IP Library Granted Patent US 12,278,906
Granted Patent B2
US 12,278,906 · App. 17/650,474 · Granted Apr 15, 2025

Method and device for checking an incoming secured, encrypted message

Inventors: Gobinath Ramasamy Muthusamy (Heilbronn, DE); Martin Friedrich (Untergruppenbach, DE)
Assignee: ROBERT BOSCH GMBH
H04L9/3242H04L2209/84
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,278,906
App. No.
17/650,474
Granted
Apr 15, 2025
Kind
B2
Abstract

A method for checking an incoming message. In the method, based on the message authentication code, an authentication of the useful data is performed by a hardware security module and the hardware security module is subjected to a function check.

Claims (35)

1. A method for checking an incoming message that includes useful data and a message authentication code, the method comprising the following steps:

performing, by a hardware security module, an authentication of the useful data based on the message authentication code;

performing a function check on the hardware security module, wherein:

the authentication and function check include a comparison of the message authentication code;

for the function check, an input for the comparison is taken from a lookup table;

for the comparison, a computational message authentication code is ascertained and a comparison of the computational message authentication code to the input is made; and

a result of the comparison is output for the authentication or the function check;

utilizing the useful data when the result indicates satisfactorily passing of the comparison; and

discarding the useful data when the result indicates satisfactorily not passing of the comparison.

2. The method as recited in claim 1 , wherein:

the authentication takes place on a functional level; and

the function check take place via continuous monitoring of the hardware security module on a monitoring level.

3. The method as recited in claim 2 , wherein:

the functional level satisfies general quality standards; and

the monitoring level satisfies safety requirements according to ISO (International Organization for Standardization) 26262.

4. The method as recited in claim 1 , wherein: for the function check, the result is evaluated based on the lookup table.

5. The method as recited in claim 1 , wherein the message is received via a vehicle network.

6. A non-transitory machine-readable memory medium on which is stored a computer program for checking an incoming message that includes useful data and a message authentication code, the computer program, when executed by a computer, causing the computer to perform the following steps:

performing, by a hardware security module, an authentication of the useful data based on the message authentication code;

performing a function check on the hardware security module, wherein:

the authentication and function check include a comparison of the message authentication code;

for the function check, an input for the comparison is taken from a lookup table;

for the comparison, a computational message authentication code is ascertained and a comparison of the computational message authentication code to the input is made; and

a result of the comparison is output for the authentication or the function check

utilizing the useful data when the result indicates satisfactorily passing of the comparison; and

discarding the useful data when the result indicates satisfactorily not passing of the comparison.

7. A device configured to check an incoming message that includes useful data and a message authentication code, the device including a hardware security module and configured to:

perform, using the hardware security module, an authentication of the useful data based on the message authentication code;

perform a function check on the hardware security module, wherein:

the authentication and function check include a comparison of the message authentication code;

for the function check, an input for the comparison is taken from a lookup table;

for the comparison, a computational message authentication code is ascertained and a comparison of the computational message authentication code to the input is made; and

a result of the comparison is output for the authentication or the function check;

utilize the useful data when the result indicates satisfactorily passing of the comparison; and

discard the useful data when the result indicates satisfactorily not passing of the comparison.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 20, 2022
From: RAMASAMY MUTHUSAMY, GOBINATH; FRIEDRICH, MARTIN
To: ROBERT BOSCH GMBH
Reel/Frame 060562/0224 →
Priority Claims (1)
DE 10 2021 201 444.5 · Feb 16, 2021 · national
Continuity (1)
Related Publication 20220271941A1 · Aug 25, 2022
References Cited (7)
US 10095634B2 · Sharma · 2018 [cited by examiner]
US 11951917B2 · Iwata · 2024 [cited by examiner]
US 20160255154A1 · Kim · 2016 [cited by examiner]
US 20200244442A1 · Zeh · 2020 [cited by examiner]
DE 102013206185A1 · 2014 [cited by applicant]
DE 102017209557A1 · 2018 [cited by applicant]
SEDAN: Security-Aware Design of Time-Critical Automotive Networks, Kukkala et al, Aug. 2020 (Year: 2020). [cited by examiner]