Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

137 results about "Message authentication code" patented technology

In cryptography, a message authentication code (MAC), sometimes known as a tag, is a short piece of information used to authenticate a message—in other words, to confirm that the message came from the stated sender (its authenticity) and has not been changed. The MAC value protects both a message's data integrity as well as its authenticity, by allowing verifiers (who also possess the secret key) to detect any changes to the message content.

Method and system for mutual authentication and key agreement between vehicles

The invention discloses an inter-vehicle bidirectional authentication and key agreement method and system, and relates to the technical field of Internet of Vehicles information security, and the method comprises the steps: a registration stage: a vehicle and a trusted mechanism derive a temporary session key based on ECDH and HKDF, and achieve the secure interaction; the trusted institution generates a basic identity label, a part of private key, a signature and a basic certificate for the vehicle, and encrypts and transmits the basic identity label, the part of private key, the signature and the basic certificate to the vehicle; the vehicle generates a hardware fingerprint and extracts a secret key by using the embedded PUF, and part of the private key is encrypted and then is locally and safely stored with the basic certificate; in the authentication stage, the two communication parties dynamically recover part of private keys through PUF, and generate dynamic pseudo names, temporary ECDH key pairs and cryptographic evidence; and calculating a cross item and a binding item by interaction parameters of the two parties, negotiating a unique session key, and completing bidirectional confirmation through a message authentication code. According to the method and the device, efficient, physical attack-resistant and privacy-protecting V2V security mutual recognition and key agreement are realized in a resource-limited vehicle-mounted environment.
Owner:CHANGZHOU INST OF TECH

Data transmission method and system for meteorological satellite communication system

The invention discloses a data transmission method for a meteorological satellite communication system, and relates to the technical field of data transmission. Receiving original meteorological data, performing security level analysis on the original meteorological data, determining a security level, and processing the key change parameter by using the master key based on a preset key derivation function to obtain an encrypted session key; performing encryption processing on the original meteorological data based on the encrypted session key to obtain first ciphertext data; combining the key change parameter with the communication identification information to obtain first associated data; performing message authentication code calculation on the first associated data and the first ciphertext data to obtain a message authentication code; assembling the security level, the first associated data, the first ciphertext data and the message authentication code based on a preset format to obtain a target data frame; and sending the target data frame to a meteorological data center so as to decrypt the target data frame to obtain original meteorological data. By implementing the technical scheme provided by the invention, the security in the transmission process is ensured.
Owner:ZHONGMAN TECH (BEIJING) CO LTD

Secure message system and method of the same

A computer-implemented method that causes data processing hardware to perform operations including generating, at a first device, a message having a header including a message type and a service ID, receiving, at a second device, the message including the header and a key serial number (KSN) of the first device, determining, based on the header, the message type of the message, verifying, at a high performance crypto accelerator (HPCA) of the second device, a message authentication code (MAC) of the message based on the determined message type being the service event, obtaining, based on the KSN from the message, a key slot from a message authentication code table (MACT), identifying, based on the key slot, a key associated with the key slot obtained from the MACT, the key including at least one of a primary key and a secondary key, and verifying, using the key and the key slot obtained from the MACT, the MAC.
Owner:GM GLOBAL TECHNOLOGY OPERATIONS LLC

An encryption communication system applied to new energy vehicles and charging piles

This invention relates to the field of new energy vehicle technology and discloses an encrypted communication system for communication between new energy vehicles and charging piles. The system includes: a vehicle gateway, used to generate an initial vehicle-to-charging pile communication key and a message authentication code, and to send the initial vehicle-to-charging pile communication key and the message authentication code to both communicating parties; and, upon receiving a message indicating successful communication between the battery management system and the charging pile, updating the current vehicle-to-charging pile communication key and regenerating the message authentication code to send to both communicating parties; the battery management system and the charging pile, i.e., the two communicating parties, verify each received message authentication code based on the code. If the verification is successful, they initiate the current round of communication using the current vehicle-to-charging pile communication key; after each message transmission, the current vehicle-to-charging pile communication key is updated, and a message indicating successful communication for the current round is sent to the vehicle gateway. This invention updates the key multiple times during vehicle-to-charging pile communication and verifies it in each round of communication, thus improving communication security.
Owner:CHERY NEW ENERGY AUTOMOBILE TECH CO LTD

