Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

341 results about "Message authentication code" patented technology

In cryptography, a message authentication code (MAC), sometimes known as a tag, is a short piece of information used to authenticate a message—in other words, to confirm that the message came from the stated sender (its authenticity) and has not been changed. The MAC value protects both a message's data integrity as well as its authenticity, by allowing verifiers (who also possess the secret key) to detect any changes to the message content.

Communication encryption method and device, equipment, storage medium and computer program product

The invention relates to the technical field of communication security, in particular to a communication encryption method and device, equipment, a storage medium and a computer program product. The method comprises the following steps: dynamically generating a main session key between two communication parties based on a preset key negotiation protocol; dynamically generating sub-keys according to a preset time interval based on the main session key and the key sequence; performing encryption processing on each data block in the communication data stream based on the sub-key and the encryption strategy; generating a message authentication code for each encrypted data block; adding timestamp information based on the message authentication code, and introducing a random offset into the timestamp information; and the encrypted data blocks, the message authentication code and the timestamp information are packaged into the target data message, so that the transmission security of the communication data is improved.
Owner:SHENZHEN DINSTAR TECH

Privacy information retrieval system and method based on block chain and function secret sharing

The invention relates to the technical field of information retrieval, and provides a privacy information retrieval system and method based on a block chain and function secret sharing, and the method comprises the steps: carrying out the encryption and keyword extraction of a data document; generating a Bloom filter index table between the keyword and the document based on the keyword trap door; uploading the encrypted file and the Bloom filter index table to a DSSP end, and transmitting the hash value of the encrypted file and the Bloom filter index table to a block chain for on-chain storage; storing the encrypted file in a distributed storage node under the chain according to the divided share; and the block chain calculates data of each column of the Bloom filter index table through consensus to obtain a message verification code, and the message verification code is stored on the block chain. According to the method, the index is constructed through symmetric encryption and the Bloom filter, and block chain evidence storage and FSS distributed storage are combined, so that data privacy protection and index credibility are realized. Through verification and tampering prevention, the problem that the existing FSS lacks verification and auditing mechanisms is solved.
Owner:SHANDONG COMP SCI CENTNAT SUPERCOMP CENT IN JINAN

Imaging devices, host devices, and method

Imaging devices, host devices, and a method are disclosed. In one example, an image sensor includes a first register, a second register, a communication interface, and a controller. The first register storing a first key. The second register storing a counter value. The communication interface configured to communicate with a host device. The controller configured to control the communication interface to receive a request from the host device, change the counter value to generate an updated counter value, and generate a message authentication code based on the first key and the updated counter value in response to receiving the request from the host device.
Owner:SONY SEMICON SOLUTIONS CORP

Quantum key transmission method, apparatus, and system

An application device sends a key request packet to a quantum device, where the key request packet includes a user identifier corresponding to the application device, a first public key, and a first message authentication code value. If verification performed on the first message authentication code value succeeds, the quantum device sends a key response packet to the application device, where the key response packet includes a first ciphertext and a second message authentication code value. If verification performed on the second message authentication code value succeeds, the application device decrypts the first ciphertext by using a first private key, to obtain quantum key information allocated by the quantum device to the application device. The first public key and the first private key are from a key pair obtained by the application device by running a post-quantum key generation algorithm.
Owner:HUAWEI TECH CO LTD

Modbus protocol security enhancement method in multicast communication scene

The invention discloses a Modbus protocol security enhancement method in a multicast communication scene, which comprises the following steps: when a master node initiates an identity authentication request, the master node calculates a first message authentication code of a first random number according to a session key; wherein the session key is obtained according to random numbers pre-generated by the master node and the slave node; broadcasting and sending the encrypted session key and the first message authentication code to each slave node; the slave node decrypts the encrypted session key, and calculates a second message authentication code of the first random number according to the obtained session key; when the message authentication codes are the same, authenticating the identity of the main node; the slave node calculates a third message authentication code of the second random number by using the session key, and sends the third message authentication code to the master node; the main node uses the session key to calculate and obtain a fourth message authentication code of each second random number; and when the message authentication codes are the same, authenticating the identity of the corresponding slave node. According to the invention, the identity verification efficiency is improved, and the safety and reliability are improved.
Owner:XIDIAN UNIV

