Quantitative Finance · Book 14 · Technology

Networks, Hardware and Trading Infrastructure

Networks, Hardware and Trading Infrastructure · Technology

4Time Synchronisation

European rules require a firm that trades with a high-frequency algorithmic technique to keep the clocks that timestamp its orders within 100 microseconds of UTC, and to timestamp to the microsecond. The Network Time Protocol’s specification assumes that an ordinary computer clock may run off frequency by 15 parts per million: fifteen microseconds gained or lost every second. Such a clock, set right and then left alone, is out of the rule within seven seconds. Staying inside it is a control loop that runs all day, and proving that it did is a record that must be kept.

The book has used time everywhere: the exchange and receive timestamps of One Quant Book 1, the hardware timestamps of One Quant Book 13, the captures of chapter 5 to come. This chapter says where a trading firm’s time comes from, how it is carried to every server across a network that delays it by variable amounts, and what the regulators ask a firm to show.

4.1 Clocks, oscillators and drift

A clock counts the cycles of an oscillator. If the oscillator runs slightly fast, the clock gains; if its rate itself wanders (temperature, ageing), the gain wanders too.

Definition 4.1 (Clock offset, fractional frequency offset)

The clock offset ϑ(t)\vartheta(t) of a clock is the difference between the time it shows and the reference time at the same instant. Its fractional frequency offset yf(t)=dϑ/dty_{\mathrm f}(t) = d\vartheta/dt is the rate at which the offset grows, a dimensionless number quoted in parts per million (ppm) or per billion (ppb): a clock with yf=1y_{\mathrm f} = 1 ppm gains a microsecond every second.

Definition 4.2 (Allan deviation)

The Allan deviation σy(τ)\sigma_y(\tau) of a clock is the root mean square of the change in its average fractional frequency between successive intervals of length τ\tau, divided by 2\sqrt2: σy2(τ)=12E[(yˉk+1−yˉk)2]\sigma_y^2(\tau) = \tfrac12 \E\bigl[(\bar y_{k+1} - \bar y_k)^2\bigr]. From phase samples xix_i spaced τ\tau apart it is σy2(τ)=E[(xi+2−2xi+1+xi)2]/(2τ2)\sigma_y^2(\tau) = \E\bigl[(x_{i+2} - 2x_{i+1} + x_i)^2\bigr] / (2\tau^2).

The Allan deviation answers the question a firm actually has: over an interval of τ\tau, by how much can the clock’s rate be trusted? Unlike the ordinary standard deviation, it converges for the random-walk wanderings of real oscillators, and its slope against τ\tau on a log-log plot identifies the noise: −1-1 for white phase noise (a clock whose readings are jittered but whose rate is right), +12+\tfrac12 for a random walk of frequency (a rate that wanders). Figure 4.4 shows both.

Definition 4.3 (Holdover)

Holdover is the operation of a clock that has lost its reference and keeps time on its own oscillator from the last frequency correction it had; the holdover time is how long it stays within a tolerance.

Proposition 4.4 (Holdover time)

A clock entering holdover with offset ϑ0\vartheta_0, residual frequency error y0y_0 and a constant ageing DD (frequency change per unit time) has offset ϑ(t)=ϑ0+y0t+12Dt2\vartheta(t) = \vartheta_0 + y_0 t + \tfrac12 D t^2. It stays within a limit L>∣ϑ0∣L > |\vartheta_0| until the first positive root of ∣ϑ(t)∣=L|\vartheta(t)| = L; with no ageing, t=(L−ϑ0)/y0t = (L - \vartheta_0)/y_0 for y0>0y_0 > 0.

Proof. Integrate dϑ/dt=y0+Dtd\vartheta/dt = y_0 + Dt from ϑ(0)=ϑ0\vartheta(0) = \vartheta_0. ∎

4.2 Two-way time transfer: NTP and PTP

A server learns the time from a master by exchanging messages with it. The difficulty is that a message’s arrival time mixes the clocks’ offset with the network’s delay; two messages in opposite directions separate them, under one assumption.

