Secure System Time Updates Using Cumulative Source Trust

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Automotive and computing systems face challenges in maintaining accurate system time, which is crucial for safety-critical functions like ADAS and digital certificate validity, due to potential drift or malicious attacks, necessitating effective protection and updating mechanisms.

Innovation Solution

A method that determines a cumulative trustworthiness score for available time sources to update system time, using secure storage for default and recovery times to ensure reliability and protection against attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If system time is updated based on available time sources, then time accuracy can be improved, but the system becomes vulnerable to drift and malicious attacks

Engineering Contradiction:
Improvetime accuracyVSAvoidsystem time protection
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent introduces a secure element as an intermediary component that stores trusted root certificates and time source information. This secure element acts as a mediator between the time sources and the system, verifying the authenticity of time updates through cryptographic signatures before applying them, thus preventing unauthorized or malicious time changes while maintaining accuracy.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary actions by pre-storing trusted root certificates and establishing a chain of trust before time updates occur. The secure element contains pre-configured authentication credentials that enable verification of time sources beforehand, ensuring that only authenticated time updates can modify the system time, thereby preventing drift and attacks.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If multiple time sources are used to update system time, then time accuracy can be improved, but the complexity of managing and verifying these sources increases

Engineering Contradiction:
Improvetime accuracyVSAvoidtime source management
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The secure element serves as a centralized intermediary that manages multiple time sources. It stores root certificates for various trusted time sources and handles the verification process uniformly, abstracting away the complexity of managing multiple sources from the main system. The system simply queries the secure element for authenticated time updates, simplifying the management architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent merges the functions of multiple time sources through a unified verification mechanism in the secure element. Instead of implementing separate verification logic for each time source, the system combines them under a single cryptographic verification framework that handles all trusted sources consistently, reducing overall system complexity.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If the system stores time values in protected storage, then security against attacks can be improved, but the ease of accessing and updating time information decreases

Engineering Contradiction:
Improvesecurity protectionVSAvoidtime access and update
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The secure element performs self-service by automatically verifying the authenticity of time updates using stored root certificates and cryptographic signatures. When a time source provides a time update, the secure element independently validates it against its stored credentials and either applies or rejects the update without requiring external intervention, thus maintaining both security and operational efficiency.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The secure element acts as an intermediary that simplifies access to protected time information. Applications can request time updates through the secure element's standardized interface, and the secure element handles all security operations internally, returning only authenticated results. This mediates between the security requirements of protected storage and the operational needs of time access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3862901B1Techniques for protection and accuracy of system time
Publication Date: 2024.01.03 HARMAN INT IND INC
  • EP3862901B1 patent drawingFigure 1
  • EP3862901B1 patent drawingFigure 2
  • EP3862901B1 patent drawingFigure 3

AI summary

Techniques are disclosed for the protection and accuracy of system time used in systems, such as automotive systems, from attacks. In some embodiments, a cumulative trustworthiness score is determined for available time sources, other than a real time clock, by adding together trustworthiness scores associated with the available time sources after a system time is initialized to time of the real time clock during booting. The cumulative trustworthiness score is then used to determine an appropriate technique for updating the system time based on time from one of the available time sources, depending on whether the cumulative trustworthiness score is greater than a maximum threshold, between a minimum threshold and the maximum threshold, or less than the minimum threshold.