QKD system authentication method and device based on fusion of QRNG and PQC

The invention discloses a QKD system authentication method and device based on fusion of QRNG and PQC, and belongs to the technical field of information security, and the method comprises the following steps: S1, constructing a key encryption module based on QRNG and PQC, and when a QKD system starts a key negotiation process, carrying out identity verification based on a digital certificate to determine a negotiation object; s2, generating an encrypted random number based on a QRNG in a key encryption module, and obtaining a shared key between negotiation objects based on the encrypted random number and a PQC in a key encryption algorithm; and S3, generating a message authentication code based on the shared key, and performing authentication based on the message authentication code. The technical problem that the complexity is difficult to reduce while the security is improved in the prior art is solved, and the flexibility and expandability of authentication are also improved.
Owner:STATE GRID ZHEJIANG ELECTRIC POWER CO LTD SHAOXING POWER SUPPLY CO

Modbus protocol security enhancement method and system in unicast communication scene

The invention provides a Modbus protocol security enhancement method and system in a unicast communication scene, and relates to the technical field of industrial control networks. Comprising the following steps: sharing a first ciphertext and a second ciphertext between a master node and a slave node; the master node generates a first message authentication code according to the second ciphertext, a preset key and the first random number, and sends the first message to the slave node by using the target function code; the slave node authenticates the identity of the master node according to the first message authentication code, the first ciphertext, the preset key and the second random number; when the slave node successfully authenticates the identity of the master node, the slave node generates a second message authentication code according to the first ciphertext, the preset key and the second random number, and sends a second message to the master node by using the target function code; and the master node authenticates the identity of the slave node according to the second message authentication code, the second ciphertext, the preset key and the first random number. Therefore, the validity of the identities of the two communication parties can be ensured, and the integrity and confidentiality of the data in the transmission process are guaranteed.
Owner:XIDIAN UNIV

Sufficiently secure controller area network

As automotive security concerns are rising, the Controller Area Network (CAN)—the de facto standard of in-vehicle communication protocol—has come under scrutiny due to its lack of encryption and authentication. Several vulnerabilities, such as eavesdropping, spoofing, and replay attacks, have shown that the current implementation needs to be extended. Both academic and commercial solutions for a secure CAN have been proposed, but OEMs have not yet integrated them into their products. The main reasons for this lack of adoption are their heavy use of limited computational resources in the vehicle, increased latency that can lead to missed deadlines for safety-critical messages, as well as insufficient space available in a CAN frame to include a Message Authentication Code (MAC). By making a trade-off between security and performance, this disclosure overcomes the aforementioned problems of a secure CAN.
Owner:THE RGT UNIV OF MICHIGAN

Data enhancement encryption method, system and equipment based on AES (Advanced Encryption Standard) and medium

The invention provides an AES (Advanced Encryption Standard)-based data enhancement encryption method, system and equipment and a medium, and belongs to the technical field of data security. The method comprises the following steps: receiving plaintext data to be encrypted and a password provided by a user; deriving a master key and an HMAC key from the password and the randomly generated salt value by using a key derivation function; randomly generating an initialization vector, and encrypting the plaintext data through the master key by using an AES encryption mode to obtain encrypted ciphertext data; performing message authentication code calculation on the ciphertext data, the initialization vector and the salt value through an HMAC key to generate an HMAC check value; and combining the salt value, the initialization vector, the ciphertext data and the HMAC verification value into a final output encrypted data packet. According to the method, a series of enhancement mechanisms such as strong key derivation, random salt values, message authentication codes and initialization vectors are introduced, so that the security and integrity of data are further improved.
Owner:SHANDONG INSPUR ULTRA HD INTELLIGENT TECH CO LTD

