Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

55 results about "Message integrity" patented technology

Definition of: message integrity. message integrity. The validity of a transmitted message. Message integrity means that a message has not been tampered with or altered. The most common approach is to use a hash function that combines all the bytes in the message with a secret key and produces a message digest that is difficult to reverse.

Safety transmission system based on multimedia short message

The invention discloses a secure transmission system based on a multimedia short message, and relates to the technical field of communication and network security, and the system comprises a protocol stack security reinforcement module which carries out the hierarchical reconstruction of an MMS protocol stack, comprises a preprocessing layer, is used for intercepting and filtering illegal characters, and verifies the legality of a message structure through a finite-state machine; the analysis layer is used for pre-judging memory requirements based on message types and lengths by adopting a dynamic memory allocation strategy; the execution layer is integrated with a null pointer checking mechanism, and the validity of a pointer is forcibly verified before a protocol stack calls a function; the encryption and signature module is used for carrying out end-to-end encryption on a message body and metadata by adopting a hybrid encryption algorithm and carrying out message integrity verification through a lightweight hash tree; and the vulnerability real-time monitoring module is embedded into an abnormal behavior detection model based on machine learning and is used for dynamically identifying memory occupation abnormity and illegal instruction calling high-risk operation when the protocol stack runs.
Owner:BEIJING XUNYIN TECH CO LTD

Methods, systems, and computer readable media for providing end-to-end message integrity checking for service-based interface (SBI) messages communicated via a service communication proxy (SCP)

A method for checking end-to-end SBI message integrity includes receiving a first traffic feed from a first NF, the first traffic feed including copies of SBI messages transmitted from the first NF to an SCP. The method further includes receiving a second traffic feed from a second NF, the second traffic feed including copies of SBI messages received by the second NF from the SCP. The method further includes identifying, from the first traffic feed, a copy of a first SBI message transmitted by the first NF to the SCP. The method further includes identifying, from the second traffic feed, a copy of a second SBI message received by the second NF from the SCP and that is associated with the copy of the first SBI message. The method further includes performing, using the message copies, an end-to-end SBI message integrity check for the first SBI message.
Owner:ORACLE INT CORP

Communications Systems with Control Frame Protection

A communication system is provided in which access points (APs) communicate with stations (STAs). An AP may communicate with a STA according to a multiple basic service set identifier (M-BSSID) scheme. The AP may transmit an initial control frame (ICF) to STAs associated with different BSSIDs of the AP. The AP may integrity protect the ICF by generating one or more control message integrity checks (CMICs) and inserting the CMIC(s) into the ICF. The AP may generate a common CMIC shared across BSSIDs using a control frame integrity group temporal key (CIGTK) that is BSSID-specific or BSSID-independent. A BSSID-independent CIGTK may be a newly defined or may be a beacon integrity group temporal key (BIGTK). As another example, the AP may generate different CMICs in the ICF for each BSSID using different BSSID-specific CIGTKs for each BSSID.
Owner:APPLE INC

Communication system with header and acknowledgement integrity protection

The invention relates to a communication system with header and acknowledgement integrity protection. A communication system is provided in which an access point (AP) communicates with a station (STA). The AP and STA may transmit an integrity protection frame. The AP and STA may perform an integrity check on the integrity protection frame. The AP and STA may transmit an integrity protection block acknowledgement (BA) frame in response to receiving the integrity protection frame. The AP and STA may perform an integrity check on the integrity protection BA frame. Padding may be inserted into the integrity protection frame and / or BA frame to accommodate processing delays associated with generating and verifying message integrity checks (MICs) in the frame and / or BA frame. An integrity check may be performed on a corresponding BA frame before, after, or before and after transmission of the frame.
Owner:APPLE INC

Method for provisioning credentials to user equipment in a private telecommunications network - Patent Application 20070122997

