IP Library › Granted Patent US 12,634,147
Granted Patent B2
US 12,634,147 · App. 18/799,334 · Granted May 19, 2026

Secure message system and method of the same

Inventors: Brian Farrell (Troy, MI); Sherif Aly (West Bloomfield, MI)
Assignee: GM Global Technology Operations LLC
H04L9/3242H04L69/22H04W48/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,634,147
App. No.
18/799,334
Granted
May 19, 2026
Kind
B2
Abstract

A computer-implemented method that causes data processing hardware to perform operations including generating, at a first device, a message having a header including a message type and a service ID, receiving, at a second device, the message including the header and a key serial number (KSN) of the first device, determining, based on the header, the message type of the message, verifying, at a high performance crypto accelerator (HPCA) of the second device, a message authentication code (MAC) of the message based on the determined message type being the service event, obtaining, based on the KSN from the message, a key slot from a message authentication code table (MACT), identifying, based on the key slot, a key associated with the key slot obtained from the MACT, the key including at least one of a primary key and a secondary key, and verifying, using the key and the key slot obtained from the MACT, the MAC.

Claims (45)

1 . A computer-implemented method when executed by data processing hardware causes the data processing hardware to perform operations comprising:

generating, at a first device, a message having a header including a message type and a service identifier (ID), the message type being one of a service discovery and a service event;

receiving, at a secure environment of a second device, the message including the header and a key serial number (KSN) of the first device;

generating, outside of a secure environment of the first device, a KSN/service ID table including storing the KSN and the service ID from the message;

determining, based on the header, the message type of the message;

verifying, at a high performance crypto accelerator (HPCA) of the second device, a message authentication code (MAC) of the message based on the determined message type being the service event;

obtaining, based on the KSN from the message, a key slot from a message authentication code table (MACT);

identifying, based on the key slot, a key associated with the key slot obtained from the MACT, the key including at least one of a primary key and a secondary key; and

verifying, using the key and the key slot obtained from the MACT, the MAC.

2 . The method of claim 1 , wherein determining the message type includes determining that the message type is a service discovery.

3 . The method of claim 1 , wherein generating the KSN/service ID table includes associating an offered service of the message with the KSN of the second device.

4 . The method of claim 3 , wherein verifying the MAC includes determining an error based on the KSN from the message and the stored service ID at the KSN/service ID table.

5 . The method of claim 4 , wherein determining the error includes issuing an error message and terminating the service event.

6 . The method of claim 1 , wherein identifying the key includes executing a key derivation function and generating the secondary key.

7 . A computer-implemented method when executed by data processing hardware causes the data processing hardware to perform operations comprising:

generating, at a first device, a message having a header including a message type and a service identifier (ID), the message type being one of a service discovery and a service event;

receiving, at a secure environment of a second device, the message including the header and a key serial number (KSN) of the first device;

generating, outside of a secure environment of the first device, a KSN/service ID table including storing the KSN and the service ID from the message;

determining, based on the header, the message type of the message;

bypassing, based on the determined message type being the service event, a message authentication code (MAC) generate allow list (MGAL);

comparing, based on the KSN from the message, the service ID from the message with a stored service ID from a message authentication code table (MACT);

validating, based on the service ID matching the stored service ID, the KSN at the MACT;

obtaining, based on the validated KSN, a key slot from the MACT;

identifying, based on the key slot, a key associated with the key slot obtained from the MACT, the key including at least one of a primary key and a secondary key; and

verifying, using the key and the key slot obtained from the MACT, the MAC.

8 . The method of claim 7 , wherein determining the message type includes determining that the message type is a service discovery.

9 . The method of claim 7 , wherein generating the KSN/service ID table includes associating an offered service of the message with the KSN of the second device.

10 . The method of claim 9 , wherein verifying the MAC includes determining an error based on the KSN from the message and the stored service ID at the KSN/service ID table and issuing an error message and terminating the service event.

11 . The method of claim 10 , wherein bypassing the MGAL includes verifying, by a high performance crypto accelerator (HPCA), the service event.

12 . The method of claim 7 , wherein identifying the key includes executing a key derivation function and generating the secondary key.

13 . A secure message system for a vehicle, the secure message system comprising:

data processing hardware; and memory hardware in communication with the data processing hardware, the memory hardware storing instructions that when executed on the data processing hardware cause the data processing hardware to perform operations comprising:

generating, at a first device, a message having a header including a message type and a service identifier (ID), the message type being one of a service discovery and a service event;

receiving, at a secure environment of a second device, the message including the header and a key serial number (KSN) of the first device;

generating, outside of a secure environment of the first device, a KSN/service ID table including storing the KSN and the service ID from the message;

determining, based on the header, the message type of the message;

verifying, at a high performance crypto accelerator (HPCA) of the second device, a message authentication code (MAC) of the message based on the determined message type being the service event;

obtaining, based on the KSN from the message, a key slot from a message authentication code table (MACT);

identifying, based on the key slot, a key associated with the key slot obtained from the MACT, the key including at least one of a primary key and a secondary key; and

verifying, using the key and the key slot obtained from the MACT, the message authentication code (MAC).

14 . The secure message system of claim 13 , wherein determining the message type includes determining that the message type is a service discovery.

15 . The secure message system of claim 13 , wherein generating the KSN/service ID table includes associating an offered service of the message with the KSN of the second device.

16 . The secure message system of claim 15 , wherein verifying the MAC includes determining an error based on the KSN from the message and the stored service ID at the KSN/service ID table.

17 . The secure message system of claim 16 , wherein determining the error includes issuing an error message and terminating the service event.

18 . The secure message system of claim 13 , wherein identifying the key includes executing a key derivation function and generating the secondary key.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 9, 2024
From: FARRELL, BRIAN; ALY, SHERIF
To: GM GLOBAL TECHNOLOGY OPERATIONS LLC
Reel/Frame 068241/0522 →
Continuity (1)
Related Publication 20260046139A1 · Feb 12, 2026
References Cited (16)
US 11765256B2 · Weber · 2023 [cited by examiner]
US 20060047771A1 · Blackmore · 2006 [cited by examiner]
US 20070174171A1 · Sheffield · 2007 [cited by examiner]
US 20080279381A1 · Narendra · 2008 [cited by examiner]
US 20100118771A1 · Lee · 2010 [cited by examiner]
US 20160205222A1 · Shaffer · 2016 [cited by examiner]
US 20180167216A1 · Walrant · 2018 [cited by examiner]
US 20240187401A1 · Farrell · 2024 [cited by examiner]
CN 109309689B · 2019 [cited by examiner]
CN 116489209A · 2023 [cited by examiner]
DE 102023120351A1 · 2024 [cited by applicant]
JP 2016057672A · 2016 [cited by examiner]
WO WO2022242775A1 · 2022 [cited by examiner]
Farrell et al. “Securing In-Vehicle Service Oriented Architecture with MAC Generate Allow List Enforcement in Host Device”, U.S. Appl. No. 18/459,603, filed Sep. 1, 2023. [cited by applicant]
Farrell et al. “Securing In-Vehicle Service Oriented Architecture with MAC Generate Allow List ”, U.S. Appl. No. 18/073,540, filed Dec. 1, 2023. [cited by applicant]
Farrell et al. “Method To Secure In-Vehicle Service Oriented Architecture With Message Authentication Code (MAC) Generate Allow List (MGAL) ”, U.S. Appl. No. 18/420,086, filed Jan. 23, 2024. [cited by applicant]