Secure IEEE 1588 One-Step Clock Synchronization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing IEEE 1588 protocol for time synchronization in substation automation systems lacks effective security measures, particularly for the one-step-clock approach, which is challenging to secure, especially in high-speed networks like 1 Gbit/sec, and is prone to delays and jitter in transmission.

Innovation Solution

A method is introduced to securely synchronize clocks using a one-step IEEE 1588 clock by preparing and securing synchronization messages in advance, employing cryptographic means such as checksums or hashes, and using a dedicated hardware component to ensure timely transmission without delay or jitter, allowing for both symmetric and asymmetric protection schemes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If a one-step-clock approach is used for IEEE 1588 time synchronization, then time synchronization precision is improved, but security protection becomes impossible or extremely difficult to implement

Engineering Contradiction:
Improvetime synchronization precisionVSAvoidsecurity protection
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent applies preliminary action by preparing and securing the synchronization message in advance before transmission. The master clock device creates the synchronization message with timestamp and applies cryptographic security measures (checksum/hash calculation and digital signature) beforehand, then stores the secured message in a buffer for timed transmission. This resolves the contradiction by enabling security protection while maintaining one-step-clock precision.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If cryptographic security measures are applied to synchronization messages in real-time, then security protection is improved, but transmission delay and jitter increase

Engineering Contradiction:
Improvesecurity protectionVSAvoidtransmission delay and jitter
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent eliminates transmission delay and jitter by performing all cryptographic operations (checksum/hash calculation and digital signature) in advance during message preparation, before the transmission deadline. The secured message is then transmitted without any processing delay during the critical transmission phase, resolving the contradiction between security and timing precision.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If a two-step-clock approach is used for IEEE 1588 time synchronization, then security protection becomes trivial to implement, but time synchronization precision deteriorates

Engineering Contradiction:
Improvesecurity protectionVSAvoidtime synchronization precision
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent achieves both one-step-clock precision and two-step-clock security by applying preliminary action: preparing and securing the complete synchronization message (including timestamp and cryptographic elements) in advance as a single operation, then transmitting it immediately. This combines the precision advantage of one-step-clock with the security advantage of two-step-clock approaches.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2395404B2Secure clock synchronization
Publication Date: 2021.02.24 ABB POWER GRIDS SWITZERLAND AG
  • EP2395404B2 patent drawingFigure 1~2
  • EP2395404B2 patent drawingFigure 3~4

AI summary

The present invention is concerned with a secure one-step IEEE 1588 clock using either a symmetric or asymmetric protection scheme. Clocks of mission-critical or highly-available devices in industrial automation systems connected to a communication network are synchronized by sending, by a master clock, a synchronization message, in particular a single message of the one-step-clock type according to IEEE 1588, including a time stamp, and by receiving and evaluating, by a slave clock, the synchronization message. A synchronization component or module of the master clock prepares, or composes, prior to a projected send time tsend, a synchronization message including a time stamp of the projected send time, and secures the synchronization message still in advance of the projected send time. Securing the synchronization message takes place by suitable cryptographic means allowing at least for authentication of the time stamp at a receiving slave clock, e.g. by calculating and signing a checksum or hash of the synchronization message. At the projected send time, the secured synchronization message is transmitted.