Device Fingerprinting via TCP Timestamp Clock Skew

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional Network Access Control (NAC) systems are ineffective in securing network access against unauthorized devices that can spoof or impersonate legitimate devices, particularly for devices that cannot support client software, such as storage devices and VoIP phones, as they rely on easily imitable MAC addresses.

Innovation Solution

Employing device fingerprinting using clock skews and time drift analysis, such as linear regression on TCP timestamps, to uniquely identify devices and verify their authenticity, thereby enhancing security by utilizing immutable physical characteristics that are difficult to subvert.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If MAC address-based NAC policy is used for devices that cannot support client software, then device admission is simplified, but security is compromised because MAC addresses can be easily spoofed

Engineering Contradiction:
Improvedevice admission processVSAvoiddevice identity verification
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces the mechanical/mac-address-based identification system with a timing-based identification system. Instead of relying on the device's reported MAC address, the system measures the device's clock skew through TCP timestamp analysis, substituting a physical timing characteristic that is much harder to spoof for the traditional MAC address verification method.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent changes the verification parameter from static MAC address to dynamic timing characteristics (clock skew). By measuring how a device's clock drifts over time through TCP timestamps, the system creates a verification mechanism that is inherent to the device's hardware timing properties rather than a configurable network parameter like MAC address.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If TCP timestamp analysis for clock skew measurement is implemented, then device identification accuracy is improved, but measurement complexity increases

Engineering Contradiction:
Improvedevice identification accuracyVSAvoidmeasurement and verification system
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent makes the device identify itself through its natural TCP timestamp behavior without requiring any special software or configuration on the device side. The device's clock skew is revealed through its normal TCP communication timing, allowing the system to extract identification information from the device's inherent operational characteristics rather than requiring the device to provide explicit identification data.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent uses TCP timestamps as an intermediary to measure clock skew. Rather than directly measuring the device's internal clock, the system uses the TCP protocol's timestamp mechanism as a mediator that naturally reveals the device's timing characteristics through standard network communication, simplifying the measurement process while maintaining precision.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8261324B2Identification and verification of peripheral devices accessing a secure network
Publication Date: 2012.09.04 JOHNS HOPKINS UNIVERSITY
  • US8261324B2 patent drawing
  • US8261324B2 patent drawing
  • US8261324B2 patent drawing

AI summary

A system and method for identifying and verifying a client to access a secure network. Timing characteristics are acquired from the client, such as a peripheral device, and further verified and identified via a policy enforcement points and a policy decision points, or a measurer device in the secure network.