Apparatuses and methods for authenticating messages in communication system
By processing intermediate MACs using operations like exclusive-OR to produce a final 32-bit MAC, the method enhances message authentication security with larger keys while maintaining compatibility with the 5G air interface, addressing the challenge of MAC collisions and ensuring backward compatibility.
Patent Information
- Application Number
- PCT/US2024/051355
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-11-15
- Filing Date
- 2024-10-15
- Publication Date
- 2025-05-22
AI Technical Summary
Current message authentication methods in communication systems, particularly with larger keys like 256-bit keys, face vulnerabilities due to the fixed size of message authentication codes (MACs), which can lead to collisions and compromise security without altering the 5G air interface design.
The method involves generating an intermediate MAC using a larger key, processing it by combining portions using operations like exclusive-OR, and producing a final MAC that is compatible with the existing 32-bit MAC size, thereby enhancing security without modifying the 5G air interface.
This approach reduces the likelihood of MAC collisions, enhances the security of message authentication with larger keys, and maintains compatibility with existing 5G infrastructure, ensuring backward compatibility and interoperability.
Smart Images

Figure US2024051355_22052025_PF_FP_ABST
Abstract
Description
APPARATUSES AND METHODS FOR AUTHENTICATING MESSAGES IN COMMUNICATION SYSTEMCROSS REFERENCE TO RELATED APPLICATIONS
[0001] This application claims priority to U.S. Provisional Application No. 63 / 599,398, entitled “METHOD FOR IMPROVING SECURITY OF MESSAGE AUTHENTICATION IN 5G,” filed on November 15, 2023, which is hereby incorporated in its entirety by this reference.TECHNICAL FIELD
[0002] The present disclosure relates to the field of communication systems, and more particularly, to apparatuses and methods for authenticating messages in a communication system.BACKGROUND
[0003] Message authentication is a fundamental security mechanism used in communication systems to ensure data integrity and authenticity. It typically involves generating a message authentication code (MAC) using an integrity algorithm and a shared secret key. As communication technologies evolve, larger key sizes are being adopted to enhance security. However, while key sizes may increase, the size of the MAC used for authentication may remain fixed. This can create potential vulnerabilities, as compressing a larger message into a smaller MAC increases the likelihood of collisions, where different messages could produce the same MAC. Addressing this challenge requires methods that enhance security without significantly altering the communication system's design.
[0004] Therefore, there is a need for apparatuses and methods for authenticating messages in a communication system.SUMMARY
[0005] An object of the present disclosure is to propose apparatuses and methods for authenticating messages in a communication system, which can preserve backward compatibility and interoperability and / or enhance security.
[0006] In a first aspect of the present disclosure, a method for authenticating messages in a communication system, includes generating, by a processor, an intermediate message authentication code (MAC) for a message using a key, processing, by the processor, the intermediate MAC by combining portions of the intermediate MAC using at least one combining operation, and producing, by the processor, a final MAC based on the intermediate MAC for use in authenticating the message, wherein the size of the final MAC is less than the size of the intermediate MAC.
[0007] In a second aspect of the present disclosure, a communication system includes a memory, a transceiver, and a processor coupled to the memory and the transceiver. The processor is configured to perform: generating an intermediate message authentication code (MAC) for a message using a key, processing the intermediate MAC by combining portions of the intermediate MAC using at least one combining operation, and producing a final MAC based on the intermediate MAC for use in authenticating the message, wherein the size of the final MAC is less than the size of the intermediate MAC.
[0008] In a third aspect of the present disclosure, a non-transitory machine-readable storage medium has stored thereon instructions that, when executed by a computer, cause the computer to perform the above method.
[0009] In a fourth aspect of the present disclosure, a chip includes a processor, configured to call and run a computer program stored in a memory, to cause a device in which the chip is installed to execute the above method.
[0010] In a fifth aspect of the present disclosure,
[0011] In a sixth aspect of the present disclosure, a computer readable storage medium, in which a computer program is stored, causes a computer to execute the above method.
[0012] In a seventh aspect of the present disclosure, a computer program product includes a computer program, and the computer program causes a computer to execute the above method.
[0013] In an eighth aspect of the present disclosure, a computer program causes a computer to execute the above method.BRIEF DESCRIPTION OF DRAWINGS
[0014] In order to illustrate the embodiments of the present disclosure or related art more clearly, the following figures will be described in the embodiments are briefly introduced. It is obvious that the drawings are merely some embodiments of the present disclosure, a person having ordinary skill in this field can obtain other figures according to these figures without paying the premise.
[0015] FIG. 1 is a flowchart illustrating an example of message ciphering and integrity protection.
[0016] FIG. 2 is a block diagram of a communication system according to an embodiment of the present disclosure.
[0017] FIG. 3 is a flowchart illustrating a method for authenticating messages in a communication system according to an embodiment of the present disclosure.
[0018] FIG. 4 is a flowchart illustrating an example of combining two blocks into one using exclusive-OR operation according to an embodiment of the present disclosure.
[0019] FIG. 5 is a flowchart illustrating an example of MAC with multiple blocks according to an embodiment of the present disclosure.
[0020] FIG. 6 is a flowchart illustrating an example of multiple rounds of MAC operation according to an embodiment of the present disclosure.
[0021] FIG. 7 is a block diagram of an example of a computing device according to an embodiment of the present disclosure.
[0022] FIG. 8 is a block diagram of a communication system according to an embodiment of the present disclosure.DETAILED DESCRIPTION OF EMBODIMENTS
[0023] Embodiments of the present disclosure are described in detail with the technical matters, structural features, achieved objects, and effects with reference to the accompanying drawings as follows. Specifically, the terminologies in the embodiments of the present disclosure are merely for describing the purpose of the certain embodiment, but not to limit the disclosure.
[0024] The technical solutions of the embodiments of the present disclosure can be applied to various communication systems, such as a global system of mobile communication (GSM) system, a code division multiple access (CDMA) system, a wideband code division multiple access (WCDMA) system, a general packet radio service (GPRS), a long term evolution (LTE) system, a LTE frequency division duplex (FDD) system, a LTE time division duplex (TDD) system, an advanced long term evolution (LTE-A) system, a future 5th generation (5G) system (may also be called a new radio (NR) system), an evolution system of a NR system, a LTE-based access to unlicensed spectrum (LTE-U) system, a NR-based access to unlicensed spectrum (NR-U) system, an universal mobile telecommunication system (UMTS), a global interoperability for microwave access (WiMAX) communication system, wireless local area networks (WLAN), wireless fidelity (Wi-Fi), or other communication systems, etc.
