Multi-mode challenge response identity authentication method and system based on PUF (Physical Unclonable Function)

Through the PUF identity authentication method combining dynamic factors and static factors, random challenge codes and adaptive PUF responses are generated, which solves the problem of insufficient adaptability of PUF authentication solutions in multiple scenarios, and realizes efficient and secure identity authentication, which is suitable for the Internet of Things, Internet of Vehicles, and anti-counterfeiting and traceability fields.

CN120263420AInactive Publication Date: 2025-07-04HANGZHOU GUZI CULTURE TECHNOLOGY CO LTD
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510506916.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-22
Publication Date
2025-07-04
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Most of the existing PUF identity authentication solutions are concentrated in a single application scenario, lacking a general and efficient challenge-response identity authentication framework, and cannot adapt to the multi-scenario authentication needs.

Method used

After receiving the authentication instructions, the dynamic input factor is dynamically determined according to the target scene, a random challenge code that integrates the characteristics of the scene is generated using the dynamic weight allocation algorithm, and an adaptive PUF response is generated through the PUF chip, and a composite anti-counterfeiting code is generated in combination with the static factor to generate a composite anti-counterfeiting code for authentication, which enhances the randomness and scene adaptability of the challenge code.

Benefits of technology

It realizes multi-scene authentication based on PUF, reduces computing overhead, improves the randomness of challenge codes and scenario adaptability, and is suitable for anti-counterfeiting traceability, Internet of Things, Internet of Vehicles and other scenarios in high-interference environments, resists quantum computing attacks, and ensures future communication security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120263420A_ABST
    Figure CN120263420A_ABST
Patent Text Reader

Abstract

The invention provides a PUF-based multi-mode challenge response identity authentication method and system, and the method comprises the steps: receiving an authentication instruction, and dynamically determining a dynamic input factor according to a target scene; according to the dynamic input factor and the static factor, using a dynamic weight distribution algorithm to generate a random challenge code fused with scene characteristics; sending the random challenge code to a target device, so that the target device generates a self-adaptive PUF response through a PUF chip, and binding the self-adaptive PUF response with a physical label to generate a composite anti-counterfeiting code; and according to the random challenge code and the composite anti-counterfeiting code, performing identity verification through verification logic. According to the invention, identity authentication based on the PUF in combination with a specific target scene is realized, the method is suitable for multi-scene identity authentication requirements, the calculation overhead is greatly reduced, and the randomness of challenge codes and the scene adaptability are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application belongs to the field of information security and identity authentication technology, and in particular, relates to a PUF-based multimodal challenge-response identity authentication method. Background Art

[0002] In the era of modernization, digitization, and intelligence, identity authentication is a key link in ensuring system security. Traditional identity authentication methods (such as username / password, digital certificates, etc.) have many security risks, such as password leakage, certificate tampering, etc. In addition, with the rapid development of the Internet of Things and Internet of Vehicles technologies, the number of devices has increased dramatically, which has put forward higher requirements for lightweight and high-security identity authentication technologies. In some industries, such as cards and figurines in the second dimension, many popular products will encounter piracy and the risk of affecting the security of users' activities after they are released. A more product-oriented security solution is needed to meet the user's experience and emotional value.

[0003] PUF technology uses the physical characteristics of hardware to generate a unique and unclonable identifier, and implements identity authentication through a challenge-response mechanism. Compared with traditional methods, PUF technology has the advantages of being unclonable, unpredictable, and not requiring key storage, which can effectively improve the security of identity authentication.

[0004] However, most of the existing PUF authentication schemes focus on a single application scenario, and there is currently a lack of a universal and efficient challenge-response authentication framework.

[0005] The above statements are only used to provide background technical information related to the present application. Unless otherwise stated herein, the contents described in this section are not prior art for the contents of other parts of the present application. Summary of the invention

[0006] The present invention proposes a PUF-based multimodal challenge-response identity authentication method and system, which realizes identity authentication based on PUF combined with specific target scenarios, is suitable for identity authentication requirements in multiple scenarios, greatly reduces the calculation overhead, and improves the randomness and scenario adaptability of the challenge code.

[0007] According to a first aspect of an embodiment of the present application, a PUF-based multimodal challenge-response identity authentication method is provided, which is applied to an authentication server and includes:

[0008] After receiving the authentication instruction, the dynamic input factor is dynamically determined according to the target scenario;

[0009] Based on the dynamic input factors and static factors, a dynamic weight allocation algorithm is used to generate a random challenge code that integrates the scene characteristics;

[0010] Send a random challenge code to the target device so that the target device generates an adaptive PUF response through the PUF chip, and generate a composite anti-counterfeiting code after binding the adaptive PUF response with the physical tag;

[0011] Authenticate the identity through the verification logic according to the random challenge code and the composite anti-counterfeiting code.

[0012] In some embodiments of the present application, the method further includes:

[0013] After the authentication is passed, the authentication server generates a session key based on the PUF response and the dynamic input factors, and performs encrypted communication transmission with the target device using a post-quantum encryption algorithm.

[0014] In some embodiments of the present application, the target scenarios include the Internet of Things, the Internet of Vehicles, and anti-counterfeiting traceability;

[0015] The dynamic input factors include environmental factors, behavioral factors, and time factors; the environmental factors include GPS coordinate values, environmental temperature values, and voltage fluctuation values;

[0016] The behavioral factors include the hash value of the device operation log and the user interaction behavior pattern;

[0017] The time factors include millisecond-level timestamps and historical authentication time series entropy values;

[0018] The static factors include device identifiers and product serial numbers.

[0019] In some embodiments of the present application, generating a random challenge code that fuses scenario characteristics using a dynamic weight allocation algorithm includes:

[0020] Calculate the information entropy of each factor, and normalize the entropy value of each factor to obtain the weight coefficient of each factor;

[0021] Introduce a scenario adjustment coefficient for dynamic scenario adjustment of the weight coefficient to obtain a dynamic weight coefficient;

[0022] Determine the weighted factor set according to the dynamic weight coefficient and the corresponding factors;

[0023] After splicing the weighted factors, use the HMAC-DRBG algorithm to generate a random challenge code.

