This application provides a PLC instruction-level two-factor
authentication system and method based on a hardware root of trust. It includes: a session
authentication module for performing session-level two-factor
authentication based on device
authentication information corresponding to the user
password factor and the
client device's device identity key; a key derivation module for deriving a token key and an instruction key based on the session
master key; an instruction
encryption module for performing authentication
encryption processing on control instructions using the instruction key, and generating instruction
ciphertext and an authentication tag; and an instruction execution module for decrypting the token
ciphertext using the token key and verifying the device identifier, validity period information, and instruction permission information of the decrypted
security token. If the
verification passes, the instruction
ciphertext is decrypted to obtain the control instruction and executed. This application can improve the strength of instruction-level authentication and
authorization verification, enhance cross-layer identity consistency assurance capabilities, and reduce the
processing overhead of instruction security
verification.