[0025] Optionally, the communication system in the embodiment of the present application may be applied to an unlicensed spectrum, where the unlicensed spectrum may also be considered as a shared spectrum, or the communication system in the embodiment of the present application may also be applied to a licensed spectrum, where the licensed spectrum can also be considered an unshared spectrum.
[0026] In some embodiments, a method for enhancing message authentication and integrity protection in a communication system, such as a 5G network, is disclosed. The method involves using the entire message as input into a well-known integrity protection algorithm, which utilizes a symmetric shared secret key. This shared secret key is established between two entities following mutual authentication. The method is adaptable for both 128-bit and 256-bit key sizes, which are generated for enhanced security between the communicating parties.
[0027] In this implementation, when the message is significantly larger than an expected message authentication code (MAC), the integrity protection algorithm compresses the message to produce a smaller MAC, such as a 32-bit output from a larger input (e.g., 128-bit or 256-bit). This compression is relevant when migrating from 128-bit security to 256-bit security in next-generation systems like 5G, as operators seek to maintain strong security while minimizing the impact on existing network architectures.
[0028] The method continues to support air interface integrity protection, even as the key size increases from 128 bits to 256 bits. Although the natural expectation is for the MAC size to increase to 64 bits with larger key sizes, the present implementation retains a 32-bit MAC for backward compatibility with the existing 5G air interface, avoiding changes that could cause interoperability issues.
[0029] In some embodiment, the integrity algorithm compresses a larger message into a smaller MAC, but this may lead to potential information loss. For instance, compressing 128 bits into 32 bits could result in collisions, where multiple different input patterns (around 296combinations) produce the same MAC output. To address this, the method introduces a 64-bit MAC option for systems utilizing a 256-bit key. By increasing the MAC size to 64 bits, the number of potential collision patterns is significantly reduced, enhancing the security of the communication system.
[0030] In one variation of some embodiments, if a 256-bit integrity algorithm is used, the resulting 32-bit MAC would experience a collision rate of approximately 2224, but this can be improved. By extending the MAC size to 64 bits, the system reduces the collision rate to around 2192, providing more robust security.
[0031] In a further embodiment, the proposed method applies the use of exclusive-OR operations or other similar logical functions to combine the results of intermediate 32-bit or 64-bit MACs into a final, smaller MACvalue without altering the fundamental structure of the communication system’s air interface. This example ensures the migration to 256-bit security is smooth, maintaining compatibility with current network designs while improving overall security by reducing the likelihood of MAC collisions.
[0032] To address the challenges posed by the limitations of current message authentication methods, particularly when using larger keys (e.g., 256-bit keys), the present disclosure provides a method for improving security in 5G networks without altering the underlying 5G air interface. This method ensures stronger message authentication while maintaining compatibility with existing network designs.
[0033] Encryption and integrity protection are critical in ensuring secure communication between entities in wireless networks. These protections rely on the secrecy of cipher and integrity keys, which are currently 128 bits in length in 5G. Symmetric key algorithms like Advanced Encryption Standard (AES), SNOW-3G, and ZUC have been standardized for use in both 4G and 5G by 3GPP. However, as computational capabilities advance and crypto-analysis techniques improve, the security of 128-bit encryption is at increasing risk of being compromised. As a result, the industry is moving toward adopting 256-bit encryption and integrity protection for stronger security.
[0034] The drawback of maintaining a 32-bit message authentication code (MAC) with larger keys, such as 256 bits, is an increased risk of collisions — where different inputs yield the same MAC. On the other hand, using a larger MAC would require alterations to the 5G air interface, which could create backward compatibility issues. The present disclosure offers a solution that improves message authentication and security with 256-bit keys while avoiding these changes to the 5G air interface.
[0035] Encryption transforms a message into unrecognizable random bits, protecting it from unauthorized access, while integrity protection generates a cryptographic checksum, or message authentication code (MAC), to verify that the message has not been altered during transmission. In current 4G and 5G networks, the MAC size is fixed at 32 bits. With the migration from 128-bit to 256-bit keys for enhanced security, the industry norm suggests that the MAC size should increase proportionally, typically to at least 64 bits. However, expanding the MAC size from 32 bits to 64 bits in 5G would significantly disrupt the air interface.
[0036] The 5G air interface is meticulously designed to balance efficiency and reliability, with constraints on the maximum number of bits per packet and a fixed block size that includes the 32-bit MAC. Enlarging the MAC to 64 bits would either reduce the available payload capacity or necessitate an increase in the maximum packet size, both of which would require a fundamental redesign of the air interface. Given the widespread deployment of 5G, modifying the air interface to accommodate a larger MAC is not feasible. Therefore, any solution must enhance security without altering the 5G air interface.
[0037] FIG. 1 illustrates the process of applying ciphering and integrity protection to a message before it is transmitted over the air. In both 4G and 5G systems, the message undergoes encryption to ensure confidentiality, transforming it into unrecognizable random bits. Following encryption, integrity protection is applied to the message by generating a cryptographic checksum known as the Message Authentication Code (MAC). This MAC is currently set to 32 bits in length, which ensures that any alteration during transit can be detected while maintaining compatibility with the existing 4G and 5G air interface design.
[0038] FIG. 2 illustrates a communication system 200 according to an embodiment of the present disclosure. The UE 200 is configured to implement some embodiments of the disclosure. Some embodiments of thedisclosure may be implemented into the UE 200 using any suitably configured hardware and / or software. The UE 200 may include a memory 201, a transceiver 202, and a processor 203 coupled to the memory 201 and the transceiver 202. The processor 203 may be configured to implement proposed functions, procedures and / or methods described in this description. Layers of radio interface protocol may be implemented in the processor 203. The memory 201 is operatively coupled with the processor 203 and stores a variety of information to operate the processor 203. The transceiver 202 is operatively coupled with the processor 203, and the transceiver 202 transmits and / or receives a radio signal. The processor 203 may include application-specific integrated circuit (ASIC), other chipset, logic circuit and / or data processing device. The memory 201 may include read-only memory (ROM), random access memory (RAM), flash memory, memory card, storage medium and / or other storage device. The transceiver 202 may include baseband circuitry to process radio frequency signals. When the embodiments are implemented in software, the techniques described herein can be implemented with modules (e.g., procedures, functions, and so on) that perform the functions described herein. The modules can be stored in the memory 201 and executed by the processor 203. The memory 201 can be implemented within the processor 203 or external to the processor 203 in which case those can be communicatively coupled to the processor 203 via various means as is known in the art.