Method and system for securely selecting applications

The disclosure relates to a method and system for securely selecting applications using application identifiers. The method for securely selecting applications using Application Identifiers (AIDs), wherein application-specific static keys are utilized to encrypt AIDs, ensuring privacy and preventing inference about the selected application. The method includes generating a random number to embed in the encryption for uniqueness and replay attack prevention, authenticating the selection command with a Message Authentication Code (MAC) for integrity, and transmitting the encrypted selection command to a recipient device for further processing.
Owner:ASSA ABLOY AB

DEFEATING DELAY ATTACKS IN A COMMUNICATION NETWORK

A communication network for mitigating delay attacks comprises one or more sender nodes that communicate electronically with one or more receiver nodes. The one or more receiver nodes execute instructions to periodically send a challenge message to a sender node. In response to the acceptance of the challenge message and the determination that data is to be sent to the receiver node, the sender node sends a function message to the receiver node.In response to the finding that an updated freshness value is more recent than a current freshness value associated with the sender node, that a sender message authentication code is correct and consistent across at least one previous challenge message, and that the response to the challenge message from the receiver node is correct, the receiver node updates the current freshness value to match the updated freshness value and accepts the function message.
Owner:GM GLOBAL TECHNOLOGY OPERATIONS LLC

Automobile external equipment access authentication method and system, equipment and medium

The invention provides an automobile external equipment access authentication method and system, equipment and a medium, and belongs to the technical field of automobile safety communication, and the method comprises the steps: obtaining a second identity authentication message sent by a T-BOX; if the T-BOX self-increasing serial number is greater than or equal to the gateway self-increasing serial number, the first-level authentication succeeds, otherwise, the first-level authentication fails; when the first-level authentication is successful, judging whether the T-BOX unique identity identifier and the identity information of the remote vehicle control instruction APP terminal in the first identity authentication message are consistent with the T-BOX unique identity identifier and the identity information of the remote vehicle control instruction APP terminal stored in the gateway, if so, determining that the second-level authentication is successful, and otherwise, determining that the second-level authentication fails; and when the second-level authentication succeeds, calculating the first identity authentication message and the T-BOX self-increasing serial number in the received second identity authentication message through a preset message authentication code algorithm to generate a second message authentication code, comparing the second message authentication code with the first message authentication code in the second identity authentication message, if the second message authentication code is consistent with the first message authentication code in the second identity authentication message, determining that the third-level authentication succeeds, otherwise, determining that the third-level authentication fails.
Owner:DONGFENG MOTOR GRP

Derived unique key per hash encapsulated encrypted transaction (DUKPHEET)

The arrangements disclosed herein relate to generating, by a first server, a first seed using a Hash-Based Message Authentication Code (HMAC) based at least in part on a Hash Key (HK), providing, by the first server to each of a first device and a second device, the first seed, providing, by a second server to each of the first device or the second device, a second seed. The second seed is based at least in part on a stream of photons. Each of the first device or the second device generates a Derived Key (DK) based at least in part on the first seed and the second seed. Each of the first device or the second device generates a first key based at least in part on the DK and a first random number generated by a Quantum Random Number Generator (QRNG). The first device encrypts first data using the first key to obtain first ciphertext and provides the first ciphertext to the second device. The second device derives the first key and decrypts the first ciphertext using the first key.
Owner:WELLS FARGO BANK NA