Systems and methods for memory replay protection

Systems and methods for memory replay protection are disclosed. In an example, a system in the form of a device includes a processor, and a replay protection circuit coupled to the processor and including a memory interface circuit, wherein the replay protection circuit is configured to generate a message authentication code (MAC) from at least one block of data and to access the at least one of block of data via the memory interface circuit using ciphertext that is generated by the replay protection circuit in response to a plaintext memory address received from the processor.
Owner:PENSANDO SYSTEMS INC

System and method for providing secure can communication

The present disclosure provides systems and methods for providing secure CAN communications. Exemplary embodiments of the present disclosure provide secure CAN communication between vehicle components. According to an embodiment, a method for providing may include: generating, by at least one processing unit of a transmitter, a one-time password (OTP); acquiring, by at least one processing unit of the transmitter, a master key provided in advance to the transmitter and the receiver; deriving, by at least one processing unit of the transmitter, a shared key based on the OTP and the master key; generating, by at least one processing unit of the transmitter, a message authentication code (MAC) based on the derived shared key; attaching, by at least one processing unit of the transmitter, the MAC to the message; and transmitting the attached message to the receiver via the CAN bus by at least one processing unit of the transmitter.
Owner:TOYOTA JIDOSHA KK

Data security processing method, computer program product, electronic device and storage medium

The invention relates to the field of information security, in particular to a data security processing method, a computer program product, electronic equipment and a storage medium. The data security processing comprises the steps of obtaining to-be-transmitted target data; encrypting to-be-transmitted target data by using the key to obtain a ciphertext; packaging the ciphertext, the serial number and the truncation message authentication code to obtain a message frame; the truncation message authentication code is generated based on the ciphertext, the serial number and the key; and sending the message frame to a receiving end, so that the receiving end verifies and decrypts the message frame, and the data security can be improved.
Owner:CHONGQING JINKANG NEW ENERGY VEHICLE CO LTD

Systems and methods of personalizing contactless card

Methods and systems for personalizing contactless cards are provided. An exemplary method includes: preinstalling, by a server, an applet on the contactless card; assigning, by the server, a first unique identifier to the contactless card; pre-provisioning, by the server, a first unique derived key to the contactless card; generating, by the server a first nonce; generating, by the server, a data file containing script for updating the contactless card and further containing a message authentication code (MAC); transmitting, by the server, the data file and the first nonce to the contactless card; validating, by the contactless card, the MAC based on the first unique derived key and the first nonce; and personalizing the contactless card by the preinstalled applet executing the script.
Owner:CAPITAL ONE SERVICES LLC

Method and system for mutual authentication and key agreement between vehicles

The invention discloses an inter-vehicle bidirectional authentication and key agreement method and system, and relates to the technical field of Internet of Vehicles information security, and the method comprises the steps: a registration stage: a vehicle and a trusted mechanism derive a temporary session key based on ECDH and HKDF, and achieve the secure interaction; the trusted institution generates a basic identity label, a part of private key, a signature and a basic certificate for the vehicle, and encrypts and transmits the basic identity label, the part of private key, the signature and the basic certificate to the vehicle; the vehicle generates a hardware fingerprint and extracts a secret key by using the embedded PUF, and part of the private key is encrypted and then is locally and safely stored with the basic certificate; in the authentication stage, the two communication parties dynamically recover part of private keys through PUF, and generate dynamic pseudo names, temporary ECDH key pairs and cryptographic evidence; and calculating a cross item and a binding item by interaction parameters of the two parties, negotiating a unique session key, and completing bidirectional confirmation through a message authentication code. According to the method and the device, efficient, physical attack-resistant and privacy-protecting V2V security mutual recognition and key agreement are realized in a resource-limited vehicle-mounted environment.
Owner:CHANGZHOU INST OF TECH

Data transmission security protection system adaptive to communication base station