[0039] In some embodiments, the processor 203 is configured to perform: generating an intermediate message authentication code (MAC) for a message using a key, processing the intermediate MAC by combining portions of the intermediate MAC using at least one combining operation, and producing a final MAC based on the intermediate MAC for use in authenticating the message, wherein the size of the final MAC is less than the size of the intermediate MAC. This can solve issues in the prior art and other issues. Further, the proposed some embodiments can preserve backward compatibility and interoperability and / or enhance security.
[0040] FIG. 3 illustrates a method 300 for authenticating messages in a communication system according to an embodiment of the present disclosure. The method 300 for authenticating messages in the communication system is configured to implement some embodiments of the disclosure. Some embodiments of the disclosure may be implemented into the method 300 for authenticating messages in the communication system using any suitably configured hardware and / or software. In some embodiments, the method 300 for authenticating messages in the communication system includes: an operation 302, generating, by a processor, an intermediate message authentication code (MAC) for a message using a key, an operation 304, processing, by the processor, the intermediate MAC by combining portions of the intermediate MAC using at least one combining operation, and an operation 306, producing, by the processor, a final MAC based on the intermediate MAC for use in authenticating the message, wherein the size of the final MAC is less than the size of the intermediate MAC. This can solve issues in the prior art and other issues. Further, the proposed some embodiments can preserve backward compatibility and interoperability and / or enhance security.
[0041] Some embodiments of the present disclosure aim to enhance the security of message authentication when using larger keys, such as 256-bit keys, while preserving the existing 5G air interface design. Given the complexity of the 5G air interface, which plays a crucial role in ensuring efficiency, security, and performance, it is essential that any improvements in security, including the use of larger keys, do not necessitate modifications to the air interface. This ensures that security enhancements can be implemented without impacting the stability, backward compatibility, or performance of the 5G system.
[0042] In some embodiments of the present disclosure, when using a larger key, such as a 256-bit key, the message authentication code (MAC) is calculated across the entire message, generating an intermediate 64-bit MAC. Instead of truncating this value to 32 bits, the 64 bits are divided into two 32-bit blocks, with the most significant 32 bits in the first block and the least significant 32 bits in the second block. These two blocks are then combined, for instance, using an exclusive-OR operation, to produce a 32-bit MAC. This resulting 32-bit MAC is then used for message authentication.
[0043] In some embodiments of the present disclosure, a method is provided for improving the security of message authentication in a communication system while utilizing larger keys, such as a 256-bit key, without impacting the air interface design. In current systems, message authentication is performed by calculating a message authentication code (MAC) over the entire message, and the resulting MAC is typically truncated to fit within the air interface constraints. For instance, a 32-bit MAC is commonly used in both 4G and 5G systems due to the fixed size limit set by the air interface design. However, as security demands increase and the industry moves toward larger key sizes (e.g., 256-bit keys), the expected MAC length would ideally increase to 64 bits to maintain security proportional to the larger key size.
[0044] Some embodiments introduce a method for calculating a MAC using a larger key, such as a 256-bit key, while maintaining compatibility with the 5G air interface. Instead of simply truncating the MAC to fit within the 32-bit constraint, the 64-bit MAC produced from the larger key is split into two 32-bit blocks. Specifically, the most significant 32 bits (e.g., from left to right) of the 64-bit MAC form the first block, and the least significant 32 bits form the second block. The two blocks are then combined using an exclusive-OR operation to produce a final 32-bit MAC.
[0045] Some embodiments ensure that the MAC is not merely truncated, which could compromise the security benefits of using a larger key. Instead, the entire 64-bit MAC is utilized in a way that adheres to the 32-bit limit set by the 5G air interface, thus maintaining both security and efficiency. The combination of the two 32-bit blocks via the exclusive-OR operation preserves critical information from both halves of the MAC, ensuring that the resulting 32-bit MAC is as secure as possible given the constraints.
[0046] After the message authentication calculation produces a temporary 64-bit MAC, the 64-bit value is divided into two 32-bit blocks. The first block contains the most significant 32 bits, and the second block contains the least significant 32 bits. The two blocks are then combined using an exclusive-OR operation to yield the final 32-bit MAC, which is used for message authentication. This process allows for the continued use of the existing 5G air interface design while offering improved security through the use of larger keys. The disclosed method addresses the challenges associated with the migration to 256-bit keys without altering the 5G air interface. This is particularly important because making changes to the air interface would require extensive updates to existing deployments, potentially causing backward compatibility issues and operational disruptions. By splitting and combining the 64-bit MAC in the manner described, the present disclosure ensures that 5G systems can support stronger security mechanisms without impacting the performance or design of the established network infrastructure.
[0047] FIG. 4 illustrates this process, showing the generation of the 64-bit temporary MAC, followed by the application of the exclusive-OR operation to produce the final 32-bit MAC. This embodiment details a method for generating a final 32-bit Message Authentication Code (MAC) while maintaining the security benefits of alarger key size (e.g., 256-bit) without requiring changes to the air interface design in 5G systems. The method allows for the use of a larger key, which enhances the overall security of the system, while producing a MAC that is compatible with existing 5G infrastructure. In a communication system such as 5G, where the air interface is highly optimized for efficiency and reliability, changes to the length of the MAC could impact system performance and compatibility. Therefore, to prevent modifications to the 5G air interface, this embodiment provides a mechanism to generate a 32-bit MAC from a temporary 64-bit MAC, preserving security while adhering to current air interface constraints.
[0048] FIG. 4 illustrates the overall process of generating a 32-bit MAC from a 64-bit temporary MAC. The process begins with a standard message authentication algorithm, which takes the full message and a 256-bit key as inputs. The key is used to perform a cryptographic hash over the message, which results in a 64-bit intermediate value known as the temporary MAC. This temporary MAC comprises two 32-bit blocks: one containing the most significant 32 bits, and the other containing the least significant 32 bits. The process for generating the final 32-bit MAC proceeds as follows: Input Message and Key: A message that requires authentication is received along with a key for the authentication process. The key is typically larger than the previously used 128-bit key, such as a 256-bit key, which provides enhanced security. Temporary MAC Generation: The entire message, along with the 256-bit key, is input into an integrity algorithm. The algorithm processes the message and generates a 64-bit temporary MAC. This temporary MAC is an intermediate cryptographic output that is intended to provide a higher level of security. Splitting the Temporary MAC: The 64-bit temporary MAC is split into two 32-bit blocks. The first block contains the most significant 32 bits (from left to right), and the second block contains the least significant 32 bits (also from left to right). Exclusive-OR Operation: After the temporary MAC is split into two blocks, an exclusive-OR (XOR) operation is applied to combine these blocks. The XOR operation takes the first 32-bit block and XORs it with the second 32-bit block. This process effectively reduces the 64-bit MAC into a final 32-bit value. Final 32-bit MAC: The result of the XOR operation is a 32-bit MAC. This final 32-bit MAC retains the benefits of the larger key (e.g., 256-bit) but fits within the constraints of the existing 5G air interface design, which was optimized for a 32-bit MAC. MAC Transmission: The final 32-bit MAC is then used to authenticate the message as it is transmitted over the air. By maintaining a 32-bit MAC, the system ensures compatibility with existing 5G infrastructure while enhancing the security provided by the larger key size.
