US2018109956A1PendingUtilityA1

Method and Apparatus for Securing Timing Packets Over Untrusted Packet Transport Network

Assignee: NOKIA SOLUTIONS & NETWORKS OYPriority: May 21, 2015Filed: Dec 13, 2017Published: Apr 19, 2018
Est. expiryMay 21, 2035(~8.8 yrs left)· nominal 20-yr term from priority
H04W 12/10H04L 2463/121H04L 43/106H04L 63/0272H04W 12/02H04J 3/0661H04L 63/0428H04L 2209/80H04L 63/164H04L 47/825H04W 12/61H04W 12/03
50
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Methods, devices, systems, techniques, and computer program products are provided to secure timing synchronization to network nodes connected over an inherently insecure best effort public network with mechanisms to improve accuracy of timing protocols such as a statistically estimated edge timestamp offset encoded into the timing message to account for network jitter and processing latency variances incurred due to the security packet processing and encryption; to ensure slave network nodes shall only accept timing messages from trusted timing sources; to establish a secure tunnel with a trusted timing source for exchange of timing packets; to provide authentication and security for timing packets over the insecure public network; and to enhance message anonymity with variable payload padding.

Claims

exact text as granted — not AI-modified
1 . (canceled) 
     
     
         2 . (canceled) 
     
     
         3 . (canceled) 
     
     
         4 . (canceled) 
     
     
         5 . (canceled) 
     
     
         6 . A method comprising:
 receiving an ingress encrypted Timing over Packet (ToP) packet in a second timing module of a second node in a wireless communication system from a first node via a secure transport;   decrypting the ingress encrypted ToP packet to retrieve a ToP packet; and   applying a timestamp to the ToP packet using a local timing module.   
     
     
         7 . The method of  claim 6 , wherein the secure transport for the timing over packet comprises setting up an Internet Protocol Security (IPsec) session in tunnel mode, wherein processing ToP packets comprises a specific SPI for the session. 
     
     
         8 . The method of  claim 7 , further comprising authenticating a node in wireless communication system to another node in the wireless communication system. 
     
     
         9 . A method comprising:
 determining a list of servers for a timing service;   resolving specified domain names with secure name servers from the determined list;   creating a prioritized list of preferred servers from the specified names;   choosing a most preferred server from the created prioritized list to avail timing service; and   establishing a secure transport with the most preferred server.   
     
     
         10 . A method comprising:
 establishing a secure transport between a slave node and a timing server node in a communications network;   mutually authenticating the slave node and the timing server node;   exchanging, between the slave node and the timing sever node, encrypted ToP packets via the secure transport.   
     
     
         11 . The method of  claim 10 , wherein the secure transport comprises an IPsec session in tunnel mode with the most preferred server among the list of prioritized servers, and wherein the secure keys comprise IPsec Internet Key Exchange messages. 
     
     
         12 . The method of  claim 10 , wherein establishing authenticity further comprises using domain specific, pre-configured, or third party signed certificates during IPsec session setup. 
     
     
         13 . The method of  claim 10 , wherein exchanging encrypted timing messages via the secure transport comprises exchanging ToP packets via an IPsec in tunnel mode with encryption including an authentication option. 
     
     
         14 . The method of  claim 10 , further comprising:
 setting, by an operator, a lifetime for the secure transport per a policy of the operator.   
     
     
         15 . The method of  claim 14 , further comprising:
 reestablishing the secure transport after expiration of the lifetime; and   changing a security parameter index for each reestablishment.

Join the waitlist — get patent alerts

Track US2018109956A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.