Invention Grant
- Patent Title: Clock rollback security
-
Application No.: US14701561Application Date: 2015-05-01
-
Publication No.: US10114945B2Publication Date: 2018-10-30
- Inventor: Gary Barton , Brandon Olekas
- Applicant: Citrix Systems, Inc.
- Applicant Address: US FL Fort Lauderdale
- Assignee: Citrix Systems, Inc.
- Current Assignee: Citrix Systems, Inc.
- Current Assignee Address: US FL Fort Lauderdale
- Agency: Banner & Witcoff, Ltd.
- Main IPC: G06F21/55
- IPC: G06F21/55 ; G06F21/62 ; G06F21/72 ; H04L29/08

Abstract:
Methods and systems for preventing clock rollback attacks are described herein. A rollback attack may occur when a user manually sets a system clock to a date/time earlier than the actual present day date and time, thereby tricking any software relying on the system clock to believe it is in fact the earlier date and time rather than the current date and time. According to aspects described herein, a particular application may check and store a record of the system time when an application goes inactive (or at intervals) and again when the application subsequently is activated again. When the application determines that the time has gone backward, the application (or system) may take some remedial measure(s) to prevent further use of the application (or system) until the user reestablishes trust (e.g., by reauthenticating or reestablishing a connection with a trusted time server).
Public/Granted literature
- US20150317478A1 Clock Rollback Security Public/Granted day:2015-11-05
Information query