Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

257 results about "Message authentication code" patented technology

In cryptography, a message authentication code (MAC), sometimes known as a tag, is a short piece of information used to authenticate a message—in other words, to confirm that the message came from the stated sender (its authenticity) and has not been changed. The MAC value protects both a message's data integrity as well as its authenticity, by allowing verifiers (who also possess the secret key) to detect any changes to the message content.

Method and system for mutual authentication and key agreement between vehicles

The invention discloses an inter-vehicle bidirectional authentication and key agreement method and system, and relates to the technical field of Internet of Vehicles information security, and the method comprises the steps: a registration stage: a vehicle and a trusted mechanism derive a temporary session key based on ECDH and HKDF, and achieve the secure interaction; the trusted institution generates a basic identity label, a part of private key, a signature and a basic certificate for the vehicle, and encrypts and transmits the basic identity label, the part of private key, the signature and the basic certificate to the vehicle; the vehicle generates a hardware fingerprint and extracts a secret key by using the embedded PUF, and part of the private key is encrypted and then is locally and safely stored with the basic certificate; in the authentication stage, the two communication parties dynamically recover part of private keys through PUF, and generate dynamic pseudo names, temporary ECDH key pairs and cryptographic evidence; and calculating a cross item and a binding item by interaction parameters of the two parties, negotiating a unique session key, and completing bidirectional confirmation through a message authentication code. According to the method and the device, efficient, physical attack-resistant and privacy-protecting V2V security mutual recognition and key agreement are realized in a resource-limited vehicle-mounted environment.
Owner:CHANGZHOU INST OF TECH

Data transmission method and system for meteorological satellite communication system

The invention discloses a data transmission method for a meteorological satellite communication system, and relates to the technical field of data transmission. Receiving original meteorological data, performing security level analysis on the original meteorological data, determining a security level, and processing the key change parameter by using the master key based on a preset key derivation function to obtain an encrypted session key; performing encryption processing on the original meteorological data based on the encrypted session key to obtain first ciphertext data; combining the key change parameter with the communication identification information to obtain first associated data; performing message authentication code calculation on the first associated data and the first ciphertext data to obtain a message authentication code; assembling the security level, the first associated data, the first ciphertext data and the message authentication code based on a preset format to obtain a target data frame; and sending the target data frame to a meteorological data center so as to decrypt the target data frame to obtain original meteorological data. By implementing the technical scheme provided by the invention, the security in the transmission process is ensured.
Owner:ZHONGMAN TECH (BEIJING) CO LTD

Anti-quantum message authentication code construction method and system adopting adjustable block cipher

The invention belongs to the field of passwords, and discloses an anti-quantum message authentication code construction method and system adopting an adjustable block cipher. The MAC generation method comprises the steps that two communication parties share a key value K generated by a key generation algorithm, the label length tau = Tag is agreed, the tau is limited to be smaller than or equal to n, and n represents the packet length; and taking the key K, the message M and the unique value N as input to generate a tau-bit message authentication code Tag. Furthermore, the MAC verification method verifies the generated message authentication code, and judges whether the message is correct or not and whether the message is accepted or not. According to the method, the adjustment handle value is an encryption result of a unique value initially, and then the adjustment handle is updated by using a function h when the adjustable block cipher is called every time. The method has the quantum attack resisting capability, and compared with the existing known MAC scheme with the quantum attack resisting capability, the required storage is small under the condition of providing the same quantum security intensity.
Owner:INST OF SOFTWARE - CHINESE ACAD OF SCI +1

System and method for secure authentication of contact-free card

A security authentication system is provided that includes a server including a processor and a memory. The server is configured to: generate an authentication challenge; storing the authentication challenge in a memory; transmitting the authentication challenge to the user device; generating a session key based on the master key; storing the session key in a memory; receiving, from the user equipment, an encrypted message authentication code (MAC) password incorporating an authentication challenge; decrypting the encrypted MAC password using one or more cryptographic algorithms and the session key; and validating the authentication challenge received from the user device.
Owner:CAPITAL ONE SERVICES LLC

