It's about Time: Securing Broadcast Time Synchronization with Data Origin Authentication

Robert Annessi, Joachim Fabini, Tanja Zseby · 2017

Due to the increasing dependency of critical infrastructure on synchronized clocks, network time synchronization protocols have become an attractive target for attackers. We identify data origin authentication as the key security objective and therefore conduct a comprehensive, theoretical evaluation of data origin authentication schemes from different application fields with regard to their applicability to secure broadcast time synchronization. Some evaluated schemes were found to be susceptible to message delay attacks in the context of time synchronization - including TESLA, the approach currently favored by the IETF NTP working group and also on the shortlist of the P1588 Security Subcommittee for PTP. Two of the evaluated schemes, however, come somewhat close to meeting the evaluation criteria derived from our time synchronization specific threat analysis, and therefore qualify as promising candidates to secure broadcast time synchronization.

Read the paper · More papers on PaperTik