[0049] Benefits of the Exclusive-OR Operation: The exclusive-OR operation plays a key role in this embodiment. It effectively compresses the 64-bit temporary MAC into a final 32-bit MAC without losing significant security benefits. The XOR operation is computationally efficient, making it suitable for high- performance communication systems such as 5G. Additionally, because XOR is a standard operation in cryptographic algorithms, it can be implemented without introducing significant processing overhead or complexity. In a practical scenario, consider two devices communicating over a 5 G network where high security is required. The communication between these devices involves sending messages that must be authenticated using a 256-bit key. The devices use the method described in this embodiment to generate a 32-bit MAC from a 64-bit temporary MAC. By using the XOR operation, they produce a 32-bit MAC that complies with the existing 5G air interface. This ensures that the message is authenticated securely without requiring modifications to the infrastructure.
[0050] The splitting of the 64-bit temporary MAC into two blocks and combining them using an XOR operation provides enhanced security compared to truncating the MAC directly to 32 bits. While truncation could lead to higher collision rates (i.e., different messages producing the same MAC), the XOR operation reduces the likelihood of such collisions, making the system more secure. Specifically, the probability of a collision is significantly reduced when using this process compared to direct truncation. Moreover, by using a 256-bit key instead of a 128-bit key, the overall security of the system is enhanced. A larger key size increases the difficulty for attackers to break the cryptographic protections, providing a stronger defense against potential threats. FIG. 4 illustrates an efficient method to generate a 32-bit MAC from a 64-bit temporary MAC, ensuring compatibility with existing 5G air interface designs while improving security. By using an exclusive-OR operation to combine two 32-bit blocks derived from the 64-bit MAC, the method achieves a final 32-bit MAC that can be used for secure message authentication without requiring any modifications to the underlying 5G infrastructure. This approach balances the need for stronger security with the operational constraints of the 5G system.
[0051] In some embodiments of the present disclosure, an initial temporary message authentication code (MAC) is generated in multiple 32-bit blocks. These blocks are then combined recursively using operations such as exclusive-OR to produce a final 32-bit MAC.
[0052] This process, as illustrated in FIG. 5, allows for the generation of a 32-bit MAC from multiple intermediate blocks, maintaining compatibility with the 5G air interface while improving security with larger keys. In this embodiment, a method for generating a 32-bit Message Authentication Code (MAC) from multiple intermediate blocks is described. This method is designed to enhance security by using larger cryptographic keys (e.g., 256-bit) while preserving compatibility with the existing 5G air interface. The solution ensures that the security improvements brought by larger keys do not require modifications to the 5G air interface, which has been optimized for efficiency and reliability using a fixed 32-bit MAC.
[0053] FIG. 5 illustrates the detailed process of generating a final 32-bit MAC from multiple intermediate blocks. The process is similar to the one described for a single temporary MAC in the previous embodiment but introduces multiple 32-bit intermediate blocks for greater flexibility and security. Input Message and Key: A message that requires authentication is received, along with a larger key for authentication, such as a 256-bit key. The use of a larger key provides stronger cryptographic protection compared to the commonly used 128- bit key. Multiple Intermediate MAC Blocks Generation: The entire message and the 256-bit key are input into an integrity protection algorithm. This algorithm processes the message and produces multiple 32-bit intermediate MAC blocks, rather than just a single 64-bit MAC as in the previous embodiment. Each intermediate block represents a portion of the overall message's cryptographic signature. Recursive Exclusive- OR Operation: Once the intermediate 32-bit blocks are generated, they are combined using an exclusive-OR (XOR) operation. In this recursive process, the first two blocks are XORed together to produce a combined block. The result is then XORed with the next block, and this process is repeated until all blocks have been processed. The final result of this recursive XOR operation is a single 32-bit MAC. Final 32-bit MAC: The final 32-bit MAC, which is the result of XORing all intermediate blocks, is used for authenticating the message. This ensures that even though the message is protected by a larger key, the resulting MAC is still compatible with the fixed 32-bit MAC size used in the 5G air interface. MAC Transmission: The 32-bit MAC is then used to authenticatethe message when it is transmitted over the air. Since the 32-bit MAC fits within the constraints of the existing 5G air interface, there is no need to modify the infrastructure while still benefiting from the stronger security provided by the larger key. Recursive XOR Operation: The recursive XOR operation applied to the multiple 32- bit intermediate MAC blocks ensures that the integrity of the message is maintained throughout the process. This operation is computationally efficient and well-suited for use in high-performance communication systems like 5G. Additionally, the XOR operation ensures that all intermediate blocks contribute to the final MAC, making the authentication process more secure than simple truncation.
[0054] Benefits of the Multi-Block MAC Generation: Stronger Security: By generating multiple intermediate blocks from the message and using a larger key, this process offers stronger cryptographic protection compared to traditional 32-bit MAC generation techniques. The use of multiple blocks ensures that more of the message is considered in the authentication process. Compatibility with 5G Air Interface: Despite the increased security provided by the larger key, the final 32-bit MAC is compatible with the existing 5G air interface. This eliminates the need for infrastructure changes, which could otherwise disrupt existing deployments and create backward compatibility issues. Collision Resistance: One of the main challenges in message authentication is avoiding collisions, where two different messages produce the same MAC. By using a recursive XOR operation over multiple blocks, this embodiment reduces the likelihood of collisions, enhancing the overall security of the system.
[0055] Consider two devices communicating over a 5G network. The devices need to authenticate messages using a 256-bit key. Using this embodiment, the integrity protection algorithm generates multiple intermediate 32-bit MAC blocks from the message. These blocks are combined using a recursive XOR operation to produce a final 32-bit MAC, which is used to authenticate the message. The devices benefit from the enhanced security of a larger key without requiring changes to the underlying air interface. Using multiple intermediate blocks for MAC generation, rather than a single block or a direct truncation of the larger MAC, reduces the risk of collisions. This is particularly important in 5G, where message integrity is critical for secure communication. By considering more portions of the message in the authentication process, the system becomes more resistant to cryptographic attacks. Additionally, the use of a recursive XOR operation ensures that the final MAC incorporates all the intermediate blocks, further enhancing security. Even with a larger key size, the system remains efficient and does not introduce significant computational overhead. FIG. 5 illustrates a process for generating a 32-bit MAC from multiple 32-bit intermediate blocks using a recursive XOR operation. This method maintains compatibility with the 5G air interface while leveraging the security benefits of larger keys, such as 256-bit keys. By generating multiple intermediate blocks and combining them in an efficient and secure manner, the system ensures strong message authentication without requiring changes to the 5G infrastructure.