Multi-part transaction integrity protection and encryption

Multi-part transaction integrity protection and encryption are disclosed, including generating, by a first device, a first message authentication code (MAC) for authenticating a plurality of packets of a transaction, the plurality of packets including at least a first packet received over a data link from a second device and a second packet generated by the first device in response to receiving the first packet, the first MAC is generated using data included in the plurality of packets; and transmitting, by the first device, the second packet and the first MAC over the data link to the second device.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Programmable electronic detonator safety communication system and safety communication method

The invention provides a programmable electronic detonator safety communication system and a safety communication method, and relates to the technical field of electronic communication safety. The programmable electronic detonator safety communication system comprises a detonation controller and at least one electronic detonator, wherein the electronic detonator is internally provided with a secure communication module, and the secure communication module is configured to generate a unique physical identity label of the electronic detonator based on a physical unclonable function response value generated by the SRAM PUF unit; receiving an encryption instruction frame from the detonation controller for decryption and authentication; sending an encrypted response frame to a detonation controller; the detonation controller is configured to perform bidirectional identity authentication with each electronic detonator and negotiate or derive a session key; constructing a communication frame containing anti-replay parameters and instruction data, encrypting the communication frame by using the session key and generating a message authentication code; and verifying the integrity and freshness of the response frame of the electronic detonator. According to the method, the safety intensity can be ensured, and hardware guarantee is provided for maintaining millisecond-level instruction response.
Owner:JIANGHAN UNIVERSITY +1

Dynamic Integrity and Data Encryption (IDE) Aggregation Size

To reduce bandwidth overheads associated with a message authentication code (MAC), aggregation is useful. To ensure there is no latency impact, something more than aggregation is needed. Integrity and Data Encryption (IDE) securing transaction layer packets (TLPs) can be used in a dynamic manner whereby before aggregating a new packet to the IDE TLP, a determination is made regarding whether the packet contains user data so that the packets with user data can be sent immediately rather than wanting for more packets to aggregate. On the receiving side, execution of the packet can occur before completing an integrity check that occurs in IDE TLP transfers to reduce latency.
Owner:SANDISK TECHNOLOGIES LLC

Secure message system and method of the same

A computer-implemented method that causes data processing hardware to perform operations including generating, at a first device, a message having a header including a message type and a service ID, receiving, at a second device, the message including the header and a key serial number (KSN) of the first device, determining, based on the header, the message type of the message, verifying, at a high performance crypto accelerator (HPCA) of the second device, a message authentication code (MAC) of the message based on the determined message type being the service event, obtaining, based on the KSN from the message, a key slot from a message authentication code table (MACT), identifying, based on the key slot, a key associated with the key slot obtained from the MACT, the key including at least one of a primary key and a secondary key, and verifying, using the key and the key slot obtained from the MACT, the MAC.
Owner:GM GLOBAL TECHNOLOGY OPERATIONS LLC

An encryption communication system applied to new energy vehicles and charging piles

This invention relates to the field of new energy vehicle technology and discloses an encrypted communication system for communication between new energy vehicles and charging piles. The system includes: a vehicle gateway, used to generate an initial vehicle-to-charging pile communication key and a message authentication code, and to send the initial vehicle-to-charging pile communication key and the message authentication code to both communicating parties; and, upon receiving a message indicating successful communication between the battery management system and the charging pile, updating the current vehicle-to-charging pile communication key and regenerating the message authentication code to send to both communicating parties; the battery management system and the charging pile, i.e., the two communicating parties, verify each received message authentication code based on the code. If the verification is successful, they initiate the current round of communication using the current vehicle-to-charging pile communication key; after each message transmission, the current vehicle-to-charging pile communication key is updated, and a message indicating successful communication for the current round is sent to the vehicle gateway. This invention updates the key multiple times during vehicle-to-charging pile communication and verifies it in each round of communication, thus improving communication security.
Owner:CHERY NEW ENERGY AUTOMOBILE TECH CO LTD