[0024] In some embodiments of the present application, authenticating the identity through the verification logic according to the random challenge code and the composite anti-counterfeiting code includes:

[0025] Bind the random challenge code with the composite anti-counterfeiting code to form a unique response pair;

[0026] Generate an irreversible hash value through hash operation according to the response pair;

[0027] Compare the hash value with the pre - stored key, and complete the verification through a smart contract or a local database; after successful verification, update the pre - stored key.

[0028] According to the second aspect of the embodiments of the present application, a multi - modal challenge - response identity authentication method based on PUF is provided, which is applied to a target device and includes:

[0029] Send an authentication instruction to an authentication server so that the authentication server dynamically determines dynamic input factors according to the target scenario; and generate a random challenge code integrating scenario characteristics using a dynamic weight allocation algorithm according to the dynamic input factors and static factors;

[0030] Receive the random challenge code and generate an adaptive PUF response through a PUF chip;

[0031] Bind the adaptive PUF response with a physical tag to generate a composite anti - counterfeiting code;

[0032] Send the composite anti - counterfeiting code to the authentication server so that the authentication server performs identity authentication through a verification logic according to the random challenge code and the composite anti - counterfeiting code.

[0033] In some embodiments of the present application, receiving the random challenge code and generating an adaptive PUF response through a PUF chip includes:

[0034] Generate an original PUF response using a PUF (Physically Unclonable Function) according to the random challenge code;

[0035] Collect real - time data of the PUF operating environment;

[0036] Establish a response deviation model between each environmental parameter and the PUF response deviation;

[0037] Predict the deviation based on the response deviation model and perform real - time correction on the original PUF response to obtain an adaptive PUF response.

[0038] According to the third aspect of the embodiments of the present application, a multi - modal challenge - response identity authentication device based on PUF is provided, which is applied to an authentication server and includes:

[0039] Factor module: used to dynamically determine dynamic input factors according to the target scenario after receiving an authentication instruction;

[0040] Generation module: used to generate a random challenge code integrating scenario characteristics using a dynamic weight allocation algorithm according to the dynamic input factors and static factors;

[0041] Response module: used to send the random challenge code to the target device so that the target device generates an adaptive PUF response through a PUF chip, and binds the adaptive PUF response with a physical tag to generate a composite anti - counterfeiting code;

[0042] Verification module: used to perform identity authentication through verification logic based on a random challenge code and a composite anti-counterfeiting code.

[0043] According to the fourth aspect of the embodiments of the present application, a PUF-based multi-modal challenge-response identity authentication device is provided, which is applied to a target device and includes:

[0044] Challenge module: used to send an authentication instruction to an authentication server, so that the authentication server dynamically determines dynamic input factors according to the target scenario; and generates a random challenge code integrating scenario characteristics using a dynamic weight allocation algorithm based on the dynamic input factors and static factors;

[0045] First response module: used to receive the random challenge code and generate an adaptive PUF response through a PUF chip;

[0046] Second response module: used to generate a composite anti-counterfeiting code after binding the adaptive PUF response with a physical label;

[0047] Sending module: used to send the composite anti-counterfeiting code to the authentication server, so that the authentication server performs identity authentication through verification logic based on the random challenge code and the composite anti-counterfeiting code.

[0048] According to the fifth aspect of the embodiments of the present application, a PUF-based multi-modal challenge-response identity authentication system is provided, including an authentication server and a target device;

[0049] Authentication server: used to, after receiving an authentication instruction, dynamically determine dynamic input factors according to the target scenario; generate a random challenge code integrating scenario characteristics using a dynamic weight allocation algorithm based on the dynamic input factors and static factors; send the random challenge code to the target device, so that the target device generates an adaptive PUF response through a PUF chip, generates a composite anti-counterfeiting code after binding the adaptive PUF response with a physical label; perform identity authentication through verification logic based on the random challenge code and the composite anti-counterfeiting code;

[0050] Target device: used to send an authentication instruction to the authentication server, so that the authentication server dynamically determines dynamic input factors according to the target scenario; and generates a random challenge code integrating scenario characteristics using a dynamic weight allocation algorithm based on the dynamic input factors and static factors; receive the random challenge code, generate an adaptive PUF response through a PUF chip; generate a composite anti-counterfeiting code after binding the adaptive PUF response with a physical label; send the composite anti-counterfeiting code to the authentication server, so that the authentication server performs identity authentication through verification logic based on the random challenge code and the composite anti-counterfeiting code.

[0051] According to a sixth aspect of the embodiments of the present application, a PUF-based multi-modal challenge-response identity authentication device is provided, including: a storage unit for storing executable instructions; and a processing unit for connecting to a memory to execute the executable instructions to complete a PUF-based multi-modal challenge-response identity authentication method.

[0052] According to a seventh aspect of the embodiments of the present application, a computer-readable storage medium is provided, on which a computer program is stored; the computer program is executed by a processor to implement a PUF-based multi-modal challenge-response identity authentication method.

[0053] Adopting the PUF-based multi-modal challenge-response identity authentication method and system of the present application, after receiving an authentication instruction, a dynamic input factor is dynamically determined according to the target scenario; according to the dynamic input factor and the static factor, a random challenge code integrating the characteristics of the scenario is generated using a dynamic weight allocation algorithm; the random challenge code is sent to the target device so that the target device generates an adaptive PUF response through a PUF chip, and a composite anti-counterfeiting code is generated after binding the adaptive PUF response with a physical tag; identity authentication is performed through a verification logic according to the random challenge code and the composite anti-counterfeiting code. Identity authentication based on PUF combined with a specific target scenario is realized, which is applicable to the identity authentication requirements of multiple scenarios, greatly reducing the calculation overhead and enhancing the randomness and scenario adaptability of the challenge code.

[0054] The present application breaks through the traditional single hardware dependence of PUF, integrates multi-dimensional factors of physics, behavior, and time, and adapts to the requirements of complex scenarios; greatly enhances the randomness and scenario adaptability of the challenge code.