[0056] In some embodiments of the present disclosure, alternative operations, such as addition, subtraction, or other logical or arithmetic operations, may be used either in addition to or as a replacement for the exclusive- OR operation to generate a final 32-bit message authentication code (MAC). This flexibility in operations allows for customization based on security requirements while still maintaining the 32-bit MAC size.
[0057] In another embodiment of the present disclosure, the result of a first message authentication code (MAC) calculation is used as input for a subsequent MAC calculation, as illustrated in FIG. 6. In this embodiment, the intermediate MAC result generated during the first calculation is not necessarily truncated to64 bits, as illustrated in FIG. 4 or FIG. 5, and can be of a larger size. The final MAC, however, is truncated to 32 bits to ensure compatibility with the air interface constraints of the communication system. In this embodiment, the message authentication process involves multiple stages of Message Authentication Code (MAC) calculations, where the result of a first MAC calculation is used as input for a subsequent MAC calculation. This cascading process provides an additional layer of security by introducing further complexity into the MAC generation, ensuring stronger message authentication. The method described maintains compatibility with the 5G air interface while improving security through iterative authentication steps.
[0058] FIG. 6 illustrates the process of cascading MAC calculations, where each subsequent MAC calculation uses the output from the previous MAC calculation as its input. This embodiment ensures that the final MAC result incorporates multiple stages of cryptographic operations, making it significantly more difficult for unauthorized entities to compromise the authentication process. Input Message and Key: A message is received along with a cryptographic key, such as a 256-bit key, to be used for message authentication. The larger key size provides enhanced security compared to traditional 128-bit keys. First MAC Calculation: The entire message and the cryptographic key are input into a standard integrity protection algorithm, which computes an initial MAC. This first MAC serves as an intermediate result and is not truncated or split into smaller blocks as in other embodiments. Input to Subsequent MAC Calculation: The output of the first MAC calculation is used as input for a second MAC calculation. This subsequent calculation takes both the original message and the intermediate MAC from the first step into account when producing its final result. The intermediate MAC may be longer than the traditional 64-bit value and can be processed as a full-length block in the subsequent calculation. Iterative MAC Calculation: In some embodiments, the process can be repeated for additional rounds of MAC calculation. The output of each round is used as input for the next round, further increasing the complexity of the message authentication process. Final 32-bit MAC Output: After the final stage of the iterative MAC calculations, the result is truncated to produce a 32-bit MAC. This final 32-bit MAC is then used to authenticate the message in a manner that is compatible with the 5G air interface, ensuring that no modifications to the underlying infrastructure are required.
[0059] Advantages of Cascading MAC Calculation: Enhanced Security: By using the result of a previous MAC calculation as input for a subsequent calculation, the system introduces an additional layer of cryptographic complexity. This makes it more difficult for attackers to reverse-engineer or guess the final MAC, significantly reducing the risk of unauthorized access or manipulation. Improved Resistance to Collisions: Cascading the MAC calculations reduces the risk of collisions (i.e., two different inputs producing the same MAC). Since each stage of the process introduces new cryptographic operations, the final 32-bit MAC is far less likely to result in a collision compared to simpler MAC generation techniques. Backward Compatibility: Despite the additional complexity of the MAC generation process, the final MAC is still truncated to 32 bits. This ensures that the system remains fully compatible with the existing 5G air interface, avoiding the need for infrastructure changes that could disrupt current deployments. Flexibility: The number of iterations in the MAC calculation process can be adjusted based on the security requirements of the system. For applications requiring higher levels of security, more iterations can be introduced without affecting the 5G air interface or increasing transmission overhead.
[0060] Consider a scenario where two devices in a 5G network are exchanging sensitive data. To ensure the integrity of the communication, the devices use the cascading MAC calculation process described in this embodiment. The first MAC calculation produces an intermediate result based on the entire message, which is then fed into a second MAC calculation. The final MAC, after multiple iterations, is truncated to 32 bits and used to authenticate the message when it is transmitted over the 5G network. By using this approach, the devices achieve stronger security without requiring changes to the air interface or introducing additional transmission overhead. This is particularly important in 5G networks, where efficiency and security must be balanced to support a wide range of applications, from mobile communications to loT devices.
[0061] The cascading MAC calculation process described in this embodiment provides a higher level of security compared to traditional methods. By introducing multiple rounds of MAC generation, the system becomes more resistant to cryptographic attacks, such as brute-force attempts to reverse-engineer the MAC. Each stage of the calculation adds complexity, making it more difficult for attackers to identify patterns or vulnerabilities in the system. Additionally, the use of a final 32-bit MAC ensures that the system remains compatible with the existing 5G air interface, which is optimized for both security and efficiency. This compatibility is critical for maintaining the integrity of current deployments while allowing for the adoption of stronger cryptographic keys, such as 256-bit keys.
[0062] FIG. 6 illustrates the cascading MAC calculation process, where the result of each MAC calculation is used as input for the next calculation. This method ensures stronger message authentication by incorporating multiple stages of cryptographic operations, while maintaining compatibility with the 5G air interface. By truncating the final result to 32 bits, the system achieves enhanced security without requiring infrastructure changes or increasing transmission overhead. This embodiment is particularly well-suited for applications that require both high levels of security and efficient communication in 5G networks.
[0063] Some embodiments of the present disclosure provide a method for supporting the migration of 5G systems from 128-bit to 256-bit security, enabling operators to strengthen security without altering the 5G air interface. As migration to 256-bit security is inevitable to ensure robust encryption and integrity protection, it is crucial to implement this enhancement without disrupting the existing 5G infrastructure. Any changes to the 5G air interface could negatively impact current deployments, creating backward compatibility and interoperability challenges. Therefore, the disclosed method allows for improved security through the use of larger keys (e.g., 256-bit) while maintaining compatibility with the existing 5G air interface, ensuring that operators can meet evolving security demands without impacting the performance or design of the established network.
[0064] In some embodiments, with the disclosed solution, the likelihood of collision (i.e., the process of identifying another input set that produces the same Message Authentication Code (MAC)) is significantly reduced to between 2192and 2224, offering a notable improvement over the previous collision rate of 2224. This reduction enhances the overall security of the system, ensuring stronger message authentication and protection against potential attacks.