Method and system for securely selecting applications

The disclosure relates to a method and system for securely selecting applications using application identifiers. The method for securely selecting applications using Application Identifiers (AIDs), wherein application-specific static keys are utilized to encrypt AIDs, ensuring privacy and preventing inference about the selected application. The method includes generating a random number to embed in the encryption for uniqueness and replay attack prevention, authenticating the selection command with a Message Authentication Code (MAC) for integrity, and transmitting the encrypted selection command to a recipient device for further processing.
Owner:ASSA ABLOY AB

Message authentication code generation method, message authentication code verification method and computer readable storage medium

The invention relates to a message authentication code generation method, a message authentication code verification method and a computer readable storage medium. The generation method comprises the steps of generating a public parameter, generating a key by using the public parameter, and finally generating an authentication code of a to-be-transmitted message according to the key. The method specifically comprises the following steps: randomly selecting a positive integer R from {1, 2,..., p-1}; randomly selecting any bit string E from the bit string set N; randomly generating a bit string V with the length of v, and inputting the message to be transmitted and the bit string V into the hash function hash to obtain a bit string A; calculating to obtain B; and respectively converting R and B into bit strings Rb and Bb, connecting Rb, Bb and V to form a bit string, converting the bit string into a decimal number (I) 10, and inputting (I) 10 into a permutation function per to obtain a message authentication code. The method can resist quantum computer attacks and has higher safety and reliability.
Owner:ZHEJIANG WANLI UNIV

DEFEATING DELAY ATTACKS IN A COMMUNICATION NETWORK

A communication network for mitigating delay attacks comprises one or more sender nodes that communicate electronically with one or more receiver nodes. The one or more receiver nodes execute instructions to periodically send a challenge message to a sender node. In response to the acceptance of the challenge message and the determination that data is to be sent to the receiver node, the sender node sends a function message to the receiver node.In response to the finding that an updated freshness value is more recent than a current freshness value associated with the sender node, that a sender message authentication code is correct and consistent across at least one previous challenge message, and that the response to the challenge message from the receiver node is correct, the receiver node updates the current freshness value to match the updated freshness value and accepts the function message.
Owner:GM GLOBAL TECHNOLOGY OPERATIONS LLC

A method and apparatus for executing a round function

A method performed by a processing unit for determining a round function. A first share and a second share are generated using a current state and an input string. One or more linear operations are separately applied to the first share and the second share. A plurality of functions (which include a masking value from a paired S-box) are further applied to shares of each value input to a non-linear S-box operation to generate S-box output shares. The S-box output shares are then compressed to generate shares of the processed state. The round function may be a part of a sponge algorithm and the round function forms at least part of an absorbing phase. The method may be used to generate one of: a salted hash, a message authentication code, a pseudorandom number or a cipher. The round function may be one of: Keccak , PRINCE, Midori, LED, or SKINNY. The one or more linear operations may be θ, ρ, and π, and the S-box operation may be ꭓ. It is claimed that the first register 21 may be removed without loss of security as the compressor 28 won’t leak information in subsequent round transformations.
Owner:PQSHIELD LTD

Automobile external equipment access authentication method and system, equipment and medium

The invention provides an automobile external equipment access authentication method and system, equipment and a medium, and belongs to the technical field of automobile safety communication, and the method comprises the steps: obtaining a second identity authentication message sent by a T-BOX; if the T-BOX self-increasing serial number is greater than or equal to the gateway self-increasing serial number, the first-level authentication succeeds, otherwise, the first-level authentication fails; when the first-level authentication is successful, judging whether the T-BOX unique identity identifier and the identity information of the remote vehicle control instruction APP terminal in the first identity authentication message are consistent with the T-BOX unique identity identifier and the identity information of the remote vehicle control instruction APP terminal stored in the gateway, if so, determining that the second-level authentication is successful, and otherwise, determining that the second-level authentication fails; and when the second-level authentication succeeds, calculating the first identity authentication message and the T-BOX self-increasing serial number in the received second identity authentication message through a preset message authentication code algorithm to generate a second message authentication code, comparing the second message authentication code with the first message authentication code in the second identity authentication message, if the second message authentication code is consistent with the first message authentication code in the second identity authentication message, determining that the third-level authentication succeeds, otherwise, determining that the third-level authentication fails.
Owner:DONGFENG MOTOR GRP

