IP Library Granted Patent US 12,695,629
Granted Patent B2
US 12,695,629 · App. 18/335,731 · Granted Jul 28, 2026

Authentication method and apparatus

Inventors: Zhe Wang (Dongguan, CN); Yawen Wu (Shanghai, CN); Xuezhong Chu (Shenzhen, CN)
Assignee: YINWANG INTELLIGENT TECHNOLOGIES CO., LTD.
H04L9/3271G06F21/12G06F21/44G06F21/74H04L9/0819H04L9/0863H04L9/0869H04L9/3226H04L9/0816
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,695,629
App. No.
18/335,731
Filed
Jun 15, 2023
Granted
Jul 28, 2026
Kind
B2
Art Unit
2407
USPC
380/44
Abstract

This application provides example authentication methods and apparatuses. One example authentication method is used for a terminal device. The method includes receiving, by the first service unit, a first request from a second device, wherein the first request is used to request a first seed. The first service unit sends the first request to the first authentication unit. The first authentication unit sends a first response to the first service unit, wherein the first response comprises the first seed. The first service unit sends the first response to the second device. The first service unit receives a second seed from the second device. The first service unit sends the second seed to the first authentication unit. The first authentication unit determines a third seed based on a first key and the second seed, wherein the first key is determined based on the first seed.

Claims (66)

1 . An authentication method, applied to a first device, wherein the first device comprises a transceiver, a first service processor storing service information of the first device, and a first authentication processor, wherein an authentication operation in the first authentication processor is isolated from the service information in the first service processor, and wherein the method comprises:

receiving, by the first service processor through the transceiver, a first request from a second device, wherein the first request is used to request a first seed;

sending, by the first service processor, the first request to the first authentication processor;

sending, by the first authentication processor, a first response to the first service processor, wherein the first response comprises the first seed;

sending, by the first service processor through the transceiver, the first response to the second device;

receiving, by the first service processor through the transceiver, a second seed from the second device;

sending, by the first service processor, the second seed to the first authentication processor;

determining, by the first authentication processor, a third seed based on a first key and the second seed, wherein the first key is determined based on the first seed;

determining, by the first authentication processor, a matching result between the third seed and the first seed;

sending, by the first authentication processor, the matching result to the first service processor; and

sending, by the first service processor through the transceiver, the matching result to the second device.

2 . The authentication method according to claim 1 , wherein the method further comprises:

determining, by the first authentication processor, the first key based on a first key material, a first key generation algorithm, and the first seed, wherein the first key material and the first key generation algorithm are stored in the first authentication processor.

3 . The authentication method according to claim 2 , wherein the first request comprises an access level, and before the determining, by the first authentication processor, the first key based on a first key material, a first key generation algorithm, and the first seed, the method further comprises:

determining, by the first authentication processor, the first key material and the first key generation algorithm based on the access level.

4 . The authentication method according to claim 1 , wherein:

the sending, by the first service processor, the second seed to the first authentication processor comprises:

sending, by the first service processor, the second seed and identification information to the first authentication processor, wherein the identification information corresponds to the first key; and

before the determining, by the first authentication processor, a third seed based on a first key and the second seed, the method further comprises:

determining, by the first authentication processor, the first key based on the identification information.

5 . The authentication method according to claim 4 , wherein the method further comprises:

sending, by the first authentication processor, the identification information to the first service processor, wherein the identification information is determined based on the first key.

6 . The authentication method according to claim 1 , wherein the method further comprises:

deleting, by the first authentication processor, the first key.

7 . An authentication method, applied to a second device, wherein the second device comprises a transceiver, a second service processor storing service information of the second device, and a second authentication processor, wherein an authentication operation in the second authentication processor is isolated from the service information in the second service processor, and wherein the method comprises:

sending, by the second authentication processor, a first request to the second service processor, wherein the first request is used to request a first seed;

sending, by the second service processor through the transceiver, the first request to a first device;

receiving, by the second service processor through the transceiver, a first response from the first device, wherein the first response comprises the first seed;

sending, by the second service processor, the first response to the second authentication processor;

sending, by the second authentication processor, a second seed to the second service processor, wherein the second seed is determined based on the first seed and a second key, and the second key is determined based on the first seed;

sending, by the second service processor through the transceiver, the second seed to the first device; and

receiving, by the second service processor through the transceiver, a matching result from the first device.

8 . The authentication method according to claim 7 , wherein the method further comprises:

determining, by the second authentication processor, the second key based on a second key material, a second key generation algorithm, and the first seed, wherein the second key material and the second key generation algorithm are stored in the second authentication processor.

9 . The authentication method according to claim 7 , wherein the method further comprises:

deleting, by the second authentication processor, the second key.

10 . An authentication apparatus, wherein the authentication apparatus comprises a transceiver, a first service processor configured to store service information of the authentication apparatus, and a first authentication processor, and wherein:

an authentication operation in the first authentication processor is isolated from the service information in the first service processor;

the first service processor is configured to receive a first request from a second device through the transceiver, wherein the first request is used to request a first seed;

the first service processor is further configured to send the first request to the first authentication processor;

the first authentication processor is configured to send a first response to the first service processor, wherein the first response comprises the first seed;

the first service processor is further configured to send the first response to the second device through the transceiver;

the first service processor is further configured to receive a second seed from the second device through the transceiver;

the first service processor is further configured to send the second seed to the first authentication processor;

the first authentication processor is further configured to determine a third seed based on a first key and the second seed, wherein the first key is determined based on the first seed;

the first authentication processor is further configured to determine a matching result between the third seed and the first seed;

the first authentication processor is further configured to send the matching result to the first service processor; and

the first service processor is further configured to send the matching result to the second device through the transceiver.