[0065] An alternative approach is to perform a straightforward truncation of the MAC calculation to 32 bits without any further processing. While this would yield a 32-bit MAC, it fails to achieve the enhanced security that comes from using a longer-length MAC. This method does not provide the added protection and strength that a more complex MAC processing technique offers. Specifically, truncating the MAC directly to 32 bits doesnot leverage the additional information provided by the 256-bit key. This would result in a loss of security strength, as the MAC would be more susceptible to collisions — situations where different input messages generate the same MAC, thus weakening the integrity protection. The direct truncation method does not mitigate this risk, which can lead to vulnerabilities in the authentication process, especially as attack techniques become more sophisticated. In contrast, the method disclosed in the present embodiment, which involves splitting the 64-bit MAC into two blocks and combining them using an exclusive-OR operation, ensures that the full potential of the larger key is utilized. By processing the MAC in this manner, the system gains the added protection of a longer key without altering the 5G air interface, significantly reducing the probability of collisions compared to a simple truncation.
[0066] Another alternative is to increase the MAC size to 64 bits, but this approach necessitates modifications to the air interface, which could lead to compatibility issues and impact the existing 5G infrastructure. Another alternative method to improve security is to increase the message authentication code (MAC) size from 32 bits to 64 bits, aligning it with the expected size for a 256-bit key. This approach would theoretically provide a stronger level of security by directly addressing the limitations of a smaller MAC and reducing the likelihood of collisions — instances where different messages produce the same MAC. By expanding the MAC size to 64 bits, the security integrity of the communication could be significantly enhanced, as it would be more difficult for attackers to generate identical authentication codes with different inputs. However, increasing the MAC size to 64 bits requires modifications to the 5G air interface, as the current design is built to accommodate a 32-bit MAC. The air interface in 5 G is a crucial part of the system's overall architecture, designed to optimize both efficiency and reliability. Expanding the MAC size would necessitate an overhaul of the air interface, leading to significant changes in how data is transmitted and processed across the network. These modifications would introduce compatibility challenges, as existing devices and infrastructure are not configured to handle a 64-bit MAC. Such a change could disrupt backward compatibility, requiring operators to make costly updates to their network infrastructure and potentially leading to interoperability issues with devices that rely on the current 32- bit MAC configuration. Furthermore, introducing a larger MAC may reduce the available payload for user data within each packet, as the increased authentication code would consume more of the fixed packet size. Therefore, while increasing the MAC size to 64 bits would improve security, it poses significant challenges for maintaining the stability and performance of the 5G air interface. This approach could negatively impact existing deployments, making it less desirable as a practical solution compared to other methods that preserve the current air interface design.
[0067] In summary, some embodiments of the present disclosure provide a method to enhance the security of message authentication by employing larger keys (e.g., 256-bit) while maintaining the integrity of the existing 5G air interface design. This approach enables the deployment of stronger security measures without requiring modifications to the 5G air interface, which is crucial for ensuring efficiency, reliability, and backward compatibility with current network infrastructures. By addressing the need for improved security without disrupting the underlying communication architecture, the present disclosure offers a practical and effective solution for migrating from 128-bit to 256-bit security in 5G systems.
[0068] Commercial interests for some embodiments are as follows. 1. Solve issues in the prior art. 2. Solve other issues. 3. Preserve backward compatibility and interoperability. 4. Enhance security. 5. Provide a goodcommunication performance. 6. Provide high reliability. 7. Some embodiments of the present disclosure are used by chipset vendors, video system development vendors, automakers including cars, trains, trucks, buses, bicycles, moto-bikes, helmets, and etc., drones (unmanned aerial vehicles), smartphone makers, communication devices for public safety use, AR / VR / MR device maker for example gaming, conference / seminar, education purposes. Some embodiments of the present disclosure are a combination of “techniques / processes” that can be adopted in video standards to create an end product. Some embodiments of the present disclosure propose technical mechanisms. The at least one proposed solution, method, system, and apparatus of some embodiments of the present disclosure may be used for current and / or new / future standards regarding communication systems such as an AIoT device, a node (UE / BS), and / or a communication system. Compatible products follow at least one proposed solution, method, system, and apparatus of some embodiments of the present disclosure. The proposed solution, method, system, and apparatus are widely used in an AIoT device, a node (UE / BS), and / or a communication system. With the implementation of the at least one proposed solution, method, system, and apparatus of some embodiments of the present disclosure, at least one modification to communication methods and apparatus are considered for standardizing.
[0069] FIG. 7 is an example of a computing device 1200 according to an embodiment of the present disclosure. Any suitable computing device can be used for performing the operations described herein. For example, FIG. 7 illustrates an example of the computing device 1200 that can implement apparatuses and methods of the above embodiments of FIGs. 1 to 6, using any suitably configured hardware and / or software. In some embodiments, the computing device 1200 can include a processor 1412 that is communicatively coupled to a memory 1414 and that executes computer-executable program code and / or accesses information stored in the memory 1414. The processor 1412 may include a microprocessor, an application-specific integrated circuit (“ASIC”), a state machine, or other processing device. The processor 1412 can include any of a number of processing devices, including one. Such a processor can include or may be in communication with a computer-readable medium storing instructions that, when executed by the processor 1412, cause the processor to perform the operations described herein.
[0070] The memory 1414 can include any suitable non-transitory computer-readable medium. The computer- readable medium can include any electronic, optical, magnetic, or other storage device capable of providing a processor with computer-readable instructions or other program code. Non-limiting examples of a computer- readable medium include a magnetic disk, a memory chip, a read-only memory (ROM), a random access memory (RAM), an application specific integrated circuit (ASIC), a configured processor, optical storage, magnetic tape or other magnetic storage, or any other medium from which a computer processor can read instructions. The instructions may include processor-specific instructions generated by a compiler and / or an interpreter from code written in any suitable computer-programming language, including, for example, C, C++, C#, visual basic, java, python, perl, javascript, and actionscript.
[0071] The computing device 1200 can also include a bus 1416. The bus 1416 can communicatively couple one or more components of the computing device 1200. The computing device 1200 can also include a number of external or internal devices such as input or output devices. For example, the computing device 1200 is illustrated with an input / output (“I / O”) interface 1418 that can receive input from one or more input devices1420 or provide output to one or more output devices 1422. The one or more input devices 1420 and one or more output devices 1422 can be communicatively coupled to the I / O interface 1418. The communicative coupling can be implemented via any suitable manner (e.g., a connection via a printed circuit board, connection via a cable, communication via wireless transmissions, etc.). Non-limiting examples of input devices 1420 include a touch screen (e g., one or more cameras for imaging a touch area or pressure sensors for detecting pressure changes caused by a touch), a mouse, a keyboard, or any other device that can be used to generate input events in response to physical actions by a user of a computing device. Non-limiting examples of output devices 1422 include a liquid crystal display (LCD) screen, an external monitor, a speaker, or any other device that can be used to display or otherwise present outputs generated by a computing device.