Derived unique key per hash encapsulated encrypted transaction (DUKPHEET)

The arrangements disclosed herein relate to generating, by a first server, a first seed using a Hash-Based Message Authentication Code (HMAC) based at least in part on a Hash Key (HK), providing, by the first server to each of a first device and a second device, the first seed, providing, by a second server to each of the first device or the second device, a second seed. The second seed is based at least in part on a stream of photons. Each of the first device or the second device generates a Derived Key (DK) based at least in part on the first seed and the second seed. Each of the first device or the second device generates a first key based at least in part on the DK and a first random number generated by a Quantum Random Number Generator (QRNG). The first device encrypts first data using the first key to obtain first ciphertext and provides the first ciphertext to the second device. The second device derives the first key and decrypts the first ciphertext using the first key.
Owner:WELLS FARGO BANK NA

Message verification for vehicle ecus

A computer includes a processor and a memory, and the memory stores instructions executable by the processor to nondeterministically select a message from a plurality of messages, the messages including respective message authentication codes; set a current trust status by verifying the message authentication code from the selected message; and forward the selected message to a recipient in response to a previous trust status being trusted.
Owner:FORD GLOBAL TECH LLC

Secure RDMA for low-latency real-time applications

A vehicle network communications system including a sending processor for generating a data in response to a first vehicle control algorithm, a sending network interface configured to receive the data from the sending processor, to generate a message authentication code in response to the data, to generate a communications packet for transmission according to a remote direct memory access network protocol, wherein the message authentication code is appended to the communications packet, and to transmit the communications packet via a communications network, a receiving network interface configured to receive the communications packet from the sending network interface via the communications network, to decode the message authentication code to extract the data, and to couple the data the memory, and a memory configured to store the data for use by a receiving processor performing a second vehicle control algorithm.
Owner:GM GLOBAL TECHNOLOGY OPERATIONS LLC

Cryptographic key update system for updating arbitrary length cryptographic keys

A method for updating arbitrary length cryptographic keys having a bit length greater than 256 bits by a cryptographic key update system includes transmitting, by a sender, a first transmission to one or more controllers that are part of a vehicle and transmitting, by the sender, a second transmission to the one or more controllers, where the second transmission is a symmetric key encryption under a key encryption key of a concatenation of a plurality of parameters and a new cryptographic key. The sender derives the key encryption key by transforming an authentication key and a bit string of constant values based on an N-bit compression function. The method includes transmitting, by the sender, a third transmission to the one or more controllers that is an N-bit message authentication code under a first message authentication code (MAC) key of a concatenation of the first transmission and the second transmission.
Owner:GM GLOBAL TECHNOLOGY OPERATIONS LLC

Instruction to accelerate hash-based message authentication code processing

An instruction is executed to generate an authentication code. Executing the instruction includes performing a plurality of operations of the instruction to generate the authentication code. The plurality of operations includes performing a sequence of hash operations on a message to generate an intermediate message digest, and performing an outer-key padding and hashing operation using the cryptographic key to generate another output chaining value to be used in generating a final output message digest based on a final input message digest produced using the intermediate message digest. The final output message digest being a resulting authentication code. The performing the sequence of hash operations and the outer-key padding and hashing operation are performed as part of a single invocation of the instruction.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Method, device and electronic equipment for identity authentication

