IKE protocol security enhancement method based on PUF dynamic authentication and post quantum hybrid key

By combining PUF and Kyber KEM, the post-quantum security key exchange and identity authentication of the IKE protocol are implemented, solving the problem of insufficient security of the IKE protocol under quantum computing attacks and is suitable for IoT devices.

CN120281485APending Publication Date: 2025-07-08MIXUAN TECHNOLOGY (HANGZHOU) CO LTD
View PDF 0 Cites 5 Cited by

Patent Information

Application Number
CN202510560144.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-30
Publication Date
2025-07-08

AI Technical Summary

Technical Problem

When the existing IKE protocol faces quantum computing attacks, there are insufficient security problems of key exchange and identity authentication, especially the Diffie-Hellman key exchange algorithm is vulnerable to attacks, and the traditional identity authentication mechanism cannot withstand the attacks of quantum computers.

Method used

Combining physical non-cloneable function (PUF) and post-quantum cryptographic algorithm (PQC, specifically Kyber KEM), dynamic pre-shared keys are generated through PUF and combined with the improved IKE protocol to achieve dual post-quantum security of key exchange and identity authentication.

Benefits of technology

It realizes post-quantum-security key exchange and identity authentication, enhances resistance to classical computing and quantum computing attacks, is suitable for resource-constrained IoT devices, and is easy to deploy and compatible with existing IKE protocols.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120281485A_ABST
    Figure CN120281485A_ABST
Patent Text Reader

Abstract

The invention provides an IKE (Internet Key Exchange) protocol security enhancement method based on PUF (Physical Unclonable Function) dynamic authentication and a post-quantum mixed key, which organically combines a PUF, a post-quantum cryptographic algorithm (PQC, especially Kyber KEM) and an improved Internet Key Exchange Protocol (IKE) to realize key exchange of post-quantum security and enhanced identity authentication. The method comprises the following steps: generating a dynamic pre-shared key (PSK) by utilizing the PUF; the method comprises the following steps: integrating a Kyber KEM to an IKE protocol, and replacing traditional Diffie-Hellman key exchange; the PUF-driven dynamic PSK is used as an identity authentication method of the IKE; meanwhile, Kyber KEM and ECDH are adopted for key exchange, and a final session key is generated through joint participation of a Kyber negotiation key, an ECDH negotiation key and PSK derived by PUF; and an IKE protocol process is optimized, and Kyber key exchange and PUF (Physical Unclonable Function) authentication are completed in an IKESAINIT stage and an IKEINTERMEDIATE stage. According to the method, key exchange is post-quantum secure, identity authentication is also post-quantum secure, and the final key integrates three key components of Kyber, ECDH and PUF, so that triple security assurance is provided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the fields of network security and cryptography, and particularly relates to a network key negotiation method that combines a Physical Unclonable Function (PUF), the Internet Key Exchange protocol (IKE), and a Post-Quantum Cryptography (PQC) algorithm. This method is applied to network communication scenarios that resist classical computing attacks and quantum computing attacks, and is particularly suitable for virtual private networks (VPNs), etc. Background Art

[0002] Network communication security mainly relies on traditional public-key cryptosystems, such as RSA, ECC, and Diffie-Hellman (DH) key exchange. However, with the development of quantum computing technology, especially the emergence of the Shor algorithm, these traditional cryptosystems are facing serious threats.

[0003] To address the security challenges brought by quantum computing, the research and standardization work of Post-Quantum Cryptography (PQC) is being actively promoted. IPsec VPN widely uses the IKE protocol to negotiate and establish security associations. However, the existing IKE protocol usually uses the Diffie-Hellman key exchange algorithm to generate shared keys, which is vulnerable to attacks by quantum computers.

[0004] The industry has proposed a solution to integrate the PQC algorithm into the IKE protocol, mainly by replacing the DH key exchange algorithm in IKE with a PQC key exchange algorithm (such as Kyber) to achieve post-quantum security. However, these solutions usually ignore the protection of the identity authentication mechanism in the IKE protocol, and the identity authentication mechanism (such as the pre-shared key PSK or digital certificate) also cannot resist attacks by quantum computers.

[0005] In addition, some research has proposed applying Physical Unclonable Function (PUF) technology to the identity authentication of network devices. However, existing PUF-based identity authentication schemes usually only focus on the authentication of the device itself and are not closely combined with the key exchange protocol.

[0006] Quantum Key Distribution (QKD) technology can theoretically achieve secure key negotiation, but there are practical problems such as high cost and difficult deployment. The traditional certificate system has serious adaptation problems in the Internet of Things scenario.

