenges in secure time synchronization due to the vulnerability of existing time synchronization protocols like NTP, which lack integrity protection, making them susceptible to manipulation, especially in complex systems with numerous components.
Innovation Solution
A method for secure time synchronization in industrial plants using a certificate management system with a public key infrastructure (PKI), where time synchronization requests and responses are secured through signatures and timestamps, eliminating the need for additional key transmission and storage, and leveraging existing certificate management protocols like CMP for secure and reliable synchronization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If NTP protocol is used for time synchronization, then time synchronization can be achieved in packet-based networks with variable latency, but the protocol lacks integrity protection making it susceptible to manipulation
Solution Approach 1:
The patent combines time synchronization functionality with certificate management functionality into a single integrated system. The registration service of the PKI system performs both certificate registration and time synchronization, eliminating the need for separate NTP infrastructure and leveraging existing cryptographic protections for time synchronization integrity
Solution Approach 2:
The registration service acts as an intermediary that provides authenticated time synchronization. Instead of direct peer-to-peer time synchronization vulnerable to manipulation, all time synchronization requests are mediated through the registration service which verifies authenticity using cryptographic signatures before providing time information
2Object-affected harmful factors
If Secure NTP with cryptographic hash functions is used, then time synchronization security is improved, but symmetric keys must be exchanged and securely stored which increases implementation complexity
Solution Approach 1:
The registration service of the PKI system is designed to perform multiple functions: certificate registration, verification, and time synchronization. By making the registration service universal, the system eliminates the need for separate key management infrastructure for time synchronization, as the same asymmetric key pairs used for certificate management also secure time synchronization requests and responses
Solution Approach 2:
The system uses the existing asymmetric key pairs that plant components already possess for certificate management to also secure time synchronization. Each plant component signs its own time synchronization requests with its private key, and the registration service verifies these signatures using the component's public key from its certificate, eliminating the need for separate symmetric key exchange and storage mechanisms
3Reliability
If certificates are used for secure communication, then communication security is ensured, but system time synchronization is required for certificate verification which creates additional security requirements
Solution Approach 1:
The patent merges certificate management and time synchronization into a single integrated process. When a plant component communicates with the registration service for certificate operations, time synchronization is automatically performed as part of the same authenticated session, ensuring that time synchronization security requirements are met without adding separate security infrastructure
Data Source
Figure 1
Figure 2~3
Figure 4
AI summary
The present invention relates to a method (100) for reliable time synchronization in an industrial plant (10) and a corresponding system (1). A synchronization request (5) from a plant component (3) is transmitted to a registration service (2) of a certificate management system of the plant (10), and the registration service (2) checks the synchronization request (5). Depending on the result of the check, a synchronization response (7) is then transmitted to the requesting plant component (3), and the system time of the plant component (3) is adjusted to the system time of the registration service (2) based on the synchronization response (7).