Method of sequentially authenticating CAN packets using divided MACS and apparatus for implementing the same
US-9729535-B2 · Aug 8, 2017 · US
US9894081B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-9894081-B2 |
| Application number | US-201715491663-A |
| Country | US |
| Kind code | B2 |
| Filing date | Apr 19, 2017 |
| Priority date | Apr 20, 2016 |
| Publication date | Feb 13, 2018 |
| Grant date | Feb 13, 2018 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
A method and device for avoiding manipulation of a data transmission. A message containing a message authentication code is received at a processing unit, the message from the processing unit is transferred to a hardware module, a check value as a function of the received message is computed in the hardware module, the received message authentication code and the check value are compared in the hardware module, a result of the comparison is transferred from the hardware module to the processing unit as an output variable, the message authentication code received in the message from the processing unit is checked in the processing unit based on the output variable.
Opening claim text (preview).
What is claimed is: 1. A method far avoiding manipulation of a data transmission, comprising: receiving, at a processing unit, a message containing a message authentication code; transferring the message from the processing unit to a hardware module; computing, in the hardware module, a check value as a function of the received message; comparing, in the hardware module, the received message authentication code and the check value; transferring a value that indicates a result of the comparison and the check value from the hardware module to the processing unit; checking, in the processing unit, the value that indicates the result of the comparison; and checking, in the processing unit, the message authentication code received in the message at the processing unit based on the check value. 2. The method as recited in claim 1 , wherein the value of the result of the comparison is set to a value that signals that the received message authentication code and the check value match. 3. The method as recited in claim 1 , wherein the message authentication code is a cipher-based message authentication code. 4. A device for avoiding manipulation of a data transmission, the device comprising: a processing unit; and a hardware module; the device designed to: receive, at the processing unit, a message containing a message authentication code; transfer the message from the processing unit to the hardware module; compute, in the hardware module, a check value as a function of the received message; compare, in the hardware module, the received message authentication code and the check value; transfer a value that indicates a result of the comparison and the check value from the hardware module to the processing unit; check, in the processing unit, the value that indicates the result of the comparison; and check, in the processing unit, the message authentication code received in the message at the processing unit based on the check value. 5. A non-transitory computer readable storage medium on which is stored a computer program for avoiding manipulation of a data transmission, the computer program, when executed by a processor, causing the processor to perform: receiving, at a processing unit, a message containing a message authentication code; transferring the message from the processing unit to a hardware module; computing, in the hardware module, a check value as a function of the received message; comparing, in the hardware module, the received message authentication code and the check value; transferring a value that indicates a result of the comparison and the check value from the hardware module to the processing unit; checking, in the processing unit, the value that indicates the result of the comparison; and checking, in the processing unit, the message authentication code received in the message at the processing unit based on the check value.
received data contents, e.g. message integrity · CPC title
Active attacks involving interception, injection, modification, spoofing of data unit addresses, e.g. hijacking, packet injection or TCP sequence number attacks · CPC title
involving keyed hash functions, e.g. message authentication codes [MACs], CBC-MAC or HMAC · CPC title
Vehicles · CPC title
using a predetermined code, e.g. password, passphrase or PIN (network architectures or network communication protocols for supporting authentication of entities using passwords in a packet data network H04L63/083) · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.