The invention relates to the technical field of data transmission, and particularly discloses a data transmission security protection system adapted to a communication base station, which comprises a sending end, a communication base station, a receiving end and a block chain verification unit, the sending end is in communication connection with the receiving end through a network transmission interface of the communication base station, and the sending end and the receiving end are both connected with the block chain verification unit. Through cooperative operation of a sending end, a communication base station, a receiving end and a block chain verification unit, in terms of data integrity verification, a dual mechanism combining a message authentication code technology and a digital signature is adopted, the message authentication code technology can quickly check whether data is tampered or not, the digital signature ensures that a data source is real and non-repudiation, and common tampering attacks are effectively resisted; and meanwhile, a block chain distributed account book technology is introduced, safe storage and reliable verification are provided for important data transmission records by utilizing decentralization and tamper-resistant characteristics of the block chain distributed account book technology, and even if data are tampered, the tampered data can be timely perceived through an original hash value, so that the data integrity protection capability is greatly improved.
Owner:HENAN TRACEABILITY COMM TECH CO LTD

Self-adaptive authentication method for space-air-ground cooperative NOMA communication system

The invention discloses a self-adaptive authentication method for a space-air-ground cooperative NOMA communication system, which introduces a self-adaptive access authentication mechanism based on an NTRU encryption algorithm, designs a dual-security mechanism for trusted and untrusted NOMA relays, ensures data security through authentication and key exchange in a trusted mode, and improves the security of the communication system. And in an untrusted mode, data tampering and stealing are prevented through a temporary session key and a message authentication code, and flexible application guarantee is provided. Meanwhile, in combination with a certification authority (CA) and a digital certificate technology, it is ensured that the public key is not tampered in the transmission process, man-in-the-middle attack is avoided, and the reliability of communication node identity authentication is further improved.
Owner:NORTHWESTERN POLYTECHNICAL UNIV

Data transmission method and system for meteorological satellite communication system

The invention discloses a data transmission method for a meteorological satellite communication system, and relates to the technical field of data transmission. Receiving original meteorological data, performing security level analysis on the original meteorological data, determining a security level, and processing the key change parameter by using the master key based on a preset key derivation function to obtain an encrypted session key; performing encryption processing on the original meteorological data based on the encrypted session key to obtain first ciphertext data; combining the key change parameter with the communication identification information to obtain first associated data; performing message authentication code calculation on the first associated data and the first ciphertext data to obtain a message authentication code; assembling the security level, the first associated data, the first ciphertext data and the message authentication code based on a preset format to obtain a target data frame; and sending the target data frame to a meteorological data center so as to decrypt the target data frame to obtain original meteorological data. By implementing the technical scheme provided by the invention, the security in the transmission process is ensured.
Owner:ZHONGMAN TECH (BEIJING) CO LTD

Method and device for enhancing security in as layer in next-generation mobile communication system

The present disclosure provides a method performed by means of a terminal in a wireless communication system. The method may comprise the steps of: acquiring information including a Message Authentication Code for Integrity (MAC-I) in an RRC idle state; verifying the MAC-I; and performing a procedure for an RRC connection with a base station if the MAC-I is valid on the basis of the verification.
Owner:SAMSUNG ELECTRONICS CO LTD

Anti-quantum message authentication code construction method and system adopting adjustable block cipher

The invention belongs to the field of passwords, and discloses an anti-quantum message authentication code construction method and system adopting an adjustable block cipher. The MAC generation method comprises the steps that two communication parties share a key value K generated by a key generation algorithm, the label length tau = Tag is agreed, the tau is limited to be smaller than or equal to n, and n represents the packet length; and taking the key K, the message M and the unique value N as input to generate a tau-bit message authentication code Tag. Furthermore, the MAC verification method verifies the generated message authentication code, and judges whether the message is correct or not and whether the message is accepted or not. According to the method, the adjustment handle value is an encryption result of a unique value initially, and then the adjustment handle is updated by using a function h when the adjustable block cipher is called every time. The method has the quantum attack resisting capability, and compared with the existing known MAC scheme with the quantum attack resisting capability, the required storage is small under the condition of providing the same quantum security intensity.
Owner:INST OF SOFTWARE - CHINESE ACAD OF SCI +1