11 . The authentication apparatus according to claim 10 , wherein the first authentication processor is further configured to determine the first key based on a first key material, a first key generation algorithm, and the first seed, wherein the first key material and the first key generation algorithm are stored in the first authentication processor.

12 . The authentication apparatus according to claim 11 , wherein the first request comprises an access level, and the first authentication processor is further configured to determine the first key material and the first key generation algorithm based on the access level.

13 . The authentication apparatus according to claim 10 , wherein:

the first service processor is further configured to send the second seed and identification information to the first authentication processor, wherein the identification information corresponds to the first key; and

the first authentication processor is further configured to determine the first key based on the identification information.

14 . The authentication apparatus according to claim 13 , wherein the first authentication processor is further configured to send the identification information to the first service processor, and wherein the identification information is determined based on the first key.

15 . The authentication apparatus according to claim 10 , wherein the first authentication processor is further configured to delete the first key.

16 . An authentication apparatus, wherein the authentication apparatus comprises a transceiver, a second service processor configured to service information of the authentication apparatus, and a second authentication processor, and wherein:

an authentication operation in the second authentication processor is isolated from the service information in the second service processor;

the second authentication processor is configured to send a first request to the second service processor, wherein the first request is used to request a first seed;

the second service processor is configured to send the first request to a first device through the transceiver;

the second service processor is further configured to receive a first response from the first device through the transceiver, wherein the first response comprises the first seed;

the second service processor is further configured to send the first response to the second authentication processor;

the second authentication processor is further configured to send a second seed to the second service processor, wherein the second seed is determined based on the first seed and a second key, and the second key is determined based on the first seed;

the second service processor is further configured to send the second seed to the first device through the transceiver; and

the second service processor is further configured to receive a matching result sent by the first device through the transceiver.

17 . The authentication apparatus according to claim 16 , wherein the second authentication processor is further configured to determine the second key based on a second key material, a second key generation algorithm, and the first seed, and wherein the second key material and the second key generation algorithm are stored in the second authentication processor.

18 . The authentication apparatus according to claim 16 , wherein the second authentication processor is further configured to delete the second key.

Assignments (3)
CHANGE OF NAME Recorded Apr 28, 2026
From: SHENZHEN YINWANG INTELLIGENT TECHNOLOGIES CO., LTD.
To: YINWANG INTELLIGENT TECHNOLOGIES CO., LTD.
Reel/Frame 075492/0796 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 12, 2024
From: HUAWEI TECHNOLOGIES CO., LTD.
To: SHENZHEN YINWANG INTELLIGENT TECHNOLOGIES CO., LTD.
Reel/Frame 069336/0125 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 1, 2024
From: WANG, ZHE; WU, YAWEN; CHU, XUEZHONG
To: HUAWEI TECHNOLOGIES CO., LTD.
Reel/Frame 069111/0452 →
Priority Claims (1)
CN 202011503283.3 · Dec 18, 2020 · national
Continuity (2)
Continuation PCTCN2021131545 · Nov 18, 2021
Related Publication 20230327869A1 · Oct 12, 2023
References Cited (16)
US 9569353B2 · Miyake · 2017 [cited by examiner]
US 20130111582A1 · Forest · 2013 [cited by applicant]
US 20140344920A1 · Jung · 2014 [cited by examiner]
US 20160035147A1 · Huang · 2016 [cited by examiner]
US 20180139191A1 · Shi · 2018 [cited by examiner]
US 20180357408A1 · Suzuki · 2018 [cited by examiner]
US 20190349208A1 · Merchan · 2019 [cited by examiner]
US 20210288806A1 · Wakita · 2021 [cited by examiner]
CN 103529823B · 2016 [cited by applicant]
CN 106814675A · 2017 [cited by applicant]
CN 117914557A · 2024 [cited by examiner]
Kurachi et al., “Evaluation of Security Access Service in Automotive Diagnostic Communication,” Proceedings of 2019 IEEE 89th Vehicular Technology Conference (VTC2019-Spring), Kuala Lumpur, Malaysia, Apr. 28-May 1, 2019… [cited by applicant]
Liu, “Design and Implementation of Vehicle Safety Management Platform Based on OBD,” Thesis for the degree of Master, Beijing University of Technology, May 2018, 213 pages (with English translation). [cited by applicant]
Wang et al., “Security Access Control for Remote Automobile Fault Diagnosis System,” Microprocessors, No. 2, Apr. 2013, 5 pages (with English translation). [cited by applicant]
Subke et al., “Measures to Prevent Unauthorized Access to the In-Vehicle E/E System, Due to the Security Vulnerability of a Remote Diagnostic Tester,” SAE International, Mar. 28, 2017, 8 pages. [cited by applicant]
Ring et al., “Evaluation of Vehicle Diagnostics Security-Implementation of a Reproducible Security Access,” Proceedings of SECURWARE 2014 : The Eighth International Conference on Emerging Security Information, Systems a… [cited by applicant]