Netnod presents Roughtime protocol for IoT device time security
Netnod has presented the Roughtime protocol, designed to securely provide time to devices, especially in IoT scenarios, without requiring an accurate starting time. The protocol can offer cryptographic proof of server malfeasance.

Netnod, a Swedish internet infrastructure provider, has highlighted the Roughtime protocol as a solution to enhance time synchronization for devices, with a particular focus on the Internet of Things (IoT) sector.
During the Netnod Meeting 2025, Marcus Dansarie, an independent consultant at Netnod, presented the Roughtime draft protocol. The protocol aims to securely deliver time to devices, even if they do not have an accurate starting point. Additionally, it can provide cryptographic evidence of malicious server behavior and serve as a supplement to established time protocols like NTP and NTS.
Accurate time is critical for numerous security-sensitive applications, including DNSSEC, TLS certificates, and authentication tokens. Incorrect time can lead to security vulnerabilities, such as accepting revoked certificates or rejecting valid ones. Roughtime addresses these issues by offering an authenticated time service that does not depend on the device's initial precise time. The protocol utilizes long-term public keys and advises clients to query multiple servers to mitigate risks associated with a single misbehaving server.
Roughtime is engineered to be a secure-by-default protocol with low CPU and memory requirements. It possesses the capability to detect and prove server malfeasance and can timestamp arbitrary data. The protocol is currently in development, with expectations of becoming an experimental RFC in the coming months, which is anticipated to foster the growth of a global Roughtime server ecosystem.