IP Library › Granted Patent US 9,615,258
Granted Patent B2
US 9,615,258 · App. 14/718,271 · Granted Apr 4, 2017

Method and apparatus for securing timing packets over untrusted packet transport network

Inventors: David T. Chen (Wilmette, IL); Umamaheswar Kakinada (Carpenterville, IL); Mohammed Petiwala (Wheeling, IL); Mohsin Zia (Elmhurst, IL)
Assignee: Nokia Solutions and Networks Oy
H04W12/10H04L43/106H04L47/825H04L63/0428H04L63/164
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,615,258
App. No.
14/718,271
Granted
Apr 4, 2017
Kind
B2
Abstract

Methods, devices, systems, techniques, and computer program products are provided to secure timing synchronization to network nodes connected over an inherently insecure best effort public network with mechanisms to improve accuracy of timing protocols such as a statistically estimated edge timestamp offset encoded into the timing message to account for network jitter and processing latency variances incurred due to the security packet processing and encryption; to ensure slave network nodes shall only accept timing messages from trusted timing sources; to establish a secure tunnel with a trusted timing source for exchange of timing packets; to provide authentication and security for timing packets over the insecure public network; and to enhance message anonymity with variable payload padding.

Claims (13)

1. A method comprising:

establishing, based on a security policy database, an Internet Key Exchange (IKE) security association between a gateway node and an access node in a wireless communication systems;

creating multiple child security associations comprising at least one or more security associations to use exclusively for a packet-based two-way message exchange protocol for synchronizing clocks between the gateway node and the access node;

collecting the one or more exclusive security associations in a security associations database;

embedding, in Internet Protocol (IP) packets at wireless communication nodes, timing information with one of the one or more exclusive security associations from the security association database;

creating one or more Internet Protocol Security (IPsec) tunnels between the gateway node and the access node based on the one or more security associations;

encrypting the packets;

exchanging the packets between the gateway node and the access node; and

authenticating the packets with a security parameter index.

2. The method of claim 1 , wherein the embedding further comprises a 1588v2 packet inside IPsec Encapsulating Security Payload (ESP) payload.

3. The method of claim 2 , further comprising:

adding a variable padding to the IPsec ESP payload, wherein the variable padding provides anonymity to the Timing over Packet (ToP) packets in transit.

4. The method of claim 3 , wherein standard ToP packet size cannot be used to identify the ToP packets in transit.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 24, 2015
From: CHEN, DAVID; KAKINADA, UMAMAHESWAR; PETIWALA, MOHAMMED; ZIA, MOHSIN
To: NOKIA SOLUTIONS AND NETWORKS OY
Reel/Frame 036170/0837 →
Continuity (1)
Related Publication 20160345179A1 · Nov 24, 2016