Security aspects for IEEE 1588 based clock synchronization protocols

Security aspects for IEEE 1588 based clock synchronization protocols
复制标题

基于 IEEE 1588 的时钟同步协议的安全问题

DOI:
--
复制
发表时间:
2006
期刊:
IEEE International Workshop on Factory Communication Systems
影响因子:
--
通讯作者:
T. Sauter
T. Sauter
中科院分区:
--
文献类型:
--
作者:
G. Gaderer;A. Treytl;T. Sauter

文献摘要

被引文献

相似文献

分布式系统中的时钟同步是许多应用的一项支持技术。通常,时钟同步以主从方式完成,以获得高且可预测的精度。这种方法的著名代表是 IEEE 1588 和单主 NTP(网络时间协议)的简化形式。尽管与民主方法相比,主从(1:n)方法的简单性在实施和操作方面具有优势,但它也非常容易出现故障或恶意攻击。一个例子是对任何恶意主人(例如,)的反应能力很差。例如,拜占庭或“胡言乱语的白痴”节点有可能以错误的时钟值危害所有连接的节点。现有协议解决了分布式系统中时钟正确同步的问题,但安全性处理较差。本文将研究基于主从的时钟同步算法的常见安全特性,分析适用的威胁并提出对策以实现更可靠的系统。
The synchronization of clocks in distributed systems is an enabling technology for many applications. Often clock synchronization is done in a master-slave fashion in order to gain high and predictable accuracy. Well-known representatives of this approach are IEEE 1588 and simplified forms of single-master NTP (Network Time Protocol). Although the simplicity of the master-slave (1:n) approach has advantages for implementation and operation compared to democratic approaches, it is also very vulnerable to failures or malicious attacks. One example is the poor ability to react on the fact that any malicious master, e. g., a Byzantine or “babbling idiot” node, has the potential to compromise all connected nodes with a wrong clock value. Available protocols solve the problem of correct synchronization of clocks in distributed systems, but poorly handle security. This paper will investigate common security properties of master-slave based clock synchronization algorithms, analyse the applicable threats and propose countermeasures to achieve more dependable systems.