Attacker localization based on tracking anomaly propagation in time-sensitive networking

US12301599B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-12301599-B2
Application numberUS-202117484197-A
CountryUS
Kind codeB2
Filing dateSep 24, 2021
Priority dateSep 24, 2021
Publication dateMay 13, 2025
Grant dateMay 13, 2025

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Systems, apparatuses and methods may provide for technology that detects one or more non-compliant nodes with respect to a timing schedule, detects one or more compliant nodes with respect to the timing schedule, and identifies a malicious node based on positions of the one or more non-compliant nodes and the one or more compliant nodes in a network topography. The non-compliant node(s) and the compliant node(s) may be detected based on post-synchronization messages, historical attribute data and/or plane diversity data.

First claim

Opening claim text (preview).

We claim: 1. An apparatus comprising: processing circuitry coupled to a memory, the processing circuitry to: detect one or more non-compliant nodes with respect to a timing schedule; detect one or more compliant nodes with respect to the timing schedule, wherein the timing schedule is based on one or more post-synchronization messages that are based on one or more remote performance measurements including one or more frame ingress time measurements; and identify a malicious node based on positions of the one or more non-compliant nodes and the one or more compliant nodes in a network topography, wherein the positions refer to placements of the one or more non-compliant nodes and the one or more compliant nodes with respect to one or more paths within the network topography, wherein the one or more non-compliant nodes and the one or more compliant nodes are to be detected based on the one or more post-synchronization messages. 2. The apparatus of claim 1 , wherein at least one of the one or more post-synchronization messages includes a remote performance measurement of the one or more remote per for measurements and a keyed hash value. 3. The apparatus of claim 2 , wherein the remote performance measurement includes a frame ingress time measurement of the one or more frame ingress time measurements, a residence time measurement or a correction field measurement. 4. The apparatus of claim 2 , wherein the keyed hash value is to be associated with a time stamp and a key pair shared by a monitor node and at least one of the one or more non-compliant nodes. 5. The apparatus of claim 1 , wherein the one or more non-compliant nodes are to be detected based on historical attribute data and plane diversity data. 6. At least one non-transitory computer-readable medium having stored thereon instructions which, when executed, cause a computing device to perform operations comprising: detecting one or more non-compliant nodes with respect to a timing schedule; detecting one or more compliant nodes with respect to the timing schedules wherein the timing schedule is based on one or more post-synchronization messages that are based on one or more remote performance measurements including one or more frame ingress time measurements; and identifying a malicious node based on positions of the one or more non-compliant nodes and the one or more compliant nodes in a network topography, wherein the positions refer to placements of the one or more non-compliant nodes and the one or more compliant nodes with respect to one or more paths within the network topography, wherein the one or more non-compliant nodes and the one or more compliant nodes are to be detected based on the one or more post-synchronization messages. 7. The non-transitory computer-readable of claim 6 , wherein at least one of the one or more post-synchronization messages includes a remote performance measurement of the one or more remote performance measurements and a keyed hash value. 8. The non-transitory computer-readable medium of claim 7 , wherein the remote performance measurement includes a frame ingress time measurement of the one or more frame ingress time measurements, a residence time measurement or a correction field measurement. 9. The non-transitory computer-readable medium of claim 7 , wherein the keyed hash value is to be associated with a time stamp and a key pair shared by a monitor node and at least one of the one or more non-compliant nodes. 10. The non-transitory computer-readable medium of claim 6 , wherein the one or more non-compliant nodes are to be detected based on historical attribute data and plane diversity data. 11. A method comprising: detecting one or more non-compliant nodes with respect to a timing schedule; detecting one or more compliant nodes with respect to the timing schedule, wherein the timing schedule is based on one or post-synchronization messages that are based on one or more remote performance measurements including one or more frame ingress time measurements; and identifying a malicious node based on positions of the one or more non-compliant nodes and the one or more compliant nodes in a network topography, wherein the positions refer to placements of the one or more non-compliant nodes and the one or more compliant nodes with respect to one or more paths within the network topography, wherein the one or more non-compliant nodes and the one or more compliant nodes are to be detected based on the one or more post-synchronization messages. 12. The method of claim 11 , wherein at least one of the one or more post-synchronization messages includes a remote performance measurement of the one or more remote performance measurements and a keyed hash value. 13. The method of claim 12 , wherein the remote performance measurement includes a frame ingress time measurement of the one or more frame ingress time measurements, a residence time measurement or a correction field measurement. 14. The method of claim 12 , wherein the keyed hash value is associated with a timestamp and a key pair shared by a monitor node and at least one of the one or more non-compliant nodes. 15. The method of claim 11 , wherein the one or more non-compliant nodes are detected based on historical attribute data and plane diversity data.

Assignees

Inventors

Classifications

  • involving identification of individual flows · CPC title

  • in relation to timing considerations · CPC title

  • Timestamp · CPC title

  • Tracing the source of attacks · CPC title

  • Traffic logging, e.g. anomaly detection · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US12301599B2 cover?
Systems, apparatuses and methods may provide for technology that detects one or more non-compliant nodes with respect to a timing schedule, detects one or more compliant nodes with respect to the timing schedule, and identifies a malicious node based on positions of the one or more non-compliant nodes and the one or more compliant nodes in a network topography. The non-compliant node(s) and the…
Who is the assignee on this patent?
Intel Corp
What technology area does this patent fall under?
Primary CPC classification H04L63/1425. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue May 13 2025 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 6 related publications on this page (citations in our corpus or others sharing the same primary CPC).