[0072] The computing device 1200 can execute program code that configures the processor 1412 to perform one or more of the operations described above with respect to methods of the above embodiments of FIGs. 1 to 6. The program code may be resident in the memory 1414 or any suitable computer-readable medium and may be executed by the processor 1412 or any other suitable processor.
[0073] The computing device 1200 can also include at least one network interface device 1424. The network interface device 1424 can include any device or group of devices suitable for establishing a wired or wireless data connection to one or more data networks 1428. Non limiting examples of the network interface device 1424 include an Ethernet network adapter, a modem, and / or the like. The computing device 1200 can transmit messages as electronic or optical signals via the network interface device 1424.
[0074] FIG. 8 is a block diagram of an example of a communication system 1500 according to an embodiment of the present disclosure. Embodiments described herein may be implemented into the communication system 1500 using any suitably configured hardware and / or software. FIG. 8 illustrates the communication system 1500 including a radio frequency (RF) circuitry 1510, a baseband circuitry 1520, an application circuitry 1530, a memory / storage 1540, a display 1550, a camera 1560, a sensor 1570, and an input / output (I / O) interface 1580, coupled with each other at least as illustrated.
[0075] The application circuitry 1530 may include a circuitry such as, but not limited to, one or more singlecore or multi-core processors. The processors may include any combination of general-purpose processors and dedicated processors, such as graphics processors, application processors. The processors may be coupled with the memory / storage and configured to execute instructions stored in the memory / storage to enable various applications and / or operating systems running on the system. The communication system 1500 can execute program code that configures the application circuitry 1530 to perform one or more of the operations described above with respect to methods of the above embodiments of FIGs. 1 to 6. The program code may be resident in the application circuitry 1530 or any suitable computer-readable medium and may be executed by the application circuitry 1530 or any other suitable processor.
[0076] The baseband circuitry 1520 may include circuitry such as, but not limited to, one or more single-core or multi-core processors. The processors may include a baseband processor. The baseband circuitry may handle various radio control functions that may enable communication with one or more radio networks via the RF circuitry. The radio control functions may include, but are not limited to, signal modulation, encoding, decoding, radio frequency shifting, etc. In some embodiments, the baseband circuitry may provide for communicationcompatible with one or more radio technologies. For example, in some embodiments, the baseband circuitry may support communication with an evolved universal terrestrial radio access network (EUTRAN) and / or other wireless metropolitan area networks (WMAN), a wireless local area network (WLAN), a wireless personal area network (WPAN). Embodiments in which the baseband circuitry is configured to support radio communications of more than one wireless protocol may be referred to as multi-mode baseband circuitry.
[0077] In various embodiments, the baseband circuitry 1520 may include circuitry to operate with signals that are not strictly considered as being in a baseband frequency. For example, in some embodiments, baseband circuitry may include circuitry to operate with signals having an intermediate frequency, which is between a baseband frequency and a radio frequency. The RF circuitry 1510 may enable communication with wireless networks using modulated electromagnetic radiation through a non-solid medium. In various embodiments, the RF circuitry may include switches, filters, amplifiers, etc. to facilitate the communication with the wireless network. In various embodiments, the RF circuitry 1510 may include circuitry to operate with signals that are not strictly considered as being in a radio frequency. For example, in some embodiments, RF circuitry may include circuitry to operate with signals having an intermediate frequency, which is between a baseband frequency and a radio frequency.
[0078] In various embodiments, the transmitter circuitry, control circuitry, or receiver circuitry discussed above with respect to apparatuses and methods of the above embodiments of FIGs. 1 to 6 may be embodied in whole or in part in one or more of the RF circuitry, the baseband circuitry, and / or the application circuitry. As used herein, “circuitry” may refer to, be part of, or include an application specific integrated circuit (ASIC), an electronic circuit, a processor (shared, dedicated, or group), and / or a memory (shared, dedicated, or group) that execute one or more software or firmware programs, a combinational logic circuit, and / or other suitable hardware components that provide the described functionality. In some embodiments, the electronic device circuitry may be implemented in, or functions associated with the circuitry may be implemented by, one or more software or firmware modules. In some embodiments, some or all of the constituent components of the baseband circuitry, the application circuitry, and / or the memory / storage may be implemented together on a system on a chip (SOC). The memory / storage 1540 may be used to load and store data and / or instructions, for example, for system. The memory / storage for one embodiment may include any combination of suitable volatile memory, such as dynamic random access memory (DRAM)), and / or non-volatile memory, such as flash memory.
[0079] In various embodiments, the I / O interface 1580 may include one or more user interfaces designed to enable user interaction with the system and / or peripheral component interfaces designed to enable peripheral component interaction with the system. User interfaces may include, but are not limited to a physical keyboard or keypad, a touchpad, a speaker, a microphone, etc. Peripheral component interfaces may include, but are not limited to, a non-volatile memory port, a universal serial bus (USB) port, an audio jack, and a power supply interface. In various embodiments, the sensor 1570 may include one or more sensing devices to determine environmental conditions and / or location information related to the system. In some embodiments, the sensors may include, but are not limited to, a gyro sensor, an accelerometer, a proximity sensor, an ambient light sensor, and a positioning unit. The positioning unit may also be part of, or interact with, the baseband circuitry and / orRF circuitry to communicate with components of a positioning network, e.g., a global positioning system (GPS) satellite.
[0080] In various embodiments, the display 1550 may include a display, such as a liquid crystal display and a touch screen display. In various embodiments, the communication system 1500 may be a mobile computing device such as, but not limited to, a laptop computing device, a tablet computing device, a netbook, an ultrabook, a smartphone, an AR / VR glasses, etc. In various embodiments, system may have more or less components, and / or different architectures. Where appropriate, methods described herein may be implemented as a computer program. The computer program may be stored on a storage medium, such as a non-transitory storage medium.
[0081] A person having ordinary skill in the art understands that each of the units, algorithm, and steps described and disclosed in the embodiments of the present disclosure are realized using electronic hardware or combinations of software for computers and electronic hardware. Whether the functions run in hardware or software depends on the condition of application and design requirement for a technical plan. A person having ordinary skill in the art can use different ways to realize the function for each specific application while such realizations should not go beyond the scope of the present disclosure. It is understood by a person having ordinary skill in the art that he / she can refer to the working processes of the system, device, and unit in the above-mentioned embodiment since the working processes of the above-mentioned system, device, and unit are basically the same. For easy description and simplicity, these working processes will not be detailed.
