Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

32 results about "Message integrity" patented technology

Definition of: message integrity. message integrity. The validity of a transmitted message. Message integrity means that a message has not been tampered with or altered. The most common approach is to use a hash function that combines all the bytes in the message with a secret key and produces a message digest that is difficult to reverse.

Method for provisioning credentials to user equipment in a private telecommunications network - Patent Application 20070122997

The present invention proposes a method for provisioning a credential to a user equipment (10) in a private telecommunications network, the private telecommunications network including a credential holder and a gNB / AMF or eNB / MME, the method comprising: a) sending a provisioning request (40) from the user equipment (10) to the gNB / AMF or eNB / MME (11); b) establishing a PLS key (41) between the user equipment (10) and the gNB / AMF or eNB / MME (11) by physical layer security; c) providing a PLS key to the user equipment (10) via a PLS key; d) transmitting 43 a message from the user equipment 10 to the gNB / AMF or eNB / MME 11, the message including data permitting identification of the user of the user equipment 10 and / or the user equipment 10 and the master key, the message being integrity and confidentiality protected by a PLS key or a key derived from the PLS key; e) transmitting 44 a message from the gNB / AMF or eNB / MME 11 to the credential holder 12, the message including data permitting identification of the user of the user equipment 10 and / or the user equipment 10 and the master key, the message being integrity and confidentiality protected by a PLS key or a key derived from the PLS key. f) verifying in the credential holder (12) the data that allows identifying the user of the user equipment (10) and / or the user equipment (10); g) if the verification is positive, assigning in the credential holder (12) a unique subscription identifier to the user equipment (10) and generating corresponding keys, security parameters, and key derivation functions; h) transmitting the unique subscription identifier from the credential holder (12) to the gNB / AMF or eNB / MME (11). i) transmitting the unique subscription identifier, security parameters, and key derivation function from the gNB / AMF or eNB / MME (11) to the user equipment (10) in a message integrity and confidentiality protected by a PLS key or a key derived from the PLS key (47); j) generating a final key at the user equipment (10), the final key being a credential including the unique subscription identifier, security parameters, and final key (48);Including.
Owner:THALES SA +1

Power efficient data polling by a wireless mesh network device

Methods and device architectures for improving the energy efficiency of end devices in a wireless mesh network. In an example, an end device of the network includes a wireless transceiver, a first processing core configured to implement a media access control layer (MAC), and a second processing core configured to implement a physical layer (PHY). The PHY operates to receive a first data poll message from the MAC and transmit the message to an external device via the wireless transceiver. The PHY further operates to receive an acknowledge message including a frame pending value. If the frame pending value indicates that the external device does not have buffered data for the end device, the PHY generates a second data poll message based on the first data poll message, including incrementing one or more of a sequence number field value, a frame counter field value, and a message integrity check field of the first data poll message, thereby enabling the MAC to remain in a low power state while the PHY transmits the second data poll message.
Owner:NXP USA INC

Malicious node detection method and apparatus, malicious node defense method and apparatus, and device

PCT designated stageWO2026108501A1Security arrangementData packDecision model
The present application discloses a malicious node detection method and apparatus, a malicious node defense method and apparatus, and a device. The malicious node detection method comprises: on the basis of monitoring data of nodes in a network, determining forwarding success rates, message integrity, energy levels and resource scores of the nodes, wherein the message integrity represents the integrity of data packets forwarded by the nodes, the energy levels represent the activity levels and states of charge of the nodes, and the resource scores represent the transmission capabilities of the nodes; determining comprehensive trust values of the nodes on the basis of the forwarding success rates, message integrity and energy levels of the nodes, wherein the comprehensive trust values represent the credibility of the nodes; and inputting the comprehensive trust values, message integrity and resource scores of the nodes into a pre-trained classification decision model, and classifying the nodes into trusted nodes and untrusted nodes on the basis of the outputted classification results. In the present application, untrusted nodes can be identified before malicious behavior is fully exposed, thereby improving the overall security of a network.
Owner:CHINA TELECOM NETWORK SECURITY TECH CO LTD