Definition 4.5 (Network Time Protocol, Precision Time Protocol)

The Network Time Protocol (NTP) synchronises a client to servers by request-response exchanges over UDP, typically every few seconds to minutes, with timestamps taken in software. The Precision Time Protocol (PTP, IEEE 1588) synchronises clocks on a network to a master by frequent exchanges, many a second, designed for timestamps taken in the network hardware and for switches that take part in the protocol.

PTP’s delay request-response exchange. t_1 and t_4 are read on the master’s clock, t_2 and t_3 on the slave’s. The first difference is the path delay from master to slave plus the slave’s offset; the second is the path delay back minus the offset. Time runs downward.
Figure 4.1. PTP’s delay request-response exchange. t1t_1 and t4t_4 are read on the master’s clock, t2t_2 and t3t_3 on the slave’s. The first difference is the path delay from master to slave plus the slave’s offset; the second is the path delay back minus the offset. Time runs downward.

Proposition 4.6 (Two-way offset and its blind spot)

Let the master send at t1t_1 (its clock), the slave receive at t2t_2 and reply at t3t_3 (its clock), the master receive at t4t_4, and let the one-way delays be dmsd_{\mathrm{ms}} and dsmd_{\mathrm{sm}}. The estimate

ϑ^=12[(t2−t1)−(t4−t3)]equalsϑ+12 (dms−dsm),\hat\vartheta = \tfrac12\bigl[(t_2 - t_1) - (t_4 - t_3)\bigr] \quad\text{equals}\quad \vartheta + \tfrac12\,(d_{\mathrm{ms}} - d_{\mathrm{sm}}),

and the round trip (t4−t1)−(t3−t2)=dms+dsm(t_4 - t_1) - (t_3 - t_2) = d_{\mathrm{ms}} + d_{\mathrm{sm}} does not depend on ϑ\vartheta. The two-way method is exact when the two directions take the same time, and no exchange of messages can measure how much they differ.

Proof. t2=t1+dms+ϑt_2 = t_1 + d_{\mathrm{ms}} + \vartheta and t4=t3−ϑ+dsmt_4 = t_3 - \vartheta + d_{\mathrm{sm}}; substitute. Any (ϑ,dms,dsm)(\vartheta, d_{\mathrm{ms}}, d_{\mathrm{sm}}) and (ϑ+a,dms−a,dsm+a)(\vartheta + a, d_{\mathrm{ms}} - a, d_{\mathrm{sm}} + a) produce the same four timestamps. ∎

Definition 4.7 (Path asymmetry, clock servo)

The path asymmetry of a timing path is the difference dms−dsmd_{\mathrm{ms}} - d_{\mathrm{sm}} between its two one-way delays; half of it appears, undetected, in every two-way offset estimate. A clock servo is the control loop that turns successive offset estimates into corrections of the slave’s phase and frequency.

The asymmetry is fixed by cables (a longer fibre one way), by transceivers and by switches that treat the two directions differently; the queueing in each direction adds a varying part, which averaging reduces and the servo filters. A firm finds the fixed part by calibration against a second, independent reference, and subtracts it by configuration: no protocol can find it.

    q_ms = rng.exponential(path.queue_ns, path.hops).sum()
    q_sm = rng.exponential(path.queue_ns, path.hops).sum()
    d_ms = path.base_ns + path.asym_ns / 2 + q_ms
    d_sm = path.base_ns - path.asym_ns / 2 + q_sm
    n = rng.normal(0.0, path.stamp_ns, 4)
    t1 = 0.0
    t2 = d_ms + slave_offset + n[1] - n[0]
    t3 = t2 + 1_000.0
    t4 = t3 - slave_offset + d_sm + n[3] - n[2]
    corr_ms, corr_sm = (q_ms, q_sm) if transparent else (0.0, 0.0)
    return ((t2 - t1 - corr_ms) - (t4 - t3 - corr_sm)) / 2, (t4 - t1) - (t3 - t2)
Listing 4.1. One exchange in firm.clocksync: queueing in both directions, timestamp noise, and the transparent clocks’ correction when there are any. code/firm/clocksync/firm_clocksync.py

