Method of and system for authenticating and operating personal communication devices over public safety networks
US-9332431-B2 · May 3, 2016 · US
US11212118B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-11212118-B2 |
| Application number | US-201816627622-A |
| Country | US |
| Kind code | B2 |
| Filing date | Jun 18, 2018 |
| Priority date | Jul 26, 2017 |
| Publication date | Dec 28, 2021 |
| Grant date | Dec 28, 2021 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
The application relates to a method for checking the data transport across a first communication connection between two data processing devices, said first communication connection being realized between two first interface units, wherein the payload to be transferred can be divided into payload blocks and there is at least one second communication connection between the data processing devices, which is established by means of second interface units, and wherein, in order to implement a challenge-response authentication, a request requiring retrieval of randomly selected data units from identifiable, randomly selected payload blocks of the payload is sent as a challenge by an authentication unit to the first interface units by means of the second communication connection, an authentication assembly of each of the first interface units extracts the requested response data from the payload and transmits the same back to the authentication unit and a successful check is determined if the response data match.
Opening claim text (preview).
The invention claimed is: 1. A method for checking a data transportation between a first data processing device and a second data processing device in an apparatus, the method comprising: sending, by the first data processing device, a transmitting payload to the second data processing device through a first communication connection, wherein the transmitting payload is divided into payload blocks and the first communication connection is realized between a first interface unit of the first data processing device and a first interface unit of the second data processing device; sending, by a first authentication unit of the first data processing device, a request to the first interface unit of the first data processing device, wherein the request requires data units in randomly selected positions of randomly selected and identifiable payload blocks; sending to the first interface unit of the second data processing device, by the first authentication unit of the first data processing device, the request through a second communication connection, wherein the second communication connection is realized between a second interface unit of the first data processing device and a second interface unit of the second data processing device; extracting, by a first authentication assembly of the first interface unit of the first data processing device, first response data from the transmitting payload based on the request; receiving, by the first authentication unit, the first response data from the first interface unit of the first data processing device; receiving, by the first authentication unit, second response data from the second data processing device, wherein the second response data is extracted by a second authentication assembly of the first interface unit of the second data processing device from a receiving payload based on the request; and determining, by the first authentication unit, a successful check result if the first response data match the second response data. 2. The method according to claim 1 , wherein the first data processing unit is a control unit and the second data processing unit is a display apparatus, wherein the transmitting payload includes image data that are to be displayed on the display apparatus, wherein the image data have payload structures separated by frame-start indicators which form the payload blocks. 3. The method according to claim 1 , wherein the first interface unit of the first data processing unit and the first interface unit of the second data processing unit are designed as microchips and the first authentication assembly and the second authentication assembly are integrated into the microchips. 4. The method according to claim 3 , wherein the first and second authentication assemblies have cyclically resetting counters for the payload blocks, wherein the request is based on a counter pass, wherein the counter pass is generated from the cyclically resetting counters and used to identify the payload blocks. 5. The method according to claim 4 , wherein the request is sent at a beginning of the counter pass, wherein the payload has a head section, a middle section and a trail section, and the counter pass indicates the payload blocks in the middle section, wherein the middle section is decided such that the request reaches the second authentication assembly of the second data processing device before a first payload block required by the request reaches the first interface unit of the second data processing device and the second response data reach the first authentication unit of the first data processing unit before an end of the counter pass. 6. The method according to claim 1 , wherein identification data for identifying the payload blocks are written in free areas of the payload blocks. 7. The method according to claim 1 , wherein the second communication connection is encrypted by means of a key stored in the second interface unit of the first data processing device and the second interface unit of the second data processing device. 8. The method according to claim 7 , wherein the key is different from a second key used in a second apparatus having at least two data processing devices. 9. The method according to claim 1 , further comprising: sending, by the first interface unit of the first data processing device, the transmitting payload to a first interface unit of a third data processing device; sending, by the first authentication unit of the first data processing device, a second request to the first interface unit of the first data processing device; sending, by the first authentication unit of the first data processing device, the second request to the first interface unit of the third data processing device; receiving, by the first authentication unit of the first data processing device, third response data from the first interface unit of the first data processing device based on the second request; receiving, by the first authentication unit, fourth response data from the third data processing device based on the second request; and determining, by the first authentication unit, a second successful check result if the third response data match the fourth response data. 10. The method according to claim 9 , wherein the transmitting payload includes payload blocks associated with the second data processing device and payload blocks associated with the third data processing device, wherein the first request requires the payload blocks associated with the second data processing device and the second request requires the payload blocks associated with the third data processing device. 11. The method according to claim 10 , further comprising: removing, by the second data processing device, the payload blocks associated with the second data processing unit from the receiving payload to form a modified receiving payload; sending, by the second data processing device, the modified receiving payload to a fourth data processing device; generating, by the first data processing device, a third request based on the modified receiving payload; and sending, by the first data processing device, the third request to the fourth data processing device. 12. The method according to claim 9 , further comprising: sending, by the second data processing device, a fourth request to the fourth data processing device if information of the modified receiving payload is not available to the first data processing device, wherein the fourth request is based on the modified receiving payload; sending, by a second authentication unit of the second data processing device, the fourth request to the first interface unit of the second data processing device; receiving, by the second authentication unit, fifth response data from the first interface unit of the second data processing device based on the fourth request; receiving, by the second authentication unit, sixth response data from the fourth data processing device based on the fourth request; and determining, by the second authentication unit, a third successful check result if the fifth response data match the sixth response data. 13. The method according to claim 1 , wherein the first authentication unit is integrated in the second interface unit of the first data processing device. 14. The method according to claim 1 , wherein the first data processing device is a control device of a motor vehicle and the second data processing device is a display apparatus of the motor vehicle. 15. A motor vehicle comprises a first data processing devices and a second processing device, wherein the first data processing device is configured
using challenge-response · CPC title
specially adapted for proprietary or special-purpose networking environments, e.g. medical networks, sensor networks, networks in vehicles or remote metering networks · CPC title
using different networks or channels, e.g. using out of band channels (cryptographic mechanisms or cryptographic arrangements for key distribution involving distinctive intermediate devices or communication paths H04L9/0827; cryptographic mechanisms or cryptographic arrangements for authentication using a plurality of channels H04L9/3215) · CPC title
using separate channels for security data · CPC title
Authentication · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.