Methods, systems, and computer readable media for providing end-to-end message integrity checking for service-based interface (SBI) messages communicated via a service communication proxy (SCP)

PCT designated stageWO2025250353A1Security arrangementSecuring communicationTelecommunicationsMessage integrity
A method for checking end-to-end SBI message integrity includes receiving a first traffic feed from a first NF, the first traffic feed including copies of SBI messages transmitted from the first NF to an SCP. The method further includes receiving a second traffic feed from a second NF, the second traffic feed including copies of SBI messages received by the second NF from the SCP. The method further includes identifying, from the first traffic feed, a copy of a first SBI message transmitted by the first NF to the SCP. The method further includes identifying, from the second traffic feed, a copy of a second SBI message received by the second NF from the SCP and that is associated with the copy of the first SBI message. The method further includes performing, using the message copies, an end-to-end SBI message integrity check for the first SBI message.
Owner:ORACLE INT CORP

User identity verification method and device, equipment, storage medium and product

The invention discloses a user identity verification method and device, equipment, a storage medium and a product, and relates to the technical field of secure digital identity verification, and the method comprises the steps: storing biological characteristic data in an SIM card with high performance, and when a user needs to perform identity verification, sending the biological characteristic data to the SIM card; the platform side can read the biological characteristic data in the SIM card in various modes to realize complex biological characteristic data comparison; when the SIM card feeds back data, the biological characteristic metadata and the biological characteristic vector are encrypted in different modes in a segmented manner, so that secret key updating is realized in a biological characteristic information encryption process with a relatively high security requirement, and the security is improved; and meanwhile, signature verification and MAC message check codes are added to the whole data ciphertext, so that the message integrity and non-repudiation are ensured.
Owner:CHINA MOBILE FINANCIAL TECHNOLOGY CO LTD +1

Power efficient data polling by a wireless mesh network device

Methods and device architectures for improving the energy efficiency of end devices in a wireless mesh network. In an example, an end device of the network includes a wireless transceiver, a first processing core configured to implement a media access control layer (MAC), and a second processing core configured to implement a physical layer (PHY). The PHY operates to receive a first data poll message from the MAC and transmit the message to an external device via the wireless transceiver. The PHY further operates to receive an acknowledge message including a frame pending value. If the frame pending value indicates that the external device does not have buffered data for the end device, the PHY generates a second data poll message based on the first data poll message, including incrementing one or more of a sequence number field value, a frame counter field value, and a message integrity check field of the first data poll message, thereby enabling the MAC to remain in a low power state while the PHY transmits the second data poll message.
Owner:NXP USA INC

Method and apparatus for enhanced security in wireless LAN system

Disclosed are a method and apparatus for enhanced security in a wireless LAN system. A method performed by a first station (STA) in a wireless LAN system, according to an embodiment of the present disclosure, may comprise the steps of: constructing additional authentication data (AAD) on the basis of one or more fields or subfields of a medium access control (MAC) header of an MAC protocol data unit (MPDU); and transmitting, to a second STA, a physical layer PDU (PPDU) including the MPDU configured on the basis of the AAD. The MPDU includes a message integrity check (MIC) field, and a value of the MIC field may be based on at least the AAD. The one or more fields or subfields of the MAC header may include one or more of a duration / identifier (ID) field or at least a part of a high throughput (HT) control field.
Owner:LG ELECTRONICS INC

Transaction System and Method

The invention relates to systems and methods for executing a digital-asset transaction using a dual-tier messaging architecture. A central messaging server provides tamper detection and message-integrity verification while routing bilateral messages between transacting devices. A permissioned-blockchain channel manages a smart-contract escrow that holds digital assets in cold storage. A fiat-rail channel integrates a real-time payment protocol to obtain bank or rail confirmation that fiat funds are credited to a seller account. Upon receipt of settlement evidence and a validated session state, the escrow releases the digital asset from a seller cold-storage wallet to a buyer cold-storage wallet. Embodiments may capture a seller opt-in via a banking application, generate a dual-ledger audit trail across permissioned and public blockchains, and emit transaction identifiers for cross-system reconciliation. The approach improves compliance, reduces counterparty risk, and provides verifiable audit artifacts for regulated settlement of digital-asset transfers.
Owner:HONEYWELL SEAN WILLIAM