4.3 Grandmasters, satellite references and holdover

Definition 4.8 (Grandmaster clock, GNSS time reference)

A grandmaster clock is the clock at the top of a PTP network, the master of all others. A GNSS time reference is a receiver of a global navigation satellite system (GPS, Galileo and others) used as a source of UTC: each satellite’s signal carries the system’s time and its offset from UTC as kept by a national laboratory.

A trading firm’s grandmaster is usually a dedicated appliance in each cage: a satellite antenna on the data centre’s roof, a cable down to the receiver, and an oscillator that the receiver disciplines and that keeps time in holdover when the signal is lost (jamming, a failed antenna, a cut cable). The European rule accepts UTC from a satellite system “provided that any offset from UTC is accounted for and removed”. GPS’s own performance standard specifies the accuracy of the UTC offset it broadcasts: 30 nanoseconds, 95% of the time. The rest of the error budget is the firm’s: the antenna cable’s delay (a fixed, measurable length), the receiver, and every hop from the grandmaster to the timestamp.

A cage’s timing chain. The grandmaster takes UTC from satellites and serves PTP; a boundary clock is a slave on one side and a master on the other; a transparent clock forwards PTP messages and corrects them for the time they spent inside it. Every link of the chain adds to the error budget of the timestamps at its end.
Figure 4.2. A cage’s timing chain. The grandmaster takes UTC from satellites and serves PTP; a boundary clock is a slave on one side and a master on the other; a transparent clock forwards PTP messages and corrects them for the time they spent inside it. Every link of the chain adds to the error budget of the timestamps at its end.

4.4 Boundary and transparent clocks: removing the network’s error

Definition 4.9 (Boundary clock, transparent clock)

A boundary clock is a network device with its own clock that is a PTP slave on one port and a master on its others: it ends one exchange and starts new ones, so that no PTP message crosses it. A transparent clock forwards PTP messages and adds to a correction field in each the time the message spent inside the device (its residence time), which the endpoints subtract from their timestamps.

The queueing in a switch is the largest variable delay on a timing path, and it is not symmetric: the Sync message may wait behind a market-data burst while the Delay_Req, going the other way, does not. A transparent clock measures that wait and reports it; a boundary clock removes the problem by never letting the message queue across the switch. Both need the switch’s own hardware to timestamp, and both leave the fixed asymmetry of cables and transceivers untouched.

Simulation: a server’s clock (20 ppm off, wandering) disciplined over a path of three switches with a mean 5\, µ s of queueing per switch and direction, eight exchanges a second. Queueing, not the timestamps, dominates until transparent clocks remove it; the dashed line is the 100-microsecond limit. Model values; data: fig_clock.py on firm.clocksync (seeded).
Figure 4.3. Simulation: a server’s clock (20 ppm off, wandering) disciplined over a path of three switches with a mean 5 µs5\,\text{µ}\mathrm{s} of queueing per switch and direction, eight exchanges a second. Queueing, not the timestamps, dominates until transparent clocks remove it; the dashed line is the 100-microsecond limit. Model values; data: fig_clock.py on firm.clocksync (seeded).