[0007] This application aims to simultaneously achieve post-quantum secure key exchange and identity authentication in the IKE protocol, and overcome the limitations of existing technologies in terms of security, performance, cost, and deployment. Summary of the Invention

[0008] To solve the above problems, this application proposes a security enhancement method for the IKE protocol based on PUF dynamic authentication and post-quantum hybrid keys. This method organically combines the Physical Unclonable Function (PUF), the post-quantum cryptographic algorithm (PQC, specifically KyberKEM), and the improved Internet Key Exchange protocol (IKE) to achieve post-quantum secure key exchange and enhanced identity authentication.

[0009] The core technical solutions of this application include:

[0010] PUF-driven dynamic Pre-Shared Key (PSK): In the client registration phase, multiple Challenge-Response Pairs (CRPs) are generated using PUF and securely stored on the server; in the authentication phase, the server sends a challenge value, and the client PUF generates a response, and a dynamic PSK is derived from the hash value of this response. Different from traditional static PSKs, this PSK has dynamicity and unpredictability.

[0011] Deep integration of PQC (Kyber KEM) and PUF authentication: Integrate Kyber KEM into the IKE protocol to replace the traditional Diffie-Hellman key exchange; use the above PUF-driven dynamic PSK as the identity authentication method for IKE. It realizes double post-quantum reinforcement of key exchange and identity authentication.

[0012] Hybrid key negotiation: Simultaneously use Kyber KEM and ECDH for key exchange; the final session key is jointly generated by the Kyber negotiated key, the ECDH negotiated key, and the PSK derived from PUF. The triple key components significantly enhance security.

[0013] Optimized IKE protocol process: Complete Kyber key exchange and PUF authentication in the IKE_SA_INIT and IKE_INTERMEDIATE phases. The process is optimized, reducing latency and overhead.

[0014] Advantages over the prior art:

[0015] Comprehensive post-quantum security: Not only is the key exchange post-quantum secure (Kyber KEM), but the identity authentication is also post-quantum secure (PUF dynamic PSK).

[0016] Triple key guarantee: The final key integrates three key components of Kyber, ECDH, and PUF, far exceeding the security of a single key mechanism.

[0017] Enhanced dynamic authentication: The PUF dynamic PSK avoids the inherent risks of static PSKs (such as leakage and replay attacks).

[0018] IoT - friendly: The hardware characteristics of PUF and the lightweight design of Kyber are very suitable for resource - constrained IoT devices.

[0019] Efficient and easy to deploy: Optimizes the IKE process, is compatible with the existing IKE protocol framework, and is easy to upgrade and deploy.

[0020] Core innovations of this application:

[0021] For the first time, combines PUF technology with the PSK authentication mechanism of the IKE protocol to achieve dynamic, post - quantum - secure pre - shared key generation and avoid the security risks of static PSKs.

[0022] Proposes an IKE protocol framework that integrates PQC key exchange and PUF authentication to achieve dual post - quantum - secure protection. Adopts Kyber KEM and does not use PQC signature algorithms to keep the protocol lightweight.

[0023] Designs a hybrid key negotiation mechanism that balances security and performance. The final key integrates three key components: Kyber, ECDH, and PUF, further enhancing security.

[0024] Lightweight adaptation for IoT devices: The native hardware characteristics of the PUF module can directly generate dynamic keys (without key storage). Combining with the memory - occupancy advantage of the Kyber algorithm, it reduces power consumption, decreases memory occupancy, and adapts to low - bandwidth scenarios.

[0025] Optimizes the IKE protocol process to reduce the transmission overhead and computational latency of PUF responses.

[0026] The final session key integrates the results of PUF, Kyber, and DH to provide triple security. Description of the drawings

[0027] To more clearly illustrate the technical solutions of the embodiments of this application, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of this application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0028] Figure 1 Is the client registration flowchart;

[0029] Figure 2 Is the IKE protocol flowchart (enhanced Kyber KEM and hybrid key negotiation details). Detailed implementation manners

[0030] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions in the embodiments of this application will be described below with reference to the accompanying drawings. In the description of the embodiments of this application, words such as "exemplary", "for example", or "for instance" are used to indicate examples, illustrations, or explanations. Any embodiment or design solution described as "exemplary", "for example", or "for instance" in the embodiments of this application should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Rather, the use of words such as "exemplary", "for example", or "for instance" is intended to present related concepts in a specific manner.