System and method for secure authentication of contact-free card

A security authentication system is provided that includes a server including a processor and a memory. The server is configured to: generate an authentication challenge; storing the authentication challenge in a memory; transmitting the authentication challenge to the user device; generating a session key based on the master key; storing the session key in a memory; receiving, from the user equipment, an encrypted message authentication code (MAC) password incorporating an authentication challenge; decrypting the encrypted MAC password using one or more cryptographic algorithms and the session key; and validating the authentication challenge received from the user device.
Owner:CAPITAL ONE SERVICES LLC

Multi-part transaction integrity protection and encryption

Multi-part transaction integrity protection and encryption are disclosed, including generating, by a first device, a first message authentication code (MAC) for authenticating a plurality of packets of a transaction, the plurality of packets including at least a first packet received over a data link from a second device and a second packet generated by the first device in response to receiving the first packet, the first MAC is generated using data included in the plurality of packets; and transmitting, by the first device, the second packet and the first MAC over the data link to the second device.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Programmable electronic detonator safety communication system and safety communication method

The invention provides a programmable electronic detonator safety communication system and a safety communication method, and relates to the technical field of electronic communication safety. The programmable electronic detonator safety communication system comprises a detonation controller and at least one electronic detonator, wherein the electronic detonator is internally provided with a secure communication module, and the secure communication module is configured to generate a unique physical identity label of the electronic detonator based on a physical unclonable function response value generated by the SRAM PUF unit; receiving an encryption instruction frame from the detonation controller for decryption and authentication; sending an encrypted response frame to a detonation controller; the detonation controller is configured to perform bidirectional identity authentication with each electronic detonator and negotiate or derive a session key; constructing a communication frame containing anti-replay parameters and instruction data, encrypting the communication frame by using the session key and generating a message authentication code; and verifying the integrity and freshness of the response frame of the electronic detonator. According to the method, the safety intensity can be ensured, and hardware guarantee is provided for maintaining millisecond-level instruction response.
Owner:JIANGHAN UNIVERSITY +1

Communication method and communication device supporting variable authentication tag length

The invention provides a communication method and a communication device supporting a variable authentication label length, and the method comprises the steps: generating a first key stream and a second key stream according to input data through employing a ZUC algorithm, and carrying out the encryption processing of the input data through employing the first key stream, and obtaining a ciphertext message; a secret key mixing step: performing shift operation on the current secret key and the next secret key in the second secret key stream to obtain secret key mixed data; a first updating step: updating the next secret key as the current secret key, and sequentially repeating the secret key mixing step and the first updating step for at least one time until all secret key mixed data is obtained; calculating a target message authentication code according to the second key stream and all key mixed data; and sending the ciphertext message and the target message authentication code to a communication receiver. The problem that in the prior art, the bit number of integrity verification is too single, and integrity verification of different lengths cannot be adopted for messages of different importance degrees, so that the risk that a secret key is attacked and cracked is increased is solved.
Owner:BEIJING SYLINCOM TECHNOLOGY CO LTD

Security Negotiation

A wireless device sends, to a base station, a registration request message comprising one or more first parameters that indicate security algorithms supported by the wireless device, and comprise at least a first security algorithm with a first key length and at least a second security algorithm with a second key length. The wireless device receives, from the base station, a first radio resource control (RRC) message, wherein the first RRC message comprises a message authentication code-integrity (MAC-I), and indicates a selected security algorithm, among the first security algorithm and the second security algorithm. The wireless device sends, to the base station, a second RRC message comprising a second MAC-I, based on the selected security algorithm.
Owner:OFINNO LLC

