Securing Timing Packets Over Untrusted Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing timing protocols over insecure public networks face challenges in securing timing messages, particularly for large-scale cellular networks, due to vulnerabilities in current standards like IEEE 1588 PTP and 802.1AS, which can lead to attacks on message integrity and network architecture, impacting synchronization accuracy and security.

Innovation Solution

The method involves assigning timestamps to timing packets, encrypting them, and establishing secure IPsec tunnels with mutual authentication between nodes, using exclusive security associations and statistical offset estimation to account for processing delays, ensuring only trusted sources provide timing services and maintaining packet anonymity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If timing packets are transmitted over public networks without encryption, then network operation simplicity is maintained, but security against attacks on timing messages is compromised

Engineering Contradiction:
Improvesecurity of timing messagesVSAvoidcomplexity of securing timing packets
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces IPsec tunnels as an intermediary layer between timing servers and client nodes. These tunnels provide encryption and authentication mechanisms that protect timing packets from attacks while maintaining compatibility with existing IEEE 1588 PTP and 802.1AS protocols. The IPsec layer acts as a mediator that adds security without requiring changes to the underlying timing protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary authentication and key exchange mechanisms before timing packet transmission. IPsec security associations are established in advance between timing servers and clients, creating secure channels before any timing synchronization occurs. This preliminary action ensures that when timing packets are transmitted, the security framework is already in place.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If encryption is applied to timing packets, then security is improved, but processing delay increases

Engineering Contradiction:
Improvesecurity of timing messagesVSAvoidprocessing delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent extracts the security processing functions into a separate IPsec layer, distinct from the timing protocol processing. This separation allows timing packets to be encrypted and authenticated efficiently without timing protocol overhead. The IPsec security processing is handled independently, preventing it from adding unnecessary delay to the critical timing synchronization path.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If timing packets are secured with authentication mechanisms, then message integrity is protected, but packet processing complexity increases

Engineering Contradiction:
Improveintegrity of timing messagesVSAvoidcomplexity of security processing
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent leverages the universal IPsec protocol suite, which provides multiple security functions (encryption, authentication, integrity checking) through a single standardized framework. This multi-functionality allows the system to achieve comprehensive security protection without implementing multiple separate security mechanisms, thereby reducing overall processing complexity while maintaining robust message integrity protection.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9900778B2Method and apparatus for securing timing packets over untrusted packet transport network
Publication Date: 2018.02.20 NOKIA SOLUTIONS & NETWORKS OY
  • US9900778B2 patent drawing
  • US9900778B2 patent drawing
  • US9900778B2 patent drawing

AI summary

Methods, devices, systems, techniques, and computer program products are provided to secure timing synchronization to network nodes connected over an inherently insecure best effort public network with mechanisms to improve accuracy of timing protocols such as a statistically estimated edge timestamp offset encoded into the timing message to account for network jitter and processing latency variances incurred due to the security packet processing and encryption; to ensure slave network nodes shall only accept timing messages from trusted timing sources; to establish a secure tunnel with a trusted timing source for exchange of timing packets; to provide authentication and security for timing packets over the insecure public network; and to enhance message anonymity with variable payload padding.