[0031] In the description of the embodiments of this application, the term "and / or" merely describes the association relationship of associated objects and indicates that three relationships may exist. For example, A and / or B may represent: A exists alone, B exists alone, and both A and B exist simultaneously. Additionally, unless otherwise specified, the meaning of the term "plural" refers to two or more. For example, multiple systems refer to two or more systems, and multiple CRPs refer to two or more challenge-response pairs.

[0032] Furthermore, the terms "first" and "second" are only used for descriptive purposes and cannot be construed as indicating or implying relative importance or implicitly specifying the indicated technical features. Thus, features defined with "first" and "second" may explicitly or implicitly include one or more of such features. The terms "include", "comprise", "have", and their variants all mean "including but not limited to", unless otherwise specifically emphasized in another way.

[0033] The embodiments of this application provide a method for enhancing the security of the IKE protocol based on PUF dynamic authentication and post-quantum hybrid keys. The core of this method lies in combining the physically unclonable function (PUF), the post-quantum cryptographic algorithm (PQC, specifically KyberKEM), and the improved Internet Key Exchange protocol (IKE) to achieve post-quantum secure key exchange and enhanced identity authentication. The specific implementation steps of this method will be described in detail below.

[0034] First, perform the client registration process, as Figure 1 shown. The client registration process is the basis of the entire method, used to establish a trust relationship between the client and the server and provide necessary parameters for subsequent key exchange and identity authentication.

[0035] The client registration process mainly includes the following steps:

[0036] Generate multiple random numbers: The client generates multiple random numbers as the challenge values (C1, C2...Cn) of the PUF. These random numbers are used to trigger different responses from the PUF, thereby enhancing security. The number n of random numbers should be large enough, and it is recommended that n >= 128 to provide sufficient security and diversity.

[0037] PUF module response: For each challenge value Ci, the PUF module of the client generates a PUF response value Ri based on the challenge value Ci. Due to the physical unclonable nature of the PUF, each challenge value will generate a unique and unpredictable response value. The specific type of PUF can be SRAM PUF, Ring Oscillator PUF, Arbiter PUF, or other types of PUF. The choice of which PUF depends on the specific hardware platform and security requirements.

[0038] Hash processing: Perform hash processing on each PUF response value Ri to obtain a hash value Hi = Hash(Ri). The purpose of hash processing is to convert the PUF response value into a hash value of a fixed length and ensure its one-wayness and collision resistance, further improving security. It is recommended to use the SHA-256 hash algorithm or a stronger hash algorithm to resist potential attacks.

[0039] Device registration: The client sends the device ID, multiple challenge values (C1...Cn), and multiple hash values (H1...Hn) to the server. The device ID is used to uniquely identify the client device, and the challenge values and hash values are used for subsequent authentication processes.

[0040] Return result: The server returns the registration result to the client, informing the client whether the registration is successful.

[0041] Device and CRP registration: The server stores the device ID and the corresponding multiple CRPs (challenge-response pairs) in the PUF database. It should be noted that what is stored in the PUF database is the hash value (H1...Hn) of the response value, rather than the original PUF response value (R1...Rn). The advantage of doing this is to prevent the leakage of the PUF response value. Even if the PUF database is obtained by an attacker, the original response of the PUF cannot be directly obtained.

[0042] The PUF database is used to store the CRP data generated during the client registration phase and provides a query interface for the server to use during the authentication phase. There are multiple ways to implement the PUF database:

[0043] Relational Database: Relational databases such as MySQL and PostgreSQL can be used to store CRP data. The database table structure can include the following fields: device_id (unique identifier of the client device, primary key), challenge (PUF challenge value), response_hash (hash value of the PUF response value), status (CRP status, e.g., "active", "used", "expired"), and metadata (other metadata, e.g., registration time, device model, etc.).

[0044] NoSQL Database: NoSQL databases such as MongoDB and Redis can be used to store CRP data. NoSQL databases generally have better scalability and performance and are suitable for storing large amounts of CRP data.

[0045] Dedicated Hardware Security Module (HSM): If very high security requirements are needed, an HSM can be used to store CRP data. An HSM is a hardware device specifically designed to protect keys and sensitive data and has functions of anti-tampering and anti-theft.

[0046] Regardless of the storage method adopted, appropriate security measures need to be taken to protect CRP data and prevent unauthorized access and tampering. For example, security measures such as encrypted storage, access control, and data backup can be adopted.

[0047] After the server receives the client's registration information, it will store the device ID and the corresponding CRP data in the PUF database. When storing, integrity verification of the CRP data needs to be performed to ensure that the data has not been tampered with during transmission.