The present invention proposes a method for provisioning a credential to a user equipment (10) in a private telecommunications network, the private telecommunications network including a credential holder and a gNB / AMF or eNB / MME, the method comprising: a) sending a provisioning request (40) from the user equipment (10) to the gNB / AMF or eNB / MME (11); b) establishing a PLS key (41) between the user equipment (10) and the gNB / AMF or eNB / MME (11) by physical layer security; c) providing a PLS key to the user equipment (10) via a PLS key; d) transmitting 43 a message from the user equipment 10 to the gNB / AMF or eNB / MME 11, the message including data permitting identification of the user of the user equipment 10 and / or the user equipment 10 and the master key, the message being integrity and confidentiality protected by a PLS key or a key derived from the PLS key; e) transmitting 44 a message from the gNB / AMF or eNB / MME 11 to the credential holder 12, the message including data permitting identification of the user of the user equipment 10 and / or the user equipment 10 and the master key, the message being integrity and confidentiality protected by a PLS key or a key derived from the PLS key. f) verifying in the credential holder (12) the data that allows identifying the user of the user equipment (10) and / or the user equipment (10); g) if the verification is positive, assigning in the credential holder (12) a unique subscription identifier to the user equipment (10) and generating corresponding keys, security parameters, and key derivation functions; h) transmitting the unique subscription identifier from the credential holder (12) to the gNB / AMF or eNB / MME (11). i) transmitting the unique subscription identifier, security parameters, and key derivation function from the gNB / AMF or eNB / MME (11) to the user equipment (10) in a message integrity and confidentiality protected by a PLS key or a key derived from the PLS key (47); j) generating a final key at the user equipment (10), the final key being a credential including the unique subscription identifier, security parameters, and final key (48);Including.
Owner:THALES SA +1

Biometric Sender Verification System for Electronic Messaging

A system is presented for verifying the human sender of an electronic message using biometrics and securely transmitting the verification status to recipients. The sender registers an email account and provides a biometric sample. A public / private key pair is generated to encrypt a unique account identifier. When sending a message, the user authenticates with biometrics. The account identifier is encrypted with the private key and transmitted with the email. The receiving server decrypts the identifier using the sender's public key and verifies it matches the sender address. If matched, the message is tagged as verified. The invention prevents email spoofing by binding the user's identity to their account with biometrics. Encrypted verification data prevents tampering. Recipients can trust message integrity as the expected human sender is cryptographically verified.
Owner:OWENS NICHOLAS

5G message transmission method, device, electronic device and storage medium

The present invention provides a 5G message transmission method, apparatus, electronic device, and storage medium, including: receiving an HTTP / 2 message, determining whether the current framed message in the HTTP / 2 message is the last framed message based on a structure; if it is determined to be the last framed message, assembling the framed message and verifying the message integrity. By proposing a method for framing and assembling HTTP / 2 messages and retransmitting them for 5G communications, the present invention enables a server to quickly assemble a complete message body after receiving a framed message, immediately freeing up memory space occupied by the message, and completing message validity and integrity verification.
Owner:CHINA MOBILE GROUP JIANGSU +1

Counter mode with encrypted block link message authentication code protocol (CCMP) encapsulation and de-encapsulation including multi-link operation for enhanced privacy frames

In a counter mode with encrypted block link message authentication code protocol (CCMP) encryption encapsulation, a station (STA) may incrementally increase a packet number (PN). The STA may construct additional authentication data (AAD) based on a plain text medium access control (MAC) protocol data unit (MPDU) header and an association with authentication medium access control (aaMAC) address. The STA may construct a random number based on the aaMAC address, the PN, and the priority value of the MPDU. The STA may form an encrypted message integrity code (MIC) based on the ADD and the random number. The STA may form an encrypted MPDU based on the MPDU header, the ciphertext, the MIC, and the CCMP header. The STA may then transmit the encrypted MDPU. The aaMAC address may be different from a multi-link device (MID) MAC address. The STA may be in non-multilink operation (MLO) communication with an access point (AP).
Owner:INTERDIGITAL PATENT HOLDINGS INC

Power efficient data polling by a wireless mesh network device

Methods and device architectures for improving the energy efficiency of end devices in a wireless mesh network. In an example, an end device of the network includes a wireless transceiver, a first processing core configured to implement a media access control layer (MAC), and a second processing core configured to implement a physical layer (PHY). The PHY operates to receive a first data poll message from the MAC and transmit the message to an external device via the wireless transceiver. The PHY further operates to receive an acknowledge message including a frame pending value. If the frame pending value indicates that the external device does not have buffered data for the end device, the PHY generates a second data poll message based on the first data poll message, including incrementing one or more of a sequence number field value, a frame counter field value, and a message integrity check field of the first data poll message, thereby enabling the MAC to remain in a low power state while the PHY transmits the second data poll message.
Owner:NXP USA INC

