Patents Assigned to Huawei International PTE., Ltd.
-
Patent number: 11985238Abstract: Embodiments disclose a vehicle-mounted device upgrade method and a related device. The method may be applied to an intelligent vehicle, the intelligent vehicle includes a vehicle-mounted control device, and the method may include: receiving, by the vehicle-mounted control device, a first partial key sent by the communications device; restoring, by the vehicle-mounted control device, a first key by using the first partial key and a second partial key that is stored on the vehicle-mounted control device; and performing, by the vehicle-mounted control device, secure processing on a first upgrade file by using the first key, to obtain the securely processed first upgrade file, where the secure processing includes generating first message authentication code (MAC), and the securely processed first upgrade file includes the first upgrade file and the first MAC. According to this application, the vehicle-mounted device can be securely and efficiently upgraded.Type: GrantFiled: October 30, 2020Date of Patent: May 14, 2024Assignee: Huawei International Pte. Ltd.Inventors: Yanjiang Yang, Zhuo Wei, Hsiao-Ying Lin, He Wei, Junqiang Shen
-
Patent number: 11895157Abstract: Embodiments of this application provide a network security management method and an apparatus. The method includes: receiving, by a first network device, a session request sent by a terminal device, where the session request is used to request establishment of a first session with a first data network, the session request includes first authentication information for the first session, and the first authentication information includes identifier information of the first data network; obtaining, by the first network device, second authentication information for a second session of the terminal device, where the second authentication information includes identifier information of a second data network to which the second session is connected; and if the identifier information of the first data network is the same as the identifier information of the second data network, authorizing the terminal device to establish the first session with the first data network.Type: GrantFiled: September 7, 2022Date of Patent: February 6, 2024Assignee: HUAWEI INTERNATIONAL PTE. LTD.Inventors: Zhongding Lei, Lichun Li, Haiguang Wang, Xin Kang
-
Patent number: 11662991Abstract: A vehicle-mounted device upgrade method and a related device. The method may be applied to a vehicle-mounted system, a vehicle-mounted control device and one or more to-be-upgraded vehicle-mounted devices, and the method may include: obtaining, by the vehicle-mounted control device, a vehicle-mounted upgrade package, where the vehicle-mounted upgrade package includes a plurality of upgrade files, and each upgrade file is used to upgrade at least one to-be-upgraded vehicle-mounted device; performing, by the vehicle-mounted control device, security verification on the plurality of upgrade files; and sending, by the vehicle-mounted control device, a target upgrade file to a target to-be-upgraded vehicle-mounted device that is to be upgraded by using the target upgrade file, where the target upgrade file is an upgrade file on which security verification succeeds in the plurality of upgrade files. According to this application, the vehicle-mounted device can be securely and efficiently upgraded.Type: GrantFiled: April 23, 2020Date of Patent: May 30, 2023Assignee: Huawei International Pte. Ltd.Inventors: Yanjiang Yang, Zhuo Wei, Hsiao-Ying Lin, Tieyan Li, Junqiang Shen
-
Patent number: 11637707Abstract: This application discloses a mobile device and method for managing installation of an application package (APK) in the mobile device. The device receives an installation request for installing the APK. The device retrieves a permission certificate for the APK according to the installation request. The permission certificate includes a cryptographic signature. The device determines validity of the permission certificate by verifying the cryptographic signature included in the permission certificate using a permission certification public key provided by a manufacturer of the device. The permission certification public key is stored in the device. The installation of the APK in the device is allowed when the permission certificate is determined to be valid. Using the method, the APK requires the device to grant specific high-risk permissions to the application upon installation.Type: GrantFiled: December 4, 2020Date of Patent: April 25, 2023Assignee: Huawei International Pte. Ltd.Inventors: Yongzheng Wu, Xuejun Wen
-
Patent number: 11588622Abstract: A vehicle communication access framework and a method are provided. The vehicle communication access framework comprises: a first device residing in a vehicle, a first processing system operated by a trusted third party, a second processing system operated by an original equipment manufacturer (OEM) of the vehicle, and a third processing system operated by a third party provider; wherein communication accesses among the first device, second processing system and third processing system are based on Identity Based Cryptography (IBC) private keys generated by the first processing system to respective first device, second processing system and third processing system.Type: GrantFiled: March 27, 2020Date of Patent: February 21, 2023Assignee: Huawei International Pte. Ltd.Inventors: Rehana Yasmin, Zhuo Wei, Fei Hua, Yanjiang Yang
-