[0048] When querying CRP data, the server queries the corresponding CRP record according to the client ID. When querying, available CRP can be selected according to the status field. The server can adopt strategies such as random selection, polling, or other strategies to select a challenge value from the available CRP and send it to the client.

[0049] After completing the client registration process, enter the IKE protocol process, as Figure 2 shown. The IKE protocol process is the core of this method and is used to negotiate keys and perform authentication between the client and the server.

[0050] IKE_SA_INIT Phase:

[0051] The client sends an IKE_SA_INIT request to the server, which includes the client ID, Kyber KEM parameters, and ECDH parameters. The client indicates in the request that it supports the Kyber KEM algorithm (e.g., Kyber768) and the ECDH algorithm (e.g., curve25519) for subsequent key negotiation.

[0052] An example of the IKE_SA_INIT request message (client -> server) is as follows:

[0053] HDR, SAi1, KEi, Ni, [IDi], [CP(KEM_ALGO=KYBER768)], [CP(KE_ALGO=CURVE25519)]

[0054] Where:

[0055] HDR: IKE header.

[0056] SAi1: Initiator (client) security proposal.

[0057] KEi: Initiator key exchange payload (containing Kyber or ECDH public parameters).

[0058] Ni: Initiator nonce.

[0059] [IDi]: Optional client identity.

[0060] [CP(...)]: Optional configuration payload for specifying algorithm preferences.

[0061] The server queries the PUF database, selects a PUF challenge value (based on a certain policy, such as random selection, polling, etc.), and returns the PUF challenge value, Kyber KEM parameters, and ECDH parameters in the IKE_SA_INIT response. The server selects the corresponding algorithm according to the client's request and selects a challenge value from the PUF database for subsequent PUF authentication.

[0062] An example of the IKE_SA_INIT response message (server -> client) is as follows:

[0063] HDR, SAr1, KEr, Nr, [IDr], [CP(KEM_ALGO=KYBER768)], [CP(KE_ALGO=CURVE25519)], [PUF_CHALLENGE=C_i]

[0064] Where:

[0065] HDR: IKE header.

[0066] SAr1:Responder (Server) Security Proposal.

[0067] KEr:Responder Key Exchange Payload (contains Kyber or ECDH public parameters).

[0068] Nr:Responder nonce.

[0069] [IDr]:Optional Server Identity.

[0070] [CP(...)]:Optional Configuration Payload for specifying algorithm selection.

[0071] [PUF_CHALLENGE = C_i]:PUF Challenge Value (C_i is selected from the PUF database).

[0072] IKE_INTERMEDIATE Phase (Kyber KEM Key Exchange):

[0073] The client generates a Kyber key pair (3.1). The client generates a public key (pk_C) and a private key (sk_C) pair required for the Kyber KEM algorithm.

[0074] The client sends the Kyber public key pk_C to the server via an IKE_INTERMEDIATE message (3.2).

[0075] An example of an IKE_INTERMEDIATE request message (client -> server) is as follows:

[0076] HDR, SK{KEi}

[0077] Where:

[0078] HDR:IKE Header.

[0079] SK{...}:Encrypted Payload (encrypted using the key negotiated in the IKE_SA_INIT phase).

[0080] KEi:The client's Kyber public key (pk_C).

[0081] The server generates a random number m (4.1). This random number is used in the Kyber KEM encapsulation process.

[0082] The server performs Kyber encapsulation to generate a ciphertext c and a shared key K_Kyber (4.2). The server uses the client's Kyber public key (pk_C) and the generated random number ( m), runs the encapsulation algorithm of Kyber KEM (KEM.Encaps) to generate a ciphertext ( c ), and a shared key ( K_Kyber ).

[0083] The server sends the ciphertext c to the client via an IKE_INTERMEDIATE message (4.3).

[0084] An example of an IKE_INTERMEDIATE response message (server -> client) is as follows:

[0085] HDR, SK{KEr}

[0086] Where:

[0087] HDR: IKE header.

[0088] SK{...}: Encrypted payload (encrypted using the key negotiated in the IKE_SA_INIT phase).

[0089] KEr: Ciphertext of Kyber encapsulation ( c ).

[0090] The client performs Kyber decapsulation to obtain the shared key K_Kyber (5.1). The client uses its own Kyber private key (sk_C) and the received ciphertext ( c ), runs the decapsulation algorithm of Kyber KEM (KEM.Decaps) to obtain the shared key ( K_Kyber ).