Securing control frames in wireless networks

An embodiment is a method performed by a wireless device to secure a control frame. The method includes generating the control frame, wherein the control frame includes a key ID field that appears before at least one field included in a body of the control frame and a message integrity check (MIC) field that appears after the at least one field, wherein the key ID field carries a key ID and a packet number, wherein the MIC field carries an authentication value for checking an integrity of the control frame. The method further includes transmitting the control frame.
Owner:NEWRACOM INC

Secure control frames in wireless communications

This disclosure provides methods, components, devices and systems for secure control frames in wireless communications. Some aspects more specifically relate to security for control frames based on one or more fields included in the control frames. In some examples, a frame is transmitted with a control message integrity check (MIC) field (CMF) that includes an identifier of a security key, at least a portion of a packet number (PN), and at least a portion of an integrity check computed based on one or more portions of the frame including the control information and the security key. The CMF may be transmitted is separate parts, such as a first portion of the CMF that includes the identifier of the security key and at least the portion of the PN, and a second portion of the CMF that includes at least a truncated portion of the integrity check.
Owner:QUALCOMM INC

A secure and efficient authentication method for smart devices based on alliance chain

The present invention discloses a secure and efficient authentication method for smart devices based on a consortium chain. The method is as follows: Step 1: A registration agency generates a challenge set and sends it to a sensor device. The sensor device calculates a response using a PUF and maps it to an elliptic curve group element. The final information is stored on the consortium chain; Step 2: The sensor device generates a signature and constructs a zero-knowledge proof, ensures message integrity and authentication by using the Fiat-Shamir heuristic transformation, and sends the generated proof to an edge device; Step 3: The edge device uses the received pseudonym and proof to verify the identity of the sensor device and the legitimacy of the message. After successful verification, the edge device adds the pseudonym to the used list and records the verification result in the consortium chain to ensure data transparency and immutability. The present invention enhances the security of device authentication and is suitable for scenarios such as the industrial Internet of Things that require high security and privacy protection.
Owner:HARBIN INST OF TECH

Malicious node detection method and apparatus, malicious node defense method and apparatus, and device

PCT designated stageWO2026108501A1Security arrangementData packDecision model
The present application discloses a malicious node detection method and apparatus, a malicious node defense method and apparatus, and a device. The malicious node detection method comprises: on the basis of monitoring data of nodes in a network, determining forwarding success rates, message integrity, energy levels and resource scores of the nodes, wherein the message integrity represents the integrity of data packets forwarded by the nodes, the energy levels represent the activity levels and states of charge of the nodes, and the resource scores represent the transmission capabilities of the nodes; determining comprehensive trust values of the nodes on the basis of the forwarding success rates, message integrity and energy levels of the nodes, wherein the comprehensive trust values represent the credibility of the nodes; and inputting the comprehensive trust values, message integrity and resource scores of the nodes into a pre-trained classification decision model, and classifying the nodes into trusted nodes and untrusted nodes on the basis of the outputted classification results. In the present application, untrusted nodes can be identified before malicious behavior is fully exposed, thereby improving the overall security of a network.
Owner:CHINA TELECOM NETWORK SECURITY TECH CO LTD

Communication system with control frame protection

The invention relates to a communication system with control frame protection. A communication system is provided in which an access point (AP) communicates with a station (STA). The AP may communicate with the STA according to a multi-basic service set identifier (M-BSSID) scheme. The AP may transmit an initial control frame (ICF) to an STA associated with a different BSSID of the AP. The AP may integrity protect the ICF by generating one or more control message integrity checks (CMICs) and inserting the CMICs into the ICF. The AP may use a BSSID-specific or BSSID-independent Control Frame Integrity Group Temporary Key (CIGTK) to generate a common CMIC that is shared across the BSSID. The CIGTK independent of the BSSID may be a newly defined Beacon Integrity Group Temporary Key (BIGTK), or may be a Beacon Integrity Group Temporary Key (BIGTK). As another example, the AP may generate a different CMIC for each BSSID in the ICF using a different BSSID-specific CIGTK for each BSSID.
Owner:APPLE INC