The application discloses a kind of identity authentication method, device and electronic equipment.Therein, the method includes: sending key request to secure chip, receiving the first response information returned by secure chip, wherein the first response information at least includes: key;According to application identification, the session identification corresponding to this session is created, and the request for obtaining authentication key is initiated to quantum key management system;Determine the authentication key returned by quantum key management system, at least encrypt login authentication credential according to authentication key to generate login information ciphertext, and generate the message authentication code corresponding to login information ciphertext;Send login information ciphertext, message authentication code and session identification to identity authentication server;Receive the second response information returned by identity authentication server.The application solves the technical problem that the security is poor and data leakage is easy to cause in the related art based on the security verification mode of username and password.
Owner:CHINA TELECOM CORP LTD

System and method for providing secured can communications

Example embodiments of the present disclosure provide secured controller area network (CAN) communications among vehicle components. According to embodiments, a method for providing may include: generating, by at least one processing unit of a sender, a one-time passcode (OTP); obtaining, by the at least one processing unit of the sender, a master key pre-provisioned to the sender and the receiver; deriving, by the at least one processing unit of the sender, a shared key based on the OTP and the master key; generating, by the at least one processing unit of the sender, a message authentication code (MAC) based on the derived shared key; appending, by the at least one processing unit of the sender, the MAC to a message; and transmitting, by the at least one processing unit of the sender, the appended message to a receiver via a CAN bus.
Owner:TOYOTA JIDOSHA KK

SecOC vehicle-mounted safety communication method based on dynamic key management enhancement

The invention discloses a SecOC vehicle-mounted safety communication method based on dynamic key management enhancement, which realizes on-demand distribution, dynamic updating and full life cycle management of SecOC keys by introducing a key distribution center. The ECU negotiates a unique preset key through the KDC client and the KDC server; the KDC client requests a service bill from the KDC server based on the service identifier of the application; the SecOC key is dynamically distributed by the KDC, and automatic rotation based on a time strategy and emergency update based on a security event are supported. The SecOC message adopts a gPTP timestamp as a freshness value, and after the data unit and the freshness value are spliced, a message authentication code is calculated. According to the invention, the secret key is not statically preset any more, but is dynamically distributed by the KDC and supports online updating, and through combination of bidirectional certificate authentication and timestamp double-factor authentication, full-life-cycle safety management of the vehicle service secret key is realized, and the risk of secret key leakage is effectively coped with.
Owner:AUTOCORE INTELLIGENT TECH (NANJING) CO LTD

Data transmission method and device, equipment, storage medium and program product

The invention provides a data transmission method, which can be applied to the financial field, and comprises the following steps: identifying to-be-transmitted service data corresponding to a service request, and determining a first type of data and a second type of data in the to-be-transmitted service data, the first type of data being service data containing sensitive fields, and the second type of data being service data containing non-sensitive fields; performing first encryption processing on a first type of data in the to-be-transmitted service data to obtain a partially encrypted service data body; assembling the service request context and the partially encrypted service data volume to obtain a complete data packet to be subjected to signature verification; calculating a message authentication code for the complete data packet through the symmetric key of the current session, and adding the message authentication code into the complete data packet to generate a target data packet to be transmitted; and performing second encryption processing on the to-be-transmitted target data packet through the symmetric key, and sending the to-be-transmitted target data packet to the server. The invention further provides a data transmission device, equipment, a storage medium and a program product.
Owner:CHINA CONSTRUCTION BANK +1

Method for generating EMM transport message

According to one embodiment of this specification, there is provided an operation method of user equipment (UE). The method may comprise: if the UE is using an Evolved Packet System (EPS) service with control plane Cellular Internet of Things (CIoT) EPS optimization with overhead reduction, generating an EPS Mobility Management (EMM) transport message. The EMM transport message may include a protocol discriminator, a security header type, a message authentication code and a sequence number. If the EMM transport message is sent in an EMM data transport procedure or if the EMM transport message is sent in a service request procedure for UE using the EPS service with control plane CIoT EPS optimization with overhead reduction to send a user data, a short message service (SMS) message or a location service (LCS) message, the EMM transport message may further include a data container.
Owner:H3NITY CO LTD