The tutorial runs the four set-ups of Figure 4.3 for an hour. After the first six minutes the largest offset is 26.3 µs26.3\,\text{µ}\mathrm{s} with software timestamps and 25.9 µs25.9\,\text{µ}\mathrm{s} with hardware timestamps: timestamping in hardware barely helps when the messages queue for microseconds. Keeping, of every eight exchanges, the one with the smallest round trip (the idea of NTP’s clock filter: the least-delayed exchange is the least queued) brings it to 11.1 µs11.1\,\text{µ}\mathrm{s}. Transparent clocks bring it to 25 ns25\,\mathrm{n}\mathrm{s}, a thousand times better. With transparent clocks, a fixed asymmetry of 2 µs2\,\text{µ}\mathrm{s} leaves the clock 1 µs1\,\text{µ}\mathrm{s} off, exactly as Proposition 4.6 says, and no amount of filtering sees it.

    osc, path = osc or Oscillator(), path or Path()
    rng_o, rng_p = np.random.default_rng(osc.seed + seed), np.random.default_rng(path.seed + seed)
    n = int(hours * 3600 / interval_s)
    servo = Servo(kp, ki)
    offset, y = 0.0, osc.freq_ppm * 1e3                   # ns; fractional frequency in ppb
    out, buf = np.empty(n), []
    for k in range(n):
        y += rng_o.normal(0.0, osc.walk_ppb * math.sqrt(interval_s))
        offset += (y - servo.freq_ppb) * interval_s          # ppb * s = ns
        buf.append(exchange(rng_p, offset, path, transparent))
        if len(buf) >= min_filter:
            use = min(buf, key=lambda e: e[1])[0]
            buf = []
            step, _ = servo.update(use, interval_s * min_filter)
            offset -= step
        out[k] = offset
    return {"t_s": np.arange(1, n + 1) * interval_s, "offset_ns": out}
Listing 4.2. The simulation: the oscillator wanders, the offset grows, an exchange measures it, and the servo corrects phase and frequency. code/firm/clocksync/firm_clocksync.py
Simulation: Allan deviation of the chapter’s oscillator left alone and of the same clock disciplined over transparent clocks. The free clock’s frequency wanders (slope +1/2); the disciplined clock’s readings jitter by nanoseconds around a correct rate (slope -1). Below a few seconds (between 2 and 8) the free oscillator is the steadier of the two; above, the servo wins by orders of magnitude. Model values; data: fig_clock.py.
Figure 4.4. Simulation: Allan deviation of the chapter’s oscillator left alone and of the same clock disciplined over transparent clocks. The free clock’s frequency wanders (slope +12+\tfrac12); the disciplined clock’s readings jitter by nanoseconds around a correct rate (slope −1-1). Below a few seconds (between 2 and 8) the free oscillator is the steadier of the two; above, the servo wins by orders of magnitude. Model values; data: fig_clock.py.

4.5 The regulatory requirements and proving your clock

As of September 2026 — What the rules ask of clocks

In the European Union, Commission Delegated Regulation (EU) 2017/574 (“RTS 25”) sets, for members and participants of trading venues using a high-frequency algorithmic trading technique, a maximum divergence from UTC of 100 microseconds and a timestamp granularity of 1 microsecond or better; for trading venues whose gateway-to-gateway latency is one millisecond or less, the same; for voice and human-mediated request-for-quote systems, one second. UTC is taken from a timing centre listed by the BIPM or from a satellite system with its offset removed. Firms must establish traceability to UTC, identify the exact point at which each timestamp is applied, and review compliance at least once a year. In the United States, FINRA Rule 6820 requires industry members reporting to the consolidated audit trail to synchronise their business clocks within 50 milliseconds of the NIST atomic clock (one second for manual orders), before each day’s open and throughout the day, to log the synchronisation for five years, and to certify compliance.

Definition 4.10 (Traceability to UTC)

Traceability to UTC is an unbroken, documented chain of comparisons from a firm’s timestamps to UTC, each with a stated uncertainty, such that the firm can show, for any timestamp, how far from UTC it could have been.