Wireless network handover method and apparatus

ActiveCN112995993BNetwork topologiesSecurity arrangementEngineeringMessage integrity
The application discloses a wireless network switching method, in which a requesting device and a target access device directly generate a message integrity check key through a domain key, and verify an integrity check code based on the message integrity check key, so that identity authentication of both sides is realized; when the identity authentication of both sides is passed, a session key is generated by combining the domain key and random numbers of both sides, so that the switching process is simplified, and safe and efficient network switching is realized. The application also discloses corresponding requesting devices and access devices.
Owner:CHINA IWNCOMM

PKI-to-IBC heterogeneous broadcast signcryption and key negotiation method oriented to Internet of Things communication equipment

The invention discloses a PKI-to-IBC heterogeneous broadcast signcryption and key negotiation method oriented to Internet of Things communication equipment. The method sequentially comprises six stages of system initialization, data collection base station registration, terminal sensing equipment registration, heterogeneous signcryption, de-signcryption and key negotiation. In a system initialization stage, a registration management mechanism generates elliptic curve parameters and a system master key, and issues system parameters including a system public key, a related hash function and the like; in the registration stage, a data collection base station obtains a digital certificate through a PKI mechanism, and terminal sensing equipment obtains a private key and public key reconstruction factor through an IBC mechanism; in the signcryption stage, the data collection base station signcrypts messages based on a broadcast mechanism and sends the messages to multiple devices at the same time; in the de-signcryption stage, the terminal sensing device verifies the message integrity and the source legality by using the own key; in the key negotiation stage, the data collection base station and the terminal sensing device cooperatively generate a shared session key and establish a secure communication channel.
Owner:WUHAN UNIV

Key-based authentication for a mobile edge computing network

Apparatuses, methods, and systems are disclosed for key-based authentication for a mobile edge computing network. One method (800) includes deriving (805), at a user equipment, a first network key after authentication with a network function of a wireless core network, deriving (810) a second network key based on the first network key, the second network key for a first network function of a mobile edge computing network, sending (815) a registration request message to the first network function of the mobile edge computing network, the registration request message integrity protected with the second network key, receiving (820) a registration response message from the first network function, and, in response to verifying the integrity of the registration response message using the second network key, establishing (825) a secure communication with the first network function of the mobile edge computing network based on the second network key.
Owner:LENOVO (BEIJING) LTD

Encryption authentication method based on hash function and Feistel structure

The invention relates to the technical field of information security, and provides an encryption authentication method based on a hash function and a Feistel structure, the encryption authentication method comprises an encryption authentication algorithm and a decryption verification algorithm, the encryption authentication method is realized by taking the Feistel structure as a password structure, selecting a hash function as a round function of the Feistel structure, and instantiating the round function into a hash function. According to the invention, encryption and decryption and message integrity verification can be carried out. The plaintext length and the secret key length are selectable, and the method is high in universality, good in expansibility, low in error code diffusion and high in safety. The method can be widely applied to wireless communication environments such as satellite internet and internet of things.
Owner:SPACE STAR TECH CO LTD +1

Communication method, device and system

The invention discloses a communication method, device and system, and relates to the technical field of communication. The present application supports an Institute of Electrical and Electronic Engineers (IEEE) protocol, such as an IEEE 802.11 be / Wi-Fi 7 / EHT protocol, an IEEE 802.11 bn / UHR / Wi-Fi 8 protocol, an Integrating mmWave / Integrated Millimeter Wave / IMMW protocol, an IEEE 802.15 / UWB protocol, or an IEEE 802.11 bf / sensing / perceptual protocol, for example, an IEEE (Institute of Electrical and Electronic Engineers) protocol. The method comprises the following steps: a first site generates a management frame and sends the management frame to a second site; the management frame comprises a first message complete check code obtained based on a first secret key, and the first secret key is generated based on address information related to the first link and KDK. Therefore, the processing time delay of processing the management frame by the multi-link equipment is reduced, and the data processing efficiency is improved.
Owner:HUAWEI TECH CO LTD