[0055] In addition, the present application enhances the response stability, is applicable to high-interference environments (such as vehicle-mounted and industrial) for realizing the immutability of anti-counterfeiting and traceability on the blockchain chain, reducing the risk of centralized storage; resists quantum computing attacks through post-quantum encrypted session keys to ensure communication security in the next decade; realizes the system's autonomous adaptive response ability to environmental changes and attacks through noise compensation during PUF response. Description of the Drawings

[0056] The drawings described herein are used to provide a further understanding of the present application, and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application, and do not constitute an improper limitation to the present application. In the drawings:

[0057] Figure 1 shows a schematic diagram of the steps of a PUF-based multi-modal challenge-response identity authentication method according to an embodiment of the present application;

[0058] Figure 2 shows a schematic diagram of the steps of generating a random challenge code integrating the characteristics of the scenario using a dynamic weight allocation algorithm according to an embodiment of the present application;

[0059] Figure 3 The schematic diagram of the steps for authentication through verification logic according to an embodiment of the present application is shown;

[0060] Figure 4 The schematic diagram of the steps for another PUF-based multi-modal challenge-response authentication method according to an embodiment of the present application is shown;

[0061] Figure 5 The schematic diagram of the steps for generating an adaptive PUF response according to an embodiment of the present application is shown;

[0062] Figure 6 The schematic diagram of the structure of a PUF-based multi-modal challenge-response authentication device according to an embodiment of the present application is shown;

[0063] Figure 7 The schematic diagram of the structure of another PUF-based multi-modal challenge-response authentication device according to an embodiment of the present application is shown;

[0064] Figure 8 The schematic diagram of the structure of another PUF-based multi-modal challenge-response authentication system according to an embodiment of the present application is shown;

[0065] Figure 9 The schematic diagram of the structure of a PUF-based multi-modal challenge-response authentication device according to an embodiment of the present application is shown. Detailed implementation manners

[0066] Regarding the present application, the PUF technology generates a unique and non-clonable identifier by using the physical characteristics of hardware, and realizes authentication through a challenge-response mechanism. However, most of the existing PUF authentication schemes focus on single application scenarios, and currently there is a lack of a general and efficient challenge-response authentication framework.

[0067] Regarding PUF (Physical Unclonable Function), it is a hardware security technology that uses the inherent physical characteristics in hardware to generate unique and non-replicable digital fingerprints. This technology is often used in security authentication, key generation, and encrypted hardware protection.

[0068] Its physical characteristics include but are not limited to: randomness of microfabrication processes, electrical characteristic differences, optical characteristics, magnetic characteristics, mechanical characteristics, thermal characteristics, random noise characteristics, and so on.

[0069] This application provides a multi-modal challenge-response identity authentication method based on PUF. During each communication process, leveraging the technical characteristics of PUF, based on the randomness of hardware physical characteristics and combined with specific target scenarios, a challenge is input each time, and PUF outputs a unique response. The challenge can be used as the "seed" in the application, and the response serves as the basis for the application scenario result. Due to the high randomness and unpredictability of the PUF output, it is safer and more unpredictable than traditional pseudo-random number generators. Dynamic key generation is used for result encryption. PUF can be used to dynamically generate keys instead of storing static keys. By inputting different challenges, PUF can generate different keys. During the authentication application process, the keys generated by PUF can be used to encrypt the results each time to ensure that the application results cannot be tampered with or leaked before being announced.

[0070] This application breaks through the traditional single-hardware dependence of PUF, integrates multi-dimensional factors of physics, behavior, and time, and adapts to the requirements of complex scenarios; greatly improves the randomness and scenario adaptability of the challenge code.

[0071] In addition, this application enhances the response stability, is applicable to high-interference environments (such as vehicle-mounted and industrial), realizes the immutability of anti-counterfeiting and traceability in blockchain on-chain verification, reduces the risk of centralized storage; resists quantum computing attacks through post-quantum encrypted session keys to ensure communication security in the next decade; realizes the system's autonomous adaptive response ability to environmental changes and attacks through noise compensation during PUF response.

[0072] To make the technical solutions and advantages in the embodiments of this application clearer, the following further details the exemplary embodiments of this application with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, rather than an exhaustive list of all embodiments. It should be noted that, without conflict, the embodiments in this application and the features in the embodiments can be combined with each other.

[0073] Embodiment 1

[0074] Figure 1 The step schematic diagram of the multi-modal challenge-response identity authentication method based on PUF according to the embodiment of this application is shown.

[0075] As Figure 1 shown, a multi-modal challenge-response identity authentication method based on PUF according to the embodiment of this application, applied to an authentication server, includes:

[0076] S1: After receiving the authentication instruction, dynamically determine the dynamic input factor according to the target scenario;

[0077] S2: Generate a random challenge code integrating scene characteristics using a dynamic weight allocation algorithm based on dynamic input factors and static factors;

[0078] S3: Send the random challenge code to the target device so that the target device generates an adaptive PUF response through the PUF chip, and generates a composite anti-counterfeiting code after binding the adaptive PUF response with the physical label;

[0079] S4: Perform identity authentication through the verification logic based on the random challenge code and the composite anti-counterfeiting code.

[0080] This application realizes identity authentication based on PUF combined with specific target scenarios, is applicable to multi-scenario identity authentication requirements, greatly reduces the computational overhead, and improves the randomness and scene adaptability of the challenge code.

[0081] During specific implementation, after the identity authentication is passed, the authentication server generates a session key based on the adaptive PUF response and the dynamic input factors, and uses a post-quantum encryption algorithm to perform encrypted communication transmission with the target device.

[0082] According to the adaptive response generated in S3, use a fuzzy extractor to eliminate environmental noise and generate a stable key seed Kseed; the dynamic weighted factor obtained by fusing the dynamic input factors; through a key derivation function (KDF), combine the key seed Kseed and the dynamic weighted factor to generate the final session key SK; then generate

[0083] NTRU key pair: public key PK, private key SK NTRU ; Finally, perform encrypted transmission and decrypted dialogue communication through the encrypted key pair.