Methods, systems, and computer readable media for providing end-to-end message integrity checking for service-based interface (SBI) messages communicated via a service communication proxy (SCP)

A method for checking end-to-end SBI message integrity includes receiving a first traffic feed from a first NF, the first traffic feed including copies of SBI messages transmitted from the first NF to an SCP. The method further includes receiving a second traffic feed from a second NF, the second traffic feed including copies of SBI messages received by the second NF from the SCP. The method further includes identifying, from the first traffic feed, a copy of a first SBI message transmitted by the first NF to the SCP. The method further includes identifying, from the second traffic feed, a copy of a second SBI message received by the second NF from the SCP and that is associated with the copy of the first SBI message. The method further includes performing, using the message copies, an end-to-end SBI message integrity check for the first SBI message.
Owner:ORACLE INT CORP

User identity verification method and device, equipment, storage medium and product

The invention discloses a user identity verification method and device, equipment, a storage medium and a product, and relates to the technical field of secure digital identity verification, and the method comprises the steps: storing biological characteristic data in an SIM card with high performance, and when a user needs to perform identity verification, sending the biological characteristic data to the SIM card; the platform side can read the biological characteristic data in the SIM card in various modes to realize complex biological characteristic data comparison; when the SIM card feeds back data, the biological characteristic metadata and the biological characteristic vector are encrypted in different modes in a segmented manner, so that secret key updating is realized in a biological characteristic information encryption process with a relatively high security requirement, and the security is improved; and meanwhile, signature verification and MAC message check codes are added to the whole data ciphertext, so that the message integrity and non-repudiation are ensured.
Owner:CHINA MOBILE FINANCIAL TECHNOLOGY CO LTD +1

Power efficient data polling by a wireless mesh network device

Methods and device architectures for improving the energy efficiency of end devices in a wireless mesh network. In an example, an end device of the network includes a wireless transceiver, a first processing core configured to implement a media access control layer (MAC), and a second processing core configured to implement a physical layer (PHY). The PHY operates to receive a first data poll message from the MAC and transmit the message to an external device via the wireless transceiver. The PHY further operates to receive an acknowledge message including a frame pending value. If the frame pending value indicates that the external device does not have buffered data for the end device, the PHY generates a second data poll message based on the first data poll message, including incrementing one or more of a sequence number field value, a frame counter field value, and a message integrity check field of the first data poll message, thereby enabling the MAC to remain in a low power state while the PHY transmits the second data poll message.
Owner:NXP USA INC

Method and apparatus for enhanced security in wireless LAN system

Disclosed are a method and apparatus for enhanced security in a wireless LAN system. A method performed by a first station (STA) in a wireless LAN system, according to an embodiment of the present disclosure, may comprise the steps of: constructing additional authentication data (AAD) on the basis of one or more fields or subfields of a medium access control (MAC) header of an MAC protocol data unit (MPDU); and transmitting, to a second STA, a physical layer PDU (PPDU) including the MPDU configured on the basis of the AAD. The MPDU includes a message integrity check (MIC) field, and a value of the MIC field may be based on at least the AAD. The one or more fields or subfields of the MAC header may include one or more of a duration / identifier (ID) field or at least a part of a high throughput (HT) control field.
Owner:LG ELECTRONICS INC

Method for autonomous integrity monitoring of navigation satellite messages

The application provides a navigation satellite message autonomous integrity monitoring method, which comprises the following steps: calculating first state information at a predetermined time through extrapolation based on historical navigation message parameters of an on-board message, and calculating second state information according to navigation message parameters of a new on-board message on the predetermined time, calculating a first difference between the two; obtaining regional system signals and global system signals on the same time, and calculating corresponding state information and a second difference between the state information; judging whether the first difference and the second difference exceed corresponding alarm thresholds, and if both exceed, generating an alarm information of the message integrity. Thus, the application can realize on-board message autonomous integrity monitoring, can monitor and alarm abnormalities of the message caused by uplink injection, malicious tampering and the like, and prevent error positioning results caused by the error message broadcast to the ground users.
Owner:CHINA ACADEMY OF SPACE TECHNOLOGY