Secure RDMA for low-latency real-time applications

A vehicle network communications system including a sending processor for generating a data in response to a first vehicle control algorithm, a sending network interface configured to receive the data from the sending processor, to generate a message authentication code in response to the data, to generate a communications packet for transmission according to a remote direct memory access network protocol, wherein the message authentication code is appended to the communications packet, and to transmit the communications packet via a communications network, a receiving network interface configured to receive the communications packet from the sending network interface via the communications network, to decode the message authentication code to extract the data, and to couple the data the memory, and a memory configured to store the data for use by a receiving processor performing a second vehicle control algorithm.
Owner:GM GLOBAL TECHNOLOGY OPERATIONS LLC

Method, device and electronic equipment for identity authentication

The application discloses a kind of identity authentication method, device and electronic equipment.Therein, the method includes: sending key request to secure chip, receiving the first response information returned by secure chip, wherein the first response information at least includes: key;According to application identification, the session identification corresponding to this session is created, and the request for obtaining authentication key is initiated to quantum key management system;Determine the authentication key returned by quantum key management system, at least encrypt login authentication credential according to authentication key to generate login information ciphertext, and generate the message authentication code corresponding to login information ciphertext;Send login information ciphertext, message authentication code and session identification to identity authentication server;Receive the second response information returned by identity authentication server.The application solves the technical problem that the security is poor and data leakage is easy to cause in the related art based on the security verification mode of username and password.
Owner:CHINA TELECOM CORP LTD

System and method for providing secured can communications

Example embodiments of the present disclosure provide secured controller area network (CAN) communications among vehicle components. According to embodiments, a method for providing may include: generating, by at least one processing unit of a sender, a one-time passcode (OTP); obtaining, by the at least one processing unit of the sender, a master key pre-provisioned to the sender and the receiver; deriving, by the at least one processing unit of the sender, a shared key based on the OTP and the master key; generating, by the at least one processing unit of the sender, a message authentication code (MAC) based on the derived shared key; appending, by the at least one processing unit of the sender, the MAC to a message; and transmitting, by the at least one processing unit of the sender, the appended message to a receiver via a CAN bus.
Owner:TOYOTA JIDOSHA KK

SecOC vehicle-mounted safety communication method based on dynamic key management enhancement

The invention discloses a SecOC vehicle-mounted safety communication method based on dynamic key management enhancement, which realizes on-demand distribution, dynamic updating and full life cycle management of SecOC keys by introducing a key distribution center. The ECU negotiates a unique preset key through the KDC client and the KDC server; the KDC client requests a service bill from the KDC server based on the service identifier of the application; the SecOC key is dynamically distributed by the KDC, and automatic rotation based on a time strategy and emergency update based on a security event are supported. The SecOC message adopts a gPTP timestamp as a freshness value, and after the data unit and the freshness value are spliced, a message authentication code is calculated. According to the invention, the secret key is not statically preset any more, but is dynamically distributed by the KDC and supports online updating, and through combination of bidirectional certificate authentication and timestamp double-factor authentication, full-life-cycle safety management of the vehicle service secret key is realized, and the risk of secret key leakage is effectively coped with.
Owner:AUTOCORE INTELLIGENT TECH (NANJING) CO LTD

Data transmission method and device, equipment, storage medium and program product

The invention provides a data transmission method, which can be applied to the financial field, and comprises the following steps: identifying to-be-transmitted service data corresponding to a service request, and determining a first type of data and a second type of data in the to-be-transmitted service data, the first type of data being service data containing sensitive fields, and the second type of data being service data containing non-sensitive fields; performing first encryption processing on a first type of data in the to-be-transmitted service data to obtain a partially encrypted service data body; assembling the service request context and the partially encrypted service data volume to obtain a complete data packet to be subjected to signature verification; calculating a message authentication code for the complete data packet through the symmetric key of the current session, and adding the message authentication code into the complete data packet to generate a target data packet to be transmitted; and performing second encryption processing on the to-be-transmitted target data packet through the symmetric key, and sending the to-be-transmitted target data packet to the server. The invention further provides a data transmission device, equipment, a storage medium and a program product.
Owner:CHINA CONSTRUCTION BANK +1

