Timing Attack Detection in Time Sensitive Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security mechanisms in time-sensitive networks, such as IEEE 1588, fail to detect timing attacks that alter packet timing, which can cause phase shifts and jitter, leading to potential damage or errors in coordinated actions across the network.

Innovation Solution

Implementing timing attack detection and mitigation logic on network nodes or a network tap to monitor and compare PTP times and propagation delays, identifying deviations beyond a threshold to prevent incorrect time adjustments and mitigate timing attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional security mechanisms (error detection codes, authentication, encryption) are used to protect data in TSN, then data integrity and confidentiality are improved, but the ability to detect timing attacks remains insufficient

Engineering Contradiction:
Improvedata integrityVSAvoidtiming attack detection
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent extends security monitoring from the traditional data content dimension to the timing dimension by measuring packet arrival times and calculating propagation delays. This dimensional expansion allows detection of timing attacks that would be invisible to conventional data integrity checks, as the attack manifests in the time domain rather than the data domain.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent introduces an intermediary timing monitoring mechanism that observes packet transmission without altering the data flow. This intermediary layer calculates propagation delays and compares timing values across different packet streams, enabling detection of timing anomalies while maintaining the original data transmission integrity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If packet timing is monitored and verified to detect timing attacks, then timing security is improved, but system complexity increases due to additional monitoring logic and calculations

Engineering Contradiction:
Improvetiming securityVSAvoidmonitoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service timing verification where network nodes autonomously perform timing measurements and propagation delay calculations using their own local clocks and received packet timestamps. Each node independently verifies timing integrity without requiring centralized timing authority, distributing the monitoring function across the network infrastructure that already exists.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent makes existing TSN infrastructure multi-functional by enabling standard PTP packets to serve both their original synchronization function and the additional function of timing attack detection. The same packet exchange mechanism used for clock synchronization is simultaneously used to measure propagation delays and detect timing anomalies, eliminating the need for separate dedicated monitoring channels.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If propagation delay measurements are performed frequently to detect timing attacks, then detection accuracy is improved, but network overhead increases due to additional monitoring traffic

Engineering Contradiction:
Improvetiming measurement accuracyVSAvoidnetwork traffic volume
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent applies partial monitoring by selectively measuring propagation delays only for specific critical packet streams or during suspected attack conditions rather than continuously monitoring all traffic. This selective approach achieves sufficient detection accuracy for security purposes while minimizing the overhead of timing measurement operations on the network.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent performs preliminary timing characterization during normal operation to establish baseline propagation delay values and variability ranges. This preliminary action creates a reference profile that enables later detection of timing attacks without requiring continuous high-frequency measurements, as deviations from the established baseline can be detected with less intensive monitoring.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11563768B2Methods, systems, and computer readable media for detecting and mitigating effects of timing attacks in time sensitive networks
Publication Date: 2023.01.24 KEYSIGHT TECHNOLOGIES INC
  • US11563768B2 patent drawing
  • US11563768B2 patent drawing
  • US11563768B2 patent drawing

AI summary

A method for providing timing security in a time sensitive network (TSN), includes monitoring TSN times in timing synchronization packets exchanged between TSN network nodes. The method further includes monitoring TSN timing values calculated by TSN network nodes. The method further includes determining, using TSN times and TSN timing values, whether a timing attack is indicated. The method further includes, in response to determining that a timing attack is indicated, performing a timing attack effects mitigation action.