Method 4.11 (Proving your clock)

  1. Document the chain (Figure 4.2): reference, grandmasters, every boundary and transparent clock, the card’s clock of each server, the step to the host’s clock and the exact point where each kind of timestamp is taken.
  2. Write the error budget link by link, with its evidence (a specification, a calibration, a measurement), and compare its worst case with the limit.
  3. Monitor continuously: each slave’s measured offset and path delay, the grandmaster’s lock state and holdover, the card-to-host step; alarm well inside the limit.
  4. Keep the records for the regulators’ retention periods, including every period in holdover or out of tolerance.
  5. Calibrate the fixed asymmetries against an independent reference, and re-check after every change of cabling or equipment.
  6. Review the whole system at least once a year.

4.6 Tutorial: disciplining a clock

Goal. Discipline a simulated server clock four ways over a loaded network and read what limits each. End state: Figures 4.3 and 4.4, the four largest offsets quoted in the text, and the asymmetry experiment.

  1. The pieces. firm.clocksync holds the oscillator, the path (base delay, asymmetry, queueing per switch, timestamp noise), one exchange (Listing 4.1) and the servo; simulate runs the loop (Listing 4.2).
  2. Four set-ups. nw_clock.SETUPS differs only in timestamp noise, filtering and transparent clocks; summary(name) gives each one’s largest offset after six minutes.
  3. Stability. adev() computes the Allan deviation of the free and the disciplined clock.
  4. The blind spot. asymmetry_bias(2000) adds a fixed 2 µs2\,\text{µ}\mathrm{s} asymmetry and returns the offset it leaves, against −a/2-a/2. python fig_clock.py writes the charts’ data.

What to change next. Raise the queueing to 50 µs50\,\text{µ}\mathrm{s} per switch and find the set-ups that break the 100-microsecond limit; halve the exchange rate and read the transparent-clock offset again.

4.7 Build: the clock-synchronisation model

Purpose. A model of the firm’s timing chain in which the effect of every choice (timestamps, filters, transparent clocks, asymmetry, holdover) can be computed before it is bought, and a compliance report of offsets against a rule.

Interface. firm_clocksync: Oscillator(freq_ppm, walk_ppb, seed), Path(base_ns, asym_ns, queue_ns, hops, stamp_ns, seed), Servo(kp, ki).update(offset, interval), exchange, simulate(hours, interval_s, osc, path, transparent, kp, ki, seed, min_filter), allan_deviation, holdover_s, compliance; C++20 servo twin in cpp/.

Rules. Times in nanoseconds, frequencies in ppb; the estimate is the two-way formula and nothing else; transparent clocks correct queueing only; every draw is seeded.

Acceptance tests. code/firm/clocksync/tests/: the two-way formula exact without asymmetry and biased by half of it with; transparent clocks remove queueing; the servo converges from a 20 ppm error; the servo fixture reproduced in Python and C++; white phase noise gives an Allan slope of −1-1; holdover with and without ageing; compliance counting.

Stretch. A boundary clock with its own servo between master and slave, and the error it adds; the peer-delay mechanism; a monitoring report in the format a regulator would ask to see.

Sources and further reading

  • Commission Delegated Regulation (EU) 2017/574 (RTS 25), articles 1 and 4 and annex; FINRA Rule 6820.
  • RFC 5905, Network Time Protocol Version 4; linuxptp, ptp4l(8).
  • U.S. Department of Defense, GPS Standard Positioning Service Performance Standard, 5th edition (2020).

4.8 Exercises

Exercise 4.1 ★

A clock runs 15 ppm fast. How long after being set correctly does it breach a 100-microsecond limit, and a 50-millisecond one?

Solution

Solution of Exercise 4.1.

It gains 15 µs15\,\text{µ}\mathrm{s} a second: 100/15=6.7 s100/15 = 6.7\,\mathrm{s} to breach 100 microseconds, 50 000/15=3 33350\,000/15 = 3\,333 s, about 56 minutes, to breach 50 milliseconds.

Exercise 4.2 ★

An exchange gives t1=0t_1 = 0, t2=5 300t_2 = 5\,300, t3=6 300t_3 = 6\,300, t4=8 900t_4 = 8\,900 (nanoseconds). What are the estimated offset and the round trip?

