Outer Rim Archives
Archives · 2021 · 20210211461

Application (pre-grant publication)

SYSTEM AND METHOD FOR PROVIDING SECURITY FOR MASTER CLOCKS

Number
20210211461
Published
2021-07-08
Filed
2020-01-03
Assignee
Disney Enterprises, Inc.
Inventors
BEARDSLEY; Craig L., STREIN; Michael J.
CPC
H04J3/0602; H04J3/0641; H04J3/0658; H04J3/0688; H04L63/1425; H04L63/1466; H04L63/1483; H04L69/325; H04L7/0008
Verdict
Set aside network timing security, infra
Source
Google Patents · FreePatentsOnline

Abstract

Embodiments describe monitoring network activity and behavior of authorized clocks to identify suspicious activity, and in response, removing a clock for an authorized clock list. In one embodiment, a network monitor detects changes in profiles corresponding to the authorized clocks such as a disconnecting from a port, changing a network location, unexpected changes in the clock signal, changes to the clock ID or MAC address, and the like. If the network monitor deems these changes suspicious, it removes the clock from the authorized clock list. When the current master clock fails, the PTP endpoints select a new master clock only if that clock is included in the authorized clock list. In this manner, the network monitor can constantly update the authorized clock list to ensure it contains only clocks that have not been tampered with or replaced with rogue clocks.

Background

BACKGROUND

The Precision Time Protocol (PTP) is defined by the Institute of Electrical and Electronics Engineers (IEEE®) 1588 standard and adopted by the Society of Motion Picture and Television Engineers® (SMPTE®) 2059. The PTP standard provides a timestamp that has 80 bits of precision and is accurate to the microsecond range. Generally, SMPTE 2059 is directed to leveraging PTP to provide timestamps for video data that is encapsulated in Internet Protocol (IP) packets. Using these protocols, PTP time reference data can be shared throughout a network to provide a synchronized clock to media nodes (e.g., cameras, audio devices, video encoders, audio encoders, etc.) connected to the network. That is, the switches and other network devices distribute clock signals (e.g., timestamps) that can synchronize local clocks to a master clock.

When the current master clock fails, candidate clocks broadcast announcement messages to PTP endpoints. The endpoints use the information in these message to perform a Best Master Clock (BMC) algorithm as defined in IEEE 1588 to select the next master clock. Because the endpoints follow the same protocol and assuming they all receive the same announcement messages, each PTP endpoint selects the same candidate clock to use as the next master clock.

However, PTP does not consider security issues that may arise from a nefarious actor plugging a rogue clock into the network. The nefarious actor can configure the announcement messa

Claims

1. A method, comprising: identifying a plurality of candidate master clocks connected to a network, wherein at least one clock ID for each of the plurality of candidate master clocks is stored in an authorized clock list; monitoring network activity corresponding to the plurality of candidate master clocks; determining suspicious activity associated with a first clock of the plurality of candidate master clocks; removing a clock ID of the first clock from the authorized clock list; and selecting, using the clock IDs remaining in the authorized clock list, a master clock from the plurality of candidate master clocks. || 8. A non-transitory computer-readable medium containing computer program code that, when executed by operation of one or more computer processors, performs an operation comprising: identifying a plurality of candidate master clocks connected to a network, wherein at least one clock ID for each of the plurality of candidate master clocks is stored in an authorized clock list; monitoring network activity corresponding to the plurality of candidate master clocks; determining suspicious activity associated with a first clock of the plurality of candidate master clocks; and removing a clock ID of the first clock from the authorized clock list, wherein the first clock is no longer a candidate master clock once removed from the authorized clock list. || 15. A system, comprising: a network; a plurality of candidate master clocks connected to the network, wherein at least one clock ID for each of the plurality of candidate master clocks is stored in an authorized clock list; a network monitor configured to: monitor network activity corresponding to the plurality of candidate master clocks, determine suspicious activity associated with a first clock of the plurality of candidate master clocks, and remove a clock ID of the first clock from the authorized clock list, wherein the first clock is no longer a candidate master clock once removed from the authorized clock list; and a plurality of endpoints connected to the network and configured to select, using the clock IDs remaining in the authorized clock list, a master clock from the plurality of candidate master clocks.