IP Library Granted Patent US 12,250,321
Granted Patent B2
US 12,250,321 · App. 17/429,137 · Granted Mar 11, 2025

Method for authenticating messages in resource limited systems

Inventors: Dacfey Dzung (Wettingen, CH); Thanikesavan Sivanthi (Würenlingen, CH)
Assignee: Hitachi Energy Ltd
H04L9/3242H04L9/50H04L2209/30
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,250,321
App. No.
17/429,137
Granted
Mar 11, 2025
Kind
B2
Abstract

The present invention provides a method for message authentication, in particular in case of low of transmission or storage capacities. The present invention further provides corresponding devices for generating or sending authenticated messages and for receiving or retrieving authenticated messages as well as a system comprising such devices. In an embodiment, the method may comprise (a) preparing a data block having an uncompressed length; (b) compressing the data block so that the data block has a compressed length smaller than the uncompressed length; (c) determining an available length from at least the compressed length and a maximum length of a data frame; (d) calculating a message authentication code, MAC, from at least the data block, having a MAC length not greater than the available length; and (e) creating the data frame, comprising the data block and the MAC.

Claims (57)

1. A method for message authentication, comprising preparing a data block having a block length;

determining an available length based on the block length and a maximum length of a data frame;

calculating a message authentication code (MAC) based on the data block, the MAC having a MAC length not greater than the available length;

calculating an additional MAC based on the data block, the additional MAC having an additional MAC length not greater than the available length;

creating the data frame that comprises the data block and the MAC; and

creating an additional data frame that comprises the data block and the additional MAC.

2. The method of claim 1 , further comprising encrypting the data block.

3. The method of claim 1 , further comprising transmitting or storing the data frame and transmitting or storing the additional data frame.

4. The method of claim 3 , wherein the MAC or the additional MAC is calculated based on the data block and a previously transmitted or stored data block.

5. The method of claim 3 , further comprising:

receiving or retrieving the data frame and the additional data frame; and

verifying the MAC and the additional MAC.

6. The method of claim 5 , further comprising attributing a trust level to the data frame and to the additional data frame.

7. The method of claim 6 , further comprising verifying that the trust level is above a threshold of acceptance.

8. The method of claim 5 , further comprising attributing a trust level to the data block and verifying that the trust level is above a threshold of acceptance.

9. The method of claim 1 , wherein preparing the data block comprises:

preparing the data block having an uncompressed length; and

compressing the data block to obtain a compressed data block that has a compressed length that is smaller than the uncompressed length, the compressed length being the block length.

10. The method of claim 9 , further comprising encrypting the data block.

11. The method of claim 9 , further comprising transmitting or storing the data frame.

12. The method of claim 11 , wherein the MAC is calculated based on the data block and a previously transmitted or stored data block.

13. The method of claim 11 , further comprising receiving or retrieving the data frame and verifying the MAC.

14. The method of claim 13 , further comprising attributing a trust level to the data frame and verifying that the trust level is above a threshold of acceptance.

15. The method of claim 13 , further comprising attributing a trust level to the data block.

16. The method of claim 15 , further comprising verifying that the trust level is above a threshold of acceptance.

17. The method of claim 9 , further comprising:

preparing a second data block having a second uncompressed length;

compressing the second data block to obtain a second compressed data block that has a second compressed length that is smaller than the second uncompressed length;

determining a second available length based on the second compressed length and the maximum length of a second data frame;

calculating a second MAC based on the second data block, the second MAC having a second MAC length not greater than the second available length, wherein the second MAC length is different than the MAC length; and

creating the second data frame comprising the second data block and the second MAC.

18. A non-transitory computer-readable data carrier having stored thereon a computer program comprising instructions which, when the computer program is executed by a computer or a computer system, cause the computer or the computer system to carry out the method of claim 1 .

19. A non-transitory computer-readable data carrier having stored thereon a computer program comprising instructions which, when the computer program is executed by a computer or a computer system, cause the computer or the computer system to carry out the method of claim 9 .

20. A device for generating authenticated messages, the device comprising:

a non-transitory computer-readable memory storing instructions; and

a computer processing device coupled to the memory and configured to execute the instructions to:

prepare a data block having an uncompressed length or a block length;

compress the data block such that the compressed data block has a compressed length smaller than the uncompressed length;

determine an available length based on the compressed length and a maximum length of a data frame;

calculate a message authentication code (MAC) based on the data block, the MAC having a MAC length not greater than the available length; and

create the data frame, which comprises the data block and the MAC;

calculate an additional MAC having an additional MAC length not greater than the available length; and

create an additional data frame that comprises the data block and the additional MAC.