[0084] This application resists quantum computing attacks through post-quantum encrypted session keys. By combining the hardware uniqueness of PUF, the scene adaptability of dynamic factors, and the post-quantum security of NTRU, this solution provides an end-to-end encrypted communication framework for high-security requirement scenarios such as the Internet of Things and the Internet of Vehicles. Through the seamless integration of dynamic key generation and anti-quantum algorithms, the balance between long-term security and real-time performance is ensured.

[0085] During specific implementation, the target scenarios of the embodiments of this application include the Internet of Things, the Internet of Vehicles, and anti-counterfeiting traceability.

[0086] The dynamic input factors include environmental factors, behavior factors, and time factors. The environmental factors include GPS coordinate values, environmental temperature values, and voltage fluctuation values; the behavior factors include device operation log hash values and user interaction behavior patterns; the time factors include millisecond-level timestamps and historical authentication time series entropy values.

[0087] Static factors include device identification and product serial number.

[0088] Regarding environmental factors, it also includes scenario factors of the target scenario. For example, the Internet of Things also includes scenario factors such as sensor data (temperature and humidity, light intensity). The Internet of Vehicles also includes scenario factors such as vehicle speed, CAN bus status, and OBD-II fault codes. Anti-counterfeiting and traceability also includes scenario factors such as material spectral hash value and production batch information.

[0089] All relevant factors are collected in real time through device sensors, system logs, or user input. Then, standardization processing is performed: non-numerical factors (such as GPS coordinates) are converted into numerical values or hash values in a fixed format.

[0090] Figure 2 The schematic diagram of the steps for generating a random challenge code that fuses scenario characteristics by the dynamic weight allocation algorithm according to an embodiment of the present application is shown.

[0091] As Figure 2 shown, next, in S2, a random challenge code that fuses scenario characteristics is generated using the dynamic weight allocation algorithm, including:

[0092] S21: Calculate the information entropy of each factor, and normalize the entropy value of each factor to obtain the weight coefficient of each factor.

[0093] The information entropy of each factor is calculated using the Shannon entropy formula:

[0094]

[0095] where X i is the set of possible values of the i-th factor, and P(x) is the probability of taking a value (statistically based on historical data).

[0096] Normalize the entropy value to the weight coefficient:

[0097]

[0098] where W i is the weight coefficient of the i-th factor.

[0099] S22: Introduce a scenario adjustment coefficient to perform dynamic scenario adjustment of the weight coefficient to obtain the dynamic weight coefficient w′ i .

[0100] Introduce a scenario adjustment coefficient α s , such as in the Internet of Vehicles scenario, α s = 1.2, and in anti-counterfeiting and traceability, α s = 0.8.

[0101] w′ i = w i·α s ·(1 + β · real - time risk score);

[0102] where β is the risk - sensitivity coefficient (which can be set according to the target scenario), and the real - time risk score is output by the threat detection model (0 - 1).

[0103] Ensure that the sum of the weights is 1 to obtain the final dynamic weight coefficient w″ i :

[0104]

[0105] S23: Determine the weighted factor set {(F1, w″1), (F2, w″2),..., (F n , w″ n )} according to the dynamic weight coefficient and the corresponding factor.

[0106] where F1, F2, F n is the numerical value or hash value of each factor, and w″ i is the dynamic weight coefficient corresponding to each factor.

[0107] S24: After concatenating the weighted factors, use the HMAC - DRBG algorithm to generate a random challenge code.

[0108] First, sort the factors by weight, allocate high - weight factors to the high positions and then concatenate them to obtain intermediate data:

[0109]

[0110] where Encode(Fi) is to convert the factor into a fixed - length binary (such as 32 - bit); is the bit - wise exclusive - or operation to ensure non - linear fusion.

[0111] Then, use the HMAC - DRBG algorithm to generate the final challenge code:

[0112] Challenge code = HMAC - DRBG(intermediate data || hardware entropy source, key material);

[0113] where the key material is the combination of the pre - set server key and the timestamp entropy value, and its output length is 256 bits (32 bytes), which is converted into Base64 or hexadecimal format.

[0114] Regarding the hardware entropy source, it refers to the source that generates random numbers at the hardware level, mainly used to generate true random numbers (TRNG). The hardware entropy source relies on the randomness of physical phenomena, such as quantum effects, electronic noise, etc., to generate unpredictable random numbers.

[0115] The process of generating the random challenge code above is further illustrated by specific examples. For example, in the scenario of vehicle networking device authentication.

[0116] Static factor: Device VIN code: VIN-1HGBH41JXMN109186

[0117] Dynamic factors: Timestamp 20240520123045123; Real-time vehicle speed 80 km / h; CAN bus status 0x1A3F. Ambient temperature 35°C.

[0118] Then, the entropy values and weights of each factor are calculated.

[0119] The VIN code has a low entropy value (fixed identifier), and the weight w1 = 0.1; the timestamp has a high entropy value, and the weight w2 = 0.4; the vehicle speed has a medium entropy value, and the weight w3 = 0.3; the CAN status has a high entropy value, and the weight w4 = 0.2.

[0120] When the scenario is adjusted, α s = 1.2, and the real-time risk score = 0.3.

[0121] We get w′2 = 0.4·1.2·(1 + 0.1·0.3) = 0.494; the other weights are adjusted similarly and finally normalized.

[0122] The factors are concatenated and fused to obtain: Intermediate data = (w1·VIN) ⊕ (w2·timestamp) ⊕ (w3·vehicle speed) ⊕ (w4·CAN status).

[0123] Finally, the challenge code is generated:

[0124] Challenge code = HMAC-DRBG(Intermediate data || CPU noise, key) = 0x8A9C...F2B1.

[0125] This application generates a random challenge code through a dynamic weight distribution algorithm, achieving a highly scenario-adaptive and secure challenge code generation mechanism through dynamic weight distribution, multi-factor fusion, and cryptographic random number generation, which can be widely applied in fields such as the Internet of Things, vehicle networking, and anti-counterfeiting traceability.