[0091] PUF Authentication:

[0092] The client's PUF module generates a response based on the challenge value sent by the server (5.2). The client, based on the challenge value (C_i) sent by the server in the IKE_SA_INIT phase, calls the PUF module to generate a response value (R_i). Then, the client calculates the hash value of the response value (H_i = Hash(R_i)) and generates a dynamic pre-shared key (PSK_PUF = KDF(H_i)) from the hash value using a key derivation function. The key derivation function can use HKDF (HMAC-based Extract-and-Expand Key Derivation Function) or other secure key derivation functions.

[0093] The client sends the encrypted PUF response (7). The client encrypts the hash value (H_i) of the PUF response using the negotiated key (generated by Kyber KEM and ECDH key exchange), and then sends it to the server via the IKE_AUTH message.

[0094] The server verifies the client's PUF response (6). The server retrieves the hash value (H_i') corresponding to the challenge value (C_i) from the PUF database and compares it with the result after decrypting the encrypted response sent by the client. If they are the same, the verification passes; otherwise, the verification fails. The server also uses the same hash function and key derivation function as the client to calculate the hash value of the expected PUF response.

[0095] IKE_AUTH phase:

[0096] The client and the server exchange the encrypted PUF response / authentication information (based on the negotiated key). This step is the standard process of the IKEv2 protocol for mutual authentication. In this application, it is mainly used to transmit and verify the PUF response.

[0097] An example of the IKE_AUTH request message (client -> server) is as follows:

[0098] HDR, SK{IDi, [AUTH], [SA], [TSi], [TSr]}

[0099] Among them, AUTH contains the hash value of the encrypted PUF response.

[0100] An example of the IKE_AUTH response message (server -> client) is as follows:

[0101] HDR, SK{IDr, [AUTH], [SA], [TSi], [TSr]}

[0102] The server can also choose to include its own PUF response in the response message (if two-way PUF authentication is required).

[0103] Key generation:

[0104] The client and the server respectively calculate the final shared key (9). The final shared key is calculated by the key derivation function KDF from the Kyber KEM key (K_Kyber), the ECDH key (K_ECDH), and the PSK generated by the PUF (PSK_PUF): K_final = KDF(K_Kyber || K_ECDH || PSK_PUF)

[0105] Among them, K_final is the final session key, K_Kyber is the Kyber negotiation key, K_ECDH is the ECDH negotiation key, PSK_PUF is the dynamic PSK derived from PUF, and KDF is the key derivation function (such as HKDF). By mixing three different key components (Kyber KEM key, ECDH key, and PUF-derived PSK) together, the security of the final key can be significantly improved, enabling it to resist classical computing attacks and quantum computing attacks. Even if one of the key components is compromised, the attacker cannot obtain the complete key information.

[0106] Establish IPsec SA:

[0107] The client and the server establish an IPsec SA (10) based on the final shared key (K_final). The IPsec SA is used to protect subsequent application data transmissions, providing data confidentiality, integrity, and authentication.

[0108] Thus, the security enhancement process of the IKE protocol based on PUF dynamic authentication and post-quantum hybrid keys is completed. This process realizes post-quantum secure key exchange and enhanced identity authentication, and can effectively resist classical computing attacks and quantum computing attacks.

[0109] Alternative:

[0110] Although this application mainly illustrates with Kyber KEM and SRAM PUF, Ring Oscillator PUF, Arbiter PUF as examples, those skilled in the art can understand that the technical solutions of this application can have various alternatives and extensions:

[0111] PUF type: In addition to SRAM PUF, Ring Oscillator PUF, Arbiter PUF, other types of PUF can also be used, such as Bistable Ring PUF, Transient Effect Ring Oscillator PUF, etc. Different PUFs have different characteristics and application scenarios, and can be selected according to specific requirements.

[0112] PQC algorithm: In addition to Kyber KEM, other NIST PQC standardized candidate algorithms can also be used, such as SABER, NTRU, etc. Different PQC algorithms have different security levels, performance, and key sizes, and can be selected according to specific requirements.

[0113] KDF algorithm: In addition to HKDF, other key derivation functions can also be used, such as the KDF defined in NIST SP 800-108 or other secure key derivation functions.

[0114] ECDH algorithm: Different elliptic curve parameters can be selected according to actual needs, such as curve25519, P-256, P-384, etc.

[0115] These alternative solutions all fall within the protection scope of this application. Those skilled in the art can make various modifications and deformations to this application without departing from the spirit and scope of this application.