Patent number: 11570008Abstract: A pseudonym credential configuration method and apparatus are provided. The method includes: receiving an identifier of a terminal device and information about N to-be-requested pseudonym credentials from the terminal device, sending N second request messages to a pseudonym credential generation server, and storing a tag of each second request message in association with the identifier of the terminal device in the registration server, so that the registration server can obtain, based on the tag, the identifier that is of the terminal device and that is associated with the tag; and generating N pseudonym credentials. The pseudonym credential generated in this application may enable a behavior investigation server to learn of a real identity of the terminal device.Type: GrantFiled: December 21, 2020Date of Patent: January 31, 2023Assignee: Huawei International Pte. Ltd.Inventors: Xin Kang, Yanjiang Yang, Haiguang Wang, Zhongding Lei
-
Patent number: 11563565Abstract: A system and method generate private keys for devices participating in a self-certified identity based encryption scheme. A private key is used by the devices to establish a common session key for encoding digital communications between devices.Type: GrantFiled: August 8, 2019Date of Patent: January 24, 2023Assignee: Huawei International Pte. Ltd.Inventors: Yanjiang Yang, Guilin Wang, Tieyan Li
-
Patent number: 11483142Abstract: A key agreement system, method, and apparatus are provided. The method includes: generating, by a first device, a private-public key pair, sending a public key in the private-public key pair to a second device, and receiving a ciphertext and a commitment value; obtaining, by the first device, a first result, obtaining an original key based on a private key in the private-public key pair and the ciphertext, determining a second bit string based on some bits in the original key, calculating a second result based on the second bit string and the first result, and sending the second result to the second device; and receiving, by the first device, an opening value, performing authentication on the second device based on the opening value and the commitment value to obtain an authentication result, and generating a session key used to communicate with the second device.Type: GrantFiled: November 30, 2020Date of Patent: October 25, 2022Assignee: Huawei International Pte. Ltd.Inventors: David Pointcheval, Guilin Wang
-
Patent number: 11477242Abstract: Embodiments of this application provide a network security management method and an apparatus. The method includes: receiving, by a first network device, a session request sent by a terminal device, where the session request is used to request establishment of a first session with a first data network, the session request includes first authentication information for the first session, and the first authentication information includes identifier information of the first data network; obtaining, by the first network device, second authentication information for a second session of the terminal device, where the second authentication information includes identifier information of a second data network to which the second session is connected; and if the identifier information of the first data network is the same as the identifier information of the second data network, authorizing the terminal device to establish the first session with the first data network.Type: GrantFiled: January 17, 2020Date of Patent: October 18, 2022Assignee: Huawei International Pte. Ltd.Inventors: Zhongding Lei, Lichun Li, Haiguang Wang, Xin Kang
-
Patent number: 11429511Abstract: This document describes a device and method for a device to reinforce the control flow integrity of a software application as the application is being executed on the device.Type: GrantFiled: August 27, 2019Date of Patent: August 30, 2022Assignee: Huawei International Pte. Ltd.Inventors: Ting Dai, Yongzheng Wu
-
Patent number: 11432157Abstract: The disclosure provides a network authentication method, a network device, and a core network device, the network authentication method including: receiving, by a first network device, an access request message sent by a terminal device, where the access request message includes an identity of the terminal device; determining, by the first network device based on the identity of the terminal device, whether to allow authentication on the terminal device; if the first network device does not allow the authentication on the terminal device, sending, by the first network device, the identity of the terminal device to a core network device, so that the core network device performs network authentication based on the identity of the terminal device.Type: GrantFiled: November 27, 2019Date of Patent: August 30, 2022Assignee: Huawei International Pte. Ltd.Inventors: Haiguang Wang, Xin Kang, Zhongding Lei, Fei Liu
-
Patent number: 11425202Abstract: Embodiments of a session processing method and a device relating to a data network are provided. The method includes a data-network network element in the data network receiving a data network access request sent by a session management function (SMF) network element of the data network, where the data network access request includes an identifier of user equipment UE and a session address to be used by the UE. The data-network network element sends a response message to the SMF, where the response message instructs the SMF to allow the UE to access the data network, so that the SMF establishes a data packet unit session of the UE. The data-network network element detects, based on the session address or the identifier of the UE, that the data packet unit session of the UE needs to be processed, generates a session processing request, and instructs, by using the session processing request, the SMF to process the data packet unit session of the UE.Type: GrantFiled: October 21, 2019Date of Patent: August 23, 2022Assignee: Huawei International Pte. Ltd.Inventors: Lichun Li, Zhongding Lei, Bo Zhang
-