Transaction System and Method

The invention relates to systems and methods for executing a digital-asset transaction using a dual-tier messaging architecture. A central messaging server provides tamper detection and message-integrity verification while routing bilateral messages between transacting devices. A permissioned-blockchain channel manages a smart-contract escrow that holds digital assets in cold storage. A fiat-rail channel integrates a real-time payment protocol to obtain bank or rail confirmation that fiat funds are credited to a seller account. Upon receipt of settlement evidence and a validated session state, the escrow releases the digital asset from a seller cold-storage wallet to a buyer cold-storage wallet. Embodiments may capture a seller opt-in via a banking application, generate a dual-ledger audit trail across permissioned and public blockchains, and emit transaction identifiers for cross-system reconciliation. The approach improves compliance, reduces counterparty risk, and provides verifiable audit artifacts for regulated settlement of digital-asset transfers.
Owner:HONEYWELL SEAN WILLIAM

Quantum key transmission methods, devices and systems

This application discloses a quantum key transmission method, apparatus, and system, belonging to the field of network technology. An application device sends a key request message to a quantum device. This message includes a user identifier corresponding to the application device, a first public key, and a first message authentication code value. If the quantum device verifies the first message authentication code value, it sends a key response message to the application device. This response message includes a first ciphertext and a second message authentication code value. If the application device verifies the second message authentication code value, it uses a first private key to decrypt the first ciphertext to obtain the quantum key information assigned to it by the quantum device. The first public key and the first private key are a key pair obtained by the quantum key generation algorithm run by the application device. This application achieves two-way authentication and message integrity verification between the application device and the quantum device, while also ensuring the confidentiality of quantum key transmission.
Owner:HUAWEI TECH CO LTD

Wireless network handover method and apparatus

The application discloses a wireless network switching method, in which a requesting device and a target access device directly generate a message integrity check key through a domain key, and verify an integrity check code based on the message integrity check key, so that identity authentication of both sides is realized; when the identity authentication of both sides is passed, a session key is generated by combining the domain key and random numbers of both sides, so that the switching process is simplified, and safe and efficient network switching is realized. The application also discloses corresponding requesting devices and access devices.
Owner:CHINA IWNCOMM

PKI-to-IBC heterogeneous broadcast signcryption and key negotiation method oriented to Internet of Things communication equipment

The invention discloses a PKI-to-IBC heterogeneous broadcast signcryption and key negotiation method oriented to Internet of Things communication equipment. The method sequentially comprises six stages of system initialization, data collection base station registration, terminal sensing equipment registration, heterogeneous signcryption, de-signcryption and key negotiation. In a system initialization stage, a registration management mechanism generates elliptic curve parameters and a system master key, and issues system parameters including a system public key, a related hash function and the like; in the registration stage, a data collection base station obtains a digital certificate through a PKI mechanism, and terminal sensing equipment obtains a private key and public key reconstruction factor through an IBC mechanism; in the signcryption stage, the data collection base station signcrypts messages based on a broadcast mechanism and sends the messages to multiple devices at the same time; in the de-signcryption stage, the terminal sensing device verifies the message integrity and the source legality by using the own key; in the key negotiation stage, the data collection base station and the terminal sensing device cooperatively generate a shared session key and establish a secure communication channel.
Owner:WUHAN UNIV

Key-based authentication for a mobile edge computing network

Apparatuses, methods, and systems are disclosed for key-based authentication for a mobile edge computing network. One method (800) includes deriving (805), at a user equipment, a first network key after authentication with a network function of a wireless core network, deriving (810) a second network key based on the first network key, the second network key for a first network function of a mobile edge computing network, sending (815) a registration request message to the first network function of the mobile edge computing network, the registration request message integrity protected with the second network key, receiving (820) a registration response message from the first network function, and, in response to verifying the integrity of the registration response message using the second network key, establishing (825) a secure communication with the first network function of the mobile edge computing network based on the second network key.
Owner:LENOVO (BEIJING) LTD

Encryption authentication method based on hash function and Feistel structure

The invention relates to the technical field of information security, and provides an encryption authentication method based on a hash function and a Feistel structure, the encryption authentication method comprises an encryption authentication algorithm and a decryption verification algorithm, the encryption authentication method is realized by taking the Feistel structure as a password structure, selecting a hash function as a round function of the Feistel structure, and instantiating the round function into a hash function. According to the invention, encryption and decryption and message integrity verification can be carried out. The plaintext length and the secret key length are selectable, and the method is high in universality, good in expansibility, low in error code diffusion and high in safety. The method can be widely applied to wireless communication environments such as satellite internet and internet of things.
Owner:SPACE STAR TECH CO LTD +1