[0082] It is understood that the disclosed system, device, and method in the embodiments of the present disclosure can be realized with other ways. The above-mentioned embodiments are exemplary only. The division of the units is merely based on logical functions while other divisions exist in realization. It is possible that a plurality of units or components are combined or integrated in another system. It is also possible that some characteristics are omitted or skipped. On the other hand, the displayed or discussed mutual coupling, direct coupling, or communicative coupling operate through some ports, devices, or units whether indirectly or communicatively by ways of electrical, mechanical, or other kinds of forms.
[0083] The units as separating components for explanation are or are not physically separated. The units for display are or are not physical units, that is, located in one place or distributed on a plurality of network units. Some or all of the units are used according to the purposes of the embodiments. Moreover, each of the functional units in each of the embodiments can be integrated in one processing unit, physically independent, or integrated in one processing unit with two or more than two units.
[0084] If the software function unit is realized and used and sold as a product, it can be stored in a readable storage medium in a computer. Based on this understanding, the technical plan proposed by the present disclosure can be essentially or partially realized as the form of a software product. Or, one part of the technical plan beneficial to the conventional technology can be realized as the form of a software product. The software product in the computer is stored in a storage medium, including a plurality of commands for a computational device (such as a personal computer, a server, or a network device) to run all or some of the steps disclosed by the embodiments of the present disclosure. The storage medium includes a USB disk, a mobile hard disk, a readonly memory (ROM), a random access memory (RAM), a floppy disk, or other kinds of media capable of storing program codes.
[0085] While the present disclosure has been described in connection with what is considered the most practical and preferred embodiments, it is understood that the present disclosure is not limited to the disclosed embodiments but is intended to cover various arrangements made without departing from the scope of the broadest interpretation of the appended claims.
Claims
WHAT IS CLAIMED IS:
1. A method for authenticating messages in a communication system, comprising: generating, by a processor, an intermediate message authentication code (MAC) for a message using a key; processing, by the processor, the intermediate MAC by combining portions of the intermediate MAC using at least one combining operation; and producing, by the processor, a final MAC based on the intermediate MAC for use in authenticating the message, wherein the size of the final MAC is less than the size of the intermediate MAC.
2. The method of claim 1, wherein generating, by the processor, the intermediate MAC for the message using the key comprises: receiving, by a transceiver, the message and the key for authentication; and calculating, by the processor, the intermediate MAC over the message using the key.
3. The method of claim 1, wherein the key is a 256-bit key.
4. The method of claim 1, wherein processing, by the processor, the intermediate MAC by combining the portions of the intermediate MAC using the at least one combining operation comprises: splitting the intermediate MAC into at least two blocks; and combining the at least two blocks using the at least one combining operation to produce the final MAC.
5. The method of claim 4, wherein the intermediate MAC is a value of 64 bits, and the final MAC is a value of 32 bits.
6. The method of claim 5, wherein the at least two blocks comprise a most significant 32 bits form a first block and a least significant 32 bits form a second block.
7. The method of claim 5, wherein the at least one combining operation comprises an exclusive-OR operation or a recursive operation.
8. The method of claim 7, wherein the exclusive-OR operation or the recursive operation is performed until a single 32-bit block is produced as the final MAC.
9. The method of claim 5, wherein the intermediate MAC is calculated over multiple blocks of 32 bits, and the multiple blocks are recursively combined using an exclusive-OR operation to produce the final MAC of 32 bits.
10. The method of claim 5, wherein a result of a first MAC calculation is used as input to a second MAC calculation, and the final MAC is truncated to 32 bits.
11. The method of claim 5, wherein the final MAC of 32 bits is used for message authentication without truncating the intermediate MAC of 64 bits.
12. The method of claim 5, wherein the final MAC of 32 bits is applied for secure message authentication while maintaining an original air interface of the communication system.
13. A communication system, comprising: a memory; a transceiver; and a processor coupled to the memory and the transceiver; wherein the processor is configured to perform: generating an intermediate message authentication code (MAC) for a message using a key; processing the intermediate MAC by combining portions of the intermediate MAC using at least one combining operation; and producing a final MAC based on the intermediate MAC for use in authenticating the message, wherein the size of the final MAC is less than the size of the intermediate MAC.
14. The communication system of claim 13, wherein the transceiver is configured to receive the message and the key for authentication, and the processor is configured to calculate the intermediate MAC over the message using the key.
15. The communication system of claim 13, wherein the key is a 256-bit key.
16. The communication system of claim 13, wherein the processor is configured to split the intermediate MAC into at least two blocks and combine the at least two blocks using the at least one combining operation to produce the final MAC.
17. The communication system of claim 16, wherein the intermediate MAC is a value of 64 bits, and the final MAC is a value of 32 bits.
18. The communication system of claim 17, wherein the at least two blocks comprise a most significant 32 bits form a first block and a least significant 32 bits form a second block.
19. The communication system of claim 17, wherein the at least one combining operation comprises an exclusive-OR operation or a recursive operation.
20. The communication system of claim 19, wherein the exclusive-OR operation or the recursive operation is performed until a single 32-bit block is produced as the final MAC.
21. The communication system of claim 17, wherein the intermediate MAC is calculated over multiple blocks of 32 bits, and the multiple blocks are recursively combined using an exclusive-OR operation to produce the final MAC of 32 bits.
22. The communication system of claim 17, wherein a result of a first MAC calculation is used as input to a second MAC calculation, and the final MAC is truncated to 32 bits.
23. The communication system of claim 17, wherein the final MAC of 32 bits is used for message authentication without truncating the intermediate MAC of 64 bits.
24. The communication system of claim 17, wherein the final MAC of 32 bits is applied for secure message authentication while maintaining an original air interface of the communication system.
25. A non-transitory machine-readable storage medium having stored thereon instructions that, when executed by a computer, cause the computer to perform the method of any one of claims 1 to 12.
26. A chip, comprising: a processor, configured to call and run a computer program stored in a memory, to cause a device in which the chip is installed to execute the method of any one of claims 1 to 12.
27. A computer readable storage medium, in which a computer program is stored, wherein the computer program causes a computer to execute the method of any one of claims 1 to 12.
28. A computer program product, comprising a computer program, wherein the computer program causes a computer to execute the method of any one of claims 1 to 12.
29. A computer program, wherein the computer program causes a computer to execute the method of any one of claims 1 to 12.
Citation Information
Patent Citations
Message authentication system and method
US20030041242A1
Methods and apparatus for providing a message authentication code using a pipeline
US20060245588A1
Paralleizeable integrity-aware encryption technique
US20130287205A1
Methods and devices for providing message authentication code suitable for short messages
US20220006644A1