Patent number: 11381973Abstract: A data transmission method, a related device, and a related system. The method includes: receiving, by a first access network device, a data packet (for example, small data) sent by user equipment (for example, an IoT device), where the data packet includes a first cookie and raw data; verifying, by the first access network device, the first cookie, to obtain a verification result; and processing, by the first access network device, the raw data based on the verification result. Implementation of embodiments can reduce load on a network side when a large quantity of user equipments need to perform communication, thereby increasing data transmission efficiency.Type: GrantFiled: January 21, 2020Date of Patent: July 5, 2022Assignee: Huawei International Pte. Ltd.Inventors: Xin Kang, Haiguang Wang, Zhongding Lei, Fei Liu
-
Patent number: 11265161Abstract: This document describes a system and method for generating two types of session keys for encoding digital communications between two devices. In particular, the first type of session key possesses escrow properties whereby a trusted third party will be able to generate the first type of session key to decode the digital communications between the two devices while the second type of session key does not possess escrow properties.Type: GrantFiled: August 7, 2020Date of Patent: March 1, 2022Assignee: Huawei International Pte. Ltd.Inventors: Rehana Yasmin, Yanjiang Yang, Zhuo Wei, Tieyan Li, Hai Yu
-
Patent number: 11258598Abstract: A symmetric key-based generation and distribution system and method for a vehicle access authentication framework is provided, the framework comprising: a first device operated by a car owner, a second device operated by a delegated user, and a third device residing in a vehicle. The first device is configured to: request for an authentication key from the third device, the request for the authentication key comprising an ID of the first device, idO; receive an authentication key KidO from the third device; and generate a delegated authentication key KidU based on authentication key KidO and an ID of the second device in response to receiving a request for delegated authentication key from the second device, the request for delegated authentication key comprising the ID of the second device.Type: GrantFiled: November 18, 2019Date of Patent: February 22, 2022Assignee: Huawei International Pte. Ltd.Inventors: Yanjiang Yang, Zhuo Wei, Cheng Kang Chu, Jie Shi
-
Patent number: 11252134Abstract: This document describes a system and method for managing communications between modules in a Controller Area Network (CAN) in a secure manner. In particular, the system employs a hierarchical key generation method that allows a module in the CAN to use a single ascendant key together with relevant identifiers to generate descendant keys for CAN identities in the Controller Area Network. These keys are then used by the broadcasting and receiving CAN modules to authenticate published messages.Type: GrantFiled: January 21, 2020Date of Patent: February 15, 2022Assignee: Huawei International Pte. Ltd.Inventors: Yanjiang Yang, Zhuo Wei, Hsiao-Ying Lin, Qingdi Sha
-
Patent number: 11228589Abstract: This document describes a system and method for a device to communicate efficiently and securely with another device by utilizing two different types of schemes for the generation of data to be transmitted and the handling of received data.Type: GrantFiled: August 1, 2019Date of Patent: January 18, 2022Assignee: Huawei International Pte. Ltd.Inventors: David Naccache, Elizabeth Quaglia, Benjamin Smyth
-
Patent number: 11159311Abstract: A key management method/apparatus (user equipment) are described. The key management includes encrypting user identity information based on a first public key. The user equipment sends a first user identity message to a first network device. The first user identity message includes the user identity information, an indication identifier that indicates whether the user identity information is encrypted, and a reference identifier for indexing the first public key. The first network device sends, to a second network device, a third user identity message including the user identity information and the reference identifier that indexes the first public key. Thus, when receiving the third user identity message, the second network device can determine the encrypted user identity information, according to a pre-stored mapping table including the first private key.Type: GrantFiled: November 19, 2019Date of Patent: October 26, 2021Assignee: Huawei International Pte. Ltd.Inventors: Haiguang Wang, Xin Kang, Zhongding Lei, Fei Liu
-
Patent number: 11146390Abstract: A system for controlling access to encrypted vehicular data employs a hierarchical access control method that allows select encrypted vehicular data stored in a cloud server to be accessed by an authorized user in a hierarchical manner whereby the authorized user is then able to decrypt the select encrypted data and all child data associated with the select encrypted data.Type: GrantFiled: April 30, 2019Date of Patent: October 12, 2021Assignee: Huawei International Pte. Ltd.Inventors: Cheng Kang Chu, Zhuo Wei, Chengfang Fang
-
Patent number: 11044081Abstract: This document describes a system and method for generating a common session key for encoding digital communications between devices. In particular, the system allows two devices to verify the veracity of each device before these authenticated devices proceed to generate a common session key that is then utilized to encode digital communications between these two devices.Type: GrantFiled: January 25, 2019Date of Patent: June 22, 2021Assignee: Huawei International Pte. Ltd.Inventors: Yanjiang Yang, Jie Shi, Guilin Wang