Server ECU Time Synchronization Using Shadow Grandmaster Clocks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Ethernet-based time synchronization protocols in vehicles have a single point of failure, the Grandmaster Clock, which is easily identifiable and vulnerable to attacks, posing a significant risk to operational safety, especially in systems with high automation or autonomy.
Innovation Solution
Implement a method where additional network devices mimic the Grandmaster Clock by sending synchronized time messages with unique identifiers, obscuring the actual Grandmaster's location, and monitor for deviations to detect and mitigate potential attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If a single Grandmaster Clock is used for time synchronization in the network, then time synchronization accuracy is improved, but system reliability deteriorates due to single point of failure
Solution Approach 1:
The patent divides the single Grandmaster Clock into multiple shadow clocks distributed across different network devices. Each shadow clock maintains the same time synchronization function but operates independently, segmenting the single point of failure into multiple redundant components that can continue functioning if one fails.
Solution Approach 2:
The patent creates copies of the Grandmaster Clock function by implementing shadow clocks that replicate the time synchronization behavior. These shadow clocks send identical time synchronization messages to network devices, providing redundancy without requiring additional hardware complexity.
2Ease of operation
If the Grandmaster Clock location is made transparent in time synchronization messages, then ease of operation is improved, but security deteriorates due to easy identification and targeting
Solution Approach 1:
The patent uses shadow clocks that generate identical time synchronization messages as the real Grandmaster Clock, making it impossible for attackers to distinguish between the real Grandmaster and shadow clocks based on message content alone. This copying approach maintains operational transparency while providing security through indistinguishability.
Solution Approach 2:
The patent introduces shadow clocks as intermediary entities that mediate between the real Grandmaster Clock and network devices. These intermediaries replicate the Grandmaster's function and messages, creating a buffer that protects the real Grandmaster's identity while maintaining the same time synchronization service.
Data Source
Figure 1~2
Figure 3~5
Figure 6
AI summary
The invention relates to a method for securing the time synchronization in a server ECU, wherein a time synchronization is carried out according to a time synchronization standard, having the steps of: - initializing the time synchronization of the components; - storing a unique clock identification of a grandmaster clock ascertained during the initialization step in each server ECU component which does not provide the previously ascertained grandmaster clock; - identifying a shadow controller which is selected from the server ECU components; - transmitting the synchronization messages; - requesting the transmission time in the shadow controller; - using the time in the follow-up message by means of the controller, which forms the grandmaster clock, and forwarding the time; and - transmitting additional messages for the time synchronization by means of selected network devices which do not provide the previously ascertained grandmaster clock, wherein the time information transmitted in the additional messages for the time synchronization, the clock parameters relevant to ascertaining the best clock using the BMCA, and the domain number match or are comparable to those of the previously ascertained grandmaster clock, and the additional messages for time synchronization contain a unique clock identification which corresponds to the identification of the respective selected network device.