Solution

Solution of Exercise 4.2.

ϑ^=12[(5 300−0)−(8 900−6 300)]=1350 ns\hat\vartheta = \tfrac12[(5\,300 - 0) - (8\,900 - 6\,300)] = 1350\,\mathrm{n}\mathrm{s}; round trip 8 900−1 000=7900 ns8\,900 - 1\,000 = 7900\,\mathrm{n}\mathrm{s}.

Exercise 4.3 ★

The fibre from master to slave is 40 metres longer than the fibre back. What offset does the two-way method leave, with a group index of 1.462?

Solution

Solution of Exercise 4.3.

The asymmetry is 40×4.88=195.1 ns40 \times 4.88 = 195.1\,\mathrm{n}\mathrm{s}; half of it, 97.5 ns97.5\,\mathrm{n}\mathrm{s}, remains in every estimate.

Exercise 4.4 ★★

Why did hardware timestamps barely help in Figure 4.3, and why does keeping the least-delayed exchange of eight help?

Solution

Solution of Exercise 4.4.

The timestamps’ noise (5 µs5\,\text{µ}\mathrm{s} in software, nanoseconds in hardware) is small against queueing of several microseconds per switch in each direction, which the estimate inherits as a random asymmetry. The least-delayed exchange of eight is the one that queued least in both directions, so its asymmetry is smallest.

Exercise 4.5 ★★

A grandmaster in holdover has a residual frequency error of 1 ppb and ages by 10−510^{-5} ppb a second. How long does it stay within 100 µs100\,\text{µ}\mathrm{s}?

Solution

Solution of Exercise 4.5.

Solve 12×10−5t2+t=100 000\tfrac12 \times 10^{-5} t^2 + t = 100\,000: t=(1+2−1)/10−5=73 205t = (\sqrt{1 + 2} - 1)/10^{-5} = 73\,205 s, about 20.3 hours.

Exercise 4.6 ★★

Read Figure 4.4: over which averaging times is the disciplined clock worse than the free one, and why is that not a problem?

Solution

Solution of Exercise 4.6.

Below a few seconds (the curves cross between 2 and 8 s): the servo’s corrections jitter the disciplined clock by nanoseconds from one exchange to the next, while the free oscillator’s rate is steady over short times. What matters for the rule is the offset, which the servo keeps at nanoseconds; over longer times the free clock’s wandering rate dominates, and there the disciplined clock is better by orders of magnitude.

Exercise 4.7 ★★★

Coding. With firm.clocksync, raise the mean queueing to 50 µs50\,\text{µ}\mathrm{s} per switch and direction and compute the largest offset after six minutes with hardware timestamps, with the min-delay filter and with transparent clocks. Which break the 100-microsecond rule?

Solution

Solution of Exercise 4.7.

With 50 µs50\,\text{µ}\mathrm{s} of queueing per switch and direction: about 259 µs259\,\text{µ}\mathrm{s} with hardware timestamps alone and 111 µs111\,\text{µ}\mathrm{s} with the min-delay filter, both beyond the rule; 25 ns25\,\mathrm{n}\mathrm{s} with transparent clocks, which remove queueing whatever its size.

Exercise 4.8 ★★★

Find the flaw. “Our servers’ PTP statistics show offsets below 50 ns all day, so our timestamps are within 50 ns of UTC.”

Solution

Solution of Exercise 4.8.

PTP statistics measure the offset to the master along the path, with the path’s fixed asymmetry invisible; they say nothing about the master’s own error to UTC, the card-to-host step, or where the timestamp is really taken. The 50 ns is one link of the chain, not the chain.

