Secure Time Establishment via Federated Hash Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Connected devices face challenges in maintaining accurate and secure internal time values, as they can be manipulated or tampered with, especially when relying on unauthenticated GPS signals, leading to potential unauthorized access or temporal window exploitation.

Innovation Solution

A method involving a connected device receiving time values and hashes from a federation of independent time servers, where digital certificates are validated to establish a secure time value, ensuring the authenticity and integrity of the time data through a communication protocol like TLS, and rejecting or updating the time value based on validity checks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If the connected device relies on GPS satellite signals to obtain time values, then the device can obtain time values from external sources, but the time values may be susceptible to manipulation and lack authentication

Engineering Contradiction:
Improvetime value accuracyVSAvoidtime value trustworthiness
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The connected device performs preliminary validation of digital certificates and hash verification of pinsets before accepting time values from time servers. This preliminary authentication ensures that only trusted, authenticated time values are accepted, preventing manipulation while maintaining accuracy.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces digital certificates and hash-based pinset verification as intermediary authentication mechanisms between the connected device and time servers. These intermediaries act as trusted mediators that validate the authenticity of time values, resolving the contradiction between obtaining external time values and ensuring their trustworthiness.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the connected device accepts time values from multiple independent time servers, then the device can cross-validate time values for enhanced security, but the complexity of the time establishment process increases

Engineering Contradiction:
Improvetime value securityVSAvoidtime establishment process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the time validation process into distinct modular steps: receiving time values from multiple servers, validating digital certificates separately, verifying hash of pinsets independently, and then determining validity based on predefined criteria. This segmentation reduces complexity by making each step manageable and independent.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The connected device obtains copies of digital certificates and pinsets from multiple independent time servers and validates them against locally stored reference copies. This copying and comparison approach enables cross-validation for enhanced security while using standardized validation routines that reduce overall process complexity.

Inventive Principle:
Principle #26Copying

3Reliability

If the connected device implements hash verification of pinsets and digital certificate validation, then the device can authenticate time values from time servers, but the computational overhead and processing time increase

Engineering Contradiction:
Improvetime value authenticationVSAvoidtime establishment duration
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The connected device performs hash verification of pinsets and digital certificate validation as preliminary actions before accepting time values. By completing these authentication steps in advance, the device ensures reliable authentication while establishing a clear, efficient workflow that minimizes overall processing time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements selective validation where the device verifies hashes of pinsets and digital certificates only for time servers that are candidates for providing the authoritative time value. This partial validation approach maintains strong authentication while reducing unnecessary computational overhead from validating all possible time servers.

Inventive Principle:
Principle #16Partial or excessive action

4Reliability

If the connected device rejects time values that are earlier than the current time value, then the device can prevent time manipulation attacks, but the device may also reject valid time values during legitimate time adjustments

Engineering Contradiction:
Improvetime manipulation resistanceVSAvoidtime value update flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The connected device implements a feedback mechanism where rejected time values trigger additional validation steps, such as verifying the digital certificate's validity period and checking the hash of the pinset. This feedback loop allows the device to distinguish between malicious time manipulation and legitimate time adjustments, maintaining both security and flexibility.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent applies preliminary anti-action by validating digital certificates and pinsets before comparing time values. This preliminary authentication ensures that even if a time value appears to be in the future, it can be accepted if it comes from an authenticated source, while still preventing manipulation from unauthenticated sources.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS10243955B2Securely establishing time values at connected devices
Publication Date: 2019.03.26 GM GLOBAL TECHNOLOGY OPERATIONS LLC
  • US10243955B2 patent drawing
  • US10243955B2 patent drawing
  • US10243955B2 patent drawing

AI summary

A system and method of establishing a secure time value in a connected device. The method includes: receiving a hash of a pinset at the connected device from each independent time server in a federation, wherein the pinset is stored at the connected device as well as at the independent time servers remotely located from the connected device; receiving at the connected device a time value along with each hash of the pinset; attempting to verify the hashes of the pinset received from each of the plurality of independent time servers at the connected device; and determining at the connected device which time values received from the plurality of independent time servers are valid based on validity of the hashes.