Lightweight encryption and authentication method for wireless sensor network, and related device

Provided in the present application is a lightweight encryption and authentication method for a wireless sensor network. The method comprises: a gateway node respectively generating a sensor ephemeral key and a user ephemeral key on the basis of a one-way hash function and a preconfigured physically unclonable function, and respectively sending to a user end and a sensor node the sensor ephemeral key, the user ephemeral key, a preconfigured sensor long-term key and a preconfigured user long-term key; and after the user end and the sensor node are registered, the user end performing identity authentication on identity information currently input by a user, and performing, on the basis of the identity information, mutual authentication between the user end, the gateway node and the sensor node, so as to send a sensor hash-based message authentication code and a user hash-based message authentication code to the sensor node on the basis of the authentication result, such that the sensor node and the gateway node perform key agreement and authentication to obtain a session key, and wireless sensor network communication can thus be performed on the basis of the session key, thereby effectively solving the problem of authenticating the security of a wireless sensor network.
Owner:SHENZHEN UNIV

Session key generation method, key downloading method and electronic equipment

The invention discloses a session key generation method, a key downloading method and electronic equipment. The key generation method comprises the following steps: sending a starting message to key distribution equipment; receiving a binding message and a binding message signature of the key distribution equipment; constructing a first key exchange message and a first exchange message signature based on a binding message and the binding message signature; sending the first key exchange message and the first exchange message signature to a key distribution device, and receiving a second key exchange message and a second exchange message signature sent by the key distribution device; verifying the second key exchange message and the second exchange message signature, and after the verification is passed, generating a first session key and a first message verification code key through a shared secret in the second key exchange message by using a derivation algorithm; wherein the derivation algorithm comprises an algorithm of an extensible output function based on an SHA-3 standard. According to the invention, output is realized through highly complex nonlinear transformation, so that the safety of the system is improved.
Owner:FUJIAN LANDI COMMERCIAL EQUIPMENT CO LTD

Enhanced UE parameter update (UPU) procedure

Systems, methods, and software to perform UE parameter updates (UPUs) of a user equipment. In one embodiment, a user equipment receives a first UPU container from a network, the first UPU container including UPU data for UE parameter updates and a first message authentication code protecting the UPU data, and performs verification of the first message authentication code. The user equipment generates a UPU acknowledgement indicating whether the verification is successful, derives a second message authentication code based on the UPU acknowledgement, and sends a second message to the network, the second message including a second UPU container including the second message authentication code, and an indicator indicating whether the user equipment supports UPU header protection.
Owner:NOKIA TECHNOLOGIES OY

Data storage device and method of operation thereof

The present invention relates to a data storage device and an operating method thereof. According to the present invention, a data storage device providing an improved security function includes a memory device including a protected storage block protected by a security protocol; and a memory controller configured to receive a command protocol component associated with the security protocol, the security protocol including a host-side protection message requesting to write data from a host to the protected storage block, perform an authentication operation on the protected storage block using a host message authentication code included in the host-side protection message, and store the data from the host according to a result of the authentication operation.
Owner:SK HYNIX INC

Sending replay protected monotonic counter commands to a memory device

Various aspects of the present disclosure generally relate to memory systems. In some aspects, a controller may send, to a memory device, a replay protected monotonic counter (RPMC) command associated with a hardware attack protection, wherein the RPMC command is one of: a write root key register command, an update hash-based message authentication code (HMAC) key register command, a request monotonic counter (MC) command, or an increment MC command. The controller may send, to the memory device, a read data command based at least in part on the write root key register command, the update HMAC key register command, the request MC command, or the increment MC command. Numerous other aspects are described.
Owner:QUALCOMM INC