4.9 Problem: A Hundred Microseconds to UTC

Problem 4.1

Weekend problem — an error budget and a holdover

A firm’s timing chain has these error terms (model values, in nanoseconds): the satellite’s broadcast UTC offset 30; the antenna cable’s delay after compensation 20; the grandmaster 40; two boundary clocks 50 each; the residual path asymmetry after transparent clocks, half of 200 ns200\,\mathrm{n}\mathrm{s}; the card’s clock 20; the step from the card’s clock to the host’s clock 500; the software timestamp point 1 500. The rule is 100 microseconds.

Part I — The budget.

  1. What is the worst-case error, summing the terms?
  2. What is the root-sum-square, if they are independent?
  3. Which two terms dominate, and what share of the worst case are they?
  4. What margin does the worst case leave under the rule?

Part II — Better timestamps.

  1. The firm timestamps orders on the card instead of in software. What are the new worst case and root-sum-square?
  2. Why does that also remove the card-to-host step from the budget of those timestamps?
  3. Which term dominates now?
  4. What would halve the remaining worst case?

Part III — Holdover.

  1. The antenna fails. The grandmaster’s oscillator has a residual frequency error of 1 ppb and ages by 10−510^{-5} ppb a second. How long before the grandmaster alone uses up the margin of question 4?
  2. A cheaper grandmaster has 50 ppb of residual error and ages by 10−310^{-3} ppb a second. How long?
  3. Over a weekend of 60 hours without repair, which one stays compliant?
  4. What should the monitoring do during holdover?

Part IV — The verdict.

  1. State the named result: the chain’s worst-case error with software and with card timestamps, and the two holdover times.
  2. How does the European rule’s granularity requirement constrain the software timestamp?
  3. Why is a second grandmaster with an independent antenna worth more than a better oscillator?
  4. What does traceability require beyond the budget?
  5. Which of these terms could an auditor check without trusting the firm’s own clock?
  6. What would a 20-microsecond asymmetry (a misconfigured link) do to the budget?
  7. How does the American rule compare with this budget?
  8. In one sentence: what does a firm have to know to say how far its timestamps are from UTC?
Solution

Solution of Problem 4.1.

  1. 30+20+40+50+50+100+20+500+1 500=2310 ns30 + 20 + 40 + 50 + 50 + 100 + 20 + 500 + 1\,500 = 2310\,\mathrm{n}\mathrm{s}.
  2. 2 518 300≈1587 ns\sqrt{2\,518\,300} \approx 1587\,\mathrm{n}\mathrm{s}.
  3. The software timestamp point and the card-to-host step: 2 000/2 3102\,000/2\,310, 87%.
  4. 100 000−2 310=97 690 ns100\,000 - 2\,310 = 97\,690\,\mathrm{n}\mathrm{s}.
  5. Worst case 310 ns310\,\mathrm{n}\mathrm{s}, root-sum-square 18 300≈135 ns\sqrt{18\,300} \approx 135\,\mathrm{n}\mathrm{s}.
  6. The card stamps the packet with its own clock, which PTP disciplines directly; the host’s clock is no longer involved.
  7. The residual path asymmetry, 100 ns100\,\mathrm{n}\mathrm{s}.
  8. Calibrating the asymmetry away and removing a boundary clock.
  9. Solve 12×10−5t2+t=97 690\tfrac12 \times 10^{-5} t^2 + t = 97\,690: about 71 866 s, 20.0 hours.
  10. Solve 12×10−3t2+50 t=97 690\tfrac12 \times 10^{-3} t^2 + 50\,t = 97\,690: about 1 917 s, 32 minutes.
  11. Neither: 60 hours is three times the better one’s holdover.
  12. Record every minute in holdover, alarm at once, and switch to a second, independent reference if one exists.
  13. Named result. The chain’s worst case is 2310 ns2310\,\mathrm{n}\mathrm{s} with software timestamps and 310 ns310\,\mathrm{n}\mathrm{s} with card timestamps; the grandmaster holds the remaining margin for 20.0 hours with the good oscillator and 32 minutes with the cheap one.
  14. Timestamps must resolve a microsecond: a software timestamp read from a microsecond clock satisfies it, but its point of application must also be identified and consistent.
  15. Holdover is bounded however good the oscillator is; an independent reference keeps the chain traceable, and lets each reference be checked against the other.
  16. The documented design, the exact timestamp points, continuous monitoring records and an annual review.
  17. The satellite’s broadcast offset and a calibrated asymmetry, measured against an independent receiver or a portable reference.
  18. Add 10 µs10\,\text{µ}\mathrm{s}, more than the rest of the chain together, still inside the rule.
  19. The American 50-millisecond limit is more than twenty thousand times the chain’s worst case.
  20. Every link from UTC to the point where the timestamp is taken, with its uncertainty.