[0126] Breaking the fixed pattern through dynamic weights and multi-factor fusion to resist statistical analysis attacks; enhancing scenario adaptability and optimizing the balance between security and performance in different scenarios through adjustment coefficients.

[0127] Figure 3 The schematic diagram of the steps for identity authentication through the verification logic according to the embodiments of the present application is shown.

[0128] As Figure 3 shown, next, in S4, identity authentication is performed through the verification logic based on the random challenge code and the composite anti-counterfeiting code, including:

[0129] S41: Bind the random challenge code to the composite anti-counterfeiting code to form a unique response pair. For example: (Challenge||Response||TagData).

[0130] S42: Generate an irreversible hash value through hash operation based on the response pair.

[0131] Hash = SM3(Challenge||Response||TagData);

[0132] SM3 is a collision-resistant hash algorithm, and SHA-256 algorithm can also be used as an alternative.

[0133] Then generate a hash value with a fixed length (such as 256 bits).

[0134] S43: Compare the hash value with the pre-stored key, and complete the verification through a smart contract or a local database; after successful verification, update the pre-stored key.

[0135] When the device is registered, store the hash value of the response pair in the blockchain or a centralized database.

[0136] For example, storing in the blockchain: write the hash value into the smart contract to ensure immutability. Storing in the local database: use digital signature to protect the reference value (such as ECDSA signature).

[0137] During verification, first the device sends the generated hash value to the authentication server or a blockchain node; during comparison, for blockchain verification: the smart contract automatically executes the comparison logic to check whether the hash value stored on the chain matches, and for local verification: the server queries the database to compare the received hash value with the pre-stored value; finally, if the match is successful: return an authentication passed signal to trigger subsequent operations (such as updating logistics records, activating session keys). If the match fails: trigger an alarm mechanism (such as locking the device, recording exception logs).

[0138] This application achieves immutability through the above verification process: blockchain storage ensures that the reference hash value cannot be maliciously modified. Achieves efficient verification: the hash comparison has a time complexity of O(1), supporting high-concurrency scenarios. Achieves anti-environmental interference: PUF response dynamic compensation mechanism + timestamp constraint, reducing the misjudgment rate. Achieves cross-platform compatibility: hash algorithm standardization (such as SM3, SHA-256), adapting to different hardware and protocols.

[0139] Therefore, this application can provide highly secure and reliable identity verification services in scenarios such as anti-counterfeiting traceability and Internet of Things device authentication.

[0140] In summary, the PUF-based multi-modal challenge-response identity authentication method according to the embodiments of the present application includes: after receiving an authentication instruction, dynamically determining dynamic input factors according to the target scenario; using a dynamic weight allocation algorithm to generate a random challenge code that integrates scenario characteristics according to the dynamic input factors and static factors; sending the random challenge code to the target device so that the target device generates an adaptive PUF response through the PUF chip, and generating a composite anti-counterfeiting code after binding the adaptive PUF response with the physical tag; and performing identity authentication through the verification logic according to the random challenge code and the composite anti-counterfeiting code. It realizes identity authentication based on PUF combined with specific target scenarios, is applicable to multi-scenario identity authentication requirements, greatly reduces the computational overhead, and improves the randomness and scenario adaptability of the challenge code.

[0141] The present application breaks through the traditional single hardware dependence of PUF, integrates physical, behavioral, and time multi-dimensional factors, and adapts to the requirements of complex scenarios; greatly improves the randomness and scenario adaptability of the challenge code.

[0142] In addition, the present application enhances the response stability, is applicable to high-interference environments (such as vehicle-mounted and industrial), realizes the immutability of anti-counterfeiting and traceability in the blockchain chain verification, reduces the risk of centralized storage; resists quantum computing attacks through post-quantum encrypted session keys, and ensures communication security in the next decade; realizes the system's autonomous adaptive response ability to environmental changes and attacks through noise compensation during PUF response.

[0143] Embodiment 2

[0144] This embodiment provides another PUF-based multi-modal challenge-response identity authentication method. For details not disclosed in the PUF-based multi-modal challenge-response identity authentication method of this embodiment, please refer to the specific implementation content of the PUF-based multi-modal challenge-response identity authentication scheme in other embodiments.

[0145] Figure 4 The step schematic diagram of another PUF-based multi-modal challenge-response identity authentication method according to the embodiments of the present application is shown.

[0146] As Figure 4 shown, a PUF-based multi-modal challenge-response identity authentication method, applied to a target device, includes:

[0147] S5: Sending an authentication instruction to an authentication server so that the authentication server dynamically determines dynamic input factors according to the target scenario; and using a dynamic weight allocation algorithm to generate a random challenge code that integrates scenario characteristics according to the dynamic input factors and static factors;

[0148] S6: Receiving the random challenge code and generating an adaptive PUF response through the PUF chip;

[0149] S7: Generate a composite anti-counterfeiting code after binding the adaptive PUF response with the physical tag;

[0150] S8: Send the composite anti-counterfeiting code to the authentication server so that the authentication server can perform identity authentication through the verification logic based on the random challenge code and the composite anti-counterfeiting code.

[0151] This application breaks through the traditional single hardware dependence of PUF, integrates physical, behavioral, and time multi-dimensional factors, and adapts to the requirements of complex scenarios; greatly improves the randomness and scenario adaptability of the challenge code.

[0152] Figure 5 The schematic diagram of the steps for generating the adaptive PUF response according to the embodiment of the present application is shown.

[0153] As Figure 5 shown, receiving the random challenge code in S6 and generating the adaptive PUF response through the PUF chip includes the following steps:

[0154] S61: Generate the original PUF response R using the PUF (Physical Unclonable Function) according to the random challenge code raw .

[0155] S62: Collect the real-time data of the PUF operating environment, environmental parameters (T current , V current ).

[0156] By embedding an environmental noise compensation module such as: integrating a temperature sensor and a voltage monitoring circuit; real-time monitoring of environmental parameters (temperature, voltage, humidity, etc.), and real-time correction of the response deviation caused by temperature and voltage fluctuations.