Determining integrity-driven error types in memory buffer devices

Technologies for detecting an error using a message authentication code (MAC) associated with cache line data and differentiating the error as having been caused by an attack on memory or a MAC verification failure caused by an ECC escape. One memory buffer device includes an in-line memory encryption (IME) circuit to generate the MACs and verify the MACs. Upon a MAC verification failure, the memory buffer device can analyze at least one of the historical MAC verification failures or historical ECC-corrected errors over time to determine if the error is caused by an attack on memory.
Owner:RAMBUS INC

Systems, methods, and media for enhanced message-to-code data tie (EMCDT) for electronic message authentication

Techniques are provided for Enhanced Message-to-Code Data Tie (EMCDT) for electronic message authentication. A processor may receive a navigation message with navigation data that requires authentication and adheres to a delayed key disclosure protocol. There may be a service interruption to the authentication service. The processor can still authenticate the navigation data based on performance of an EMCDT algorithm that uses a Message Authentication Code and Key (MACK) MACK that corresponds to previously authenticated navigation message. Specifically, the MACK for the previously authenticated message can be used when the transmitter identifier of the navigation data to be authenticated matches a PRND value associated with the previously authenticated message and when a version identifier of the navigation data to be authenticated matches the version identifier of the previously authenticated message.
Owner:NOVATEL INC

Method, apparatus, device and medium for backhaul link security protection

The present application relates to the technical field of network security, and provides a backhaul link security protection method, device, equipment and medium, which comprises the following steps: sending initial request information to a gateway station; receiving a parameter response message sent by the gateway station, wherein the parameter response message comprises a gateway station signature or a gateway station message authentication code, a responder temporary public key, a responder session identifier, a responder credential reference identifier and first gateway station additional authorization information; generating an authentication completion message after authenticating the identity of the gateway station according to the parameter response message, wherein the authentication completion message comprises an initiator credential reference identifier, a base station signature or a base station message authentication code and second base station additional authorization information. The present application realizes mutual identity authentication and key negotiation, is suitable for scenarios with limited resources on the satellite, and ensures the security of the backhaul link.
Owner:CHINA MOBILE COMM LTD RES INST +1

Enhanced vehicle secure onboard communication protocol with encryption

A control system for a vehicle includes a first electronic control unit (ECU) configured to obtain data for communication to another ECU of the vehicle and to encrypt the data using a first key pair to obtain encrypted data, calculate a message authentication code (MAC) using a second key pair, append the MAC to the encrypted data to obtain a MAC-appended encrypted data, and transmit the MAC-appended encrypted data via a controller area network (CAN) of the vehicle, and a second ECU configured to receive the MAC-appended encrypted data from the first ECU via the CAN and to using the second key pair, attempt to verify the MAC and obtain the encrypted data, and in response to verifying the MAC using the second key pair, decrypt the encrypted data using the first key pair to obtain the data.
Owner:FCA US LLC

Autonomous key management for data, digital and computative devices and method therefor

The secure data system and communicative method is deployed on first and second edge nodes (the 1st node may be a network manager (NM)). Each edge node has a processor, a data store (with a file), and a secure data enclave. A keyed hash message authentication code (HMAC) is separately run on each node's processor, data store, file, and the HMAC is stored in the respective enclave. The first node (or NM) generates and stores in each node's enclave a synchronized security data set (SDSet) which includes the 1st node / NM's HMAC, creating an Autonomous Key Management Security Relationship (ASR) in both nodes. Communications from NM to designated node are accessed and processed by designated node only if the SDSet and HMAC match the enclave-stored HMAC and SDSet.
Owner:AKM CYBER CORP

Quantum security parallelizable message authentication code construction method and system