21. A system for authenticating messages comprising:

the device according to claim 20 ; and

a device for receiving authenticated messages, wherein the device for receiving authenticated messages is configured to:

receive a data frame that comprises a data block and a received MAC;

verify the received MAC;

receive an additional data frame that comprises the data block and an additional received MAC; and

verify the additional received MAC.

22. A device for receiving authenticated messages, the device comprises:

a non-transitory computer-readable memory storing instructions; and

a computer processing device coupled to the memory and configured to execute the instructions to:

receive a data frame that comprises a data block and a Message Authentication Code (MAC);

verify the MAC;

receive an additional data frame that comprises the same data block and an additional MAC; and

verify the additional MAC.

Assignments (5)
MERGER Recorded Nov 13, 2023
From: HITACHI ENERGY SWITZERLAND AG
To: HITACHI ENERGY LTD
Reel/Frame 065548/0905 →
CHANGE OF NAME Recorded Dec 31, 2021
From: ABB POWER GRIDS SWITZERLAND AG
To: HITACHI ENERGY SWITZERLAND AG
Reel/Frame 058601/0692 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 25, 2021
From: SIVANTHI, THANIKESAVAN
To: ABB SCHWEIZ AG
Reel/Frame 057280/0590 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 25, 2021
From: ABB SCHWEIZ AG
To: ABB POWER GRIDS SWITZERLAND AG
Reel/Frame 057280/0633 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 25, 2021
From: DZUNG, DACFEY
To: ABB POWER GRIDS SWITZERLAND AG
Reel/Frame 057295/0211 →
Priority Claims (1)
EP 19155836 · Feb 6, 2019 · regional
Continuity (1)
Related Publication 20220094552A1 · Mar 24, 2022
References Cited (26)
US 5673318A · Bellare et al. · 1997 [cited by applicant]
US 7426636B1 · McGrew et al. · 2008 [cited by applicant]
US 7725927B2 · Yang · 2010 [cited by examiner]
US 9667634B2 · Struik · 2017 [cited by examiner]
US 20020174332A1 · Vialen et al. · 2002 [cited by applicant]
US 20070101412A1 · Yang et al. · 2007 [cited by applicant]
US 20090103820A1 · Chang · 2009 [cited by examiner]
US 20100208886A1 · Boehl et al. · 2010 [cited by applicant]
US 20130198509A1 · Buruganahalli et al. · 2013 [cited by applicant]
US 20150270968A1 · Nairn et al. · 2015 [cited by applicant]
US 20160099939A1 · Jung · 2016 [cited by examiner]
US 20170126409A1 · Freudiger et al. · 2017 [cited by applicant]
US 20170366354A1 · Alomair · 2017 [cited by applicant]
US 20180091308A1 · Durham · 2018 [cited by examiner]
US 20180316504A1 · Boehl et al. · 2018 [cited by applicant]
EP 1615370A1 · 2006 [cited by applicant]
EP 2541829A1 · 2013 [cited by applicant]
GB 2459735A · 2009 [cited by applicant]
JP H06315027A · 1994 [cited by applicant]
JP 2016100632A · 2016 [cited by applicant]
JP 2018032903A · 2018 [cited by applicant]
JP 2019016987A · 2019 [cited by applicant]
WO 2015170452A1 · 2015 [cited by applicant]
Saxena, Navrati, et al., “Efficient IoT Gateway over 5G Wireless: A New Design with Prototype and Implementation Results”, Practical Perspectives on IoT in 5G Networks: Theory, Industrial Challenges, and Business Opport… [cited by applicant]
Popovic, M., et al., “iPRP—The Parallel Redundancy Protocol for IP Netowrks: Protocol Design and Operation,” IEEE Transactions on Industrial Informatics, vol. 12, No. 5, Oct. 2016, 13 pages. [cited by applicant]
Schneier, B., “Applied Cryptography, Second Edition: Protocols, Algorthms, and Source Code in Code in C (cloth),” John Wiley & Sons, Inc., Jan. 1, 1996, 1027 pages. [cited by applicant]