Lightweight encryption and authentication method for wireless sensor network, and related device

Provided in the present application is a lightweight encryption and authentication method for a wireless sensor network. The method comprises: a gateway node respectively generating a sensor ephemeral key and a user ephemeral key on the basis of a one-way hash function and a preconfigured physically unclonable function, and respectively sending to a user end and a sensor node the sensor ephemeral key, the user ephemeral key, a preconfigured sensor long-term key and a preconfigured user long-term key; and after the user end and the sensor node are registered, the user end performing identity authentication on identity information currently input by a user, and performing, on the basis of the identity information, mutual authentication between the user end, the gateway node and the sensor node, so as to send a sensor hash-based message authentication code and a user hash-based message authentication code to the sensor node on the basis of the authentication result, such that the sensor node and the gateway node perform key agreement and authentication to obtain a session key, and wireless sensor network communication can thus be performed on the basis of the session key, thereby effectively solving the problem of authenticating the security of a wireless sensor network.
Owner:SHENZHEN UNIV

Methods and apparatus for selective encryption of execute in place (XIP) data

An example apparatus includes: interface circuitry; and programmable circuitry configured to: obtain a set of processor instructions; select a first subset of processor instructions from the set; encrypt the first subset of processor instructions; select a second subset of processor instructions from the set; compute a plurality of message authentication codes (MACs) corresponding to the second subset of processor instructions; cause the interface circuitry to write the set of processor instructions to an external memory; and cause the interface circuitry to write a description of the first subset of processor instructions, a description of the second subset of processor instructions, and the plurality of MACs to the external memory.
Owner:TEXAS INSTRUMENTS INC

Network-bound data security techniques

Techniques are described for securing data stored on a non-volatile storage medium from unauthorized access using improved network-bound data security techniques. The data is secured using network-bound security techniques without the entities involved in the processing (e.g., clients and servers) having to exchange any client-specific or server-specific keys, secrets, or other secret data with each other. The techniques disclosed herein provide the network-bound data security functionality using a sequence of Message Authentication Codes (macs) generated using Hash-based Message Authentication Code (HMAC) generation techniques.
Owner:ORACLE INT CORP

Session key generation method, key downloading method and electronic equipment

The invention discloses a session key generation method, a key downloading method and electronic equipment. The key generation method comprises the following steps: sending a starting message to key distribution equipment; receiving a binding message and a binding message signature of the key distribution equipment; constructing a first key exchange message and a first exchange message signature based on a binding message and the binding message signature; sending the first key exchange message and the first exchange message signature to a key distribution device, and receiving a second key exchange message and a second exchange message signature sent by the key distribution device; verifying the second key exchange message and the second exchange message signature, and after the verification is passed, generating a first session key and a first message verification code key through a shared secret in the second key exchange message by using a derivation algorithm; wherein the derivation algorithm comprises an algorithm of an extensible output function based on an SHA-3 standard. According to the invention, output is realized through highly complex nonlinear transformation, so that the safety of the system is improved.
Owner:FUJIAN LANDI COMMERCIAL EQUIPMENT CO LTD

Enhanced UE parameter update (UPU) procedure

Systems, methods, and software to perform UE parameter updates (UPUs) of a user equipment. In one embodiment, a user equipment receives a first UPU container from a network, the first UPU container including UPU data for UE parameter updates and a first message authentication code protecting the UPU data, and performs verification of the first message authentication code. The user equipment generates a UPU acknowledgement indicating whether the verification is successful, derives a second message authentication code based on the UPU acknowledgement, and sends a second message to the network, the second message including a second UPU container including the second message authentication code, and an indicator indicating whether the user equipment supports UPU header protection.
Owner:NOKIA TECHNOLOGIES OY