Securing Unprotected NTP Implementations Using an NTS Daemon

Martin Langer, Thomas Behn, R. Bermbach
{"title":"Securing Unprotected NTP Implementations Using an NTS Daemon","authors":"Martin Langer, Thomas Behn, R. Bermbach","doi":"10.1109/ISPCS.2019.8886645","DOIUrl":null,"url":null,"abstract":"This paper presents a method to secure the time synchronization messages of various Network Time Protocol (NTP) services. It uses the Network Time Security protocol (NTS), which is now in a final, pre-RFC state, without the necessity of changes of their underlying implementations. A dedicated NTS service – the so-called NTS daemon (NTSd) – captures the standard NTP messages of the client and passes them on to an NTS server (tunneling). Supplied with the respective timestamps the secured message travels back via the NTS daemon to the NTP client, a procedure completely transparent to the NTP services. The presented research and the implementation of the method show advantages and limitations of the approach. Furthermore, it offers limited correction of NTS related time message asymmetries. Measurements provide an insight into the achievable accuracy and show the differences to NTP services with integrated NTS capability.","PeriodicalId":193584,"journal":{"name":"2019 IEEE International Symposium on Precision Clock Synchronization for Measurement, Control, and Communication (ISPCS)","volume":"1 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2019-09-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2019 IEEE International Symposium on Precision Clock Synchronization for Measurement, Control, and Communication (ISPCS)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ISPCS.2019.8886645","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1

Abstract

This paper presents a method to secure the time synchronization messages of various Network Time Protocol (NTP) services. It uses the Network Time Security protocol (NTS), which is now in a final, pre-RFC state, without the necessity of changes of their underlying implementations. A dedicated NTS service – the so-called NTS daemon (NTSd) – captures the standard NTP messages of the client and passes them on to an NTS server (tunneling). Supplied with the respective timestamps the secured message travels back via the NTS daemon to the NTP client, a procedure completely transparent to the NTP services. The presented research and the implementation of the method show advantages and limitations of the approach. Furthermore, it offers limited correction of NTS related time message asymmetries. Measurements provide an insight into the achievable accuracy and show the differences to NTP services with integrated NTS capability.
使用NTS守护进程保护未受保护的NTP实现
本文提出了一种保护各种网络时间协议(NTP)服务的时间同步消息的方法。它使用网络时间安全协议(NTS),该协议现在处于最终的、pre-RFC状态,无需更改其底层实现。专用的NTS服务-所谓的NTS守护进程(NTSd) -捕获客户端的标准NTP消息并将其传递到NTS服务器(隧道)。提供相应的时间戳后,安全消息通过NTS守护进程返回到NTP客户端,这是一个对NTP服务完全透明的过程。本文的研究和实现表明了该方法的优点和局限性。此外,它提供了有限的NTS相关的时间消息不对称校正。测量提供了一个洞察到可实现的准确性,并显示与集成的NTS能力NTP服务的差异。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信