Interaction control method, device and equipment in game and storage medium

This invention provides an interactive control method, apparatus, device, and storage medium for games. The method includes: during a game preparation phase, providing a game map corresponding to the game battle phase on a first terminal; responding to a route editing operation triggered by the game map, determining an action route set for the game battle phase, wherein the action route is used to guide a first character to perform actions during the game battle phase; responding to entering the game battle phase, displaying a game scene corresponding to the game battle phase on the first terminal, wherein the game scene includes at least a first character and a second character; and sending the action route to a second terminal to instruct the first character's action route on the second terminal. This embodiment reduces the data flow of voice communication, lowers resource consumption, maintains low game latency, reduces manual message editing operations, maintains message integrity, lowers communication costs between users, and improves collaboration efficiency between users.
Owner:GUANGZHOU BOGUAN TELECOMM TECH LTD

Internet of vehicles authentication method based on conditional privacy protection

The invention belongs to the technical field of digital information transmission, and particularly relates to an Internet of Vehicles authentication method based on conditional privacy protection, which comprises the following steps that: a trusted third-party mechanism and a key generation center issue parameters, and a vehicle and a road side unit make a registration request in the trusted third-party mechanism; the trusted third-party mechanism judges whether the registration request is accepted, and if the request is accepted, first anonymous information and second anonymous information are distributed; based on the first anonymous information or the second anonymous information, the key generation center generates a secret value and a part of private keys for the corresponding vehicle; when the vehicle enters the roadside unit area and a preset condition is established, the vehicle generates a temporary pseudonym based on the vehicle secret value, the timestamp and the first anonymous information, and forms a complete private key and a complete public key at the same time; before a vehicle broadcasts traffic information, a message signature is carried out to form a broadcast message tuple; and performing information verification on the broadcast message tuple, including verification of timestamp freshness and verification of message integrity, and accepting the message if the verification is passed.
Owner:BEIHANG UNIV

A method for securing multicast communications

The application discloses a multicast communication security guarantee method, comprising the following steps: a multicast sender periodically sends multicast messages; after a receiver receives the multicast messages, if there is no security check requirement for the received information, the receiver directly uses a security code to check the message integrity, directly uses the message after checking the message disorder, deletion and repetition according to a time stamp and a serial number; and if there is a security check requirement for the received information, the receiver performs security check, including verifying a security signature by using a pre-configured encryption algorithm and key, checking the message integrity, disorder, deletion and repetition, and performing delay check. The application can save communication bandwidth, reduce the number of links and simplify link management based on multicast mechanism transmission of security information.
Owner:浙江众合科技股份有限公司

Beacon extension design

PendingCN122460209ADevice typeStation
The present disclosure provides methods, components, devices, and systems for beacon extension design. A wireless station can receive one or more beacon containers including a beacon extension container and can communicate one or more messages based on a section of the one or more beacon containers related to the wireless station. Each section can correspond to a respective device type. Each section can include a frame check sequence and a message integrity code corresponding to each respective section. The wireless station can receive a first beacon container according to a first periodicity and a second beacon container according to a second periodicity. The first periodicity and the second periodicity can have different values based on a device type of the wireless station. The beacon container can include a type-specific section corresponding to the device type. Each type-specific section can include a parameter or updated information of the wireless station.
Owner:QUALCOMM INC

