US2005268091A1PendingUtilityA1
Secure distributed time service in the fabric environment
Est. expiryJan 31, 2022(expired)· nominal 20-yr term from priority
H04L 41/0213H04L 41/0894H04L 63/20H04L 41/0893
43
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
A secure and distributed time service is discussed for use in a network. In particular, the invention relates to Fibre Channel networks and the secure distribution of time service using a push model. In order to distribute time on a push model, one entity assumes responsibility for time in the network. Other entities in the network receive periodic time updates and check the validity of their own time by gauging the elapsed time since the previous time update. The time service is secured using by applying a unique combination of encryption techniques.
Claims
exact text as granted — not AI-modified1 - 17 . (canceled)
18 . A method of securely distributing time updates in a network having a primary timekeeping entity and one or more other time keeping devices, the method comprising the steps of:
checking all timekeeping devices to determine if each is capable of participating in a secure time distribution system; at the primary timekeeping entity, ascertaining the time and constructing a time update item; creating a first-type derivative of said time update item; creating a time update message comprising said time update item and said first-type derivative of said time update item; sending the time update message to all timekeeping devices; at a first timekeeping device receiving said time update message, processing said time update message, wherein processing said time update message includes the sub-steps of, (i) noting a time of arrival and storing said time of arrival in a first memory; (ii) starting a counter to measure the age of the received time update at a time interval Tmeasure; (iii) storing in a second memory, the time from said time update message; (iv) creating a second-type derivative of said update item; and (v) comparing said created second-type derivative of said update item with the received first-type derivative of said update item.
19 . The method of claim 18 wherein processing said time update message comprises the additional sub-step of performing a frame delay check.
20 . The method of claim 19 wherein the sub-step of performing a frame delay check comprises the steps of:
determining a difference between said time of arrival and said time from said time update message; and comparing said difference with an information transfer delay threshold, said threshold representing the maximum tolerable latency for the transport of the time update message from the primary timekeeping entity to said first timekeeping device.
21 . The method of claim 18 wherein said first memory and said second memory are the same.
22 . The method of claim 18 wherein any device not capable of participating in said secure time distribution system is excluded from network.
23 . The method of claim 18 wherein if any device is not capable of participating in said secure time distribution system, negating the availability of a secure mode in said network.
24 . The method of claim 18 wherein the step of checking all timekeeping devices to determine if each is capable of participating in a secure time distribution system, comprises the sub-step of determining, for each checked timekeeping device, a software version or a hardware version.
25 . The method of claim 18 wherein said first-type derivative and said second-type derivative comprise the same derivation process.
26 . The method of claim 18 wherein creating a first-type derivative comprises the step to applying a hash function to achieve a first hashed result.
27 . The method of claim 26 wherein creating a first-type derivative further involves the step of encrypting said first hashed result.
28 . The method of claim 18 wherein the sub-step of comparing said created second-type derivative of said update item with the received first-type derivative of said update item comprises the step of decrypting said first-type derivative.
29 . The method of claim 18 wherein the step of checking all timekeeping devices to determine if each is capable of participating in a secure time distribution system comprises the sub-step of distributing encryption key information to each timekeeping device that is determined capable of participating in a secure time distribution system.
30 . A computer readable media encoded with program instructions for causing one or more of said timekeeping devices to perform the method of claim 18 .
31 . A Fibre Channel network having securely distributing time updates, said network comprising:
a primary timekeeping switch; one or more other time keeping switches; a first microprocessor at said primary timekeeping switch for (i) causing a check of all timekeeping devices to determine if each is capable of participating in a secure time distribution system, (ii) ascertaining the time and constructing a time update item; (iii) causing the creation of a first-type derivative of said time update item, (iv) causing the creation of a time update message comprising said time update item and said first-type derivative of said time update item; a first port for sending the time update message to all timekeeping devices;
at a second timekeeping device,
a second port for receiving said time update message,
a first memory for storing said a time of arrival of said update message,
a counter for measuring the age of the received time update at a time interval Tmeasure;
a second memory for storing the time from said time update message;
a second microprocessor for causing (1) the creation of a second-type derivative of said update item; and (2) the comparison of said created second-type derivative of said update item with the received first-type derivative of said update item.
32 . The invention of claim 31 wherein said second microprocessor is also for causing frame delay check.
33 . The invention of claim 32 wherein causing a frame delay check comprises,
determining a difference between said time of arrival and said time from said time update message; and comparing said difference with an information transfer delay threshold, said threshold representing the maximum tolerable latency for the transport of the time update message from the primary timekeeping entity to said first timekeeping device.
34 . The invention 31 wherein said first memory and said second memory are the same.
35 . The invention of claim 31 wherein said Fibre Channel network may not include any device not capable of participating in said secure time distribution.
36 . The invention of claim 31 wherein said first-type derivative and said second-type derivative comprise the same derivation process.
37 . A Fibre Channel switch for securely maintaining distributed time in a network having a plurality of timekeeping devices and a primary timekeeping entity, said Fibre Channel switch comprising:
a first port for receiving a time update message comprising (i) a time update item comprising the time, and (ii) a first-type derivative of said time update item; a first memory for storing said a time of arrival of said update message, a counter for measuring the age of the received time update at a time interval Tmeasure; a second memory for storing the time from said time update message; a microprocessor for causing (1) the creation of a second-type derivative of said update item; and (2) the comparison of said created second-type derivative of said update item with the received first-type derivative of said update item.
38 . The invention of claim 37 wherein said microprocessor is also for causing frame delay check.
39 . The invention of claim 38 wherein causing a frame delay check comprises:
determining a difference between said time of arrival and said time from said time update message; and comparing said difference with an information transfer delay threshold, said threshold representing the maximum tolerable latency for the transport of the time update message from the primary timekeeping entity to said first timekeeping device.
40 . The invention of claim 37 wherein said first memory and said second memory are the same.
41 . The invention of claim 37 wherein said first-type derivative and said second-type derivative comprise the same derivation process.Join the waitlist — get patent alerts
Track US2005268091A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.