Shared secret generation method and device based on post-quantum secret key negotiation, and electronic passport password authentication method

The invention discloses a shared secret generation method and device based on post-quantum secret key negotiation and an electronic passport password authentication method, and the method comprises the steps: enabling a passport reader to read an information code in a machine reading region as a shared password; the reader and the chip take the shared password as seed input to perform key negotiation to generate a shared secret, and the electronic passport password authentication method based on post-quantum key negotiation generates a session key and a message authentication code by using the shared secret generated by key negotiation to perform electronic passport password authentication. The anti-quantum security authentication protocol is realized by utilizing a module lattice encryption algorithm ML-KEM and combining a symmetric encryption algorithm AES and a hash authentication algorithm SHA3-512. According to the technical scheme, on the premise of keeping an original PACE protocol authentication process, the security strength and the future adaptive capacity of the system are improved, and the method is suitable for a new-generation high-security electronic passport authentication scene.
Owner:WUHAN UNIV

Dynamic Integrity and Data Encryption (IDE) Aggregation Size

To reduce bandwidth overheads associated with a message authentication code (MAC), aggregation is useful. To ensure there is no latency impact, something more than aggregation is needed. Integrity and Data Encryption (IDE) securing transaction layer packets (TLPs) can be used in a dynamic manner whereby before aggregating a new packet to the IDE TLP, a determination is made regarding whether the packet contains user data so that the packets with user data can be sent immediately rather than wanting for more packets to aggregate. On the receiving side, execution of the packet can occur before completing an integrity check that occurs in IDE TLP transfers to reduce latency.
Owner:SANDISK TECHNOLOGIES LLC

Secure message system and method of the same

A computer-implemented method that causes data processing hardware to perform operations including generating, at a first device, a message having a header including a message type and a service ID, receiving, at a second device, the message including the header and a key serial number (KSN) of the first device, determining, based on the header, the message type of the message, verifying, at a high performance crypto accelerator (HPCA) of the second device, a message authentication code (MAC) of the message based on the determined message type being the service event, obtaining, based on the KSN from the message, a key slot from a message authentication code table (MACT), identifying, based on the key slot, a key associated with the key slot obtained from the MACT, the key including at least one of a primary key and a secondary key, and verifying, using the key and the key slot obtained from the MACT, the MAC.
Owner:GM GLOBAL TECHNOLOGY OPERATIONS LLC

An encryption communication system applied to new energy vehicles and charging piles

This invention relates to the field of new energy vehicle technology and discloses an encrypted communication system for communication between new energy vehicles and charging piles. The system includes: a vehicle gateway, used to generate an initial vehicle-to-charging pile communication key and a message authentication code, and to send the initial vehicle-to-charging pile communication key and the message authentication code to both communicating parties; and, upon receiving a message indicating successful communication between the battery management system and the charging pile, updating the current vehicle-to-charging pile communication key and regenerating the message authentication code to send to both communicating parties; the battery management system and the charging pile, i.e., the two communicating parties, verify each received message authentication code based on the code. If the verification is successful, they initiate the current round of communication using the current vehicle-to-charging pile communication key; after each message transmission, the current vehicle-to-charging pile communication key is updated, and a message indicating successful communication for the current round is sent to the vehicle gateway. This invention updates the key multiple times during vehicle-to-charging pile communication and verifies it in each round of communication, thus improving communication security.
Owner:CHERY NEW ENERGY AUTOMOBILE TECH CO LTD

Method and system for securely selecting applications

The disclosure relates to a method and system for securely selecting applications using application identifiers. The method for securely selecting applications using Application Identifiers (AIDs), wherein application-specific static keys are utilized to encrypt AIDs, ensuring privacy and preventing inference about the selected application. The method includes generating a random number to embed in the encryption for uniqueness and replay attack prevention, authenticating the selection command with a Message Authentication Code (MAC) for integrity, and transmitting the encrypted selection command to a recipient device for further processing.
Owner:ASSA ABLOY AB