Protecting timing synchronization function values with security parameters

ActiveUS12634698B2Network topologiesSecurity arrangementBeacon frameTiming Synchronization Function
This disclosure provides methods, components, devices and systems for protecting timing synchronization function (TSF) values with message integrity checks (MICs). Various aspects relate generally to methods for a wireless device to protect the TSF field using an MIC. Some aspects more specifically relate to methods for the wireless device to include a MIC value generated using a TSF field of a beacon frame in a beacon extension frame. Some aspects more specifically relate to methods for the wireless device to include the MIC value generated using the TSF field in an information element (IE) of a beacon frame. In some examples, a vendor-specific (VS) IE or another IE. In some examples, the associated TSF field may be a TSF field of the beacon frame or of a recurring time epoch, such as a target beacon transmission time (TBTT) of the beacon frame.
Owner:QUALCOMM INC

Hardware maintenance system and method for sampling message integrity in airborne network

The invention discloses a hardware maintenance system and method for sampling message integrity in an airborne network, a sampling message receiving buffer area and a buffer area management register group are connected to a host interface management unit, and an address mark register group is connected to a receiving management unit and a receiving frame counting management unit. The receiving management unit is connected to a sampling message receiving buffer area through a data buffering and shunting controller; the receiving management unit is further connected to the msgID logic position management unit, the frame new / old state management unit and the buffer area effective state management unit, the frame new / old state management unit and the buffer area effective state management unit are connected to the buffer area management register set, and the host interface management unit is connected to the msgID logic position management unit.
Owner:XIAN AVIATION COMPUTING TECH RES INST OF AVIATION IND CORP OF CHINA

Communication method and apparatus, and communication device

PendingUS20250386192A1Signal allocationSecurity arrangementBeacon frameMessage integrity
A communication method and a communication device. In the method, a first device sends a beacon frame to a second device, and receives a first frame sent by the second device, the first frame carries a first message integrity code (MIC), and the first MIC is used for the first device to verify the legitimacy of the second device.
Owner:GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD

Lightweight encryption communication method for road traffic terminal

The invention discloses a lightweight encryption communication method suitable for a road traffic terminal. The method belongs to the technical field of information security and intelligent traffic. According to the method, when a terminal is activated for the first time, terminal identity initialization and key pre-distribution are realized through a physical security channel, and a master key seed is only stored in a security area. In the communication process, self-adaptive block encryption and a session key dynamic derivation mechanism are adopted for data, lightweight message authentication is combined, and message integrity and identity rapid verification are achieved. The method supports rapid updating and anomaly detection of the secret key, and obviously improves the anti-eavesdropping and replaying capabilities in the communication process. And after the session is finished, the temporary key and the cache are automatically and safely logged out, and a session abstract and an abnormal event record are generated according to an audit strategy, so that key leakage and sensitive data recovery are effectively prevented. The scheme has high security and resource friendliness, and is suitable for security communication requirements in a traffic terminal environment with limited resources.
Owner:ZHONGLU HI TECH TRAFFIC TECH GRP

Access point capabilities protection for enhanced open networks

A method is performed by a wireless client configured to communicate with wireless infrastructure equipment. The method comprises: upon connecting to the wireless infrastructure equipment without authenticating to the wireless infrastructure equipment, receiving from the wireless infrastructure equipment an individual probe protection key (IPPK) unique to the wireless client; storing the IPPK; sending to the wireless infrastructure equipment a probe request; receiving from the wireless infrastructure equipment a probe response that includes a message integrity check; validating the message integrity check using the IPPK; and accepting or rejecting the probe response depending on a result of validating.
Owner:CISCO TECHNOLOGY INC

Anti-quantum federated learning framework and training security processing method

The application relates to the technical field of distributed machine learning and network security, in particular to a quantum-resistant federated learning framework and a training security processing method. The quantum-resistant federated learning framework comprises at least one server and at least one client corresponding to each server; and a federated training scheduling module, a post-quantum key encapsulation module, a post-quantum digital signature algorithm module, a symmetric encryption protection module and a security verification and aggregation module respectively arranged on each server and each client. The framework can integrate the post-quantum secure communication capability by extending the gRPC transmission layer of Flower, improve the message confidentiality, message integrity, identity authentication and the continuity, security and controllability of the multi-round training process of the federated learning system under the threat of quantum computing, and be suitable for distributed collaborative modeling scenes such as medical treatment, finance, government affairs and industrial internet which have high requirements for communication security and long-term password strength.
Owner:SHANGHAI SECOND POLYTECHNIC UNIVERSITY