[0157] Specifically, embed high-precision sensors inside or near the PUF chip. Include a temperature sensor (such as PT100 or digital temperature sensor DS18B20); a voltage monitoring circuit: real-time measurement of the power supply voltage fluctuation of the PUF (±5% accuracy); a humidity sensor (optional, for high-humidity scenarios).

[0158] The sensor data is digitized through an ADC (Analog-to-Digital Converter) and transmitted to the microcontroller. When sampling the data, set the sampling rate according to the environmental change speed (such as sampling the temperature every 10 ms).

[0159] S63: Establish a response deviation model for each environmental parameter and the PUF response deviation.

[0160] Collect PUF response data under different environmental conditions (such as temperature -40°C to 85°C, voltage ±10% fluctuation).

[0161] Construct a mapping model of environmental parameters (temperature T, voltage V) and response deviation ΔR as follows:

[0162] ΔR = F(T, V) = a·T + b·V + c·T·V + ∈;

[0163] Wherein, a, b, and c are fitting coefficients, and ∈ is the residual. The model parameters are optimized using machine learning algorithms (such as linear regression, support vector machine).

[0164] S64: Based on the predicted deviation from the response deviation model, the original PUF response is corrected in real time to obtain an adaptive PUF response.

[0165] The current environmental parameters (T current , V current ) are input into the model in real time to obtain the predicted deviation ΔR predicted .

[0166] The original PUF response R raw is corrected as follows:

[0167]

[0168] Wherein, ⊕ represents a bitwise exclusive OR operation (or other non-linear compensation logic).

[0169] For a dynamic environment (such as vehicle vibration), the real-time deviation is predicted through Kalman filtering and the result is smoothed and corrected.

[0170] The PUF response deviation is predicted through a Kalman filter, and the output value is dynamically corrected to increase the error tolerance rate to ±10%.

[0171] Through the above adaptive mechanism of the PUF response, the cross-scenario applicability can be significantly improved during the PUF response generation stage, ensuring high-reliability identity authentication services can still be provided in complex environments.

[0172] Embodiment 3

[0173] This embodiment provides a PUF-based multi-modal challenge-response identity authentication device. For details not disclosed in the PUF-based multi-modal challenge-response identity authentication device of this embodiment, please refer to the specific implementation content of the PUF-based multi-modal challenge-response identity authentication scheme in other embodiments.

[0174] Figure 6 The structural schematic diagram of a PUF-based multi-modal challenge-response identity authentication device according to an embodiment of the present application is shown in

[0175] As Figure 6 shown, a PUF-based multi-modal challenge-response identity authentication device according to an embodiment of the present application, which is applied to an authentication server, includes:

[0176] Factor module 10: After receiving an authentication instruction, it dynamically determines dynamic input factors according to the target scenario;

[0177] Generation module 20: It is used to generate a random challenge code that integrates scene characteristics using a dynamic weight allocation algorithm according to the dynamic input factors and static factors;

[0178] Response module 30: It is used to send the random challenge code to the target device so that the target device generates an adaptive PUF response through the PUF chip, and generates a composite anti-counterfeiting code after binding the adaptive PUF response with the physical tag;

[0179] Verification module 40: It is used to perform identity verification through verification logic based on the random challenge code and the composite anti-counterfeiting code.

[0180] In summary, the PUF-based multi-modal challenge-response identity authentication system according to the embodiments of the present application includes: after the factor module 10 receives an authentication instruction, it dynamically determines dynamic input factors according to the target scenario; the generation module 20 generates a random challenge code that integrates scene characteristics using a dynamic weight allocation algorithm according to the dynamic input factors and static factors; the response module 30 sends the random challenge code to the target device so that the target device generates an adaptive PUF response through the PUF chip, and generates a composite anti-counterfeiting code after binding the adaptive PUF response with the physical tag; the verification module 40 performs identity verification through verification logic based on the random challenge code and the composite anti-counterfeiting code. The present application realizes identity authentication based on PUF combined with specific target scenarios, is applicable to multi-scenario identity verification requirements, greatly reduces the computing overhead, and improves the randomness and scene adaptability of the challenge code.

[0181] The present application breaks through the traditional single hardware dependence of PUF, integrates physical, behavioral, and time multi-dimensional factors, and adapts to complex scenario requirements; greatly improves the randomness and scene adaptability of the challenge code.

[0182] In addition, the present application enhances the response stability, is applicable to high-interference environments (such as vehicle-mounted and industrial), realizes the immutability of anti-counterfeiting traceability in blockchain on-chain verification, and reduces the risk of centralized storage; resists quantum computing attacks through post-quantum encrypted session keys to ensure communication security in the next decade; realizes the system's autonomous adaptive response ability to environmental changes and attacks through noise compensation during PUF response.

[0183] Embodiment 4

[0184] This embodiment provides another PUF-based multi-modal challenge-response identity authentication device. For details not disclosed in the PUF-based multi-modal challenge-response identity authentication device of this embodiment, please refer to the specific implementation content of the PUF-based multi-modal challenge-response identity authentication solution in other embodiments.

[0185] Figure 7 The structural schematic diagram of another PUF-based multi-modal challenge-response identity authentication device according to an embodiment of the present application is shown.

[0186] As Figure 7 shown, a PUF-based multi-modal challenge-response identity authentication device according to an embodiment of the present application is applied to a target device and includes:

[0187] A challenge module 50: configured to send an authentication instruction to an authentication server so that the authentication server dynamically determines dynamic input factors according to a target scenario; and generate a random challenge code integrating scenario characteristics using a dynamic weight allocation algorithm according to the dynamic input factors and static factors;

[0188] A first response module 60: configured to receive the random challenge code and generate an adaptive PUF response through a PUF chip;

[0189] A second response module 70: configured to generate a composite anti-counterfeiting code after binding the adaptive PUF response with a physical tag;

[0190] A sending module 80: configured to send the composite anti-counterfeiting code to the authentication server so that the authentication server performs identity authentication through a verification logic according to the random challenge code and the composite anti-counterfeiting code.

