Trusted Physical Layer Timing Attestation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing clock synchronization protocols in communication systems are vulnerable to compromised timing sources, which can disrupt the proper operation of components relying on time synchronization, such as token verification and cluster synchronization, due to the lack of trusted attestation mechanisms for validating the integrity of timing information.

Innovation Solution

The method involves distributing frequency synchronization information using attestation, where a node receives frequency information from a trusted source and verifies its integrity through attestation messages, such as hardware fingerprints or endorsement keys, within the physical layer of a communication connection, ensuring the trustworthiness of the timing information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If clock synchronization protocols are implemented without attestation mechanisms, then timing information can be distributed freely and easily, but the system becomes vulnerable to compromised timing sources that can disrupt operations

Engineering Contradiction:
Improvetrustworthiness of timing informationVSAvoidcomplexity of synchronization protocol
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an attestation mechanism as an intermediary between timing sources and synchronization recipients. This intermediary validates the integrity of timing information through cryptographic verification, allowing the system to maintain reliability without requiring fundamental changes to the synchronization protocol structure

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary validation of timing sources through attestation before synchronization occurs. By pre-verifying the trustworthiness of timing information using hardware-based cryptographic credentials, the system prevents compromised timing sources from disrupting operations without adding complexity to the ongoing synchronization process

Inventive Principle:
Principle #10Preliminary action

2Reliability

If timing information is distributed without validation, then the system operates with simpler procedures, but compromised timing sources can impact token verification, logging, and cluster synchronization

Engineering Contradiction:
Improveintegrity of timing sourcesVSAvoidsimplicity of timing distribution
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent enables timing sources to self-validate through hardware-based attestation mechanisms. Each timing source automatically provides cryptographic proof of its integrity, eliminating the need for manual verification or complex validation procedures while ensuring reliability

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements a feedback mechanism where attestation information is continuously provided with timing messages. This feedback loop allows recipients to verify the ongoing integrity of timing sources without adding operational complexity, as the validation is automatically included in the existing message exchange

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11294417B2Distribution of trusted physical layer timing information using attestation
Publication Date: 2022.04.05 CISCO TECHNOLOGY INC
  • US11294417B2 patent drawing
  • US11294417B2 patent drawing
  • US11294417B2 patent drawing

AI summary

This disclosure describes methods and systems to for a method for a first computing node to receive frequency information of a system clock. The first computing node receives the frequency information of the system clock from a second computing node at a physical layer of a connection between the first computing node and the second computing node. The first computing node also receives a message from the second computing node at above the physical layer of the connection between the first computing node and the second computing node. The message includes an attestation of the frequency information from which the first computing node may verify that the second computing node is a trusted source of the frequency information.