Data processing method, terminal, server, electronic device, and storage medium

The embodiment of the application provides a kind of data processing method, terminal, server, electronic equipment and storage medium, it is related to computer technical field.The method comprises: in response to selecting at least one target session message, display session verification control;In response to triggering the session verification control, display the message consistency verification result and / or message integrity verification result after the target session message is verified by session;Wherein, message consistency verification result is used to indicate whether target session message is tampered with;Message integrity verification result is used to indicate whether the context of target session message is tampered with.The embodiment of the application can avoid the disadvantages of not considering privacy and no knowledge caused by reproducing chat record content when verifying in prior art.
Owner:TENCENT TECHNOLOGY (SHENZHEN) CO LTD

Method and apparatus for protecting lower layer signaling

PendingUS20260067897A1Security arrangementTelecommunicationsMessage integrity
Various aspects of the present disclosure relate to a User Equipment (UE) configured to or operable to receive, from a network entity, a grant for a set of resources, generate a transport block (TB) for transmission, wherein the TB includes a first medium access control-control element (MAC-CE), select one of a first type of message authentication code for integrity (MAC-I) or a second type of MAC-I for validating the first MAC-CE, wherein the first type of MAC-I is different from the second type of MAC-I, and transmit, to the network entity, the TB using the set of resources, wherein the TB includes the first MAC-CE and the selected one of the first type of MAC-I or the second type of MAC-I.
Owner:LENOVO UNITED STATES INC

Quality of service (QoS) mapping method for fragmented internet protocol (IP) message

The invention belongs to the technical field of network communication, and particularly relates to a fragmented IP message QoS mapping method, which comprises the following steps of: obtaining message position information including message type results of an unfragmented message, a head fragment, a middle fragment and a tail fragment; obtaining a forwarding action, a header fragment mapping result and message identification information; obtaining an intermediate mapping result and a context release state of the intermediate fragment; obtaining a temporary mapping result and a message integrity judgment result; and executing coverage management based on the loop array to obtain a resource updating state. The technical problems that in the prior art, disordered arrival processing of fragmented messages is inconsistent, resources are released too early to cause matching failure due to the fact that tail fragmentation is carried out in advance, large storage space is occupied when packet loss suddenly occurs, and matching efficiency is low are effectively solved.
Owner:SHANGHAI BEITONG NAVIGATION TECH DEV CO LTD

Trigger frame with security user INFO field

Methods and apparatus are described for generating Trigger frames including specialized User Info fields. In an example method, a first device generates a Trigger frame for soliciting a responsive physical layer (PHY) protocol data unit (PPDU). The Trigger frame of includes at least one User Info field carrying uplink scheduling information for at least one recipient wireless device. The Trigger frame further includes a plurality of Security User Info fields, the plurality of Security User Info fields carrying a packet number (PN) and message integrity check (MIC) value (PN+MIC value). In other examples, the Trigger frame may include User Info fields carrying an intermediate Frame Check Sequence (I-FCS) and / or feedback information. The first device subsequently transmits the Trigger frame for reception by the at least one recipient wireless device.
Owner:NXP USA INC

Incorporating interrogation frame signature into message integrity check (MIC) of response frame

PendingCN121240080AError preventionSecurity arrangementComputer hardwareMessage integrity
The invention relates to integrating interrogation frame signatures into message integrity check (MIC) of response frames. Methods, systems, and computer readable media for performing operations including: receiving an interrogation frame from a device; generating a response frame including a message integrity check (MIC), wherein the MIC is determined based at least in part on one or more values of the interrogation frame; and transmitting the response frame to the device.
Owner:APPLE INC