The invention discloses a parallel message authentication code construction method and system for quantum security. The method comprises the following steps: 1) selecting an adjustable block cipher algorithm key K, nonlinear transformation theta and the length tau of a message identification code by a participant; 2) the sender executes an MAC generation scheme, takes the key K, the temporary value N and the message M as input, outputs a message identification code and sends the message identification code to the receiver; the flow of the MAC generation scheme is as follows: a) dividing a message M into a plurality of n-bit groups; b) encrypting the ith group Mi by using an algorithm, and inputting theta to obtain a state Si after the output and the state Si-1 are subjected to XOR; c) intercepting the leftmost side tau bit of the state Sm corresponding to the last group as a message identification code; and 3) the receiver executes an MAC verification scheme, and verifies whether (MAC, M) is correct or not by taking the key K, the temporary value N, the message M and the message authentication code MAC as input.
Owner:INST OF SOFTWARE - CHINESE ACAD OF SCI

Methods and devices enhancing security mode establishment for user equipment communications

Methods and devices in a wireless communication network provide enhancements to the Security Mode establishment. A user equipment (102) receives (604), from a network entity (104, 110, 140), a first security mode command and a first message authentication code. The first security mode command indicates an integrity protection algorithm and a first ciphering algorithm. The user equipment transmits (612), to the network entity, a response to the first security mode command, the response indicating that the first ciphering algorithm is not allowed by the UE.
Owner:GOOGLE LLC

Address translation security verification method, host system, device and program product

The invention provides an address translation security verification method, a host system, equipment and a program product, and the method mainly executes address translation through a memory management module, and a security management module generates a message authentication code and verifies an access request with the authentication code, so that the security verification of the address translation is realized while the performance advantages of address translation service ATS are compatible. A real-time and efficient security verification level is constructed for memory access initiated by the device based on the cache address, and illegal access of the device by using tampered address information is effectively prevented.
Owner:GUANGDONG LEAPFIVE TECH CO LTD

Configuration file management method and configuration file management system based on quantum key

The invention provides a quantum key-based configuration file management method and a quantum key-based configuration file management system. The method comprises the following steps: an eSIM data management platform coordinates an eSIM terminal and a quantum key management platform to carry out bidirectional identity authentication; after completion, the eSIM data management platform establishes a first secure communication channel with the eSIM terminal, sends a configuration file request to the SM-DP + platform, and receives a returned target configuration file; the eSIM data management platform encrypts the target configuration file to obtain an encrypted configuration file; generating a message authentication code based on the target message authentication key; packaging the encrypted configuration file and the message authentication code into packaging configuration file data, and sending the packaging configuration file data to the eSIM terminal; and the eSIM terminal decrypts the received encrypted configuration file to recover and store the target configuration file. According to the mode, the confidentiality, the integrity and the tamper-resistant capability of the configuration file in the downloading and transmitting process can be improved.
Owner:GUANGDONG CHUTIAN DRAGON SMART CARD

Quantum resistant asymmetric key

An example operation includes one or more of sharing a hash-based message authentication code (HMAC) key between a sending system and a receiving system, establishing a communication session between the sending system and the receiving system over a data communication network, generating a seed value for the communication session based on the HMAC key, generating a dynamic public key based on the seed value and a public key, generating a session key based on the dynamic public key, and encrypting a communication based on the session key and transmitting the encrypted communication from the sending system to the receiving system via the communication session.
Owner:TOYOTA MOTOR NORTH AMERICA INC +1

Database access control method and computer device

PendingCN122286835AHash functionEngineering
This application provides a database access control method and computer device. The method first receives a privileged access request and generates a request digest and session identifier to determine the session validity period. Then, after the approval node completes valid signing, a threshold authorization token is generated. Next, an alias seed is generated using a key derivation function with an alias root key and multiple authorization information including at least the threshold authorization token and session identifier. Based on this seed, a transient access alias and a role lease identifier are derived using a hash message authentication code and a hash function, respectively. Finally, a zero-resident privileged session is established based on the transient access alias, role lease identifier, and session validity period, valid only in the current session. The transient access alias and role lease identifier are reclaimed when the session ends or a revocation condition is triggered. Through these steps, security risks are reduced, and on-demand, dynamic, and revocable database privileged access control is achieved, significantly improving database access security.
Owner:JIUYOU TECH (SHENZHEN) CO LTD