[0191] Embodiment 5

[0192] This embodiment provides a PUF-based multi-modal challenge-response identity authentication system. For details not disclosed in the PUF-based multi-modal challenge-response identity authentication system of this embodiment, please refer to the specific implementation content of the PUF-based multi-modal challenge-response identity authentication solution in other embodiments.

[0193] Figure 8 The structural schematic diagram of another PUF-based multi-modal challenge-response identity authentication system according to an embodiment of the present application is shown.

[0194] As Figure 8 shown, a PUF-based multi-modal challenge-response identity authentication system according to an embodiment of the present application includes an authentication server 1 and a target device 2;

[0195] The authentication server 1: configured to, after receiving an authentication instruction, dynamically determine dynamic input factors according to a target scenario; generate a random challenge code integrating scenario characteristics using a dynamic weight allocation algorithm according to the dynamic input factors and static factors; send the random challenge code to the target device so that the target device generates an adaptive PUF response through a PUF chip and generates a composite anti-counterfeiting code after binding the adaptive PUF response with a physical tag; perform identity authentication through a verification logic according to the random challenge code and the composite anti-counterfeiting code;

[0196] Target device 2: It is used to send an authentication instruction to the authentication server so that the authentication server can dynamically determine the dynamic input factor according to the target scenario; and according to the dynamic input factor and the static factor, use the dynamic weight allocation algorithm to generate a random challenge code that integrates the scenario characteristics; receive the random challenge code, generate an adaptive PUF response through the PUF chip; bind the adaptive PUF response with the physical tag to generate a composite anti-counterfeiting code; send the composite anti-counterfeiting code to the authentication server so that the authentication server can perform identity authentication through the verification logic according to the random challenge code and the composite anti-counterfeiting code.

[0197] Embodiment 6

[0198] This embodiment provides another PUF-based multi-modal challenge-response identity authentication device. For the details not disclosed in the PUF-based multi-modal challenge-response identity authentication device of this embodiment, please refer to the specific implementation content of the PUF-based multi-modal challenge-response identity authentication method or system in other embodiments.

[0199] Figure 9 The structural schematic diagram of the PUF-based multi-modal challenge-response identity authentication device 400 according to an embodiment of the present application is shown.

[0200] As Figure 9 shown, the PUF-based multi-modal challenge-response identity authentication device 400 includes: a storage unit 402: used to store executable instructions; and a processing unit 401: used to connect with the storage unit 402 to execute the executable instructions so as to complete the PUF-based multi-modal challenge-response identity authentication method.

[0201] Those skilled in the art can understand that the schematic Figure 9 is only an example of the PUF-based multi-modal challenge-response identity authentication device 400, and does not constitute a limitation on the PUF-based multi-modal challenge-response identity authentication device 400. It may include more or fewer components than shown in the figure, or combine some components, or different components. For example, the PUF-based multi-modal challenge-response identity authentication device 400 may also include input / output devices, network access devices, buses, etc.

[0202] The so-called processing unit 401 (Central Processing Unit, CPU) can also be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor, or the processing unit 401 can also be any conventional processor, etc. The processing unit 401 is the control center of the PUF-based multi-modal challenge-response identity authentication device 400, and connects all parts of the PUF-based multi-modal challenge-response identity authentication device 400 through various interfaces and lines.

[0203] The storage unit 402 can be used to store computer-readable instructions. The processing unit 401 realizes various functions of the PUF-based multi-modal challenge-response identity authentication device 400 by running or executing the computer-readable instructions or modules stored in the storage unit 402, and by calling the data stored in the storage unit 402. The storage unit 402 mainly includes a program storage area and a data storage area. Among them, the program storage area can store an operating system, application programs required for at least one function (such as a sound playback function, an image playback function, etc.); the data storage area can store data created according to the use of the PUF-based multi-modal challenge-response identity authentication device 400. In addition, the storage unit 402 can include a hard disk, memory, plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, at least one magnetic disk storage device, flash device, read-only memory (ROM), random access memory (RAM), or other non-volatile / volatile storage devices.

[0204] If the modules integrated in the PUF-based multi-modal challenge-response identity authentication device 400 are implemented in the form of software function modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, to implement all or part of the processes in the above-mentioned embodiment methods of the present invention, it can also be completed by instructing relevant hardware through computer-readable instructions. The computer-readable instructions can be stored in a computer-readable storage medium. When the computer-readable instructions are executed by a processor, the steps of the above-mentioned various method embodiments can be implemented.

[0205] Example 7

[0206] This embodiment provides a computer-readable storage medium, on which a computer program is stored; the computer program is executed by a processor to implement the PUF-based multi-modal challenge-response identity authentication method in other embodiments.

[0207] Those skilled in the art should understand that the terms used in the present invention are only for the purpose of describing specific embodiments and are not intended to limit the present invention. The singular forms "a", "the" and "said" used in the present invention and the appended claims are also intended to include the plural forms unless the context clearly dictates otherwise. It should also be understood that the term "and / or" as used herein refers to and encompasses any and all possible combinations of one or more of the associated listed items.

[0208] It should be understood that although the terms first, second, third, etc. may be used in the present invention to describe various information, such information should not be limited to these terms. These terms are only used to distinguish the same type of information from each other. For example, without departing from the scope of the present invention, the first information may also be referred to as the second information, and similarly, the second information may also be referred to as the first information. Depending on the context, the word "if" as used herein may be interpreted as "when" or "while" or "in response to determining".

[0209] Although the preferred embodiments of the present application have been described, those skilled in the art can make additional changes and modifications once they learn the basic creative concept. Therefore, the appended claims are intended to be interpreted to include the preferred embodiments as well as all changes and modifications that fall within the scope of the present application.

[0210] Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalent technologies, the present application is also intended to include these modifications and variations.

Claims

1. A multi-modal challenge-response identity authentication method based on PUF, characterized in that, Applied to an authentication server, including: After receiving an authentication instruction, dynamically determine dynamic input factors according to the target scenario; According to the dynamic input factors and static factors, use a dynamic weight allocation algorithm to generate a random challenge code that integrates scene characteristics; Send the random challenge code to the target device so that the target device generates an adaptive PUF response through the PUF chip, and generate a composite anti-counterfeiting code after binding the adaptive PUF response with the physical tag; Perform identity authentication through the verification logic according to the random challenge code and the composite anti-counterfeiting code.

