Attacker Localization via Anomaly Propagation Tracking in TSN

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In time-sensitive networking environments, attackers can disrupt time synchronization by delaying messages and modifying residence times on switch nodes, leading to desynchronization of follower nodes and remaining undetected.

Innovation Solution

The solution involves tracking anomaly propagation in time-sensitive networking environments by using a monitor node to detect non-compliant nodes based on remote performance measurements and keyed hash values, and identifying malicious nodes by analyzing their positions in the network topography.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If time synchronization protocol is implemented in TSN environment, then time synchronization is achieved, but attacker can disrupt synchronization by delaying messages and modifying residence times

Engineering Contradiction:
Improvetime synchronization reliabilityVSAvoiddesynchronization attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements a feedback mechanism where the monitor node continuously observes performance measurements (residence times, frame ingress times) from follower nodes and switch nodes. When anomalies are detected that indicate desynchronization attacks, the system generates alerts and can trigger resynchronization protocols. This closed-loop feedback enables the TSN network to detect and respond to synchronization disruptions, resolving the vulnerability while maintaining synchronization reliability.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces a monitor node as an intermediary between the leader node and follower nodes. This intermediary continuously collects performance measurements, analyzes them for anomalies, and identifies potential attack sources by comparing expected versus actual residence times. The monitor node acts as a security layer that protects the time synchronization protocol from attacks without requiring changes to the core synchronization mechanism.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-generated harmful factors

If attacker delays messages and modifies residence times, then desynchronization occurs, but attacker remains undetected in compromised node

Engineering Contradiction:
Improvedesynchronization effectVSAvoidattacker detection difficulty
Core Design Contradiction:
Object-generated harmful factorsVSDifficulty of detecting and measuring

Solution Approach 1:

The patent replaces traditional security mechanisms (which would require complex authentication and encryption at each node) with a measurement-based detection system. By substituting security verification with performance measurement analysis (comparing expected versus actual residence times), the system can detect attackers through their behavioral impact on message timing rather than requiring direct security credentials at each node.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The monitor node serves as an intermediary that aggregates and analyzes performance measurements from multiple nodes. By collecting data from the leader node, follower nodes, and switch nodes, the monitor can triangulate the source of desynchronization attacks. This intermediary approach makes detection feasible by centralizing the analysis of timing anomalies that would be difficult to detect at individual nodes.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If monitor node tracks anomaly propagation using performance measurements, then malicious nodes are localized, but system complexity increases

Engineering Contradiction:
Improveattacker localization precisionVSAvoidmonitoring system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the monitoring function into distinct components: the monitor node that collects and analyzes data, the leader node that generates synchronization messages, follower nodes that provide performance measurements, and switch nodes that report residence times. This segmentation allows each component to perform a specific function with relatively simple logic, while the overall system achieves sophisticated attacker localization through the coordinated interaction of these segmented parts.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12301599B2Attacker localization based on tracking anomaly propagation in time-sensitive networking
Publication Date: 2025.05.13 INTEL CORP
  • US12301599B2 patent drawing
  • US12301599B2 patent drawing
  • US12301599B2 patent drawing

AI summary

Systems, apparatuses and methods may provide for technology that detects one or more non-compliant nodes with respect to a timing schedule, detects one or more compliant nodes with respect to the timing schedule, and identifies a malicious node based on positions of the one or more non-compliant nodes and the one or more compliant nodes in a network topography. The non-compliant node(s) and the compliant node(s) may be detected based on post-synchronization messages, historical attribute data and/or plane diversity data.