[0116] In the embodiments of this application, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the embodiments of this application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center in a wired manner (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or a wireless manner (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that can be accessed by a computer, or a data storage device such as a server or data center that includes one or more integrated available media. The available medium can be a magnetic medium (such as a floppy disk, hard disk, magnetic tape), an optical medium (such as a DVD), or a semiconductor medium (such as a solid state disk (SSD)), etc.

[0117] It can be understood that the various numerical numbers involved in the embodiments of this application are only for the convenience of description and are not used to limit the scope of the embodiments of this application. It should be understood that in the embodiments of this application, the magnitudes of the sequence numbers of the above processes do not mean the order of execution. The order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of this application.

[0118] The specific embodiments described above further elaborate on the purpose, technical solutions, and beneficial effects of this application. It should be understood that the above is only the specific embodiments of this application and is not used to limit the protection scope of this application. Any modifications, equivalent replacements, improvements, etc. made on the basis of the technical solutions of this application should be included in the protection scope of this application.

Claims

1. A security enhancement method for IKE protocol based on PUF dynamic authentication and post-quantum hybrid key, characterized in that, The method includes: In the client registration phase, multiple challenge-response pairs (CRPs) are generated using a Physical Unclonable Function (PUF) and securely stored on the server. In the IKE_SA_INIT phase, the server selects a PUF challenge value and sends it to the client. The client uses the PUF to generate a response corresponding to the challenge value and derives a dynamic pre-shared key (PSK) based on the hash value of the response. In the IKE_INTERMEDIATE phase, the Kyber Key Encapsulation Mechanism (KEM) is used for key exchange to generate a Kyber negotiation key. At the same time, Elliptic Curve Diffie-Hellman (ECDH) is used for key exchange to generate an ECDH negotiation key. The dynamic PSK derived from the PUF is used as the pre-shared key for the IKE authentication method. The final session key is jointly generated by the Kyber negotiation key, the ECDH negotiation key, and the dynamic PSK derived from the PUF.

2. The method according to claim 1, wherein The client registration phase includes: The client generates multiple random numbers as challenge values for the PUF. The client's PUF module generates PUF response values according to each challenge value. Each PUF response value is hashed to obtain a hash value. The client sends the device ID, the multiple challenge values, and the multiple hash values to the server. The server stores the device ID and the corresponding multiple CRPs in the PUF database, where the response value in the CRP is the hash value.

3. The method according to claim 1, wherein In the IKE_INTERMEDIATE phase, using Kyber KEM for key exchange to generate a Kyber negotiation key includes: The client generates a Kyber key pair. The client sends the Kyber public key to the server. The server generates a random number. The server uses the client's Kyber public key and the random number to run the encapsulation algorithm of Kyber KEM to generate a ciphertext and a Kyber negotiation key. The server sends the ciphertext to the client. The client uses its own Kyber private key and the received ciphertext to run the decapsulation algorithm of Kyber KEM to obtain the Kyber negotiation key.

4. The method according to claim 1, characterized in that The generation method of the final session key is: K_final = KDF(K_Kyber || K_ECDH || PSK_PUF) where K_final is the final session key, K_Kyber is the Kyber negotiation key, K_ECDH is the ECDH negotiation key, PSK_PUF is the dynamic PSK derived from the PUF, and KDF is the key derivation function.

5. The method according to claim 1, wherein The method further includes: In the IKE_AUTH phase, the client and the server exchange encrypted PUF responses or authentication information.

6. The method according to claim 2, wherein The PUF database is implemented using a relational database, a NoSQL database, or a dedicated Hardware Security Module (HSM).

7. The method according to claim 2, wherein The CRP data is stored using security measures such as encrypted storage or access control.

8. The method according to claim 1, characterized in that The PUF is an SRAM PUF, Ring Oscillator PUF, Arbiter PUF, Bistable Ring PUF, or Transient Effect Ring Oscillator PUF.

9. The method according to claim 1, wherein The Kyber KEM is replaced by the SABER KEM or NTRU KEM.

10. The method according to claim 4, characterized in that The KDF is the HKDF or the KDF defined in NIST SP 800-108.

Citation Information

Cited By

  • Identity authentication method and related equipment

    CN120602103A

  • Identity authentication method and related device

    CN120602103B

  • IPSec VPN security gateway communication method based on post quantum cryptography

    CN120768614A

  • Wafer information encryption authentication method and system, server and storage medium

    CN121030721A

  • QKD remote key distribution method, system and device based on PQC channel and medium

    CN121923817A