2. The multi-modal challenge-response identity authentication method based on PUF according to claim 1, characterized in that The method further includes: After the identity authentication is passed, the authentication server generates a session key based on the adaptive PUF response and the dynamic input factors, and uses a post-quantum encryption algorithm to perform encrypted communication transmission with the target device.

3. The multi-modal challenge-response identity authentication method based on PUF according to claim 1, characterized in that The target scenarios include the Internet of Things, the Internet of Vehicles, and anti-counterfeiting traceability; The dynamic input factors include environmental factors, behavior factors, and time factors; the environmental factors include GPS coordinate values, environmental temperature values, and voltage fluctuation values; The behavior factors include device operation log hash values and user interaction behavior patterns; The time factors include millisecond-level timestamps and historical authentication time series entropy values; The static factors include device identifiers and product serial numbers.

4. The multi-modal challenge-response identity authentication method based on PUF according to claim 1, characterized in that, The using a dynamic weight allocation algorithm to generate a random challenge code that integrates scene characteristics includes: Calculate the information entropy of each factor, and normalize the entropy value of each factor to obtain the weight coefficient of each factor; Introduce a scene adjustment coefficient to perform dynamic scene adjustment of the weight coefficient to obtain a dynamic weight coefficient; Determine a weighted factor set according to the dynamic weight coefficient and the corresponding factor; After splicing the weighted factors, use the HMAC-DRBG algorithm to generate a random challenge code.

5. The multi-modal challenge-response identity authentication method based on PUF according to claim 1, wherein The performing identity authentication through the verification logic according to the random challenge code and the composite anti-counterfeiting code includes: Bind the random challenge code with the composite anti-counterfeiting code to form a unique response pair; Generate an irreversible hash value through hash operation according to the response pair; Compare the hash value with the pre-stored key, and complete the verification through a smart contract or a local database; update the pre-stored key after successful verification.

6. A multi-modal challenge-response identity authentication method based on PUF, characterized in that, Applied to a target device, including: Send an authentication instruction to the authentication server so that the authentication server dynamically determines dynamic input factors according to the target scenario; and use a dynamic weight allocation algorithm to generate a random challenge code that integrates scene characteristics according to the dynamic input factors and static factors; Receive the random challenge code and generate an adaptive PUF response through the PUF chip; Generate a composite anti-counterfeiting code after binding the adaptive PUF response with the physical tag; Send the composite anti-counterfeiting code to the authentication server so that the authentication server performs identity authentication through the verification logic according to the random challenge code and the composite anti-counterfeiting code.

7. The method for multi-modal challenge-response identity authentication based on PUF according to claim 6, wherein The receiving the random challenge code and generating an adaptive PUF response through the PUF chip includes: Generate an original PUF response using a PUF (physically unclonable function) according to the random challenge code; Collect real-time data of the PUF operating environment; Establish a response deviation model between each environmental parameter and the PUF response deviation; Based on the predicted deviation of the response deviation model, the original PUF response is corrected in real time to obtain an adaptive PUF response.

8. A multi-modal challenge-response identity authentication device based on PUF, characterized in that, Applied to the authentication server, it includes: Factor module: After receiving the authentication instruction, it is used to dynamically determine the dynamic input factors according to the target scenario; Generation module: It is used to generate a random challenge code that integrates the scenario characteristics using a dynamic weight allocation algorithm according to the dynamic input factors and static factors; Response module: It is used to send the random challenge code to the target device, so that the target device generates an adaptive PUF response through the PUF chip, and generates a composite anti-counterfeiting code after binding the adaptive PUF response with the physical label; Verification module: It is used to perform identity verification through the verification logic according to the random challenge code and the composite anti-counterfeiting code.

9. A multi-modal challenge-response identity authentication device based on PUF, characterized in that, Applied to the target device, it includes: Challenge module: It is used to send an authentication instruction to the authentication server, so that the authentication server dynamically determines the dynamic input factors according to the target scenario; and generates a random challenge code that integrates the scenario characteristics using a dynamic weight allocation algorithm according to the dynamic input factors and static factors; First response module: It is used to receive the random challenge code and generate an adaptive PUF response through the PUF chip; Second response module: It is used to generate a composite anti-counterfeiting code after binding the adaptive PUF response with the physical label; Sending module: It is used to send the composite anti-counterfeiting code to the authentication server, so that the authentication server performs identity verification through the verification logic according to the random challenge code and the composite anti-counterfeiting code.

10. A PUF-based multi-modal challenge-response identity authentication system, characterized in that, It includes an authentication server and a target device; The authentication server: After receiving the authentication instruction, it is used to dynamically determine the dynamic input factors according to the target scenario; generate a random challenge code that integrates the scenario characteristics using a dynamic weight allocation algorithm according to the dynamic input factors and static factors; send the random challenge code to the target device, so that the target device generates an adaptive PUF response through the PUF chip, and generates a composite anti-counterfeiting code after binding the adaptive PUF response with the physical label; perform identity verification through the verification logic according to the random challenge code and the composite anti-counterfeiting code; The target device: It is used to send an authentication instruction to the authentication server, so that the authentication server dynamically determines the dynamic input factors according to the target scenario; and generates a random challenge code that integrates the scenario characteristics using a dynamic weight allocation algorithm according to the dynamic input factors and static factors; receive the random challenge code, generate an adaptive PUF response through the PUF chip; generate a composite anti-counterfeiting code after binding the adaptive PUF response with the physical label; send the composite anti-counterfeiting code to the authentication server, so that the authentication server performs identity verification through the verification logic according to the random challenge code and the composite anti-counterfeiting code.

Citation Information

Cited By

  • Identity authentication method and related equipment

    CN120602103A

  • Identity authentication method, target device, verification terminal, system, device, medium and product

    CN121125127A