4.10 Interview questions

Interview question 4.1 ★ developer

Derive the two-way offset estimate. What assumption does it make?

Solution

Solution of Interview question 4.1.

t2=t1+dms+ϑt_2 = t_1 + d_{\mathrm{ms}} + \vartheta, t4=t3−ϑ+dsmt_4 = t_3 - \vartheta + d_{\mathrm{sm}}, so 12[(t2−t1)−(t4−t3)]=ϑ+12(dms−dsm)\tfrac12[(t_2 - t_1) - (t_4 - t_3)] = \vartheta + \tfrac12(d_{\mathrm{ms}} - d_{\mathrm{sm}}). It assumes equal delays both ways; the asymmetry cannot be measured by exchanges.

What the interviewer is looking for: the derivation and the unmeasurable asymmetry.

Interview question 4.2 ★★ developer

What is the difference between a boundary clock and a transparent clock, and why does either matter in a trading network?

Solution

Solution of Interview question 4.2.

A boundary clock terminates PTP: it is a slave upstream and a master downstream. A transparent clock forwards PTP and corrects each message for its residence time. Either removes the switch’s queueing from the estimate, which is otherwise the largest error on a loaded trading network.

What the interviewer is looking for: queueing as the problem, and the two ways of removing it.

Interview question 4.3 ★★ developer

Why would you choose PTP over NTP for a trading host? When is NTP good enough?

Solution

Solution of Interview question 4.3.

PTP with hardware timestamps and participating switches reaches nanoseconds to tens of nanoseconds on a local network; NTP with software timestamps reaches microseconds at best, milliseconds over a wide area. NTP is enough for hosts whose timestamps must meet a millisecond rule, such as a 50-millisecond audit-trail requirement.

What the interviewer is looking for: hardware timestamps, participating switches, and matching the tool to the rule.

Interview question 4.4 ★★ developer, researcher

You compare timestamps from two servers and one says a fill arrived before the order that caused it. What do you check?

Solution

Solution of Interview question 4.4.

The two clocks’ synchronisation logs at that moment (offsets, holdover, alarms), where each timestamp was taken (card or software, send or receive), any fixed asymmetry of the paths to the grandmaster, and whether the difference is within the sum of both budgets; then look for a genuine bug in the ordering.

What the interviewer is looking for: error budgets before conclusions.

Interview question 4.5 ★★★ developer

How would you prove to a regulator that your timestamps were within 100 microseconds of UTC last Tuesday?

Solution

Solution of Interview question 4.5.

Show the documented chain and budget, the monitoring records for that day (grandmaster lock, every slave’s offset and delay, no holdover or excursions), the calibration of fixed asymmetries, the timestamp points, and the last annual review.

What the interviewer is looking for: records and traceability, not a single number.

Interview question 4.6 ★★ developer

The satellite antenna fails on a Friday evening. What happens to your clocks, and what do you do?

Solution

Solution of Interview question 4.6.

The grandmaster goes into holdover and its offset grows with its oscillator’s residual error and ageing; the slaves follow it. Switch to an independent reference if there is one, alarm, compute from the oscillator’s figures when the budget runs out, record the whole period, and repair before then.

What the interviewer is looking for: holdover arithmetic and a second reference.

Terms defined in this chapter

See all 2333 terms in the glossary