Device Fingerprinting via TCP Timestamp Clock Skew
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional Network Access Control (NAC) systems are ineffective in securing network access against unauthorized devices that can spoof or impersonate legitimate devices, particularly for devices that cannot support client software, such as storage devices and VoIP phones, as they rely on easily imitable MAC addresses.
Innovation Solution
Employing device fingerprinting using clock skews and time drift analysis, such as linear regression on TCP timestamps, to uniquely identify devices and verify their authenticity, thereby enhancing security by utilizing immutable physical characteristics that are difficult to subvert.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If MAC address-based NAC policy is used for devices that cannot support client software, then device admission is simplified, but security is compromised because MAC addresses can be easily spoofed
Solution Approach 1:
The patent replaces the mechanical/mac-address-based identification system with a timing-based identification system. Instead of relying on the device's reported MAC address, the system measures the device's clock skew through TCP timestamp analysis, substituting a physical timing characteristic that is much harder to spoof for the traditional MAC address verification method.
Solution Approach 2:
The patent changes the verification parameter from static MAC address to dynamic timing characteristics (clock skew). By measuring how a device's clock drifts over time through TCP timestamps, the system creates a verification mechanism that is inherent to the device's hardware timing properties rather than a configurable network parameter like MAC address.
2Measurement precision
If TCP timestamp analysis for clock skew measurement is implemented, then device identification accuracy is improved, but measurement complexity increases
Solution Approach 1:
The patent makes the device identify itself through its natural TCP timestamp behavior without requiring any special software or configuration on the device side. The device's clock skew is revealed through its normal TCP communication timing, allowing the system to extract identification information from the device's inherent operational characteristics rather than requiring the device to provide explicit identification data.
Solution Approach 2:
The patent uses TCP timestamps as an intermediary to measure clock skew. Rather than directly measuring the device's internal clock, the system uses the TCP protocol's timestamp mechanism as a mediator that naturally reveals the device's timing characteristics through standard network communication, simplifying the measurement process while maintaining precision.
Data Source
AI summary
A system and method for identifying and verifying a client to access a secure network. Timing characteristics are acquired from the client, such as a peripheral device, and further verified and identified via a policy enforcement points and a policy decision points, or a measurer device in the secure network.


