Secure System Time Updates Using Cumulative Source Trust
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Automotive and computing systems face challenges in maintaining accurate system time, which is crucial for safety-critical functions like ADAS and digital certificate validity, due to potential drift or malicious attacks, necessitating effective protection and updating mechanisms.
Innovation Solution
A method that determines a cumulative trustworthiness score for available time sources to update system time, using secure storage for default and recovery times to ensure reliability and protection against attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If system time is updated based on available time sources, then time accuracy can be improved, but the system becomes vulnerable to drift and malicious attacks
Solution Approach 1:
The patent introduces a secure element as an intermediary component that stores trusted root certificates and time source information. This secure element acts as a mediator between the time sources and the system, verifying the authenticity of time updates through cryptographic signatures before applying them, thus preventing unauthorized or malicious time changes while maintaining accuracy.
Solution Approach 2:
The system performs preliminary actions by pre-storing trusted root certificates and establishing a chain of trust before time updates occur. The secure element contains pre-configured authentication credentials that enable verification of time sources beforehand, ensuring that only authenticated time updates can modify the system time, thereby preventing drift and attacks.
2Measurement precision
If multiple time sources are used to update system time, then time accuracy can be improved, but the complexity of managing and verifying these sources increases
Solution Approach 1:
The secure element serves as a centralized intermediary that manages multiple time sources. It stores root certificates for various trusted time sources and handles the verification process uniformly, abstracting away the complexity of managing multiple sources from the main system. The system simply queries the secure element for authenticated time updates, simplifying the management architecture.
Solution Approach 2:
The patent merges the functions of multiple time sources through a unified verification mechanism in the secure element. Instead of implementing separate verification logic for each time source, the system combines them under a single cryptographic verification framework that handles all trusted sources consistently, reducing overall system complexity.
3Reliability
If the system stores time values in protected storage, then security against attacks can be improved, but the ease of accessing and updating time information decreases
Solution Approach 1:
The secure element performs self-service by automatically verifying the authenticity of time updates using stored root certificates and cryptographic signatures. When a time source provides a time update, the secure element independently validates it against its stored credentials and either applies or rejects the update without requiring external intervention, thus maintaining both security and operational efficiency.
Solution Approach 2:
The secure element acts as an intermediary that simplifies access to protected time information. Applications can request time updates through the secure element's standardized interface, and the secure element handles all security operations internally, returning only authenticated results. This mediates between the security requirements of protected storage and the operational needs of time access.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Techniques are disclosed for the protection and accuracy of system time used in systems, such as automotive systems, from attacks. In some embodiments, a cumulative trustworthiness score is determined for available time sources, other than a real time clock, by adding together trustworthiness scores associated with the available time sources after a system time is initialized to time of the real time clock during booting. The cumulative trustworthiness score is then used to determine an appropriate technique for updating the system time based on time from one of the available time sources, depending on whether the cumulative trustworthiness score is greater than a maximum threshold, between a minimum threshold and the maximum threshold, or less than the minimum threshold.