Wireless communication method and apparatus, and device and storage medium

The present application belongs to the technical field of communications. Disclosed are a wireless communication method and apparatus, and a device and a storage medium. The wireless communication method in the embodiments of the present application comprises: a first terminal device receiving first information, wherein the first information comprises first challenge information; sending first authentication information and second information to a first communication node; and the first communication node executing a first operation and a second operation, wherein the first operation comprises verifying the first authentication information on the basis of third authentication information, and the second operation comprises at least one of the following: decrypting third information on the basis of a second key, verifying first message integrity check information on the basis of a third key, the third information or fifth information, and at least one of the following: the first challenge information and the first authentication information, and verifying second message integrity check information on the basis of a fourth key, fourth information or sixth information, and at least one of the following: the first challenge information and the first authentication information.
Owner:VIVO MOBILE COMM CO LTD

Communication method, device and system

The invention discloses a communication method, device and system, and relates to the technical field of communication. The present application supports an Institute of Electrical and Electronic Engineers (IEEE) protocol, such as an IEEE 802.11 be / Wi-Fi 7 / EHT protocol, an IEEE 802.11 bn / UHR / Wi-Fi 8 protocol, an Integrating mmWave / Integrated Millimeter Wave / IMMW protocol, an IEEE 802.15 / UWB protocol, or an IEEE 802.11 bf / sensing / perceptual protocol, for example, an IEEE (Institute of Electrical and Electronic Engineers) protocol. The method comprises the following steps: a first site generates a management frame and sends the management frame to a second site; the management frame comprises a first message complete check code obtained based on a first secret key, and the first secret key is generated based on address information related to the first link and KDK. Therefore, the processing time delay of processing the management frame by the multi-link equipment is reduced, and the data processing efficiency is improved.
Owner:HUAWEI TECH CO LTD

Communication method and apparatus, and communication device

Provided in an embodiment of the present application are a communication method and apparatus, and a communication device, the method comprising: a first device sending a beacon frame to a second device, and receiving a first frame sent by the second device; wherein the first frame carries a first message complete code MIC, and the first MIC is used by the first device to verify the legality of the second device.
Owner:GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD

Interaction control method, device and equipment in game and storage medium

This invention provides an interactive control method, apparatus, device, and storage medium for games. The method includes: during a game preparation phase, providing a game map corresponding to the game battle phase on a first terminal; responding to a route editing operation triggered by the game map, determining an action route set for the game battle phase, wherein the action route is used to guide a first character to perform actions during the game battle phase; responding to entering the game battle phase, displaying a game scene corresponding to the game battle phase on the first terminal, wherein the game scene includes at least a first character and a second character; and sending the action route to a second terminal to instruct the first character's action route on the second terminal. This embodiment reduces the data flow of voice communication, lowers resource consumption, maintains low game latency, reduces manual message editing operations, maintains message integrity, lowers communication costs between users, and improves collaboration efficiency between users.
Owner:GUANGZHOU BOGUAN TELECOMM TECH LTD

Internet of vehicles authentication method based on conditional privacy protection

The invention belongs to the technical field of digital information transmission, and particularly relates to an Internet of Vehicles authentication method based on conditional privacy protection, which comprises the following steps that: a trusted third-party mechanism and a key generation center issue parameters, and a vehicle and a road side unit make a registration request in the trusted third-party mechanism; the trusted third-party mechanism judges whether the registration request is accepted, and if the request is accepted, first anonymous information and second anonymous information are distributed; based on the first anonymous information or the second anonymous information, the key generation center generates a secret value and a part of private keys for the corresponding vehicle; when the vehicle enters the roadside unit area and a preset condition is established, the vehicle generates a temporary pseudonym based on the vehicle secret value, the timestamp and the first anonymous information, and forms a complete private key and a complete public key at the same time; before a vehicle broadcasts traffic information, a message signature is carried out to form a broadcast message tuple; and performing information verification on the broadcast message tuple, including verification of timestamp freshness and verification of message integrity, and accepting the message if the verification is passed.
Owner:BEIHANG UNIV