Redundant Clock Managers for Secure TSN Time Synchronization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing time-sensitive networking (TSN) systems are vulnerable to attacks that compromise clock manager software, leading to incorrect timekeeping and potential system malfunctions, which can disrupt synchronization and deterministic data delivery.
Innovation Solution
Implementing a detector that monitors clock manager software using a physics-based analytical model to identify abnormal behavior, and switches to a redundant clock manager in case of compromise, ensuring timely and secure time synchronization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a single clock manager is used in TSN systems, then device complexity is reduced, but reliability deteriorates due to vulnerability to attacks and software compromises
Solution Approach 1:
The clock manager functionality is segmented into multiple independent instances: a primary clock manager and a redundant clock manager. Each instance operates independently with separate software code, allowing the system to detect and isolate compromised instances while maintaining operational clock management through the secure instance.
Solution Approach 2:
The system changes the operational parameter from a single clock manager instance to multiple instances with different security states. By introducing a redundant instance with identical functional parameters but isolated execution environment, the system achieves enhanced reliability without changing the fundamental clock management parameters.
2Measurement precision
If clock manager software is monitored continuously, then detection precision improves, but use of energy increases due to continuous monitoring operations
Solution Approach 1:
The system performs preliminary actions by pre-configuring a redundant clock manager instance that is ready to take over immediately upon detection of compromise. The monitoring mechanism is pre-established with detection thresholds and response protocols, enabling rapid response without continuous high-energy monitoring of all clock manager operations.
Solution Approach 2:
A copy of the clock manager functionality is created in the form of a redundant instance. This copy consumes minimal energy during normal operation since it is in a standby state, yet provides comprehensive detection capability by comparing its operational state with the primary instance, achieving high detection precision with low energy overhead.
3Reliability
If a redundant clock manager is implemented, then reliability improves through failover capability, but device complexity increases due to additional hardware and software components
Solution Approach 1:
The redundant clock manager instance is merged with the primary instance in terms of functional architecture and interface design. Both instances share the same operational parameters, communication protocols, and integration points with the TSN stack, reducing the complexity overhead by maintaining uniformity while providing redundancy.
Solution Approach 2:
The redundant clock manager instance serves multiple functions: it acts as a backup for failover, provides a security reference for detecting compromise, and can serve as the primary instance if the original becomes compromised. This multi-functionality reduces the need for separate dedicated components, thereby managing complexity while enhancing reliability.
Data Source
AI summary
An apparatus for clock manager redundancy comprises a clock circuitry to manage a clock for a device; a first processing circuitry coupled to the clock circuitry to execute instructions to perform operations for a clock manager, the clock manager to receive messages with time information for a network and generate clock manager control information to adjust the clock to a network time for the network; a hardened execution environment coupled to the clock circuitry and the first processing circuitry, the hardened execution environment to comprise: a detector to monitor the clock manager and generate an alert when the detector identifies abnormal behavior of the clock manager; and a second processing circuitry to execute instructions to perform operations for a redundant clock manager, the redundant clock manager to take over operations for the clock manager in response to the alert from the detector. Other embodiments are described and claimed.


